OAuth follow-ups: DCR off by default on 2.38, unnoticed nightly scope failures, CLI inheriting CODER_SESSION_TOKEN
Les mainteneurs répondent en général sous 2 jours
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Accessibilité débutants
- 68/100
- Type d'issue
- Bug
- Clarté
- Clairement spécifiée
- Activité
- Active
- Stack technique
- node.js, typescript
- Domaine
- developer-experience
Piste de recherche
Three independent follow-ups; pick one and scope it explicitly. For item 3, start at runCliCommand in src/api/workspace.ts and the spawn sites in src/core/cliExec.ts, and find where the CLI is handed process.env; done means CODER_SESSION_TOKEN (and other CODER_* auth vars) never reach the child process and the live suite still passes. For item 2, read .github/workflows/oauth-scopes.yaml and make a failed scheduled run open or comment on a tracking issue; for item 1, trace the OAuth registration failure path in the extension's sign-in flow so the 403 names dynamic_client_registration_enabled and falls back to session-token sign-in.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Follow-ups found while fixing OAuth scopes (#1138) and adding the live scope suite (#1128).
1. OAuth sign-in fails on 2.38+ unless an admin enables dynamic client registration
On release/2.38 and main, dynamic client registration (DCR) is a runtime setting that is off by default. Admins turn it on with PUT /api/v2/oauth2-provider/settings and {"dynamic_client_registration_enabled": true}.
Discovery (/.well-known/oauth-authorization-server) still lists registration_endpoint, so the extension offers OAuth. Then POST /oauth2/register fails with 403 invalid_request: Dynamic client registration is disabled on this deployment, and sign-in fails with no hint at the cause.
Proposed: when registration is refused, show an error naming the setting, and fall back to session-token sign-in.
2. Nightly scope-suite failures notify almost no one
.github/workflows/oauth-scopes.yaml runs nightly against ghcr.io/coder/coder-preview:latest to catch server-side changes before they ship, such as new OAuth or DCR requirements, or a changed scope or permission. GitHub emails a failed scheduled run only to the user who last edited the cron line, so a failure can go unnoticed.
Proposed: when a scheduled run fails, open or update a tracking issue (for example with gh issue create, or by commenting on an existing issue).
3. CLI calls inherit the extension host's environment, including CODER_SESSION_TOKEN
Every CLI call spawns the binary with the full process.env:
runCliCommandinsrc/api/workspace.ts(coder start,coder update)src/core/cliExec.ts(speedtest,support bundle,ping)
The CLI prefers CODER_SESSION_TOKEN over the session the extension stores, whether in the --global-config directory or the keyring. If the extension host's environment has that variable, as it does inside some Coder workspaces, these commands run with that token instead of the user's session. They then fail with 401 You are signed out, or act as a different user. The live suite hit this when run from a Coder workspace and now unsets the variable.
The SSH ProxyCommand that Remote-SSH spawns may be affected the same way (not verified).
Proposed: pass the CLI an environment without CODER_SESSION_TOKEN, and probably without other CODER_* auth variables, since the extension already passes --url and the stored session explicitly.
- Langage dominant
- TypeScript
- Étoiles
- 132
- Forks
- 48
- Merge moyen
- 2 j 5 h
- PR mergées (30 j)
- 19
Préparer son environnement
Lance le conteneur de développement du projet dans votre navigateur, avec votre propre compte GitHub.
- Aucun Dockerfile ni fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de coder/vscode-coder
-
bug
Difficulté 3/5 1-2 jours Accessibilité débutants 72/100
coder/vscode-coder#1141 · 1 commentaire ·
Les mainteneurs répondent en général sous 2 jours
-
Split commands.ts by topicOuverteImprovement tech-debt vs-code
Difficulté 4/5 3-5 jours Accessibilité débutants 48/100
coder/vscode-coder#1135 · 1 commentaire ·
Les mainteneurs répondent en général sous 2 jours
-
Migrate CI setup to pnpm/setupPeut-être pris @EhabY l’a pris il y a 19 jours. Ouvertetech-debt
coder/vscode-coder#1119 · 1 commentaire · 1 personne assignée ·
Les mainteneurs répondent en général sous 2 jours
-
Design the VS Code Workspaces panelPeut-être pris @chrifro l’a pris il y a 22 jours. Ouverte
coder/vscode-coder#1113 · 3 commentaires · 1 personne assignée ·
Les mainteneurs répondent en général sous 2 jours
-
bug upstream
Difficulté 4/5 3-5 jours Accessibilité débutants 42/100
coder/vscode-coder#1087 · 1 commentaire ·
Les mainteneurs répondent en général sous 2 jours
Toutes les issues de coder/vscode-coder
Issues similaires
-
ble-needs-fable-review bug mobile priority:P2
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 76/100
ColeMurray/background-agents#2305 ·
Les mainteneurs répondent en général sous 1 jour
-
bug from-studio
Difficulté 2/5 1-3 heures Accessibilité débutants 63/100
esengine/DeepSeek-Reasonix#12355 ·
Les mainteneurs répondent en général sous 1 jour
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
oblien/openship#1086 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
Les mainteneurs répondent en général sous 1 jour