fix(install): verify claim status before setting a default homepage - #252
Conversation
A locally unclaimed profile can be stale after the environment is claimed elsewhere. Reuse the claim-nonce API to confirm live status before implicit homepage writes, and skip writes on failed or unavailable confirmation. Apply the check in the shared helper for both installer paths, matching the expected client ID when available. Explicit homepage overrides remain unchanged. This is a best-effort preflight, not an atomic claim/write operation.
|
| (clientId !== undefined && environment.clientId !== clientId) | ||
| ) | ||
| return false; | ||
| const claim = await createClaimNonce(environment.clientId, environment.claimToken); |
There was a problem hiding this comment.
Claim check uses another host If the active profile has a custom endpoint or
WORKOS_API_URL is set, this nonce request goes to that host, while the homepage PUT still goes to https://api.workos.com. A failed check can leave the homepage unset even when the write endpoint is available, and a successful check does not confirm claim status at the host receiving the write. Use the same API host for both requests.
Knowledge Base Used: Authentication and configuration lifecycle
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/lib/workos-management.ts
Line: 162
Comment:
**Claim check uses another host** If the active profile has a custom endpoint or `WORKOS_API_URL` is set, this nonce request goes to that host, while the homepage PUT still goes to `https://api.workos.com`. A failed check can leave the homepage unset even when the write endpoint is available, and a successful check does not confirm claim status at the host receiving the write. Use the same API host for both requests.
**Knowledge Base Used:** [Authentication and configuration lifecycle](https://app.greptile.com/workos/-/custom-context/knowledge-base/workos/cli/-/docs/authentication-and-configuration.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| // for an environment the server still reports as unclaimed. Local claim | ||
| // status can be stale. With a login, the later dashboard step reads the | ||
| // current value and fills an empty one. | ||
| const writeHomepage = Boolean(options.homepageUrl) || (await isUnclaimedEnvironmentKey(apiKey)); |
There was a problem hiding this comment.
Claim check delays other settings This path waits for the nonce request before starting redirect and CORS registration or showing setup progress. If the request stalls, its 30-second timeout delays both settings, although claim status is needed only for the homepage decision. Start the additive settings independently of the check.
Knowledge Base Used: Application installation workflows
Prompt To Fix With AI
This is a comment left during a code review.
Path: src/lib/workos-management.ts
Line: 261
Comment:
**Claim check delays other settings** This path waits for the nonce request before starting redirect and CORS registration or showing setup progress. If the request stalls, its 30-second timeout delays both settings, although claim status is needed only for the homepage decision. Start the additive settings independently of the check.
**Knowledge Base Used:** [Application installation workflows](https://app.greptile.com/workos/-/custom-context/knowledge-base/workos/cli/-/docs/application-installation.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
Problem
A local profile can still say an environment is unclaimed after someone claims it elsewhere. The installer then treats its default homepage write as safe and can replace a homepage configured in the dashboard.
Change
Ports the previously staged follow-up onto current main after #250:
--homepage-urloverrides independent of the claim check.The probe creates a claim nonce but does not claim the environment. It inherits the existing request timeout. This is a best-effort preflight, not an atomic guard against an environment being claimed concurrently with the homepage write. Dashboard-session setup is unchanged.
Validation
Only four files change; no dependency or CI changes.