Merge pull request #782 from kaitranntt/dev

feat(release): promote dev to main
This commit is contained in:
Kai (Tam Nhu) Tran authored and GitHub committed 2026-03-24 11:48:40 -04:00
commit 785773d49b
109 files changed
+6233 -2884

No files matched your search

+29 -16
View File
@@ -11,8 +11,7 @@ concurrency:
jobs:
release:
# Skip if commit message contains [skip ci]
if: "!contains(github.event.head_commit.message, '[skip ci]')"
if: ${{ github.ref == 'refs/heads/dev' && (github.event_name != 'push' || !contains(github.event.head_commit.message, '[skip ci]')) }}
runs-on: ubuntu-latest
permissions:
@@ -26,6 +25,7 @@ jobs:
uses: actions/checkout@v4
with:
fetch-depth: 0
ref: dev
# Always use the built-in workflow token; PAT rotation/breakage must not block dev releases.
token: ${{ github.token }}
@@ -65,12 +65,7 @@ jobs:
# Use custom dev release script instead of semantic-release
# This ensures dev versions follow {stable}-dev.{N} pattern
chmod +x scripts/dev-release.sh
if ./scripts/dev-release.sh; then
echo "released=true" >> $GITHUB_OUTPUT
else
echo "Dev release failed or skipped"
echo "released=false" >> $GITHUB_OUTPUT
fi
./scripts/dev-release.sh
- name: Notify Discord
if: success() && steps.release.outputs.released == 'true'
@@ -87,28 +82,46 @@ jobs:
if: success() && steps.release.outputs.released == 'true'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PREVIOUS_DEV_TAG: ${{ steps.release.outputs.previous_dev_tag }}
STABLE_TAG: ${{ steps.release.outputs.stable_tag }}
run: |
# Get version from package.json
VERSION=$(jq -r '.version' package.json)
# Get commits ONLY since last dev tag (not all release commits)
# This prevents re-tagging issues from older releases
LAST_DEV_TAG=$(git tag -l "v*-dev.*" --sort=-v:refname | head -1 || echo "")
if [ -n "$LAST_DEV_TAG" ]; then
if [[ -n "$PREVIOUS_DEV_TAG" ]]; then
# Commits between last dev tag and current (excluding release commit)
RANGE="${LAST_DEV_TAG}..HEAD~1"
RANGE="${PREVIOUS_DEV_TAG}..HEAD~1"
else
# First dev release - check commits since last stable tag
STABLE_TAG=$(git tag -l "v[0-9]*.[0-9]*.[0-9]" --merged origin/main --sort=-v:refname | grep -E '^v[0-9]+\.[0-9]+\.[0-9]+$' | head -1 || echo "")
RANGE="${STABLE_TAG:-HEAD~10}..HEAD~1"
fi
echo "Checking commits in range: $RANGE"
# Extract issue numbers from commit messages
ISSUES=$(git log $RANGE --pretty=format:"%s %b" 2>/dev/null | \
grep -oE "(Fixes|Closes|Resolves|Refs?) #[0-9]+" | \
COMMIT_TEXT=$(git log $RANGE --pretty=format:"%s%n%b" 2>/dev/null || true)
ISSUES_FROM_COMMITS=$(printf '%s\n' "$COMMIT_TEXT" | \
perl -ne 'if (/(fixes|closes|resolves|refs?)(.*)/i) { print "$2\n"; }' | \
grep -oE '#[0-9]+' || true)
PR_CANDIDATES=$(printf '%s\n' "$COMMIT_TEXT" | \
grep -oE "Merge pull request #[0-9]+|\\(#[0-9]+\\)" | \
grep -oE "[0-9]+" | sort -u || true)
PR_TEXT=""
for PR_NUM in $PR_CANDIDATES; do
DETAILS=$(gh pr view "$PR_NUM" --repo "${{ github.repository }}" --json title,body --jq '.title + "\n" + (.body // "")' 2>/dev/null || true)
if [[ -n "$DETAILS" ]]; then
PR_TEXT="${PR_TEXT}"$'\n'"${DETAILS}"
fi
done
ISSUES_FROM_PRS=$(printf '%s\n' "$PR_TEXT" | \
perl -ne 'if (/(fixes|closes|resolves|refs?)(.*)/i) { print "$2\n"; }' | \
grep -oE '#[0-9]+' || true)
ISSUES=$(printf '%s\n%s\n' "$ISSUES_FROM_COMMITS" "$ISSUES_FROM_PRS" | \
grep -oE "#[0-9]+" | sort -u || true)
if [[ -z "$ISSUES" ]]; then
+51 -16
View File
@@ -1,17 +1,23 @@
name: Publish Docker Image
on:
push:
tags:
- 'v*.*.*'
release:
types:
- published
workflow_dispatch:
inputs:
tag:
description: Stable tag to publish manually, for example v7.55.0
required: true
type: string
concurrency:
group: docker-release-${{ github.ref }}
group: docker-release-${{ github.event_name == 'release' && github.event.release.tag_name || inputs.tag || github.ref }}
cancel-in-progress: false
jobs:
publish:
if: startsWith(github.ref, 'refs/tags/v') && !contains(github.ref_name, '-')
if: ${{ github.event_name != 'release' || !github.event.release.prerelease }}
runs-on: ubuntu-latest
permissions:
@@ -19,19 +25,36 @@ jobs:
packages: write
steps:
- name: Checkout release tag
uses: actions/checkout@v4
- name: Resolve target tag
id: target
env:
MANUAL_TAG: ${{ inputs.tag }}
RELEASE_EVENT_TAG: ${{ github.event.release.tag_name }}
run: |
if [[ "${GITHUB_EVENT_NAME}" == "release" ]]; then
TARGET_TAG="${RELEASE_EVENT_TAG}"
else
TARGET_TAG="${MANUAL_TAG}"
fi
echo "tag=${TARGET_TAG}" >> "$GITHUB_OUTPUT"
- name: Validate stable semver tag
id: tag
run: |
if [[ "${GITHUB_REF_NAME}" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
if [[ "${{ steps.target.outputs.tag }}" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "publish=true" >> "$GITHUB_OUTPUT"
exit 0
fi
echo "publish=false" >> "$GITHUB_OUTPUT"
echo "Skipping non-stable semver tag ${GITHUB_REF_NAME}"
echo "Skipping non-stable semver tag ${{ steps.target.outputs.tag }}"
- name: Checkout release tag
if: steps.tag.outputs.publish == 'true'
uses: actions/checkout@v4
with:
ref: ${{ steps.target.outputs.tag }}
- name: Set up QEMU
if: steps.tag.outputs.publish == 'true'
@@ -44,18 +67,34 @@ jobs:
- name: Derive image metadata
if: steps.tag.outputs.publish == 'true'
id: meta
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
VERSION="${GITHUB_REF_NAME#v}"
VERSION="${{ steps.target.outputs.tag }}"
VERSION="${VERSION#v}"
MINOR="${VERSION%.*}"
MAJOR="${VERSION%%.*}"
OWNER_LOWER=$(echo "${GITHUB_REPOSITORY_OWNER}" | tr '[:upper:]' '[:lower:]')
IMAGE="ghcr.io/${OWNER_LOWER}/ccs-dashboard"
REVISION=$(git rev-parse HEAD)
TAGS="${IMAGE}:${VERSION}"
if [[ "${GITHUB_EVENT_NAME}" == "release" ]]; then
TAGS="${TAGS}
${IMAGE}:${MINOR}
${IMAGE}:${MAJOR}
${IMAGE}:latest"
fi
{
echo "version=${VERSION}"
echo "minor=${MINOR}"
echo "major=${MAJOR}"
echo "image=${IMAGE}"
echo "revision=${REVISION}"
echo "tags<<EOF"
echo "${TAGS}"
echo "EOF"
} >> "$GITHUB_OUTPUT"
- name: Log in to GitHub Container Registry
@@ -74,17 +113,13 @@ jobs:
file: docker/Dockerfile
platforms: linux/amd64,linux/arm64
push: true
tags: |
${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.version }}
${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.minor }}
${{ steps.meta.outputs.image }}:${{ steps.meta.outputs.major }}
${{ steps.meta.outputs.image }}:latest
tags: ${{ steps.meta.outputs.tags }}
labels: |
org.opencontainers.image.title=ccs-dashboard
org.opencontainers.image.description=CCS Dashboard container image
org.opencontainers.image.url=https://github.com/${{ github.repository }}
org.opencontainers.image.source=https://github.com/${{ github.repository }}
org.opencontainers.image.version=${{ steps.meta.outputs.version }}
org.opencontainers.image.revision=${{ github.sha }}
org.opencontainers.image.revision=${{ steps.meta.outputs.revision }}
cache-from: type=gha
cache-to: type=gha,mode=max
+50 -22
View File
@@ -2,7 +2,7 @@ name: Label Pending Release
on:
pull_request:
types: [opened, reopened]
types: [opened, reopened, edited, synchronize]
branches: [dev]
jobs:
@@ -10,34 +10,62 @@ jobs:
runs-on: ubuntu-latest
permissions:
issues: write
pull-requests: read
steps:
- name: Label linked issues as pending-release
- name: Reconcile pending-release labels for open dev PRs
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_TITLE: ${{ github.event.pull_request.title }}
PR_BODY: ${{ github.event.pull_request.body }}
run: |
# Extract issue numbers from PR title and body (passed via env vars for safety)
# Using env vars prevents shell injection from backticks in markdown
PR_TEXT="$PR_TITLE $PR_BODY"
ISSUES=$(echo "$PR_TEXT" | grep -oE "(Fixes|Closes|Resolves|Refs?) #[0-9]+" | grep -oE "#[0-9]+" | sort -u || true)
# Recompute the complete open-PR issue set so edited/synchronized PRs
# can remove stale pending-release labels as well as add new ones.
OPEN_PRS=$(gh pr list \
--repo "${{ github.repository }}" \
--base dev \
--state open \
--json number,title,body \
--jq '.[] | @base64' 2>/dev/null || true)
ALL_REFERENCED_ISSUES=""
while IFS= read -r PR_ROW; do
[[ -z "$PR_ROW" ]] && continue
PR_JSON=$(printf '%s' "$PR_ROW" | base64 --decode)
PR_NUM=$(printf '%s' "$PR_JSON" | jq -r '.number')
PR_TITLE=$(printf '%s' "$PR_JSON" | jq -r '.title')
PR_BODY=$(printf '%s' "$PR_JSON" | jq -r '.body // ""')
COMMIT_TEXT=$(gh api "repos/${{ github.repository }}/pulls/${PR_NUM}/commits" --paginate --jq '.[].commit.message' 2>/dev/null || true)
PR_TEXT="$PR_TITLE
$PR_BODY
$COMMIT_TEXT"
PR_ISSUES=$(printf '%s\n' "$PR_TEXT" | \
perl -ne 'if (/(fixes|closes|resolves|refs?)(.*)/i) { print "$2\n"; }' | \
grep -oE '#[0-9]+' || true)
if [[ -n "$PR_ISSUES" ]]; then
ALL_REFERENCED_ISSUES=$(printf '%s\n%s\n' "$ALL_REFERENCED_ISSUES" "$PR_ISSUES")
fi
done <<< "$OPEN_PRS"
ISSUES=$(printf '%s\n' "$ALL_REFERENCED_ISSUES" | grep -oE '#[0-9]+' | sort -u || true)
CURRENT_PENDING=$(gh issue list --repo "${{ github.repository }}" --label "pending-release" --state all --json number --jq '.[].number' 2>/dev/null || true)
gh label create "pending-release" \
--color "fbca04" \
--description "Fix in review, awaiting merge" \
--repo ${{ github.repository }} 2>/dev/null || true
if [[ -z "$ISSUES" ]]; then
echo "No linked issues found in PR"
exit 0
echo "No linked issues found across open dev PRs"
else
for ISSUE in $ISSUES; do
NUM=${ISSUE#\#}
echo "Ensuring issue #$NUM has pending-release"
gh issue edit "$NUM" --add-label "pending-release" --repo "${{ github.repository }}" || true
done
fi
for ISSUE in $ISSUES; do
NUM=${ISSUE#\#}
echo "Labeling issue #$NUM as pending-release"
# Create label if doesn't exist
gh label create "pending-release" \
--color "fbca04" \
--description "Fix in review, awaiting merge" \
--repo ${{ github.repository }} 2>/dev/null || true
# Add label to issue
gh issue edit $NUM --add-label "pending-release" --repo ${{ github.repository }} || true
for NUM in $CURRENT_PENDING; do
if ! printf '%s\n' "$ISSUES" | grep -qx "#${NUM}"; then
echo "Removing stale pending-release from issue #$NUM"
gh issue edit "$NUM" --remove-label "pending-release" --repo "${{ github.repository }}" 2>/dev/null || true
fi
done
+71 -21
View File
@@ -7,6 +7,7 @@ on:
jobs:
release:
if: ${{ github.ref == 'refs/heads/main' }}
runs-on: ubuntu-latest
permissions:
@@ -57,10 +58,17 @@ jobs:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
OUTPUT=$(bunx semantic-release 2>&1) || true
set +e
OUTPUT=$(bunx semantic-release 2>&1)
STATUS=$?
