Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 68278822f5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 716f6d7911
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
d3d23d0 to
ec96f56
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
# Conflicts: # src/Exceptionless.Web/ClientApp/src/lib/features/auth/index.svelte.ts
fc0f025 to
a4c506a
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a4c506a146
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bfaa57a3cd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3fdd94da54
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Replace Windows Live authentication with Microsoft Identity Platform v2 and Microsoft Graph in the API and both login UIs. Reuse the existing OAuth client and require authenticated linking when Microsoft email matches an existing account: Graph email alone does not establish account ownership. Svelte now displays the API’s recovery instructions through the shared OAuth error path on login, signup, and account linking.
Validation: 811 frontend tests pass, including eight focused OAuth cases and a real fetch-client regression; Svelte validation (zero type errors/warnings), production build, Release backend build (zero warnings/errors), five isolated auth-handler tests, Angular lint/build, and four Angular callback-state tests pass. Local integration also passed: six Microsoft endpoint, 51 adjacent auth endpoint, and four OpenAPI snapshot tests. Latest main is integrated. Current-head hosted API, client, E2E, Docker, version, and CLA checks pass.
Limitations: The local Aspire API, Svelte app, and Angular server were healthy. Local browser login/logout with seeded credentials passed, and an empty Microsoft exchange returned the expected 422. A separate localhost browser check with a mocked 403 verified the recovery message on login and signup. The Angular browser was blocked by its development certificate in the in-app browser; its state guard has focused tests and a production build. Real Microsoft consent/callback verification requires an Entra app registration and remains the product acceptance gate before merging, despite green CI and a clean merge state.
Approved breaking changes:
/api/v2/auth/liveis replaced by/api/v2/auth/microsoft; the bundled Windows Live client ID is removed. Existing users must sign in through another method or password recovery before linking Microsoft. Login stays hidden until configured.Implementation and setup
User.Read, and create a client secret. SetMicrosoftId=<client-id>;MicrosoftSecret=<secret>;inEX_ConnectionStrings__OAuth.npm run test:unit -- --run src/lib/features/auth/microsoft.test.ts. Pre-push checks:npm run validateandnpm run build.