Skip to content

fix(WCD-6067): exit auth_required on rejected login - #6

Merged
m3talux merged 2 commits into
mainfrom
fix/wcd-6067-auth-exit-code-and-timeout-without-wait
Sep 25, 2026
Merged

m3talux merged 2 commits into
mainfrom
fix/wcd-6067-auth-exit-code-and-timeout-without-wait

Conversation

@m3talux

@m3talux m3talux commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Description

  • exits auth_required instead of internal_error when the token endpoint rejects the login code
  • rejects --timeout without --wait at invocation with validation_failed, matching its documented requirement

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Chore (general housekeeping)

Related issue

WCD-6067

Related PRs

N/A

Usage

$ wcloud cluster create --timeout 5s -o json
exit 2, code validation_failed

$ wcloud auth login
token endpoint rejects the code, exit 3, code auth_required

A rejected token exchange during login returned a bare tokenError with
no error code, defaulting to internal_error/exit 1; a genuine rejected
grant (4xx, not 429) now maps to auth_required/exit 3, matching every
other not-signed-in case. 429/5xx from the token endpoint stay
unclassified/transient, mirroring the same distinction the refresh
path (RequireToken) already draws, rather than misreporting a
rate-limited or momentarily-down auth server as "not authenticated".
--timeout without --wait on cluster create was silently accepted and
ignored despite its own help text; it now fails at invocation with
validation_failed/exit 2 before any request is made. Guide updated to
name the new login-exchange-rejected outcome alongside the existing
not-signed-in/timeout ones.
@m3talux
m3talux requested a review from a team as a code owner September 25, 2026 14:32

@orca-security-eu orca-security-eu Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Infrastructure as Code high 0   medium 0   low 0   info 0 View in Orca
Passed Passed SAST high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Vulnerabilities high 0   medium 0   low 0   info 0 View in Orca

@m3talux
m3talux merged commit b38ab69 into main Sep 25, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants