Skip to content

[codex] Suppress stale extension search credential prompts - #5037

Merged
serrrfirat merged 1 commit into
mainfrom
codex/suppress-stale-extension-search-credentials
Jun 19, 2026
Merged

serrrfirat merged 1 commit into
mainfrom
codex/suppress-stale-extension-search-credentials

Conversation

@serrrfirat

@serrrfirat serrrfirat commented Jun 17, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Make extension_search discovery-only by stripping credential requirements/onboarding from model-facing search results.
  • Strengthen activation success copy so activated=true explicitly covers write-capable tools and tells the model not to ask for token/OAuth/config unless a later tool reports auth_required.
  • Add regression coverage for available, installed, configured, and active GitHub search results plus activation descriptor/message behavior.

Root Cause

After #5034, activation correctly succeeded and reported that no additional authorization was needed, but earlier same-turn extension_search/installed search results could still carry GitHub PAT onboarding. The model combined that stale setup copy with the activation success and added a bogus “PAT for write operations” caveat. Search should only discover extensions; activation/tool execution should be the only place that asks for credentials.

Validation

  • cargo fmt --all --check
  • cargo test -p ironclaw_reborn_composition --lib local_dev_extension_search_hides_onboarding_after_credentialed_activation
  • cargo test -p ironclaw_reborn_composition --lib local_dev_extension_lifecycle_tools_manage_visible_extension_surface
  • cargo test -p ironclaw_reborn_composition --lib local_dev_agent_surface_exposes_extension_lifecycle_tools
  • cargo test -p ironclaw_reborn_composition --lib local_dev_extension_activate_returns_auth_gate_when_account_lacks_required_scope

@coderabbitai

coderabbitai Bot commented Jun 17, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

An error occurred during the review process. Please try again later.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 92f3ba9d-be35-4a0f-8b75-d4b4759f097d

📥 Commits

Reviewing files that changed from the base of the PR and between 46c0262 and 30ad57b.

📒 Files selected for processing (2)
  • crates/ironclaw_reborn_composition/src/extension_lifecycle.rs
  • crates/ironclaw_reborn_composition/src/extension_lifecycle_capabilities.rs

📝 Walkthrough

Summary by CodeRabbit

Bug Fixes

  • Extension search results no longer display credential requirements and onboarding information.
  • Extension activation responses now explicitly state that no tokens, OAuth credentials, or authorization configuration should be requested after activation is complete.

Walkthrough

search_summary now unconditionally clears credential_requirements and onboarding on every extension search result via a new suppress_search_credential_onboarding helper, removing the prior conditional that depended on search_setup_is_complete. The ExtensionActivate success message and the builtin.extension_activate capability manifest are updated to explicitly prohibit requesting auth after activated=true. Tests are extended to assert suppression in pre-install and installed-inactive states.

Changes

Suppress credential onboarding in extension search

Layer / File(s) Summary
Unconditional suppression helper and search_summary wiring
crates/ironclaw_reborn_composition/src/extension_lifecycle.rs
Removes search_setup_is_complete; adds suppress_search_credential_onboarding that clears credential_requirements and sets onboarding to None; search_summary calls it before any phase logic. ExtensionActivate success text extended to forbid token/OAuth/config requests after activated=true.
Capability manifest update and test assertions
crates/ironclaw_reborn_composition/src/extension_lifecycle_capabilities.rs
builtin.extension_activate description updated to instruct ignoring earlier search/install onboarding hints unless a later tool call raises auth_required. Test local_dev_extension_search_hides_onboarding_after_credentialed_activation adds a pre-install search step and asserts credential_requirements/onboarding are absent in both available and installed-inactive states.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • nearai/ironclaw#4996: Directly overlaps — modifies RebornLocalExtensionManagementPort search to suppress credential_requirements/onboarding in extension search results, the same code path changed here.
  • nearai/ironclaw#5034: Both PRs touch extension_lifecycle.rs and extension_lifecycle_capabilities.rs to alter ExtensionActivate messaging and onboarding suppression logic.

Suggested reviewers

  • think-in-universe
  • italic-jinxin

Poem

🦀 No token begging, no OAuth pleas,
Once activated=true — do as you please.
Credential fields? Wiped clean, every one.
The helper's unconditional — the old check: done.
Search returns silence where PATs used to speak. 🔇

🚥 Pre-merge checks | ✅ 2 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Title check ⚠️ Warning Title uses descriptive summary without following Conventional Commits style (type(scope): summary format). Reformat title to Conventional Commits style, e.g., 'feat(extension_lifecycle): suppress stale extension search credential prompts'.
Description check ⚠️ Warning Description covers summary, root cause, and validation but omits required Change Type, Linked Issue, Reborn Trust-Boundary Checklist, and Review track sections. Complete missing template sections: select Change Type (likely 'Bug fix'), specify Linked Issue, fill Reborn Trust-Boundary Checklist (critical for credential/auth changes), and indicate Review track (likely 'C').
✅ Passed checks (2 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5037 June 17, 2026 16:41 Destroyed
@railway-app

railway-app Bot commented Jun 17, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5037 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jun 17, 2026 at 7:20 pm

@github-actions github-actions Bot added size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jun 17, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request refactors the extension lifecycle to suppress credential requirements and onboarding details during extension searches, ensuring they are not exposed before activation. It also updates the activation success messages and capability descriptions to clarify that activated extensions are ready for both read and write-capable tools without requiring further user authorization. Additionally, the test suite has been updated to verify these changes. I have no feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5037 June 17, 2026 17:05 Destroyed
@github-actions github-actions Bot added the scope: docs Documentation label Jun 17, 2026
@serrrfirat serrrfirat changed the title [codex] Suppress stale extension search credential prompts [codex] Fix stale extension auth and GitHub identity prompts Jun 17, 2026
@serrrfirat
serrrfirat force-pushed the codex/suppress-stale-extension-search-credentials branch from 5fa3beb to 30ad57b Compare June 17, 2026 19:20
@serrrfirat serrrfirat changed the title [codex] Fix stale extension auth and GitHub identity prompts [codex] Suppress stale extension search credential prompts Jun 17, 2026
@serrrfirat
serrrfirat marked this pull request as ready for review June 17, 2026 19:22
@serrrfirat
serrrfirat merged commit 158366e into main Jun 19, 2026
137 checks passed
@serrrfirat
serrrfirat deleted the codex/suppress-stale-extension-search-credentials branch June 19, 2026 14:57
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5037 — 5fa3beba Deployed Jun 17, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant