Repository navigation
Conversation
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Developer JWTs name the license (
ethereum_address= client ID) but not the API key (license signer) that minted them. Disabling a signer stops new tokens, but existing ones keep working for their full 336 hours. token-exchange-api, vehicle-triggers-api, tesla-oracle and credit-tracker will checkisSigner(signer_address)on each request; this is the first half.What
isSigner). It stores the address inIdentity.ConnectorDataas{"signer_address": "0x…"}.ethereum_addressis a developer license.exchangeAuthCode: reads that connector data, andnewIDTokenemitssigner_address(checksummed) on both the access token and the ID token.auth_requestandauth_codecolumns, so there is no storage migration.code.Release
Don't merge until all four dex deployments are pinned to
v2.30.100(dev, prod, roles-rights dev, roles-rights prod; a cluster-helm-charts PR, not opened yet). Today they all rundimozone/dex:latestwithpullPolicy: Always, and a merge here republisheslatest, so any pod restart would pick this up unreleased.v2.30.100is already tagged at the currentmaster(c13c657), and its image is on Docker Hub.v2.30.101and pin dev only. Production follows after the console-teams live pass in dev.Successor services
dauthisn't live. If it replaces dex, it must emit the same claim.Tests
TestRecoverSigner.TestEOALoginandTestBlockchainBackend.TestExchangeAuthCodeSignerAddressClaim: present, absent, another connector's data, malformed, non-JSON.TestSubmitChallengeSignerAddressClaim: end to end throughgenerate_challenge→finalizeLogin→ code → token, with a stub Web3 connector, with and without a signer.