Skip to content

Port upstream 0.61.0: OpenRouter diagnostics and Activity summary - #703

Closed
Finesssee wants to merge 1 commit into
port/upstream-0.61.0from
port/micro-0.61.0-openrouter-activity-summary
Closed

Finesssee wants to merge 1 commit into
port/upstream-0.61.0from
port/micro-0.61.0-openrouter-activity-summary

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Found by the 0.60.4-0.69.0 port gap audit.

Summary

OpenRouter now reports why an optional request degraded and shows an Activity summary, matching upstream v0.61.0:

  • /credits, /key and Activity each get a 4 s deadline (was 30 s credits, 1 s key and Activity).
  • Degraded requests carry a safe reason (Request timed out, Request failed, Request returned HTTP <n>, Response was invalid, Management API key required for an Activity 403, Management API key not configured). The reason was previously only logged at debug level; it now appears in the provider detail rows and the CLI text output.
  • New detail rows: Credits remaining / used / total added (or Credits balance: Unavailable right now with the reason), API key limit (with "Spending cap, not balance"), API key remaining / used, Reset window (or No limit configured, or Unavailable right now with the reason), Activity tokens / requests / models for the last 30 completed UTC days (or Spend history (last 30 days): Unavailable right now with the reason).
  • Activity aggregation checks the safe-integer range for tokens, reasoning tokens and requests like upstream. Tokens are prompt + completion; reasoning is not added again.

Rows use the existing ProviderDisplayDetail path (menu card, provider detail pane, CLI), so no bridge or frontend change was needed.

Upstream reference

Ported / Deferred

Ported: items above.

Deferred:

  • Per-model, per-date Activity entries on the cost snapshot (upstream costUsage.entries). They only feed upstream's Usage & Spend model breakdown; Win-CodexBar's CostSnapshot has no per-model shape, so this needs a separate spend-catalog change.
  • Upstream's "Today / This week / This month" key-spend detail rows and the "Key spend" bar chart. The same values already show as the Daily/Weekly/Monthly spend lanes on Windows, so duplicating them would repeat rows.
  • Upstream's "Response was unavailable" reason: no equivalent state exists locally (a missing body is a parse failure).
  • Flat detail rows carry the section name in the title (for example Activity tokens) because ProviderDisplayDetail has no section grouping. Titles are English strings like other providers' detail rows; no locale keys were added.

Validation

All with cargo +1.98.0, slot-5 target dir, E-core wrappers:

  • cargo fmt --all: clean
  • cargo clippy --workspace --all-targets -- -D warnings: pass
  • cargo test -p codexbar openrouter: 38 passed, 0 failed (new: detail rows for success, uncapped key and degraded sources; HTTP status and auth typing; timeout vs other transport failure against a stalled local listener; Activity summary counts, dedupe, model counting, safe-integer aggregate overflow)
  • cargo test -p codexbar (full): 2169 passed, 0 failed, 1 ignored
  • Tauri crate and frontend untouched; pnpm test not run.

Affected areas

  • Provider (OpenRouter)
  • UI surface (provider detail rows in menu card, detail pane, CLI text)
  • Settings, tray, float bar, installer

UI proof

Pending: coordinator will capture CUA proof on a fresh build.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 685e710a-2e50-4d57-bb66-7a693948c447

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Finesssee added a commit that referenced this pull request Oct 1, 2026
…ty summary (#703)

Merge port/micro-0.61.0-openrouter-activity-summary. Both branches change
openrouter/activity.rs: keep #703's checked safe-integer token aggregate as
the single token total for the CLI history line (dropping this branch's
separate saturating sum, which would double count after the merge), keep
the cost provenance, and move this branch's tests to the ActivityReport
return shape.
@Finesssee

Finesssee commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator Author

UI proof (browser-use)

Result: PASS on build 3e63802c616e7d3e4705c70a817d5e9d5eeb3116, the current PR head.

  • Tray panel: the OpenRouter card shows the new credits, API key and Activity rows with upstream 0.61.0's titles and reasons, in four fixture scenarios: healthy, credits HTTP 500 with Activity 403, no key cap and no management key, and an invalid /key response.
  • Settings > Providers: the same rows appear in the provider detail pane.
  • Requests: Activity is only requested when a management-capable key exists, and is skipped otherwise.

At the maintainer's direction, this proof drove the app's WebView2 over CDP with the browser-use CLI instead of CUA. It used no keyboard, mouse or focus. Refreshes were DOM element.click() calls on the panel's own Refresh button, and the global shortcut was off in the kit settings.

Setup

  • Build: pnpm run tauri:build:debug in the worker worktree at 3e63802c. The exe was copied to the proof kit; its SHA-256 is 459fef98…ab436bb9, and it loads index-OTO_h_Fk.js.
  • Proof-only patch: never committed, and reverted after the build.
    • A workspace Cargo.toml [patch.crates-io] dirs shim for an isolated home, plus the resulting Cargo.lock change.
    • A no-focus overlay, because this branch doesn't include Stop CodexBar from stealing focus #713. It changes only window focus.
    • An OpenRouter fixture hook in rust/src/providers/openrouter/mod.rs. It renames the keyring target, so the user's Credential Manager entry is never read. When CODEXBAR_PROOF_OPENROUTER_FIXTURE names a folder, /credits, /key and /activity read fixture files from it instead of calling https://openrouter.ai. No request is sent, and TLS and URL validation are untouched.
    • The hook decodes each body with the PR's real response types and runs the same validate() as the network path. A <name>.status file takes the same status branches as the network path, built with the PR's own Degraded constructors, and a decode failure maps to Degraded::invalid exactly as Degraded::body does. Every reason string below therefore comes from the PR's code. Each served request is logged with its endpoint and key kind only, never the key.
  • Home and providers: USERPROFILE, HOME, APPDATA, LOCALAPPDATA and XDG_CONFIG_HOME pointed at a home inside the kit. CODEX_HOME, CLAUDE_CONFIG_DIR and GEMINI_HOME pointed at empty kit folders, and PATH was cut to the Windows system folders.
  • Keys: OPENROUTER_API_KEY was a dummy placeholder. OPENROUTER_MANAGEMENT_API_KEY and OPENROUTER_API_URL were unset.
  • Settings: only OpenRouter was enabled. The theme was auto, the float bar was off and the global shortcut was empty.
  • Commands:
    • bash launch.sh trayPanel (CODEXBAR_PROOF_MODE=trayPanel) for S1 to S4, then bash launch.sh settings:providers.
    • Both set WEBVIEW2_ADDITIONAL_BROWSER_ARGUMENTS=--remote-debugging-port=9335 .... Checks ran as BU_CDP_URL=http://127.0.0.1:9335 BU_NAME=worker-703 BH_TAB_MARKER=0 browser-use.
    • Before each attach, curl /json/version showed Edg/154 WebView2, and the port 9335 listener was a WebView2 child of the kit exe.

Fixture scenarios

Scenario /credits /key /activity
S1 healthy $50.00 total, $12.34 used limit $20, remaining $7.50, limit_reset: monthly, usage $15.25, is_management_key: true 3 rows: 2026-09-30 openai/gpt-5 (150,000 tokens, 40 requests, $1.25); 2026-09-15 anthropic/claude-sonnet-4.5 (100,000 tokens, 25 requests, $0.90 plus $0.10 BYOK); 2026-08-20, outside the window. The latest-day request returns only the 2026-09-30 row.
S2 degraded HTTP 500 as S1 HTTP 403
S3 no cap as S1 limit: null, limit_reset: null, usage $4.75, is_management_key: false not configured
S4 invalid key as S1 "limit": "twenty" (fails to decode) not configured

Results

# Assertion Result
T0 No real email or account from the host is visible. The app page was scanned before each screenshot, and no scan found an @ address or the host user name. The app logs contain neither. PASS
T1 Dark under theme auto on both surfaces: prefers-color-scheme: dark, data-theme=dark, body rgb(28, 28, 30) and text rgb(245, 245, 247). PASS
T2 S1 healthy, tray. One details section, no error. The rows, in order: Credits remaining: $37.66; Credits used: $12.34; Credits total added: $50.00; API key limit: $20.00 (secondary "Spending cap, not balance"); API key remaining: $7.50; API key used: $15.25; Reset window: monthly; Activity tokens: 250000 (secondary "Last 30 completed UTC days"); Activity requests: 65; Activity models: 2. The meters read "Credits 25% used" and "API key limit 63% used". get_cached_providers returned the cost as $2.25 for "Last 30 days (UTC)", with daily points of $1.00 on 2026-09-15 and $1.25 on 2026-09-30. The 2026-08-20 row was excluded. PASS
T3 S2 credits 500 and Activity 403, tray. The rows: Credits balance: Unavailable right now (secondary "Request returned HTTP 500"); API key limit: $20.00 (secondary "Spending cap, not balance"); API key remaining: $7.50; API key used: $15.25; Reset window: monthly; Spend history (last 30 days): Unavailable right now (secondary "Management API key required"). The meters read "Credits" with "Account balance unavailable", and "API key limit 63% used". There was no card error, and the cached cost was null. PASS
T4 S3 no cap and no management key, tray. The rows: the three credits rows; API key limit: No limit configured; Spend history (last 30 days): Unavailable right now (secondary "Management API key not configured"). This refresh sent no Activity request. PASS
T5 S4 invalid /key body, tray. The rows: the three credits rows; API key limit: Unavailable right now (secondary "Response was invalid"); Spend history (last 30 days): Unavailable right now (secondary "Management API key not configured"). The card kept the credits metric and showed no error. PASS
T6 Settings > Providers (S1). The OpenRouter detail pane lists the same 10 rows in the same order. PASS
T7 Requests followed the key kind. The fixture log recorded 5 refreshes. Each sent /credits and /key. The three management-capable refreshes (S1, S2 and the Settings launch) each sent the 30-day /activity request and the latest-day one (date=2026-09-30). S3 and S4 sent none. Every request used the API key, as expected when /key reports is_management_key: true. PASS
T8 The proof never took focus. The app page reported document.hasFocus() as false at every step. PASS

Validation at 3e63802c

Run in the worker worktree on Rust 1.98.0. This PR doesn't change the frontend.

Command Result
cargo +1.98.0 fmt --all --check pass
cargo +1.98.0 clippy --workspace --all-targets -- -D warnings pass
cargo +1.98.0 test -p codexbar openrouter 38 passed
cargo +1.98.0 test -p codexbar 2169 passed, 0 failed, 1 ignored
cargo +1.98.0 test -p codexbar-desktop-tauri -- --skip bootstrap_payload_exposes_every_provider_variant 461 passed, 0 failed. The skipped test is the non-hermetic #684 test that #711 fixes.

Screenshots

All paths are under %LOCALAPPDATA%\Win-CodexBar\port-audit\proof\703\shots\.

File What it shows
703-tray-s1-healthy.png S1: credits, API key and Activity rows with both meters.
703-tray-s2-degraded.png S2: "Credits balance" and "Spend history" unavailable, with their reasons; the key lanes stay.
703-tray-s3-no-cap-no-management.png S3: "No limit configured" and "Management API key not configured".
703-tray-s4-invalid-key.png S4: "API key limit: Unavailable right now" with "Response was invalid".
703-settings-providers-s1.png Settings > Providers: the OpenRouter rows in the detail pane.

Not blocking (already on main)

None of these come from this PR; its diff touches only rust/src/providers/openrouter/.

  • Settings > Providers doesn't show the secondary values ("Spending cap, not balance", the unavailable reasons), because UsageSection passes no secondaryClassName to ProviderDisplayRow. The same pane labels OpenRouter's two meters "Session" and "Weekly", where the tray says "Credits" and "API key limit".
  • In the tray, a row's secondary text sits flush against its value with no separator, for example "Unavailable right nowRequest returned HTTP 500" (DisplayDetailRow in MenuCardDetails.tsx).
  • The overview "Usage & Spend · 30d" header kept showing $2.25 after Activity failed in S2 to S4. OverviewSpendSummary fetches get_usage_spend_summary only when the provider ids change. A read-only call after S2 already returned thirtyDay: null for OpenRouter.
  • An empty global_shortcut logs WARN codexbar_desktop_tauri::shortcut_bridge: Could not parse global shortcut: at every launch. This was already reported on Fix reset refresh timer for resets over 24.8 days away #720.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation passed at 084d019

Scope: OpenRouter diagnostics and Activity summary (#703, upstream 0.61.0 steipete#3272/steipete#3733), validated as merged into release/v0.70.0 (merge 084d019).

Attacks (highest-risk semantics, from the merged tree):

  • Activity summary comes from the diagnostics endpoint with key-kind routing: the merged openrouter/activity.rs routes the Activity request with the Management key when configured and the regular key otherwise; the seed/proof ran S1 healthy, S2 credits-500+Activity-403, S3 no-cap+no-management-key, S4 invalid-key — covering all four key-kind branches the audit lists.
  • Fail-closed error mapping: each branch surfaces a distinct state (403 on Activity with a Management key present, 403 on credits vs Activity differentiated, no-cap-without-management-key) rather than collapsing everything to a generic error — the tests pin each branch's error identity, not just non-null.
  • Provisioned-key nuance: the tests cover the "Management key required" case where a regular key gets 403 on the Activity route — the branch most likely to be mis-implemented by sharing the credits key.
  • Windows-specific: no UI layout change; the diagnostics surface through the existing provider detail rows, so the float bar/tray paths are untouched (matching the audit's "no UI layout change" classification).

No defects found. The browser-use proof (issuecomment-5924935539 at 3e63802) covered all four seed branches across tray and Settings. READY for the un-draft rule.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Shipped in v0.70.0: this PR's head is included in main via #735 (merge commit 9d0a37a). Closing as integrated.

@Finesssee Finesssee closed this Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant