Skip to content

Fix Link callback ownership for Eve inbox tokens - #155

Merged
fmhall merged 1 commit into
mainfrom
mason/fix-eve-inbox-ownership
Oct 2, 2026
Merged

fmhall merged 1 commit into
mainfrom
mason/fix-eve-inbox-ownership

Conversation

@fmhall

@fmhall fmhall commented Oct 2, 2026

Copy link
Copy Markdown
Member

Link consent saved the wallet successfully, but its return callback failed with forbidden: Session not found. The ownership parser recognized older hook tokens and rejected Eve 0.66.3's eve:inbox:v1: wrapper before checking session ownership.

Unwrap the recognized v1 inbox prefix before resolving the session ID. Keep workspace ownership checks, supported legacy tokens, and rejection of unknown token versions and kinds. Regression coverage includes the encoded Link callback path and an owned callback reaching Eve's actual callback handler.

Validation: pnpm check (779 tests, all six tasks), pnpm build, and pnpm exec eve build passed. Focused callback and OAuth suites passed 11 tests; the original code failed the new regressions. Independent read-only review found no issues.

@fmhall
fmhall merged commit 09b629d into main Oct 2, 2026
2 checks passed

This branch was successfully deployed

1 active deployment
Preview — 956e712d Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant