Skip to content

fix(auth): normalize cluster suffix in OSC token-service URL - #369

Merged
birme merged 1 commit into
mainfrom
backend/fix-317-osc-environment-token-url
Sep 24, 2026
Merged

birme merged 1 commit into
mainfrom
backend/fix-317-osc-environment-token-url

Conversation

@birme

@birme birme commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Summary

On OSC's Elastx cluster, docker-entrypoint.sh derives OSC_ENVIRONMENT from the instance hostname (*.auto.prod-se.osaas.io), producing OSC_ENVIRONMENT=prod-se. That is the name of the hosting cluster, not the OSC platform environment. api_re_auth.ts and api_share.ts then built the shared token-service URL as https://token.svc.prod-se.osaas.io/..., which does not exist on the platform. As a result reauth failed with a 500 (ServiceToken Service failed to generate new SAT Token after 3 attempts) and share delegation silently fell back, for every Elastx-hosted instance that had not been hand-patched.

This is the conservative Option 1 from #317: normalize the cluster suffix only when constructing the shared token-service host, leaving OSC_ENVIRONMENT itself untouched for any other use.

  • New shared helpers in src/utils.ts:
    • oscPlatformEnvironment(raw) strips a trailing per-cluster suffix (prod-se -> prod, stage-se -> stage), leaving bare prod/stage/dev unchanged.
    • oscTokenServiceBaseUrl(raw) builds https://token.svc.<platform-env>.osaas.io.
  • api_re_auth.ts and api_share.ts — the only two sites that build token.svc.*.osaas.io — now build their URL via oscTokenServiceBaseUrl(OSC_ENVIRONMENT) instead of interpolating the raw value.
  • docker-entrypoint.sh and the OSC_ENVIRONMENT value are unchanged, so the pre-set override added in chore: bump Fastify, fix OSC_ENVIRONMENT override, remove stray dotenv.config() #254 still works.

Test plan

  • npm run typecheck — passes.
  • npm run lint — passes (0 errors; only pre-existing no-explicit-any warnings).
  • npm test — 339 passed / 18 suites.
  • New unit tests in src/utils.test.ts lock in prod-se -> prod, stage-se -> stage, and bare prod/stage/dev unchanged, plus the full base-URL construction.
  • Extended src/api_re_auth.test.ts to assert the token-service fetch targets https://token.svc.prod.osaas.io/servicetoken.

Closes #317

🤖 Generated with Claude Code

`docker-entrypoint.sh` derives `OSC_ENVIRONMENT` from the instance
hostname. On OSC's Elastx cluster the hostname is `*.auto.prod-se.osaas.io`,
so this yields `OSC_ENVIRONMENT=prod-se` — the name of the *hosting cluster*,
not the OSC *platform environment*. `api_re_auth.ts` and `api_share.ts` then
built the shared token-service URL as `https://token.svc.prod-se.osaas.io/...`,
which does not exist on the platform, so reauth failed with a 500 and share
delegation silently fell back for every non-hand-patched Elastx instance.

Add a small shared helper (`oscTokenServiceBaseUrl` /
`oscPlatformEnvironment` in `utils.ts`) that strips a trailing per-cluster
suffix (e.g. `-se`) so `prod-se` -> `prod` and `stage-se` -> `stage`, while
leaving bare `prod`/`stage`/`dev` unchanged. The normalization is applied
only when constructing the shared token-service host; `OSC_ENVIRONMENT`
itself is left untouched for any other use, and the `OSC_ENVIRONMENT`
override added in #254 still works.

Closes #317

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@birme

birme commented Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

Code review verdict: LGTM (separate code-reviewer invocation; recorded as a marker since GitHub blocks self-approval on the authoring account).

Verified: exactly two sites build the token-service URL (api_re_auth.ts /servicetoken, api_share.ts /delegate) and both now route through oscTokenServiceBaseUrl(); OSC_ENVIRONMENT is untouched for other uses and the #254 pre-set override is preserved; docker-entrypoint.sh unchanged. The /-[a-z]+$/ normalization correctly maps prod-se→prod/stage-se→stage and leaves bare prod/stage/dev alone — a deliberate, well-commented future-proofing choice that is safe under the (currently-true) invariant that OSC platform envs are always bare words and hyphenated values are hosting-cluster tags. typecheck / lint / unittests all pass.

Non-blocking follow-up (not gating): add a delegate-URL assertion to api_share.test.ts so that call site has direct regression coverage (currently covered only via the shared utils.test.ts unit test).

@birme
birme merged commit bf28a5f into main Sep 24, 2026
4 checks passed
@birme
birme deleted the backend/fix-317-osc-environment-token-url branch September 24, 2026 12:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OSC_ENVIRONMENT derived from OSC_HOSTNAME breaks reauth on Elastx (prod-se) instances

2 participants