Skip to content

Port upstream 0.68.0: Venice web session per-browser fall-through (stacked on #626) - #729

Draft
Finesssee wants to merge 2 commits into
port/micro-0.68.0-venice-clerkfrom
port/micro-0.68.0-venice-browser-fallthrough
Draft

Finesssee wants to merge 2 commits into
port/micro-0.68.0-venice-clerkfrom
port/micro-0.68.0-venice-browser-fallthrough

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

Ports upstream CodexBar v0.68.0 to v0.70.0 Venice web-session behavior (GAP-09). In Web mode with browser cookies, every detected browser that holds a venice.ai session is tried in order instead of stopping at the first browser with any cookies.

  • An unusable session (401/403 or empty token, expired token, anonymous user type, or missing quota claims) falls through to the next browser.
  • Any other failure (network error, non-401/403 HTTP status, JWT parse failure) stops immediately and is returned.
  • If every candidate fails, the last candidate's error is returned. A browser with no Venice session cookie is skipped; no candidates at all returns the existing missing-credentials message.
  • A manual cookie header still wins and never triggers a browser import.
  • Existing error values are preserved exactly: a private VeniceWebFailure classifies failures for the loop and maps back to the same ProviderError as before.
  • New shared helper get_cookies_by_browser_for_domain (browser/cookies.rs) and browser_cookie_candidates_for_domain (providers/mod.rs) return per-browser cookies with domain metadata so the exact-host venice.ai filter still applies. get_cookies_for_domain is unchanged.
  • Venice tests moved to venice/tests.rs to keep mod.rs under 1000 lines.

Stacked on #626 (Clerk session cookies). Merge #626 first; this PR targets its branch.

Not ported (scope): per-profile fall-through within one browser (the Windows extractor groups cookies per browser, not per profile).

Checks

  • cargo +1.98.0 fmt --all --check: clean
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: pass
  • cargo test -p codexbar: 2171 passed, 0 failed, 1 ignored (venice: 16, 5 new fall-through tests)
  • No UI change; no CUA proof needed. Tauri crate not modified (compiled via clippy only).

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…ypes as unusable sessions

Merges port/micro-0.68.0-venice-clerk. A 200 session reply with a missing, null or non-string token maps to InvalidSession so fetch_web_sessions tries the next browser. The anonymous user type set now matches upstream: anonymous, anon, guest, unauthenticated, logged_out.
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at 97cfbe9

Both review items confirmed and fixed. This branch now merges #626 (head d49c021), which carries the shared token-parsing fix.

  • Tokenless session reply ends the fall-through: a 200 reply with a missing, null or non-string token now maps to VeniceWebFailure::InvalidSession (upstream invalidCredentials), so fetch_web_sessions tries the next browser. A non-object body and a non-JWT token stay Parse errors. The reply handling moved into snapshot_from_session_body so it can be exercised inside fetch_web_sessions. Tests: {} and {"token":null} alone, falling through from a stale Chrome session to a live Edge session, and being reported as the expired-session error when it is the last candidate.
  • Anonymous user types: is_anonymous_user_type now matches upstream's set (anonymous, anon, guest, unauthenticated, logged_out) case-insensitively. A guest session with quota claims raises Anonymous (AuthRequired when last) and falls through to the next browser. Tests cover each spelling, non-anonymous values, and fall-through with and without a live second session.

The earlier PR body wording ("401/403 or empty token", "anonymous user type") is superseded by the above: fall-through now covers 401/403, a missing/blank/non-string token, and any upstream anonymous user type.

Commands run: cargo +1.98.0 fmt --all --check; cargo +1.98.0 clippy --workspace --all-targets -- -D warnings; cargo +1.98.0 test -p codexbar (2179 passed, venice 24); cargo +1.98.0 test -p codexbar-desktop-tauri (461 passed, 1 known environment failure bootstrap_payload_exposes_every_provider_variant, 79 vs 78, real-settings dependent, #684/#711). No frontend change.

Finesssee added a commit that referenced this pull request Oct 2, 2026
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation passed at ee23d2d

Scope: Venice web session per-browser fall-through (#729, upstream 0.68.0, stacked on #626), validated as merged into release/v0.70.0 (merge ee23d2d = merge of 97cfbe9 into 8569cd3).

Attacks (highest-risk semantics, from the merged tree):

  • Per-BROWSER (not per-profile) fall-through: the merged code iterates browser cookie candidates and continues to the next browser on four separate dead ends (no usable credential, invalid session, anonymous user, transport failure) — the audit's per-browser scope, with the error text "Venice session unusable; trying the next browser" logged per hop rather than failing the fetch on the first bad session.
  • Anonymous user types are upstream's exact set: the anonymous|anon|guest|unauthenticated|logged_out list matches upstream anonymousUserTypes and is case-insensitive via is_anonymous_user_type — so a signed-out-but-cookie-present session falls through rather than rendering a 0% bar.
  • Tokenless/null/non-string reply is invalid-session: snapshot_from_session_body treats a tokenless reply as an invalid session (not a parse crash), feeding the fall-through; the audit's "tokenless reply fails closed" is preserved from Port upstream 0.68.0: accept Venice Clerk session cookies with Bearer auth #626.
  • Test honesty: venice/tests.rs carries 24 tests (5 new fall-through) moved there for the 1000-line cap — the fall-through tests drive the real fetch loop with mockito rather than stubbing the browser scan.
  • Windows-specific: no localStorage reader; the Chromium cookie scan is the same path other providers use, so no new Windows-specific failure mode.

No defects found. READY for the un-draft rule.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant