Repository navigation
fix(auth): show a temporary server error when token refresh gets 503 dependency_unavailable - #695
timmyconnect wants to merge 1 commit into
Conversation
Silo Kody — review completeReview finished. Check the inline comments for findings and verify each suggestion against the code and tests. Reviewing changes in Silo
Review settingsReview OptionsThe following review options are enabled or disabled:
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughRefresh handling now recognizes 503 ChangesRefresh outage handling
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to Waiting requests will now get the 503 temporary server problem when the database is down, rather than a misleading session-expired message. The change is small and tested. It carries no identified merge-blocking risk. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Note Grok commenting on Quick's behalf. Evidence incomplete. The PR says Missing: a before-and-after capture of that error on iOS (iPhone simulator is fine) when token refresh returns 503 |
…dependency_unavailable Requests waiting on a refresh that met a database outage failed with their original 401, which reads as "session expired" while the user is still signed in. They now fail with the 503 itself, as they already do for provider_unavailable. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ea60412 to
b657854
Compare
Silo Kody — review completeReview finished. Check the inline comments for findings and verify each suggestion against the code and tests. Reviewing changes in Silo
Review settingsReview OptionsThe following review options are enabled or disabled:
|
Problem
Closes #602
Related issue: Silo-Server/silo-server#1951
Validation tasks: none
When the Silo server cannot reach its database, it answers
POST /api/v2/auth/refreshwith 503dependency_unavailable. The app keeps its tokens, but the requests that were waiting on that refresh failed with their original 401, so iPhone, iPad, Apple TV and Mac showed "Your session has expired. Sign in again to continue." to a user who was still signed in. This change makes those requests fail with the 503, which reads as a temporary server problem.Approach
The refresh path already hands 503
provider_unavailableto the waiting requests as their error.dependency_unavailablenow takes the same route on both the ordinary and the scoped refresh. As with a provider outage, a request whose access token has not yet expired is still sent with that token.The approver-bearer path (
freshAccessToken(serverId:)) is unchanged: it keeps.providerUnavailablefor the sign-in provider only, and a database outage stays.unreachablethere, so the provider-specific wording does not appear for a database outage.Retry-Afteris not honoured; the issue lists it as optional.Validation
Evidence
Evidence: none. The error message does change, but it was verified by unit test only; no before-and-after capture was taken, because reproducing it needs a server with its database down.
Risks
None identified. Only a 503 whose problem type is
dependency_unavailableis handled differently; the session is kept in both the old and the new behaviour.Checklist
AI Disclosure
xcodebuild,xcodegen, GitHub CLI🤖 Generated with Claude Code
Note
Treat 503
dependency_unavailablerefresh failures as temporary server errors inHTTPClientisRefreshOutageandisOutageRefreshclassifiers in HTTPClient.swift. They recognize bothprovider_unavailableanddependency_unavailable503 problem responses as outages.refreshScopedTokensandrefreshTokensnow return these 503s as outage failures instead of invalidating the session. Waiting requests receive the 503 problem.dependency_unavailable503.problemIdentifierparser that extracts the final component of the problem type identifier; the provider-only predicate now uses it.ExternalSignInTests.testDatabaseOutageOnRefreshReadsAsATemporaryServerProblemcovering the 503 surfacing and token preservation.dependency_unavailableduring refresh no longer clears the session or the saved tokens; it is surfaced as a temporary server error.Macroscope summarized b657854.