Hmbown/CodeWhale · error
Codewhale-owned OAuth path has an invalid basename
Error message
Codewhale-owned OAuth path has an invalid basename
What it means
After confirming the credential path's directory, get_owned_credentials_at requires the file's basename to be either the provider's legacy file name or a valid generation name (provider.is_valid_generation). Any other basename is rejected so only known credential files can be read from the owned store.
Solutions
- Rename the file back to the provider's canonical (legacy or generation) file name.
- Use store.path_for(name) to derive the correct path instead of hardcoding it.
- Re-run the provider login to regenerate credentials under the canonical name.
Example fix
// before
get_owned_credentials_at(p, &dir.join("xai-backup.json"))
// after
get_owned_credentials_at(p, &dir.join(p.legacy_file_name())) Defensive patterns
Strategy: validation
Validate before calling
const name = path.basename(requested); if (name !== provider.legacyFileName && !provider.isValidGeneration(name)) useCanonicalName(provider);
Type guard
const isValidOwnedName = (p, provider) => [path.basename(p)].some(n => n === provider.legacyFileName || provider.isValidGeneration(n));
Try / catch
try { loadOwnedAt(p); } catch (e) { if (String(e).includes('invalid basename')) loadOwnedAt(dir.join(provider.legacyFileName())); } Prevention
- Do not rename or copy credential files to backup names inside the store directory
- Store backups outside the credentials directory
- Use provider.legacy_file_name()/path_for to build file names
When it happens
Trigger: Calling get_owned_credentials_at with a file name that is neither provider.legacy_file_name() nor a recognized generation file — e.g. "xai-old.json", a backup copy, or a typo'd name.
Common situations: Manually copying/renaming credential files for backup and pointing the API at the copy; restoring from a backup under a new name; guessing the file name instead of using path_for.
Understand the failure class
Background: "invalid id" errors: invalid identifier format — why libraries reject IDs before lookup, and how to fix them — this error's family across 37 libraries.
Related errors
- Codewhale-owned OAuth path escaped the credentials directory
- Codewhale-owned xAI OAuth DACL is not current-user-only
- Codewhale-owned xAI OAuth DACL must grant only one user
- Codewhale-owned xAI OAuth storage must have an owner-only…
- returned a verification URI with embedded credentials
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/08abf7015aeab18b.
Report an issue: GitHub.
Appendix: source
Thrown at crates/tui/src/oauth.rs:2208
.context("Codewhale-owned OAuth path must have a UTF-8 basename")?;
codewhale_config::with_xai_oauth_lifecycle_lock(|store| {
get_owned_credentials_locked(provider, store, name, |issuer, client_id, refresh| {
refresh_for_provider(provider, client, issuer, client_id, refresh)
})
})
}
fn get_owned_credentials_at(provider: OAuthProvider, path: &Path) -> Result<OwnedOAuthCredentials> {
let directory = codewhale_config::xai_oauth_credentials_dir()?;
anyhow::ensure!(
path.parent() == Some(directory.as_path()),
"Codewhale-owned OAuth path escaped the credentials directory"
);
let name = path
.file_name()
.and_then(|name| name.to_str())
.context("Codewhale-owned OAuth path must have a UTF-8 basename")?;
anyhow::ensure!(
name == provider.legacy_file_name() || provider.is_valid_generation(name),
"Codewhale-owned OAuth path has an invalid basename"
);
codewhale_config::with_xai_oauth_lifecycle_lock(|store| {
get_owned_credentials_locked(provider, store, name, |issuer, client_id, refresh| {
refresh_for_provider(
provider,
&ReqwestOAuthFormClient,
issuer,
client_id,
refresh,
)
})
})
}
fn get_owned_credentials_locked<F>(
provider: OAuthProvider,View on GitHub (pinned to 73e0f67d83)