M1/F1: Kimi Code OAuth device-code flow
Replace the xAI OAuth stack with the Kimi device authorization grant:
- kimi_oauth.rs wire layer (device_authorization + token poll + refresh
against kigi_env::oauth_host(); client_id per PRD; retryable statuses
429/5xx with backoff; expired_token restarts authorization)
- X-Msh-Device-{Name,Model,Id} headers; device_id minted uuid4-hex at
~/.kigi/device_id (0600)
- Storage: system keyring service `kigi`, entry `oauth/kimi-code`
(macOS/Windows native backends), atomic-file fallback under ~/.kigi;
official client's keyring/~/.kimi never touched
- Refresh manager: 60s tick, threshold max(300, expires_in*0.5),
401-tombstone keyed by rejected refresh token with 300s cooldown and
rotation auto-clear, cross-process lock with sibling-adoption
triple-check, sleep/wake forced refresh
- Deleted xAI machinery: enterprise OIDC (PKCE/JWKS/teams), devbox login,
external auth provider, JWT tier gating + subscription paywall stack,
X-XAI-Token-Auth marker headers, ZDR gates, /user enrichment
- kigi login / TUI /login both drive the device flow; login-host display
now derives from kigi_env::oauth_host()
- 264 auth unit/wiremock tests; live contract probe of
auth.kimi.com/api/oauth/device_authorization matches the wire shapes
Gates: check/clippy --all-targets clean, fmt, deny ok, kigi-shell lib
5131 tests green.
This commit is contained in:
@@ -418,9 +418,9 @@ pub(crate) fn pre_acp_auth_manager(
|
||||
) -> std::sync::Arc<kigi_shell::auth::AuthManager> {
|
||||
let auth = std::sync::Arc::new(kigi_shell::auth::AuthManager::new(
|
||||
&kigi_shell::util::kigi_home::kigi_home(),
|
||||
agent_config.grok_com_config.clone(),
|
||||
agent_config.kimi_code_config.clone(),
|
||||
));
|
||||
auth.configure_refresher(agent_config.grok_com_config.auth_provider_command.clone());
|
||||
auth.configure_refresher();
|
||||
auth
|
||||
}
|
||||
/// Preflight: preferred id must be a UUID and not a persisted session under `cwd`.
|
||||
@@ -621,7 +621,7 @@ async fn resolve_existing_session(
|
||||
use kigi_shell::util::kigi_home::kigi_home;
|
||||
let deployment_key = agent_config.endpoints.deployment_key.clone();
|
||||
ensure_authenticated_or_noninteractive(
|
||||
&agent_config.grok_com_config,
|
||||
&agent_config.kimi_code_config,
|
||||
deployment_key.is_some(),
|
||||
None,
|
||||
)
|
||||
@@ -629,7 +629,7 @@ async fn resolve_existing_session(
|
||||
.map_err(|e| anyhow::anyhow!("Failed to authenticate for session restore: {}", e))?;
|
||||
let auth_manager = std::sync::Arc::new(AuthManager::new(
|
||||
&kigi_home(),
|
||||
agent_config.grok_com_config.clone(),
|
||||
agent_config.kimi_code_config.clone(),
|
||||
));
|
||||
let registry_client =
|
||||
SessionRegistryClient::new(agent_config.endpoints.proxy_url(), String::new())
|
||||
|
||||
Reference in New Issue
Block a user