Skip to content

fix(auth): treat OIDC discovery 5xx as unavailable - #288

Merged
steipete merged 1 commit into
openclaw:mainfrom
SebTardif:fix/clickclack-f007
Oct 7, 2026
Merged

steipete merged 1 commit into
openclaw:mainfrom
SebTardif:fix/clickclack-f007

Conversation

@SebTardif

@SebTardif SebTardif commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

A temporary discovery HTTP 5xx from the default OpenClaw ID issuer used to abort server startup even though ClickClack has documented fallback endpoints. Treat HTTP 500–599 as unavailable discovery, just like network failure and HTTP 404. Custom issuers still fail closed; malformed documents, redirects, client errors, and statuses outside the server-error range are rejected. Explicit endpoint overrides remain intact.

Expanded regression coverage exercises both issuer types, fallback status boundaries, rejected responses, and each endpoint override. Updated the authentication guide and Unreleased changelog. Thanks @SebTardif for the fix.

Validation: the original regression failed against main for HTTP 500, 502, and 503. The expanded discovery tests and full pnpm check passed on AWS Crabbox with Go 1.27.1, Node.js 24.19.0, and pnpm 12.7.0. Independent Codex autoreview is scoped-clean through P2. Test credential strings are inert fixtures, not live credentials. GitHub CI must pass on the updated head before merge.

@SebTardif
SebTardif requested a review from a team as a code owner October 4, 2026 02:46
@clawsweeper

clawsweeper Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review blocked

Automated review did not run, so no review verdict was produced.

Reason: The input-safety check rejected material in this revision. No detected value, path, or scanner output is reproduced here.

Automatic review is on hold, including after source changes. Request a fresh re-review after resolving the failure; maintainers can also release the hold through an intentional scanner-policy update.

Next step: If this is a genuine credential, remove and rotate it. If it is an intentional test fixture, a maintainer must review and qualify it.

View the workflow run.

Preserve strict custom issuer discovery and explicit endpoint overrides.

Co-authored-by: Sebastien Tardif <sebtardif@ncf.ca>
@steipete
steipete force-pushed the fix/clickclack-f007 branch from 445579e to d852ae1 Compare October 7, 2026 04:17
@steipete
steipete merged commit 8ca28be into openclaw:main Oct 7, 2026
10 checks passed
@steipete

steipete commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Merged as 8ca28be. Thanks @SebTardif.

The original test reproduced default-issuer startup failures for discovery HTTP 500, 502, and 503 on main. On the finished patch, the expanded discovery tests and full pnpm check passed on AWS Crabbox (Go 1.27.1, Node.js 24.19.0, pnpm 12.7.0). Independent Codex review found no actionable P0–P2 issues.

All checks passed on exact head d852ae1: server/web/Docker/browser CI and Windows/macOS/Linux desktop CI. Custom issuers remain fail-closed, endpoint overrides are preserved, and docs/changelog now describe the fallback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants