login: skip unreachable legacy entry for non-default --server, redact URL errors

main

Commit

toothbrush3mo ago

Address PR #1404 review comments and the broken login integration tests:

  • Every legacy-keyring read keys by api.AuthBaseURL(), which is always the default origin now — a legacy entry saved under a non-default --server origin was unreadable forever and undeletable by logout (Bugbot's logout finding, fixed at the write side instead). For a non-default server the context is the sole record of the login, so RecordLoginContext failure becomes fatal there instead of a warning.
  • parseLoginServer errors now echo u.Redacted() rather than the raw flag value, so a password in a rejected userinfo URL can't land in CI logs.
  • The login integration tests still exported the retired ENTIRE_AUTH_BASE_URL (rejected at startup since 6e40fcaa432) and served the v1 device-code path the default split-host provider no longer uses. They now pass --server, serve /device_authorization, mint an iss-bearing fake JWT (context recording needs claims), and sandbox ENTIRE_CONFIG_DIR/token store so the spawned binary can't touch the real ~/.config/entire or OS keychain.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com Entire-Checkpoint: 6849b1e6a444

Checkpoints

Address PR #1404 Login Review Comments

Claude CodeFable 5.[1m]
View session
Checkpoint 1