Skip to content

Port upstream 0.68.0: accept Venice Clerk session cookies with Bearer auth - #626

Open
Finesssee wants to merge 3 commits into
port/upstream-0.68.0from
port/micro-0.68.0-venice-clerk
Open

Finesssee wants to merge 3 commits into
port/upstream-0.68.0from
port/micro-0.68.0-venice-clerk

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

Venice Web and Manual modes now accept Clerk session cookies (__session and __session_<non-empty suffix>). A Clerk value is sent as Authorization: Bearer <value> with no Cookie header; the legacy __venice-auth.session-token cookie (exact, then contiguous numbered chunks) keeps priority and is still sent as a Cookie header. Browser cookies are filtered after extraction to the exact venice.ai domain (dots trimmed, case-insensitive), because the shared extractor also returns subdomain cookies such as clerk.venice.ai __client. Missing-credential and invalid/expired-session errors use upstream's recovery text verbatim and are classified as sign-in / expired-session states.

Upstream reference

Ported / Deferred

Ported: cookie-name family, priority (legacy over Clerk, unsuffixed over first suffixed, last repeated __session wins), Bearer vs Cookie, exact-domain filter, error messages, and tests mirroring VeniceClerkSessionTests.
Deferred: upstream retries the next imported browser profile on a session-auth failure; the Windows extractor returns merged cookies for one lookup, so there is no per-profile list to retry. No Venice docs page exists in this repo, so the note that Web mode does not refresh unattended (Clerk sessions last about 60 s) lives only in the error text. The Settings source description in usageSourcePolicy.ts is unchanged (UI untouched).

Validation

  • cargo +1.98.0 fmt --all: clean
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: pass
  • cargo +1.98.0 test -p codexbar venice: 11 passed, 0 failed

Affected areas

Rust backend, Venice provider only (rust/src/providers/venice/mod.rs, +291/-39, 833 lines). No frontend, tray, settings, or dependency changes.

UI proof

Not applicable

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 52f012ee-22c4-4718-ad79-a040543192cf

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Review follow-up (codex-1 lane). Reviewed the Clerk session change against upstream v0.70.0 VeniceCookieHeader, VeniceWebUsageFetcher and VeniceClerkSessionTests. Credential priority (exact legacy, contiguous chunks, then Clerk with unsuffixed __session first), Bearer-only Clerk sends, exact venice.ai domain filter and the 401/403 recovery message all match upstream.

One fix pushed (dc34ebb): a manual header pasted from DevTools with a leading Cookie: prefix was parsed as a cookie named Cookie: __session and rejected. The prefix is now stripped case-insensitively (upstream CookieHeaderNormalizer does the same). Two assertions were added to the existing header test.

Checks on dc34ebb: cargo +1.98.0 fmt --all clean; cargo +1.98.0 clippy --workspace --all-targets -D warnings pass; cargo test -p codexbar --lib venice 11 pass. The branch is 2 commits behind main; it was not rebased or merged, so the merge base is unchanged.

A 200 reply with a missing, null or non-string token now takes the invalid-session path like upstream, instead of a serde parse error. Document the ~60 s Clerk session lifetime in PROVIDERS.md and README.
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at d49c021

Both review items confirmed and fixed.

  • Docs: added a "Venice web session" subsection to docs/PROVIDERS.md (Web mode needs a signed-in venice.ai tab, Clerk sessions last about 60 s so Web does not refresh unattended, Manual mode needs a freshly pasted Cookie header) and updated the Venice row in README.md.
  • Tokenless session reply: VeniceSessionResponse { token: String } is replaced by session_token_from_body. The body is parsed as a JSON object; a missing, null, non-string or blank token is the invalid/expired-session error (upstream invalidCredentials), while a non-object or non-JSON body stays a Parse error. Tests added for {}, {"token":null}, a numeric token, blank tokens, non-object bodies and the happy path.

Commands run: cargo +1.98.0 fmt --all --check; cargo +1.98.0 clippy --workspace --all-targets -- -D warnings; cargo +1.98.0 test -p codexbar (2169 passed). The desktop crate is untouched by this change and was exercised on the stacked #729 branch (466 passed, 1 known environment failure bootstrap_payload_exposes_every_provider_variant, 79 vs 78, real-settings dependent).

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation (Claude Opus 5.5) passed at d49c021

Scope re-checked (round 2): GAP-48, Venice Clerk session cookies. Compared against upstream v0.70.0 VeniceCookieHeader.swift, VeniceWebUsageFetcher.swift, VeniceUsageError.swift, VeniceClerkSessionTests.swift and VeniceWebUsageFetcherTests.swift. Covered: legacy __venice-auth.session-token (exact, then contiguous chunks) wins over Clerk; unsuffixed __session wins over __session_<suffix>; Clerk values are sent only as Authorization: Bearer with no Cookie header, legacy values only as a Cookie header; browser cookies are limited to the exact venice.ai host; non-session Clerk and Authjs cookie names cannot authenticate; 401/403 and a tokenless session reply ({}, {"token":null}, blank or non-string token) give the active-tab recovery message classified as an expired session; the missing-cookie message names both cookie families. The round-1 items are fixed: the ~60 s Clerk lifetime is documented in docs/PROVIDERS.md and README.md, and a tokenless reply is no longer a parse error.

Checks run on this head (detached worktree, gated build):

  • cargo +1.98.0 fmt --all --check: clean
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: pass
  • cargo +1.98.0 test -p codexbar --lib venice: 14 passed
  • cargo +1.98.0 test -p codexbar: 2169 passed, 0 failed, 1 ignored
  • cargo +1.98.0 test -p codexbar-desktop-tauri -- --skip bootstrap_payload_exposes_every_provider_variant: 461 passed, 0 failed (the skipped test reads the host's real settings)

No frontend, locale, dependency or UI change. rust/src/providers/venice/mod.rs is 911 lines. Per-browser fall-through after an unusable first browser session is out of scope here and is covered by the stacked #729.

Finesssee added a commit that referenced this pull request Oct 2, 2026
Finesssee added a commit that referenced this pull request Oct 2, 2026
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation passed at 8569cd3

Scope: accept Venice Clerk session cookies with Bearer auth (#626, upstream 0.68.0), validated as merged into release/v0.70.0 (merge 8569cd3 = merge of d49c021 into fe5d877).

Attacks (highest-risk semantics, from the merged tree):

  • Cookie priority order is exact: legacy __venice-auth.session-token (exact, then contiguous chunks) wins over Clerk; among Clerk cookies the unsuffixed __session wins over the first suffixed one (__session_<suffix>) — matching the audit's priority list, with the domain filter keeping clerk.venice.ai cookies like __client out.
  • Clerk cookies authenticate via Bearer, legacy via Cookie header: the merged code sends Authorization: Bearer <token> for a Clerk __session value and Cookie: __venice-auth.session-token=<value> for the legacy path — the two auth schemes the audit named, with the chunk-reassembly test covering name.0/name.1 continuation.
  • Tokenless reply fails closed: the follow-up fix (session_token_from_body rejecting a tokenless/null/non-string token reply as invalid-session) is on the merged base, with tests.
  • Fixes at d49c021 preserved: the pasted-header "Cookie:" prefix strip (2 assertions) and the docs/PROVIDERS.md section (60 s Clerk lifetime) are in the merged tree.
  • Windows-specific: the browser scan is Chromium-cookie based with no localStorage reader dependency; the message names all three accepted cookie names.

No defects found. READY for the un-draft rule.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant