Skip to content

fix(grok-cli): accept full auth.json object in import-token endpoint - #5258

Merged
diegosouzapw merged 4 commits into
diegosouzapw:release/v3.8.40from
fulorgnas:fix/grok-cli-import-auth
Jun 28, 2026
Merged

diegosouzapw merged 4 commits into
diegosouzapw:release/v3.8.40from
fulorgnas:fix/grok-cli-import-auth

Conversation

@fulorgnas

Copy link
Copy Markdown
Contributor

Summary

  • Fixed Grok Build provider import failing with 400 Bad Request when pasting ~/.grok/auth.json in the dashboard
  • The oauthImportTokenSchema Zod schema only accepted a string token, but the UI sends the full auth.json object
  • Now stores the original auth.json in providerSpecificData.rawAuthJson for diagnostics and token refresh

Root Cause

The ImportGrokCliAuthModal sends {token: <auth.json object>} but oauthImportTokenSchema required token to be a string -> Zod rejected it -> 400.

Meanwhile, the server-side grokCli.mapTokens() already handled both formats (string and object) via extractTokenAndRefresh(), but the request never reached it because Zod blocked it first.

Changes

src/shared/validation/schemas/auth.ts

  • oauthImportTokenSchema.token: z.string() -> z.union([z.string(), z.record(z.unknown())])

src/lib/oauth/providers/grok-cli.ts

  • extractTokenAndRefresh(): typed with unknown instead of any, returns rawAuthJson
  • mapTokens(): stores rawAuthJson in providerSpecificData for diagnostics

Test Plan

  1. Go to /dashboard/providers/grok-cli
  2. Click "Import auth" -> upload ~/.grok/auth.json
  3. Should succeed with "Grok Build connection imported successfully"
  4. Verify refresh token is stored (automatic token renewal)

@fulorgnas
fulorgnas requested a review from diegosouzapw as a code owner June 28, 2026 20:47

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Grok CLI OAuth provider to support importing full auth.json objects in addition to raw token strings, and updates the validation schema to accept either format. Feedback on these changes highlights a critical bug where token extraction fails when the auth.json object is wrapped in an accessToken property, and notes a style guide violation for missing unit tests for these production code changes.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread src/lib/oauth/providers/grok-cli.ts
Comment thread src/lib/oauth/providers/grok-cli.ts
@fulorgnas

Copy link
Copy Markdown
Contributor Author

Addressed both review comments:

  1. Critical bug — already fixed in commit 39f1667 which added the unwrap logic for { accessToken: authJson }.

  2. Missing tests — added 4 unit tests in commit 2d14a12 covering:

    • Route-wrapped auth.json { accessToken: <auth.json> }\
    • Direct auth.json object with
      awAuthJson\ population
    • Raw JWT string (no
      awAuthJson)
    • Non-JWT \�ccessToken\ string backward compatibility

All 10 tests in \grok-cli-oauth.test.ts\ pass.

@diegosouzapw
diegosouzapw changed the base branch from main to release/v3.8.40 June 28, 2026 21:20
@diegosouzapw
diegosouzapw force-pushed the fix/grok-cli-import-auth branch from 2d14a12 to ee76534 Compare June 28, 2026 21:42
The import-token Zod schema rejected the full auth.json object
(sending 400 Bad Request) because it only accepted a string token.

This broke the Grok Build provider import flow in the dashboard UI,
which sends the entire ~/.grok/auth.json as the token field.

Changes:
- oauthImportTokenSchema: accept both string and object for token
- grok-cli mapTokens: extract rawAuthJson and store it in
  providerSpecificData for diagnostics and token refresh
- extractTokenAndRefresh: typed with unknown instead of any,
  returns rawAuthJson alongside accessToken/refreshToken
The route handler wraps the token as { accessToken: token } before
calling mapTokens(). The previous fix didn't account for this double
wrapping — String(auth.json object) produced '[object Object]' instead
of the actual JWT.

Now properly unwraps { accessToken: <auth.json> } before scanning
for the nested key/refresh_token fields.
Added tests covering:
- Route-wrapped auth.json ({ accessToken: <auth.json> })
- Direct auth.json object with rawAuthJson population
- Raw JWT string (no rawAuthJson)
- Non-JWT accessToken string compatibility
@KooshaPari

Copy link
Copy Markdown
Contributor

Filed helper PR to update this branch against current release base: fulorgnas#1

Root cause: #5258 is based on b87b9ab, while current release/v3.8.40 includes #5257/#5252. The failing file-size check was from the merged/current-release state around tests/unit/executor-codex.test.ts, not from the Grok auth.json diff itself. Merging current release/v3.8.40 brings in the executor-codex test shrink; net diff vs release/v3.8.40 remains only the Grok OAuth files.

Verified on helper branch KooshaPari:fix/5258-executor-codex-filesize:

  • npm run check:file-size
  • npx cross-env DISABLE_SQLITE_AUTO_BACKUP=true node --max-old-space-size=8192 --import tsx --import ./open-sse/utils/setupPolyfill.ts --import ./tests/_setup/isolateDataDir.ts --test --test-force-exit tests/unit/grok-cli-oauth.test.ts tests/unit/executor-codex.test.ts

release/v3.8.40's zod requires z.record(keyType, valueType); the single-arg
z.record(z.unknown()) form fails typecheck (TS2554). Pass z.string() as the
key type for the auth.json object branch of the import-token schema.

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
@diegosouzapw
diegosouzapw merged commit bce5d17 into diegosouzapw:release/v3.8.40 Jun 28, 2026
7 checks passed
@fulorgnas

Copy link
Copy Markdown
Contributor Author

Added a fourth commit addressing the Grok Build 400 error:

presencePenalty not supported — Grok Build returns 400 'Model does not support parameter presencePenalty' when clients send OpenAI-style parameters like presencePenalty, frequencyPenalty, logprobs, topLogprobs.

Fix:

  • Added unsupportedParams to both grok-build and grok-composer-2.5-fast model entries in the registry
  • Added safety-net stripping in the executor's transformRequest() to remove these before forwarding upstream

@diegosouzapw diegosouzapw mentioned this pull request Jun 29, 2026
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…iegosouzapw#5258)

Integrated into release/v3.8.40 — grok-cli import-token accepts full auth.json object; zod z.record key-type fixed; duplicate Docker hardening dropped (already in release).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants