modelstudioai / modelstudioai/cli
[bug] International site: console commands still report NotLogined after AK/SK auto-refresh (GenerateCLIAccessToken token rejected)
まだ誰も着手していません。
- 主要言語
- TypeScript
- スター
- 333
- フォーク
- 28
- 平均マージ
- 1日 9時間
- マージ済み PR(30日)
- 33
説明
Environment
bl1.20.0, macOS- Alibaba Cloud international account, console gateway
ap-southeast-1/international - Profile:
token-plan(base_urlhttps://token-plan.ap-southeast-1.maas.aliyuncs.com) - Credentials: RAM user (Permanent AccessKey only) with
AliyunBailianFullAccess
Expected (per #95)
After bl auth login --open-api, a console command that hits NotLogined silently refreshes the access token from AK/SK and retries successfully.
Actual
The refresh runs and GenerateCLIAccessToken returns 200 with a cliAccessToken, but the retried console call still fails with Console session is not logged in or has expired. (exit 3). Every console command is affected (usage token-plan, usage free, workspace list).
Two separate problems observed:
1. Region resolution falls back to cn for non-DashScope base URLs
packages/core/src/auth/refresh-token.ts → resolveRegion() only matches the three REGIONS DashScope URLs. A token-plan profile (*.ap-southeast-1.maas.aliyuncs.com) doesn't match, so the refresh goes to modelstudio.cn-beijing.aliyuncs.com for an international account.
> POST https://bailian-singapore-cs.alibabacloud.com/cli/api.json?action=IntlBroadScopeAspnGateway&...
< 200
Refreshing access token...
> POST https://modelstudio.cn-beijing.aliyuncs.com/modelstudio/cli/generateAccessToken
< 200 OK
> POST https://bailian-singapore-cs.alibabacloud.com/cli/api.json?...
< 200
Error: Console session is not logged in or has expired.
2. Even with the correct intl host, the token is rejected
To rule out (1) I created a profile with base_url=https://dashscope-intl.aliyuncs.com, console_site=international, console_region=ap-southeast-1, then bl auth login --open-api. The refresh now hits modelstudio.ap-southeast-1.aliyuncs.com and gets a token, but the intl console gateway still answers NotLogined for all console commands.
So on the international site the token produced by GenerateCLIAccessToken does not appear to be accepted by IntlBroadScopeAspnGateway (at least for a RAM user). Is there a required RAM permission / workspace membership / site setting for this to work, or is intl not supported yet?
Side effect worth noting
bl auth login --open-api and every failed auto-refresh overwrite access_token in config.json, which replaces a still-valid browser-login console session with an unusable token. A guard (only overwrite when the new token actually passes a console call) would avoid that.
Repro
- International account, RAM user with
AliyunBailianFullAccess, Permanent AccessKey. bl auth login --console(works), thenbl auth login --open-api --access-key-id ... --access-key-secret ...bl usage token-plan --verbose→ refresh 200, console still NotLogined.
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
packages/core/src/auth/refresh-token.ts、特に resolveRegion() と REGIONS のマッピングから始め、次に issue に記載されているプロファイルとコマンドを使って国際フローを再現します。生成された token の host とコンソールのレスポンスを比較し、config.json の access_token がどのように上書きされるかを調べます。国際的な挙動が理解され、報告されている refresh、拒否、セッション上書きのケースに明確なテストまたは文書化された制約があれば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- typescript
- 領域
- authentication, cli
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 55/100