Repository navigation
fix(ENGKNOW-3998): only look up email usernames in CSA - #152
Merged
Merged
Conversation
… CSA Since ENGKNOW-3936 service-account tokens resolve a username (e.g. sequenceminer), so CsaApiUtils.updateWithCsaApi now looks them up in CSA. They have no CSA user record, so every new token caused 404s, each retried with a re-auth, and logged as WARN with a full stack trace. - HttpJsonServiceClient throws HttpStatusException (an IOException) carrying the HTTP status for error responses. - CsaApiService no longer retries 404s with new auth. - CsaApiUtils remembers users (and project/user pairs) CSA answered 404 for for 10 minutes, skips their user/role lookups meanwhile, and logs the miss once at INFO without a stack trace. Other CSA errors still log WARN. The resulting auth info is unchanged: empty user id and no CSA roles, as before the lookups started. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…f caching 404s CSA looks users up by email, so skip the CSA user id/role lookup when the username is not an email (e.g. service accounts such as sequenceminer). Replaces the HttpStatusException, no-retry-on-404 and negative cache from the previous commit with a single check, Strings.isEmail in the util module. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gmagnu
marked this pull request as ready for review
October 6, 2026 22:32
- Strings.isEmail requires a single '@' and rejects whitespace and '/', as the username is put unencoded into CSA URL paths. - Drop the redundant username check in the CSA role lookup. - Remove unused stubs from UTestCsaApiUtils. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
bragnarsson
approved these changes
Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Jira: ENGKNOW-3998
Problem
Since ENGKNOW-3936 (#143), service-account tokens resolve a username (e.g.
sequenceminer) instead ofnull, soCsaApiUtils.updateWithCsaApinow looks them up in CSA (users/by_email/<name>,projects/<p>/users/<name>). They have no CSA user, so CSA returns 404, and each request logs WARNs with a stack trace (~600–1,000/h on clinops-prd gor-query-server).Fix
CSA looks users up by email, so
CsaApiUtilsnow only does the CSA user id/role lookup when the username is an email. The check is a neworg.gorpipe.util.Strings.isEmail; neither the codebase nor its dependencies had one. Service accounts get the sameGorAuthInfoas before ENGKNOW-3936: empty user id and no CSA roles. JWT roles are unaffected.Tests
UTestCsaApiUtils: a non-email user gets no CSA user/role lookup and keeps an empty id/roles. An email user still gets id and roles.UTestStrings.testIsEmail.UTestPlatformAuthUsername.jwtAuthCachesServiceAccountsSeparatelynow proves separate caching with two project lookups instead of CSA user ids. Service accounts no longer get CSA user ids../gradlew :auth:test(55 tests, 0 failed),:util:test --tests UTestStrings(3 tests, 0 failed).🤖 Generated with Claude Code