Skip to content

fix(devframe): defer auth code generation - #345

Merged
antfu merged 1 commit into
devframes:mainfrom
onmax:fix/defer-auth-code-generation
Sep 3, 2026
Merged

fix(devframe): defer auth code generation#345
antfu merged 1 commit into
devframes:mainfrom
onmax:fix/defer-auth-code-generation

Conversation

@onmax

@onmax onmax commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Importing devframe/initiate currently generates a six-digit authentication code and starts its TTL during module evaluation, even when no Devframe instance or interactive auth flow is created. This change creates the code and expiry together on first auth-state use, while preserving refresh, expiry, lockout, exchange, and replay behavior.

Reproduction: https://github.com/onmax/repros/tree/main/devframe-eager-auth-code

@coldtea-pr-lens

coldtea-pr-lens Bot commented Sep 3, 2026

Copy link
Copy Markdown

◈ PR Lens

🟢 +0 new · 🟠 ~1 changed · 🔴 -0 removed · 1 flow · 2 files · commit a182ac2


Architecture

Architecture diagram for devframes/devframe at a182ac2

1 component touched across 2 lanes.

Open full size


Data flow

Data flow diagram for devframes/devframe at a182ac2

Lazy OTP initialization and authentication handshake

Open full size


Drill down
Devframe Core Engine — 1 component
🟡 CHANGED Authentication Subsystem

Manages OTP generation, code verification, and session trust with deferred code generation on first access.


View

  • Architecture lens
  • Data flow lens
  • Expand every detail
  • Show unchanged neighbours

Tip

Draw a diff before it is even a pull request: npx @coldtea/pr-lens-cli analyze --base origin/main reads the diff with your own model key, and npx @coldtea/pr-lens-cli render .pr-lens/graph.json draws the same lenses on your machine.

🪧 More tips
  • Run PR Lens on your own machine: npx skills add coldteadotai/pr-lens installs the agent skill. Then tell your coding agent: "Diagram the change you just made with PR Lens and attach it to the pull request."
  • The boxes under View are live. Tick Architecture lens or Data flow lens to choose which diagrams appear, or Expand every detail to open every drill-down at once. The comment redraws in place a few seconds later.
  • Show unchanged neighbours lists the components this change did not touch alongside the ones it did, so the drill-down shows what the changed code sits next to.
  • GitHub will not let you zoom an image in a comment. The link under each diagram opens it full size on a page of its own, where you can.
  • The CLI's render picks up .github/pr-lens.yml automatically and applies your corrections (renames, exclusions, lane pins) at draw time.
  • Would you rather run it from CI on a key of your own? Add .github/workflows/pr-lens.yml with coldteadotai/pr-lens/packages/action@v0 and a model key in your repository secrets, say GEMINI_API_KEY. The Action asks Gemini by default, or OpenAI and any endpoint speaking /chat/completions through its provider input.
  • PR Lens is free for open source. A star on the repository is what keeps it going.
  • Push a new commit and the whole comment re-renders for the new head. An older run never overwrites a newer one, so a slow render cannot put a stale diagram back.
  • The diagrams follow your GitHub theme, so dark mode gets the dark render and light mode the light one, and the moving dots show this pull request's data in motion.

◈ Rendered by PR Lens · crafted with ❤️ by the Coldtea team · Something drawn wrong?

@vercel

vercel Bot commented Sep 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
devframe Skipped Skipped Sep 3, 2026 9:32am UTC

@antfu
antfu merged commit e705b0c into devframes:main Sep 3, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants