Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Review follow-up (codex-1 lane). Reviewed the Clerk session change against upstream v0.70.0 VeniceCookieHeader, VeniceWebUsageFetcher and VeniceClerkSessionTests. Credential priority (exact legacy, contiguous chunks, then Clerk with unsuffixed One fix pushed (dc34ebb): a manual header pasted from DevTools with a leading Checks on dc34ebb: cargo +1.98.0 fmt --all clean; cargo +1.98.0 clippy --workspace --all-targets -D warnings pass; cargo test -p codexbar --lib venice 11 pass. The branch is 2 commits behind main; it was not rebased or merged, so the merge base is unchanged. |
A 200 reply with a missing, null or non-string token now takes the invalid-session path like upstream, instead of a serde parse error. Document the ~60 s Clerk session lifetime in PROVIDERS.md and README.
|
Fixes landed at d49c021 Both review items confirmed and fixed.
Commands run: |
|
Adversarial validation (Claude Opus 5.5) passed at d49c021 Scope re-checked (round 2): GAP-48, Venice Clerk session cookies. Compared against upstream v0.70.0 Checks run on this head (detached worktree, gated build):
No frontend, locale, dependency or UI change. |
…all-through (stacked on #626)
|
Adversarial validation passed at 8569cd3 Scope: accept Venice Clerk session cookies with Bearer auth (#626, upstream 0.68.0), validated as merged into release/v0.70.0 (merge 8569cd3 = merge of d49c021 into fe5d877). Attacks (highest-risk semantics, from the merged tree):
No defects found. READY for the un-draft rule. |
Summary
Venice Web and Manual modes now accept Clerk session cookies (
__sessionand__session_<non-empty suffix>). A Clerk value is sent asAuthorization: Bearer <value>with noCookieheader; the legacy__venice-auth.session-tokencookie (exact, then contiguous numbered chunks) keeps priority and is still sent as aCookieheader. Browser cookies are filtered after extraction to the exactvenice.aidomain (dots trimmed, case-insensitive), because the shared extractor also returns subdomain cookies such asclerk.venice.ai__client. Missing-credential and invalid/expired-session errors use upstream's recovery text verbatim and are classified as sign-in / expired-session states.Upstream reference
Sources/CodexBarCore/Providers/Venice/VeniceCookieHeader.swift,VeniceWebUsageFetcher.swift,VeniceCookieImporter.swift,VeniceUsageError.swift,Tests/CodexBarTests/VeniceClerkSessionTests.swift.Ported / Deferred
Ported: cookie-name family, priority (legacy over Clerk, unsuffixed over first suffixed, last repeated
__sessionwins), Bearer vs Cookie, exact-domain filter, error messages, and tests mirroring VeniceClerkSessionTests.Deferred: upstream retries the next imported browser profile on a session-auth failure; the Windows extractor returns merged cookies for one lookup, so there is no per-profile list to retry. No Venice docs page exists in this repo, so the note that Web mode does not refresh unattended (Clerk sessions last about 60 s) lives only in the error text. The Settings source description in
usageSourcePolicy.tsis unchanged (UI untouched).Validation
cargo +1.98.0 fmt --all: cleancargo +1.98.0 clippy --workspace --all-targets -- -D warnings: passcargo +1.98.0 test -p codexbar venice: 11 passed, 0 failedAffected areas
Rust backend, Venice provider only (
rust/src/providers/venice/mod.rs, +291/-39, 833 lines). No frontend, tray, settings, or dependency changes.UI proof
Not applicable