feat: add proactive cf_clearance/User-Agent hint to grok-web connection dialog (#7567)#7713
Merged
Merged
Conversation
…eb connection dialog (#7567)
Contributor
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
diegosouzapw
added a commit
that referenced
this pull request
Jul 19, 2026
… hint (base-red unblock) #7713 added hintKey/hintFallback (proactive cf_clearance/User-Agent guidance) to the grok-web web-session metadata without touching this test's deepEqual, turning unit shard 2/4 red for every PR on release/v3.8.49. Rewritten in the same contract-only style the file already uses for lmarena: structural fields stay strictly asserted, the hint asserts key + intent (cf_clearance / User-Agent) without freezing operator copy. Net stronger than before — the old assertion never checked the hint at all.
diegosouzapw
added a commit
that referenced
this pull request
Jul 19, 2026
…rift again (#7798) * docs(free-tiers): correct the headline to the 1.37B the catalog actually computes The 2026-06-17 honesty correction landed 1.54B, but v3.8.42 reclassified longcat from a 150M/mo recurring grant to a one-time 10M signup credit and the doc was never resynced. Verified against computeFreeModelTotals() at every release tag from 3.8.13 to HEAD: no free provider was lost by mistake. * feat(quality): gate the free-tier headline against the live catalog The README headlined ~1.6B free tokens/mo for seven releases after the catalog had already been corrected down to 1.37B. No gate watched that number, so the drift was invisible — check:docs-counts only covered providers, locales, executors, strategies, oauth, a2a skills and cloud agents. Adds a STRICT check that runs computeFreeModelTotals() (the same function behind /api/free-tier/summary) and fails the build when README.md or FREE_TIERS.md publish a headline that no longer rounds to it. Degrades to a skip if tsx is unavailable rather than going falsely red. The extractor is a whitelist: the theoretical ceiling (~10B), the historical ~1.94B and per-model rows (~1.00B) are legitimate figures that must never trip the gate. Also adds the biweekly-audit note under the README headline, so readers know the number moves both ways and is what the catalog computes rather than a rounded-up best case. * feat(quality): extend the counts gate to engines, MCP tools/scopes and CLI tools The v3.8.49 audit found four more numbers that had silently drifted, all invisible to CI because check:docs-counts only watched providers/locales/executors/strategies/oauth/ a2a/cloud-agents: 10->11 compression engines, 94->104 MCP tools, 30->31 scopes, 26->33 CLI tools. Adds a generic makeNumberClaimValidator that reads every fact in ONE tsx subprocess via the same functions the app serves (ENGINE_IDS, countUniqueMcpTools, the live scope union, CLI_TOOLS) — never a hardcoded copy — with DATA_DIR redirected to a throwaway dir so importing the MCP tool modules can't touch the operator's SQLite. Each check declares a skip pattern so legitimate non-aggregate figures never trip it: per-module tool counts ('Memory tool definitions (3 tools)') and the CLI catalog total sitting next to the MCP total. Degrades to a skip when tsx is unavailable rather than a false red. 7 new unit tests (all pass) covering the exact stale values this audit found and proving per-module counts are ignored. * docs(diagrams): sync the animated cards and mermaid sources to the audited v3.8.49 numbers The README text was fixed in #7795 but the SVG cards and mermaid sources kept the old numbers baked in — exactly the drift the readers see first. - compression-pipeline.svg: 10 -> 11 engine cells (Omniglyph added as #8, matching the README alt text), re-spaced 51px cells, highlight cascade re-timed, the Caveman kill-dot repositioned inside its cell, default-stack bracket recentered - free-tier-budget.svg: bar and grid rebuilt from computeFreeModelTotals() — 21 -> 19 countable pools (LongCat-2.0 moved to one-time credit, Inclusion provider removed), huggingchat entry is now ERNIE 4.5 VL, kiro shows Claude Sonnet 4.5, signup credits ~616M -> ~626M (+longcat 10M pill), aria said 'about 1.6 billion' -> 1.4/2.0, lower sections shifted up 30px (viewBox 872 -> 842) - promise-pillars.svg: 26 -> 33 coding agents - mcp-tools-94.mmd -> mcp-tools-104.mmd: real per-collection unique contributions (42 base + memory 3 + skill 4 + githubSkill 3 + pool 6 + gamification 8 + plugin 8 + notion 6 + obsidian 22 + compression 2), exported SVG regenerated, zh-CN ref synced - request-pipeline.mmd: 17 -> 18 strategies, exported SVG regenerated - README free-tier alt + docs/diagrams/README.md synced to the same numbers Both edited cards pass validate-svg.sh and were render-verified at 4 timestamps (animation runs; first frame is the finished composition). * docs(env): register the 4 env vars missing from the .env.example contract (base-red unblock) FREE_PROXY_AUTO_SYNC_ENABLED / FREE_PROXY_AUTO_SYNC_INTERVAL_MS (scheduler.ts) and MITM_ROOT_CA_ENABLED / MITM_CERT_MODE (mitm manager/server, #6684) landed on release/v3.8.49 without their .env.example + ENVIRONMENT.md entries, turning the docs-gates job red for every PR on the branch. Documented with their real defaults and the set-by-manager caveat for MITM_CERT_MODE. * fix(dashboard): narrow the Codex session ParseResult with an equality check (base-red unblock) #7725 landed 'if (!result.ok)' in OAuthModal — under this repo's strict:false, tsc 6 only narrows a discriminated union on the equality form, so the negation raised TS2339 (Property 'error' does not exist on ParseResult) and turned the dashboard-typecheck gate red for every PR on release/v3.8.49. Runtime semantics are identical (ok is a strict boolean). Also ratchets the frozen baseline down 260 -> 259: the real fix here plus 3 baselined errors that other merges already fixed (CostOverviewTab TS2304, SidebarTab TS2322, FreePoolTab TS2304). Baseline diff is deletions-only. * fix(dashboard): keep OAuthModal within the frozen file-size cap The narrowing comment pushed the file to 1032 > 1030 frozen; the rationale lives in the previous commit message and the dashboard-typecheck gate itself guards the '=== false' form from being refactored back to '!result.ok'. * test(providers): align the grok-web credential assertion with the #7567 hint (base-red unblock) #7713 added hintKey/hintFallback (proactive cf_clearance/User-Agent guidance) to the grok-web web-session metadata without touching this test's deepEqual, turning unit shard 2/4 red for every PR on release/v3.8.49. Rewritten in the same contract-only style the file already uses for lmarena: structural fields stay strictly asserted, the hint asserts key + intent (cf_clearance / User-Agent) without freezing operator copy. Net stronger than before — the old assertion never checked the hint at all. * test(golden): regenerate translate-path snapshot for the notion-web endpoint move (base-red unblock) #7768 switched notion-web to app.notion.com without regenerating the golden, turning unit shard 3/4 red for every PR on release/v3.8.49. Two-line regen, reflects the deliberate production change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a
grok-web-specifichintKey(grokWebCookieHint) to the Add-connection dialog, replacing the generic "Required cookie: sso + sso-rw…" copy with step-by-step guidance for the real failure mode reported in #7567.grok-web's
cf_clearancecookie is pinned to the IP, User-Agent, and TLS fingerprint of the browser that earned it — pasting it from a different machine/IP produces a403that is intentional Cloudflare behavior, not a bug. This PR does not change that 403 error text; it makes the fix discoverable in the UI: pastesso/sso-rw, then fill the existing Custom User-Agent field under Advanced Settings with the exact browser User-Agent, and reuse the same IP/proxy.Follows the exact
hintKey/hintFallbackoverride mechanism already used byt3-web(#5465) andlmarena— no schema change, no executor change, no change toopen-sse/services/grokTlsClient.ts.Changes
src/shared/providers/webSessionCredentials.ts— addhintKey: "grokWebCookieHint"+hintFallbackto thegrok-webentrysrc/i18n/messages/en.json(source of truth) +src/i18n/messages/pt-BR.json(mirrored) — newgrokWebCookieHintstringtests/unit/grokweb-cookie-ua-hint-7567.test.ts— new behavior test (5 cases): hintKey wiring, hint content (User-Agent/IP/cf_clearance), no fallback to generic circular hint, edit-flow regression guard, hintFallback-when-translation-missingchangelog.d/features/7567-grokweb-ua-hint.mdHow it was validated (TDD, Hard Rule #18)
Confirmed the test fails against the base branch (no
hintKeyongrok-webthere —git show origin/release/v3.8.49:src/shared/providers/webSessionCredentials.ts), then wired thehintKeyand confirmed all 5 cases pass:Gates run green:
check-test-discovery.mjs,typecheck:core,typecheck:noimplicit:core(clean on changed files; remaining errors are pre-existing on unrelated files),eslint --suppressions-location(0 new errors on changed files),check:complexity-ratchets(baseline unchanged),check-file-size.mjs(no✗on changed files),check:cycles,check:docs-sync.npm run i18n:check-ui-coverageshows 37 locales already below the 80% threshold — pre-existing systemic translation-pipeline lag unrelated to this 1-key change (bothen.json/source-of-truth andpt-BR.json/ratcheted are updated; remaining locales backfill via the existingi18n:runpipeline, matching howt3ChatWebCookieHint/lmarenaWebCookieHintshipped).npm run test:coverageintentionally not run locally (heaviest gate, shared/loaded box) — this is additive-only (new file + 2 new i18n keys + 1 new object field), CI runs it authoritatively.Closes #7567