Skip to content

fix(api): derive default API base URL from the login environment - #13

Open
dealako wants to merge 2 commits into
mainfrom
claude/autopatch-scan-29eb251e-vuln-4956724-uubawi
Open

dealako wants to merge 2 commits into
mainfrom
claude/autopatch-scan-29eb251e-vuln-4956724-uubawi

Conversation

@dealako

@dealako dealako commented Oct 1, 2026

Copy link
Copy Markdown

Summary

When --hostname is not passed, lfx api now takes its base URL from the compiled-in default API audience for the login's environment (see lfx auth environments), instead of from the audience value stored in state.json.

If the stored audience differs from that environment's default, lfx api refuses the request with an error telling the user to re-run lfx auth login (or, for development logins, to pass --hostname explicitly). This works like the existing check in loadDeviceStateForBackend that the stored IdP domain matches the environment.

Changes

  • internal/commands/api.go: new apiDefaultBaseURL helper, used by runAPI when --hostname is not set; removes the now-unreachable "no API base URL available" branch.
  • internal/commands/api_test.go: table tests for apiDefaultBaseURL, plus an end-to-end lfx api test against a local server showing that no request is sent when the stored audience doesn't match the environment default.
  • internal/commands/auth.go, internal/credstore/credstore.go: doc-comment updates describing how the stored audience is now used.
  • README.md: notes the lfx api base URL behavior.

Behavior changes

  • Logins made with a non-default lfx auth login --audience can no longer use lfx api without --hostname. Development logins can pass --hostname on each call; for production and staging, re-run lfx auth login with the default audience. lfx auth token is unaffected.
  • State files from before default audiences became environment-specific (staging/development logins that stored the production audience) will get an error asking the user to run lfx auth login again.

Suggested release: patch.

Testing

  • go test ./..., go vet ./..., gofmt, and golangci-lint run ./... all pass. revive was not available locally.

🤖 Generated with Claude Code

https://claude.ai/code/session_01L8qMuq3je1uuU2JMLHuYBG


Generated by Claude Code

Copilot AI balanced review requested due to automatic review settings October 1, 2026 22:19
@dealako
dealako requested review from a team and emsearcy as code owners October 1, 2026 22:19
@dealako
dealako requested a review from jordane October 1, 2026 22:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation and coverage are sound; the remaining README wording issue is non-blocking.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Derives the default lfx api base URL from the authenticated environment rather than persisted audience data.

Changes:

  • Validates stored audiences against compiled-in environment defaults.
  • Documents the updated audience and API routing behavior.
  • Adds unit and integration coverage for mismatched audiences.
File Description
README.md Documents default API routing behavior.
internal/​commands/​api.go Adds environment-based URL selection and validation.
internal/​commands/​api_test.go Tests defaults and mismatch refusal.
internal/​commands/​auth.go Updates token-resolution documentation.
internal/​credstore/​credstore.go Clarifies persisted audience usage.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread README.md Outdated
Without --hostname, `lfx api` now always uses the compiled-in default
API audience for the login's environment as its base URL, rather than
the audience value persisted in state.json. A stored audience that
differs from that default is refused with an error asking the user to
run `lfx auth login` again (or, for development logins, to pass
--hostname explicitly), mirroring the existing IdP domain consistency
check in loadDeviceStateForBackend.

Logins made with a non-default --audience therefore need --hostname
(development only) to use `lfx api`; `lfx auth token` is unaffected.

Signed-off-by: David Deal <ddeal@linuxfoundation.org>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L8qMuq3je1uuU2JMLHuYBG
@dealako
dealako force-pushed the claude/autopatch-scan-29eb251e-vuln-4956724-uubawi branch from 2d50739 to cbe5782 Compare October 1, 2026 22:22
Describe the environment's default API as the behavior when --hostname
is not passed, rather than implying it applies unconditionally.

Signed-off-by: David Deal <ddeal@linuxfoundation.org>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L8qMuq3je1uuU2JMLHuYBG
Copilot AI balanced review requested due to automatic review settings October 1, 2026 22:26

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation matches the stated security behavior and includes focused regression coverage.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@dealako dealako added the security An issue, task, feature, bug, or pull request related security or security audit. label Oct 1, 2026
@dealako dealako self-assigned this Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security An issue, task, feature, bug, or pull request related security or security audit.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants