fix(cli): continue local chat after account sign-in - #1054
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
dcramer
force-pushed
the
codex/local-oauth-assets
branch
from
July 26, 2026 16:54
8d12b5a to
f40e3c8
Compare
dcramer
marked this pull request as ready for review
July 26, 2026 21:45
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 6edb5ad. Configure here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Local
junior chatused to stop whenever GitHub or an MCP tool needed the user to sign in. It now prints the sign-in link, waits for the browser callback, and continues the same request. This also lets GitHub image uploads use the connected user's credential, as required by GitHub's user-attachment endpoint.The browser still returns through the public development URL, then a signed, expiring redirect sends it to the waiting CLI. Credentials remain outside the sandbox, sensitive callback data is removed from telemetry, and duplicate, late, or stalled callbacks cannot resume the wrong request. Plugin and MCP authorization share the same small runtime capability, while local dev-server signaling stays behind an authenticated sandbox transport. Slack behavior is unchanged, and local chat still works without the dev server when no sign-in is needed.
OAuth QA exposed a separate dev-server restart bug: the outer command could exit while its Nitro process kept the port, leaving the tunnel alive but unable to reach a healthy replacement. The dev launcher now stops each long-running command as one process tree before restarting it, and the local QA skill verifies both the loopback and public callback paths before presenting an authorization URL.
The end-to-end coverage exchanges a code with a fake provider through the real loopback server, resumes the parked local turn, and verifies that the resumed slice completes durably. A live Linear MCP check also completed browser authorization, resumed the same CLI turn, and fetched the requested teams without repeating the prompt.