Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

A shell OPENAI_API_KEY overrides the profile key; its 401s retry as 5xx

Offen
#1,590 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
68/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
go
Bereich
api, authentication, cli

Rechercherichtung

Start with internal/config/apikey.go at the cited key-selection lines, then inspect internal/seniordev/app/solo.go:405-425 for retry classification. Reproduce the isolated-profile flow with codeaf doctor and senior-dev --json using the listed dev build. Done means the saved OpenRouter key is selected or an override warning is shown, and a 401 stops immediately without retries.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

area:provider bug sev:serious

Seen on: dev 837b2b0.

Behaviour

With OPENAI_API_KEY set in the shell, a headless senior-dev run used it over the profile's saved OpenRouter key (codeaf doctor: key set · OPENAI_API_KEY). Every call failed API error (401): Missing Authentication header and was retried as provider-5xx. Two problems: a key for another service silently wins over the profile's own key, and an auth failure is retried as a server error instead of stopping with a plain line.

Replication

  1. Build dev 837b2b0 (git checkout 837b2b0 && make build, binary bin/codeaf), or install the dev build with curl -fsSL https://agentfield.ai/get/devaf | bash.
  2. Use an isolated profile: export HOME=$(mktemp -d), export OPENROUTER_API_KEY, and keep the default model (~deepseek/deepseek-v4-flash-latest, crew on auto).
  3. On a busy machine set task.max_load to 0 (/settings, Tasks) so the busy-machine gate does not hold tasks.
  4. Save an OpenRouter key in the profile (first-run setup), then unset OPENROUTER_API_KEY; export OPENAI_API_KEY=sk-not-for-openrouter.
  5. codeaf doctor (see which key is used), then codeaf senior-dev --json "add a README.md with one line" in a small git repo.

Evidence

  • codeaf doctor: key set · OPENAI_API_KEY; calls fail API error (401): Missing Authentication header, retry class provider-5xx (quoted from the screen).
  • internal/config/apikey.go:53 and :61: firstNonEmpty(os.Getenv(APIKeyEnv), os.Getenv("OPENAI_API_KEY"), persistedAPIKey…) puts the shell's OPENAI key before the saved key.
  • internal/seniordev/app/solo.go:405-425: the retry classifier; the 401 reached the provider-5xx class, probably through a path where the status code was not set.

Guessed cause

A guess from reading the code, not a confirmed diagnosis. The key order prefers any OPENAI_API_KEY in the environment over the profile's key, and the retry classifier does not treat a 401 without a parsed status as permanent.

Acceptance

  • e2e: with the setup above, the run uses the saved OpenRouter key (or codeaf doctor warns that a shell key overrides it), and a 401 ends the run at once with a key message, no retries.

Found while writing the public docs; manual text differences are in #1545.

🤖 Generated with Claude Code

Vorherrschende Sprache
Go
Sterne
115
Forks
14
Ø Merge
9 Std. 37 Min.
Gemergte PRs (30 T.)
755

Entwicklungsumgebung

Die Einrichtungsdateien dieses Projekts haben wir noch nicht geprüft. Beginnen Sie mit der README; die allgemeinen Schritte stehen in unserem Leitfaden für den ersten Beitrag.

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus Agent-Field/CodeAF

Alle Issues in Agent-Field/CodeAF

Ähnliche Issues

Weitere Issues zu Go

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.