auth: make logout credential deletion part of the success contract

main

Commit

toothbrush3mo ago

Review finding: RemoveCurrentContext/RemoveContext deleted the contexts.json entry first and swallowed keyring-delete failures, so a locked or failing keychain still printed "Logged out." while the long-lived refresh token survived, mintable by any keyring-capable process. Deletion now runs credentials-first (refresh slot before access, so a partial failure strands at worst the short-lived token) and any failure aborts with the entry intact — the benign direction: the context reads as not logged in and a retry no-ops the deletes.

Also rewords the login-token validation comments: opaque tokens pass the trust check but can no longer complete a login — RecordLoginContext is the sole persistence path and requires iss/handle claims; legacy opaque-token servers are intentionally unsupported.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com Entire-Checkpoint: ac4fd24010aa

Checkpoints

Auth Refactor: Eliminate Static Fallbacks

Claude CodeFable 5.[1m]
View session
Checkpoint 1