Skip to content

Hosted: always show the consent screen so Claude completes sign-in - #20

Merged
alex-brecher merged 1 commit into
mainfrom
fix/claude-always-consent
Sep 28, 2026
Merged

alex-brecher merged 1 commit into
mainfrom
fix/claude-always-consent

Conversation

@alex-brecher

Copy link
Copy Markdown
Owner

Claude never called /token for sign-ins that skipped consent via a remembered approval (10 of 10 on 2026-09-28, audit DB), while all consent-path sign-ins issued tokens (Claude 3/3, ChatGPT 3/3). This removes the remembered-approval shortcut so every OAuth sign-in shows the consent screen. Tests: npm test, 213 pass.

Claude dropped every authorization code that the server returned by a direct
302 at the end of the Shopify sign-in chain for an app approved earlier (it
never called /token: 10 of 10 on 2026-09-28), while every sign-in that went
through the consent screen issued a token. Approvals are no longer remembered;
the consent screen shows on every OAuth sign-in. Regression test updated.
@alex-brecher
alex-brecher merged commit 074d76d into main Sep 28, 2026
11 of 12 checks passed
@alex-brecher
alex-brecher deleted the fix/claude-always-consent branch September 28, 2026 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant