diff --git a/claude-code/.devcontainer/claude-sandbox/devcontainer.json b/claude-code/.devcontainer/claude-sandbox/devcontainer.json index 8067bde..6330110 100644 --- a/claude-code/.devcontainer/claude-sandbox/devcontainer.json +++ b/claude-code/.devcontainer/claude-sandbox/devcontainer.json @@ -122,8 +122,9 @@ "DEVCONTAINER": "true", "NODE_OPTIONS": "--max-old-space-size=4096", "CLAUDE_CONFIG_DIR": "/home/node/.claude", - // Required — the sandbox firewall blocks OAuth login, so the token must be - // injected from the host. See "Sandbox Authentication" section in README. + // Optional — only needed when the sandbox is used without the default variant, whose + // sign-in lands on the shared ~/.claude volume. Resolves to "" when the host var is + // unset. See "Sandbox Authentication" section in README. "CLAUDE_CODE_OAUTH_TOKEN": "${localEnv:CLAUDE_CODE_OAUTH_TOKEN}" }, // The find command chowns all node_modules volume mount points in one pass. diff --git a/claude-code/README.md b/claude-code/README.md index fc00253..1c33a3f 100644 --- a/claude-code/README.md +++ b/claude-code/README.md @@ -164,9 +164,13 @@ After the one-time copy, the skill manages its own updates. ### Sandbox Authentication -The sandbox firewall blocks outbound traffic, so `claude login` (which opens a browser OAuth flow) won't work inside the container. Instead, generate a token on the host and inject it via environment variable. +**Usual path: sign in once in the default variant.** Both variants mount the same `myproject-claude-config-*` volume at `/home/node/.claude`, so credentials created by signing in to the default variant (VS Code extension, or `claude` in a terminal) are already there when the sandbox starts. No token is needed. -**Setup (one-time):** +**Standalone sandbox: inject a token.** If you use the sandbox without ever opening the default variant, sign-in has to happen inside the sandbox, where the firewall blocks the browser OAuth flow that `claude login` opens. Generate a token on the host and inject it via environment variable instead. + +When `CLAUDE_CODE_OAUTH_TOKEN` is unset on the host, `${localEnv:CLAUDE_CODE_OAUTH_TOKEN}` resolves to an empty string, so the variable still exists in the container, but empty. That is expected: with an empty token, Claude Code authenticates from the credentials on the shared volume. + +**Setup (one-time, standalone sandbox only):** 1. Generate a setup token on your host machine: ```bash