[codex] Preserve auth HTTP failure diagnostics - #3419

Closed
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics
Closed

[codex] Preserve auth HTTP failure diagnostics#3419
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Jun 20, 2026

Copy link
Copy Markdown
Member

Summary

  • retain exact underlying causes on typed auth HTTP 500 errors while keeping public JSON schemas redacted
  • log only bounded failure tags and reason counts, and suppress synthetic interruption failures
  • replace the remaining broad cookie catch with exhaustive catchTags handling

Validation

  • vp test apps/server/src/auth/http.test.ts apps/server/src/auth/EnvironmentAuth.test.ts
  • vp check (passes with 20 pre-existing warnings)
  • vp run typecheck

Stacked on #3240.


Note

Medium Risk
Touches auth HTTP 500 and logging paths where mishandling could hide real failures or leak data; changes are guarded by new tests and redacted API encoding.

Overview
Auth HTTP internal failures now keep the full underlying cause on a typed EnvironmentHttpInternalError, while public JSON still encodes only code, reason, and traceId (no raw errors in responses).

Logging no longer dumps full Cause/error objects. Request and operation failures log a bounded failureTag plus reason/failure/defect/interruption counts. Request finalizers skip logging when the exit is interrupt-only.

failEnvironmentInternal re-propagates nested interruption causes instead of turning them into synthetic 500s. browserSession cookie handling uses catchTags for CookieError only, passing the cause into internal failure handling.

Reviewed by Cursor Bugbot for commit f0537a8. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Preserve auth HTTP failure diagnostics by summarizing causes instead of serializing them

  • Replaces raw cause/error serialization in auth HTTP logs with bounded diagnostics: a trimmed failureTag and counts of failures, defects, and interruptions via a new failureLogAttributes helper.
  • Adds findInterruptCause to detect nested interruption causes and re-propagate them directly, avoiding conversion into synthetic internal errors and suppressing redundant logs.
  • Introduces EnvironmentHttpInternalError with a bounded failureTag field and preserved original cause as a defect, replacing the generic internal error type.
  • Limits annotateEnvironmentRequest finalizer so it skips logging entirely when the exit cause contains only interrupts.
  • Narrows the browserSession cookie error catch to only handle CookieError, letting other errors fall through to upstream handling.

Macroscope summarized f0537a8.

@coderabbitai

coderabbitaiBot commented Jun 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: a45a65f5-35b3-4d38-a1ea-48d64d1ce31c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/auth-http-diagnostics

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jun 20, 2026
@macroscopeapp

macroscopeappBot commented Jun 20, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Changes modify files in the auth directory (apps/server/src/auth/http.ts), which requires human review regardless of change complexity per security guidelines.

No code changes detected at f0537a8. Prior analysis still applies.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 0f8b837 to edf63a7CompareJune 20, 2026 22:46
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f476f6d to 519cb0aCompareJune 20, 2026 22:47
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from edf63a7 to d430f59CompareJune 20, 2026 22:50
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 519cb0a to 265d3cbCompareJune 20, 2026 22:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from d430f59 to fae19efCompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 265d3cb to 55daaa4CompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from fae19ef to 2b5e1cfCompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 55daaa4 to 6d9fb38CompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 2b5e1cf to 8728ebfCompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 6d9fb38 to 5697b83CompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 8728ebf to 55e9cd5CompareJune 21, 2026 00:08
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 5697b83 to a1f24c7CompareJune 21, 2026 00:08
Base automatically changed from codex/server-auth-error-boundaries to codex/redact-dpop-request-targetJune 21, 2026 00:14
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from a1f24c7 to c26e2ffCompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 70fdb85 to 5a80908CompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from c26e2ff to 89040c9CompareJune 21, 2026 00:28
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch 2 times, most recently from 553daf6 to ed36096CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 89040c9 to 2d37a35CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from ed36096 to 15aa01aCompareJune 21, 2026 01:10
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 2d37a35 to 307df64CompareJune 21, 2026 01:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Autofix Details

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Interrupt missed in Cause
    • Extracted the loop body into a recursive walkForInterrupt helper that, upon encountering a non-interrupt-only Cause, iterates its Fail reasons and continues walking each error's .cause chain to find nested interrupt causes.

Create PR

Or push these changes by commenting:

@cursor push 5780d93e6f
Preview (5780d93e6f)
diff --git a/apps/server/src/auth/http.ts b/apps/server/src/auth/http.ts--- a/apps/server/src/auth/http.ts+++ b/apps/server/src/auth/http.ts@@ -83,10 +83,27 @@
function findInterruptCause(input: unknown): Cause.Cause<never> | undefined {
const seen = new Set<object>();
+ return walkForInterrupt(input, seen, 0);+}++function walkForInterrupt(+ input: unknown,+ seen: Set<object>,+ depth: number,+): Cause.Cause<never> | undefined {
let current = input;
- for (let depth = 0; depth < MAX_CAUSE_CHAIN_DEPTH; depth += 1) {+ for (let d = depth; d < MAX_CAUSE_CHAIN_DEPTH; d += 1) {
if (Cause.isCause(current)) {
- return Cause.hasInterruptsOnly(current) ? (current as Cause.Cause<never>) : undefined;+ if (Cause.hasInterruptsOnly(current)) {+ return current as Cause.Cause<never>;+ }+ for (const reason of current.reasons) {+ if (Cause.isFailReason(reason)) {+ const found = walkForInterrupt(reason.error, seen, d + 1);+ if (found !== undefined) return found;+ }+ }+ return undefined;
}
if (typeof current !== "object" || current === null || seen.has(current)) {
return undefined;

You can send follow-ups to the cloud agent here.

Comment threadapps/server/src/auth/http.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 307df64 to 07d8a37CompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 15aa01a to bd937beCompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 07d8a37 to e9e9089CompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from bd937be to 517c1eaCompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 517c1ea to 8d916bcCompareJune 21, 2026 01:44
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from e9e9089 to 629ce09CompareJune 21, 2026 01:44
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 8d916bc to 7670d78CompareJune 21, 2026 01:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 629ce09 to 9c1fed6CompareJune 21, 2026 01:51
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 7670d78 to 1ed6271CompareJune 21, 2026 02:03
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 9c1fed6 to f5fe411CompareJune 21, 2026 02:04
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: IPC openExternal breaks boolean contract
    • Added Effect.orElseSucceed(() => false) to the IPC handler so that ElectronShellOpenExternalError is caught and returns false instead of rejecting the IPC call, preserving the boolean contract for renderer callers.

Create PR

Or push these changes by commenting:

@cursor push f71e08ecb0
Preview (f71e08ecb0)
diff --git a/apps/desktop/src/ipc/methods/window.ts b/apps/desktop/src/ipc/methods/window.ts--- a/apps/desktop/src/ipc/methods/window.ts+++ b/apps/desktop/src/ipc/methods/window.ts@@ -141,6 +141,6 @@
result: Schema.Boolean,
handler: Effect.fn("desktop.ipc.window.openExternal")(function* (url) {
const shell = yield* ElectronShell.ElectronShell;
- return yield* shell.openExternal(url);+ return yield* shell.openExternal(url).pipe(Effect.orElseSucceed(() => false));
}),
});

You can send follow-ups to the cloud agent here.

Reviewed by Cursor Bugbot for commit f5fe411934d709ab8dbc660896ff7eabf85c8222. Configure here.

Comment threadapps/desktop/src/electron/ElectronShell.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from c91fad6 to 9e0c536CompareJune 21, 2026 02:22
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f5fe411 to efacbf7CompareJune 21, 2026 02:24
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from efacbf7 to 15a2898CompareJune 21, 2026 02:44
juliusmarmingeand others added 2 commits June 20, 2026 20:12
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 15a2898 to f0537a8CompareJune 21, 2026 03:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[codex] Preserve auth HTTP failure diagnostics - #3419

Closed
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics
Closed

[codex] Preserve auth HTTP failure diagnostics#3419
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Jun 20, 2026

Copy link
Copy Markdown
Member

Summary

  • retain exact underlying causes on typed auth HTTP 500 errors while keeping public JSON schemas redacted
  • log only bounded failure tags and reason counts, and suppress synthetic interruption failures
  • replace the remaining broad cookie catch with exhaustive catchTags handling

Validation

  • vp test apps/server/src/auth/http.test.ts apps/server/src/auth/EnvironmentAuth.test.ts
  • vp check (passes with 20 pre-existing warnings)
  • vp run typecheck

Stacked on #3240.


Note

Medium Risk
Touches auth HTTP 500 and logging paths where mishandling could hide real failures or leak data; changes are guarded by new tests and redacted API encoding.

Overview
Auth HTTP internal failures now keep the full underlying cause on a typed EnvironmentHttpInternalError, while public JSON still encodes only code, reason, and traceId (no raw errors in responses).

Logging no longer dumps full Cause/error objects. Request and operation failures log a bounded failureTag plus reason/failure/defect/interruption counts. Request finalizers skip logging when the exit is interrupt-only.

failEnvironmentInternal re-propagates nested interruption causes instead of turning them into synthetic 500s. browserSession cookie handling uses catchTags for CookieError only, passing the cause into internal failure handling.

Reviewed by Cursor Bugbot for commit f0537a8. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Preserve auth HTTP failure diagnostics by summarizing causes instead of serializing them

  • Replaces raw cause/error serialization in auth HTTP logs with bounded diagnostics: a trimmed failureTag and counts of failures, defects, and interruptions via a new failureLogAttributes helper.
  • Adds findInterruptCause to detect nested interruption causes and re-propagate them directly, avoiding conversion into synthetic internal errors and suppressing redundant logs.
  • Introduces EnvironmentHttpInternalError with a bounded failureTag field and preserved original cause as a defect, replacing the generic internal error type.
  • Limits annotateEnvironmentRequest finalizer so it skips logging entirely when the exit cause contains only interrupts.
  • Narrows the browserSession cookie error catch to only handle CookieError, letting other errors fall through to upstream handling.

Macroscope summarized f0537a8.

@coderabbitai

coderabbitaiBot commented Jun 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: a45a65f5-35b3-4d38-a1ea-48d64d1ce31c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/auth-http-diagnostics

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jun 20, 2026
@macroscopeapp

macroscopeappBot commented Jun 20, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Changes modify files in the auth directory (apps/server/src/auth/http.ts), which requires human review regardless of change complexity per security guidelines.

No code changes detected at f0537a8. Prior analysis still applies.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 0f8b837 to edf63a7CompareJune 20, 2026 22:46
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f476f6d to 519cb0aCompareJune 20, 2026 22:47
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from edf63a7 to d430f59CompareJune 20, 2026 22:50
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 519cb0a to 265d3cbCompareJune 20, 2026 22:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from d430f59 to fae19efCompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 265d3cb to 55daaa4CompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from fae19ef to 2b5e1cfCompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 55daaa4 to 6d9fb38CompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 2b5e1cf to 8728ebfCompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 6d9fb38 to 5697b83CompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 8728ebf to 55e9cd5CompareJune 21, 2026 00:08
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 5697b83 to a1f24c7CompareJune 21, 2026 00:08
Base automatically changed from codex/server-auth-error-boundaries to codex/redact-dpop-request-targetJune 21, 2026 00:14
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from a1f24c7 to c26e2ffCompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 70fdb85 to 5a80908CompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from c26e2ff to 89040c9CompareJune 21, 2026 00:28
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch 2 times, most recently from 553daf6 to ed36096CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 89040c9 to 2d37a35CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from ed36096 to 15aa01aCompareJune 21, 2026 01:10
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 2d37a35 to 307df64CompareJune 21, 2026 01:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Autofix Details

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Interrupt missed in Cause
    • Extracted the loop body into a recursive walkForInterrupt helper that, upon encountering a non-interrupt-only Cause, iterates its Fail reasons and continues walking each error's .cause chain to find nested interrupt causes.

Create PR

Or push these changes by commenting:

@cursor push 5780d93e6f
Preview (5780d93e6f)
diff --git a/apps/server/src/auth/http.ts b/apps/server/src/auth/http.ts--- a/apps/server/src/auth/http.ts+++ b/apps/server/src/auth/http.ts@@ -83,10 +83,27 @@
function findInterruptCause(input: unknown): Cause.Cause<never> | undefined {
const seen = new Set<object>();
+ return walkForInterrupt(input, seen, 0);+}++function walkForInterrupt(+ input: unknown,+ seen: Set<object>,+ depth: number,+): Cause.Cause<never> | undefined {
let current = input;
- for (let depth = 0; depth < MAX_CAUSE_CHAIN_DEPTH; depth += 1) {+ for (let d = depth; d < MAX_CAUSE_CHAIN_DEPTH; d += 1) {
if (Cause.isCause(current)) {
- return Cause.hasInterruptsOnly(current) ? (current as Cause.Cause<never>) : undefined;+ if (Cause.hasInterruptsOnly(current)) {+ return current as Cause.Cause<never>;+ }+ for (const reason of current.reasons) {+ if (Cause.isFailReason(reason)) {+ const found = walkForInterrupt(reason.error, seen, d + 1);+ if (found !== undefined) return found;+ }+ }+ return undefined;
}
if (typeof current !== "object" || current === null || seen.has(current)) {
return undefined;

You can send follow-ups to the cloud agent here.

Comment threadapps/server/src/auth/http.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 307df64 to 07d8a37CompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 15aa01a to bd937beCompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 07d8a37 to e9e9089CompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from bd937be to 517c1eaCompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 517c1ea to 8d916bcCompareJune 21, 2026 01:44
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from e9e9089 to 629ce09CompareJune 21, 2026 01:44
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 8d916bc to 7670d78CompareJune 21, 2026 01:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 629ce09 to 9c1fed6CompareJune 21, 2026 01:51
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 7670d78 to 1ed6271CompareJune 21, 2026 02:03
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 9c1fed6 to f5fe411CompareJune 21, 2026 02:04
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: IPC openExternal breaks boolean contract
    • Added Effect.orElseSucceed(() => false) to the IPC handler so that ElectronShellOpenExternalError is caught and returns false instead of rejecting the IPC call, preserving the boolean contract for renderer callers.

Create PR

Or push these changes by commenting:

@cursor push f71e08ecb0
Preview (f71e08ecb0)
diff --git a/apps/desktop/src/ipc/methods/window.ts b/apps/desktop/src/ipc/methods/window.ts--- a/apps/desktop/src/ipc/methods/window.ts+++ b/apps/desktop/src/ipc/methods/window.ts@@ -141,6 +141,6 @@
result: Schema.Boolean,
handler: Effect.fn("desktop.ipc.window.openExternal")(function* (url) {
const shell = yield* ElectronShell.ElectronShell;
- return yield* shell.openExternal(url);+ return yield* shell.openExternal(url).pipe(Effect.orElseSucceed(() => false));
}),
});

You can send follow-ups to the cloud agent here.

Reviewed by Cursor Bugbot for commit f5fe411934d709ab8dbc660896ff7eabf85c8222. Configure here.

Comment threadapps/desktop/src/electron/ElectronShell.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from c91fad6 to 9e0c536CompareJune 21, 2026 02:22
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f5fe411 to efacbf7CompareJune 21, 2026 02:24
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from efacbf7 to 15a2898CompareJune 21, 2026 02:44
juliusmarmingeand others added 2 commits June 20, 2026 20:12
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 15a2898 to f0537a8CompareJune 21, 2026 03:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[codex] Preserve auth HTTP failure diagnostics - #3419

Closed
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics
Closed

[codex] Preserve auth HTTP failure diagnostics#3419
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Jun 20, 2026

Copy link
Copy Markdown
Member

Summary

  • retain exact underlying causes on typed auth HTTP 500 errors while keeping public JSON schemas redacted
  • log only bounded failure tags and reason counts, and suppress synthetic interruption failures
  • replace the remaining broad cookie catch with exhaustive catchTags handling

Validation

  • vp test apps/server/src/auth/http.test.ts apps/server/src/auth/EnvironmentAuth.test.ts
  • vp check (passes with 20 pre-existing warnings)
  • vp run typecheck

Stacked on #3240.


Note

Medium Risk
Touches auth HTTP 500 and logging paths where mishandling could hide real failures or leak data; changes are guarded by new tests and redacted API encoding.

Overview
Auth HTTP internal failures now keep the full underlying cause on a typed EnvironmentHttpInternalError, while public JSON still encodes only code, reason, and traceId (no raw errors in responses).

Logging no longer dumps full Cause/error objects. Request and operation failures log a bounded failureTag plus reason/failure/defect/interruption counts. Request finalizers skip logging when the exit is interrupt-only.

failEnvironmentInternal re-propagates nested interruption causes instead of turning them into synthetic 500s. browserSession cookie handling uses catchTags for CookieError only, passing the cause into internal failure handling.

Reviewed by Cursor Bugbot for commit f0537a8. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Preserve auth HTTP failure diagnostics by summarizing causes instead of serializing them

  • Replaces raw cause/error serialization in auth HTTP logs with bounded diagnostics: a trimmed failureTag and counts of failures, defects, and interruptions via a new failureLogAttributes helper.
  • Adds findInterruptCause to detect nested interruption causes and re-propagate them directly, avoiding conversion into synthetic internal errors and suppressing redundant logs.
  • Introduces EnvironmentHttpInternalError with a bounded failureTag field and preserved original cause as a defect, replacing the generic internal error type.
  • Limits annotateEnvironmentRequest finalizer so it skips logging entirely when the exit cause contains only interrupts.
  • Narrows the browserSession cookie error catch to only handle CookieError, letting other errors fall through to upstream handling.

Macroscope summarized f0537a8.

@coderabbitai

coderabbitaiBot commented Jun 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: a45a65f5-35b3-4d38-a1ea-48d64d1ce31c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/auth-http-diagnostics

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jun 20, 2026
@macroscopeapp

macroscopeappBot commented Jun 20, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Changes modify files in the auth directory (apps/server/src/auth/http.ts), which requires human review regardless of change complexity per security guidelines.

No code changes detected at f0537a8. Prior analysis still applies.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 0f8b837 to edf63a7CompareJune 20, 2026 22:46
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f476f6d to 519cb0aCompareJune 20, 2026 22:47
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from edf63a7 to d430f59CompareJune 20, 2026 22:50
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 519cb0a to 265d3cbCompareJune 20, 2026 22:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from d430f59 to fae19efCompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 265d3cb to 55daaa4CompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from fae19ef to 2b5e1cfCompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 55daaa4 to 6d9fb38CompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 2b5e1cf to 8728ebfCompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 6d9fb38 to 5697b83CompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 8728ebf to 55e9cd5CompareJune 21, 2026 00:08
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 5697b83 to a1f24c7CompareJune 21, 2026 00:08
Base automatically changed from codex/server-auth-error-boundaries to codex/redact-dpop-request-targetJune 21, 2026 00:14
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from a1f24c7 to c26e2ffCompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 70fdb85 to 5a80908CompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from c26e2ff to 89040c9CompareJune 21, 2026 00:28
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch 2 times, most recently from 553daf6 to ed36096CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 89040c9 to 2d37a35CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from ed36096 to 15aa01aCompareJune 21, 2026 01:10
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 2d37a35 to 307df64CompareJune 21, 2026 01:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Autofix Details

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Interrupt missed in Cause
    • Extracted the loop body into a recursive walkForInterrupt helper that, upon encountering a non-interrupt-only Cause, iterates its Fail reasons and continues walking each error's .cause chain to find nested interrupt causes.

Create PR

Or push these changes by commenting:

@cursor push 5780d93e6f
Preview (5780d93e6f)
diff --git a/apps/server/src/auth/http.ts b/apps/server/src/auth/http.ts--- a/apps/server/src/auth/http.ts+++ b/apps/server/src/auth/http.ts@@ -83,10 +83,27 @@
function findInterruptCause(input: unknown): Cause.Cause<never> | undefined {
const seen = new Set<object>();
+ return walkForInterrupt(input, seen, 0);+}++function walkForInterrupt(+ input: unknown,+ seen: Set<object>,+ depth: number,+): Cause.Cause<never> | undefined {
let current = input;
- for (let depth = 0; depth < MAX_CAUSE_CHAIN_DEPTH; depth += 1) {+ for (let d = depth; d < MAX_CAUSE_CHAIN_DEPTH; d += 1) {
if (Cause.isCause(current)) {
- return Cause.hasInterruptsOnly(current) ? (current as Cause.Cause<never>) : undefined;+ if (Cause.hasInterruptsOnly(current)) {+ return current as Cause.Cause<never>;+ }+ for (const reason of current.reasons) {+ if (Cause.isFailReason(reason)) {+ const found = walkForInterrupt(reason.error, seen, d + 1);+ if (found !== undefined) return found;+ }+ }+ return undefined;
}
if (typeof current !== "object" || current === null || seen.has(current)) {
return undefined;

You can send follow-ups to the cloud agent here.

Comment threadapps/server/src/auth/http.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 307df64 to 07d8a37CompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 15aa01a to bd937beCompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 07d8a37 to e9e9089CompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from bd937be to 517c1eaCompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 517c1ea to 8d916bcCompareJune 21, 2026 01:44
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from e9e9089 to 629ce09CompareJune 21, 2026 01:44
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 8d916bc to 7670d78CompareJune 21, 2026 01:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 629ce09 to 9c1fed6CompareJune 21, 2026 01:51
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 7670d78 to 1ed6271CompareJune 21, 2026 02:03
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 9c1fed6 to f5fe411CompareJune 21, 2026 02:04
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: IPC openExternal breaks boolean contract
    • Added Effect.orElseSucceed(() => false) to the IPC handler so that ElectronShellOpenExternalError is caught and returns false instead of rejecting the IPC call, preserving the boolean contract for renderer callers.

Create PR

Or push these changes by commenting:

@cursor push f71e08ecb0
Preview (f71e08ecb0)
diff --git a/apps/desktop/src/ipc/methods/window.ts b/apps/desktop/src/ipc/methods/window.ts--- a/apps/desktop/src/ipc/methods/window.ts+++ b/apps/desktop/src/ipc/methods/window.ts@@ -141,6 +141,6 @@
result: Schema.Boolean,
handler: Effect.fn("desktop.ipc.window.openExternal")(function* (url) {
const shell = yield* ElectronShell.ElectronShell;
- return yield* shell.openExternal(url);+ return yield* shell.openExternal(url).pipe(Effect.orElseSucceed(() => false));
}),
});

You can send follow-ups to the cloud agent here.

Reviewed by Cursor Bugbot for commit f5fe411934d709ab8dbc660896ff7eabf85c8222. Configure here.

Comment threadapps/desktop/src/electron/ElectronShell.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from c91fad6 to 9e0c536CompareJune 21, 2026 02:22
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f5fe411 to efacbf7CompareJune 21, 2026 02:24
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from efacbf7 to 15a2898CompareJune 21, 2026 02:44
juliusmarmingeand others added 2 commits June 20, 2026 20:12
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 15a2898 to f0537a8CompareJune 21, 2026 03:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[codex] Preserve auth HTTP failure diagnostics - #3419

Closed
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics
Closed

[codex] Preserve auth HTTP failure diagnostics#3419
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Jun 20, 2026

Copy link
Copy Markdown
Member

Summary

  • retain exact underlying causes on typed auth HTTP 500 errors while keeping public JSON schemas redacted
  • log only bounded failure tags and reason counts, and suppress synthetic interruption failures
  • replace the remaining broad cookie catch with exhaustive catchTags handling

Validation

  • vp test apps/server/src/auth/http.test.ts apps/server/src/auth/EnvironmentAuth.test.ts
  • vp check (passes with 20 pre-existing warnings)
  • vp run typecheck

Stacked on #3240.


Note

Medium Risk
Touches auth HTTP 500 and logging paths where mishandling could hide real failures or leak data; changes are guarded by new tests and redacted API encoding.

Overview
Auth HTTP internal failures now keep the full underlying cause on a typed EnvironmentHttpInternalError, while public JSON still encodes only code, reason, and traceId (no raw errors in responses).

Logging no longer dumps full Cause/error objects. Request and operation failures log a bounded failureTag plus reason/failure/defect/interruption counts. Request finalizers skip logging when the exit is interrupt-only.

failEnvironmentInternal re-propagates nested interruption causes instead of turning them into synthetic 500s. browserSession cookie handling uses catchTags for CookieError only, passing the cause into internal failure handling.

Reviewed by Cursor Bugbot for commit f0537a8. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Preserve auth HTTP failure diagnostics by summarizing causes instead of serializing them

  • Replaces raw cause/error serialization in auth HTTP logs with bounded diagnostics: a trimmed failureTag and counts of failures, defects, and interruptions via a new failureLogAttributes helper.
  • Adds findInterruptCause to detect nested interruption causes and re-propagate them directly, avoiding conversion into synthetic internal errors and suppressing redundant logs.
  • Introduces EnvironmentHttpInternalError with a bounded failureTag field and preserved original cause as a defect, replacing the generic internal error type.
  • Limits annotateEnvironmentRequest finalizer so it skips logging entirely when the exit cause contains only interrupts.
  • Narrows the browserSession cookie error catch to only handle CookieError, letting other errors fall through to upstream handling.

Macroscope summarized f0537a8.

@coderabbitai

coderabbitaiBot commented Jun 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: a45a65f5-35b3-4d38-a1ea-48d64d1ce31c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/auth-http-diagnostics

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jun 20, 2026
@macroscopeapp

macroscopeappBot commented Jun 20, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Changes modify files in the auth directory (apps/server/src/auth/http.ts), which requires human review regardless of change complexity per security guidelines.

No code changes detected at f0537a8. Prior analysis still applies.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 0f8b837 to edf63a7CompareJune 20, 2026 22:46
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f476f6d to 519cb0aCompareJune 20, 2026 22:47
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from edf63a7 to d430f59CompareJune 20, 2026 22:50
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 519cb0a to 265d3cbCompareJune 20, 2026 22:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from d430f59 to fae19efCompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 265d3cb to 55daaa4CompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from fae19ef to 2b5e1cfCompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 55daaa4 to 6d9fb38CompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 2b5e1cf to 8728ebfCompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 6d9fb38 to 5697b83CompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 8728ebf to 55e9cd5CompareJune 21, 2026 00:08
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 5697b83 to a1f24c7CompareJune 21, 2026 00:08
Base automatically changed from codex/server-auth-error-boundaries to codex/redact-dpop-request-targetJune 21, 2026 00:14
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from a1f24c7 to c26e2ffCompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 70fdb85 to 5a80908CompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from c26e2ff to 89040c9CompareJune 21, 2026 00:28
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch 2 times, most recently from 553daf6 to ed36096CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 89040c9 to 2d37a35CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from ed36096 to 15aa01aCompareJune 21, 2026 01:10
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 2d37a35 to 307df64CompareJune 21, 2026 01:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Autofix Details

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Interrupt missed in Cause
    • Extracted the loop body into a recursive walkForInterrupt helper that, upon encountering a non-interrupt-only Cause, iterates its Fail reasons and continues walking each error's .cause chain to find nested interrupt causes.

Create PR

Or push these changes by commenting:

@cursor push 5780d93e6f
Preview (5780d93e6f)
diff --git a/apps/server/src/auth/http.ts b/apps/server/src/auth/http.ts--- a/apps/server/src/auth/http.ts+++ b/apps/server/src/auth/http.ts@@ -83,10 +83,27 @@
function findInterruptCause(input: unknown): Cause.Cause<never> | undefined {
const seen = new Set<object>();
+ return walkForInterrupt(input, seen, 0);+}++function walkForInterrupt(+ input: unknown,+ seen: Set<object>,+ depth: number,+): Cause.Cause<never> | undefined {
let current = input;
- for (let depth = 0; depth < MAX_CAUSE_CHAIN_DEPTH; depth += 1) {+ for (let d = depth; d < MAX_CAUSE_CHAIN_DEPTH; d += 1) {
if (Cause.isCause(current)) {
- return Cause.hasInterruptsOnly(current) ? (current as Cause.Cause<never>) : undefined;+ if (Cause.hasInterruptsOnly(current)) {+ return current as Cause.Cause<never>;+ }+ for (const reason of current.reasons) {+ if (Cause.isFailReason(reason)) {+ const found = walkForInterrupt(reason.error, seen, d + 1);+ if (found !== undefined) return found;+ }+ }+ return undefined;
}
if (typeof current !== "object" || current === null || seen.has(current)) {
return undefined;

You can send follow-ups to the cloud agent here.

Comment threadapps/server/src/auth/http.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 307df64 to 07d8a37CompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 15aa01a to bd937beCompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 07d8a37 to e9e9089CompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from bd937be to 517c1eaCompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 517c1ea to 8d916bcCompareJune 21, 2026 01:44
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from e9e9089 to 629ce09CompareJune 21, 2026 01:44
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 8d916bc to 7670d78CompareJune 21, 2026 01:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 629ce09 to 9c1fed6CompareJune 21, 2026 01:51
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 7670d78 to 1ed6271CompareJune 21, 2026 02:03
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 9c1fed6 to f5fe411CompareJune 21, 2026 02:04
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: IPC openExternal breaks boolean contract
    • Added Effect.orElseSucceed(() => false) to the IPC handler so that ElectronShellOpenExternalError is caught and returns false instead of rejecting the IPC call, preserving the boolean contract for renderer callers.

Create PR

Or push these changes by commenting:

@cursor push f71e08ecb0
Preview (f71e08ecb0)
diff --git a/apps/desktop/src/ipc/methods/window.ts b/apps/desktop/src/ipc/methods/window.ts--- a/apps/desktop/src/ipc/methods/window.ts+++ b/apps/desktop/src/ipc/methods/window.ts@@ -141,6 +141,6 @@
result: Schema.Boolean,
handler: Effect.fn("desktop.ipc.window.openExternal")(function* (url) {
const shell = yield* ElectronShell.ElectronShell;
- return yield* shell.openExternal(url);+ return yield* shell.openExternal(url).pipe(Effect.orElseSucceed(() => false));
}),
});

You can send follow-ups to the cloud agent here.

Reviewed by Cursor Bugbot for commit f5fe411934d709ab8dbc660896ff7eabf85c8222. Configure here.

Comment threadapps/desktop/src/electron/ElectronShell.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from c91fad6 to 9e0c536CompareJune 21, 2026 02:22
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f5fe411 to efacbf7CompareJune 21, 2026 02:24
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from efacbf7 to 15a2898CompareJune 21, 2026 02:44
juliusmarmingeand others added 2 commits June 20, 2026 20:12
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 15a2898 to f0537a8CompareJune 21, 2026 03:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[codex] Preserve auth HTTP failure diagnostics - #3419

Closed
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics
Closed

[codex] Preserve auth HTTP failure diagnostics#3419
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Jun 20, 2026

Copy link
Copy Markdown
Member

Summary

  • retain exact underlying causes on typed auth HTTP 500 errors while keeping public JSON schemas redacted
  • log only bounded failure tags and reason counts, and suppress synthetic interruption failures
  • replace the remaining broad cookie catch with exhaustive catchTags handling

Validation

  • vp test apps/server/src/auth/http.test.ts apps/server/src/auth/EnvironmentAuth.test.ts
  • vp check (passes with 20 pre-existing warnings)
  • vp run typecheck

Stacked on #3240.


Note

Medium Risk
Touches auth HTTP 500 and logging paths where mishandling could hide real failures or leak data; changes are guarded by new tests and redacted API encoding.

Overview
Auth HTTP internal failures now keep the full underlying cause on a typed EnvironmentHttpInternalError, while public JSON still encodes only code, reason, and traceId (no raw errors in responses).

Logging no longer dumps full Cause/error objects. Request and operation failures log a bounded failureTag plus reason/failure/defect/interruption counts. Request finalizers skip logging when the exit is interrupt-only.

failEnvironmentInternal re-propagates nested interruption causes instead of turning them into synthetic 500s. browserSession cookie handling uses catchTags for CookieError only, passing the cause into internal failure handling.

Reviewed by Cursor Bugbot for commit f0537a8. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Preserve auth HTTP failure diagnostics by summarizing causes instead of serializing them

  • Replaces raw cause/error serialization in auth HTTP logs with bounded diagnostics: a trimmed failureTag and counts of failures, defects, and interruptions via a new failureLogAttributes helper.
  • Adds findInterruptCause to detect nested interruption causes and re-propagate them directly, avoiding conversion into synthetic internal errors and suppressing redundant logs.
  • Introduces EnvironmentHttpInternalError with a bounded failureTag field and preserved original cause as a defect, replacing the generic internal error type.
  • Limits annotateEnvironmentRequest finalizer so it skips logging entirely when the exit cause contains only interrupts.
  • Narrows the browserSession cookie error catch to only handle CookieError, letting other errors fall through to upstream handling.

Macroscope summarized f0537a8.

@coderabbitai

coderabbitaiBot commented Jun 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: a45a65f5-35b3-4d38-a1ea-48d64d1ce31c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/auth-http-diagnostics

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jun 20, 2026
@macroscopeapp

macroscopeappBot commented Jun 20, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Changes modify files in the auth directory (apps/server/src/auth/http.ts), which requires human review regardless of change complexity per security guidelines.

No code changes detected at f0537a8. Prior analysis still applies.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 0f8b837 to edf63a7CompareJune 20, 2026 22:46
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f476f6d to 519cb0aCompareJune 20, 2026 22:47
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from edf63a7 to d430f59CompareJune 20, 2026 22:50
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 519cb0a to 265d3cbCompareJune 20, 2026 22:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from d430f59 to fae19efCompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 265d3cb to 55daaa4CompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from fae19ef to 2b5e1cfCompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 55daaa4 to 6d9fb38CompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 2b5e1cf to 8728ebfCompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 6d9fb38 to 5697b83CompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 8728ebf to 55e9cd5CompareJune 21, 2026 00:08
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 5697b83 to a1f24c7CompareJune 21, 2026 00:08
Base automatically changed from codex/server-auth-error-boundaries to codex/redact-dpop-request-targetJune 21, 2026 00:14
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from a1f24c7 to c26e2ffCompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 70fdb85 to 5a80908CompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from c26e2ff to 89040c9CompareJune 21, 2026 00:28
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch 2 times, most recently from 553daf6 to ed36096CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 89040c9 to 2d37a35CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from ed36096 to 15aa01aCompareJune 21, 2026 01:10
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 2d37a35 to 307df64CompareJune 21, 2026 01:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Autofix Details

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Interrupt missed in Cause
    • Extracted the loop body into a recursive walkForInterrupt helper that, upon encountering a non-interrupt-only Cause, iterates its Fail reasons and continues walking each error's .cause chain to find nested interrupt causes.

Create PR

Or push these changes by commenting:

@cursor push 5780d93e6f
Preview (5780d93e6f)
diff --git a/apps/server/src/auth/http.ts b/apps/server/src/auth/http.ts--- a/apps/server/src/auth/http.ts+++ b/apps/server/src/auth/http.ts@@ -83,10 +83,27 @@
function findInterruptCause(input: unknown): Cause.Cause<never> | undefined {
const seen = new Set<object>();
+ return walkForInterrupt(input, seen, 0);+}++function walkForInterrupt(+ input: unknown,+ seen: Set<object>,+ depth: number,+): Cause.Cause<never> | undefined {
let current = input;
- for (let depth = 0; depth < MAX_CAUSE_CHAIN_DEPTH; depth += 1) {+ for (let d = depth; d < MAX_CAUSE_CHAIN_DEPTH; d += 1) {
if (Cause.isCause(current)) {
- return Cause.hasInterruptsOnly(current) ? (current as Cause.Cause<never>) : undefined;+ if (Cause.hasInterruptsOnly(current)) {+ return current as Cause.Cause<never>;+ }+ for (const reason of current.reasons) {+ if (Cause.isFailReason(reason)) {+ const found = walkForInterrupt(reason.error, seen, d + 1);+ if (found !== undefined) return found;+ }+ }+ return undefined;
}
if (typeof current !== "object" || current === null || seen.has(current)) {
return undefined;

You can send follow-ups to the cloud agent here.

Comment threadapps/server/src/auth/http.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 307df64 to 07d8a37CompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 15aa01a to bd937beCompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 07d8a37 to e9e9089CompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from bd937be to 517c1eaCompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 517c1ea to 8d916bcCompareJune 21, 2026 01:44
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from e9e9089 to 629ce09CompareJune 21, 2026 01:44
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 8d916bc to 7670d78CompareJune 21, 2026 01:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 629ce09 to 9c1fed6CompareJune 21, 2026 01:51
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 7670d78 to 1ed6271CompareJune 21, 2026 02:03
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 9c1fed6 to f5fe411CompareJune 21, 2026 02:04
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: IPC openExternal breaks boolean contract
    • Added Effect.orElseSucceed(() => false) to the IPC handler so that ElectronShellOpenExternalError is caught and returns false instead of rejecting the IPC call, preserving the boolean contract for renderer callers.

Create PR

Or push these changes by commenting:

@cursor push f71e08ecb0
Preview (f71e08ecb0)
diff --git a/apps/desktop/src/ipc/methods/window.ts b/apps/desktop/src/ipc/methods/window.ts--- a/apps/desktop/src/ipc/methods/window.ts+++ b/apps/desktop/src/ipc/methods/window.ts@@ -141,6 +141,6 @@
result: Schema.Boolean,
handler: Effect.fn("desktop.ipc.window.openExternal")(function* (url) {
const shell = yield* ElectronShell.ElectronShell;
- return yield* shell.openExternal(url);+ return yield* shell.openExternal(url).pipe(Effect.orElseSucceed(() => false));
}),
});

You can send follow-ups to the cloud agent here.

Reviewed by Cursor Bugbot for commit f5fe411934d709ab8dbc660896ff7eabf85c8222. Configure here.

Comment threadapps/desktop/src/electron/ElectronShell.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from c91fad6 to 9e0c536CompareJune 21, 2026 02:22
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f5fe411 to efacbf7CompareJune 21, 2026 02:24
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from efacbf7 to 15a2898CompareJune 21, 2026 02:44
juliusmarmingeand others added 2 commits June 20, 2026 20:12
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 15a2898 to f0537a8CompareJune 21, 2026 03:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[codex] Preserve auth HTTP failure diagnostics - #3419

Closed
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics
Closed

[codex] Preserve auth HTTP failure diagnostics#3419
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Jun 20, 2026

Copy link
Copy Markdown
Member

Summary

  • retain exact underlying causes on typed auth HTTP 500 errors while keeping public JSON schemas redacted
  • log only bounded failure tags and reason counts, and suppress synthetic interruption failures
  • replace the remaining broad cookie catch with exhaustive catchTags handling

Validation

  • vp test apps/server/src/auth/http.test.ts apps/server/src/auth/EnvironmentAuth.test.ts
  • vp check (passes with 20 pre-existing warnings)
  • vp run typecheck

Stacked on #3240.


