Repository navigation
feat: resolve auth endpoint from ENV/CAMPUS_ENV (mirrors campus_python) - #22
Merged
Merged
Conversation
auth_url now resolves as: CAMPUS_AUTH_URL > config file auth_url > ENV/CAMPUS_ENV-derived URL (ENV wins) > development default, matching campus_python's base URL resolution so one environment variable routes both API commands and CLI auth. testing maps to development; invalid values raise ValueError like campus_python. CLI staging/production auth URLs carry the /auth/v1 prefix (the CLI appends /oauth/... paths itself, campus_python does not). With no staging/production auth deployments yet, ENV=staging|production makes API commands hit real targets while auth commands fail loudly — documented, not a regression. Also fixes the routing gap behind #17's logout revocation: revocation now follows the same resolution as token issuance instead of always targeting the dev default.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Config.auth_urlnow resolves in the same order as campus_python's base URL resolution (campus-api-python#53), so one environment variable routes both API commands and CLI auth:CAMPUS_AUTH_URL(explicit)auth_urlconfig-file keyENV/CAMPUS_ENV-derived URL —ENVwins,testingmaps to development, invalid values raiseValueError(all mirroring campus_python)No
DeprecationWarningin the CLI: it never derived URLs fromHOSTNAME, so #53's warning text would be misleading.The CLI's staging/production auth URLs carry the
/auth/v1prefix (the CLI appends/oauth/...paths itself; campus_python adds the prefix internally).Why
ENV/CAMPUS_ENVbefore #53 too — the CLI was the outlier. WithENV=production, API commands already targeted production while CLI auth (login, refresh, and feat: revoke tokens server-side on auth logout (best-effort RFC 7009) #17's logout revocation) stayed on the dev default. RFC 7009 servers return 200 even for unknown tokens, so revocation against the wrong deployment was a silent false success. This PR closes that gap.ENVnow triggers the existing re-auth prompt instead of a silent mismatch.Railway fleet notes (audited via
railwayCLI, 2026-10-01)ENV=development;CAMPUS_ENVis set nowhere (fleet convention isENV).campus.apideploys to staging/production (api.campus.nyjc.dev/.appbound). No staging/production auth deployments or domains exist yet, so withENV=staging|production, API commands hit real targets while auth commands fail loudly at login — a documented infrastructure limitation, not a regression.Tests
tests/unit/test_config.pypin the contract: development default when unset, per-ENV URL mapping,ENVoverCAMPUS_ENV,CAMPUS_ENVfallback, explicit env var and config-file precedence over deploy-env routing, invalidENV→ValueError.ruff checkrun manually (worktree checkouts have no local.venvfor the hooks).