fix(auth): don't let the default data origin mask a staging login in jurisdiction mint · Entire
fix(auth): don't let the default data origin mask a staging login in jurisdiction mint
f04927a·
jagregory·4d ago·2 files·+57 added/-9 removed
entire auth token --jurisdiction (and the shared entire-api cell URL
templating) derive their prod-vs-staging "environment family" via
environmentFamily(dataOrigin, discoveredCore). The stored-context path
(resolveStoredCellSubject) sets dataOrigin to api.BaseURL(), which
defaults to prod entire.io when ENTIRE_API_BASE_URL is unset — so a
partial.to login minted a token audienced to https://us.entire.io
instead of https://us.partial.to, which a partial.to cell rejects. The
ENTIRE_TOKEN path was already correct (it passes the token's own core as
dataOrigin).
Fix the shared resolution: only an EXPLICIT ENTIRE_API_BASE_URL override wins; otherwise the discovered login core (which issued/trusts the JWT being exchanged) determines the family, so a partial.to login yields a partial.to audience even with the data origin left at its prod default.
Also introduce familyEntireIO/familyPartialTo constants for the two apex strings. Adds TestEnvironmentFamilyPrefersDiscoveredCoreOverDefaultOrigin.
Sessions
01KXD78RRFFBDJF08RHTW0DEK9View transcript
Changes
2
cmd/entire/cli/auth
Mcell_data_api.go+33/-9
- Mcell_data_api_test.go+24
31 unmodified lines
// clustersAPIPath is entire-core's cluster catalog endpoint.
clustersAPIPath = "/api/v1/clusters"
// familyEntireIO / familyPartialTo are the registrable apexes the two Entire
// environments live under (prod / staging). Used to template jurisdiction
audience/core URLs from whichever environment the caller is logged into.
familyEntireIO = "entire.io"
familyPartialTo = "partial.to"
// jurisdictionLabelPattern bounds a home_jurisdiction claim to a single DNS
}
// environmentFamily picks the registrable apex to template jurisdiction URLs
// against. The configured data host (what the user pointed the CLI at) is the
// most reliable signal for prod-vs-staging, so it wins; the discovered login
// core is the fallback.
// against, in precedence order:
//
// - an EXPLICIT ENTIRE_API_BASE_URL override: the user deliberately pointed
// the data plane at a specific environment, so its family wins. The *default*
// data origin (prod entire.io, used when the env var is unset) must NOT win —
// it would mask the login environment and mint an entire.io audience for a
// partial.to session (the stored-context jurisdiction-mint bug this guards
// against). ENTIRE_TOKEN callers pass the token's own core as dataOrigin, so
// they are unaffected either way.
// - otherwise the discovered login core: it is the core that issued / trusts
// the login JWT being exchanged, so its environment is the one the minted
// token must be audienced for. This lets a partial.to login yield a
// partial.to audience even with the data-API origin left at its prod default.
// - last resort (loopback/custom discovered core): the data origin's family.
func environmentFamily(dataOrigin, discoveredCore string) string {
if fam := entireDomainFamily(dataOrigin); fam != "" {
// Blank counts as unset, matching api.BaseURL()'s own TrimSpace check, so an
// empty ENTIRE_API_BASE_URL doesn't masquerade as an explicit choice.
if raw := strings.TrimSpace(os.Getenv(api.BaseURLEnvVar)); raw != "" {
if fam := entireDomainFamily(dataOrigin); fam != "" {
return fam
}
}
if fam := entireDomainFamily(discoveredCore); fam != "" {
return fam
}
return entireDomainFamily(discoveredCore)
return entireDomainFamily(dataOrigin)
}
// jurisdictionAudience returns the aud the entire-api cell for `jurisdiction`
Mcmd/entire/cli/auth/cell_data_api.go+33/-9
89 unmodified lines
}
// TestEnvironmentFamilyPrefersDiscoveredCoreOverDefaultOrigin locks in the
// stored-context jurisdiction-mint fix: resolveStoredCellSubject sets dataOrigin
// to api.BaseURL(), which defaults to prod entire.io when ENTIRE_API_BASE_URL is
// unset. That default must NOT mask a staging (partial.to) discovered login
// core — otherwise a partial.to login mints an entire.io-audienced token. Only
// an EXPLICIT ENTIRE_API_BASE_URL override wins.
func TestEnvironmentFamilyPrefersDiscoveredCoreOverDefaultOrigin(t *testing.T) {
const prodOrigin = "https://" + familyEntireIO
// Empty ENTIRE_API_BASE_URL is treated as unset (matches api.BaseURL()).
t.Setenv("ENTIRE_API_BASE_URL", "")
if got := environmentFamily(prodOrigin, "https://us.auth.partial.to"); got != familyPartialTo {
t.Fatalf("family = %q, want partial.to (discovered core wins over default origin)", got)
}
if got := environmentFamily(prodOrigin, "https://us.auth.entire.io"); got != familyEntireIO {
t.Fatalf("family = %q, want entire.io", got)
}
// An explicit ENTIRE_API_BASE_URL override is a deliberate choice and wins,
// even over a staging discovered core.
t.Setenv("ENTIRE_API_BASE_URL", prodOrigin)
if got := environmentFamily(prodOrigin, "https://us.auth.partial.to"); got != familyEntireIO {
t.Fatalf("family = %q, want entire.io (explicit override wins)", got)
}
}
func TestJurisdictionCoreURLHonorsLoopbackAndFamily(t *testing.T) {
t.Setenv("ENTIRE_CORE_BASE_URL_TEMPLATE", "")
// Local dev: a loopback discovered core must be honored verbatim, NOT