app
Fusion - the Fusion 360 Bridge
Public Made by Adomby adom
Drive Autodesk Fusion 360 from the cloud via Adom Bridge: component libraries, IPC package generation, board layout, exports (STEP/Gerbers/BOM/CPL), fast APS cloud search, and parametric modeling.
← Commit history
fusion-aps-signin: background nb flow + 180s listener race + Google SSO branch
1 file changed
+53−1
skills/fusion-aps-signin/SKILL.md+53−1@@ -1,6 +1,6 @@ --- name: fusion-aps-signin-description: Drive the Autodesk sign-in flow in the user's real browser to set up APS (Autodesk Platform Services) for the Fusion bridge's fusion_aps_* cloud search — open a dedicated browser window, foreground it, MONITOR the sign-in, and auto-retrieve + enter the emailed one-time passcode (OTP) via adom-google before it expires. Use when signing into Autodesk/APS, registering an APS app, configuring fusion_aps_search, or any "log me into Fusion/Autodesk for APS" request. Trigger words — aps signin, sign in to autodesk, autodesk otp, fusion aps login, register aps app, aps client id, fusion_aps_signin, autodesk verification code, link google account autodesk.+description: Drive the Autodesk sign-in flow in the user's real browser (native-browser extension, nbrowser_*) to set up APS (Autodesk Platform Services) for the Fusion bridge's fusion_aps_* cloud search — open a dedicated BACKGROUND window (no foregrounding needed), MONITOR the sign-in, and auto-retrieve + enter the emailed one-time passcode (OTP) via adom-google before it expires. Handles native email+password AND Google/Apple/Microsoft SSO (warm-session account pick, no password) plus the "Account already exists → Link Google account" interstitial. Use when signing into Autodesk/APS, registering an APS app, configuring fusion_aps_search, or any "log me into Fusion/Autodesk for APS" request. Trigger words — aps signin, sign in to autodesk, autodesk otp, fusion aps login, register aps app, aps client id, fusion_aps_signin, autodesk verification code, link google account autodesk, google sso autodesk, callback listener expired, localhost refused to connect. --- # Fusion / APS sign-in (driven, with auto-OTP)@@ -46,6 +46,58 @@ AD-connected laptop: `adom-bridge --target <laptop> nbrowser_* '{...}'`. and offer to set it up (`adom-google auth`) so you can fetch the code for them. Gmail for Adom = **[email protected]** (work account). +## PROVEN END-TO-END, 2026-08-22 ([email protected], Google-federated, fully in the BACKGROUND)++A complete real run, start to signed-in APS token, driven entirely through `nbrowser_*` on the+user's real profile with **no foregrounding**. Read this before the step-by-step — it captures the+two things that actually make or break the flow.++### ⏱ THE #1 KILLER: the callback listener lives only ~180 seconds++`fusion_aps_signin` binds a localhost listener (port 8917/8918/8920) that captures the auth code,+and that listener **self-closes after 180s** (`aps.py start_signin`, the `_serve` deadline). The+whole SSO + OTP + account-linking sequence below can easily take LONGER than 3 minutes, and if it+does the redirect lands on **"This site can't be reached — localhost refused to connect"**, the code+is lost, and `fusion_aps_status` still shows the OLD user. This bit us twice.+- **Mint the authUrl LAST, then move fast.** Do any slow parts (waking the profile, finding the+ account, one-time account-linking) on a THROWAWAY first pass, THEN call `fusion_aps_signin` and+ race the now-fast, already-linked flow to the callback inside 180s.+- **If you see "localhost refused to connect":** the listener died, nothing is broken — just call+ `fusion_aps_signin` again for a fresh 180s window and rush it. The second pass is much faster+ because SSO is warm and any linking is already done.+- Suppress the bridge's own auto-open (`fusion_aps_signin {noOpen:true, autoOpen:false}`), grab the+ returned `authUrl`, and drive it in YOUR nb window so nothing foregrounds.++### The Google/Apple/Microsoft-SSO branch (no password, ever)++Many Autodesk accounts are federated. In the user's real profile the SSO session is warm, so:+1. Email-first page → type the email → **Next** may redirect to `accounts.google.com/...accountchooser`+ ("Sign in with Google → Choose an account to continue to Autodesk"). Click the account tile by+ text (`nbrowser_click {text:"[email protected]"}`) — the warm session means **no password prompt**.+2. Autodesk still sends an **email OTP** ("One-time passcode") → fetch + fill the segmented boxes+ (steps 3-4 below).+3. First-time federation shows **"Account already exists … Link Google account"** → click+ **Link Google account**. The OTP already proved ownership, so **no Autodesk password is needed**;+ it lands on "Google account linked → Continue in N seconds" and auto-proceeds to consent.+4. Consent page ("Authorize application — Adom Fusion Bridge is requesting permission") →+ `nbrowser_click {text:"Allow"}` → callback → token captured.++### Fetch the OTP for a SPECIFIC account, and verify WHO you got++- The account whose inbox holds the code is the one signing in — target it explicitly:+ `adom-google --account personal ...` (jlauer12) / `--account media`. The `adom-google gmail`+ subcommand only handles attachments; use `adom-google --account <a> api "https://gmail.googleapis.com/..."`+ for search/read (see step 3).+- After the callback, confirm identity with `fusion_aps_status` → `signedInAs.email`. As of **bridge+ 1.9.139** this is correct per-account; before it, a cache keyed on the JWT prefix (identical header+ across all Autodesk tokens) made every account display as the FIRST one signed in. If you see the+ wrong `signedInAs` on an OLD bridge, update it — the token itself was always right.++### Reuse-window note++`nbrowser_navigate {sessionId}` on a window YOU opened (owned session) is fine for re-pointing it at+a fresh authUrl during a retry — the never-navigate rule only protects the user's OWN windows.+ ## Step-by-step ### 1. Open + foreground a dedicated window at the APS portal