Skip to content

Preserve auth failure detail in account/read workspace routing discovery #962

Description

@shiny-code-app

Problem

account/read workspace routing discovery discards the backend error. When GET /backend-api/wham/accounts/check returns HTTP 401 with code: token_revoked, the client only sees:

account/read failed: workspace routing discovery failed (code -32603)

The status code, error code, and "token was revoked, sign in again" meaning are all lost. Users can't tell a revoked login apart from a network outage or a backend bug.

Evidence

  • Observed 2026-09-23 on v0.1.0-lab.8 (0e7f6ef41e), launching codex-lab from ~/Developer/codex-skills.
  • Calling the same endpoint directly with the token from ~/.codex-lab/auth.json returned:
    • wham/accounts/check → 401 {"error":{"message":"Encountered invalidated oauth token for user, failing request","code":"token_revoked"}}
    • wham/usage → the same 401 token_revoked
  • The local access token hadn't expired (its exp was 2026-10-01), so the server had revoked it.
  • The ~/.codex token for the same account returned 200 at the same moment.
  • After codex-lab login, both endpoints returned 200 and the TUI started normally.

Refs

Finish Line

  • A 401/403 from accounts/check reaches the account/read client as an auth failure the client can recognize, such as a distinct error message or structured error data. It must not look like a generic internal error.
  • Non-auth failures still report their underlying cause (status or transport) without exposing tokens.
  • Covered by an app-server test in workspace_routing_tests.rs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions