Skip to content

fix(claude-code): authorize login and check macOS terminal launch - #6185

Closed
Eloitor wants to merge 3 commits into
tinyhumansai:mainfrom
Eloitor:fix/claude-login-terminal-permission
Closed

Eloitor wants to merge 3 commits into
tinyhumansai:mainfrom
Eloitor:fix/claude-login-terminal-permission

Conversation

@Eloitor

@Eloitor Eloitor commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Permit the Claude Code sign-in command from the main desktop window.
  • Report macOS terminal launch failures instead of treating a successful osascript spawn as a successful launch.
  • Bound the asynchronous launcher wait to 30 seconds and terminate the launcher on timeout.

Problem

On macOS, clicking Claude Code Sign in can show “Could not open the login terminal” before Rust runs: claude_code_login_launch is registered but absent from the app permissions. After permission is granted, the existing launcher reports success even when AppleScript exits unsuccessfully, for example after an Automation denial.

This complements #5790. That PR fixes the authentication command and translated hints; it does not add the Tauri permission or wait for the launcher result.

Solution

A dedicated desktop capability allows only claude_code_login_launch, only in the main window. The macOS branch awaits /usr/bin/osascript using Tokio, checks the exit status, and applies a 30-second timeout with kill_on_drop. Tests exercise the ACL wiring, successful and unsuccessful exit statuses, missing executables, and timeout. The release smoke checklist covers the real macOS Automation prompt.

Submission Checklist

If a section does not apply to this change, mark the item as N/A with a one-line reason. Do not delete items.

  • Tests added or updated (happy path + at least one failure / edge case).
  • Diff coverage ≥ 80% — coverage gate remains required; regression tests cover the launcher branches. Local numerical coverage is unavailable because cargo-llvm-cov is not installed; CI must verify the percentage before merge.
  • N/A: Coverage matrix unchanged; behavior-only correction to existing login.
  • N/A: No feature IDs added or removed.
  • No new external network dependencies introduced; process tests run local stand-in commands without contacting authentication services.
  • Manual smoke checklist updated in docs/RELEASE-MANUAL-SMOKE.md for macOS Terminal/Automation behavior.
  • N/A: No separate issue to close; this complements fix(claude-code): launch claude auth login, not the obsolete claude login #5790 and references Claude Code login launcher uses the wrong authentication command #5710 without claiming to close its command bug.

Impact

Desktop permission applies to Linux, macOS, and Windows. The launcher wait changes macOS only. No migration or configuration change. Other windows receive no new permission. The existing Windows/Linux launch strategy and authentication command remain unchanged; #5790 owns the command correction.

Related


AI Authored PR Metadata (required for Codex/Linear PRs)

Linear Issue

  • Key: N/A
  • URL: N/A

Commit & Branch

  • Branch: fix/claude-login-terminal-permission
  • Commit SHA: e1884d8

Validation Run

  • Targeted Prettier checks for the capability JSON and smoke checklist.
  • N/A: pnpm typecheck; no TypeScript changes.
  • Focused tests: cargo test --manifest-path app/src-tauri/Cargo.toml --lib --no-default-features --features gateways claude_code::tests — 4 passed, 0 failed.
  • Rust fmt/check: rustfmt --edition 2021 --check on changed Rust files.
  • Tauri fmt/check: cargo fmt --manifest-path app/src-tauri/Cargo.toml --check and cargo clippy --manifest-path app/src-tauri/Cargo.toml --lib --no-default-features --features gateways -- -D warnings passed. The core dependency emitted a pre-existing unused-import warning; the shell check completed successfully.

Validation Blocked

  • command: cargo llvm-cov
  • error: cargo-llvm-cov is not installed locally.
  • impact: numerical diff coverage must be confirmed in CI. Real Automation UI remains a documented release smoke check, not a claimed automated test.

Behavior Changes

  • Intended behavior change: authorize the existing main-window login command and return failure when the macOS terminal launcher fails or times out.
  • User-visible effect: Sign in reaches Rust, and a failed Terminal launch is no longer acknowledged as successful.

Parity Contract

  • Legacy behavior preserved: existing command arguments and Windows/Linux launch behavior.
  • Guard/fallback/dispatch parity checks: main-window-only permission; process success, failure, missing launcher, and timeout tests.

Duplicate / Superseded PR Handling

Summary by CodeRabbit

  • New Features

    • Added Claude Code sign-in support from the main window’s settings.
    • Added platform-specific permission handling for launching the Claude Code sign-in terminal.
  • Bug Fixes

    • Improved macOS sign-in reliability by reporting launch failures clearly.
    • The app now remains responsive when macOS Automation access is denied.
    • Unanswered permission prompts stop waiting after 30 seconds.
  • Documentation

    • Added macOS release smoke-check guidance for validating the Claude Code sign-in flow.

@Eloitor
Eloitor requested a review from a team September 10, 2026 09:36
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-11T22:51:13.877414Z ea0a1a4 New commits
🔒 Security Review ✅ Completed 2026-09-11T16:29:11.383944Z a6afd62 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: b074de02-f4e9-4e87-a6b2-21d5df370cd4

📥 Commits

Reviewing files that changed from the base of the PR and between e1884d8 and a6afd62.

📒 Files selected for processing (3)
  • app/src-tauri/src/claude_code.rs
  • app/src-tauri/src/claude_code_tests.rs
  • docs/RELEASE-MANUAL-SMOKE.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • docs/RELEASE-MANUAL-SMOKE.md

Included review availability: Your plan provides up to 10 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The Claude Code login command now uses asynchronous macOS Terminal launching with timeout and failure handling. New Tauri permission wiring, automated tests, and a macOS release smoke check cover the flow.

Changes

Claude Code login flow

Layer / File(s) Summary
Permission and capability wiring
app/src-tauri/permissions/allow-claude-code-login.toml, app/src-tauri/capabilities/claude-code-login.json, app/src-tauri/src/claude_code_tests.rs
The main window can invoke claude_code_login_launch on Linux, macOS, and Windows. Tests verify the permission, capability, and command registration.
Asynchronous Terminal launch
app/src-tauri/src/claude_code.rs
The command is asynchronous on macOS. The implementation waits for osascript, enforces a 30-second timeout, terminates dropped processes, and reports spawn or nonzero-exit failures.
Launch validation and release checks
app/src-tauri/src/claude_code_tests.rs, docs/RELEASE-MANUAL-SMOKE.md
Tests cover launcher arguments and successful, failed, missing, and timed-out processes. The release checklist covers granted, denied, and unanswered macOS Automation prompts.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant MainWindowSettings
  participant claude_code_login_launch
  participant osascript
  MainWindowSettings->>claude_code_login_launch: invoke login command
  claude_code_login_launch->>osascript: launch Terminal.app asynchronously
  osascript-->>claude_code_login_launch: return exit status or timeout
  claude_code_login_launch-->>MainWindowSettings: return success or launch error
Loading

Suggested reviewers: senamakel

Merge Risk: ⚪ Minimal · up to ea0a1

The sign-in launch flow is scoped to the main window and handles successful, failed, missing, and timed-out macOS launcher outcomes without an identified merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main changes: authorizing Claude Code login and validating macOS terminal launch behavior.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 15 functions across 2 files. (1 skipped: 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

I hop through commands with a bright little cheer
The Terminal opens, and the path is clear
If waiting goes long, a timeout rings
Tests guard each launcher and all its small things
Permissions unlock the sign-in door
macOS smoke checks watch the flow once more

Comment @coderabbitai help to get the list of available commands.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

$0.0000 · 0 in / 0 out

@tinysweeper

tinysweeper Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

How this change flows

1 changed behaviour across 4 relationships. 3 surrounding behaviours are shown (60 graph nodes walked). 22 further behaviours left out to keep the diagram readable.

flowchart LR
  n0["claude_code_login_launch<br/>changed"]:::changed
  n1["format"]:::impacted
  n2["map_err"]:::impacted
  n3["apply_app_update"]:::impacted
  n0 -->|calls| n1
  n0 -->|calls| n2
  n3 -->|calls| n1
  n3 -->|calls| n2
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading

Green: changed behaviour. Grey: surrounding behaviour. Arrows name the call, use, implementation, or test relationship. Orange: has findings. Red: has a finding that blocks the merge.

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot added the priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. label Sep 10, 2026
coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 10, 2026
@deepc0py

Copy link
Copy Markdown

pls merge this, wanna use Claude

@senamakel senamakel self-assigned this Sep 11, 2026
# Conflicts:
#	app/src-tauri/src/claude_code.rs
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@senamakel
senamakel requested a review from M3gA-Mind September 12, 2026 02:32
@senamakel

Copy link
Copy Markdown
Member

@tinyhumansai/maintainers @M3gA-Mind can you guys check on this?

@senamakel senamakel left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tinyhumansai/maintainers @M3gA-Mind can you guys check on this?

test this live and lmk if this looks good.

@senamakel senamakel closed this Sep 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants