Skip to content

feat(auth): offer Continue with ChatGPT on the sign-in screen - #6973

Merged
iscekic merged 2 commits into
mainfrom
kwf/chatgpt-signin-cta
Sep 29, 2026
Merged

iscekic merged 2 commits into
mainfrom
kwf/chatgpt-signin-cta

Conversation

@iscekic

@iscekic iscekic commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator

Adds the ChatGPT sign-in option to the first sign-in screen.

Change

  • The sign-in screen renders Continue with ChatGPT in the OAuth provider group, on the first screen and before the email step.
  • The sign-in-with-chatgpt flag no longer hides the sign-in button. The flag still gates the BYOK card, the sidebar entry, and the BYOK page.
  • Deletes useChatGptSignInAccess and its test.

Why

The sign-in page cannot read the flag before the visitor types an address: the release condition matches the email person property, and a signed-out visitor has no person. The button therefore appeared only after the email step.

Reviewer note

The flag is a UI gate only. isOpenAiChatGptEligibleForOwner reads the stored connection and the served model, not the flag. Every visitor can now see the option and connect a ChatGPT plan. If the allow-list must hold on the sign-in path, say so and I will keep the button behind the known address instead.

Verification

  • pnpm --filter web lint — 0 warnings, 0 errors.
  • scripts/typecheck-all.sh --changes-only — pass.
  • Jest SignInForm.signInOptions, SignInForm, auth-touch-targets — 32 tests pass.
  • Local dev stack smoke: the sign-in page and the sign-up page both render Continue with ChatGPT beside the other providers.

The sign-in screen renders 'Continue with ChatGPT' with the other OAuth
providers on the first screen, before the visitor takes the email step.

The ChatGPT access flag needs a person, because its release condition holds
the approved email domains. A signed-out visitor has no person, so the button
was hidden until the visitor submitted an address. The flag now gates only the
BYOK connection surfaces.
@iscekic iscekic self-assigned this Sep 29, 2026
@iscekic
iscekic marked this pull request as ready for review September 29, 2026 18:33
Comment thread apps/web/src/components/auth/SignInForm.tsx
@kilo-code-bot

kilo-code-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: 1 Issue Found | Recommendation: Address before merge

Executive Summary

Removing the sign-in-with-chatgpt gate exposes the ChatGPT sign-in/connect path to every visitor, and no server-side allow-list check remains on that path.

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 0
Issue Details (click to expand)

WARNING

File Line Issue
apps/web/src/components/auth/SignInForm.tsx 343 ChatGPT sign-in option is now rendered for all visitors with no server-side allow-list enforcement (also affects lines 220 and 369). Confirm whether the flag's approved-domain list is a partner/business constraint.
Files Reviewed (6 files)
  • apps/web/src/components/auth/SignInForm.tsx - 1 warning
  • apps/web/src/components/auth/SignInForm.signInOptions.test.ts - no issues
  • apps/web/src/components/auth/auth-touch-targets.test.ts - no issues
  • apps/web/src/hooks/useChatGptSignInAccess.ts - deleted, no remaining references
  • apps/web/src/hooks/useChatGptSignInAccess.test.ts - deleted
  • apps/web/src/lib/auth/openai/access.ts - no issues

No memory-leak risk introduced: the change removes a hook with onFeatureFlags subscriptions and its unmount cleanup rather than adding new subscriptions.

Fix these issues in Kilo Cloud


Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants