Skip to content

feat(codewhale): add LMM OAuth companion adapter and independent client registration - #440

Merged
LIghtJUNction merged 9 commits into
mainfrom
feat/codewhale-lmm-oauth-provider
Sep 21, 2026
Merged

LIghtJUNction merged 9 commits into
mainfrom
feat/codewhale-lmm-oauth-provider

Conversation

@LIghtJUNction

@LIghtJUNction LIghtJUNction commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

实现

接入 Codewhale 的独立 LMM OAuth 伴随适配器与一键安装菜单。

  • packages/codewhale-lmm-provider 固定 8c78be0f936fb8f508badabc0195cdb21442a75d。
  • packages/lmm-scripts 固定 32a636358c80274bd4431c939fb6c060e61d1145。
  • 脚本依赖 feat: add Codewhale one-click OAuth setup and menu integration lmm-scripts#5 已合并;其 main 保留该固定提交,合并提交为 575a43688a924119423f157699a0144466e6a03d。
  • 本 PR 验证 head:4c8ce20f7cb68a09603b8aed3283a32c67158f0e。

服务端新增独立 lmm-codewhale 客户端,复用 PKCE S256、state/issuer/resource 绑定、刷新轮换和撤销。基础权限仅 catalog:read balance:read usage:read models:invoke,分组由同意流程追加,不包含 MCP/market。Pi、DSH、CLI 原有授权与部署开关不变。

适配器使用伴随 CLI 和官方 openai-compatible provider,不声称提供原生 /login provider hook。只接受目录声明 openai-completions 的模型,严格选择模型/分组。桥接仅监听 127.0.0.1,检查 Host、Origin 和每次运行随机凭据;LMM OAuth token 不传入宿主配置。每次请求重新核对目录,断开时取消上游,推理 POST 不自动重放。

脚本默认 setup 安装并引导本人浏览器授权,再询问是否选模型启动;install 仅安装。新增桌面第 8 项、Termux 第 6 项,保留原菜单编号。入口固定提交并验证 SHA-256;Windows 使用原生程序与无 shell 参数传递。不复制凭据、不覆盖原 TOML、不改变 registry、不绕过授权或模型审批。

实际审查与验证

已逐项审查父项目七文件差异、适配器 OAuth/会话存储/桥接/CLI 实现,以及脚本共用实现、两种入口和菜单。旧 CodeQL 明文日志线程已由安全机器人标记 resolved/outdated;当前 CLI 对账户查询采用显式字段白名单,不直接输出完整 OAuth 响应。未手工关闭任何安全检查。

本 PR exact head 的四套工作流均通过:

  • CI 35647440730
  • Server release qualification 35647440793
  • Codewhale LMM provider 35647440829
  • LMM CLI 35647440973

脚本 exact head 的 Codewhale installer 35647234663 与完整 Installer checks 35647234679 也均通过,覆盖 Ubuntu/macOS/Windows、PowerShell 7/5.1、伪终端菜单和隔离 npm 实装。此前“完整脚本 CI 仍运行”的说明已过期。

比较父 PR base 4032394 与当前 main e7e1ce2:新增主线提交未改动本 PR 的七个文件;本次不会覆盖已合并的权限、计费和 relay 修复。没有强推、跳过测试或降低检查门槛。

部署与平台边界

这里只合并源码,不部署、不启用生产 OAuth、不进行真实账号授权或推理计费。服务端部署注册后才可进行生产互通验收,安装通过不等于登录或账单验证。

需要 Node.js 22+ 和 npm。Responses-only/Messages-only、MCP/市场工具不在范围内。Termux 为预览,未做真机验收;Windows 适配器尚未实现独立 ACL 加固,不支持共享 Windows 账号场景。现有权限限制与这些边界均保留。

…ient registration

Stage independent package under packages/codewhale-lmm-provider pending remote
repository creation. Add PKCE, private refresh journal, group-bound streaming
bridge, tests, documentation and explicit submodule publication script.
No changes to existing submodules or production OAuth activation flags.
Copilot AI lite review requested due to automatic review settings September 21, 2026 18:29
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-09-21T18:44:21.594764Z 6cd7ae7 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Comment thread packages/codewhale-lmm-provider/src/cli.mjs Fixed
Resolve argv[1] to its real path before ESM entrypoint detection. Add direct,
symlink and argument-redaction regressions. 36 tests pass locally; actual
packed installation prints help. Initial remote registration and adapter CI
jobs also passed.
@LIghtJUNction
LIghtJUNction merged commit e639e99 into main Sep 21, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants