auth: say "login server" not "core" in user-facing text · Entire

auth: say "login server" not "core" in user-facing text

0b6eacf→main·

toothbrush·1mo ago·2 files·+14 added/-12 removed

Address PR review: auth use help said control-plane commands dial "the context's core" — reworded to "login server" (core is internal wording). Also reword the "build core API client" client-construction errors to "build Entire API client".

Scope New()'s doc comment correctly: the active context is used as-is for control-plane commands because they target a login server directly (no resource host to match against, unlike clone / the data API), and ENTIRE_AUTH_BASE_URL is the no-context fallback, not an override.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com

Sessions

7a049f08ce46View transcript

[?
Context-Aware Control-Plane Target ResolutionClaude Code·1 step](/content/gh/entireio/cli/session/d6b8ae84-4338-458e-ae8a-594eb414b667#timeline-7a049f08ce46/index.html)

Changes

2

23 unmodified lines

24
25
26
27
27
28
29
30

23 unmodified lines

Long: "Switch the active login context.\n\n" +
        "The active context is the preferred identity for `git clone entire://…` and\n" +
        "the control-plane commands (auth status, org/project/repo/grant), which dial\n" +
        "the context's core. The switch takes effect on the next operation.\n\n" +
        "the context's login server. The switch takes effect on the next operation.\n\n" +
        "Data-API commands (activity/search/trail/dispatch) still target\n" +
        "ENTIRE_API_BASE_URL and do not follow the active context yet.",
        Args:              cobra.ExactArgs(1),

Mcmd/entire/cli/auth_context.go+1/-1

18 unmodified lines

19
20
21
22
23
24
25
26
27
28
29
22
23
24
25
26
27
28
29
30
31
32
33
34
2 unmodified lines

37
38
39
38
40
41
42
43
7 unmodified lines

51
52
53
52
54
55
56
57
58
59
58
60
61
62
63

18 unmodified lines

// New returns a *Client wired to talk to the Entire control plane (Core
// API) as the currently logged-in user.

// The host and bearer come from auth.ResolveControlPlaneTarget: the active
// contexts.json login's core (so `entire auth use <ctx>` retargets the
// control plane), or — when no context is active — the configured auth host
// (ENTIRE_AUTH_BASE_URL or the default). The Core API is served at
// <core>/api/v1. The bearer is resolved lazily per request; for an active
// context it re-mints silently from the stored refresh token, and for the
// static path an RFC 8693 exchange happens transparently when the stored
// token's audience doesn't cover the core.
// The host and bearer come from auth.ResolveControlPlaneTarget. Control-plane
// commands target a login server directly — unlike `git clone` or the data
// API, there's no resource host to match a context against — so the active
// contexts.json login is used as-is, and `entire auth use <ctx>` retargets the
// control plane onto that login server. ENTIRE_AUTH_BASE_URL / the default is
// only the fallback when no context is active, not an override. The Core API
// is served at <host>/api/v1. The bearer is resolved lazily per request; for
// an active context it re-mints silently from the stored refresh token, and
// for the fallback path an RFC 8693 exchange happens transparently when the
// stored token's audience doesn't cover the host.
func New() (*Client, error) {
    target, err := auth.ResolveControlPlaneTarget()
    if err != nil {

2 unmodified lines

src := &providerSource{provide: target.TokenSource}
    client, err := NewClient(strings.TrimRight(target.CoreURL, "/")+apiBasePath, src)
    if err != nil {
        return nil, fmt.Errorf("build core API client: %w", err)
        return nil, fmt.Errorf("build Entire API client: %w", err)
    }
    return client, nil
}
7 unmodified lines

base := strings.TrimRight(coreBaseURL, "/")
client, err := NewClient(base+apiBasePath, staticBearer{token: token})
if err != nil {
    return nil, fmt.Errorf("build core API client: %w", err)
    return nil, fmt.Errorf("build Entire API client: %w", err)
}
return client, nil
}

// staticBearer is a SecuritySource that returns a fixed bearer token. Same
// sessionAuth-skipping rationale as bearerSource.
// sessionAuth-skipping rationale as providerSource.
type staticBearer struct{ token string }

func (s staticBearer) BearerAuth(context.Context, OperationName) (BearerAuth, error) {