Skip to content

fix(accounts): report managed OAuth failures accurately - #8552

Merged
waleedlatif1 merged 1 commit into
stagingfrom
codex/managed-oauth-completion
Oct 2, 2026
Merged

waleedlatif1 merged 1 commit into
stagingfrom
codex/managed-oauth-completion

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • Distinguish managed MCP consent cancellation from authorization failures and provider outages; log only recognized OAuth error codes.
  • Settle expired or invalid managed OAuth popups using the exact attempt nonce while preserving the existing success channel and authorization checks.

Type of Change

  • Bug fix

Testing

  • 1,011 focused account, credential, MCP, callback, and popup regressions passed.
  • New regression cases failed before the fix; independent guard-removal controls verified classification, correlation, and diagnostic redaction.
  • Actual callback HTML and popup code communicate over real BroadcastChannel in the protocol tests.
  • 27 real Postgres/Redis integration tests, app type-check, lint, all 54 audits, generators, registry and docs parity checks.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 2, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 2, 2026 12:23am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Improves OAuth error reporting in managed account connections.

The PR appears safe to merge; no actionable issue was identified in the changed behavior.

Summary

The PR distinguishes managed MCP consent cancellation, authorization failures, and provider outages while limiting logged provider error codes. It also lets an expired managed OAuth callback notify the initiating popup by its attempt nonce.

  • Adds callback and popup regression coverage for failure classification and nonce correlation.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Managed OAuth callback] --> B{Stored attempt available?}
  B -- No --> C[Broadcast invalid_state with nonce]
  C --> D[Matching popup reports expired attempt]
  B -- Yes --> E{Provider error?}
  E -- Yes --> F[Classify error and redirect to completion]
  E -- No --> G[Complete authorization]
Loading

Reviews (1) · Last reviewed commit: "fix(accounts): report managed OAuth fail..."

@waleedlatif1
waleedlatif1 merged commit 31503c5 into staging Oct 2, 2026
24 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/managed-oauth-completion branch October 2, 2026 00:29

This branch was previously deployed

1 inactive deployment
Preview — d17ff652 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant