Repository navigation
Conversation
EhabY
force-pushed
the
fix/oauth-scope-session-lifecycle
branch
from
October 9, 2026 23:05
e8d23c6 to
8125427
Compare
EhabY
force-pushed
the
fix/oauth-scope-session-lifecycle
branch
3 times, most recently
from
October 10, 2026 16:26
0e48fb6 to
ccc5842
Compare
Clean up replaced OAuth sessions without forcing a re-login when the required scopes change. - Insufficient scopes prevent refresh but keep the stored access token, so normal 401 recovery applies after expiry. Rename the check to `canRefreshOAuthSession`. - Save a successful replacement first, then revoke the overwritten OAuth pair in the background with the client registration captured before login. Failed or cancelled logins, same-token reuse and stored-session adoption revoke nothing. - Keep refresh credentials and scopes when the exact token and deployment are reused, instead of turning it into a manual-token session. - Share revocation with logout through `withOAuthMetadata`, which token refresh also uses, and request `user:update_personal` to refresh expired external-auth links.
EhabY
force-pushed
the
fix/oauth-scope-session-lifecycle
branch
from
October 10, 2026 16:30
ccc5842 to
7ecec2f
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to #1138's token-cleanup comment: clean up replaced OAuth sessions without forcing immediate re-login when required scopes change.
canRefreshOAuthSession.src/oauth/revocation.tsand is used by both logout and replacement. Client creation and metadata discovery move towithOAuthMetadatainsrc/oauth/metadataClient.ts, which token refresh also uses.user:update_personalfor refreshing expired workspace external-auth links. Inbox permissions remain optional.No startup/remote admission gates, per-action permission maps, or recovery redesign. Users may encounter feature-specific permission errors before expiry; those do not automatically prompt for login.
Change size
Diff against the PR merge base; counts include moved code and rename edits.
src/**)test/**)Validation
Single commit on top of #1134.
pnpm test: 189 files, 2,826 passed, 6 skipped.pnpm typecheck,pnpm lint, andpnpm format:check: passed.xvfb-run -a pnpm test:integration: passed on VS Code 1.105.0 and 1.141.0 before the rebase (activation/command smoke tests, not a live OAuth exchange). Not rerun after the latest cleanup.Approved narrow implementation plan
coder:allremain accepted.Server source checked on Coder main
89d9492and v2.38.0c3c6a67: token responses report granted scopes; discovery lists recognized names, not guaranteed grants; revocation targets the presented token pair, not independent replacement credentials. Older servers omit scope and grant unrestricted access.Generated by Coder Agents on behalf of @EhabY.