Skip to content

Fix/multi tenant auth - #136

Open
SVLaursen wants to merge 4 commits into
mainfrom
fix/multi-tenant-auth
Open

SVLaursen wants to merge 4 commits into
mainfrom
fix/multi-tenant-auth

Conversation

@SVLaursen

Copy link
Copy Markdown
Collaborator

Summary

Based on PR #125 by @agustino-lim

In addition to the multi-tenant related changes provided in the aforementioned PR, a subdomain clean process has been added that verifies the subdomain url against app domain knowledge retrieved from VCAP_APPLICATION information in the CloudFoundry runtime.

This fix will NOT work for Kyma runtimes to my knowledge.

Type of Change

  • 🚀 Feature - New functionality or enhancement
  • 🐛 Bug Fix - Non-breaking change that fixes an issue
  • 🚨 Hotfix - Critical fix for production issue
  • 🔧 Chore - Maintenance, refactoring, or tooling changes
  • 📚 Documentation - Documentation updates only
  • ⚡ Performance - Performance improvements
  • 🎨 Style - Code style/formatting changes

Related Issues

What Changed

  • Change 1
  • Change 2
  • Change 3

Testing

  • Unit tests pass
  • Integration tests pass
  • Manual testing completed
  • No new warnings/errors

Impact

  • Breaking changes (migration guide in description)
  • API changes (documented below)
  • Performance impact (benchmarks provided)
  • Security implications (review requested)
  • Documentation updated

Review Focus

  • Code quality and architecture
  • Test coverage and quality
  • Performance and security
  • Documentation accuracy
  • Breaking change handling

Additional Context


agustino-lim and others added 4 commits February 10, 2026 12:19
…ents

In multi-tenant BTP deployments, OAuth metadata and token exchanges were resolved
against provider-level XSUAA endpoints, causing tokens to be issued for the wrong
tenant. This change derives the subscriber-specific XSUAA URLs from the request
host so that OAuth flows run in the correct tenant context.
Resolved conflict in src/auth/utils.ts by accepting main branch version
that keeps the OAuth protected resource endpoint disabled as a hotfix.

The endpoint causes authentication failures because MCP clients don't
send application/json in Accept headers, causing XSUAA to return HTML.

This follows the KISS principle: keep the safe, documented hotfix until
proper investigation and testing can be completed.

Co-authored-by: Cursor <cursoragent@cursor.com>
- Replace generic SecurityContext<any, any> with XsuaaSecurityContext
- Remove hardcoded uaadomain fallback, now throws error if missing
@SVLaursen SVLaursen self-assigned this Mar 5, 2026
@SVLaursen

Copy link
Copy Markdown
Collaborator Author

@geert-janklaps if you have some time, can you check if this PR resolves the issues you reported on #125? 😄

@agustino-lim

Copy link
Copy Markdown
Contributor

@SVLaursen ,

Thanks for looking into the issues and helping move this forward. I’ve been quite busy recently, so I really appreciate you taking over the PR.

For context, I tested this in our environment with multi-tenancy on Cloud Foundry only. I haven’t tested it on Kyma yet

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OAuth Token Exchange Uses Provider URL Instead of Subscriber-Specific XSUAA URL in Multi-Tenant Deployments

2 participants