Repository navigation
fix(auth)!: send API token directly as Bearer, drop /api/auth/token exchange - #119
Merged
Merged
Conversation
…xchange The backend (nudgebee/nudgebee-enterprise#37216) removed POST /api/auth/token and /api/auth/revoke. A raw `sk-nb-…` API token now authenticates on its own as a Bearer, so nbctl no longer exchanges {email, secret} for a session token. - authTransport sets `Authorization: Bearer <api-key>` on every request; drop token fetch/caching/refresh/retry logic - clear error when no API key is configured, and a 401 hint explaining the token may be deleted/expired/pre-dating direct auth (plus a prefix hint for non-`sk-nb-` keys) - dedupe NewClient/NewHTTPClient setup; remove unused WithUsername option (username stays in config for nubi/mcp) - tests: replace exchange tests, drop /api/auth/token mocks - docs: README/TESTING updated BREAKING CHANGE: API keys must be `sk-nb-…` tokens accepted by the direct flow; tokens created before direct token auth must be recreated. Co-Authored-By: Claude Opus 5.5 <[email protected]>
blue4209211
marked this pull request as draft
October 1, 2026 13:53
There was a problem hiding this comment.
Code Review
This pull request simplifies the authentication mechanism by transitioning from a token exchange flow to direct token authentication using a personal API token (sk-nb-...) sent directly as a Bearer token. This change removes the /api/auth/token endpoint and the WithUsername option across the client, tests, and mock helpers, and updates the documentation accordingly. Feedback on these changes highlights a potential file descriptor leak in newTransport when logging is enabled, recommending a lazily-initialized global logger, and points out redundant option resolution between NewClient and NewHTTPClient which can be optimized with an internal helper.
…e option resolution Co-Authored-By: Claude Opus 5.5 <[email protected]>
blue4209211
marked this pull request as ready for review
October 8, 2026 07:40
mayankpande88
approved these changes
Oct 8, 2026
RamanKharchee
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
nudgebee/nudgebee-enterprise#37216 removed
POST /api/auth/tokenandPOST /api/auth/revoke. A rawsk-nb-…API token now authenticates on its own as a Bearer. Released nbctl binaries call the removed exchange endpoint, so they will get 401s once that change is deployed.This PR makes nbctl send the configured
api-keydirectly asAuthorization: Bearer <api-key>.pkg/client:authTransportsets the Bearer header on every request. The token fetch, caching, refresh and retry-on-401 code is removed.sk-nb-keys also get a prefix hint.NewClientandNewHTTPClientnow share setup code. The unusedWithUsernameoption is removed;usernamestays in config because nubi/mcp use it./api/auth/tokenmocks are removed.API keys must be
sk-nb-…tokens that the direct flow accepts. Tokens created before direct token auth existed have notoken_sha256and must be recreated in Settings → API Tokens.Testing
go test ./...,go vet ./...andgolangci-lint runpass (0 issues).make install, against dev with ansk-nb-profile:accounts list,auth users list,auth roles list,workflow list,events listandnubi agents listall return data.sk-nb-key and a non-sk-nb-key each return the expected 401 hint.🤖 Generated with Claude Code