Skip to content

Rename the authz surface to "exchange" (siwe + exchange) - #13

Merged
elffjs merged 1 commit into
mainfrom
rename-exchange-surface
Jun 25, 2026
Merged

elffjs merged 1 commit into
mainfrom
rename-exchange-surface

Conversation

@elffjs

@elffjs elffjs commented Jun 25, 2026

Copy link
Copy Markdown
Member

What

Names the two surfaces for the actions they perform — /siwe (sign-in) and /exchange — replacing the lingering "token exchange" package/identifier verbiage. This also finally aligns the internal name with the shipped gRPC TokenExchangeService.

The one distinction that drives the whole diff

There were two sacds doing different jobs, and they go opposite directions:

  • exchange = the surface → renamed everywhere
  • SACD = the on-chain access-control primitive → stays exactly as-is

A blanket find/replace would have corrupted real contract code; this PR carefully preserves the domain term.

Surface → exchange (packages, URL, env, secrets, docs)

  • internal/tokenexchange/ → internal/exchange/ (all import paths)
  • Public route → /exchange, which drives the issuer (iss == the URL the discovery doc is served from): EXCHANGE_ISSUER=https://dauth.dimo.zone/exchange
  • Env vars → EXCHANGE_ISSUER / EXCHANGE_SIGNING_KEY_*
  • AWS secret path → <ns>/exchange/signing_key_1
  • ExchangeController, exchange*.go, swagger basePath, README, charts, dockerfile, run-local, local keyfile

SACD-the-domain — unchanged

contracts/sacd, sacdproxy, models.SACDData, SACDInterface, autheval's sacd* maps, GetValidSacdDoc, TypeSACD, CONTRACT_ADDRESS_SACD, and every "on-chain SACD access check". The permissions claim and the "permission token" artifact name are part of the token contract and are likewise untouched.

Kept frozen

The gRPC contract consumers depend on — TokenExchangeService, pkg/grpc/token-exchange-api.*, TokenExchangeServer, ServiceName — which already carries the "exchange" term.

Deploy follow-ups (flag-day, consumer-owned)

  • Consumers repoint to …/exchange/keys and iss https://dauth.dimo.zone/exchange (telemetry/dq/fetch auth0 validators pin that iss).
  • Provision the AWS secret at the new path <ns>/exchange/signing_key_1.

Verification

Build, vet, gofmt, full test suite, and helm lint (dev + prod) all pass.

🤖 Generated with Claude Code

The two surfaces are now named for the actions they perform: /siwe
(sign-in) and /exchange. This replaces the lingering "token exchange"
package/identifier verbiage and the brief interim "sacd" naming, and it
finally aligns the internal name with the shipped gRPC TokenExchangeService.

Surface (renamed everywhere — packages, URL, env, secrets, docs):
- internal/tokenexchange -> internal/exchange (all import paths)
- public route /permissions had become /sacd; now /exchange, which drives
  the issuer (iss == the URL the discovery doc is served from):
  EXCHANGE_ISSUER=https://dauth.dimo.zone/exchange
- env vars -> EXCHANGE_ISSUER / EXCHANGE_SIGNING_KEY_*
- AWS secret path -> <ns>/exchange/signing_key_1
- ExchangeController, exchange*.go, swagger basePath, README, charts,
  docker, run-local, local keyfile

SACD-the-domain stays SACD (it's the on-chain access-control primitive,
not the surface): contracts/sacd, sacdproxy, models.SACDData,
SACDInterface, autheval's sacd* maps, GetValidSacdDoc, TypeSACD,
CONTRACT_ADDRESS_SACD, and every "on-chain SACD access check". The
`permissions` claim and the "permission token" artifact name are part of
the token contract and are likewise unchanged.

Kept frozen: the gRPC contract consumers depend on (TokenExchangeService,
pkg/grpc/token-exchange-api.*, TokenExchangeServer, ServiceName) — it
already carries the "exchange" term.

Build, vet, gofmt, full test suite, and helm lint (dev + prod) all pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SDG5nQUwFwLsJmVeAorpPq
@elffjs
elffjs merged commit d0df91f into main Jun 25, 2026
2 checks passed
@elffjs
elffjs deleted the rename-exchange-surface branch June 25, 2026 19:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant