data-api: drop unused jwks_uri from discovery struct · Entire
data-api: drop unused jwks_uri from discovery struct
049e66c→main·
toothbrush·1mo ago·3 files·+12 added/-7 removed
The CLI never fetches JWKS — that's a server-side verification concern — so modelling the field only created a name/shape coupling to the server. entire.io#2281 renames it to jwks_uris (plural); rather than chase that, drop the field entirely. Go ignores unknown JSON fields on decode, so the server can evolve it freely. Test body now sends jwks_uris to prove we tolerate it.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com
Sessions
cb5ddec166d9View transcript
Changes
3
docs/architecture
- Mupstream-host-resolution.md+5/-1
internal/entireclient/clusterdiscovery
Mapi_discovery.go+4/-4
Mapi_discovery_test.go+3/-2
83 unmodified lines
84
85
86
87
87
88
89
90
91
92
93
94
95
96
97
83 unmodified lines
"issuer": "https://us.auth.partial.to",
"trusted_issuers": ["https://us.auth.partial.to", "https://eu.auth.partial.to"],
"audience": "https://partial.to",
"jwks_uri": "https://us.auth.partial.to/.well-known/jwks.json"
"jwks_uris": {"https://us.auth.partial.to": "https://us.auth.partial.to/.well-known/jwks.json"}
}
```
The CLI reads only `trusted_issuers` and `audience`; `jwks_uris` is a
server-side verification concern (the CLI never fetches JWKS) and is ignored
on decode, so the server can evolve that field freely.
> **Audience = the data host origin, not an opaque string.** entire.io's
> `ENTIRE_CORE_JWT_AUDIENCE` is `https://entire.io` (prod) / `https://partial.to`
> (staging). The core's STS exchange stamps `aud` = the requested audience for
Mdocs/architecture/upstream-host-resolution.md+5/-1
```
30 unmodified lines
31
32
33
34
35
36
37
34
35
36
37
38
39
40
30 unmodified lines
// advertised (not assumed) so the server can change it without a CLI
// release.
Audience string `json:"audience"`
// JWKSURI is where Issuer publishes its signing keys. Informational
// for the CLI today; the API uses it server-side to verify inbound
// tokens.
JWKSURI string `json:"jwks_uri"`
// The server also advertises its JWKS URI(s) for verifying inbound
// tokens, but that's a server-side concern — the CLI never fetches
// JWKS — so we don't model the field here. Unknown JSON fields are
// ignored on decode, so the server's shape can evolve freely.
//
}
// ErrDiscoveryUnavailable wraps every "the API didn't give us a usable
```
Minternal/entireclient/clusterdiscovery/api_discovery.go+4/-4
```
22 unmodified lines
23
24
25
26
27
28
29
30
31
30
32
33
34
35
107 unmodified lines
143
144
145
144
146
147
148
22 unmodified lines
return s.base.RoundTrip(req)
// apiDiscoveryBody includes jwks_uris (the server's real field, plural per
// entire.io#2281) to prove the CLI ignores fields it doesn't model.
const apiDiscoveryBody = `{
"issuer": "https://us.auth.partial.to",
"trusted_issuers": ["https://us.auth.partial.to", "https://eu.auth.partial.to"],
"audience": "https://partial.to",
"jwks_uri": "https://us.auth.partial.to/.well-known/jwks.json"
"jwks_uris": {"https://us.auth.partial.to": "https://us.auth.partial.to/.well-known/jwks.json"}
}`
func TestDiscoverAPI(t *testing.T) {
107 unmodified lines
Issuer: trustedIssuers[0],
TrustedIssuers: trustedIssuers,
Audience: apiTestAudience,
JWKSURI: trustedIssuers[0] + "/.well-known/jwks.json",
}
body, err := json.Marshal(doc)
require.NoError(t, err)
```
Minternal/entireclient/clusterdiscovery/api_discovery_test.go+3/-2