Skip to content

fix(mobile): render repository picker and avoid dev-host sign-in alert - #6703

Merged
iscekic merged 4 commits into
mainfrom
kwf/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1
Sep 26, 2026
Merged

iscekic merged 4 commits into
mainfrom
kwf/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1

Conversation

@iscekic

@iscekic iscekic commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Changelog for users

  • The New session screen's Repository section always shows a selector under its heading, so it no longer leaves a blank gap above Start session.
  • The selector reports its own state instead of disappearing: 'Loading...' while repositories load, 'Select repository' when none are available, and the chosen repository once set.
  • On iOS, signing in to a non-Kilo (dev or preview) web address opens a plain browser and no longer raises the system consent alert naming that raw address.

Changelog for maintainers

  • The repository picker renders unconditionally. Gating it on hasRepos || anyLoading could leave the Repository heading as the section's only child, because a paused provider query reports isLoading === false with no data. (Findings 1 and 2)
  • resolveProviderStatus treats an undefined integrationInstalled as loading; connect now requires an explicit false, and connected-empty requires a zero count with true.
  • use-device-auth selects the browser API by host: openBrowserAsync on Android or any non-product host, and openAuthSessionAsync only for PRODUCTION_HOSTS. (Finding 3)
  • The iOS change swaps only the browser API; approval still polls the server and never consumes the session redirect, so the signed-in and signed-out flows are unchanged.
  • Review first: the browser-selection branch in use-device-auth and the picker's isLoading={!hasRepos && anyLoading}.
  • Device proof for all three findings ran on Android; the request asked for iOS, and the iOS-only system consent alert cannot be observed on Android, so the iOS behavior rests on the unit tests.
  • Regression tests in the diff cover the empty and loading picker groups and the host-based browser choice.

E2E proof

[e2] new session repository section (finding 2) — with no provider connected the Repository heading still shows the picker's disabled Select repository trigger, and the connect card sits under it; the… — Android (emulator-5604): signed in for this run only as the worktree-scoped no-provider account e2-empty-...@example.com, ran state.sh agent-picker then the pack replay-e2.json -> 'SCENE e2 OK' (e2-scene.log). e2-repository-section.log (extracted from e2-scene.xml) shows the heading text="Repository" bounds [37,1139][1045,1185] immediately followed by content-desc="Repository: Select repository" ... enabled="false" bounds [37,1203][1043,1319], then content-desc="Connect GitHub" ... enabled="true" [76,1386][1004,1432] and content-desc="Connect GitLab" [76,1801][1004,1847]; e2-scene.log lists…

new session repository section (finding 2) — with no provider connected the Repository heading still shows the picker's disabled Select repository trigger, and the connect card sits under it; the…

[e5] ux-check: new-task with the Finding 2 seed (credits 25; org; seeded code-reviews and github-integration) on iOS: the 'Repository' heading is never the section's last visible child; a selector control… — android (host is android-only); e5-scene.log SCENE e5 OK shows 'Repository: Select repository' then 'Repository: GitHub · iscekic/panon-deking' both directly under the Repository heading [37,1074][1045,1120] at the trigger bounds [37,1138][1043,1254]; e5-repo-loading.log shows 'Button "Repository: Loading..." [disabled]' under the same heading; the pending digest (e5-loading.log), resolved empty digest (state-agent-picker.txt) and selected digest share identical coords for Changes [37,1301][1045,1347] and Start session [37,2117][1043,2232], so nothing below moves when the repository list…

ux-check: new-task with the Finding 2 seed (credits 25; org; seeded code-reviews and github-integration) on iOS: the 'Repository' heading is never the section's last visible child; a selector control…

ux-check: signin-more-options-web-auth on the iOS dev stack: no system sign-in consent dialog naming '127.0.0.1' is presented; the web sign-in page opens in an in-app browser and the pending screen…

[e4] ux-check: new-task Finding 1 seed — Repository selector rendered, no empty gap (android) — android (pack says iOS; android is this host's only platform). e4-script.log: TextView Repository tappable [37,1074][1045,1120] is followed directly by Button Repository: Select repository tappable [37,1138][1043,1254] on first paint, and after selection by Button Repository: GitHub · iscekic/backtester tappable [37,1138][1043,1254], with Button Start session [37,2180][1043,2295] below — no empty gap (e4-load.png, e4.png, e4-load-scene.xml, e4-scene.xml, e4.replay.json). Seed satisfied by the signed-in account's existing iscekic/backtester integration. No UX-DEFECT. Note: the transient…

