Handle inactive PAT owner as invalid OAuth token

This commit is contained in:
elky
2026-06-21 11:39:20 +08:00
parent 279735ae7f
commit 61bdd304b7
4 changed files with 90 additions and 0 deletions
+22
View File
@@ -952,6 +952,9 @@ pub fn codex_looks_like_token_invalidated(message: Option<&str>) -> bool {
|| lowered.contains("authentication token has been invalidated")
|| lowered.contains("token has been invalidated")
|| lowered.contains("token invalidated")
|| lowered.contains("personal access token owner is inactive")
|| lowered.contains("biscuit_baker_service_auth_credential_error_status")
|| lowered.contains("auth_credential")
|| lowered.contains("invalidated")
|| lowered.contains("revoked")
|| lowered.contains("已撤销")
@@ -1777,6 +1780,25 @@ mod tests {
);
}
#[test]
fn codex_runtime_invalid_reason_marks_inactive_pat_owner_403_as_token_invalid() {
assert_eq!(
codex_runtime_invalid_reason(403, Some("Personal access token owner is inactive.")),
Some(format!(
"{OAUTH_EXPIRED_PREFIX}Personal access token owner is inactive."
))
);
assert_eq!(
codex_runtime_invalid_reason(
403,
Some("biscuit_baker_service_auth_credential_error_status")
),
Some(format!(
"{OAUTH_EXPIRED_PREFIX}biscuit_baker_service_auth_credential_error_status"
))
);
}
#[test]
fn codex_runtime_invalid_reason_marks_402_as_account_blocked() {
assert_eq!(
@@ -158,6 +158,9 @@ pub fn oauth_token_reason_is_hard_invalid(reason: &str) -> bool {
"authentication token has been invalidated",
"token has been invalidated",
"token invalidated",
"personal access token owner is inactive",
"biscuit_baker_service_auth_credential_error_status",
"auth_credential",
"invalidated",
"revoked",
"已撤销",
@@ -722,6 +725,20 @@ mod tests {
assert!(!snapshot.recoverable);
}
#[test]
fn account_snapshot_marks_inactive_pat_owner_as_token_invalid() {
let snapshot = resolve_account_status_snapshot(
Some("codex"),
None,
Some("[OAUTH_EXPIRED] Personal access token owner is inactive."),
);
assert_eq!(snapshot.code, "oauth_token_invalid");
assert_eq!(snapshot.label.as_deref(), Some("Token 失效"));
assert!(snapshot.blocked);
assert!(!snapshot.recoverable);
}
#[test]
fn account_snapshot_marks_oauth_expired_as_token_expired() {
let snapshot = resolve_account_status_snapshot(