OAuth follow-ups: DCR off by default on 2.38, unnoticed nightly scope failures, CLI inheriting CODER_SESSION_TOKEN
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 68/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- node.js, typescript
調査の方向性
Three independent follow-ups; pick one and scope it explicitly. For item 3, start at runCliCommand in src/api/workspace.ts and the spawn sites in src/core/cliExec.ts, and find where the CLI is handed process.env; done means CODER_SESSION_TOKEN (and other CODER_* auth vars) never reach the child process and the live suite still passes. For item 2, read .github/workflows/oauth-scopes.yaml and make a failed scheduled run open or comment on a tracking issue; for item 1, trace the OAuth registration failure path in the extension's sign-in flow so the 403 names dynamic_client_registration_enabled and falls back to session-token sign-in.
索引モデルが issue の本文から書いたものです。
説明
Follow-ups found while fixing OAuth scopes (#1138) and adding the live scope suite (#1128).
1. OAuth sign-in fails on 2.38+ unless an admin enables dynamic client registration
On release/2.38 and main, dynamic client registration (DCR) is a runtime setting that is off by default. Admins turn it on with PUT /api/v2/oauth2-provider/settings and {"dynamic_client_registration_enabled": true}.
Discovery (/.well-known/oauth-authorization-server) still lists registration_endpoint, so the extension offers OAuth. Then POST /oauth2/register fails with 403 invalid_request: Dynamic client registration is disabled on this deployment, and sign-in fails with no hint at the cause.
Proposed: when registration is refused, show an error naming the setting, and fall back to session-token sign-in.
2. Nightly scope-suite failures notify almost no one
.github/workflows/oauth-scopes.yaml runs nightly against ghcr.io/coder/coder-preview:latest to catch server-side changes before they ship, such as new OAuth or DCR requirements, or a changed scope or permission. GitHub emails a failed scheduled run only to the user who last edited the cron line, so a failure can go unnoticed.
Proposed: when a scheduled run fails, open or update a tracking issue (for example with gh issue create, or by commenting on an existing issue).
3. CLI calls inherit the extension host's environment, including CODER_SESSION_TOKEN
Every CLI call spawns the binary with the full process.env:
runCliCommandinsrc/api/workspace.ts(coder start,coder update)src/core/cliExec.ts(speedtest,support bundle,ping)
The CLI prefers CODER_SESSION_TOKEN over the session the extension stores, whether in the --global-config directory or the keyring. If the extension host's environment has that variable, as it does inside some Coder workspaces, these commands run with that token instead of the user's session. They then fail with 401 You are signed out, or act as a different user. The live suite hit this when run from a Coder workspace and now unsets the variable.
The SSH ProxyCommand that Remote-SSH spawns may be affected the same way (not verified).
Proposed: pass the CLI an environment without CODER_SESSION_TOKEN, and probably without other CODER_* auth variables, since the extension already passes --url and the stored session explicitly.
- 主要言語
- TypeScript
- スター
- 132
- フォーク
- 48
- 平均マージ
- 2日 15分
- マージ済み PR(30日)
- 17
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
coder/vscode-coder のほかの issue
-
Improvement tech-debt vs-code
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
coder/vscode-coder#1135 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
Migrate CI setup to pnpm/setup対応中かも @EhabY が 19 日前に担当しました。 オープンtech-debt
coder/vscode-coder#1119 · コメント 1 件 · 担当者 1 名 ·
メンテナーはふだん 2 日以内に返信
-
Design the VS Code Workspaces panel対応中かも @chrifro が 22 日前に担当しました。 オープン
coder/vscode-coder#1113 · コメント 3 件 · 担当者 1 名 ·
メンテナーはふだん 2 日以内に返信
-
Flush the connection log buffer after N failed reconnect attempts against an unreachable server対応中かも @aqandrew が 7 日前に担当しました。 オープンenhancement tech-debt
難易度 5/5 1週間以上 初心者へのやさしさ 45/100
coder/vscode-coder#1112 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
bug upstream
難易度 4/5 3〜5日 初心者へのやさしさ 42/100
coder/vscode-coder#1087 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
coder/vscode-coder の issue をすべて見る
似ている issue
-
ble-needs-fable-review bug mobile priority:P2
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
ColeMurray/background-agents#2305 ·
メンテナーはふだん 1 日以内に返信
-
bug from-studio
難易度 2/5 1〜3時間 初心者へのやさしさ 63/100
esengine/DeepSeek-Reasonix#12355 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
oblien/openship#1086 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信