Conversation
…redentials Adapt the bounded REST recovery and credential forwarding from Nick Nisi's PR #219 (e730323, latest head 0ce2d03) to current main. This is an adaptation, not a cherry-pick: reject pasted or foreign-target keys, keep sandbox safeguards, and never claim authentication refreshed when the session was reused. Offer one retry through existing auth facilities; wait for concurrent writes, preserve typed 401s, keep manual fallback, and redact credential endpoint failures. Cover real legacy Ruby/Go/.NET orchestration with offline auth/network/agent mocks. Refs: AUTH-6735, #219 Co-authored-by: Nick Nisi <nick.nisi@workos.com>
Reach AUTH-6735 recovery from the current post-agent Next.js and other-framework URL setup. Pin environment/application identity and transport across the single retry, re-read/reconcile partial writes, and keep validation plus final read-back mandatory. Adopt an accepted sandbox pair only after atomically replacing the known JS .env.local file, then update shared state and downstream options. Non-JS post-agent key replacement stays manual because generated credential formats are not authoritative. Preserve structured auth/cancel exit codes, explicit CI/JSON policy and the shared TUI prompt host. Tests exercise actual post-agent orchestration, target ambiguity/change, same or rejected credentials, partial writes, file/state consistency, manual/cancel/headless paths and secret-safe failures. Attribution for the original PR219 concept and forwarding work is recorded in the preceding commit. Refs: AUTH-6735
nicknisi
marked this pull request as ready for review
September 28, 2026 21:06
|
Follow up PR255 review of a91baf5. Reproductions confirmed the rejected-but-unexpired session stop and the legacy success headline after a skipped homepage write. P1 disposition: Nick chose option B, retaining manual session replacement rather than introducing explicit reauth policy. Explain that auth login alone can reuse a rejected session; offer user-controlled host logout/login for the same account or manual URL verification. Do not log a reused rejected session as needing no login. No auth, logout, target, retry-budget or headless policy changes. P2 disposition: retain the ownership guard. A recovered staging pair does not authorize using stale profile claim evidence to write a default homepage. The optional homepage result and post-agent unverified/manual outcome were already intentional; replace the legacy full-success headline with explicit partial guidance. Explicit homepage overrides retain their existing semantics. Offline regressions cover real unexpired-session guards and login reuse, failed/cancelled auth checks, post-agent file preservation, unclaimed-profile key replacement, preserved homepage settings and explicit overrides. Focused 202 tests and full 3290 tests pass; typecheck, lint, format:check and standalone build pass. Refs: AUTH-6735, #255 (comment), #255 (comment)
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Complete the local implementation and verification for AUTH-6735: robust bounded retry/recovery for Unauthorized dashboard configuration in the current WorkOS CLI. Preserve and adapt the useful work from existing CLI PR219 to today's installer architecture, resolve real review findings and formatting issues, and add regression proof. Produce a small reviewed-change-ready branch, not another investigation-only report; distinguish offline proof from any still-required live acceptance.
Riker's check
bun run test && bun run typecheck && bun run lint && bun run format:checkpassed.Opened as a draft by Riker (job 11).