auth: silent login-token refresh for git-remote-entire

Commit

toothbrush3mo ago

Device-flow login now requests offline_access, captures the returned refresh token through the poll plumbing, and persists it to the paired <service>:refresh keyring slot. git-remote-entire's login-JWT provider is now refresh-aware: an expired login JWT is re-minted from the refresh token instead of failing the operation with a re-login.

The provider is backed by auth-go's tokenmanager, which serialises refreshes across processes (advisory file lock) and goroutines and persists the rotated refresh token. That matters because the server issues single-use refresh tokens with reuse detection + family revocation: two concurrent git-remote-entire processes (e.g. a recursive submodule fetch) racing a naive refresh would replay the same token and get the whole family revoked. A thin per-context tokenstore.Store adapter maps the keyring slots onto tokenmanager.

Behaviour is a strict superset of before: a still-valid token is returned with no network call, and a context with no refresh token (a login predating this change) behaves exactly as it did — valid token used, expired token surfaces a re-login error.

Server-side support already existed in entire-core (offline_access on the device grant, refresh_token grant for the public client, rotating single-use families), so no server changes are required.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 0192d919e856

Checkpoints

Debug Cluster Context Git Remote Lookup

Claude Code
View session
Checkpoint 1