Skip to content

fix: pass Flarial OAuth2 access tokens into beta API v2 sessions - #4

Closed
aShanki wants to merge 1 commit into
mainfrom
rajesh/f6c9cff12525bfc2831e-oauth2
Closed

aShanki wants to merge 1 commit into
mainfrom
rajesh/f6c9cff12525bfc2831e-oauth2

Conversation

@aShanki

@aShanki aShanki commented Oct 4, 2026

Copy link
Copy Markdown
Member

Beta API v2 activation now accepts Flarial Account OAuth2 tokens, while the served DLL still reads Discord refresh credentials. This supplies the current account access token to the injected DLL through its target-process memory handoff. Refresh tokens stay with the launcher in PasswordVault under Flarial Launcher / Flarial Account; access tokens never go to disk or the DLL credential store.

Refresh account access before beta verification/download, including cache reuse, then inject and publish the token to FlarialBetaAccessTokenHandoff. Release injection keeps its existing behavior. Avoid re-entering the account semaphore on failed refresh. Existing credentials stored under the old Discord slot require a fresh Flarial Account sign-in.

This must ship together with the DLL OAuth2 session change on apiv2. Earlier DLLs lack the handoff export and cannot use this beta launch path.

Validation:

  • Runtime Debug and Release builds passed with zero warnings/errors on .NET 10.0.401 (EnableWindowsTargeting=true).
  • Windows handoff smoke-test runner compiles with zero warnings/errors. Its CI test exercises actual writes into a loaded native module, the 4096-byte boundary, invalid tokens and an invalid target process.
  • Live Minecraft launch and real OAuth2 session activation remain to be tested on Windows before beta rollout.

@aShanki aShanki closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant