{"record":{"id":"d69ae6f6685126dc","repo":"jdx/mise","slug":"brew-cask-requested-token-requested-token-doe-d69ae6","errorCode":null,"errorMessage":"brew-cask: requested token '{requested_token}' does not match API token '{}'","messagePattern":"brew-cask: requested token '(.+?)' does not match API token '(.+?)'","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/system/packages/brew/cask/fetch.rs","lineNumber":122,"sourceCode":"    validate_cask_identity(&cask, requested_token, official_api)?;\n    Ok(cask)\n}\n\npub(super) fn validate_cask_identity(\n    cask: &Cask,\n    requested_token: &str,\n    official_api: bool,\n) -> Result<()> {\n    validate_cask_path_component(\"API token\", &cask.token)?;\n    validate_cask_path_component(\"version\", &cask.version)?;\n    let trusted_alias = official_api\n        && cask\n            .aliases\n            .iter()\n            .chain(&cask.old_tokens)\n            .any(|alias| alias == requested_token);\n    if cask.token != requested_token && !trusted_alias {\n        bail!(\n            \"brew-cask: requested token '{requested_token}' does not match API token '{}'\",\n            cask.token\n        );\n    }\n    Ok(())\n}\n\npub(super) fn validate_cask_path_component(kind: &str, value: &str) -> Result<()> {\n    let mut components = Path::new(value).components();\n    let valid = !value.is_empty()\n        && !value.contains('\\0')\n        && !value.contains('\\\\')\n        && matches!(components.next(), Some(Component::Normal(_)))\n        && components.next().is_none()\n        && value != \".metadata\"\n        && !value.starts_with(\".mise-\");\n    if !valid {\n        bail!(\"brew-cask: invalid {kind} '{value}'\");","sourceCodeStart":104,"sourceCodeEnd":140,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/system/packages/brew/cask/fetch.rs#L104-L140","documentation":"`validate_cask_identity` verifies that the token the user requested matches the token reported by the fetched Homebrew API cask JSON, allowing trusted aliases listed in the cask's `aliases`/`old_tokens`. A mismatch means the API returned metadata for a different cask than asked for — possibly a redirect, renamed cask, or spoofed/incorrect mapping — so the fetch is aborted rather than installing the wrong software.","triggerScenarios":"fetch_cask or fetch_cask_url fetches cask JSON whose `token` field differs from `requested_token` and the requested token is not in the cask's `aliases` or `old_tokens` lists.","commonSituations":"A cask was renamed upstream while a cached or pinned token was used; a tap's token-to-JSON mapping is wrong; a shorthand/alias was guessed by the user that is not an official alias.","solutions":["Use the exact API token reported in the error message as the requested token","Refresh cask metadata/caches so renamed tokens resolve to their new names","If the old name should still work, add it to the cask's `aliases`/`old_tokens` in the tap"],"exampleFix":"// before\nbrew-cask install \"old-cask-name\"\n// after\nbrew-cask install \"new-cask-name\"","handlingStrategy":"validation","validationCode":"// After fetching cask JSON, confirm the token identity before installing\nif api_json[\"token\"] != requested_token\n    && !api_json[\"aliases\"].as_array().map_or(false, |a| a.iter().any(|v| v == requested_token))\n    && !api_json[\"old_tokens\"].as_array().map_or(false, |a| a.iter().any(|v| v == requested_token)) {\n    eprintln!(\"requested token {} does not match API token {}\", requested_token, api_json[\"token\"]);\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use the exact token returned by the API, not a guessed shorthand","Refresh cached cask metadata after upstream renames","Verify alias names exist before scripting installs"],"tags":["homebrew","cask","identity-mismatch","token"],"backgroundTag":"unexpected-response-shape","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}