fix: prevent non-SSE stream pipe crash and cross-IdP account overwrites (#2244)
- streamingHandler: when upstream returns non-SSE/JSON (e.g. Cloudflare 5xx HTML), read body, sanitize <title>, notify streamController and return a clean JSON error instead of crashing the pipe. - connectionsRepo: dedup OAuth connections on (email + username) so cross-IdP accounts sharing an email no longer overwrite each other; workspace providers keep workspace-id matching. - kimchi: bump User-Agent to 0.1.50, add svg asset + browser-login service, and 21 unit tests. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -98,13 +98,26 @@ export async function createProviderConnection(data) {
|
||||
|
||||
let existing = null;
|
||||
if (data.authType === "oauth" && data.email) {
|
||||
const incomingUsername = data.providerSpecificData?.username;
|
||||
const incomingWs = data.providerSpecificData?.chatgptAccountId;
|
||||
existing = all.find(c => {
|
||||
if (c.authType !== "oauth" || c.email !== data.email) return false;
|
||||
// If both sides have a workspace ID, they must match for dedup
|
||||
// Workspace providers (Codex) use workspace ID when both sides have it
|
||||
const existingWs = c.providerSpecificData?.chatgptAccountId;
|
||||
if (incomingWs && existingWs) return incomingWs === existingWs;
|
||||
return true; // fallback: email-only match for non-workspace providers
|
||||
if (incomingWs && !existingWs) return false;
|
||||
if (!incomingWs && existingWs) return false;
|
||||
// Non-workspace providers: match on (email + username) so cross-IdP
|
||||
// accounts don't overwrite each other. Require username on both sides
|
||||
// — if only one side has it, treat as a distinct identity rather than
|
||||
// collapsing onto the bare-email fallback (which would re-introduce
|
||||
// the cross-IdP overwrite).
|
||||
const existingUsername = c.providerSpecificData?.username;
|
||||
if (incomingUsername && existingUsername) {
|
||||
return incomingUsername === existingUsername;
|
||||
}
|
||||
if (incomingUsername || existingUsername) return false;
|
||||
return true;
|
||||
});
|
||||
} else if (data.authType === "apikey" && data.name) {
|
||||
existing = all.find(c => c.authType === "apikey" && c.name === data.name);
|
||||
|
||||
Reference in New Issue
Block a user