Skip to content

fix(executors): reconstruct LMArena split auth cookie (#4271) - #4331

Merged
diegosouzapw merged 3 commits into
release/v3.8.30from
fix/4271-arena-split-cookie
Jun 20, 2026
Merged

diegosouzapw merged 3 commits into
release/v3.8.30from
fix/4271-arena-split-cookie

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Closes #4271

Problem

LMArena migrated to @supabase/ssr chunked auth cookies: when the session JWT exceeds Supabase's chunk size it splits across arena-auth-prod-v1.0, arena-auth-prod-v1.1, … (ascending) and leaves the base arena-auth-prod-v1 cookie empty. Our UX told users to copy the single arena-auth-prod-v1, which now carries no value, so the forwarded Cookie had an empty session → upstream rejected it as "invalid cookie". (Confirmed by a commenter: arena-auth-prod-v1 empty, .0/.1 populated.)

Fix

reconstructLMArenaCookie() in open-sse/executors/lmarena.ts rebuilds the single cookie from its chunks following Supabase's combineChunks (ascending .N, plain join(""), no base64-decode / no JSON-parse — the base64- prefix is part of LMArena's token and is kept verbatim), preserving the rest of the pasted jar. A non-empty single arena-auth-prod-v1 is forwarded unchanged (back-compat). Wired into all branches of readLMArenaCookie. The credential UX (webSessionCredentials.ts placeholder/storageKeys, providers.ts authHint) now instructs pasting the full Cookie header and recognizes the .0/.1 keys.

Validation (Hard Rule #18)

tests/unit/lmarena-split-cookie-4271.test.ts (7 cases): ascending-chunk reconstruction, single-cookie back-compat, out-of-order paste, jar preservation, empty-base→no-session, storage-keys/placeholder. RED (no reconstructLMArenaCookie export) → GREEN (27/27 with the existing lmarena suite). Lint 0-err, typecheck:core clean, no file-size bump.

⚠️ Live-validation caveat: the parsing/reconstruction is fully unit-TDD-covered, but full end-to-end auth against LMArena needs a real chunked session that upstream accepts — a VPS/live test with a real arena-auth-prod-v1.0/.1 cookie is recommended before declaring the connectivity bug fully closed. The unit tests prove we reconstruct the cookie correctly; only a live call proves LMArena accepts it.

LMArena migrated to @supabase/ssr chunked auth cookies: the single
arena-auth-prod-v1 cookie is now empty and the session is split across
arena-auth-prod-v1.0, .1, … (ascending). Pasting the now-empty single
cookie sent an empty session, which upstream rejected as "invalid cookie".

reconstructLMArenaCookie() rebuilds the single cookie from its chunks
(ascending join, no decode/parse — combineChunks semantics), preserving
the rest of the pasted jar; a non-empty single cookie is forwarded
unchanged (back-compat). The credential UX now instructs pasting the full
Cookie header and tracks the .0/.1 storage keys.

Closes #4271
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@diegosouzapw
diegosouzapw merged commit 5cca4ff into release/v3.8.30 Jun 20, 2026
diegosouzapw added a commit that referenced this pull request Jun 20, 2026
…4271)

#4271/#4331 updated webSessionCredentials.ts for lmarena's split auth cookie —
new placeholder text and storageKeys arena-auth-prod-v1.0/.1 — but did not update
web-session-credentials.test.ts, which still asserted the old placeholder + 3-key
storageKeys. Align the expected metadata to the merged source; test-only, no prod change.
diegosouzapw added a commit that referenced this pull request Jun 20, 2026
…4271 arena metadata) (#4346)

* test(db-rules): align audited-module count to 28 (apiKey db helpers)

#4335 added apiKeyColumnFallbacks + apiKeyUsageLimitFields to INTENTIONALLY_INTERNAL
(both db-internal, consumed only by db/apiKeys.ts) but did not update the parity test
in check-db-rules-classification.test.ts, which still expected exactly 26 audited
modules — leaving it red on release/v3.8.30 (28 != 26). Add the two modules to the
expected list and bump the count to 28. Test-only alignment; no production change.

* test(web-session): align lmarena metadata to the split-cookie source (#4271)

#4271/#4331 updated webSessionCredentials.ts for lmarena's split auth cookie —
new placeholder text and storageKeys arena-auth-prod-v1.0/.1 — but did not update
web-session-credentials.test.ts, which still asserted the old placeholder + 3-key
storageKeys. Align the expected metadata to the merged source; test-only, no prod change.
@diegosouzapw
diegosouzapw deleted the fix/4271-arena-split-cookie branch June 20, 2026 04:21
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
) (diegosouzapw#4331)

LMArena migrated to @supabase/ssr chunked auth cookies: the single
arena-auth-prod-v1 cookie is now empty and the session is split across
arena-auth-prod-v1.0, .1, … (ascending). Pasting the now-empty single
cookie sent an empty session, which upstream rejected as "invalid cookie".

reconstructLMArenaCookie() rebuilds the single cookie from its chunks
(ascending join, no decode/parse — combineChunks semantics), preserving
the rest of the pasted jar; a non-empty single cookie is forwarded
unchanged (back-compat). The credential UX now instructs pasting the full
Cookie header and tracks the .0/.1 storage keys.

Closes diegosouzapw#4271
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…les count + diegosouzapw#4271 arena metadata) (diegosouzapw#4346)

* test(db-rules): align audited-module count to 28 (apiKey db helpers)

diegosouzapw#4335 added apiKeyColumnFallbacks + apiKeyUsageLimitFields to INTENTIONALLY_INTERNAL
(both db-internal, consumed only by db/apiKeys.ts) but did not update the parity test
in check-db-rules-classification.test.ts, which still expected exactly 26 audited
modules — leaving it red on release/v3.8.30 (28 != 26). Add the two modules to the
expected list and bump the count to 28. Test-only alignment; no production change.

* test(web-session): align lmarena metadata to the split-cookie source (diegosouzapw#4271)

diegosouzapw#4271/diegosouzapw#4331 updated webSessionCredentials.ts for lmarena's split auth cookie —
new placeholder text and storageKeys arena-auth-prod-v1.0/.1 — but did not update
web-session-credentials.test.ts, which still asserted the old placeholder + 3-key
storageKeys. Align the expected metadata to the merged source; test-only, no prod change.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant