Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 7 additions & 2 deletions internal/commands/auth.go
Original file line number Diff line number Diff line change
Expand Up @@ -121,8 +121,7 @@ func newAuthLoginCommand() *cli.Command {
},
&cli.StringFlag{
Name: audienceFlagName,
Usage: "Auth0 API audience to request tokens for (independent of --env)",
Value: defaultAudience,
Usage: "Auth0 API audience to request tokens for (defaults to the selected environment's LFX API audience)",
},
},
Action: runAuthLogin,
Expand All @@ -141,6 +140,12 @@ func runAuthLogin(ctx context.Context, cmd *cli.Command) error {
return err
}
audience := cmd.String(audienceFlagName)
if !cmd.IsSet(audienceFlagName) {
audience, err = defaultAudienceForEnvironment(env)
if err != nil {
return err
}
}
insecure := cmd.Bool(insecureStorageFlagName)
backend := cmd.String(backendFlagName)

Expand Down
42 changes: 42 additions & 0 deletions internal/commands/auth_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,48 @@ func newInsecureStore(t *testing.T) credstore.Store {
return store
}

func TestDefaultAudienceForEnvironment(t *testing.T) {
tests := []struct {
name string
env authEnvironment
want string
}{
{
name: "prod",
env: envProd,
want: "https://lfx-api.v2.cluster.lfx.dev/",
},
{
name: "staging",
env: envStaging,
want: "https://lfx-api.staging.v2.cluster.linuxfound.info/",
},
{
name: "development",
env: envDevelopment,
want: "https://lfx-api.dev.v2.cluster.linuxfound.info/",
},
}

for _, tc := range tests {
t.Run(tc.name, func(t *testing.T) {
got, err := defaultAudienceForEnvironment(tc.env)
if err != nil {
t.Fatalf("defaultAudienceForEnvironment(%q): %v", tc.env, err)
}
if got != tc.want {
t.Errorf("defaultAudienceForEnvironment(%q) = %q, want %q", tc.env, got, tc.want)
}
})
}
}

func TestDefaultAudienceForEnvironmentInvalid(t *testing.T) {
if _, err := defaultAudienceForEnvironment(authEnvironment("invalid")); err == nil {
t.Fatal("defaultAudienceForEnvironment(invalid): got nil error, want invalid-environment error")
}
}

func TestPersistLoginSuccess(t *testing.T) {
store := newInsecureStore(t)

Expand Down
23 changes: 18 additions & 5 deletions internal/commands/environment.go
Original file line number Diff line number Diff line change
Expand Up @@ -58,11 +58,14 @@ var authClientIDs = map[authEnvironment]string{

// cspell:enable

// defaultAudience is the production LFX v2 API audience used unless
// overridden via `--audience`. It intentionally does not vary with `--env`:
// the audience is independent of the selected environment and must be set
// explicitly when testing a non-prod API.
const defaultAudience = "https://lfx-api.v2.cluster.lfx.dev/"
// defaultAudiences maps each authEnvironment to the matching LFX v2 API
// audience used when `lfx auth login` is run without an explicit
// `--audience` override.
var defaultAudiences = map[authEnvironment]string{
envProd: "https://lfx-api.v2.cluster.lfx.dev/",
envStaging: "https://lfx-api.staging.v2.cluster.linuxfound.info/",
envDevelopment: "https://lfx-api.dev.v2.cluster.linuxfound.info/",
}

// errInvalidEnvironment is returned by resolveEnvironment for an
// unrecognized authEnvironment value.
Expand All @@ -76,3 +79,13 @@ func resolveEnvironment(env authEnvironment) (domain, clientID string, err error
}
return domain, authClientIDs[env], nil
}

// defaultAudienceForEnvironment returns the default LFX v2 API audience
// for env.
func defaultAudienceForEnvironment(env authEnvironment) (string, error) {
audience, ok := defaultAudiences[env]
if !ok {
return "", fmt.Errorf("%w: %q (must be one of prod, staging, development)", errInvalidEnvironment, env)
}
return audience, nil
}
Loading