Skip to content

refactor(composition): group product-auth cluster under product_auth/ (dissection n4) - #5686

Merged
serrrfirat merged 4 commits into
mainfrom
reborn/composition-dissection-pr-n4
Jul 7, 2026
Merged

serrrfirat merged 4 commits into
mainfrom
reborn/composition-dissection-pr-n4

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

What this is

Dissection n4 — step 4 of the composition internal-module plan (docs/plans/2026-07-02-reborn-internal-module-refactor.md §3, on main). Pure behavior-preserving module move: the product-auth cluster (~23k lines, 57 files) groups under one internal product_auth/ module, mirroring the pattern #5585 established for observability//outbound//support/.

Draft while the verification tail (full composition test suite + ingress + architecture + clippy all-features) finishes locally — will be marked ready on the green report. Check matrix (full-feature / default / no-default), reborn_cli, fmt, and the public-API freeze have already passed.

Mapping

New module Absorbs
product_auth::api auth.rs, auth_prompt.rs, auth_dcr_tests.rs
product_auth::oauth oauth_dcr(.rs/_protocol), oauth_gate.rs, oauth_provider_client (+tests), google_oauth/, notion_oauth.rs
product_auth::durable product_auth_durable + its 8 submodules
product_auth::serve product_auth_serve/ (cfg-gated webui-v2-beta)
product_auth::credentials product_auth_runtime_credentials (+tests), product_auth_providers.rs, product_auth_refresh_lock.rs, credential_refresh_worker.rs, manual_token_flow.rs

Deliberately NOT absorbed (other domains per the plan): profile_approval_authorization (runtime-profile policy — root), extension_activation_credentials + extension_credential_requirements (extension_host, n7), input.rs (build config), nearai_login_serve (llm_admin, n6).

API stability

Crate-root pub use blocks re-pointed 1:1 — exported item set byte-identical (verified against composition-pubuse.snapshot). The snapshot file is updated in this PR for the path re-points and to pick up AttachmentTestSupport, which landed on main after the baseline was generated. Architecture boundary tests: path updates only, no assertion changes.

Sequence

Includes a fresh-main merge (post-#5593) with fallout sweep (zero stale-path references). Next in the series: n5 projection → n6 llm_admin → n7 extension_host → n8 slack → n9 automation → n10 webui → n11 root collapse.

🤖 Generated with Claude Code

serrrfirat and others added 2 commits July 6, 2026 12:34
… (dissection n4)

Step 4 of the composition dissection (docs/plans/2026-07-02-reborn-internal-module-refactor.md §3).
Pure module move — no behavior change, crate public API unchanged (crate-root
pub use re-pointed 1:1; composition-pubuse.snapshot updated for the re-points
and to pick up AttachmentTestSupport, which landed on main after the baseline).

Mapping:
- product_auth::api          <- auth.rs, auth_prompt.rs, auth_dcr_tests.rs
- product_auth::oauth        <- oauth_dcr(.rs/_protocol.rs), oauth_gate.rs, oauth_provider_client(+tests), google_oauth/, notion_oauth.rs
- product_auth::durable      <- product_auth_durable(+8 submodules)
- product_auth::serve        <- product_auth_serve/ (cfg-gated webui-v2-beta)
- product_auth::credentials  <- product_auth_runtime_credentials(+tests), product_auth_providers.rs, product_auth_refresh_lock.rs, credential_refresh_worker.rs, manual_token_flow.rs

Deliberately NOT absorbed (other domains per the plan): profile_approval_authorization
(runtime-profile policy), extension_activation_credentials + extension_credential_requirements
(extension_host, n7), input.rs (build config), nearai_login_serve (llm_admin, n6).
Architecture boundary tests: path updates only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ironloopai

ironloopai Bot commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

❌ IronLoop Review Status

Head: 333a0024a9555a26d465086048f5bbea36921c8f
Result: Reviewer planning is blocked by the trusted agent configuration.
Next: Fix the target repository's .ironloop/agents.yaml and agent instruction files, then re-run @ironloopai review or update the pull request.
Updated: 2026-07-07T09:08:40.638Z

Stage Status Detail
received reached GitHub delivered the event to IronLoop.
admitted reached The event passed routing and authorization.
config blocked Trusted agent config is invalid: Invalid type: Expected Object but received true
reviewer jobs pending No reviewer jobs were queued because configuration loading failed.
Configuration error

Message: Trusted agent config is invalid: Invalid type: Expected Object but received true

  • reviewers.0.auto_review: Invalid type: Expected Object but received true
Available commands
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent-id-or-alias>
  • @ironloopai status
Run metadata

Origin: auto
Event: pull_request.synchronize
Config path: .ironloop/agents.yaml
Trusted ref: ca88418d89e672c4bee1829f97d2b133797dd11c
Delivery: 70b911b0-79e3-11f1-8b3d-a9822a47107c

@coderabbitai

coderabbitai Bot commented Jul 6, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f146a61f-e88e-4cd0-8527-09748ae1e434

📥 Commits

Reviewing files that changed from the base of the PR and between 18497d2 and 333a002.

