A shell OPENAI_API_KEY overrides the profile key; its 401s retry as 5xx
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 68/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- go
- Área
- api, authentication, cli
Línea de trabajo
Start with internal/config/apikey.go at the cited key-selection lines, then inspect internal/seniordev/app/solo.go:405-425 for retry classification. Reproduce the isolated-profile flow with codeaf doctor and senior-dev --json using the listed dev build. Done means the saved OpenRouter key is selected or an override warning is shown, and a 401 stops immediately without retries.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Seen on: dev 837b2b0.
Behaviour
With OPENAI_API_KEY set in the shell, a headless senior-dev run used it over the profile's saved OpenRouter key (codeaf doctor: key set · OPENAI_API_KEY). Every call failed API error (401): Missing Authentication header and was retried as provider-5xx. Two problems: a key for another service silently wins over the profile's own key, and an auth failure is retried as a server error instead of stopping with a plain line.
Replication
- Build dev 837b2b0 (
git checkout 837b2b0 && make build, binarybin/codeaf), or install the dev build withcurl -fsSL https://agentfield.ai/get/devaf | bash. - Use an isolated profile:
export HOME=$(mktemp -d), exportOPENROUTER_API_KEY, and keep the default model (~deepseek/deepseek-v4-flash-latest, crew on auto). - On a busy machine set
task.max_loadto0(/settings, Tasks) so the busy-machine gate does not hold tasks. - Save an OpenRouter key in the profile (first-run setup), then
unset OPENROUTER_API_KEY; export OPENAI_API_KEY=sk-not-for-openrouter. codeaf doctor(see which key is used), thencodeaf senior-dev --json "add a README.md with one line"in a small git repo.
Evidence
codeaf doctor:key set · OPENAI_API_KEY; calls failAPI error (401): Missing Authentication header, retry classprovider-5xx(quoted from the screen).internal/config/apikey.go:53and:61:firstNonEmpty(os.Getenv(APIKeyEnv), os.Getenv("OPENAI_API_KEY"), persistedAPIKey…)puts the shell's OPENAI key before the saved key.internal/seniordev/app/solo.go:405-425: the retry classifier; the 401 reached theprovider-5xxclass, probably through a path where the status code was not set.
Guessed cause
A guess from reading the code, not a confirmed diagnosis. The key order prefers any OPENAI_API_KEY in the environment over the profile's key, and the retry classifier does not treat a 401 without a parsed status as permanent.
Acceptance
- e2e: with the setup above, the run uses the saved OpenRouter key (or
codeaf doctorwarns that a shell key overrides it), and a 401 ends the run at once with a key message, no retries.
Found while writing the public docs; manual text differences are in #1545.
🤖 Generated with Claude Code
- Lenguaje dominante
- Go
- Estrellas
- 115
- Forks
- 14
- Merge medio
- 9 h 44 min
- PR fusionados (30 d)
- 775
Preparar el entorno
Aún no hemos revisado los archivos de configuración de este proyecto. Empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de Agent-Field/CodeAF
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Agent-Field/CodeAF#1679 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
Agent-Field/CodeAF#1678 ·
Los mantenedores suelen responder en 1 día
-
area:chat bug sev:papercut
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
Agent-Field/CodeAF#1592 ·
Los mantenedores suelen responder en 1 día
-
codeaf do "" runs a paid job with an empty briefPosiblemente ocupada @santoshkumarradha la tomó hace 2 días. Abiertoarea:headless bug sev:critical
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Agent-Field/CodeAF#1566 · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
area:chat feature
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Agent-Field/CodeAF#1510 ·
Los mantenedores suelen responder en 1 día
Todos los issues de Agent-Field/CodeAF
Issues similares
-
area: global bug dx priority: low
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
grafana/mcp-grafana#1267 ·
Los mantenedores suelen responder en 1 día
-
automation models
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
coverage-gap good-first-pattern help wanted
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
GoogleCloudPlatform/k8s-aibom#114 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
txn2/mcp-data-platform#1984 ·
Los mantenedores suelen responder en 1 día