Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: coder/coder
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: c029869a044526bda2915fd336ad825b454a4783
Choose a base ref
...
head repository: coder/coder
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: cdc233e9b3e0245cdc3cb90ee228ebeea3a2bb7b
Choose a head ref
  • 3 commits
  • 5 files changed
  • 1 contributor

Commits on Aug 24, 2026

  1. fix(coderd): canonicalize API key scope aliases at ingress

    IsExternalScope accepts `all` and `application_connect`, which are not
    api_key_scope enum members. The plural Scopes field appended the requested
    name verbatim, so POST /users/{user}/keys/tokens with {"scopes":["all"]}
    passed validation and then failed inside apikey.Generate, answering HTTP 500
    with `invalid API key scope: "all"`. codersdk still exports APIKeyScopeAll and
    APIKeyScopeApplicationConnect, so a caller reaches this by passing the
    constants the SDK offers for exactly this purpose.
    
    Route every accepted name through rbac.CanonicalScopeName. That fixes the
    plural path and deletes the two open-coded alias switches, which restated a
    mapping the rbac package already owns and had to be kept in step by hand. The
    singular Scope field behaves as before, now by the shared table.
    BobbyHo committed Aug 24, 2026
    Configuration menu
    Copy the full SHA
    4a402d3 View commit details
    Browse the repository at this point in the history
  2. fix: canonicalize API key scopes in apikey.Generate

    Generate taught the deprecated singular Scope field to accept alias
    spellings and left the plural Scopes field passing its input to the enum
    check unchanged, so the alias bug this branch fixes at the handler still
    existed one layer down, on the field callers are being moved toward. No
    caller hits it today, but Generate is the choke point every key creation
    passes through, and the OAuth2 token paths will fill Scopes once their
    scope TODOs resolve.
    
    Canonicalize in the loop that already checks each name, so all three
    cases are covered by one statement, and build a new slice so the
    caller's is left alone. Deduplicate afterwards: an alias and its
    canonical spelling are two names on the way in and one name here, and
    without this "coder tokens create --scope all --scope coder:all" stored
    coder:all twice and listed it twice.
    
    Cover the rejection path, which no test watched. Both handler guards
    could be deleted with the suite still green, while
    {"scopes":["debug_info:read"]} would have persisted an internal-only
    scope that IsExternalScope deliberately refuses and the enum check
    accepts.
    
    Add TestExternalScopesAreStorable to pin the class rather than the two
    instances: any public scope name the api_key_scope enum cannot store
    fails inside Generate after the handler has accepted the request. The
    rbac package cannot check this itself, since database imports rbac.
    
    Use the canonical spellings in the token docs, which taught the commands
    that reproduced the original 500 and now report back a different name
    than the operator typed.
    BobbyHo committed Aug 24, 2026
    Configuration menu
    Copy the full SHA
    d9753b5 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    cdc233e View commit details
    Browse the repository at this point in the history
Loading