set -e
echo "$OUTPUT"
# Strip ANSI color codes before matching (semantic-release outputs colored text)
CLEAN=$(echo "$OUTPUT" | sed 's/\x1b\[[0-9;]*m//g')
if [[ "$STATUS" -ne 0 ]]; then
echo "released=false" >> $GITHUB_OUTPUT
exit "$STATUS"
fi
if echo "$CLEAN" | grep -q "Published GitHub release"; then
echo "released=true" >> $GITHUB_OUTPUT
else
@@ -83,31 +91,73 @@ jobs:
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
# semantic-release already adds "released" label via .releaserc.cjs
# This step removes transitional labels and closes issues now in stable.
VERSION=$(jq -r '.version' package.json)
RELEASE_BODY=$(gh release view "v${VERSION}" --repo "${{ github.repository }}" --json body --jq '.body' 2>/dev/null || echo "")
PREVIOUS_STABLE_TAG=$(git tag -l "v[0-9]*.[0-9]*.[0-9]" --sort=-v:refname | \
grep -E '^v[0-9]+\.[0-9]+\.[0-9]+$' | \
grep -vx "v${VERSION}" | head -1 || echo "")
RANGE="${PREVIOUS_STABLE_TAG:+${PREVIOUS_STABLE_TAG}..HEAD~1}"
if [[ -z "$RANGE" ]]; then
RANGE="HEAD~50..HEAD~1"
fi
# Find issues with both "released" and "released-dev" labels
ISSUES=$(gh issue list --label "released" --label "released-dev" --state all --json number --jq '.[].number' 2>/dev/null || echo "")
COMMIT_TEXT=$(git log $RANGE --pretty=format:"%s%n%b" 2>/dev/null || true)
PR_CANDIDATES=$(printf '%s\n' "$COMMIT_TEXT" | \
grep -oE "Merge pull request #[0-9]+|\\(#[0-9]+\\)" | \
grep -oE "[0-9]+" | sort -u || true)
for NUM in $ISSUES; do
echo "Cleaning up labels on issue #$NUM"
gh issue edit "$NUM" --remove-label "released-dev" --remove-label "pending-release" --repo "${{ github.repository }}" 2>/dev/null || true
PR_TEXT=""
for PR_NUM in $PR_CANDIDATES; do
DETAILS=$(gh pr view "$PR_NUM" --repo "${{ github.repository }}" --json title,body --jq '.title + "\n" + (.body // "")' 2>/dev/null || true)
if [[ -n "$DETAILS" ]]; then
PR_TEXT="${PR_TEXT}"$'\n'"${DETAILS}"
fi
done
# Also clean pending-release from any issues with released label
PENDING=$(gh issue list --label "released" --label "pending-release" --state all --json number --jq '.[].number' 2>/dev/null || echo "")
RELEASE_ISSUES_FROM_BODY=$(printf '%s\n' "$RELEASE_BODY" | \
perl -ne 'if (/(fixes|closes|resolves|refs?)(.*)/i) { print "$2\n"; }' | \
grep -oE '#[0-9]+' | tr -d '#' || true)
RELEASE_ISSUES_FROM_COMMITS=$(printf '%s\n' "$COMMIT_TEXT" | \
perl -ne 'if (/(fixes|closes|resolves|refs?)(.*)/i) { print "$2\n"; }' | \
grep -oE '#[0-9]+' | tr -d '#' || true)
RELEASE_ISSUES_FROM_PRS=$(printf '%s\n' "$PR_TEXT" | \
perl -ne 'if (/(fixes|closes|resolves|refs?)(.*)/i) { print "$2\n"; }' | \
grep -oE '#[0-9]+' | tr -d '#' || true)
RELEASE_ISSUES=$(printf '%s\n%s\n%s\n' \
"$RELEASE_ISSUES_FROM_BODY" \
"$RELEASE_ISSUES_FROM_COMMITS" \
"$RELEASE_ISSUES_FROM_PRS" | sort -u || true)
for NUM in $PENDING; do
echo "Removing pending-release from issue #$NUM"
gh issue edit "$NUM" --remove-label "pending-release" --repo "${{ github.repository }}" 2>/dev/null || true
done
RESOLVED_ISSUES_FROM_BODY=$(printf '%s\n' "$RELEASE_BODY" | \
perl -ne 'if (/(fixes|closes|resolves)(.*)/i) { print "$2\n"; }' | \
grep -oE '#[0-9]+' | tr -d '#' || true)
RESOLVED_ISSUES_FROM_COMMITS=$(printf '%s\n' "$COMMIT_TEXT" | \
perl -ne 'if (/(fixes|closes|resolves)(.*)/i) { print "$2\n"; }' | \
grep -oE '#[0-9]+' | tr -d '#' || true)
RESOLVED_ISSUES_FROM_PRS=$(printf '%s\n' "$PR_TEXT" | \
perl -ne 'if (/(fixes|closes|resolves)(.*)/i) { print "$2\n"; }' | \
grep -oE '#[0-9]+' | tr -d '#' || true)
RESOLVED_ISSUES=$(printf '%s\n%s\n%s\n' \
"$RESOLVED_ISSUES_FROM_BODY" \
"$RESOLVED_ISSUES_FROM_COMMITS" \
"$RESOLVED_ISSUES_FROM_PRS" | sort -u || true)
# Close open issues that are marked as released
OPEN_RELEASED=$(gh issue list --label "released" --state open --json number --jq '.[].number' 2>/dev/null || echo "")
if [[ -z "$RELEASE_ISSUES" ]]; then
echo "No release-scoped issues found for v${VERSION}"
exit 0
fi
for NUM in $OPEN_RELEASED; do
echo "Closing released issue #$NUM"
gh issue close "$NUM" \
--comment "[bot] Closing issue because this fix/feature is now in stable release (@latest)." \
--repo "${{ github.repository }}" || true
for NUM in $RELEASE_ISSUES; do
echo "Cleaning release state on issue #$NUM"
gh issue edit "$NUM" \
--remove-label "released-dev" \
--remove-label "pending-release" \
--repo "${{ github.repository }}" 2>/dev/null || true
HAS_RELEASED=$(gh issue view "$NUM" --repo "${{ github.repository }}" --json labels --jq '[.labels[].name | select(. == "released")] | length' 2>/dev/null || echo "0")
if [[ "$HAS_RELEASED" -gt 0 ]] && printf '%s\n' "$RESOLVED_ISSUES" | grep -qx "$NUM"; then
gh issue close "$NUM" \
--comment "[bot] Closing issue because this fix/feature is now in stable release (@latest)." \
--repo "${{ github.repository }}" || true
fi
done
+3 -6
View File
@@ -1,15 +1,12 @@
name: Sync Dev After Main Release
on:
workflow_run:
workflows: ["Release"]
types: [completed]
branches: [main]
release:
types: [published]
jobs:
sync-dev:
# Only run if Release workflow succeeded on main branch
if: ${{ github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_branch == 'main' }}
if: ${{ !github.event.release.prerelease && github.event.release.target_commitish == 'main' && startsWith(github.event.release.tag_name, 'v') && !contains(github.event.release.tag_name, '-') }}
runs-on: ubuntu-latest
permissions:
+45 -28
View File
@@ -156,6 +156,8 @@ The dashboard provides visual management for all account types:
> **OAuth providers** authenticate via browser on first run. Tokens are cached in `~/.ccs/cliproxy/auth/`.
> **Kiro / Copilot account naming:** Manual nicknames are optional. If the provider does not expose an email, CCS derives a safe internal identifier automatically and you can rename it later.
> **AI Providers dashboard:** Configure CLIProxy-managed API key families at `ccs config` -> `CLIProxy` -> `AI Providers`. Use `API Profiles` only for CCS-native Anthropic-compatible profiles.
**Powered by:**
@@ -192,16 +194,25 @@ ccs api export glm --out ./glm.ccs-profile.json # Export for cross-device trans
ccs api import ./glm.ccs-profile.json # Import exported profile bundle
```
### Droid Alias (`argv[0]` pattern)
### Runtime Aliases (built-in bins / `argv[0]` pattern)
By default, invoking CCS as `ccsd` auto-selects the Droid target:
Built-in Droid runtime aliases are installed with the package:
```bash
ln -s "$(command -v ccs)" /usr/local/bin/ccsd
ccsd glm
ccs-droid glm # explicit alias
ccsd glm # legacy shortcut
```
Need additional alias names? Set `CCS_DROID_ALIASES` as a comma-separated list (for example: `CCS_DROID_ALIASES=ccs-droid,mydroid`).
Need additional alias names? First create the matching symlink or another launcher that
preserves the invoked basename, then map that name with `CCS_TARGET_ALIASES` (preferred) or legacy
`CCS_DROID_ALIASES`:
```bash
ln -s "$(command -v ccs)" /usr/local/bin/mydroid
CCS_TARGET_ALIASES='droid=mydroid'
# Legacy fallback still supported:
CCS_DROID_ALIASES='mydroid'
```
For Factory BYOK compatibility, CCS also stores a per-profile Droid provider hint
(`CCS_DROID_PROVIDER`) using one of:
@@ -215,9 +226,9 @@ which Droid treats as queued prompt text.
CCS supports structural Droid command passthrough after profile selection:
```bash
ccsd codex exec --skip-permissions-unsafe "fix failing tests"
ccsd codex --skip-permissions-unsafe "fix failing tests" # auto-routed to: droid exec ...
ccsd codex -m custom:gpt-5.3-codex "fix failing tests" # short exec flags auto-routed too
ccs-droid codex exec --skip-permissions-unsafe "fix failing tests"
ccs-droid codex --skip-permissions-unsafe "fix failing tests" # auto-routed to: droid exec ...
ccs-droid codex -m custom:gpt-5.3-codex "fix failing tests" # short exec flags auto-routed too
```
If you pass exec-only flags without a prompt (for example `--skip-permissions-unsafe`),
@@ -243,10 +254,10 @@ ccs cliproxy create mycodex --provider codex --target droid
Built-in CLIProxy providers also work with Droid alias/target override:
```bash
ccsd codex
ccsd agy
ccs-droid codex
ccs-droid agy
ccs codex --target droid
ccsd codex exec --auto high "triage this bug report"
ccs-droid codex exec --auto high "triage this bug report"
```
Dashboard parity:
@@ -528,24 +539,26 @@ Without Developer Mode, CCS falls back to copying directories.
## WebSearch
Third-party profiles (Gemini, Codex, GLM, etc.) cannot use Anthropic's native WebSearch. CCS automatically provides web search via CLI tools with automatic fallback.
Third-party profiles (Gemini, Codex, GLM, etc.) cannot use Anthropic's native WebSearch. CCS intercepts those requests and resolves them through real local search backends instead of depending on another model CLI to do the search.
### How It Works
| Profile Type | WebSearch Method |
|--------------|------------------|
| Claude (native) | Anthropic WebSearch API |
| Third-party profiles | CLI Tool Fallback Chain |
| Third-party profiles | Local Search Backend Chain |
### CLI Tool Fallback Chain
### Local Search Backend Chain
CCS intercepts WebSearch requests and routes them through available CLI tools:
CCS intercepts WebSearch requests and routes them through deterministic search providers:
| Priority | Tool | Auth | Install |
|----------|------|------|---------|
| 1st | Gemini CLI | OAuth (free) | `npm install -g @google/gemini-cli` |
| 2nd | OpenCode | OAuth (free) | `curl -fsSL https://opencode.ai/install \| bash` |
| 3rd | Grok CLI | API Key | `npm install -g @vibe-kit/grok-cli` |
| Priority | Provider | Setup | Notes |
|----------|----------|-------|-------|
| 1st | Exa | `EXA_API_KEY` | API-backed search with extracted content |
| 2nd | Tavily | `TAVILY_API_KEY` | Agent-oriented search API |
| 3rd | Brave Search | `BRAVE_API_KEY` | Cleaner API-backed results |
| 4th | DuckDuckGo | None | Built-in default fallback |
| 5th | Gemini / OpenCode / Grok | Optional | Legacy compatibility fallback only |
### Configuration
@@ -554,17 +567,21 @@ Configure via dashboard (**Settings** page) or `~/.ccs/config.yaml`:
```yaml
websearch:
enabled: true # Enable/disable (default: true)
gemini:
enabled: true # Use Gemini CLI (default: true)
model: gemini-2.5-flash # Model to use
opencode:
enabled: true # Use OpenCode as fallback
grok:
enabled: false # Requires XAI_API_KEY
providers:
exa:
enabled: false # Enable when EXA_API_KEY is set
tavily:
enabled: false # Enable when TAVILY_API_KEY is set
duckduckgo:
enabled: true # Built-in zero-setup fallback
brave:
enabled: false # Enable when BRAVE_API_KEY is set
gemini:
enabled: false # Optional legacy fallback
```
> [!TIP]
> **Gemini CLI** is recommended - free OAuth authentication with 1000 requests/day. Just run `gemini` once to authenticate via browser.
> **DuckDuckGo** still works out of the box. Add **Exa**, **Tavily**, or **Brave Search** if you want API-backed results, then keep Gemini/OpenCode/Grok only if you explicitly want legacy fallback behavior.
See [docs/websearch.md](./docs/websearch.md) for detailed configuration and troubleshooting.
+2 -1
View File
@@ -200,7 +200,8 @@ Resolves which adapter to use via `resolveTargetType()`:
↓
2. Profile config: profileConfig.target field
↓
3. argv[0] detection (busybox pattern):
3. argv[0] detection (runtime alias pattern):
- ccs-droid → droid
- ccsd → droid
- ccs → default
↓
+1 -1
View File
@@ -246,7 +246,7 @@ The targets module provides an extensible interface for dispatching profiles to
2. **Target Resolution** - Priority order:
- `--target <cli>` flag (CLI argument)
- Per-profile `target` field (from config.yaml)
- `argv[0]` detection (busybox pattern: `ccsd` → droid)
- `argv[0]` detection (runtime alias pattern: `ccs-droid` / `ccsd` → droid)
- Default: `claude`
3. **Implementations:**
+5 -2
View File
@@ -1,6 +1,6 @@
# Dashboard Authentication CLI
Last Updated: 2026-03-17
Last Updated: 2026-03-23
CLI commands for managing CCS dashboard authentication.
@@ -10,6 +10,8 @@ The CCS dashboard (`ccs config`) can be protected with username/password authent
Authentication is **disabled by default** for backward compatibility. Use the CLI to configure and enable it.
When auth stays disabled, CCS now applies a localhost-only fallback on sensitive management endpoints. Remote devices can still open the dashboard UI when you intentionally bind it beyond loopback, but write-capable routes such as AI Provider management and CLIProxy auth/status helpers reject non-loopback requests until you enable dashboard auth.
## Account Context Modes (Related Feature)
Dashboard auth and account context metadata are separate:
@@ -180,7 +182,8 @@ dashboard_auth:
1. **Bcrypt hashing**: Passwords are hashed with bcrypt (10 rounds) before storage
2. **Session cookies**: Sessions use HTTP-only cookies (not accessible via JavaScript)
3. **Rate limiting**: Login attempts are rate-limited (5 per 15 minutes)
4. **File permissions**: Config file is created with 0o600 permissions
4. **Fail-closed remote writes**: When auth is disabled, sensitive management routes allow localhost only
5. **File permissions**: Config file is created with 0o600 permissions
## Troubleshooting
+6 -5
View File
@@ -35,7 +35,7 @@ CCS provides:
3. **AI Providers**: Dedicated CLIProxy dashboard for Gemini, Codex, Claude, Vertex, and OpenAI-compatible API-key families
4. **API Profiles**: GLM, Kimi, OpenRouter, any Anthropic-compatible API
5. **Visual Dashboard**: React SPA for configuration management
6. **Automatic WebSearch**: MCP fallback for third-party providers
6. **Automatic WebSearch**: Real backend fallback chain for third-party providers
7. **Usage Analytics**: Token tracking, cost analysis, model breakdown
---
@@ -92,8 +92,9 @@ CCS provides:
- Validate symlinks and permissions
### FR-007: WebSearch Fallback
- Auto-configure MCP web search for third-party profiles
- Support Gemini CLI, OpenCode, Grok providers
- Intercept WebSearch for third-party profiles that cannot reach Anthropic's native tool
- Support Exa, Tavily, Brave, and DuckDuckGo real search backends
- Keep Gemini CLI, OpenCode, and Grok as optional legacy fallback
- Graceful fallback chain
### FR-008: Remote CLIProxy Support
@@ -169,8 +170,8 @@ CCS provides:
### TR-002: Optional Dependencies
- CLIProxyAPI binary (auto-managed)
- Gemini CLI for WebSearch
- Additional MCP servers
- Exa/Tavily/Brave API keys for higher-quality WebSearch
- Gemini CLI for legacy WebSearch fallback
### TR-003: Configuration
- YAML-based config (`~/.ccs/config.yaml`)
+3 -1
View File
@@ -1,6 +1,6 @@
# CCS Project Roadmap
Last Updated: 2026-03-19
Last Updated: 2026-03-23
Forward-looking roadmap documenting current priorities, GitHub issues, and future feature plans.
@@ -41,6 +41,8 @@ All major modularization work is complete. The codebase evolved from monolithic
### Recent Fixes
- **2026-03-23**: CLIProxy providers that do not expose an email no longer require a user-supplied nickname on first auth. CCS now derives a stable internal account identifier for Kiro/Copilot-style flows, preserves later rename support, hardens account discovery/registry sync around that identifier, and updates AI Provider CRUD to use stable entry IDs instead of dashboard list indexes.
- **2026-03-23**: Sensitive dashboard management routes now fail closed to localhost-only access whenever dashboard auth is disabled. Remote access remains available after `ccs config auth setup`, but AI Provider management, CLIProxy auth/status helpers, and other write-capable settings endpoints no longer trust unauthenticated non-loopback requests.
- **2026-03-19**: **#649** CCS splits CLIProxy provider-key authoring into a dedicated `CLIProxy -> AI Providers` dashboard route. `/cliproxy` now stays focused on OAuth accounts and variants, `/cliproxy/ai-providers` owns Gemini/Codex/Claude/Vertex/OpenAI-compatible key management, and `/providers` stays reserved for CCS-native API Profiles.
- **2026-03-18**: **#755** Marketplace refresh no longer reuses one shared `known_marketplaces.json` across isolated instances. CCS now keeps marketplace payload directories shared while reconciling per-instance marketplace metadata so Claude Code validation succeeds for alternating or concurrent profiles, including Windows copy fallback.
- **2026-03-17**: Deprecated user-facing GLMT discovery across CLI help, completions, presets, and docs. Existing `glmt` profiles now run through a compatibility path that normalizes legacy proxy settings to the direct GLM endpoint.
+5 -4
View File
@@ -86,11 +86,12 @@ Spawn Target Process
- Spawns: `droid -m custom:ccs-<profile> <args>`
- Model config includes baseUrl, apiKey, provider
**Binary alias pattern (busybox-style):**
**Runtime alias pattern (built-in bins / argv[0]-style):**
```
ccs → Target: claude (default)
ccsd → Target: droid (auto-selected via argv[0])
ccs → Target: claude (default)
ccs-droid → Target: droid (explicit alias)
ccsd → Target: droid (legacy shortcut)
```
For details on the adapter architecture, see [Target Adapters](./target-adapters.md).
@@ -392,7 +393,7 @@ See [Provider Flows](./provider-flows.md) → Authentication Flow section.
|
+---> Creates symlink: ccs --> dist/ccs.js
|
+---> Binary alias: ccsd → ccs (auto-selects droid target)
+---> Runtime aliases: ccs-droid / ccsd → ccs (auto-select droid target)
|
+---> First run creates: ~/.ccs/
```
@@ -361,6 +361,10 @@ function selectBestAccount(accounts: AccountInfo[]): AccountInfo | null {
**Providers**: GitHub Copilot (ghcp)
Provider identity note:
- Providers that do not expose a reliable email no longer require a manual nickname during first auth.
- CCS derives a stable internal account identifier from the token/cache context and still allows the user to rename the account later.
```
+===========================================================================+
| OAuth - Device Code Flow (No Port Needed) |
@@ -432,6 +436,8 @@ function selectBestAccount(accounts: AccountInfo[]): AccountInfo | null {
- Device Code method uses /start route (no callback port)
- Callback/social methods use /start-url + status polling
- Some management flows return state first, auth_url later
- Manual nicknames are optional when the upstream provider does not return an email
- Account storage uses a stable internal identifier so reauth/update flows do not depend on dashboard list order
```
### API Key Profiles (GLM, Kimi)
+21 -11
View File
@@ -79,8 +79,9 @@ CCS resolves which adapter to use via priority-ordered checks:
glm:
target: droid
3. argv[0] detection (busybox pattern) — binary name mapping
└─ ccsd (symlink/batch file) → droid
3. argv[0] detection (runtime alias pattern) — binary name mapping
└─ ccs-droid (explicit alias) → droid
└─ ccsd (legacy shortcut) → droid
└─ ccs (regular command) → default
4. Fallback: 'claude' — lowest priority
@@ -351,22 +352,31 @@ ccs --target droid glm
(credentials loaded from ~/.factory/settings.json)
```
### Binary Alias Pattern
### Runtime Alias Pattern
```bash
# Create alias/symlink to auto-select droid target
# Built-in alias: ccsd
ln -s /path/to/ccs /path/to/ccsd
# Built-in package bin aliases
ccs-droid glm
→ Target: droid (forced by runtime alias)
→ droid -m custom:ccs-glm "args..."
# Usage
# Legacy shortcut still works
ccsd glm
→ Target: droid (detected from argv[0])
→ Target: droid (forced by runtime alias)
→ droid -m custom:ccs-glm "args..."
```
On Windows, `ccsd.cmd`, `ccsd.bat`, `ccsd.ps1`, and `ccsd.exe` wrappers are also recognized.
On Windows, `ccs-droid.cmd`, `ccsd.cmd`, `ccsd.bat`, `ccsd.ps1`, and `ccsd.exe` wrappers are also recognized.
Additional alias names can be configured at runtime via `CCS_DROID_ALIASES` (comma-separated). Example: `CCS_DROID_ALIASES=ccs-droid,mydroid`.
Additional alias names can be configured at runtime after you create a matching
symlink or another launcher that preserves the invoked basename. Use `CCS_TARGET_ALIASES` (preferred,
`target=alias1,alias2;...`) or legacy `CCS_DROID_ALIASES` (comma-separated).
Example:
```bash
ln -s /path/to/ccs /path/to/mydroid
CCS_TARGET_ALIASES=droid=mydroid
```
---
@@ -612,7 +622,7 @@ ccs --target claude help
ccs --target droid help
# Test argv[0] detection
ccsd help
ccs-droid help
```
---
+92 -155
View File
@@ -1,97 +1,71 @@
# WebSearch Configuration Guide
Last Updated: 2026-02-26
Last Updated: 2026-03-23
CCS provides automatic web search capability for all profiles, including third-party providers that cannot access Anthropic's native WebSearch API.
CCS provides automatic web search for third-party profiles that cannot access Anthropic's native WebSearch API.
## How WebSearch Works
### Native Claude Accounts
When using a native Claude subscription account, WebSearch is handled by Anthropic's server-side API ($10/1000 searches, usage-based billing).
Native Claude subscription accounts still use Anthropic's server-side WebSearch directly.
### Third-Party Profiles
Third-party profiles (OAuth and API-based) cannot use Anthropic's WebSearch because:
- Claude Code CLI executes tools locally
- CLIProxyAPI only receives conversation messages
- Tool execution never reaches the third-party backend
CCS solves this with a hybrid fallback approach:
1. **Gemini CLI Transformer** (Primary) - Uses positional Gemini prompt mode (with legacy `-p` fallback) and `google_web_search` tool
2. **MCP Fallback Chain** (Secondary) - MCP-based web search servers
Third-party profiles cannot execute Anthropic's server-side WebSearch because the tool never reaches their backend. CCS now solves that by intercepting WebSearch and running real local search providers directly.
## Architecture
```
┌──────────────────────────────────────────────────────────────┐
│ Claude Code CLI │
│ │
│ WebSearch Tool Request │
│ │ │
│ ├── Native Claude Account? → Anthropic WebSearch API │
│ │ ($10/1000 searches) │
│ │ │
│ └── Third-party Profile? → PreToolUse Hook │
│ │ │
│ ├── 1. Gemini CLI │
│ │ (google_web_search) │
│ │ No API key needed! │
│ │ │
│ └── 2. MCP Fallback Chain │
│ ├── web-search-prime │
│ ├── Brave Search │
│ └── Tavily │
│ Claude Code CLI │
│ │
│ WebSearch Tool Request │
│ │ │
│ ├── Native Claude Account? → Anthropic WebSearch API │
│ │ │
│ └── Third-party Profile? → PreToolUse Hook │
│ │ │
│ ├── 1. Exa Search API │
│ ├── 2. Tavily Search API │
│ ├── 3. Brave Search API │
│ ├── 4. DuckDuckGo HTML │
│ └── 5. Legacy CLI fallback │
│ (Gemini/OpenCode/Grok) │
└──────────────────────────────────────────────────────────────┘
```
## Gemini CLI Integration (Primary)
## Why This Changed
The **ultimate solution** for third-party WebSearch. Uses `gemini` CLI with OAuth authentication - **no API key needed!**
The previous design asked another model CLI to perform web search and summarize the answer. That was brittle:
### How It Works
- CLI syntax changed upstream
- auth state varied per tool
- prompt/tool behavior drifted across releases
1. A PreToolUse hook intercepts WebSearch tool calls
2. Executes `gemini "<prompt>"` (positional mode) with explicit google_web_search instruction
3. Returns search results directly to Claude via the hook's deny reason
4. Claude receives full search results and continues the conversation
The new flow matches the `goclaw` model more closely: web search is treated as a first-class deterministic capability, not an LLM-to-LLM workaround.
### Requirements
## Providers
- `gemini` CLI installed and authenticated (run `gemini` to authenticate via browser)
- OAuth authentication (no GEMINI_API_KEY needed)
### Installation
The Gemini CLI is installed via npm:
```bash
npm install -g @google/gemini-cli
```
Then authenticate by running gemini once (opens browser):
```bash
gemini
```
## MCP Providers
| Provider | Type | Cost | API Key Required | Notes |
|----------|------|------|------------------|-------|
| web-search-prime | HTTP MCP | z.ai subscription | No | Requires z.ai coding plan |
| Brave Search | stdio MCP | Free tier | `BRAVE_API_KEY` | 15k queries/month |
| Tavily | stdio MCP | Paid | `TAVILY_API_KEY` | AI-optimized search |
| Provider | Type | Setup | Default | Notes |
|----------|------|-------|---------|-------|
| Exa | HTTP API | `EXA_API_KEY` | No | High-quality API search with extracted content |
| Tavily | HTTP API | `TAVILY_API_KEY` | No | Agent-oriented search API |
| DuckDuckGo | HTML fetch | None | Yes | Built-in zero-setup fallback |
| Brave Search | HTTP API | `BRAVE_API_KEY` | No | Cleaner snippets and metadata |
| Gemini CLI | Legacy CLI | `npm i -g @google/gemini-cli` | No | Optional compatibility fallback |
| OpenCode | Legacy CLI | `curl -fsSL https://opencode.ai/install \| bash` | No | Optional compatibility fallback |
| Grok CLI | Legacy CLI | `npm i -g @vibe-kit/grok-cli` + `GROK_API_KEY` | No | Optional compatibility fallback |
## Configuration
### Via Dashboard
1. Open dashboard: `ccs config`
2. Navigate to **Settings** page
3. Configure WebSearch options:
- **Enable/Disable**: Toggle auto-configuration
- **Provider**: Choose preferred provider
- **Fallback**: Enable/disable fallback chain
Open `ccs config` → `Settings` → `WebSearch`.
- Enable Exa, Tavily, Brave, or DuckDuckGo in the backend chain
- Export the matching API key first for Exa, Tavily, or Brave
- Review whether any legacy fallback CLIs are still enabled in config
### Via Config File
@@ -99,111 +73,74 @@ Edit `~/.ccs/config.yaml`:
```yaml
websearch:
enabled: true # Enable auto-config (default: true)
provider: auto # auto | web-search-prime | brave | tavily
fallback: true # Enable fallback chain (default: true)
webSearchPrimeUrl: "https://..." # Optional: custom endpoint
# Gemini CLI configuration (new!)
gemini:
enabled: true # Use Gemini CLI for WebSearch (default: true)
timeout: 55 # Timeout in seconds (default: 55)
enabled: true
providers:
exa:
enabled: false
max_results: 5
tavily:
enabled: false
max_results: 5
duckduckgo:
enabled: true
max_results: 5
brave:
enabled: false
max_results: 5
gemini:
enabled: false
model: gemini-2.5-flash
timeout: 55
opencode:
enabled: false
model: opencode/grok-code
timeout: 90
grok:
enabled: false
timeout: 55
```
### Environment Variables
## Environment Variables
The WebSearch hook also respects these environment variables:
| Variable | Description | Default |
|----------|-------------|---------|
| `CCS_WEBSEARCH_SKIP` | Skip WebSearch hook entirely | `0` |
| `CCS_GEMINI_SKIP` | Skip Gemini CLI, use MCP only | `0` |
| `CCS_GEMINI_TIMEOUT` | Gemini CLI timeout (seconds) | `55` |
| `CCS_DEBUG` | Enable debug output | `0` |
### Provider Options
- **auto** (default): Uses web-search-prime, adds Brave/Tavily if API keys available
- **web-search-prime**: Requires z.ai coding plan subscription
- **brave**: Requires `BRAVE_API_KEY` env var
- **tavily**: Requires `TAVILY_API_KEY` env var
## Setting Up Optional Providers
### Brave Search (Free Tier)
1. Get API key: [brave.com/search/api](https://brave.com/search/api)
2. Set environment variable:
```bash
export BRAVE_API_KEY="your-api-key"
```
3. Restart CCS - Brave will be added to fallback chain
**Free tier limits**: 15,000 queries/month, 1 query/second
### Tavily (AI-Optimized)
1. Get API key: [tavily.com](https://tavily.com)
2. Set environment variable:
```bash
export TAVILY_API_KEY="your-api-key"
```
3. Restart CCS - Tavily will be added to fallback chain
## MCP Configuration
CCS writes MCP configuration to `~/.claude/.mcp.json`. Example:
```json
{
"mcpServers": {
"web-search-prime": {
"type": "http",
"url": "https://api.z.ai/api/mcp/web_search_prime/mcp",
"headers": {}
},
"brave-search": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-brave-search"],
"env": { "BRAVE_API_KEY": "..." }
}
}
}
```
| Variable | Description |
|----------|-------------|
| `EXA_API_KEY` | Enables Exa when `providers.exa.enabled: true` |
| `TAVILY_API_KEY` | Enables Tavily when `providers.tavily.enabled: true` |
| `BRAVE_API_KEY` | Enables Brave Search when `providers.brave.enabled: true` |
| `GROK_API_KEY` | Required only for legacy Grok CLI fallback |
| `CCS_WEBSEARCH_SKIP` | Skip hook entirely |
| `CCS_DEBUG` | Verbose hook logging |
## Troubleshooting
### Gemini CLI Issues
### WebSearch says "Ready (DuckDuckGo)"
1. **Not installed**: Install with `npm install -g @google/gemini-cli`
2. **Not authenticated**: Run `gemini` to open browser for OAuth login
3. **Timeout**: Increase timeout in config or via `CCS_GEMINI_TIMEOUT=90`
4. **Skip Gemini**: Set `CCS_GEMINI_SKIP=1` to use MCP fallback only
That is expected. DuckDuckGo is the default zero-setup backend.
### WebSearch Not Working
### Exa, Tavily, or Brave is enabled but not ready
1. **Check config**: Ensure `websearch.enabled: true` in config
2. **Verify MCP**: Check `~/.claude/.mcp.json` exists
3. **Debug mode**: Run with `CCS_DEBUG=1 ccs gemini` for verbose output
Export the matching API key in the environment that launches CCS, then refresh status:
### MCP Server Errors
```bash
export EXA_API_KEY="your-api-key"
# or: export TAVILY_API_KEY="your-api-key"
# or: export BRAVE_API_KEY="your-api-key"
ccs config
```
1. **Network issues**: web-search-prime requires internet access
2. **npx failures**: Brave/Tavily require Node.js and npx
3. **API key issues**: Verify env vars are set correctly
### I still want Gemini/OpenCode/Grok fallback
### Existing MCP Config
Those providers remain supported, but they are no longer the primary path. Enable them explicitly in `config.yaml` if you want them as last-resort fallback.
CCS respects existing web search MCP configuration. If you have manually configured web search MCPs, CCS will not overwrite them.
### WebSearch returns no results
To reset:
1. Remove web search entries from `~/.claude/.mcp.json`
2. Run any CCS third-party profile to regenerate
1. Check `websearch.enabled: true`
2. Keep DuckDuckGo enabled unless you have a strong reason to disable it
3. If using Exa, Tavily, or Brave, verify the matching API key
4. Run with `CCS_DEBUG=1` for hook logs
## Security Considerations
- API keys are stored in environment variables only
- API keys stay in environment variables, not in dashboard state
- Never commit API keys to version control
- Use `.env` files with proper permissions (chmod 600)
- Dashboard settings are stored in `~/.ccs/config.yaml` (no API keys)
- Use shell profile or `.env` tooling with proper permissions
File diff suppressed because it is too large. Load diff
+3 -2
View File
@@ -1,6 +1,6 @@
{
"name": "@kaitranntt/ccs",
"version": "7.56.0",
"version": "7.56.0-dev.6",
"description": "Claude Code Switch - Instant profile switching between Claude, GLM, Kimi, and more",
"keywords": [
"cli",
@@ -27,7 +27,8 @@
"types": "dist/ccs.d.ts",
"bin": {
"ccs": "dist/ccs.js",
"ccsd": "dist/ccs.js"
"ccs-droid": "dist/bin/droid-runtime.js",
"ccsd": "dist/bin/droid-runtime.js"
},
"files": [
"dist/",
+33 -20
View File
@@ -4,36 +4,49 @@
const fs = require('fs');
const path = require('path');
function getExecutablePaths() {
const packageJsonPath = path.join(__dirname, '../package.json');
const packageJson = JSON.parse(fs.readFileSync(packageJsonPath, 'utf8'));
const binEntries = packageJson.bin || {};
const uniqueRelativePaths = [...new Set(Object.values(binEntries))];
return uniqueRelativePaths.map((relativePath) => path.join(__dirname, '..', relativePath));
}
/**
* Add shebang to dist/ccs.js and make executable
* Add shebangs to all published bin entrypoints and make them executable.
* Run after: tsc
*/
function addShebang() {
const ccsPath = path.join(__dirname, '../dist/ccs.js');
if (!fs.existsSync(ccsPath)) {
console.error('[X] dist/ccs.js not found. Run tsc first.');
const executablePaths = getExecutablePaths();
const missingPaths = executablePaths.filter((executablePath) => !fs.existsSync(executablePath));
if (missingPaths.length > 0) {
console.error(`[X] Missing built executable(s): ${missingPaths.join(', ')}. Run tsc first.`);
process.exit(1);
}
let content = fs.readFileSync(ccsPath, 'utf8');
for (const executablePath of executablePaths) {
let content = fs.readFileSync(executablePath, 'utf8');
// Add shebang if missing
if (!content.startsWith('#!/usr/bin/env node')) {
content = '#!/usr/bin/env node\n' + content;
fs.writeFileSync(ccsPath, content);
console.log('[OK] Shebang added to dist/ccs.js');
}
if (!content.startsWith('#!/usr/bin/env node')) {
content = '#!/usr/bin/env node\n' + content;
fs.writeFileSync(executablePath, content);
console.log(`[OK] Shebang added to ${path.relative(path.join(__dirname, '..'), executablePath)}`);
}
// Make executable (Unix-like systems)
if (process.platform !== 'win32') {
try {
fs.chmodSync(ccsPath, 0o755);
console.log('[OK] dist/ccs.js is now executable');
} catch (err) {
console.warn('[!] Could not chmod dist/ccs.js:', err.message);
if (process.platform !== 'win32') {
try {
fs.chmodSync(executablePath, 0o755);
console.log(
`[OK] ${path.relative(path.join(__dirname, '..'), executablePath)} is now executable`
);
} catch (err) {
console.warn(
`[!] Could not chmod ${path.relative(path.join(__dirname, '..'), executablePath)}: ${err.message}`
);
}
}
}
}
addShebang();
addShebang();
+102 -50
View File
@@ -26,8 +26,8 @@ log_info() { echo -e "${GREEN}[i]${NC} $1"; }
log_warn() { echo -e "${YELLOW}[!]${NC} $1"; }
log_error() { echo -e "${RED}[X]${NC} $1"; }
# Ensure we have the latest tags
git fetch --tags origin main
# Ensure we have the latest tags and branch refs
git fetch --tags origin main dev
# Get latest stable tag from main (exclude prereleases like -dev, -beta, -rc)
# Match only clean semver tags: vX.Y.Z
@@ -39,58 +39,100 @@ if [ -z "$STABLE_TAG" ]; then
fi
STABLE=${STABLE_TAG#v}
CURRENT_VERSION=$(jq -r '.version' package.json)
HEAD_SUBJECT=$(git log -1 --pretty=%s 2>/dev/null || echo "")
DEV_VERSION_REGEX="^${STABLE//./\\.}-dev\\.[0-9]+$"
PREVIOUS_DEV_TAG=""
RECOVERY_MODE=false
log_info "Current stable version: ${STABLE}"
# Find latest dev tag for this stable version
LATEST_DEV=$(git tag -l "v${STABLE}-dev.*" --sort=-v:refname | head -1 || echo "")
if [[ "$CURRENT_VERSION" =~ $DEV_VERSION_REGEX ]] && [[ "$HEAD_SUBJECT" == "chore(release): ${CURRENT_VERSION} [skip ci]" ]]; then
VERSION="$CURRENT_VERSION"
CURRENT_TAG="v${VERSION}"
PREVIOUS_DEV_TAG=$(git tag -l "v${STABLE}-dev.*" --sort=-v:refname | grep -vx "$CURRENT_TAG" | head -1 || echo "")
RECOVERY_MODE=true
log_warn "Recovery mode for ${VERSION}"
# Calculate next dev number
if [ -z "$LATEST_DEV" ]; then
DEV_NUM=1
log_info "No existing dev tags for ${STABLE}, starting at dev.1"
if git rev-parse "${CURRENT_TAG}" >/dev/null 2>&1; then
TAG_COMMIT=$(git rev-parse "${CURRENT_TAG}^{commit}")
HEAD_COMMIT=$(git rev-parse HEAD)
if [[ "$TAG_COMMIT" != "$HEAD_COMMIT" ]]; then
log_error "Tag ${CURRENT_TAG} exists but does not point to HEAD"
exit 1
fi
log_info "Reusing existing tag ${CURRENT_TAG}"
else
git tag "${CURRENT_TAG}"
log_warn "Recreated missing tag ${CURRENT_TAG} on release commit"
fi
else
DEV_NUM=$(echo "$LATEST_DEV" | sed 's/.*dev\.\([0-9]*\)/\1/')
DEV_NUM=$((DEV_NUM + 1))
log_info "Latest dev tag: ${LATEST_DEV}, incrementing to dev.${DEV_NUM}"
# Find latest dev tag for this stable version
LATEST_DEV=$(git tag -l "v${STABLE}-dev.*" --sort=-v:refname | head -1 || echo "")
PREVIOUS_DEV_TAG="$LATEST_DEV"
# Calculate next dev number
if [ -z "$LATEST_DEV" ]; then
DEV_NUM=1
log_info "No existing dev tags for ${STABLE}, starting at dev.1"
else
DEV_NUM=$(echo "$LATEST_DEV" | sed 's/.*dev\.\([0-9]*\)/\1/')
DEV_NUM=$((DEV_NUM + 1))
log_info "Latest dev tag: ${LATEST_DEV}, incrementing to dev.${DEV_NUM}"
fi
VERSION="${STABLE}-dev.${DEV_NUM}"
CURRENT_TAG="v${VERSION}"
log_info "New version: ${VERSION}"
# Check if tag already exists (safety check)
if git rev-parse "${CURRENT_TAG}" >/dev/null 2>&1; then
log_error "Tag ${CURRENT_TAG} already exists!"
exit 1
fi
# Update package.json
npm version "$VERSION" --no-git-tag-version
log_info "Updated package.json to ${VERSION}"
# Configure git for GitHub Actions
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
# Commit version change
git add package.json
git commit -m "chore(release): ${VERSION} [skip ci]"
log_info "Created release commit"
# Create tag
git tag "${CURRENT_TAG}"
log_info "Created tag ${CURRENT_TAG}"
fi
VERSION="${STABLE}-dev.${DEV_NUM}"
log_info "New version: ${VERSION}"
# Check if tag already exists (safety check)
if git rev-parse "v${VERSION}" >/dev/null 2>&1; then
log_error "Tag v${VERSION} already exists!"
exit 1
PACKAGE_NAME=$(jq -r '.name' package.json)
if npm view "${PACKAGE_NAME}@${VERSION}" version >/dev/null 2>&1; then
log_info "npm already has ${PACKAGE_NAME}@${VERSION}, skipping publish"
else
npm publish --tag dev
log_info "Published to npm with @dev tag"
fi
# Update package.json
npm version "$VERSION" --no-git-tag-version
log_info "Updated package.json to ${VERSION}"
if git merge-base --is-ancestor HEAD origin/dev >/dev/null 2>&1; then
log_info "origin/dev already contains release commit"
else
git push origin HEAD:dev
log_info "Pushed release commit to origin/dev"
fi
# Configure git for GitHub Actions
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
# Commit version change
git add package.json
git commit -m "chore(release): ${VERSION} [skip ci]"
log_info "Created release commit"
# Create tag
git tag "v${VERSION}"
log_info "Created tag v${VERSION}"
# Push commit and tag
git push origin dev
git push origin "v${VERSION}"
log_info "Pushed to origin"
# Publish to npm with dev tag
npm publish --tag dev
log_info "Published to npm with @dev tag"
if git ls-remote --exit-code --tags origin "refs/tags/${CURRENT_TAG}" >/dev/null 2>&1; then
log_info "Remote tag ${CURRENT_TAG} already exists"
else
git push origin "${CURRENT_TAG}"
log_info "Pushed tag ${CURRENT_TAG}"
fi
# Generate release notes from commits since last tag
PREV_TAG=$(git tag -l "v*" --sort=-v:refname | sed -n '2p' || echo "")
PREV_TAG="${PREVIOUS_DEV_TAG:-$STABLE_TAG}"
if [ -n "$PREV_TAG" ]; then
# Get commits between previous tag and the one before our release commit
NOTES=$(git log --pretty=format:"- %s" "${PREV_TAG}..HEAD~1" 2>/dev/null | grep -v "chore(release):" | head -15 || echo "- Dev release")
@@ -99,12 +141,16 @@ else
fi
# Create GitHub prerelease
gh release create "v${VERSION}" \
--title "v${VERSION}" \
--notes "${NOTES}" \
--prerelease
if gh release view "${CURRENT_TAG}" >/dev/null 2>&1; then
log_info "GitHub prerelease ${CURRENT_TAG} already exists"
else
gh release create "${CURRENT_TAG}" \
--title "${CURRENT_TAG}" \
--notes "${NOTES}" \
--prerelease
log_info "Created GitHub prerelease"
log_info "Created GitHub prerelease"
fi
# Save release info for Discord notification
# This file is read by send-discord-release.cjs for dev releases
@@ -117,7 +163,13 @@ EOF
log_info "Saved release info for Discord notification"
# Output for GitHub Actions
echo "version=${VERSION}" >> "${GITHUB_OUTPUT:-/dev/null}"
echo "released=true" >> "${GITHUB_OUTPUT:-/dev/null}"
{
echo "current_tag=${CURRENT_TAG}"
echo "previous_dev_tag=${PREVIOUS_DEV_TAG}"
echo "recovery_mode=${RECOVERY_MODE}"
echo "released=true"
echo "stable_tag=${STABLE_TAG}"
echo "version=${VERSION}"
} >> "${GITHUB_OUTPUT:-/dev/null}"
log_info "Dev release ${VERSION} complete!"
+11 -15
View File
@@ -12,11 +12,7 @@ import { getCcsDir, getConfigPath, loadConfigSafe } from '../../utils/config-man
import { ensureProfileHooks } from '../../utils/websearch/profile-hook-injector';
import { isSensitiveKey } from '../../utils/sensitive-keys';
import { isReservedName } from '../../config/reserved-names';
import {
isUnifiedMode,
loadOrCreateUnifiedConfig,
saveUnifiedConfig,
} from '../../config/unified-config-loader';
import { isUnifiedMode, mutateUnifiedConfig } from '../../config/unified-config-loader';
import { validateApiName } from './validation-service';
import { listApiProfiles } from './profile-reader';
import { validateApiProfileSettingsPayload } from './profile-lifecycle-validation';
@@ -64,17 +60,17 @@ function writeJsonObjectAtomically(filePath: string, value: unknown): void {
function registerApiProfileInConfig(name: string, target: TargetType, force = false): void {
if (isUnifiedMode()) {
const config = loadOrCreateUnifiedConfig();
if (config.profiles[name] && !force) {
throw new Error(`API profile already exists: ${name}`);
}
mutateUnifiedConfig((config) => {
if (config.profiles[name] && !force) {
throw new Error(`API profile already exists: ${name}`);
}
config.profiles[name] = {
type: 'api',
settings: `~/.ccs/${name}${SETTINGS_FILE_SUFFIX}`,
...(target !== 'claude' && { target }),
};
saveUnifiedConfig(config);
config.profiles[name] = {
type: 'api',
settings: `~/.ccs/${name}${SETTINGS_FILE_SUFFIX}`,
...(target !== 'claude' && { target }),
};
});
return;
}
+33 -41
View File
@@ -7,11 +7,7 @@ import * as path from 'path';
import { getCcsDir, getConfigPath, loadConfigSafe } from '../../utils/config-manager';
import { expandPath } from '../../utils/helpers';
import { validateApiName } from './validation-service';
import {
loadOrCreateUnifiedConfig,
saveUnifiedConfig,
isUnifiedMode,
} from '../../config/unified-config-loader';
import { mutateUnifiedConfig, isUnifiedMode } from '../../config/unified-config-loader';
import { ensureProfileHooks } from '../../utils/websearch/profile-hook-injector';
import type { TargetType } from '../../targets/target-adapter';
import { resolveDroidProvider } from '../../targets/droid-provider';
@@ -198,13 +194,13 @@ function createApiProfileUnified(
// Inject WebSearch hooks into profile settings
ensureProfileHooks(name);
const config = loadOrCreateUnifiedConfig();
config.profiles[name] = {
type: 'api',
settings: `~/.ccs/${settingsFile}`,
...(target !== 'claude' && { target }),
};
saveUnifiedConfig(config);
mutateUnifiedConfig((config) => {
config.profiles[name] = {
type: 'api',
settings: `~/.ccs/${settingsFile}`,
...(target !== 'claude' && { target }),
};
});
}
/** Create a new API profile */
@@ -308,17 +304,17 @@ export function updateApiProfileTarget(
): UpdateApiProfileTargetResult {
try {
if (isUnifiedMode()) {
const config = loadOrCreateUnifiedConfig();
if (!config.profiles[name]) {
return { success: false, error: `API profile not found: ${name}` };
}
mutateUnifiedConfig((config) => {
if (!config.profiles[name]) {
throw new Error(`API profile not found: ${name}`);
}
if (target === 'claude') {
delete config.profiles[name].target;
} else {
config.profiles[name].target = target;
}
saveUnifiedConfig(config);
if (target === 'claude') {
delete config.profiles[name].target;
} else {
config.profiles[name].target = target;
}
});
return { success: true, target };
}
@@ -357,30 +353,26 @@ export function updateApiProfileTarget(
/** Remove API profile from unified config */
function removeApiProfileUnified(name: string): void {
const config = loadOrCreateUnifiedConfig();
const profile = config.profiles[name];
mutateUnifiedConfig((config) => {
const profile = config.profiles[name];
if (!profile) {
throw new Error(`API profile not found: ${name}`);
}
// Delete the settings file if it exists.
// Uses expandPath() for cross-platform path handling.
if (profile.settings) {
const settingsPath = expandPath(profile.settings);
if (fs.existsSync(settingsPath)) {
fs.unlinkSync(settingsPath);
if (!profile) {
throw new Error(`API profile not found: ${name}`);
}
}
delete config.profiles[name];
if (profile.settings) {
const settingsPath = expandPath(profile.settings);
if (fs.existsSync(settingsPath)) {
fs.unlinkSync(settingsPath);
}
}
// Clear default if it was the deleted profile
if (config.default === name) {
config.default = undefined;
}
delete config.profiles[name];
saveUnifiedConfig(config);
if (config.default === name) {
config.default = undefined;
}
});
}
/** Remove API profile from legacy config */
+48 -50
View File
@@ -3,7 +3,7 @@ import * as path from 'path';
import { ProfileMetadata } from '../types';
import {
loadOrCreateUnifiedConfig,
saveUnifiedConfig,
mutateUnifiedConfig,
isUnifiedMode,
} from '../config/unified-config-loader';
import type { AccountConfig } from '../config/unified-config-types';
@@ -313,74 +313,72 @@ export class ProfileRegistry {
* Create account in unified config (config.yaml)
*/
createAccountUnified(name: string, metadata: CreateMetadata = {}): void {
const config = loadOrCreateUnifiedConfig();
if (config.accounts[name]) {
throw new Error(`Account already exists: ${name}`);
}
config.accounts[name] = this.normalizeUnifiedAccountConfig({
created: new Date().toISOString(),
last_used: null,
context_mode: metadata.context_mode,
context_group: metadata.context_group,
continuity_mode: metadata.continuity_mode,
bare: metadata.bare,
mutateUnifiedConfig((config) => {
if (config.accounts[name]) {
throw new Error(`Account already exists: ${name}`);
}
config.accounts[name] = this.normalizeUnifiedAccountConfig({
created: new Date().toISOString(),
last_used: null,
context_mode: metadata.context_mode,
context_group: metadata.context_group,
continuity_mode: metadata.continuity_mode,
bare: metadata.bare,
});
});
saveUnifiedConfig(config);
}
/**
* Update account metadata in unified config
*/
updateAccountUnified(name: string, updates: Partial<AccountConfig>): void {
const config = loadOrCreateUnifiedConfig();
if (!config.accounts[name]) {
throw new Error(`Account not found: ${name}`);
}
config.accounts[name] = this.normalizeUnifiedAccountConfig({
...config.accounts[name],
...updates,
mutateUnifiedConfig((config) => {
if (!config.accounts[name]) {
throw new Error(`Account not found: ${name}`);
}
config.accounts[name] = this.normalizeUnifiedAccountConfig({
...config.accounts[name],
...updates,
});
});
saveUnifiedConfig(config);
}
/**
* Remove account from unified config
*/
removeAccountUnified(name: string): void {
const config = loadOrCreateUnifiedConfig();
if (!config.accounts[name]) {
throw new Error(`Account not found: ${name}`);
}
delete config.accounts[name];
// Clear default if it was the deleted account
if (config.default === name) {
config.default = undefined;
}
saveUnifiedConfig(config);
mutateUnifiedConfig((config) => {
if (!config.accounts[name]) {
throw new Error(`Account not found: ${name}`);
}
delete config.accounts[name];
if (config.default === name) {
config.default = undefined;
}
});
}
/**
* Set default profile in unified config
*/
setDefaultUnified(name: string): void {
const config = loadOrCreateUnifiedConfig();
// Check if exists in accounts, profiles, or cliproxy variants
const exists =
config.accounts[name] || config.profiles[name] || config.cliproxy?.variants?.[name];
if (!exists) {
throw new Error(`Profile not found: ${name}`);
}
config.default = name;
saveUnifiedConfig(config);
mutateUnifiedConfig((config) => {
const exists =
config.accounts[name] || config.profiles[name] || config.cliproxy?.variants?.[name];
if (!exists) {
throw new Error(`Profile not found: ${name}`);
}
config.default = name;
});
}
/**
* Clear default profile in unified config (restore original CCS behavior)
*/
clearDefaultUnified(): void {
const config = loadOrCreateUnifiedConfig();
config.default = undefined;
saveUnifiedConfig(config);
mutateUnifiedConfig((config) => {
config.default = undefined;
});
}
/**
@@ -418,13 +416,13 @@ export class ProfileRegistry {
* Update account last_used in unified config
*/
touchAccountUnified(name: string): void {
const config = loadOrCreateUnifiedConfig();
if (!config.accounts[name]) {
throw new Error(`Account not found: ${name}`);
}
config.accounts[name].last_used = new Date().toISOString();
config.accounts[name] = this.normalizeUnifiedAccountConfig(config.accounts[name]);
saveUnifiedConfig(config);
mutateUnifiedConfig((config) => {
if (!config.accounts[name]) {
throw new Error(`Account not found: ${name}`);
}
config.accounts[name].last_used = new Date().toISOString();
config.accounts[name] = this.normalizeUnifiedAccountConfig(config.accounts[name]);
});
}
// ==========================================
+2
View File
@@ -0,0 +1,2 @@
process.env.CCS_INTERNAL_ENTRY_TARGET = 'droid';
require('../ccs');
+3
View File
@@ -28,8 +28,11 @@ export {
getPausedDir,
getAccountTokenPath,
extractAccountIdFromTokenFile,
deriveNoEmailProviderAccountId,
generateNickname,
validateNickname,
hasAccountNameConflict,
findAccountNameMatch,
tokenFileExists,
loadAccountsRegistry,
saveAccountsRegistry,
+3
View File
@@ -21,8 +21,11 @@ export {
getPausedDir,
getAccountTokenPath,
extractAccountIdFromTokenFile,
deriveNoEmailProviderAccountId,
generateNickname,
validateNickname,
hasAccountNameConflict,
findAccountNameMatch,
tokenFileExists,
} from './token-file-ops';
+5 -7
View File
@@ -6,7 +6,7 @@
import { CLIProxyProvider } from '../types';
import { CLIPROXY_PROFILES } from '../../auth/profile-detector';
import { AccountInfo } from './types';
import { loadAccountsRegistry, syncRegistryWithTokenFiles, saveAccountsRegistry } from './registry';
import { loadAccountsRegistry, syncRegistryWithTokenFiles } from './registry';
/**
* Get all accounts for a provider
@@ -14,10 +14,8 @@ import { loadAccountsRegistry, syncRegistryWithTokenFiles, saveAccountsRegistry
export function getProviderAccounts(provider: CLIProxyProvider): AccountInfo[] {
const registry = loadAccountsRegistry();
// Sync with actual token files (removes stale entries)
if (syncRegistryWithTokenFiles(registry)) {
saveAccountsRegistry(registry);
}
// Sync in-memory view with actual token files without mutating disk on read.
syncRegistryWithTokenFiles(registry);
const providerAccounts = registry.providers[provider];
@@ -67,12 +65,12 @@ export function findAccountByQuery(provider: CLIProxyProvider, query: string): A
if (exactMatch) return exactMatch;
// Partial match on nickname or email prefix
const partialMatch = accounts.find(
const partialMatches = accounts.filter(
(a) =>
a.nickname?.toLowerCase().startsWith(lowerQuery) ||
a.email?.toLowerCase().startsWith(lowerQuery)
);
return partialMatch || null;
return partialMatches.length === 1 ? partialMatches[0] : null;
}
/**
+321 -348
View File
@@ -5,15 +5,18 @@
import * as fs from 'fs';
import * as path from 'path';
import * as lockfile from 'proper-lockfile';
import { CLIProxyProvider } from '../types';
import { PROVIDER_TYPE_VALUES } from '../auth/auth-types';
import { getAuthDir } from '../config-generator';
import { getAuthDir, getCliproxyDir } from '../config-generator';
import { AccountsRegistry, AccountInfo, PROVIDERS_WITHOUT_EMAIL } from './types';
import {
getAccountsRegistryPath,
getPausedDir,
extractAccountIdFromTokenFile,
deriveNoEmailProviderAccountId,
generateNickname,
hasAccountNameConflict,
validateNickname,
moveTokenToPaused,
moveTokenFromPaused,
@@ -21,37 +24,65 @@ import {
} from './token-file-ops';
/** Default registry structure */
const DEFAULT_REGISTRY: AccountsRegistry = {
version: 1,
providers: {},
};
function createDefaultRegistry(): AccountsRegistry {
return {
version: 1,
providers: {},
};
}
/**
* Load accounts registry
*/
export function loadAccountsRegistry(): AccountsRegistry {
const registryPath = getAccountsRegistryPath();
function withAccountsRegistryLock<T>(callback: () => T): T {
const lockTarget = getCliproxyDir();
let release: (() => void) | undefined;
if (!fs.existsSync(registryPath)) {
return { ...DEFAULT_REGISTRY };
if (!fs.existsSync(lockTarget)) {
fs.mkdirSync(lockTarget, { recursive: true, mode: 0o700 });
}
try {
const content = fs.readFileSync(registryPath, 'utf-8');
const data = JSON.parse(content);
return {
version: data.version || 1,
providers: data.providers || {},
};
} catch {
return { ...DEFAULT_REGISTRY };
release = lockfile.lockSync(lockTarget, { stale: 10000 }) as () => void;
return callback();
} finally {
if (release) {
try {
release();
} catch {
// Best-effort release
}
}
}
}
/**
* Save accounts registry
*/
export function saveAccountsRegistry(registry: AccountsRegistry): void {
function readAccountsRegistryFromDisk(): AccountsRegistry {
const registryPath = getAccountsRegistryPath();
if (!fs.existsSync(registryPath)) {
return createDefaultRegistry();
}
const content = fs.readFileSync(registryPath, 'utf-8');
let data: unknown;
try {
data = JSON.parse(content);
} catch (error) {
throw new Error(`Accounts registry is corrupted: ${(error as Error).message}`);
}
if (!data || typeof data !== 'object') {
throw new Error('Accounts registry is corrupted: expected object');
}
const parsed = data as { version?: unknown; providers?: unknown };
return {
version: typeof parsed.version === 'number' ? parsed.version : 1,
providers:
parsed.providers && typeof parsed.providers === 'object'
? (parsed.providers as AccountsRegistry['providers'])
: {},
};
}
function writeAccountsRegistryToDisk(registry: AccountsRegistry): void {
const registryPath = getAccountsRegistryPath();
const dir = path.dirname(registryPath);
@@ -59,9 +90,39 @@ export function saveAccountsRegistry(registry: AccountsRegistry): void {
fs.mkdirSync(dir, { recursive: true, mode: 0o700 });
}
fs.writeFileSync(registryPath, JSON.stringify(registry, null, 2) + '\n', {
const tempPath = `${registryPath}.tmp.${process.pid}`;
fs.writeFileSync(tempPath, JSON.stringify(registry, null, 2) + '\n', {
mode: 0o600,
});
fs.renameSync(tempPath, registryPath);
}
function mutateAccountsRegistry<T>(mutator: (registry: AccountsRegistry) => T): T {
return withAccountsRegistryLock(() => {
const registry = readAccountsRegistryFromDisk();
const initialSnapshot = JSON.stringify(registry);
const result = mutator(registry);
if (JSON.stringify(registry) !== initialSnapshot) {
writeAccountsRegistryToDisk(registry);
}
return result;
});
}
/**
* Load accounts registry
*/
export function loadAccountsRegistry(): AccountsRegistry {
return readAccountsRegistryFromDisk();
}
/**
* Save accounts registry
*/
export function saveAccountsRegistry(registry: AccountsRegistry): void {
withAccountsRegistryLock(() => {
writeAccountsRegistryToDisk(registry);
});
}
/**
@@ -115,8 +176,8 @@ export function syncRegistryWithTokenFiles(registry: AccountsRegistry): boolean
* Called after successful OAuth to record the account
*
* For providers without email (kiro, ghcp):
* - nickname is REQUIRED and used as accountId
* - Uniqueness is enforced to prevent overwriting
* - internal accountId is derived from token metadata
* - nickname is optional metadata
*
* For providers with email:
* - email is used as accountId
@@ -129,110 +190,103 @@ export function registerAccount(
nickname?: string,
projectId?: string
): AccountInfo {
const registry = loadAccountsRegistry();
return mutateAccountsRegistry((registry) => {
syncRegistryWithTokenFiles(registry);
// Initialize provider section if needed
if (!registry.providers[provider]) {
registry.providers[provider] = {
default: 'default',
accounts: {},
};
}
const providerAccounts = registry.providers[provider];
if (!providerAccounts) {
throw new Error('Failed to initialize provider accounts');
}
// Determine account ID based on provider type
let accountId: string;
let accountNickname: string;
if (PROVIDERS_WITHOUT_EMAIL.includes(provider)) {
// For kiro/ghcp: nickname is REQUIRED and used as accountId
if (!nickname || nickname === 'default') {
throw new Error(
`Nickname is required when adding ${provider} accounts. ` +
`Use --nickname <name> or provide a nickname in the UI.`
);
if (!registry.providers[provider]) {
registry.providers[provider] = {
default: 'default',
accounts: {},
};
}
// Validate nickname format
const validationError = validateNickname(nickname);
if (validationError) {
throw new Error(validationError);
const providerAccounts = registry.providers[provider];
if (!providerAccounts) {
throw new Error('Failed to initialize provider accounts');
}
// Check uniqueness
for (const [existingId, _account] of Object.entries(providerAccounts.accounts)) {
if (existingId.toLowerCase() === nickname.toLowerCase()) {
throw new Error(
`An account with nickname "${nickname}" already exists for ${provider}. ` +
`Choose a different nickname.`
);
let accountId: string;
let accountNickname: string;
if (PROVIDERS_WITHOUT_EMAIL.includes(provider)) {
accountId = email
? extractAccountIdFromTokenFile(tokenFile, email)
: deriveNoEmailProviderAccountId(provider, tokenFile, providerAccounts.accounts);
const existingAccount = providerAccounts.accounts[accountId];
if (nickname) {
const validationError = validateNickname(nickname);
if (validationError) {
throw new Error(validationError);
}
const existingAccounts = Object.entries(providerAccounts.accounts).map(([id, account]) => ({
id,
nickname: account.nickname,
}));
if (hasAccountNameConflict(existingAccounts, nickname, accountId)) {
throw new Error(
`An account with nickname "${nickname}" already exists for ${provider}. ` +
`Choose a different nickname.`
);
}
}
accountNickname =
nickname || existingAccount?.nickname || (email ? generateNickname(email) : accountId);
} else {
accountId = extractAccountIdFromTokenFile(tokenFile, email);
accountNickname = nickname || generateNickname(email);
}
accountId = nickname;
accountNickname = nickname;
} else {
// For other providers: use email as accountId, fallback to filename extraction
accountId = extractAccountIdFromTokenFile(tokenFile, email);
accountNickname = nickname || generateNickname(email);
}
const isFirstAccount = Object.keys(providerAccounts.accounts).length === 0;
const existingAccount = providerAccounts.accounts[accountId];
const accountMeta: Omit<AccountInfo, 'id' | 'provider' | 'isDefault'> = {
email,
nickname: accountNickname,
tokenFile,
createdAt: existingAccount?.createdAt || new Date().toISOString(),
lastUsedAt: new Date().toISOString(),
};
const isFirstAccount = Object.keys(providerAccounts.accounts).length === 0;
if (provider === 'agy' && projectId) {
accountMeta.projectId = projectId;
}
// Create or update account
const accountMeta: Omit<AccountInfo, 'id' | 'provider' | 'isDefault'> = {
email,
nickname: accountNickname,
tokenFile,
createdAt: new Date().toISOString(),
lastUsedAt: new Date().toISOString(),
};
providerAccounts.accounts[accountId] = accountMeta;
// Include projectId for Antigravity accounts
if (provider === 'agy' && projectId) {
accountMeta.projectId = projectId;
}
if (isFirstAccount) {
providerAccounts.default = accountId;
}
providerAccounts.accounts[accountId] = accountMeta;
// Set as default if first account
if (isFirstAccount) {
providerAccounts.default = accountId;
}
saveAccountsRegistry(registry);
return {
id: accountId,
provider,
isDefault: accountId === providerAccounts.default,
email,
nickname: accountNickname,
tokenFile,
createdAt: providerAccounts.accounts[accountId].createdAt,
lastUsedAt: providerAccounts.accounts[accountId].lastUsedAt,
projectId: providerAccounts.accounts[accountId].projectId,
};
return {
id: accountId,
provider,
isDefault: accountId === providerAccounts.default,
email,
nickname: accountNickname,
tokenFile,
createdAt: providerAccounts.accounts[accountId].createdAt,
lastUsedAt: providerAccounts.accounts[accountId].lastUsedAt,
projectId: providerAccounts.accounts[accountId].projectId,
};
});
}
/**
* Set default account for a provider
*/
export function setDefaultAccount(provider: CLIProxyProvider, accountId: string): boolean {
const registry = loadAccountsRegistry();
const providerAccounts = registry.providers[provider];
return mutateAccountsRegistry((registry) => {
const providerAccounts = registry.providers[provider];
if (!providerAccounts || !providerAccounts.accounts[accountId]) {
return false;
}
if (!providerAccounts || !providerAccounts.accounts[accountId]) {
return false;
}
providerAccounts.default = accountId;
saveAccountsRegistry(registry);
return true;
providerAccounts.default = accountId;
return true;
});
}
/**
@@ -240,27 +294,26 @@ export function setDefaultAccount(provider: CLIProxyProvider, accountId: string)
* Moves token file to paused/ subdir so CLIProxyAPI won't discover it
*/
export function pauseAccount(provider: CLIProxyProvider, accountId: string): boolean {
const registry = loadAccountsRegistry();
const providerAccounts = registry.providers[provider];
return mutateAccountsRegistry((registry) => {
const providerAccounts = registry.providers[provider];
if (!providerAccounts?.accounts[accountId]) {
return false;
}
if (!providerAccounts?.accounts[accountId]) {
return false;
}
const accountMeta = providerAccounts.accounts[accountId];
const accountMeta = providerAccounts.accounts[accountId];
if (accountMeta.paused) {
return true;
}
// Skip if already paused (idempotent)
if (accountMeta.paused) {
if (!moveTokenToPaused(accountMeta.tokenFile)) {
return false;
}
providerAccounts.accounts[accountId].paused = true;
providerAccounts.accounts[accountId].pausedAt = new Date().toISOString();
return true;
}
// Move token file to paused directory (if it exists in auth dir)
moveTokenToPaused(accountMeta.tokenFile);
providerAccounts.accounts[accountId].paused = true;
providerAccounts.accounts[accountId].pausedAt = new Date().toISOString();
saveAccountsRegistry(registry);
return true;
});
}
/**
@@ -268,55 +321,53 @@ export function pauseAccount(provider: CLIProxyProvider, accountId: string): boo
* Moves token file back from paused/ to auth/ so CLIProxyAPI can discover it
*/
export function resumeAccount(provider: CLIProxyProvider, accountId: string): boolean {
const registry = loadAccountsRegistry();
const providerAccounts = registry.providers[provider];
return mutateAccountsRegistry((registry) => {
const providerAccounts = registry.providers[provider];
if (!providerAccounts?.accounts[accountId]) {
return false;
}
if (!providerAccounts?.accounts[accountId]) {
return false;
}
const accountMeta = providerAccounts.accounts[accountId];
const accountMeta = providerAccounts.accounts[accountId];
if (!accountMeta.paused) {
return true;
}
// Skip if already active (idempotent)
if (!accountMeta.paused) {
if (!moveTokenFromPaused(accountMeta.tokenFile)) {
return false;
}
providerAccounts.accounts[accountId].paused = false;
providerAccounts.accounts[accountId].pausedAt = undefined;
return true;
}
// Move token file back from paused directory (if it exists in paused dir)
moveTokenFromPaused(accountMeta.tokenFile);
providerAccounts.accounts[accountId].paused = false;
providerAccounts.accounts[accountId].pausedAt = undefined;
saveAccountsRegistry(registry);
return true;
});
}
/**
* Remove an account
*/
export function removeAccount(provider: CLIProxyProvider, accountId: string): boolean {
const registry = loadAccountsRegistry();
const providerAccounts = registry.providers[provider];
return mutateAccountsRegistry((registry) => {
const providerAccounts = registry.providers[provider];
if (!providerAccounts || !providerAccounts.accounts[accountId]) {
return false;
}
if (!providerAccounts || !providerAccounts.accounts[accountId]) {
return false;
}
// Delete token file from both auth and paused directories
const tokenFile = providerAccounts.accounts[accountId].tokenFile;
deleteTokenFile(tokenFile);
const tokenFile = providerAccounts.accounts[accountId].tokenFile;
if (!deleteTokenFile(tokenFile)) {
return false;
}
// Remove from registry
delete providerAccounts.accounts[accountId];
delete providerAccounts.accounts[accountId];
// Update default if needed
const remainingAccounts = Object.keys(providerAccounts.accounts);
if (providerAccounts.default === accountId && remainingAccounts.length > 0) {
providerAccounts.default = remainingAccounts[0];
}
const remainingAccounts = Object.keys(providerAccounts.accounts);
if (providerAccounts.default === accountId && remainingAccounts.length > 0) {
providerAccounts.default = remainingAccounts[0];
}
saveAccountsRegistry(registry);
return true;
return true;
});
}
/**
@@ -332,36 +383,36 @@ export function renameAccount(
throw new Error(validationError);
}
const registry = loadAccountsRegistry();
const providerAccounts = registry.providers[provider];
return mutateAccountsRegistry((registry) => {
const providerAccounts = registry.providers[provider];
if (!providerAccounts?.accounts[accountId]) {
return false;
}
if (!providerAccounts?.accounts[accountId]) {
return false;
}
// Check if nickname is already used by another account
for (const [id, account] of Object.entries(providerAccounts.accounts)) {
if (id !== accountId && account.nickname?.toLowerCase() === newNickname.toLowerCase()) {
const existingAccounts = Object.entries(providerAccounts.accounts).map(([id, account]) => ({
id,
nickname: account.nickname,
}));
if (hasAccountNameConflict(existingAccounts, newNickname, accountId)) {
throw new Error(`Nickname "${newNickname}" is already used by another account`);
}
}
providerAccounts.accounts[accountId].nickname = newNickname;
