Skip to content

fix(usage): clear auth-expired message for Kiro social-auth (Google/GitHub) accounts - #4512

Merged
diegosouzapw merged 1 commit into
release/v3.8.33from
fix/port-pr-620-kiro-social-quota-auth
Jun 21, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.33from
fix/port-pr-620-kiro-social-quota-auth

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Summary

A Kiro connection added via /api/oauth/kiro/social-exchange (Google or GitHub social-login device flow) carries a token format that AWS CodeWhisperer's GetUsageLimits quota API routinely rejects with 401/403 even when /messages still works.

The usage card was throwing the raw upstream error blob:

Failed to fetch Kiro usage: Kiro API error (401): {"__type":"AccessDeniedException"}

…which is noisy and tells users nothing. Legacy social-auth users with a different marker already saw the friendly Kiro quota API authentication expired. Chat may still work. message — newly-added social-auth accounts didn't.

Fix

getKiroUsage (open-sse/services/usage.ts) now detects the social-auth carveout from providerSpecificData:

authMethod === "imported" && provider in {"Google", "Github"}

— exactly the markers social-exchange/route.ts persists when adding a Kiro account through Google/GitHub. When GetUsageLimits returns 401/403 and the account matches the carveout, return the friendly message instead of throwing.

Builder-ID / IDC / kiro-cli imports keep the existing throw-on-failure behavior so transient upstream errors don't get silently masked as "auth expired".

Files

  • open-sse/services/usage.ts — getKiroUsage branch + isSocialAuthKiroAccount helper (also wired into __testing export for the new tests)
  • tests/unit/kiro-iam-profilearn-usage.test.ts — two new regression tests (TDD)
  • CHANGELOG.md — entry under [3.8.32] → 🐛 Fixed
  • config/quality/file-size-baseline.json — bump open-sse/services/usage.ts 3408 → 3443 (+35 LoC: branch + helper + comments)

Test plan

  • TDD: new test getKiroUsage returns a friendly auth-expired message for social-auth Kiro on 401/403 — RED before the fix, GREEN after (asserts /authentication expired/i and that GetUsageLimits was actually called after profile discovery).
  • TDD guard: getKiroUsage still throws on 401/403 for non-social Kiro accounts (Builder-ID/IDC) — confirms the fix doesn't overreach and mask transient errors for non-social accounts.
  • Broader Kiro/usage suite: 27/27 tests pass across kiro-iam-profilearn-usage, kiro-overage-usage-4469, usage-extractor.
  • npm run typecheck:core — clean (exit 0).
  • npx eslint open-sse/services/usage.ts tests/unit/kiro-iam-profilearn-usage.test.ts — clean.
  • node scripts/check/check-file-size.mjs — only pre-existing drift remains (src/lib/db/core.ts, src/lib/usage/providerLimits.ts, src/shared/constants/providers.ts — already over budget on release/v3.8.32 base); my file matches the bumped baseline exactly.
  • node scripts/check/check-docs-sync.mjs — PASS.

Notes

  • Co-authored-by: Anurag Saxena <anuragg.saxenaa@gmail.com> (original upstream fix author — the OmniRoute adaptation is non-trivial because our getKiroUsage throws on non-OK rather than tracking the sawAuthError / authMethod state machine the upstream patch targets; the carveout had to be moved into the response-handler with social-auth detection derived from OmniRoute's own providerSpecificData schema).
  • Scope-creep dropped: the upstream PR also touched DroidToolCard.js + droid-settings/route.js for unrelated Droid CLI multi-model support (94% of the upstream diff LoC). Those changes are not in scope for "Kiro quota auth expired" and are not ported here.

Inspired-by: decolua/9router#620

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Kiro usage service to gracefully handle 401 and 403 authentication errors for social-auth Kiro accounts (Google/GitHub) by returning a friendly 'auth expired' message instead of throwing an error. It introduces a helper function isSocialAuthKiroAccount to identify these accounts, updates the file size baseline, and adds corresponding unit tests to verify the new behavior and ensure that non-social accounts still throw errors as expected. There are no review comments, so I have no feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@diegosouzapw
diegosouzapw changed the base branch from release/v3.8.32 to release/v3.8.33 June 21, 2026 14:01
…ccounts

A Kiro connection added via /api/oauth/kiro/social-exchange (Google or
GitHub social-login device flow) carries a token format that AWS
CodeWhisperer's GetUsageLimits API routinely rejects with 401/403 even
when /messages still works. The quota card was throwing the raw upstream
error blob ("Failed to fetch Kiro usage: Kiro API error (401): {...}"),
which is noisy and unhelpful.

getKiroUsage now detects the social-auth carveout from providerSpecificData
({ authMethod: "imported", provider: "Google" | "Github" } — exactly what
social-exchange/route.ts persists) and returns the same friendly
"Kiro quota API authentication expired. Chat may still work." message
that legacy social-auth users already see. Builder-ID / IDC / kiro-cli
imports keep the existing throw-on-failure behavior so transient upstream
errors don't get silently masked.

TDD: kiro-iam-profilearn-usage.test.ts gets two new cases — the social-auth
path resolves to the friendly message (RED before the fix), and the
non-social Builder-ID path still throws on 401/403 (guards against the
fix overreaching).

Inspired-by: decolua/9router#620
Co-authored-by: Anurag Saxena <anuragg.saxenaa@gmail.com>
@diegosouzapw
diegosouzapw force-pushed the fix/port-pr-620-kiro-social-quota-auth branch from dcca183 to ccacc27 Compare June 21, 2026 17:07
@diegosouzapw
diegosouzapw merged commit 3a0c40b into release/v3.8.33 Jun 21, 2026
3 checks passed
@diegosouzapw diegosouzapw mentioned this pull request Jun 22, 2026
@diegosouzapw
diegosouzapw deleted the fix/port-pr-620-kiro-social-quota-auth branch June 22, 2026 02:48
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…iegosouzapw#4512)

Rebuilt onto release/v3.8.33; usage.ts baseline reconciled for the diegosouzapw#4493/diegosouzapw#4494/diegosouzapw#4512 quota trio. Integrated into release/v3.8.33.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant