721f6d4a08
Codex review flagged that advertising `launchUrl` (http://localhost:<omp-port>/launch) as the visible `Copy URL:` breaks SSH/WSL/headless users: their local browser resolves the URL against the local machine (no OMP listening) and fails before ever hitting the provider. On terminals without OSC 8 support, they lose the manual `/login <redirect>` path entirely. Every OAuth-facing surface now shows the full authorization URL as the primary copy target and offers `launchUrl` as an additional "Local shortcut (this machine only)" line for wide-terminal local users who want the truncation-safe convenience: - MCPAuthorizationLinkPrompt renders `Copy URL:` with the full URL and appends the local-shortcut row only when `launchUrl` differs. OSC 52 clipboard staging in the MCP onAuth handler switches to the full URL (OSC 52 is a wire-level protocol — the terminal writes to the caller's LOCAL clipboard even when OMP is on a remote SSH box). - LoginDialogComponent.showAuth, selector-controller onAuth, setup-wizard sign-in, and the auth-broker CLI mirror the pattern: full URL first, launchUrl as an optional local shortcut. - Setup wizard uses `wrapTextWithAnsi`, not truncation, so the RFC 7636 §4.3 downgrade bug that motivated launchUrl is unreachable through it; still surfaces launchUrl for wide-terminal convenience. Regression tests in `packages/coding-agent/test/modes/controllers/mcp-authorization-link.test.ts` now assert: - Full URL is the primary `Copy URL:` line so SSH sessions can complete. - launchUrl still appears beneath as `Local shortcut (this machine only): …` when it differs from the full URL. - No shortcut row when launchUrl is absent OR equals the full URL.