Repository navigation
fix: Route OAuth-connected Linear calls through linear-proxy - #597
Merged
Ziinc merged 4 commits intoSep 29, 2026
Merged
Conversation
Settings offered "Connect via OAuth", but every Linear command (and the
auto-kickoff poller) returned "OAuth proxy not ready" when a repo had no
API key, so OAuth-connected users had no working integration.
- The frontend pushes the Supabase URL and access token to Rust on sign-in
and every refresh (shared with the SSH relay token sync). Repos without
an API key now send GraphQL to the linear-proxy Edge Function with that
session. An API key still takes precedence.
- linear-proxy sends the OAuth token with the Bearer scheme Linear
requires, refreshes it when it is within a minute of expiry, and
passes Linear's body through so GraphQL errors reach the app.
- Proxy errors ("Linear account not linked", expired grant) surface as
readable messages instead of the API-key text.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015cmSSvMnu4gc6NhMhKrt2v
…oauth-proxy # Conflicts: # src-tauri/src/linear.rs
Rust: an OAuth session must reach `{supabase}/functions/v1/linear-proxy`
with the Bearer JWT, and a proxy `{"error": ...}` body must surface as
the message. Both fail on the previous code ("OAuth proxy not ready";
"rejected the API key").
linear-proxy: move request logic to lib.ts (no Deno or Supabase imports)
and test it under vitest like _shared/merge-queue. The tests cover the
Bearer header, GraphQL error pass-through, 401 reconnect, refresh near
expiry, missing refresh token, and a concurrent refresh. Six of the eight
fail against the previous handler; the other two pin unchanged behavior.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015cmSSvMnu4gc6NhMhKrt2v
…oauth-proxy # Conflicts: # src-tauri/src/lib.rs
Ziinc
added a commit
that referenced
this pull request
Sep 29, 2026
Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stack 4/4 (based on the auto-kickoff label filter PR #596).
Problem
Settings offers "Connect via OAuth", but with no repo API key every Linear command and the auto-kickoff poller returned "OAuth proxy not ready". The
linear-proxyEdge Function had three more problems:Bearerscheme Linear requires.expires_atandrefresh_token.Change
Desktop
linear_set_proxy_session(supabase_url, access_token)command.src/lib/supabase-token-sync.ts. Relay behavior is unchanged.LinearClientSource::Proxysends GraphQL to{supabase}/functions/v1/linear-proxywith the user's JWT.{"error": ...}bodies show asLinear: <message>. A 401/403 from the proxy tells the user to sign in to treq again.linear-proxy
lib.ts, which has no Deno or Supabase imports.index.tsonly handles auth and connectslib.tsto Supabase.lib.tsis unit tested under vitest, the same way as_shared/merge-queue.Bearer <token>.Testing (red → green)
oauth_session_reaches_linear_through_the_proxychecks the path and theBearerheader.proxy_explains_an_unlinked_linear_accountchecks the error message.test/linear-proxy/proxy.test.ts(8 tests):Bearerheader, GraphQL errors passed through, 401 → reconnect, refresh then store then use, no refresh while the token is valid, no refresh token, concurrent refresh.linear-proxy-auth,remote-relay-authanduseLinearAutoKickoff;deno checkanddeno fmt;tsc; eslint; oxlint; clippy-D warnings;cargo fmt --check.Not run: service-qa against the local Supabase stack, because its Docker images need more disk than the sandbox has. A real Linear OAuth round trip is also untested.
🤖 Generated with Claude Code
https://claude.ai/code/session_015cmSSvMnu4gc6NhMhKrt2v