fix(quota): retry Antigravity summary 403 with compatibility UA - #5976
RHODIZSECURITY wants to merge 1 commit into
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: lidge-jun/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe Antigravity quota probe now retries a quota-summary request once with a compatibility User-Agent when the initial response is HTTP 403. It does not retry HTTP 401. Tests cover both response paths and update request-count expectations. ChangesAntigravity quota summary
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to The quota compatibility retry is ready for normal merge checks; no issue requiring a pre-merge fix was identified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The retry keeps the same account credentials and fixed provider destination, with no identified credential-exposure path. A failure during the retry can, however, change a denied quota result into a fallback result; that behavior has not been validated for retry failures. Retained concerns
Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
⏳ DRAFT
What to do
Review readiness checklist
0/4 boxes ticked. This PR stays in draft until every box above is ticked. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
리뷰 · 우선순위 60 / 80안티그래비티 계정 중에는 로그인과 추론은 되는데, 사용량만 거절되는 계정이 있습니다. 지금 프로그램 이름으로 사용량 요약을 물어보면 서버가 403을 줍니다. 같은 로그인 토큰과 같은 프로젝트로, 옛 이름 라인 - 라인 - 같은 함수 287줄. 두 번째 응답이 성공(200)도 아니고 401·403도 아니면, 함수는 그 try를 그냥 나옵니다. 실패 이유는 비어 있습니다. 역시 모델 목록으로 넘어가고, 목록이 성공하면 사용량이 있는 것처럼 보입니다. 새 테스트는 403 다음에 200이 오는 경우와, 401은 다시 보내지 않는 경우만 확인합니다. 두 번째가 실패하는 경우는 없습니다. 메인테이너의 판단이 필요한 지점 같은 수정의 열린 PR이 이미 있습니다. #5943( 너의 추천 403일 때만 같은 주소로 한 번 더 보내는 방향은 맞습니다. 401을 다시 보내지 않는 것도 맞습니다. 두 번째가 예외이거나 401·403이 아닌 오류이면, 모델 목록으로 사용량을 만들기 전에 접근 거절로 끝내는 쪽을 추천합니다. 그 경우를 테스트로 하나 넣으면 됩니다. #5943과 이 PR 중 하나만 머지하면 됩니다. 이 PR은 이름 상수와 403·401 테스트가 더 분명합니다. 위의 실패 처리를 고친 뒤 이쪽을 남기고 #5943을 닫아도 됩니다. 바탕이 이미 이 댓글은 grok-bot이 작성했습니다 |
| PR | Change | Author | | --- | --- | --- | | #5968 | Revalidate context relay admission against the live hub-link key policy before dispatch. | luvs01 | | #5966 | Start the link tunnel supervisor only after the listener owns a bound target, and start it after issue recovery. | luvs01 | | #5933 | Honor an explicitly configured Devin reset wait while preserving stream heartbeats and bounded retry behavior. | luvs01 | | #5952 | Expand measured Command Code effort ladders. | codingbooo | | #5942 | Project Claude input estimates onto the settled wire and canonical combo target. | moseoridev | | #5943 | Retry a quota-summary 403 once on the same fixed Antigravity endpoint with the legacy User-Agent. | codingbooo | Integration commits add a real delayed-body hub-link revocation regression; a failed-bind and recovered-bind supervisor regression; the first rejected Command Code send retry; and explicit layout registrations for the Devin cooldown and Claude projection tests. The Claude source PR already records `targetRoute.modelId` and includes the combo-alias regression; reverting that line makes the alias case fail. Review follow-up: the DeepSeek V4 Flash DSH/ZCode export expectations now match all five calibrated efforts. Devin combo children now bypass the optional stated-reset wait and surface their pre-output refusal, so the combo can advance promptly; standalone opted-in turns retain reset waiting and heartbeats. The delayed-reset combo and real Devin adapter regressions were red before the fix and green after it. The alternate Antigravity 403 PR (#5976) was left out because the included implementation covers the same retry with more extensive tests for bearer/project identity, cancellation failure, retry bounds, redirects, and fallback. No code was taken from that alternative. Independent security review is requested before merge for link admission and tunnel startup (`src/server/index/serve-options.ts`, `src/server/index/optional-listeners.ts`, `src/server/index/link-listener.ts`, `src/server/management/link-routes.ts`), Devin wait/replay (`src/adapters/devin.ts`, `src/adapters/devin/cloud-direct/stated-reset-retry.ts`, `src/adapters/run-turn-queue.ts`, `src/server/responses/run-turn-execution.ts`), and the credential-bearing Antigravity retry (`src/providers/quota/antigravity.ts`). Co-authored-by: Epinephrine <luvs01@hanmail.net> Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: codingbo <cnsdbo@163.com> Co-authored-by: moseoridev <sjssjs1344@gmail.com>
Closes #5940.
Some valid Google Antigravity OAuth identities return HTTP 403 from
retrieveUserQuotaSummaryonly when the quota probe uses the current IDE User-Agent. The same bearer and project succeed with the legacy Antigravity client family.This change retries the canonical quota-summary endpoint exactly once on 403 with
User-Agent: antigravity/1.0.Safety boundaries:
Validation on current
dev:bun x tsc --noEmit: PASSNo credentials, raw account identifiers, or private provider payloads are included.
Review readiness checklist
This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:
Required local validation passed; commands, results, and any full-suite exception are documented.
I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
I resolved all correct Codex and CodeRabbit findings.
My PR is ready for review.
Summary by CodeRabbit