Skip to content

fix(auth): recover from provider credential failures - #1188

Merged
TheGreatAxios merged 20 commits into
mainfrom
cl-9347-recover-from-and-explain-auth-failures-instead-of-leaving
Sep 27, 2026
Merged

TheGreatAxios merged 20 commits into
mainfrom
cl-9347-recover-from-and-explain-auth-failures-instead-of-leaving

Conversation

@TheGreatAxios

@TheGreatAxios TheGreatAxios commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • re-resolve the exact OAuth profile and retry uncommitted credential failures once without silent provider failover
  • redact provider credentials across diagnostics and show actionable /connect recovery with explicit provider switching
  • make Codex and xAI credential rotation race-safe and document the recovery contract

Verification

  • bun run check passes
  • focused authentication, retry, redaction, race, and TUI recovery suites pass

Fixes CL-9347

@linear-code

linear-code Bot commented Sep 27, 2026

Copy link
Copy Markdown

CL-9347

@TheGreatAxios TheGreatAxios left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Primary review: approved. The full branch passes the repository gate, including 8,072 randomized tests, and all CL-9347 recovery, replay, redaction, and race-safety criteria are satisfied.

@TheGreatAxios

Copy link
Copy Markdown
Collaborator Author

Critic review: approved with no blocking or should-fix findings. Exact-source OAuth recovery, actionable guidance, credential sanitization, selector identity validation, and replay fences are covered by permanent regressions.

@TheGreatAxios

Copy link
Copy Markdown
Collaborator Author

Warden security review: GO. Provider-auth provenance, authoritative refresh winners, access and refresh credential redaction, concurrent refresh races, and explicit switch authorization are closed with synthetic-secret tests.

@TheGreatAxios

Copy link
Copy Markdown
Collaborator Author

Greybeard architecture review: approved. Credential stores own committed winners, provider sessions install exact winners, the inference harness owns immutable retry and commitment state, and the TUI owns generation-scoped explicit recovery.

@TheGreatAxios
TheGreatAxios force-pushed the cl-9347-recover-from-and-explain-auth-failures-instead-of-leaving branch from 683949d to 462c78d Compare September 27, 2026 22:34
@TheGreatAxios
TheGreatAxios enabled auto-merge (squash) September 27, 2026 22:37
@TheGreatAxios
TheGreatAxios merged commit 187b155 into main Sep 27, 2026
12 of 13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant