Repository navigation
Conversation
|
@Cedric921 is attempting to deploy a commit to the Rohan Verma's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughRepeat sign-in captures tokens from an existing ChatGPT connection and revokes them after saving when revocation is permitted. Integration tests cover repeat sign-in with and without an active grant. Architecture documentation describes the updated behavior. ChangesChatGPT repeat sign-in
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The replacement sign-in remains successful even if the revocation request fails. No actionable merge-blocking issue was identified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change closes an existing credential-cleanup gap while preserving the replacement sign-in when revocation fails. No introduced security concern was established. Risk remains low because issuer behavior has only been exercised with a fake service, and revocation remains best effort. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 2 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…-revoke-on-sign-in-again # Conflicts: # docs/architecture/chatgpt-subscription.md
What
Signing in again on a ChatGPT connection that is still signed in now revokes the refresh token it replaces, the same way sign-out and delete do since #2156.
flows._savereads the connection's current tokens throughrevocation.tokens_to_revokebeforesave_sign_inoverwrites them, then commits.revocation.revoke, so the new sign-in stands whatever OpenAI answers.Why
docs/architecture/chatgpt-subscription.mdlisted it under Known gaps, a line #2156 added at review: Sign in again on a live connection overwrote its tokens without revoking the grant they replace, which left that grant open at OpenAI with nothing on this machine able to end it.Fixes
No issue. This closes that Known gaps line, which is deleted here. The URL table row and the revocation bullet now name signing in again.
How to test
cd surfsense_local/backend uv run pytest tests/integration/llm/chatgpt tests/integration/llm/test_connections.py -q uv run ruff check modules/llm tests/integration/llm/chatgpt python ../../scripts/check_docs.pyTwo new tests in
test_sign_in_routes.py:56 passed.
High-level PR Summary
This PR fixes a security gap where signing in again on an existing ChatGPT connection would overwrite tokens without revoking the replaced OAuth grant at OpenAI. The fix ensures that when a user signs in again over a live connection, the old refresh token is revoked at OpenAI (similar to how sign-out and delete already work), preventing orphaned grants that couldn't be terminated. The implementation reads tokens before overwriting them, commits the new sign-in, then revokes the old tokens as a best-effort operation.
⏱️ Estimated Review Time: 5-15 minutes
💡 Review Order Suggestion
docs/architecture/chatgpt-subscription.mdsurfsense_local/backend/tests/integration/llm/chatgpt/test_sign_in_routes.pysurfsense_local/backend/modules/llm/subscriptions/chatgpt/flows.pySummary by CodeRabbit