Skip to content

fix: release the Prover's OAuth return as soon as nothing needs it - #104

Merged
Wondertan merged 2 commits into
mainfrom
fix/prover-oauth-return
Oct 2, 2026
Merged

Wondertan merged 2 commits into
mainfrom
fix/prover-oauth-return

Conversation

@Wondertan

Copy link
Copy Markdown
Member

Closes #95.

  • Popup: accept takes the fragment snapshot off PopupWindow.current(). Only a document that isn't isolated and has an isolation fallback keeps it, in the fallback URL's hash, until its endpoint ends; the hop reads that URL before releasing. An isolated document, or one without the option, keeps nothing. The public API is unchanged.
  • Ceremony: the leaving Prover now ends its run, and drops its OAuth input, on any connection end, including the expected end when it hops to the isolation fallback.

Spec conformance: the fragment still travels byte for byte through the isolation replacement (REQ-POPUP-CONT-07/08, REQ-DIST-03 "preserve that capture through replacement"), and the fallback still captures and clears it on arrival.

Tests:

  • A new popup test, POPUP-CONNECTION-013, covers the isolated case, the port hop, failure without a hop, and no fallback option.
  • The fallback-constructor hop test also checks the fragment is dropped.
  • The Prover hop test, now LIBID-OAUTH-023, expects cleanup and ignores a late ProveIdentity.
  • The new assertions fail on the old code.

Validation: build, typecheck (both e2e configs too), unit tests (popup 154, ceremony 994), lint, fmt. Playwright: popup 173 passed (2 skipped), ceremony 193/193.

PopupWindow.current kept its fragment snapshot, an OAuth return included, for as long as the connection lived. accept now takes the snapshot off the window. Only a document that isn't isolated and has an isolation fallback keeps it, in the fallback URL's hash, until its endpoint ends. The hop reads that URL before releasing, so the fragment still travels byte for byte. An isolated document, or one accepted without the option, keeps nothing.

Signed-off-by: Wondertan <hlibwondertan@gmail.com>
Assisted-by: Claude Opus 5.5
…llback

The isolation hop is an expected connection end, so the leaving Prover never cleaned up and kept its OAuth input. Any end of the connection now ends the run and drops the input, as failure, denial and delivery already did. The LIBID-OAUTH-023 traceability row no longer lists the gap.

Closes #95

Signed-off-by: Wondertan <hlibwondertan@gmail.com>
Assisted-by: Claude Opus 5.5
@Wondertan
Wondertan force-pushed the fix/prover-oauth-return branch from 18e16d9 to 8cd53b6 Compare October 2, 2026 18:51
@Wondertan
Wondertan merged commit 8cd53b6 into main Oct 2, 2026
17 checks passed
@Wondertan
Wondertan deleted the fix/prover-oauth-return branch October 2, 2026 18:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ceremony: Prover keeps the raw OAuth return for the connection's lifetime

1 participant