M1/F1: Kimi Code OAuth device-code flow
Replace the xAI OAuth stack with the Kimi device authorization grant:
- kimi_oauth.rs wire layer (device_authorization + token poll + refresh
against kigi_env::oauth_host(); client_id per PRD; retryable statuses
429/5xx with backoff; expired_token restarts authorization)
- X-Msh-Device-{Name,Model,Id} headers; device_id minted uuid4-hex at
~/.kigi/device_id (0600)
- Storage: system keyring service `kigi`, entry `oauth/kimi-code`
(macOS/Windows native backends), atomic-file fallback under ~/.kigi;
official client's keyring/~/.kimi never touched
- Refresh manager: 60s tick, threshold max(300, expires_in*0.5),
401-tombstone keyed by rejected refresh token with 300s cooldown and
rotation auto-clear, cross-process lock with sibling-adoption
triple-check, sleep/wake forced refresh
- Deleted xAI machinery: enterprise OIDC (PKCE/JWKS/teams), devbox login,
external auth provider, JWT tier gating + subscription paywall stack,
X-XAI-Token-Auth marker headers, ZDR gates, /user enrichment
- kigi login / TUI /login both drive the device flow; login-host display
now derives from kigi_env::oauth_host()
- 264 auth unit/wiremock tests; live contract probe of
auth.kimi.com/api/oauth/device_authorization matches the wire shapes
Gates: check/clippy --all-targets clean, fmt, deny ok, kigi-shell lib
5131 tests green.
This commit is contained in:
@@ -2191,8 +2191,10 @@ mod tests {
|
||||
let mut cfg = minimal_config();
|
||||
cfg.extra_headers
|
||||
.insert("x-test-header".to_string(), "test-value".to_string());
|
||||
cfg.extra_headers
|
||||
.insert("x-XAI-token-auth".to_string(), "xai-grok-cli".to_string());
|
||||
cfg.extra_headers.insert(
|
||||
"x-custom-auth-marker".to_string(),
|
||||
"marker-value".to_string(),
|
||||
);
|
||||
let _client = SamplingClient::new(cfg).expect("client with extra headers should construct");
|
||||
}
|
||||
|
||||
|
||||
@@ -38,8 +38,7 @@ pub enum AuthScheme {
|
||||
/// composing chat-state's `kigi_sampling_types::SamplingConfig`
|
||||
/// with `Credentials` (api key, client version).
|
||||
///
|
||||
/// URL-derived request headers (e.g. `X-XAI-Token-Auth` for the
|
||||
/// cli-chat-proxy) are
|
||||
/// URL-derived request headers are
|
||||
/// folded into [`Self::extra_headers`] by
|
||||
/// `agent::config::inject_url_derived_headers` before the
|
||||
/// `SamplerConfig` is handed to the actor. Auth is selected separately
|
||||
|
||||
Reference in New Issue
Block a user