Skip to content

[Bug] Windows: Antigravity CLI collector fails with "quota service did not become ready" due to missing CSRF token #140

Description

@kats1123

Summary

On Windows, the Antigravity CLI collector fails with:
level=ERROR msg="Failed to fetch Antigravity quotas" source=cli error="antigravity cli: quota service did not become ready"

Cause

In internal/api/antigravity_cli.go:

  1. Line 264 notes // No CSRF token is required for the CLI's server.
  2. On Windows, agy.exe enforces CSRF validation on its Connect-RPC endpoint. Without a token, requests return HTTP 401:
    {"code":"unauthenticated","message":"missing CSRF token"}
  3. launch() does not supply --csrf_token <token> to agy.exe, and post() does not send the X-Codeium-Csrf-Token header, causing awaitReady() to time out after 90 seconds.

Proposed Fix

  1. In launch(), generate a session token (e.g., uuid.New().String()) and pass --csrf_token <token> to agy.
  2. In post(), add header req.Header.Set("X-Codeium-Csrf-Token", r.sess.csrfToken).

Validation

Tested against agy.exe on Windows 11. Supplying --csrf_token and the X-Codeium-Csrf-Token header returns HTTP 200 with all 4 quota pools and model limits. Omitting it reproduces the 401 unauthenticated response immediately.

Note

Drafted with AI assistance during homelab deployment troubleshooting and verified on a live Windows 11 environment.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions