Skip to content

fix(images): refresh OAuth credentials and rotate accounts after 401 - #9231

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
Bl0ck154:codex/fix-image-oauth-refresh-rotation
Aug 6, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.50from
Bl0ck154:codex/fix-image-oauth-refresh-rotation

Conversation

@Bl0ck154

@Bl0ck154 Bl0ck154 commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • pass the parsed image model id into quota-aware credential selection
  • proactively refresh expiring OAuth credentials before image generation
  • retry an upstream 401 with each remaining eligible connection at most once
  • recalculate per-connection proxy context for every attempt
  • share the lifecycle across both image-generation entry points while preserving no-auth providers

Fixes #9230.

Why

The chat route calls checkAndRefreshToken() before dispatch and has account fallback, but /v1/images/generations previously selected one credential and sent it unchanged. An expired access token therefore caused an immediate 401 even when its refresh token was valid or another healthy connection was available.

Validation

  • node --import tsx/esm --import ./open-sse/utils/setupPolyfill.ts --test tests/unit/image-generation-route.test.ts (20/20)
  • npm run typecheck:core
  • ESLint on all changed files
  • Prettier check on all changed files
  • npm run check:cycles

New route coverage verifies:

  • expired Antigravity OAuth access token is refreshed and persisted before image dispatch;
  • upstream 401 rotates to a second account and succeeds;
  • provider-scoped image generation uses the same fallback;
  • existing no-auth SD WebUI behavior remains successful.

@Bl0ck154
Bl0ck154 requested a review from diegosouzapw as a code owner August 2, 2026 16:33
@diegosouzapw
diegosouzapw merged commit 3f9507f into diegosouzapw:release/v3.8.50 Aug 6, 2026
3 checks passed
fenix007 pushed a commit to fenix007/OmniRoute that referenced this pull request Aug 20, 2026
)

Validated in local merge-train (devbox-vm-06-dev002) @ combined-tip (FAST gates green: static + changed tests + vitest — only pre-existing audit.test.ts flake). Evidence: /home/diegosouzapw/dev/proxys/OmniRoute/.claude/worktrees/merge-train-20260805-213228-suite.log

(cherry picked from commit 3f9507f)
fenix007 pushed a commit to fenix007/OmniRoute that referenced this pull request Aug 20, 2026
check:complexity-ratchets has been red on stable since fork.3, which rebaselined
check:file-size for its ported fixes but left the two complexity ratchets behind.

Measured per tag with one ESLint walk each, so the drift is attributed rather
than assumed:

- cyclomatic + max-lines: 2056 baseline, but pristine v3.8.48 (fork.1, which
  carries only docker/CI commits) already measures 2058 — inherited from
  upstream, which does not run this gate on the fast-path PR->release. fork.2
  adds +1 (peekCodexSseTransientError, diegosouzapw#7570/diegosouzapw#8043) and fork.3 adds +1
  (recordProviderFailure, diegosouzapw#10116).
- cognitive: 890 baseline matches fork.1 exactly. fork.2 adds +3 (two functions
  in codex.ts plus imageCredentialRetry.ts, diegosouzapw#9231/diegosouzapw#8307) and fork.3 adds +2
  (accountFallback.ts diegosouzapw#10116, providerLimits.ts diegosouzapw#10534).

fork.4 measures the same 2060 / 895: the error-status patch set added zero
violations, verified by diffing the per-violation lists between the two trees.
No fork-owned code sits over either threshold — every flagged function comes
from an upstream commit upstream rebaselined on its own branch, so the ratchets
are moved to the measured values instead of refactoring ported code away from
its upstream shape.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
)

Validated in local merge-train (devbox-vm-06-dev002) @ combined-tip (FAST gates green: static + changed tests + vitest — only pre-existing audit.test.ts flake). Evidence: /home/diegosouzapw/dev/proxys/OmniRoute/.claude/worktrees/merge-train-20260805-213228-suite.log
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(providers): image generations route lacks OAuth refresh + account rotation after upstream 401

2 participants