Repository navigation
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
CUA proof for the Credential Expiry Alerts settings toggle (local Windows debug build, cua-driver CLI). Build: commit Isolation: the exe ran with Drive:
Not covered: toast delivery on a real sign-in failure. That is covered by the 11 new Local artifacts (not committed):
The screenshots show settings chrome only, with no emails or tokens. The |
|
Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude Thermo-nuclear review of #660 (credential expiry alerts). Findings:
|
|
Follow-up: the four findings above are fixed and pushed. Nothing left open. Note: a 403 from the Codex usage API now returns its own "forbidden" message (previously it shared the 401 text), so it never triggers the sign-in alert or the token-refresh retry. Commands run (Rust 1.98.0, E-cores): |
CUA proofBuild commit: 5d03b7f (PR head, detached), Proof-only patch (uncommitted, reverted afterwards, never pushed): root Commands:
Not covered: the OS toast itself (needs a real sign-in-required provider failure); dedupe logic is covered by the PR's cargo tests. Screenshots (local, not committed), |
Adversarial validation (lane-B review)Head validated: Verdict: no blocking defects. Spec coverage verified in source at head:
Validation re-run at head (pinned 1.98.0, E-cores): UI proof: waived per user 2026-10-02 directive (fast-track); the episode state machine is covered by the new Rust tests; the Settings toggle is covered by GeneralTab tests. |
UI proof (browser-use)Combined build of
Every surface also passed the privacy check (no email-like text, account e-mail nodes or profile paths in the DOM) and theme Validation at |
Conflicts: rust/src/notifications.rs keeps the release identity_gaps module and test-only toast capture next to the new credential episodes. The PR makes show_toast return whether the toast was handed to the OS; the release's #[cfg(test)] recorder now returns true (recorded = handed over), and the Windows / non-Windows senders stay #[cfg(not(test))], so credential tests never spawn PowerShell. locale/tests.rs keeps both the Aixy gateway and credential-expiry key checks. PopOutPanel.test.tsx stays deleted (PopOut layout retired on the release).
Summary
Adds opt-in credential-expiry alerts. New setting
credential_expiry_notifications_enabled(default off, toggle under Settings > Notifications, "Credential Expiry Alerts").When a provider refresh fails with a typed sign-in state (
ProviderStateKind::NeedsAuthenticationorExpiredSession, taken fromProvider::error_state_kind, so providers whoseNotInstalledmeans a missing local runtime do not alert), the first failure for a (provider, account scope) posts one toast: " needs sign-in" with the generic body "Open CodexBar to review the account error and sign in again." The toast never contains the raw error, email or account id.quota_notification_account_identity(token-account id, then email, then org). A failed fetch has no identity of its own, so the identity of the last good snapshot is used. An empty scope (no evidence) is a wildcard for that provider: it is covered by any open episode, and a success without identity ends all of that provider's episodes, so an identity gap neither re-alerts every refresh nor hides a real recovery.Upstream reference
ref=v0.67.0):Sources/CodexBar/ProviderCredentialFailure.swift,Sources/CodexBar/UsageStore+CredentialNotifications.swift(handleCredentialOutcome),docs/credential-notifications.md,AppNotifications.swift,PreferencesNotificationsPane.swift, testsCredentialNotificationTests.swift.Ported / Deferred
Ported: episode model, per-account scoping, fresh-success-only recovery, retry after failed delivery, toggle semantics, disabled-provider retirement, generic toast copy, Settings toggle, locale keys (en-US; other locales fall back).
Deferred / not applicable:
ProviderCredentialFailure.isAuthenticationFailure, per-provider Swift error types) is replaced by the existing typedProviderStateKind, per the audit spec. Classification quality therefore follows each provider'serror_state_kind.AppNotifications.remove): Windows toasts here are fire-and-forget PowerShell dispatches with no handle to withdraw.refresh_codex_account_lanes) are not observed; only the primary provider refresh is.Validation
cargo +1.98.0 fmt --all -- --check: clean.cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: clean.cargo +1.98.0 test -p codexbar -- --test-threads=4: 2172 passed, 0 failed, 1 ignored (includes 11 newnotifications::credentialtests: per-ProviderError-variant alert table, provider-specific offline state, toast copy, fail/fail/timeout/replay/fresh-success/fail = two toasts, failed-toast retry, account/provider independence, identity-gap wildcard, toggle off then on, recovery while off, disabled-provider retirement, master-switch policy; plusneeds_sign_inand settings default/back-compat assertions).cargo +1.98.0 test -p codexbar-desktop-tauri -- --test-threads=4: 464 passed, 1 failed. The failure iscommands::tests::bootstrap_payload_exposes_every_provider_variant(catalog 79 vs 78): it reads this machine's real settings, which have the deprecatedkimik2provider enabled, and is unrelated to this change (the same failure is reported on other port PRs). Newcommands::credential_alertstests pass.pnpm --dir apps/desktop-tauri exec vitest run src: 67 files, 403 passed (new toggle test inGeneralTab.test.tsx).pnpm --dir apps/desktop-tauri run lint: only existing warnings in untouched files.pnpm --dir apps/desktop-tauri run build(includescheck-locale): OK.Affected areas
UI proof
Pending: coordinator will capture CUA proof (Notifications tab toggle) and a manual toast capture on a fresh build.