Repository navigation
Preserve existing sessions through credential cutover - #143
Conversation
📝 WalkthroughWalkthroughThe change adds a durable grace-period cutoff for legacy Stack tenant credentials. Server startup persists and shares the cutoff with the multi-tenant handler. Matching legacy credentials work before the cutoff and return unauthorized at or after it. ChangesLegacy credential expiration
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant Serve
participant Registry
participant MultiTenant
participant Client
Serve->>Registry: Ensure persistent legacy credential cutoff
Registry-->>Serve: Return cutoff
Serve->>MultiTenant: Configure cutoff and shared registry
Client->>MultiTenant: Submit legacy tenant credential
MultiTenant-->>Client: 200 OK before cutoff or 401 Unauthorized at cutoff
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@deploy/gcp/README.md`:
- Around line 101-104: Update the deployment README text describing the
legacy-key cutoff to state that 30 days is the default, document the
--stack-legacy-key-grace option for configuring the grace period, and specify
its maximum of 90 days.
In `@internal/tenant/tenant.go`:
- Around line 154-156: Update the cutoff rename flow in the relevant tenant
method to sync r.stateDir immediately after os.Rename(temporaryPath, path)
succeeds. Preserve the existing error return for the rename, and propagate any
parent-directory sync error before returning success so the rename survives a
host crash.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 04047138-b27a-42af-a0b5-4d3d27d5dae3
📒 Files selected for processing (6)
cmd/subrouter/main.godeploy/gcp/README.mdinternal/proxy/multitenant.gointernal/proxy/multitenant_test.gointernal/tenant/tenant.gointernal/tenant/tenant_test.go
| rejected. A durable 30-day cutoff lets tenant keys issued before the broker | ||
| migration survive the deployment without extending their lifetime on restart; | ||
| after the cutoff they fail closed. A fresh `sr login` rotates to the scoped key. | ||
| The CLI writes the tenant-scoped public URL to the local Codex configuration. |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Document the configurable grace period.
Line 101 states a fixed 30-day cutoff. --stack-legacy-key-grace permits a configured grace period up to 90 days. State that 30 days is the default and document the flag and cap.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@deploy/gcp/README.md` around lines 101 - 104, Update the deployment README
text describing the legacy-key cutoff to state that 30 days is the default,
document the --stack-legacy-key-grace option for configuring the grace period,
and specify its maximum of 90 days.
Preserves already-running clients while hosted credentials rotate.
sr loginrotates to scoped credentialsRegression sequence:
49d76c2adds the failing continuity and durable-cutoff tests78e8845implements the transitionVerification:
go test ./...Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Adds a fixed, one-time cutoff for legacy Stack-derived tenant keys with a default 30-day grace so existing sessions survive the deployment and expire on schedule. The cutoff is persisted atomically and directory-synced; sync failures are surfaced and safe to retry without extending the deadline.
New Features
--stack-legacy-key-graceflag (default 30d, max 90d); cutoff is logged at startup.Migration
sr loginto rotate to scoped, broker-issued credentials.--stack-legacy-key-grace.Written for commit 94f0216. Summary will update on new commits.
Summary by CodeRabbit
New Features
sr loginrequests issue a new scoped credential.Bug Fixes