Repository navigation
[codex] Suppress stale extension search credential prompts - #5037
Conversation
|
Caution Review failedAn error occurred during the review process. Please try again later. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughSummary by CodeRabbitBug Fixes
Walkthrough
ChangesSuppress credential onboarding in extension search
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Comment |
|
🚅 Deployed to the ironclaw-pr-5037 environment in ironclaw-ci-preview
|
There was a problem hiding this comment.
Code Review
This pull request refactors the extension lifecycle to suppress credential requirements and onboarding details during extension searches, ensuring they are not exposed before activation. It also updates the activation success messages and capability descriptions to clarify that activated extensions are ready for both read and write-capable tools without requiring further user authorization. Additionally, the test suite has been updated to verify these changes. I have no feedback to provide.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
5fa3beb to
30ad57b
Compare
Summary
extension_searchdiscovery-only by stripping credential requirements/onboarding from model-facing search results.activated=trueexplicitly covers write-capable tools and tells the model not to ask for token/OAuth/config unless a later tool reportsauth_required.Root Cause
After #5034, activation correctly succeeded and reported that no additional authorization was needed, but earlier same-turn
extension_search/installed search results could still carry GitHub PAT onboarding. The model combined that stale setup copy with the activation success and added a bogus “PAT for write operations” caveat. Search should only discover extensions; activation/tool execution should be the only place that asks for credentials.Validation
cargo fmt --all --checkcargo test -p ironclaw_reborn_composition --lib local_dev_extension_search_hides_onboarding_after_credentialed_activationcargo test -p ironclaw_reborn_composition --lib local_dev_extension_lifecycle_tools_manage_visible_extension_surfacecargo test -p ironclaw_reborn_composition --lib local_dev_agent_surface_exposes_extension_lifecycle_toolscargo test -p ironclaw_reborn_composition --lib local_dev_extension_activate_returns_auth_gate_when_account_lacks_required_scope