Skip to content

fix(core): handle missing credentials gracefully in deleteCredentials#21949

Closed
mvanhorn wants to merge 1 commit intogoogle-gemini:mainfrom
mvanhorn:osc/21768-fix-delete-credentials
Closed

fix(core): handle missing credentials gracefully in deleteCredentials#21949
mvanhorn wants to merge 1 commit intogoogle-gemini:mainfrom
mvanhorn:osc/21768-fix-delete-credentials

Conversation

@mvanhorn
Copy link
Copy Markdown

Summary

KeychainTokenStorage.deleteCredentials() and FileTokenStorage.deleteCredentials() throw errors when the credential doesn't exist, causing cascading "Failed to clear OAuth credentials" errors during re-auth flows.

Changes

packages/core/src/mcp/token-storage/keychain-token-storage.ts:

  • Removed the if (!deleted) throw check - now silently succeeds when entry doesn't exist

packages/core/src/mcp/token-storage/file-token-storage.ts:

  • Changed to return early when server name not found in token map instead of throwing

Tests updated:

  • keychain-token-storage.test.ts: Added test for deleting non-existent credentials
  • file-token-storage.test.ts: Changed "should throw" test to "should not throw"

Scenarios fixed

  • Double logout (/auth logout twice)
  • Auth-switch without prior login
  • Token refresh race conditions

Fixes #21768

This contribution was developed with AI assistance (Claude Code).

@mvanhorn mvanhorn requested a review from a team as a code owner March 10, 2026 23:35
@google-cla
Copy link
Copy Markdown

google-cla bot commented Mar 10, 2026

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@gemini-code-assist
Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request enhances the robustness of credential deletion mechanisms by preventing deleteCredentials methods from throwing errors when attempting to remove non-existent credentials. This change improves the stability of authentication flows, particularly in scenarios like double logout, auth-switch without prior login, and token refresh race conditions, by ensuring that credential cleanup operations complete silently and successfully even if the target credential is not found.

Highlights

  • Error Handling: Modified deleteCredentials methods in KeychainTokenStorage and FileTokenStorage to gracefully handle cases where credentials do not exist, preventing errors from being thrown.
  • Test Updates: Updated existing tests and added new ones to reflect the change in behavior, ensuring deleteCredentials does not throw errors for non-existent credentials.
Changelog
  • packages/core/src/mcp/token-storage/file-token-storage.test.ts
    • Changed "should throw" test to "should not throw"
  • packages/core/src/mcp/token-storage/file-token-storage.ts
    • Changed to return early when server name not found in token map instead of throwing
  • packages/core/src/mcp/token-storage/keychain-token-storage.test.ts
    • Added test for deleting non-existent credentials
  • packages/core/src/mcp/token-storage/keychain-token-storage.ts
    • Removed the if (!deleted) throw check - now silently succeeds when entry doesn't exist
Activity
  • No human activity has been recorded on this pull request yet.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request modifies deleteCredentials in FileTokenStorage and KeychainTokenStorage to handle non-existent credentials gracefully by not throwing an error, making the operation idempotent. This change is intended to prevent cascading errors in authentication flows. The tests have been updated accordingly to reflect the new behavior. While the change is correct for deleteCredentials, a related method in KeychainTokenStorage remains inconsistent, which could lead to similar issues in other code paths.

Comment on lines 65 to 68
async deleteCredentials(serverName: string): Promise<void> {
const sanitizedName = this.sanitizeServerName(serverName);
const deleted = await this.keychainService.deletePassword(sanitizedName);

if (!deleted) {
throw new Error(`No credentials found for ${serverName}`);
}
await this.keychainService.deletePassword(sanitizedName);
}
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

This change correctly makes deleteCredentials idempotent. For consistency, I recommend applying the same logic to the deleteSecret method in this file. Currently, deleteSecret (lines 166-173) throws an error if the secret is not found. This inconsistency can lead to bugs similar to the one this PR is fixing, but in code paths that use secrets instead of credentials.

@gemini-cli gemini-cli bot added the priority/p1 Important and should be addressed in the near term. label Mar 10, 2026
Wrap credential deletion in try/catch to prevent cascading errors
when credentials don't exist (e.g., double logout, auth-switch).

Fixes google-gemini#21768
@gemini-cli
Copy link
Copy Markdown
Contributor

gemini-cli bot commented Mar 25, 2026

Hi there! Thank you for your interest in contributing to Gemini CLI.

To ensure we maintain high code quality and focus on our prioritized roadmap, we have updated our contribution policy (see Discussion #17383).

We only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'. All other community pull requests are subject to closure after 14 days if they do not align with our current focus areas. For this reason, we strongly recommend that contributors only submit pull requests against issues explicitly labeled as 'help-wanted'.

This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding and for being part of our community!

@gemini-cli gemini-cli bot closed this Mar 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority/p1 Important and should be addressed in the near term.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

deleteCredentials throws on missing entry, causing re-auth error loops

1 participant