Repository navigation
Conversation
There was a problem hiding this comment.
All reported issues were addressed across 5 files
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
auth logout and auth revoke on an agent profile said to rotate the client secret in Basecamp to end the agent's access. My > Agent has no rotate control (reconnecting is the rotation), and a rotation leaves the agent's tokens alive for their hour anyway. Disconnect is what ends its access, so that is what both now say. auth agent's help also stops calling every agent one an administrator created: a personal agent is created by its owner when they connect it.
The Agents section still told the owner to rotate the client secret to end an agent's access, the advice auth logout and auth revoke just stopped giving. Disconnecting is what ends it.
513a778 to
64b77e8
Compare
|
@codex review |
|
@cubic-dev-ai review |
@jeremy I have started the AI code review. It will take a few minutes to complete. |
|
Codex Review: Didn't find any major issues. Keep it up! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Rebased onto main (943dbb5) with no conflicts. Review threads: 1 resolved (1 fixed, 0 declined).
CI is green on 64b77e8. Codex reported on 64b77e8 with no major issues, and cubic found no issues. Copilot can't review because the requester's quota is exhausted. |
A follow-up named on My > Agent: refine the UI of the connect flow:
basecamp auth logoutstill tells agent users to "rotate the client secret". It should tell them to disconnect.Problem
On an agent profile,
auth logoutforgets the credential locally and then says:auth revokegives the same advice in its hint. That advice is wrong in two ways:Change
auth logout:Logged out (forgot the agent credential; it stays connected until you disconnect the agent in Basecamp)auth revokehint:… and disconnect the agent in Basecamp to end its accessauth agent --helpno longer says every agent is "an identity your Basecamp administrator created". A personal agent is created by its owner when they connect it.RevokeSkippedAgentsays the same.The JSON envelope is unchanged:
reason: "agent",revoked: false.Tests
TestAuthLogoutHumanCopy/agentcovers the summary, that the word "rotate" doesn't appear, that no revocation is sent, and that the credential is forgotten.TestAgentRevokeIsRefusedAndKeepsTheCredentialnow asserts the disconnect hint.bin/ciis green on linux.#805 also edits
internal/commands/auth.go, in other functions. Whichever lands second may need a trivial rebase.Summary by cubic
Fixes the advice
auth logoutandauth revokegive on an agent profile, telling the owner to disconnect the agent in Basecamp instead of rotating the client secret. Basecamp has no rotate control for agents (reconnecting is the rotation), and a rotation leaves the agent's tokens valid until their TTL, while disconnecting revokes the secret and every token immediately.auth agent --helpno longer calls every agent an identity created by an administrator — a personal agent is created by its owner when they connect it. The README's Agents section receives the same correction. The JSON envelope is unchanged (reason: "agent",revoked: false).Written for commit 64b77e8. Summary will update on new commits.