Repository navigation
fix(server): fail fast when stored CLI credential has no refresh token - #12024
Adamulek123 wants to merge 2 commits into
Conversation
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This targeted fix prevents an invalid stored OAuth credential from making an empty refresh request and adds a regression test for the no-network path. Because it changes authentication and credential-refresh behavior across server flows, human review is warranted. Notes:
You can add or adjust custom eligibility rules. Learn more. |
This comment has been minimized.
This comment has been minimized.
|
Important Review skippedWe couldn't safely recover the incremental review. No full review was started, and the last reviewed checkpoint was preserved. Retry later, or explicitly request a full review by commenting You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: pingdotgg/t3code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📥 CommitsReviewing files that changed from the base of the PR and between 3b27df88beb70394e86da752aa195f21d77adc80 and ec3eb3927b858845970e28c97012d649bf671a5d. 📒 Files selected for processing (4)
Included review availability: Your plan provides up to 10 included reviews per hour; 4 remain after this review. 📝 WalkthroughWalkthroughThe refresh flow now returns a dedicated error for stored credentials without a refresh token. CLI authorization falls through to device authorization, HTTP reconciliation maps the error, and tests verify that no network request occurs. ChangesCLI credential refresh handling
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to Missing refresh tokens now fail without an unnecessary request, while CLI login fallback and other error handling remain covered. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
This comment has been minimized.
This comment has been minimized.
ec3eb39 to
c8e9f40
Compare
c8e9f40 to
418ca49
Compare
|
Rebased onto current What the rebase surfaced. Two conflicts, both from work that landed after this branch was cut:
Validation. Note on the environment: this branch's The premise is unchanged and still live on If CI comes back green I'd appreciate a re-look. If the |
418ca49 to
a1e38f7
Compare
|
Correction to my previous comment: I reported typecheck as clean. That was wrong, and CI caught it — the first run on the rebased head failed What happened: after the rebase I "cleaned up" a So my "validation" line in that comment overstated the evidence, and the honest sequence is: rebase → tests pass → typecheck pass → introduce the failure → CI typecheck fail → revert → typecheck pass. Worth noting because the diagnostic that tempted the change was a repo-wide suggestion, not an error, and I treated a suggestion as noise when it was flagging a real type constraint. Everything else in that comment stands. For the record, verified on the current head:
The I'll hold off on further edits unless CI surfaces something else. |
|
Note Written by Hi! We are cleaning up open PRs, and this one does not say which model created it and was opened more than two weeks ago. If this change is still important, please rebuild it on current main with a newer model and note the model in the PR description. |
Summary
When a grant response omits
refresh_token, the CLI stores an empty string and then burns a doomed network round trip (refresh_token='') on every later refresh before falling through to a fresh login.What changed
refreshinapps/server/src/cloud/CliTokenManager.tsfails immediately with the new no-causeCloudCliMissingRefreshTokentag (a member of the exportedCloudCliTokenManagerErrorunion) on an empty stored refresh token, preserving the existing fall-through-to-login contract without the wasted request.Validation
vp test run apps/server/src/cloud/CliTokenManager.test.ts— 9/9 pass, including a new test that seeds an expired token with an empty refresh token and asserts refresh failure with zero HTTP calls.Summary by CodeRabbit