Repository navigation
fix(auth): point users with a valid key to the license acceptance page (ENG-886) - #1340
Open
eddiebergman-priorlabs wants to merge 7 commits into
Open
eddiebergman-priorlabs wants to merge 7 commits into
eddiebergman-priorlabs wants to merge 7 commits into
Conversation
…e (ENG-886) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… in tests (ENG-886) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
eddiebergman-priorlabs
marked this pull request as ready for review
October 1, 2026 12:22
dianaprior
reviewed
Oct 1, 2026
| if no_browser and no_browser not in ("0", "false", "no", "off"): | ||
| browser_disabled = no_browser and no_browser not in ("0", "false", "no", "off") | ||
| token = None if browser_disabled else try_browser_login(gui_url, hf_repo_id) | ||
| if token is None and has_token_without_license: |
There was a problem hiding this comment.
In case browser_disabled is true & user has a valid token, but just didn't accept the license, wouldn't a better path be directing user to accept the license without setting token to None?
With a valid API key and an unaccepted license, the browser flow now goes straight to the license acceptance page instead of the full login. The outcomes are spelled out as an exhaustive match over what is missing (login or acceptance) and why the browser produced no key (disabled or unavailable), so the valid-key case no longer relies on resetting the token to None. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The browser may be signed in to another account than the API key. A TABPFN_TOKEN key outranks the saved browser key, so every later run would reopen the browser without saying why. Re-check the key the next run will use and explain the mismatch. Without a display, a valid key no longer asks for a key to paste; the error links to the acceptance page. Browser URLs and the acceptance link now come from one helper, and the helpers take required keyword arguments. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 64b5353. Configure here.
A rejected TABPFN_TOKEN survives the cache cleanup, so after a normal login the re-check saw it and wrongly reported a different account. Only the acceptance step started from a verified key, so limit the check to it. Also shorten the changelog entry. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

tldr; ended up re-organizing as it was a bit chaotic with nested if and overloaded meaning of
None. Also fixes a potential issue where token is for an account, other than the one that is logged in. This could lead to a potentially frustrating exp. where the user could accept the license for their account, but perhaps be using some org shared token or otherwise.Motivation and Context
People create an API key, set
TABPFN_TOKEN, and forget to accept the model license. TabPFN sees that the key is valid and the license is not accepted, so it tries to open the browser. That can't happen in a notebook without a TTY, in CI, in an agent, or withTABPFN_NO_BROWSERset, so it raises the generic error telling the user to log in, copy an API key and setTABPFN_TOKEN. They already did that, and the message doesn't say what is missing.Now, when the cached key is valid, the license is not accepted, and browser login can't run, the error says the user is logged in but hasn't accepted the license, and links to
<gui>/accept-license?hf_repo_id=<model>. The existing error for a browser login that ends without acceptance uses the same message.When a browser is available and the key is valid, TabPFN now opens
<gui>/accept-license?hf_repo_id=<model>&callback=...directly instead of the full login. Without a display there is nothing to paste, since the key is already set, so it raises the error with that link. If the browser isn't signed in, the web app takes the user through login and back to the acceptance page. If the browser is signed in to a different account than aTABPFN_TOKENkey, acceptance would land on the wrong account and every later run would reopen the browser. TabPFN now re-checks the key the next run will use and says so.The outcomes are now one exhaustive
matchon two things: what is missing (_AuthStep.LOGINor_AuthStep.ACCEPT_LICENSE), and why the browser produced no key (_NoBrowserToken.DISABLEDorUNAVAILABLE). The valid-key case no longer setstokentoNone, and mypy flags any combination that isn't handled.Public API Changes
How Has This Been Tested?
Added
test_browser_is_asked_for_the_missing_step(a valid key asks only for acceptance; no key asks for login), plus tests that the graphical flow opens/accept-licensefor the acceptance step, that the headless flow defers to the error with that link, and that acceptance in a different browser account raises for aTABPFN_TOKENkey but just works for a cached key. Also addedtest_valid_token_without_license_links_to_acceptancetotests/test_browser_auth.py, parametrized over browser disabled, browser unavailable, and a browser login that ends without acceptance. The first two failed on main with the generic message and pass now. The disabled case also checks that no browser is opened. The rest oftests/test_browser_auth.pypasses, as does pre-commit (ruff, mypy).Checklist
🤖 Generated with Claude Code