fix(mcp-oauth): api_keys.company_id nullable so companyless signups can mint their key (#1919)
Every fresh Claude.ai authorization died at POST /api/mcp-oauth/token with a silent 500: the multi-tenant refactor's dynamic loop (20260330130000, line ~250) set company_id NOT NULL on api_keys, and the companyless key insert from the popup-signup flow (#1814) violates it. Nothing exercised the real insert before (unit tests mock the client; no pg test inserted an unbound key), so repo, CI and prod all agreed and all were wrong. DROP NOT NULL, log the insert/rotation failures at the token endpoint, and pin the unbound insert + lazy bind on real Postgres. Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6 Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Jakob Wennberg
Claude Fable 5
parent
3e4b5ddc80
commit
b1a03de34e
@@ -167,6 +167,13 @@ async function handleAuthorizationCodeGrant(params: URLSearchParams) {
|
||||
})
|
||||
|
||||
if (insertError) {
|
||||
// This 500 was silent while api_keys.company_id was NOT NULL and every
|
||||
// companyless signup died here (2026-08-26): always log the DB error.
|
||||
console.error('[mcp-oauth/token] api key insert failed', {
|
||||
code: insertError.code,
|
||||
message: insertError.message,
|
||||
companyless: companyId === null,
|
||||
})
|
||||
return NextResponse.json(
|
||||
{ error: 'server_error', error_description: 'Failed to create API key' },
|
||||
{ status: 500 }
|
||||
@@ -214,6 +221,7 @@ async function handleRefreshTokenGrant(params: URLSearchParams) {
|
||||
})
|
||||
|
||||
if (error) {
|
||||
console.error('[mcp-oauth/token] refresh rotation failed', { code: error.code, message: error.message })
|
||||
return NextResponse.json(
|
||||
{ error: 'server_error', error_description: 'Failed to rotate refresh token' },
|
||||
{ status: 500 }
|
||||
|
||||
Reference in New Issue
Block a user