fix: prevent non-SSE stream pipe crash and cross-IdP account overwrites (#2244)

- streamingHandler: when upstream returns non-SSE/JSON (e.g. Cloudflare
  5xx HTML), read body, sanitize <title>, notify streamController and
  return a clean JSON error instead of crashing the pipe.
- connectionsRepo: dedup OAuth connections on (email + username) so
  cross-IdP accounts sharing an email no longer overwrite each other;
  workspace providers keep workspace-id matching.
- kimchi: bump User-Agent to 0.1.50, add svg asset + browser-login
  service, and 21 unit tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
KunN-21
2026-07-03 11:07:08 +07:00
committed by decolua
parent abc0add031
commit cb0135b695
7 changed files with 410 additions and 8 deletions

View File

@@ -98,13 +98,26 @@ export async function createProviderConnection(data) {
let existing = null;
if (data.authType === "oauth" && data.email) {
const incomingUsername = data.providerSpecificData?.username;
const incomingWs = data.providerSpecificData?.chatgptAccountId;
existing = all.find(c => {
if (c.authType !== "oauth" || c.email !== data.email) return false;
// If both sides have a workspace ID, they must match for dedup
// Workspace providers (Codex) use workspace ID when both sides have it
const existingWs = c.providerSpecificData?.chatgptAccountId;
if (incomingWs && existingWs) return incomingWs === existingWs;
return true; // fallback: email-only match for non-workspace providers
if (incomingWs && !existingWs) return false;
if (!incomingWs && existingWs) return false;
// Non-workspace providers: match on (email + username) so cross-IdP
// accounts don't overwrite each other. Require username on both sides
// — if only one side has it, treat as a distinct identity rather than
// collapsing onto the bare-email fallback (which would re-introduce
// the cross-IdP overwrite).
const existingUsername = c.providerSpecificData?.username;
if (incomingUsername && existingUsername) {
return incomingUsername === existingUsername;
}
if (incomingUsername || existingUsername) return false;
return true;
});
} else if (data.authType === "apikey" && data.name) {
existing = all.find(c => c.authType === "apikey" && c.name === data.name);