fix(auth): don't let the default data origin mask a staging login in jurisdiction mint · Entire

fix(auth): don't let the default data origin mask a staging login in jurisdiction mint

f04927a·

jagregory·4d ago·2 files·+57 added/-9 removed

entire auth token --jurisdiction (and the shared entire-api cell URL templating) derive their prod-vs-staging "environment family" via environmentFamily(dataOrigin, discoveredCore). The stored-context path (resolveStoredCellSubject) sets dataOrigin to api.BaseURL(), which defaults to prod entire.io when ENTIRE_API_BASE_URL is unset — so a partial.to login minted a token audienced to https://us.entire.io instead of https://us.partial.to, which a partial.to cell rejects. The ENTIRE_TOKEN path was already correct (it passes the token's own core as dataOrigin).

Fix the shared resolution: only an EXPLICIT ENTIRE_API_BASE_URL override wins; otherwise the discovered login core (which issued/trusts the JWT being exchanged) determines the family, so a partial.to login yields a partial.to audience even with the data origin left at its prod default.

Also introduce familyEntireIO/familyPartialTo constants for the two apex strings. Adds TestEnvironmentFamilyPrefersDiscoveredCoreOverDefaultOrigin.

Sessions

01KXD78RRFFBDJF08RHTW0DEK9View transcript

Changes

2

31 unmodified lines

// clustersAPIPath is entire-core's cluster catalog endpoint.
clustersAPIPath = "/api/v1/clusters"

// familyEntireIO / familyPartialTo are the registrable apexes the two Entire
// environments live under (prod / staging). Used to template jurisdiction
audience/core URLs from whichever environment the caller is logged into.
familyEntireIO  = "entire.io"
familyPartialTo = "partial.to"
// jurisdictionLabelPattern bounds a home_jurisdiction claim to a single DNS

}

// environmentFamily picks the registrable apex to template jurisdiction URLs
// against. The configured data host (what the user pointed the CLI at) is the
// most reliable signal for prod-vs-staging, so it wins; the discovered login
// core is the fallback.
// against, in precedence order:
//
//   - an EXPLICIT ENTIRE_API_BASE_URL override: the user deliberately pointed
//     the data plane at a specific environment, so its family wins. The *default*
//     data origin (prod entire.io, used when the env var is unset) must NOT win —
//     it would mask the login environment and mint an entire.io audience for a
//     partial.to session (the stored-context jurisdiction-mint bug this guards
//     against). ENTIRE_TOKEN callers pass the token's own core as dataOrigin, so
//     they are unaffected either way.
//   - otherwise the discovered login core: it is the core that issued / trusts
//     the login JWT being exchanged, so its environment is the one the minted
//     token must be audienced for. This lets a partial.to login yield a
//     partial.to audience even with the data-API origin left at its prod default.
//   - last resort (loopback/custom discovered core): the data origin's family.
func environmentFamily(dataOrigin, discoveredCore string) string {
if fam := entireDomainFamily(dataOrigin); fam != "" {
// Blank counts as unset, matching api.BaseURL()'s own TrimSpace check, so an
// empty ENTIRE_API_BASE_URL doesn't masquerade as an explicit choice.
if raw := strings.TrimSpace(os.Getenv(api.BaseURLEnvVar)); raw != "" {
if fam := entireDomainFamily(dataOrigin); fam != "" {
return fam
}
}
if fam := entireDomainFamily(discoveredCore); fam != "" {
return fam
}
return entireDomainFamily(discoveredCore)
return entireDomainFamily(dataOrigin)
}

// jurisdictionAudience returns the aud the entire-api cell for `jurisdiction`  

Mcmd/entire/cli/auth/cell_data_api.go+33/-9

89 unmodified lines

}

// TestEnvironmentFamilyPrefersDiscoveredCoreOverDefaultOrigin locks in the
// stored-context jurisdiction-mint fix: resolveStoredCellSubject sets dataOrigin
// to api.BaseURL(), which defaults to prod entire.io when ENTIRE_API_BASE_URL is
// unset. That default must NOT mask a staging (partial.to) discovered login
// core — otherwise a partial.to login mints an entire.io-audienced token. Only
// an EXPLICIT ENTIRE_API_BASE_URL override wins.
func TestEnvironmentFamilyPrefersDiscoveredCoreOverDefaultOrigin(t *testing.T) {
const prodOrigin = "https://" + familyEntireIO
// Empty ENTIRE_API_BASE_URL is treated as unset (matches api.BaseURL()).
t.Setenv("ENTIRE_API_BASE_URL", "")
if got := environmentFamily(prodOrigin, "https://us.auth.partial.to"); got != familyPartialTo {
t.Fatalf("family = %q, want partial.to (discovered core wins over default origin)", got)
}
if got := environmentFamily(prodOrigin, "https://us.auth.entire.io"); got != familyEntireIO {
t.Fatalf("family = %q, want entire.io", got)
}
// An explicit ENTIRE_API_BASE_URL override is a deliberate choice and wins,
// even over a staging discovered core.
t.Setenv("ENTIRE_API_BASE_URL", prodOrigin)
if got := environmentFamily(prodOrigin, "https://us.auth.partial.to"); got != familyEntireIO {
t.Fatalf("family = %q, want entire.io (explicit override wins)", got)
}
}

func TestJurisdictionCoreURLHonorsLoopbackAndFamily(t *testing.T) {
t.Setenv("ENTIRE_CORE_BASE_URL_TEMPLATE", "")
// Local dev: a loopback discovered core must be honored verbatim, NOT