data-api: drop unused jwks_uri from discovery struct · Entire

data-api: drop unused jwks_uri from discovery struct

049e66c→main·

toothbrush·1mo ago·3 files·+12 added/-7 removed

The CLI never fetches JWKS — that's a server-side verification concern — so modelling the field only created a name/shape coupling to the server. entire.io#2281 renames it to jwks_uris (plural); rather than chase that, drop the field entirely. Go ignores unknown JSON fields on decode, so the server can evolve it freely. Test body now sends jwks_uris to prove we tolerate it.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com

Sessions

cb5ddec166d9View transcript

Changes

3

83 unmodified lines

84
85
86
87
87
88
89
90
91
92
93
94
95
96
97

83 unmodified lines

"issuer": "https://us.auth.partial.to",
  "trusted_issuers": ["https://us.auth.partial.to", "https://eu.auth.partial.to"],
  "audience": "https://partial.to",
  "jwks_uri": "https://us.auth.partial.to/.well-known/jwks.json"
  "jwks_uris": {"https://us.auth.partial.to": "https://us.auth.partial.to/.well-known/jwks.json"}
}
```

The CLI reads only `trusted_issuers` and `audience`; `jwks_uris` is a
server-side verification concern (the CLI never fetches JWKS) and is ignored
on decode, so the server can evolve that field freely.

> **Audience = the data host origin, not an opaque string.** entire.io's
> `ENTIRE_CORE_JWT_AUDIENCE` is `https://entire.io` (prod) / `https://partial.to`
> (staging). The core's STS exchange stamps `aud` = the requested audience for

Mdocs/architecture/upstream-host-resolution.md+5/-1

```
30 unmodified lines

31
32
33
34
35
36
37
34
35
36
37
38
39
40

30 unmodified lines

// advertised (not assumed) so the server can change it without a CLI
    // release.
    Audience string `json:"audience"`
    // JWKSURI is where Issuer publishes its signing keys. Informational
    // for the CLI today; the API uses it server-side to verify inbound
    // tokens.
    JWKSURI string `json:"jwks_uri"`
    // The server also advertises its JWKS URI(s) for verifying inbound
    // tokens, but that's a server-side concern — the CLI never fetches
    // JWKS — so we don't model the field here. Unknown JSON fields are
    // ignored on decode, so the server's shape can evolve freely.
    //
}

// ErrDiscoveryUnavailable wraps every "the API didn't give us a usable
```

Minternal/entireclient/clusterdiscovery/api_discovery.go+4/-4

```
22 unmodified lines

23
24
25
26
27
28
29
30
31
30
32
33
34
35
107 unmodified lines

143
144
145
144
146
147
148

22 unmodified lines

return s.base.RoundTrip(req)

// apiDiscoveryBody includes jwks_uris (the server's real field, plural per
// entire.io#2281) to prove the CLI ignores fields it doesn't model.
const apiDiscoveryBody = `{
"issuer": "https://us.auth.partial.to",
"trusted_issuers": ["https://us.auth.partial.to", "https://eu.auth.partial.to"],
"audience": "https://partial.to",
"jwks_uri": "https://us.auth.partial.to/.well-known/jwks.json"
"jwks_uris": {"https://us.auth.partial.to": "https://us.auth.partial.to/.well-known/jwks.json"}
}`

func TestDiscoverAPI(t *testing.T) {
107 unmodified lines

Issuer:         trustedIssuers[0],
        TrustedIssuers: trustedIssuers,
        Audience:       apiTestAudience,
        JWKSURI:        trustedIssuers[0] + "/.well-known/jwks.json",
    }
    body, err := json.Marshal(doc)
    require.NoError(t, err)
```

Minternal/entireclient/clusterdiscovery/api_discovery_test.go+3/-2