modelstudioai / modelstudioai/cli
[bug] International site: console commands still report NotLogined after AK/SK auto-refresh (GenerateCLIAccessToken token rejected)
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- TypeScript
- Star
- 333
- Fork
- 28
- Merge trung bình
- 1 ngày 9 giờ
- Pull request đã merge (30 ngày)
- 33
Mô tả
Environment
bl1.20.0, macOS- Alibaba Cloud international account, console gateway
ap-southeast-1/international - Profile:
token-plan(base_urlhttps://token-plan.ap-southeast-1.maas.aliyuncs.com) - Credentials: RAM user (Permanent AccessKey only) with
AliyunBailianFullAccess
Expected (per #95)
After bl auth login --open-api, a console command that hits NotLogined silently refreshes the access token from AK/SK and retries successfully.
Actual
The refresh runs and GenerateCLIAccessToken returns 200 with a cliAccessToken, but the retried console call still fails with Console session is not logged in or has expired. (exit 3). Every console command is affected (usage token-plan, usage free, workspace list).
Two separate problems observed:
1. Region resolution falls back to cn for non-DashScope base URLs
packages/core/src/auth/refresh-token.ts → resolveRegion() only matches the three REGIONS DashScope URLs. A token-plan profile (*.ap-southeast-1.maas.aliyuncs.com) doesn't match, so the refresh goes to modelstudio.cn-beijing.aliyuncs.com for an international account.
> POST https://bailian-singapore-cs.alibabacloud.com/cli/api.json?action=IntlBroadScopeAspnGateway&...
< 200
Refreshing access token...
> POST https://modelstudio.cn-beijing.aliyuncs.com/modelstudio/cli/generateAccessToken
< 200 OK
> POST https://bailian-singapore-cs.alibabacloud.com/cli/api.json?...
< 200
Error: Console session is not logged in or has expired.
2. Even with the correct intl host, the token is rejected
To rule out (1) I created a profile with base_url=https://dashscope-intl.aliyuncs.com, console_site=international, console_region=ap-southeast-1, then bl auth login --open-api. The refresh now hits modelstudio.ap-southeast-1.aliyuncs.com and gets a token, but the intl console gateway still answers NotLogined for all console commands.
So on the international site the token produced by GenerateCLIAccessToken does not appear to be accepted by IntlBroadScopeAspnGateway (at least for a RAM user). Is there a required RAM permission / workspace membership / site setting for this to work, or is intl not supported yet?
Side effect worth noting
bl auth login --open-api and every failed auto-refresh overwrite access_token in config.json, which replaces a still-valid browser-login console session with an unusable token. A guard (only overwrite when the new token actually passes a console call) would avoid that.
Repro
- International account, RAM user with
AliyunBailianFullAccess, Permanent AccessKey. bl auth login --console(works), thenbl auth login --open-api --access-key-id ... --access-key-secret ...bl usage token-plan --verbose→ refresh 200, console still NotLogined.
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Bắt đầu với packages/core/src/auth/refresh-token.ts, đặc biệt là resolveRegion() và các ánh xạ REGIONS, sau đó tái hiện luồng quốc tế bằng các profile và command được liệt kê trong issue. So sánh host của token được tạo ra và phản hồi của console, đồng thời kiểm tra cách access_token bị ghi đè trong config.json. Được xem là hoàn tất khi hành vi quốc tế đã được hiểu và các trường hợp refresh, từ chối và ghi đè session được báo cáo có các test rõ ràng hoặc các giới hạn được ghi lại.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- typescript
- Lĩnh vực
- authentication, cli
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Sôi nổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 55/100