Skip to content

test(core): reproduce OAuth refresh omission during batching - #46616

Closed
kitlangton wants to merge 1 commit into
v2from
oauth-batch-repro
Closed

kitlangton wants to merge 1 commit into
v2from
oauth-batch-repro

Conversation

@kitlangton

Copy link
Copy Markdown
Contributor

Why

A plugin can await registration of its OAuth refresh implementation and then resolve its saved connection during the same activation batch. The resolver reads the old published registry, misses the refresh implementation, and returns the expired access token unchanged.

For Console, that token can make the initial provider-configuration request fail with 401. The plugin logs the failure and captures no remote provider inventory, so account-provided models can disappear or a session can fail with Model unavailable. This is not a server-side account lockout. Completing the activation batch does not retry the failed inventory fetch, so simply waiting need not recover it.

What Changes

Reproducer only, intentionally failing. One test uses the production Integration, Credential, and State implementations to register and resolve inside State.batch, matching the ordering used by plugin activation.

The same test resolves the same connection again after the batch as a passing control:

Observation During the batch After the batch
Returned access token expired fresh
Persisted access token expired fresh
Refresh callback invocations so far 0 1

The final assertion requires the during-batch resolution to have returned and persisted a fresh credential. It fails on current v2, after the after-batch control assertions pass. The test clock explicitly places the stored credential in the past.

Scope

No production changes and no proposed fix. This branch is based directly on v2, independently of #45810; it includes neither State.resolve() nor State.flush().

The test isolates the registration-visibility failure. It does not run the Console plugin, issue the subsequent HTTP request, or exercise UI rendering. All token values and the refresh callback are synthetic; no real credentials or external network are used.

Verification

From packages/core, using Bun 1.4.0:

bun run test test/integration.test.ts --test-name-pattern 'during batched registration'
bun run test test/integration.test.ts --test-name-pattern 'during batched registration' --rerun-each 20
bun run test test/integration.test.ts
bun typecheck
  • The reproducer fails as intended, consistently 20/20 times, with zero refresh calls and an expired returned/persisted credential inside the batch.
  • The post-batch control succeeds before each failing assertion, using the same registered method and saved connection.
  • Complete Integration suite: 13 passed, 1 intentionally failed.
  • Core typechecking, formatting, and whitespace checks pass. The only changed file is packages/core/test/integration.test.ts.
  • The unmodified pre-push hook passed all 33 repository typecheck tasks.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Automated PR Cleanup

Thank you for contributing to opencode.

Due to the high volume of PRs from users and AI agents, we periodically close older PRs using automated criteria so maintainers can focus review time on the most active and community-supported contributions.

This PR was closed because it matched the following cleanup criteria:

  • The PR was created more than 1 month ago
  • The PR had fewer than 2 positive reactions
  • Positive reactions are counted as thumbs-up, heart, celebration, or rocket reactions on the PR

PRs created within the last month are not affected by this cleanup.

If you believe this PR was closed incorrectly, or if you are still actively working on it, please leave a comment explaining why it should be reopened. A maintainer can review and reopen it if appropriate.

Thanks again for taking the time to contribute.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant