Skip to content

CLI login: send the browser to the styled result pages - #40

Merged
ndbroadbent merged 1 commit into
mainfrom
nathan/cli-login-result-pages
Oct 10, 2026
Merged

ndbroadbent merged 1 commit into
mainfrom
nathan/cli-login-result-pages

Conversation

@ndbroadbent

Copy link
Copy Markdown
Member

The RFC 8252 loopback login (#22) ended on a bare HTML page served by the CLI ("Login approved"), replacing the styled CLIAuthSuccessPage the SPA used to show. This restores the styled pages and has the CLI send the browser to them.

Changes

  • CLI loopback listener:
    • It no longer renders HTML.
    • It holds the browser on the callback until the terminal has redeemed the login code and saved the session, then redirects with 303 to /app/cli/auth/success.
    • Failures redirect to /app/cli/auth/error?error=<code>. The code is the gateway's own error code, or one of the CLI's: state_mismatch, missing_code, or cli_incomplete (redeeming or saving failed).
    • The browser therefore shows how the login really ended, not just that a code arrived.
    • The redirect sends Referrer-Policy: no-referrer (the callback URL carries the login code) and Cache-Control: no-store.
  • SPA:
    • Restores CLIAuthSuccessPage ("Authentication Complete").
    • Adds CLIAuthErrorPage, which maps each known error code to a fixed title and description, plus "run rack-gateway login to try again".
    • Unknown codes get a generic message, and the code itself is never rendered, so a crafted link can't put text on the page.
  • Tests:
    • Go: the browser is held until finish, then sent to the success page. An unfinished login (redeem failure) goes to cli_incomplete. Gateway error, missing code and state mismatch each get their own redirect. An end-to-end runLoopbackLogin test saves the session before the success redirect, and another sends a redeem failure to the error page.
    • Vitest: known, CLI-side, unknown, prototype-key and missing codes on the error page.
    • Playwright: the fake CLI in e2e/cli-loopback.ts now behaves like the real one (redeems, then redirects), and the CLI login specs assert the browser lands on "Authentication Complete".
  • Docs: the CLI user guide, auth overview, OAuth flow page and internal/cli/CLAUDE.md describe the final redirect.

Compatibility

A CLI from this branch talking to a v0.1.2 gateway lands on a route that gateway's SPA doesn't have. Deploy the gateway before switching CLIs, or together.

Verification

task ci passes locally.

The loopback login ended on a bare HTML page served by the CLI. The CLI now holds
the browser on its callback until it has redeemed the login code and saved the
session, then redirects to the SPA's /app/cli/auth/success page (restored) or the
new /app/cli/auth/error page, which maps known error codes to fixed messages.

Co-Authored-By: Claude <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown

Warning

Review limit reached

  • Run on-demand review

This review includes 13 billable files and costs up to $3.25.

  • Ask an admin to make reviews automatic

Open in CodeRabbit

Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing.

Or wait 10 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used all 2 included reviews currently available. Your 56 included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 17d76180-13cf-4298-9f21-a9bb0ea91243

📥 Commits

Reviewing files that changed from the base of the PR and between bdfdb74 and 58a4285.


📒 Files selected for processing (13)
  • docs/src/content/docs/security/authentication/index.mdx
  • docs/src/content/docs/security/authentication/oauth-flow.mdx
  • docs/src/content/docs/user-guide/cli/authentication.mdx
  • internal/cli/CLAUDE.md
  • internal/cli/cli_login.go
  • internal/cli/login_loopback.go
  • internal/cli/login_loopback_test.go
  • web/e2e/cli-login-webui.spec.ts
  • web/e2e/cli-loopback.ts
  • web/src/app.tsx
  • web/src/pages/cli-auth-error-page.test.tsx
  • web/src/pages/cli-auth-error-page.tsx
  • web/src/pages/cli-auth-success-page.tsx


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@deepsource-io

deepsource-io Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in bdfdb74...58a4285 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
JavaScript Oct 10, 2026 1:21a.m. Review ↗
Go Oct 10, 2026 1:21a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@ndbroadbent
ndbroadbent merged commit 7534a7e into main Oct 10, 2026
12 checks passed
@ndbroadbent
ndbroadbent deleted the nathan/cli-login-result-pages branch October 10, 2026 01:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant