Skip to content

Recover expired Access sign-in while preserving open work - #719

Merged
witbrock merged 2 commits into
mainfrom
codex/von-115be2098aa8e0fd
Sep 16, 2026
Merged

witbrock merged 2 commits into
mainfrom
codex/von-115be2098aa8e0fd

Conversation

@witbrock

@witbrock witbrock commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

Merge decision: ready — interrupted Access sign-in now has a normal sign-in route while the original tab retains its conversation, unsent text and attachments; proportionate tests show recovery without replaying a message.

User outcome

A lapsed Cloudflare Access session can make browser fetches fail even while Von is healthy. The recovery view now explains that sign-in, network or server problems may be responsible and offers Sign in again in a new tab. After sign-in, returning to the original tab rechecks the connection and retries failed conversation reads without reloading the composer.

Native task: #V#task_agent_7e1403047bb7730408a837def239f77d.

Material changes

  • Read health with manual redirect handling; distinguish opaque redirects, access refusal, HTTP errors and unexpected responses. A generic TypeError remains uncertain.
  • Add a same-origin, user-triggered sign-in link with noopener noreferrer to both the open-page recovery view and cached offline shell. Keep all open work in the original tab.
  • Retry conversation-list and failed/missing transcript reads after reconnection, preserving the composer and avoiding replacement of live answers.
  • Install the public health helper and offline shell in a separate cache version so interrupted upgrades preserve the active bundle; no health responses or authenticated content are cached.

Evidence

  • 322 targeted Jest tests passed: health interpretation, maintenance/draft recovery, health-state thresholds, interrupted worker upgrades and chat behaviour, including the failed-read recovery regression.
  • tests/browser/outageComponents.cjs passed with production outage components and a disposable cross-origin HTTP/cookie fixture. The baseline fetch raised TypeError; the candidate observed opaqueredirect. New-tab sign-in restored conversation access with text, attachment and selection retained. The cached offline shell also recovered after sign-in. Healthy, HTTP 503, device-offline, transient failure and active-thinking paths passed; zero non-GET requests.
  • Four viewports covered, including desktop and mobile. Screenshots and receipt retained in .run/access-recovery/ for the controller's execution archive.
  • Frontend static lint passed with zero errors and one pre-existing unused-catch-variable warning in main.js; git diff --check passed.

Ship boundary

Minimum ship evidence is satisfied for this bounded frontend recovery path. Lost drafts, replaced conversation selection, automatic message replay, false certainty about session expiry, or broken genuine-outage recovery would block merge.

The browser replay is a local fixture, not a real Cloudflare/Google OAuth session, full authenticated Von backend or physical-phone test. Production conversation-read recovery is separately covered by Jest. No model prompts were submitted. The assignment expressly permits nearest-faithful evidence when a real edge replay is unavailable.

No Cloudflare policy, credentials, database routing, backend authentication or infrastructure changes. This task authorises publication and merge but does not request deployment; live activation remains separate.

@witbrock
witbrock merged commit abcf1e6 into main Sep 16, 2026
2 checks passed
@witbrock
witbrock deleted the codex/von-115be2098aa8e0fd branch September 16, 2026 03:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant