auth: stop hitting entire.io PAT endpoint; sessions live on entire-core

main

Commit

toothbrush4mo ago

auth status and logout were pointing session list/revoke at entire.io's /api/v1/auth/tokens — which is the legacy ent_ personal-access-token surface, not login sessions. For a JWT login that endpoint lists nothing (no ent_ PATs) and rejects DELETE /current with 400 ("revoke entire-core JWTs via entire-core"). The CLI never mints or sends ent_ PATs, so it has no business there.

Repoint session management at entire-core (the auth host) /api/auth/tokens, authenticated with the session-scoped login JWT (resolveAuthHostToken — a same-host resolution that preserves the entire:session scope core's session routes require):

  • auth status: drop the server-side session table entirely. Status is now local: GET /me (profile + liveness) + the active login context. No PAT endpoint, no empty "active sessions".
  • logout: revoke the current session (and --all: every session on the core) via entire-core, not entire.io.

Removes the now-dead session-table rendering + date-formatting helpers.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 99a4950a334d

Checkpoints

Refactor Auth Commands for Session Management

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1