Skip to content

fix(export): pair a long-lived Claude token with its profile home - #5

Merged
jiunbae merged 1 commit into
mainfrom
fix/export-profile-home
Sep 22, 2026
Merged

jiunbae merged 1 commit into
mainfrom
fix/export-profile-home

Conversation

@jiunbae

@jiunbae jiunbae commented Sep 22, 2026

Copy link
Copy Markdown
Member

The bug

aas export printed CLAUDE_CODE_OAUTH_TOKEN instead of CLAUDE_CONFIG_DIR for an account carrying a long-lived token — an else if, not two pushes:

$ aas export k-june@claude                              # before
export CLAUDE_CODE_OAUTH_TOKEN="sk-ant-oat01-…"

$ aas export k-june@claude                              # after
export CLAUDE_CODE_OAUTH_TOKEN="sk-ant-oat01-…"
export CLAUDE_CONFIG_DIR="…/asx/profiles/claude-k-june_claude"

So eval "$(aas export k-june@claude)" left the shell authenticated as the account while claude wrote its history, settings and todos into ~/.claude. Profile isolation quietly disappeared for exactly the accounts that use a long-lived token.

Why both belong

They answer different questions — one says who you are, the other says where the session lives — and Claude Code takes a long-lived token only from the environment, preferring it over whatever the config dir holds. Three things already say so:

  • aas exec installs both for the same account (exec.rs token injection + profile home), and that is the path the long-lived flow is built on.
  • grok already exports GROK_HOME and XAI_API_KEY together. claude was the one provider where the credential displaced the home.
  • The module's own summary: "print the shell env needed to use a profile in the current shell".

Change

The variable list moves into profile_env_vars(key, system, home, secret), a pure function, so the pairing is covered by tests rather than by reading match arms. Four tests: long-lived + profile, long-lived + system profile, ordinary OAuth credential, and grok as the existing precedent.

Behaviour for every other provider is unchanged.

🤖 Generated with Claude Code

`aas export` printed `CLAUDE_CODE_OAUTH_TOKEN` *instead of*
`CLAUDE_CONFIG_DIR` for an account that carries a long-lived token, so
`eval "$(aas export k-june@claude)"` left the shell authenticated as the
account while `claude` wrote its history, settings and todos into
`~/.claude`. The profile isolation quietly disappeared for exactly the
accounts that use a long-lived token.

The two answer different questions and both have to be answered. Claude
Code takes a long-lived token only from the environment and prefers it
over whatever the config dir holds, which is why `aas exec` has always
installed both for the same account — and why the module's own summary
is "the shell env needed to use a profile". `grok` already exported
`GROK_HOME` and `XAI_API_KEY` together; `claude` was the one provider
where the credential displaced the home.

The variable list moves into `profile_env_vars`, a pure function over
(provider, system, home, secret), so the pairing is covered by tests
rather than by reading the match arms.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@jiunbae
jiunbae merged commit f53cbe3 into main Sep 22, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant