fix(providers): complete OAuth logins that finish in the browser

OpenCode's authorize response reports how the client must finish: `code`
expects a pasted code, while `auto` requires the client to call
oauth/callback immediately and hold it open — upstream blocks in there
polling for the device code or waiting on its loopback redirect, and only
that call persists the credential. Every auth plugin OpenCode ships uses
`auto`; none use `code`.

The page implemented only `code`. It opened the browser, showed a paste
field no provider can fill, and never called back, so a successful sign-in
stored nothing and the app sat unchanged. Authorization now drives the UI:
`auto` chains straight into the callback behind a waiting state with a
cancel, and the paste field appears only when a provider actually asks
for a code.

Two smaller failures shared that surface. Prompts were never collected,
which put GitHub Copilot Enterprise out of reach entirely, so a method
that declares them now asks first and passes the answers to authorize.
Device codes are also recovered from the instructions text, where they
actually live — the old code read fields the API does not return, so the
copy button never appeared.

The callback is exempt from the ordinary proxy deadline and gets a
15-minute budget, bounded by the shortest upstream expiry we know of.
A human sign-in with 2FA does not fit in four minutes, and expiring it
turned a completed login into a 504.
This commit is contained in:
Bohdan Triapitsyn
2026-08-04 19:14:58 +03:00
parent 8c37061886
commit 687681c83b
19 changed files with 1239 additions and 290 deletions
@@ -1392,6 +1392,17 @@ export const settingsDict = {
'settings.providers.page.auth.apiKeyPlaceholder': 'sk-...',
'settings.providers.page.auth.oauthMethodFallback': 'OAuth 方法 {index}',
'settings.providers.page.auth.pasteAuthorizationCodePlaceholder': '認証コードを貼り付け',
'settings.providers.page.auth.oauth.starting': '認証を開始しています…',
'settings.providers.page.auth.oauth.waiting': '認証を待っています…',
'settings.providers.page.auth.oauth.waitingHint': 'ブラウザーでサインインを完了してください。このページは開いたままにしてください。接続は自動的に完了します。',
'settings.providers.page.auth.oauth.codeHint': 'ブラウザーから認証コードをコピーして、ここに貼り付けてください。',
'settings.providers.page.auth.oauth.deviceCodeLabel': 'デバイスコード',
'settings.providers.page.auth.oauth.linkLabel': '認証リンク',
'settings.providers.page.auth.oauth.promptRequired': '続行するには「{field}」を入力してください',
'settings.providers.page.auth.oauth.error.sessionExpired': '認証リクエストの有効期限が切れました。もう一度接続してやり直してください。',
'settings.providers.page.auth.oauth.error.codeRequired': 'このプロバイダーにはブラウザーの認証コードが必要です。',
'settings.providers.page.auth.oauth.error.declined': '認証が拒否されたか、完了しませんでした。',
'settings.providers.page.auth.oauth.error.invalidInput': '入力された内容は拒否されました。',
'settings.providers.page.auth.connected': '接続済み',
'settings.providers.page.auth.incomplete': '認証情報が不足しています',
'settings.providers.page.auth.incompleteHint': '· チャットでこのプロバイダーを使う前に API キーまたは {env:VAR} を追加してください',
@@ -1424,6 +1435,9 @@ export const settingsDict = {
'settings.providers.page.actions.open': '開く',
'settings.providers.page.actions.copy': 'コピー',
'settings.providers.page.actions.complete': '完了',
'settings.providers.page.actions.continue': '続行',
'settings.providers.page.actions.cancel': 'キャンセル',
'settings.providers.page.actions.tryAgain': '再試行',
'settings.providers.page.actions.hide': '非表示',
'settings.providers.page.actions.reconnect': '再接続',
'settings.providers.page.actions.edit': '編集',
@@ -1439,7 +1453,6 @@ export const settingsDict = {
'settings.providers.page.toast.apiKeySaved': 'API キーを保存しました',
'settings.providers.page.toast.oauthStartFailed': 'OAuth フローの開始に失敗しました',
'settings.providers.page.toast.oauthDetailsMissing': 'OAuth の詳細が返されませんでした',
'settings.providers.page.toast.completeOAuthInBrowser': 'ブラウザで OAuth フローを完了してください',
'settings.providers.page.toast.oauthCompleteFailed': 'OAuth フローの完了に失敗しました',
'settings.providers.page.toast.oauthCompleted': 'OAuth 接続が完了しました',
'settings.providers.page.toast.oauthLinkCopied': 'OAuth リンクをコピーしました',