Repository navigation
migration: loopback OAuth login and organization token submission - #8
GroophyLifefor wants to merge 1 commit into
Conversation
Adds a loopback OAuth login that keeps the organization session in memory only, and submits scans with the organization token, the v2 client markers and the x-org-id organization header. A rejected session triggers exactly one re-authentication and one resubmission. The delivery email stays a delivery address, name and company are optional, and the success output prints the queued status and the accounts-ui reports URL. Verified with unit tests, lint and an end-to-end run against the local ingestion service.
WalkthroughReport submission migrates from an anonymous v1 POST to an authenticated v2 flow. A new Validation: cloned the head, Assessment
The core auth design is sound: loopback-only binding, random Verdict: REQUEST_CHANGES — one blocking Windows compatibility defect in the browser launcher; the rest of the change is well-structured and well-tested. |
| return new Promise((resolve) => { | ||
| const platform = process.platform | ||
| const command = platform === 'darwin' ? 'open' : platform === 'win32' ? 'cmd' : 'xdg-open' | ||
| const args = platform === 'win32' ? ['/c', 'start', '', url] : [url] |
There was a problem hiding this comment.
lib/auth.js:53
On Windows the sign-in URL is handed to cmd /c start "" <url>. The URL's query string contains & (.../sign-in?extension=nsolid-plugin&port=8765&state=…), and & is a command separator for cmd.exe. Because the argument has no spaces, libuv's argument quoting leaves it unquoted, so cmd.exe splits the line and start receives only the URL up to the first & — port and state never reach the accounts UI, so the loopback callback can't complete. The full URL is also printed to stderr, so a user can still finish the login manually, but the auto-open path silently fails on Windows.
Quote the URL so cmd.exe treats it as a single token, e.g. ['/c', 'start', '', "${url}"] (or open via explorer.exe <url>, which does not reparse shell metacharacters), and confirm on a Windows host.
🤖 Ask ns-control-tower to fix this
@ns-control-tower please fix: on Windows defaultBrowserLauncher passes the sign-in URL unquoted to cmd /c start, so & in the query string truncates it; quote the URL (or use explorer.exe) so the full URL opens.
| } | ||
| log.info('Session rejected, re-authenticating once') | ||
| const freshSession = await deps.relogin() | ||
| token = freshSession?.token |
There was a problem hiding this comment.
🛠️ Refactor suggestion
lib/submit.js:329
After a 401, post() reuses the original session.consoleId for the x-org-id header while swapping in the fresh token. login() also returns a consoleId, so if the user re-authenticates into a different org the retry sends a fresh token paired with a stale org id (a second 401/403 would then surface, but the request is still inconsistent). Refresh consoleId from freshSession too — or rebuild the header — so the retry is self-consistent.
🤖 Ask ns-control-tower to fix this
@ns-control-tower please fix: on 401 re-auth in submitReport, refresh session.consoleId from the freshSession so the retried x-org-id matches the new token.
Closes #5.
Closes #6.
Loopback login with an in memory organization session and organization
token submission, verified end to end against the local ingestion service
(scan stored under the organization prefix, worker produced data.json and
report.pdf).