ChatGPT sign-in: the redirect URI says localhost but the callback server binds only 127.0.0.1
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- node.js, typescript
- Domain
- authentication
Research direction
Start with src/main/llm/codex_auth.ts, especially the redirect URI at line 23 and server binding at line 244. Read the OAuth callback setup and check how the server reports bind failures; the issue proposes supporting both 127.0.0.1 and ::1 and refusing to start if either is occupied. Done means sign-in callbacks work with either localhost address and a local port conflict is reported.
Written by the indexing model from the issue text.
Description
From Finding 5 of the earlier SECURITY-REVIEW.md and the Oct 7 audit, checked against the current code.
Problem
The OAuth redirect is http://localhost:1455/auth/callback (src/main/llm/codex_auth.ts:23), but the server listens only on 127.0.0.1 (codex_auth.ts:244). Browsers may resolve localhost to ::1 first. Another local process listening on [::1]:1455 would then get the callback instead of Patch, or sign-in would fail. PKCE (S256) and the random state mean an intercepted code can't be exchanged, so the realistic impact is a failed or blocked sign-in, not token theft. The port is fixed by the provider's client registration.
Proposal
Listen on both 127.0.0.1 and ::1 (two servers, or one with ipv6Only: false on ::), and refuse to start if either is taken. Document that a local process can block sign-in.
- Dominant language
- TypeScript
- Stars
- 2
- Forks
- 2
- Avg merge
- 5h 52m
- Merged PRs (30d)
- 18
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from PierrunoYT/patch
-
enhancement priority: low security severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
PierrunoYT/patch#208 ·
Maintainers usually reply within 1 day
-
enhancement platform: windows priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#198 ·
Maintainers usually reply within 1 day
-
bug priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#190 ·
Maintainers usually reply within 1 day
-
Unbounded waits: revokeProjectGrant has no timeout, and timed-out browser waiters are never removedOpenbug priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
PierrunoYT/patch#188 ·
Maintainers usually reply within 1 day
-
bug priority: medium severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
PierrunoYT/patch#179 ·
Maintainers usually reply within 1 day
All issues in PierrunoYT/patch
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
farbenmeer/tapi#531 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
naver/egjs-flicking#971 ·
-
Renderer treats a sub-pixel width difference as a resize, which cancels the `motion()` entranceOpen
Difficulty 1/5 Under an hour Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Tenant
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
MTES-MCT/Dossier-Facile-Frontend#2061 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
backnotprop/plannotator#1784 ·
Maintainers usually reply within 1 day