fix(auth): normalize cluster suffix in OSC token-service URL - #369
Conversation
`docker-entrypoint.sh` derives `OSC_ENVIRONMENT` from the instance hostname. On OSC's Elastx cluster the hostname is `*.auto.prod-se.osaas.io`, so this yields `OSC_ENVIRONMENT=prod-se` — the name of the *hosting cluster*, not the OSC *platform environment*. `api_re_auth.ts` and `api_share.ts` then built the shared token-service URL as `https://token.svc.prod-se.osaas.io/...`, which does not exist on the platform, so reauth failed with a 500 and share delegation silently fell back for every non-hand-patched Elastx instance. Add a small shared helper (`oscTokenServiceBaseUrl` / `oscPlatformEnvironment` in `utils.ts`) that strips a trailing per-cluster suffix (e.g. `-se`) so `prod-se` -> `prod` and `stage-se` -> `stage`, while leaving bare `prod`/`stage`/`dev` unchanged. The normalization is applied only when constructing the shared token-service host; `OSC_ENVIRONMENT` itself is left untouched for any other use, and the `OSC_ENVIRONMENT` override added in #254 still works. Closes #317 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Code review verdict: LGTM (separate code-reviewer invocation; recorded as a marker since GitHub blocks self-approval on the authoring account). Verified: exactly two sites build the token-service URL ( Non-blocking follow-up (not gating): add a delegate-URL assertion to |
Summary
On OSC's Elastx cluster,
docker-entrypoint.shderivesOSC_ENVIRONMENTfrom the instance hostname (*.auto.prod-se.osaas.io), producingOSC_ENVIRONMENT=prod-se. That is the name of the hosting cluster, not the OSC platform environment.api_re_auth.tsandapi_share.tsthen built the shared token-service URL ashttps://token.svc.prod-se.osaas.io/..., which does not exist on the platform. As a result reauth failed with a 500 (ServiceToken Service failed to generate new SAT Token after 3 attempts) and share delegation silently fell back, for every Elastx-hosted instance that had not been hand-patched.This is the conservative Option 1 from #317: normalize the cluster suffix only when constructing the shared token-service host, leaving
OSC_ENVIRONMENTitself untouched for any other use.src/utils.ts:oscPlatformEnvironment(raw)strips a trailing per-cluster suffix (prod-se->prod,stage-se->stage), leaving bareprod/stage/devunchanged.oscTokenServiceBaseUrl(raw)buildshttps://token.svc.<platform-env>.osaas.io.api_re_auth.tsandapi_share.ts— the only two sites that buildtoken.svc.*.osaas.io— now build their URL viaoscTokenServiceBaseUrl(OSC_ENVIRONMENT)instead of interpolating the raw value.docker-entrypoint.shand theOSC_ENVIRONMENTvalue are unchanged, so the pre-set override added in chore: bump Fastify, fix OSC_ENVIRONMENT override, remove stray dotenv.config() #254 still works.Test plan
npm run typecheck— passes.npm run lint— passes (0 errors; only pre-existingno-explicit-anywarnings).npm test— 339 passed / 18 suites.src/utils.test.tslock inprod-se->prod,stage-se->stage, and bareprod/stage/devunchanged, plus the full base-URL construction.src/api_re_auth.test.tsto assert the token-service fetch targetshttps://token.svc.prod.osaas.io/servicetoken.Closes #317
🤖 Generated with Claude Code