- auth.rs: AuthRecord (OAuth {access, refresh, expires} | Api {key}) with
is_expired(now, skew) honoring expires==0 = never; AuthStorage keyed by
provider id over ~/.local/share/ai-harness/auth.json.
- Read-modify-write on every op so concurrent refresh/login don't clobber;
writes go through a temp-file rename set to 0600 (unix) to avoid truncated
auth files.
- 6 tempdir tests: missing→empty, set/get/overwrite, multi-provider coexist,
scoped remove (+ no-op on absent), expiry skew/never, 0600 perms.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>