Repository navigation
Release 1.1.1: clear re-auth prompt when Claude refresh token is dead - #7
Merged
Merged
Conversation
When the stored Claude refresh token is permanently invalid (OAuth invalid_grant — revoked, rotated away, or expired), the bridge previously started a five-minute backoff and "Refresh Claude Login" surfaced a generic "backing off after a recent failure". Refresh can never succeed in that state, so the message was misleading and gave the user no way forward. - Bridge: on invalid_grant, skip the transient backoff, remember the dead refresh token, and return reauth_required so the next refresh short-circuits without hammering the OAuth endpoint. State self-heals once a new credential is stored; GET /claude/status now exposes a reauth_required flag. - App: "Refresh Claude Login" tells the user to run `claude auth login` instead of wrongly recommending a bridge restart. - Tests: cover the invalid_grant path (no backoff, short-circuit, self-heal). - Bump app version to 1.1.1 (build 2) and document in CHANGELOG. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
When the stored Claude refresh token is permanently invalid — the OAuth token endpoint returns
invalid_grant(token revoked, rotated away by a login elsewhere, or expired) — the app could not recover and gave the user no useful guidance:Refresh backing off after a recent failure.claude auth login— but nothing told the user that.This was hit in practice: a stale Keychain credential showed "Claude login: Expired" with no path forward from the UI.
Fix
Bridge (
codex_usage_server.py)invalid_grant, do not start the transient backoff (waiting can't revive a dead token).reauth_required: true; the next refresh short-circuits without hitting the OAuth endpoint again (no hammering).claude auth login) or a valid token is observed, the flag clears.GET /claude/statusnow exposesreauth_required.App (
BridgeService.swift)claude auth login… to sign in again" withrestartRecommended: false, instead of wrongly suggesting a bridge restart.Release
1.1→1.1.1(build1→2).Tests
Added
test_invalid_grant_flags_reauth_and_skips_backoff: verifies no backoff is set, the dead token short-circuits the second attempt (endpoint hit once), status reportsreauth_required, and the state self-heals when a fresh credential appears. All 10 bridge tests pass; secret scan clean.🤖 Generated with Claude Code