chore: promote staging to staging-promote/edbf0eaa-24719068222 (2026-04-21 13:10 UTC) - #2786
Conversation
* fix(auth): switch OAuth URL construction to url crate to prevent char loss (#2391) Google OAuth was reportedly receiving `access_type=offlin` instead of `access_type=offline` when users ran `ironclaw tool auth google-calendar`, breaking the offline-token flow every Google WASM tool relies on (Calendar, Gmail, Drive, Docs, Sheets, Slides). The hand-rolled `format!` + `urlencoding::encode` loops in `auth::oauth::build_oauth_url` and `tools::mcp::auth::build_authorization_url` are replaced with `url::Url` + `query_pairs_mut()`, routing every query parameter through a single well-tested `application/x-www-form-urlencoded` serializer. The old concat path is kept as a defensive fallback for the (never-observed-in-practice) case where the authorization URL itself fails to parse. Regression coverage added at the call-site level per `.claude/rules/testing.md`: * `test_build_oauth_url_preserves_access_type_offline_exactly` — parses the returned URL and asserts `access_type == "offline"` exactly (not via `.contains()`, which would have passed on `offlin`). * `test_build_oauth_url_extra_params_preserve_all_chars_across_hash_orderings` — loops 16 iterations so random `HashMap` iteration order surfaces any bug sensitive to which param lands last. * `test_google_calendar_capabilities_produce_correct_oauth_url` — loads the shipped `google-calendar-tool.capabilities.json` shape, parses it via `CapabilitiesFile::from_json`, and drives the same `build_oauth_url` call site that `cli::tool::auth_tool_oauth` uses. * `test_build_authorization_url_extra_params_preserve_all_chars` — parallel regression for the MCP authorization-URL builder. The two pre-existing helper tests were also tightened to round-trip through `url::Url::parse` + `query_pairs()` rather than relying on substring assertions, so a 1-char truncation can no longer pass as a prefix match. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(auth): address PR #2746 review feedback - Reject malformed authorization URLs with a specific error instead of concat-normalizing them (gemini-code-assist review). - Rebuild HashMap per iteration in order-probe tests so different iteration orders are actually exercised (Copilot review). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(auth): surface malformed OAuth descriptors at call sites (#2746) Address review feedback from @serrrfirat on PR #2746: two call sites of `build_pending_oauth_launch` were using `.ok()?` to silently drop `OAuthUrlError::MalformedConfig`, which regressed the fail-closed posture this PR introduced. Replaces `.ok()?` in both: - `AuthManager::start_skill_oauth_if_supported` - `ExtensionManager::start_secret_oauth_flow` with an explicit `match` that emits `tracing::error!` (carrying credential/extension/secret/user context) before falling back to the manual-token path. Operators now get a signal when an OAuth descriptor is misconfigured, rather than seeing the browser auth flow silently disappear. Signatures stay `Option<...>` — the existing `test_build_oauth_url_rejects_malformed_authorization_url` covers the helper-level regression; this change is call-site observability. [skip-regression-check] Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Code reviewFound 3 issues:
https://github.com/anthropics/ironclaw/blob/3921ad3285fd9e6b4b5f5f34c76b9a8c05e4c99e/src/auth/oauth.rs#L217-L225
https://github.com/anthropics/ironclaw/blob/3921ad3285fd9e6b4b5f5f34c76b9a8c05e4c99e/src/bridge/auth_manager.rs#L766-L777 |
Auto-promotion from staging CI
Batch range:
7fb41555a9e55677d1aaea29ca567a5b369c2b05..07972fc0992d74fc0ec97911ededf0ee273097aePromotion branch:
staging-promote/07972fc0-24724183222Base:
staging-promote/edbf0eaa-24719068222Triggered by: Staging CI batch at 2026-04-21 13:10 UTC
Commits in this batch (62):
onboardfails with "Failed to save settings to database", butironclawstarts successfully and applies migrations #846) (fix(setup): run migrations during onboard when DATABASE_URL preset (#846) #2309)Current commits in this promotion (1)
Current base:
staging-promote/edbf0eaa-24719068222Current head:
staging-promote/07972fc0-24724183222Current range:
origin/staging-promote/edbf0eaa-24719068222..origin/staging-promote/07972fc0-24724183222Auto-updated by staging promotion metadata workflow
Waiting for gates:
Auto-created by staging-ci workflow