Skip to content

Prevent Claude UUID collisions from losing rotated credentials - #46

Merged
rexdotsh merged 1 commit into
mainfrom
fix/claude-account-identity
Sep 23, 2026
Merged

rexdotsh merged 1 commit into
mainfrom
fix/claude-account-identity

Conversation

@rexdotsh

Copy link
Copy Markdown
Owner

Summary

Correct the account-identity regression in merged #43 found by an independent Opus 5.5 xhigh review. account.uuid identifies a Claude user, not a uniquely routable Max/Console/organization credential. Writing it into the unique (provider, account_id) column can cause a second row's refresh to fail after Anthropic has already rotated the token, leaving that row unrecoverable.

  • Stop using Claude's user UUID as the database account ID for new connections or refreshes. Preserve any existing account ID without promoting an unscoped UUID; Max and Console connections remain separate rows. Existing-account reauthorization still targets its row explicitly and preserves its stored account ID.
  • Clear stale reauthorize status when a credential upsert replaces tokens, so a reconnect/import with a matching identity can refresh later.
  • Sanitize token-bearing libSQL update errors and classify unique-identity collisions as reauthorization conflicts instead of exposing SQL parameters.

Verification

  • bun test (140 passed), bun typecheck, bun lint
  • Regression tests cover two legacy Claude rows sharing a user UUID, Max+Console connection separation, reauthorization of an existing identified row, reconnect clearing failure status, and a duplicate-identity conflict without token disclosure.

Follow-up: define a safe account+organization+mode identity if deduplicating Claude logins is desired. A timeout after upstream rotation and repeated 401s on newly issued tokens remain separate reliability investigations. Please do not merge without explicit approval.

@rexdotsh
rexdotsh merged commit 9566f75 into main Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant