Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

A shell OPENAI_API_KEY overrides the profile key; its 401s retry as 5xx

Ouverte
#1,590 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
68/100
Type d'issue
Bug
Clarté
Clairement spécifiée
Activité
Active
Stack technique
go
Domaine
api, authentication, cli

Piste de recherche

Start with internal/config/apikey.go at the cited key-selection lines, then inspect internal/seniordev/app/solo.go:405-425 for retry classification. Reproduce the isolated-profile flow with codeaf doctor and senior-dev --json using the listed dev build. Done means the saved OpenRouter key is selected or an override warning is shown, and a 401 stops immediately without retries.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

area:provider bug sev:serious

Seen on: dev 837b2b0.

Behaviour

With OPENAI_API_KEY set in the shell, a headless senior-dev run used it over the profile's saved OpenRouter key (codeaf doctor: key set · OPENAI_API_KEY). Every call failed API error (401): Missing Authentication header and was retried as provider-5xx. Two problems: a key for another service silently wins over the profile's own key, and an auth failure is retried as a server error instead of stopping with a plain line.

Replication

  1. Build dev 837b2b0 (git checkout 837b2b0 && make build, binary bin/codeaf), or install the dev build with curl -fsSL https://agentfield.ai/get/devaf | bash.
  2. Use an isolated profile: export HOME=$(mktemp -d), export OPENROUTER_API_KEY, and keep the default model (~deepseek/deepseek-v4-flash-latest, crew on auto).
  3. On a busy machine set task.max_load to 0 (/settings, Tasks) so the busy-machine gate does not hold tasks.
  4. Save an OpenRouter key in the profile (first-run setup), then unset OPENROUTER_API_KEY; export OPENAI_API_KEY=sk-not-for-openrouter.
  5. codeaf doctor (see which key is used), then codeaf senior-dev --json "add a README.md with one line" in a small git repo.

Evidence

  • codeaf doctor: key set · OPENAI_API_KEY; calls fail API error (401): Missing Authentication header, retry class provider-5xx (quoted from the screen).
  • internal/config/apikey.go:53 and :61: firstNonEmpty(os.Getenv(APIKeyEnv), os.Getenv("OPENAI_API_KEY"), persistedAPIKey…) puts the shell's OPENAI key before the saved key.
  • internal/seniordev/app/solo.go:405-425: the retry classifier; the 401 reached the provider-5xx class, probably through a path where the status code was not set.

Guessed cause

A guess from reading the code, not a confirmed diagnosis. The key order prefers any OPENAI_API_KEY in the environment over the profile's key, and the retry classifier does not treat a 401 without a parsed status as permanent.

Acceptance

  • e2e: with the setup above, the run uses the saved OpenRouter key (or codeaf doctor warns that a shell key overrides it), and a 401 ends the run at once with a key message, no retries.

Found while writing the public docs; manual text differences are in #1545.

🤖 Generated with Claude Code

Langage dominant
Go
Étoiles
115
Forks
14
Merge moyen
9 h 44 min
PR mergées (30 j)
766

Préparer son environnement

Nous n'avons pas encore vérifié les fichiers d'installation de ce projet. Commencez par son README, et consultez notre guide de la première contribution pour les étapes générales.

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de Agent-Field/CodeAF

Toutes les issues de Agent-Field/CodeAF

Issues similaires

Plus d'issues Go

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.