Ask before a pasted secret replaces the signed-in account - #1864
Conversation
Pasting an agent secret for a different agent than the signed-in account's used to end that account's session straight away and then show a toast, "Signed out of your account here — that secret belongs to a different one". The session is shared with the portal, so this signed people out of atomic.place too, and they only learned why afterwards. The sign-in now stops first on a screen that names the signed-in account, shows both agents, and offers "Stay signed in as <email>" or "Use this secret and sign out". The session is only ended after the second choice.
browser/CHANGELOG.md and the four .po catalogs conflicted; both sides' entries are kept.
Only browser/CHANGELOG.md conflicted; both sides' entries are kept.
|
Run 4749 on d24311a (this PR with develop 58408ac merged in) is red on one e2e test, and it failed all three attempts: This test looks like it belongs to this PR rather than develop:
Handed to the thread that owns this PR. I'm not re-running, because three failed attempts in one run is not a flake. Generated by Claude Code |
|
The red
No fix exists for it yet. Develop run 4750 will show whether it's load or a regression on develop. Generated by Claude Code |
Brings in the raised test walls for canvas-live-update and filePicker.
Before: signed in to atomic.place as joep@ontola.io, pasting an agent secret for another agent (an older atomicdata.dev agent, or a local node's) signed that account out right away, including out of atomic.place, since the portal and the app share the session. Only afterwards did a toast say "Signed out of your account here — that secret belongs to a different one", without saying which account or which agent.
After: the sign-in stops on "This secret is for a different account". It names the signed-in account, shows its agent next to the secret's agent, and offers "Stay signed in as joep@ontola.io" (the default) or "Use this secret and sign out". The session is only ended after the second choice, and the toast then names the account that was signed out.
How:
secretAccountConflict()inrecovery.tscompares the account backup's agent with the secret's agent throughsameAgent, sodid:ad:andatomic:spellings still count as one agent.handleSignInWithSecretinGettingStartedFlow.tsxruns that check before it stores or activates the agent, shows the newsecret-conflictstep when they differ, and callsreleaseConflictingPortalSessiononly after the user confirms. There are unit tests for the helper and component tests for both choices and for the matching-agent path. The two conflict tests fail on develop. The.pocatalogs were extracted withwuchalewithout--clean.Generated by Claude Code