5 Commits

Author SHA1 Message Date
Teknium
522e114109 refactor(agent/credential_pool): split refresh/seed god methods, unify sync + status helpers (-1107 LOC) 2026-09-02 18:57:14 -07:00
Teknium
b5aa16f785 refactor(agent/creds): unify auth-store OAuth removal and suppress-only steps; compact credential_sources/persistence (-35% LOC)
- credential_sources: _remove_nous_device_code/_remove_minimax_oauth/xai/codex
  share _remove_auth_store_oauth; hint-only steps (claude_code, qwen-cli,
  config:*) built by _suppress_only(); registry is a literal ordered list
  (register()/_register_all_sources() removed; order preserved, first match wins).
- credential_persistence: fold _fingerprint_value into fingerprint_secret_value;
  compact key tables and docstrings.
- Behavior parity verified old vs new: removal-step lookup + hint text for 12
  (provider, source) cases; 3000 random sanitize/fingerprint payloads.
2026-09-02 13:29:45 -07:00
joaomarcos
07faed33bb fix(auth): make the Anthropic refresh commit part of the transaction
Anthropic OAuth refresh tokens are single-use: the POST that returns a new
pair invalidates the one that was sent. The replacement therefore only
becomes real once it reaches its authoritative store -
~/.claude/.credentials.json for claude_code entries,
~/.hermes/.anthropic_oauth.json for hermes_pkce ones. Both writers caught
OSError/IOError, logged at debug level and returned nothing, so no caller
could tell a durable commit from a failed one.

That let a refresh spend the only refresh token, report success, and leave
the consumed pre-rotation pair on disk. _seed_from_singletons() re-reads
those files on every load_pool(), so the next process seeded the spent pair
back over the fresh pool row and the following refresh replayed a consumed
token (invalid_grant / refresh_token_reused) - exactly the failure this PR
set out to remove.

- _write_claude_code_credentials() and _write_hermes_oauth_credentials()
  now raise CredentialPersistError instead of swallowing the write error.
- _refresh_oauth_token() treats a failed commit as a failed refresh and
  returns None rather than handing back an access token whose refresh half
  was lost.
- _refresh_entry_impl() fails closed on both the primary and the recovery
  path: the rotated pair is never marked, persisted or returned, and the
  entry is quarantined DEAD with a credential_persist_failed reason so it
  leaves rotation and surfaces as an explicit re-auth instead of a silent
  fallback to another provider. The retry path now commits to the singleton
  before persisting the pool row.
- _upsert_entry() no longer treats re-seeding a borrowed source as a
  rotation. Borrowed rows (claude_code, env-backed) are written to auth.json
  without their secret, so comparing the re-seeded token against the empty
  stored value reported a rotation on every load and cleared the DEAD state
  the previous process had just written - resurrecting the quarantined,
  already-consumed credential on restart. It now compares the incoming
  token against the row's secret_fingerprint.

Adds failure-injection coverage for both writers, the direct resolver, the
claude_code and hermes_pkce pool paths and the retry path, each asserting
that a reload cannot bring the pre-refresh pair back as a usable credential.
2026-08-29 18:34:35 -07:00
Jaaneek
5ef0b8acb0 feat(auth): make xAI Grok OAuth device-code-only, drop loopback login
Replace the loopback/PKCE-callback server and manual-paste fallback with
the RFC 8628 device-code flow as the only xAI Grok OAuth login path. The
flow works in headless/SSH/container sessions with no 127.0.0.1 listener,
shrinking the local attack surface.

- Poll the token endpoint with server-provided interval, honoring
  slow_down and expires_in; store tokens with auth_mode
  oauth_device_code.
- Adaptive proactive refresh skew for short-lived device-code JWTs;
  rotated tokens sync back to auth.json, the global root store, and the
  credential pool (no refresh-token replay).
- Clear source suppression on successful re-login (CLI + dashboard) and
  drop the duplicate dashboard pool entry so exactly one seeded
  device_code entry exists.
- Use the shared device_code source name for consistency with the
  nous/codex device-code providers.
- Desktop: remove the loopback OAuth flow states and dead type variants;
  pkce providers' sign-in URL selection is unchanged.
- Docs (EN + zh-Hans) rewritten for device-code login; drop the deleted
  --manual-paste flag from documented commands.
2026-07-02 13:17:41 -07:00
Hasan Ali
d7c5d5dee5 fix: avoid persisting borrowed credential secrets (#31416) 2026-05-25 00:32:08 -07:00