Skip to content

fix(console): classify token exchange failures safely - #482

Merged
Pigbibi merged 1 commit into
mainfrom
codex/oauth-token-exchange-diagnostic-20260930
Sep 30, 2026
Merged

Pigbibi merged 1 commit into
mainfrom
codex/oauth-token-exchange-diagnostic-20260930

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Change

A fresh login after the timeout patch reached token exchange but failed without an attributable error. Expose only the HTTP status and four documented GitHub error categories on the existing 502 page and fixed diagnostic log. Unknown values become unknown; never expose provider descriptions, URLs, authorization codes, state, tokens, or credentials.

The request, authorization checks, success condition, cookie clearing, timeout, and no-retry behavior remain unchanged.

Validation

Node syntax and git diff --check passed. Independent static privacy/authentication review passed. No local tests added or run. Existing CI and a bounded fresh login after deployment are separate acceptance checks; the upstream failure category is still unknown.

Co-Authored-By: Codex <noreply@openai.com>
@Pigbibi
Pigbibi merged commit 0c06df9 into main Sep 30, 2026
6 checks passed
@Pigbibi
Pigbibi deleted the codex/oauth-token-exchange-diagnostic-20260930 branch September 30, 2026 15:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant