feat(accounts): add platform credential slots - #436
Conversation
Obiente previewNC Native · Obiente updates this comment as the preview changes. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b5e6014e2e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d0bb0e52ff
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6dabe16e75
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5849f1719f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
d6d0017 to
4daca37
Compare
4daca37 to
f7931ce
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f7931ce047
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0b1e4cb658
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
0b1e4cb to
c0526df
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c0526df17f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
c0526df to
bbc70fc
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bbc70fc564
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
28965a7 to
1d310d0
Compare
07d146e to
ab6601c
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ab6601c399
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7ce005b917
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
7ce005b to
b02b997
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b02b9973ae
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
1478f63 to
6f8eb35
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6f8eb351d5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| } | ||
| } | ||
| } | ||
| is AndroidAccountCredentialStoreRead.Invalid -> clearInvalidStore(read.encrypted) |
There was a problem hiding this comment.
Recover independent slots before clearing the session
When the aggregate credential blob is malformed but the credential-free registry and per-account slots remain valid, loadSession() can still authenticate through those slots, yet signing out takes this branch and calls clearInvalidStore, whose empty replacement deletes every account slot rather than only the active account. This silently removes credentials for all retained accounts; fresh evidence beyond the earlier malformed-login issue is that the final clearSession invalid-store branch still bypasses readIndependentCredentialSlotState(). Reconstruct the independent state and remove only its active account before clearing.
AGENTS.md reference: AGENTS.md:L325-L329
Useful? React with 👍 / 👎.
| selected = accountOperationGuard.withSyncRunLock { | ||
| sessionPublicationGuard.serialize { | ||
| accountCredentials.selectAccount(accountId)?.also { session -> |
There was a problem hiding this comment.
Serialize desktop pair removal with account selection
When a pair-removal action captured for account A resumes after this selection commits account B, removeFileSyncPair does not acquire accountOperationGuard or withSyncRunLock and does not revalidate the active session. It can therefore call DesktopFileSyncEngine.removePair with A's stale session, perform authenticated cleanup of A's remote upload collections, and delete A's local pair after the switch has completed. The new checks cover sync runs and conflict resolution but not pair removal, so that path should use the same serialization and active-session preflight.
AGENTS.md reference: AGENTS.md:L373-L376
Useful? React with 👍 / 👎.
| removeQueuedUploads = { session -> | ||
| incomingShareAccountCleanup.removeForAccount(session) | ||
| durableUploadAccountCleanup.removeForAccount(NextcloudDocumentIds.accountKey(session)) | ||
| }, |
There was a problem hiding this comment.
Retire persisted sync pairs when removing an account
When an Android account with configured folder-sync pairs is removed, this cleanup retires incoming-share and multipart-upload jobs but leaves the account's persisted sync pairs intact. If the same account is later added again with the same URL spelling, replaceActiveStateWhileOperationsIdle invokes restorePersistedPairSchedules, which discovers those old pairs and resumes automatic local and remote synchronization without the user recreating them. Beyond the now-cleaned upload stores, this is a separate durable write path from the deleted account lifecycle, so account removal must purge or explicitly retire its sync pairs before completing.
AGENTS.md reference: AGENTS.md:L375-L376
Useful? React with 👍 / 👎.
| val accountLease = acquireAndroidDocumentWritebackAccountLease( | ||
| session, | ||
| file.path, | ||
| services::loadSession, | ||
| ) |
There was a problem hiding this comment.
Lease every DocumentsProvider mutation across account changes
The new account lease protects only writable-descriptor setup and its delayed writeback, while createDocument, renameDocument, deleteDocument, and moveDocument still capture a session and execute DAV writes without participating in ANDROID_ACCOUNT_OPERATION_GUARD. If selection or removal starts after one of those methods calls requireSession(), the transition can finish before the synchronous mutation runs with the old account credential. Fresh evidence beyond the earlier descriptor finding is that the final lease was added solely in openWritableDocument; acquire and revalidate the same lease around each direct DocumentsProvider mutation as well.
AGENTS.md reference: AGENTS.md:L373-L376
Useful? React with 👍 / 👎.
| val accepted = accountOperationGuard.tryActivateResource { | ||
| if (!desktopResourceActivationMatchesActiveAccount(activeAccountId(), session.accountId)) { | ||
| false |
There was a problem hiding this comment.
Reject stale credentials when activating desktop resources
When a hydration request captured before same-account reauthentication reaches this check after the new password is committed, the account ID is unchanged, so the request is accepted even though its session still contains the superseded credential. The pre-save live-resource check cannot see this not-yet-registered job, and it then performs authenticated reads with the old password and may occupy the hydration slot until failure. Fresh evidence beyond the earlier account-switch race is that final activation validates only activeAccountId() rather than the complete persisted session; compare the supplied session with loadSession() while holding the activation guard.
AGENTS.md reference: AGENTS.md:L373-L376
Useful? React with 👍 / 👎.
Outcome
Advances #172. This PR depends on #429.
Verification
Build-host commands:
The full source and packaging validation ran on exact #429 parent
78eb576fc8881a246feb1fac8b0b443d4ed1b903. Before publication, #429 advanced tof0696b474a625bd52dfffb29d5695a0a8f996265with only a one-line automated marketing capture-manifest update. The child source was unchanged. The final child commit only links this PR number in the already-validated changelog fragment.Compatibility and risk
Visual changes
Not applicable.