feat(gui): native Kiro device login and auto-selection chips in the dashboard - #6016
Conversation
…ashboard Kiro's Add account and Login buttons open a chooser: Kiro CLI (unchanged import), Builder ID, Google or GitHub device sign-in. The dialog shows the user code, links only to the exact Kiro/AWS verification hosts, cancels by flowId, and hands an unfinished flow to a module-scoped finalizer so the server reconciles a committed login after the dialog closes. Kiro account rows show why an account is not auto-selected (quota exhausted, suspended). Plan: devlog/_plan/260926_kiro_lb_parity2/100_gui_device_login_and_skip_reason.md
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
✅ Deterministic PR hygiene checks passed. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: lidge-jun/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (28)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: de640c340e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const openLogin = (addAccount: boolean) => { | ||
| if (item.name === "kiro") setKiroChooser({ addAccount }); | ||
| else void authHandlers?.onLogin(item.name, addAccount); |
There was a problem hiding this comment.
Route the add-provider Kiro buttons through the chooser
This interception covers only the workspace ProviderAuthPanel. In the Add provider modal's Accounts tab, CatalogAccountRow.tsx still sends Kiro's Login/Add account buttons through Providers.onAccountLogin, which calls requestLoginOAuth directly. Those dashboard buttons therefore bypass the new chooser and immediately launch the legacy Kiro CLI flow; Add account can even sign the CLI out temporarily. Route the modal's Kiro actions through the same chooser.
Useful? React with 👍 / 👎.
| const refreshDerivedAfterLogin = useCallback(() => { | ||
| void fetchConfig(); | ||
| void fetchProviderQuotas(true); | ||
| bumpModelsRefresh(); | ||
| }, [fetchConfig, fetchProviderQuotas, bumpModelsRefresh]); |
There was a problem hiding this comment.
Refresh OAuth status after native login
When a native login adds an account, this refresh path updates the roster, config, quotas, and models but never calls fetchOauth or updates oauthStatus. Since accountLoginStatus is derived solely from oauthStatus, reopening the Add provider Accounts tab can continue showing Kiro as logged out and offer Login rather than Add/Manage until the page is reloaded. Refresh OAuth status here as the other login/logout paths do.
Useful? React with 👍 / 👎.
리뷰 · 우선순위 63 / 80이 PR은 대시보드의 Kiro 로그인에 기기 로그인을 붙입니다. 공급자 화면의 로그인 버튼과 계정 추가 버튼이 선택 창을 엽니다. 맨 위는 Kiro CLI입니다. 이 버튼은 예전과 같은 가져오기 요청을 보냅니다. Builder ID, Google, GitHub는 서버에 기기 로그인을 시작합니다. 창에는 사용자 코드와 복사 버튼이 있습니다. 확인 페이지로 가는 링크는 두 종류의 주소만 됩니다. 라인 - 라인 - 라인 - 메인테이너의 판단이 필요한 지점 공급자 추가 창의 Kiro 버튼을 이번 선택 창에 연결할지 정해야 합니다. 이번 PR은 그 버튼을 Kiro CLI로 남겨 두었습니다. 534행의 로그인 표시가 옛 값이면, 방금 계정을 넣은 뒤에도 그 버튼은 첫 로그인으로 보입니다. 81행 알림을 취소에는 끌지 정해야 합니다. 저장이 겹쳤을 때를 위해 목록 확인 문구를 남길 수도 있습니다. 너의 추천
이 댓글은 grok-bot이 작성했습니다 |
Ingwannu
left a comment
There was a problem hiding this comment.
Requesting one P2 lifecycle correction on exact head ab107482b9.
use-kiro-device-login.ts sends the status fetch without an abort signal and hands Response.clone() to the finalizer. In kiro-device-login-finalizer.ts, the current bounded wrapper ends as soon as it obtains that Response; the following response.json() has no deadline. If headers arrive but the body never finishes, then close/unmount hands off a permanently pending stream: the stated 45-second read bound and 16-minute finalizer bound are bypassed, subsequent reconciliation/terminal notice/roster refresh never run, and the active entry is never released.
Please bound both obtaining and consuming inherited responses, then add a regression using a real never-closing ReadableStream handed off by close/unmount. The current parsing test delays only the original Response's overridden json() while its clone already has a complete fixture body, so it does not exercise this transport stall.
The rest of the reviewed auth/verification-link boundaries are coherent; do not weaken exact flow-id ownership or the existing HTTPS/hostname restrictions while fixing this.
|
Exact-head CI on ab10748: test 1-4/4, gates, react-doctor, structure gate, docs site build, docker smoke, npm-global (ubuntu/windows), keyring, desktop shell all pass; remaining jobs skipped by path filter. Local receipt at the same head: GUI 2,577 pass / 0 fail, ratchet + structure 60 pass, structure:check and privacy:scan pass. |
Summary
The dashboard could only add a Kiro account through
kiro-cli, and nothing showed why the router skipped an account. Both already work on the server side: native device login landed in #6001, and per-accountautoSelectable/skipReasonin #6002. This PR exposes them in the GUI.Login. Kiro's Add account and Login buttons now open a chooser:
Dialog. The dialog shows the user code with a copy button and a status line. It also has an "Open verification page" link, rendered only for the exact verification hosts:
device.sso.us-east-1.amazonaws.com, andkiro.devor its subdomains. Any other URL is shown as plain text next to a warning.Cancel and close. Cancel and ESC cancel the flow by
flowId. The server can answer a cancel withdoneonce the commit has begun, so that reply is treated as provisional, and success is shown only after a status reply confirms it.Finishing after close. A module-level finalizer finishes any flow the dialog stops watching (close, unmount, or navigating to another provider). The cancel is sent first, then the finalizer reads status until the flow ends. That status read is also what makes the server reconcile its running config after a successful add. A 404 is treated as "login ended", not "expired", and never shows a success notice.
Account rows. Kiro rows now show "Not auto-selected: quota exhausted / suspended". Nothing extra is shown where an existing badge already says the same thing (reauth, cooldown).
Unchanged:
kiro-cliout.The screenshots were taken from a real proxy on an isolated
OPENCODEX_HOME. A scratch shim sat in front of it and returned fixture replies for the device-login calls and the Kiro account roster, so no live Kiro or AWS call was made.Known limit: if the whole browser tab is closed during the few seconds of a commit, the account is saved on disk, but the running config is not reconciled until the next reload. This existed before (#6001) and is recorded as a server follow-up in
000_plan.md.Plan and audit trail:
devlog/_plan/260926_kiro_lb_parity2/100_gui_device_login_and_skip_reason.md.Verification
cd gui && bun test --isolate tests: 2,577 pass, 0 fail. The newkiro-device-login.test.tsxandkiro-account-skip-reason.test.tsxcover:doneon cancel, thendoneorfailed;donefollowed by 404;kiro.dev.evil.com,evilkiro.dev,x.awsapps.com, S3 hosts, userinfo, port, http, control characters);method.lint:i18n,lint,build,doctor(54 files, no issues): all pass.typecheck,file-size-ratchetplusstructure-ssot(60 pass),structure:check,privacy:scan, and the docs-site build (537 pages).Checklist
gui/, docs, structure only; nosrc/change)guides/providers.md,reference/cli/providers-accounts.md,structure/gui-and-management-api.md)rel="noopener noreferrer"; cancel is scoped by flowId)Summary by CodeRabbit