- adds
tg auth listandtg auth switch <handle-or-did> - stores OAuth and app-password sessions independently by account DID
- maintains an
accounts:indexKeychain entry for account discovery and active-account selection - makes logout account-scoped and add
tg auth logout --all - lazily migrates existing singleton Keychain sessions
OAuth and app-password credentials use separate Keychain entries:
oauth:<did>password:<did>accounts:index
tested on macos, untested on linux. tested live by creating issues on okami.mom/tg with alternating accounts
code written by gpt 5.6 sol and has been reviewed/tested by me
Looks good! merging.
also looks like there's an issue where, if the refresh token is expired, we're not properly handling the 401 with app passwords, and auth status/authlist is just lying (it doesn't validate sessions before telling you ok).
Not related to this PR, but I discovered it here and thought it was bugged. we need better auth checking/handling/failures throughout anyway, so I'll push a fix as a follow up! ty!