Skip to content

Hide expired OAuth tokens from the account token list - #2004

Merged
asim merged 1 commit into
mainfrom
fix/expired-oauth-tokens
Oct 2, 2026
Merged

asim merged 1 commit into
mainfrom
fix/expired-oauth-tokens

Conversation

@asim

@asim asim commented Oct 2, 2026

Copy link
Copy Markdown
Member

OAuth access tokens expire after 24 hours, but ListTokens still returned every expired grant. Reconnecting ChatGPT therefore left unusable entries accumulating on the account Tokens page.

Exclude expired OAuth grants from the shared account token listing, covering both the HTML page and JSON response. Recognize current OAuthClientID metadata and older OAuth-prefixed entries. Active and non-expiring OAuth grants remain visible. Personal tokens and admin OAuth audit records retain their existing behavior; this does not extend token validity or delete credentials.

Verified with go test -race ./internal/auth ./account -short, go build -buildvcs=false ./... and git diff --check. Regression coverage includes legacy entries, active grants, account isolation and retained audit records. No layout changes; authenticated browser verification was unavailable.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T10:35:18.529152Z 9cf8e6a PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@asim
asim merged commit cfba175 into main Oct 2, 2026
1 check passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9cf8e6a793

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/auth/auth.go
Comment on lines +1120 to +1121
oauth := token.OAuthClientID != "" || strings.HasPrefix(token.Name, "OAuth: ")
if oauth && !token.ExpiresAt.IsZero() && !token.ExpiresAt.After(now) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid treating user-named PATs as OAuth grants

A personal token can be created with any name, including OAuth: backup, while CreateToken leaves its OAuthClientID empty. Once that token expires, this prefix check misclassifies it as a legacy OAuth grant and removes it from both the HTML and JSON token listings, unlike every other expired personal token, so its owner can no longer discover or delete it through the account UI/API. Use authoritative OAuth metadata or otherwise disambiguate legacy grants from user-controlled names.

AGENTS.md reference: AGENTS.md:L567-L567

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant