Skip to content

Add provider-specific token account routing - #620

Draft
Finesssee wants to merge 8 commits into
codex/port-0.65-provider-packfrom
codex/port-0.65-account-source-pack
Draft

Finesssee wants to merge 8 commits into
codex/port-0.65-provider-packfrom
codex/port-0.65-account-source-pack

Conversation

@Finesssee

@Finesssee Finesssee commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adds provider-specific token-account routing for Kimi, Doubao, and OpenCode Go using the existing shared account model.

  • Kimi kimi-auth accounts force the regional web route, isolate the selected cookie from API credentials, and fail closed without ambient fallback.
  • Doubao Ark accounts use only the selected key and do not fall back to ambient credentials.
  • OpenCode Go distinguishes API-key and Cookie accounts, preserves saved source settings, and rejects explicit Web or CLI sources for an API-key account to avoid reporting a different identity.
  • Preserves selected credentials through Tauri fetch-context construction so the selected-account routes compile.

This draft stacks on #619 (codex/port-0.65-provider-pack).

Validation

  • On the first commit, Rust account tests passed (153 passed, 1 ignored), and the Kimi selected-session rejection test passed.
  • After the routing and ownership fixes: cargo fmt --all -- --check and git diff --check passed; deterministic routing coverage was added.
  • The newest regression tests and Tauri shell tests were not run locally because free disk is below 35 GiB. Hosted validation is pending.

No frontend/UI files changed.

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee
Finesssee force-pushed the codex/port-0.65-account-source-pack branch from 15734d0 to 220c804 Compare September 25, 2026 04:27
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Thermo review finding — P2, blocking approval:

Provider/account source routing for Kimi, Doubao, and OpenCode Go is duplicated between build_fetch_context in commands/providers.rs and project_token_account in rust/src/cli/usage/fetch_helpers.rs. Those independent matches can drift, causing the tray and CLI to route the same selected account differently.

Please move the provider/account/source decision into one small shared policy helper in the Rust core, while leaving shell and CLI settings/account selection in their current owners. Cover Kimi cookie → Web, Doubao API key → OAuth, OpenCode Go Cookie + Auto → Web, and OpenCode Go API-key Auto/OAuth plus explicit Web/CLI rejection.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation (lane-A) at 4663218

Review verdict: no defects in A-620's own diff (e7b4e14..e0a4bdc, 18 files, +817/−98). The routing matches the 0.65.0 audit spec: Kimi selected accounts force the regional web route with isolated cookies and fail closed, Doubao Ark accounts use only the projected key, OpenCode Go distinguishes API-key and Cookie accounts, preserves saved source settings, and rejects explicit Web/CLI for an API-key account. Coverage in commands/tests.rs (4 fetch-context cases) and usage_tests.rs (3 projection cases) plus provider-local fail-closed tests.

Merge defect found and fixed (the branch had to absorb the current #619 head 26181982 per stacking rules; the merge resolution initially broke build_fetch_context):

  1. 667d34be + 250f1d8c: the no-cookie-domain branch was mismerged — it returned the old single-usage_source form instead of the (source_mode, cookie_header, missing_cookie) tuple, and dropped .clone()s (E0308/E0382 compile errors).
  2. 4663218d: the upstream session-only arm ("off" | "manual" if cookie_source_scopes_session_only()) belongs in the cookie-domain-present branch (Hyper has cookie_domain() == Some("hyper.charm.land")), but the merge had moved it into the no-cookie branch where it can never fire; the CLI-remap block then rewrote Hyper's off/manual routes to Web. Restored the arm to the cookie-domain branch and taught the remap block to skip session-scoped providers.

Checks at 4663218 (CARGO_TARGET_DIR=W:\cargo-target\lane-a, jobs=4, RUST_TEST_THREADS=4):

  • cargo fmt --all --check: pass.
  • cargo clippy both manifests --all-targets -- -D warnings: only the 3 documented pre-existing main-drift findings (alibabatokenplan/cli.rs:163, kiro/usage_limits.rs:315, openai/subscription.rs:206); 0 findings in this PR's diff.
  • cargo test rust manifest: 2286 passed / 0 failed / 1 ignored.
  • cargo test desktop manifest: 489 passed / 1 failed — the only failure is bootstrap_payload_exposes_every_provider_variant, the documented Isolate bootstrap payload test from real settings #684 environment-dependent baseline on branches without Make the bootstrap catalog test hermetic (#684) #711 (expected; hermetic fix lives on release/v0.70.0).
  • session_cookie_scope_tests: 6/6 pass (4 previously failing Hyper routing tests now green).
  • Frontend: no apps/desktop-tauri/src (TS/TSX) files changed — backend only, no UI proof required.

Fast-forward pushed e0a4bdc2..4663218d.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation passed at 9240e34

Scope: provider-specific token account routing / account source pack (#620, upstream 0.65.0), validated as merged into release/v0.70.0 (merge 9240e34 = merge of 4663218 into f3375b8).

Attacks (highest-risk semantics, from the merged tree):

  • Token account is an identity boundary, not just a key source: the merged Kimi web path treats ctx.token_account_isolated as an account boundary (the comment "A selected token account is an identity boundary, so the web…"), meaning a token-account-selected web session cannot be mixed with the ambient account's data — the isolation rule the audit named.
  • Account-source order matches the upstream Kimi fetch plan: the merged kimi/mod.rs carries the classified account-source order with the token-account step placed per upstream, and the fetch-context test family (usage_tests +82 lines) covers the CLI paths (diagnose, guard, hooks, serve, usage) all threading the same helper — no CLI surface left wiring the account through a different route.
  • Wallet rule fold-in: the Port upstream 0.64.0: Hugging Face 12 h identity cache, billing-permission message, API-only without cookies #725 wallet SourceMode::Auto-only guard is honored in the merged Kimi/opencodego fetch contexts, so a token-account-selected session still respects the API-only/cookie-source rules from Make the bootstrap catalog test hermetic (#684) #711-era fixes.
  • Windows-specific: the desktop commands/providers.rs (+195) and its test file (+133) cover the settings UI surface for token accounts — the Windows settings pane is where a user actually selects one, and it is test-covered.

No defects found. READY for the un-draft rule.

Finesssee added a commit that referenced this pull request Oct 2, 2026
…Auto rule, thread CurrencyRateCache through TrayPresentationPlan, complete struct fields in tests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant