Skip to content

fix: read the AuthKit issuer only from configuration - #84

Merged
bryanfawcett merged 3 commits into
mainfrom
fix/authkit-domain-from-config
Oct 3, 2026
Merged

bryanfawcett merged 3 commits into
mainfrom
fix/authkit-domain-from-config

Conversation

@bryanfawcett

Copy link
Copy Markdown
Member

The owner's rule: never hardcode the AuthKit domain.

Both Workers in this repo committed the AuthKit issuer as a [vars] entry:

  • site/wrangler.toml (Worker nyuchi-docs): WORKOS_ISSUER = "https://accounts.mukoko.com" — removed. src/worker/gate.ts now normalises the env value (bare host or https origin, no trailing slash) and answers 503 WORKOS_ISSUER is not configured for visibility: internal pages and /oauth/callback when it is unset. Public pages are unaffected.
  • nyuchi-docs-mcp-worker/wrangler.toml (Worker nyuchi-docs-mcp): same var removed. src/auth.ts already failed closed (no issuer → no token verifies → public content only); it now normalises the value and logs when a bearer token arrives with no issuer configured.

Comments say the value is required, set per environment as a secret, never committed.

Do not merge until both nyuchi-docs and nyuchi-docs-mcp have WORKOS_ISSUER set as a secret. Today each has it only as a plain-text var from these files, so the deploy from this merge would drop it. Neither Worker is in owner-actions.sh step workos_domains yet; the value is the AuthKit domain with https:// (1Password nyuchi/workos, field WORKOS_AUTHKIT_DOMAIN).

🤖 Generated with Claude Code

https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq

Remove WORKOS_ISSUER = "https://accounts.mukoko.com" from the [vars] of
both site/wrangler.toml (nyuchi-docs) and
nyuchi-docs-mcp-worker/wrangler.toml (nyuchi-docs-mcp). The issuer is a
required Worker secret set per environment. The site gate answers 503
"WORKOS_ISSUER is not configured" for internal pages and the OAuth
callback when it is missing; the MCP worker already fails closed (no
token verifies, internal content stays hidden). Both normalise the value
(bare host or https origin, no trailing slash).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
nyuchi-docs-mcp 3953907 Commit Preview URL

Branch Preview URL
Oct 03 2026, 01:52 AM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
shamwari-docs-ai 3953907 Commit Preview URL

Branch Preview URL
Oct 03 2026, 01:52 AM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
nyuchi-docs 3953907 Commit Preview URL

Branch Preview URL
Oct 03 2026, 01:52 AM

bryanfawcett and others added 2 commits October 3, 2026 03:51
Parse the configured AuthKit issuer with URL rather than prepending a
scheme to a string, in both the MCP worker and the site gate. A bare
host or an https origin (any case) is accepted; path, query and fragment
are dropped; http, other schemes, credentials and unparseable values are
treated as unset, so the MCP worker treats callers as unauthenticated and
the gate answers 503. The JWKS, authorize and token URLs are built with
new URL, and iss is bound by exact match against the origin. A correctly
configured https value resolves to the same origin as before.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
@bryanfawcett
bryanfawcett merged commit 1b4b89b into main Oct 3, 2026
18 of 20 checks passed
@bryanfawcett
bryanfawcett deleted the fix/authkit-domain-from-config branch October 3, 2026 02:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant