PR review surfaced a data-loss path: pingKey returned False on ANY exception,
so a VPN flap or DNS hiccup made Rules 1/2 (reuse existing valid key) fall
through to Rule 3 (mint new shadow), silently rotating the user's API key
and rewriting plugin-sync targets (~/.claude/settings.json, .zshrc).
Now pingKey returns False ONLY on a definitive auth failure (HTTP 401/403).
Network errors, timeouts, and 5xx responses return True so the existing key
is preferred over re-minting. Mirror change in both Python and Node.
Additional fixes from the same review pass:
- --agent-caller is now PATCHed to the backend when supplied on a Rule 1
or Rule 2 reuse path (previously silently dropped). Best-effort —
failures don't break reuse.
- bootstrap_via_backend / bootstrapViaBackend renames the `body` local on
the error path to `err_body` (no longer shadows the request payload).
Same rename in the claim flow.
- Bootstrap envelope is now validated for non-empty api_key +
default_user_id before mutation — defends against partial backend
responses silently persisting null/undefined into typed string fields.
- Stale docstrings in agent_detect.{py,ts} and bootstrap_via_backend no
longer claim env-var sniffing fills `agent_caller`; the field is
self-declared via --agent-caller only.
Tests (new file mirrored across runtimes):
- test_init_internals.py / init-internals.test.ts
- pingKey: 200/401/403/5xx/connect-error/timeout matrix
- plugin_sync.updateShellRc: trailing-newline preservation, no-create,
surrounding-content preservation, idempotency, missing-file no-op
- plugin_sync.updateClaudeSettings: no env-block creation, no
MEM0_API_KEY insertion into existing env, idempotency, malformed JSON
no-op
- Python only: bootstrap 403 "permission" → daily-limit translation
Python: 161 tests pass. Node: 112 tests pass. ruff + biome clean.