mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
The orchestrator injects ROBOCO_AGENT_TOKEN=UNSIGNED when the HMAC secret is unset at spawn. The API middleware rejects a presented-but-unverifiable token with 401 'signature mismatch' even in dev mode (auth not required), so forwarding UNSIGNED turned every flow/do/SDK/secretary/git verb into a 401 — the live pr_reviewer/i_am_idle signature-mismatch loop. Omit the header when the token is the UNSIGNED sentinel at all five agent-side header builders; dev accepts a missing token, prod 401s with 'Missing X-Agent-Token' (the clear respawn-with-secret signal). Add a structlog diagnostic on the middleware reject path so the next mismatch logs the exact (id, role, team, token_unsigned, auth_required) inputs.