Skip to content

fix: detach the OIDC compat's normal-path body releases - #2393

Merged
cliffhall merged 2 commits into
v2/mainfrom
v2/fix/2389-oidc-detached-body-release
Sep 16, 2026
Merged

cliffhall merged 2 commits into
v2/mainfrom
v2/fix/2389-oidc-detached-body-release

Conversation

@cliffhall

Copy link
Copy Markdown
Member

Closes #2389

withRfc8414OidcCompat still awaited releaseBody() at two normal-path sites — a non-OK probe, and the original response a substitution discards. ReadableStream.cancel() may never settle, so either could hang discovery with the caller's abort unable to end it (the recheck sat after the await).

Change

  • Both sites now use releaseBodyDetached, as every exceptional exit already did. The post-release abort recheck on the non-OK path is kept.
  • releaseBodyDetached's comment now covers the normal path too.

Tests

Two new cases in oidcDiscoveryCompat.test.ts, using a body whose cancel() never settles:

  • an abort landing during a non-OK probe's release rejects with the caller's reason and stops probing;
  • a non-OK probe with a stalled release still walks on to the next candidate and substitutes it — and both bodies are still cancelled.

Checked both against the old code: both time out there, and pass on the fix. The existing connection-release tests are unchanged and still pass. npm run local:gate is green.

🤖 Generated with Claude Code

Neither the non-OK probe's release nor the substituted original's is awaited
any more, so a body cancel that never settles can no longer stall discovery
or keep the caller's abort from reaching it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall cliffhall added the v2 Issues and PRs for v2 label Sep 16, 2026
@cliffhall
cliffhall requested a balanced review from Copilot September 16, 2026 17:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The implementation satisfies issue #2389’s acceptance criteria with focused regression coverage.

Pull request overview

Prevents stalled response-body cancellation from blocking OIDC discovery and caller aborts.

Changes:

  • Detaches normal-path body releases.
  • Adds regression tests for stalled cancellation and abort handling.
File summaries
File Description
core/auth/oidcDiscoveryCompat.ts Makes body release non-blocking.
clients/web/src/test/core/auth/oidcDiscoveryCompat.test.ts Covers stalled cancellation paths.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

…etached-body-release

Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall
cliffhall merged commit 2b6e7ba into v2/main Sep 16, 2026
4 checks passed
@cliffhall
cliffhall deleted the v2/fix/2389-oidc-detached-body-release branch September 16, 2026 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Issues and PRs for v2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OIDC discovery compat awaits body cancel on its normal path, so a stalled cancel blocks the caller's abort

2 participants