fork: present --api-key instead of silently ignoring it - #13
Merged
Merged
Conversation
--api-key is documented as valid for fork, but fork() called ctx.biscuit() directly instead of ctx.authority(), so a passed key was never presented and the command fell through to the cached workspace token. fork now holds either carrier the way archive does, and the client method takes Auth and posts the bearer with an empty body biscuit. Only an ACCOUNT-WIDE key forks (ADR-0069 §3 amendment, 2026-08-31): the fleet refuses a workspace-scoped key, whose children would be born outside its scope list. The new api_key_scoped_cannot_fork refusal gets a sentence row pointing at an unscoped `keys mint`, and the --api-key help says which kind of key fork takes. Pairs with the controld change that gives /fork the same rpak1-to-Biscuit exchange every other keyed route already had. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EQwbWnXNHsyFfmj9LXwMqo
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VLbzGZPZLCHZSng8deSdeb
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
--api-key is documented as valid for fork, but fork() called ctx.biscuit() directly instead of ctx.authority(), so a passed key was never presented and the command silently fell through to the cached workspace token. fork now holds either carrier the way archive does, and the client method takes Auth and posts the bearer with an empty body biscuit.
Only an account-wide key forks (ADR-0069 §3 amendment, owner ruling 2026-08-31): the fleet refuses a workspace-scoped key, whose children would be born outside its scope list. The new api_key_scoped_cannot_fork refusal gets a sentence row pointing at an unscoped
keys mint, and the --api-key help says which kind of key fork takes.Pairs with Reachpad/reachpad-infra fix-fork-api-key, which gives /fork the same rpak1-to-Biscuit exchange every other keyed route already had. Land the infra side first or together: against an old fleet, fork with a key now sends a bearer the server ignores and an empty biscuit, which refuses instead of silently using the cached token.
All test suites pass.
🤖 Generated with Claude Code
https://claude.ai/code/session_01EQwbWnXNHsyFfmj9LXwMqo