feat(codewhale): add LMM OAuth companion adapter and independent client registration - #440
Merged
Merged
Conversation
…ient registration Stage independent package under packages/codewhale-lmm-provider pending remote repository creation. Add PKCE, private refresh journal, group-bound streaming bridge, tests, documentation and explicit submodule publication script. No changes to existing submodules or production OAuth activation flags.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Resolve argv[1] to its real path before ESM entrypoint detection. Add direct, symlink and argument-redaction regressions. 36 tests pass locally; actual packed installation prints help. Initial remote registration and adapter CI jobs also passed.
References TokenNotIncluded/lmm-scripts#5. Update only the lmm-scripts gitlink; preserve the provider, Pi and DSH revisions.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
实现
接入 Codewhale 的独立 LMM OAuth 伴随适配器与一键安装菜单。
服务端新增独立 lmm-codewhale 客户端,复用 PKCE S256、state/issuer/resource 绑定、刷新轮换和撤销。基础权限仅 catalog:read balance:read usage:read models:invoke,分组由同意流程追加,不包含 MCP/market。Pi、DSH、CLI 原有授权与部署开关不变。
适配器使用伴随 CLI 和官方 openai-compatible provider,不声称提供原生 /login provider hook。只接受目录声明 openai-completions 的模型,严格选择模型/分组。桥接仅监听 127.0.0.1,检查 Host、Origin 和每次运行随机凭据;LMM OAuth token 不传入宿主配置。每次请求重新核对目录,断开时取消上游,推理 POST 不自动重放。
脚本默认 setup 安装并引导本人浏览器授权,再询问是否选模型启动;install 仅安装。新增桌面第 8 项、Termux 第 6 项,保留原菜单编号。入口固定提交并验证 SHA-256;Windows 使用原生程序与无 shell 参数传递。不复制凭据、不覆盖原 TOML、不改变 registry、不绕过授权或模型审批。
实际审查与验证
已逐项审查父项目七文件差异、适配器 OAuth/会话存储/桥接/CLI 实现,以及脚本共用实现、两种入口和菜单。旧 CodeQL 明文日志线程已由安全机器人标记 resolved/outdated;当前 CLI 对账户查询采用显式字段白名单,不直接输出完整 OAuth 响应。未手工关闭任何安全检查。
本 PR exact head 的四套工作流均通过:
脚本 exact head 的 Codewhale installer 35647234663 与完整 Installer checks 35647234679 也均通过,覆盖 Ubuntu/macOS/Windows、PowerShell 7/5.1、伪终端菜单和隔离 npm 实装。此前“完整脚本 CI 仍运行”的说明已过期。
比较父 PR base 4032394 与当前 main e7e1ce2:新增主线提交未改动本 PR 的七个文件;本次不会覆盖已合并的权限、计费和 relay 修复。没有强推、跳过测试或降低检查门槛。
部署与平台边界
这里只合并源码,不部署、不启用生产 OAuth、不进行真实账号授权或推理计费。服务端部署注册后才可进行生产互通验收,安装通过不等于登录或账单验证。
需要 Node.js 22+ 和 npm。Responses-only/Messages-only、MCP/市场工具不在范围内。Termux 为预览,未做真机验收;Windows 适配器尚未实现独立 ACL 加固,不支持共享 Windows 账号场景。现有权限限制与这些边界均保留。