fix(auth): don't let the default data origin mask a staging login in jurisdiction mint

Commit

jagregory2mo ago

entire auth token --jurisdiction (and the shared entire-api cell URL templating) derive their prod-vs-staging "environment family" via environmentFamily(dataOrigin, discoveredCore). The stored-context path (resolveStoredCellSubject) sets dataOrigin to api.BaseURL(), which defaults to prod entire.io when ENTIRE_API_BASE_URL is unset — so a partial.to login minted a token audienced to https://us.entire.io instead of https://us.partial.to, which a partial.to cell rejects. The ENTIRE_TOKEN path was already correct (it passes the token's own core as dataOrigin).

Fix the shared resolution: only an EXPLICIT ENTIRE_API_BASE_URL override wins; otherwise the discovered login core (which issued/trusts the JWT being exchanged) determines the family, so a partial.to login yields a partial.to audience even with the data origin left at its prod default.

Also introduce familyEntireIO/familyPartialTo constants for the two apex strings. Adds TestEnvironmentFamilyPrefersDiscoveredCoreOverDefaultOrigin.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 01KXD78RRFFBDJF08RHTW0DEK9

Checkpoints

Fix Auth Token Jurisdiction Environment Derivation

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1