fix: stop retrying token rotation with an invalid refresh token - #679
Merged
Merged
Conversation
When tooling.tokens.rotate returns invalid_refresh_token, remove the stored refresh token and warn to run slack login so rotation is not retried on every command. Rotation is also attempted at most once per refresh token per process, and the API host is restored when rotation fails.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #679 +/- ##
==========================================
+ Coverage 78.19% 78.22% +0.03%
==========================================
Files 239 239
Lines 18132 18144 +12
==========================================
+ Hits 14178 14193 +15
+ Misses 3954 3951 -3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
mwbrooks
commented
Sep 28, 2026
| auth.RefreshToken = result.RefreshToken | ||
| auth.LastUpdated = time.Now() | ||
|
|
||
| // now restore the previous default apiHost |
Member
Author
There was a problem hiding this comment.
note: This explicit restore only ran on the success path, so a failed rotation returned early and left the API host pointing at the auth's host. It's replaced by defer c.api.SetHost(activeAPIHostBeforeRotation) right after the host is captured, which restores the host on both success and error.
Member
Author
|
Thanks for the quick reviews @srtaalej! 🙇🏻 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changelog
Fixed an issue where an expired login with an invalid refresh token caused the CLI to retry token rotation on every command. The CLI now removes the invalid refresh token and asks you to run
slack loginagain.Summary
This pull request stops the CLI from repeatedly retrying token rotation when the stored refresh token is no longer valid.
tooling.tokens.rotatereturnsinvalid_refresh_token, the refresh token is removed fromcredentials.jsonand a warning asks you to runslack login. Before, the failure was only logged at debug level, so every command retried the rotation.internal_erroror network errors.Preview
Testing
slack login.expfor that auth in~/.slack/credentials.jsonto a past timestamp:refresh_tokenvalue with an invalid token, e.g.xoxe-1-invalid.slack auth list --verboseand confirm:tooling.tokens.rotaterequest that returnsinvalid_refresh_tokenslack loginrefresh_tokenis removed from~/.slack/credentials.jsonslack auth list --verboseagain and confirm notooling.tokens.rotaterequest is made.slack loginto restore a working auth.Notes
internal_errorare treated as transient: the refresh token is kept and rotation is retried in the next command, but only once per command.activity --tail(andslack runactivity polling) keeps polling after auth errors. That will be addressed in a separate PR.Requirements