Skip to content

Fix hosted OAuth refresh via proxy - #1602

Merged
henrypark133 merged 6 commits into
stagingfrom
codex/hosted-oauth-refresh-proxy
Mar 24, 2026
Merged

henrypark133 merged 6 commits into
stagingfrom
codex/hosted-oauth-refresh-proxy

Conversation

@henrypark133

Copy link
Copy Markdown
Collaborator

Summary

  • route hosted OAuth access-token refreshes through the compose-api proxy instead of posting directly to the provider
  • share the hosted Google client-secret suppression logic between extension auth setup and WASM refresh config resolution
  • add Rust unit coverage plus a Python HTTP E2E that expires a stored Gmail token in libSQL and verifies the hosted refresh proxy request

Testing

  • cargo fmt --check
  • cargo clippy --all --benches --tests --examples -- -D warnings
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings
  • cargo clippy --all --benches --tests --examples --no-default-features --features libsql -- -D warnings
  • cargo test oauth_defaults::tests --lib
  • cargo test loader::tests --lib
  • cargo test wrapper::tests --lib
  • tests/e2e/.venv/bin/python -m pytest tests/e2e/scenarios/test_oauth_refresh.py -q

Copilot AI review requested due to automatic review settings March 23, 2026 19:08
@github-actions github-actions Bot added scope: channel/cli TUI / CLI channel scope: tool/wasm WASM tool sandbox scope: extensions Extension management scope: docs Documentation size: XL 500+ changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Mar 23, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses a critical issue in hosted OAuth deployments by ensuring that access token refreshes are securely handled through a designated proxy. It centralizes the client secret management for Google OAuth, preventing configuration errors, and introduces robust testing to validate the new refresh flow and secret handling mechanisms.

Highlights

  • Hosted OAuth Refresh Routing: Hosted OAuth access-token refreshes are now routed through the compose-api proxy instead of directly posting to the provider, enhancing security and control over the refresh process.
  • Shared Client Secret Suppression Logic: The logic for suppressing the baked-in Google client-secret has been unified and shared between the extension authentication setup and WASM refresh configuration resolution, preventing client ID/secret mismatches in hosted deployments.
  • Comprehensive Testing: New Rust unit tests cover the client secret suppression and proxy refresh functionality, complemented by a Python HTTP E2E test that simulates an expired Gmail token refresh via the hosted proxy.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request is a solid improvement, correctly routing hosted OAuth refresh tokens through a proxy. The refactoring to share the client secret suppression logic is clean, and the addition of comprehensive unit and E2E tests significantly boosts confidence in this complex flow. I have one minor suggestion to improve code clarity.

Comment thread src/tools/wasm/wrapper.rs

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Routes hosted OAuth access-token refresh through the configured compose-api proxy and unifies hosted Google client-secret suppression across extension auth setup and WASM OAuth refresh config, with added Rust + Python E2E regression coverage.

Changes:

  • Add proxy-based OAuth refresh support (proxy URL + gateway token) for WASM tool OAuth auto-refresh.
  • Move/centralize hosted Google baked-in client-secret suppression into cli::oauth_defaults and reuse it from both extension manager and WASM loader.
  • Add Rust unit tests and a Python E2E that forces Gmail token expiry in libSQL and asserts refresh goes through the hosted /oauth/refresh proxy without forwarding client_secret.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
tests/e2e/scenarios/test_oauth_refresh.py New hosted-mode E2E covering token expiry + refresh proxy behavior.
tests/e2e/mock_llm.py Adds mock OAuth refresh endpoint + state tracking to assert proxy payloads.
tests/e2e/conftest.py Adds hosted-mode server fixture and refactors coverage env forwarding.
tests/e2e/CLAUDE.md Documents the new E2E scenario and fixture behavior.
src/tools/wasm/wrapper.rs Implements proxy refresh path and persists refreshed tokens; adds unit coverage with mock proxy.
src/tools/wasm/loader.rs Resolves proxy refresh config (proxy URL + gateway token) for WASM tools; adds unit tests.
src/extensions/manager.rs Switches to shared hosted client-secret suppression helper.
src/cli/oauth_defaults.rs Adds shared hosted-secret suppression + refresh-via-proxy helper and unit tests.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/tools/wasm/loader.rs Outdated
Comment thread src/tools/wasm/wrapper.rs
Comment thread src/cli/oauth_defaults.rs

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/tools/wasm/loader.rs Outdated
Comment thread src/tools/wasm/wrapper.rs Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/cli/oauth_defaults.rs
Comment thread src/tools/wasm/wrapper.rs Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/cli/oauth_defaults.rs

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated no new comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@nickpismenkov

Copy link
Copy Markdown
Contributor

@claude review

@henrypark133
henrypark133 merged commit dcb2d89 into staging Mar 24, 2026
18 checks passed
@henrypark133
henrypark133 deleted the codex/hosted-oauth-refresh-proxy branch March 24, 2026 20:51
bkutasi pushed a commit to bkutasi/ironclaw that referenced this pull request Mar 28, 2026
* Fix hosted OAuth refresh via proxy

* Address OAuth refresh review feedback

* Address new OAuth refresh review comments

* Address additional OAuth refresh review feedback

* Harden proxy exchange redirects
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
* Fix hosted OAuth refresh via proxy

* Address OAuth refresh review feedback

* Address new OAuth refresh review comments

* Address additional OAuth refresh review feedback

* Harden proxy exchange redirects
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: channel/cli TUI / CLI channel scope: docs Documentation scope: extensions Extension management scope: tool/wasm WASM tool sandbox size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants