Skip to content

login: wrap and propagate errors - #2

Closed
Fizzadar wants to merge 1 commit into
mainfrom
nick/login-error-propagation
Closed

Fizzadar wants to merge 1 commit into
mainfrom
nick/login-error-propagation

Conversation

@Fizzadar

Copy link
Copy Markdown
Contributor

No description provided.

The login goroutine's error was handed straight back to the provisioning API,
which replaced it with a generic 500 M_UNKNOWN "Internal error in login step".
That was doubly bad here: redditchat's status errors embed up to 500 bytes of
raw response body, which local bridges surface directly to the user.

redditchat distinguished SSO-only accounts, blocked browser verification and
rejected credentials, but only as bare errors.New values with no exported
sentinel, so none of it could be matched on. Export sentinels for those cases
plus rejected OTP codes, and map them onto declared RespErrors.

This also removes the substring match on "otp required" that gated the whole
2FA branch. It tested err.Error() against a message built inline at the call
site, so rewording that message would have silently broken OTP login rather
than failing loudly. It now uses errors.Is against the sentinel.

Also use bridgev2.ErrInvalidLoginFlowID for unknown flow IDs so they 404
instead of 500.
Fizzadar added a commit that referenced this pull request Oct 8, 2026
Port the remaining fixes from #2 onto the new step-based login. Rejected
credentials, rejected OTP codes and SSO-only accounts now have exported
sentinels in redditchat, and the connector maps those plus blocked browser
verification onto declared RespErrors instead of a generic 500. Unmapped
failures are wrapped in an M_UNKNOWN RespError so only the mapped message
reaches the client while the original error stays in the chain for logs.

Missing credentials and malformed OTP codes now 400, and unknown flow IDs
use bridgev2.ErrInvalidLoginFlowID so they 404.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Fizzadar

Fizzadar commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #3, which ports these fixes onto the reworked step-based login in 18c7892.

@Fizzadar Fizzadar closed this Oct 8, 2026
@Fizzadar
Fizzadar deleted the nick/login-error-propagation branch October 8, 2026 14:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant