Carry main fixes into redesign main (#746) - #662
Merged
thomasluizon merged 5 commits intoSep 29, 2026
Merged
Conversation
Bumps AWSSDK.SimpleEmailV2 from 4.0.105 to 4.0.105.1 Bumps coverlet.collector from 10.0.1 to 10.1.0 Bumps FirebaseAdmin from 3.6.0 to 3.7.0 --- updated-dependencies: - dependency-name: AWSSDK.SimpleEmailV2 dependency-version: 4.0.105.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: coverlet.collector dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch - dependency-name: coverlet.collector dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch - dependency-name: coverlet.collector dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch - dependency-name: coverlet.collector dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch - dependency-name: FirebaseAdmin dependency-version: 3.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (cherry picked from commit eb18808)
Bumps the github-actions group with 5 updates: | Package | From | To | | --- | --- | --- | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.1` | `4.38.2` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.1` | `4.38.2` | | [pullfrog/pullfrog](https://github.com/pullfrog/pullfrog) | `0.1.83` | `0.1.84` | | [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `5.1.1` | `6.3.0` | | [hashicorp/setup-terraform](https://github.com/hashicorp/setup-terraform) | `3.1.2` | `4.0.1` | Updates `github/codeql-action/init` from 4.38.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@1c5b675...2892aa5) Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@1c5b675...2892aa5) Updates `pullfrog/pullfrog` from 0.1.83 to 0.1.84 - [Release notes](https://github.com/pullfrog/pullfrog/releases) - [Commits](pullfrog/pullfrog@e9f8115...99c5e78) Updates `aws-actions/configure-aws-credentials` from 5.1.1 to 6.3.0 - [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases) - [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md) - [Commits](aws-actions/configure-aws-credentials@61815dc...e125382) Updates `hashicorp/setup-terraform` from 3.1.2 to 4.0.1 - [Release notes](https://github.com/hashicorp/setup-terraform/releases) - [Changelog](https://github.com/hashicorp/setup-terraform/blob/main/CHANGELOG.md) - [Commits](hashicorp/setup-terraform@v3.1.2...dfe3c3f) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: pullfrog/pullfrog dependency-version: 0.1.84 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: aws-actions/configure-aws-credentials dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: hashicorp/setup-terraform dependency-version: 4.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (cherry picked from commit a78ba3a)
* Fix MCP Google authorization redirect * Catalog MCP Google redirect actions * Style Google redirect link as button * Preserve calendar tokens during MCP sign-in * Fix MCP Google redirect review findings (cherry picked from commit 1d80602)
(cherry picked from commit 1f8d762)
There was a problem hiding this comment.
Caution
Anonymous requests to the authorization page now allocate unbounded server-side state without a rate limit, exposing the API to memory exhaustion. Please bound allocation before merging.
Reviewed changes across all 26 files and four commits in this carry into redesign/main:
- Dependency and workflow pins: Updates NuGet packages and pinned GitHub Actions.
- MCP Google sign-in: Adds a server-side Google redirect, PKCE state store, identity-only callback, Terraform callback settings, and OAuth tests while preserving the legacy route.
- Audio transcription: Passes the signed-in user ID through the command and hints transcription with the saved account language, with controller and handler coverage.
GPT Sol | 𝕏
A valid anonymous GET /oauth/authorize used to allocate a pending Google
request in OAuthAuthorizationStore even when the visitor never clicked
Google. The route carried no rate limit and the store carried no capacity
bound, so repeated page views could retain arbitrarily many entries until
the five-minute sweep and exhaust the API's memory.
The authorize page now hands its already-validated MCP parameters straight
to /oauth/google/start, which revalidates the client, the redirect URI and
the PKCE method server side before it allocates anything. A page view
allocates no server state.
The store gains a hard cap on pending Google requests, evicts expired
entries on insert, and refuses a new allocation once the cap is reached.
GoogleStart turns that refusal into the localized "unavailable" message on
the authorize page, where email sign-in stays available.
Both browser routes now carry the DistributedRateLimit("auth") policy.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
(cherry picked from commit 5dc0a01)
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes since the prior Pullfrog review: the Google sign-in flow now bounds anonymous pending state and preserves the existing MCP authorization behavior.
- Moved state allocation: The authorize page renders without creating pending state; the Google start route revalidates parameters and creates the single-use request.
- Bounded pending requests: Auth rate limits cover both browser routes, and the store caps live Google requests at 1,000 with expired-entry eviction.
- Expanded OAuth coverage: Controller and store tests cover the new start flow, no-allocation page view, rate-limit attributes, capacity, and fallback.
GPT Sol | 𝕏
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Refs thomasluizon/orbit-tickets#746
Change
Carry the four named main commits into
redesign/mainin order withgit cherry-pick -x. No commits were skipped.eb18808b(Bump the nuget-minor-patch group with 3 updates #658): updated AWSSDK.SimpleEmailV2, FirebaseAdmin, and coverlet.collector versions in the infrastructure and test project files. Applied without a conflict.a78ba3aa(Chore(deps): bump the github-actions group with 5 updates #657): updated pinned CodeQL, Pullfrog, AWS credentials, and Terraform setup actions in four workflow files. Applied without a conflict.1d806028(Fix Google sign-in on MCP authorization page #660): carried the server-side Google authorization redirect and callback, pending request store, identity-only token handling, Terraform redirect settings, agent catalog entries, controller and store tests, and generated OpenAPI document. The conflict intests/Orbit.Infrastructure.Tests/Controllers/OAuthControllerTests.cscame from redesign commits23396af4(Redesign the transactional emails, AI push copy and error messages (R20) #532), which changed error assertions, anda2f54698(Clean timeless text on redesign branch for #715 #577), which changed test data. Kept those redesign assertions and data, retained tests for the still available deprecatedPOST /oauth/googleroute, and added the new callback tests. The API build regeneratedsrc/Orbit.Api/openapi.jsonafter the final cherry-pick.1f8d7629(Pass saved account language to audio transcription #661): carried the signed-in user ID into transcription, mapped the saved account language to the transcription hint, and carried the handler, validator, and controller tests. Applied without a conflict. The HTTP request and response shape remains the same.No EF migration changed.
dotnet ef migrations has-pending-model-changes --project src/Orbit.Infrastructure --startup-project src/Orbit.Apireported no pending model changes, so there is no migration ordering question.Assumptions
POST /oauth/googleroute remains covered by its redesign tests because the carried controller still exposes it; removing those tests with the original main patch was rejected.CreatePendingGoogleStatehelper is deleted rather than kept, because it modelled the page-view allocation#962removed and nothing calls it.Manual steps
https://api.useorbit.org/oauth/google/callbackandhttps://api-staging.useorbit.org/oauth/google/callback. The original main PR recorded these as registered. A completed Google MCP sign-in on each host confirms the callback works.infra/Terraform configuration to theorbit-production-apiandorbit-staging-apienvironment groups if the main release has not already applied it. ConfirmGoogle__AllowedRedirectUris__1ishttps://api.useorbit.org/oauth/google/callbackin production andGoogle__AllowedRedirectUris__3ishttps://api-staging.useorbit.org/oauth/google/callbackin staging. Release the carrying API build throughrelease.ymlfor each target environment.Test evidence
LANGandLC_ALLunset,dotnet build Orbit.slnx --verbosity quietexited 0 with zero errors, anddotnet test --verbosity quietpassed 8,170 tests.LANGunset andLC_ALL=en_US.UTF-8, the same build exited 0 with zero errors, and the same test command passed 8,170 tests.node tools/arch-map.mjs,terraform fmt -check infra/configuration.tf, the dash and timeless checks, andgit diff --checkpassed. The OpenAPI generator left the committed document unchanged after the final build.56953fc3:git cherry-pick -x 5dc0a016(themainfix for the review thread,api#663, ticket#962). One conflicted file,tests/Orbit.Infrastructure.Tests/Controllers/OAuthControllerTests.cs: the using block keeps both sides; the second hunk keeps this branch'sGoogleAuth_WithNonce_BindsNonceRetrievableAtTokenExchangeand addsmain'sAuthorize_PageViewAllocatesNoPendingGoogleRequest; the helperCreatePendingGoogleStateis removed becausemainreplaced it withCreatePendingGoogleRequestandStartGoogleand it had no callers left.dotnet build Orbit.slnxexit 0 withLANGunset and withLC_ALL=en_US.UTF-8.dotnet test Orbit.slnxexit 0 in both: 8,183 passed, 0 failed. Focused OAuth controller and store run: 101 passed.node tools/check-suppression-allowlist.mjsexit 0 (98 sites).openapi.jsonregenerated by the build and unchanged.External interface evidence
AudioTranscriptionOptions.Language, including its conditional multipartlanguagefield.