fix(server): one failed Claude probe no longer sticks as an auth warning - #13838
StiensWout wants to merge 1 commit into
Conversation
One stalled capability probe replaced a ready Claude snapshot with "Could not verify Claude authentication status", cached that result for five minutes, and dropped the cause. The probe now fails with its real error and logs the tag. When a probe fails, the last good probe answers once more, so one stall keeps Claude ready with the same account and slash commands. A second failure in a row, or a failure before any good probe, shows a warning that says whether the probe timed out or the CLI failed. The cache never keeps that failure. Fixes pingdotgg#13635 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This production change modifies Claude authentication-status reporting and capability caching, including retaining authenticated state after a failed probe and changing behavior after repeated failures. The scope and tests are focused, but the authentication implications require human review. You can add or adjust custom eligibility rules. Learn more. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: pingdotgg/t3code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughClaude capability probes now use a five-minute success cache. Failed refreshes can use the last good capabilities without usage data. Provider status reports probe failures as warnings with unknown authentication status. The Claude driver uses the cache for status checks and invalidation. ChangesClaude capability probe
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to No merge-blocking issue was established for the Claude probe resilience change; it is ready for normal merge checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to A failed account check can temporarily preserve and publish an earlier account state as ready. This improves resilience to transient failures, but can also delay visibility of a revoked, changed, or otherwise invalid account state. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
Full details: Linked Issues checkExplanation The changes address several requirements in [
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Fixes #13635
One stalled Claude capability probe turned a working Claude into "Could not verify Claude authentication status from initialization result." The probe mapped every failure (a timeout, an SDK error) to
undefined, the driver cached that result for five minutes, and nothing logged the cause. The warning also drops Claude out of the new-thread picker, even though its running threads keep working.Fix
Timed out after 25s while checking Claude account status.orClaude Agent CLI failed while checking account status.The cache never keeps that failure, so the next status check probes again.There is no new timer. Retries use the existing refresh loop and its client-demand gate, as the triage asked. A stalled
claude --versionstill reports an error, which #7232 covers. #13643 adds only the log line; this PR logs the same tag.Because the last good probe carries its slash commands, one failed probe no longer empties the
/menu either (#7111).Before
One stalled refresh, with the Claude CLI hanging on init, turns Claude into an auth warning:
After
The same stalled refresh keeps Claude authenticated:
A second stalled refresh in a row says what failed:
Captured with Playwright against a local dev server and a stand-in Claude CLI that stops answering
initializeon demand.Testing
ClaudeCapabilitiesProbe.test.ts: a new test walks through a first failure, a good probe served from cache, a failed probe answered by the last good account (without usage), and a second failure that reaches the caller and is retried on the next check. It fails if failures are cached, if the fallback never runs out, if success is not cached, or if the fallback is removed.ProviderRegistry.test.ts: the warning names a timeout or a CLI failure.tsc --noEmitforapps/server, plusvp lintandvp fmt --checkon the changed files.Prepared for Wout by
claude-opus-5-5in Claude Code.Summary by CodeRabbit