Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
stack-cli: support self-hosted URLs and tighten CLI auth polling #1419
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: dev
Are you sure you want to change the base?
stack-cli: support self-hosted URLs and tighten CLI auth polling #1419
Changes from all commits
e0025b2f9aa93138a64ffFile filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
There are no files selected for viewing
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The SELECT and UPDATE are separate round-trips with no row-level lock or transaction guard. A second polling request that arrives between the
$queryRaw(line 51) and the$executeRaw(line 81) will read the same row (usedAt = null,refreshTokenset) and also receive a 201 with the same token. An attacker who obtains thepolling_codebefore the legitimate client completes the handshake can race that window to claim the refresh token.The pre-existing Prisma
findFirst→updatehad the same gap. Since this PR explicitly migrates to raw SQL, the atomic fix is straightforward: replace the two-step pattern with a singleUPDATE ... WHERE "usedAt" IS NULL RETURNING "refreshToken"so the mark-as-used and the token retrieval are one atomic operation.Prompt To Fix With AI
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
2 min might be too short, apparently 10 or 15 min is common
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
don't think we need these, self-hosters would pass in these when running cli instead
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
DEFAULT_API_URL/DEFAULT_DASHBOARD_URLconstants now embed the env-var lookup themselves.resolveApiUrl()already checksprocess.env.STACK_API_URLas its first step, so the env-var insideDEFAULT_API_URLis unreachable via that fallback chain — the constant only ever contributes the hardcoded cloud URL. Using a plain literal for the exported default avoids the misleading double-lookup and keeps the single source of truth inside theresolve*functions.Prompt To Fix With AI
Uh oh!
There was an error while loading. Please reload this page.