Files
OpenShell/docs/observability
Adel Zaalouk 472e23f96a fix(proxy): include OPA deny reason in CONNECT 403 response (#2363)
* fix(proxy): include OPA deny reason in CONNECT 403 response

When a CONNECT request was denied by OPA policy, the 403 response
used a generic "not permitted by policy" message for both "endpoint
not in policy" and "endpoint matched but binary didn't match." Users
had no way to distinguish the two without reading supervisor logs.

The OPA policy already computes a detailed deny_reason (e.g.,
"binary '/usr/bin/node' not allowed in policy 'X'") but the proxy
was not including it in the HTTP response.

Now the CONNECT deny response includes a "reason" field with the
OPA deny reason when available. When the reason is empty, the field
is omitted for backward compatibility.

Fixes #2355

Signed-off-by: Adel Zaalouk <azaalouk@redhat.com>

* docs(observability): document optional reason field in CONNECT 403 response

The proxy now includes a reason field in the JSON body of denied
CONNECT responses when the policy engine provides a specific denial
cause. Update the Proxy Error Responses section to show the field
and describe when it is present vs omitted.

Signed-off-by: Adel Zaalouk <azaalouk@redhat.com>

---------

Signed-off-by: Adel Zaalouk <azaalouk@redhat.com>
2026-07-21 16:14:32 +00:00
..
2026-05-12 16:36:15 -07:00
2026-05-12 16:36:15 -07:00