Skip to content

[codex] Fix stale extension auth and GitHub self repo listing - #5034

Merged
serrrfirat merged 2 commits into
mainfrom
codex/fix-extension-auth-stale-ready
Jun 17, 2026
Merged

serrrfirat merged 2 commits into
mainfrom
codex/fix-extension-auth-stale-ready

Conversation

@serrrfirat

@serrrfirat serrrfirat commented Jun 17, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Add explicit model-visible readiness messages for configured/active extension search results.
  • Add activation success messaging that tells the model no additional auth/config is needed unless a later tool raises auth_required.
  • Fix github.list_repos so authenticated-user requests (username omitted, me, or @me) call /user/repos instead of the public /users/me/repos account.
  • Update GitHub list-repos manifest/prompt/schema and rebuild the bundled GitHub WASM artifact.
  • Cover the stale auth prompt paths and GitHub self-repo listing with regression assertions.

Root Cause

extension_search correctly suppressed stale credential requirements/onboarding for configured or active extensions, but it did not provide positive readiness evidence. In already-active flows such as “connect my GitHub”, the model could reuse older PAT onboarding text from prior search/context even though the search result was active and clean.

The later GitHub screenshot was a separate tool semantics bug, not a placeholder secret. github.list_repos required username and always queried /users/{username}/repos. When the model used username: "me" for “my GitHub repos”, GitHub interpreted that as the literal public user me, so the response showed that account's public repositories even though host credential injection was working.

Validation

  • cargo fmt --all --check
  • ./scripts/build-wasm-extensions.sh --first-party
  • cargo test --manifest-path crates/ironclaw_first_party_extensions/assets/github/wasm-src/Cargo.toml
  • cargo test -p ironclaw_host_runtime --test github_wasm_runtime_contract bundled_github_wasm_builds_create_repo_fork_and_release_requests
  • cargo test -p ironclaw_reborn_composition local_dev_extension_search_hides_onboarding_after_credentialed_activation
  • cargo test -p ironclaw_reborn_composition local_dev_extension_lifecycle_tools_manage_visible_extension_surface
  • cargo test -p ironclaw_reborn_composition local_dev_extension_activate_returns_auth_gate_when_account_lacks_required_scope

@coderabbitai

coderabbitai Bot commented Jun 17, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds user-facing success messages to commit_activation and search responses. Extracts a extension_search_has_ready_result predicate that detects configured/active extensions with no credential requirements or onboarding. Updates the builtin.extension_activate capability description and strengthens test assertions for the new messages.

Changes

Extension lifecycle success messaging

Layer / File(s) Summary
Ready-result predicate and search/activation message wiring
crates/ironclaw_reborn_composition/src/extension_lifecycle.rs
Adds extension_search_has_ready_result helper; search conditionally sets response.message when the payload has a configured/active extension with no credentials or onboarding; commit_activation sets a success message on the activation response.
Capability description update and test assertions
crates/ironclaw_reborn_composition/src/extension_lifecycle_capabilities.rs
Extends builtin.extension_activate description with activated=true ignore-earlier-hints guidance; tests assert description text, activation success message, and "already configured or active" in both configured and active search responses.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • nearai/ironclaw#4996: Directly overlaps — modifies the same extension_lifecycle.rs search logic and onboarding-suppression flow this PR extends with messaging.

Suggested reviewers

  • think-in-universe

Poem

🦀 A search comes back "already set!"
No onboarding nag to cause regret.
activated=true? Ignore the noise.
The message field now ships with poise.
Rust gates the rest — we just add voice.

🚥 Pre-merge checks | ✅ 2 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Title check ⚠️ Warning Title uses non-standard brackets and doesn't follow Conventional Commits format (type(scope): summary). Rewrite as: fix(extension-lifecycle): add readiness messages and fix GitHub self-repo listing
Description check ⚠️ Warning Description includes comprehensive summary and validation but missing Change Type checkboxes, Linked Issue, and Reborn Trust-Boundary checklist. Complete all required sections: check Change Type box(es), add Linked Issue reference, and complete Trust-Boundary checklist items.
✅ Passed checks (2 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions github-actions Bot added size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jun 17, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5034 June 17, 2026 15:23 Destroyed
@railway-app

railway-app Bot commented Jun 17, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5034 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jun 17, 2026 at 3:39 pm

@serrrfirat
serrrfirat marked this pull request as ready for review June 17, 2026 15:24

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request improves the extension lifecycle flow by adding clear guidance messages to search and activation responses, instructing the model not to prompt users for credentials if an extension is already configured or active. It also updates the activation capability description and corresponding tests. Feedback suggests refining the helper function extension_search_has_ready_result to check for a specific authorization status rather than checking the installation phase directly, preventing unexpected popups.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment on lines +1233 to +1239
extensions.iter().any(|extension| {
matches!(
extension.installation_phase,
Some(LifecyclePhase::Configured | LifecyclePhase::Active)
) && extension.summary.credential_requirements.is_empty()
&& extension.summary.onboarding.is_none()
})

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

To avoid unexpected popups, auth flows on extension activation should only be triggered for scope expansion, not for initial tool configuration. This can be achieved by checking for a status like 'awaiting_authorization' instead of checking the installation phase directly.

extensions.iter().any(|extension| {
    extension.status == Some(LifecycleStatus::AwaitingAuthorization)
})
References
  1. To avoid unexpected popups, auth flows on extension activation should only be triggered for scope expansion, not for initial tool configuration. This can be achieved by checking for a status like 'awaiting_authorization'.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5034 June 17, 2026 15:34 Destroyed
@github-actions github-actions Bot added the scope: docs Documentation label Jun 17, 2026
@serrrfirat serrrfirat changed the title [codex] Fix stale extension auth readiness prompts [codex] Fix stale extension auth and GitHub self repo listing Jun 17, 2026
@serrrfirat
serrrfirat merged commit 3d89507 into main Jun 17, 2026
58 of 66 checks passed
@serrrfirat
serrrfirat deleted the codex/fix-extension-auth-stale-ready branch June 17, 2026 15:45
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
…#5034)

* fix stale extension auth readiness prompts

* fix github self repo listing

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5034 — e5efe9c2 Deployed Jun 17, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant