Repository navigation
Conversation
EhabY
force-pushed
the
fix/oauth-scope-session-lifecycle
branch
from
October 9, 2026 23:05
e8d23c6 to
8125427
Compare
EhabY
force-pushed
the
fix/oauth-scope-session-lifecycle
branch
7 times, most recently
from
October 11, 2026 13:56
72117ed to
c01e269
Compare
Clean up replaced OAuth sessions without forcing a re-login when the required scopes change. - Insufficient scopes prevent refresh but keep the stored access token, so normal 401 recovery applies after expiry. Rename the check to `canRefreshOAuthSession`. - Save a successful replacement first, then revoke the overwritten OAuth pair in the background with the client registration captured before login. Failed or canceled logins, same-token reuse, and stored-session adoption revoke nothing. - Keep refresh credentials and scopes when the same token is reused on the same origin, instead of turning it into a manual-token session. If a refresh rotates the session while its stored token is checked, keep the rotated session. - Share revocation with logout through `withOAuthMetadata`, which token refresh also uses, and request `user:update_personal` to refresh expired external-auth links. - If the server refuses dynamic client registration (off by default from Coder 2.38), name the setting and offer session-token sign-in. - Start every CLI invocation's global flags with an empty `--token=`, so `CODER_SESSION_TOKEN` in the extension host (in any case) no longer overrides the stored session. This covers the SSH ProxyCommand and terminals too. `coder login --use-token-as-session` omits it, since it reads the token from the environment, and gets an environment without the host's case variants of the variable. Closes #1140
EhabY
force-pushed
the
fix/oauth-scope-session-lifecycle
branch
from
October 11, 2026 14:30
c01e269 to
183b2bc
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to #1138's token-cleanup comment: clean up replaced OAuth sessions without forcing an immediate re-login when required scopes change. Closes #1140: this PR covers items 1 and 3, and #1128 covers item 2.
canRefreshOAuthSession.revokeOAuthTokensinsrc/oauth/revocation.tsserves logout and replacement.withOAuthMetadatainsrc/oauth/metadataClient.tscreates the client and fetches metadata for revocation and token refresh.user:update_personalto refresh expired workspace external-auth links. Inbox permissions stay optional.dynamic_client_registration_enabledand offers Sign In with Token. Dismissing it cancels sign-in, so nothing switches methods silently.getGlobalFlagsandgetGlobalShellFlags) now start with an empty--token=. The CLI applies flags over environment variables, soCODER_SESSION_TOKENin the extension host no longer overrides the stored session. That holds for any case variant and forHOMEBREW_CODER_SESSION_TOKEN. Every invocation is covered, including the SSHProxyCommandand terminals. A user's own--tokenincoder.globalFlagscomes later and still wins.coder login --use-token-as-sessionomits the flag because it reads the token from the environment. It gets an environment with any host case variants ofCODER_SESSION_TOKENremoved, so only the extension's token remains. This behavior was checked in the Coder source from v0.25.0 (the minimum supported version) through main.Out of scope: startup or remote admission gates, per-action permission maps, and a background-refresh redesign. Before expiry, users can still see feature-specific permission errors; those don't prompt for sign-in.
Change size
Diff against the merge base; counts include moved code and renames.
src/**)test/**)Validation
Single commit on top of #1134.
pnpm test: 189 files, 2,830 passed, 6 skipped.pnpm typecheck,pnpm lint, andpnpm format:check: passed.--token=flag in every CLI invocation, a user--tokenoverriding it,storeTokenomitting it, andstoreTokendropping a hostcoder_session_token.Known limitations
Generated by Coder Agents on behalf of @EhabY.