Skip to main content

Using Anypoint Code Builder with agent-fabric-transformation 1.6.0 (agent-network.yaml, agentNetwork: 2.0.0).

Every Deploy logs this warning for my AgentScript broker:

Warning: Broker 'customer_support_broker' does not declare an 'authorization' configuration, so it will fall back to the 'user-context-propagation' policy defaults: userIdExpression '#authentication.clientId' and allowAnonymousAccess true (requests whose principal cannot be determined are forwarded anonymously). To change this, set authorization under the broker's interfaces.a2a section, e.g.:

brokers: 

    customer_support_broker: 

       interfaces: 

          a2a: 

             authorization: 

                 principal: '

#attributes.clientId

' 

                 allowAnonymousAccess: false 

 

At runtime this also throws a recurring "User ID expression resolved to invalid non-string value" warning, since I have no Client ID Enforcement policy configured (I don't need real caller identity — this broker isn't meant to authenticate clients).

Problem: following the warning's own suggested fix fails Build validation:

Message: brokers/customer_support_broker/interfaces/a2a must NOT have additional properties

So authorization isn't actually a field the current agent-network.yaml schema (v2, as validated by agent-fabric-transformation 1.6.0) accepts under interfaces.a2a — it only allows card and policies.

I then tried explicitly declaring the policy under policies.inbound instead:

brokers: 

     customer_support_broker: 

         interfaces: 

             a2a: 

                 policies: 

                     inbound: 

                         - policy: 

                             ref: 

                                 name: user-context-propagation 

                                 namespace: 68ef9520-24e9-4cf2-b2f5-620025690913 

                             configuration: 

                                 userIdExpression: '

#"anonymous"

' 

                                 allowAnonymousAccess: true

(namespace taken from the groupId on the built connection.json's policyRef for this same policy). This passes schema validation but fails with:

Cannot resolve reference user-context-propagation of kind policy (http://a.ml/vocabularies/data#invalid-reference-like)

Questions:

  1. What's the actual supported syntax to override this auto-injected default policy's configuration from agent-network.yaml?
  2. Is the authorization block from the warning message a planned/upcoming field not yet implemented in 1.6.0, or am I missing something?
  3. Alternatively, is there a supported way to just suppress the userIdExpression warning without adding real Client ID Enforcement?

Happy to share the full agent-network.yaml if useful. 

 

#MuleSoft For Agentforce  #MuleSoft  #MuleSoft Anypoint Code Builder

0/9000