docs, scripts: stop referencing retired ENTIRE_AUTH_BASE_URL · Entire

docs, scripts: stop referencing retired ENTIRE_AUTH_BASE_URL

25a0909→main

toothbrush·1mo ago·10 files·+52 added/-51 removed

README and the device-auth smoke script still told developers to export the retired var, which now makes every entire command exit at the startup gate. Both switch to entire login --server. The smoke script also catches up with reality: login prints "Login URL:" (not "Approval URL:"), and a --server login records a contexts.json context instead of a legacy auth.json entry, so verification reads contexts.json.

Stale comments describing the env var as a live fallback/override are reworded ("the default auth origin"), the upstream-host-resolution doc no longer points at the removed AuthBaseURLOverridden, and a coreapi test sentinel stops advising the retired var.

The mechanism itself (the env read in api.AuthBaseURL and the tests that t.Setenv it) stays for the part-2 demolition PR, per the plan in the PR description.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com

Sessions

889d3caa19b7View transcript

Changes

10

# Run the login flow against a local server (prompts to press Enter before opening the browser)
go run ./cmd/entire login --insecure-http-auth
go run ./cmd/entire login --server http://localhost:8787 --insecure-http-auth

# Run the focused integration coverage for login
go test -tags=integration ./cmd/entire/cli/integration_test -run TestLogin

MREADME.md+5/-6

// NewClientWithBaseURL creates a new authenticated API client targeting an
// explicit base URL. Use this for endpoints that live on the auth host (e.g.
// auth-token management) when ENTIRE_AUTH_BASE_URL splits the auth origin
// from the data API origin.
func NewClientWithBaseURL(token, baseURL string) *Client {
    return &Client{
        httpClient: &http.Client{

Mcmd/entire/cli/api/client.go+2/-2

//  1. the active contexts.json login -> its CoreURL, with a per-context
//     refreshing bearer (silent JWT re-mint). This is what makes
//     `entire auth use <ctx>` retarget the control plane onto that core.
//  2. no active context -> the configured auth origin (ENTIRE_AUTH_BASE_URL or
//     the default) + TokenForResource, the pre-contexts fallback.
func ResolveControlPlaneTarget() (ControlPlaneTarget, error) {
    c, ok, err := activeContext()
    if err != nil {

Mcmd/entire/cli/auth/control_plane.go+7/-7

// The active-context provider returns an already-tailored message; it must reach
the user unprefixed (no generic "resolve control-plane token" wrapper burying it) and without the login hint.
sentinel := errors.New(`no usable login for "ctx" (https://core.example); run ENTIRE_AUTH_BASE_URL=https://core.example entire login`)
sentinel := errors.New(`no usable login for "ctx" (https://core.example); run entire login --server https://core.example`)

Mdocs/architecture/upstream-host-resolution.md+9/-9

import json
import pathlib
import sys

auth_file = pathlib.Path(sys.argv[1])
base_url = sys.argv[2]
contexts_file = pathlib.Path(sys.argv[1])
server = sys.argv[2].rstrip("/")

if not auth_file.exists():
    raise SystemExit(f"Auth file not found: {auth_file}")
if not contexts_file.exists():
    raise SystemExit(f"Contexts file not found: {contexts_file}")

data = json.loads(auth_file.read_text())
token = data.get("tokens", {}).get(base_url, {}).get("value", "")
if not token:
    raise SystemExit(f"No token saved for {base_url} in {auth_file}")
data = json.loads(contexts_file.read_text())
if not any(c.get("core_url", "").rstrip("/") == server for c in data.get("contexts", [])):
    raise SystemExit(f"No login context for {server} in {contexts_file}")

print(f"Verified token saved for {base_url} in {auth_file}")
print(f"Verified login context for {server} in {contexts_file}")

Mscripts/local-device-auth-smoke.sh+24/-22