fix(tunnel): surface daemon login failures + 401 status hint - #29
Merged
Merged
Conversation
Two UX fixes uncovered in the field:
1. hsh login silently skipped a FAILED daemon login
loginDaemon(optional:true) treated every 'daemon not usable' case —
including a daemon that IS installed but whose control token we
couldn't read — as 'not installed' and skipped silently. Result:
hsh login reported success while the daemon kept its old (expired)
token, forcing the user to discover and run hsh tunnel login by hand.
Now optional-mode only skips silently when the daemon is GENUINELY
absent (no IPC socket on disk). When the socket exists but we can't
reach it, it's unconfigured, or its login errors, loginDaemon warns
('CLI is logged in but the daemon still holds its previous token —
run hsh tunnel login') and returns false; hsh login then exits
non-zero so the failure is visible.
2. hsh tunnel status now hints re-login on auth errors
The daemon shows Auth=authenticated whenever it merely holds a
token; a rejected/expired token only appeared as a buried
'401 Unauthorized / access denied' in last_error. status now detects
that (isAuthError) and prints a concrete next step:
'saved login expired or was rejected — hsh tunnel login'.
Tests: login-daemon.test.ts (absent → silent skip; present-but-unusable
→ failure) and tunnel-status-auth-hint.test.ts (isAuthError matches the
real serverinfo 401 string and the bare auth signals, ignores
network/route failures).
🤖 Generated with Mister Maluco
Co-Authored-By: MisterMal <teskeslab@lucasteske.dev>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Two related UX gaps found while using the newest build against
sandbox.hoop.dev:hsh loginsilently skipped a failed daemon login.loginDaemon(optional:true)treated every 'daemon not usable' case — including a daemon that is installed but whose control token couldn't be read — as 'not installed' and skipped silently. Sohsh loginreported success while the daemon kept its old (expired) token. The only way to recover was to discoverhsh tunnel loginand run it by hand.hsh tunnel statusshowedAuth: authenticatednext to an opaque401 Unauthorized. The daemon reports 'authenticated' whenever it merely holds a token; a rejected/expired token only surfaces as a buriedlast_errorHTTP string, leaving the user with no idea the fix is to log in again.Fix
Distinguish absent vs. present-but-unusable. Optional-mode now only skips silently when the daemon is genuinely absent (no IPC socket on disk). When the socket exists but the daemon is unreachable / unconfigured / its login errors,
loginDaemonwarns —— and returns false;
hsh loginexits non-zero so the failure is visible. The CLI login itself still succeeds (only the daemon leg is flagged).hsh tunnel statusauth hint. A newisAuthErrorheuristic detects 401 / unauthorized / access denied / token-expired inlast_errorand prints a concrete next step pointing athsh tunnel login.Testing
tests/login-daemon.test.ts: absent daemon → silent skip; installed-but-unauthenticatable → returns false. Driven via theHSH_TUNNELD_SOCKEToverride, no real daemon contacted.tests/tunnel-status-auth-hint.test.ts:isAuthErrormatches the real serverinfo 401 string and bare auth signals, ignores network/route failures.Context
Root cause of the stale token was the daemon storing a 12h-expiry access token with no refresh path; that's a separate, larger discussion. This PR makes the failure mode honest and actionable rather than silent.
Automated by MisterMal