feat: allow specifying callback port for OIDC auth
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 3/5
- Tempo estimado
- 1-2 dias
- Facilidade para iniciantes
- 78/100
- Tipo de issue
- Funcionalidade
- Clareza
- Claramente especificada
- Status de atividade
- Ativa
- Stack de tecnologia
- rust
- Domínio
- authentication, cli
Direção de pesquisa
Comece em crates/openshell-cli/src/oidc_auth.rs por volta das linhas 188-190 e acompanhe como a porta do listener chega à construção de redirect_uri. Atualize docs/reference/gateway-auth.mdx por volta das linhas 92-98 e 123 e adicione cobertura de testes unitários para a porta configurada e um erro de colisão de bind. A tarefa estará concluída quando a variável de ambiente selecionar a porta do listener, portas inválidas ou indisponíveis produzirem erros acionáveis e o comportamento efêmero padrão permanecer inalterado.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
User Story
As an openshell consumer, I'd need the OIDC flow to work with a specific ephemeral port for SSO login. This is because the underlying auth0 provider does not allow regex on the port for allowed callback urls
Problem Statement
Provide a way to fix the CLI ephemeral callback port to a specific value so that it's easier to add the callback url
Impact / Why This Matters
Right now the SSO login requires whitelisting every possible ephemeral port in localhost which is not ideal.
Proposed Design
Provide the control of port via env variable OPENSHELL_OIDC_CALLBACK_PORT or something similar
Acceptance Criteria
- the callback port gets opened on specific port instead of any ephemeral port
Alternatives Considered
client credentials flow is what I am considering it for now
Agent Investigation
Spike Plan: feat: allow OIDC callback listener to bind a fixed port via env var
Scope decision: Env-var only (OPENSHELL_OIDC_CALLBACK_PORT) — no GatewayMetadata/clap changes.
Problem statement: The CLI's OIDC login flow binds an OS-assigned ephemeral port (127.0.0.1:0) for the local callback listener. Providers that require pre-registering exact redirect URIs can't reasonably whitelist the full ephemeral range, so login fails or requires impractical whitelisting.
Code changes (all in crates/openshell-cli/src/oidc_auth.rs):
- :188 — check OPENSHELL_OIDC_CALLBACK_PORT; if set, parse as u16 and bind that specific port with a wrapped, actionable error on bind failure; else keep current bind("127.0.0.1:0") behavior.
- No changes needed to redirect_uri construction (:189-190) or callback handling (:660-716) — they already work off whatever port the listener has.
Labels: area:cli, state:validated
Complexity: Low · Confidence: High · Est. files: 1 (+ docs, + tests)
Risks to include in the issue: - Bind-failure UX must give actionable guidance (today's raw OS error is not user-friendly).
- Fixed port is predictable, but existing CSRF state check + PKCE already prevent exploitation — mention, not a blocker.
- No interaction with token/mTLS storage or TUI (confirmed).
Docs impact: docs/reference/gateway-auth.mdx — add the new env var to the table (~line 92-98) and update prose at line 123.
Test additions: unit test setting the env var and asserting the bound port matches; a bind-collision test asserting the friendly error message.
Checklist
- I've reviewed existing issues and the architecture docs
- This is a design proposal, not a "please build this" request
- Linguagem predominante
- Rust
- Estrelas
- 15.4k
- Forks
- 1.7k
- Merge médio
- 1d 21h
- PRs com merge (30d)
- 358
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de NVIDIA/OpenShell
-
state:triage-needed
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 65/100
Mantenedores costumam responder em até 1 dia
-
state:triage-needed
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
Mantenedores costumam responder em até 1 dia
-
docs: document workspace and provider label capabilitiesTalvez já em andamento @johntmyers assumiu há 4 dias. Abertaarea:docs
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
NVIDIA/OpenShell#4250 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentTalvez já em andamento @feloy assumiu há 6 dias. Abertastate:triage-needed
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
Mantenedores costumam responder em até 1 dia
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configTalvez já em andamento @fede-kamel assumiu há 9 dias. Abertaarea:cli os:linux os:macos state:validated
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
NVIDIA/OpenShell#4042 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
Todas as issues de NVIDIA/OpenShell
Issues semelhantes
-
C-bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
rust-lang/rust-analyzer#23501 ·
Mantenedores costumam responder em até 1 dia
-
Streamable HTTP client: a 401 or 403 with a JSON-RPC error body and no WWW-Authenticate loses its HTTP statusTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Abertabug P2 ready for work T-security T-transport
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
modelcontextprotocol/rust-sdk#1339 ·
Mantenedores costumam responder em até 3 dias
-
French BIP39 wordlist starts with a UTF-8 BOM, so generated French mnemonics carry U+FEFF and derive a non-canonical seedTalvez já em andamento @Kshot3000 assumiu hoje. Aberta
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 91/100
ergoplatform/sigma-rust#976 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
Mantenedores costumam responder em até 1 dia
-
[Bug]: Web chat input doesn't regain focus after a reply finishesTalvez já em andamento @GaijinSystems assumiu hoje. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
zeroclaw-labs/zeroclaw#11658 ·
Mantenedores costumam responder em até 2 dias