fix(auth): derive jurisdiction mint environment from the active context

Commit

jagregory2mo ago

entire auth token --jurisdiction <slug> (-j) mints a jurisdictional identity token, and the shared entire-api cell resolution templates the audience/exchange-core from an environment "family". Both derived that family from the data-API origin, which defaults to prod entire.io when ENTIRE_API_BASE_URL is unset — so a partial.to login minted a token audienced to https://us.entire.io (iss https://us.auth.entire.io), which a partial.to cell rejects. Plain entire auth token was already correct because it keys off the active login context's core_url.

Fix at the shared resolution point:

  • environmentFamily no longer lets the default data origin mask the login environment. An explicit ENTIRE_API_BASE_URL still wins; the default falls through to the discovered login core (the core that issued/trusts the JWT being exchanged), so a partial.to login yields a partial.to family.
  • New auth.MintJurisdictionIdentityToken exchanges the caller's login credential (active-context JWT or ENTIRE_TOKEN) for a jurisdictional identity token whose environment is taken from the context core, never a constant entire.io base.
  • Wire it into entire auth token behind --jurisdiction/-j.

Before (active context us.auth.partial.to): aud=https://us.entire.io. After: aud=https://us.partial.to (exchange at https://us.auth.partial.to). The entire.io context is unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 879dcfce8ae4

Checkpoints

Fix Auth Token Jurisdiction Environment Derivation

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1