Skip to content

feat(switch): ask to sign in again when an account sign-in expired - #202

Open
fajarmf10 wants to merge 5 commits into
Lampese:mainfrom
fajarmf10:feat/reauthorize-expired-account-on-switch
Open

fajarmf10 wants to merge 5 commits into
Lampese:mainfrom
fajarmf10:feat/reauthorize-expired-account-on-switch

Conversation

@fajarmf10

Copy link
Copy Markdown

Problem

A switch to an account whose refresh token is no longer accepted fails with Token refresh failed: 401 Unauthorized. The only way out is to delete the account and add it again.

Fix

  • A 401 from the token endpoint (expired, reused, or revoked refresh token) and the existing "did not return a fresh id_token" case now give an error that starts with Sign-in expired: .
  • When the Switch button or a tray switch gets that error, a dialog asks to sign in again. It uses the existing OAuth flow. The new complete_reauthorize command stores the new tokens on the existing account instead of adding a new one, and then the switch runs again.
  • The new sign-in must belong to the same account: the email and the ChatGPT workspace id must match where they are known. A sign-in to another user or workspace is rejected, and the stored tokens stay unchanged.
  • The OAuth link panel moves from AddAccountModal into OAuthLinkPanel, so both dialogs share it.
  • style(tray): apply rustfmt only formats tray.rs, because the PR check runs rustfmt on every changed Rust file.

The token endpoint answers a made-up refresh token with 401 and {"code": "invalid_refresh_token", "message": "Could not validate your refresh token. Please try signing in again."}, so 401 is the signal for a new sign-in.

Testing

  • cargo test, with new tests for the error classification and the same-account check.
  • pnpm build and pnpm test, with a new test for the error check in the UI.
  • Not tested end to end in the app, because I had no account with a revoked refresh token.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant