docs, scripts: stop referencing retired ENTIRE_AUTH_BASE_URL · Entire
docs, scripts: stop referencing retired ENTIRE_AUTH_BASE_URL
25a0909→main
toothbrush·1mo ago·10 files·+52 added/-51 removed
README and the device-auth smoke script still told developers to export the retired var, which now makes every entire command exit at the startup gate. Both switch to entire login --server. The smoke script also catches up with reality: login prints "Login URL:" (not "Approval URL:"), and a --server login records a contexts.json context instead of a legacy auth.json entry, so verification reads contexts.json.
Stale comments describing the env var as a live fallback/override are reworded ("the default auth origin"), the upstream-host-resolution doc no longer points at the removed AuthBaseURLOverridden, and a coreapi test sentinel stops advising the retired var.
The mechanism itself (the env read in api.AuthBaseURL and the tests that t.Setenv it) stays for the part-2 demolition PR, per the plan in the PR description.
Co-Authored-By: Claude Fable 5 noreply@anthropic.com
Sessions
889d3caa19b7View transcript
Changes
10
- MREADME.md+5/-6
- cmd/entire/cli
- api
- Mclient.go+2/-2
- auth
- Mcontrol_plane.go+7/-7
- Mdata_api.go+1/-1
- Mexchange.go+1/-1
- api
- docs/architecture
- Mupstream-host-resolution.md+9/-9
- internal
- coreapi
- Mclient.go+1/-1
- Mclient_test.go+1/-1
- entireclient/clusterdiscovery
- Mapi_discovery_test.go+1/-1
- coreapi
- scripts
- Mlocal-device-auth-smoke.sh+24/-22
# Run the login flow against a local server (prompts to press Enter before opening the browser)
go run ./cmd/entire login --insecure-http-auth
go run ./cmd/entire login --server http://localhost:8787 --insecure-http-auth
# Run the focused integration coverage for login
go test -tags=integration ./cmd/entire/cli/integration_test -run TestLogin
MREADME.md+5/-6
// NewClientWithBaseURL creates a new authenticated API client targeting an
// explicit base URL. Use this for endpoints that live on the auth host (e.g.
// auth-token management) when ENTIRE_AUTH_BASE_URL splits the auth origin
// from the data API origin.
func NewClientWithBaseURL(token, baseURL string) *Client {
return &Client{
httpClient: &http.Client{
Mcmd/entire/cli/api/client.go+2/-2
// 1. the active contexts.json login -> its CoreURL, with a per-context
// refreshing bearer (silent JWT re-mint). This is what makes
// `entire auth use <ctx>` retarget the control plane onto that core.
// 2. no active context -> the configured auth origin (ENTIRE_AUTH_BASE_URL or
// the default) + TokenForResource, the pre-contexts fallback.
func ResolveControlPlaneTarget() (ControlPlaneTarget, error) {
c, ok, err := activeContext()
if err != nil {
Mcmd/entire/cli/auth/control_plane.go+7/-7
// The active-context provider returns an already-tailored message; it must reach
the user unprefixed (no generic "resolve control-plane token" wrapper burying it) and without the login hint.
sentinel := errors.New(`no usable login for "ctx" (https://core.example); run ENTIRE_AUTH_BASE_URL=https://core.example entire login`)
sentinel := errors.New(`no usable login for "ctx" (https://core.example); run entire login --server https://core.example`)
Mdocs/architecture/upstream-host-resolution.md+9/-9
import json
import pathlib
import sys
auth_file = pathlib.Path(sys.argv[1])
base_url = sys.argv[2]
contexts_file = pathlib.Path(sys.argv[1])
server = sys.argv[2].rstrip("/")
if not auth_file.exists():
raise SystemExit(f"Auth file not found: {auth_file}")
if not contexts_file.exists():
raise SystemExit(f"Contexts file not found: {contexts_file}")
data = json.loads(auth_file.read_text())
token = data.get("tokens", {}).get(base_url, {}).get("value", "")
if not token:
raise SystemExit(f"No token saved for {base_url} in {auth_file}")
data = json.loads(contexts_file.read_text())
if not any(c.get("core_url", "").rstrip("/") == server for c in data.get("contexts", [])):
raise SystemExit(f"No login context for {server} in {contexts_file}")
print(f"Verified token saved for {base_url} in {auth_file}")
print(f"Verified login context for {server} in {contexts_file}")
Mscripts/local-device-auth-smoke.sh+24/-22