Skip to content

fork: present --api-key instead of silently ignoring it - #13

Merged
LopezAdan merged 2 commits into
mainfrom
fix-fork-api-key
Sep 1, 2026
Merged

LopezAdan merged 2 commits into
mainfrom
fix-fork-api-key

Conversation

@LopezAdan

Copy link
Copy Markdown
Collaborator

--api-key is documented as valid for fork, but fork() called ctx.biscuit() directly instead of ctx.authority(), so a passed key was never presented and the command silently fell through to the cached workspace token. fork now holds either carrier the way archive does, and the client method takes Auth and posts the bearer with an empty body biscuit.

Only an account-wide key forks (ADR-0069 §3 amendment, owner ruling 2026-08-31): the fleet refuses a workspace-scoped key, whose children would be born outside its scope list. The new api_key_scoped_cannot_fork refusal gets a sentence row pointing at an unscoped keys mint, and the --api-key help says which kind of key fork takes.

Pairs with Reachpad/reachpad-infra fix-fork-api-key, which gives /fork the same rpak1-to-Biscuit exchange every other keyed route already had. Land the infra side first or together: against an old fleet, fork with a key now sends a bearer the server ignores and an empty biscuit, which refuses instead of silently using the cached token.

All test suites pass.

🤖 Generated with Claude Code

https://claude.ai/code/session_01EQwbWnXNHsyFfmj9LXwMqo

LopezAdan and others added 2 commits August 31, 2026 19:20
--api-key is documented as valid for fork, but fork() called
ctx.biscuit() directly instead of ctx.authority(), so a passed key was
never presented and the command fell through to the cached workspace
token. fork now holds either carrier the way archive does, and the
client method takes Auth and posts the bearer with an empty body
biscuit.

Only an ACCOUNT-WIDE key forks (ADR-0069 §3 amendment, 2026-08-31): the
fleet refuses a workspace-scoped key, whose children would be born
outside its scope list. The new api_key_scoped_cannot_fork refusal gets
a sentence row pointing at an unscoped `keys mint`, and the --api-key
help says which kind of key fork takes. Pairs with the controld change
that gives /fork the same rpak1-to-Biscuit exchange every other keyed
route already had.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EQwbWnXNHsyFfmj9LXwMqo
@LopezAdan
LopezAdan merged commit 83c019d into main Sep 1, 2026
2 checks passed
@LopezAdan
LopezAdan deleted the fix-fork-api-key branch September 1, 2026 16:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant