Skip to content

fix: read the AuthKit issuer only from configuration - #22

Merged
bryanfawcett merged 4 commits into
mainfrom
fix/authkit-domain-from-config
Oct 3, 2026
Merged

bryanfawcett merged 4 commits into
mainfrom
fix/authkit-domain-from-config

Conversation

@bryanfawcett

Copy link
Copy Markdown
Member

The owner's rule: never hardcode the AuthKit domain.

shamwari-github-mcp (in worker/) had the AuthKit issuer in three places:

  • wrangler.toml [vars]: WORKOS_AUTHORIZATION_SERVER = "https://accounts.mukoko.com" — removed; listed with the per-environment secrets.
  • src/a2a.ts agent card: || "https://accounts.mukoko.com" fallback — removed.
  • src/auth.ts resource metadata: || "https://api.workos.com" fallback — removed.

New authorizationServer() reads only the env (normalises a bare host or https origin, strips a trailing slash). /.well-known/oauth-protected-resource and /.well-known/agent-card.json answer 503 WORKOS_AUTHORIZATION_SERVER is not configured when it is unset. README / wrangler.toml comments no longer name the host in the secret examples. Tests set the value explicitly as a fixture; new fail-closed tests.

Do not merge until the shamwari-github-mcp Worker has WORKOS_AUTHORIZATION_SERVER set as a secret. Today it is a plain-text var that comes from this wrangler.toml, and merging runs wrangler deploy (deploy-worker.yml), which would drop it. This Worker is not in owner-actions.sh step workos_domains yet; the value is the AuthKit domain with https:// (1Password nyuchi/workos, field WORKOS_AUTHKIT_DOMAIN).

🤖 Generated with Claude Code

https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq

Remove WORKOS_AUTHORIZATION_SERVER = "https://accounts.mukoko.com" from
worker/wrangler.toml [vars], the "https://accounts.mukoko.com" fallback
in the agent card and the "https://api.workos.com" fallback in the
resource metadata. Both documents now take the issuer only from the
WORKOS_AUTHORIZATION_SERVER Worker secret (normalised: bare host or
https origin, no trailing slash) and answer 503
"WORKOS_AUTHORIZATION_SERVER is not configured" when it is missing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
Comment thread worker/src/auth.ts Fixed
bryanfawcett and others added 3 commits October 3, 2026 03:28
Clears CodeQL js/polynomial-redos on the issuer normaliser.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
Parse the advertised AuthKit issuer with URL rather than prepending a
scheme to a string. A bare host or an https origin (any case) is
accepted; path, query and fragment are dropped; http, other schemes,
credentials and unparseable values are rejected and treated as unset, so
the resource metadata and agent card answer 503. The agent card's
OpenID Connect URL is built with new URL. A correctly configured https
value resolves to the same origin as before.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GHjaH1Vt2dVLWU68iz8tFq
@bryanfawcett
bryanfawcett merged commit 414770b into main Oct 3, 2026
14 checks passed
@bryanfawcett
bryanfawcett deleted the fix/authkit-domain-from-config branch October 3, 2026 02:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants