Skip to content

fix(workspaces): derive dashboard API host from PORTAL_API_URL - #6

Merged
pcfreak30 merged 1 commit into
developfrom
fix/derive-dashboard-api-url
Sep 20, 2026
Merged

pcfreak30 merged 1 commit into
developfrom
fix/derive-dashboard-api-url

Conversation

@pcfreak30

@pcfreak30 pcfreak30 commented Sep 20, 2026 •

Copy link
Copy Markdown
Member

Older portal deployments inject the bare core domain or the plugin's own subdomain as PORTAL_API_URL, but the workspace-init key-exchange routes (POST /api/auth/key) exist only behind the dashboard API's host router, so the exchange fails with 405 and first-boot automatic install is skipped.

workspace-init now rewrites such URLs onto account.<core domain> before exchanging, preserving scheme, port, and path. Hosts already rooted at the dashboard subdomain, IPs, and dotless dev hosts pass through unchanged.


Summary

This PR fixes automatic WordPress workspace installation when older portal deployments inject a PORTAL_API_URL that points at the bare core domain (e.g. https://pinner.xyz) or the plugin’s own subdomain (e.g. https://ipfs.pinner.xyz). The key-exchange routes used during install only exist on the dashboard API host (account.<core domain>), so requests to the other hosts would fail with 405 and skip automatic install.

What changed

  • Added deriveDashboardAPIURL, which normalizes the injected PORTAL_API_URL so it always targets the dashboard API host:
    • https://pinner.xyz → https://account.pinner.xyz
    • https://ipfs.pinner.xyz → https://account.pinner.xyz
    • Hosts already at account.<core domain> pass through unchanged
    • Loopback/IP/dotless dev targets (localhost, 127.0.0.1) pass through unchanged
    • Scheme, port, and path are preserved
    • Unparseable URLs are returned as-is so the failure surfaces with full context from the client
  • Applied this normalization in fetchEmail before the API client is used.
  • Added unit tests covering apex domains, plugin subdomains, already-dashboard hosts, ports, case normalization, localhost/IP passthrough, preserved paths, and invalid URLs.

Impact

Ensures the WordPress workspace-init flow reliably reaches the correct API host for email lookup regardless of which PORTAL_API_URL form is injected by older portal deployments, restoring automatic installation behavior for those environments.

Older portal deployments inject the bare core domain or the plugin's own
subdomain as PORTAL_API_URL, but the workspace-init key-exchange routes
(POST /api/auth/key) exist only behind the dashboard API's host router,
so the exchange fails with 405 and first-boot automatic install is
skipped.

workspace-init now rewrites such URLs onto account.<core domain> before
exchanging, preserving scheme, port, and path. Hosts already rooted at
the dashboard subdomain, IPs, and dotless dev hosts pass through
unchanged.
@kody-ai

kody-ai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Kody Review Complete

Great news! 🎉
No issues were found that match your current review configurations.

Keep up the excellent work! 🚀

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the @kody start-review command at the root of your PR.

  • Validate Business Logic: Ask Kody to validate your code against business rules by adding a comment with the @kody -v business-logic command.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

​

@pcfreak30
pcfreak30 marked this pull request as ready for review September 20, 2026 10:15
@pcfreak30
pcfreak30 merged commit fbea2c7 into develop Sep 20, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant