Align token issuers with the real host instead of legacy DEX hostnames - #11
Merged
Merged
Conversation
The two `iss` values were carried over verbatim from the separate DEX
services (auth.dimo.zone for sign-in, auth-roles-rights.dimo.zone for
roles/rights). Post-fold, nothing is served at those hosts — the service
lives at dauth.dimo.zone/{siwe,permissions} — so the issuers pointed at
dead hostnames and each surface's discovery document was self-inconsistent
(its `issuer` field didn't match the URL it was served from).
Set `iss = PUBLIC_BASE_URL + surface prefix`:
SIWE_ISSUER -> https://dauth.dimo.zone/siwe (dev: dauth.dev.dimo.zone/siwe)
PERMISSIONS_ISSUER -> https://dauth.dimo.zone/permissions (dev: .../permissions)
OIDC Discovery 1.0 appends /.well-known/openid-configuration to the issuer,
so a path-suffixed issuer is conformant and now matches where each doc is
actually served.
No in-process behavior change: the exchange validates the inbound sign-in
token signature-only (no iss check), and test fixtures use opaque issuer
strings. Updated chart values, config comments/validation examples, the
SIWE challenge example string (handlers.go + regenerated internal/docs),
and README (surfaces table, /challenge example, both ISSUER rows, din's
TOKEN_EXCHANGE_ISSUER example).
DEPLOY NOTE: this is a flag-day change. Downstream iss-pinning validators
(din on the sign-in iss; telemetry-api/dq/fetch-api auth0 validators on the
permission iss) must flip to the new values in lockstep with the deploy.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The two
issvalues were carried over verbatim from the separate DEX services (auth.dimo.zonefor sign-in,auth-roles-rights.dimo.zonefor roles/rights). Post-fold, nothing is served at those hosts — the service lives atdauth.dimo.zone/{siwe,permissions}— so the issuers pointed at dead hostnames, and each surface's OIDC discovery document was self-inconsistent (itsissuerfield didn't match the URL it was served from).This sets
iss = PUBLIC_BASE_URL + surface prefix:SIWE_ISSUER(prod)https://auth.dimo.zonehttps://dauth.dimo.zone/siwePERMISSIONS_ISSUER(prod)https://auth-roles-rights.dimo.zonehttps://dauth.dimo.zone/permissionsauth.dev/auth-roles-rights.devdauth.dev.dimo.zone/siwe·/permissionsOIDC Discovery 1.0 appends
/.well-known/openid-configurationto the issuer, so a path-suffixed issuer is conformant and now matches where each doc is actually served.Why no in-process breakage
internal/tokenexchange/middleware/auth.go— noisscheck), so the/permissionshandoff is unaffected.Build, vet, full test suite (14 pkgs), and
helm lint(dev + prod) all green.Files
charts/dauth/values{,-prod}.yaml— the deployed configinternal/config/config.go,internal/tokenexchange/config/settings.go— doc comments +SIWE_ISSUERvalidation exampleinternal/server/handlers.go+ generatedinternal/docs/*— SIWE challenge example string (auth.→dauth.)README.md— surfaces table,/challengeexample, both ISSUER rows, din'sTOKEN_EXCHANGE_ISSUERexampleDownstream
iss-pinning validators must flip to the new values in lockstep with the dauth deploy or they'll reject tokens (these live in other repos / cluster-helm-charts):ississ🤖 Generated with Claude Code