[e4] ux-check: new-task Finding 1 seed — Repository selector rendered, no empty gap (android) — prior/e4.png

[e4] ux-check: new-task Finding 1 seed — Repository selector rendered, no empty gap (android)

[e4] ux-check: new-task Finding 1 seed — Repository selector rendered, no empty gap (android) — prior/e4-load.png

[e8] ux-check: sign-in completes, finding-3 change did not alter the shipped flow (android) — android: signed out, then a real sign-in completed — e8-signin.log shows FLOW OK logout.js, FLOW OK login-request-code.js, FLOW OK login-verify-code.js and {"op":"login","result":"signed-in",...,"mode":"otp"}; signed-in Home tabs in e8-signedin.txt (e8-signedin.png, e8-signedout.png, e8.replay.json). On android use-device-auth takes the openBrowserAsync branch unconditionally, so the iOS native-auth-session branch this finding touched is not exercised on this host; no UX-DEFECT.

[e8] ux-check: sign-in completes, finding-3 change did not alter the shipped flow (android) — prior/e8-signedin.png

[e8] ux-check: sign-in completes, finding-3 change did not alter the shipped flow (android)

[e8] ux-check: sign-in completes, finding-3 change did not alter the shipped flow (android) — prior/e8-signedout.png

[e2] new session repository section (finding 2) — with no provider connected the Repository heading still shows the picker's disabled Select repository trigger, and the connect card sits under it; the…

[e2] new session repository section (finding 2) — with no provider connected the Repository heading still shows the picker's disabled Select repository trigger, and the connect card sits under it; the… — scripted-shard2/e2.png

E2E proof — log excerpts

[e1] ux-check: new-task with no connected repository provider (proved on android -> pass :: SCENE e1 OK on android emulator-5554 with android.widget.TextView Repository tappable [37,1074][1045,1120], android.widget.Button Repository: Select repository tappable [37,1138][1043,1254], and android.widget.Button Connect GitLab tappable [76,1321][1004,1367] beneath it (e1-scene.log).
[e2] new session repository section (finding 2) -> pass :: Android (emulator-5604): signed in for this run only as the worktree-scoped no-provider account e2-empty-...@example.com, ran state.sh agent-picker then the pack replay-e2.json -> 'SCENE e2 OK' (e2-scene.log). e2-repository-section.log (extracted from e2-scene.xml) shows the heading text="Repository" bounds [37,1139][1045,1185] immediately followed by content-desc="Repository: Select repository" ... enabled="false" bounds [37,1203][1043,1319], then content-desc="Connect GitHub" ... enabled="true" [76,1386][1004,1432] and content-desc="Connect GitLab" [76,1801][1004,1847]; e2-scene.log lists the same order (Button Repository: Select repository then Button Connect GitHub). The Repository headi
[e6] ux-check: new-task with no connected repository provider -> pass :: Android (host is android-only; iOS not available, so the iOS-named check is proven on android). e6-scene.log shows the settled no-provider new-session screen: 'android.widget.TextView Repository' [37,1139][1045,1185] then 'android.widget.Button Repository: Select repository' [37,1203][1043,1319] (the disabled/empty label) then 'android.widget.Button Connect GitHub' [76,1386][1004,1432] and 'android.widget.Button Connect GitLab' [76,1801][1004,1847] (connect cards beneath); screenshot e6.png. The only repository progress control is the single picker trigger, and the change's added unit test covers the picker's loading branch, so no duplicate/stacked indicator. UX audit of the visited (new ses
/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/e1-scene.log
android.widget.TextView Run on tappable [37,792][1045,838]
android.widget.Button Run on: Cloud Agent tappable [37,856][909,972]
android.widget.TextView Cloud Agent tappable [67,886][844,942]
android.widget.Button Refresh tappable [928,856][1043,972]
android.widget.TextView To run on your computer, start Kilo there and leave it running. tappable [36,991][1044,1028]
android.widget.TextView Repository tappable [37,1074][1045,1120]
android.widget.Button Repository: Select repository tappable [37,1138][1043,1254]
android.widget.TextView Select repository tappable [67,1168][978,1224]
android.widget.Button Connect GitLab tappable [76,1321][1004,1367]
android.widget.TextView Connect GitLab tappable [76,1321][944,1367]
android.widget.TextView Connect GitLab in your browser, then return here to pick a repository. tappable [76,1395][1004,1487]
android.widget.Button Open GitLab tappable [76,1515][870,1630]
android.widget.TextView Open GitLab tappable [175,1549][768,1595]
android.widget.Button Refresh repositories tappable [888,1515][1004,1630]
android.widget.TextView Changes tappable [37,1716][1045,1762]
android.view.View Changes tappable [37,1780][1043,1899]
android.widget.RadioButton Leave changes tappable [46,1789][540,1890]
android.widget.TextView Leave changes tappable [192,1816][393,1862]
android.widget.RadioButton Commit and push tappable [540,1789][1034,1890]
android.widget.TextView Commit and push tappable [668,1816][905,1862]
android.widget.TextView Environment tappable [37,1945][1045,1991]
android.widget.TextView busy tappable [37,2009][1045,2034]
android.widget.Button Start session [37,2117][1043,2232]
android.widget.TextView Start session tappable [442,2151][638,2197]
/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/e2-scene.log
android.widget.Button Paste from clipboard tappable [150,703][232,786]
android.widget.Button Start voice input tappable [931,698][1023,790]
android.widget.TextView Run on tappable [37,857][1045,903]
android.widget.Button Run on: Cloud Agent tappable [37,921][909,1037]
android.widget.TextView Cloud Agent tappable [67,951][844,1007]
android.widget.Button Refresh tappable [928,921][1043,1037]
android.widget.TextView To run on your computer, start Kilo there and leave it running. tappable [36,1056][1044,1093]
android.widget.TextView Repository tappable [37,1139][1045,1185]
android.widget.Button Repository: Select repository [37,1203][1043,1319]
android.widget.TextView Select repository tappable [67,1233][978,1289]
android.widget.Button Connect GitHub tappable [76,1386][1004,1432]
android.widget.TextView Connect GitHub tappable [76,1386][944,1432]
android.widget.TextView Connect GitHub in your browser, then return here to pick a repository. tappable [76,1460][1004,1552]
android.widget.Button Open GitHub tappable [76,1580][870,1695]
android.widget.TextView Open GitHub tappable [175,1614][768,1660]
android.widget.Button Refresh repositories tappable [888,1580][1004,1695]
android.widget.Button Connect GitLab tappable [76,1801][1004,1847]
android.widget.TextView Connect GitLab tappable [76,1801][944,1847]
android.widget.TextView Connect GitLab in your browser, then return here to pick a repository. tappable [76,1875][1004,1967]
android.widget.Button Open GitLab tappable [76,1995][870,2034]
android.widget.TextView Open GitLab tappable [175,2029][768,2034]
android.widget.Button Refresh repositories tappable [888,1995][1004,2034]
android.widget.Button Start session [37,2117][1043,2232]
android.widget.TextView Start session tappable [442,2151][638,2197]
/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/e2-repository-section.log
<redacted>
<redacted>
<redacted>
<redacted>
<redacted>
<redacted>
/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/restore-login.log
appium.sh: starting appium server for emulator-5604 on port 4790
login.sh: phase=app-settle t=1790264179
FLOW OK settle-app.js (android emulator-5604)
login.sh: phase=profile-navigation t=1790264194
session.sh: link delivered on emulator-5604
session.sh: open OK device=emulator-5604 route=profile mode=deeplink
login.sh: phase=profile-settle t=1790264195
FLOW OK settle-app.js (android emulator-5604)
login.sh: phase=profile-hierarchy t=1790264203
hierarchy: /tmp/kilo-e2e-signed-in.Q3GcNO (104 elements)
==> the app is signed out; running the full login
login.sh: phase=outbox-snapshot t=1790264208
==> signing out and requesting sign-in code for e2e-mobile-explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1-android@example.com
==> the probe proved the app signed out; skipping the logout pass
login.sh: phase=request-code t=1790264212
FLOW OK login-request-code.js (android emulator-5604)
login.sh: phase=outbox-delivery t=1790264254
==> verifying sign-in code
login.sh: phase=verify-code t=1790264257
FLOW OK login-verify-code.js (android emulator-5604)
FLOW OK dismiss-dialogs.js (android emulator-5604)
login.sh: phase=account-fixtures t=1790264308
login.sh: phase=report-result t=1790264310
{"op":"login","result":"signed-in","device":"emulator-5604","email":"e2e-mobile-explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1-android@example.com","mode":"otp"}
/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/e6-scene.log
android.widget.Button Paste from clipboard tappable [150,703][232,786]
android.widget.Button Start voice input tappable [931,698][1023,790]
android.widget.TextView Run on tappable [37,857][1045,903]
android.widget.Button Run on: Cloud Agent tappable [37,921][909,1037]
android.widget.TextView Cloud Agent tappable [67,951][844,1007]
android.widget.Button Refresh tappable [928,921][1043,1037]
android.widget.TextView To run on your computer, start Kilo there and leave it running. tappable [36,1056][1044,1093]
android.widget.TextView Repository tappable [37,1139][1045,1185]
android.widget.Button Repository: Select repository [37,1203][1043,1319]
android.widget.TextView Select repository tappable [67,1233][978,1289]
android.widget.Button Connect GitHub tappable [76,1386][1004,1432]
android.widget.TextView Connect GitHub tappable [76,1386][944,1432]
android.widget.TextView Connect GitHub in your browser, then return here to pick a repository. tappable [76,1460][1004,1552]
android.widget.Button Open GitHub tappable [76,1580][870,1695]
android.widget.TextView Open GitHub tappable [175,1614][768,1660]
android.widget.Button Refresh repositories tappable [888,1580][1004,1695]
android.widget.Button Connect GitLab tappable [76,1801][1004,1847]
android.widget.TextView Connect GitLab tappable [76,1801][944,1847]
android.widget.TextView Connect GitLab in your browser, then return here to pick a repository. tappable [76,1875][1004,1967]
android.widget.Button Open GitLab tappable [76,1995][870,2034]
android.widget.TextView Open GitLab tappable [175,2029][768,2034]
android.widget.Button Refresh repositories tappable [888,1995][1004,2034]
android.widget.Button Start session [37,2117][1043,2232]
android.widget.TextView Start session tappable [442,2151][638,2197]
/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/device.log
e2e-slot: xcrun at ? cannot list booted simulators; the ios side of the appium sweep is skipped
appium.sh: installing harness deps in /home/igor_kilocode_ai/Projects/.kilo_workflow.d/6241d97eb766386fd367f551bf1400c0dc86e63d …
<redacted>
e2e-slot: xcrun at ? cannot list booted simulators; the ios side of the appium sweep is skipped
appium.sh: installing harness deps in /home/igor_kilocode_ai/Projects/.kilo_workflow.d/64b47b477c93694658ec2572a94ea1143c0b99b6 …
<redacted>
e2e-slot: xcrun at ? cannot list booted simulators; the ios side of the appium sweep is skipped
Owner request

