Skip to content

fix(auth): stop requesting retired dataset scopes - #126

Merged
justinhelmer merged 4 commits into
mainfrom
codex/cli-retired-dataset-scopes
Oct 8, 2026
Merged

justinhelmer merged 4 commits into
mainfrom
codex/cli-retired-dataset-scopes

Conversation

@justinhelmer

@justinhelmer justinhelmer commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Google sign-in succeeds, but Polylane refuses to finish connecting the CLI. The consent page shows Invalid scopes requested.

The cause is a missed update between two repositories. The CLI still asks for dataset permissions that Polylane no longer allows. Polylane rejects the entire connection request when any requested permission is invalid.

Backend PR #4391 intentionally removed unused customer telemetry ingestion and datasets. Its migration also removed dataset permissions from registered applications. It merged October 7 at 2:47 p.m. Pacific and reached production at 5:41 p.m. Pacific. The separate CLI release was not updated. The current published CLI, version 0.2.48, still sends the old permission list.

This PR removes only the three dataset permissions from CLI sign-in. It preserves all other permissions and the server's authorization rules. It also checks the CLI permission list against the generated API definition, so a removed permission causes a build check to fail.

Verification:

  • The Google consent URL test fails on the original code and passes with this fix.
  • The API type check rejects the three dataset permissions before removal and passes afterward.
  • All 550 tests, typecheck, lint, build, and the version check pass locally.
  • The fixed request matches all 61 permissions in the live CLI registration.
  • features/oauth-login.md records the sign-in checks and the remaining live check.

Users need a new CLI release, then an update and a fresh sign-in. A successful Google sign-in with that released version remains unverified. No customer account or permissions were changed during this investigation.

This explains the supplied screenshot. We have not confirmed the cause of attempts before the October 7 deployment.

@justinhelmer

justinhelmer commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor Author

@claude review the current PR head 40437e3 against REVIEW.md. Preserve the intentional dataset removal and the remaining issue, agent tool, and page permissions. The PR now includes the Google redirect regression and a verification map. All 550 local tests, typecheck, lint, and build pass. Review the plain-English RCA in the updated description.

@polylane

polylane Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Warning

Polylane could not verify the production impact of this pull request.

Checked the scope removal in src/auth/oauth.ts against coreplane-prod for 72h: worker logs carry zero Invalid scopes rows and the account error rate stays near baseline (0.16% Oct 7, 0.08% Oct 8). This change edits only what a future CLI release requests, so it cannot degrade a resource already serving traffic. The new head adds one test assertion only.

Chart attached: coreplane-prod account worker errors, last 48h.

View the full analysis →

Also considered · 2 refuted
  • Refuted · Removing datasets scopes strips access a live consumer still needs · The server already removed these scopes from the registered client allowlist (nominal#4391, production Oct 7); the CLI removing them aligns the request with the registration rather than dropping a live capability.
  • Refuted · The satisfies OAuthClient['scopes'] constraint breaks the typecheck or build · The constraint is type-level only, evaluates against generated types that exclude the retired scopes, and the PR reports typecheck, lint, all 550 tests, and build passing; the earlier head already carried it unchanged.

coreplane-prod · account worker errors

Analysed against 7 cloud accounts and 1 repository
  • Cloud accounts: coreplane-prod, baseberry-uat, coreplane-infra, coreplane, coreplane-gtm, 251714435813, Polylane
  • Repository: coreplanelabs/cli

View in Polylane Disable reviews

Polylane could not find the cloud resources this repository manages, so this review looked at the entire cloud account. Connect this repository to its resources and the next review will focus on exactly what this code deploys to.

Connect resources

Polylane analysed 6b5fcb2 for production impact. You can ask follow-ups by mentioning @polylane in a comment.

Did this help? React 👍 or 👎 so the next review is sharper.

Previous verdicts (2)
Head Verdict Analysis
40437e3 Production impact not verified analysis
9e3418f Production impact not verified analysis

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No verdict submitted — not approving.

Reviewed at 40437e3.

For agents

Full review

Review blocked by infrastructure: the mandatory git rev-parse HEAD check returned metadata_unavailable / aborted, with no commit output. I could not verify the checkout against 40437e3ac0e0e5bb7d40d36a69c05bcf677b9878, so I stopped without submitting findings or a verdict.

@coreplane-switchboard coreplane-switchboard Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM: no issues found

Reviewed at 6b5fcb2.

For agents

Rationale: Only the three retired dataset scopes are removed; the remaining 61 permissions and authorization safeguards are preserved.

Full review

No actionable findings; live Google and device sign-in with a released binary remain unverified.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: coreplane-switchboard[bot] reviewed this PR and posted an LGTM verdict (see its review). A repo admin enabled this via the auto-approve workflow.

@justinhelmer
justinhelmer merged commit 5061e00 into main Oct 8, 2026
5 checks passed
@justinhelmer
justinhelmer deleted the codex/cli-retired-dataset-scopes branch October 8, 2026 15:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant