Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
|
Claude finished @alukach's task in 20s —— View job ✅ No blocking issues — safe to merge. The removal is clean. I grepped Non-blocking notes:
Docs
Simplify (ponytail)
💰 Estimated review cost: $0.16 · 0m20s · 6 turns |
Contributor
Author
|
I recommend we NOT merge this into #316 |
The API key access model (access_key_id / secret_access_key auth) is no longer used — the API now authenticates via the data proxy's OIDC bearer tokens. Remove the feature and all related tooling: - Delete the `api-keys` DynamoDB table (CDK construct + local init script) - Delete the APIKey type/schema, database client, and fixtures - Delete the API key endpoints (account-, product-, and key-scoped) - Drop the api_key:* and *:listAPIKeys authz actions, overloads, and checks - Remove the ApiKeyAuth OpenAPI security scheme - Strip api-key mocks/tests from authz and product route tests Unrelated Ory keys (ORY_PROJECT_API_KEY, proxy adminApiKey) are untouched.
alukach
force-pushed
the
chore/remove-api-keys
branch
from
October 2, 2026 18:38
d586252 to
5c35162
Compare
alukach
marked this pull request as ready for review
October 2, 2026 18:39
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What I'm changing
The legacy API keys in the
api-keystable grant no access. The data proxy stopped accepting them in source-cooperative/data.source.coop#116, and this API has accepted only the proxy's signed tokens and session cookies since #283. The six routes that still touch the table only do harm: two POSTs mint new plaintext secrets,GET /api-keys/{access_key_id}/authhands a key's plaintext secret to an admin, andDELETE /api-keys/{access_key_id}deletes nothing while answering "API key deleted successfully".This PR removes the subsystem outright:
/api/v1):POST/GET /accounts/{account_id}/api-keys,POST/GET /products/{account_id}/{repository_id}/api-keys,GET /api-keys/{access_key_id}/authandDELETE /api-keys/{access_key_id}. All now 404.APIKey,APIKeyRequestandRedactedAPIKeyschemas, theapiKeysTableclient,generateAccessKeyID/generateSecretAccessKey(all ofsrc/lib/actions/crypto.ts, which nothing else calls), theapi_key:get|create|revokeandaccount:listAPIKeys/repository:listAPIKeysauthz actions with their checks and tests, and the api-key mocks in the product route tests.ApiKeyAuthsecurity scheme, which described the<access-key-id> <secret-access-key>header this API stopped accepting in feat: OIDC auth #283. No replacement scheme is added here.api-keystable inDatabaseConstructand its Vercel grant inapi-stack.ts, its creation inscripts/init-local.ts, andfixtures/api-keys.json.Untouched:
ORY_PROJECT_API_KEYand the proxy's OryadminApiKey, which are unrelated, and the service-account API keys (service-account-keystable) from #567/#580. No UI ever managed legacy keys, so there is no UI or Storybook change.Decisions to flag
No deprecation window. #582 proposed one release of
Deprecation/Sunsetheaders on the list routes and a working DELETE. This PR goes straight to removal instead: the keys authorize nothing, so the only clients the window protects are scripts listing keys that do nothing. Merging this supersedes #582.What happens to the table on deploy.
api-stack.tsgives productionRemovalPolicy.RETAIN, so dropping the table from CDK leaves the prodapi-keystable in place, no longer managed by the stack, plaintext secrets included. Dev and staging useDESTROY, so their tables are deleted on the next deploy. Once this ships, the prod table still needs auditing and then deleting out of band (see Follow-ups).fix, notchore. release-please leaveschoreout of the changelog, and the release notes are where removing public routes gets announced.How you can test it
What I ran on this branch, rebased onto
mainat 5c35162:npm run type-check: clean.npx jest --forceExit: 83 suites, 873 tests pass.npm run lint: warnings only, none on lines this PR touches.api-keys,apiKeysTable,api_key:,listAPIKeys,APIKeySchema,ApiKeyAuthand the crypto helpers acrosssrc,scripts,deployandfixturesfinds nothing left. The remainingsecret_access_keyhits are data-connection credentials.Not run:
npm run build(it needs AWS credentials),cdk diff, and nothing against a preview or staging. Expectedcdk diffagainst prod: theapi-keystable resource and its grant on the Vercel role disappear, with the table retained.By hand on the preview:
(await fetch("/api/v1/accounts/<you>/api-keys")).statusgives 404.Docs and ADRs
docs/using-source/data-upload.mdcovers STS session credentials only. Nothing is invalidated.api-keysendpoints that "exist insource.cooptoday" are legacy, unrelated to its design, and not accepted by the proxy (ADR-001). Once this merges, "today" is out of date, but the note still records the context correctly and no decision moves, so no ADR changes.profile/README.mdinsource-cooperative/.github) listsapi-keys: Stores API keys for authentication.Follow-ups
api-keysrows, then delete the table out of band (point-in-time recovery keeps it restorable for its retention window).api-keysfrom the org profile README's table list.Related
Closes the route and table work in #549; part of #491. Supersedes #582.
🤖 Generated with Claude Code