Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The implementation and coverage are sound; the remaining README wording issue is non-blocking.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Derives the default lfx api base URL from the authenticated environment rather than persisted audience data.
Changes:
- Validates stored audiences against compiled-in environment defaults.
- Documents the updated audience and API routing behavior.
- Adds unit and integration coverage for mismatched audiences.
| File | Description |
|---|---|
README.md |
Documents default API routing behavior. |
internal/commands/api.go |
Adds environment-based URL selection and validation. |
internal/commands/api_test.go |
Tests defaults and mismatch refusal. |
internal/commands/auth.go |
Updates token-resolution documentation. |
internal/credstore/credstore.go |
Clarifies persisted audience usage. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Without --hostname, `lfx api` now always uses the compiled-in default API audience for the login's environment as its base URL, rather than the audience value persisted in state.json. A stored audience that differs from that default is refused with an error asking the user to run `lfx auth login` again (or, for development logins, to pass --hostname explicitly), mirroring the existing IdP domain consistency check in loadDeviceStateForBackend. Logins made with a non-default --audience therefore need --hostname (development only) to use `lfx api`; `lfx auth token` is unaffected. Signed-off-by: David Deal <ddeal@linuxfoundation.org> Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L8qMuq3je1uuU2JMLHuYBG
dealako
force-pushed
the
claude/autopatch-scan-29eb251e-vuln-4956724-uubawi
branch
from
October 1, 2026 22:22
2d50739 to
cbe5782
Compare
Describe the environment's default API as the behavior when --hostname is not passed, rather than implying it applies unconditionally. Signed-off-by: David Deal <ddeal@linuxfoundation.org> Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L8qMuq3je1uuU2JMLHuYBG
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
When
--hostnameis not passed,lfx apinow takes its base URL from the compiled-in default API audience for the login's environment (seelfx auth environments), instead of from the audience value stored instate.json.If the stored audience differs from that environment's default,
lfx apirefuses the request with an error telling the user to re-runlfx auth login(or, for development logins, to pass--hostnameexplicitly). This works like the existing check inloadDeviceStateForBackendthat the stored IdP domain matches the environment.Changes
internal/commands/api.go: newapiDefaultBaseURLhelper, used byrunAPIwhen--hostnameis not set; removes the now-unreachable "no API base URL available" branch.internal/commands/api_test.go: table tests forapiDefaultBaseURL, plus an end-to-endlfx apitest against a local server showing that no request is sent when the stored audience doesn't match the environment default.internal/commands/auth.go,internal/credstore/credstore.go: doc-comment updates describing how the stored audience is now used.README.md: notes thelfx apibase URL behavior.Behavior changes
lfx auth login --audiencecan no longer uselfx apiwithout--hostname. Development logins can pass--hostnameon each call; for production and staging, re-runlfx auth loginwith the default audience.lfx auth tokenis unaffected.lfx auth loginagain.Suggested release: patch.
Testing
go test ./...,go vet ./...,gofmt, andgolangci-lint run ./...all pass.revivewas not available locally.🤖 Generated with Claude Code
https://claude.ai/code/session_01L8qMuq3je1uuU2JMLHuYBG
Generated by Claude Code