fix: prevent stale Personal Server URL after Account OAuth login - #6
Merged
Conversation
Account OAuth login (the OIDC device-grant path added in #3) never returns Personal Server fields on the real token response, so the CLI silently kept a previous account's pinned personalServerUrl in ~/.vana/vana-connect-state.json after switching accounts. Clear it whenever a fresh login reports no PS, and read PS fields from id_token claims as a secondary source alongside the top-level token fields. Surface a clear "no Personal Server found" hint instead of silently omitting it. This is a preparatory correctness/UX fix, not full Account OAuth -> PS sync enablement: Unity Account has no authenticated-session endpoint that mints or returns a caller's Personal Server URL/session token (the legacy connect app's device-poll route does this via personal_servers/sessions tables, but Unity Account doesn't expose an equivalent yet). See the accompanying report for what's still needed server-side.
Contributor
|
🎉 This PR is included in version 0.15.1 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is a preparatory correctness/UX fix, not full Account-OAuth → Personal-Server sync enablement. It closes gaps that are reachable and fixable purely client-side; it does not (and cannot yet) make Account OAuth login reliably resolve a real Personal Server for every account. See "What's still needed" below.
personalServerUrlpinned in~/.vana/vana-connect-state.json. Re-logging into a different account could silently keep pointing the CLI at the wrong PS.runLoginnow always syncs (including clearing) the pinned config to the new login's result.id_tokenclaims as a fallback source, alongside the existing top-level token-response fields (personal_server_url,personal_server_session_token,ps_access_token), mirroring the existing pattern already used to resolve the account address from claims.vana server set-url <url>).What's still needed (out of scope here)
The legacy
connectapp's/api/auth/device/pollroute resolves a caller's Personal Server server-side (findServerByUserIdagainstpersonal_servers/sessionstables) and returns it in the poll response. Unity Account has no equivalent authenticated-session endpoint — nothing a CLI can call with just an OAuth access/session token to mint or fetch that caller's Personal Server URL and a fresh PS session token. The closest existing pieces (/api/oauth/introspect→linked_wallets, and the on-chainlookupPersonalServerByOwnerhelper inpackages/vana-account-client) require either wallet-signature auth the CLI doesn't have, or an on-chain contract read the CLI doesn't currently implement — a materially larger change (newviemdependency, new lookup flow) than this PR's scope. Full sync requires Account to expose (or mint) an authenticated PS URL/session-token lookup; until then, real-world cloud OAuth logins will keep landing withpersonal_server: nullunless the token response happens to include it.Full findings in the accompanying report:
/home/tnunamak/.tmp/vana-cli-account-ps-sync-report.md.Test plan
pnpm buildpnpm test(269 tests, including 3 new targeted tests)pnpm validate(lint + eslint + format + test)test/cli/auth.test.ts: OAuthid_tokenclaims resolve PS info when the token response omits it;personal_serverstaysnullwhen OAuth returns no PS info at all.test/cli/index.test.ts: stale pinned PS URL is cleared when cloud login resolves none (with the new user-facing hint); PS URL is pinned when cloud login does resolve one.