Skip to content

rollup: 2026-10-01 ctkm-1 admin usage, OpenAI verification, OAuth consent - #1723

Merged
ctkm-aelf merged 8 commits into
mainfrom
rollup-2026-10-01-ctkm-1
Oct 1, 2026
Merged

ctkm-aelf merged 8 commits into
mainfrom
rollup-2026-10-01-ctkm-1

Conversation

@ctkm-aelf

@ctkm-aelf ctkm-aelf commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Rollup: 2026-10-01 ctkm-1

This rollup starts from main commit 80a153d31200eaa8eafbf005cc13d3e3894181a9
and integrates #1721 and
#1725.
After the #1721 squash landed, main advanced through #1722 to
479840e8. The rollup merged that commit as 478b960a, preserving the latest
main history without conflicts or changes to the Admin Usage files. #1725 was
then raised against the rollup head e09c7c8e and squashed on top of it.
Admin Usage needed token counts that users can combine without double counting,
filter options and service details ready when opened, and data tables that can
stay visible or collapse per panel. The OpenAI plugin portal also needed to
verify control of the NyxID MCP host before the Codex/ChatGPT plugin can be
submitted.

Included changes

Source PR Validated source head Landed squash Result
#1721 0e24c05eee93101f562c8a165ee5f53991822e71 5983b66537b724b057880a774dc45bd01484230f Configurable token views, panel data tables, and background loading for Admin Usage.
#1725 e70ba24bd4ad58735cfa83d3432f1c94d10c2886 d85799bfb9a615b87256acd78e9674552051e1fb OpenAI apps domain verification challenge served from the MCP host.

For #1721, the source and landed commits have the same tree
(a9914949583afb92fee83004879bc7886eaf17e3), so the squash contains the
validated source exactly. The source PR was rebased onto this rollup's main
base before its final CI run; GitHub reported no merge conflicts.

For #1725, the source and landed commits have the same tree
(ffb7e232c1edba00be67fb368dd67df06f181104). The PR was based on the current
rollup head, so no rebase was needed; GitHub reported it mergeable and clean.

Behavior

  • The dashboard and list support multi-selected Total, Input, Output,
    Cache-read, and Cache-write token views. Total already includes Input and
    Output, so selecting them together displays those counts without adding
    them twice. Selected cache counts still add. An inline tooltip explains
    the overlap.
  • Each analytics panel has a Data table setting: Always open by default, or
    Accordion. The workspace API accepts and validates the persisted setting.
  • Services, Billing accounts, and Acting users options load when Usage opens.
    Visible user details preload in the background. React Query keeps these
    results fresh for five minutes and cached for ten minutes.
  • GET /.well-known/openai-apps-challenge returns the optional
    OPENAI_APPS_CHALLENGE_TOKEN as bare text/plain, the format OpenAI's
    plugin portal requires for domain verification. When the variable is unset
    the path returns 404, as before. The OIDC, OAuth authorization-server,
    protected-resource, and JWKS discovery documents are unchanged.

Validation And Rollout

The rebased #1721 source head passed 24 CI checks with no failures, including
the frontend, backend tests, billing smoke, coverage, Rust feature builds, and
CodeQL. Locally, all 18 Admin Usage browser tests, 27 focused frontend tests,
TypeScript, lint, formatting, and backend cargo check passed. The landed
source tree is identical to the tested head.

The #1725 source head passed 21 CI checks with no failures, including backend
tests, billing smoke, coverage, Clippy, formatting, Rust feature builds, and
CodeQL; frontend, CLI, and mobile jobs were skipped as unaffected. Locally, the
7 discovery handler tests (5 existing, 2 new) and cargo clippy -D warnings
passed. A local server run returned the exact token with 200 text/plain and no
redirect, returned 404 with the variable unset, and served all four discovery
documents unchanged.

Deploy the backend workspace change before the frontend. An older backend
rejects the new table_display field when saving panel settings.

To complete OpenAI domain verification after deploying the backend, set
OPENAI_APPS_CHALLENGE_TOKEN to the token shown in the portal, confirm
https://nyx-api.chrono-ai.fun/.well-known/openai-apps-challenge prints only
that token, then verify in the portal.

OAuth Consent Update

Direct rollup commit 9b4abe7c updates the standard OAuth consent screen:

  • roles, groups, and proxy have readable descriptions, and every requested scope shows its exact value.
  • Unknown scopes appear in full as the permission label.
  • App default and requested resource services stay checked and cannot be deselected; optional services remain editable.

Validation on the rollup branch: 50 standard and incremental consent tests, TypeScript, ESLint, and Prettier passed.

…ing (#1721)

Admin Usage needed a selectable token total without double counting, immediately available filters and user details, and a visible data table that each panel can show directly or as an accordion.

- Add a multi-select token picker to the dashboard and list. Total already includes Input and Output, so those selections are displayed but not added twice; selected cache-read and cache-write counts still add. An inline tooltip explains the overlap.
- Add a per-panel Data table setting, defaulting to Always open with Accordion as the alternate mode. Persist and validate the field in the backend workspace contract.
- Load Services, Billing accounts, and Acting users options when Usage opens. Preload visible user details in the background and cache usage and option queries for five minutes of freshness and ten minutes of retention.

Source PR: #1721. Its rebased head 0e24c05 passed 24 CI checks with no failures, including the full backend, frontend, coverage, Rust feature, and CodeQL jobs. All 18 Admin Usage browser tests and 27 focused frontend tests passed locally. Deploy the backend workspace schema before the frontend because older backends reject the new table_display field.
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

📊 Code coverage

Component Lines Threshold Status Δ vs base
Backend (nyxid) 87.54% 73% ✅ — 0.00
Frontend (vitest) 71.76% 15% ✅ 🔺 +0.15

Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end.

ctkm-aelf and others added 2 commits October 1, 2026 16:37
OpenAI's plugin portal verifies control of the MCP host by fetching
/.well-known/openai-apps-challenge and expecting the plugin's token as
bare plain text. The path returned 404, so submission showed
"Domain not verified".

Serve the token from the optional OPENAI_APPS_CHALLENGE_TOKEN env var on
the public /.well-known router; return 404 when unset, which matches
today's behavior. Existing discovery documents are unchanged.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ctkm-aelf ctkm-aelf changed the title rollup: 2026-10-01 ctkm-1 admin usage integration rollup: 2026-10-01 ctkm-1 admin usage and OpenAI domain verification Oct 1, 2026
@ctkm-aelf ctkm-aelf changed the title rollup: 2026-10-01 ctkm-1 admin usage and OpenAI domain verification rollup: 2026-10-01 ctkm-1 admin usage, OpenAI verification, OAuth consent Oct 1, 2026
@ctkm-aelf
ctkm-aelf merged commit 2460601 into main Oct 1, 2026
59 checks passed
@ctkm-aelf
ctkm-aelf deleted the rollup-2026-10-01-ctkm-1 branch October 1, 2026 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant