fix(oauth): let local-egress slots generate auth links and exchange directly - #216
Merged
Merged
Conversation
…irectly A slot bound to px-local has no SOCKS URL; the control plane passes proxy_url "" for it, but generate-auth-url and kin-oauth-auth treated "" as unbound and refused. Treat "" as the host default route (direct) for auth-url, pasted-code exchange and sessionKey import; null still means unbound and returns proxy_required. Rebuild bin/kin-oauth-auth (also carries the CLAUDE_WEB fix).
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: dae22dfe-76d2-4469-9f47-88275c29b008) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
问题
绑定本地出口(
px-local)的槽生成授权链接时报「该槽未绑定健康的 SOCKS5」/「虚拟机未绑定 SOCKS5,请先分配代理再生成授权链接」。本地出口没有 SOCKS URL,控制面按约定传proxy_url: "",但generateAuthUrl和kin-oauth-auth把空串当成未绑定。改动
src/lib/oauth/oauth-auth-url.mjs:proxyUrl === ''视为直连(宿主机默认路由);null仍报未绑定。bin/kin-oauth-auth:normalizeSocks("")返回空串(直连),execute改为input.proxy_url ?? null。授权链接、粘贴 code 换票、sessionKey 导入在本地出口槽都可用。二进制同时带有已推到 main 的CLAUDE_WEB修复(1bc508d)。oauth-auth-url/session-oauth-seam单测改为区分null与"";e2e 新增local egress slot generates auth url and exchanges code。docs/OAUTH.md、CHANGELOG.md同步。验证
node --test test/unit/session-oauth-seam.test.mjs test/unit/oauth-auth-url.test.mjs:19 pass / 0 fail / 7 skip(skip 是本地专用auth.js的用例)。proxy_url:""直连到claude.ai/api/organizations(假 sessionKey 回 403account_session_invalid);null回proxy_required;不通的 SOCKS 回get_organizations_transport;坏操作退出 1。generate-auth-url claude_code flavor then exchange-code在 main(1bc508d)上已经失败,原因是它断言 scope 里没有user:file_upload,但各 flavor 现在都请求完整 scope。本 PR 没碰这个用例。部署
更新 Node 控制面(
src/)和bin/kin-oauth-auth,重启一次 Node。kernel /cli-node/kin-worker未变,不需要wrap-cli/sync。Note
Medium Risk
Changes OAuth import egress semantics for local slots and ships a rebuilt kin-oauth-auth binary; mis-handling could affect credential import paths, though unbound VMs remain blocked.
Overview
Local egress (
px-local) slots can complete OAuth again. The control plane already passesproxy_url: ""for local bindings, but auth-link generation andkin-oauth-authtreated that like “no proxy” and blocked with SOCKS5 errors.normalizeSocksinoauth-auth-url.mjsnow treats""as host default-route direct whilenullstill means unbound (proxy_required). That unblocks generate auth URL, paste-code exchange, and sessionKey import on local-egress VMs; remote SOCKS5 behavior is unchanged.Docs (
docs/OAUTH.md,CHANGELOG.md) and tests were updated: unit tests distinguishnullvs"", and e2e covers bindpx-local→ generate URL → exchange code. Deploy note: update Nodesrc/andbin/kin-oauth-auth(includes the bundledCLAUDE_WEB/ empty-proxy direct fix) and restart Node once.Reviewed by Cursor Bugbot for commit fc5792b. Configure here.