CB-612: support tokenless Claude Code profiles
CI / contract (pull_request) Successful in 1m4s
CI / build (pull_request) Successful in 1m24s

This commit is contained in:
Dai Ha
2026-09-03 09:59:21 +07:00
parent 723fe494e9
commit adb7a67880
2 changed files with 19 additions and 1 deletions
@@ -258,7 +258,7 @@ public final class ClaudeCodeLauncher extends HerdrPeerLauncher {
workerEnv.remove("ANTHROPIC_AUTH_TOKEN");
} else {
workerEnv.put("ANTHROPIC_BASE_URL", baseUrl);
putIfPresent(workerEnv, "ANTHROPIC_AUTH_TOKEN", env.apply(cfg.tokenEnv()));
putIfPresent(workerEnv, "ANTHROPIC_AUTH_TOKEN", resolveEnv(cfg.tokenEnv()));
}
putIfPresent(workerEnv, "ANTHROPIC_MODEL", cfg.model());
putIfPresent(workerEnv, "CLAUDE_CONFIG_DIR", cfg.configDir());
@@ -583,6 +583,24 @@ class ClaudeCodeLauncherTest {
assertNull(env.get("GITEA_HOST"), "no forge host without a granted token");
}
@Test
void noTokenEnvSpawnsWithoutInjectingAnAuthToken() {
FakeHerdr herdr = new FakeHerdr();
FleetConfig.Profile cfg = new FleetConfig.Profile(
"local-direct", "http://gx00.gw:8000", "coder", null, null,
List.of("claude"), "tab", "fleetd-workers", "w #{n}", null, null, null);
ClaudeCodeLauncher launcher = new ClaudeCodeLauncher(new AgentControl(herdr), new WorkspaceControl(herdr),
new SubscriptionGuard(Set.of("gx00.gw")), Map.of(cfg.profile(), cfg), cfg.profile(), System::getenv);
assertDoesNotThrow(() -> {
launcher.spawn();
},
"a profile that needs no token must still spawn against its configured endpoint");
Map<String, String> env = startEnv(herdr);
assertFalse(env.containsKey("ANTHROPIC_AUTH_TOKEN"),
"an unconfigured tokenEnv must not inject an auth-token key");
}
// --- CB-117 orphan reap: the pure predicate --------------------------------
@Test