Skip to content

fix(providers): use catalog provenance for OAuth removal - #1301

Merged
TheGreatAxios merged 1 commit into
mainfrom
fix/provider-removal-provenance
Oct 2, 2026
Merged

TheGreatAxios merged 1 commit into
mainfrom
fix/provider-removal-provenance

Conversation

@TheGreatAxios

@TheGreatAxios TheGreatAxios commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Authorize OAuth profile cleanup only from matching codexProfile or xaiProfile markers on the current provider catalog entry.
  • Keep inactive and residual OAuth profiles removable while preventing custom API-key or keyless namespace collisions from deleting auth-store profiles.
  • Preserve orphan retry and the pending-removal switch guard with production-lifecycle coverage.

This follow-up to #1297 and #1298 closes the ownership gap left by source-registry authorization: the registry includes only built sources and can retain stale provenance after the catalog transitions to a custom row, while the current catalog reflects auth-store-backed ownership.

Verification

  • bun test src/auth/remove-provider.test.ts src/tui/provider-remove.test.ts passes (18 tests).
  • bun run check passes (8,147 tests, 0 failures).

@TheGreatAxios TheGreatAxios left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review · Fix verified

No findings. OAuth removal now requires matching current catalog profile provenance, preserving inactive/residual OAuth removal while preventing hand-named API-key or keyless namespace collisions from deleting credentials.

Verification: independent review is CLEAN; catalog/provenance suites pass; bun run check passes with 8,147 tests and 0 failures; all GitHub checks pass; git diff --check origin/main...HEAD passes.

@TheGreatAxios
TheGreatAxios merged commit 8db44c7 into main Oct 2, 2026
13 checks passed
@linear-code

linear-code Bot commented Oct 3, 2026

Copy link
Copy Markdown

CL-9485

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant