# auth: make `auth status` context-aware; hit /me on the active core

`721ad68`→[main](/content/gh/entireio/cli/commits/main/index.html)·

toothbrush·1mo ago·4 files·+205 added/-150 removed

`auth status` queried /me against the static api.AuthBaseURL(), so with an
active context on a different core (e.g. `auth use eu.auth.entire.io` while
AuthBaseURL defaults to us.*) it sent the context's token to the wrong core
and got a 401 — surfaced as a raw ogen decode dump because the 401 body was
text/plain.

- Resolve the active contexts.json context first (resolveStatusTarget): use
its CoreURL + session token, falling back to AuthBaseURL + the legacy
keyring entry only when no context is active. `auth use` now retargets
status. "Logged in to <core>" reflects the active context.
- Add coreapi.NewWithBearer(coreURL, token) to hit a specific login server
with a fixed bearer (no STS), used by status's /me.
- Harden isKeychainTokenRejected: a non-JSON 401 (ogen "decode response:
... (code 401)") now maps to the friendly re-login hint, not a raw dump.
- TLS-guard the resolved context core URL before sending the token.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

## Sessions

1385b003c7a8View transcript

## Changes

4

- cmd/entire/cli

- Mauth.go+75/-35

- Mauth_context_test.go+26

- Mauth_test.go+78/-115

- internal/coreapi

- Mclient.go+26

```go
118 unmodified lines
```

if errors.Is(err, auth.ErrNotLoggedIn) {
    return true
}
// A 401 whose body isn't JSON (e.g. a gateway returning text/plain) fails
// the ogen typed decode, so it never becomes an ErrorModelStatusCode — it
// arrives as a decode error whose message carries "(code 401)". Match that
// so the user still gets the re-login hint, not a raw decode dump.
if strings.Contains(err.Error(), "code 401") {
    return true
}
return strings.Contains(err.Error(), "token exchange: status 4")
}

35 unmodified lines

}

```go
}
```

// RunAuthStatus reports auth state without listing server-side sessions
//  ...
