fix(apps): an App's subdomain may also be one of its own realm's domains - #241
Merged
Merged
Conversation
Reported from the test instance: every draft apply on the system realm died with Application.SubdomainTaken — "That host is already a realm domain" — whatever the draft changed. The realm lists the shelf App's host among its own plain domains as well as in ApplicationDomains. That is a legal, working state (the host routes to the realm either way; the App match takes precedence in RealmCacheLookup), but ValidateOriginAsync treated ANY realm's domain list as a collision, the own one included. Since an apply replays every declared App with its settings, that one App failed every apply on the realm. Only another realm's domain makes a host ambiguous; the own realm's list is no longer a conflict. The message says "another realm" now. The realm-domain side (CheckDomainUniquenessAsync) already excluded the realm itself. Test: own-realm domain accepted, accepted again on re-apply, route written; another realm's domain still 409. Red without the fix (the exact 409 seen in the field), green with it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Found on the test instance: every draft apply on the system realm failed with
Application.SubdomainTaken— That host is already a realm domain — whatever the draft changed.Cause
The realm lists the
shelfApp's host both among its own plainDomainsand inApplicationDomains. That is a legal, working state — the host routes to the realm either way, and the App match takes precedence inRealmCacheLookup— butApplicationSettingsService.ValidateOriginAsynctreated any realm's domain list as a collision, the own one included. Since an apply replays every declared App with its settings, that one App failed every apply on the realm. The realm-domain side (CheckDomainUniquenessAsync) had always excluded the realm itself, which is how the state could arise in the first place.Fix
Only another realm's domain makes a host ambiguous; the own realm's list is no longer a conflict. The message now reads "already a domain of another realm". Nothing else changes: another App's route and another realm's domain are refused as before, and the host still has to be a child of the realm's primary domain.
Test plan
ApplicationSettingsAdminTests.Subdomain_May_Be_A_Domain_Of_The_Own_Realm_But_Not_Of_Another— own-realm domain accepted, accepted again on the re-apply an idempotent manifest run is, route written; another realm's domain still409. Red without the fix (the exact 409 seen in the field), green with it.🤖 Generated with Claude Code