Skip to content

fix(auth)!: send API token directly as Bearer, drop /api/auth/token exchange - #119

Merged
blue4209211 merged 2 commits into
mainfrom
shiv/nbctl-auth-api-updates-90f032
Oct 8, 2026
Merged

blue4209211 merged 2 commits into
mainfrom
shiv/nbctl-auth-api-updates-90f032

Conversation

@blue4209211

Copy link
Copy Markdown
Contributor

Summary

nudgebee/nudgebee-enterprise#37216 removed POST /api/auth/token and POST /api/auth/revoke. A raw sk-nb-… API token now authenticates on its own as a Bearer. Released nbctl binaries call the removed exchange endpoint, so they will get 401s once that change is deployed.

This PR makes nbctl send the configured api-key directly as Authorization: Bearer <api-key>.

  • pkg/client: authTransport sets the Bearer header on every request. The token fetch, caching, refresh and retry-on-401 code is removed.
    • Fails fast when no API key is configured.
    • A 401 returns a hint: the token may be deleted, expired or older than direct token auth. Non-sk-nb- keys also get a prefix hint.
    • NewClient and NewHTTPClient now share setup code. The unused WithUsername option is removed; username stays in config because nubi/mcp use it.
  • Tests: the token-exchange tests are replaced with tests for the Bearer header, the 401 hint and the missing-key error. The dead /api/auth/token mocks are removed.
  • Docs: README and TESTING are updated.

⚠️ Breaking

API keys must be sk-nb-… tokens that the direct flow accepts. Tokens created before direct token auth existed have no token_sha256 and must be recreated in Settings → API Tokens.

Testing

  • go test ./..., go vet ./... and golangci-lint run pass (0 issues).
  • After make install, against dev with an sk-nb- profile: accounts list, auth users list, auth roles list, workflow list, events list and nubi agents list all return data.
  • An unknown sk-nb- key and a non-sk-nb- key each return the expected 401 hint.

🤖 Generated with Claude Code

…xchange

The backend (nudgebee/nudgebee-enterprise#37216) removed POST /api/auth/token
and /api/auth/revoke. A raw `sk-nb-…` API token now authenticates on its own
as a Bearer, so nbctl no longer exchanges {email, secret} for a session token.

- authTransport sets `Authorization: Bearer <api-key>` on every request;
  drop token fetch/caching/refresh/retry logic
- clear error when no API key is configured, and a 401 hint explaining the
  token may be deleted/expired/pre-dating direct auth (plus a prefix hint for
  non-`sk-nb-` keys)
- dedupe NewClient/NewHTTPClient setup; remove unused WithUsername option
  (username stays in config for nubi/mcp)
- tests: replace exchange tests, drop /api/auth/token mocks
- docs: README/TESTING updated

BREAKING CHANGE: API keys must be `sk-nb-…` tokens accepted by the direct
flow; tokens created before direct token auth must be recreated.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@blue4209211
blue4209211 marked this pull request as draft October 1, 2026 13:53

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request simplifies the authentication mechanism by transitioning from a token exchange flow to direct token authentication using a personal API token (sk-nb-...) sent directly as a Bearer token. This change removes the /api/auth/token endpoint and the WithUsername option across the client, tests, and mock helpers, and updates the documentation accordingly. Feedback on these changes highlights a potential file descriptor leak in newTransport when logging is enabled, recommending a lazily-initialized global logger, and points out redundant option resolution between NewClient and NewHTTPClient which can be optimized with an internal helper.

Comment thread pkg/client/client.go
Comment thread pkg/client/client.go
@blue4209211
blue4209211 marked this pull request as ready for review October 8, 2026 07:40
@blue4209211
blue4209211 merged commit 02d06b6 into main Oct 8, 2026
2 checks passed
@blue4209211
blue4209211 deleted the shiv/nbctl-auth-api-updates-90f032 branch October 8, 2026 07:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants