Skip to content

fix(keychain): include file store account alongside keychain entries - #275

Open
itsahedge wants to merge 1 commit into
griffinmartin:mainfrom
itsahedge:fix/include-file-store-account
Open

itsahedge wants to merge 1 commit into
griffinmartin:mainfrom
itsahedge:fix/include-file-store-account

Conversation

@itsahedge

Copy link
Copy Markdown

What & Why

On macOS, readAllClaudeAccounts() treats the keychain and ~/.claude/.credentials.json as either/or: if any keychain service matching Claude Code-credentials* parses, the credentials file is never included in the account list. A stale keychain entry (for example one left behind by an older Claude Code version that no longer maintains it) can therefore hide a perfectly healthy file store completely.

In that state the fallback machinery has nothing to work with. When the stale entry's refresh gets rate-limited, tryFallbackAccount finds no sibling account, the refresh-cooldown path returns credentials_unavailable, and a long-lived process (such as an opencode serve instance) fails every request with "Claude token refresh is rate-limited; retry shortly" while a valid token sits unused in the file, indefinitely. Observed in production: plugin_init showed a single suffixed keychain account, the file store held a token valid for hours, and the process wedged until manually restarted.

This PR includes the file store as its own account alongside keychain entries, so the existing borrow/fallback paths can rescue a wedged keychain account with the file token. Keychain-first ordering is unchanged, and the file account is skipped when a keychain account already carries the same access token, which keeps the account list identical in the common case where Claude Code writes both stores.

Changes

  • readAllClaudeAccounts() appends a source: "file" account (with its config dir and email) after keychain accounts, unless a keychain account already holds the same access token.
  • Test: a usable keychain entry plus a credentials file with a different token now yields both accounts, with the file account carrying the correct credentials and config dir.
  • Test: a keychain entry whose token matches the file store yields a single account (no duplicate).

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant