test(qa): observe Codex auth failure lifecycle events

Match the failed-session snapshot on sessions.changed, the native lifecycle
metadata owner. session.message projects transcript changes independently and
does not guarantee the settled run state. Preserve exact run/session matching,
bounded recovery text across chat, agent.wait and history, and the prohibition
on starting an app-server turn after the selected credential is removed.

The stale event predicate was introduced by 876e8cdb24 (#149784). Reproduced
its line-533 failure on main baf2edda0d in the AWS lab, then verified the
three-line correction with 5 passing auth, approval and migration E2E cases
and 199 Gateway event-owner tests. Core typecheck, formatting and autoreview
through P2 passed. Auth proof test time: 53.9s; target recovery case: 16.1s
versus 21.0s before the fix, including the obsolete five-second event wait.

The baseline also hit an unrelated usage.status Timeout in the first auth
case. It did not recur in the patched family run; this test-only change does
not claim to repair that timeout. No production or protocol behavior changed.
This commit is contained in:
Peter Steinberger 2026-09-28 07:04:05 -07:00
parent 3e0def1451
commit eed9d9bf22
No known key found for this signature in database

View file

@ -521,7 +521,7 @@ describe("Codex auth product proof", () => {
expect(
events.find(
(event) =>
event.event === "session.message" &&
event.event === "sessions.changed" &&
event.payload !== null &&
typeof event.payload === "object" &&
(event.payload as { sessionKey?: unknown }).sessionKey === sessionKey &&
@ -555,7 +555,7 @@ describe("Codex auth product proof", () => {
);
const lifecycleEvent = events.find(
(event) =>
event.event === "session.message" &&
event.event === "sessions.changed" &&
event.payload !== null &&
typeof event.payload === "object" &&
(event.payload as { sessionKey?: unknown }).sessionKey === sessionKey &&
@ -563,7 +563,7 @@ describe("Codex auth product proof", () => {
(event.payload as { session?: { status?: unknown } }).session?.status === "failed",
);
expectBoundedMissingProfileRecovery(finalEvent?.payload);
// Native lifecycle publishes the failed session snapshot before broadcasting chat.error.
// Lifecycle metadata belongs to sessions.changed; transcript delivery has independent timing.
expectBoundedMissingProfileRecovery(
(lifecycleEvent?.payload as { session?: { lastRunError?: unknown } } | undefined)?.session
?.lastRunError,