fix(binjovi): one owner for the Claude MCP client #711
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/retire-duplicate-claude-registrar"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Ships with
sean/ory#120. Reverts the registrar added in #699.Two owners, one scope apart
This repository registered
binjovi-claude-code, and so doessean/ory:repository.createsean/orymanifests/stack/binjovi-mcp-claude-client.yamlclaude-code-oauth.yaml(#699)Whichever synced last won, so the scope came and went. The live client was
diffed against this registrar to confirm it: exactly one scope missing, every
other field identical.
The symptom was an MCP
create_repositorycall refused with a bareforbiddenwhile the control plane's
BINJOVI_MCP_POLICYplainly granted it — authorizationis the intersection of the policy binding and the token's
scopeclaim, andory kept winning the scope.
Why removed rather than repaired
Binjovi names the owner itself:
(
Binjovi.MCPOAuth.Protocol,@managed_clients). Matching the two scope stringswould leave two writers that must be kept in step by hand — the same shape as the
ForgejoRepositoryduplication this fleet has been removing.sean/ory#120 addsthe scope where it belongs.
The Job orphans safely
The
binjoviKustomization isprune: false, so removing the file leavesbinjovi-claude-code-oauth-v1in the cluster.ttlSecondsAfterFinished: 86400reaps it within a day, and with nothing declaring it Flux does not recreate it —
the daily re-converge loop that
tests/job-ttl-contract.shdocuments runs downinstead of round. No tombstone needed.
Guard
The public-client assertions are replaced by one refutation — no manifest in this
component may register this
client_id:Confirmed by reinstating the deleted file: the guard fails.
tests/check.shgreen, 108 guards.
https://claude.ai/code/session_01JGe4pyhQ36AhgDfPJry4d3