fix(codex): use access_token.exp instead of id_token.exp for import expiresAt - #6084
Conversation
…xpiresAt (diegosouzapw#6075) extractExpiresAt now prefers the access_token exp claim, falling back to id_token exp only when the access token has none. An expired id_token with a still-valid access_token no longer marks the connection expired on import and no longer triggers a premature refresh that could invalidate the token family. Reconstructed on the current release tip to drop unrelated stacked/base-drift changes; test rewritten from vitest to node:test so it runs under test-unit. Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
…auth-import-expiry-6075
a2c949e to
8841808
Compare
|
Merged — thank you, @anki1kr! 🙏 The core fix is exactly right: preferring I reconstructed the branch on the current release tip to keep the PR scoped to just this fix — the original branch had picked up unrelated stacked/base-drift changes (the Zed OAuth provider from #6078, plus older |
00d97ca
into
diegosouzapw:release/v3.8.44
…er (diegosouzapw#6087) No-auth account providers pack multiple accounts as UUID fingerprints inside providerSpecificData.fingerprints of a single provider_connections row. The combo builder mapped each row to one option, so only 'Account 1' appeared. expandConnectionOptions() now inflates each fingerprint into a selectable 'Account N' option whose id encodes the fingerprint for per-account pinning. Reconstructed on the current release tip to drop unrelated stacked/base-drift changes (this branch had carried diegosouzapw#6078/diegosouzapw#6084/diegosouzapw#6086 content). Complementary to the routing-time expansion in diegosouzapw#6082. Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
…xpiresAt (diegosouzapw#6075) (diegosouzapw#6084) Prefer access_token.exp over id_token.exp for Codex auth import (diegosouzapw#6075). Integrated into release/v3.8.44.
Problem
When a Codex
auth.jsonhas an expiredid_tokenbut a still-validaccess_token(common — the CLI keeps using tokens after export), the importer reads expiry fromid_token.exp. This causes:refresh_tokenwas already rotated by the Codex CLI, the refresh returnsinvalid_grant→refresh_tokenbecomesNULLRoot Cause
extractExpiresAt(idToken)only looked at the id token:The id_token's
expclaim carries its own TTL (often shorter), while theaccess_token.expis the operationally relevant expiry.Fix
extractExpiresAtnow takes both tokens and selects in order:access_token.exp— preferred (what actually gates API calls)id_token.exp— fallback when access_token carries noexpclaimnull— if neither has a decodeableexprefresh_tokenis preserved exactly as-is; the "do NOT refresh-on-import" invariant from the existing code comment remains intact.Tests
tests/unit/codex-auth-import-expiry.test.ts— 5 tests:access_token.expwhen id_token.exp is expiredid_token.expwhen access_token has no exp claimnullexpiresAt when neither has expaccess_token.expwhen both have future expiries (prefers access)refresh_tokenin all casesFixes #6075