auth: say "login server" not "core" in user-facing text · Entire
auth: say "login server" not "core" in user-facing text
0b6eacf→main·
toothbrush·1mo ago·2 files·+14 added/-12 removed
Address PR review: auth use help said control-plane commands dial "the context's core" — reworded to "login server" (core is internal wording). Also reword the "build core API client" client-construction errors to "build Entire API client".
Scope New()'s doc comment correctly: the active context is used as-is for control-plane commands because they target a login server directly (no resource host to match against, unlike clone / the data API), and ENTIRE_AUTH_BASE_URL is the no-context fallback, not an override.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com
Sessions
7a049f08ce46View transcript
[?
Context-Aware Control-Plane Target ResolutionClaude Code·1 step](/content/gh/entireio/cli/session/d6b8ae84-4338-458e-ae8a-594eb414b667#timeline-7a049f08ce46/index.html)
Changes
2
cmd/entire/cli
Mauth_context.go+1/-1
internal/coreapi
Mclient.go+13/-11
23 unmodified lines
24
25
26
27
27
28
29
30
23 unmodified lines
Long: "Switch the active login context.\n\n" +
"The active context is the preferred identity for `git clone entire://…` and\n" +
"the control-plane commands (auth status, org/project/repo/grant), which dial\n" +
"the context's core. The switch takes effect on the next operation.\n\n" +
"the context's login server. The switch takes effect on the next operation.\n\n" +
"Data-API commands (activity/search/trail/dispatch) still target\n" +
"ENTIRE_API_BASE_URL and do not follow the active context yet.",
Args: cobra.ExactArgs(1),
Mcmd/entire/cli/auth_context.go+1/-1
18 unmodified lines
19
20
21
22
23
24
25
26
27
28
29
22
23
24
25
26
27
28
29
30
31
32
33
34
2 unmodified lines
37
38
39
38
40
41
42
43
7 unmodified lines
51
52
53
52
54
55
56
57
58
59
58
60
61
62
63
18 unmodified lines
// New returns a *Client wired to talk to the Entire control plane (Core
// API) as the currently logged-in user.
// The host and bearer come from auth.ResolveControlPlaneTarget: the active
// contexts.json login's core (so `entire auth use <ctx>` retargets the
// control plane), or — when no context is active — the configured auth host
// (ENTIRE_AUTH_BASE_URL or the default). The Core API is served at
// <core>/api/v1. The bearer is resolved lazily per request; for an active
// context it re-mints silently from the stored refresh token, and for the
// static path an RFC 8693 exchange happens transparently when the stored
// token's audience doesn't cover the core.
// The host and bearer come from auth.ResolveControlPlaneTarget. Control-plane
// commands target a login server directly — unlike `git clone` or the data
// API, there's no resource host to match a context against — so the active
// contexts.json login is used as-is, and `entire auth use <ctx>` retargets the
// control plane onto that login server. ENTIRE_AUTH_BASE_URL / the default is
// only the fallback when no context is active, not an override. The Core API
// is served at <host>/api/v1. The bearer is resolved lazily per request; for
// an active context it re-mints silently from the stored refresh token, and
// for the fallback path an RFC 8693 exchange happens transparently when the
// stored token's audience doesn't cover the host.
func New() (*Client, error) {
target, err := auth.ResolveControlPlaneTarget()
if err != nil {
2 unmodified lines
src := &providerSource{provide: target.TokenSource}
client, err := NewClient(strings.TrimRight(target.CoreURL, "/")+apiBasePath, src)
if err != nil {
return nil, fmt.Errorf("build core API client: %w", err)
return nil, fmt.Errorf("build Entire API client: %w", err)
}
return client, nil
}
7 unmodified lines
base := strings.TrimRight(coreBaseURL, "/")
client, err := NewClient(base+apiBasePath, staticBearer{token: token})
if err != nil {
return nil, fmt.Errorf("build core API client: %w", err)
return nil, fmt.Errorf("build Entire API client: %w", err)
}
return client, nil
}
// staticBearer is a SecuritySource that returns a fixed bearer token. Same
// sessionAuth-skipping rationale as bearerSource.
// sessionAuth-skipping rationale as providerSource.
type staticBearer struct{ token string }
func (s staticBearer) BearerAuth(context.Context, OperationName) (BearerAuth, error) {