1use super::*;
2
3pub const IMMEDIATE_CREDENTIAL_SYNC_COOLDOWN: Duration = Duration::from_secs(5 * 60);
6
7#[derive(Debug, Clone, PartialEq, Eq)]
8pub(super) struct PendingCredentialSync {
9 pub(super) signal: CredentialSyncSignal,
10 pub(super) profile_id: String,
11}
12
13#[derive(Debug, Default)]
16pub struct CredentialSyncSignalTracker {
17 pub(super) handled_ordinals: std::collections::BTreeMap<String, u64>,
18 pub(super) last_attempts: std::collections::BTreeMap<String, Instant>,
19 pub(super) pending: std::collections::BTreeMap<String, PendingCredentialSync>,
20}
21
22impl CredentialSyncSignalTracker {
23 pub fn observe(&mut self, session_id: &str, profile_id: &str, signal: CredentialSyncSignal) {
24 if self
25 .handled_ordinals
26 .get(session_id)
27 .is_some_and(|handled| *handled >= signal.ordinal)
28 {
29 return;
30 }
31 let pending = PendingCredentialSync {
32 signal,
33 profile_id: profile_id.to_owned(),
34 };
35 match self.pending.entry(session_id.to_owned()) {
36 std::collections::btree_map::Entry::Vacant(entry) => {
37 entry.insert(pending);
38 }
39 std::collections::btree_map::Entry::Occupied(mut entry)
40 if entry.get().signal.ordinal <= pending.signal.ordinal =>
41 {
42 entry.insert(pending);
43 }
44 std::collections::btree_map::Entry::Occupied(_) => {}
45 }
46 }
47
48 pub(super) fn drain_due(
49 &mut self,
50 now: Instant,
51 ) -> Vec<(String, String, CredentialSyncReason)> {
52 let due = self
53 .pending
54 .keys()
55 .filter(|session_id| {
56 self.last_attempts.get(*session_id).is_none_or(|previous| {
57 now.saturating_duration_since(*previous) >= IMMEDIATE_CREDENTIAL_SYNC_COOLDOWN
58 })
59 })
60 .cloned()
61 .collect::<Vec<_>>();
62 due.into_iter()
63 .map(|session_id| {
64 let pending = self
65 .pending
66 .remove(&session_id)
67 .expect("due credential sync signal disappeared");
68 self.handled_ordinals
69 .insert(session_id.clone(), pending.signal.ordinal);
70 self.last_attempts.insert(session_id.clone(), now);
71 (session_id, pending.profile_id, pending.signal.reason)
72 })
73 .collect()
74 }
75}
76
77pub fn schedule_due_credential_syncs(
78 tracker: &mut CredentialSyncSignalTracker,
79 credential_sync: &CredentialSyncHandle,
80 now: Instant,
81) {
82 for (session_id, profile_id, reason) in tracker.drain_due(now) {
83 credential_sync.sync_profile_now(
84 &profile_id,
85 Some(CredentialSyncCause { session_id, reason }),
86 );
87 }
88}
89
90#[derive(Debug, Default)]
98pub struct CredentialSyncNotices {
99 pub(super) last_failures: std::collections::BTreeMap<(String, Option<String>), String>,
100}
101
102pub fn log_credential_sync_actions(result: &mj_core::credentials::CredentialSyncResult) {
103 let sessions = result.credential_sessions();
104 if sessions > 0 {
105 tracing::info!(
106 profile_id = %result.profile_id,
107 sessions,
108 "refreshed harness credentials"
109 );
110 }
111}
112
113pub(super) fn setup_token_advice(
119 profile_id: &str,
120 harness: Option<mj_core::config::HarnessKind>,
121) -> String {
122 if harness == Some(mj_core::config::HarnessKind::Claude) {
123 format!(
124 ", or store a long-lived token with `mj login --profile {profile_id} --setup-token`"
125 )
126 } else {
127 String::new()
128 }
129}
130
131impl CredentialSyncNotices {
132 pub fn notice(
135 &mut self,
136 result: &mj_core::credentials::CredentialSyncResult,
137 harness: Option<mj_core::config::HarnessKind>,
138 state: &State,
139 ) -> Option<String> {
140 let advice = setup_token_advice(&result.profile_id, harness);
141 if let Some(trigger) = &result.trigger {
