fix: Report expired sessions instead of "organization not ready" - #307
Merged
Merged
Conversation
mattdjenkinson
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Title
fix: Report expired sessions instead of "organization not ready"
Description
Summary
Before running a command, datumctl checks that the active organization has finished onboarding. Any failure of that check was reported as "We couldn't check whether this organization is ready yet. If you just finished setup in the portal, wait a moment and try again." That includes an expired or rejected session, so users with a stale login were told to wait, and switching orgs didn't help because the session is shared across orgs. Only
datumctl loginfixed it.ensureOnboardingCompletenow tells auth failures apart from other failures:UserErroralready in the chain, such as the existing "Authentication session has expired… rundatumctl login" from the token refresh, is returned as is instead of being replaced by the generic message.401, or any response whose body says "unauthenticated" or "unauthorized", shows "Your session is no longer valid. Run 'datumctl login' to re-authenticate."oauth2.RetrieveError) shows "We couldn't refresh your session." with the same hint.5xx, plain403) keeps the "not ready yet" message. A403is usually a permissions problem, and logging in again wouldn't fix it.To make this possible,
fetchOrganizationreturns a typedHTTPStatusErrorinstead of a formatted string. Its text is unchanged.The body match is a substring check, so a server error that happens to contain "unauthorized" gets the re-login message. Some gateways return auth failures with a non-401 status, so I think that trade is worth it.