The login cache is shared by every mdrs process, but the refresh was
guarded by a lock that only reaches inside one. Concurrent runs each
sent the same refresh token, and a provider that rotates them accepts
the first and refuses the rest.
- hold a lock that spans processes across the whole read-refresh-
write, checking cheaply first so ordinary requests never take it
- write the cache through a temporary file: opening it for writing
truncates it, and a reader landing in that window found it empty
and threw the session away
- take the lock for every write, not just the refresh, so a login
running beside one cannot be silently reverted
- wait for a busy lock on Windows rather than giving up after the ten
attempts msvcrt allows, and retry the rename it refuses while a
reader still holds the file open
- bound the refresh request on its own, so a provider that goes quiet
cannot hold the lock indefinitely
- accept bare hostnames such as localhost, store URLs without the
trailing slash, and join download paths through one helper
Historically, several versions in the changelog only had generic
version bump messages. This update fills in the missing details of
actual features and bug fixes by referencing the Git commit log.
- Add specific change logs for versions v1.3.3 through v1.3.15
- Include missing details for features like new command-line options
- Document bug fixes for API pagination, normalization, and downloads
Bump the package version to 1.3.18, upgrade dependencies,
consolidate module exports, add a unit test suite, and document
all changes.
- Bump package version to 1.3.18 in pyproject.toml
- Upgrade pydantic-settings to 2.14.2 and pyright to 1.1.411
- Consolidate package exports in mdrsclient/__init__.py
- Add a comprehensive unit test suite in tests/test_commands.py
- Document testing execution and add full history in CHANGELOG.md