Repository navigation
api: report clear error when refresh token is rejected - #362
NanShanFish wants to merge 1 commit into
Conversation
|
Confirmed against a self-hosted Vaultwarden, and the red Reproduction. rbw 1.15.0, Vaultwarden, refresh token no longer accepted: The identity endpoint answers exactly as this PR assumes: That body is 25 bytes, which is where "column 25" comes from. So The lint failure is pre-existing drift. I checked out f51c504 (this PR) and 77464d4 (master) and ran the lint job's commands locally with clippy 0.1.98. Both fail the same four lints:
None of them is in this diff; the api.rs one is the same pre-existing function, shifted by the lines added here. |
Problem
rbw sync(and any command that needs to refresh the access token) reports a confusing error when the server rejects the stored refresh token:Cause:
exchange_refresh_tokenandexchange_refresh_token_asyncdeserialize the response body unconditionally. When the identity server returns an error like{"error":"invalid_grant"}(HTTP 400), serde fails withmissing field 'access_token', masking the real cause. This is a common real-world scenario: the refresh token has been revoked or has expired (e.g. after changing the master password), leaving the user without an actionable recovery path.Relates to #32.
Changes
src/api.rs: check the response status code before parsing the response in bothexchange_refresh_token*functions. On a non-200 response, parse the standardConnectErrorResand classify it through a newclassify_refresh_token_errorhelper (consistent with the existingclassify_login_errorpattern):invalid_grant→ newError::RefreshTokenInvalidinvalid_client→Error::IncorrectApiKeyError::RequestFailedsrc/error.rs: addError::RefreshTokenInvalid, with an error message telling users how to recover (rbw purgefollowed byrbw login).invalid_grant,invalid_client).Result
Note: this fix targets
doy/rbwupstream; the PR currently lives on the fork.