Repository navigation
feat(socrate): export ServiceToken for calling other services as the app - #78
Merged
Merged
Conversation
ServiceToken(ctx) returns the cached client_credentials access token and its expiry; the unexported getServiceToken now wraps it. A token response without access_token is an error. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014dfgURbaXrGaV6cdxw8JBt
…n is absent Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014dfgURbaXrGaV6cdxw8JBt
…es_in from the request Review of #78. The returned expiry is what a caller relies on, so it must never be later than the real one: - the token's own exp claim comes first, as the instant every verifier checks; - otherwise expires_in is counted from just before the request is sent, not from after the response (which was late by the round trip); - a response with neither is trusted for one minute instead of a guessed 55 minutes, longer than a Socrate token lives. Tests: exp preferred over expires_in; expires_in counted from the request (slow server); the no-expiry fallback stays within a minute. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA
Owner
Author
|
Review: the change is sound (one exchange path, fail closed on a missing
New tests: Generated by Claude Code |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Adds
(*socrate.Client).ServiceToken(ctx) (token string, expiresAt time.Time, err error). It returns the application'sclient_credentialsaccess token and its expiry: the same cached token the service-account calls already use. The token is exchanged again within 30 s of expiry, and concurrent callers share one exchange. The unexportedgetServiceTokennow wraps it, so there is one exchange path.Requested by Lakebridge. Its consumer client (
EL-LAKE-SPEC-004,NewSocrateTokenSource(c *socrate.Client)) calls the gateway with the consumer app's Socrate service token. Until now the token could only be had by re-implementing the OAuth exchange outside backendkit.A
200without anaccess_tokenis now an error instead of an empty token that is cached and sent (fail closed).How it was tested
New
socrate/service_token_test.go:access_token, noClientSecret, a cancelled context.The existing
TestGetServiceToken_ExchangesCredentialsstill passes through the wrapper.go mod tidy && git diff --exit-code go.sumleavesgo.sumunchangedgo build ./...passesgo vet ./...passesgo test -race -count=1 -timeout=120s ./...passesgolangci-lint run ./...(v2.14.0, built with Go 1.27.1) reports no issuegovulncheck ./...reports no vulnerability (run against a database built fromgolang/vulndb;vuln.go.devis not reachable from my environment)## [Unreleased]inCHANGELOG.mdREADME (socrate section) and
docs/CLIENT-INTEGRATION.md(M2M method table, port table and service-account section) document the method.Compatibility
(*socrate.Client).ServiceToken. No existing symbol changes.access_tokenis an error. Before, an empty token was cached and every service-account call failed at Socrate, so no working caller is affected.🤖 Generated with Claude Code
https://claude.ai/code/session_014dfgURbaXrGaV6cdxw8JBt
Generated by Claude Code