Skip to content

fix(web): request current ChatGPT token consent scope - #6781

Merged
iscekic merged 1 commit into
mainfrom
fix/chatgpt-token-consent
Sep 28, 2026
Merged

iscekic merged 1 commit into
mainfrom
fix/chatgpt-token-consent

Conversation

@iscekic

@iscekic iscekic commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Change

  • Request chatgpt.tokens.use.obo for token sharing.
  • Send force_reconsent=true from personal and organization BYOK settings.
  • Replace the old scope in grant checks and tests.
  • Confirm no code reads the retired X-OpenAI-ChatPass-User-ID header.

Check

  • OAuth and callback tests: 53 passed.
  • Web typecheck passed.
  • Changed files passed the format check and git diff --check.

@iscekic iscekic self-assigned this Sep 28, 2026
@iscekic
iscekic marked this pull request as ready for review September 28, 2026 01:04
@kilo-code-bot

kilo-code-bot Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 0
Files Reviewed (5 files)
  • apps/web/src/lib/auth/openai/scopes.ts - scope constant and delegated-grant list swapped to chatgpt.tokens.use.obo consistently; no other references to the retired scope remain in the repo
  • apps/web/src/lib/auth/openai/connect.ts - force_reconsent: 'true' added to signIn authorization params
  • apps/web/src/lib/auth/openai/config.test.ts - expected scope list and comment updated
  • apps/web/src/lib/user/server-signin-callback.test.ts - grant scope fixtures updated
  • apps/web/src/components/organizations/byok/OpenAiChatGptCard.test.ts - signIn arg assertions updated

Notes

  • A repo-wide search confirms chatpass.enable.request is fully removed; no code, fixture, or snapshot still reads it.
  • Stored connections are not re-validated by scope at runtime (isOpenAiTokenSharingGrant is only used on sign-in persistence), so pre-existing rows are unaffected by the scope rename.
  • force_reconsent flows through the same NextAuth authorizationParams path already used for scope, so no additional wiring is required.

Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants