fix(executors): reconstruct LMArena split auth cookie (#4271) - #4331
Merged
Merged
Conversation
LMArena migrated to @supabase/ssr chunked auth cookies: the single arena-auth-prod-v1 cookie is now empty and the session is split across arena-auth-prod-v1.0, .1, … (ascending). Pasting the now-empty single cookie sent an empty session, which upstream rejected as "invalid cookie". reconstructLMArenaCookie() rebuilds the single cookie from its chunks (ascending join, no decode/parse — combineChunks semantics), preserving the rest of the pasted jar; a non-empty single cookie is forwarded unchanged (back-compat). The credential UX now instructs pasting the full Cookie header and tracks the .0/.1 storage keys. Closes #4271
Contributor
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
diegosouzapw
added a commit
that referenced
this pull request
Jun 20, 2026
…4271) #4271/#4331 updated webSessionCredentials.ts for lmarena's split auth cookie — new placeholder text and storageKeys arena-auth-prod-v1.0/.1 — but did not update web-session-credentials.test.ts, which still asserted the old placeholder + 3-key storageKeys. Align the expected metadata to the merged source; test-only, no prod change.
diegosouzapw
added a commit
that referenced
this pull request
Jun 20, 2026
…4271 arena metadata) (#4346) * test(db-rules): align audited-module count to 28 (apiKey db helpers) #4335 added apiKeyColumnFallbacks + apiKeyUsageLimitFields to INTENTIONALLY_INTERNAL (both db-internal, consumed only by db/apiKeys.ts) but did not update the parity test in check-db-rules-classification.test.ts, which still expected exactly 26 audited modules — leaving it red on release/v3.8.30 (28 != 26). Add the two modules to the expected list and bump the count to 28. Test-only alignment; no production change. * test(web-session): align lmarena metadata to the split-cookie source (#4271) #4271/#4331 updated webSessionCredentials.ts for lmarena's split auth cookie — new placeholder text and storageKeys arena-auth-prod-v1.0/.1 — but did not update web-session-credentials.test.ts, which still asserted the old placeholder + 3-key storageKeys. Align the expected metadata to the merged source; test-only, no prod change.
tkgo11
pushed a commit
to tkgo11/OmniRoute
that referenced
this pull request
Sep 23, 2026
) (diegosouzapw#4331) LMArena migrated to @supabase/ssr chunked auth cookies: the single arena-auth-prod-v1 cookie is now empty and the session is split across arena-auth-prod-v1.0, .1, … (ascending). Pasting the now-empty single cookie sent an empty session, which upstream rejected as "invalid cookie". reconstructLMArenaCookie() rebuilds the single cookie from its chunks (ascending join, no decode/parse — combineChunks semantics), preserving the rest of the pasted jar; a non-empty single cookie is forwarded unchanged (back-compat). The credential UX now instructs pasting the full Cookie header and tracks the .0/.1 storage keys. Closes diegosouzapw#4271
tkgo11
pushed a commit
to tkgo11/OmniRoute
that referenced
this pull request
Sep 23, 2026
…les count + diegosouzapw#4271 arena metadata) (diegosouzapw#4346) * test(db-rules): align audited-module count to 28 (apiKey db helpers) diegosouzapw#4335 added apiKeyColumnFallbacks + apiKeyUsageLimitFields to INTENTIONALLY_INTERNAL (both db-internal, consumed only by db/apiKeys.ts) but did not update the parity test in check-db-rules-classification.test.ts, which still expected exactly 26 audited modules — leaving it red on release/v3.8.30 (28 != 26). Add the two modules to the expected list and bump the count to 28. Test-only alignment; no production change. * test(web-session): align lmarena metadata to the split-cookie source (diegosouzapw#4271) diegosouzapw#4271/diegosouzapw#4331 updated webSessionCredentials.ts for lmarena's split auth cookie — new placeholder text and storageKeys arena-auth-prod-v1.0/.1 — but did not update web-session-credentials.test.ts, which still asserted the old placeholder + 3-key storageKeys. Align the expected metadata to the merged source; test-only, no prod change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #4271
Problem
LMArena migrated to
@supabase/ssrchunked auth cookies: when the session JWT exceeds Supabase's chunk size it splits acrossarena-auth-prod-v1.0,arena-auth-prod-v1.1, … (ascending) and leaves the basearena-auth-prod-v1cookie empty. Our UX told users to copy the singlearena-auth-prod-v1, which now carries no value, so the forwardedCookiehad an empty session → upstream rejected it as "invalid cookie". (Confirmed by a commenter:arena-auth-prod-v1empty,.0/.1populated.)Fix
reconstructLMArenaCookie()inopen-sse/executors/lmarena.tsrebuilds the single cookie from its chunks following Supabase'scombineChunks(ascending.N, plainjoin(""), no base64-decode / no JSON-parse — thebase64-prefix is part of LMArena's token and is kept verbatim), preserving the rest of the pasted jar. A non-empty singlearena-auth-prod-v1is forwarded unchanged (back-compat). Wired into all branches ofreadLMArenaCookie. The credential UX (webSessionCredentials.tsplaceholder/storageKeys,providers.tsauthHint) now instructs pasting the full Cookie header and recognizes the.0/.1keys.Validation (Hard Rule #18)
tests/unit/lmarena-split-cookie-4271.test.ts(7 cases): ascending-chunk reconstruction, single-cookie back-compat, out-of-order paste, jar preservation, empty-base→no-session, storage-keys/placeholder. RED (noreconstructLMArenaCookieexport) → GREEN (27/27 with the existing lmarena suite). Lint 0-err,typecheck:coreclean, no file-size bump.