{"record":{"id":"767c87e02a6a0b62","repo":"Hmbown/CodeWhale","slug":"message-device-code","errorCode":null,"errorMessage":"{message}","messagePattern":"\\{message\\}","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/config/src/device_code.rs","lineNumber":173,"sourceCode":"                        }\n                    };\n                }\n            }\n\n            // Never sleep past the code's expiry, even after slow_down backoff.\n            let remaining = deadline.saturating_duration_since(Instant::now());\n            if remaining.is_zero() {\n                break;\n            }\n            sleep(interval.min(remaining));\n        }\n\n        Err(self.timed_out(saw_slow_down))\n    }\n\n    fn timed_out(&self, saw_slow_down: bool) -> anyhow::Error {\n        match (saw_slow_down, self.slow_down_timeout_message.as_deref()) {\n            (true, Some(message)) => anyhow::anyhow!(\"{message}\"),\n            _ => anyhow::anyhow!(\"{}\", self.timeout_message),\n        }\n    }\n}\n\n/// Reject a device-code verification URI that must not be handed to a browser\n/// opener.\n///\n/// Ported from pi's `validateVerificationUri`\n/// (`packages/ai/src/auth/oauth/xai.ts`, MIT, Copyright (c) 2025 Mario\n/// Zechner): the URI comes straight off the wire and is passed to the platform\n/// \"open this\" call, so a malicious or compromised response could otherwise\n/// launch `file:`, a custom app scheme, or a helper with attacker-chosen\n/// arguments. pi requires `https:`; Codewhale additionally allows `http:` on a\n/// loopback host, which is what self-hosted issuers and the device-code tests\n/// use — matching the loopback allowance the account login already makes.\n///\n/// Embedded credentials are rejected in every case.","sourceCodeStart":155,"sourceCodeEnd":191,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/config/src/device_code.rs#L155-L191","documentation":"During the OAuth device-code flow, `timed_out` builds the terminal error when polling exceeds the allowed window. With `saw_slow_down == true` and a provider-specific `slow_down_timeout_message` configured, that message is returned instead of the generic timeout message. It lets each provider describe its own slow-down policy failure.","triggerScenarios":"The device-code polling loop (`run`) receives `slow_down` responses from the provider and ultimately exhausts its retry/timeout budget, and the device-code config supplies a `slow_down_timeout_message`.","commonSituations":"User delayed too long between opening the verification URL and entering the code, causing repeated `slow_down` responses until the flow times out.","solutions":["Restart the device-code login (`codewhale auth login` or equivalent) and complete verification promptly.","Open the verification URL immediately when shown and enter the code without long delays.","If it persists, check the provider's status page — persistent slow_down can indicate rate limiting on the account."],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"match auth.login_device_code() {\n    Err(e) if e.to_string().contains(\"slow\") || e.to_string().contains(\"timed out\") => {\n        eprintln!(\"Restart login and complete verification promptly.\");\n        auth.login_device_code()?;\n    }\n    other => other?,\n}","preventionTips":["Open the verification URL as soon as it is displayed","Do not pause or delay between receiving and entering the code","Check the provider's rate-limit status if slow_down repeats"],"tags":["oauth","device-code","timeout","rate-limit"],"backgroundTag":"request-timeout","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}