PER-16377: retire the eu region in the CLI - #149
Merged
Merged
Conversation
Permit's EU region was torn down on 2026-09-28; every EU host is gone. Drop eu as a selectable region and remove its URL mappings. A saved or passed eu (PERMIT_REGION, the keychain value, or --region eu) now fails with a clear error before any request, instead of falling back to US and sending the old EU credentials there. US URLs are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A user with eu saved in the keychain who ran `permit login` without --region got a successful login, but the keychain kept eu, so the next command failed again with the retired-region error. Login now saves us after the token on every successful login, which replaces the stale value. A keychain failure while saving it is shown as a login error instead of an unhandled rejection. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Cover the cli.tsx fail-fast path: with PERMIT_REGION=eu the CLI prints the retirement message and exits 1 before any command runs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
zeevmoney
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Permit's EU region was torn down on 2026-09-28 (PER-16073 / PER-16377). All customers are on the US region, and every EU host (api.eu, app.eu, cloudpdp and pdp-statistics under eu-central-1) is gone. This removes
eufrom the CLI.What changed
source/config.ts:PermitRegionis now just'us'and the EU URL mappings are removed. The URL getters return the same US URLs as before. Each getter checks the configured region first and throwsRetiredRegionErrorif it iseu(case-insensitive), so no URL, and so no request, can be built for it.CLOUD_PDP_URL/PERMIT_API_URL/ ... constants computed at import time are removed. Their three callers (facts API,pdp runconfig fetch,pdp stats) now use the getters. The values are the same.login:--regiononly documentsus.--region euprints the retirement message and exits 1 before the login flow starts.AuthProvider: it used to swallow everyloadRegion()failure and continue as US. Keychain read errors are still ignored, as before. A storedeunow stops with the error instead of going to the login flow or to US. This covers both the stored-token path and the--api-keypath.cli.tsx:PERMIT_REGION=euis rejected at startup, before any command runs.api_urlfromgetPermitApiUrl()and had no EU values of their own, so they need no code change. They now always emithttps://api.permit.io, or fail foreu.What users with
eusaved will seeThe CLI then exits with code 1.
permit logoutclears the stored region, as before. It is only blocked ifPERMIT_REGION=euis still set in the environment, and the message covers that case.Testing
npm run build,npm run lint(0 errors; the 8 warnings are all in files and lines this PR doesn't touch),npm run test:ts, andnpm run testall pass: 117 files, 690 tests.tests/lib/config.test.ts,client-region.test.ts,auth-oauth-region.test.ts,auth.test.ts) are replaced. They now check that every getter returns the US URL, thateuthrows in every getter, thatuseClientandbrowserAuthfail without callingcreateClientor opening the browser, and that a storedeuis rejected byloadRegion.tests/components/AuthProviderRetiredRegion.test.tsx: witheuin the keychain, both the stored-token and--api-keypaths show the error, never callfetchand exit 1, and a storedusstill reacheshttps://api.permit.io. I checked that these tests fail against the oldAuthProvider.tests/loginRetiredRegion.test.tsx:login --region eushows the error, makes no request and writes nothing to the keychain.PERMIT_REGION=eu permit env export terraform,PERMIT_REGION=eu permit logoutandpermit login --region euall print the message and exit 1.🤖 Generated with Claude Code