Isolate credential diagnostics from public runtime streams - #1485
Merged
Merged
Conversation
7 of 53 tasks
7 of 51 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix credential diagnostics in public stream errors
A synthetic expired credential reproduced private refresh-error text in actual Earendil 0.99.1
ModelRuntime.streamandstreamSimpleterminal events and results, before provider inference. UpstreamModelsErrorincorporates cause text during lazy auth setup.Change
Inject a public
CredentialStorefacade around Piclaw's backing store atcreateRuntimeModelServices:DOMExceptioncancellation.Regression tests exercise both public stream methods with permanent refresh, exhausted transient refresh and malformed storage, plus successful retry through public
getAuth. No inference/network calls. Existing lifecycle/store checks remain green.Validation
Limits and initial failures
This protects rejected app-owned store operations entering Piclaw's runtime. Provider login/
toAuthfailures outside store operations, unrelated transport diagnostics, historical data, live providers, Delegate parity and native MCP acceptance are unqualified.Initial fixture tests completed assertions but stayed alive and hit the parent deadline. The owned fixture now explicitly exits after assertions and cleanup; natural runtime teardown is outside scope. A public
AuthResult.auth.apiKeyassertion was corrected after a failed run. All initial failures retained locally.No private upstream imports, live credential reads, inference, deployment or restart. #1442/#1458 remain open.
Refs #1458.