Skip to content

feat: add proactive cf_clearance/User-Agent hint to grok-web connection dialog (#7567)#7713

Merged
diegosouzapw merged 2 commits into
release/v3.8.49from
feat/7567-grokweb-ua-hint
Jul 19, 2026
Merged

feat: add proactive cf_clearance/User-Agent hint to grok-web connection dialog (#7567)#7713
diegosouzapw merged 2 commits into
release/v3.8.49from
feat/7567-grokweb-ua-hint

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Summary

Adds a grok-web-specific hintKey (grokWebCookieHint) to the Add-connection dialog, replacing the generic "Required cookie: sso + sso-rw…" copy with step-by-step guidance for the real failure mode reported in #7567.

grok-web's cf_clearance cookie is pinned to the IP, User-Agent, and TLS fingerprint of the browser that earned it — pasting it from a different machine/IP produces a 403 that is intentional Cloudflare behavior, not a bug. This PR does not change that 403 error text; it makes the fix discoverable in the UI: paste sso/sso-rw, then fill the existing Custom User-Agent field under Advanced Settings with the exact browser User-Agent, and reuse the same IP/proxy.

Follows the exact hintKey/hintFallback override mechanism already used by t3-web (#5465) and lmarena — no schema change, no executor change, no change to open-sse/services/grokTlsClient.ts.

Changes

  • src/shared/providers/webSessionCredentials.ts — add hintKey: "grokWebCookieHint" + hintFallback to the grok-web entry
  • src/i18n/messages/en.json (source of truth) + src/i18n/messages/pt-BR.json (mirrored) — new grokWebCookieHint string
  • tests/unit/grokweb-cookie-ua-hint-7567.test.ts — new behavior test (5 cases): hintKey wiring, hint content (User-Agent/IP/cf_clearance), no fallback to generic circular hint, edit-flow regression guard, hintFallback-when-translation-missing
  • changelog.d/features/7567-grokweb-ua-hint.md

How it was validated (TDD, Hard Rule #18)

Confirmed the test fails against the base branch (no hintKey on grok-web there — git show origin/release/v3.8.49:src/shared/providers/webSessionCredentials.ts), then wired the hintKey and confirmed all 5 cases pass:

node --import tsx/esm --test tests/unit/grokweb-cookie-ua-hint-7567.test.ts
✔ grok-web requirement carries the grokWebCookieHint override (#7567)
✔ grok-web add-connection hint explains cf_clearance IP/UA/TLS pinning and the Custom User-Agent fix (#7567)
✔ grok-web add-connection hint does not fall back to the generic circular cookie hint (#7567)
✔ grok-web edit-connection flow is unaffected by the new hintKey (#7567 regression guard)
✔ grok-web hintFallback is used verbatim when the translation key is missing (#7567)
ℹ tests 5, pass 5, fail 0

Gates run green: check-test-discovery.mjs, typecheck:core, typecheck:noimplicit:core (clean on changed files; remaining errors are pre-existing on unrelated files), eslint --suppressions-location (0 new errors on changed files), check:complexity-ratchets (baseline unchanged), check-file-size.mjs (no on changed files), check:cycles, check:docs-sync. npm run i18n:check-ui-coverage shows 37 locales already below the 80% threshold — pre-existing systemic translation-pipeline lag unrelated to this 1-key change (both en.json/source-of-truth and pt-BR.json/ratcheted are updated; remaining locales backfill via the existing i18n:run pipeline, matching how t3ChatWebCookieHint/lmarenaWebCookieHint shipped).

npm run test:coverage intentionally not run locally (heaviest gate, shared/loaded box) — this is additive-only (new file + 2 new i18n keys + 1 new object field), CI runs it authoritatively.

Closes #7567

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@diegosouzapw
diegosouzapw merged commit e5842c7 into release/v3.8.49 Jul 19, 2026
13 of 20 checks passed
@diegosouzapw
diegosouzapw deleted the feat/7567-grokweb-ua-hint branch July 19, 2026 21:00
diegosouzapw added a commit that referenced this pull request Jul 19, 2026
… hint (base-red unblock)

#7713 added hintKey/hintFallback (proactive cf_clearance/User-Agent guidance) to the
grok-web web-session metadata without touching this test's deepEqual, turning unit
shard 2/4 red for every PR on release/v3.8.49. Rewritten in the same contract-only
style the file already uses for lmarena: structural fields stay strictly asserted,
the hint asserts key + intent (cf_clearance / User-Agent) without freezing operator
copy. Net stronger than before — the old assertion never checked the hint at all.
diegosouzapw added a commit that referenced this pull request Jul 19, 2026
…rift again (#7798)

* docs(free-tiers): correct the headline to the 1.37B the catalog actually computes

The 2026-06-17 honesty correction landed 1.54B, but v3.8.42 reclassified longcat
from a 150M/mo recurring grant to a one-time 10M signup credit and the doc was
never resynced. Verified against computeFreeModelTotals() at every release tag
from 3.8.13 to HEAD: no free provider was lost by mistake.

* feat(quality): gate the free-tier headline against the live catalog

The README headlined ~1.6B free tokens/mo for seven releases after the catalog had
already been corrected down to 1.37B. No gate watched that number, so the drift was
invisible — check:docs-counts only covered providers, locales, executors, strategies,
oauth, a2a skills and cloud agents.

Adds a STRICT check that runs computeFreeModelTotals() (the same function behind
/api/free-tier/summary) and fails the build when README.md or FREE_TIERS.md publish a
headline that no longer rounds to it. Degrades to a skip if tsx is unavailable rather
than going falsely red.

The extractor is a whitelist: the theoretical ceiling (~10B), the historical ~1.94B and
per-model rows (~1.00B) are legitimate figures that must never trip the gate.

Also adds the biweekly-audit note under the README headline, so readers know the number
moves both ways and is what the catalog computes rather than a rounded-up best case.

* feat(quality): extend the counts gate to engines, MCP tools/scopes and CLI tools

The v3.8.49 audit found four more numbers that had silently drifted, all invisible to
CI because check:docs-counts only watched providers/locales/executors/strategies/oauth/
a2a/cloud-agents: 10->11 compression engines, 94->104 MCP tools, 30->31 scopes,
26->33 CLI tools.

Adds a generic makeNumberClaimValidator that reads every fact in ONE tsx subprocess via
the same functions the app serves (ENGINE_IDS, countUniqueMcpTools, the live scope union,
CLI_TOOLS) — never a hardcoded copy — with DATA_DIR redirected to a throwaway dir so
importing the MCP tool modules can't touch the operator's SQLite. Each check declares a
skip pattern so legitimate non-aggregate figures never trip it: per-module tool counts
('Memory tool definitions (3 tools)') and the CLI catalog total sitting next to the MCP
total. Degrades to a skip when tsx is unavailable rather than a false red.

7 new unit tests (all pass) covering the exact stale values this audit found and proving
per-module counts are ignored.

* docs(diagrams): sync the animated cards and mermaid sources to the audited v3.8.49 numbers

The README text was fixed in #7795 but the SVG cards and mermaid sources kept the
old numbers baked in — exactly the drift the readers see first.

- compression-pipeline.svg: 10 -> 11 engine cells (Omniglyph added as #8, matching
  the README alt text), re-spaced 51px cells, highlight cascade re-timed, the
  Caveman kill-dot repositioned inside its cell, default-stack bracket recentered
- free-tier-budget.svg: bar and grid rebuilt from computeFreeModelTotals() — 21 -> 19
  countable pools (LongCat-2.0 moved to one-time credit, Inclusion provider removed),
  huggingchat entry is now ERNIE 4.5 VL, kiro shows Claude Sonnet 4.5, signup credits
  ~616M -> ~626M (+longcat 10M pill), aria said 'about 1.6 billion' -> 1.4/2.0,
  lower sections shifted up 30px (viewBox 872 -> 842)
- promise-pillars.svg: 26 -> 33 coding agents
- mcp-tools-94.mmd -> mcp-tools-104.mmd: real per-collection unique contributions
  (42 base + memory 3 + skill 4 + githubSkill 3 + pool 6 + gamification 8 + plugin 8
  + notion 6 + obsidian 22 + compression 2), exported SVG regenerated, zh-CN ref synced
- request-pipeline.mmd: 17 -> 18 strategies, exported SVG regenerated
- README free-tier alt + docs/diagrams/README.md synced to the same numbers

Both edited cards pass validate-svg.sh and were render-verified at 4 timestamps
(animation runs; first frame is the finished composition).

* docs(env): register the 4 env vars missing from the .env.example contract (base-red unblock)

FREE_PROXY_AUTO_SYNC_ENABLED / FREE_PROXY_AUTO_SYNC_INTERVAL_MS (scheduler.ts) and
MITM_ROOT_CA_ENABLED / MITM_CERT_MODE (mitm manager/server, #6684) landed on
release/v3.8.49 without their .env.example + ENVIRONMENT.md entries, turning the
docs-gates job red for every PR on the branch. Documented with their real defaults
and the set-by-manager caveat for MITM_CERT_MODE.

* fix(dashboard): narrow the Codex session ParseResult with an equality check (base-red unblock)

#7725 landed 'if (!result.ok)' in OAuthModal — under this repo's strict:false,
tsc 6 only narrows a discriminated union on the equality form, so the negation
raised TS2339 (Property 'error' does not exist on ParseResult) and turned the
dashboard-typecheck gate red for every PR on release/v3.8.49. Runtime semantics
are identical (ok is a strict boolean).

Also ratchets the frozen baseline down 260 -> 259: the real fix here plus 3
baselined errors that other merges already fixed (CostOverviewTab TS2304,
SidebarTab TS2322, FreePoolTab TS2304). Baseline diff is deletions-only.

* fix(dashboard): keep OAuthModal within the frozen file-size cap

The narrowing comment pushed the file to 1032 > 1030 frozen; the rationale lives
in the previous commit message and the dashboard-typecheck gate itself guards the
'=== false' form from being refactored back to '!result.ok'.

* test(providers): align the grok-web credential assertion with the #7567 hint (base-red unblock)

#7713 added hintKey/hintFallback (proactive cf_clearance/User-Agent guidance) to the
grok-web web-session metadata without touching this test's deepEqual, turning unit
shard 2/4 red for every PR on release/v3.8.49. Rewritten in the same contract-only
style the file already uses for lmarena: structural fields stay strictly asserted,
the hint asserts key + intent (cf_clearance / User-Agent) without freezing operator
copy. Net stronger than before — the old assertion never checked the hint at all.

* test(golden): regenerate translate-path snapshot for the notion-web endpoint move (base-red unblock)

#7768 switched notion-web to app.notion.com without regenerating the golden,
turning unit shard 3/4 red for every PR on release/v3.8.49. Two-line regen,
reflects the deliberate production change.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(providers): grok-web (subscription) fails to validate cookie with (anti-bot/Cloudflare block)

1 participant