Skip to content

feat: add Codewhale one-click OAuth setup and menu integration - #5

Merged
LIghtJUNction merged 11 commits into
mainfrom
feat/codewhale-install-menu
Sep 21, 2026
Merged

LIghtJUNction merged 11 commits into
mainfrom
feat/codewhale-install-menu

Conversation

@LIghtJUNction

@LIghtJUNction LIghtJUNction commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Changes

Add Codewhale installation/OAuth setup through codewhale.sh, codewhale.ps1 and a shared codewhale.mjs. Default setup installs the official npm host and pinned adapter, verifies native startup, guides browser authorization when needed, then asks before choosing a model and launching. Install-only never logs in.

Both menus retain old numbering and append Codewhale: desktop option 8, Termux option 6. Login, model selection, run, status, balance, usage, logout and doctor remain separately callable; interactive revocation asks for confirmation.

Adapter revision: 8c78be0f936fb8f508badabc0195cdb21442a75d. Standalone wrappers pin helper 354a0e7 and verify SHA-256; menus pin complete installer bd0a81d. Download/checksum failures stop execution. Windows invokes the official native executable and npm JS entrypoint without a shell, retaining PowerShell 5.1 literal-argument/exit-code fixes.

No duplicate credentials, existing TOML overwrite, registry change, sudo/force install, model approval bypass or OAuth consent bypass. Existing Pi/DSH installer behavior is retained; the Windows broad-CI fix only exposes and checks the job's actual Pi install path.

Verified head

32a6363.

Both complete workflows were rechecked after their earlier pending state. Coverage includes Ubuntu/macOS/Windows, offline contracts, Unix real pseudo-terminal menus, PowerShell 7/5.1, isolated real npm installation and native/adapter startup without OAuth or inference. This supersedes the earlier note that broad Installer checks were still running.

Reviewed the implementation, entrypoint checksum rejection, shell-free argument forwarding, menus, workflow changes and PR discussion. No checks were bypassed or disabled.

Integration and rollout boundary

Parent TokenNotIncluded/api.lmm.best#440 pins this exact scripts commit. Preserve that pinned commit in main's history when merging this PR.

Requires Node.js 22+ and npm. Backend lmm-codewhale registration must also be merged and deployed before production OAuth can work. Android/Termux remains preview; Windows adapter ACL hardening is not implemented and shared Windows accounts are unsupported. No production account authorization, model inference, billing or physical-device acceptance is claimed. Merging source does not deploy or enable OAuth.

Copilot AI lite review requested due to automatic review settings September 21, 2026 19:37
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-09-21T19:58:24.254781Z 856bf5c PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

LIghtJUNction added a commit to TokenNotIncluded/api.lmm.best that referenced this pull request Sep 21, 2026
References TokenNotIncluded/lmm-scripts#5. Update only the lmm-scripts gitlink; preserve the provider, Pi and DSH revisions.
Fix issues observed in Windows/Ubuntu PowerShell and macOS CI without weakening assertions.
All assertions were passing, but the Actions PowerShell wrapper propagated the last deliberately failing checksum-test process status. Explicitly exit zero only after every assertion and cleanup succeeds.
Assign the decoded JSON array directly; wrapping the pipeline in @() nests the array under Windows PowerShell 5.1.
@LIghtJUNction
LIghtJUNction merged commit 575a436 into main Sep 21, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants