fix(cli): complete session-local logout and document auth flows - #1044
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (47)
Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review. WalkthroughThe change updates native logout to use session-bound validation, detached renewal, publishable-key admission, and strict revocation confirmation. It adds CLI and persistent-auth coverage, documents authentication boundaries, and changes CLI release guidance from the preview channel to stable 0.1.0. ChangesAuthentication and CLI release
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant CLI
participant AuthClient
participant CredentialStore
participant SupabaseIssuer
CLI->>AuthClient: auth logout
AuthClient->>CredentialStore: clear local custody
AuthClient->>SupabaseIssuer: detached refresh if session is near expiry
AuthClient->>SupabaseIssuer: verify identity
AuthClient->>SupabaseIssuer: POST /logout?scope=local with Bearer and apikey
SupabaseIssuer-->>AuthClient: 200 or 204
AuthClient-->>CLI: confirmed revocation and signed-out status
Merge Risk: ⚪ Minimal · up to The session-local logout and stable CLI release changes are ready to merge. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 4.55% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 22 functions across 27 files. (20 skipped: 20 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
CLI logout clears local credentials but can leave remote revocation unconfirmed: its issuer logout request omits the public project admission key, and it cannot revoke an expired access session. This fixes the endpoint contract and logout lifecycle, with a cross-client auth blueprint explaining credential ownership and logout scope.
grida@0.1.0for npmlatest, with plainnpm install -g gridainstructions and the matching documentation guard.The cause is an integration-contract gap: successful OAuth token exchange and permissive local logout did not prove hosted logout admission. No database migration, new server endpoint, or production setting change is introduced. Web/Desktop logout scope is unchanged.
Validation: 444 auth tests passed (one opt-in real-keyring smoke skipped), 422 CLI tests passed, 52 repository typecheck tasks passed, guard/release tests passed, and all-locale docs build plus installed docs checks passed. Stable release metadata and the corresponding install-example guard also passed focused release/docs checks. Real local OAuth and the final packed CLI prove revocation and preservation of other sessions. Expiry coverage uses synthetic issuer expiry enforcement and explicitly bounded client-clock advancement against real local Auth; hosted installed acceptance remains a release gate.
Ready for peer review. No production mutation or npm publication has been performed.