mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-29 18:46:59 +00:00
refactor(photon): route setup token check through validate_photon_token
Maintainer follow-up to the #72763 salvage: check_photon_token_valid() now delegates to the existing validate_photon_token() (session lookup + /api/projects/) instead of a bespoke get-session-only probe, since the device flow can mint tokens that pass the session check but fail the project APIs that setup actually uses. Semantics preserved: definitive auth rejection = stale, transient errors = probably-valid.
This commit is contained in:
parent
cd158466d1
commit
eccf39dded
1 changed files with 10 additions and 7 deletions
|
|
@ -201,18 +201,21 @@ def clear_photon_token() -> None:
|
|||
def check_photon_token_valid(token: str) -> bool:
|
||||
"""Return True if the token is accepted by the dashboard API.
|
||||
|
||||
Makes a lightweight ``GET /api/auth/get-session`` call. A non-401
|
||||
response (including non-auth errors like network blips) is treated as
|
||||
"probably valid" so transient failures don't force unnecessary re-login.
|
||||
Only a definitive 401 / 403 is treated as stale.
|
||||
Delegates to :func:`validate_photon_token`, which checks both
|
||||
``/api/auth/get-session`` and ``/api/projects/`` — the device flow can
|
||||
mint tokens that pass the session lookup but are rejected by the project
|
||||
APIs, and setup's management calls all hit the project APIs. A
|
||||
definitive rejection (``PhotonDashboardAuthError``) is treated as stale;
|
||||
transient failures (network blips, 5xx) are treated as "probably valid"
|
||||
so they don't force an unnecessary re-login.
|
||||
"""
|
||||
if not token:
|
||||
return False
|
||||
try:
|
||||
resp = _dashboard_get("/api/auth/get-session", token)
|
||||
if resp.status_code in (401, 403):
|
||||
return False
|
||||
validate_photon_token(token)
|
||||
return True
|
||||
except PhotonDashboardAuthError:
|
||||
return False
|
||||
except Exception:
|
||||
# Transient error — don't force a re-auth; let the caller's
|
||||
# management-call error propagate if the token really is bad.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue