fix(kiro): route IdC auth to regional CodeWhisperer surface (#2297)
IAM Identity Center (authMethod=idc) tokens failed every request with 403 "bearer token invalid". Treat idc like api_key/external_idp: - executors/kiro.js: route idc to *.amazonaws.com CodeWhisperer surface, region-aware from credentials.region instead of hardcoded us-east-1. - openai-to-kiro.js / claude-to-kiro.js: send resolved profileArn or empty for idc/external_idp, never the shared builder-id placeholder ARN. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
committed by
decolua
parent
9102c4c6d8
commit
abc0add031
@@ -393,9 +393,12 @@ export function claudeToKiroRequest(model, body, stream, credentials) {
|
||||
reconcileOrphanedToolResults(history, currentMessage);
|
||||
}
|
||||
|
||||
// API-key auth must never use the shared default ARN (403); OAuth/social fall back to it.
|
||||
// api_key / idc / external_idp must never use the shared default ARN (belongs
|
||||
// to another account → 403 "bearer token invalid"); OAuth/social fall back to it.
|
||||
const authMethod = credentials?.providerSpecificData?.authMethod;
|
||||
const profileArn = authMethod === "api_key"
|
||||
const accountBoundAuth =
|
||||
authMethod === "api_key" || authMethod === "idc" || authMethod === "external_idp";
|
||||
const profileArn = accountBoundAuth
|
||||
? (credentials?.providerSpecificData?.profileArn || "")
|
||||
: (credentials?.providerSpecificData?.profileArn || resolveDefaultProfileArn(authMethod));
|
||||
|
||||
|
||||
Reference in New Issue
Block a user