mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-02 05:12:11 +03:00
The Quota / Providers dashboard (POST /api/usage/provider-limits -> syncAllProviderLimits, GET /api/usage/[connectionId]) calls refreshAndUpdateCredentials() per connection, in concurrent chunks. For rotating-refresh providers (Codex/OpenAI share one Auth0 client_id) the single-use refresh_token is rotated on every refresh; refreshing siblings concurrently makes Auth0 revoke the whole token family (openai/codex#9648), killing every account but the last with [403] <!DOCTYPE html>. On the affected VM expires_at was persisted as ~0 so needsRefresh() was effectively always true -> every codex account refreshed on every page visit -> guaranteed cascade. Fix #1: refreshAndUpdateCredentials skips proactive refresh for rotating providers (rotationGroupFor) and reuses the current access_token for the quota fetch; genuine expiry is handled by the reactive, serialized 401 path. Fix #2 (defense in depth): serializeRefresh inserts a settle gap between two QUEUED sibling refreshes (default 2000ms, CODEX_REFRESH_SPACING_MS, '0' to opt out) but releases a lone refresh immediately, adding no latency to the reactive request path. Tests: codex-quota-sync-no-proactive-refresh (skip + non-rotating guard), refresh-serializer-spacing (default/opt-out + lone-vs-queued behavior).
5.6 KiB
5.6 KiB