fix(qoder): address review findings
Correctness: - testUtils: drop checkExpiry so the userinfo URL probe actually runs (revoked tokens used to look "active" until local 30-day expiry passed) - auth.parseExpiry: handle numeric expiresAt, swap parseInt before Date.parse so "2026" doesn't get interpreted as year-2026, treat expires_in:0 as already-expired instead of fabricating a 30-day default - providers.mapTokens: synthesize email from userId when fetchUserInfo fails so OAuth dedup works (re-logins no longer accumulate "Account N" rows) SSE wrapper: - wrapQoderSSE: add !doneEmitted guard on success branch (chunks could leak past [DONE] when an error envelope shared a TCP packet with a valid one) - flush(): finalize TextDecoder + drain trailing buffer so the chunk carrying finish_reason is delivered when upstream closes without a final \n - sanitize literal \n inside inner OpenAI body so SSE framing stays intact Robustness: - executor: wrap buildCosyHeaders in try/catch so a missing accessToken returns 401 (re-auth) instead of bubbling as 500 - executor: short-circuit on missing accessToken before signing - executor: plumb proxyOptions/signal through buildQoderRequestBody so proxy-only networks can fetch the model_config catalog - qoderModels: dedupe concurrent first-time misses with an in-flight Promise map (parallel chat windows now do 1 upstream fetch instead of N) - qoderModels: check signal.aborted before addEventListener so a pre-aborted parent signal cancels the inner fetch immediately - auth: AbortController + 15s timeout on pollDeviceToken / fetchUserInfo to prevent hung sockets when openapi.qoder.sh stalls mid-response UX: - OAuthModal: derive polling deadline from device-code expires_in (qoder publishes 300s; the previous fixed 120s caused timeouts when users took more than 2 minutes on the consent page) Cleanup: - delete src/lib/oauth/services/qoder.js — referenced removed config fields (clientId/clientSecret/tokenUrl/authorizeUrl) and was re-exported from services/index.js, so any future caller would TypeError on first use
This commit is contained in:
@@ -63,6 +63,26 @@ export function initiateDeviceFlow() {
|
||||
};
|
||||
}
|
||||
|
||||
// Timeout for OAuth helper calls. The OAuth modal polls every 2s for up to
|
||||
// 5 minutes; an individual request that stalls beyond this is treated as a
|
||||
// failed poll attempt and the next poll iteration retries.
|
||||
const FETCH_TIMEOUT_MS = 15_000;
|
||||
|
||||
/**
|
||||
* Wrap fetch with an AbortController-based timeout. Without this, a stalled
|
||||
* upstream socket hangs on Node's default keepalive timeout (minutes) and
|
||||
* abandoned polls accumulate hung sockets.
|
||||
*/
|
||||
async function fetchWithTimeout(url, init = {}) {
|
||||
const controller = new AbortController();
|
||||
const timer = setTimeout(() => controller.abort("timeout"), FETCH_TIMEOUT_MS);
|
||||
try {
|
||||
return await fetch(url, { ...init, signal: controller.signal });
|
||||
} finally {
|
||||
clearTimeout(timer);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Single poll attempt. Returns one of:
|
||||
* { status: "pending" } — keep polling
|
||||
@@ -77,7 +97,7 @@ export async function pollDeviceToken({ nonce, codeVerifier }) {
|
||||
}
|
||||
const url = `${QODER_DEVICE_TOKEN_URL}?nonce=${encodeURIComponent(nonce)}&verifier=${encodeURIComponent(codeVerifier)}&challenge_method=S256`;
|
||||
|
||||
const response = await fetch(url, {
|
||||
const response = await fetchWithTimeout(url, {
|
||||
method: "GET",
|
||||
headers: {
|
||||
Accept: "application/json",
|
||||
@@ -132,7 +152,7 @@ export async function pollDeviceToken({ nonce, codeVerifier }) {
|
||||
*/
|
||||
export async function fetchUserInfo(accessToken) {
|
||||
try {
|
||||
const response = await fetch(QODER_USERINFO_URL, {
|
||||
const response = await fetchWithTimeout(QODER_USERINFO_URL, {
|
||||
method: "GET",
|
||||
headers: {
|
||||
Authorization: `Bearer ${accessToken}`,
|
||||
@@ -154,18 +174,36 @@ export async function fetchUserInfo(accessToken) {
|
||||
|
||||
/**
|
||||
* Convert the upstream's expiry hint into a Unix-millisecond timestamp.
|
||||
* Accepts RFC3339 strings, ms-epoch integer strings, or seconds-from-now
|
||||
* (`expires_in`). Falls back to "now + 30 days" when both are missing.
|
||||
* Accepts:
|
||||
* - numeric (ms-epoch): returned as-is
|
||||
* - numeric string of ms-epoch: e.g. "1781594470000"
|
||||
* - RFC3339 string: e.g. "2026-06-16T07:15:04Z"
|
||||
* - seconds-from-now via expiresInSeconds (>= 0)
|
||||
* Falls back to "now + 30 days" when both are missing.
|
||||
*
|
||||
* Order matters: try numeric (string or number) before Date.parse, since
|
||||
* Date.parse accepts short numeric strings like "2026" as years and would
|
||||
* otherwise return a misleading year-2026 timestamp instead of falling
|
||||
* through to the integer branch.
|
||||
*/
|
||||
function parseExpiry(expiresAt, expiresInSeconds) {
|
||||
if (typeof expiresAt === "number" && Number.isFinite(expiresAt) && expiresAt > 0) {
|
||||
return expiresAt;
|
||||
}
|
||||
const trimmed = typeof expiresAt === "string" ? expiresAt.trim() : "";
|
||||
if (trimmed) {
|
||||
// Pure numeric string → ms-epoch (don't let Date.parse swallow short
|
||||
// numerics as years).
|
||||
if (/^\d+$/.test(trimmed)) {
|
||||
const ms = Number.parseInt(trimmed, 10);
|
||||
if (Number.isFinite(ms) && ms > 0) return ms;
|
||||
}
|
||||
const parsed = Date.parse(trimmed);
|
||||
if (!Number.isNaN(parsed)) return parsed;
|
||||
const ms = Number.parseInt(trimmed, 10);
|
||||
if (!Number.isNaN(ms) && ms > 0) return ms;
|
||||
}
|
||||
if (typeof expiresInSeconds === "number" && expiresInSeconds > 0) {
|
||||
// expiresInSeconds === 0 means "already expired"; honor that by returning
|
||||
// the current time rather than fabricating a 30-day default.
|
||||
if (typeof expiresInSeconds === "number" && Number.isFinite(expiresInSeconds) && expiresInSeconds >= 0) {
|
||||
return Date.now() + expiresInSeconds * 1000;
|
||||
}
|
||||
return Date.now() + 30 * 24 * 60 * 60 * 1000;
|
||||
|
||||
Reference in New Issue
Block a user