Skip to content

Port upstream 0.67.0: OpenRouter API key and Management key guidance - #686

Closed
Finesssee wants to merge 2 commits into
port/upstream-0.67.0from
port/micro-0.67.0-openrouter-key-guidance
Closed

Finesssee wants to merge 2 commits into
port/upstream-0.67.0from
port/micro-0.67.0-openrouter-key-guidance

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

Copy-only change. OpenRouter now tells users that the required API key field accepts either a regular API key or a Management API key, and that the optional Management API key field does not replace it.

  • Missing-key error (rust/src/providers/openrouter/mod.rs): the two duplicated literals become one MISSING_API_KEY_MESSAGE const with the upstream 0.67.0 text.
  • API key field help (ProviderConfigInfo.api_key_help, shown in Settings > Providers) now says it is required, accepts both key types, and that Management keys also enable account Activity on the official API.
  • Management field help (OpenRouterManagementKeyHelp, en-US) now says it is an optional additional key for account Activity, only needed for a separate Management key. The existing OPENROUTER_MANAGEMENT_API_KEY env hint is kept.
  • docs/PROVIDERS.md: short "OpenRouter keys" section.
  • Behavior unchanged: a filled Management field alone does not select an account for quota or balance.

Upstream reference

  • Release 0.67.0 (OpenRouter key guidance), tag-pinned files at v0.67.0:
    • Sources/CodexBarCore/Providers/OpenRouter/OpenRouterProviderDescriptor.swift (OpenRouterSettingsError.missingToken)
    • Sources/CodexBar/Providers/OpenRouter/OpenRouterProviderImplementation.swift (field subtitles)
    • Sources/CodexBarCore/Resources/Plugins/openrouter.js, docs/openrouter.md

Ported / Deferred

  • Ported: all copy listed above.
  • Deferred: none. No locale catalog other than en-US defines these keys today, so they keep falling back to en-US. The upstream docs describe the Management field taking precedence for Activity; the local Activity behavior is untouched by this PR.

Validation

  • cargo +1.98.0 fmt --all: clean
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: pass
  • cargo +1.98.0 test -p codexbar openrouter: 31 passed (includes 2 new tests for the message and API key help)
  • cargo +1.98.0 test -p codexbar locale: 16 passed; api_keys: 3 passed
  • cargo +1.98.0 test -p codexbar-desktop-tauri credentials: 2 passed
  • pnpm --dir apps/desktop-tauri run check-locale: OK, 879 keys match

Affected areas

  • Provider (OpenRouter, copy only)
  • Settings UI (help text under API key and Management API key fields)
  • Docs
  • Tray / float bar / CLI behavior

UI proof

Pending: coordinator will capture CUA proof on a fresh build (OpenRouter settings pane, both field help texts).

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Thermo-nuclear review

Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude

  • P3 rust/src/providers/openrouter/mod.rs: the keyring error branches in get_api_token duplicated the same env fallback and missing-key error. Fixed: collapsed into one fallback chain, key priority unchanged.
  • P3 rust/src/settings/tests.rs: the settings-catalog help assertion lived in the OpenRouter provider tests. Fixed: moved next to the settings catalog tests.

No other findings; copy matches the 0.67.0 spec.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Thermo review fixes landed (commit "Address thermo review").

  • Fixed: both P3 items above (fallback chain simplification, test relocation). No behavior or UI change.
  • Left: none.
  • Commands run: cargo +1.98.0 fmt --all --check (Codex), cargo +1.98.0 clippy --manifest-path rust/Cargo.toml --all-targets -D warnings, cargo test --lib openrouter (31 passed) and the relocated settings test. Tauri crate clippy skipped: no Tauri or frontend files changed.

@Finesssee

Finesssee commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator Author

CUA proof

Build commit: 27ff74ec1343403c82c47c6b17eda491300e6233 (PR head) plus uncommitted proof-only patches, reverted and never committed or pushed:

  • Cargo.toml [patch.crates-io] dirs = <local shim> (Cargo.lock follows): redirects home/config/data dirs under CODEXBAR_PROOF_HOME, so no real profile data is read.
  • rust/src/providers/openrouter/mod.rs: keyring target codexbar-openrouter renamed to codexbar-openrouter-proof686, so the user's real credential is never read.

Commands: pnpm --dir apps/desktop-tauri install --frozen-lockfile, pnpm --dir apps/desktop-tauri run tauri:build:debug, then the debug exe was driven with the cua-driver CLI only (background get_window_state and set_window_frame; no foreground focus, no global input) on a secondary monitor. Only OpenRouter was enabled, with no key configured and OPENROUTER_API_KEY / OPENROUTER_MANAGEMENT_API_KEY unset, so the real missing-key path runs without any network call. Theme setting is auto.

# Assertion Result
1 No real email/account from the machine visible PASS
2 Settings > Providers > OpenRouter, API key help: "Required. Enter a regular API key or a Management API key here. Management keys also enable account Activity on the official OpenRouter API." PASS
3 Management API key help: "Optional additional key for account Activity. Only needed to use a separate Management API key from the one in the required API key field above. You can also set OPENROUTER_MANAGEMENT_API_KEY." PASS
4 Tray panel with no key shows "Provider not installed: Enter a regular API key or a Management API key in the API key field, or set OPENROUTER_API_KEY. In Settings, the optional Management API key field does not replace it." (the "Provider not installed:" prefix is the existing ProviderError::NotInstalled wording; the Settings detail pane hides error details by design) PASS
5 Theme stays dark under auto in Settings and tray PASS

Screenshots (local, not committed), in %LOCALAPPDATA%\Win-CodexBar\port-audit\proof\686\shots\:

  • 01-settings-providers.png
  • 02-settings-tall.png (window enlarged to show the full OpenRouter detail pane)
  • 03-tray.png

Kit and plan: %LOCALAPPDATA%\Win-CodexBar\port-audit\proof\686\ (PLAN.md, proof-only.diff).

Finesssee added a commit that referenced this pull request Oct 2, 2026
…t key guidance (keeps both #703/#708 and #686 test additions)
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation passed at 504bd67

Scope: OpenRouter API key and Management key guidance (#686, upstream 0.67.0), validated as merged into release/v0.70.0 (merge 504bd67 = merge of 27ff74e into 66b6594).

Attacks (highest-risk semantics, from the merged tree):

  • The Management key cannot substitute for the primary key: MISSING_API_KEY_MESSAGE states it explicitly, and the code enforces it — resolve_key errors NotInstalled when no primary key resolves from keyring or env, before configured_management_key() is ever consulted, so an account can never be selected for quota/balance on a Management key alone.
  • Activity enrichment stays optional: the merged fetch comments and implements "a missing/denied management key never discards credits/quota" — the Activity request is an add-on, and its failure path cannot zero the quota data.
  • is_management_key doesn't misattribute keys: the deprecated metadata field is still deserialized but asserted ignored (deprecated_rate_limit_metadata_is_ignored), so a response claiming management-key status cannot change key handling.
  • Integration seam: the merge kept BOTH Port upstream 0.61.0: OpenRouter diagnostics and Activity summary #703/Port upstream 0.61.0: CLI provider history line with provenance and token totals #708 and Port upstream 0.67.0: OpenRouter API key and Management key guidance #686 test additions in openrouter/tests.rs and both PROVIDERS.md sections — no test was dropped to resolve the conflict.

No defects found. READY for the un-draft rule.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Shipped in v0.70.0: this PR's head is included in main via #735 (merge commit 9d0a37a). Closing as integrated.

@Finesssee Finesssee closed this Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant