fix(auth): let auth login replace a token the service rejects - #467
Conversation
|
@claude /review |
|
Claude finished @theCodeDrift's task in 3m 37s —— View job Review completeReview mode: incremental — read 0 prior review thread(s) before reviewing.
SummarySolid, well-scoped change. The core behavior change ( One gap worth addressing:
Minor, non-blocking observation:
|
5426900 to
3d628d4
Compare
Status coverage: fixed in 3d628d4. The status wording moved into a pure Also rebased onto — AI Coding Agent |
Every message that asks a user to re-authenticate after a
401pointed atauth login, andauth loginrefused whenever any token was present. A token the service has revoked or expired is still present locally, so the advice could not be followed. WithTASKLESS_TOKENset it was worse:auth logoutprintedNot logged in.,auth loginkept refusing, and nothing mentioned the variable.What changes
auth loginchecks a saved token with the service before refusing. A401runs the device flow and replaces the token. An accepted token, or a service that could not answer, is kept with the existing "already logged in" answer, since an unreachable service says nothing about the token.--jsonoutput is unchanged.rejectedTokenRemedy()inauth/token.ts), used bycheck,rule create/improve(submit, poll and fetch) andrule restore/rollback/revisions. A saved token getsauth login. ATASKLESS_TOKENtoken gets "replace or unset it;auth loginandauth logoutdo not change it". Therule create/improvemessages that only saidLog in again.now name the command.TASKLESS_TOKENis named:auth loginpoints at the variable instead of atauth logout.auth logoutsays the variable is still used.taskless authadds "via TASKLESS_TOKEN" and separates a rejected token, with its remedy, from an unreachable service.auth logoutthenauth login. Its token is valid, soauth loginalone would keep it.authagent recipe topic v2, and a patch changeset.OpenSpec
rejected-token-recovery, a single PR, archived in the second commit. It adds the login, logout and 401 behavior tocli-auth. It also corrects requirements that still described the global~/.config/taskless/auth.jsonstore, which the CLI no longer reads or writes. Two of those are REMOVED and re-ADDED under new titles, because a MODIFIED block can neither rename a requirement nor drop a scenario. The proposal lists each scenario that was replaced. I compared the scenario list before and after the archive: every earlier scenario is either still present or listed there.Verification
pnpm typecheck,pnpm lint,openspec validate --specs --strict, and the full CLI suite (2035 tests) pass after rebasing onto416a2db. New tests cover:loginInteractivewith an environment token, an accepted token, an unreachable service, and a rejected tokenauth login/auth logoutwithTASKLESS_TOKENsetFixes #450