fix(grok-cli): accept full auth.json object in import-token endpoint - #5258
diegosouzapw merged 4 commits into
Conversation
There was a problem hiding this comment.
Code Review
This pull request updates the Grok CLI OAuth provider to support importing full auth.json objects in addition to raw token strings, and updates the validation schema to accept either format. Feedback on these changes highlights a critical bug where token extraction fails when the auth.json object is wrapped in an accessToken property, and notes a style guide violation for missing unit tests for these production code changes.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
|
Addressed both review comments:
All 10 tests in \grok-cli-oauth.test.ts\ pass. |
2d14a12 to
ee76534
Compare
The import-token Zod schema rejected the full auth.json object (sending 400 Bad Request) because it only accepted a string token. This broke the Grok Build provider import flow in the dashboard UI, which sends the entire ~/.grok/auth.json as the token field. Changes: - oauthImportTokenSchema: accept both string and object for token - grok-cli mapTokens: extract rawAuthJson and store it in providerSpecificData for diagnostics and token refresh - extractTokenAndRefresh: typed with unknown instead of any, returns rawAuthJson alongside accessToken/refreshToken
The route handler wraps the token as { accessToken: token } before
calling mapTokens(). The previous fix didn't account for this double
wrapping — String(auth.json object) produced '[object Object]' instead
of the actual JWT.
Now properly unwraps { accessToken: <auth.json> } before scanning
for the nested key/refresh_token fields.
Added tests covering:
- Route-wrapped auth.json ({ accessToken: <auth.json> })
- Direct auth.json object with rawAuthJson population
- Raw JWT string (no rawAuthJson)
- Non-JWT accessToken string compatibility
ee76534 to
ae652e4
Compare
|
Filed helper PR to update this branch against current release base: fulorgnas#1 Root cause: #5258 is based on b87b9ab, while current release/v3.8.40 includes #5257/#5252. The failing file-size check was from the merged/current-release state around tests/unit/executor-codex.test.ts, not from the Grok auth.json diff itself. Merging current release/v3.8.40 brings in the executor-codex test shrink; net diff vs release/v3.8.40 remains only the Grok OAuth files. Verified on helper branch KooshaPari:fix/5258-executor-codex-filesize:
|
release/v3.8.40's zod requires z.record(keyType, valueType); the single-arg z.record(z.unknown()) form fails typecheck (TS2554). Pass z.string() as the key type for the auth.json object branch of the import-token schema. Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
|
Added a fourth commit addressing the Grok Build 400 error:
Fix:
|
…iegosouzapw#5258) Integrated into release/v3.8.40 — grok-cli import-token accepts full auth.json object; zod z.record key-type fixed; duplicate Docker hardening dropped (already in release).
Summary
400 Bad Requestwhen pasting~/.grok/auth.jsonin the dashboardoauthImportTokenSchemaZod schema only accepted a string token, but the UI sends the full auth.json objectproviderSpecificData.rawAuthJsonfor diagnostics and token refreshRoot Cause
The
ImportGrokCliAuthModalsends{token: <auth.json object>}butoauthImportTokenSchemarequiredtokento be a string -> Zod rejected it -> 400.Meanwhile, the server-side
grokCli.mapTokens()already handled both formats (string and object) viaextractTokenAndRefresh(), but the request never reached it because Zod blocked it first.Changes
src/shared/validation/schemas/auth.tsoauthImportTokenSchema.token:z.string()->z.union([z.string(), z.record(z.unknown())])src/lib/oauth/providers/grok-cli.tsextractTokenAndRefresh(): typed withunknowninstead ofany, returnsrawAuthJsonmapTokens(): storesrawAuthJsoninproviderSpecificDatafor diagnosticsTest Plan
/dashboard/providers/grok-cli~/.grok/auth.json