feat(chatgpt): partner guideline notices and the shared-services connection - #6702
Conversation
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Files Reviewed (10 files)
Previous Review Summaries (6 snapshots, latest commit 70dfc58)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 70dfc58)Status: 3 Issues Found | Recommendation: Address before merge Executive SummaryThe organization's shared-services connection is stored against the connecting user's Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (38 files)
Fix these issues in Kilo Cloud Previous review (commit caa7394)Status: No Issues Found | Recommendation: Merge Executive SummaryThe only change since the last review is added test coverage for the plan-limit status path; it matches the router and store contracts, with no new issues. Files Reviewed (1 file)
Previous review (commit d7eba0f)Status: No Issues Found | Recommendation: Merge Executive SummaryThe only change since the last review is added test coverage for the plan-limit status path; it matches the router and store contracts, with no new issues. Files Reviewed (1 file)
Previous review (commit bf276e0)Status: No Issues Found | Recommendation: Merge Files Reviewed (14 files)
Previous review (commit adc3fc4)Status: 5 Issues Found | Recommendation: Address before merge Executive SummaryThe shared-services connect flow cannot work: Overview
Issue Details (click to expand)CRITICAL
WARNING
SUGGESTION
Files Reviewed (30 files)
Fix these issues in Kilo Cloud Previous review (commit 4213bf1)Status: 5 Issues Found | Recommendation: Address before merge Executive SummaryThe shared-services connect flow cannot work: Overview
Issue Details (click to expand)CRITICAL
WARNING
SUGGESTION
Files Reviewed (30 files)
Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0 Review guidance: REVIEW.md from base branch |
The gateway records a reached ChatGPT plan limit on the connection, and the status query reports it while it is current. The BYOK card then shows the usage-limit message and the usage link from the Sign-in-with-ChatGPT partner guidelines, and the usage page shows the same link above its panels.
One row per organization, separate from each member's personal connection. The platform's own callers (code reviewer, Slack bot, auto-triage) use it for an eligible OpenAI model request and fall back to the caller's own connection, which is the behavior every existing caller has today.
…zation BYOK page The link carries the shared-services scope through the linking session, so the callback stores the organization's single row. Only an organization owner or admin can start it or manage it, and the card shows the connected account, the usage link and the usage-limit message.
An expired linking session made the callback fall back to the sign-in gate, which redirected to the app sign-in route with TURNSTILE_REQUIRED. The callback route translated only the two NextAuth hops, so the connect failed with no message. Translate the app sign-in hop when it carries a failure code, and name the timeout on the card. A code-free redirect there stays untouched, so the plain sign-in flow does not change.
A first-time OpenAI consent needs a login, a second factor, a workspace choice, and the consent screen. Five minutes is too short and the link then fails.
main took 0260 for free_amazoness, so this migration moves to 0261 and its snapshot and journal entry follow. The generated SQL is unchanged.
caa7394 to
70dfc58
Compare
softDeleteUser deleted every row by kilo_user_id, so deleting the connecting person removed the organization's only shared connection. Make kilo_user_id nullable with ON DELETE SET NULL, delete only personal rows, and null the reference on the shared row. Retie both connector fields when a shared credential is replaced, and correct the usage-limit comment: a reconnect clears the record, a success does not.
The role was checked when the link started but not when OAuth returned, so a person whose owner or admin role was revoked during the consent could still persist the organization's shared connection. Recheck the membership with canManageOrganization before persisting, and refuse through the readable failure redirect.
