fix: make runtime prefetch task registration executable end-to-end

SchedulerClient.register_volatile_fetch (consolidation's prefetch
routing) registered tasks that were dead on arrival:
- JSON body stored under 'body', which rest_api_executor ignores
  (it only reads config['payload'])
- no auth block, so the scheduled POST to /volatile/fetch would 401
  against library-desk's verify_api_key
- user placed in the body while /volatile/fetch endpoints require it
  as a query parameter (RequiredUserQuery) - would 422 regardless

The task config now carries user in the URL query string (encoded),
an empty payload, and auth {type: bearer, token: ${LIBRARY_API_KEY}}
substituted Scheduler-side (never stored raw).

SchedulerClient also sent no Authorization to the Scheduler API itself,
so registration 401'd silently at consolidation time; it now sends
Bearer auth from the new scheduler_api_key setting.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QbFZyDvYksazX6nYQYZ67L
This commit is contained in:
2026-07-14 15:16:09 +02:00
co-authored by Claude Fable 5
parent b4a5a92fee
commit bc68d3b691
5 changed files with 173 additions and 7 deletions
+7
View File
@@ -145,6 +145,13 @@ class Settings(BaseSettings):
# Scheduler Service
scheduler_url: str = Field(default="http://scheduler:8090", description="Scheduler service URL")
scheduler_api_key: str = Field(
default="",
description=(
"Bearer key for the Scheduler's auth-guarded task-management API; "
"required for runtime prefetch task registration"
),
)
@property
def qdrant_url(self) -> str: