fix(auth): restrict CLI start session reuse to GitHub auth

Dev-token sessions now carry a non-empty IdpIdentity, so filtering by
identity presence alone let the CLI start flow auto-resume under a
dev-token session. Tighten eligibility to GitHub-authenticated sessions
and update the auth_harness test helper to pass auth_mode by reference
to match the current build_router_with_options signature.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Bryan Helmkamp 2026-04-21 12:13:07 -04:00
parent 17020ee445
commit 3d831ef273
No known key found for this signature in database
2 changed files with 4 additions and 2 deletions

View file

@ -92,7 +92,7 @@ impl RealAuthHarness {
let github_base = github_base_url(&twin.base_url);
let router = build_router_with_options(
state,
auth_mode,
&auth_mode,
Arc::new(IpAllowlistConfig::default()),
RouterOptions {
web_enabled: true,

View file

@ -754,7 +754,9 @@ fn session_cookie_secure(state: &AppState) -> bool {
}
fn eligible_session(session: Option<&SessionCookie>) -> Option<&SessionCookie> {
session.filter(|session| session.identity.is_some())
session.filter(|session| {
session.identity.is_some() && session.auth_method == RunAuthMethod::Github
})
}
fn valid_state_token(state: &str) -> bool {