From 2ca139f2f7115b8f3855424c7c4b32aaa3b84fe5 Mon Sep 17 00:00:00 2001 From: "Joshua J. Bouw" Date: Tue, 15 Sep 2026 09:46:25 +0400 Subject: [PATCH] feat(wit): expose authenticated connection principal Signed-off-by: Joshua J. Bouw --- host/request-context@1.0.0.wit | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/host/request-context@1.0.0.wit b/host/request-context@1.0.0.wit index 360806a..443159e 100644 --- a/host/request-context@1.0.0.wit +++ b/host/request-context@1.0.0.wit @@ -16,4 +16,11 @@ interface host { /// authenticated strongly enough to own interactive requests. Consumers /// must fail closed for owner-scoped prompts when this is `none`. connection-owner: func(connection: borrow) -> result, error-code>; + + /// Return the principal authenticated for an accepted local connection. + /// + /// `none` means the stream is outbound, remotely accepted, or did not + /// complete principal authentication. A bridge must not substitute a + /// payload-supplied principal when this is `none`. + connection-principal: func(connection: borrow) -> result, error-code>; }