Skip to content

refactor(auth): remove unused POST /v1/key-data route - #21321

Open
vbudhram wants to merge 1 commit into
mainfrom
fxa-14618
Open

vbudhram wants to merge 1 commit into
mainfrom
fxa-14618

Conversation

@vbudhram

@vbudhram vbudhram commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Because

  • The legacy POST /v1/key-data route is unused. It is an old alias of POST /v1/account/scoped-key-data and uses the same keyDataHandler.
  • No FxA client calls it. We checked fxa-auth-client, fxa-settings, fxa-content-server and PyFxA.

This pull request

  • Removes the POST /v1/key-data route from key_data.js, plus two orphaned imports.
  • Removes the KEY_DATA_POST swagger entry and its overview link from oauth-server-api.ts.
  • Removes the POST /key-data test block and the orphaned BAD_CLIENT_ID const from oauth_api.in.spec.ts.
  • Does not change POST /v1/account/scoped-key-data or keyDataHandler.

Issue that this pull request solves

Closes: https://mozilla-hub.atlassian.net/browse/FXA-14618

Checklist

Put an x in the boxes that apply

  • My commit is GPG signed.
  • If applicable, I have modified or added tests which pass locally.
  • I have added necessary documentation (if appropriate).
  • I have verified that my changes render correctly in RTL (if appropriate).
  • I have manually reviewed all AI generated code.

How to review (Optional)

  • Key files/areas to focus on: key_data.js
  • Suggested review order: key_data.js, oauth-server-api.ts, oauth_api.in.spec.ts
  • Risky or complex parts: This PR removes a public endpoint. A client that calls POST /v1/key-data now gets a 404.

Screenshots (Optional)

Other information (Optional)

Local checks:

  • npx jest lib/routes/oauth/index.spec.ts: 8 passed, 0 failed. This covers /account/scoped-key-data.
  • npx nx lint fxa-auth-server: exit 0. tsc shows no errors in the changed files. git grep finds no remaining references.
  • We did not run the remote *.in.spec.ts tests or the functional tests locally. CI runs them.

Follow-ups, out of scope:

  • The deleted test block held the only tests for some keyDataHandler branches: multiple scopes, unknown client, disallowed scopes, and the fxa-keysChangedAt / fxa-generation fallback. A follow-up can move these tests to /account/scoped-key-data.

Copilot AI lite review requested due to automatic review settings September 25, 2026 18:33
@vbudhram
vbudhram requested a review from a team as a code owner September 25, 2026 18:33
@vbudhram vbudhram added the auto label Sep 25, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Restore coverage for the active handler’s key behavior before removing the existing integration tests.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Removes the unused legacy POST /v1/key-data endpoint while preserving /v1/account/scoped-key-data.

Changes:

  • Removes the legacy route and unused imports.
  • Removes its Swagger documentation.
  • Removes obsolete tests and the unused client constant.
  • Handler behavior coverage should be moved to the replacement route before approval.
File Summary
packages/​fxa-auth-server/​test/​remote/​oauth_api.in.spec.ts Removes legacy endpoint tests and constant; existing handler behavior coverage must be adapted to the replacement route.
packages/​fxa-auth-server/​lib/​routes/​oauth/​key_data.js Removes the legacy route.
packages/​fxa-auth-server/​docs/​swagger/​oauth-server-api.ts Removes legacy endpoint documentation.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/fxa-auth-server/test/remote/oauth_api.in.spec.ts
## Because

- `POST /v1/key-data` is a legacy alias of `POST /v1/account/scoped-key-data`. Both routes run the same `keyDataHandler`.
- No FxA client calls `/v1/key-data`. We checked fxa-auth-client, fxa-settings, fxa-content-server and PyFxA.

## This pull request

- Removes the `POST /v1/key-data` route and two orphaned imports from `key_data.js`. `POST /v1/account/scoped-key-data` and `keyDataHandler` do not change.
- Removes the `KEY_DATA_POST` swagger entry and its overview link from `oauth-server-api.ts`.
- Moves the `POST /key-data` integration tests in `oauth_api.in.spec.ts` to `POST /account/scoped-key-data`. They use session-token credentials. The bad-assertion case is now an invalid-session-token case, because the route does not accept `assertion`.
- Sets `oauth.secretKey` in `test/lib/server.ts`, so that the in-process oauth server can verify the assertions that the route signs.

## Issue that this pull request solves

Closes: https://mozilla-hub.atlassian.net/browse/FXA-14618
Copilot AI review requested due to automatic review settings September 25, 2026 18:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Removing a public endpoint warrants final human review.

Review effort: Lite
Findings: None

Resolved since last review (1)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants