fix(auth): recover from provider credential failures - #1188
TheGreatAxios merged 20 commits into
Conversation
TheGreatAxios
left a comment
There was a problem hiding this comment.
Primary review: approved. The full branch passes the repository gate, including 8,072 randomized tests, and all CL-9347 recovery, replay, redaction, and race-safety criteria are satisfied.
|
Critic review: approved with no blocking or should-fix findings. Exact-source OAuth recovery, actionable guidance, credential sanitization, selector identity validation, and replay fences are covered by permanent regressions. |
|
Warden security review: GO. Provider-auth provenance, authoritative refresh winners, access and refresh credential redaction, concurrent refresh races, and explicit switch authorization are closed with synthetic-secret tests. |
|
Greybeard architecture review: approved. Credential stores own committed winners, provider sessions install exact winners, the inference harness owns immutable retry and commitment state, and the TUI owns generation-scoped explicit recovery. |
683949d to
462c78d
Compare
Summary
/connectrecovery with explicit provider switchingVerification
bun run checkpassesFixes CL-9347