Skip to content

fix(antigravity): launch the managed agy with a CSRF token - #141

Merged
prakersh merged 1 commit into
mainfrom
fix/antigravity-cli-csrf
Sep 28, 2026
Merged

prakersh merged 1 commit into
mainfrom
fix/antigravity-cli-csrf

Conversation

@prakersh

Copy link
Copy Markdown
Contributor

Fixes #140.

agy's language server rejects Connect-RPC calls without a CSRF token. On Windows it enforces one even when none was given at launch, so the managed agy session never became ready and every Antigravity CLI poll failed with "quota service did not become ready" after 90s.

Change

  • Each managed agy launch gets a fresh random --csrf_token (16 bytes, hex). A relaunch gets a new one.
  • The token is sent as X-Codeium-Csrf-Token on the readiness probe, the quota summary and user status calls, and the health check.
  • The token is never logged.

Verification

agy's language server rejects Connect-RPC calls that lack a CSRF token.
On Windows it enforces one even when none was given, so the quota
service never became ready and every poll failed after 90s.

Start agy with a random --csrf_token per launch and send it as
X-Codeium-Csrf-Token on the probe and every call.

Fixes #140
@codecov

codecov Bot commented Sep 28, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 40.90909% with 13 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
internal/api/antigravity_cli.go 40.90% 12 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

@prakersh
prakersh merged commit 8a755e8 into main Sep 28, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] Windows: Antigravity CLI collector fails with "quota service did not become ready" due to missing CSRF token

1 participant