Repository navigation
feat: bind stored credentials to their issuing auth endpoint - #20
Merged
Merged
Conversation
Implements #18 and the near-term half of #19. - store token_auth_url alongside the token set at login and refresh - fail fast in get_api_client and auth refresh when the stored token was issued by a different endpoint than the one currently targeted (trailing-slash-insensitive), with a re-login instruction - credentials stored before this change have no binding and are treated as matching; they bind at the next login or refresh - auth login no longer short-circuits as already-authenticated when the binding mismatches; it re-authenticates against the new target - auth login and auth status show the targeted endpoint and the endpoint that issued the stored token; auth status --json gains auth_url, token_auth_url and endpoint_match - logout clears the binding along with the token
…nding # Conflicts: # campus_cli/auth/common.py # campus_cli/auth/login.py
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #18. Addresses the near-term (surface-the-endpoint) half of #19; the production-default flip stays open there until a prod deployment exists.
What
campus auth loginand every successful token refresh now store atoken_auth_urlkeyring entry recording the resolved auth URL that minted the tokens.get_api_client()andcampus auth refreshcompare the stored URL against the currently resolved one (trailing-slash-insensitive) and fail fast with:campus auth loginno longer short-circuits as "Already authenticated" when the binding mismatches — it warns and re-authenticates against the current target.auth loginprints the endpoint it authenticates against;auth statusshows the targeted endpoint plus the endpoint that issued the stored token (flagging mismatches);auth status --jsongainsauth_url,token_auth_urlandendpoint_match.Migration / existing credentials
Deliberately zero-action, per #18:
token_auth_urland are treated as matching — no wave of false failures on upgrade.logout && loginto also revoke the stale dev tokens server-side.Testing
pytest -q), including new unit tests for the binding helpers and refresh stamping, and integration tests for the mismatch UX (status flag, login bypass of the short-circuit, refresh fail-fast, login stamping).ruff check .clean.campus auth statusagainst real legacy (unbound) credentials: shows both endpoints, reports binding as pending, no false mismatch.Implements the design from #18; per-host key namespacing remains explicitly out of scope there.