Skip to content

fix(socrate): RegisterUser and GetUserAsService call the service-account routes - #61

Merged
ovander merged 1 commit into
mainfrom
fix/service-user-routes
Sep 30, 2026
Merged

ovander merged 1 commit into
mainfrom
fix/service-user-routes

Conversation

@ovander

@ovander ovander commented Sep 30, 2026

Copy link
Copy Markdown
Owner

What and why

socrate.Client.RegisterUser and GetUserAsService sent a client_credentials token to /api/apps/{id}/users…. Those routes need an app admin's user token, so Socrate answered 401 invalid token claims and neither method ever worked.

  • RegisterUser now posts to POST /api/apps/{id}/service/users, the service-account route InviteUserAsService already uses. Name is still sent; Socrate accepts it.
  • GetUserAsService now reads GET /api/apps/{id}/service/users/{user_id}. That route is added in ovander/go-oauth2 (separate PR) and arrives in the Socrate release after v1.5.3.
    • It returns nil, nil only for Socrate's own JSON 404 (not a member of the app, or no such user).
    • A Socrate without the route answers the router's plain-text 404. That is now an error naming the version, never a silent "user not found".

How it was tested

  • New socrate/service_user_routes_test.go, against a fake Socrate whose user-token routes answer a service token with 401, as the real one does:

    • RegisterUser hits POST /api/apps/3/service/users with the service bearer and the full body;
    • GetUserAsService hits GET /api/apps/3/service/users/7;
    • a JSON 404 gives nil, nil;
    • a plain 404 (missing route) gives an error.
  • The existing GetUserAsService and attribution tests now point at the new path.

  • go mod tidy && git diff --exit-code go.sum leaves go.sum unchanged

  • go build ./... passes

  • go vet ./... passes

  • go test -race -count=1 -timeout=120s ./... passes

  • golangci-lint run ./... (v2.14.0) reports no issue

  • govulncheck ./...: couldn't run in the sandbox (vuln.go.dev returns 403); CI runs it

  • A line is added under ## [Unreleased] in CHANGELOG.md

Compatibility

  • Exported-API change: no. Same symbols and signatures; doc comments updated.
  • Behaviour change for existing callers: both methods now work. GetUserAsService needs a Socrate that has the new route; against an older one it returns an error, where it used to return a 401 error.
  • Breaking change: none.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA


Generated by Claude Code

…unt routes

Both methods sent a client_credentials token to /api/apps/{id}/users...,
routes that need an app admin's user token, so Socrate answered 401.

RegisterUser now posts to /api/apps/{id}/service/users (Name still sent).
GetUserAsService now reads GET /api/apps/{id}/service/users/{user_id}
(added in the Socrate release after v1.5.3); it returns nil, nil only for
Socrate's own JSON 404 and an error for a router 404, so a missing route
is never read as "no such user". No exported identifier changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA
@ovander
ovander merged commit 56f0db1 into main Sep 30, 2026
3 checks passed
@ovander ovander mentioned this pull request Sep 30, 2026
1 task done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants