Repository navigation
CLI login: send the browser to the styled result pages - #40
Conversation
The loopback login ended on a bare HTML page served by the CLI. The CLI now holds the browser on its callback until it has redeemed the login code and saved the session, then redirects to the SPA's /app/cli/auth/success page (restored) or the new /app/cli/auth/error page, which maps known error codes to fixed messages. Co-Authored-By: Claude <noreply@anthropic.com>
|
Warning Review limit reached
This review includes 13 billable files and costs up to $3.25.
Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing. Or wait 10 minutes for your next included review. View limit detailsLimit details: You’ve used all 2 included reviews currently available. Your 56 included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (13)
Comment |
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Oct 10, 2026 1:21a.m. | Review ↗ | |
| Go | Oct 10, 2026 1:21a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
The RFC 8252 loopback login (#22) ended on a bare HTML page served by the CLI ("Login approved"), replacing the styled
CLIAuthSuccessPagethe SPA used to show. This restores the styled pages and has the CLI send the browser to them.Changes
/app/cli/auth/success./app/cli/auth/error?error=<code>. The code is the gateway's own error code, or one of the CLI's:state_mismatch,missing_code, orcli_incomplete(redeeming or saving failed).Referrer-Policy: no-referrer(the callback URL carries the login code) andCache-Control: no-store.CLIAuthSuccessPage("Authentication Complete").CLIAuthErrorPage, which maps each known error code to a fixed title and description, plus "runrack-gateway loginto try again".finish, then sent to the success page. An unfinished login (redeem failure) goes tocli_incomplete. Gateway error, missing code and state mismatch each get their own redirect. An end-to-endrunLoopbackLogintest saves the session before the success redirect, and another sends a redeem failure to the error page.e2e/cli-loopback.tsnow behaves like the real one (redeems, then redirects), and the CLI login specs assert the browser lands on "Authentication Complete".internal/cli/CLAUDE.mddescribe the final redirect.Compatibility
A CLI from this branch talking to a v0.1.2 gateway lands on a route that gateway's SPA doesn't have. Deploy the gateway before switching CLIs, or together.
Verification
task cipasses locally.