Skip to content

Tell an agent's owner to disconnect it, not rotate its secret - #851

Open
jeremy wants to merge 2 commits into
mainfrom
agent-logout-says-disconnect
Open

jeremy wants to merge 2 commits into
mainfrom
agent-logout-says-disconnect

Conversation

@jeremy

@jeremy jeremy commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

A follow-up named on My > Agent: refine the UI of the connect flow: basecamp auth logout still tells agent users to "rotate the client secret". It should tell them to disconnect.

Problem

On an agent profile, auth logout forgets the credential locally and then says:

forgot the agent credential; rotate the client secret in Basecamp to end its access

auth revoke gives the same advice in its hint. That advice is wrong in two ways:

  • My > Agent has no rotate control. It was removed in bc3#13597 because reconnecting is the rotation. An agent's owner who goes looking finds Disconnect and nothing else.
  • Rotating doesn't end access. A rotation leaves outstanding self-tokens valid until their TTL. Disconnect revokes the secret and every token immediately.

Change

  • auth logout: Logged out (forgot the agent credential; it stays connected until you disconnect the agent in Basecamp)
  • auth revoke hint: … and disconnect the agent in Basecamp to end its access
  • auth agent --help no longer says every agent is "an identity your Basecamp administrator created". A personal agent is created by its owner when they connect it.
  • The comment on RevokeSkippedAgent says the same.

The JSON envelope is unchanged: reason: "agent", revoked: false.

Tests

  • New TestAuthLogoutHumanCopy/agent covers the summary, that the word "rotate" doesn't appear, that no revocation is sent, and that the credential is forgotten.
  • TestAgentRevokeIsRefusedAndKeepsTheCredential now asserts the disconnect hint.
  • bin/ci is green on linux.

#805 also edits internal/commands/auth.go, in other functions. Whichever lands second may need a trivial rebase.


Summary by cubic

Fixes the advice auth logout and auth revoke give on an agent profile, telling the owner to disconnect the agent in Basecamp instead of rotating the client secret. Basecamp has no rotate control for agents (reconnecting is the rotation), and a rotation leaves the agent's tokens valid until their TTL, while disconnecting revokes the secret and every token immediately. auth agent --help no longer calls every agent an identity created by an administrator — a personal agent is created by its owner when they connect it. The README's Agents section receives the same correction. The JSON envelope is unchanged (reason: "agent", revoked: false).

Written for commit 64b77e8. Summary will update on new commits.

Review in cubic Turn on auto-fix

Copilot AI balanced review requested due to automatic review settings October 6, 2026 17:56
@github-actions github-actions Bot added commands CLI command implementations tests Tests (unit and e2e) auth OAuth authentication labels Oct 6, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 5 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread internal/commands/auth.go
@jeremy
jeremy marked this pull request as ready for review October 7, 2026 03:49
@jeremy
jeremy requested a review from a team as a code owner October 7, 2026 03:49
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T04:17:16.793218Z 64b77e8 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

jeremy added 2 commits October 6, 2026 21:05
auth logout and auth revoke on an agent profile said to rotate the client
secret in Basecamp to end the agent's access. My > Agent has no rotate
control (reconnecting is the rotation), and a rotation leaves the
agent's tokens alive for their hour anyway. Disconnect is what ends its
access, so that is what both now say.

auth agent's help also stops calling every agent one an administrator
created: a personal agent is created by its owner when they connect it.
The Agents section still told the owner to rotate the client secret to end
an agent's access, the advice auth logout and auth revoke just stopped
giving. Disconnecting is what ends it.
Copilot AI balanced review requested due to automatic review settings October 7, 2026 04:11
@jeremy
jeremy force-pushed the agent-logout-says-disconnect branch from 513a778 to 64b77e8 Compare October 7, 2026 04:11
@github-actions github-actions Bot added the docs label Oct 7, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@jeremy

jeremy commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

@codex review

@jeremy

jeremy commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

@cubic-dev-ai review

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review

@jeremy I have started the AI code review. It will take a few minutes to complete.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

Reviewed commit: 64b77e8cf6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 6 files

Turn on auto-fix | Re-trigger cubic

@jeremy

jeremy commented Oct 7, 2026

Copy link
Copy Markdown
Member Author

Rebased onto main (943dbb5) with no conflicts.

Review threads: 1 resolved (1 fixed, 0 declined).

CI is green on 64b77e8. Codex reported on 64b77e8 with no major issues, and cubic found no issues. Copilot can't review because the requester's quota is exhausted.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auth OAuth authentication commands CLI command implementations docs tests Tests (unit and e2e)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants