v0.7.3 — Auth: Stop OTP Re-Prompt After Short Sleeps
What's new in v0.7.3
Fix
- Auth: stop OTP re-prompt after short laptop sleeps. Access token TTL bumped from 15 minutes to 4 hours so typical sleep durations no longer expire the access token while the laptop is napping. Refresh token TTL unchanged at 7 days. For a single-user LAN dev tool gated by first-pair TOTP, the 4h window aligns with realistic work sessions.
- Refresh path hardened. Transient post-wake Wi-Fi glitches (NIC re-associating after sleep) no longer nuke the refresh token and force re-OTP:
Auth.refresh()returns tri-state and distinguishes network errors from HTTP auth errors. Network errors preserve the refresh token.handleUnauthorized()(REST + image upload) only clears the access token on network error and surfaces a recoverableNetworkUnavailableerror — no OTP modal.- WebSocket
onclosewith code4401now refresh-first via the single-flight mutex BEFORE reconnect, so the reconnect storm uses a fresh token from the first attempt instead of hammering the server with stale credentials.
Security
Server-side refresh-rotation chain-burn-on-reuse defense, token signing (HS256), token storage (localStorage), and validation strictness all unchanged. The TTL extension is a deliberate UX/security trade-off bounded by the existing threat model (single-user LAN tool, TOTP-gated, no public exposure).
Install
Download the DMG attached below, mount, drag Cloude Code.app to Applications.
Verification
shasum -a 256 "Cloude Code-0.7.3-arm64.dmg"
# expected: 204c171661f71bd0762158d0bac0569797436b3ce91b616c8986e442b6283107
Notes
- DMG is signed (Developer ID Application) but not notarized (consistent with prior 0.7.x releases). On first launch macOS Gatekeeper may show a warning — right-click the app and choose Open to bypass.
- Apple Silicon (arm64) only.
- v0.7.0, v0.7.1, v0.7.2 remain available as prior releases for rollback.