Skip to content

fix(oauth): preserve ownership for custom slot credentials - #219

Open
zhoudashuaibi wants to merge 1 commit into
dofastted:mainfrom
zhoudashuaibi:fix/custom-slot-credential-owner
Open

zhoudashuaibi wants to merge 1 commit into
dofastted:mainfrom
zhoudashuaibi:fix/custom-slot-credential-owner

Conversation

@zhoudashuaibi

Copy link
Copy Markdown
Contributor

变更

修复自定义槽位名称的 OAuth 凭证属主推导。slotUidGidFromHomeDir() 现在接受任意合法槽位目录名,并复用 slotRuntimeOwner() 的 UID/GID 规则;因此启动时的 subscriptionType 迁移和重新授权写入不会再把新凭证文件留在 root:root。

Fixes #218

根因

从 v1.3.93 开始,服务启动会原子重写缺少 subscriptionType 的 credentials.json。旧逻辑只识别 vm-数字 目录,自定义槽位如 claude-ios-145 无法完成 chown,槽容器 UID/GID 10001:987 随后无法读取凭证并返回 credential_required / needs_refresh 401。

验证

  • npx biome format
  • node --check(src、scripts)
  • node --test --test-name-pattern "ensureSlotSubscriptionType|slotUidGidFromHomeDir|ensureSlotClaudeOwnership" test/unit/oauth-credentials.test.mjs
  • git diff --check

完整 npm run test:unit 在 Windows 本地受到既有 symlink、SQLite EBUSY 和 Unix socket EACCES 环境限制;Ubuntu CI 将执行完整套件。

未发起任何 Claude 模型请求。

Reuse the runtime owner mapping for any slot id so startup subscription migration and credential rewrites do not publish root-owned files for custom-named slots. Add regression coverage for custom slot home paths.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] 启动迁移导致自定义槽位凭证属主错误并持续返回 401

1 participant