fix(workspaces): derive dashboard API host from PORTAL_API_URL - #6
Merged
Merged
Conversation
Older portal deployments inject the bare core domain or the plugin's own subdomain as PORTAL_API_URL, but the workspace-init key-exchange routes (POST /api/auth/key) exist only behind the dashboard API's host router, so the exchange fails with 405 and first-boot automatic install is skipped. workspace-init now rewrites such URLs onto account.<core domain> before exchanging, preserving scheme, port, and path. Hosts already rooted at the dashboard subdomain, IPs, and dotless dev hosts pass through unchanged.
Kody Review CompleteGreat news! 🎉 Keep up the excellent work! 🚀 Kody Guide: Usage and ConfigurationInteracting with Kody
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
pcfreak30
marked this pull request as ready for review
September 20, 2026 10:15
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Older portal deployments inject the bare core domain or the plugin's own subdomain as
PORTAL_API_URL, but the workspace-init key-exchange routes (POST /api/auth/key) exist only behind the dashboard API's host router, so the exchange fails with 405 and first-boot automatic install is skipped.workspace-initnow rewrites such URLs ontoaccount.<core domain>before exchanging, preserving scheme, port, and path. Hosts already rooted at the dashboard subdomain, IPs, and dotless dev hosts pass through unchanged.Summary
This PR fixes automatic WordPress workspace installation when older portal deployments inject a
PORTAL_API_URLthat points at the bare core domain (e.g.https://pinner.xyz) or the plugin’s own subdomain (e.g.https://ipfs.pinner.xyz). The key-exchange routes used during install only exist on the dashboard API host (account.<core domain>), so requests to the other hosts would fail with 405 and skip automatic install.What changed
deriveDashboardAPIURL, which normalizes the injectedPORTAL_API_URLso it always targets the dashboard API host:https://pinner.xyz→https://account.pinner.xyzhttps://ipfs.pinner.xyz→https://account.pinner.xyzaccount.<core domain>pass through unchangedlocalhost,127.0.0.1) pass through unchangedfetchEmailbefore the API client is used.Impact
Ensures the WordPress workspace-init flow reliably reaches the correct API host for email lookup regardless of which
PORTAL_API_URLform is injected by older portal deployments, restoring automatic installation behavior for those environments.