Skip to content

fix(auth): expose stable session subject - #16

Merged
nullStack65 merged 3 commits into
mainfrom
envfix/t3-auth-identity-surface-20261002
Oct 2, 2026
Merged

nullStack65 merged 3 commits into
mainfrom
envfix/t3-auth-identity-surface-20261002

Conversation

@nullStack65

Copy link
Copy Markdown
Owner

Adds the authenticated session subject to GET /api/auth/session as an optional non-secret field. The subject is stable across token rotation for the same issued principal and drifts when the issued subject changes; unauthenticated responses omit it. Credentials, proof keys, managed-launch key IDs, and provider-host identity remain unexposed and separate.

Tests: vp test run apps/server/src/auth/EnvironmentAuth.test.ts packages/contracts/src/auth.test.ts (blocked in this checkout because vite-plus is not installed); git diff --check passed.

Model/harness: GPT-5 Codex.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: nullStack65/t3code/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 7726e4f7-4c72-42a7-b6d2-c985eac856bb

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S labels Oct 2, 2026

Copy link
Copy Markdown
Owner Author

ENVFIX — PR16 source proof preserved; exact fork CI/capacity dependency

Current #16 remains open at 09964c1d14a0d70b8b9dbaa1afbb4e2d10390c0b, base 419f7574010c066a56974fc9e3ac0709a08efb33. Preserve ENVFIX's exact-head independent PASS and offline frozen-dependency 17/17 qualified tests; the source proof is completed.

Bounded current check read: 16 check records = 5 success, 2 skipped, 9 queued, no completed failure. CI run 36954638855 has eight queued jobs (Check, Test, Test Server 1/2/3, Rust, Release Smoke, Mobile Native Changes); separate native fingerprint job on run 36954638854 is also queued. Current .github/workflows/ci.yml requests Blacksmith Ubuntu labels (2/4/8 vCPU) and Blacksmith 6-vCPU macOS 26. The recently restored Closura ARC/Linux fleet does not by itself establish runner eligibility for these labels.

Scoped independent next action, existing ENVFIX owner: use existing authorized access to resolve this fork's required CI policy and matching runner/capacity/provider eligibility. Return actual queue/eligibility or billing/permission blocker and its current owner. If an approved source/workflow correction is necessary, refresh claims and keep it a separately reviewed bounded change on this fork; do not silently change required checks, skip tests, relabel runners or create a new fleet. No unsupported-provider queue is asserted to be a code failure; no unobserved capacity fix is claimed.

Normal source landing and qualified installed T3 upgrade remain under the existing ENVFIX owner. After its legitimate CI/landing disposition, obtain installed authenticated stable subject readback with same-subject rotation stability, changed-subject drift and anonymous omission. Non-settling DELIVERY-4 consumers need that subject; managed launch separately retains provider-key and distinct host-instance gates. Return START/RESULT and exact installed/candidate identity to existing DELIVERY-4 thread. No credential/proof/hash disclosure, installation or access change is performed by this packet.

@nullStack65
nullStack65 force-pushed the envfix/t3-auth-identity-surface-20261002 branch from 09964c1 to 218f44b Compare October 2, 2026 04:08

@jeffreysmithclosura jeffreysmithclosura left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head 218f44b67020141942bd58c23666eaed474526c4 against base 0975683e984a65612f5ab18a67c413b899219098. The rebase retains the intended three-file auth-subject delta only: EnvironmentAuth.ts, its focused test, and packages/contracts/src/auth.ts; no unrelated drift or PR17 regression is present in that comparison. git diff --check origin/main...HEAD passed, and vp test apps/server/src/auth/EnvironmentAuth.test.ts packages/contracts/src/auth.test.ts passed (1 file, 17 tests). Authenticated session state exposes only the stable nonsecret verified subject; anonymous state omits it; same-subject token rotation remains stable; changing the subject is observable drift; the response does not expose a token, session ID, proof key, hash, or credential. Managed-launch key IDs and provider-host identity remain separate concerns. Exact-head GitHub checks read once: CodeRabbit success; no pending checks observed.

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 13.5 KiB 13.5 KiB −41 B (−0.3%) 15.1 KiB ✅
Codex Thread snapshot wire 7.1 KiB 7.1 KiB −3 B (−0.0%) 7.3 KiB ✅
Codex Live turn WebSocket wire 6.4 KiB 6.4 KiB −38 B (−0.6%) 7.8 KiB ✅
Codex Live turn WebSocket decoded 56.3 KiB 56.2 KiB −88 B (−0.2%) 66.4 KiB ✅
Codex Live turn messages 10 8 −2 (−20.0%) 21 ✅
Claude Total thread wire 13.5 KiB 13.5 KiB −5 B (−0.0%) 15.1 KiB ✅
Claude Thread snapshot wire 7.1 KiB 7.1 KiB +5 B (+0.1%) 7.3 KiB ✅
Claude Live turn WebSocket wire 6.4 KiB 6.4 KiB −10 B (−0.2%) 7.8 KiB ✅
Claude Live turn WebSocket decoded 57.0 KiB 57.0 KiB −44 B (−0.1%) 66.4 KiB ✅
Claude Live turn messages 9 8 −1 (−11.1%) 21 ✅

Baseline: 0975683 · PR result: 2fe5464 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 113.9 KiB
  • Claude decoded thread snapshot: 114.6 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@jeffreysmithclosura jeffreysmithclosura left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up review at exact head 8a94666e087d9214d953565710eaa1d16e4f2c2e against base 0975683e984a65612f5ab18a67c413b899219098. PASS retained: the base comparison remains the intended three-file auth-subject delta, and the only change from prior reviewed head 218f44b67020141942bd58c23666eaed474526c4 is mechanical formatting in apps/server/src/auth/EnvironmentAuth.test.ts (1 insertion, 3 deletions), with no source-semantic change. git diff --check origin/main...HEAD passed; focused vp test apps/server/src/auth/EnvironmentAuth.test.ts packages/contracts/src/auth.test.ts passed (17/17). The stable nonsecret verified subject, anonymous omission, same-subject rotation stability, observable subject drift, and credential/proof/token/session-ID/hash non-disclosure boundaries remain intact; managed-launch key IDs and provider-host identity remain separate. Fresh exact-head status read once: CodeRabbit success. No new repository CI success was observed, so overall merge remains blocked pending CI.

@jeffreysmithclosura jeffreysmithclosura left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PASS — exact-head review of 2fe5464 against 0975683.

The schema-based JSON encoding repair is sound: it avoids the prior TS377026 issue without serializing or exposing bearer credentials. The focused test confirms the response carries the stable issued subject across token rotation, changes when the issued subject changes, omits it for unauthenticated requests, and does not contain the access token. Runtime behavior only adds subject: session.subject to authenticated AuthSessionState; the contract keeps it optional and explicitly separates managed-launch key identifiers and other identity material.

Local evidence: vp check apps/server/src/auth/EnvironmentAuth.test.ts passed; vp test run apps/server/src/auth/EnvironmentAuth.test.ts passed (17/17); bounded server typecheck passed; git diff --check passed. Fresh exact-head GitHub CI was inspected but remains in progress, so it is not treated as green.

@nullStack65
nullStack65 merged commit 0399d91 into main Oct 2, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants