Skip to content

fix(main): harden auth and external lifecycle - #715

Merged
zortos293 merged 1 commit into
devfrom
capy/fixmain-harden-auth-and
Aug 8, 2026
Merged

fix(main): harden auth and external lifecycle#715
zortos293 merged 1 commit into
devfrom
capy/fixmain-harden-auth-and

Conversation

@zortos293

@zortos293 zortos293 commented Aug 8, 2026

Copy link
Copy Markdown
Collaborator

OAuth and external-link lifecycle failures could leave callback work unobserved, produce misleading shutdown telemetry, or block legitimate user-selected store launcher URLs.

  • Make browser OAuth startup and callback waiting one coordinated operation that always clears timers, closes the loopback server, and observes cancellation or launch failures.
  • Suppress renderer-termination exceptions only after an app shutdown has already been requested; unexpected crashes, kills, and OOM exits remain reportable.
  • Permit a narrow platform-specific allowlist of store launcher schemes for explicit IPC requests while keeping automatic navigation restricted to HTTP(S) and rejecting dangerous or arbitrary protocols.

Focused tests cover OAuth success/failure/timeout cleanup, renderer lifecycle classification, and external URL policy boundaries.

Open in Capy

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
@zortos293 zortos293 added the capy Generated by capy.ai label Aug 8, 2026 — with Image Capy AI
@cursor

cursor Bot commented Aug 8, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@coderabbitai

coderabbitai Bot commented Aug 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 5f3406aa-b68b-488b-a7f1-892575780b2c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@zortos293
zortos293 merged commit 85ed926 into dev Aug 8, 2026
17 checks passed
ap0ught added a commit to ap0ught/OpenNOW that referenced this pull request Aug 15, 2026
…#4)

* feat(stream): redesign Ctrl+G overlay with tabs and controller support (OpenCloudGaming#622)

* refactor: split oversized modules into focused files (OpenCloudGaming#626)

Co-authored-by: Zortos <zortosdev@proton.me>

* feat(renderer): polish queue shaders and Motion animations (OpenCloudGaming#628)

* feat(native): internal one-window renderer with external fallback (OpenCloudGaming#619)

* Stabilize WebRTC streaming and native window behavior (OpenCloudGaming#635)

* fix(native): honor Windows DPI scaling (OpenCloudGaming#637)

* feat: add nightly builds and opt-in update channel (OpenCloudGaming#638)

* fix(updater): Preserve nested macOS signatures (OpenCloudGaming#631)

* fix(build): configure relocated GStreamer plugins

* fix(ci): use supported macOS runner size

* fix(native): mark Objective-C selectors thread-safe

* fix(build): sign unsigned nested macOS bundles

* fix(build): sign nested macOS Mach-O code

* fix(build): enforce nested macOS signing order

* fix(release): upload assets before publishing

* fix(release): target repository when publishing

* fix(native): stabilize high-FPS Vulkan streaming and input (OpenCloudGaming#639)

* fix(native): enable DX11 tearing and VRR presentation (OpenCloudGaming#640)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix: align settings/library UI and preserve GFN auth/library ownership (OpenCloudGaming#644)

* fix(ui): repair settings interactions and accessibility (OpenCloudGaming#649)

* fix(ui): smooth animation lifecycles (OpenCloudGaming#651)

* feat(streaming): add 90 FPS mode (OpenCloudGaming#652)

* fix(ci): preserve LF endings for patch files (OpenCloudGaming#653)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(ci): build only patched D3D11 target (OpenCloudGaming#654)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(ci): align Windows GStreamer Vulkan runtime (OpenCloudGaming#655)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(ci): bundle and verify Vulkan loader (OpenCloudGaming#656)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* feat(input): Scandinavian keyboard layouts (OpenCloudGaming#624) (OpenCloudGaming#660)

* fix(controller): make bottom hint overlay clickable with mouse (OpenCloudGaming#620) (OpenCloudGaming#661)

fixes OpenCloudGaming#620

* fix(streaming): stop synthesizing 90 FPS from entitlements (OpenCloudGaming#662)

* feat(gfn): add Identify as Steam Deck option for Deck modes and 90 FPS (OpenCloudGaming#663)

Spoof official Steam Deck device headers on MES/CloudMatch so entitlements
return Deck resolutions and 90 FPS, and refresh video options when toggled.

* fix: Mac missing fullscreen (OpenCloudGaming#642)

* fix(deps): update dependencies and clear npm audit vulnerabilities (OpenCloudGaming#664)

* feat: PostHog telemetry, consent, and in-app feedback (OpenCloudGaming#668)

* fix(build): restore macOS plist packaging compatibility

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* docs: link the OpenNOW Switch prototype (OpenCloudGaming#670)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* Fix Nintendo Switch release documentation (OpenCloudGaming#674)

* New translations en.json (Romanian)

[ci skip]

* New translations en.json (French)

[ci skip]

* New translations en.json (Spanish)

[ci skip]

* New translations en.json (German)

[ci skip]

* New translations en.json (Japanese)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Dutch)

[ci skip]

* New translations en.json (Polish)

[ci skip]

* New translations en.json (Russian)

[ci skip]

* New translations en.json (Turkish)

[ci skip]

* New translations en.json (Chinese Simplified)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* fix(native): bundle Windows DLL dependency closure (OpenCloudGaming#676)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* feat(native): add Linux and Raspberry Pi codec support (OpenCloudGaming#679)

* feat(native): add Linux hardware codec support

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* ci(native): verify Linux release builds

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

---------

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(settings): centralize platform defaults (OpenCloudGaming#683)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(settings): split stream settings modules (OpenCloudGaming#685)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(stream): decompose StreamView runtime (OpenCloudGaming#686)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(gfn): modularize NVST RTSP probe (OpenCloudGaming#682)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(native): extract streamer runtime helpers (OpenCloudGaming#684)

* refactor(native): extract streamer runtime helpers

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* test(native): make path fixtures portable

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* test(native): normalize Windows path assertions

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

---------

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(renderer): extract App stream runtime orchestration (OpenCloudGaming#690)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(gfn): decompose auth service (OpenCloudGaming#689)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(gfn): split input protocol modules (OpenCloudGaming#688)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(gfn): modularize SDP transformations (OpenCloudGaming#687)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* refactor(gfn): compose WebRTC client from focused controllers (OpenCloudGaming#691)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* feat(discord): show game artwork in rich presence (OpenCloudGaming#681)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(security): verify signaling TLS certificates

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* chore(release): prepare v0.5.3

* fix(input): keep gameplay interactive after Escape unlock (OpenCloudGaming#711)

* fix(input): preserve interaction after Escape unlock

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(input): pin cursor before fallback clicks

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(input): order fallback cursor pins reliably

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

---------

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(main): harden auth and external lifecycle (OpenCloudGaming#715)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(main): tolerate closed output and streamer pipes (OpenCloudGaming#714)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(input): prevent recursive mouse flush scheduling (OpenCloudGaming#712)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* fix(media): recover shader and audio playback (OpenCloudGaming#713)

Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>

* feat(stream): align SDP and BWE with official client (OpenCloudGaming#720)

Co-authored-by: Akamiya Chizui <127862333+Chizuui@users.noreply.github.com>

* feat(catalog): add game detail modal (OpenCloudGaming#721)

Co-authored-by: Akamiya Chizui <127862333+Chizuui@users.noreply.github.com>

* Harden codec capability selection and negotiation fallback (OpenCloudGaming#722)

Adds capability-aware codec selection and bounded negotiation fallback, preserving official-client SDP/BWE behavior while preventing unsupported codec choices from leaving sessions without video.

Co-authored-by: Akamiya Chizui <127862333+Chizuui@users.noreply.github.com>

* Add accurate stream diagnostics telemetry (OpenCloudGaming#723)

Adds typed telemetry for server game FPS, receive/decode rates, ICE transport, network capacity, and session location so the compact/full HUD reports distinct measurements accurately.

Co-authored-by: Akamiya Chizui <127862333+Chizuui@users.noreply.github.com>

* Add GFN-style compact and full stats HUD (OpenCloudGaming#724)

Adds off, compact, and full frame-stat modes with distinct server, receive, decode, and render telemetry; configurable corner placement; localized diagnostics; and a guarded Ctrl+N shortcut.

Co-authored-by: Akamiya Chizui <127862333+Chizuui@users.noreply.github.com>

* New translations en.json (Romanian)

[ci skip]

* New translations en.json (French)

[ci skip]

* New translations en.json (Spanish)

[ci skip]

* New translations en.json (German)

[ci skip]

* New translations en.json (Japanese)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Dutch)

[ci skip]

* New translations en.json (Polish)

[ci skip]

* New translations en.json (Russian)

[ci skip]

* New translations en.json (Turkish)

[ci skip]

* New translations en.json (Chinese Simplified)

[ci skip]

* New translations en.json (English)

[ci skip]

* Harden browser recording controls and performance (OpenCloudGaming#725)

Adds bounded browser recording controls, presented-frame capture, ordered chunk persistence, and reliable finalization without importing native GStreamer recording scope.

Co-authored-by: Akamiya Chizui <127862333+Chizuui@users.noreply.github.com>

* New translations en.json (Romanian)

[ci skip]

* New translations en.json (French)

[ci skip]

* New translations en.json (Spanish)

[ci skip]

* New translations en.json (German)

[ci skip]

* New translations en.json (Japanese)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Dutch)

[ci skip]

* New translations en.json (Polish)

[ci skip]

* New translations en.json (Russian)

[ci skip]

* New translations en.json (Turkish)

[ci skip]

* New translations en.json (Chinese Simplified)

[ci skip]

* New translations en.json (English)

[ci skip]

* Reorganize streaming and diagnostics settings (OpenCloudGaming#726)

Groups stream quality and recording controls under Stream, moves HUD and codec tests into Diagnostics, preserves persisted settings, and restores legacy search aliases.

Co-authored-by: Akamiya Chizui <127862333+Chizuui@users.noreply.github.com>

* New translations en.json (Romanian)

[ci skip]

* New translations en.json (French)

[ci skip]

* New translations en.json (Spanish)

[ci skip]

* New translations en.json (German)

[ci skip]

* New translations en.json (Japanese)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Dutch)

[ci skip]

* New translations en.json (Polish)

[ci skip]

* New translations en.json (Russian)

[ci skip]

* New translations en.json (Turkish)

[ci skip]

* New translations en.json (Chinese Simplified)

[ci skip]

* New translations en.json (English)

[ci skip]

* Harden media lifecycles and refresh dependencies (OpenCloudGaming#728)

* Harden media lifecycles and refresh dependencies

* Harden authorized CloudMatch endpoints

* feat: add recurring anti-AFK reminders (OpenCloudGaming#729)

* feat: add recurring anti-AFK reminders

* docs: add anti-AFK reminder previews

* fix(input): retain pointer capture on Escape (OpenCloudGaming#735)

* feat(queue): add ad mute control (OpenCloudGaming#733)

* feat(desktop): add account menu exit button (OpenCloudGaming#731)

* fix(linux): restore app icon on Wayland (OpenCloudGaming#732)

* New translations en.json (Romanian)

[ci skip]

* New translations en.json (French)

[ci skip]

* New translations en.json (Spanish)

[ci skip]

* New translations en.json (German)

[ci skip]

* New translations en.json (Japanese)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Dutch)

[ci skip]

* New translations en.json (Polish)

[ci skip]

* New translations en.json (Russian)

[ci skip]

* New translations en.json (Turkish)

[ci skip]

* New translations en.json (Chinese Simplified)

[ci skip]

* New translations en.json (English)

[ci skip]

* feat: support an isolated secondary app instance (OpenCloudGaming#736)

* fix(native): avoid X11 embedding under Wayland (OpenCloudGaming#737)

* Improve app performance and repair light theme (OpenCloudGaming#739)

* perf: optimize app runtime and repair light theme

* fix: harden performance changes against regressions

* Add controller-first console mode with PIN-protected profiles (OpenCloudGaming#697)

* fix(release): keep changelog comparisons current (OpenCloudGaming#740)

* fix(console): harden profile PINs and controller flows (OpenCloudGaming#741)

* feat(console): suggest controller mode on gamepad connection (OpenCloudGaming#742)

* feat(console): suggest controller mode on gamepad connection

* feat(console): control mode prompt with gamepad

* style(console): color controller action glyphs

* refactor(console): reuse shared controller glyphs

* New translations en.json (Romanian)

[ci skip]

* New translations en.json (French)

[ci skip]

* New translations en.json (Spanish)

[ci skip]

* New translations en.json (German)

[ci skip]

* New translations en.json (Japanese)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Dutch)

[ci skip]

* New translations en.json (Polish)

[ci skip]

* New translations en.json (Russian)

[ci skip]

* New translations en.json (Turkish)

[ci skip]

* New translations en.json (Chinese Simplified)

[ci skip]

* style(console): polish controller mode prompt (OpenCloudGaming#747)

* style(console): polish controller mode prompt

* style(console): align prompt with standard modals

---------

Co-authored-by: Capy Agent <agent@capy.test>

* fix(stream): show accurate region and server GPU stats (OpenCloudGaming#748)

* Add desktop bug reporting and session summaries

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Fix bug report timeout and consent handling

* New translations en.json (Romanian)

[ci skip]

* New translations en.json (French)

[ci skip]

* New translations en.json (Spanish)

[ci skip]

* New translations en.json (German)

[ci skip]

* New translations en.json (Japanese)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Dutch)

[ci skip]

* New translations en.json (Polish)

[ci skip]

* New translations en.json (Russian)

[ci skip]

* New translations en.json (Turkish)

[ci skip]

* New translations en.json (Chinese Simplified)

[ci skip]

* New translations en.json (English)

[ci skip]

* feat(catalog): show premium membership requirements

* feat(settings): add compact icon rail variant (OpenCloudGaming#744)

Co-authored-by: Capy Agent <agent@capy.test>

* New translations en.json (Romanian)

[ci skip]

* New translations en.json (French)

[ci skip]

* New translations en.json (Spanish)

[ci skip]

* New translations en.json (German)

[ci skip]

* New translations en.json (Japanese)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Dutch)

[ci skip]

* New translations en.json (Polish)

[ci skip]

* New translations en.json (Russian)

[ci skip]

* New translations en.json (Turkish)

[ci skip]

* New translations en.json (Chinese Simplified)

[ci skip]

* New translations en.json (English)

[ci skip]

* New translations en.json (Romanian)

[ci skip]

* New translations en.json (French)

[ci skip]

* New translations en.json (Spanish)

[ci skip]

* New translations en.json (German)

[ci skip]

* New translations en.json (Japanese)

[ci skip]

* New translations en.json (Korean)

[ci skip]

* New translations en.json (Dutch)

[ci skip]

* New translations en.json (Polish)

[ci skip]

* New translations en.json (Russian)

[ci skip]

* New translations en.json (Turkish)

[ci skip]

* New translations en.json (Chinese Simplified)

[ci skip]

* chore(release): prepare v0.5.4

* fix(gfn): recover catalog requests from proxy failures (OpenCloudGaming#758)

* feat(gfn): use Railway community session proxy (OpenCloudGaming#759)

* chore(release): prepare v0.5.5

* Update star history image source URLs in README

---------

Co-authored-by: Zortos <zortosdev@proton.me>
Co-authored-by: Luiz Eduardo Kowalski <luizeduardokowalski@gmail.com>
Co-authored-by: Zortos <65777760+zortos293@users.noreply.github.com>
Co-authored-by: capy-ai[bot] <230910855+capy-ai[bot]@users.noreply.github.com>
Co-authored-by: Anderson Shindy Oki <anderson.vs.oki@gmail.com>
Co-authored-by: Kiefer <67562560+Kief5555@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Akamiya Chizui <127862333+Chizuui@users.noreply.github.com>
Co-authored-by: Capy Agent <agent@capy.test>
Co-authored-by: Kiefer <kieferlin1001@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

capy Generated by capy.ai

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant