cli: reject claim-free login tokens at validation, not at save

main

Commit

toothbrush3mo ago

An opaque or claims-free token could never complete a login — RecordLoginContext keys the context and keychain slot on iss and handle/sub — but it only failed at the save step with a bare parse error. validateReceivedToken now requires parseable claims, iss, and handle-or-sub up front, with errors naming the requirement.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com Entire-Checkpoint: 6c73d489af9e

Checkpoints

Auth Refactor: Eliminate Static Fallbacks

Claude CodeFable 5.[1m]
View session
Checkpoint 1