Filing gate: ① a product defect, class a, reach: a public HTTP door measured once with a wrong result (in-process, on a real composition; production timing not measured).
Filed by the repo:cloud seat (repo:cloud#1, session session_01YSygzqVmrY31BnZge8KDo6, R43), from the cloud#2526 dev's measure-first report (an out-of-scope finding, class a). The producer is framework code, so it is filed here, bare; routing and grading are triage's.
Measured
On the cloud control-plane composition (cloud main 0ae69f6d, framework pin 4b4ee88f), booted in-process on both the bare-adapter and the OS_NODE_SERVE=1 paths:
- When the first request arrives before
plugin-auth has finished its async OIDC discovery mount, the mount throws Can not add a route since the matcher is already built. That is logged at ERROR and swallowed.
GET /.well-known/openid-configuration and GET /.well-known/oauth-authorization-server then answer 404 ENDPOINT_NOT_FOUND. They still do 3 s later, and for the life of the process.
- With 5 s idle before the first request, both answer
200.
NOT MEASURED: whether a production container's first request lands inside that window.
Mechanism (read at objectstack main 2821e9f15)
packages/plugins/plugin-auth/src/auth-plugin.ts :3230 is void this.registerOidcDiscoveryRoutes(rawApp, ctx).catch(...). registerOidcDiscoveryRoutes (:3244) awaits the auth instance before calling rawApp.get(...). If Hono's router has already frozen its matcher on a first request, the late get throws.
Related: cloud#2526 (where this was measured).
Generated by Claude Code
Filing gate: ① a product defect, class a,
reach:a public HTTP door measured once with a wrong result (in-process, on a real composition; production timing not measured).plugin-auth; the hint isdomain:services.search_issueson objectstack for "OIDC discovery well-known openid-configuration 404 matcher already built registerOidcDiscoveryRoutes": 4 hits, all closed and unrelated ([finding]registerDiscoveryEndpoints' auth branch strips only the retired/projects/:environmentId, so a scoped/discoveryadvertisesroutes.authstill scoped — and with an unsubstituted:environmentId#16538, runtime dispatcher's two discovery bodies (.well-known + REST-less {prefix}/discovery fallback) are the machine-read { data } class #9436 ruled on, and sit outside check-route-envelope's scan #9813, [bug] OIDC SSO registration is broken end-to-end: the bridge always sendsoidcConfig.mapping.id, which@better-auth/sso@1.7.0-rc.2rejects as an unrecognized key #8193, routes.mcp 是 REST /discovery 发出、objectui 真实消费、但 ApiRoutesSchema 从未声明的键(#4828 同族,低一层) #5679).Filed by the
repo:cloudseat (repo:cloud#1, sessionsession_01YSygzqVmrY31BnZge8KDo6, R43), from the cloud#2526 dev's measure-first report (an out-of-scope finding, class a). The producer is framework code, so it is filed here, bare; routing and grading are triage's.Measured
On the cloud control-plane composition (cloud
main0ae69f6d, framework pin4b4ee88f), booted in-process on both the bare-adapter and theOS_NODE_SERVE=1paths:plugin-authhas finished its async OIDC discovery mount, the mount throwsCan not add a route since the matcher is already built. That is logged at ERROR and swallowed.GET /.well-known/openid-configurationandGET /.well-known/oauth-authorization-serverthen answer404 ENDPOINT_NOT_FOUND. They still do 3 s later, and for the life of the process.200.NOT MEASURED: whether a production container's first request lands inside that window.
Mechanism (read at objectstack
main2821e9f15)packages/plugins/plugin-auth/src/auth-plugin.ts:3230 isvoid this.registerOidcDiscoveryRoutes(rawApp, ctx).catch(...).registerOidcDiscoveryRoutes(:3244) awaits the auth instance before callingrawApp.get(...). If Hono's router has already frozen its matcher on a first request, the lategetthrows.Related: cloud#2526 (where this was measured).
Generated by Claude Code