Probe an agent's token through its person record in auth status and doctor - #785
Conversation
…octor
`auth status --check` and doctor's API Connectivity check both asked
/authorization.json whether the server accepts the token. Basecamp
refuses every agent self-token there, since it has no identity behind
it, so a working agent profile was reported as rejected ("valid": false)
and as "Cannot connect to Basecamp API".
Both now take the path `me` takes for an agent profile: its person
record in the account it is bound to. The detection moves into one
helper, agentProfile, shared by all three.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Account validation ordering and authorization-header coverage must be fixed; the help text also needs updating.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Updates agent-token validation to use the account-scoped person record instead of /authorization.json.
Changes:
- Centralizes agent-profile detection.
- Updates auth status and doctor connectivity probes.
- Adds regression tests for agent-token probes.
| File | Review |
|---|---|
internal/commands/people.go |
Adds shared agent-profile detection. |
internal/commands/doctor.go |
Probes agent connectivity through the person record. |
internal/commands/auth.go |
Adds the account-scoped probe, but validates the account too late and leaves help text inaccurate. |
internal/commands/agent_probe_test.go |
Covers probe paths, but does not verify the bearer token. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
--check on an agent profile with no account now says so before any token is minted, and its help names the person-record probe. The probe tests also require the agent's own bearer token.
|
@codex review |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |


Stacked on #784 (base:
fix-me-agent-profile). Follow-up to the "Not changed here" note there, from this card.What was wrong
basecamp auth status --checkand doctor's "API Connectivity" check both ask/authorization.jsonwhether the server accepts the token. Basecamp answers 401 to every agent self-token there, because the token has no identity behind it (see #784). So a working agent profile was reported as:auth status --check:"valid": falsedoctor:API Connectivity: fail — Cannot connect to Basecamp API: Authorization failed: invalid or expired tokenBoth are confirmed by the new tests, which fail on
fix-me-agent-profilewith exactly those results and a request to/authorization.json.What changed
agentProfile(app)(inpeople.go) is the one check for "requests go out on a stored agent credential":BASECAMP_TOKENunset and storedoauth_typeisagent.menow uses it instead of its inline condition.checkWithServer(auth status--check): for an agent profile, it sends the same freshly produced token to/{account}/my/profile.jsoninstead of/authorization.json. The verdict logic after the request is unchanged, so an auth-class refusal there still reads as "rejected".checkAPIConnectivity(doctor): for an agent profile, it reads the person record through the account client.BASECAMP_TOKENare unchanged.Tests
agent_probe_test.go:TestAuthStatusCheckAcceptsAValidAgentTokenandTestDoctorAPIConnectivityPassesForAValidAgentToken. Each stores a valid agent credential against a fake server that refuses/authorization.json. They assert the probe passes and that only/555/my/profile.jsonwas requested.Summary by cubic
auth status --checkand doctor's API Connectivity check now validate agent tokens through the agent's person record instead of/authorization.json.Basecamp refuses every agent self-token at
/authorization.jsonbecause the token has no identity behind it, so a working agent profile was reported as"valid": falseand as "Cannot connect to Basecamp API". Both checks now probe/{account}/my/profile.jsonfor agent profiles, matching the pathmetakes.agentProfilehelper used byme,auth status --check, and doctor.BASECAMP_TOKENusage are unchanged./555/my/profile.json, plus a test for the missing-account case.Written for commit 8424aa9. Summary will update on new commits.