# auth: say 'login server' not 'core' in two more user-facing errors

`f9c7d97`→[main](/content/gh/entireio/cli/commits/main/index.html)·

toothbrush·1mo ago·3 files·+3 added/-3 removed

repo-token exchange hint and git-remote-entire's trust-gate error both surfaced the internal 'core' term; reword to 'login server' and update the trust-gate test assertion.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

## Sessions

c7e0df0e441fView transcript

## Changes

3

- cmd
  
  - entire/cli/auth
    
    - Mrepo_token.go+1/-1
  
  - git-remote-entire
    
    - Mmain.go+1/-1
    
    - Mmain_test.go+1/-1

```
74 unmodified lines

75
76
77
78
78
79
80
81

74 unmodified lines

func RepoScopedToken(ctx context.Context, clusterBaseURL, repoSlug, action string) (string, error) {
	provider := CurrentProvider()
	if strings.TrimSpace(provider.STSPath) == "" {
		return "", errors.New("repo-scoped token exchange requires a v2 auth host (set ENTIRE_AUTH_BASE_URL to a core that exposes /oauth/token)")
		return "", errors.New("repo-scoped token exchange requires a v2 auth host (set ENTIRE_AUTH_BASE_URL to a login server that exposes /oauth/token)")
	}

loginJWT, err := LookupCurrentToken()
```

Mcmd/entire/cli/auth/repo_token.go+1/-1

```
278 unmodified lines

279
280
281
282
282
283
284
285

278 unmodified lines

return nil, err //nolint:wrapcheck // ResolveClusterCores returns a user-facing discovery error
}
if !coreTrusted(coreURL, cores) {
	return nil, fmt.Errorf("%s aud %q is not a trusted core for cluster %s (advertised: %s); the token belongs to a different cluster",
	return nil, fmt.Errorf("%s aud %q is not a trusted login server for cluster %s (advertised: %s); the token belongs to a different cluster",
		auth.EnvTokenVar, coreURL, clusterHost, strings.Join(cores, ", "))
}

debuglog.Printf("authenticating via %s; core=%s", auth.EnvTokenVar, coreURL)
```

Mcmd/git-remote-entire/main.go+1/-1

```
231 unmodified lines

232
233
234
235
235
236
237
238

231 unmodified lines

if creds != nil {
		t.Fatal("expected nil creds when aud is untrusted")
	}
	if !strings.Contains(err.Error(), "not a trusted core") {
	if !strings.Contains(err.Error(), "not a trusted login server") {
		 t.Fatalf("expected trust-gate error, got: %v", err)
	}
}
```

Mcmd/git-remote-entire/main_test.go+1/-1
