auth: say 'login server' not 'core' in two more user-facing errors · Entire
auth: say 'login server' not 'core' in two more user-facing errors
f9c7d97→main·
toothbrush·1mo ago·3 files·+3 added/-3 removed
repo-token exchange hint and git-remote-entire's trust-gate error both surfaced the internal 'core' term; reword to 'login server' and update the trust-gate test assertion.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com
Sessions
c7e0df0e441fView transcript
Changes
3
cmd
entire/cli/auth
- Mrepo_token.go+1/-1
git-remote-entire
Mmain.go+1/-1
Mmain_test.go+1/-1
74 unmodified lines
75
76
77
78
78
79
80
81
74 unmodified lines
func RepoScopedToken(ctx context.Context, clusterBaseURL, repoSlug, action string) (string, error) {
provider := CurrentProvider()
if strings.TrimSpace(provider.STSPath) == "" {
return "", errors.New("repo-scoped token exchange requires a v2 auth host (set ENTIRE_AUTH_BASE_URL to a core that exposes /oauth/token)")
return "", errors.New("repo-scoped token exchange requires a v2 auth host (set ENTIRE_AUTH_BASE_URL to a login server that exposes /oauth/token)")
}
loginJWT, err := LookupCurrentToken()
Mcmd/entire/cli/auth/repo_token.go+1/-1
278 unmodified lines
279
280
281
282
282
283
284
285
278 unmodified lines
return nil, err //nolint:wrapcheck // ResolveClusterCores returns a user-facing discovery error
}
if !coreTrusted(coreURL, cores) {
return nil, fmt.Errorf("%s aud %q is not a trusted core for cluster %s (advertised: %s); the token belongs to a different cluster",
return nil, fmt.Errorf("%s aud %q is not a trusted login server for cluster %s (advertised: %s); the token belongs to a different cluster",
auth.EnvTokenVar, coreURL, clusterHost, strings.Join(cores, ", "))
}
debuglog.Printf("authenticating via %s; core=%s", auth.EnvTokenVar, coreURL)
Mcmd/git-remote-entire/main.go+1/-1
231 unmodified lines
232
233
234
235
235
236
237
238
231 unmodified lines
if creds != nil {
t.Fatal("expected nil creds when aud is untrusted")
}
if !strings.Contains(err.Error(), "not a trusted core") {
if !strings.Contains(err.Error(), "not a trusted login server") {
t.Fatalf("expected trust-gate error, got: %v", err)
}
}
Mcmd/git-remote-entire/main_test.go+1/-1