Surface: mobile-app

Explorer finding: 3 visual defects on ios: On the New session screen the 'Repositor; The Repository section shows its heading; The system sign-in consent dialog asks t

The user-agent explorer found these 3 while using the app like a user. They are one kind of defect on one platform, so they are ONE item: the pull request must fix and prove every one of them.
One must-run scenario per finding: the plan needs 3 musts, one for each finding below.
The explorer never edits product code.

Evidence (from the device runs):

--- Finding 1 of 3: new-task: On the New session screen the 'Repository' section header sits above a blank void with no selector or empty-state text, while the 'Start session' button is the only control below it.
Flow: new-task
Found on revision: f11be79
Repro:

  1. set this state first: credits 30; reviews 3; seed app:api-token e2e-mobile-cloud-android@example.com; org; seed app:github-integration a7e4d40b-c28c-4df1-9a1e-f88e7eb467f1 --installation-id=144771093 --repository=iscekic/backtester
  2. open the app on 2E687210-E477-4D23-94F1-9736C860ACD8
  3. reach new-task
  4. the capture shows the defect named below
    Observed: On the New session screen the 'Repository' section header sits above a blank void with no selector or empty-state text, while the 'Start session' button is the only control below it.
    Expected: the screen renders without this defect

--- Finding 2 of 3: new-task: The Repository section shows its heading with an empty gap where the selector belongs, so the label floats above the Start session button with no control under it.
Flow: new-task
Found on revision: e8b1caa
Repro:

  1. set this state first: credits 25; reviews 3; org; seed code-reviews:review-list --email e2e-mobile-cloud-android@example.com --count 3; seed app:org-dashboard; seed app:github-integration a7e4d40b-c28c-4df1-9a1e-f88e7eb467f1 --installation-id=144771093 --repository=iscekic/backtester
  2. open the app on 2E687210-E477-4D23-94F1-9736C860ACD8
  3. reach new-task
  4. the capture shows the defect named below
    Observed: The Repository section shows its heading with an empty gap where the selector belongs, so the label floats above the Start session button with no control under it.
    Expected: the screen renders without this defect

--- Finding 3 of 3: signin-more-options-web-auth: The system sign-in consent dialog asks the user to sign in to "127.0.0.1", exposing a raw developer address instead of the product domain.
Flow: signin-more-options-web-auth
Found on revision: 70f3ee0
Repro:

  1. open the app on B6F4F8DE-8DBF-41E2-9114-908DADAD1B68
  2. reach signin-more-options-web-auth
  3. the capture shows the defect named below
    Observed: The system sign-in consent dialog asks the user to sign in to "127.0.0.1", exposing a raw developer address instead of the product domain.
    Expected: the screen renders without this defect

[e7] ux-check: signin-more-options-web-auth on the iOS dev stack: no system sign-in consent dialog naming '127.0.0.1' is presented; the web sign-in page opens in an in-app browser and the pending screen… — [android/emulator-5606] from signed-out, tapping More sign-in options opened the web sign-in page in an in-app Chrome Custom Tab at 127.0.0.1:4300 with no consent dialog, back showed the pending screen with user code 7LVR-MBDK (matches the device_auth_requests row) and a Cancel that returned to the sign-in screen, so no UX-DEFECT; the iOS ASWebAuthenticationSession consent alert is an iOS-only surface and is not observable on Android (e7-web-auth.log, e7-web-auth-browser.png, e7-pending-code.png, e7-welcome-signed-out.png).

[e7] ux-check: signin-more-options-web-auth on the iOS dev stack: no system sign-in consent dialog naming '127.0.0.1' is presented; the web sign-in page opens in an in-app browser and the pending screen… — e7-pending-code.png

[e7] ux-check: signin-more-options-web-auth on the iOS dev stack: no system sign-in consent dialog naming '127.0.0.1' is presented; the web sign-in page opens in an in-app browser and the pending screen…

[e7] ux-check: signin-more-options-web-auth on the iOS dev stack: no system sign-in consent dialog naming '127.0.0.1' is presented; the web sign-in page opens in an in-app browser and the pending screen… — e7-welcome-signed-out.png

Follow-ups (not changed here)

  • not proved live: signin-more-options-web-auth (finding 3) — platform:ios (the ASWebAuthenticationSession consent alert exists only on iOS): tapping More sign-in options opens the Kilo web sign-in page in an in-app browser and no system dialog names a raw developer address (no capture cited it)
  • not proved live: ux-check: iOS sign-in where the auth host is a product host (app.kilo.ai): the native auth session path is used as before and sign-in completes, confirming the finding-3 change did not alter the shipped sign-in flow. (no capture cited it)
  • not proved live: ux-check: new-task on iOS with no connected repository provider: under the 'Repository' heading the control shows a visible disabled/empty label (e.g. 'Select repository') with the provider connect card beneath it, and the heading does not float above blank space; only one loading/progress indicator is present at a time. (no capture cited it)
  • not proved live: ux-check: new-task with the Finding 1 seed (credits 30; org; seeded github-integration with iscekic/backtester) on iOS: below the 'Repository' heading a selector control is rendered on first paint and stays — its label is the repository name, or a loading label while the list resolves — and there is no empty gap between the heading and the 'Start session' button. (no capture cited it)

Open findings (not fixed here)

  • not proved live: new-task.png is no longer on the host that took it, so no publish can carry it
  • not proved live: signin-more-options-web-auth.png is no longer on the host that took it, so no publish can carry it

e6

Surface: mobile-app

Explorer finding: 3 visual defects on ios: On the New session screen the 'Repositor; The Repository section shows its heading; The system sign-in consent dialog asks t

The user-agent explorer found these 3 while using the app like a user. They are one kind of defect on one platform, so they are ONE item: the pull request must fix and prove every one of them.
One must-run scenario per finding: the plan needs 3 musts, one for each finding below.
The explorer never edits product code.

Evidence (from the device runs):

--- Finding 1 of 3: new-task: On the New session screen the 'Repository' section header sits above a blank void with no selector or empty-state text, while the 'Start session' button is the only control below it.
Flow: new-task
Found on revision: f11be79
Repro:
1. set this state first: credits 30; reviews 3; seed app:api-token e2e-mobile-cloud-android@example.com; org; seed app:github-integration a7e4d40b-c28c-4df1-9a1e-f88e7eb467f1 --installation-id=144771093 --repository=iscekic/backtester
2. open the app on 2E687210-E477-4D23-94F1-9736C860ACD8
3. reach new-task
4. the capture shows the defect named below
Observed: On the New session screen the 'Repository' section header sits above a blank void with no selector or empty-state text, while the 'Start session' button is the only control below it.
Expected: the screen renders without this defect
- ~/.local/share/kwf/findings/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f538
@kilo-code-bot

kilo-code-bot Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental changes add the host-aware auth-browser helper, dismiss the plain dev-host browser on approval, and add a clarifying comment plus regression tests; no bugs, security, or memory issues were found in the changed lines.

Files Reviewed (7 files)
  • apps/mobile/src/lib/auth/auth-browser.ts
  • apps/mobile/src/lib/auth/device-auth-poll.ts
  • apps/mobile/src/lib/auth/device-auth-poll.test.ts
  • apps/mobile/src/lib/auth/use-device-auth.ts
  • apps/mobile/src/lib/auth/use-device-auth.test.ts
  • apps/mobile/src/components/agents/new-session-repository-section.tsx
  • apps/mobile/src/components/agents/new-session-repository-section.test.ts
Previous Review Summary (commit fcfdafb)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit fcfdafb)

Status: No Issues Found | Recommendation: Merge

The change renders the repository picker unconditionally, treats an undefined integrationInstalled as loading, and selects the browser API by host; the new tests match the changed contracts and no bugs, security, or diff-introduced issues were found.

Files Reviewed (6 files)
  • apps/mobile/src/components/agents/new-session-repository-section.tsx
  • apps/mobile/src/components/agents/new-session-repository-section.test.ts
  • apps/mobile/src/components/agents/new-session-repository-state.ts
  • apps/mobile/src/components/agents/new-session-repository-state.test.ts
  • apps/mobile/src/lib/auth/use-device-auth.ts
  • apps/mobile/src/lib/auth/use-device-auth.test.ts

Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

@iscekic iscekic added the human-ready The PR is ready for human review. label Sep 25, 2026
Comment thread apps/mobile/src/lib/auth/use-device-auth.ts Outdated
…-defects-on-ios-on-the-new-session-scree-4948f-e3c1
The device-auth flow ends on the poll's approval, not on the page's
redirect. Approval always called `dismissAuthSession`, which does nothing
to the plain browser that iOS opens for a non-product host, so that page
stayed over the approved app.

Move the browser choice into one module that names the presentation
(`auth-session` or `plain-browser`), open with it, and dismiss with the
API that matches the presentation the flow opened. Pass the presentation
to the poll. Android behaviour is unchanged.
@iscekic
iscekic marked this pull request as draft September 25, 2026 19:09
@iscekic
iscekic marked this pull request as ready for review September 25, 2026 19:09
…-defects-on-ios-on-the-new-session-scree-4948f-e3c1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

human-ready The PR is ready for human review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants