Commit Graph

18 Commits

Author SHA1 Message Date
brymko 9e898fa185 fix(coding-agent): cancelled stale mcp oauth reauthorization
Repeated /mcp reauth commands could remain blocked by a prior
unfinished login because each command receives a fresh controller.
Coordinate flows through session-shared state so a replacement cancels
and cleans up the old flow before proceeding.
2026-08-05 18:46:49 +08:00
can1357 63b07f8ec0 chore: rewrite changelogs 2026-08-03 05:52:53 +02:00
roboomp 4d74fabe70 test(mcp): restored OAuth env after reauth coverage
Preserved pre-existing MCP_OAUTH_CLIENT_ID and MCP_OAUTH_CLIENT_SECRET values
instead of deleting them after the env-expansion regression test, preventing
later tests in the same Bun process from observing mutated caller state.

Fixes #7440
2026-08-03 00:37:55 +00:00
roboomp c6a057073b fix(mcp): expand env vars in reauth oauth credentials and reject empty tokens
/mcp reauth read OAuth clientId/clientSecret from the raw, unexpanded config
while URL and resource used expandEnvVarsDeep, so `${VAR}` placeholders were
sent literally to the token exchange. MCPOAuthFlow.exchangeToken() also accepted
any HTTP-success body, storing an empty access token when a provider signals
failure with HTTP 200 (e.g. Slack `{ ok: false, error }`), surfacing only later
as invalid_token.

- Select flow client credentials from runtimeBaseConfig / expanded auth block;
  keep the raw placeholder for the persisted config file.
- Reject token responses without a non-empty access_token, including the
  sanitized provider error when present.
- Add regression tests for env-expanded reauth credentials and HTTP-200 token
  error bodies.

Fixes #7440
2026-08-03 00:33:36 +00:00
roboomp b8ab418dd6 test(coding-agent): update MCP reauth fake for reload deps
reloadServers() now reads ctx.settings and session.setMCPPromptCommands, which
the shared /mcp reauth|unauth harness did not provide, so those tests threw
inside reload and failed their showError assertions. Add both members to the
fake context.

Fixes #7189
2026-07-31 16:59:38 +00:00
can1357 395e5ba288 fix(coding-agent): bypass anonymous-connect guard when a tool auth challenge is present
Servers may allow the unauthenticated MCP handshake yet protect individual
tool calls via _meta["mcp/www_authenticate"]. The 'reauthorization is not
required' guard would silently abort the tool-challenge reauth path.
2026-07-23 11:37:11 +02:00
slee1996 2145ab8f8e fix(coding-agent): retry MCP tool auth challenges 2026-07-22 23:44:38 -06:00
can1357 e0c717e07f merged PR #5427: fix(tui): defer command output during streaming 2026-07-16 03:32:03 +02:00
roboomp fb98465923 fix(mcp): preserved discovered registration endpoint
Threaded the authorization server's advertised registration endpoint through OAuth discovery, add, reauth, and the client flow instead of deriving metadata from the authorization endpoint.

Added pathful-issuer discovery and end-to-end DCR regression coverage.

Fixes #5267
2026-07-14 17:46:24 +00:00
roboomp d3f4830ceb fix(tui): deferred command output during streaming
- Queued transcript command panels until the active agent turn ends.

- Added regression coverage for slash-command output mounting exactly once.

Fixes #4806
2026-07-14 16:35:18 +00:00
roboomp 3106a15f7d fix(mcp): raced oauth login against cancellation
Esc and wizard abort signals now race the MCP OAuth login promise directly, so cancellation wins even before OAuthCallbackFlow reaches its callback wait and registers an abort listener. OAuthCallbackFlow also checks pre-aborted signals before opening/waiting on the callback server and its wait path handles already-aborted signals.

Threaded the abort signal into MCP OAuth fetches so dynamic client registration, metadata discovery, authorization probes, and token exchange unblock promptly when the user cancels.

Added a regression test where MCPOAuthFlow.login never observes ctrl.signal, matching the pre-wait race called out in review.

Fixes #3888
2026-06-30 10:21:26 +00:00
roboomp 4300f46039 style: bun run fix 2026-06-30 10:08:21 +00:00
roboomp a6b2bac882 fix(mcp): made Esc cancel /mcp reauth and /mcp add OAuth flow
#handleOAuthFlow now installs an editor.onEscape hook that aborts its
AbortController, and accepts an external abortSignal so the add-wizard
can thread its own controller through (the wizard owns focus and absorbs
Esc itself). Cancellation surfaces as MCPOAuthCancelledError, which the
reauth and add catches translate into a neutral status line instead of
the generic OAuth failure banner. Disambiguated from the existing 5-min
timeout via a userCancelled flag so timeouts still read as errors.

The wizard intercepts Esc/Ctrl+C while #oauthAbort is set so its own
"Press Esc to cancel" advertisement now matches the behaviour, and
renames its error heading + tip when the failure is a user cancel. Also
fixed the misleading "(Press Ctrl+C to cancel)" message in the chat
transcript onAuth block to say "Press Esc" — Ctrl+C is bound to the
editor clear action, not interrupt.

Fixes #3888
2026-06-30 10:07:05 +00:00
can1357 74d7dfd2fa Merge PR #3354: fix: migrate coding-agent tests to removeWithRetries (@oldschoola) 2026-06-27 02:06:38 +02:00
can1357 9ffaace8bc test(coding-agent): prevented sqlite database handle leaks in tests
- Track and explicitly close in-memory SQLite database handles in MCP auth tests.
- Resolved Bun GC-related crashes occurring when parallel tests finalize dangling database handles.
2026-06-25 20:59:38 +02:00
oldschoola a2854ba768 fix: migrate coding-agent tests from fs.rm to removeWithRetries
Migrate 203 test files (356 call sites) from fs.rm/fs.rmSync to
removeWithRetries/removeSyncWithRetries to reduce EBUSY test failures
on Windows. removeWithRetries is now exported from @oh-my-pi/pi-utils.

The migration uses a regex-based approach that:
- Replaces fs.rm(path, { recursive, force }) → removeWithRetries(path)
- Replaces fs.rmSync(path, { recursive, force }) → removeSyncWithRetries(path)
- Replaces fs.rm(path) → removeWithRetries(path) (no options)
- Skips fs.rm/fs.rmSync inside template literals (bun --eval scripts)
- Adds imports to existing @oh-my-pi/pi-utils import or creates new one
- Removes unused fs imports where fs.rm was the only fs usage (4 files)
2026-06-23 15:28:05 -07:00
Ogrodev f9bc96e96c fix(coding-agent): harden profile auth shipping gaps 2026-06-14 20:30:50 -03:00
Ogrodev fc9b0a4707 fix(coding-agent): preserve mcp reauth credentials 2026-06-11 21:22:25 -03:00