Fix hosted OAuth refresh via proxy - #1602
Conversation
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request addresses a critical issue in hosted OAuth deployments by ensuring that access token refreshes are securely handled through a designated proxy. It centralizes the client secret management for Google OAuth, preventing configuration errors, and introduces robust testing to validate the new refresh flow and secret handling mechanisms. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request is a solid improvement, correctly routing hosted OAuth refresh tokens through a proxy. The refactoring to share the client secret suppression logic is clean, and the addition of comprehensive unit and E2E tests significantly boosts confidence in this complex flow. I have one minor suggestion to improve code clarity.
There was a problem hiding this comment.
Pull request overview
Routes hosted OAuth access-token refresh through the configured compose-api proxy and unifies hosted Google client-secret suppression across extension auth setup and WASM OAuth refresh config, with added Rust + Python E2E regression coverage.
Changes:
- Add proxy-based OAuth refresh support (proxy URL + gateway token) for WASM tool OAuth auto-refresh.
- Move/centralize hosted Google baked-in client-secret suppression into
cli::oauth_defaultsand reuse it from both extension manager and WASM loader. - Add Rust unit tests and a Python E2E that forces Gmail token expiry in libSQL and asserts refresh goes through the hosted
/oauth/refreshproxy without forwardingclient_secret.
Reviewed changes
Copilot reviewed 8 out of 8 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
| tests/e2e/scenarios/test_oauth_refresh.py | New hosted-mode E2E covering token expiry + refresh proxy behavior. |
| tests/e2e/mock_llm.py | Adds mock OAuth refresh endpoint + state tracking to assert proxy payloads. |
| tests/e2e/conftest.py | Adds hosted-mode server fixture and refactors coverage env forwarding. |
| tests/e2e/CLAUDE.md | Documents the new E2E scenario and fixture behavior. |
| src/tools/wasm/wrapper.rs | Implements proxy refresh path and persists refreshed tokens; adds unit coverage with mock proxy. |
| src/tools/wasm/loader.rs | Resolves proxy refresh config (proxy URL + gateway token) for WASM tools; adds unit tests. |
| src/extensions/manager.rs | Switches to shared hosted client-secret suppression helper. |
| src/cli/oauth_defaults.rs | Adds shared hosted-secret suppression + refresh-via-proxy helper and unit tests. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 8 out of 8 changed files in this pull request and generated no new comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
@claude review |
* Fix hosted OAuth refresh via proxy * Address OAuth refresh review feedback * Address new OAuth refresh review comments * Address additional OAuth refresh review feedback * Harden proxy exchange redirects
* Fix hosted OAuth refresh via proxy * Address OAuth refresh review feedback * Address new OAuth refresh review comments * Address additional OAuth refresh review feedback * Harden proxy exchange redirects
Summary
Testing