Skip to content

feat: resolve auth endpoint from ENV/CAMPUS_ENV (mirrors campus_python) - #22

Merged
nycomp merged 1 commit into
mainfrom
feat/auth-env-routing
Oct 1, 2026
Merged

nycomp merged 1 commit into
mainfrom
feat/auth-env-routing

Conversation

@nycomp

@nycomp nycomp commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Config.auth_url now resolves in the same order as campus_python's base URL resolution (campus-api-python#53), so one environment variable routes both API commands and CLI auth:

  1. CAMPUS_AUTH_URL (explicit)
  2. auth_url config-file key
  3. ENV/CAMPUS_ENV-derived URL — ENV wins, testing maps to development, invalid values raise ValueError (all mirroring campus_python)
  4. Built-in development default

No DeprecationWarning in the CLI: it never derived URLs from HOSTNAME, so #53's warning text would be misleading.

The CLI's staging/production auth URLs carry the /auth/v1 prefix (the CLI appends /oauth/... paths itself; campus_python adds the prefix internally).

Why

Railway fleet notes (audited via railway CLI, 2026-10-01)

  • All seven campus dev services set ENV=development; CAMPUS_ENV is set nowhere (fleet convention is ENV).
  • Only campus.api deploys to staging/production (api.campus.nyjc.dev / .app bound). No staging/production auth deployments or domains exist yet, so with ENV=staging|production, API commands hit real targets while auth commands fail loudly at login — a documented infrastructure limitation, not a regression.

Tests

  • 7 new tests in tests/unit/test_config.py pin the contract: development default when unset, per-ENV URL mapping, ENV over CAMPUS_ENV, CAMPUS_ENV fallback, explicit env var and config-file precedence over deploy-env routing, invalid ENV → ValueError.
  • Full suite: 107 passed. Smoke tests and ruff check run manually (worktree checkouts have no local .venv for the hooks).

auth_url now resolves as: CAMPUS_AUTH_URL > config file auth_url >
ENV/CAMPUS_ENV-derived URL (ENV wins) > development default, matching
campus_python's base URL resolution so one environment variable routes
both API commands and CLI auth. testing maps to development; invalid
values raise ValueError like campus_python.

CLI staging/production auth URLs carry the /auth/v1 prefix (the CLI
appends /oauth/... paths itself, campus_python does not). With no
staging/production auth deployments yet, ENV=staging|production makes
API commands hit real targets while auth commands fail loudly —
documented, not a regression.

Also fixes the routing gap behind #17's logout revocation: revocation
now follows the same resolution as token issuance instead of always
targeting the dev default.
@nycomp
nycomp merged commit c3b9cd0 into main Oct 1, 2026
1 check passed
@nycomp
nycomp deleted the feat/auth-env-routing branch October 1, 2026 05:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants