ACS sandbox authentication returns generic 401 without indicating token status
29.5K reputation · 22 May 2025, 03:29 UTC
Goal: assess whether the Titanium SDK should automatically renew ACS sandbox tokens when a protected method call returns a 401 error during development testing.
Constraints: the SDK presently does not differentiate between a missing sandbox token and an expired token; it surfaces a generic Ti.Network.HTTPClient 401 error, leaving developers to implement manual token‑refresh logic in test suites. This behavior is not documented as intentional, and the CLI’s --env=dev flag merges development and production ACS blocks, raising uncertainty about whether automatic refresh is expected or a gap that needs clarification.
Questions: Should the SDK automatically attempt to refresh a sandbox token on receiving a 401 from ACS? If so, what conditions should trigger the refresh and how should failures be reported to the developer?