Skip to content

Forward connected-account callbacks with v2's state prefix to v2 - #2218

Closed
RhysSullivan wants to merge 1 commit into
cloud/v1-edge-v2-forward-testsfrom
cloud/v1-edge-oauth-callback
Closed

RhysSullivan wants to merge 1 commit into
cloud/v1-edge-v2-forward-testsfrom
cloud/v1-edge-oauth-callback

Conversation

@RhysSullivan

@RhysSullivan RhysSullivan commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

v1 and v2 share https://executor.sh/api/oauth/callback. v2 starts every connected-account OAuth state with a fixed prefix; the edge forwards a callback to v2 only when the query's state starts with it. Everything else (no state, empty state, v1 state, lookalikes) stays with v1. No lookups and no body reads.

  • New wrangler var V2_OAUTH_STATE_PREFIX, set to x2.. It must equal the prefix v2 mints.
  • The prefix must be URL-safe and contain . or ~. v1's states are base64url (raw, or the org-wrapped JSON), so no v1 state can start with such a prefix.
  • The edge's settings are now passed as one object (V2, V2_SIGN_UP_URL, V2_OAUTH_STATE_PREFIX), all set or none.
  • With broken settings, v1 keeps every callback, because which callbacks are v2's depends on the settings. The paths the edge always owns still answer 500.

Forwarded callbacks lose their cookies like every other v2 forward; v2 answers with a redirect to app.executor.sh, which is returned unfollowed.

Tests are in the PR above this one.

Replaces #2211, which GitHub closed when the stack was reordered.

@RhysSullivan
RhysSullivan added this pull request to stack #2219 October 8, 2026 19:00
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Cloudflare preview

Torn down — the PR is closed.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
executor-marketing 706f299 Commit Preview URL

Branch Preview URL
Oct 08 2026, 07:03 PM

@pkg-pr-new

pkg-pr-new Bot commented Oct 8, 2026

Copy link
Copy Markdown

Open in StackBlitz

@executor-js/cli

npm i https://pkg.pr.new/@executor-js/cli@2218

@executor-js/config

npm i https://pkg.pr.new/@executor-js/config@2218

@executor-js/execution

npm i https://pkg.pr.new/@executor-js/execution@2218

@executor-js/sdk

npm i https://pkg.pr.new/@executor-js/sdk@2218

@executor-js/codemode-core

npm i https://pkg.pr.new/@executor-js/codemode-core@2218

@executor-js/runtime-quickjs

npm i https://pkg.pr.new/@executor-js/runtime-quickjs@2218

@executor-js/plugin-file-secrets

npm i https://pkg.pr.new/@executor-js/plugin-file-secrets@2218

@executor-js/plugin-graphql

npm i https://pkg.pr.new/@executor-js/plugin-graphql@2218

@executor-js/plugin-keychain

npm i https://pkg.pr.new/@executor-js/plugin-keychain@2218

@executor-js/plugin-mcp

npm i https://pkg.pr.new/@executor-js/plugin-mcp@2218

@executor-js/plugin-onepassword

npm i https://pkg.pr.new/@executor-js/plugin-onepassword@2218

@executor-js/plugin-openapi

npm i https://pkg.pr.new/@executor-js/plugin-openapi@2218

executor

npm i https://pkg.pr.new/executor@2218

commit: 706f299

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
executor-cloud 706f299 Oct 08 2026, 07:03 PM

@RhysSullivan

Copy link
Copy Markdown
Collaborator Author

Merged into main through the integration PRs #2220 and #2217 (squash), so this layer is already live.

Sent from my Claude

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant