Skip to content

fix(reborn): guide Google OAuth refresh setup - #5054

Closed
serrrfirat wants to merge 6 commits into
mainfrom
codex/require-google-oauth-refresh-token
Closed

serrrfirat wants to merge 6 commits into
mainfrom
codex/require-google-oauth-refresh-token

Conversation

@serrrfirat

@serrrfirat serrrfirat commented Jun 17, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • keep Google OAuth callbacks non-blocking when the provider omits a refresh token
  • add Google OAuth auth-prompt guidance that tells the agent/user to use the consent link for offline access and reconnect if tokens expire after about an hour
  • cover both the access-only callback behavior and the WebUI projection prompt text

Tests

  • cargo fmt --check
  • git diff --check
  • CARGO_INCREMENTAL=0 cargo test -p ironclaw_reborn_composition --lib oauth_provider_client::tests::google_exchange_allows_access_only_response_without_blocking_callback
  • CARGO_INCREMENTAL=0 cargo test -p ironclaw_reborn_composition --lib projection::tests::turn_stream_auth::webui_event_stream_creates_google_oauth_prompt_for_runtime_credential_gate
  • CARGO_INCREMENTAL=0 cargo clippy -p ironclaw_reborn_composition --lib -- -D warnings

Note: I did not rerun all-targets clippy after this update because this worktree filesystem had only ~116 MB free during verification; the broad all-targets test build failed on disk exhaustion before any code assertion ran. I cleaned generated Cargo incremental artifacts and ran the targeted library checks above.

@railway-app

railway-app Bot commented Jun 17, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5054 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jun 18, 2026 at 10:07 am

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5054 June 17, 2026 22:40 Destroyed
@github-actions github-actions Bot added size: S 10-49 changed lines risk: low Changes to docs, tests, or low-risk modules labels Jun 17, 2026
@coderabbitai

coderabbitai Bot commented Jun 17, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a GOOGLE_OAUTH_REFRESH_GUIDANCE constant and refactors auth_prompt_view_for_blocked_auth to conditionally append it to the prompt body when a Google OAuth requirement is detected (via two new internal helpers). A new test verifies access-token-only Google callback exchange succeeds with no refresh secret stored. Prompt body assertions are extended and a mixed-credential negative test is added. A static HTML preview page is included.

Changes

Google OAuth access-only exchange and refresh guidance

Layer / File(s) Summary
Refresh guidance constant and auth prompt injection
crates/ironclaw_reborn_composition/src/auth_prompt.rs, docs/drafts/previews/pr-5054-google-oauth-auth-prompt.html
Defines GOOGLE_OAUTH_REFRESH_GUIDANCE, refactors auth_prompt_view_for_blocked_auth to compute the view then wrap it with with_google_oauth_refresh_guidance, and introduces is_google_oauth_requirement. HTML preview reflects the injected guidance text.
Access-only exchange and prompt body tests
crates/ironclaw_reborn_composition/src/oauth_provider_client/tests.rs, crates/ironclaw_reborn_composition/src/projection/tests/turn_stream_auth.rs
New test confirms exchange succeeds when refresh_token is absent and no refresh handle is written to the secret store. Existing Google OAuth prompt test gains body-text assertions; new mixed-credential test asserts guidance is absent when GitHub manual token requirements coexist.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • nearai/ironclaw#4957: Modifies the same auth_prompt.rs to differentiate OAuth vs. manual-token credential rendering and adds WebUI auth-prompt tests around Google OAuth gating.

Suggested reviewers

  • think-in-universe
  • zetyquickly

Poem

🔑 No refresh? No fright—access alone will do,
The prompt now whispers guidance, Google-blue.
Mixed creds stay silent, no hint of offline cheer,
The secret store writes once—the log is clear.
One token suffices; the gate swings open here. 🚪

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning PR description is complete with summary, validation steps, and test output, but missing Linked Issue, Change Type checkboxes, and template sections required by repo standards. Add Change Type checkboxes (New feature likely), Linked Issue reference, and complete remaining template sections including Security Impact, Reborn Trust-Boundary Checklist, Database Impact, Blast Radius, Rollback Plan, Review Track, and Review Follow-Through.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed Title follows Conventional Commits style (fix scope: summary) and clearly describes the main change: Google OAuth refresh guidance.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Jun 17, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a new configuration field requires_refresh_token_on_exchange to HostOAuthProviderSpec to enforce the presence of a refresh token during the OAuth token exchange process. This is enabled for Google but disabled for Notion. Additionally, a check has been added to HostOAuthProviderClient::exchange_callback to return a TokenExchangeFailed error if a required refresh token is missing, and a corresponding unit test has been added to verify this behavior. There are no review comments, so I have no feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5054 June 17, 2026 22:50 Destroyed
@serrrfirat serrrfirat changed the title fix(reborn): require Google OAuth refresh tokens fix(reborn): guide Google OAuth refresh setup Jun 17, 2026
@github-actions github-actions Bot added size: M 50-199 changed lines and removed size: S 10-49 changed lines labels Jun 17, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_reborn_composition/src/auth_prompt.rs`:
- Around line 181-184: The Google OAuth refresh guidance is being appended
whenever any credential requirement is Google OAuth, but this is inconsistent
with the logic in auth_prompt_from_credential_requirement which only derives
provider-specific fields when there is exactly one requirement. This causes
Google-specific instructions to be added to prompts in multi-requirement
scenarios where multiple providers are involved. Modify the condition that calls
with_google_oauth_refresh_guidance to also verify that credential_requirements
has exactly one requirement, similar to the check performed around line 160, so
that Google-specific guidance is only injected when Google OAuth is the sole
requirement.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 1379c17d-e57b-4f07-b8eb-7dcf7b6632cf

📥 Commits

Reviewing files that changed from the base of the PR and between 64f03be and 92ca6ed.

📒 Files selected for processing (3)
  • crates/ironclaw_reborn_composition/src/auth_prompt.rs
  • crates/ironclaw_reborn_composition/src/oauth_provider_client/tests.rs
  • crates/ironclaw_reborn_composition/src/projection/tests/turn_stream_auth.rs

Comment thread crates/ironclaw_reborn_composition/src/auth_prompt.rs Outdated
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5054 June 18, 2026 08:30 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5054 June 18, 2026 09:54 Destroyed
@github-actions github-actions Bot added size: L 200-499 changed lines scope: docs Documentation and removed size: M 50-199 changed lines labels Jun 18, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5054 June 18, 2026 10:00 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5054 June 18, 2026 10:07 Destroyed
@github-actions github-actions Bot added size: M 50-199 changed lines and removed size: L 200-499 changed lines labels Jun 18, 2026
@serrrfirat serrrfirat closed this Jul 2, 2026

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5054 — f6937e0e Deployed Jun 18, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant