fix(shared): redeem reset credits through the hub when it holds the account - #10462
Conversation
…ccount When a Codex account is signed in natively and also pooled behind a CLIProxyAPI hub, "Use reset" could redeem through either path. Which one it picked came down to whichever usage snapshot happened to be fresher, because one flag decided both which credit balance to display and which path to redeem through. Redeeming natively resets the subscription upstream but never calls the hub's `reset-quota`, so the hub kept refusing to route to an account that had just been reset, until its own cooldown expired days later. Split the two decisions. The displayed balance still follows the fresher snapshot; the redemption path now always prefers the hub when it has a credit for that account, falling back to the native instance only when the hub has nothing to redeem. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ApprovabilityVerdict: Would Approve Macroscope's review found this PR approvable — This is a small, self-contained usage-limit bug fix that changes only the redemption route for accounts duplicated between a native provider and a hub, while preserving the freshest displayed balance and all unaffected paths. Both shared aggregation paths have focused regression tests, with no schema, default, deployment, or static-analysis changes. Not approved because:
Review your spending limits in Billing settings. You can add or adjust custom eligibility rules. Learn more. |
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
collectLimitAccounts, which backs the pooled usage panel on web and mobile, picked its redemption target the same way the composer report did: whichever contributor had credits and the freshest snapshot. When a native instance read more recently than the hub, the panel redeemed natively and left the hub's cooldown armed. Prefer a hub redemption target whenever one exists, independent of freshness. A hub contributor only carries a target when it actually has a credit id, so the native fallback still covers the case where the hub has nothing to redeem. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
## What's Changed * fix(web): show load balancing note for a single machine by @maria-rcks in pingdotgg/t3code#10433 * fix(server): follow placeholder branches after checkout updates by @Yash-Singh1 in pingdotgg/t3code#10441 * fix(mobile): expand single-line tool details in work logs by @Yash-Singh1 in pingdotgg/t3code#10442 * fix(server): import transcripts with oversized tool records by @Yash-Singh1 in pingdotgg/t3code#10430 * fix(marketing): deploy site with nightly releases by @t3dotgg in pingdotgg/t3code#10443 * fix(web): preserve multiline composer drafts during timeline scrolling by @Yash-Singh1 in pingdotgg/t3code#10444 * fix(server): handle JSON-wrapped titles and verbose Claude output by @Noojuno in pingdotgg/t3code#10446 * fix(marketing): restore continuous endorsement scrolling by @t3dotgg in pingdotgg/t3code#10450 * Revert "fix(marketing): restore continuous endorsement scrolling" by @t3dotgg in pingdotgg/t3code#10454 * fix(marketing): bring back the endorsement marquee by @t3dotgg in pingdotgg/t3code#10455 * chore: enable CodeRabbit automatic reviews by @t3dotgg in pingdotgg/t3code#10457 * fix(codex): keep Spark limits from replacing the main allowance by @Yash-Singh1 in pingdotgg/t3code#10458 * fix(marketing): send 95 nightly downloads to the downloads page by @t3dotgg in pingdotgg/t3code#10460 * fix(web): composer regains focus when you tab back into T3 Code by @t3dotgg in pingdotgg/t3code#10463 * fix(web): keep sidebar drag dividers clear and gestures smooth by @juliusmarminge in pingdotgg/t3code#10453 * fix(server): mark Cursor transport error answers as failed by @shivamhwp in pingdotgg/t3code#10337 * fix(web): clear stuck panel resize cursor by @t3dotgg in pingdotgg/t3code#10461 * fix(web): clarify sidebar drag dividers and empty targets by @juliusmarminge in pingdotgg/t3code#10464 * fix(web): make onboarding a shared multi-computer wizard by @juliusmarminge in pingdotgg/t3code#10465 * fix(shared): redeem reset credits through the hub when it holds the account by @juliusmarminge in pingdotgg/t3code#10462 **Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260907.1325...v0.0.39-nightly.20260907.1332 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260907.1332
Merges 141 upstream commits (`b438447f6..8b2838e`) into the fork, following the `fork-upstream-merge` skill. Landed as a merge commit; conflicts resolved by the path-policy verdicts in `docs/fork/inventory.json`. ## Merge shape 563 files landed (`git diff --stat HEAD^1 HEAD`) against 563 in the upstream range, so no upstream work was dropped. Fork delta 720 files. ## Conflicts 14 files, resolved by concern. The merge commit message names each. Two are worth carrying forward: - Upstream extracted the project action rows into `ProjectActionsList.tsx`. The fork's Edit gate now rides an `editable` prop that defaults to upstream's always-editable behavior, so the gate survives the next extraction. - Upstream moved the `agent-browser-access` setting onto its new `/settings/projects` page. `settingsSearch.ts` points that item there and drops a fork delta. ## Two things a clean merge did not show **Upstream can delete an export the fork still imports.** pingdotgg#10225 removed `ClientTracingLive` as unused. `apps/web/src/lib/runtime.ts` still installs it, and neither file conflicted, so the typecheck failed four ways on a merge git called clean. Restored with a `// Fork:` comment naming the consumer. **A green test step can hide a suite that never finished.** `vp run -r test` kills the packages still running when one of them fails. A `@t3tools/desktop` failure truncated `apps/web` and `@t3tools/mobile` after each had reported hundreds of passing files, and `verify.mjs` counted any package with labeled output as tested. Four failing web tests went unreported. The check now keys on the closing `Test Files` line and runs every unfinished package alone. ## Unsupported methods `unsupported-methods.mjs` reports 0 ADD, 0 DROP, 2 KEEP, against 61 dispatched backend methods and 131 contract methods. Getting there took a fix. The backend moved its dispatch from `crates/t3code/src/lib.rs` to `crates/t3code/src/rpc/dispatch.rs`, where every arm is a one-line call into a handler below the match. The script read the old path and reported zero dispatched methods, then read the new one and called `vcs.switchRef` a DROP, because the `unsupported_exit` that refuses it had moved out of the arm. It now tries both paths and follows an arm two calls deep. Contract changes: `provider.consumeResetCredit` and `server.getHostResources` gained `UnsupportedMethodError`; `server.getUsageSummary` lost it, which closes the item the previous merge left open. ## Feature classification **Usable as-is** — client-only, nothing new on the wire. Sidebar drag across sections with destination cues and a named drop action (pingdotgg#9731, pingdotgg#9750, pingdotgg#10378, pingdotgg#10453, pingdotgg#10464). Composer behavior: a multiline draft survives timeline scrolling (pingdotgg#10444), the composer stops collapsing on blur (pingdotgg#10437) and regains focus when you tab back (pingdotgg#10463). Panel and preview chrome: resize the floating preview from any edge (pingdotgg#10467), toolbar controls stay anchored (pingdotgg#10478), the stuck resize cursor clears (pingdotgg#10461), the browser hides as the right panel closes (pingdotgg#10385), manual panel choices hold during a turn (pingdotgg#10113). Settings and accessibility polish (pingdotgg#10177, pingdotgg#10262, pingdotgg#10415, pingdotgg#10258, pingdotgg#10124, pingdotgg#10125, pingdotgg#10127, pingdotgg#10128, pingdotgg#10175). Performance (pingdotgg#10413, pingdotgg#10190, pingdotgg#10118). Plus the GitHub mark on `github.com` links (pingdotgg#10324), the Tux icon for WSL (pingdotgg#8511), a remembered usage page selection (pingdotgg#10189), project settings in the legacy sidebar menu (pingdotgg#10021), and text-only preview snapshots (pingdotgg#10232). **Unsupported in Moatless** — resolves to a refusal, or falls through to its own empty state. Each is recorded in `docs/fork/gaps.md`: - Reset credits through the hub and CLIProxyAPI (pingdotgg#10462, pingdotgg#10395, pingdotgg#10308). `provider.consumeResetCredit`, new union entry. `UsageLimits.tsx` catches the refusal and shows "Could not use the reset credit." - Balancing new threads across connected machines (pingdotgg#9895, pingdotgg#10433, pingdotgg#10407). `server.getHostResources`, new union entry. Nothing polls until a user picks automatic routing, and the composer then reads "Auto balance unavailable." - Onboarding: import grouped by repository (pingdotgg#10493), the shared multi-computer wizard (pingdotgg#10465), agent install without Node or npm (pingdotgg#10402). All ride `agentSessions.scan` and `.import`, an existing gap. - Shared project defaults and scoped overrides (pingdotgg#9754). The page reads, and every write goes through `server.updateSettings`, which the backend does not dispatch. - Two new `orchestration.dispatchCommand` types: `thread.active.reorder` (pingdotgg#9729) and `thread.user-input.dismiss` (pingdotgg#10431). Both are ordinary controls, a sidebar drag and a Dismiss button, and a dispatched command cannot be refused per type. That is the standing _A command cannot be refused_ gap, now 26 members wide. **Backend behavior to consider reproducing in Moatless** — upstream server fixes whose behavior the fork's client assumes: - Invalid script IDs no longer crash threads (pingdotgg#10019). The fork ships project scripts, so this one is worth reading first. - Settlement: settle inactive threads without a PR lookup (pingdotgg#10103), skip disabled settlement lookups (pingdotgg#10424), settle threads with unanswered async questions (pingdotgg#10400). - Interrupted threads stay resumable after a restart (pingdotgg#10421). - Completed requests stay closed across clients (pingdotgg#10123). - Placeholder branches are followed after a checkout updates (pingdotgg#10441). - A thread's PR links without an open client (pingdotgg#10101), and checkpoints are captured before a PR status refresh (pingdotgg#10347). - Adapters declare their own context compaction (pingdotgg#10112). - Transcripts with oversized tool records import (pingdotgg#10430), and git status scans are skipped while the index is locked (pingdotgg#9845). - Usage limits pool per provider across accounts and environments (pingdotgg#10300). The client renders what `server.getUsageSummary` returns, so this shows something only if the Moatless payload carries per-account limits. Mobile, marketing, desktop, provider adapters and release tooling are not this fork's surface and are not classified. ## Also fixed here, and not upstream's doing - Three `browser-*` search items still routed to `/settings/integrations`, which the fork owns for its Moatless administration page. A non-administrator who searched for them was redirected away from the result. - `moatless/listSearch.ts` carried no fork-only declaration. - `pnpm fmt:check` failed on 294 files, 293 of them orval output. The generator now formats what it writes through an `afterAllFilesWrite` hook. - `@t3tools/moatless-api` exported `./generated`, a barrel that is never checked in. ## Verification `inventory-check.mjs` clean. `verify.mjs` green on seven checks: duplicate-adds, tripwires, resolution-check, unsupported-methods, `fmt:check` (3876 files), `lint` and `typecheck`. `test` is red on one package, and it is the machine. `@t3tools/desktop`'s `bundled libsecret helper` shells out to `pkg-config` for `libsecret-1`, which this sandbox does not have; it fails the same way when retried alone. Everything else passes: `apps/web` 369 files, `t3` 291, `@t3tools/mobile` 149, `t3code-relay` 27, `@t3tools/client-runtime` 71, plus the smaller packages. `spec:check` cannot run in a sandbox: it needs a sibling `moatless` checkout or a deployment URL and has neither. Written by Claude Opus 5 in Claude Code. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --- Moatless task: https://moatless.soaplabstest.com/tasks/8d348ecf-f9cb-4e65-b96b-6c1054a8ed33
Problem
When a Codex account is signed in natively and also pooled behind a CLIProxyAPI hub, the "Use reset" button could redeem down either path. Which one it took came down to whichever usage snapshot happened to be fresher, because a single flag decided both which credit balance to display and which path to redeem through.
Those are different questions. Redeeming natively goes through the local Codex app-server against the instance's own
CODEX_HOME, which resets the subscription upstream but never calls the hub's/v0/management/reset-quota. The hub therefore kept its routing cooldown for that account and went on refusing every request to it — in the case that prompted this, for another ~119h — even though the account had just been reset. Redeeming through the hub does both, becausecliproxyApi.consumeclears the cooldown after a successful redemption.The user has no way to choose: a hub account that duplicates a native provider is folded into the native entry, so there is exactly one button and a
checkedAtrace decides where it goes.This is client-side logic in
packages/shared, and it had the same defect in two independent builders, so both are fixed here:collectProviderUsageLimits— the chat view and composer banners (ChatView.tsx,ComposerUsageLimits.tsx).collectLimitAccounts— the pooled usage panel (UsageLimitsPooled.tsx).Both are imported by web and mobile, and desktop wraps web, so all three surfaces are covered.
Fix
Split the fused decision in each builder. Display still follows the fresher snapshot. The redemption path now prefers the hub whenever it has a credit for that account, and falls back to the native instance only when the hub genuinely has nothing to redeem — a hub contributor only carries a redemption target when it has a credit id, so that fallback keeps working.
One case worth naming: if the hub snapshot is stale and its
nextCreditIdwas already spent by an earlier native redeem, we now send that spent id. The hub returnsalready_redeemed, which is already treated as a success that still clears the cooldown, and the clients already have copy for it. That is strictly better than the old behavior, which left the hub cooling down a healthy account.Verification
checkedAt, hub duplicate on the same email with a staler one. Both fail onmain— the first with the exact production symptom,expected { instanceId: 'codex' } to deeply equal { sourceId: 'hub', … }— and pass here.packages/shared/src/usageLimits.test.ts: 41 passed. The existing tests that assert a native redemption target still pass, because in those the hub has no credit to redeem.tsgo --noEmiton@t3tools/sharedclean; lint andfmt --checkclean.?? { instanceId }fallback only fires when the field is absent, which never happens for native providers, and the contract union already carried both shapes.No UI change — nothing about the rendered output moves, only which backend path the existing button takes.
Written by Claude Opus 5 (1M context) in Claude Code.
🤖 Generated with Claude Code