Repository navigation
app sign-ins confirm the account, so sign out then sign in can pick another one - #16661
Conversation
|
All contributors have signed the CLA ✍️ ✅ |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (2)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe sign-in handler now identifies app-directed return targets and passes that status, along with initial sign-in state, to entry selection. Signed-in app sign-ins select an account unless the user just signed in on the page or is returning from OAuth. ChangesApp sign-in account selection
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to No actionable issue is established that prevents merging. The existing-session hard-reload behavior remains unverified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change generally adds account confirmation for app sign-ins, while keeping separate checks on where session credentials can be returned. No credential-return bypass was established. Some uncertainty remains about distinguishing a completed sign-in from other session changes and recovering from a failed account switch. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Merge receipt for |
541c735 fix(remote): reject unknown Eternal Terminal equals options (manaflow-ai#15987) ecb963b fix(cli): reject trailing remotes list/remove arguments (manaflow-ai#15978) 17a8a94 ci: pass the frame pacing fling count as an argument (manaflow-ai#16617) aa6f57e app sign-ins confirm the account, so sign out then sign in can pick another one (manaflow-ai#16661) 4adc8e4 Fix updater readiness wait reset loop (manaflow-ai#16664) 6f77178 Keep only Invite in Cloud sidebar header (manaflow-ai#16636) 72f2915 notify: add --desktop flag to post to the panel without a native banner (manaflow-ai#14688) 4ba0d8a Expose per-surface prompt and unread state to custom sidebars (manaflow-ai#11142) b3da20c Allow browser drags across Cloud workspaces (manaflow-ai#16390) 6529dfd Stop retrying Cloud terminals on stale replay daemons (manaflow-ai#16327) b10f7e2 test: create the requested cwd in the stale-reported split test (manaflow-ai#16653) 9b5b35f Fix Computer Use onboarding readiness after permissions are granted (manaflow-ai#14281) c45da7e Merge pull request manaflow-ai#16623 from manaflow-ai/fix-ios-cloudvpn-appstore-signing 6e67724 fix: close CloudVPN profile and identity gaps 7e9d6ab fix: sign CloudVPN in App Store exports 1984d1e test: cover App Store CloudVPN signing # Conflicts: # .github/workflows/cmux-next-frame-pacing.yml # .github/workflows/ios-app-store.yml # .github/workflows/ios-appstore-upload.yml
Summary
follow-up to #16364, from Austin: signing out in the app and signing in again lands straight back in the same account. the app's sign-out only signs the app out; the browser's cmux.com session stays (on purpose, the same as Slack or Figma desktop), so the sign-in page sees a signed-in browser and continues. only Switch Account asked for the chooser.
now any sign-in started by the Mac app shows the account chooser when the browser is already signed in: "continue as you" in one click, or use another account. so sign out, sign in, chooser.
prompt: after-sign-in with the app's callback and that attempt'scmux_auth_state(signInIsForApp). that survives detours wherepromptgets dropped, like a cancelled Google sign-in going through the auth-error page's "back to sign in".cmux_continue), restricted accounts (onboarding first), and the in-app pricing webview, whose callback has no attempt state and gets after-sign-in's own confirmation as before.web only, so it ships with the web deploy and applies to the app builds people already have.
Testing
bun test tests/sign-in-entry.test.ts tests/after-sign-in-route.test.ts tests/app-pricing-page.test.tsx tests/account-sessions.test.ts: 99 pass. new tests cover the app rule, the just-signed-in guard, andsignInIsForAppfor app, web, pricing and malformed targets.bun run typecheck, eslint and the oxlint complexity check clean.cmux-dev-*://auth-callback); the auth-error page's back link still shows the chooser; a web sign-in while signed in still continues; the pricing webview target still skips it.Changelog
Fixed: Signing in again after signing out of the app now asks which account to use instead of signing back in to the same one
Demo Video
Checklist
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Signing in again after signing out of the Mac app now shows the account chooser instead of returning to the same account.
after-sign-inwithcmux_auth_state) rather thanprompt, so it works even after detours like a cancelled Google sign-in.Written for commit 11fc4a0. Summary will update on new commits.
Summary by CodeRabbit