Skip to content

fix(accounts): scope organization OAuth outbound requests - #8533

Merged
waleedlatif1 merged 2 commits into
stagingfrom
codex/lucid-oauth-outbound-scope
Oct 1, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
codex/lucid-oauth-outbound-scope

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Establish outbound ownership from the authorized organization for connected-account operations, and from the verified owned account for reconnect. Managed MCP OAuth discovery and dynamic registration can then use the configured organization route instead of failing with missing scope.
  • Preserve membership checks, provider ownership, blocked routes, error mapping, and the existing audit lifecycle. Reuse the standard outbound context helper without adding credentials or configuration fallbacks.

Type of Change

  • Bug fix

Testing

  • Real Postgres, Redis, SDK OAuth discovery/registration, and loopback HTTP regressions cover both Connect and Reconnect. Each failed before its fix; independently removing each scope guard reproduced its three routing failures while authorization denials remained intact.
  • 42 integration tests across organization OAuth, shared MCP clients, and Search setup; 569 surrounding account, OAuth, and network regressions passed, including eight real TLS CONNECT gateway tests.
  • App type-check, lint, 54 audits, artifact generators, block registry, and docs manifest checks passed. Integration JSON reports record each test and duration. OAuth provider responses are local fixtures, not a live provider-account authorization.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 1, 2026 6:54pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Wraps OAuth flows with organization-scoped network context.

The PR appears safe to merge; no outstanding or new actionable findings were identified.

Summary

The PR scopes organization account connections and personal account reconnections to the authorized account owner before starting OAuth. The expanded integration test checks reconnect routing, blocked routes, and authorization denials. The previously raised gateway-test suggestion was withdrawn.

Reviews (2) · Last reviewed commit: "fix(accounts): preserve outbound ownersh..."

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit b6a598e into staging Oct 1, 2026
23 of 24 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/lucid-oauth-outbound-scope branch October 1, 2026 18:58

This branch was previously deployed

1 inactive deployment
Preview — af4c7bf6 Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant