auth: say 'login server' not 'core' in two more user-facing errors · Entire

auth: say 'login server' not 'core' in two more user-facing errors

f9c7d97→main·

toothbrush·1mo ago·3 files·+3 added/-3 removed

repo-token exchange hint and git-remote-entire's trust-gate error both surfaced the internal 'core' term; reword to 'login server' and update the trust-gate test assertion.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com

Sessions

c7e0df0e441fView transcript

Changes

3

74 unmodified lines

75
76
77
78
78
79
80
81

74 unmodified lines

func RepoScopedToken(ctx context.Context, clusterBaseURL, repoSlug, action string) (string, error) {
    provider := CurrentProvider()
    if strings.TrimSpace(provider.STSPath) == "" {
        return "", errors.New("repo-scoped token exchange requires a v2 auth host (set ENTIRE_AUTH_BASE_URL to a core that exposes /oauth/token)")
        return "", errors.New("repo-scoped token exchange requires a v2 auth host (set ENTIRE_AUTH_BASE_URL to a login server that exposes /oauth/token)")
    }

loginJWT, err := LookupCurrentToken()

Mcmd/entire/cli/auth/repo_token.go+1/-1

278 unmodified lines

279
280
281
282
282
283
284
285

278 unmodified lines

return nil, err //nolint:wrapcheck // ResolveClusterCores returns a user-facing discovery error
}
if !coreTrusted(coreURL, cores) {
    return nil, fmt.Errorf("%s aud %q is not a trusted core for cluster %s (advertised: %s); the token belongs to a different cluster",
    return nil, fmt.Errorf("%s aud %q is not a trusted login server for cluster %s (advertised: %s); the token belongs to a different cluster",
        auth.EnvTokenVar, coreURL, clusterHost, strings.Join(cores, ", "))
}

debuglog.Printf("authenticating via %s; core=%s", auth.EnvTokenVar, coreURL)

Mcmd/git-remote-entire/main.go+1/-1

231 unmodified lines

232
233
234
235
235
236
237
238

231 unmodified lines

if creds != nil {
        t.Fatal("expected nil creds when aud is untrusted")
    }
    if !strings.Contains(err.Error(), "not a trusted core") {
    if !strings.Contains(err.Error(), "not a trusted login server") {
         t.Fatalf("expected trust-gate error, got: %v", err)
    }
}

Mcmd/git-remote-entire/main_test.go+1/-1