Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

A shell OPENAI_API_KEY overrides the profile key; its 401s retry as 5xx

Abierto
#1,590 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
68/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
go

Línea de trabajo

Start with internal/config/apikey.go at the cited key-selection lines, then inspect internal/seniordev/app/solo.go:405-425 for retry classification. Reproduce the isolated-profile flow with codeaf doctor and senior-dev --json using the listed dev build. Done means the saved OpenRouter key is selected or an override warning is shown, and a 401 stops immediately without retries.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

area:provider bug sev:serious

Seen on: dev 837b2b0.

Behaviour

With OPENAI_API_KEY set in the shell, a headless senior-dev run used it over the profile's saved OpenRouter key (codeaf doctor: key set · OPENAI_API_KEY). Every call failed API error (401): Missing Authentication header and was retried as provider-5xx. Two problems: a key for another service silently wins over the profile's own key, and an auth failure is retried as a server error instead of stopping with a plain line.

Replication

  1. Build dev 837b2b0 (git checkout 837b2b0 && make build, binary bin/codeaf), or install the dev build with curl -fsSL https://agentfield.ai/get/devaf | bash.
  2. Use an isolated profile: export HOME=$(mktemp -d), export OPENROUTER_API_KEY, and keep the default model (~deepseek/deepseek-v4-flash-latest, crew on auto).
  3. On a busy machine set task.max_load to 0 (/settings, Tasks) so the busy-machine gate does not hold tasks.
  4. Save an OpenRouter key in the profile (first-run setup), then unset OPENROUTER_API_KEY; export OPENAI_API_KEY=sk-not-for-openrouter.
  5. codeaf doctor (see which key is used), then codeaf senior-dev --json "add a README.md with one line" in a small git repo.

Evidence

  • codeaf doctor: key set · OPENAI_API_KEY; calls fail API error (401): Missing Authentication header, retry class provider-5xx (quoted from the screen).
  • internal/config/apikey.go:53 and :61: firstNonEmpty(os.Getenv(APIKeyEnv), os.Getenv("OPENAI_API_KEY"), persistedAPIKey…) puts the shell's OPENAI key before the saved key.
  • internal/seniordev/app/solo.go:405-425: the retry classifier; the 401 reached the provider-5xx class, probably through a path where the status code was not set.

Guessed cause

A guess from reading the code, not a confirmed diagnosis. The key order prefers any OPENAI_API_KEY in the environment over the profile's key, and the retry classifier does not treat a 401 without a parsed status as permanent.

Acceptance

  • e2e: with the setup above, the run uses the saved OpenRouter key (or codeaf doctor warns that a shell key overrides it), and a 401 ends the run at once with a key message, no retries.

Found while writing the public docs; manual text differences are in #1545.

🤖 Generated with Claude Code

Lenguaje dominante
Go
Estrellas
115
Forks
14
Merge medio
9 h 44 min
PR fusionados (30 d)
775

Preparar el entorno

Aún no hemos revisado los archivos de configuración de este proyecto. Empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de Agent-Field/CodeAF

Todos los issues de Agent-Field/CodeAF

Issues similares

Más issues de Go

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.