The server issues a connect.sid cookie on every response, including a rejected login (which re-renders the form as 200). login() treated any returned cookie as success, so bad creds silently cached an anonymous session and the CLI stayed logged out with no warning — and since it only re-authenticates on a 401 (which the server never sends), the stale cookie was never refreshed. Trust the redirect status instead (302 = success, 2xx = rejected) and throw a clear error with the HTTP code on failure. Add a `bliss login` command that forces a fresh login past any stale cookie. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| live-editor | ||
| bliss | ||
| client.js | ||
| SKILL.md | ||