Skip to content

fix(oauth): revoke replaced sessions and preserve token metadata - #1147

Open
EhabY wants to merge 4 commits into
mainfrom
fix/oauth-scope-session-lifecycle
Open

EhabY wants to merge 4 commits into
mainfrom
fix/oauth-scope-session-lifecycle

Conversation

@EhabY

@EhabY EhabY commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #1138's token-cleanup comment: clean up replaced OAuth sessions without forcing immediate re-login when required scopes change.

  • Keep existing expiry behavior: insufficient scopes prevent refresh, but do not invalidate the stored access token. Normal 401 recovery applies after expiry. Rename the eligibility check to canRefreshOAuthSession.
  • Fix replacement cleanup: save successful replacement first, then best-effort revoke the overwritten OAuth pair with the client registration captured before login. Failed/cancelled login, same-token reuse, and stored-session adoption do not trigger cleanup.
  • Preserve OAuth metadata on reuse: retain refresh credentials and scope data for the exact same token/deployment, rather than silently converting it to a manual-token session.
  • Share revocation code with logout and request user:update_personal for refreshing expired workspace external-auth links. Inbox permissions remain optional.

No startup/remote admission gates, per-action permission maps, or recovery redesign. Users may encounter feature-specific permission errors before expiry; those do not automatically prompt for login.

Change size

Diff against the PR merge base; counts include moved code and rename edits.

Area Added Removed Net
Production (src/**) 135 82 +53
Tests (test/**) 128 17 +111
Changelog 7 3 +4
Total 270 102 +168

Validation

  • pnpm test:extension: 2,377 passed, 6 skipped before the final persistence-only cleanup; the affected login/session suites passed again afterwards (75 tests).
  • pnpm typecheck, pnpm lint, pnpm format:check, pnpm build, and git diff --check: passed.
  • xvfb-run -a pnpm test:integration: passed on VS Code 1.105.0 and 1.141.0 (activation/command smoke tests, not a live OAuth exchange).
  • Regression tests cover stored/provided token reuse, manual/provided/OAuth replacement, rotated old credentials, captured registration, save-before-revoke ordering, and failed/cancelled login. Existing tests cover outdated-scope refresh eligibility and logout revocation.
Approved narrow implementation plan
  1. Retain fix(oauth): request the scopes the extension and CLI actually need #1138's scope-filtered refresh paths: missing required scopes means no refresh, not immediate sign-out. Tokens with coder:all remain accepted.
  2. Rename the misleading OAuth-presence check to describe refresh eligibility.
  3. Preserve OAuth metadata only for reuse of the exact token and deployment URL; do not attach it to a replacement manual token.
  4. Capture client registration before login can change it. Reread the credentials being overwritten at save time, save successful replacement, then attempt cleanup using that snapshot. Do not revoke on failed/cancelled login, same-token reuse, or stored-session adoption.
  5. Share explicit-credential revocation between logout and replacement. Keep cleanup best effort; no locking subsystem or background-refresh redesign.
  6. Keep compact regression coverage for the narrow contract.

Server source checked on Coder main 89d9492 and v2.38.0 c3c6a67: token responses report granted scopes; discovery lists recognized names, not guaranteed grants; revocation targets the presented token pair, not independent replacement credentials. Older servers omit scope and grant unrestricted access.

Generated by Coder Agents on behalf of @EhabY.

@EhabY
EhabY force-pushed the fix/oauth-scope-session-lifecycle branch from e8d23c6 to 8125427 Compare October 9, 2026 23:05
@EhabY EhabY changed the title fix(oauth): preserve and revoke sessions across scope upgrades fix(oauth): revoke replaced sessions and preserve token metadata Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant