Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

A shell OPENAI_API_KEY overrides the profile key; its 401s retry as 5xx

オープン
#1,590 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
68/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
go

調査の方向性

Start with internal/config/apikey.go at the cited key-selection lines, then inspect internal/seniordev/app/solo.go:405-425 for retry classification. Reproduce the isolated-profile flow with codeaf doctor and senior-dev --json using the listed dev build. Done means the saved OpenRouter key is selected or an override warning is shown, and a 401 stops immediately without retries.

索引モデルが issue の本文から書いたものです。

説明

area:provider bug sev:serious

Seen on: dev 837b2b0.

Behaviour

With OPENAI_API_KEY set in the shell, a headless senior-dev run used it over the profile's saved OpenRouter key (codeaf doctor: key set · OPENAI_API_KEY). Every call failed API error (401): Missing Authentication header and was retried as provider-5xx. Two problems: a key for another service silently wins over the profile's own key, and an auth failure is retried as a server error instead of stopping with a plain line.

Replication

  1. Build dev 837b2b0 (git checkout 837b2b0 && make build, binary bin/codeaf), or install the dev build with curl -fsSL https://agentfield.ai/get/devaf | bash.
  2. Use an isolated profile: export HOME=$(mktemp -d), export OPENROUTER_API_KEY, and keep the default model (~deepseek/deepseek-v4-flash-latest, crew on auto).
  3. On a busy machine set task.max_load to 0 (/settings, Tasks) so the busy-machine gate does not hold tasks.
  4. Save an OpenRouter key in the profile (first-run setup), then unset OPENROUTER_API_KEY; export OPENAI_API_KEY=sk-not-for-openrouter.
  5. codeaf doctor (see which key is used), then codeaf senior-dev --json "add a README.md with one line" in a small git repo.

Evidence

  • codeaf doctor: key set · OPENAI_API_KEY; calls fail API error (401): Missing Authentication header, retry class provider-5xx (quoted from the screen).
  • internal/config/apikey.go:53 and :61: firstNonEmpty(os.Getenv(APIKeyEnv), os.Getenv("OPENAI_API_KEY"), persistedAPIKey…) puts the shell's OPENAI key before the saved key.
  • internal/seniordev/app/solo.go:405-425: the retry classifier; the 401 reached the provider-5xx class, probably through a path where the status code was not set.

Guessed cause

A guess from reading the code, not a confirmed diagnosis. The key order prefers any OPENAI_API_KEY in the environment over the profile's key, and the retry classifier does not treat a 401 without a parsed status as permanent.

Acceptance

  • e2e: with the setup above, the run uses the saved OpenRouter key (or codeaf doctor warns that a shell key overrides it), and a 401 ends the run at once with a key message, no retries.

Found while writing the public docs; manual text differences are in #1545.

🤖 Generated with Claude Code

主要言語
Go
スター
115
フォーク
14
平均マージ
9時間 37分
マージ済み PR(30日)
755

環境構築

このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

Agent-Field/CodeAF のほかの issue

Agent-Field/CodeAF の issue をすべて見る

似ている issue

Go の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。