Account identity for multi-account credential overlays - #4
Merged
Merged
Conversation
One ~/.claude used to imply one account; deva-style runners bind-mount a different .credentials.json per container over the same shared config home, and the account-scoped caches bled across accounts: B rendered A's 5h/7d bars whenever A fetched last, profile.cache stuck to the first account for 24h. Tokens rotate, so the credentials file cannot identify itself — the runner says who the session is. - STATUSLINE_ACCOUNT (explicit) or DEVA_AUTH_TAG (deva --auth-with) resolve to an account tag; sanitized before touching any path - user segment renders @tag chip; tag beats profile display name (two accounts can carry the same human name) - account state moves to accounts/<tag>/ under the shared statusline dir: same-account sessions share one fetch, different accounts stop clobbering each other; auth-default and explicit CLAUDE_DATA_DIR / CLAUDE_CACHE_DIR overrides change nothing - chip also renders for api-key/custom-endpoint sessions that skip the OAuth quota block — the sessions only a tag can tell apart - legacy-state migration never lands in a tagged account dir - tests: 3 unit + 6 integration; helpers unset host DEVA_AUTH_TAG so suites running inside tagged deva containers stay hermetic Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
One ~/.claude used to imply one account. deva-style runners bind-mount a
different .credentials.json per container over the same shared config
home — the account-scoped caches then bleed across accounts: B renders
A's 5h/7d bars whenever A fetched last, profile.cache sticks to the
first account for 24h, usage.jsonl interleaves both histories.
Tokens rotate, so the credentials file cannot identify itself. The
runner says who the session is:
feat: export DEVA_AUTH_TAG for in-container account identity deva#497) -> account tag, sanitized before pathing
display name (two accounts can carry the same human name)
dir: same-account sessions still share one fetch, different accounts
stop clobbering each other
change nothing; chip also renders for api-key sessions that skip the
OAuth quota block
Tests: 3 unit + 6 integration, full suite 287 green. Helpers now unset
host DEVA_AUTH_TAG so suites running inside tagged deva containers stay
hermetic.
Stacked on feat/v0.18.0-cache-expiry-deadline (branch base) to keep the
diff to this change only.
🤖 Generated with Claude Code