You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(coding-agent,ai): scope auth-stale to credential failures; clear lockouts only on successful explicit selection
Fresh-eyes review fixes:
- New "permission" failure kind: 403s and permission/forbidden/access-denied
error types (Anthropic permission_error, SDK PermissionDeniedError, AWS
AccessDeniedException) are entitlement or policy denials, not bad
credentials. They are permanent (no retry) but never mark auth stale, so
a model/org/region-scoped 403 cannot lock out the whole provider.
- An auth verdict now needs structured evidence (401 status or an explicit
authentication error type); free-form message text alone no longer
launders into a stale-marking "structured" auth diagnostic.
- AgentSession.setModel is the single owner of the stale-auth clear and
commits it only when staleness is the sole blocker of an explicit
selection; the in-process and daemon set_model lookups consult the full
catalog for stale-auth providers instead of mutating stale state before
validation, so a mistyped model id or failed refresh no longer unlocks
a provider that was proven bad.
- Changed failure classification to stop treating bare 403 responses as authentication failures; an explicit authentication/permission error type or a 401 status is required.
2
+
- Added a `permission` failure kind: 403/permission-type errors classify as entitlement denials (permanent, no retry) instead of authentication failures, and auth verdicts require structured evidence (401 or an explicit authentication error type).
- Removed the 401/403 message-text sniffing that could mark a whole provider auth-stale from non-auth errors (e.g. region-block 403s); auth-stale now requires a structured provider auth failure.
2
2
- Changed explicit model selection to clear a provider's stale-auth lockout so the request runs again instead of failing with "Model not found"; a structured auth failure re-marks it.
3
+
- Changed the stale-auth clear to commit only when an explicit model selection is blocked solely by staleness; failed lookups and validations no longer unlock a provider.
0 commit comments