Skip to content

feat(providers): expose actionable OAuth refresh failures - #2887

Open
mrunalp wants to merge 4 commits into
NVIDIA:mainfrom
mrunalp:2886-oauth-refresh-actionable-errors/mrunalp
Open

feat(providers): expose actionable OAuth refresh failures#2887
mrunalp wants to merge 4 commits into
NVIDIA:mainfrom
mrunalp:2886-oauth-refresh-actionable-errors/mrunalp

Conversation

@mrunalp

@mrunalp mrunalp commented Aug 21, 2026

Copy link
Copy Markdown
Collaborator

Summary

Expose structured, provider-neutral recovery guidance for OAuth refresh failures so consumers can distinguish transient retries, operator configuration problems, and user reauthorization without parsing provider error text. Preserve safe diagnostics, stop rapid retries for terminal grants, and keep the existing credential-driver storage boundary unchanged.

Related Issue

Closes #2886

Changes

  • Parse bounded OAuth error responses and persist stable recovery actions, failure codes, safe provider subtypes, and failure timestamps.
  • Park refresh grants that require user reauthorization, retry configuration failures hourly, and retain short retries for transient failures and rotated-token persistence recovery.
  • Surface actionable refresh status through the CLI and curated Go SDK, including correct handling of the parked-refresh next-time sentinel.
  • Add unit coverage for classification, persistence, cleared success state, scheduling, response bounds, provider gates, and post-mint failures.
  • Add a rootless Podman + Keycloak E2E lane that uses the default database credential store and verifies refresh, revocation, and reauthorization status.
  • Document the recovery contract in provider docs, gateway architecture, protobuf comments, and the OpenShell CLI skill.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated
  • E2E tests added/updated (if applicable)
  • cargo test -p openshell-server --lib (1,430 passed, 8 ignored)
  • mise run go:ci
  • mise run e2e:provider-refresh-keycloak

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

Signed-off-by: Mrunal Patel <mrunalp@gmail.com>
Signed-off-by: Mrunal Patel <mrunalp@gmail.com>
Signed-off-by: Mrunal Patel <mrunalp@gmail.com>
Signed-off-by: Mrunal Patel <mrunalp@gmail.com>
@mrunalp
mrunalp requested review from a team, derekwaynecarr and sjenning as code owners August 21, 2026 23:50
@copy-pr-bot

copy-pr-bot Bot commented Aug 21, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(providers): expose actionable OAuth refresh failures

1 participant