Skip to content

fix: Report expired sessions instead of "organization not ready" - #307

Merged
JoseSzycho merged 1 commit into
mainfrom
fix/onboarding-auth-errors
Oct 1, 2026
Merged

JoseSzycho merged 1 commit into
mainfrom
fix/onboarding-auth-errors

Conversation

@JoseSzycho

Copy link
Copy Markdown
Contributor

Title

fix: Report expired sessions instead of "organization not ready"

Description

Summary

Before running a command, datumctl checks that the active organization has finished onboarding. Any failure of that check was reported as "We couldn't check whether this organization is ready yet. If you just finished setup in the portal, wait a moment and try again." That includes an expired or rejected session, so users with a stale login were told to wait, and switching orgs didn't help because the session is shared across orgs. Only datumctl login fixed it.

ensureOnboardingComplete now tells auth failures apart from other failures:

  • A UserError already in the chain, such as the existing "Authentication session has expired… run datumctl login" from the token refresh, is returned as is instead of being replaced by the generic message.
  • A 401, or any response whose body says "unauthenticated" or "unauthorized", shows "Your session is no longer valid. Run 'datumctl login' to re-authenticate."
  • Any other failed token refresh (oauth2.RetrieveError) shows "We couldn't refresh your session." with the same hint.
  • Everything else (network errors, 5xx, plain 403) keeps the "not ready yet" message. A 403 is usually a permissions problem, and logging in again wouldn't fix it.

To make this possible, fetchOrganization returns a typed HTTPStatusError instead of a formatted string. Its text is unchanged.

The body match is a substring check, so a server error that happens to contain "unauthorized" gets the re-login message. Some gateways return auth failures with a non-401 status, so I think that trade is worth it.

@JoseSzycho
JoseSzycho merged commit e0c5c69 into main Oct 1, 2026
2 checks passed
@JoseSzycho
JoseSzycho deleted the fix/onboarding-auth-errors branch October 1, 2026 12:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants