Skip to content

fix: refresh GitHub OIDC tokens per request - #65

Open
ivanmilevtues wants to merge 1 commit into
mainfrom
fix/refresh-oidc-per-request
Open

fix: refresh GitHub OIDC tokens per request#65
ivanmilevtues wants to merge 1 commit into
mainfrom
fix/refresh-oidc-per-request

Conversation

@ivanmilevtues

Copy link
Copy Markdown
Member

Summary

  • run a loopback relay for hosted Action runs
  • mint a fresh GitHub OIDC JWT for every proxy request instead of freezing one at setup
  • cover repeated forwarding with a stdlib integration test

Root cause

The Action minted one short-lived GitHub OIDC JWT before analysis. Long analyses then reused that bearer after it expired, and the hosted Lambda correctly returned 401 Invalid GitHub OIDC token.

Validation

  • python3 -m unittest discover -s tests -v (180 tests)
  • actionlint
  • git diff --check

A live free-tier smoke run will follow from a disposable branch using this Action branch.

@ivanmilevtues
ivanmilevtues marked this pull request as ready for review July 30, 2026 15:32
@codeboarding-review

codeboarding-review Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Architecture review · 1 component changed

graph LR
    n_Analysis_Engine_Adapter["Analysis Engine Adapter"]
    n_Visual_Rendering_Engine["Visual Rendering Engine"]
    n_Structural_Diff_Engine["Structural Diff Engine"]
    n_Telemetry_Feedback_Handler["Telemetry #38; Feedback Handler"]
    n_Interaction_Orchestrator["Interaction Orchestrator"]
    n_Visual_Rendering_Engine -- "Queries for architectural changes" --> n_Structural_Diff_Engine
    n_Visual_Rendering_Engine -- "Provides metadata for CTA generation" --> n_Interaction_Orchestrator
    n_Structural_Diff_Engine -- "Provides change-set data" --> n_Visual_Rendering_Engine
    n_Interaction_Orchestrator -- "Dispatches interactive UI elements" --> n_Telemetry_Feedback_Handler
    n_Analysis_Engine_Adapter -- "Orchestrates documentation generation" --> n_Visual_Rendering_Engine
    n_Telemetry_Feedback_Handler -- "Captures user intent from UI" --> n_Interaction_Orchestrator
    n_Interaction_Orchestrator -- "Consumes issue counts for UI" --> n_Visual_Rendering_Engine
    classDef added fill:#1f883d,stroke:#0b5d23,color:#ffffff;
    classDef modified fill:#bf8700,stroke:#7d4e00,color:#ffffff;
    classDef deleted fill:#cf222e,stroke:#82071e,color:#ffffff,stroke-dasharray:5 3;
    class n_Interaction_Orchestrator modified;
    linkStyle 1,3 stroke:#0b5d23,stroke-width:2px;
    linkStyle 4,5,6 stroke:#82071e,stroke-width:2px,stroke-dasharray:5 3;
Loading

Colors indicate component changes compared to target branch main: 🟩 Added · 🟨 Modified · 🟥 Removed

Download the PR analysis artifacts from this workflow artifact.

Interaction Orchestrator : 1 file changed
  • scripts/oidc_relay.py

⚠️ 1 architecture issue found — open CodeBoarding to explore them.

Explore this PR’s architecture in your browser or VS Code.

codeboarding-action · run 30557231308

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant