Skip to content

feat: use oauth to authenticate (COR-14002) - #31

Merged
effervescentia merged 2 commits into
masterfrom
ben/cor-14002
Sep 22, 2026
Merged

effervescentia merged 2 commits into
masterfrom
ben/cor-14002

Conversation

@effervescentia

Copy link
Copy Markdown
Contributor

No description provided.

Copilot AI balanced review requested due to automatic review settings September 18, 2026 19:03
@linear-code

linear-code Bot commented Sep 18, 2026

Copy link
Copy Markdown

COR-14002

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

OAuth refresh, callback validation, concurrent rotation, credential cleanup, and documented override behavior have unresolved correctness and security issues.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds browser-based OAuth 2.0 authentication with PKCE, secure credential storage, and automatic token refresh.

Changes:

  • Implements OAuth discovery, registration, callback, token, refresh, and storage flows.
  • Integrates OAuth into authentication commands and API client credential resolution.
  • Adds comprehensive tests and user documentation.
File summaries
File Description
README.md Documents browser sign-in and credential precedence.
internal/oauth/token.go Implements token exchange and refresh.
internal/oauth/token_test.go Tests token endpoint behavior.
internal/oauth/testsupport_test.go Adds shared OAuth test helpers.
internal/oauth/store.go Persists sessions and client registrations.
internal/oauth/store_test.go Tests keychain and file storage.
internal/oauth/register.go Implements dynamic client registration.
internal/oauth/pkce.go Generates PKCE verifiers and challenges.
internal/oauth/pkce_test.go Tests PKCE generation.
internal/oauth/oauth.go Coordinates login, refresh, and logout flows.
internal/oauth/metadata.go Implements authorization-server discovery.
internal/oauth/metadata_test.go Tests discovery and authorization URLs.
internal/oauth/login_test.go Tests end-to-end login and refresh.
internal/oauth/command.go Provides OAuth command integration.
internal/oauth/command_test.go Tests command flags and status output.
internal/oauth/callback.go Implements the loopback callback server.
internal/oauth/callback_test.go Tests callback validation and responses.
internal/oauth/browser.go Opens authorization URLs in browsers.
internal/client/client.go Adds OAuth credential resolution.
internal/cli/whoami.go Displays OAuth session status.
internal/cli/auth.go Makes browser OAuth the default login flow.
docs/vf_auth.md Updates authentication command documentation.
docs/vf_auth_login.md Documents OAuth login flags and behavior.
Review details

Files not reviewed (3)

  • internal/cli/auth.go: Generated file
  • internal/cli/whoami.go: Generated file
  • internal/client/client.go: Generated file
  • Files reviewed: 20/23 changed files
  • Comments generated: 9
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/oauth/metadata.go
Comment thread internal/oauth/store.go
Comment thread internal/client/client.go Outdated
Comment thread internal/oauth/callback.go
Comment thread internal/oauth/oauth.go Outdated
Comment thread internal/oauth/oauth.go
Comment thread internal/oauth/oauth.go Outdated
Comment thread README.md Outdated
Comment thread internal/oauth/command.go
@github-actions

Copy link
Copy Markdown

Prerelease v0.255.0-pr.31.1.1 built from dd85573.

Binaries for all six platforms are attached to the release. Not published to npm.

gh release download v0.255.0-pr.31.1.1 --repo voiceflow/cli --pattern 'vf_Darwin_arm64.tar.gz'
tar xzf vf_Darwin_arm64.tar.gz && ./vf version

Re-add the prerelease label to build again after pushing a new commit.

Nine findings from the PR review, all verified against the code:

- metadata: require the discovered issuer to be present and to match the
  one discovery was run against (RFC 8414 §3.3).
- callback: validate state before handling a success *or* error response,
  and never deliver a result for a mismatch, so an unsolicited request to
  a predictable loopback port cannot abort a live login.
- store: report keychain deletion failures from ClearSession instead of
  swallowing them, and keep the session file so a retry can finish.
- store: report the persisted storage state back to the caller so login
  prints the keychain rather than always the session file.
- oauth: honour VF_OAUTH_REDIRECT_URI in the dynamic-registration path —
  validate cached registrations against it and register that list.
- oauth: serialise refresh across processes with a file lock, so parallel
  commands cannot have one delete the session the other just rotated.
- oauth: refresh a token whose response carried no expires_in after an
  assumed lifetime rather than reusing it forever.
- client: propagate non-ErrNoSession OAuth failures out of NewClient
  instead of sending a request that fails with a misleading API error.
- README: document that SSH sign-in needs loopback port forwarding, not
  just --no-browser.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@effervescentia
effervescentia merged commit 99cde56 into master Sep 22, 2026
3 of 4 checks passed
@effervescentia
effervescentia deleted the ben/cor-14002 branch September 22, 2026 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants