fix: release the Prover's OAuth return as soon as nothing needs it - #104
Merged
Merged
Conversation
PopupWindow.current kept its fragment snapshot, an OAuth return included, for as long as the connection lived. accept now takes the snapshot off the window. Only a document that isn't isolated and has an isolation fallback keeps it, in the fallback URL's hash, until its endpoint ends. The hop reads that URL before releasing, so the fragment still travels byte for byte. An isolated document, or one accepted without the option, keeps nothing. Signed-off-by: Wondertan <hlibwondertan@gmail.com> Assisted-by: Claude Opus 5.5
…llback The isolation hop is an expected connection end, so the leaving Prover never cleaned up and kept its OAuth input. Any end of the connection now ends the run and drops the input, as failure, denial and delivery already did. The LIBID-OAUTH-023 traceability row no longer lists the gap. Closes #95 Signed-off-by: Wondertan <hlibwondertan@gmail.com> Assisted-by: Claude Opus 5.5
Wondertan
force-pushed
the
fix/prover-oauth-return
branch
from
October 2, 2026 18:51
18e16d9 to
8cd53b6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #95.
accepttakes the fragment snapshot offPopupWindow.current(). Only a document that isn't isolated and has an isolation fallback keeps it, in the fallback URL's hash, until its endpoint ends; the hop reads that URL before releasing. An isolated document, or one without the option, keeps nothing. The public API is unchanged.Spec conformance: the fragment still travels byte for byte through the isolation replacement (REQ-POPUP-CONT-07/08, REQ-DIST-03 "preserve that capture through replacement"), and the fallback still captures and clears it on arrival.
Tests:
Validation: build, typecheck (both e2e configs too), unit tests (popup 154, ceremony 994), lint, fmt. Playwright: popup 173 passed (2 skipped), ceremony 193/193.