feat: add Codewhale one-click OAuth setup and menu integration - #5
Merged
Merged
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
LIghtJUNction
added a commit
to TokenNotIncluded/api.lmm.best
that referenced
this pull request
Sep 21, 2026
References TokenNotIncluded/lmm-scripts#5. Update only the lmm-scripts gitlink; preserve the provider, Pi and DSH revisions.
Fix issues observed in Windows/Ubuntu PowerShell and macOS CI without weakening assertions.
All assertions were passing, but the Actions PowerShell wrapper propagated the last deliberately failing checksum-test process status. Explicitly exit zero only after every assertion and cleanup succeeds.
Assign the decoded JSON array directly; wrapping the pipeline in @() nests the array under Windows PowerShell 5.1.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Add Codewhale installation/OAuth setup through codewhale.sh, codewhale.ps1 and a shared codewhale.mjs. Default setup installs the official npm host and pinned adapter, verifies native startup, guides browser authorization when needed, then asks before choosing a model and launching. Install-only never logs in.
Both menus retain old numbering and append Codewhale: desktop option 8, Termux option 6. Login, model selection, run, status, balance, usage, logout and doctor remain separately callable; interactive revocation asks for confirmation.
Adapter revision: 8c78be0f936fb8f508badabc0195cdb21442a75d. Standalone wrappers pin helper 354a0e7 and verify SHA-256; menus pin complete installer bd0a81d. Download/checksum failures stop execution. Windows invokes the official native executable and npm JS entrypoint without a shell, retaining PowerShell 5.1 literal-argument/exit-code fixes.
No duplicate credentials, existing TOML overwrite, registry change, sudo/force install, model approval bypass or OAuth consent bypass. Existing Pi/DSH installer behavior is retained; the Windows broad-CI fix only exposes and checks the job's actual Pi install path.
Verified head
32a6363.
Both complete workflows were rechecked after their earlier pending state. Coverage includes Ubuntu/macOS/Windows, offline contracts, Unix real pseudo-terminal menus, PowerShell 7/5.1, isolated real npm installation and native/adapter startup without OAuth or inference. This supersedes the earlier note that broad Installer checks were still running.
Reviewed the implementation, entrypoint checksum rejection, shell-free argument forwarding, menus, workflow changes and PR discussion. No checks were bypassed or disabled.
Integration and rollout boundary
Parent TokenNotIncluded/api.lmm.best#440 pins this exact scripts commit. Preserve that pinned commit in main's history when merging this PR.
Requires Node.js 22+ and npm. Backend lmm-codewhale registration must also be merged and deployed before production OAuth can work. Android/Termux remains preview; Windows adapter ACL hardening is not implemented and shared Windows accounts are unsupported. No production account authorization, model inference, billing or physical-device acceptance is claimed. Merging source does not deploy or enable OAuth.