| name | dapr-middleware-validator |
| description | Automatically validate DAPR HTTP middleware configuration files. Checks for correct middleware types, proper secret references, pipeline ordering, and security best practices. Use when configuring OAuth2, Bearer tokens, OPA policies, rate limiting, or other middleware. |
| allowed-tools | Read, Grep, Glob |
DAPR Middleware Configuration Validator
This skill validates DAPR HTTP middleware components for security and correctness.
When to Use
Claude automatically uses this skill when:
- A middleware YAML file is created or modified
- User configures OAuth2, Bearer, OPA, or rate limiting
- Pipeline configuration is being set up
- Before deploying middleware-protected APIs
Middleware Types
Authentication Middleware
| Type | Component Type | Purpose |
|---|
| OAuth2 | middleware.http.oauth2 | Authorization Code flow |
| OAuth2 CC | middleware.http.oauth2clientcredentials | Service-to-service auth |
| Bearer | middleware.http.bearer | JWT/OIDC token validation |
Authorization Middleware
| Type | Component Type | Purpose |
|---|
| OPA | middleware.http.opa | Policy-based authorization |
Traffic Control Middleware
| Type | Component Type | Purpose |
|---|
| Rate Limit | middleware.http.ratelimit | Request throttling |
| Sentinel | middleware.http.sentinel | Circuit breaker/flow control |
Request Processing Middleware
| Type | Component Type | Purpose |
|---|
| Router Alias | middleware.http.routeralias | Route rewriting |
| Router Checker | middleware.http.routerchecker | Route validation |
| WASM | middleware.http.wasm | Custom WebAssembly logic |
| Uppercase | middleware.http.uppercase | Testing only |
Validation Rules
OAuth2 Middleware Validation
apiVersion: dapr.io/v1alpha1
kind: Component
metadata:
name: oauth2
spec:
type: middleware.http.oauth2
version: v1
metadata:
- name: clientId
secretKeyRef:
name: oauth-secrets
key: client-id
- name: clientSecret
secretKeyRef:
name: oauth-secrets
key: client-secret
- name: scopes
value: "openid profile"
- name: authURL
value: "https://..."
- name: tokenURL
value: "https://..."
- name: redirectURL
value: "..."
Checks performed:
Bearer Token Validation
spec:
type: middleware.http.bearer
metadata:
- name: audience
value: "api://..."
- name: issuer
value: "https://..."
Checks performed:
OPA Middleware Validation
spec:
type: middleware.http.opa
metadata:
- name: defaultStatus
value: "403"
- name: rego
value: |
package http
default allow = false # REQUIRED: Default deny
Checks performed:
Rate Limit Validation
spec:
type: middleware.http.ratelimit
metadata:
- name: maxRequestsPerSecond
value: "100"
Checks performed:
Sentinel Validation
spec:
type: middleware.http.sentinel
metadata:
- name: appName
value: "my-service"
- name: flowRules
value: |
[...]
Checks performed:
WASM Validation
spec:
type: middleware.http.wasm
metadata:
- name: url
value: "file://..."
Checks performed:
Router Alias Validation
spec:
type: middleware.http.routeralias
metadata:
- name: routes
value: |
{"/api": "/v1.0/invoke/..."}
Checks performed:
Router Checker Validation
spec:
type: middleware.http.routerchecker
metadata:
- name: rule
value: "^[A-Za-z0-9/._-]+$"
Checks performed:
Pipeline Order Validation
Correct middleware ordering:
spec:
httpPipeline:
handlers:
- name: routerchecker
type: middleware.http.routerchecker
- name: ratelimit
type: middleware.http.ratelimit
- name: bearer-auth
type: middleware.http.bearer
- name: opa-authz
type: middleware.http.opa
- name: routeralias
type: middleware.http.routeralias
Order checks:
Security Checks
Critical Security Issues
- Plain-text credentials - clientId/clientSecret not in secretKeyRef
- HTTP URLs - Auth/token URLs using HTTP instead of HTTPS
- Default allow - OPA policy without explicit default deny
- No rate limiting - APIs without request throttling
Warnings
- Missing forceHTTPS - OAuth2 without HTTPS enforcement
- High rate limits - Very permissive request limits
- Overly permissive OPA - Policies with broad allow rules
- Missing headers - OPA not checking Authorization header
Output Format
DAPR Middleware Validation Report
==================================
✓ components/oauth2-auth.yaml - Valid
- Type: middleware.http.oauth2
- Credentials use secretKeyRef: Yes
- HTTPS enforced: Yes
⚠ components/ratelimit.yaml - Warning
- Type: middleware.http.ratelimit
- Warning: Rate limit of 10000 RPS is very high
- Recommendation: Consider lower limit for public APIs
✗ components/bearer-auth.yaml - Invalid
- Type: middleware.http.bearer
- Error: Missing required field 'audience'
- Error: 'issuer' uses HTTP instead of HTTPS
Pipeline Analysis:
✗ Rate limiting should come BEFORE authentication middleware
Current order: [bearer-auth, ratelimit]
Recommended: [ratelimit, bearer-auth]
Security Summary:
- Critical: 1 (plain-text credentials)
- Warnings: 2
- Valid: 3
Common Issues and Fixes
Plain-Text Credentials
- name: clientSecret
value: "my-secret-key"
- name: clientSecret
secretKeyRef:
name: oauth-secrets
key: client-secret
HTTP Instead of HTTPS
- name: tokenURL
value: "http://auth.example.com/token"
- name: tokenURL
value: "https://auth.example.com/token"
Default Allow in OPA
# BAD (insecure - allows everything by default)
package http
default allow = true
# GOOD (secure - denies by default)
package http
default allow = false
allow { ... specific conditions ... }
Wrong Pipeline Order
handlers:
- name: oauth2
type: middleware.http.oauth2
- name: ratelimit
type: middleware.http.ratelimit
handlers:
- name: ratelimit
type: middleware.http.ratelimit
- name: oauth2
type: middleware.http.oauth2
Integration Points
This skill integrates with:
middleware-expert agent for detailed configuration help
security-scanner skill for broader security analysis
/dapr:middleware command to generate valid configs
/dapr:security command for pre-deployment checks