Repository navigation
Name unsupported Claude OAuth token in CLI secret setup - #66669
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
An existing credential-resolution test becomes dependent on the developer’s ambient Claude OAuth environment.
1 open finding
What changed in this PR
Adds explicit diagnostics when Claude secret setup encounters only the unsupported OAuth token.
Changes:
- Detects
CLAUDE_CODE_OAUTH_TOKENwithout exposing its value. - Preserves supported API-key and repository-secret precedence.
- Adds interactive and secret-resolution tests.
| File | Description |
|---|---|
pkg/cli/engine_secrets.go |
Adds unsupported-token detection and guidance. |
pkg/cli/engine_secrets_test.go |
Tests detection and credential precedence. |
pkg/cli/add_interactive_secrets_test.go |
Tests interactive setup diagnostics. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
| if engine == string(constants.ClaudeEngine) && value == "" && os.Getenv("CLAUDE_CODE_OAUTH_TOKEN") != "" { //nolint:osgetenvlibrary | ||
| return "", "", false, errUnsupportedClaudeOAuthToken |
There was a problem hiding this comment.
Fixed in 324e108: TestGetEngineSecretNameAndValue now clears CLAUDE_CODE_OAUTH_TOKEN at setup; the focused OAuth test still sets it explicitly.
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 9bd7c88
|
…ame-unsupported-clause-code-oauth-tok Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Merged the latest |
|
🎉 This pull request is included in a new release. Release: |
PR #66669 changed the gh aw CLI secret setup path to detect CLAUDE_CODE_OAUTH_TOKEN and fail with an explicit error naming the token and the supported alternatives, instead of silently ignoring it. Update the two docs call out sites that still described the old silent-ignore / unnamed-error behavior. Closes #66656

Claude Code users with only
CLAUDE_CODE_OAUTH_TOKENreceive an unclear authentication failure because gh-aw does not support that credential.ANTHROPIC_API_KEYor Anthropic Workload Identity Federation. Never include the token value in the error.