📒 Files selected for processing (3)
  • crates/ironclaw_reborn_composition/src/product_auth/credentials/credential_refresh_worker.rs
  • docs/extensions/building-a-tool.md
  • docs/reborn/contracts/auth-product.md

📝 Walkthrough

Summary by CodeRabbit

  • Refactor
    • Reorganized the authentication/OAuth module layout and updated how runtime credential resolution and the credential refresh worker are wired internally.
    • Updated public crate re-exports so auth challenge components are now exposed from the revised auth-prompt location.
  • Tests
    • Updated dependency-boundary checks and test imports to reflect the new module structure.
  • Documentation
    • Refreshed the crate public export snapshot and related guidance to match the new module grouping and feature-gated exports.

Walkthrough

Moves Reborn composition auth/OAuth/credential code under product_auth::*, rewires internal imports and crate-root re-exports, widens flow_secret_handle visibility, and updates the boundary test plus docs/snapshot references to the new paths.

Changes

product_auth restructure

Layer / File(s) Summary
New product_auth module tree declarations
crates/ironclaw_reborn_composition/src/product_auth/mod.rs, .../api/mod.rs, .../credentials/mod.rs, .../oauth/mod.rs, .../lib.rs
Declares the new product_auth module cluster and moves crate-root auth re-exports to the new namespace.
Auth API and auth_prompt path updates
.../product_auth/api/auth.rs, .../product_auth/api/auth_dcr_tests.rs, .../projection/turn_events.rs, .../slack_delivery.rs, .../product_auth/serve/mod.rs, .../product_auth/serve/oauth.rs, .../product_auth/serve/oauth_start_tests.rs, .../factory/auth_tests.rs
Rewires auth API, prompt, and related test imports to product_auth::api::*.
OAuth provider module path updates
.../input.rs, .../product_auth/oauth/*, .../projection/tests/turn_stream_auth.rs, .../test_support/oauth_product_auth.rs
Redirects Google, Notion, DCR, provider-client, and OAuth gate imports and test construction to product_auth::oauth::*.
Runtime credentials selection path updates
.../extension_activation_credentials.rs, .../extension_lifecycle.rs, .../extension_lifecycle_capabilities.rs, .../extension_lifecycle_capabilities_auth_tests.rs, .../gsuite.rs, .../lifecycle.rs, .../webui_extension_credentials.rs, .../runtime.rs, .../runtime/local_dev/tests.rs, .../product_auth/durable/tests.rs
Repoints runtime credential selection trait, request, and visibility imports to product_auth::credentials::runtime_credentials.
Durable auth and credential refresh worker/lock path updates
.../factory.rs, .../product_auth/credentials/*, .../runtime.rs, .../test_support/oauth_product_auth.rs
Repoints filesystem auth services, credential refresh worker wiring, leader-lock types, and supporting test harness code to product_auth::durable and product_auth::credentials paths.
Boundary test and public re-export snapshot updates
crates/ironclaw_architecture/tests/reborn_dependency_boundaries.rs, docs/plans/composition-pubuse.snapshot, docs/extensions/building-a-tool.md, docs/reborn/contracts/auth-product.md
Updates the architecture boundary test scan targets and the composition pub-use snapshot plus documentation references to match the reorganized module and re-export layout.

Estimated code review effort: 2 (Simple) | ~15 minutes

Possibly related issues

Possibly related PRs

  • nearai/ironclaw#4916: Touches the same extension_lifecycle_capabilities_auth_tests.rs runtime-credential test surface.
  • nearai/ironclaw#5087: Shares the credential refresh worker / leader-lock wiring refactor in factory.rs, runtime.rs, and product_auth/credentials/*.

Suggested reviewers: ilblackdragon, henrypark133

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description is relevant but does not follow the required template and omits several mandatory sections. Restructure it to match the template: Summary, Change Type, Linked Issue, Validation, Security Impact, Trust-Boundary Checklist, Database Impact, Blast Radius, Rollback Plan, Review Follow-Through, and Review track.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and accurately describes the product-auth module refactor.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5686 July 6, 2026 10:47 Destroyed
@github-actions github-actions Bot added scope: docs Documentation size: L 200-499 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 6, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request reorganizes the product_auth modules in ironclaw_reborn_composition into a cleaner, nested directory structure (api, credentials, durable, oauth, and serve) and updates all internal imports and public exports accordingly. The review feedback correctly identifies a test coverage gap in reborn_dependency_boundaries.rs, where the path to the serve module's entry point was incorrectly updated to serve.rs instead of serve/mod.rs.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment on lines 1618 to +1620
collect_forbidden_reborn_auth_path_uses(
&root.join("crates/ironclaw_reborn_composition/src/product_auth_serve"),
&root.join("crates/ironclaw_reborn_composition/src/product_auth_serve.rs"),
&root.join("crates/ironclaw_reborn_composition/src/product_auth/serve"),
&root.join("crates/ironclaw_reborn_composition/src/product_auth/serve.rs"),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The entry point file for the serve module is located at crates/ironclaw_reborn_composition/src/product_auth/serve/mod.rs rather than crates/ironclaw_reborn_composition/src/product_auth/serve.rs. Passing a non-existent file path to collect_forbidden_reborn_auth_path_uses will cause the test to silently skip scanning the module's entry point, creating a test coverage gap.

Suggested change
collect_forbidden_reborn_auth_path_uses(
&root.join("crates/ironclaw_reborn_composition/src/product_auth_serve"),
&root.join("crates/ironclaw_reborn_composition/src/product_auth_serve.rs"),
&root.join("crates/ironclaw_reborn_composition/src/product_auth/serve"),
&root.join("crates/ironclaw_reborn_composition/src/product_auth/serve.rs"),
collect_forbidden_reborn_auth_path_uses(
&root.join("crates/ironclaw_reborn_composition/src/product_auth/serve"),
&root.join("crates/ironclaw_reborn_composition/src/product_auth/serve/mod.rs"),

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 2813b7a7e49c170d40a78895053c055ba134de2f

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No concrete correctness, security, or maintainability issues were found in this module reorganization. The public product-auth re-exports appear preserved, internal references were updated to the new product_auth::* paths, and whitespace checks passed.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@github-actions

github-actions Bot commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.45% (276153 / 323179 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 323179 lines now vs 320188 at floor capture (+2991 lines, +0.93%) — not a material change

⚠️ 3 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts, ironclaw_skill_learning

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.45% — 276153 / 323179 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 347
ironclaw_skill_learning 0% 0 / 61
ironclaw_wasm_sandbox_core 7.37% 7 / 95
ironclaw_runtime_policy 33.2% 80 / 241
ironclaw_event_projections 43.34% 673 / 1553
ironclaw_run_state 52.73% 222 / 421
ironclaw_authorization 53.54% 461 / 861
ironclaw_triggers 60.32% 1736 / 2878
ironclaw_observability 61.54% 16 / 26
ironclaw_mcp 63.15% 581 / 920
ironclaw_reborn_cli 64.58% 3988 / 6175
ironclaw_filesystem 65.93% 3234 / 4905
ironclaw_webui_v2 66.15% 2423 / 3663
ironclaw_reborn_migration 67.01% 1172 / 1749
ironclaw_memory 67.12% 747 / 1113
ironclaw_dispatcher 67.15% 92 / 137
ironclaw_trust 72.88% 661 / 907
ironclaw_reborn_event_store 73.27% 940 / 1283
ironclaw_capabilities 74.08% 1658 / 2238
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_extractors 74.72% 538 / 720
ironclaw_first_party_extensions 77.62% 5410 / 6970
ironclaw_llm 77.88% 19480 / 25013
ironclaw_product_context 78.57% 11 / 14
ironclaw_wasm_product_adapters 80.58% 1510 / 1874
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_reborn_openai_compat 80.95% 956 / 1181
ironclaw_memory_native 81.86% 3226 / 3941
ironclaw_secrets 82.33% 2716 / 3299
ironclaw_wasm 82.54% 950 / 1151
ironclaw_events 83.44% 1759 / 2108
ironclaw_processes 84.06% 965 / 1148
ironclaw_host_api 84.8% 3131 / 3692
ironclaw_threads 85.16% 3278 / 3849
ironclaw_projects 85.92% 659 / 767
ironclaw_network 86.12% 670 / 778
ironclaw_auth 86.32% 2727 / 3159
ironclaw_product_workflow 86.33% 10709 / 12405
ironclaw_turns 86.36% 10481 / 12136
ironclaw_common 86.59% 1472 / 1700
ironclaw_slack_v2_adapter 86.79% 1806 / 2081
ironclaw_reborn_config 86.98% 1730 / 1989
ironclaw_product_adapters 87.29% 3207 / 3674
ironclaw_reborn_traces 87.35% 10325 / 11820
ironclaw_skills 87.36% 4335 / 4962
ironclaw_hooks 87.84% 9916 / 11289
ironclaw_product_adapter_registry 87.96% 526 / 598
ironclaw_extensions 88.26% 2631 / 2981
ironclaw_reborn_identity 88.43% 344 / 389
ironclaw_reborn_composition 89.11% 68977 / 77410
ironclaw_host_runtime 89.13% 17303 / 19413
ironclaw_conversations 90% 2924 / 3249
ironclaw_approvals 90.51% 1507 / 1665
ironclaw_reborn 91.19% 17477 / 19166
ironclaw_event_streams 91.48% 1009 / 1103
ironclaw_reborn_webui_ingress 91.68% 2094 / 2284
ironclaw_loop_support 92.22% 14231 / 15432
ironclaw_attachments 93.06% 630 / 677
ironclaw_telegram_v2_adapter 94.01% 2447 / 2603
ironclaw_resources 94.2% 3605 / 3827
ironclaw_agent_loop 94.54% 8753 / 9259
ironclaw_safety 94.81% 3669 / 3870
ironclaw_first_party_extension_ports 95% 3094 / 3257
ironclaw_outbound 95.59% 3556 / 3720

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (4 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_oauth v1-only: consumed only by root ironclaw (src/auth/oauth.rs); no crates/* dependents. Crate's own doc comment confirms v1-only. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@serrrfirat
serrrfirat marked this pull request as ready for review July 6, 2026 11:10
@railway-app

railway-app Bot commented Jul 6, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5686 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 7, 2026 at 9:16 am

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5686 July 6, 2026 21:49 Destroyed
@ironloopai

ironloopai Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

🗂️ Archived IronLoop Review: reviewer

This result is from an older PR head and is no longer the active review.

Field Value
Status Superseded
Verdict ✅ Approved
Findings 0 blocking / 0 notes
Reviewed head 2813b7a7e49c
Archived summary

No concrete correctness, security, or maintainability issues were found in this module reorganization. The public product-auth re-exports appear preserved, internal references were updated to the new product_auth::* paths, and whitespace checks passed.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 18497d2bdb3afa5e037d7f5e4396c1d701e519d6

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No concrete, actionable regressions found. The PR reorganizes Reborn product-auth modules under a product_auth cluster and updates internal references, architecture boundary paths, and the public-use snapshot accordingly.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@serrrfirat serrrfirat left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Multi-agent review complete for PR #5686.

Reviewers: security clean, bugs clean, performance/concurrency clean, tests clean, conventions found 2 anchored issues.

Findings posted inline:

  • Medium: current docs still reference old product-auth paths after the module move.
  • Low: one moved comment still names the old durable module.

//! WebUI route serving (`serve`), and runtime credential resolution/refresh
//! (`credentials`) — behind one internal module. The crate root re-exports the
//! same public items from here so the crate's public API is unchanged.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium - repo-rule conformance

This move introduces the new product_auth module layout, but current docs still point readers at the old paths: docs/extensions/building-a-tool.md still references src/notion_oauth.rs, src/oauth_provider_client.rs, and src/product_auth_serve/; docs/reborn/contracts/auth-product.md still references src/product_auth_serve/mod.rs. .claude/rules/review-discipline.md requires updating .md/CLAUDE.md references to moved paths in the same refactor PR.

Fix: update those docs to the new product_auth/oauth/... and product_auth/serve/... paths.

@@ -103,12 +103,12 @@ pub(crate) trait CredentialRefreshCandidateSource: Send + Sync {
// Note: this requires the `product_auth_durable` module to be `pub(crate)`.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Low - stale comment

This comment still says the blanket impl requires the old product_auth_durable module to be pub(crate), but the impl now targets crate::product_auth::durable::FilesystemAuthProductServices. That leaves a stale path immediately after the move.

Fix: change the comment to name product_auth::durable, or remove the module-path detail.

@coderabbitai coderabbitai Bot mentioned this pull request Jul 24, 2026
20 of 29 tasks

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5686 — 333a0024 Deployed Jul 7, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: docs Documentation size: L 200-499 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant