fix: detect claude.ai's 403 session-invalid as an expired key; ChatGPT .1 cookie is optional
claude.ai answers an invalid or expired sessionKey with 403 account_session_invalid, never 401, so the refresh-your-cookie message could not fire for Claude. Auth detection is now a provider decision (_is_auth_failure); Claude matches the 403 on its error code so a real permission error still reports as itself. README and .env.example no longer claim both ChatGPT cookie chunks are required. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LbnmGHnFqDjyhPcCg1SEfF
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
d3745e1de4
commit
b6ce636891
+10
-2
@@ -6,10 +6,18 @@
|
||||
|
||||
# --- ChatGPT ---
|
||||
# How to get: open chatgpt.com in Chrome → F12 → Application tab
|
||||
# → Cookies → https://chatgpt.com → find the two cookie chunks:
|
||||
# → Cookies → https://chatgpt.com → find the session token cookie. Chrome splits a
|
||||
# cookie only above ~4KB, so you will see ONE of these two layouts:
|
||||
#
|
||||
# __Secure-next-auth.session-token (the whole value) → CHATGPT_SESSION_TOKEN
|
||||
# (leave _1 empty)
|
||||
# or, when the token was large enough to be split:
|
||||
# __Secure-next-auth.session-token.0 (starts with "eyJ") → CHATGPT_SESSION_TOKEN
|
||||
# __Secure-next-auth.session-token.1 (the remainder) → CHATGPT_SESSION_TOKEN_1
|
||||
# Token type: JWE. Typically valid for ~7 days.
|
||||
#
|
||||
# CHATGPT_SESSION_TOKEN_1 is OPTIONAL — leave it empty when there is no .1 cookie.
|
||||
# But if a .1 cookie does exist, you must copy it: a partial .0 fails silently
|
||||
# (HTTP 200 with no accessToken). Token type: JWE. Typically valid for ~7 days.
|
||||
CHATGPT_SESSION_TOKEN=
|
||||
CHATGPT_SESSION_TOKEN_1=
|
||||
|
||||
|
||||
Reference in New Issue
Block a user