Skip to content

fix(oauth): let local-egress slots generate auth links and exchange directly - #216

Merged
dofastted merged 1 commit into
mainfrom
fix/px-local-oauth-direct
Oct 3, 2026
Merged

dofastted merged 1 commit into
mainfrom
fix/px-local-oauth-direct

Conversation

@dofastted

@dofastted dofastted commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

问题

绑定本地出口(px-local)的槽生成授权链接时报「该槽未绑定健康的 SOCKS5」/「虚拟机未绑定 SOCKS5,请先分配代理再生成授权链接」。本地出口没有 SOCKS URL,控制面按约定传 proxy_url: "",但 generateAuthUrl 和 kin-oauth-auth 把空串当成未绑定。

改动

  • src/lib/oauth/oauth-auth-url.mjs:proxyUrl === '' 视为直连(宿主机默认路由);null 仍报未绑定。
  • bin/kin-oauth-auth:normalizeSocks("") 返回空串(直连),execute 改为 input.proxy_url ?? null。授权链接、粘贴 code 换票、sessionKey 导入在本地出口槽都可用。二进制同时带有已推到 main 的 CLAUDE_WEB 修复(1bc508d)。
  • 测试:oauth-auth-url / session-oauth-seam 单测改为区分 null 与 "";e2e 新增 local egress slot generates auth url and exchanges code。
  • docs/OAUTH.md、CHANGELOG.md 同步。

验证

  • node --test test/unit/session-oauth-seam.test.mjs test/unit/oauth-auth-url.test.mjs:19 pass / 0 fail / 7 skip(skip 是本地专用 auth.js 的用例)。
  • e2e 新用例通过。
  • 二进制:proxy_url:"" 直连到 claude.ai/api/organizations(假 sessionKey 回 403 account_session_invalid);null 回 proxy_required;不通的 SOCKS 回 get_organizations_transport;坏操作退出 1。
  • 已知问题:e2e generate-auth-url claude_code flavor then exchange-code 在 main(1bc508d)上已经失败,原因是它断言 scope 里没有 user:file_upload,但各 flavor 现在都请求完整 scope。本 PR 没碰这个用例。

部署

更新 Node 控制面(src/)和 bin/kin-oauth-auth,重启一次 Node。kernel / cli-node / kin-worker 未变,不需要 wrap-cli/sync。


Note

Medium Risk
Changes OAuth import egress semantics for local slots and ships a rebuilt kin-oauth-auth binary; mis-handling could affect credential import paths, though unbound VMs remain blocked.

Overview
Local egress (px-local) slots can complete OAuth again. The control plane already passes proxy_url: "" for local bindings, but auth-link generation and kin-oauth-auth treated that like “no proxy” and blocked with SOCKS5 errors.

normalizeSocks in oauth-auth-url.mjs now treats "" as host default-route direct while null still means unbound (proxy_required). That unblocks generate auth URL, paste-code exchange, and sessionKey import on local-egress VMs; remote SOCKS5 behavior is unchanged.

Docs (docs/OAUTH.md, CHANGELOG.md) and tests were updated: unit tests distinguish null vs "", and e2e covers bind px-local → generate URL → exchange code. Deploy note: update Node src/ and bin/kin-oauth-auth (includes the bundled CLAUDE_WEB / empty-proxy direct fix) and restart Node once.

Reviewed by Cursor Bugbot for commit fc5792b. Configure here.

…irectly

A slot bound to px-local has no SOCKS URL; the control plane passes proxy_url "" for it, but generate-auth-url and kin-oauth-auth treated "" as unbound and refused. Treat "" as the host default route (direct) for auth-url, pasted-code exchange and sessionKey import; null still means unbound and returns proxy_required. Rebuild bin/kin-oauth-auth (also carries the CLAUDE_WEB fix).
@cursor

cursor Bot commented Oct 3, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: dae22dfe-76d2-4469-9f47-88275c29b008)

@dofastted
dofastted merged commit 0e242d2 into main Oct 3, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant