refactor(auth): simplify jurisdiction mint per cleanup review · Entire

refactor(auth): simplify jurisdiction mint per cleanup review

7c8497e· jagregory·4d ago·4 files·+33 added/-29 removed

Behavior unchanged; fmt + lint clean, tests green.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com

Sessions

23e771a1a94fView transcript

Changes

4

179 unmodified lines

180
181
182
183
183
184
185
186

179 unmodified lines

// derived from target.coreURL — the active context's core (or the env
        // token's aud) — never a hardcoded entire.io base.
        if j := strings.TrimSpace(jurisdiction); j != "" {
            jtoken, _, _, mintErr := auth.MintJurisdictionIdentityToken(cmd.Context(), target.coreURL, target.token, j, insecure)
            jtoken, mintErr := auth.MintJurisdictionIdentityToken(cmd.Context(), target.coreURL, target.token, j, insecure)
            if mintErr != nil {
                cmd.SilenceUsage = true
                return fmt.Errorf("mint jurisdictional token: %w", mintErr)

Mcmd/entire/cli/auth.go+1/-1

43 unmodified lines

44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
148 unmodified lines

209
210
211
201
202
212
213
214
215
216
252 unmodified lines

469
470
471
461
462
463
472
473
474
475
466
476
477
468
469
478
479
480
481
472
482
483
484
475
485
486
487
488
3 unmodified lines

492
493
494
485
486
495
496
497
488
498
499
500
501
492
502
503
494
504
505
496
506
507
508
509

43 unmodified lines

// "us.auth.evil.tld") into jurisdictionAudience / jurisdictionCoreURL.
var jurisdictionLabelPattern = regexp.MustCompile(`^[a-z0-9]([a-z0-9-]{0,38}[a-z0-9])?$`)

// validateJurisdictionLabel confirms slug is a single DNS label safe to template
// into jurisdiction URLs. Shared by targetJurisdiction (home-JWT / repo target)
// and MintJurisdictionIdentityToken so the label policy and its error message
// live in one place.
func validateJurisdictionLabel(slug string) error {
    if !jurisdictionLabelPattern.MatchString(slug) {
        return fmt.Errorf("jurisdiction %q is not a valid label; refusing to route", slug)
    }
    return nil
}

// CellTarget pins the entire-api cell a repo-scoped call must reach and the
// jurisdiction its identity token must be minted for. The cli layer resolves it
// from the repo's own cluster (via coreapi mirrors/clusters), so a repo-scoped
148 unmodified lines

if jurisdiction == "" {
        return "", errors.New("login token has no home_jurisdiction claim; cannot route to entire-api cell")
    }
    if !jurisdictionLabelPattern.MatchString(jurisdiction) {
        return "", fmt.Errorf("jurisdiction %q is not a valid label; refusing to route", jurisdiction)
    if err := validateJurisdictionLabel(jurisdiction); err != nil {
        return "", err
    }
    return jurisdiction, nil
}
252 unmodified lines

// / ENTIRE_API_AUDIENCE_TEMPLATE overrides and loopback local-dev cores exactly
// as the entire-api cell path does.
//
// Returns the minted token plus the audience and exchange core it was minted
// against (surfaced for diagnostics and tests).
func MintJurisdictionIdentityToken(ctx context.Context, contextCoreURL, subjectToken, jurisdiction string, insecureHTTP bool) (token, audience, exchangeCore string, err error) {
// Returns the minted jurisdictional identity token.
func MintJurisdictionIdentityToken(ctx context.Context, contextCoreURL, subjectToken, jurisdiction string, insecureHTTP bool) (string, error) {
    jurisdiction = strings.TrimSpace(jurisdiction)
    if jurisdiction == "" {
        return "", "", "", errors.New("jurisdiction must not be empty")
        return "", errors.New("jurisdiction must not be empty")
    }
    if !jurisdictionLabelPattern.MatchString(jurisdiction) {
        return "", "", "", fmt.Errorf("jurisdiction %q is not a valid label; refusing to route", jurisdiction)
    if err := validateJurisdictionLabel(jurisdiction); err != nil {
        return "", err
    }
    if strings.TrimSpace(subjectToken) == "" {
        return "", "", "", errors.New("no login credential to exchange for a jurisdictional token")
        return "", errors.New("no login credential to exchange for a jurisdictional token")
    }
    if strings.TrimSpace(contextCoreURL) == "" {
        return "", "", "", errors.New("no login core to derive the jurisdiction environment from")
        return "", errors.New("no login core to derive the jurisdiction environment from")
    }
    if insecureHTTP {
        EnableInsecureHTTP()
3 unmodified lines

// mint's environment is the login context, never the data-API origin, so even
    // the ENTIRE_API_BASE_URL override branch inside environmentFamily resolves
    // from the context core (not a possibly-prod data URL a script may have set).
    audience = jurisdictionAudience(jurisdiction, contextCoreURL, contextCoreURL)
    exchangeCore = jurisdictionCoreURL(jurisdiction, contextCoreURL, contextCoreURL)
    audience := jurisdictionAudience(jurisdiction, contextCoreURL, contextCoreURL)
    exchangeCore := jurisdictionCoreURL(jurisdiction, contextCoreURL, contextCoreURL)
    if err := requireSafeExchangeURL("entire-core", exchangeCore); err != nil {
        return "", "", "", err
        return "", err
    }

httpClient := &http.Client{Timeout: cellDataAPITimeout, Transport: cellExchangeTransportForTest}
    token, err = exchangeJurisdictionToken(ctx, exchangeCore, subjectToken, audience, httpClient)
    token, err := exchangeJurisdictionToken(ctx, exchangeCore, subjectToken, audience, httpClient)
    if err != nil {
        return "", "", "", fmt.Errorf("exchange jurisdictional identity token: %w", err)
        return fmt.Errorf("exchange jurisdictional identity token: %w", err)
    }
    return token, audience, exchangeCore, nil
    return token, nil
}

func exchangeJurisdictionToken(ctx context.Context, coreURL, loginJWT, audience string, httpClient *http.Client) (string, error) {

Mcmd/entire/cli/auth/cell_data_api.go+26/-16

158 unmodified lines

159
160
161
162
162
163
164
165
166
167
168
169
170
171
172
173
174
169
170
171
10 unmodified lines

182
183
184
191
185
186
187
194
188
189
190
197
191
192
193
200
194
195
196
197

158 unmodified lines

// srv.URL is loopback → jurisdictionCoreURL honours it verbatim, so the
    // exchange reaches the test server rather than a templated prod host.
    token, audience, core, err := MintJurisdictionIdentityToken(context.Background(), srv.URL, "login-jwt", "us", true)
    token, err := MintJurisdictionIdentityToken(context.Background(), srv.URL, "login-jwt", "us", true)
    if err != nil {
        t.Fatalf("MintJurisdictionIdentityToken: %v", err)
    }
    if token != "juris-token" {
            t.Errorf("token = %q, want juris-token", token)
    }
    if audience != wantUSPartialAud {
            t.Errorf("audience = %q, want %s", audience, wantUSPartialAud)
    }
    if core != srv.URL {
            t.Errorf("exchange core = %q, want %q", core, srv.URL)
    }
    if gotAudience != wantUSPartialAud {
            t.Errorf("posted audience = %q, want %s", gotAudience, wantUSPartialAud)
    }
10 unmodified lines

func TestMintJurisdictionIdentityTokenRejectsBadInput(t *testing.T) {
    t.Parallel()
    if _, _, _, err := MintJurisdictionIdentityToken(context.Background(), "https://us.auth.partial.to", "login-jwt", "", false); err == nil {
    if _, err := MintJurisdictionIdentityToken(context.Background(), "https://us.auth.partial.to", "login-jwt", "", false); err == nil {
            t.Error("empty jurisdiction should error")
    }
    if _, _, _, err := MintJurisdictionIdentityToken(context.Background(), "https://us.auth.partial.to", "login-jwt", "us.auth.evil.tld", false); err == nil {
    if _, err := MintJurisdictionIdentityToken(context.Background(), "https://us.auth.partial.to", "login-jwt", "us.auth.evil.tld", false); err == nil {
            t.Error("non-label jurisdiction should error")
    }
    if _, _, _, err := MintJurisdictionIdentityToken(context.Background(), "https://us.auth.partial.to", "", "us", false); err == nil {
    if _, err := MintJurisdictionIdentityToken(context.Background(), "https://us.auth.partial.to", "", "us", false); err == nil {
            t.Error("empty subject token should error")
    }
    if _, _, _, err := MintJurisdictionIdentityToken(context.Background(), "", "login-jwt", "us", false); err == nil {
    if _, err := MintJurisdictionIdentityToken(context.Background(), "", "login-jwt", "us", false); err == nil {
            t.Error("empty context core should error")
    }
}

Mcmd/entire/cli/auth/cell_data_api_test.go+5/-11

15 unmodified lines

16
17
18
19
19
20
21
22

15 unmodified lines

// redirectTransport rewrites every request to point at target, so a mint that
// dials a templated prod host (https://us.auth.partial.to) is intercepted by a
// loopback httptest server. It records the last request it saw.
// loopback httptest server.
type redirectTransport struct {
    target *url.URL
}

Mcmd/entire/cli/auth_token_test.go+1/-1