fix(providers): complete OAuth logins that finish in the browser

OpenCode's authorize response reports how the client must finish: `code`
expects a pasted code, while `auto` requires the client to call
oauth/callback immediately and hold it open — upstream blocks in there
polling for the device code or waiting on its loopback redirect, and only
that call persists the credential. Every auth plugin OpenCode ships uses
`auto`; none use `code`.

The page implemented only `code`. It opened the browser, showed a paste
field no provider can fill, and never called back, so a successful sign-in
stored nothing and the app sat unchanged. Authorization now drives the UI:
`auto` chains straight into the callback behind a waiting state with a
cancel, and the paste field appears only when a provider actually asks
for a code.

Two smaller failures shared that surface. Prompts were never collected,
which put GitHub Copilot Enterprise out of reach entirely, so a method
that declares them now asks first and passes the answers to authorize.
Device codes are also recovered from the instructions text, where they
actually live — the old code read fields the API does not return, so the
copy button never appeared.

The callback is exempt from the ordinary proxy deadline and gets a
15-minute budget, bounded by the shortest upstream expiry we know of.
A human sign-in with 2FA does not fit in four minutes, and expiring it
turned a completed login into a 504.
This commit is contained in:
Bohdan Triapitsyn
2026-08-04 19:14:58 +03:00
parent 8c37061886
commit 687681c83b
19 changed files with 1239 additions and 290 deletions
@@ -1359,6 +1359,17 @@ export const settingsDict = {
"settings.providers.page.auth.apiKeyPlaceholder": "sk-...",
"settings.providers.page.auth.oauthMethodFallback": "Método OAuth {index}",
"settings.providers.page.auth.pasteAuthorizationCodePlaceholder": "Pegar código de autorización",
"settings.providers.page.auth.oauth.starting": "Iniciando la autorización…",
"settings.providers.page.auth.oauth.waiting": "Esperando la autorización…",
"settings.providers.page.auth.oauth.waitingHint": "Termina de iniciar sesión en el navegador. Mantén esta página abierta: la conexión se completará sola.",
"settings.providers.page.auth.oauth.codeHint": "Copia el código de autorización del navegador y pégalo aquí.",
"settings.providers.page.auth.oauth.deviceCodeLabel": "Código del dispositivo",
"settings.providers.page.auth.oauth.linkLabel": "Enlace de autorización",
"settings.providers.page.auth.oauth.promptRequired": "Completa «{field}» para continuar",
"settings.providers.page.auth.oauth.error.sessionExpired": "La solicitud de autorización caducó. Vuelve a conectar para reiniciarla.",
"settings.providers.page.auth.oauth.error.codeRequired": "Este proveedor necesita el código de autorización de tu navegador.",
"settings.providers.page.auth.oauth.error.declined": "La autorización se rechazó o no se completó.",
"settings.providers.page.auth.oauth.error.invalidInput": "Se rechazaron los datos introducidos.",
"settings.providers.page.auth.connected": "Conectado",
"settings.providers.page.auth.incomplete": "Faltan credenciales",
"settings.providers.page.auth.incompleteHint": "· Añade una clave API o {env:VAR} antes de usar este proveedor en el chat",
@@ -1391,6 +1402,9 @@ export const settingsDict = {
"settings.providers.page.actions.open": "Abrir",
"settings.providers.page.actions.copy": "Copiar",
"settings.providers.page.actions.complete": "Completar",
"settings.providers.page.actions.continue": "Continuar",
"settings.providers.page.actions.cancel": "Cancelar",
"settings.providers.page.actions.tryAgain": "Reintentar",
"settings.providers.page.actions.hide": "Ocultar",
"settings.providers.page.actions.reconnect": "Reconectar",
"settings.providers.page.actions.edit": "Editar",
@@ -1406,7 +1420,6 @@ export const settingsDict = {
"settings.providers.page.toast.apiKeySaved": "Clave API guardada",
"settings.providers.page.toast.oauthStartFailed": "No se pudo iniciar el flujo OAuth",
"settings.providers.page.toast.oauthDetailsMissing": "No se devolvieron detalles de OAuth",
"settings.providers.page.toast.completeOAuthInBrowser": "Completa el flujo OAuth en tu navegador",
"settings.providers.page.toast.oauthCompleteFailed": "No se pudo completar el flujo OAuth",
"settings.providers.page.toast.oauthCompleted": "Conexión OAuth completada",
"settings.providers.page.toast.oauthLinkCopied": "Enlace de OAuth copiado",