Note

Medium Risk
Touches auth HTTP 500 and logging paths where mishandling could hide real failures or leak data; changes are guarded by new tests and redacted API encoding.

Overview
Auth HTTP internal failures now keep the full underlying cause on a typed EnvironmentHttpInternalError, while public JSON still encodes only code, reason, and traceId (no raw errors in responses).

Logging no longer dumps full Cause/error objects. Request and operation failures log a bounded failureTag plus reason/failure/defect/interruption counts. Request finalizers skip logging when the exit is interrupt-only.

failEnvironmentInternal re-propagates nested interruption causes instead of turning them into synthetic 500s. browserSession cookie handling uses catchTags for CookieError only, passing the cause into internal failure handling.

Reviewed by Cursor Bugbot for commit f0537a8. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Preserve auth HTTP failure diagnostics by summarizing causes instead of serializing them

  • Replaces raw cause/error serialization in auth HTTP logs with bounded diagnostics: a trimmed failureTag and counts of failures, defects, and interruptions via a new failureLogAttributes helper.
  • Adds findInterruptCause to detect nested interruption causes and re-propagate them directly, avoiding conversion into synthetic internal errors and suppressing redundant logs.
  • Introduces EnvironmentHttpInternalError with a bounded failureTag field and preserved original cause as a defect, replacing the generic internal error type.
  • Limits annotateEnvironmentRequest finalizer so it skips logging entirely when the exit cause contains only interrupts.
  • Narrows the browserSession cookie error catch to only handle CookieError, letting other errors fall through to upstream handling.

Macroscope summarized f0537a8.

@coderabbitai

coderabbitaiBot commented Jun 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: a45a65f5-35b3-4d38-a1ea-48d64d1ce31c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/auth-http-diagnostics

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jun 20, 2026
@macroscopeapp

macroscopeappBot commented Jun 20, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Changes modify files in the auth directory (apps/server/src/auth/http.ts), which requires human review regardless of change complexity per security guidelines.

No code changes detected at f0537a8. Prior analysis still applies.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 0f8b837 to edf63a7CompareJune 20, 2026 22:46
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f476f6d to 519cb0aCompareJune 20, 2026 22:47
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from edf63a7 to d430f59CompareJune 20, 2026 22:50
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 519cb0a to 265d3cbCompareJune 20, 2026 22:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from d430f59 to fae19efCompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 265d3cb to 55daaa4CompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from fae19ef to 2b5e1cfCompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 55daaa4 to 6d9fb38CompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 2b5e1cf to 8728ebfCompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 6d9fb38 to 5697b83CompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 8728ebf to 55e9cd5CompareJune 21, 2026 00:08
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 5697b83 to a1f24c7CompareJune 21, 2026 00:08
Base automatically changed from codex/server-auth-error-boundaries to codex/redact-dpop-request-targetJune 21, 2026 00:14
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from a1f24c7 to c26e2ffCompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 70fdb85 to 5a80908CompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from c26e2ff to 89040c9CompareJune 21, 2026 00:28
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch 2 times, most recently from 553daf6 to ed36096CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 89040c9 to 2d37a35CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from ed36096 to 15aa01aCompareJune 21, 2026 01:10
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 2d37a35 to 307df64CompareJune 21, 2026 01:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Autofix Details

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Interrupt missed in Cause
    • Extracted the loop body into a recursive walkForInterrupt helper that, upon encountering a non-interrupt-only Cause, iterates its Fail reasons and continues walking each error's .cause chain to find nested interrupt causes.

Create PR

Or push these changes by commenting:

@cursor push 5780d93e6f
Preview (5780d93e6f)
diff --git a/apps/server/src/auth/http.ts b/apps/server/src/auth/http.ts--- a/apps/server/src/auth/http.ts+++ b/apps/server/src/auth/http.ts@@ -83,10 +83,27 @@
function findInterruptCause(input: unknown): Cause.Cause<never> | undefined {
const seen = new Set<object>();
+ return walkForInterrupt(input, seen, 0);+}++function walkForInterrupt(+ input: unknown,+ seen: Set<object>,+ depth: number,+): Cause.Cause<never> | undefined {
let current = input;
- for (let depth = 0; depth < MAX_CAUSE_CHAIN_DEPTH; depth += 1) {+ for (let d = depth; d < MAX_CAUSE_CHAIN_DEPTH; d += 1) {
if (Cause.isCause(current)) {
- return Cause.hasInterruptsOnly(current) ? (current as Cause.Cause<never>) : undefined;+ if (Cause.hasInterruptsOnly(current)) {+ return current as Cause.Cause<never>;+ }+ for (const reason of current.reasons) {+ if (Cause.isFailReason(reason)) {+ const found = walkForInterrupt(reason.error, seen, d + 1);+ if (found !== undefined) return found;+ }+ }+ return undefined;
}
if (typeof current !== "object" || current === null || seen.has(current)) {
return undefined;

You can send follow-ups to the cloud agent here.

Comment threadapps/server/src/auth/http.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 307df64 to 07d8a37CompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 15aa01a to bd937beCompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 07d8a37 to e9e9089CompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from bd937be to 517c1eaCompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 517c1ea to 8d916bcCompareJune 21, 2026 01:44
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from e9e9089 to 629ce09CompareJune 21, 2026 01:44
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 8d916bc to 7670d78CompareJune 21, 2026 01:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 629ce09 to 9c1fed6CompareJune 21, 2026 01:51
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 7670d78 to 1ed6271CompareJune 21, 2026 02:03
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 9c1fed6 to f5fe411CompareJune 21, 2026 02:04
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: IPC openExternal breaks boolean contract
    • Added Effect.orElseSucceed(() => false) to the IPC handler so that ElectronShellOpenExternalError is caught and returns false instead of rejecting the IPC call, preserving the boolean contract for renderer callers.

Create PR

Or push these changes by commenting:

@cursor push f71e08ecb0
Preview (f71e08ecb0)
diff --git a/apps/desktop/src/ipc/methods/window.ts b/apps/desktop/src/ipc/methods/window.ts--- a/apps/desktop/src/ipc/methods/window.ts+++ b/apps/desktop/src/ipc/methods/window.ts@@ -141,6 +141,6 @@
result: Schema.Boolean,
handler: Effect.fn("desktop.ipc.window.openExternal")(function* (url) {
const shell = yield* ElectronShell.ElectronShell;
- return yield* shell.openExternal(url);+ return yield* shell.openExternal(url).pipe(Effect.orElseSucceed(() => false));
}),
});

You can send follow-ups to the cloud agent here.

Reviewed by Cursor Bugbot for commit f5fe411934d709ab8dbc660896ff7eabf85c8222. Configure here.

Comment threadapps/desktop/src/electron/ElectronShell.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from c91fad6 to 9e0c536CompareJune 21, 2026 02:22
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f5fe411 to efacbf7CompareJune 21, 2026 02:24
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from efacbf7 to 15a2898CompareJune 21, 2026 02:44
juliusmarmingeand others added 2 commits June 20, 2026 20:12
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 15a2898 to f0537a8CompareJune 21, 2026 03:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[codex] Preserve auth HTTP failure diagnostics - #3419

Closed
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics
Closed

[codex] Preserve auth HTTP failure diagnostics#3419
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Jun 20, 2026

Copy link
Copy Markdown
Member

Summary

  • retain exact underlying causes on typed auth HTTP 500 errors while keeping public JSON schemas redacted
  • log only bounded failure tags and reason counts, and suppress synthetic interruption failures
  • replace the remaining broad cookie catch with exhaustive catchTags handling

Validation

  • vp test apps/server/src/auth/http.test.ts apps/server/src/auth/EnvironmentAuth.test.ts
  • vp check (passes with 20 pre-existing warnings)
  • vp run typecheck

Stacked on #3240.


Note

Medium Risk
Touches auth HTTP 500 and logging paths where mishandling could hide real failures or leak data; changes are guarded by new tests and redacted API encoding.

Overview
Auth HTTP internal failures now keep the full underlying cause on a typed EnvironmentHttpInternalError, while public JSON still encodes only code, reason, and traceId (no raw errors in responses).

Logging no longer dumps full Cause/error objects. Request and operation failures log a bounded failureTag plus reason/failure/defect/interruption counts. Request finalizers skip logging when the exit is interrupt-only.

failEnvironmentInternal re-propagates nested interruption causes instead of turning them into synthetic 500s. browserSession cookie handling uses catchTags for CookieError only, passing the cause into internal failure handling.

Reviewed by Cursor Bugbot for commit f0537a8. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Preserve auth HTTP failure diagnostics by summarizing causes instead of serializing them

  • Replaces raw cause/error serialization in auth HTTP logs with bounded diagnostics: a trimmed failureTag and counts of failures, defects, and interruptions via a new failureLogAttributes helper.
  • Adds findInterruptCause to detect nested interruption causes and re-propagate them directly, avoiding conversion into synthetic internal errors and suppressing redundant logs.
  • Introduces EnvironmentHttpInternalError with a bounded failureTag field and preserved original cause as a defect, replacing the generic internal error type.
  • Limits annotateEnvironmentRequest finalizer so it skips logging entirely when the exit cause contains only interrupts.
  • Narrows the browserSession cookie error catch to only handle CookieError, letting other errors fall through to upstream handling.

Macroscope summarized f0537a8.

@coderabbitai

coderabbitaiBot commented Jun 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: a45a65f5-35b3-4d38-a1ea-48d64d1ce31c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/auth-http-diagnostics

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jun 20, 2026
@macroscopeapp

macroscopeappBot commented Jun 20, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Changes modify files in the auth directory (apps/server/src/auth/http.ts), which requires human review regardless of change complexity per security guidelines.

No code changes detected at f0537a8. Prior analysis still applies.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 0f8b837 to edf63a7CompareJune 20, 2026 22:46
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f476f6d to 519cb0aCompareJune 20, 2026 22:47
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from edf63a7 to d430f59CompareJune 20, 2026 22:50
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 519cb0a to 265d3cbCompareJune 20, 2026 22:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from d430f59 to fae19efCompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 265d3cb to 55daaa4CompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from fae19ef to 2b5e1cfCompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 55daaa4 to 6d9fb38CompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 2b5e1cf to 8728ebfCompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 6d9fb38 to 5697b83CompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 8728ebf to 55e9cd5CompareJune 21, 2026 00:08
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 5697b83 to a1f24c7CompareJune 21, 2026 00:08
Base automatically changed from codex/server-auth-error-boundaries to codex/redact-dpop-request-targetJune 21, 2026 00:14
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from a1f24c7 to c26e2ffCompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 70fdb85 to 5a80908CompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from c26e2ff to 89040c9CompareJune 21, 2026 00:28
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch 2 times, most recently from 553daf6 to ed36096CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 89040c9 to 2d37a35CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from ed36096 to 15aa01aCompareJune 21, 2026 01:10
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 2d37a35 to 307df64CompareJune 21, 2026 01:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Autofix Details

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Interrupt missed in Cause
    • Extracted the loop body into a recursive walkForInterrupt helper that, upon encountering a non-interrupt-only Cause, iterates its Fail reasons and continues walking each error's .cause chain to find nested interrupt causes.

Create PR

Or push these changes by commenting:

@cursor push 5780d93e6f
Preview (5780d93e6f)
diff --git a/apps/server/src/auth/http.ts b/apps/server/src/auth/http.ts--- a/apps/server/src/auth/http.ts+++ b/apps/server/src/auth/http.ts@@ -83,10 +83,27 @@
function findInterruptCause(input: unknown): Cause.Cause<never> | undefined {
const seen = new Set<object>();
+ return walkForInterrupt(input, seen, 0);+}++function walkForInterrupt(+ input: unknown,+ seen: Set<object>,+ depth: number,+): Cause.Cause<never> | undefined {
let current = input;
- for (let depth = 0; depth < MAX_CAUSE_CHAIN_DEPTH; depth += 1) {+ for (let d = depth; d < MAX_CAUSE_CHAIN_DEPTH; d += 1) {
if (Cause.isCause(current)) {
- return Cause.hasInterruptsOnly(current) ? (current as Cause.Cause<never>) : undefined;+ if (Cause.hasInterruptsOnly(current)) {+ return current as Cause.Cause<never>;+ }+ for (const reason of current.reasons) {+ if (Cause.isFailReason(reason)) {+ const found = walkForInterrupt(reason.error, seen, d + 1);+ if (found !== undefined) return found;+ }+ }+ return undefined;
}
if (typeof current !== "object" || current === null || seen.has(current)) {
return undefined;

You can send follow-ups to the cloud agent here.

Comment threadapps/server/src/auth/http.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 307df64 to 07d8a37CompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 15aa01a to bd937beCompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 07d8a37 to e9e9089CompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from bd937be to 517c1eaCompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 517c1ea to 8d916bcCompareJune 21, 2026 01:44
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from e9e9089 to 629ce09CompareJune 21, 2026 01:44
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 8d916bc to 7670d78CompareJune 21, 2026 01:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 629ce09 to 9c1fed6CompareJune 21, 2026 01:51
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 7670d78 to 1ed6271CompareJune 21, 2026 02:03
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 9c1fed6 to f5fe411CompareJune 21, 2026 02:04
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: IPC openExternal breaks boolean contract
    • Added Effect.orElseSucceed(() => false) to the IPC handler so that ElectronShellOpenExternalError is caught and returns false instead of rejecting the IPC call, preserving the boolean contract for renderer callers.

Create PR

Or push these changes by commenting:

@cursor push f71e08ecb0
Preview (f71e08ecb0)
diff --git a/apps/desktop/src/ipc/methods/window.ts b/apps/desktop/src/ipc/methods/window.ts--- a/apps/desktop/src/ipc/methods/window.ts+++ b/apps/desktop/src/ipc/methods/window.ts@@ -141,6 +141,6 @@
result: Schema.Boolean,
handler: Effect.fn("desktop.ipc.window.openExternal")(function* (url) {
const shell = yield* ElectronShell.ElectronShell;
- return yield* shell.openExternal(url);+ return yield* shell.openExternal(url).pipe(Effect.orElseSucceed(() => false));
}),
});

You can send follow-ups to the cloud agent here.

Reviewed by Cursor Bugbot for commit f5fe411934d709ab8dbc660896ff7eabf85c8222. Configure here.

Comment threadapps/desktop/src/electron/ElectronShell.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from c91fad6 to 9e0c536CompareJune 21, 2026 02:22
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f5fe411 to efacbf7CompareJune 21, 2026 02:24
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from efacbf7 to 15a2898CompareJune 21, 2026 02:44
juliusmarmingeand others added 2 commits June 20, 2026 20:12
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 15a2898 to f0537a8CompareJune 21, 2026 03:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[codex] Preserve auth HTTP failure diagnostics - #3419

Closed
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics
Closed

[codex] Preserve auth HTTP failure diagnostics#3419
juliusmarminge wants to merge 2 commits into
codex/redact-dpop-request-targetfrom
codex/auth-http-diagnostics

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Jun 20, 2026

Copy link
Copy Markdown
Member

Summary

  • retain exact underlying causes on typed auth HTTP 500 errors while keeping public JSON schemas redacted
  • log only bounded failure tags and reason counts, and suppress synthetic interruption failures
  • replace the remaining broad cookie catch with exhaustive catchTags handling

Validation

  • vp test apps/server/src/auth/http.test.ts apps/server/src/auth/EnvironmentAuth.test.ts
  • vp check (passes with 20 pre-existing warnings)
  • vp run typecheck

Stacked on #3240.


Note

Medium Risk
Touches auth HTTP 500 and logging paths where mishandling could hide real failures or leak data; changes are guarded by new tests and redacted API encoding.

Overview
Auth HTTP internal failures now keep the full underlying cause on a typed EnvironmentHttpInternalError, while public JSON still encodes only code, reason, and traceId (no raw errors in responses).

Logging no longer dumps full Cause/error objects. Request and operation failures log a bounded failureTag plus reason/failure/defect/interruption counts. Request finalizers skip logging when the exit is interrupt-only.

failEnvironmentInternal re-propagates nested interruption causes instead of turning them into synthetic 500s. browserSession cookie handling uses catchTags for CookieError only, passing the cause into internal failure handling.

Reviewed by Cursor Bugbot for commit f0537a8. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Preserve auth HTTP failure diagnostics by summarizing causes instead of serializing them

  • Replaces raw cause/error serialization in auth HTTP logs with bounded diagnostics: a trimmed failureTag and counts of failures, defects, and interruptions via a new failureLogAttributes helper.
  • Adds findInterruptCause to detect nested interruption causes and re-propagate them directly, avoiding conversion into synthetic internal errors and suppressing redundant logs.
  • Introduces EnvironmentHttpInternalError with a bounded failureTag field and preserved original cause as a defect, replacing the generic internal error type.
  • Limits annotateEnvironmentRequest finalizer so it skips logging entirely when the exit cause contains only interrupts.
  • Narrows the browserSession cookie error catch to only handle CookieError, letting other errors fall through to upstream handling.

Macroscope summarized f0537a8.

@coderabbitai

coderabbitaiBot commented Jun 20, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: a45a65f5-35b3-4d38-a1ea-48d64d1ce31c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/auth-http-diagnostics

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jun 20, 2026
@macroscopeapp

macroscopeappBot commented Jun 20, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Changes modify files in the auth directory (apps/server/src/auth/http.ts), which requires human review regardless of change complexity per security guidelines.

No code changes detected at f0537a8. Prior analysis still applies.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 0f8b837 to edf63a7CompareJune 20, 2026 22:46
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f476f6d to 519cb0aCompareJune 20, 2026 22:47
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from edf63a7 to d430f59CompareJune 20, 2026 22:50
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 519cb0a to 265d3cbCompareJune 20, 2026 22:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from d430f59 to fae19efCompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 265d3cb to 55daaa4CompareJune 20, 2026 23:11
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from fae19ef to 2b5e1cfCompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 55daaa4 to 6d9fb38CompareJune 20, 2026 23:20
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 2b5e1cf to 8728ebfCompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 6d9fb38 to 5697b83CompareJune 20, 2026 23:49
@juliusmarminge
juliusmarmingeforce-pushed the codex/server-auth-error-boundaries branch from 8728ebf to 55e9cd5CompareJune 21, 2026 00:08
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 5697b83 to a1f24c7CompareJune 21, 2026 00:08
Base automatically changed from codex/server-auth-error-boundaries to codex/redact-dpop-request-targetJune 21, 2026 00:14
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from a1f24c7 to c26e2ffCompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 70fdb85 to 5a80908CompareJune 21, 2026 00:21
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from c26e2ff to 89040c9CompareJune 21, 2026 00:28
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch 2 times, most recently from 553daf6 to ed36096CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 89040c9 to 2d37a35CompareJune 21, 2026 00:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from ed36096 to 15aa01aCompareJune 21, 2026 01:10
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 2d37a35 to 307df64CompareJune 21, 2026 01:10

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Autofix Details

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Interrupt missed in Cause
    • Extracted the loop body into a recursive walkForInterrupt helper that, upon encountering a non-interrupt-only Cause, iterates its Fail reasons and continues walking each error's .cause chain to find nested interrupt causes.

Create PR

Or push these changes by commenting:

@cursor push 5780d93e6f
Preview (5780d93e6f)
diff --git a/apps/server/src/auth/http.ts b/apps/server/src/auth/http.ts--- a/apps/server/src/auth/http.ts+++ b/apps/server/src/auth/http.ts@@ -83,10 +83,27 @@
function findInterruptCause(input: unknown): Cause.Cause<never> | undefined {
const seen = new Set<object>();
+ return walkForInterrupt(input, seen, 0);+}++function walkForInterrupt(+ input: unknown,+ seen: Set<object>,+ depth: number,+): Cause.Cause<never> | undefined {
let current = input;
- for (let depth = 0; depth < MAX_CAUSE_CHAIN_DEPTH; depth += 1) {+ for (let d = depth; d < MAX_CAUSE_CHAIN_DEPTH; d += 1) {
if (Cause.isCause(current)) {
- return Cause.hasInterruptsOnly(current) ? (current as Cause.Cause<never>) : undefined;+ if (Cause.hasInterruptsOnly(current)) {+ return current as Cause.Cause<never>;+ }+ for (const reason of current.reasons) {+ if (Cause.isFailReason(reason)) {+ const found = walkForInterrupt(reason.error, seen, d + 1);+ if (found !== undefined) return found;+ }+ }+ return undefined;
}
if (typeof current !== "object" || current === null || seen.has(current)) {
return undefined;

You can send follow-ups to the cloud agent here.

Comment threadapps/server/src/auth/http.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 307df64 to 07d8a37CompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 15aa01a to bd937beCompareJune 21, 2026 01:26
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 07d8a37 to e9e9089CompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from bd937be to 517c1eaCompareJune 21, 2026 01:38
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 517c1ea to 8d916bcCompareJune 21, 2026 01:44
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from e9e9089 to 629ce09CompareJune 21, 2026 01:44
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 8d916bc to 7670d78CompareJune 21, 2026 01:51
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 629ce09 to 9c1fed6CompareJune 21, 2026 01:51
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from 7670d78 to 1ed6271CompareJune 21, 2026 02:03
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 9c1fed6 to f5fe411CompareJune 21, 2026 02:04
@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Jun 21, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: IPC openExternal breaks boolean contract
    • Added Effect.orElseSucceed(() => false) to the IPC handler so that ElectronShellOpenExternalError is caught and returns false instead of rejecting the IPC call, preserving the boolean contract for renderer callers.

Create PR

Or push these changes by commenting:

@cursor push f71e08ecb0
Preview (f71e08ecb0)
diff --git a/apps/desktop/src/ipc/methods/window.ts b/apps/desktop/src/ipc/methods/window.ts--- a/apps/desktop/src/ipc/methods/window.ts+++ b/apps/desktop/src/ipc/methods/window.ts@@ -141,6 +141,6 @@
result: Schema.Boolean,
handler: Effect.fn("desktop.ipc.window.openExternal")(function* (url) {
const shell = yield* ElectronShell.ElectronShell;
- return yield* shell.openExternal(url);+ return yield* shell.openExternal(url).pipe(Effect.orElseSucceed(() => false));
}),
});

You can send follow-ups to the cloud agent here.

Reviewed by Cursor Bugbot for commit f5fe411934d709ab8dbc660896ff7eabf85c8222. Configure here.

Comment threadapps/desktop/src/electron/ElectronShell.ts
@juliusmarminge
juliusmarmingeforce-pushed the codex/redact-dpop-request-target branch from c91fad6 to 9e0c536CompareJune 21, 2026 02:22
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from f5fe411 to efacbf7CompareJune 21, 2026 02:24
@github-actionsgithub-actionsBot added size:L 100-499 changed lines (additions + deletions). and removed size:XXL 1,000+ changed lines (additions + deletions). labels Jun 21, 2026
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from efacbf7 to 15a2898CompareJune 21, 2026 02:44
juliusmarmingeand others added 2 commits June 20, 2026 20:12
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
@juliusmarminge
juliusmarmingeforce-pushed the codex/auth-http-diagnostics branch from 15a2898 to f0537a8CompareJune 21, 2026 03:12
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge