Add local OpenCompany Tauri desktop app - #525
Conversation
Co-authored-by: Medulla <medulla@tinyhumans.ai>
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 40 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (4)
📒 Files selected for processing (12)
Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d667e44af3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| let server = tokio::spawn(async move { axum::serve(listener, app).await }); | ||
| Ok(DesktopRuntime { | ||
| config: DesktopConfig { | ||
| api_url: format!("http://{address}"), |
There was a problem hiding this comment.
Keep desktop authentication on a same-site origin
In the packaged desktop flow, this loopback URL makes every console request cross-site (http://tauri.localhost → http://127.0.0.1:<port>). Although OpenCompanyClient uses credentials: "include", the session minted by auth/verify is explicitly SameSite=Lax in src/server/users/cookie.rs, so the webview cannot establish/send it on these cross-site fetches; verification may return successfully, but the following authenticated status request receives 401 and the desktop console cannot remain signed in. The desktop API should be exposed same-site or use an authentication mechanism compatible with this native cross-origin boundary.
Useful? React with 👍 / 👎.
| }) | ||
| .with_home(home.into()) | ||
| .with_cors(CorsConfig { | ||
| allowed_origins: vec![TAURI_WEBVIEW_ORIGIN.to_string()], |
There was a problem hiding this comment.
Allow the configured Tauri development origin
With frontend/src-tauri/tauri.conf.json configured to load http://localhost:5173 during tauri dev, the webview sends that value as its Origin, but this runtime permits only http://tauri.localhost. The bootstrap's JSON POST therefore fails its CORS preflight, the catch block silently falls through, and the console mounts without the random loopback API URL, making the newly added tauri:dev command unusable. Include the committed devUrl origin when running the development shell.
Useful? React with 👍 / 👎.
Summary
Validation
npm run typechecknpm run buildcargo test --test desktop_e2ecargo check -p opencompany-desktopnpm run tauri:build -- --debug --no-bundle