Skip to content

fix(apps): an App's subdomain may also be one of its own realm's domains - #241

Merged
windischb merged 1 commit into
developfrom
fix/app-origin-own-realm-domain
Sep 23, 2026
Merged

windischb merged 1 commit into
developfrom
fix/app-origin-own-realm-domain

Conversation

@windischb

Copy link
Copy Markdown
Contributor

Summary

Found on the test instance: every draft apply on the system realm failed with Application.SubdomainTaken — That host is already a realm domain — whatever the draft changed.

Cause

The realm lists the shelf App's host both among its own plain Domains and in ApplicationDomains. That is a legal, working state — the host routes to the realm either way, and the App match takes precedence in RealmCacheLookup — but ApplicationSettingsService.ValidateOriginAsync treated any realm's domain list as a collision, the own one included. Since an apply replays every declared App with its settings, that one App failed every apply on the realm. The realm-domain side (CheckDomainUniquenessAsync) had always excluded the realm itself, which is how the state could arise in the first place.

Fix

Only another realm's domain makes a host ambiguous; the own realm's list is no longer a conflict. The message now reads "already a domain of another realm". Nothing else changes: another App's route and another realm's domain are refused as before, and the host still has to be a child of the realm's primary domain.

Test plan

  • ApplicationSettingsAdminTests.Subdomain_May_Be_A_Domain_Of_The_Own_Realm_But_Not_Of_Another — own-realm domain accepted, accepted again on the re-apply an idempotent manifest run is, route written; another realm's domain still 409. Red without the fix (the exact 409 seen in the field), green with it.
  • App-settings, manifest, provisioning and realm integration classes (166) + unit suite (1739) green
  • CI on this PR

🤖 Generated with Claude Code

Reported from the test instance: every draft apply on the system realm died
with Application.SubdomainTaken — "That host is already a realm domain" —
whatever the draft changed. The realm lists the shelf App's host among its own
plain domains as well as in ApplicationDomains. That is a legal, working state
(the host routes to the realm either way; the App match takes precedence in
RealmCacheLookup), but ValidateOriginAsync treated ANY realm's domain list as
a collision, the own one included. Since an apply replays every declared App
with its settings, that one App failed every apply on the realm.

Only another realm's domain makes a host ambiguous; the own realm's list is
no longer a conflict. The message says "another realm" now. The realm-domain
side (CheckDomainUniquenessAsync) already excluded the realm itself.

Test: own-realm domain accepted, accepted again on re-apply, route written;
another realm's domain still 409. Red without the fix (the exact 409 seen in
the field), green with it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@windischb
windischb merged commit 5aa1ff3 into develop Sep 23, 2026
8 checks passed
@windischb
windischb deleted the fix/app-origin-own-realm-domain branch September 23, 2026 13:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant