Distinguish expired OAuth token status

This commit is contained in:
elky
2026-06-12 19:43:59 +08:00
parent 308cc88ef7
commit 68038c182b
16 changed files with 332 additions and 58 deletions
@@ -21,7 +21,10 @@ fn oauth_invalid_reason_is_account_level_block(reason: Option<&str>) -> bool {
snapshot.blocked
&& !matches!(
snapshot.code.trim().to_ascii_lowercase().as_str(),
"oauth_token_invalid" | "oauth_expired" | "oauth_refresh_failed"
"oauth_token_invalid"
| "oauth_token_expired"
| "oauth_expired"
| "oauth_refresh_failed"
)
}
@@ -13,6 +13,10 @@ pub(super) fn codex_looks_like_token_invalidated(message: Option<&str>) -> bool
admin_provider_quota_pure::codex_looks_like_token_invalidated(message)
}
pub(super) fn codex_looks_like_token_expired(message: Option<&str>) -> bool {
admin_provider_quota_pure::codex_looks_like_token_expired(message)
}
pub(super) fn codex_looks_like_workspace_deactivated(message: Option<&str>) -> bool {
admin_provider_quota_pure::codex_looks_like_workspace_deactivated(message)
}
@@ -3,7 +3,7 @@ mod parse;
mod plan;
use self::invalid::{
codex_build_invalid_state, codex_looks_like_token_invalidated,
codex_build_invalid_state, codex_looks_like_token_expired, codex_looks_like_token_invalidated,
codex_looks_like_workspace_deactivated, codex_soft_request_failure_reason,
codex_structured_invalid_reason,
};
@@ -275,6 +275,7 @@ pub(crate) async fn refresh_codex_provider_quota_locally(
}
403 => {
let candidate_reason = if codex_looks_like_token_invalidated(err_msg.as_deref())
|| codex_looks_like_token_expired(err_msg.as_deref())
{
codex_structured_invalid_reason(403, err_msg.as_deref())
} else {
@@ -304,6 +304,7 @@ fn admin_pool_trimmed_string(value: Option<&Value>) -> Option<String> {
fn admin_pool_account_code_status_filter(code: &str) -> Option<&'static str> {
match code.trim().to_ascii_lowercase().as_str() {
"oauth_token_invalid" => Some("invalid"),
"oauth_token_expired" => Some("expired"),
"account_banned" | "account_suspended" => Some("account_banned"),
"account_disabled" => Some("account_disabled"),
"workspace_deactivated" => Some("workspace_deactivated"),
@@ -265,14 +265,16 @@ fn build_provider_key_oauth_status_snapshot(key: &StoredProviderCatalogKey) -> V
if let Some(reason) =
tagged_oauth_invalid_reason(invalid_reason.as_deref(), OAUTH_EXPIRED_PREFIX)
{
let (code, label) =
admin_provider_status_pure::oauth_token_snapshot_status_parts(reason.as_str());
return json!({
"code": "invalid",
"label": "已失效",
"code": code,
"label": label,
"reason": reason,
"expires_at": expires_at_unix_secs,
"invalid_at": invalid_at_unix_secs,
"source": "oauth_invalid",
"requires_reauth": true,
"requires_reauth": code == "invalid",
"expiring_soon": false,
});
}