Commit da1cffb
fix(runtime): the dispatcher's scope strip matches
* fix(runtime): the dispatcher's scope strip matches `/environments/`, the prefix its own hint parser reads
`HttpDispatcher.dispatch()` reads one scoped-URL convention in three places:
`extractEnvironmentIdFromPath` (the environment-id hint), the
`acceptOAuthAccessToken` test, and the scope strip that lets
`DomainHandlerRegistry` match the remainder. Only the first had been moved to
the ADR-0006 `/environments/` spelling. The strip's comment already claimed
`/environments/:environmentId`; its regex matched `/projects/`.
Driven through the real `@objectstack/hono` catch-all — the entry cloud hosts
mount, and the only one that hands `dispatch()` a still-scoped path — the
strip never fired, and the registry matches from the head of the path:
GET /api/v1/environments/env_alpha/health 404 ROUTE_NOT_FOUND -> 200
GET /api/v1/environments/env_alpha/data/task 404 ROUTE_NOT_FOUND -> reaches /data
GET /api/v1/health (control) 200 -> 200
GET /api/v1/data/task (control) reaches /data, unchanged
GET /api/v1/no-such-domain (negative) 404 -> 404
The legacy spelling is not kept as an alias. Nothing parses `/projects/<id>`,
so stripping it discarded the only place the request named an environment and
served it from the host default; ADR-0006 D2 retired `project` on the API
surface with no aliases, and `content/docs/api/environment-routing.mdx` tells
callers to replace it. It now answers 404, which is the honest response.
The OAuth-on-MCP gate moves in the same change because repairing the strip is
what makes it reachable: left behind, a scoped `/mcp` caller would reach the
domain with its OAuth 2.1 access token refused. The orphaned pre-rename
docblock stacked above `extractEnvironmentIdFromPath` is deleted — it named a
"project UUID" and the retired URL form, and it is the shape of prose this
card exists to remove.
Part of #15488
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D47qPfEWVPmhguWgBZCi5N
* docs(runtime): the denial envelope's docblock names the prefix the strip actually removes
`routeObjectFromPath` documents what it expects of the dispatcher's cleaned
path, and said `/projects/:environmentId` prefix stripped. Same sentence, same
strip, same retired spelling as the regex this branch repaired — a comment that
teaches the next reader the wrong invariant is the whole subject of this card,
so leaving one of them standing one file over would only defer it.
Prose only; `routeObjectFromPath` itself matches `/^\/data\/([^/?#]+)/` and is
unchanged.
Part of #15488
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D47qPfEWVPmhguWgBZCi5N
---------
Co-authored-by: Claude <noreply@anthropic.com>/environments/, the prefix its own hint parser reads (#15859)1 parent 4ca358d commit da1cffb
4 files changed
Lines changed: 233 additions & 10 deletions
File tree
- .changeset
- packages/runtime/src
- security
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
Lines changed: 172 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
560 | 560 | | |
561 | 561 | | |
562 | 562 | | |
563 | | - | |
564 | | - | |
565 | | - | |
| 563 | + | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
566 | 575 | | |
567 | 576 | | |
568 | 577 | | |
| |||
1130 | 1139 | | |
1131 | 1140 | | |
1132 | 1141 | | |
1133 | | - | |
1134 | | - | |
1135 | | - | |
1136 | | - | |
1137 | | - | |
1138 | 1142 | | |
1139 | 1143 | | |
1140 | 1144 | | |
| |||
2195 | 2199 | | |
2196 | 2200 | | |
2197 | 2201 | | |
2198 | | - | |
| 2202 | + | |
| 2203 | + | |
| 2204 | + | |
| 2205 | + | |
| 2206 | + | |
| 2207 | + | |
| 2208 | + | |
| 2209 | + | |
| 2210 | + | |
| 2211 | + | |
| 2212 | + | |
| 2213 | + | |
| 2214 | + | |
| 2215 | + | |
| 2216 | + | |
| 2217 | + | |
| 2218 | + | |
| 2219 | + | |
| 2220 | + | |
| 2221 | + | |
| 2222 | + | |
| 2223 | + | |
| 2224 | + | |
| 2225 | + | |
| 2226 | + | |
| 2227 | + | |
| 2228 | + | |
| 2229 | + | |
| 2230 | + | |
2199 | 2231 | | |
2200 | 2232 | | |
2201 | 2233 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
| 64 | + | |
65 | 65 | | |
66 | 66 | | |
67 | 67 | | |
| |||
0 commit comments