Skip to content

fix(cli,mcp): keep saved token on transient errors, harden API error handling - #2

Merged
bmc08gt merged 1 commit into
mainfrom
fix/cli-mcp-token-handling
Oct 1, 2026
Merged

bmc08gt merged 1 commit into
mainfrom
fix/cli-mcp-token-handling

Conversation

@bmc08gt

@bmc08gt bmc08gt commented Oct 1, 2026

Copy link
Copy Markdown
Member

blip logs a user out whenever /v1/sessions/me returns anything other than 200. ensureToken in cli/.../client/ApiClient.kt treated a 5xx, a 429, or a network error the same as an invalid token: it created a new anonymous session and overwrote ~/.config/blip/config.json. A paying user hitting a deploy restart lost their saved token and their Pro inboxes.

CLI

  • ensureToken discards the saved token only on 401. Other failures throw "Blip API unavailable, try again" and leave the token alone. A failed POST /v1/sessions now errors instead of saving nothing.
  • config.json is created rw------- and ~/.config/blip rwx------ (skipped on non-POSIX). It held the token with default umask permissions.
  • Config.load() used to swallow parse errors and return an empty config, which then minted a new session. It now prints the file path and the parse error and exits 1.
  • blip open still passes the token in the /app?token= URL. The web app strips it on load; a one-time code exchange would avoid it entirely and is left as a follow-up. Comments mark both URL-token call sites.

MCP server

  • blipFetch maps errors to messages an agent can act on: 401 → invalid or expired key; 402 → upgrade hint; 403 → upgrade hint when the server message mentions plan/tier, otherwise "Access denied" (the server also uses 403 for resources the key doesn't own); 429 → rate-limit message with the Retry-After value.
  • wait_for_email retries 5xx, 429 and network errors with backoff from 2s to 10s (or Retry-After if larger) instead of failing the tool call. The overall timeout is unchanged.
  • zod was imported but only installed transitively through the SDK. It is now a direct dependency (~4.3.6, what the lock already resolved), and the SDK is pinned to ~1.27.1.
  • The reported server version is read from package.json; it was hardcoded 0.1.2 against package version 0.1.3.

ttl_minutes is sent as windowMinutes, which matches CreateInboxRequest: InboxService.createInbox uses it as the TTL for AGENT (capped at 90 days) and as the sniper window for PRO. No change there.

@bmc08gt bmc08gt self-assigned this Oct 1, 2026
…handling

CLI: ensureToken replaced the saved token with a new anonymous session on
any non-200 or exception from /v1/sessions/me, so a 5xx, 429 or network
error logged a paying user out. It now discards the token only on 401 and
otherwise fails with "Blip API unavailable, try again".

CLI: config.json is created owner-only (0600, dir 0700) on POSIX. A config
parse error now prints the file path and exits 1 instead of returning an
empty config that would mint a new session over the saved token.

MCP server: declare zod as a direct dependency, pin the SDK to ~1.27.1,
and report the version from package.json (was hardcoded 0.1.2 while the
package is 0.1.3). blipFetch maps 401, 402/403 tier errors and 429
(honoring Retry-After) to readable messages. wait_for_email retries 5xx,
429 and network errors with 2s-10s backoff within the existing timeout.
@bmc08gt
bmc08gt force-pushed the fix/cli-mcp-token-handling branch from 0248c69 to 7be3cb7 Compare October 1, 2026 02:20
@bmc08gt
bmc08gt merged commit bd3728e into main Oct 1, 2026
3 checks passed
@bmc08gt
bmc08gt deleted the fix/cli-mcp-token-handling branch October 1, 2026 02:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant