Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

OAuth follow-ups: DCR off by default on 2.38, unnoticed nightly scope failures, CLI inheriting CODER_SESSION_TOKEN

オープン
#1,140 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
68/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
node.js, typescript

調査の方向性

Three independent follow-ups; pick one and scope it explicitly. For item 3, start at runCliCommand in src/api/workspace.ts and the spawn sites in src/core/cliExec.ts, and find where the CLI is handed process.env; done means CODER_SESSION_TOKEN (and other CODER_* auth vars) never reach the child process and the live suite still passes. For item 2, read .github/workflows/oauth-scopes.yaml and make a failed scheduled run open or comment on a tracking issue; for item 1, trace the OAuth registration failure path in the extension's sign-in flow so the 403 names dynamic_client_registration_enabled and falls back to session-token sign-in.

索引モデルが issue の本文から書いたものです。

説明

bug tech-debt

Follow-ups found while fixing OAuth scopes (#1138) and adding the live scope suite (#1128).

1. OAuth sign-in fails on 2.38+ unless an admin enables dynamic client registration

On release/2.38 and main, dynamic client registration (DCR) is a runtime setting that is off by default. Admins turn it on with PUT /api/v2/oauth2-provider/settings and {"dynamic_client_registration_enabled": true}.

Discovery (/.well-known/oauth-authorization-server) still lists registration_endpoint, so the extension offers OAuth. Then POST /oauth2/register fails with 403 invalid_request: Dynamic client registration is disabled on this deployment, and sign-in fails with no hint at the cause.

Proposed: when registration is refused, show an error naming the setting, and fall back to session-token sign-in.

2. Nightly scope-suite failures notify almost no one

.github/workflows/oauth-scopes.yaml runs nightly against ghcr.io/coder/coder-preview:latest to catch server-side changes before they ship, such as new OAuth or DCR requirements, or a changed scope or permission. GitHub emails a failed scheduled run only to the user who last edited the cron line, so a failure can go unnoticed.

Proposed: when a scheduled run fails, open or update a tracking issue (for example with gh issue create, or by commenting on an existing issue).

3. CLI calls inherit the extension host's environment, including CODER_SESSION_TOKEN

Every CLI call spawns the binary with the full process.env:

  • runCliCommand in src/api/workspace.ts (coder start, coder update)
  • src/core/cliExec.ts (speedtest, support bundle, ping)

The CLI prefers CODER_SESSION_TOKEN over the session the extension stores, whether in the --global-config directory or the keyring. If the extension host's environment has that variable, as it does inside some Coder workspaces, these commands run with that token instead of the user's session. They then fail with 401 You are signed out, or act as a different user. The live suite hit this when run from a Coder workspace and now unsets the variable.

The SSH ProxyCommand that Remote-SSH spawns may be affected the same way (not verified).

Proposed: pass the CLI an environment without CODER_SESSION_TOKEN, and probably without other CODER_* auth variables, since the extension already passes --url and the stored session explicitly.

主要言語
TypeScript
スター
132
フォーク
48
平均マージ
2日 15分
マージ済み PR(30日)
17

環境構築

Codespaces で開く

このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

coder/vscode-coder のほかの issue

coder/vscode-coder の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。