Skip to content

fix(api): remove legacy API keys and the api-keys table - #374

Open
alukach wants to merge 1 commit into
mainfrom
chore/remove-api-keys
Open

alukach wants to merge 1 commit into
mainfrom
chore/remove-api-keys

Conversation

@alukach

@alukach alukach commented Jun 19, 2026 •

Copy link
Copy Markdown
Contributor

What I'm changing

The legacy API keys in the api-keys table grant no access. The data proxy stopped accepting them in source-cooperative/data.source.coop#116, and this API has accepted only the proxy's signed tokens and session cookies since #283. The six routes that still touch the table only do harm: two POSTs mint new plaintext secrets, GET /api-keys/{access_key_id}/auth hands a key's plaintext secret to an admin, and DELETE /api-keys/{access_key_id} deletes nothing while answering "API key deleted successfully".

This PR removes the subsystem outright:

  • Routes (under /api/v1): POST/GET /accounts/{account_id}/api-keys, POST/GET /products/{account_id}/{repository_id}/api-keys, GET /api-keys/{access_key_id}/auth and DELETE /api-keys/{access_key_id}. All now 404.
  • Code: the APIKey, APIKeyRequest and RedactedAPIKey schemas, the apiKeysTable client, generateAccessKeyID/generateSecretAccessKey (all of src/lib/actions/crypto.ts, which nothing else calls), the api_key:get|create|revoke and account:listAPIKeys/repository:listAPIKeys authz actions with their checks and tests, and the api-key mocks in the product route tests.
  • OpenAPI: the ApiKeyAuth security scheme, which described the <access-key-id> <secret-access-key> header this API stopped accepting in feat: OIDC auth #283. No replacement scheme is added here.
  • Infrastructure: the api-keys table in DatabaseConstruct and its Vercel grant in api-stack.ts, its creation in scripts/init-local.ts, and fixtures/api-keys.json.

Untouched: ORY_PROJECT_API_KEY and the proxy's Ory adminApiKey, which are unrelated, and the service-account API keys (service-account-keys table) from #567/#580. No UI ever managed legacy keys, so there is no UI or Storybook change.

Decisions to flag

No deprecation window. #582 proposed one release of Deprecation/Sunset headers on the list routes and a working DELETE. This PR goes straight to removal instead: the keys authorize nothing, so the only clients the window protects are scripts listing keys that do nothing. Merging this supersedes #582.

What happens to the table on deploy. api-stack.ts gives production RemovalPolicy.RETAIN, so dropping the table from CDK leaves the prod api-keys table in place, no longer managed by the stack, plaintext secrets included. Dev and staging use DESTROY, so their tables are deleted on the next deploy. Once this ships, the prod table still needs auditing and then deleting out of band (see Follow-ups).

fix, not chore. release-please leaves chore out of the changelog, and the release notes are where removing public routes gets announced.

How you can test it

What I ran on this branch, rebased onto main at 5c35162:

  • npm run type-check: clean.
  • npx jest --forceExit: 83 suites, 873 tests pass.
  • npm run lint: warnings only, none on lines this PR touches.
  • A grep for api-keys, apiKeysTable, api_key:, listAPIKeys, APIKeySchema, ApiKeyAuth and the crypto helpers across src, scripts, deploy and fixtures finds nothing left. The remaining secret_access_key hits are data-connection credentials.

Not run: npm run build (it needs AWS credentials), cdk diff, and nothing against a preview or staging. Expected cdk diff against prod: the api-keys table resource and its grant on the Vercel role disappear, with the table retained.

By hand on the preview: (await fetch("/api/v1/accounts/<you>/api-keys")).status gives 404.

Docs and ADRs

  • docs.source.coop: a search of the repo finds no page describing legacy keys; docs/using-source/data-upload.md covers STS session credentials only. Nothing is invalidated.
  • data.source.coop ADRs: ADR-013's context note says the api-keys endpoints that "exist in source.coop today" are legacy, unrelated to its design, and not accepted by the proxy (ADR-001). Once this merges, "today" is out of date, but the note still records the context correctly and no decision moves, so no ADR changes.
  • Out of date once the prod table is deleted: the org profile README (profile/README.md in source-cooperative/.github) lists api-keys: Stores API keys for authentication.