144 let session_id = &trigger.session_id;
145 let session = state.session_notice_name(session_id);
146 let sync_failure = result.failure.as_deref().or_else(|| {
147 result.failures().find_map(|(failed_session, detail)| {
148 (failed_session == session_id).then_some(detail)
149 })
150 });
151 if let Some(detail) = sync_failure {
152 return Some(match trigger.reason {
153 CredentialSyncReason::AuthenticationFailure => format!(
154 "Auth failure on profile {} (session {}); credential reconciliation failed: {detail}. Run `mj login --profile {}`{advice}.",
155 result.profile_id, session, result.profile_id
156 ),
157 CredentialSyncReason::EmptyPromptResponse => format!(
158 "Session {} returned no response; credential reconciliation for profile {} failed: {detail}. The failure is recorded in the transcript.",
159 session, result.profile_id
160 ),
161 });
162 }
163 return Some(match (trigger.reason, result.pushed_to(session_id)) {
166 (CredentialSyncReason::AuthenticationFailure, true) => format!(
167 "Auth failure on profile {} (session {}); refreshed credentials were pushed. Retry the prompt, and if it repeats run `mj login --profile {}`{advice}.",
168 result.profile_id, session, result.profile_id
169 ),
170 (CredentialSyncReason::AuthenticationFailure, false) => format!(
171 "Auth failure on profile {} (session {}); nothing fresher to push. Run `mj login --profile {}`{advice}.",
172 result.profile_id, session, result.profile_id
173 ),
174 (CredentialSyncReason::EmptyPromptResponse, true) => format!(
175 "Session {} returned no response; fresher credentials from profile {} were pushed. Retry the prompt.",
176 session, result.profile_id
177 ),
178 (CredentialSyncReason::EmptyPromptResponse, false) => format!(
179 "Session {} returned no response; profile {} had no newer credentials to push. The failure is recorded in the transcript.",
180 session, result.profile_id
181 ),
182 });
183 }
184
185 let mut failures = std::collections::BTreeMap::new();
186 if let Some(detail) = &result.failure {
187 failures.insert(
188 (result.profile_id.clone(), None),
189 format!(
190 "Credential sync for profile {} failed: {detail}",
191 result.profile_id
192 ),
193 );
194 }
195 for (session_id, detail) in result.failures() {
196 failures.insert(
197 (result.profile_id.clone(), Some(session_id.to_owned())),
198 format!(
199 "Credential sync for profile {} (session {}) failed: {detail}",
200 result.profile_id,
201 state.session_notice_name(session_id)
202 ),
203 );
204 }
205 self.last_failures
208 .retain(|key, _| key.0 != result.profile_id || failures.contains_key(key));
209 let mut notice = None;
210 for (key, message) in failures {
211 if self.last_failures.get(&key) != Some(&message) {
212 notice.get_or_insert_with(|| message.clone());
213 }
214 self.last_failures.insert(key, message);
215 }
216 if notice.is_some() {
217 return notice;
218 }
219
220 let mut parts = Vec::new();
221 let skills = result.skills_sessions();
222 if skills > 0 {
223 parts.push(format!(
224 "Synced skills for profile {} to {skills} session(s).",
225 result.profile_id
226 ));
227 }
228 let github_pushed = result.github_token_pushed_sessions();
229 if github_pushed > 0 {
230 parts.push(format!(
231 "Synced the GitHub CLI token to {github_pushed} session(s)."
232 ));
233 }
234 let github_removed = result.github_token_removed_sessions();
235 if github_removed > 0 {
236 parts.push(format!(
237 "Removed the GitHub CLI token from {github_removed} session(s)."
238 ));
239 }
240 (!parts.is_empty()).then(|| parts.join(" "))
241 }
242}