# cli/api: route pinned --jurisdiction to its own cell; address review

`04c7cd2`→[main](/content/gh/entireio/cli/commits/main/index.html)·

Soph·1w ago·3 files·+46 added/-7 removed

Two fixes from PR review:

\- Cursor Bugbot (correctness): when `--jurisdiction` was set, the CellTarget carried only Jurisdiction (no BaseURL). If the configured data origin was already a direct entire-api cell (a ".api." host) rather than an apex/BFF, auth kept that origin as the dial target while minting an identity token for the *pinned* jurisdiction — so `--jurisdiction eu` could mint an EU token but still dial the configured (e.g. US) cell. Fix in auth.resolveTargetCellBaseURL: an explicitly pinned jurisdiction on a non-loopback origin now resolves that jurisdiction's own cell from the cluster catalog (reusing resolveCellAPIBaseURL) instead of dialing the origin verbatim. Loopback dev hosts still stay verbatim (single cell, no catalog). Only the new Jurisdiction-pinned-without-BaseURL path is affected; nil-target (home) and BaseURL-set (repo-scoped experts) paths are unchanged.

\- Copilot (nit): TestResolveAPITarget now uses the apiTargetCore/apiTargetCell constants instead of hard-coded "core"/"cell" literals.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

## Sessions

51810afcea3cView transcript

## Changes

3

- cmd/entire/cli

- Mapi_cmd_test.go+4/-5

- auth

- Mcell_data_api.go+22/-2

- Mcell_data_api_test.go+20

```
149 unmodified lines

150
151
152
153
153
154
155
3 unmodified lines

159
160
161
163
162
163
165
164
165
167
166
167
169
168
169
170
171

149 unmodified lines

func TestResolveAPITarget(t *testing.T) {
	t.Parallel()

const cell = "cell"
	for _, tc := range []struct {
		name       string
		flags      apiFlags
3 unmodified lines

wantErr    bool
	} {
		// No --jurisdiction: --to is passed through untouched.
		{"default", apiFlags{to: "core"}, false, "core", "", false},
		{"default", apiFlags{to: apiTargetCore}, false, apiTargetCore, "", false},
		// --jurisdiction with default --to: implies cell, slug normalized to lowercase.
		{"implied cell", apiFlags{to: "core", jurisdiction: " US "}, false, cell, "us", false},
		{"implied cell", apiFlags{to: apiTargetCore, jurisdiction: " US "}, false, apiTargetCell, "us", false},
		// --jurisdiction with explicit --to cell: allowed.
		{"explicit cell", apiFlags{to: cell, jurisdiction: "eu"}, true, cell, "eu", false},
		{"explicit cell", apiFlags{to: apiTargetCell, jurisdiction: "eu"}, true, apiTargetCell, "eu", false},
		// --jurisdiction with explicit --to core: contradiction, rejected.
		{"contradiction", apiFlags{to: "core", jurisdiction: "eu"}, true, "", "", true},
		{"contradiction", apiFlags{to: apiTargetCore, jurisdiction: "eu"}, true, "", "", true},
	} {
		t.Run(tc.name, func(t *testing.T) {
			t.Parallel()
```

Mcmd/entire/cli/api_cmd_test.go+4/-5

```
207 unmodified lines

208
209
210
211
212
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240

207 unmodified lines

if target != nil && strings.TrimSpace(target.BaseURL) != "" {
		return strings.TrimRight(target.BaseURL, "/"), nil
	}
	if !isBFFOrigin(dataOrigin) {
		// Already a cell URL, or a loopback local-dev host: keep it verbatim.
	// The configured origin is kept verbatim when it isn't a BFF/apex fronting
	// multiple cells — i.e. it's already a direct cell or a loopback dev host —
	// EXCEPT when a jurisdiction is explicitly pinned (target.Jurisdiction, e.g.
	// `entire api --jurisdiction eu`) against a non-loopback origin. A pinned
	// jurisdiction may name a DIFFERENT cell than the configured direct-cell
	// origin, so dialing that origin verbatim would send an identity token minted
	// for the pinned jurisdiction to the wrong cell; resolve the pinned
	// jurisdiction's own cell from the catalog instead. A loopback dev host serves
	// a single cell with no jurisdiction catalog, so it always stays verbatim.
	explicitJurisdiction := target != nil && strings.TrimSpace(target.Jurisdiction) != ""
	if !isBFFOrigin(dataOrigin) && (!explicitJurisdiction || isLoopbackOrigin(dataOrigin)) {
		return strings.TrimRight(dataOrigin, "/"), nil
	}
	return resolveCellAPIBaseURL(ctx, coreURL, loginJWT, jurisdiction, httpClient)
}

// isLoopbackOrigin reports whether origin's host is a loopback address, at any
// scheme (isLoopbackHTTP only accepts http). Used to keep a local-dev cell
// verbatim even when a jurisdiction is explicitly pinned.
func isLoopbackOrigin(origin string) bool {
	u, err := url.Parse(origin)
	if err != nil {
		return false
	}
	return isLoopbackHost(strings.ToLower(u.Hostname()))
}

// isBFFOrigin reports whether origin is a BFF / apex host that fronts multiple
// cells (so the actual cell must be resolved from the cluster catalog), as
// opposed to a direct entire-api cell (host contains ".api.") or a loopback
