auth: collapse provider routing to OIDC constants, drop v1 (COR-393) · Entire
auth: collapse provider routing to OIDC constants, drop v1 (COR-393)
6241533→main·
toothbrush·1mo ago·7 files·+28 added/-317 removed
The v1 provider described the retired single-host world where entire.io was its own login server (homegrown device-code path, no STS). Everyone has been on the v2 OIDC surface since split-host became the default, so the version routing table, the ENTIRE_AUTH_PROVIDER_VERSION override, the split-host auto-detect (api.IsSplitHost), the process-wide sync.Once singleton, and the SetProviderForTest seam all reduce to four package constants.
Co-Authored-By: Claude Fable 5 noreply@anthropic.com
Sessions
4899a74ed268View transcript
Changes
7
cmd/entire/cli
api
Mbase_url.go-11
Mbase_url_test.go-31
auth
Mclient.go+11/-13
Mdata_api_test.go-3
Mprovider.go+13/-131
Dprovider_test.go-120
Mrefresh.go+4/-8
75 unmodified lines
76
77
78
79
80
81
82
83
84
85
86
87
88
89
79
80
81
75 unmodified lines
return NormalizeOriginURL(raw)
// IsSplitHost reports whether the CLI is configured for split-host —
// i.e. ENTIRE_AUTH_BASE_URL points at a different origin than the data
// API. Both sides are canonicalised via NormalizeOriginURL before
// comparison: AuthBaseURL already does this internally, but BaseURL
// only trims whitespace and a trailing slash, so a cosmetically-
// different ENTIRE_API_BASE_URL (uppercase host, explicit :443, path
// suffix) would otherwise look split when it isn't.
func IsSplitHost() bool {
return AuthBaseURL() != NormalizeOriginURL(BaseURL())
}
// ResolveURL joins an API-relative path against the effective base URL.
func ResolveURL(path string) (string, error) {
return ResolveURLFromBase(BaseURL(), path)
}
Mcmd/entire/cli/api/base_url.go-11
86 unmodified lines
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
90
91
92
86 unmodified lines
}
func TestIsSplitHost(t *testing.T) {
cases := map[string]struct {
base, auth string
want bool
}{
// Defaults are split: data on entire.io, auth on us.auth.entire.io.
"both unset": {"", "", true},
"auth unset": {"https://entire.io", "", true},
"auth same as base": {"https://api.example.com", "https://api.example.com", false},
"auth cosmetic match": {"https://api.example.com", "https://api.example.com/", false},
"different origins": {"https://api.example.com", "https://auth.example.com", true},
// Asymmetric-normalisation regressions: BaseURL only trims, AuthBaseURL
// canonicalises. IsSplitHost must normalise both before comparing, else
// cosmetic noise in ENTIRE_API_BASE_URL falsely registers as split.
"base uppercase, auth lowercase": {"HTTPS://API.EXAMPLE.COM", "https://api.example.com", false},
"base default port, auth bare": {"https://api.example.com:443", "https://api.example.com", false},
"base path suffix, auth bare": {"https://api.example.com/v1", "https://api.example.com", false},
"base trailing slash, auth bare": {"https://api.example.com/", "https://api.example.com", false},
}
for name, tc := range cases {
t.Run(name, func(t *testing.T) {
t.Setenv(BaseURLEnvVar, tc.base)
t.Setenv(AuthBaseURLEnvVar, tc.auth)
if got := IsSplitHost(); got != tc.want {
t.Errorf("IsSplitHost() = %v, want %v (base=%q auth=%q)", got, tc.want, tc.base, tc.auth)
}
})
}
}
func TestNormalizeOriginURL(t *testing.T) {
t.Parallel()
``
... (continues with additional code structures) ...