Repository navigation
[codex] Fix stale extension auth and GitHub self repo listing - #5034
Conversation
📝 WalkthroughWalkthroughAdds user-facing success messages to ChangesExtension lifecycle success messaging
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Comment |
|
🚅 Deployed to the ironclaw-pr-5034 environment in ironclaw-ci-preview
|
There was a problem hiding this comment.
Code Review
This pull request improves the extension lifecycle flow by adding clear guidance messages to search and activation responses, instructing the model not to prompt users for credentials if an extension is already configured or active. It also updates the activation capability description and corresponding tests. Feedback suggests refining the helper function extension_search_has_ready_result to check for a specific authorization status rather than checking the installation phase directly, preventing unexpected popups.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
| extensions.iter().any(|extension| { | ||
| matches!( | ||
| extension.installation_phase, | ||
| Some(LifecyclePhase::Configured | LifecyclePhase::Active) | ||
| ) && extension.summary.credential_requirements.is_empty() | ||
| && extension.summary.onboarding.is_none() | ||
| }) |
There was a problem hiding this comment.
To avoid unexpected popups, auth flows on extension activation should only be triggered for scope expansion, not for initial tool configuration. This can be achieved by checking for a status like 'awaiting_authorization' instead of checking the installation phase directly.
extensions.iter().any(|extension| {
extension.status == Some(LifecycleStatus::AwaitingAuthorization)
})References
- To avoid unexpected popups, auth flows on extension activation should only be triggered for scope expansion, not for initial tool configuration. This can be achieved by checking for a status like 'awaiting_authorization'.
…#5034) * fix stale extension auth readiness prompts * fix github self repo listing
Summary
auth_required.github.list_reposso authenticated-user requests (usernameomitted,me, or@me) call/user/reposinstead of the public/users/me/reposaccount.Root Cause
extension_searchcorrectly suppressed stale credential requirements/onboarding for configured or active extensions, but it did not provide positive readiness evidence. In already-active flows such as “connect my GitHub”, the model could reuse older PAT onboarding text from prior search/context even though the search result was active and clean.The later GitHub screenshot was a separate tool semantics bug, not a placeholder secret.
github.list_reposrequiredusernameand always queried/users/{username}/repos. When the model usedusername: "me"for “my GitHub repos”, GitHub interpreted that as the literal public userme, so the response showed that account's public repositories even though host credential injection was working.Validation
cargo fmt --all --check./scripts/build-wasm-extensions.sh --first-partycargo test --manifest-path crates/ironclaw_first_party_extensions/assets/github/wasm-src/Cargo.tomlcargo test -p ironclaw_host_runtime --test github_wasm_runtime_contract bundled_github_wasm_builds_create_repo_fork_and_release_requestscargo test -p ironclaw_reborn_composition local_dev_extension_search_hides_onboarding_after_credentialed_activationcargo test -p ironclaw_reborn_composition local_dev_extension_lifecycle_tools_manage_visible_extension_surfacecargo test -p ironclaw_reborn_composition local_dev_extension_activate_returns_auth_gate_when_account_lacks_required_scope