Skip to content

🔋 feat: Renew Scheduled OBO MCP Grants Offline - #16427

Open
lia-by-librechat[bot] wants to merge 37 commits into
devfrom
lia/scheduled-obo-renewal
Open

lia-by-librechat[bot] wants to merge 37 commits into
devfrom
lia/scheduled-obo-renewal

Conversation

@lia-by-librechat

@lia-by-librechat lia-by-librechat Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Scheduled Chats cannot renew an obo: MCP credential after the browser session ends. B1 adds explicit resource-grant enrollment, encrypted downstream refresh grants, coordinated offline renewal, revocation, and preflight/execution/resume wiring. Related to #16157.

The default OBO host remains fail-closed until its invocation-authority adapter is installed and supported-provider activation gates pass. An operator allowlist does not enable enrollment or credential delivery. Retained grants remain visible for cleanup. No browser-login refresh token is persisted; direct bearer passthrough and interactive resource-server rejection are outside this PR.

How it works

Redacted endpoint/scope preview + keyed opaque binding
  -> live owner/agent/resource authorization
  -> downstream OBO exchange with offline_access
  -> encrypted, purpose-isolated resource grant
  -> coordinated renewal + fresh authorization
  -> preflight / execution / reconnect / approval resume

The preview binding covers owner, tenant, schedule revision, root agent, server, resolved URL and scopes. Enrollment checks it before exchange and persistence. Decrypted custom variables never enter the preview response. Preview initializes only the requested selected server. The preparation form uses the shared themed Checkbox with label and keyboard support.

Scheduled storage and refresh/teardown keys use a separate purpose. Decrypted resource URLs are not persisted in token metadata: a domain-separated keyed fingerprint binds the exact URL during enrollment, retrieval and renewal. Schedule deletion quiesces renewals and rollback, advances each grant persistence fence, and holds teardown through removal. Credential diagnostics are bounded metadata through storage, the token coordinator, custom-variable lookup/decryption, OBO trust lookup, and immediate and outer discovery/recovery/runtime consumers. Error causes and failure propagation are retained. Storage propagates failures without duplicate raw logs; helper throw/fallback semantics are retained. Live operator, role and credential-binding authorization is rechecked after retrieval/renewal/adoption before delivery and after enrollment exchange before persistence. Final authority I/O precedes the last teardown-fenced generation snapshot, so completed grant revocation or purge cannot be bypassed by a manual read. Denied grants remain available for cleanup; dependency outages remain retryable. Ordinary MCP server names, including schedule-obo: names, remain valid. Legacy pre-release OBO records are unavailable to ordinary OAuth, remain revocable/deletable, and require explicit re-enrollment before use. Their purpose is retained on refresh rows, and client metadata covers the refresh lifetime. A dry-run-first, tenant-safe inventory/backfill protects dormant owners before legacy client TTL expiry. Listing and maintenance share the same duplicate-aware provenance rule. Conflicting client records cannot be tagged by listing or produce a rollout-ready result, even when a refresh row was previously tagged.

Type of change

  • Feature
  • Tests / tooling / CI

Testing

Focused regressions cover disclosure, preview drift, ordinary/scheduled credential coexistence, legacy cleanup, purpose-specific coordination, rotation/adoption, cancellation, exact resource binding, owner/tenant/agent checks, activation/resume and separate consent UI. MCP SDK, OpenID adapter and real MongoDB tests are used. Exact-head results and review coverage are recorded in the handoff comment. Builds and workspace typechecks are separate checks.

Screenshots / recordings

The retained-grant cleanup surface has no prior equivalent. Real local-app light/dark captures were generated earlier, but GitHub rejected attachment upload with unsupported authentication type. No uploaded screenshots are claimed. Current preview and cleanup behavior is covered by focused UI tests.

Risk / compatibility

Updated from dev 114394c6a02a3343bab495e7baa9a9a6be89235b, preserving its consent, execution-policy, resource-bearer and receipt-recovery paths alongside the B1 grant lifecycle. Trusted manual provenance is captured once in the immutable credential context across liveness/preflight, verified Run Now admission and authenticated job restoration. Paused manual grants can renew while retaining fresh authority checks; automatic, unknown and body-spoofed classifications receive no disabled-row exception. Host-injected authority must enforce current consent, absolute expiry/revocation and the applicable read-only policy; storage, provider and authority dependencies remain injected.

Plaintext pre-release scheduled URL bindings and changed replica keys require explicit re-enrollment; retained grants remain visible for cleanup. Inventory readiness alone is not provider or credential acceptance proof.

For installations with pre-release grants, quiesce legacy writers and run npm run migrate:scheduled-obo before client TTL expiry. Apply with -- --apply only after the inventory has no ambiguous rows. A verified ready: true result is required before rollout. Already-orphaned unmarked records require operator provenance recovery; server names are never proof. No production migration was executed.

Supported-provider acceptance, recurring runs spanning expiry without a browser, compatible replica rollout and rollback remain activation gates. Synthetic fixtures do not certify a deployed provider. #16157 remains open. No production credentials, configuration or services were changed.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff for c9a414efe12f1820f6b115a0582d76cb210320f1: provider-neutral Scheduled Chats OBO enrollment, per-server and per-schedule encrypted downstream refresh, current owner/tenant/agent/role/allowlist checks, expiry renewal, deletion/revocation fences and scope-preview UI. Please focus on grant rotation across replicas, OIDC session identity and expiry, authorization/revocation races, and ensuring no downstream token is mistaken for an upstream assertion. The tests simulate a 12-hour gap; no live Graph tenant run is claimed.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff for e6bda4e8ffd7dadbe8b9c6093044aa9ec5f4451d: the scheduled grant host no longer imports the schedule facade or preflight in a cycle; registration is injected after preflight construction. This head also rechecks base schedule policy and role permission. The local circular-dependency check and focused OBO/backend tests passed; CI is running on this SHA. Please review this new head, not its predecessor.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff for e62839a732b40c92ebda6e9ab717e0662698b282: OBO grant construction is now lazy, so unrelated API routes and agent initializers do not initialize flow storage; the default OBO resolver still wires after preflight construction. Root-agent access is also rechecked when serving a grant. The three previously failing CJS host suites now pass locally with a sandbox-only Mongo socket flag (105 tests); grant tests, typecheck, package build and static checks pass. Please review this pushed head.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff for 7ecb54994940b80355cf8163c8693a5633bd0019: the full scheduled OBO path now includes a passing two-caller, one-redemption rotation regression, and rollout guidance to enable the operator allowlist only after every replica upgrades. The previous head passed 30 CI checks with Lighthouse still pending; new CI is running against this SHA. Please review this head for credential scope/rotation and revocation races.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T14:38:38.067438Z 7b259a7 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7ecb549949

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/schedules/obo.ts Outdated
Comment thread packages/api/src/schedules/obo.ts Outdated
Comment thread packages/api/src/schedules/handlers.ts Outdated
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff for c972e131bb67f7db4eeb3c6fd6abf102c085959c: I addressed all three P2 threads. Nonexistent grant revocation no longer pauses a schedule; a grant purge must succeed before deletion can hide or erase it; and enrollment uses the established OpenID JWT/opaque access-token expiry policy. A new real @modelcontextprotocol/sdk Streamable HTTP server test calls an MCP tool before and after scheduled OBO refresh with a simulated twelve-hour expiry. Live ClickHouse Cloud MCP returns an authenticated read-only query, but advertises auth-code+refresh OAuth, not a jwt-bearer OBO grant. Therefore that real service cannot validate this PR's OBO grant path. Please review this pushed head; CI is running.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff for 9f906952c38f56547fb4d771df1cdca926c20499: all three earlier P2 threads are fixed, replied to, and resolved. The added ClickHouse Cloud negative regression passes. Public OAuth metadata and a live read-only ClickHouse MCP query confirm the hosted endpoint is direct OAuth, not an OBO grant, so it cannot certify this PR's OBO renewal. The real SDK MCP server test exercises two authenticated tool calls across a simulated twelve-hour access-token expiry with only the identity provider stubbed. Please review the exact pushed head; no live ClickHouse Scheduled Chat or provider-certified 12-hour run is claimed.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9f906952c3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/schedules/obo.ts
Comment thread packages/api/src/schedules/obo.ts
Comment thread client/src/components/SidePanel/Schedules/ScheduleCard.tsx Outdated
Comment thread client/src/components/SidePanel/Schedules/ScheduleCard.tsx Outdated
@danny-avila
danny-avila marked this pull request as draft September 28, 2026 12:24
@danny-avila
danny-avila force-pushed the lia/scheduled-obo-renewal branch from 9f90695 to b82af25 Compare September 28, 2026 12:24
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact pushed head 83a33cadc4a86f39075e698cfb79bc454fcc3b50: fixes JWT grant responses without expires_in, preserves provider refresh-token expiry on enrollment and rotation, keeps revoked-policy grants visible for owner cleanup through one indexed identifier-only read, and uses shared semantic Button variants. The 115 focused API, schedule and real MCP SDK assertions, four card UI cases, and Mongo projection test passed. Changed-workspace typechecks, package builds and committed-head static checks passed. CI is running. This does not claim a live third-party OBO renewal.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff for 44051ef6b3c15f520cf6fa91280717daa3dd7b65: all four new Codex findings were fixed in 83a33cadc4a86f39075e698cfb79bc454fcc3b50, replied to, and resolved. This follow-up removes the remaining button size overrides so both scheduled OBO actions use the shared component's standard compact variant, with focused assertions. Review this exact pushed head; CI and local checks run in parallel. The simulated renewal and real SDK tool calls do not prove a live third-party OBO provider or two actual scheduled runs twelve hours apart.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 44051ef6b3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/schedules/obo.ts Outdated
Comment thread packages/api/src/schedules/obo.ts
Comment thread packages/api/src/schedules/obo.ts
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff for d425e08003b1bb295a143facf6b5ffbb56ec80d3: fixes all three new Codex findings. Paused-to-active preflight can read an enrolled OBO grant but actual disabled-row runs cannot; authorization binds both displayed scopes and endpoint (including a post-exchange config recheck); and the token-storage coordinator is injected by the CJS host rather than imported as a runtime singleton. A paused-grant revoke now advances the schedule revision so activation already past preflight cannot commit. Real MCP SDK activation and renewal tests, explicit URL drift and owner tests, and changed-workspace typechecks passed; final combined suites and CI are running. This is not a live third-party OBO-provider or 12-hour scheduled-run proof. Please review this exact pushed head.

@lia-by-librechat

lia-by-librechat Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor Author

Exact-head review handoff for 55558309fe4b19c016ecdf594bb48733f15f15ec: fixes all four reproduced self-review issues. OBO connection/tool targets carry their exact transport URL; coherent credential snapshots and returned-generation checks prevent endpoint substitution and classify concurrent rotation as retryable. Enrollment and refresh persistence, including rollback, are guarded by an owner lease account deletion drains after its durable barrier and before the token sweep. Structured provider rejection codes now require reauthorization while genuine outages remain retryable. Local checks passed: 142 grant/quiesce/persistence tests, 558 transport/shared-storage/real SDK tests, 13 production host/account-deletion tests, API tsc --noEmit, API tsdown declaration build, and all affected PR static checks. Local Lighthouse is blocked by missing Playwright Chromium; final-head CI is running. Please review this exact head. No live third-party OBO provider or actual twelve-hour recurring-run proof is claimed.

@danny-avila
danny-avila force-pushed the lia/scheduled-obo-renewal branch from 5555830 to c0d9b48 Compare September 30, 2026 00:54
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: b9d16b254d4c44c85dfed7147defd2188a274187. Adds dry-run-first legacy grant inventory/backfill across dormant owners; apply refuses ambiguous provenance, uses tenant-safe generation-scoped writes, and verifies readiness. Both Codex corrections and merged A1/A2 remain intact; A3 stays separate. Real-Mongo checks and exact-head independent review are running. No production migration, activation or deployment.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: e89e0c286465d1f29e194afe3b9fcfc41b6717f1. Fixes the additional P2 rollout-gate bypass: online listing and maintenance share duplicate-aware provenance classification. Listing cannot tag ambiguous clients, and even already-tagged conflicts block readiness. The exact list-before-inventory sequence failed in real MongoDB before the fix; 93 storage/provenance/tenant-helper tests now pass. Changed-package build/typecheck and scoped lint/import/format checks pass. Fresh exact-head review and CI follow. No production migration, activation or deployment.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Head: e89e0c286465d1f29e194afe3b9fcfc41b6717f1. Integrated dev: f88f3fb2febb174c730338726a2b68ec32aeb1d6, preserving merged A1/A2; A3 remains separate. Current dev: 67a5fe247c2aec293c19830ca4dfd4f15f6deea3; no conflicts.

Independent exact-head review: Complete, no findings. Full frozen-diff/critical-consumer review, eight provenance checks and in-memory revocation verification completed. Reviewer dependencies were unavailable, so real-Mongo/Jest/UI/provider/type/Lighthouse checks were not independently rerun.

Finding Severity Disposition
B1-R3 secret-bearing preview URL P2 Fixed in 5b1e3d0; Codex thread replied/resolved
B1-R4 valid ordinary prefix names rejected P2 Fixed in 5b1e3d0; Codex thread replied/resolved
B1-R5 legacy cleanup after client TTL P2 Fixed in 4d7e449, with transition gate below
B1-R6 dormant-owner backfill before TTL P2 Fixed in b9d16b2
B1-R7 online listing bypassed duplicate-client inventory P2 Fixed in this head; list-before-inventory regression failed before correction

Earlier B1-R1/R2/S1 remain fixed. No findings rejected. No unresolved inline threads at the final read.

Final-source local verification Result
Grant/preflight/settlement/token/cleanup regressions 499 passed
Real-Mongo token/provenance and tenant-helper tests 93 passed
Disposable real-Mongo CLI: dry-run, apply, tenant isolation, unchanged ciphertext/lifetime, idempotence, ambiguous refusal Passed
Typechecks: API, data-schemas, data-provider, client Passed
Package and production-client builds Passed during Lighthouse preparation
Scoped ESLint, Prettier, import sorting, package validation, circular dependencies Passed

Schedule UI (109), host/OpenID (94), and shared request-contract (1) tests passed on unchanged UI/wiring at earlier head b9d16b2; they were not rerun at this head. Broader ordinary-OAuth/SDK checks (1,017) passed at 4d7e449, not this head.

CI at this read: 36 successful, 2 skipped, 6 running, no failures. CI Lighthouse passed at this exact head. Remaining: e2e (memory, shard 3/6), e2e (memory, shard 5/6), e2e (memory, shard 2/6), e2e (memory, shard 4/6), e2e (memory, shard 6/6), e2e (memory, shard 1/6).

Local npm run lighthouse was bounded by the worker execution ceiling and exited 124; no completed local performance metric is claimed. Full local design-suppression validation exceeded the worker limit; CI Static checks passed. static-checks:full config migration tests, unused i18n and unused-package gates were not run. Screenshot attachment upload remains unavailable; no uploaded screenshots are claimed.

Legacy rollout requires quiesced writers and inventory/backfill before client TTL expiry across dormant owners. Ambiguous or already-orphaned unmarked records require operator provenance recovery. Names are never proof. No production inventory/apply, provider certification, replica rollout, merge or deployment was performed. Default application OBO activation remains fail-closed.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: e358d6f213e4f50aa5a7fd6cd8723f31c975761c. Merges dev a4f6763b070c90cc392faf738e405bb94e8396d0 without rewriting branch history. Resolves six conflicts while preserving scheduled grant lifecycle, current execution-policy/receipt guards and host bearer wiring. Fixes the limits-resolver extraction mismatch with an injected availability dependency. Added overlap regressions; 657 focused backend and 109 schedule UI tests pass. Exact-head independent review, static/host checks and CI follow. No production migration, activation or deployment.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: a76aa219f5a7964cc0f890e7ad0c97b959c245e2. Resolves independent P2 finding B1-R8: the liveness OBO probe preserves manual provenance only when its trusted caller explicitly supplies automatic: false. Paused manual readiness/liveness regression failed before the fix; 519 focused tests and API typecheck pass. Automatic/unknown callers, revocation, expiry, RBAC and read-only denial stay covered. Inspector observed the missing flag before correction and manual: true afterward. Current dev integration/conflict resolutions are unchanged; fresh exact-head review and CI follow. No production migration, activation or deployment.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Head: a76aa219f5a7964cc0f890e7ad0c97b959c245e2. Integrated dev: a4f6763b070c90cc392faf738e405bb94e8396d0. All six branch conflicts remain resolved; published history was not rewritten.

Independent exact-head review: Complete, no findings. Full frozen-diff and merge-sensitive caller review completed. No independent runtime tests ran because reviewer-lane dependencies were unavailable.

B1-R8 (P2), manual provenance lost in the added OBO liveness probe: fixed in this head. Only a trusted caller's explicit automatic: false forwards manual: true. Automatic and unknown callers are not elevated. Seven regressions use real preflight/execution/consent logic; the paused manual case failed before correction. Revocation, expiry, RBAC and read-only denial remain enforced. No findings rejected; earlier B1-R1/R2/S1/R3–R7 remain fixed.

A disposable localhost inspector breakpoint observed stage: resume, oboOnly: true, and missing manual provenance before the patch. The same breakpoint observed manual: true after correction; the test passed. No credentials or production processes were inspected.

Local checks on final source Result
Grant/preflight/consent/bearer/receipt/handler tests 519 passed, including the 7 new regressions
Typechecks: API, data-schemas, data-provider, client Passed
Real-Mongo token/provenance and tenant-helper tests 93 passed
API build Passed
Scoped lint, formatting, imports, package validation and circular dependencies Passed

On integration parent e358d6f21: shared/client builds, 533 compatibility tests, 109 UI tests, 213 host tests and disposable migration CLI checks passed. Those unchanged-subsystem runs were not repeated at this head.

Local npm run lighthouse timed out (exit 124); no completed local metric is claimed.

Full local design-suppression validation and static-checks:full config migration/unused-i18n/unused-package gates were not run at this head. Actual-provider certification, replica rollout and production inventory/apply remain unverified. No merge, deployment or capability activation was performed.

CI at this read: 36 successful, 2 skipped, 6 running, no failures. CI Lighthouse passed at this exact head. Remaining: e2e (memory, shard 4/6), e2e (memory, shard 2/6), e2e (memory, shard 6/6), e2e (memory, shard 3/6), e2e (memory, shard 5/6), e2e (memory, shard 1/6).

Review source lanes are absent. Git administrative cleanup remains blocked by busy metadata; no forced deletion was attempted.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head, final review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a76aa219f5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/schedules/obo.ts
Comment thread packages/api/src/schedules/obo.ts Outdated
Comment thread client/src/components/SidePanel/Schedules/ScheduleDialog.tsx Outdated
Comment thread packages/api/src/schedules/mcp.ts
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: 21e83afc589744f43149ebca249d9c4d4a62fc99. Addresses all four new Codex findings: purpose-fenced refresh teardown on purge, safe credential diagnostics, shared themed checkbox, and target-only preview initialization. Regression evidence includes failed-before cleanup/logging/initialization tests, stale-generation and retry controls, and light/dark reference-theme keyboard tests. Focused backend/UI checks and API/client typing pass. Final builds/static checks, CI and independent review are running. No production migration, activation or deployment.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: fcb8846cc9dc6f9bf2034ee134d9dac58fe732b9. Fixes independent P2 B1-R13: trusted manual provenance is captured in the immutable credential context for preflight, verified trigger admission and authenticated job restoration. Paused manual grants can renew; automatic/unknown/body-spoofed classifications remain denied, with fresh authority/root/scope/operator/account checks. All three real grant paths failed before correction; 521 focused tests and API typing pass. The four Codex corrections remain intact. Fresh exact-head review and CI follow; no production activation or deployment.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: b5914ceef6ebec3af058eb06c1b12052ddd0a1a5. Fixes independent P1/P2 B1-R14/R15 at their owning boundaries: coordinator diagnostics are bounded metadata, storage no longer duplicates raw exception logs, and live operator/role/resource/provider authorization is rechecked after cached reads, renewal/adoption and enrollment exchange. Real-coordinator and frozen-storage regressions failed before correction; post-provider withdrawal retains cleanup, and outages remain retryable. Both prior Codex/manual-context corrections remain intact. API/schema focused checks pass; fresh exact-head review, final checks and CI follow. No production migration, activation or deployment.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Lighthouse CI failed. The last 80 log lines contain the measured budgets and assertion failures.


[WebServer] 2026-10-05 04:38:00 info: [StreamServices] Created in-memory stream services

[WebServer] 2026-10-05 04:38:00 info: [GenerationJobManager] Configured with in-memory stores

[WebServer] 2026-10-05 04:38:00 info: HTTP server timeout configuration

[WebServer] 2026-10-05 04:38:00 info: Server listening at http://localhost:3080

[WebServer] 2026-10-05 04:38:00 info: [MCPServersRegistry] Creating new instance

[WebServer] 2026-10-05 04:38:00 info: OAuth reconnect manager initialized successfully.

[WebServer] 2026-10-05 04:38:00 info: Created collection: projects

🤖: global setup has been started
🤖: using baseURL http://localhost:3080
🤖: using E2E user: testuser@example.com
🤖: 🗝  authenticating user: testuser@example.com
🤖: ✔️  localStorage: set Nav as Visible /home/runner/work/LibreChat/LibreChat/e2e/storageState.json
[WebServer] 2026-10-05 04:38:02 info: [agent-triggers] durable delivery engine started

[WebServer] 2026-10-05 04:38:03 info: [schedules] engine started

[WebServer] 2026-10-05 04:38:03 info: Server readiness checks passing.

🤖: ✔️  user successfully registered
[WebServer] 2026-10-05 04:38:06 info: [Login] [Login successful] [Username: testuser@example.com] [Request-IP: ::1] {"requestId":"cfc6c77d-e400-4ec1-b52d-4dbbc8fed4bc","request_id":"cfc6c77d-e400-4ec1-b52d-4dbbc8fed4bc","request_method":"POST","request_path":"/api/auth"}

🤖: ✔️  user successfully authenticated
🤖: ✔️  authentication state successfully saved in /home/runner/work/LibreChat/LibreChat/e2e/storageState.json
🤖: global setup has been finished

Running 1 test using 1 worker

[1/1] [chrome] › e2e/lighthouse/load.spec.ts:10:5 › serial database latency stays within web-vitals budgets
[chrome] › e2e/lighthouse/load.spec.ts:10:5 › serial database latency stays within web-vitals budgets
Lighthouse run 1/3 wrote /home/runner/work/LibreChat/LibreChat/.lighthouse/lhr-1.report.json

Lighthouse run 2/3 attempt 1 did not complete, retrying: Command failed: /opt/hostedtoolcache/node/24.16.0/x64/bin/node /home/runner/work/LibreChat/LibreChat/node_modules/lighthouse/cli/index.js http://localhost:3080/c/16390000-0000-4000-8000-000000000001 --quiet --preset=desktop --throttling-method=provided --only-categories=performance --chrome-flags=--headless=new --extra-headers={"Cookie":"token_provider=librechat; refreshToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjZhYzMyOWFhMjcxOWM0N2M5MDY4YTcwMSIsInNlc3Npb25JZCI6IjZhYzMyOWIxMjcxOWM0N2M5MDY4YTc3NSIsImlzc3VlZEF0TXMiOjE3OTExNzUwODkzNzQsImlhdCI6MTc5MTE3NTA4OSwiZXhwIjoxNzkxMTc4Njg5fQ.Hl2ceBwav3J7t1p1nKtQESCxykQp2Y0_fBjAbq4FlfQ"} --output=json --output=html --output-path=/home/runner/work/LibreChat/LibreChat/.lighthouse/lhr-2

  1) [chrome] › e2e/lighthouse/load.spec.ts:10:5 › serial database latency stays within web-vitals budgets 

    Error: Command failed: /opt/hostedtoolcache/node/24.16.0/x64/bin/node /home/runner/work/LibreChat/LibreChat/node_modules/lighthouse/cli/index.js http://localhost:3080/c/16390000-0000-4000-8000-000000000001 --quiet --preset=desktop --throttling-method=provided --only-categories=performance --chrome-flags=--headless=new --extra-headers={"Cookie":"token_provider=librechat; refreshToken=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjZhYzMyOWFhMjcxOWM0N2M5MDY4YTcwMSIsInNlc3Npb25JZCI6IjZhYzMyOWIxMjcxOWM0N2M5MDY4YTc3NSIsImlzc3VlZEF0TXMiOjE3OTExNzUwODkzNzQsImlhdCI6MTc5MTE3NTA4OSwiZXhwIjoxNzkxMTc4Njg5fQ.Hl2ceBwav3J7t1p1nKtQESCxykQp2Y0_fBjAbq4FlfQ"} --output=json --output=html --output-path=/home/runner/work/LibreChat/LibreChat/.lighthouse/lhr-2
    Runtime error encountered: Something went wrong with recording the trace over your page load. Please run Lighthouse again. (NO_NAVSTART)


    attachment #1: screenshot (image/png) ──────────────────────────────────────────────────────────
    e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/test-failed-1.png
    ────────────────────────────────────────────────────────────────────────────────────────────────

    Error Context: e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/error-context.md

    attachment #3: trace (application/zip) ─────────────────────────────────────────────────────────
    e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/trace.zip
    Usage:

        npx playwright show-trace e2e/lighthouse/.test-results/load-serial-database-latency-stays-within-web-vitals-budgets-chrome/trace.zip

    ────────────────────────────────────────────────────────────────────────────────────────────────


🤖: global teardown has been started
2026-10-05 04:39:42 �[32minfo�[39m: �[32mMongo Connection options�[39m
2026-10-05 04:39:42 �[32minfo�[39m: �[32m{�[39m
�[32m  "bufferCommands": false�[39m
�[32m}�[39m
🤖:  ✅  Connected to Database
🤖:  ✅  Found user in Database
🤖:  ✅  Deleted 1 convos & 2 messages
🤖:  ✅  Deleted user from Database
🤖: global teardown has been started
2026-10-05 04:39:42 �[32minfo�[39m: �[32mMongo Connection options�[39m
2026-10-05 04:39:42 �[32minfo�[39m: �[32m{�[39m
�[32m  "bufferCommands": false�[39m
�[32m}�[39m
🤖:  ✅  Connected to Database
🤖:  ⚠️  User not found in Database
  1 failed
    [chrome] › e2e/lighthouse/load.spec.ts:10:5 › serial database latency stays within web-vitals budgets 

Open the full run

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: 8a6d2b1a6d612323f2d8a07ff44756e8ba477bb9. Fixes independent P1 B1-R16 at the shared custom-variable helper and its MCP consumer: lookup/decryption diagnostics are bounded metadata, decryption errors retain causes without diagnostic text, and throw/fallback behavior is preserved. Seven failed-before privacy cases and ordinary MCP/Apps controls pass; 236 focused tests and API typing pass. All prior Codex/manual/operator-policy corrections remain intact. Fresh exact-head review and CI follow. No production migration, activation or deployment.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: 1d033cce78ad54a4465a4772a241dd3cd89f6cf0. Fixes the linked token-expiry CI assertion to require bounded metadata, not a raw Error. Sanitizes immediate OBO discovery/rejection/runtime/trust logs while preserving causes and propagation. Failed-before regression coverage includes factory and runtime consumers. Merges dev 114394c6a02a3343bab495e7baa9a9a6be89235b without rewriting history; locked dependencies refreshed. The linked suite, 649 focused tests, API typing and touched lint/import/format checks pass. Exact-head independent review, final gates and CI follow. No production migration, activation or deployment.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: 5288524c02cae17f11e1e4a3331f292ce4af4de3. B1-R18 (P1) outer MCP tool diagnostics and B1-R19 (P2) grant revocation during final authority I/O are fixed. Original typed causes and rejection/cancellation behavior are retained. The last generation snapshot now follows final authority I/O under the credential teardown fence; permanent policy denials stay distinct from retryable fence/store outages. All four failed-before regression cases pass. Grant/coordinator/consumer tests: 563 passed; outer-tool tests: 133 passed; API typing/build and touched static checks passed. A fresh independent review and CI follow for this exact head. No merge, production migration or activation.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review head: 7b259a7bd8f27cc2cef78fa13a556d241d065067. B1-R20 (P1), decrypted resource URLs in plaintext scheduled token metadata, is fixed. URL metadata now carries a domain-separated keyed fingerprint; read/renewal compare the exact live target binding. Ordinary OAuth metadata is unchanged. The failed-before persistence regression checks every grant row, cached delivery, renewal, drift rejection and cleanup. Old plaintext bindings and changed replica keys require explicit re-enrollment; retained grants stay revocable. Grant/consumer tests: 566 passed; host/outer tests: 138 passed; API typing/build and touched lint/format/import checks passed. Fresh exact-head review and CI follow. No production inventory, migration, activation or merge.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Head/reviewed head: 7b259a7bd8f27cc2cef78fa13a556d241d065067. Base/merge-base: 114394c6a02a3343bab495e7baa9a9a6be89235b.

The linked token-expiry failure is fixed without restoring unsafe Error logging. Its API shard passed on this head.

Finding dispositions:

  • B1-R17 (P1), immediate OBO diagnostic consumers: fixed in 1d033cce7.
  • B1-R18 (P1), outer MCP tool diagnostics, and B1-R19 (P2), manual delivery after completed revocation/purge during final authority I/O: fixed in 5288524c0.
  • B1-R20 (P1), sensitive resolved URLs in plaintext token metadata: fixed in this head. Enrollment/read/renewal use a domain-separated keyed exact-URL fingerprint. Ordinary OAuth metadata stays unchanged. Old plaintext scheduled bindings and changed keys require explicit re-enrollment; retained cleanup remains available.
  • No findings rejected. Earlier ledger corrections remain intact.

Independent review: Complete, no findings at this exact head. Frozen-source probes covered plaintext/auxiliary persistence confidentiality, rotating renewal, shared/different keys, old bindings, explicit replacement, retained inventory, ordinary isolation, outer diagnostics and late revoke/purge delivery. No independent Jest, browser, real MongoDB/SDK or distributed/provider certification is claimed.

Final-source local checks Result
Grant, coordinator, expiry, factory and manager tests 566 passed
Host/outer MCP tool tests 138 passed
Admission/execution/runtime/receipt tests 323 passed
API npx tsc --noEmit and API build Passed
Scoped ESLint, Prettier, imports, package validation and circular checks Passed

UI 111, real-Mongo/provenance 98 and the other workspace typechecks were verified at parent 1d033cce7, in unchanged source areas, not rerun locally here. CI includes the current-head backend/frontend/data-schema/type/build/static lanes.

Local Lighthouse with the existing Chromium binary exceeded the bounded worker limit (124); no completed local metric is claimed. Exact-head CI Lighthouse and Static checks passed. Local design-suppression validation previously timed out. static-checks:full config migration, unused-i18n and unused-package gates were not run. No new screenshots are claimed for these nonvisual corrections.

Default capability remains fail-closed. No production inventory/migration, provider certification, activation, replica rollout, merge or deployment occurred.

CI snapshot: 38 passed, 4 running, 2 skipped, no failures. The remaining jobs are memory E2E shards 1/6, 2/6, 5/6 and 6/6. The previously failing API shard, Lighthouse and Static checks passed at this head. All inline review threads are resolved. CI is not yet complete.

@danny-avila

Copy link
Copy Markdown
Collaborator

@codex review the latest head, final review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7b259a7bd8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

private static async executeTokenRefresh({
userId,
serverName,
scheduledGrant,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep invalid-client cleanup in the scheduled namespace

When a scheduled refresh provider throws an unstructured error recognized by isInvalidClientMessage (for example, Error('invalid_client') rather than an object with an error field), this function retains scheduledGrant for the refresh row but the cleanup branch calls deleteClientRegistration without forwarding it. That helper consequently targets mcp: instead of scheduled-mcp:, leaving the scheduled client record orphaned after the refresh row disappears from the grant list; pass scheduledGrant into that cleanup call as well.

AGENTS.md reference: AGENTS.md:L44-L46

Useful? React with 👍 / 👎.

throw missingGrant();
let response: GrantResponse;
try {
response = await provider.exchange(accessToken, `${target.scopes} offline_access`);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bind enrollment assertions to the active OpenID provider

When the configured OpenID issuer or token endpoint changes while an existing browser session remains live, the enrollment checks bind the session only to the persisted user's old issuer; they never verify that issuer is still accepted by the current getOpenIdConfig() provider. The preview fingerprint also omits provider metadata, so clicking a previously opened confirmation can send the old provider's bearer assertion to the newly configured token endpoint. Validate the session issuer against the active provider (including supported issuer templates), or bind the provider configuration into the preview, before performing this exchange.

AGENTS.md reference: AGENTS.md:L44-L46

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🗺️ Auth OAuth Infra codegraph: the taxonomy area this belongs to (classifier, confidence ≥ 0.9) 🛡️ security review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants