Repository navigation
Report a rejected Azure DevOps PAT as AuthFailed instead of faulting the update loop - #352
Merged
Merged
Conversation
…ting the update loop [patch] A rejected PAT surfaces as VssUnauthorizedException, which derives from VssException rather than VssServiceException, so it escaped both EnsureAzureDevOpsClients and the 401 handler in MakeAzureDevOpsRequestAsync. The escape faulted UpdateAsync, which stopped GitHub polling and re-ran discovery back-to-back, and the token was never cleared or shown as AuthFailed. Catch it in both places and route it to OnAuthenticationFailure. The provider takes its session factory through an internal constructor so a test can stand in for dev.azure.com refusing the token. Fixes #305 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0118yDY82foMMXSZ6XaQmc4c
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Fixes #305
Before: an expired or wrong Azure DevOps PAT made dev.azure.com throw
VssUnauthorizedException. That type derives fromVssException, notVssServiceException, so it got past both handlers in the provider. The exception faultedUpdateAsync, which stopped GitHub polling and re-ran discovery on every frame. The bad token was never cleared and the status bar never showed AuthFailed.After: both places catch
VssUnauthorizedExceptionand callOnAuthenticationFailure(). That clears the organization and token and sets the status to AuthFailed.EnsureAzureDevOpsClients: building the clients authenticates, so this is where an expired PAT shows up first.MakeAzureDevOpsRequestAsync: catches the same exception next to the existing 401VssServiceResponseExceptionhandler.Supporting changes:
AzureDevOpshas an internal constructor that takes the session factory, so a test can play the part of dev.azure.com rejecting the token. The public parameterless constructor still connects to dev.azure.com, and JSON deserialization still uses it.BuildProvider.AccountIdsetter is nowinternalinstead ofprivate, so the test can configure an organization. It is still[JsonInclude].The issue's suggestion to also catch
HttpRequestException(being offline at startup) is not in this PR. That failure is transient, and #299 (hardeningUpdateAsync) is the right place for it.Tests
New
AzureDevOpsAuthFailureTests:EnsureAzureDevOpsClientsreturns no lease, and the status is AuthFailed.UpdateRepositoriesAsyncwith a rejected token doesn't throw. A throw there is what faulted the loop and stopped GitHub polling.VssUnauthorizedExceptionreports AuthFailed.All four fail with the two catch blocks removed and pass with them in place. Full suite: 94/94 passing locally on Linux.
🤖 Generated with Claude Code
https://claude.ai/code/session_0118yDY82foMMXSZ6XaQmc4c
Generated by Claude Code