Make CSRF token handling resilient to badtoken errors - #111
Merged
Merged
Conversation
CSRF tokens fetched before mutating calls were never refreshed if MediaWiki rejected them as invalid, failing the whole operation (including mid-way through a chunked upload). Add a one-shot fetch-fresh-token-and-retry helper to MediaWikiClient (for both apiRequest-based and FormData-based chunk/commit calls) and an analogous pair of private methods to WikidataClient, and wire every mutating call site through it. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ak8tpbsoWNcVsSAhxBygf
The previous commit added new describe blocks for createPage/applySdc/ replaceCategoryInPage/nullEdit without noticing equivalent blocks already existed later in the file, creating duplicates. Merge the new badtoken-retry tests into the pre-existing blocks instead. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ak8tpbsoWNcVsSAhxBygf
MediaWikiClient had two near-identical private retry methods (apiRequestWithTokenRetry, apiUploadChunkWithTokenRetry) and WikidataClient had a third (editItemWithTokenRetry), all implementing the same fetch/reuse-token -> request -> refetch-and-retry-once-on-badtoken algorithm, differing only in how the underlying request was made. Extract this into a single withCsrfTokenRetry(label, getToken, doRequest, token?) function shared by both clients, and log a warning (with a per-call-site label, e.g. "[mw] uploadFile chunk 2/3") whenever a retry is triggered so a badtoken event is visible in logs instead of silent. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ak8tpbsoWNcVsSAhxBygf
Contributor
Confidence Score: 5/5This looks safe to merge.
Important Files Changed
Reviews (1): Last reviewed commit: "refactor: unify badtoken retry logic int..." | Re-trigger Greptile |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
MediaWiki API tokens can occasionally be rejected as invalid (
error.code === 'badtoken'), and every mutating call inMediaWikiClient/WikidataClientpreviously failed outright when that happened — including mid-way through a chunked upload, discarding chunks already staged on the server.withCsrfTokenRetryhelper: fetch/reuse a token, make the request, and onbadtokenfetch a fresh token and retry exactly once.createPage,applySdc,replaceCategoryInPage,nullEdit, both loops inuploadFile, andWikidataClient.editItem.nullEditandeditItem: neither previously inspected the API response body for anerrorfield, so abadtokenfailure was silently swallowed as success.[mw] uploadFile chunk 2/3) whenever a retry actually fires.