Skip to content

[codex] align server auth Effect services - #3180

Merged
juliusmarminge merged 6 commits into
mainfrom
codex/effect-service-server-auth
Jun 20, 2026
Merged

juliusmarminge merged 6 commits into
mainfrom
codex/effect-service-server-auth

Restore canonical Node namespace imports

daba9c6
Select commit
Loading
Failed to load commit list.
MacroscopeApp / Macroscope - Effect Service Conventions succeeded Jun 20, 2026 in 2m 37s

.completall.A

All clear. This​This PR refactors the auth-layerror handling and service definitions to follow the Effect service conventions, and the changes are consistent with them.

Verified across the changed scope (apps/server/src/auth/*, apps/server/src/cloud/*, apps/desktopop/src.ts):

  • Imports: Effect modules are imported as subpath namespaces; local service modules (ServerConfig, ServerSecretStore, SessionStore, PairingGrantStore, EnvironmentAuthPolicy) are now namespace-imported with X.X tag access. No consolidated from "effect" imports were introduced. Error-only imports (e.g. in dpop.ts) remain named, which the conventions permit.
  • Service definitions: FooShape interfaces were removed and inlined into Context.Service; references use Foo["Service"]. make is a real Effect.gen constructor and layer = Layer.effect(...) is canonical.
  • Errors/predicates: Failures are modeled with Schema.TaggedErrorClass, distinct tags split semantically distinct failures, message getters derive from structural attributes (never from cause), real causes are preserved via Schema.Defect(), Schema.Union aggregates are exported, and predicates are direct export const isFoo = Schema.is(Foo). The one multi-value discriminator (SessionClaimsEncodingError.operation) uses the permitted single-error + generic-message pattern. Caller-visible reason strings are preserved via serverAuthCredentialReason/serverAuthInvalidRequestReason.
  • File layout: Files stayed in place (in-file refactor), so no compatibility shims were needed; consumers were mechanically updated.

No convention violations were found in the PR's changed scope. Pre-existing *Shape interfaces elsewhere in the repo are outside this PR's scope and not flagged.',

Details

Note

Your check run agent prompt is: .macroscope/check-run-agents/effect-service-conventions.md
More information about how Check Run Agents work can be found in our Help Center.

Method: reviewed the full diff and inspected EnvironmentAuth.ts, SessionStore.ts, PairingGrantStore.ts, ServerSecretStore.ts, dpop.ts, cloud/http.ts, and call sites (http.ts, ws.ts). Confirmed no consolidated effect imports and no retained *Shape types in the touched auth/cloud files (remaining *Shape references are in unrelated, untouched modules). Confirmed error classes preserve cause, derive messages from structural fields, and that caller-visible reason mapping is retained at HTTP boundaries.


The agent made no additional tool calls beyond your initial Check Run Agent prompt.


Agent Credits: 108 credits