Fix SkyFi OAuth Connection flow and Settings connection states#754
Fix SkyFi OAuth Connection flow and Settings connection states#754ngoiyaeric wants to merge 1 commit into
Conversation
…ttings UI state recovery Co-authored-by: ngoiyaeric <115367894+ngoiyaeric@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Qodo reviews are paused for this user.Troubleshooting steps vary by plan Learn more → On a Teams plan? Using GitHub Enterprise Server, GitLab Self-Managed, or Bitbucket Data Center? |
|
Warning Review limit reached
Next review available in: 33 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (6)
📒 Files selected for processing (11)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
The resolution search is not responsive |
There was a problem hiding this comment.
Request changes
I found three issues that should be addressed before merge.
-
The migration journal references a missing SQL migration.
_journal.jsonadds0010_tough_the_professor, but the PR contains nodrizzle/migrations/0010_tough_the_professor.sql; it only adds the snapshot. The migration runner uses Drizzle's journal tags to read<tag>.sql, so deployments will fail while loading migrations before0011_motionless_banshee.sqlcan addredirect_uri. Please add the missing SQL migration or remove/reconcile the journal/snapshot entry. -
Changing redirect URIs replaces the client registration but preserves tokens issued to the old client.
saveClientInformationupdatesclientId/redirectUriwithout clearing token columns, whiletokens()later refreshes with the storedclientId. If a user with an existing connection starts a reconnect after the redirect URI changes and abandons it, the old refresh token can subsequently be sent with the new client ID and the connection becomes unable to refresh. Clear the old access/refresh tokens when replacing the registration, or keep the old registration until the new authorization callback successfully saves new tokens. -
The fallback redirect URI trusts request-supplied proxy headers. When
NEXT_PUBLIC_APP_URLis absent,x-forwarded-hostandx-forwarded-protodirectly control the OAuth redirect URI. Unless the ingress is guaranteed to strip and overwrite these headers, a caller can influence the registered callback/authorization redirect. Use an allowlisted canonical URL or explicitly validate that these headers came from a trusted proxy, and enforce/document the productionNEXT_PUBLIC_APP_URLinvariant.
Checks observed for this head: GitGuardian and Vercel Preview Comments passed; CodeRabbit reported success but was rate-limited; Supabase Preview was skipped; the Vercel deployment status was still pending. I did not run tests, lint, or builds during this read-only review.
|
|
This PR implements a robust set of fixes to resolve the core bug where the 'Connect SkyFi Account' button fails to route users to SkyFi's login/authorize page, alongside improvements to token exchange consistency and Settings UI states:
getRedirectUri()inlib/actions/skyfi.tsto prefer the explicitly configuredNEXT_PUBLIC_APP_URLover dynamic request header parsing. In case of headers, added proxy-header parsing forx-forwarded-hostandx-forwarded-proto.resolveClerkUserToDbUserto prevent misreporting authenticated sessions asauthRequired.Authorization: Bearer <token>header and conservatively treated missing expiry as expired/refreshable.PR created automatically by Jules for task 13021459091643289234 started by @ngoiyaeric