refactor(api-keys): single dashboard-only create path with explicit roles - #2182
multipletwigs wants to merge 3 commits into
Conversation
|
32268e2 to
c9a8742
Compare
c9a8742 to
59d38db
Compare
59d38db to
5b02ecb
Compare
5b02ecb to
de2e1ac
Compare
…oles Delete POST/GET /v1/projects/:projectId/api-keys and route all key creation through POST /v1/api-keys, which now requires a signed-in user plus x-project-id; API keys can no longer mint API keys. Role is required (zod default and column default removed), a permissions override may only narrow the role preset, and the wallet-provisioning fields are gone from the create body. created_by is always the acting user. Docs and generated reference updated.
Register POST /v1/api-keys in the internal document only, since the public document defines no clerkBearerAuth scheme, and regenerate the Postman collection and llms-full.txt. Expiration examples move to a future date. The role DROP DEFAULT migration moves to its own migrations-only PR so this change stays rollback-safe.
de2e1ac to
566ceb7
Compare
Key creation is Clerk-only now, so tests mint keys through a signed-in admin with x-project-id and an explicit role. Integration tests get a signInTestUser helper. Cases for the deleted project route, create-time wallet provisioning, and key-mints-key guards are removed.
|
On the remaining risk ("existing keys remain active" and the legacy-update gap): #2198, stacked on top of this PR, revokes every existing API key ( |
Stacked on #2197 (drops the
api_keys.rolecolumn default); #2198 on top revokes every existing key. Consolidates API-key creation onto one dashboard-only path.POST /v1/api-keysrequires a signed-in user plusx-project-id;/v1/projects/:projectId/api-keysis deleted.created_byis always the acting user.requireUserActorruns beforerequirePermissionson create, so any key gets 403.roleis required: zod default removed; the column default drop ships in fix(api): drop the api_keys.role column default #2197.permissionsoverride may only narrow the role preset, checked before the org:admin exemption and shared by create, update, and rotate. fix(api): revoke every existing API key #2198 revokes every key minted before this lands.provisionWallet/walletLabel/walletPurposeremoved from create; create the wallet via custody, then bind it.API before/after (local, key actor; before values reconstructed):
Verification:
@sdp/api+sdp-webtypecheck pass; local dashboard create flow walked end to end (wizard → generated key →api_keysandaudit_logsrows); adversarial pass over 8 vectors with live probes, 0 exploitable. Not run: vitest. CI is red on six stale suites that still exercise the deleted route and key-mints-key paths; a follow-up test PR rewrites them.