Skip to content

Align token issuers with the real host instead of legacy DEX hostnames - #11

Merged
elffjs merged 1 commit into
mainfrom
align-issuers-to-host
Jun 24, 2026
Merged

elffjs merged 1 commit into
mainfrom
align-issuers-to-host

Conversation

@elffjs

@elffjs elffjs commented Jun 24, 2026

Copy link
Copy Markdown
Member

What

The two iss values were carried over verbatim from the separate DEX services (auth.dimo.zone for sign-in, auth-roles-rights.dimo.zone for roles/rights). Post-fold, nothing is served at those hosts — the service lives at dauth.dimo.zone/{siwe,permissions} — so the issuers pointed at dead hostnames, and each surface's OIDC discovery document was self-inconsistent (its issuer field didn't match the URL it was served from).

This sets iss = PUBLIC_BASE_URL + surface prefix:

Before After
SIWE_ISSUER (prod) https://auth.dimo.zone https://dauth.dimo.zone/siwe
PERMISSIONS_ISSUER (prod) https://auth-roles-rights.dimo.zone https://dauth.dimo.zone/permissions
dev auth.dev / auth-roles-rights.dev dauth.dev.dimo.zone/siwe · /permissions

OIDC Discovery 1.0 appends /.well-known/openid-configuration to the issuer, so a path-suffixed issuer is conformant and now matches where each doc is actually served.

Why no in-process breakage

  • The exchange validates the inbound sign-in token signature-only (internal/tokenexchange/middleware/auth.go — no iss check), so the /permissions handoff is unaffected.
  • Test fixtures use opaque issuer strings, independent of the deployed values — left as-is.

Build, vet, full test suite (14 pkgs), and helm lint (dev + prod) all green.

Files

  • charts/dauth/values{,-prod}.yaml — the deployed config
  • internal/config/config.go, internal/tokenexchange/config/settings.go — doc comments + SIWE_ISSUER validation example
  • internal/server/handlers.go + generated internal/docs/* — SIWE challenge example string (auth. → dauth.)
  • README.md — surfaces table, /challenge example, both ISSUER rows, din's TOKEN_EXCHANGE_ISSUER example

⚠️ Deploy note — flag-day change

Downstream iss-pinning validators must flip to the new values in lockstep with the dauth deploy or they'll reject tokens (these live in other repos / cluster-helm-charts):

  • din pins the sign-in iss
  • telemetry-api / dq / fetch-api auth0 validators pin the permission iss

🤖 Generated with Claude Code

The two `iss` values were carried over verbatim from the separate DEX
services (auth.dimo.zone for sign-in, auth-roles-rights.dimo.zone for
roles/rights). Post-fold, nothing is served at those hosts — the service
lives at dauth.dimo.zone/{siwe,permissions} — so the issuers pointed at
dead hostnames and each surface's discovery document was self-inconsistent
(its `issuer` field didn't match the URL it was served from).

Set `iss = PUBLIC_BASE_URL + surface prefix`:
  SIWE_ISSUER        -> https://dauth.dimo.zone/siwe        (dev: dauth.dev.dimo.zone/siwe)
  PERMISSIONS_ISSUER -> https://dauth.dimo.zone/permissions (dev: .../permissions)

OIDC Discovery 1.0 appends /.well-known/openid-configuration to the issuer,
so a path-suffixed issuer is conformant and now matches where each doc is
actually served.

No in-process behavior change: the exchange validates the inbound sign-in
token signature-only (no iss check), and test fixtures use opaque issuer
strings. Updated chart values, config comments/validation examples, the
SIWE challenge example string (handlers.go + regenerated internal/docs),
and README (surfaces table, /challenge example, both ISSUER rows, din's
TOKEN_EXCHANGE_ISSUER example).

DEPLOY NOTE: this is a flag-day change. Downstream iss-pinning validators
(din on the sign-in iss; telemetry-api/dq/fetch-api auth0 validators on the
permission iss) must flip to the new values in lockstep with the deploy.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@elffjs
elffjs merged commit f190af6 into main Jun 24, 2026
2 checks passed
@elffjs
elffjs deleted the align-issuers-to-host branch June 24, 2026 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant