Repository navigation
fix(claude): drop the repeated sign-in line in the account menu and name the right Settings page - #26405
Conversation
…ame the right Settings page
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (8)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe change updates account reauthentication guidance to direct users to AI Provider Accounts. It also suppresses inactive Claude usage bars when sign-in is required and rate limits are unavailable. Tests cover the updated guidance and sign-in-related usage display. Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to The change removes redundant Claude sign-in guidance and directs users to AI Provider Accounts. The supplied tests cover the display cases, and no merge-blocking concern is evident. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 7 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 2📝 Generate docstrings 💡
🛠️ Fix failing CI checks 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…6638) Users with a saved Claude account were signed out of every Claude feature in Orca until they signed in again, and proxy setups (API key plus ANTHROPIC_BASE_URL) got 401s after signing in. Reverting before release to rework the upgrade path. The terminal daemon protocol moves forward to 43 so dev builds' v42 daemons with the claude function are not reused; v41 and v42 stay attachable. Nothing is deleted: per-account folders are left unused and the old saved-account store was never touched.
…and proxy fixes (#26801) * Revert "Revert Claude per-account folders (#24434, #26405) before release (#26638)" This reverts commit 9ca9b4e. * Move the terminal daemon protocol to 44 for the re-landed claude function v43 daemons (the revert) lack the claude account function, so new terminals must not reuse them. v42 and v43 stay attachable. * Move the local build compatibility contract to daemon protocol 44 * Point the old-terminal test at daemon protocol 44 * Claude accounts re-land: never sign anyone out, keep proxies working, accounts mirror ~/.claude (#26769) * Run a Claude account on System default until it has its own login An account saved before per-account folders has no login in its folder. While System default (~/.claude, or the user's own CLAUDE_CONFIG_DIR) is signed in to the same email, the router sends every launch there and writes that choice into the pointer file, so nobody is logged out by the update. Once the account signs in to its own folder, the next launch uses it. The WSL router follows the same rule with the guest's ~/.claude. * Refresh each Claude account folder from ~/.claude before every launch ~/.claude (or the user's own CLAUDE_CONFIG_DIR) is now the master copy. Each account folder gets its whole settings.json, including the proxy address and its key, and every .claude.json key except the login, Claude's account caches and install ids, so first-run questions are not asked again. Every other top-level entry is linked (folders) or copied (files), except Claude's per-folder daemon, jobs, live sessions, login files and throwaways. sessions is no longer shared, and an earlier link is undone. The refresh runs before every Claude Orca starts, for each new terminal and on account switch. Orca never writes back to ~/.claude. The ledger that tracked selective sharing is gone. * Route chat auth and unselected-account usage through the Claude router Chats decided whether to drop inherited Anthropic auth from the selection alone, so an account running on System default lost the user's own key. They now ask the router, as terminals, AI commit messages, automations and usage already do. Usage for an unselected account is read where its launches would run. A test reads every entry point through the fallback and fails if a launch path outside the router reads the Claude selection or builds an account folder. The router's two launch errors move to their own file to keep it under the line limit. * Show Claude account sign-in prompts only when an account cannot run With the fallback, an account System default is signed in to already works, so: - The one-time "Finish setting up your Claude accounts" toast is gone. - Accounts System default covers no longer need a sign-in: no Sign in in the status bar menu or Settings, and they can be selected. - The old-terminal banner shows only when claude in that terminal would run a different account than the selected one, and asks again after a switch. Its wording is unchanged. The retired toast's saved flag stays in the paired-client schema so an older client's write is still accepted. The email comparison moves beside the login reader to keep the router under the line limit. * Keep the user's shell Anthropic auth on Claude account launches A signed-in account's launches used to drop ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN and CLAUDE_CODE_OAUTH_TOKEN from the inherited environment while ANTHROPIC_BASE_URL passed through, so a proxy set in the shell got the subscription login and answered 401. Host launches on an account now keep the shell's auth with its address, as System default does. Chats still name the account kind in a failed sign-in, now from the router rather than from whether auth was dropped. * Share from ~/.claude only what Claude itself would seed into a new folder The deny list missed much of Claude's runtime state, so tokens, locks and live files such as .session_ingress_token, server-sessions.json and remote-control were copied or linked over each account's own every launch. The list now mirrors the one Claude uses when it seeds a fresh config folder from ~/.claude: its runtime entries, every hidden entry, daemon files and agent memory. teams, ide, downloads and scratch are on it, so they stay per folder. * Merge trusted folders and MCP servers into an account instead of replacing them Each refresh replaced the account's projects and mcpServers with ~/.claude's, so folder trust and allowed tools recorded only in the account were lost, and a refresh landing between Orca's folder-trust write and Claude's start brought the trust dialog back. Both are now merged per folder path or server name: ~/.claude wins for entries it has, the account keeps the rest, and a folder trusted in the account stays trusted. Both writers take Claude's lock on the file, so the order no longer matters. * Require the same organization before System default stands in for an account The fallback compared emails only, so one email saved for two organizations made both accounts run on whichever organization System default was signed in to. When the saved account and System default's login both name an organization, it must now match too, on the host and in WSL, and the old-terminal banner uses the same comparison. The saved-account lookup the three checks repeated is now one helper. * Treat v42 terminals as having the claude account function v42 daemons shipped the same claude function and pointer path as v44, so claude in those terminals already follows the selected account. The old-terminal banner now shows only for daemons before v42 and for v43, the revert, which dropped the function. * Fail the routing test when a new module resolves the claude binary The census only caught code that read the Claude selection, not a new launcher that runs claude without asking the router. A second check now lists every module that resolves the claude binary or loads the Agent SDK, each with why it is routed, and fails on any new one, or on a listed one that no longer matches. * Skip the account refresh on launches that run on System default A launch that falls back to System default never uses the account folder, so starting a setup for it on every launch was wasted work. Account switches still set the folder up for a later sign-in. * Give a terminal opened before the login shell's env only the account pointer At startup, a pane could be routed before the login shell reported the user's own CLAUDE_CONFIG_DIR, so the fallback compared against ~/.claude.json instead. Until that env arrives a pane gets only the pointer, and the pointer is rewritten once it does, so claude typed there reads the right folder. The recent claude --version answer moves beside the version probe to keep the router under the line limit. * Drop the chat-only Anthropic auth stripping and override refusal Chats no longer drop the shell's Anthropic auth on any account, so the chat launch's override refusal and the policy's stripAuthEnv could only be reached from test fixtures. The structured auth policy is now just which login a failed sign-in names. Terminals keep their refusal, which still guards WSL launches; the failure reason stays in the shared vocabulary for older peers. * Publish a new account state file whole The first .claude.json write went straight to the target, so a crash mid-write could leave Claude a truncated state file. It is now written to a staged file and linked into place without replacing one Claude created meanwhile. * Read an unselected WSL account's usage where the WSL router would run it Usage for an unselected WSL account read its saved folder directly, so an account the guest's ~/.claude covers showed no usage, and the read bypassed the router. It now asks the WSL router, after the same check that the distro is already running. * Keep the shell's Anthropic auth when the claude function runs an account The claude shell function (POSIX, fish and PowerShell) unset ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, CLAUDE_CODE_OAUTH_TOKEN, AWS_BEARER_TOKEN_BEDROCK and auth-like ANTHROPIC_CUSTOM_HEADERS before running Claude in an account folder, so a proxy set in the shell lost its key while keeping its address. It now only sets CLAUDE_CONFIG_DIR and Orca's marker, as on System default. Protocol 44 is unreleased, so no new bump; the shell-wrapper snapshots are regenerated. * Never drop the user's Anthropic auth from a Claude launch Orca's launches stripped ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, CLAUDE_CODE_OAUTH_TOKEN, AWS_BEARER_TOKEN_BEDROCK and auth-like ANTHROPIC_CUSTOM_HEADERS for WSL terminals, terminal splits and through the preparation's stripAuthEnv flag, and refused a launch whose agent env set them. If the user's shell overrides the login, that is their setup: every launch now keeps it, on accounts, System default and WSL alike. The flag, the strip paths and the override refusal are gone; the refusal's reason stays in the shared vocabulary so older peers still decode it. Orca's own process env and the claude --version probe still drop these variables: they are Orca's, not the user's launch. * Leave out of an account's state everything Claude resets when it signs out The .claude.json copy left out the login and keys matching cache patterns, but still carried account state such as additionalModelOptionsAnsweredAt, artifactRosterDenied, lastSeenOrgDefaultUpdatedAt and the subscription notices. The copy now leaves out the exact keys Claude resets on logout, beside the install ids, Console API key and first-token date; the cache patterns stay for account caches logout does not reset. Onboarding is still copied. * Judge an old terminal's Claude banner by the pane's own runtime The banner compared every old pane with the host selection and showed whenever only a WSL account was selected, so old host panes showed it with nothing to say and old WSL panes were judged by the host's account. The pane now names its runtime: a host pane is compared with the host selection, a WSL pane with its distro's selection through the WSL router, and a pane whose runtime is unknown, or with no account selected for it, stays hidden. * Leave an account's settings file alone when only Orca's hooks differ from the default home's * Reread a WSL account's Claude state only when the file changes * Move tests merged from main onto the account-only Claude auth policy
ELI5
In the Claude account menu, an account that needs a fresh sign-in said so twice. And one error message sent people to a Settings page by the wrong name. This removes the repeat and fixes the name.
What Changed
orcaCLI's account list had the same wrong name in "(sign in again in Orca Settings > Accounts)", and now uses the real title too.Why
The repeated line said nothing the row didn't already say. The fix is in the Claude account menu only, not in the shared usage-bar component, so other providers are untouched. The other languages have no translation of the changed message, so only the English text changed. The localization catalog generator and verifier both pass with no changes.
Linked Issue
Follow-up to #24434.
Visual Proof
Before: a saved account row showed the sign-in note, the Sign in button, and then "Sign in to see usage" underneath. After: the row shows only the note and the button. A component test covers this change, and I didn't take an after screenshot. The only other change is to message text.
Testing
New test: a Claude account that needs a sign-in no longer shows "Sign in to see usage", while a Claude account without the note still does. This test fails without the fix.
New test: another provider (Codex) with no usage still shows "Sign in to see usage".
Updated the expected text in the tests for the error message and the CLI account list.
pnpm tc; vitest onsrc/renderer/src/components/status-bar,src/renderer/src/i18n, and the CLI account tests (83 files, 735 tests pass); the localization catalog generator and verifier; oxlint;pnpm run check:code-quality:changed.I manually tested these changes locally
Automated tests added/updated, or explained why not below
AI Disclosure
Review
Agent skill upstream boundary
Notes
Only display text and a display condition change. Nothing changes for SSH, remote servers, mobile, or across platforms. On a remote server the row has no Sign in button, so it keeps showing "Sign in to see usage" exactly as before.
Checklist
N/Awith reasonpnpm lint,pnpm typecheck,pnpm test, andpnpm buildpass (or CI will cover; local preferred)