MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / attach_identity

Function attach_identity

atomic-cli/src/commands/auth.rs:348–431  ·  view source on GitHub ↗

Attach a Bearer JWT auth header to the remote config. `identity_override` — if provided, this identity name is used directly, bypassing URL-based inference. Set from `RemoteEntry.identity` or the `--identity` CLI flag. If the identity cannot be resolved (no override, no userinfo, no subdomain, or identity not found in the store) or login fails, the config is returned unmodified and a debug log i

(
    config: HttpRemoteConfig,
    remote_url: &str,
    identity_override: Option<&str>,
)

Source from the content-addressed store, hash-verified

346/// unmodified and a debug log is emitted. This keeps push/pull/clone working
347/// against servers that don't require auth (e.g. public reads).
348pub async fn attach_identity(
349 config: HttpRemoteConfig,
350 remote_url: &str,
351 identity_override: Option<&str>,
352) -> HttpRemoteConfig {
353 if identity_override.is_some() {
354 log::debug!("Using explicit identity override: {:?}", identity_override);
355 }
356
357 // Priority 1: explicit override (--identity); 2/3: URL userinfo or subdomain.
358 let inferred = resolve_identity_name_with_override(remote_url, identity_override);
359 let source = if identity_override.is_some() {
360 format!("--identity {:?}", identity_override)
361 } else {
362 "URL/config inference".to_string()
363 };
364
365 let store = match IdentityStore::open_default() {
366 Ok(s) => s,
367 Err(e) => {
368 log::debug!("Failed to open identity store: {}", e);
369 return config;
370 }
371 };
372
373 // Resolve a concrete identity, falling back to the default when the
374 // inferred name doesn't match any local identity (e.g. the `aaron`
375 // subdomain vs. a local identity named `aaron-claude`). An explicit
376 // --identity that doesn't exist does NOT fall back (returns None → no
377 // auth header, so the server rejects it with a clear 401).
378 let explicit = identity_override.is_some();
379 let identity = match resolve_identity_with_default_fallback(
380 &store,
381 inferred.as_deref(),
382 explicit,
383 &source,
384 ) {
385 Some(id) => id,
386 None => {
387 log::debug!(
388 "No usable identity for {} (inferred={:?}) and no default set",
389 remote_url,
390 inferred
391 );
392 return config;
393 }
394 };
395
396 // Tokens are keyed to the apex server (where the identity registered), not
397 // the tenant subdomain — strip the leading subdomain label from the host.
398 let server = match apex_server_url(remote_url) {
399 Some(s) => s,
400 None => {
401 log::debug!("Could not derive apex server URL from: {}", remote_url);
402 return config;
403 }
404 };
405

Callers 4

build_remote_configMethod · 0.85
build_remote_configMethod · 0.85
run_remoteMethod · 0.85
build_remote_configMethod · 0.85

Calls 7

get_tokenFunction · 0.85
delegation_headerFunction · 0.85
apex_server_urlFunction · 0.70
cloneMethod · 0.45
with_headerMethod · 0.45

Tested by

no test coverage detected