fix: read the AuthKit issuer only from configuration - #84
Merged
Merged
Conversation
Remove WORKOS_ISSUER = "https://accounts.mukoko.com" from the [vars] of both site/wrangler.toml (nyuchi-docs) and nyuchi-docs-mcp-worker/wrangler.toml (nyuchi-docs-mcp). The issuer is a required Worker secret set per environment. The site gate answers 503 "WORKOS_ISSUER is not configured" for internal pages and the OAuth callback when it is missing; the MCP worker already fails closed (no token verifies, internal content stays hidden). Both normalise the value (bare host or https origin, no trailing slash). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
nyuchi-docs-mcp | 3953907 | Commit Preview URL Branch Preview URL |
Oct 03 2026, 01:52 AM |
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
shamwari-docs-ai | 3953907 | Commit Preview URL Branch Preview URL |
Oct 03 2026, 01:52 AM |
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
nyuchi-docs | 3953907 | Commit Preview URL Branch Preview URL |
Oct 03 2026, 01:52 AM |
Parse the configured AuthKit issuer with URL rather than prepending a scheme to a string, in both the MCP worker and the site gate. A bare host or an https origin (any case) is accepted; path, query and fragment are dropped; http, other schemes, credentials and unparseable values are treated as unset, so the MCP worker treats callers as unauthenticated and the gate answers 503. The JWKS, authorize and token URLs are built with new URL, and iss is bound by exact match against the origin. A correctly configured https value resolves to the same origin as before. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The owner's rule: never hardcode the AuthKit domain.
Both Workers in this repo committed the AuthKit issuer as a
[vars]entry:site/wrangler.toml(Workernyuchi-docs):WORKOS_ISSUER = "https://accounts.mukoko.com"— removed.src/worker/gate.tsnow normalises the env value (bare host or https origin, no trailing slash) and answers 503WORKOS_ISSUER is not configuredforvisibility: internalpages and/oauth/callbackwhen it is unset. Public pages are unaffected.nyuchi-docs-mcp-worker/wrangler.toml(Workernyuchi-docs-mcp): same var removed.src/auth.tsalready failed closed (no issuer → no token verifies → public content only); it now normalises the value and logs when a bearer token arrives with no issuer configured.Comments say the value is required, set per environment as a secret, never committed.
Do not merge until both
nyuchi-docsandnyuchi-docs-mcphaveWORKOS_ISSUERset as a secret. Today each has it only as a plain-text var from these files, so the deploy from this merge would drop it. Neither Worker is inowner-actions.shstepworkos_domainsyet; the value is the AuthKit domain withhttps://(1Passwordnyuchi/workos, fieldWORKOS_AUTHKIT_DOMAIN).🤖 Generated with Claude Code
https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq