fix(mcp-oauth): api_keys.company_id nullable so companyless signups can mint their key (#1919)

Every fresh Claude.ai authorization died at POST /api/mcp-oauth/token
with a silent 500: the multi-tenant refactor's dynamic loop
(20260330130000, line ~250) set company_id NOT NULL on api_keys, and the
companyless key insert from the popup-signup flow (#1814) violates it.
Nothing exercised the real insert before (unit tests mock the client;
no pg test inserted an unbound key), so repo, CI and prod all agreed and
all were wrong. DROP NOT NULL, log the insert/rotation failures at the
token endpoint, and pin the unbound insert + lazy bind on real Postgres.


Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-08-26 09:58:25 +02:00
committed by GitHub
co-authored by Jakob Wennberg Claude Fable 5
parent 3e4b5ddc80
commit b1a03de34e
3 changed files with 65 additions and 0 deletions
+8
View File
@@ -167,6 +167,13 @@ async function handleAuthorizationCodeGrant(params: URLSearchParams) {
})
if (insertError) {
// This 500 was silent while api_keys.company_id was NOT NULL and every
// companyless signup died here (2026-08-26): always log the DB error.
console.error('[mcp-oauth/token] api key insert failed', {
code: insertError.code,
message: insertError.message,
companyless: companyId === null,
})
return NextResponse.json(
{ error: 'server_error', error_description: 'Failed to create API key' },
{ status: 500 }
@@ -214,6 +221,7 @@ async function handleRefreshTokenGrant(params: URLSearchParams) {
})
if (error) {
console.error('[mcp-oauth/token] refresh rotation failed', { code: error.code, message: error.message })
return NextResponse.json(
{ error: 'server_error', error_description: 'Failed to rotate refresh token' },
{ status: 500 }