From 876959f84bd2ae99d4c705cea0d204d3d1326ec0 Mon Sep 17 00:00:00 2001 From: "kiloconnect[bot]" <240665456+kiloconnect[bot]@users.noreply.github.com> Date: Fri, 13 Mar 2026 15:12:54 +0000 Subject: [PATCH] fix: remove redundant vscode.env.openExternal call during login flow The login flow had two browser-opening mechanisms firing simultaneously: 1. The backend's authenticateWithDeviceAuthTUI() opens the browser via the 'open' npm package during authorize() 2. handleLogin() called vscode.env.openExternal() which shows a VS Code trust dialog AND opens a second browser tab The trust dialog from vscode.env.openExternal() persisted after the user completed authentication in the browser, since nothing dismissed it. Remove the vscode.env.openExternal() call. The backend already opens the browser, and the DeviceAuthCard webview provides an 'Open Browser' button as a user-initiated fallback. Closes #7026 --- packages/kilo-vscode/src/KiloProvider.ts | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/packages/kilo-vscode/src/KiloProvider.ts b/packages/kilo-vscode/src/KiloProvider.ts index 27d41fa4610..7b286eb0125 100644 --- a/packages/kilo-vscode/src/KiloProvider.ts +++ b/packages/kilo-vscode/src/KiloProvider.ts @@ -1713,8 +1713,11 @@ export class KiloProvider implements vscode.WebviewViewProvider, TelemetryProper const codeMatch = auth.instructions?.match(/code:\s*(\S+)/i) const code = codeMatch ? codeMatch[1] : undefined - // Step 2: Open browser for user to authorize - vscode.env.openExternal(vscode.Uri.parse(auth.url)) + // The backend already opens the browser via the `open` npm package during + // authorize(). Calling vscode.env.openExternal() here would show a VS Code + // trust dialog that persists after the user completes authentication in the + // browser, and would open a second browser tab. The DeviceAuthCard webview + // provides an "Open Browser" button as a user-initiated fallback. // Send device auth details to webview this.postMessage({