Hmbown/CodeWhale · error

Codewhale-owned OAuth path has an invalid basename

Error message

Codewhale-owned OAuth path has an invalid basename

What it means

After confirming the credential path's directory, get_owned_credentials_at requires the file's basename to be either the provider's legacy file name or a valid generation name (provider.is_valid_generation). Any other basename is rejected so only known credential files can be read from the owned store.

Solutions

  1. Rename the file back to the provider's canonical (legacy or generation) file name.
  2. Use store.path_for(name) to derive the correct path instead of hardcoding it.
  3. Re-run the provider login to regenerate credentials under the canonical name.

Example fix

// before
get_owned_credentials_at(p, &dir.join("xai-backup.json"))
// after
get_owned_credentials_at(p, &dir.join(p.legacy_file_name()))
Defensive patterns

Strategy: validation

Validate before calling

const name = path.basename(requested); if (name !== provider.legacyFileName && !provider.isValidGeneration(name)) useCanonicalName(provider);

Type guard

const isValidOwnedName = (p, provider) => [path.basename(p)].some(n => n === provider.legacyFileName || provider.isValidGeneration(n));

Try / catch

try { loadOwnedAt(p); } catch (e) { if (String(e).includes('invalid basename')) loadOwnedAt(dir.join(provider.legacyFileName())); }

Prevention

When it happens

Trigger: Calling get_owned_credentials_at with a file name that is neither provider.legacy_file_name() nor a recognized generation file — e.g. "xai-old.json", a backup copy, or a typo'd name.

Common situations: Manually copying/renaming credential files for backup and pointing the API at the copy; restoring from a backup under a new name; guessing the file name instead of using path_for.

Understand the failure class

Background: "invalid id" errors: invalid identifier format — why libraries reject IDs before lookup, and how to fix them — this error's family across 37 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/08abf7015aeab18b. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/src/oauth.rs:2208

        .context("Codewhale-owned OAuth path must have a UTF-8 basename")?;
    codewhale_config::with_xai_oauth_lifecycle_lock(|store| {
        get_owned_credentials_locked(provider, store, name, |issuer, client_id, refresh| {
            refresh_for_provider(provider, client, issuer, client_id, refresh)
        })
    })
}

fn get_owned_credentials_at(provider: OAuthProvider, path: &Path) -> Result<OwnedOAuthCredentials> {
    let directory = codewhale_config::xai_oauth_credentials_dir()?;
    anyhow::ensure!(
        path.parent() == Some(directory.as_path()),
        "Codewhale-owned OAuth path escaped the credentials directory"
    );
    let name = path
        .file_name()
        .and_then(|name| name.to_str())
        .context("Codewhale-owned OAuth path must have a UTF-8 basename")?;
    anyhow::ensure!(
        name == provider.legacy_file_name() || provider.is_valid_generation(name),
        "Codewhale-owned OAuth path has an invalid basename"
    );
    codewhale_config::with_xai_oauth_lifecycle_lock(|store| {
        get_owned_credentials_locked(provider, store, name, |issuer, client_id, refresh| {
            refresh_for_provider(
                provider,
                &ReqwestOAuthFormClient,
                issuer,
                client_id,
                refresh,
            )
        })
    })
}

fn get_owned_credentials_locked<F>(
    provider: OAuthProvider,

View on GitHub (pinned to 73e0f67d83)