Skip to content

Carry main fixes into redesign main (#746) - #662

Merged
thomasluizon merged 5 commits into
redesign/mainfrom
fix/ticket-746-carry-mcp-google-transcribe
Sep 29, 2026
Merged

thomasluizon merged 5 commits into
redesign/mainfrom
fix/ticket-746-carry-mcp-google-transcribe

Conversation

@thomasluizon

@thomasluizon thomasluizon commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Refs thomasluizon/orbit-tickets#746

Change

Carry the four named main commits into redesign/main in order with git cherry-pick -x. No commits were skipped.

No EF migration changed. dotnet ef migrations has-pending-model-changes --project src/Orbit.Infrastructure --startup-project src/Orbit.Api reported no pending model changes, so there is no migration ordering question.

Assumptions

  • The deprecated POST /oauth/google route remains covered by its redesign tests because the carried controller still exposes it; removing those tests with the original main patch was rejected.
  • The dead CreatePendingGoogleState helper is deleted rather than kept, because it modelled the page-view allocation #962 removed and nothing calls it.

Manual steps

  • In Google Cloud Console, open the Orbit OAuth web client under APIs and Services > Credentials and confirm its authorized redirect URIs include https://api.useorbit.org/oauth/google/callback and https://api-staging.useorbit.org/oauth/google/callback. The original main PR recorded these as registered. A completed Google MCP sign-in on each host confirms the callback works.
  • Apply the infra/ Terraform configuration to the orbit-production-api and orbit-staging-api environment groups if the main release has not already applied it. Confirm Google__AllowedRedirectUris__1 is https://api.useorbit.org/oauth/google/callback in production and Google__AllowedRedirectUris__3 is https://api-staging.useorbit.org/oauth/google/callback in staging. Release the carrying API build through release.yml for each target environment.
  • None.

Test evidence

  • Focused OAuth controller and store tests: 88 passed. Focused transcription application tests: 11 passed. Focused chat controller tests: 12 passed.
  • With LANG and LC_ALL unset, dotnet build Orbit.slnx --verbosity quiet exited 0 with zero errors, and dotnet test --verbosity quiet passed 8,170 tests.
  • With LANG unset and LC_ALL=en_US.UTF-8, the same build exited 0 with zero errors, and the same test command passed 8,170 tests.
  • node tools/arch-map.mjs, terraform fmt -check infra/configuration.tf, the dash and timeless checks, and git diff --check passed. The OpenAPI generator left the committed document unchanged after the final build.
  • The original Google authorization PR records the unchanged authorize page test passing with One Tap still present, the strengthened test failing before implementation, and passing after. The original transcription PR records two unchanged handler tests passing before the fix, then the strengthened tests failing to compile because the user input and language argument were absent, and passing after implementation. Those before-fix observations were made in the original main PRs, not rerun in this carry.
  • Review batch 56953fc3: git cherry-pick -x 5dc0a016 (the main fix for the review thread, api#663, ticket #962). One conflicted file, tests/Orbit.Infrastructure.Tests/Controllers/OAuthControllerTests.cs: the using block keeps both sides; the second hunk keeps this branch's GoogleAuth_WithNonce_BindsNonceRetrievableAtTokenExchange and adds main's Authorize_PageViewAllocatesNoPendingGoogleRequest; the helper CreatePendingGoogleState is removed because main replaced it with CreatePendingGoogleRequest and StartGoogle and it had no callers left.
  • dotnet build Orbit.slnx exit 0 with LANG unset and with LC_ALL=en_US.UTF-8. dotnet test Orbit.slnx exit 0 in both: 8,183 passed, 0 failed. Focused OAuth controller and store run: 101 passed.
  • node tools/check-suppression-allowlist.mjs exit 0 (98 sites). openapi.json regenerated by the build and unchanged.

External interface evidence

  • The original Google authorization PR records a live response from Google's OpenID configuration endpoint confirming the authorization endpoint, code response, supported scopes, and S256 challenge method. It also cites the OAuth code response schema for callback query fields.
  • The original transcription PR links the matching OpenAI SDK 2.14.0 generated and custom source for AudioTranscriptionOptions.Language, including its conditional multipart language field.

dependabot Bot and others added 4 commits September 29, 2026 14:01
Bumps AWSSDK.SimpleEmailV2 from 4.0.105 to 4.0.105.1
Bumps coverlet.collector from 10.0.1 to 10.1.0
Bumps FirebaseAdmin from 3.6.0 to 3.7.0

---
updated-dependencies:
- dependency-name: AWSSDK.SimpleEmailV2
  dependency-version: 4.0.105.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: coverlet.collector
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: coverlet.collector
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: coverlet.collector
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: coverlet.collector
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: FirebaseAdmin
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit eb18808)
Bumps the github-actions group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.1` | `4.38.2` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.1` | `4.38.2` |
| [pullfrog/pullfrog](https://github.com/pullfrog/pullfrog) | `0.1.83` | `0.1.84` |
| [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `5.1.1` | `6.3.0` |
| [hashicorp/setup-terraform](https://github.com/hashicorp/setup-terraform) | `3.1.2` | `4.0.1` |

Updates `github/codeql-action/init` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@1c5b675...2892aa5)

Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@1c5b675...2892aa5)

Updates `pullfrog/pullfrog` from 0.1.83 to 0.1.84
- [Release notes](https://github.com/pullfrog/pullfrog/releases)
- [Commits](pullfrog/pullfrog@e9f8115...99c5e78)

Updates `aws-actions/configure-aws-credentials` from 5.1.1 to 6.3.0
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](aws-actions/configure-aws-credentials@61815dc...e125382)

Updates `hashicorp/setup-terraform` from 3.1.2 to 4.0.1
- [Release notes](https://github.com/hashicorp/setup-terraform/releases)
- [Changelog](https://github.com/hashicorp/setup-terraform/blob/main/CHANGELOG.md)
- [Commits](hashicorp/setup-terraform@v3.1.2...dfe3c3f)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: pullfrog/pullfrog
  dependency-version: 0.1.84
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: hashicorp/setup-terraform
  dependency-version: 4.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit a78ba3a)
* Fix MCP Google authorization redirect

* Catalog MCP Google redirect actions

* Style Google redirect link as button

* Preserve calendar tokens during MCP sign-in

* Fix MCP Google redirect review findings

(cherry picked from commit 1d80602)

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Anonymous requests to the authorization page now allocate unbounded server-side state without a rate limit, exposing the API to memory exhaustion. Please bound allocation before merging.

Reviewed changes across all 26 files and four commits in this carry into redesign/main:

  • Dependency and workflow pins: Updates NuGet packages and pinned GitHub Actions.
  • MCP Google sign-in: Adds a server-side Google redirect, PKCE state store, identity-only callback, Terraform callback settings, and OAuth tests while preserving the legacy route.
  • Audio transcription: Passes the signed-in user ID through the command and hints transcription with the saved account language, with controller and handler coverage.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using GPT Sol | 𝕏

Comment thread src/Orbit.Api/Controllers/OAuthController.cs Outdated
A valid anonymous GET /oauth/authorize used to allocate a pending Google
request in OAuthAuthorizationStore even when the visitor never clicked
Google. The route carried no rate limit and the store carried no capacity
bound, so repeated page views could retain arbitrarily many entries until
the five-minute sweep and exhaust the API's memory.

The authorize page now hands its already-validated MCP parameters straight
to /oauth/google/start, which revalidates the client, the redirect URI and
the PKCE method server side before it allocates anything. A page view
allocates no server state.

The store gains a hard cap on pending Google requests, evicts expired
entries on insert, and refuses a new allocation once the cap is reached.
GoogleStart turns that refusal into the localized "unavailable" message on
the authorize page, where email sign-in stays available.

Both browser routes now carry the DistributedRateLimit("auth") policy.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
(cherry picked from commit 5dc0a01)

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes since the prior Pullfrog review: the Google sign-in flow now bounds anonymous pending state and preserves the existing MCP authorization behavior.

  • Moved state allocation: The authorize page renders without creating pending state; the Google start route revalidates parameters and creates the single-use request.
  • Bounded pending requests: Auth rate limits cover both browser routes, and the store caps live Google requests at 1,000 with expired-entry eviction.
  • Expanded OAuth coverage: Controller and store tests cover the new start flow, no-allocation page view, rate-limit attributes, capacity, and fallback.

Pullfrog  | View workflow run | Using GPT Sol | 𝕏

@thomasluizon
thomasluizon merged commit cc45508 into redesign/main Sep 29, 2026
22 checks passed
@thomasluizon
thomasluizon deleted the fix/ticket-746-carry-mcp-google-transcribe branch September 29, 2026 18:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant