Keep the selected instance across a Fjord Account re-login #274
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/login-preserves-instance"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
fj auth login --fjordagainst a platform you were already signed into silently clears your default instance. Both Fjord sign-in flows (src/cli/auth_login.rs:523and:625) built a freshFjordAccountwithdefault_instance_id: Noneand passed it tohosts.upsert, which replaces the entire host entry. The selection goes, and so do the cached display name, slug, and public URL that commands read instead of re-fetching.The timing is what makes it sting. Re-login is the documented recovery from an expired session, so the command whose whole job is restoring access reports
✓ Signed inand then leaves the next command failing:Nothing was wrong with the account. The sign-in that just succeeded threw the setting away.
Both flows now build the block through one pure
fjord_account_for. It carries the previous selection forward when the stored entry is a Fjord Account entry whoseplatform_urlmatches the one being signed into, and starts empty otherwise, so a first sign-in behaves exactly as before. The platform check matters because an instance id means nothing to a platform that did not issue it: a stale or hand-edited entry sitting at the same key must not have its instance inherited.auth_flowis always the flow actually used, so a device sign-in over a previous OIDC one still recordscredentials.The two call sites also had their own local
use crate::config::hosts::{AuthKind, FjordAccount}imports; those are hoisted to the module now that three places need them.Found while verifying the recovery path in #273, and worth landing separately since it is a distinct defect in a different file.
Verified on macOS:
cargo fmt --allclean,cargo clippy --all-targets --all-features -- -D warningsclean,cargo test --allgreen (801 + 5 + 1),cargo auditclean.Carries the same rustls 0.23.40 to 0.23.45 lockfile bump as #273 (RUSTSEC-2026-0285), because the pre-push audit gate fails on
mainwithout it. Identical commit on both branches, so whichever lands first makes it a no-op for the other.