Files
twenty/packages
Sonarly Claude Code da775d437e fix: add retry with credential refresh for S3 ExpiredToken errors
https://sonarly.com/issue/19873?type=bug

Workflow code actions fail when the S3 client's cached AWS temporary credentials expire, preventing the worker from reading built logic function code from S3.

Fix: Added retry-on-credential-error logic to `S3Driver.readFile()` in `s3.driver.ts`.

**What changed:**

1. **`s3.driver.ts`**: Added a constant `RETRYABLE_CREDENTIAL_ERROR_NAMES` listing AWS error names (`ExpiredToken`, `ExpiredTokenException`, `RequestExpired`) that indicate stale temporary credentials. Added a private `isRetryableCredentialError()` helper. In `readFile()`, when the initial S3 GetObject fails with one of these errors, the driver now logs a warning and retries once with a fresh command. The retry naturally causes the AWS SDK's `fromNodeProviderChain` credential provider to refresh the expired credentials.

2. **`s3.driver.spec.ts`**: Added three test cases for the new behavior:
   - Retry succeeds on `ExpiredToken` (verifies `send` is called twice)
   - `NoSuchKey` errors are not retried (still thrown as `FileStorageException`)
   - Non-retryable errors (e.g., `AccessDenied`) propagate immediately

The fix is minimal and surgical — only the `readFile` method (the affected code path from the stack trace) is modified. The retry is limited to exactly one attempt to avoid infinite loops. If the credential refresh itself fails, the error propagates naturally.
2026-03-31 07:40:20 +00:00
..
2026-03-30 15:03:23 +00:00
2026-03-30 15:03:23 +00:00