Skip to content

test(auth): pin auth helper trust-boundary behavior - #1064

Merged
TheGreatAxios merged 1 commit into
cl-7970-clean-post-purge-stale-referencesfrom
cl-7994-pin-auth-helper-trust-boundary-tests
Sep 15, 2026
Merged

TheGreatAxios merged 1 commit into
cl-7970-clean-post-purge-stale-referencesfrom
cl-7994-pin-auth-helper-trust-boundary-tests

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Collaborator

Summary

  • Pins both auth-header helpers fail-closed on malformed input: empty and garbage access tokens still send a Bearer probe that classifies blocked
  • Pins the xAI probe to the fixed models URL with no caller-supplied host
  • Omits the account header on an empty account id and pins a non-JWT xAI token omitting the user-id header while keeping authorization

Verification

  • bun test src/auth/oauth-scope-check.test.ts --randomize --seed 424242 passes (21 pass, 0 fail)
  • bun run check passes (lint, typecheck, build, guarded suite)

Fixes CL-7994

@linear-code

linear-code Bot commented Sep 14, 2026

Copy link
Copy Markdown

CL-7994

@TheGreatAxios
TheGreatAxios merged commit 02cbf60 into cl-7970-clean-post-purge-stale-references Sep 15, 2026
13 checks passed
TheGreatAxios added a commit that referenced this pull request Sep 15, 2026
* chore: clean post-purge stale references

* fix(auth): omit empty account id and pin auth header boundaries (#1064)
TheGreatAxios added a commit that referenced this pull request Sep 15, 2026
* chore(cl-6815): trim unreachable usage formatters, demo, kickoff stub

Decision: usage display is not a product surface — delete fetch/format helpers and their tests rather than wiring them in. Keep only the live auth-header helpers used by oauth-scope-check, renamed usage.ts -> auth-headers.ts. Delete src/tui/demo.ts (410 lines, README-only reference) and the unreferenced workflows/kickoff stub. Net-negative.

* chore: clean post-purge stale references (#1052)

* chore: clean post-purge stale references

* fix(auth): omit empty account id and pin auth header boundaries (#1064)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant