Skip to content

fix(api): test connections with current OAuth credentials - #1507

Merged
frahlg merged 10 commits into
masterfrom
cursor/driver-probe-secrets-658d
Oct 6, 2026
Merged

frahlg merged 10 commits into
masterfrom
cursor/driver-probe-secrets-658d

Conversation

@frahlg

@frahlg frahlg commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Refs #1502. Depends on #1508. Includes the commits from #1517.

Test connection now uses the configured driver's current OAuth token instead of the original YAML token. It shares secrets only for the same saved name and Lua file. An explicit replacement token stays separate from the working account.

The probe uses the credential owner from #1508 for reads and durable writes. After a changed shared token has been saved and the probe removed, it restarts the configured live driver so that driver loads the new token. An unchanged token does not restart the driver. The restart target comes from the matched live driver, addressing the review on #1517.

Regression tests use a credential owner that differs from the display name and check the token actually read by the restarted Lua driver. Both changed-token and unchanged-token tests failed before the owner integration and now pass.

Validation: targeted API tests, make verify, and race-detector tests for config, state and driver probes pass on the combined branch. The earlier rotation/restart fix also has the hardware evidence recorded in #1517; the combined owner integration has not yet run on that customer's box.

segran2 and others added 5 commits October 3, 2026 12:20
Share persisted OAuth state with Test connection only when the probe
matches the saved driver name and Lua file. An explicit new token is
not overwritten or written back onto the live driver.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>

segran2 commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Hardware validation / follow-up from a real FTW site (v0.139.2-beta.6 candidate):

The shared-refresh-token race described in this PR was reproduced on beta.5: after a successful MyUplink Test connection, the probe rotated/persisted the shared refresh token while the live myuplink driver kept the older token in Lua memory. On the next refresh the live driver entered a repeated HTTP 400 invalid_grant loop; restarting FTW recovered immediately by re-reading the persisted token.

A follow-up fix was tested that restarts the live driver after a probe successfully changes a shared persisted secret (probe removal first, then RestartByName for the secret owner). Hardware result:

  • Test probe became ready (read-only).
  • Probe was removed.
  • Live myuplink was immediately removed/restarted.
  • Live MyUplink became ready (read-only) again ~320 ms later.
  • Persisted refresh-token SHA3-256 changed, confirming an actual rotation.
  • Repeated Test connection runs at 18:39, 19:37 and 19:52 all followed the same successful restart/re-ready sequence.
  • No invalid_grant occurred afterward, including well beyond the previous ~1 h failure window.

The candidate change was also covered by targeted tests for restart-on-rotation and no-restart-when-unchanged, go test ./internal/api -count=1, and the local CI script.

This provides physical-hardware confirmation that restarting the live driver after probe rotation resolves the stale in-memory refresh-token failure mode.

@frahlg
frahlg changed the base branch from master to cursor/oauth-credential-owner-658d October 6, 2026 07:47
@frahlg
frahlg marked this pull request as ready for review October 6, 2026 07:47
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

frahlg added 2 commits October 6, 2026 09:49
…able-oauth-probe-signed-20261006

Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>
Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>
@frahlg
frahlg force-pushed the cursor/oauth-credential-owner-658d branch from a7c27b3 to 54b3bc7 Compare October 6, 2026 07:49
@frahlg
frahlg force-pushed the cursor/driver-probe-secrets-658d branch from 6f762ef to 95ede97 Compare October 6, 2026 07:49
…able-oauth-probe-signed-20261006

Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>
@frahlg
frahlg changed the base branch from cursor/oauth-credential-owner-658d to master October 6, 2026 07:52
Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>
@frahlg frahlg changed the title fix(api): rebase driver Test connection secrets onto master fix(api): test connections with current OAuth credentials Oct 6, 2026
@frahlg
frahlg merged commit 4782a3e into master Oct 6, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants