Skip to content

WPB-29133 add runtime controlled development version for federation API - #5582

Open
battermann wants to merge 10 commits into
developfrom
WPB-29133-backend-add-runtime-controlled-development-version-for-federation-api
Open

battermann wants to merge 10 commits into
developfrom
WPB-29133-backend-add-runtime-controlled-development-version-for-federation-api

Conversation

@battermann

@battermann battermann commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

https://wearezeta.atlassian.net/browse/WPB-29133

Checklist

  • Add a new entry in an appropriate subdirectory of changelog.d
  • Read and follow the PR guidelines

@zebot zebot added the ok-to-test Approved for running tests in CI, overrides not-ok-to-test if both labels exist label Oct 2, 2026
@battermann
battermann marked this pull request as ready for review October 2, 2026 14:10
@battermann
battermann requested review from a team as code owners October 2, 2026 14:10
@battermann
battermann requested a lite review from Copilot October 2, 2026 14:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical federation enforcement, negotiation, compatibility, and configuration issues remain unresolved.

Review effort: Lite
Findings: 7 High severity · 1 Medium severity

Open (8)
What changed in this PR

Adds runtime-controlled Federation API V5 support, including version negotiation, middleware enforcement, service configuration, tests, Helm wiring, and documentation.

Changes:

  • Adds federation version configuration and V5 handling.
  • Propagates enabled versions through services and clients.
  • Adds tests, deployment settings, documentation, and a changelog entry.

Blocking findings:

  • Critical (1 vote): Version.hs allows /v5/federation/... to bypass disabled-version checks.
  • Critical (3 votes each): The same path-prefix bypass exists in Brig, Galley, and Cargohold middleware.
  • Critical (1 vote): Disabling V0 breaks the unversioned discovery endpoint and negotiation.
  • Critical (1 vote): The legacy supported field still advertises disabled versions.
  • Moderate (2 votes): Background notifications unconditionally use V0.
  • Critical (1 vote): Checked-in federation deployment fixtures lack the required configuration field.
File Summary
services/​galley/​src/​Galley/​Run.hs Adds federation version middleware.
services/​galley/​src/​Galley/​App.hs Supplies configured federation versions.
services/​galley/​galley.integration.yaml Adds integration configuration.
services/​federator/​test/​unit/​Test/​Federator/​Client.hs Updates client test environments.
services/​cargohold/​src/​CargoHold/​Run.hs Adds federation version middleware.
services/​cargohold/​src/​CargoHold/​Options.hs Adds federation version settings.
services/​cargohold/​src/​CargoHold/​Federation.hs Propagates configured versions.
services/​cargohold/​cargohold.integration.yaml Adds integration configuration.
services/​brig/​test/​integration/​API/​Federation.hs Updates federation integration tests.
services/​brig/​src/​Brig/​Run.hs Adds federation version middleware.
services/​brig/​src/​Brig/​Options.hs Parses federation settings.
services/​brig/​src/​Brig/​CanonicalInterpreter.hs Supplies configured versions.
services/​brig/​src/​Brig/​App.hs Stores federation version settings.
services/​brig/​src/​Brig/​API/​Federation.hs Filters advertised versions.
services/​brig/​brig.integration.yaml Adds integration configuration.
services/​background-worker/​test/​Test/​Wire/​Util.hs Updates test environments.
services/​background-worker/​test/​Test/​Wire/​BackendNotificationPusherSpec.hs Updates notification tests.
services/​background-worker/​src/​Wire/​Effects.hs Propagates federation versions.
services/​background-worker/​src/​Wire/​BackgroundWorker/​Env.hs Computes enabled versions.
services/​background-worker/​src/​Wire/​BackendNotificationPusher.hs Applies versions to notifications.
libs/​wire-subsystems/​src/​Wire/​Options/​Galley.hs Adds Galley federation settings.
libs/​wire-subsystems/​src/​Wire/​FederationAPIAccess/​Interpreter.hs Propagates client version state.
libs/​wire-api-federation/​wire-api-federation.cabal Registers dependencies and tests.
libs/​wire-api-federation/​test/​Test/​Wire/​API/​Federation/​API/​VersionSpec.hs Tests federation version behavior.
libs/​wire-api-federation/​src/​Wire/​API/​Federation/​Version.hs Implements V5, configuration, and middleware.
libs/​wire-api-federation/​src/​Wire/​API/​Federation/​Client.hs Uses configured versions for negotiation.
integration/​test/​Test/​Version.hs Adds integration coverage.
integration/​test/​API/​Brig.hs Adds federation version requests.
hack/​helm_vars/​wire-server/​values.yaml.gotmpl Configures integration defaults.
docs/​src/​developer/​reference/​config-options.md Documents federation settings.
docs/​src/​developer/​developer/​api-versioning.md Documents federation versioning.
charts/​wire-server/​values.yaml Sets the default disabled version.
charts/​wire-server/​templates/​galley/​configmap.yaml Renders Galley settings.
charts/​wire-server/​templates/​cargohold/​configmap.yaml Renders Cargohold settings.
charts/​wire-server/​templates/​brig/​configmap.yaml Renders Brig settings.
changelog.d/​6-federation/​WPB-29133 Adds the changelog entry.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread libs/wire-api-federation/src/Wire/API/Federation/Version.hs
Comment thread libs/wire-api-federation/src/Wire/API/Federation/Version.hs
Comment thread libs/wire-api-federation/src/Wire/API/Federation/Version.hs
Comment thread services/brig/src/Brig/Options.hs
Comment thread services/brig/src/Brig/Run.hs Outdated
Comment thread services/cargohold/src/CargoHold/Run.hs Outdated
Comment thread services/galley/src/Galley/Run.hs Outdated
Comment thread services/background-worker/src/Wire/BackendNotificationPusher.hs
Comment thread docs/src/developer/developer/api-versioning.md
Comment thread integration/test/Test/Version.hs
Comment thread services/cargohold/src/CargoHold/Federation.hs Outdated
Comment thread libs/wire-api-federation/src/Wire/API/Federation/Version.hs Outdated
Comment thread services/brig/src/Brig/Run.hs Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

toJSON VersionInfo {vinfoSupported} =
Aeson.object
[ "supported_versions" Aeson..= vinfoSupported,
"supported" Aeson..= filter (`elem` [0, 1]) vinfoSupported
Comment thread services/background-worker/src/Wire/BackendNotificationPusher.hs Outdated
-- this also rewrites the request
. requestIdMiddleware e.appLogger defaultRequestIdHeaderName
. Metrics.servantPrometheusMiddleware (Proxy @ServantCombinedAPI)
. federationVersionMiddleware e.disabledFederationVersions
versionMiddleware (foldMap expandVersionExp o.settings.disabledAPIVersions)
. requestIdMiddleware e.appLogger defaultRequestIdHeaderName
. servantPrometheusMiddleware (Proxy @CombinedAPI)
. federationVersionMiddleware (foldMap Federation.expandVersionExp o.settings.disabledFederationAPIVersions)
Comment on lines +114 to +115
. federationVersionMiddleware
(foldMap Federation.expandVersionExp (opts ^. settings . disabledFederationAPIVersions))
@battermann
battermann requested a review from blackheaven October 2, 2026 16:14

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ok-to-test Approved for running tests in CI, overrides not-ok-to-test if both labels exist

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants