Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

ChatGPT sign-in: the redirect URI says localhost but the callback server binds only 127.0.0.1

Open
#210 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
55/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
node.js, typescript

Research direction

Start with src/main/llm/codex_auth.ts, especially the redirect URI at line 23 and server binding at line 244. Read the OAuth callback setup and check how the server reports bind failures; the issue proposes supporting both 127.0.0.1 and ::1 and refusing to start if either is occupied. Done means sign-in callbacks work with either localhost address and a local port conflict is reported.

Written by the indexing model from the issue text.

Description

bug priority: low security severity: low

From Finding 5 of the earlier SECURITY-REVIEW.md and the Oct 7 audit, checked against the current code.

Problem

The OAuth redirect is http://localhost:1455/auth/callback (src/main/llm/codex_auth.ts:23), but the server listens only on 127.0.0.1 (codex_auth.ts:244). Browsers may resolve localhost to ::1 first. Another local process listening on [::1]:1455 would then get the callback instead of Patch, or sign-in would fail. PKCE (S256) and the random state mean an intercepted code can't be exchanged, so the realistic impact is a failed or blocked sign-in, not token theft. The port is fixed by the provider's client registration.

Proposal

Listen on both 127.0.0.1 and ::1 (two servers, or one with ipv6Only: false on ::), and refuse to start if either is taken. Document that a local process can block sign-in.

Dominant language
TypeScript
Stars
2
Forks
2
Avg merge
5h 52m
Merged PRs (30d)
18

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from PierrunoYT/patch

All issues in PierrunoYT/patch

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.