Skip to content

v0.7.3 — Auth: Stop OTP Re-Prompt After Short Sleeps

Choose a tag to compare

@Adoom666 Adoom666 released this 25 May 04:03
· 768 commits to main since this release

What's new in v0.7.3

Fix

  • Auth: stop OTP re-prompt after short laptop sleeps. Access token TTL bumped from 15 minutes to 4 hours so typical sleep durations no longer expire the access token while the laptop is napping. Refresh token TTL unchanged at 7 days. For a single-user LAN dev tool gated by first-pair TOTP, the 4h window aligns with realistic work sessions.
  • Refresh path hardened. Transient post-wake Wi-Fi glitches (NIC re-associating after sleep) no longer nuke the refresh token and force re-OTP:
    • Auth.refresh() returns tri-state and distinguishes network errors from HTTP auth errors. Network errors preserve the refresh token.
    • handleUnauthorized() (REST + image upload) only clears the access token on network error and surfaces a recoverable NetworkUnavailable error — no OTP modal.
    • WebSocket onclose with code 4401 now refresh-first via the single-flight mutex BEFORE reconnect, so the reconnect storm uses a fresh token from the first attempt instead of hammering the server with stale credentials.

Security

Server-side refresh-rotation chain-burn-on-reuse defense, token signing (HS256), token storage (localStorage), and validation strictness all unchanged. The TTL extension is a deliberate UX/security trade-off bounded by the existing threat model (single-user LAN tool, TOTP-gated, no public exposure).

Install

Download the DMG attached below, mount, drag Cloude Code.app to Applications.

Verification

shasum -a 256 "Cloude Code-0.7.3-arm64.dmg"
# expected: 204c171661f71bd0762158d0bac0569797436b3ce91b616c8986e442b6283107

Notes

  • DMG is signed (Developer ID Application) but not notarized (consistent with prior 0.7.x releases). On first launch macOS Gatekeeper may show a warning — right-click the app and choose Open to bypass.
  • Apple Silicon (arm64) only.
  • v0.7.0, v0.7.1, v0.7.2 remain available as prior releases for rollback.