Skip to content

Isolate credential diagnostics from public runtime streams - #1485

Merged
piclaw-bot merged 1 commit into
mainfrom
fix/1458-auth-stream-errors
Oct 1, 2026
Merged

piclaw-bot merged 1 commit into
mainfrom
fix/1458-auth-stream-errors

Conversation

@piclaw-bot

Copy link
Copy Markdown
Collaborator

Fix credential diagnostics in public stream errors

A synthetic expired credential reproduced private refresh-error text in actual Earendil 0.99.1 ModelRuntime.stream and streamSimple terminal events and results, before provider inference. Upstream ModelsError incorporates cause text during lazy auth setup.

Change

Inject a public CredentialStore facade around Piclaw's backing store at createRuntimeModelServices:

  • Forward all operations, callback/options identity and successful results.
  • Allow backing locking, retries and atomic commits to finish unchanged.
  • Replace rejected store diagnostics with generic auth/transient-network/cancellation errors without original message, cause, stack or custom properties.
  • Guard error classification against hostile getters/proxies; preserve DOMException cancellation.

Regression tests exercise both public stream methods with permanent refresh, exhausted transient refresh and malformed storage, plus successful retry through public getAuth. No inference/network calls. Existing lifecycle/store checks remain green.

Validation

  • Focused public-runtime/store/lifecycle set: 43 passed / 243 assertions.
  • Five typechecks, strict fixture typing, scoped Oxlint, silent-swallow, local-entrypoint and diff checks pass.
  • Independent review issues fixed and re-reviewed with no blockers.
  • Canonical gate: 5,988 passed / 8 existing or opt-in skips / 0 failures, plus 25 feature tests and 9 web checks.
  • Pack hygiene: 24,743 files. Final five typechecks pass; compose retains 95 unchanged baseline diagnostics. Private Bun cache, no shared-cache permission changes.

Limits and initial failures

This protects rejected app-owned store operations entering Piclaw's runtime. Provider login/toAuth failures outside store operations, unrelated transport diagnostics, historical data, live providers, Delegate parity and native MCP acceptance are unqualified.

Initial fixture tests completed assertions but stayed alive and hit the parent deadline. The owned fixture now explicitly exits after assertions and cleanup; natural runtime teardown is outside scope. A public AuthResult.auth.apiKey assertion was corrected after a failed run. All initial failures retained locally.

No private upstream imports, live credential reads, inference, deployment or restart. #1442/#1458 remain open.

Refs #1458.

@piclaw-bot
piclaw-bot merged commit 904ff16 into main Oct 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants