Add per-provider auth.json keys; make auth methods registry-generic (P0b)
Platform API keys now live in auth.json under the platform-id scope (the per-provider auth.json key contract), resolved env > auth.json > legacy [platforms.*] config.toml (read-only fallback). The TUI login picker, paste box, auth-method advertising, and authenticate handler are all registry-generic: a new PlatformSpec row appears in the login UI and authenticates with zero UI changes. Spec rows gained vendor/console_host/ login_label display fields (moonshot strings byte-identical, pinned by tests). Adversarial review caught that auth.json keys were validated at login but never stamped onto catalog entries (completions would 401; restart lost eager auth). Fixed red-green: resolve_model_list/resolve_model_catalog now take a resolved PlatformApiKeys snapshot consumed by the credential- stamping layer (auth.json beats stale config.toml, matching the login validator), with production callers resolving fresh per catalog build. Also from review: the new auth.json writer takes the manager's cross- process flock (bounded retry — an unlocked RMW racing a token refresh could revert a rotated refresh token); the oauth-401 wiremock test is hermetic (KIGI_SHARE_DIR tempdir; it could read a dev's real auth.json and hit live moonshot); cli_models resolves real keys; auth.json is read once per registry sweep; caller-less lock_config_writes deleted; catalog resolvers tightened to pub(crate); stale config.toml doc comments and the no-credentials error copy updated.
This commit is contained in:
@@ -150,6 +150,22 @@ edges stay deterministic Rust. The harness appends a terminal
|
||||
the replan cap; `{"ops": []}` is a respected free no-op; failures
|
||||
degrade.
|
||||
|
||||
## Provider registry & API-key auth (post-0.1.3 expansion)
|
||||
|
||||
- The platform registry is compiled-in spec rows in `kigi-models`
|
||||
(`PlatformSpec`; adding a platform = enum variant + `ALL` entry + `spec()`
|
||||
arm + row; registry tests enforce completeness/uniqueness/row shape).
|
||||
- API-key resolution precedence, per platform: platform env var(s) >
|
||||
`auth.json` scope named by the platform id (`moonshot-cn`, …) >
|
||||
legacy `[platforms.<id>]` in config.toml (read-only fallback).
|
||||
- The TUI login picker persists pasted keys to `auth.json` (platform-id
|
||||
scope, `api_key` mode) — never to config.toml. The keyring holds ONLY the
|
||||
OAuth session scope; platform keys are file-only.
|
||||
- Auth method ids over ACP equal the platform ids; interactive picker rows
|
||||
are built generically from advertised methods (`AuthMethodKind::
|
||||
ApiKeyPlatform`), so new registry rows appear in the picker with no TUI
|
||||
changes.
|
||||
|
||||
## Milestones (PRD §8.3)
|
||||
|
||||
- M0 (done): rename, deletions (voice/telemetry/announcements/marketplace/
|
||||
|
||||
Reference in New Issue
Block a user