…4554) ## Automated docs sync — 2026-09-25 This PR keeps kilo.ai/docs in sync with features merged to [Kilo-Org/cloud](https://github.com/Kilo-Org/cloud) and [Kilo-Org/kilocode](https://github.com/Kilo-Org/kilocode). Every change below links to the merged PR it documents. - Window: `2026-09-24T07:08:33.639Z` → `2026-09-25T07:05:29.302Z` - Verification (docs build + tests): **passing** ### Surface: `cloud-mobile` - Assignees / requested reviewers: @iscekic and @eshurakov - Derivation: Derived from the repository layout. A product surface is a package under packages/ that ships a distinct client, plugin, backend, or hosted service: cli = packages/opencode/ + packages/tui/ + packages/server/ + packages/sdk/ + packages/plugin/; vscode = packages/kilo-vscode/ + packages/kilo-web-ui/ + packages/kilo-ui/; jetbrains = packages/kilo-jetbrains/; gateway = packages/kilo-gateway/; web = packages/kilo-console/ + packages/kilo-indexing/ + packages/kilo-memory/ + packages/kilo-sandbox/. Docs route from the IA tree packages/kilo-docs/pages/ plus docs/jetbrains-vscode-settings-parity.md: each surface lists the pages sections that document it, and the per-platform pages under packages/kilo-docs/pages/code-with-ai/platforms/ map to the matching extension surface (the vscode/ directory to vscode, jetbrains.md to jetbrains). A doc path belongs to the surface with the longest matching prefix; a path that matches none of those prefixes falls to `other` (the explicit other prefixes are listed under other.docs). The cloud surfaces are derived the same way from the Kilo-Org/cloud layout: cloud-mobile = apps/mobile/, cloud-web = apps/web/, cloud-extension = apps/extension/, and cloud-agent = the cloud-agent packages under packages/ (packages/cloud-agent-sdk/ + packages/cloud-agent-profile/). A cloud source names its repository while a bare string still means this repository. The pages under packages/kilo-docs/pages/collaborate/ document the cloud web app (app.kilo.ai: teams dashboard, billing, SSO, adoption dashboard), so they route to cloud-web. No page under packages/kilo-docs/pages/ documents the browser side-panel extension yet, so cloud-extension lists no docs prefix. - Map: `.github/docs-sync/surfaces.json` - Surface map: `cli`, `vscode`, `jetbrains`, `gateway`, `web`, `cloud-mobile`, `cloud-web`, `cloud-extension`, `cloud-agent`, `other` - Source prefixes: `apps/mobile/` (Kilo-Org/cloud) - Doc prefixes: `packages/kilo-docs/pages/code-with-ai/platforms/mobile.md` - Paths that fall to `other`: `packages/kilo-docs/pages/community/`, `packages/kilo-docs/pages/kiloclaw/`, `packages/kilo-docs/pages/contributing/`, `packages/kilo-docs/LEARNINGS.md`, `docs/` - Reviewers are ranked from `Kilo-Org/cloud`; the workflow needs a token with `contents: read` on that repository (repository secret `CROSS_REPO_ACCESS_TOKEN`, exposed to the upsert step as `CLOUD_REPO_TOKEN`). - How the two were computed: Reviewers for `cloud-mobile` are ranked from `Kilo-Org/cloud` git history over `apps/mobile/` (a commit 180 days old counts half as much, half-life 180 days). Bots (author type "Bot" or a login matching /\[bot\]$/i) and people without admin, write, or maintain permission are excluded. ### Changes <!-- docs-sync:changes:start --> | Docs change | Source | | --- | --- | | updated pages/code-with-ai/platforms/mobile.md | [Kilo-Org/cloud#6386](Kilo-Org/cloud#6386) | | updated pages/ai-providers/openai-chatgpt-plus-pro.md | [Kilo-Org/cloud#6702](Kilo-Org/cloud#6702) | | updated pages/code-with-ai/platforms/cloud-agent.md | [Kilo-Org/cloud#6683](Kilo-Org/cloud#6683) | | updated pages/getting-started/byok.md | [Kilo-Org/cloud#6692](Kilo-Org/cloud#6692) | <!-- docs-sync:changes:end --> ### Pending — will retry <!-- docs-sync:pending:start --> _None._ <!-- docs-sync:pending:end --> ### Considered, no docs change needed <!-- docs-sync:skipped:start --> | PR | Reason | | --- | --- | | [Kilo-Org/cloud#6658](Kilo-Org/cloud#6658) | Internal sandbox lifecycle fix with no user-visible workflow or setting. | | [Kilo-Org/cloud#6673](Kilo-Org/cloud#6673) | Internal container CA trust plumbing, no user-facing behavior. | | [Kilo-Org/cloud#6672](Kilo-Org/cloud#6672) | Internal sandbox launch/recovery fix with no documented workflow change. | | [Kilo-Org/cloud#6660](Kilo-Org/cloud#6660) | Internal cloud-agent queue delivery fix; no new command, setting, or workflow for users. | | [Kilo-Org/cloud#6226](Kilo-Org/cloud#6226) | Internal gateway alias-routing change, not user-visible. | | [#14490](#14490) | Tool-call animation and streaming UI polish; users do not need to learn a new workflow. | | [#14530](#14530) | Bug fix restoring intended worktree-pool behavior, no doc change needed. | | [#14529](#14529) | Bug fix restoring tab/panel state across project switches. | | [#14531](#14531) | Reconnect recovery bug fix, restores already-documented behavior. | | [#14532](#14532) | Bug fix keeping session tab title in sync on rename. | | [Kilo-Org/cloud#6088](Kilo-Org/cloud#6088) | Removes internal/admin model-experiment surfaces, not public product docs. | | [Kilo-Org/cloud#6682](Kilo-Org/cloud#6682) | Internal control-socket reconnect race fix, no user-facing change. | | [#14534](#14534) | Transcript re-render performance bug fix. | | [#14535](#14535) | Bug fix preserving the loaded browser page across context switches. | | [Kilo-Org/cloud#6684](Kilo-Org/cloud#6684) | Reverted by Kilo-Org/cloud#6685. | | [Kilo-Org/cloud#6678](Kilo-Org/cloud#6678) | Dead-code constant removal, no user-visible effect. | | [Kilo-Org/cloud#6687](Kilo-Org/cloud#6687) | Removes internal model-experiment maintenance and retains tables, no user-facing change. | | [#14515](#14515) | JetBrains plugin unload crash fix, no documented behavior change. | | [#14520](#14520) | JetBrains transcript/list rendering performance work. | | [Kilo-Org/cloud#6614](Kilo-Org/cloud#6614) | Mobile PR Review header and session title bug fix, no doc change needed. | | [Kilo-Org/cloud#6625](Kilo-Org/cloud#6625) | Internal mobile secure-store error-handling refactor. | | [Kilo-Org/cloud#6624](Kilo-Org/cloud#6624) | Mobile auth bug fix that stops a retry loop; restores expected sign-in behavior with no new setting or workflow. | | [#14310](#14310) | Contributor/CI fix making the kilo-v2 checkout installable; not user-visible product behavior. | | [Kilo-Org/cloud#6611](Kilo-Org/cloud#6611) | Mobile notification-tap fix that selects the session's organization; restores correct behavior rather than adding a learnable feature. | | [Kilo-Org/cloud#6644](Kilo-Org/cloud#6644) | Mobile sign-in layout/alignment polish; no change to what a user must do. | | [Kilo-Org/cloud#6601](Kilo-Org/cloud#6601) | Mobile layout fix keeping empty states clear of the tab bar; purely visual. | | [#14543](#14543) | CI/release infrastructure adding Windows binary code signing; no public docs impact. | | [Kilo-Org/cloud#6616](Kilo-Org/cloud#6616) | Mobile visual defect fixes and a session-title fallback; no new user workflow or setting. | | [Kilo-Org/cloud#6630](Kilo-Org/cloud#6630) | Reports an edge-case partial worktree restore; failure-path plumbing with no new user-facing workflow, target setting, or config. | | [Kilo-Org/cloud#6699](Kilo-Org/cloud#6699) | Cloud Agent e2e stabilization plus internal idle-sandbox capacity handling; not user-visible. | | [#14545](#14545) | Automated JetBrains release/changelog PR; underlying user-facing changes are triaged from their own PRs. | | [Kilo-Org/cloud#6708](Kilo-Org/cloud#6708) | Internal AI-gateway request-logging policy change in the admin panel; no existing public docs surface and no change to how users run Kilo Code. | | [#14533](#14533) | Documentation already shipped with the merged PR. The experimental.task_model_selection flag is gone from the current source, and pages/code-with-ai/agents/model-selection.md, pages/code-with-ai/agents/context-mentions.md, and pages/getting-started/settings/index.md already describe per-task selection as default-on with no stale experiment references. | | [#14510](#14510) | Documentation already shipped with the merged PR. Marketplace companion-skill support is present in the current source (packages/opencode/src/kilocode/marketplace/companions.ts and installer), and pages/customize/marketplace.md already documents installing, publishing, and removing MCP servers with companion skills. | <!-- docs-sync:skipped:end --> --- (bot) Generated by the docs-sync workflow. Humans review and merge; while this PR stays open, the next daily run appends new changes here. Branch: `docs/auto-sync-2026-09-25`. <!-- docs-sync: processed-through 2026-09-25T07:05:29.302Z -->
Implements the Sign-in-with-ChatGPT partner UI/UX guidelines (Figma deck v1.0) that apply to this repository, plus the organization shared-services connection.
What
How
is_shared_services), separate from each member's own connection. A service request (a platform caller that carries a bot id) uses it first, and falls back to the caller's own connection, which is the behavior every existing caller has today.Excluded, with the reason
Notes
Verification
pnpm validateGuidance reference
The three treatments use the deck copy verbatim.
ChatGPT usage limit reached,Review your usage settings in ChatGPT.,Manage usage,Buy Kilo credits insteadView and manage your ChatGPT usageThis repository has no
.changesetdirectory, so this description carries the guidance reference instead of a changeset entry.