auth: stop hitting entire.io PAT endpoint; sessions live on entire-core · Entire
auth: stop hitting entire.io PAT endpoint; sessions live on entire-core
04e54e6→main· toothbrush·1mo ago·3 files·+150 added/-495 removed
auth status and logout were pointing session list/revoke at entire.io's /api/v1/auth/tokens — which is the legacy ent_ personal-access-token surface, not login sessions. For a JWT login that endpoint lists nothing (no ent_ PATs) and rejects DELETE /current with 400 ("revoke entire-core JWTs via entire-core"). The CLI never mints or sends ent_ PATs, so it has no business there.
Repoint session management at entire-core (the auth host) /api/auth/tokens, authenticated with the session-scoped login JWT (resolveAuthHostToken — a same-host resolution that preserves the entire:session scope core's session routes require):
- auth status: drop the server-side session table entirely. Status is now local: GET /me (profile + liveness) + the active login context. No PAT endpoint, no empty "active sessions".
- logout: revoke the current session (and --all: every session on the core) via entire-core, not entire.io.
Removes the now-dead session-table rendering + date-formatting helpers.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com
Sessions
99a4950a334dView transcript
Changes
3
cmd/entire/cli
Mauth.go+65/-230
Mauth_test.go+83/-263
Mlogout.go+2/-2
5 unmodified lines
6
7
8
9
9
11
10
11
12
13
14
15
16
17
18
20
21
22
23
24
25
26
27
19
20
21
22
23
24
25
26
29
30
27
28
29
30
33
31
32
33
30 unmodified lines
64
65
66
70
71
72
73
74
75
76
77
78
79
80
67
68
69
70
71
72
73
74
82
83
75
76
77
78
86
87
88
89
90
91
92
93
79
80
81
82
83
84
85
95
86
87
88
89
90
91
101
102
92
93
94
104
105
95
96
97
98
99
61 unmodified lines
161
162
163
173
174
164
165
166
167
168
14 unmodified lines
183
184
185
186
187
188
189
190
191
192
193
19 unmodified lines
213
224
...
5 unmodified lines
...
82 unmodified lines
6 unmodified lines