Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

OAuth follow-ups: DCR off by default on 2.38, unnoticed nightly scope failures, CLI inheriting CODER_SESSION_TOKEN

Ouverte
#1,140 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 2 jours

Personne n'a encore pris cette issue.

Évaluation

Difficulté
3/5
Temps estimé
1-2 jours
Accessibilité débutants
68/100
Type d'issue
Bug
Clarté
Clairement spécifiée
Activité
Active
Stack technique
node.js, typescript

Piste de recherche

Three independent follow-ups; pick one and scope it explicitly. For item 3, start at runCliCommand in src/api/workspace.ts and the spawn sites in src/core/cliExec.ts, and find where the CLI is handed process.env; done means CODER_SESSION_TOKEN (and other CODER_* auth vars) never reach the child process and the live suite still passes. For item 2, read .github/workflows/oauth-scopes.yaml and make a failed scheduled run open or comment on a tracking issue; for item 1, trace the OAuth registration failure path in the extension's sign-in flow so the 403 names dynamic_client_registration_enabled and falls back to session-token sign-in.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

bug tech-debt

Follow-ups found while fixing OAuth scopes (#1138) and adding the live scope suite (#1128).

1. OAuth sign-in fails on 2.38+ unless an admin enables dynamic client registration

On release/2.38 and main, dynamic client registration (DCR) is a runtime setting that is off by default. Admins turn it on with PUT /api/v2/oauth2-provider/settings and {"dynamic_client_registration_enabled": true}.

Discovery (/.well-known/oauth-authorization-server) still lists registration_endpoint, so the extension offers OAuth. Then POST /oauth2/register fails with 403 invalid_request: Dynamic client registration is disabled on this deployment, and sign-in fails with no hint at the cause.

Proposed: when registration is refused, show an error naming the setting, and fall back to session-token sign-in.

2. Nightly scope-suite failures notify almost no one

.github/workflows/oauth-scopes.yaml runs nightly against ghcr.io/coder/coder-preview:latest to catch server-side changes before they ship, such as new OAuth or DCR requirements, or a changed scope or permission. GitHub emails a failed scheduled run only to the user who last edited the cron line, so a failure can go unnoticed.

Proposed: when a scheduled run fails, open or update a tracking issue (for example with gh issue create, or by commenting on an existing issue).

3. CLI calls inherit the extension host's environment, including CODER_SESSION_TOKEN

Every CLI call spawns the binary with the full process.env:

  • runCliCommand in src/api/workspace.ts (coder start, coder update)
  • src/core/cliExec.ts (speedtest, support bundle, ping)

The CLI prefers CODER_SESSION_TOKEN over the session the extension stores, whether in the --global-config directory or the keyring. If the extension host's environment has that variable, as it does inside some Coder workspaces, these commands run with that token instead of the user's session. They then fail with 401 You are signed out, or act as a different user. The live suite hit this when run from a Coder workspace and now unsets the variable.

The SSH ProxyCommand that Remote-SSH spawns may be affected the same way (not verified).

Proposed: pass the CLI an environment without CODER_SESSION_TOKEN, and probably without other CODER_* auth variables, since the extension already passes --url and the stored session explicitly.

Langage dominant
TypeScript
Étoiles
132
Forks
48
Merge moyen
2 j 5 h
PR mergées (30 j)
19

Préparer son environnement

Ouvrir dans Codespaces

Lance le conteneur de développement du projet dans votre navigateur, avec votre propre compte GitHub.

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de coder/vscode-coder

Toutes les issues de coder/vscode-coder

Issues similaires

Plus d'issues TypeScript

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.