Repository navigation
fix(cli,mcp): keep saved token on transient errors, harden API error handling - #2
Merged
Merged
Conversation
…handling CLI: ensureToken replaced the saved token with a new anonymous session on any non-200 or exception from /v1/sessions/me, so a 5xx, 429 or network error logged a paying user out. It now discards the token only on 401 and otherwise fails with "Blip API unavailable, try again". CLI: config.json is created owner-only (0600, dir 0700) on POSIX. A config parse error now prints the file path and exits 1 instead of returning an empty config that would mint a new session over the saved token. MCP server: declare zod as a direct dependency, pin the SDK to ~1.27.1, and report the version from package.json (was hardcoded 0.1.2 while the package is 0.1.3). blipFetch maps 401, 402/403 tier errors and 429 (honoring Retry-After) to readable messages. wait_for_email retries 5xx, 429 and network errors with 2s-10s backoff within the existing timeout.
bmc08gt
force-pushed
the
fix/cli-mcp-token-handling
branch
from
October 1, 2026 02:20
0248c69 to
7be3cb7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
bliplogs a user out whenever/v1/sessions/mereturns anything other than 200.ensureTokenincli/.../client/ApiClient.kttreated a 5xx, a 429, or a network error the same as an invalid token: it created a new anonymous session and overwrote~/.config/blip/config.json. A paying user hitting a deploy restart lost their saved token and their Pro inboxes.CLI
ensureTokendiscards the saved token only on 401. Other failures throw "Blip API unavailable, try again" and leave the token alone. A failedPOST /v1/sessionsnow errors instead of saving nothing.config.jsonis createdrw-------and~/.config/bliprwx------(skipped on non-POSIX). It held the token with default umask permissions.Config.load()used to swallow parse errors and return an empty config, which then minted a new session. It now prints the file path and the parse error and exits 1.blip openstill passes the token in the/app?token=URL. The web app strips it on load; a one-time code exchange would avoid it entirely and is left as a follow-up. Comments mark both URL-token call sites.MCP server
blipFetchmaps errors to messages an agent can act on: 401 → invalid or expired key; 402 → upgrade hint; 403 → upgrade hint when the server message mentions plan/tier, otherwise "Access denied" (the server also uses 403 for resources the key doesn't own); 429 → rate-limit message with theRetry-Aftervalue.wait_for_emailretries 5xx, 429 and network errors with backoff from 2s to 10s (orRetry-Afterif larger) instead of failing the tool call. The overall timeout is unchanged.zodwas imported but only installed transitively through the SDK. It is now a direct dependency (~4.3.6, what the lock already resolved), and the SDK is pinned to~1.27.1.package.json; it was hardcoded0.1.2against package version0.1.3.ttl_minutesis sent aswindowMinutes, which matchesCreateInboxRequest:InboxService.createInboxuses it as the TTL for AGENT (capped at 90 days) and as the sniper window for PRO. No change there.