Skip to content

fix(ENGKNOW-3998): only look up email usernames in CSA - #152

Merged
gmagnu merged 3 commits into
mainfrom
ENGKNOW-3998-csa-404-service-account-log-flood
Oct 7, 2026
Merged

gmagnu merged 3 commits into
mainfrom
ENGKNOW-3998-csa-404-service-account-log-flood

Conversation

@gmagnu

@gmagnu gmagnu commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Jira: ENGKNOW-3998

Problem

Since ENGKNOW-3936 (#143), service-account tokens resolve a username (e.g. sequenceminer) instead of null, so CsaApiUtils.updateWithCsaApi now looks them up in CSA (users/by_email/<name>, projects/<p>/users/<name>). They have no CSA user, so CSA returns 404, and each request logs WARNs with a stack trace (~600–1,000/h on clinops-prd gor-query-server).

Fix

CSA looks users up by email, so CsaApiUtils now only does the CSA user id/role lookup when the username is an email. The check is a new org.gorpipe.util.Strings.isEmail; neither the codebase nor its dependencies had one. Service accounts get the same GorAuthInfo as before ENGKNOW-3936: empty user id and no CSA roles. JWT roles are unaffected.

Tests

  • UTestCsaApiUtils: a non-email user gets no CSA user/role lookup and keeps an empty id/roles. An email user still gets id and roles.
  • UTestStrings.testIsEmail.
  • UTestPlatformAuthUsername.jwtAuthCachesServiceAccountsSeparately now proves separate caching with two project lookups instead of CSA user ids. Service accounts no longer get CSA user ids.
  • ./gradlew :auth:test (55 tests, 0 failed), :util:test --tests UTestStrings (3 tests, 0 failed).

🤖 Generated with Claude Code

… CSA

Since ENGKNOW-3936 service-account tokens resolve a username (e.g.
sequenceminer), so CsaApiUtils.updateWithCsaApi now looks them up in CSA.
They have no CSA user record, so every new token caused 404s, each retried
with a re-auth, and logged as WARN with a full stack trace.

- HttpJsonServiceClient throws HttpStatusException (an IOException) carrying
  the HTTP status for error responses.
- CsaApiService no longer retries 404s with new auth.
- CsaApiUtils remembers users (and project/user pairs) CSA answered 404 for
  for 10 minutes, skips their user/role lookups meanwhile, and logs the miss
  once at INFO without a stack trace. Other CSA errors still log WARN.

The resulting auth info is unchanged: empty user id and no CSA roles, as
before the lookups started.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Junit Tests - Summary

4 912 tests  +3   4 741 ✅ +3   18m 46s ⏱️ - 2m 59s
  510 suites +1     171 💤 ±0 
  510 files   +1       0 ❌ ±0 

Results for commit 88bedd9. ± Comparison against base commit b79342b.

♻️ This comment has been updated with latest results.

…f caching 404s

CSA looks users up by email, so skip the CSA user id/role lookup when the
username is not an email (e.g. service accounts such as sequenceminer).
Replaces the HttpStatusException, no-retry-on-404 and negative cache from the
previous commit with a single check, Strings.isEmail in the util module.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gmagnu gmagnu changed the title fix(ENGKNOW-3998): stop CSA 404 lookups and warnings for users not in CSA fix(ENGKNOW-3998): only look up email usernames in CSA Oct 6, 2026
@gmagnu
gmagnu marked this pull request as ready for review October 6, 2026 22:32
- Strings.isEmail requires a single '@' and rejects whitespace and '/', as
  the username is put unencoded into CSA URL paths.
- Drop the redundant username check in the CSA role lookup.
- Remove unused stubs from UTestCsaApiUtils.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gmagnu
gmagnu merged commit fe063a2 into main Oct 7, 2026
14 checks passed
@gmagnu
gmagnu deleted the ENGKNOW-3998-csa-404-service-account-log-flood branch October 7, 2026 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants