Repository navigation
Reclassify OAuthException code 190 as Unauthorized - #13
Conversation
Meta returns expired/invalid/revoked access-token errors as an
OAuthException with code 190, frequently over HTTP 400 rather than 401,
and the middleware mapped purely by HTTP status. Callers could not tell
an expired token apart from a genuine bad request (both HTTP 400).
- Add an Unauthorized error class (there was none).
- Give Error an initializer carrying http_status/payload, plus #code /
#error_subcode readers (supports nested {"error":{"code"}} and flat
{"code"} envelopes).
- Middleware now raises Unauthorized whenever the payload carries code
190, and adds a 401 -> Unauthorized case. Non-token 400s still raise
BadRequest. Bump to 0.0.4.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
@claude review this PR |
|
Claude finished @craigphares's task in 2m 59s —— View job Review: Reclassify OAuthException code 190 as Unauthorized
SummaryGood, focused fix. The core problem — that a token-expiry error and a genuine bad request were indistinguishable because both raised
Suggestions
Overall: solid, well-tested fix for a real bug. The "match code 190 regardless of status/type" scoping (#1) is the one thing I'd want a second look at before merging, since it's the broadest behavioral change and is explicitly flagged as unverified against a live response in the PR description itself. |
Why
Meta returns expired / invalid / revoked access-token errors as an
OAuthExceptionwith code 190, frequently over HTTP 400 rather than 401. The middleware mapped exceptions purely by HTTP status, so a token error and a genuine bad request both raisedBadRequest. Consumers (LinkMyPhotos) could not distinguish them, which causedMedia#cleanupto soft-delete live posts on token expiry.What
Unauthorizederror class (none existed).Errornow carrieshttp_status/payloadand exposes#code/#error_subcode(supports nested{"error":{"code"}}and flat{"code"}envelopes).Unauthorizedwhenever the payload carries code 190 (any status), plus a401 -> Unauthorizedcase. Non-token 400s still raiseBadRequest. Bump to0.0.4.Test
Added
spec/raise_http_exception_spec.rb(Faraday test adapter).bundle exec rspec spec/raise_http_exception_spec.rb-> 6 examples, 0 failures.Note
Verify the exact token-error envelope against a real response: this keys on
error.code == 190. If the live Basic Display API returns a different code/shape for token expiry, adjustaccess_token_error?.