Skip to content

fix(auth): preserve 401 status for expired JWTs in OTel traces - #2

Open
ryan-crabbe wants to merge 1 commit into
mainfrom
claude/otel-expired-token-status-mwRQo
Open

fix(auth): preserve 401 status for expired JWTs in OTel traces#2
ryan-crabbe wants to merge 1 commit into
mainfrom
claude/otel-expired-token-status-mwRQo

Conversation

@ryan-crabbe

Copy link
Copy Markdown
Owner

Expired JWT access tokens raised a bare Exception("Token Expired") with
no status code. That codeless exception was logged to OpenTelemetry (via
post_call_failure_hook) before auth_exception_handler re-wrapped it into a
ProxyException(401), so get_error_information extracted an empty error_code
and the OTel span never set http.response.status_code — leaving only
StatusCode.ERROR, which trace viewers render as a generic 500. The client
still received a 401, so traces and responses diverged.

Raise a ProxyException(code=401, type=expired_key) at the source in both
JWT decode paths so the 401 is preserved end-to-end (client response and
OTel http.response.status_code), matching the virtual-key expiry behavior.

https://claude.ai/code/session_016kg8zDKSZ3ftywjX69uAYH

Expired JWT access tokens raised a bare Exception("Token Expired") with
no status code. That codeless exception was logged to OpenTelemetry (via
post_call_failure_hook) before auth_exception_handler re-wrapped it into a
ProxyException(401), so get_error_information extracted an empty error_code
and the OTel span never set http.response.status_code — leaving only
StatusCode.ERROR, which trace viewers render as a generic 500. The client
still received a 401, so traces and responses diverged.

Raise a ProxyException(code=401, type=expired_key) at the source in both
JWT decode paths so the 401 is preserved end-to-end (client response and
OTel http.response.status_code), matching the virtual-key expiry behavior.

https://claude.ai/code/session_016kg8zDKSZ3ftywjX69uAYH
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants