Validations
Gateway Ocelot Parity Validation (Server-Side)
Interpretation rule: protected routes should return `401` without JWT and should return non-`401` with JWT (allow-path reached upstream).
Metadata
- Captured UTC: 2026-04-15T23:51:32Z
- Validation method:
- route smoke: VPS shell probes to Kong proxy using
docker run --rm --network proxy curlimages/curl:8.11.1 ... -H 'Host: api.perspective-v.com' - rewrite extraction: Kong Admin API reads (
/routes,/plugins) with route-id mapping to route names
- route smoke: VPS shell probes to Kong proxy using
- JWT test issuer:
https://identity.perspective-v.com - JWT algorithm:
HS256
Route Smoke Matrix
Interpretation rule: protected routes should return 401 without JWT and should return non-401 with JWT (allow-path reached upstream).
| Probe | Expected parity behavior | Observed HTTP | Result | Notes |
|---|---|---|---|---|
public_identity_auth_no_jwt | Public route is not JWT-gated | 415 | Pass | Not 401; upstream/content-type validation reached |
protected_identity_no_jwt | Protected route denies missing JWT | 401 | Pass | JWT gate enforced |
protected_identity_with_jwt | Protected route allows valid JWT | 404 | Pass | Non-401; request passed JWT gate |
public_graph_resume_no_jwt | Public route is not JWT-gated | 415 | Pass | Not 401; upstream/content-type validation reached |
protected_graph_no_jwt | Protected route denies missing JWT | 401 | Pass | JWT gate enforced |
protected_graph_with_jwt | Protected route allows valid JWT | 500 | Pass | Non-401; JWT allow-path reached upstream, upstream returned application error |
public_syassoc_no_jwt | Public route is not JWT-gated | 404 | Pass | Not 401; public route path reached |
private_syassoc_no_jwt | Private route denies missing JWT | 401 | Pass | JWT gate enforced |
private_syassoc_with_jwt | Private route allows valid JWT | 404 | Pass | Non-401; request passed JWT gate |
Request-Transformer Rewrite Evidence
request-transformer plugin rewrites tagged under ocelot-migration:
| Kong route | replace.uri |
|---|---|
syassociates-public | /api/v$(uri_captures.version)/public/$(uri_captures.endpoint) |
graph-resume-public | /graph/resume |
identity-protected | /api/v$(uri_captures.version)/$(uri_captures.endpoint) |
graph-protected | /graph/$(uri_captures.endpoint) |
identity-auth-public | /api/v$(uri_captures.version)/auth/$(uri_captures.endpoint) |
syassociates-private | /api/v$(uri_captures.version)/private/$(uri_captures.endpoint) |
pv-web-protected | /api/v$(uri_captures.version)/$(uri_captures.endpoint) |
sms-protected | /api/v$(uri_captures.version)/$(uri_captures.endpoint) |
Conclusion
- JWT protected-only parity is confirmed for migrated protected/public route sets.
- Kong rewrite policy inventory for migrated routes is present and mapped by route name.