@@ -78,7 +78,10 @@ import { OCI_SERVICE_ID } from '@/lib/oauth/types'
7878// Fixed test material. The expected signatures were generated independently with
7979// OpenSSL 3 against Oracle's Request Signatures specification (retrieved 2026-09-03):
8080// https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm
81- // The canonical header order is cross-checked against oci-common 2.140.0.
81+ // The Identity hostname is cross-checked against Oracle's API endpoint catalog:
82+ // https://docs.oracle.com/en-us/iaas/api/
83+ // The canonical header order and hostname template are cross-checked against
84+ // oci-common and oci-identity 2.140.1.
8285// Keep the synthetic fixture's PEM delimiters split so secret scanners do not
8386// mistake checked-in conformance material for a deployable credential.
8487const PRIVATE_KEY = `${ [ '-----BEGIN' , 'PRIVATE KEY-----' ] . join ( ' ' ) }
@@ -128,6 +131,7 @@ const SECRET = JSON.stringify({
128131const STATIC_POLICY = createOciStaticEndpointPolicy ( {
129132 serviceId : OCI_SERVICE_ID ,
130133 serviceName : 'identity' ,
134+ hostnameTemplate : 'regional-oci' ,
131135} )
132136
133137function secureResponse ( params : {
@@ -239,6 +243,7 @@ describe('credential-bound OCI client', () => {
239243 const wrongPolicy = createOciStaticEndpointPolicy ( {
240244 serviceId : 'slack' ,
241245 serviceName : 'identity' ,
246+ hostnameTemplate : 'regional-oci' ,
242247 } )
243248 await expect ( client . prepareStaticEndpoint ( wrongPolicy ) ) . rejects . toMatchObject ( {
244249 code : 'invalid_endpoint' ,
@@ -252,7 +257,7 @@ describe('credential-bound OCI client', () => {
252257 code : 'invalid_endpoint' ,
253258 } )
254259 expect ( ( await createPreparedClient ( { region : 'eu-frankfurt-1' } ) ) . endpoint . origin ) . toBe (
255- 'https://identity.eu-frankfurt-1.oraclecloud.com'
260+ 'https://identity.eu-frankfurt-1.oci. oraclecloud.com'
256261 )
257262 } )
258263
@@ -274,15 +279,15 @@ describe('credential-bound OCI client', () => {
274279
275280 const authorization = authorizationFromLastRequest ( )
276281 expect ( authorization ) . toBe (
277- 'Signature version="1",keyId="ocid1.tenancy.oc1..aaaaaaaafixedvector/ocid1.user.oc1..aaaaaaaafixedvector/25:53:22:62:aa:db:ff:ef:f5:77:08:d1:a2:ed:8b:e6",algorithm="rsa-sha256",headers="x-date (request-target) host",signature="pcMhip57/dPnKl/dfg5usN7oT/illXEGUp9Oj2d9bpGb0aRMBJclgVFKRYdYXciUGPM/9vKluD5/eGPBO1Oh7w/6NCB8UX2Ejh/lw8merU1QalZ/OfHyj+wKNVOpqwQjNqettRUzSVMhCqImDnvgx8ygmVCvdc0CeLXf2ZF9iT1bYlDjOiuxOcWreN2rs1ZmfLCfal204nAjrNAvoBSgHCPVquAYnfsT2auOWP4QeHN/Hd/v7TvNqsWBFIaLCyWZOvRzpsw/ZLgLzB+jkuPTdL7l4hOZATUd7xy1QPFTJ0P1RlLHjZE1sH7hbrqVGORNXrVhA1LaArObz6GWPOOghA =="'
282+ 'Signature version="1",keyId="ocid1.tenancy.oc1..aaaaaaaafixedvector/ocid1.user.oc1..aaaaaaaafixedvector/25:53:22:62:aa:db:ff:ef:f5:77:08:d1:a2:ed:8b:e6",algorithm="rsa-sha256",headers="x-date (request-target) host",signature="szHTszQxwI2ewdVaeTurJY0ObT7qSjjTpXKLDRhnBp8g2hT1r2yxs4IaxN+wcrebh4i5tQYq5aBIuM3f5jOe4ng/e9+HCV+J8kHyRMxwk1b3nkqtImf8sPetp1ohD1XeWdT1gw5MSavC/C2mdHdDNlOrYAKD2vwxsKRbS6/C6ngRRcTispz6UU/ydmeYq3JjuFJezFPGWXRdqndM0dC+/ew19x08X/M6quZcxn9JZVw1E2YzSjq8xquLQYyISesVtpN81HEZ9KE9UOhbALNQAJcLCt6R3Su78aOR0S0vh19YkrwxCLbbTmPrVubksXsfZPcotbZmtXVIzNdLW0JpNg =="'
278283 )
279284
280285 const signature = / s i g n a t u r e = " ( [ ^ " ] + ) " / . exec ( authorization ) ?. [ 1 ]
281286 expect ( signature ) . toBeDefined ( )
282287 expect (
283288 verify (
284289 'RSA-SHA256' ,
285- 'x-date: Thu, 03 Sep 2026 19:00:00 GMT\n(request-target): get /20160918/users?limit=10&name=Team%20X\nhost: identity.us-ashburn-1.oraclecloud.com' ,
290+ 'x-date: Thu, 03 Sep 2026 19:00:00 GMT\n(request-target): get /20160918/users?limit=10&name=Team%20X\nhost: identity.us-ashburn-1.oci. oraclecloud.com' ,
286291 createPublicKey ( PRIVATE_KEY ) ,
287292 Buffer . from ( signature ! , 'base64' )
288293 )
@@ -304,7 +309,7 @@ describe('credential-bound OCI client', () => {
304309 } )
305310
306311 expect ( authorizationFromLastRequest ( ) ) . toBe (
307- 'Signature version="1",keyId="ocid1.tenancy.oc1..aaaaaaaafixedvector/ocid1.user.oc1..aaaaaaaafixedvector/25:53:22:62:aa:db:ff:ef:f5:77:08:d1:a2:ed:8b:e6",algorithm="rsa-sha256",headers="x-date (request-target) host content-type content-length x-content-sha256",signature="vyhrwd21evtwFet82VT1FvKEeZV+JSa3VZuS5p4Pj8K2zeU88GO+tGx/voUK9TFHijF7eG5gGS6WWc6tigrByTocbVOHpLtPNgBo2+1NbTbGHGUZIzCOR5CZ1ite74Ak43xZjyKBm+vZHrvS22leVOJe43V/HjqCxqyPn3WkKd7npqo9eFM1sibdj1h3Cmi79b5nXSPFe5KE+rnMRPTOB4nl7iFELvubg/Y7Y8w5hRYEe13w09zw9tTBdGJtZIuMoYwZYzPdZo5wbrN5WM6ylHC2euVh2PSazZZU99q55uhxiR6OaCQWLM0buytCqja8FeiEY8Iw3GuEbKUECKaM8Q =="'
312+ 'Signature version="1",keyId="ocid1.tenancy.oc1..aaaaaaaafixedvector/ocid1.user.oc1..aaaaaaaafixedvector/25:53:22:62:aa:db:ff:ef:f5:77:08:d1:a2:ed:8b:e6",algorithm="rsa-sha256",headers="x-date (request-target) host content-type content-length x-content-sha256",signature="W2/OGoa2XuOin6+CQt32/+/lAXG5PWoamkAHr/k84oCYGUuub2mEYw1z9p4gc6/GPgeZ30wVp4DNVLzOjup3nJir1WsEsYzAk27XAIRVjxiQ7oBzCccnSnB88KLeNz1NDz7r4QPQGxZ50MBQEe0C+DEH2P+utpfFN73o7GCUhIN9hb27COg4l7ffdSLgjBWPN/B4AiZXpjz3I/GRHo29otGAhZ3MiX10gJTjy+qeAchAfmXmTx/nJqNhF0Aj255+B2lepCrHdkpcBpiTs5E+ppE6VvML0ByQ9ZLzBISB4MBljuFyey6tnTkueT73fqjQyM/OT+aO9HrAlemc3HSAXA =="'
308313 )
309314 expect ( mocks . secureFetch . mock . calls [ 0 ] [ 1 ] . headers ) . toMatchObject ( {
310315 'content-length' : '0' ,
@@ -337,7 +342,7 @@ describe('credential-bound OCI client', () => {
337342 { body : Uint8Array ; headers : Record < string , string > } ,
338343 ]
339344 expect ( url ) . toBe (
340- 'https://identity.us-ashburn-1.oraclecloud.com/v1/%E2%98%83?z=last&a=&a=%20%21%27%28%29%2A'
345+ 'https://identity.us-ashburn-1.oci. oraclecloud.com/v1/%E2%98%83?z=last&a=&a=%20%21%27%28%29%2A'
341346 )
342347 expect ( [ ...options . body ] ) . toEqual ( [ ...body ] )
343348 expect ( options . body ) . not . toBe ( body )
@@ -666,6 +671,7 @@ describe('credential-bound OCI client', () => {
666671 const policy = createOciDiscoveredEndpointPolicy ( {
667672 serviceId : OCI_SERVICE_ID ,
668673 serviceName : 'database' ,
674+ hostnameTemplate : 'regional' ,
669675 responsePolicy : STATIC_POLICY ,
670676 source : { kind : 'json' , path : [ 'endpoint' ] } ,
671677 } )
@@ -694,6 +700,7 @@ describe('credential-bound OCI client', () => {
694700 const otherPolicy = createOciStaticEndpointPolicy ( {
695701 serviceId : OCI_SERVICE_ID ,
696702 serviceName : 'compute' ,
703+ hostnameTemplate : 'regional' ,
697704 } )
698705 const otherEndpoint = await first . client . prepareStaticEndpoint ( otherPolicy )
699706 mocks . secureFetch . mockResolvedValueOnce (
0 commit comments