Follow-ups

  1. Audit the retained prod api-keys rows, then delete the table out of band (point-in-time recovery keeps it restorable for its retention window).
  2. Drop api-keys from the org profile README's table list.

Related

Closes the route and table work in #549; part of #491. Supersedes #582.

🤖 Generated with Claude Code

@vercel

vercel Bot commented Jun 19, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
source-coop-ui Ready Ready Preview Oct 2, 2026 6:40pm UTC
source-cooperative Ready Ready Preview Oct 2, 2026 6:40pm UTC

Request Review

@claude

claude Bot commented Jun 19, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @alukach's task in 20s —— View job


✅ No blocking issues — safe to merge.

The removal is clean. I grepped src, scripts, deploy, fixtures and the docs for the deleted modules (types/api-key, database/api-keys, actions/crypto, apiKeysTable, APIKey) and found no dangling references. The Actions enum, overloads, ActionResourceMap, match arms and the OpenAPI scheme are all removed consistently. I did not run the type-check or tests. The PR description reports npm run type-check clean and 320/321 Jest passing.

Non-blocking notes:

  • Deploy: the api-keys table was created with removalPolicy (deploy/lib/database-construct.ts). The default is DESTROY, so if prod uses RETAIN the table stays orphaned in AWS. Under DESTROY the next deploy deletes the table and its data. Confirm nothing, such as the data proxy, still reads that table before this ships.
  • Deleted src/lib/actions/crypto.ts: it was only used for key generation, so that is fine. It is missing from the PR description's "Removed" list.
  • Left in place on purpose: src/lib/accounts/service-account-keys.ts and the service-accounts/*ApiKey* components are the new service-account credential flow, not the legacy access_key_id model. The description doesn't say so, but they are out of scope here.

Docs

  • The description does not mention docs.source.coop or the data.source.coop adrs/. This PR removes the legacy API-key auth endpoints (/api/v1/api-keys/..., account and repo key create/list) and the ApiKeyAuth OpenAPI scheme. That is the "API keys" area CLAUDE.md names as an ADR topic, and it may date a page in docs/using-source/.
  • The description should name the ADR or doc it checked and say why it still holds, or link the PR that updates it. Without that, silence reads the same as forgotten.

Simplify (ponytail)

  • Nothing to cut. This PR is a pure deletion.

💰 Estimated review cost: $0.16 · 0m20s · 6 turns

@alukach

alukach commented Jul 1, 2026

Copy link
Copy Markdown
Contributor Author

I recommend we NOT merge this into #316

The API key access model (access_key_id / secret_access_key auth) is no
longer used — the API now authenticates via the data proxy's OIDC bearer
tokens. Remove the feature and all related tooling:

- Delete the `api-keys` DynamoDB table (CDK construct + local init script)
- Delete the APIKey type/schema, database client, and fixtures
- Delete the API key endpoints (account-, product-, and key-scoped)
- Drop the api_key:* and *:listAPIKeys authz actions, overloads, and checks
- Remove the ApiKeyAuth OpenAPI security scheme
- Strip api-key mocks/tests from authz and product route tests

Unrelated Ory keys (ORY_PROJECT_API_KEY, proxy adminApiKey) are untouched.
@alukach
alukach force-pushed the chore/remove-api-keys branch from d586252 to 5c35162 Compare October 2, 2026 18:38
@alukach alukach changed the title chore: remove legacy API key data and tooling fix(api): remove legacy API keys and the api-keys table Oct 2, 2026
@alukach
alukach marked this pull request as ready for review October 2, 2026 18:39
@source-release-bot source-release-bot Bot added fix and removed chore labels Oct 2, 2026

This branch was successfully deployed

3 active (1 outdated) deployments
Preview – source-cooperative — 5c351623 Deployed Oct 2, 2026 by vercel[bot]
Preview – source-coop-ui — 5c351623 Deployed Oct 2, 2026 by vercel[bot]
Preview — d5862523 Deployed Jun 20, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant