Repository navigation
Fix x402 account sign-in and explain how to connect an agent - #2056
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d202c17a93
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| // OAuth state, passkeys and session cookies all use the same host. This does | ||
| // not redirect protocol requests or forward credentials between origins. | ||
| func redirectHostAccount(w http.ResponseWriter, r *http.Request) bool { | ||
| if !origin.IsX402Host(r) || (r.Method != http.MethodGet && r.Method != http.MethodHead) || app.WantsJSON(r) || r.Header.Get("Authorization") != "" { |
There was a problem hiding this comment.
Preserve legacy token requests on the x402 host
Exempt X-Micro-Token here alongside Authorization. The server explicitly supports that header as a legacy credential, but an authenticated GET/HEAD for /account or its subroutes without Accept: application/json now receives a cross-origin 303 before authentication rather than the previous response; redirect-following clients may also replay this unrecognized custom credential header on the primary host. This changes an existing authenticated client flow despite the function's promise not to redirect protocol requests.
AGENTS.md reference: AGENTS.md:L98-L100
Useful? React with 👍 / 👎.
Account actions from the x402 pricing page currently leave the browser on the payment host. Google state cookies can then disagree with the configured callback host, and account sessions and browser-origin checks do not share a consistent origin.
Redirect browser GET/HEAD account, login/signup and Google OAuth pages to the configured primary host before authentication starts, preserving the destination and query. Keep MCP, service APIs, OAuth protocol endpoints, authenticated API requests and POST bodies untouched. Do not redirect when the primary origin is absent or would loop.
After sign-in, keep billing on the primary host and explain the next step. Account and top-up pages link to service-token setup; the service-token form includes the configured x402 MCP endpoint, a configuration example, catalogue/API links and usage access. This guidance remains available after checkout without handing browser sessions between domains.
Validation: tests passed for internal/server, account and internal/auth; vet passed for account and internal/server; diff check passed. Regression coverage includes proxy hosts, preserved destinations, non-browser requests, redirect loops, successful password login on the primary origin, matching Google state/callback origin, and the service-token setup guidance. Live Google provider login and browser visual verification were not performed.