saveAccountsRegistry(registry);
return true;
providerAccounts.accounts[accountId].nickname = newNickname;
return true;
});
}
/**
* Update last used timestamp for an account
*/
export function touchAccount(provider: CLIProxyProvider, accountId: string): void {
const registry = loadAccountsRegistry();
const providerAccounts = registry.providers[provider];
if (providerAccounts?.accounts[accountId]) {
providerAccounts.accounts[accountId].lastUsedAt = new Date().toISOString();
saveAccountsRegistry(registry);
}
mutateAccountsRegistry((registry) => {
const providerAccounts = registry.providers[provider];
if (providerAccounts?.accounts[accountId]) {
providerAccounts.accounts[accountId].lastUsedAt = new Date().toISOString();
}
});
}
/**
@@ -372,16 +423,16 @@ export function setAccountTier(
accountId: string,
tier: 'free' | 'pro' | 'ultra' | 'unknown'
): boolean {
const registry = loadAccountsRegistry();
const providerAccounts = registry.providers[provider];
return mutateAccountsRegistry((registry) => {
const providerAccounts = registry.providers[provider];
if (!providerAccounts?.accounts[accountId]) {
return false;
}
if (!providerAccounts?.accounts[accountId]) {
return false;
}
providerAccounts.accounts[accountId].tier = tier;
saveAccountsRegistry(registry);
return true;
providerAccounts.accounts[accountId].tier = tier;
return true;
});
}
/**
@@ -399,181 +450,103 @@ export function discoverExistingAccounts(): void {
return;
}
const registry = loadAccountsRegistry();
const files = fs.readdirSync(authDir);
mutateAccountsRegistry((registry) => {
syncRegistryWithTokenFiles(registry);
// Track whether any accounts were discovered (to avoid saving empty registry)
let discoveredCount = 0;
for (const file of files) {
if (!file.endsWith('.json')) continue;
for (const file of files) {
if (!file.endsWith('.json')) continue;
const filePath = path.join(authDir, file);
const filePath = path.join(authDir, file);
try {
const content = fs.readFileSync(filePath, 'utf-8');
const data = JSON.parse(content);
if (!data.type) continue;
try {
const content = fs.readFileSync(filePath, 'utf-8');
const data = JSON.parse(content);
// Skip if no type field
if (!data.type) continue;
// Build reverse mapping from PROVIDER_TYPE_VALUES (type value -> provider)
// e.g., "antigravity" -> "agy", "kiro" -> "kiro", "codewhisperer" -> "kiro"
const typeValue = data.type.toLowerCase();
let provider: CLIProxyProvider | undefined;
for (const [prov, typeValues] of Object.entries(PROVIDER_TYPE_VALUES)) {
if (typeValues.includes(typeValue)) {
provider = prov as CLIProxyProvider;
break;
const typeValue = data.type.toLowerCase();
let provider: CLIProxyProvider | undefined;
for (const [prov, typeValues] of Object.entries(PROVIDER_TYPE_VALUES)) {
if (typeValues.includes(typeValue)) {
provider = prov as CLIProxyProvider;
break;
}
}
}
// Skip if unknown provider type
if (!provider) {
continue;
}
// Extract email if available, fallback to filename-based ID
let email = data.email || undefined;
// Fallback: extract email from filename (e.g., "kiro-google-user@example.com.json")
if (!email && file.includes('@')) {
const match = file.match(/([^-]+@[^.]+\.[^.]+)(?=\.json$)/);
if (match) {
email = match[1];
if (!provider) {
continue;
}
}
// Initialize provider section if needed
if (!registry.providers[provider]) {
registry.providers[provider] = {
default: 'default',
accounts: {},
let email = data.email || undefined;
if (!email && file.includes('@')) {
const match = file.match(/([^-]+@[^.]+\.[^.]+)(?=\.json$)/);
if (match) {
email = match[1];
}
}
if (!registry.providers[provider]) {
registry.providers[provider] = {
default: 'default',
accounts: {},
};
}
const providerAccounts = registry.providers[provider];
if (!providerAccounts) continue;
const existingTokenFiles = Object.values(providerAccounts.accounts).map((a) => a.tokenFile);
if (existingTokenFiles.includes(file)) {
const projectIdValue =
typeof data.project_id === 'string' && data.project_id.trim()
? data.project_id.trim()
: null;
if (provider === 'agy' && projectIdValue) {
const existingEntry = Object.entries(providerAccounts.accounts).find(
([, meta]) => meta.tokenFile === file
);
if (existingEntry && existingEntry[1].projectId !== projectIdValue) {
existingEntry[1].projectId = projectIdValue;
}
}
continue;
}
const accountId =
PROVIDERS_WITHOUT_EMAIL.includes(provider) && !email
? deriveNoEmailProviderAccountId(provider, file, providerAccounts.accounts)
: extractAccountIdFromTokenFile(file, email);
if (providerAccounts.accounts[accountId]) {
continue;
}
if (Object.keys(providerAccounts.accounts).length === 0) {
providerAccounts.default = accountId;
}
const stats = fs.statSync(filePath);
const lastModified = stats.mtime || stats.birthtime || new Date();
const accountMeta: Omit<AccountInfo, 'id' | 'provider' | 'isDefault'> = {
email,
nickname: email ? generateNickname(email) : accountId,
tokenFile: file,
createdAt: stats.birthtime?.toISOString() || new Date().toISOString(),
lastUsedAt: lastModified.toISOString(),
};
}
const providerAccounts = registry.providers[provider];
if (!providerAccounts) continue;
// Skip if token file already registered (under any accountId)
const existingTokenFiles = Object.values(providerAccounts.accounts).map((a) => a.tokenFile);
if (existingTokenFiles.includes(file)) {
// Token file exists - check if we need to update projectId for agy accounts
const projectIdValue =
const discoveredProjectId =
typeof data.project_id === 'string' && data.project_id.trim()
? data.project_id.trim()
: null;
if (provider === 'agy' && projectIdValue) {
const existingEntry = Object.entries(providerAccounts.accounts).find(
([, meta]) => meta.tokenFile === file
);
// Update if missing or changed
if (existingEntry && existingEntry[1].projectId !== projectIdValue) {
existingEntry[1].projectId = projectIdValue;
discoveredCount++; // Count projectId updates as changes
}
if (provider === 'agy' && discoveredProjectId) {
accountMeta.projectId = discoveredProjectId;
}
providerAccounts.accounts[accountId] = accountMeta;
} catch {
continue;
}
// Determine accountId based on provider type
let accountId: string;
if (PROVIDERS_WITHOUT_EMAIL.includes(provider) && !email) {
// For kiro/ghcp without email: extract from filename or generate unique
// Pattern: kiro-github-ABC123.json -> github-ABC123
const filenameId = extractAccountIdFromTokenFile(file, undefined);
if (filenameId !== 'default') {
accountId = filenameId;
} else {
// Generate unique ID: provider + incrementing index
let index = 1;
while (providerAccounts.accounts[`${provider}-${index}`]) {
index++;
}
accountId = `${provider}-${index}`;
}
} else {
// For providers with email: use email or filename extraction
accountId = extractAccountIdFromTokenFile(file, email);
}
// Skip if account already registered
if (providerAccounts.accounts[accountId]) {
continue;
}
// Set as default if first account
if (Object.keys(providerAccounts.accounts).length === 0) {
providerAccounts.default = accountId;
}
// Get file stats for creation time
const stats = fs.statSync(filePath);
// Register account with auto-generated nickname
// Use mtime as lastUsedAt (when token was last modified = last auth/refresh)
const lastModified = stats.mtime || stats.birthtime || new Date();
const accountMeta: Omit<AccountInfo, 'id' | 'provider' | 'isDefault'> = {
email,
nickname: generateNickname(email),
tokenFile: file,
createdAt: stats.birthtime?.toISOString() || new Date().toISOString(),
lastUsedAt: lastModified.toISOString(),
};
// Read project_id for Antigravity accounts (read-only field from auth token)
const discoveredProjectId =
typeof data.project_id === 'string' && data.project_id.trim()
? data.project_id.trim()
: null;
if (provider === 'agy' && discoveredProjectId) {
accountMeta.projectId = discoveredProjectId;
}
providerAccounts.accounts[accountId] = accountMeta;
discoveredCount++;
} catch {
// Skip invalid files
continue;
}
}
// Only save if at least one account was discovered or updated
// This prevents creating accounts.json with empty provider sections
if (discoveredCount === 0) {
return;
}
// Reload-merge pattern: reduce race condition with concurrent OAuth registration
// Reload fresh registry and merge discovered accounts (fresh registry wins on conflicts)
const freshRegistry = loadAccountsRegistry();
for (const [providerName, discovered] of Object.entries(registry.providers)) {
if (!discovered) continue;
// Skip empty provider sections (no accounts discovered)
if (Object.keys(discovered.accounts).length === 0) continue;
const prov = providerName as CLIProxyProvider;
if (!freshRegistry.providers[prov]) {
freshRegistry.providers[prov] = discovered;
} else {
// Merge accounts, preferring fresh registry's existing entries but updating projectId
const freshProviderAccounts = freshRegistry.providers[prov];
if (!freshProviderAccounts) continue;
for (const [id, meta] of Object.entries(discovered.accounts)) {
if (!freshProviderAccounts.accounts[id]) {
freshProviderAccounts.accounts[id] = meta;
// Set default if none exists
if (!freshProviderAccounts.default || freshProviderAccounts.default === 'default') {
freshProviderAccounts.default = id;
}
} else if (meta.projectId && !freshProviderAccounts.accounts[id].projectId) {
// Update existing account with projectId if discovered from auth file
freshProviderAccounts.accounts[id].projectId = meta.projectId;
}
}
}
}
saveAccountsRegistry(freshRegistry);
});
}
+92 -3
View File
@@ -5,6 +5,7 @@
import * as fs from 'fs';
import * as path from 'path';
import { getCliproxyDir, getAuthDir } from '../config-generator';
import type { CLIProxyProvider } from '../types';
import { AccountInfo } from './types';
/**
@@ -92,16 +93,17 @@ export function moveTokenFromPaused(tokenFile: string): boolean {
* Delete token file from both auth and paused directories
* Idempotent
*/
export function deleteTokenFile(tokenFile: string): void {
export function deleteTokenFile(tokenFile: string): boolean {
const tokenPath = path.join(getAuthDir(), tokenFile);
const pausedPath = path.join(getPausedDir(), tokenFile);
let success = true;
// Delete from auth directory
if (fs.existsSync(tokenPath)) {
try {
fs.unlinkSync(tokenPath);
} catch {
// Ignore deletion errors
success = false;
}
}
@@ -110,9 +112,11 @@ export function deleteTokenFile(tokenFile: string): void {
try {
fs.unlinkSync(pausedPath);
} catch {
// Ignore deletion errors
success = false;
}
}
return success;
}
/**
@@ -143,6 +147,50 @@ export function extractAccountIdFromTokenFile(filename: string, email?: string):
return 'default';
}
/**
* Derive a collision-safe internal account ID for providers that may not expose email.
* Reuses the existing entry when the token file is already known, otherwise prefers the
* filename-derived ID before falling back to provider-scoped sequential IDs.
*/
export function deriveNoEmailProviderAccountId(
provider: CLIProxyProvider,
tokenFile: string,
existingAccounts: Record<string, Pick<AccountInfo, 'tokenFile' | 'nickname'>>
): string {
const existingEntries = Object.entries(existingAccounts);
const existingEntry = existingEntries.find(([, account]) => account.tokenFile === tokenFile);
if (existingEntry) {
return existingEntry[0];
}
const extractedId = extractAccountIdFromTokenFile(tokenFile);
const lowerExtractedId = extractedId.toLowerCase();
if (
extractedId !== 'default' &&
!existingEntries.some(
([existingId, account]) =>
existingId.toLowerCase() === lowerExtractedId ||
account.nickname?.toLowerCase() === lowerExtractedId
)
) {
return extractedId;
}
let index = 1;
while (
existingEntries.some(
([existingId, account]) =>
existingId.toLowerCase() === `${provider}-${index}` ||
account.nickname?.toLowerCase() === `${provider}-${index}`
)
) {
index++;
}
return `${provider}-${index}`;
}
/**
* Generate nickname from email
* Takes prefix before @ symbol, sanitizes whitespace
@@ -180,3 +228,44 @@ export function validateNickname(nickname: string): string | null {
}
return null;
}
/**
* Check whether a nickname would collide with any existing account ID or nickname.
*/
export function hasAccountNameConflict(
accounts: Array<Pick<AccountInfo, 'id' | 'nickname'>>,
candidateName: string,
excludeAccountId?: string
): boolean {
const normalizedCandidate = candidateName.toLowerCase();
const normalizedExcludedId = excludeAccountId?.toLowerCase();
return accounts.some((account) => {
if (normalizedExcludedId && account.id.toLowerCase() === normalizedExcludedId) {
return false;
}
return (
account.id.toLowerCase() === normalizedCandidate ||
account.nickname?.toLowerCase() === normalizedCandidate
);
});
}
/**
* Find the existing account that already owns the supplied id/nickname.
*/
export function findAccountNameMatch(
accounts: Array<Pick<AccountInfo, 'id' | 'nickname'>>,
candidateName: string
): Pick<AccountInfo, 'id' | 'nickname'> | null {
const normalizedCandidate = candidateName.toLowerCase();
return (
accounts.find(
(account) =>
account.id.toLowerCase() === normalizedCandidate ||
account.nickname?.toLowerCase() === normalizedCandidate
) || null
);
}
+60 -4
View File
@@ -1,3 +1,4 @@
import { randomUUID } from 'crypto';
import * as fs from 'fs';
import * as yaml from 'js-yaml';
import { configExists, getCliproxyConfigPath, regenerateConfig } from '../config-generator';
@@ -21,6 +22,41 @@ type FamilyEntriesMap = {
export type FamilyEntries<F extends AiProviderFamilyId> = FamilyEntriesMap[F];
type EntryWithOptionalId = {
id?: string;
};
function createFamilyEntryId(family: AiProviderFamilyId): string {
return `${family}-${randomUUID()}`;
}
function ensureStableEntryIds<F extends AiProviderFamilyId>(
family: F,
entries: FamilyEntries<F>
): { entries: FamilyEntries<F>; changed: boolean } {
const seenIds = new Set<string>();
let changed = false;
const normalizedEntries = entries.map((entry) => {
const rawId = (entry as EntryWithOptionalId).id;
const normalizedId = typeof rawId === 'string' && rawId.trim().length > 0 ? rawId.trim() : null;
const nextId =
normalizedId && !seenIds.has(normalizedId) ? normalizedId : createFamilyEntryId(family);
if (normalizedId !== nextId) {
changed = true;
}
seenIds.add(nextId);
return {
...entry,
id: nextId,
};
}) as FamilyEntries<F>;
return { entries: normalizedEntries, changed };
}
function ensureLocalConfigPath(): string {
if (!configExists()) {
regenerateConfig();
@@ -91,7 +127,12 @@ export async function readFamilyEntries<F extends AiProviderFamilyId>(
if (!target.isRemote) {
const config = readLocalConfig();
return (config[family] || []) as FamilyEntries<F>;
const entries = (Array.isArray(config[family]) ? config[family] : []) as FamilyEntries<F>;
const normalized = ensureStableEntryIds(family, entries);
if (normalized.changed) {
writeLocalFamilySection(family, normalized.entries);
}
return normalized.entries;
}
const client = createManagementClient({
@@ -102,17 +143,29 @@ export async function readFamilyEntries<F extends AiProviderFamilyId>(
auth_token: target.authToken,
});
return client.getSection<FamilyEntries<F>[number]>(family) as Promise<FamilyEntries<F>>;
const entries = (await client.getSection<FamilyEntries<F>[number]>(family)) as FamilyEntries<F>;
const normalized = ensureStableEntryIds(
family,
Array.isArray(entries) ? entries : ([] as unknown as FamilyEntries<F>)
);
if (normalized.changed) {
await client.putSection<FamilyEntries<F>[number]>(
family,
normalized.entries as FamilyEntries<F>[number][]
);
}
return normalized.entries;
}
export async function writeFamilyEntries<F extends AiProviderFamilyId>(
family: F,
entries: FamilyEntries<F>
): Promise<void> {
const normalized = ensureStableEntryIds(family, entries);
const target = getProxyTarget();
if (!target.isRemote) {
writeLocalFamilySection(family, entries);
writeLocalFamilySection(family, normalized.entries);
return;
}
@@ -124,5 +177,8 @@ export async function writeFamilyEntries<F extends AiProviderFamilyId>(
auth_token: target.authToken,
});
await client.putSection<FamilyEntries<F>[number]>(family, entries as FamilyEntries<F>[number][]);
await client.putSection<FamilyEntries<F>[number]>(
family,
normalized.entries as FamilyEntries<F>[number][]
);
}
+49 -10
View File
@@ -51,7 +51,7 @@ function buildApiKeyEntryView(
index: number
): AiProviderEntryView {
return {
id: `${family}:${index}`,
id: entry.id || `${family}:${index}`,
index,
label: entry.prefix?.trim() || entry['base-url']?.trim() || `Entry ${index + 1}`,
baseUrl: entry['base-url']?.trim() || undefined,
@@ -67,7 +67,7 @@ function buildApiKeyEntryView(
function buildOpenAiCompatEntryView(entry: OpenAICompatEntry, index: number): AiProviderEntryView {
return {
id: `openai-compatibility:${index}`,
id: entry.id || `openai-compatibility:${index}`,
index,
name: entry.name,
label: entry.name,
@@ -131,6 +131,7 @@ function toApiKeyEntry(
: existing?.['api-key'] || '';
return {
id: existing?.id,
'api-key': nextSecret,
'base-url': input.baseUrl?.trim() || undefined,
'proxy-url': input.proxyUrl?.trim() || undefined,
@@ -155,6 +156,7 @@ function toOpenAiCompatEntry(
: (existing?.['api-key-entries'] || []).map((entry) => entry['api-key']);
return {
id: existing?.id,
name: input.name?.trim() || existing?.name || 'connector',
'base-url': input.baseUrl?.trim() || existing?.['base-url'] || '',
headers: normalizeHeaders(input.headers),
@@ -163,8 +165,41 @@ function toOpenAiCompatEntry(
};
}
function assertIndex(entries: unknown[], index: number): void {
if (!Number.isInteger(index) || index < 0 || index >= entries.length) {
function resolveEntryIndex(entries: Array<{ id?: string }>, entryId: string): number {
const normalizedEntryId = entryId.trim();
const matchedIndex = entries.findIndex((entry) => entry.id === normalizedEntryId);
if (matchedIndex !== -1) {
return matchedIndex;
}
const legacyIndex = Number.parseInt(normalizedEntryId, 10);
if (
Number.isInteger(legacyIndex) &&
legacyIndex >= 0 &&
legacyIndex < entries.length &&
String(legacyIndex) === normalizedEntryId
) {
return legacyIndex;
}
if (normalizedEntryId.startsWith('openai-compatibility:') || normalizedEntryId.includes(':')) {
const legacySuffix = normalizedEntryId.split(':').at(-1) || '';
const legacySuffixIndex = Number.parseInt(legacySuffix, 10);
if (
Number.isInteger(legacySuffixIndex) &&
legacySuffixIndex >= 0 &&
legacySuffixIndex < entries.length &&
String(legacySuffixIndex) === legacySuffix
) {
return legacySuffixIndex;
}
}
throw new Error('Entry not found');
}
function assertEntryId(entryId: string): void {
if (!entryId.trim()) {
throw new Error('Entry not found');
}
}
@@ -208,12 +243,14 @@ export async function createAiProviderEntry(
export async function updateAiProviderEntry(
family: AiProviderFamilyId,
index: number,
entryId: string,
input: UpsertAiProviderEntryInput
): Promise<void> {
assertEntryId(entryId);
if (family === 'openai-compatibility') {
const entries = await readFamilyEntries(family);
assertIndex(entries, index);
const index = resolveEntryIndex(entries, entryId);
validateFamilyInput(family, input);
entries[index] = toOpenAiCompatEntry(input, entries[index]);
await writeFamilyEntries(family, entries);
@@ -221,7 +258,7 @@ export async function updateAiProviderEntry(
}
const entries = await readFamilyEntries(family);
assertIndex(entries, index);
const index = resolveEntryIndex(entries, entryId);
validateFamilyInput(family, input);
entries[index] = toApiKeyEntry(input, entries[index]);
await writeFamilyEntries(family, entries);
@@ -229,18 +266,20 @@ export async function updateAiProviderEntry(
export async function deleteAiProviderEntry(
family: AiProviderFamilyId,
index: number
entryId: string
): Promise<void> {
assertEntryId(entryId);
if (family === 'openai-compatibility') {
const entries = await readFamilyEntries(family);
assertIndex(entries, index);
const index = resolveEntryIndex(entries, entryId);
entries.splice(index, 1);
await writeFamilyEntries(family, entries);
return;
}
const entries = await readFamilyEntries(family);
assertIndex(entries, index);
const index = resolveEntryIndex(entries, entryId);
entries.splice(index, 1);
await writeFamilyEntries(family, entries);
}
+2
View File
@@ -14,6 +14,7 @@ export interface AiProviderModelAlias {
}
export interface AiProviderApiKeyEntry {
id?: string;
'api-key': string;
'base-url'?: string;
'proxy-url'?: string;
@@ -29,6 +30,7 @@ export interface OpenAICompatApiKeyEntry {
}
export interface OpenAICompatEntry {
id?: string;
name: string;
'base-url': string;
headers?: Record<string, string>;
+46 -56
View File
@@ -8,7 +8,7 @@
*/
import { randomBytes } from 'crypto';
import { loadOrCreateUnifiedConfig, saveUnifiedConfig } from '../config/unified-config-loader';
import { loadOrCreateUnifiedConfig, mutateUnifiedConfig } from '../config/unified-config-loader';
import { CCS_INTERNAL_API_KEY, CCS_CONTROL_PANEL_SECRET } from './config-generator';
/**
@@ -87,19 +87,17 @@ export function getEffectiveManagementSecret(): string {
* @param apiKey - New API key (or undefined to reset to default)
*/
export function setGlobalApiKey(apiKey: string | undefined): void {
const config = loadOrCreateUnifiedConfig();
mutateUnifiedConfig((config) => {
if (!config.cliproxy.auth) {
config.cliproxy.auth = {};
}
if (!config.cliproxy.auth) {
config.cliproxy.auth = {};
}
if (apiKey === undefined) {
delete config.cliproxy.auth.api_key;
} else {
config.cliproxy.auth.api_key = apiKey;
}
saveUnifiedConfig(config);
if (apiKey === undefined) {
delete config.cliproxy.auth.api_key;
} else {
config.cliproxy.auth.api_key = apiKey;
}
});
}
/**
@@ -109,19 +107,17 @@ export function setGlobalApiKey(apiKey: string | undefined): void {
* @param secret - New management secret (or undefined to reset to default)
*/
export function setGlobalManagementSecret(secret: string | undefined): void {
const config = loadOrCreateUnifiedConfig();
mutateUnifiedConfig((config) => {
if (!config.cliproxy.auth) {
config.cliproxy.auth = {};
}
if (!config.cliproxy.auth) {
config.cliproxy.auth = {};
}
if (secret === undefined) {
delete config.cliproxy.auth.management_secret;
} else {
config.cliproxy.auth.management_secret = secret;
}
saveUnifiedConfig(config);
if (secret === undefined) {
delete config.cliproxy.auth.management_secret;
} else {
config.cliproxy.auth.management_secret = secret;
}
});
}
/**
@@ -132,28 +128,26 @@ export function setGlobalManagementSecret(secret: string | undefined): void {
* @param apiKey - New API key (or undefined to remove override)
*/
export function setVariantApiKey(variantName: string, apiKey: string | undefined): void {
const config = loadOrCreateUnifiedConfig();
const variant = config.cliproxy.variants[variantName];
mutateUnifiedConfig((config) => {
const variant = config.cliproxy.variants[variantName];
if (!variant) {
throw new Error(`Variant '${variantName}' not found`);
}
if (!variant.auth) {
variant.auth = {};
}
if (apiKey === undefined) {
delete variant.auth.api_key;
// Clean up empty auth object
if (Object.keys(variant.auth).length === 0) {
delete variant.auth;
if (!variant) {
throw new Error(`Variant '${variantName}' not found`);
}
} else {
variant.auth.api_key = apiKey;
}
saveUnifiedConfig(config);
if (!variant.auth) {
variant.auth = {};
}
if (apiKey === undefined) {
delete variant.auth.api_key;
if (Object.keys(variant.auth).length === 0) {
delete variant.auth;
}
} else {
variant.auth.api_key = apiKey;
}
});
}
/**
@@ -161,20 +155,16 @@ export function setVariantApiKey(variantName: string, apiKey: string | undefined
* Removes cliproxy.auth and all variant auth overrides.
*/
export function resetAuthToDefaults(): void {
const config = loadOrCreateUnifiedConfig();
mutateUnifiedConfig((config) => {
delete config.cliproxy.auth;
// Remove global auth
delete config.cliproxy.auth;
// Remove all variant auth overrides
for (const variantName of Object.keys(config.cliproxy.variants)) {
const variant = config.cliproxy.variants[variantName];
if (variant.auth) {
delete variant.auth;
for (const variantName of Object.keys(config.cliproxy.variants)) {
const variant = config.cliproxy.variants[variantName];
if (variant.auth) {
delete variant.auth;
}
}
}
saveUnifiedConfig(config);
});
}
/**
+68 -85
View File
@@ -20,6 +20,8 @@ import {
getProviderAccounts,
getDefaultAccount,
touchAccount,
hasAccountNameConflict,
findAccountNameMatch,
PROVIDERS_WITHOUT_EMAIL,
validateNickname,
} from '../account-manager';
@@ -88,6 +90,28 @@ export async function requestPasteCallbackStart(
return (await response.json()) as PasteCallbackStartData;
}
export function getCliAuthNicknameError(
provider: CLIProxyProvider,
nickname: string | undefined,
existingAccounts: Array<Pick<AccountInfo, 'id' | 'nickname'>>,
allowExistingAccountId?: string
): string | null {
if (!nickname || !PROVIDERS_WITHOUT_EMAIL.includes(provider)) {
return null;
}
const validationError = validateNickname(nickname);
if (validationError) {
return validationError;
}
if (hasAccountNameConflict(existingAccounts, nickname, allowExistingAccountId)) {
return `Nickname "${nickname}" is already in use. Choose a different one.`;
}
return null;
}
function sleep(ms: number): Promise<void> {
return new Promise((resolve) => setTimeout(resolve, ms));
}
@@ -206,74 +230,6 @@ async function promptOAuthModeChoice(callbackPort: number | null): Promise<'past
});
}
/**
* Prompt user for account nickname (required for kiro/ghcp)
* Returns null if user cancels
*/
async function promptNickname(
provider: CLIProxyProvider,
existingAccounts: AccountInfo[]
): Promise<string | null> {
const readline = await import('readline');
const rl = readline.createInterface({
input: process.stdin,
output: process.stdout,
});
const existingNicknames = existingAccounts.map(
(a) => a.nickname?.toLowerCase() || a.id.toLowerCase()
);
console.log('');
console.log(info(`${provider} accounts require a unique nickname to distinguish them.`));
if (existingNicknames.length > 0) {
console.log(` Existing: ${existingNicknames.join(', ')}`);
}
return new Promise<string | null>((resolve) => {
let resolved = false;
// Handle Ctrl+C gracefully (only if not already resolved)
rl.on('close', () => {
if (!resolved) {
resolved = true;
resolve(null);
}
});
const askForNickname = () => {
rl.question('[?] Enter a nickname for this account: ', (answer) => {
const nickname = answer.trim();
if (!nickname) {
console.log(fail('Nickname cannot be empty'));
askForNickname();
return;
}
const validationError = validateNickname(nickname);
if (validationError) {
console.log(fail(validationError));
askForNickname();
return;
}
if (existingNicknames.includes(nickname.toLowerCase())) {
console.log(fail(`Nickname "${nickname}" is already in use. Choose a different one.`));
askForNickname();
return;
}
resolved = true;
rl.close();
resolve(nickname);
});
};
askForNickname();
});
}
/**
* Run pre-flight OAuth checks
*/
@@ -350,7 +306,8 @@ async function handlePasteCallbackMode(
oauthConfig: ProviderOAuthConfig,
verbose: boolean,
tokenDir: string,
nickname?: string
nickname?: string,
expectedAccountId?: string
): Promise<AccountInfo | null> {
// Resolve CLIProxyAPI target (local or remote based on config)
const target = getProxyTarget();
@@ -474,7 +431,13 @@ async function handlePasteCallbackMode(
}
console.log(ok('Authentication successful!'));
const account = registerAccountFromToken(provider, tokenDir, nickname);
const account = registerAccountFromToken(
provider,
tokenDir,
nickname,
verbose,
expectedAccountId
);
// Account safety: check for cross-provider conflicts
if (account?.email) {
@@ -509,7 +472,7 @@ export async function triggerOAuth(
warnOAuthBanRisk(provider);
const { verbose = false, add = false, fromUI = false, noIncognito = true } = options;
const acceptAgyRisk = options.acceptAgyRisk === true;
let { nickname } = options;
const { nickname } = options;
const resolvedKiroMethod =
provider === 'kiro' ? normalizeKiroAuthMethod(options.kiroMethod) : DEFAULT_KIRO_AUTH_METHOD;
@@ -533,21 +496,26 @@ export async function triggerOAuth(
// Check for existing accounts
const existingAccounts = getProviderAccounts(provider);
const existingNameMatch = nickname ? findAccountNameMatch(existingAccounts, nickname) : null;
const nicknameError = !fromUI
? getCliAuthNicknameError(provider, nickname, existingAccounts, existingNameMatch?.id)
: null;
if (nicknameError) {
console.log(fail(nicknameError));
return null;
}
// Handle paste-callback mode
if (options.pasteCallback) {
const tokenDir = getProviderTokenDir(provider);
return handlePasteCallbackMode(provider, oauthConfig, verbose, tokenDir, nickname);
}
// For kiro/ghcp: require nickname if not provided (CLI only, not fromUI)
if (PROVIDERS_WITHOUT_EMAIL.includes(provider) && !nickname && !fromUI) {
const promptedNickname = await promptNickname(provider, existingAccounts);
if (!promptedNickname) {
console.log(info('Cancelled'));
return null;
}
nickname = promptedNickname;
return handlePasteCallbackMode(
provider,
oauthConfig,
verbose,
tokenDir,
nickname,
existingNameMatch?.id
);
}
// Handle --import flag: skip OAuth and import from Kiro IDE directly
@@ -555,7 +523,7 @@ export async function triggerOAuth(
const tokenDir = getProviderTokenDir(provider);
const success = await importKiroToken(verbose);
if (success) {
return registerAccountFromToken(provider, tokenDir, nickname);
return registerAccountFromToken(provider, tokenDir, nickname, verbose, existingNameMatch?.id);
}
return null;
}
@@ -589,12 +557,26 @@ export async function triggerOAuth(
// Non-interactive environment (piped input) - default to paste mode
if (!process.stdin.isTTY) {
const tokenDir = getProviderTokenDir(provider);
return handlePasteCallbackMode(provider, oauthConfig, verbose, tokenDir, nickname);
return handlePasteCallbackMode(
provider,
oauthConfig,
verbose,
tokenDir,
nickname,
existingNameMatch?.id
);
}
const mode = await promptOAuthModeChoice(callbackPort);
if (mode === 'paste') {
const tokenDir = getProviderTokenDir(provider);
return handlePasteCallbackMode(provider, oauthConfig, verbose, tokenDir, nickname);
return handlePasteCallbackMode(
provider,
oauthConfig,
verbose,
tokenDir,
nickname,
existingNameMatch?.id
);
}
// mode === 'forward' continues to existing port-forwarding flow below
}
@@ -678,6 +660,7 @@ export async function triggerOAuth(
verbose,
isCLI,
nickname,
expectedAccountId: existingNameMatch?.id,
});
// Show hint for Kiro users about --no-incognito option (first-time auth only)
+8 -2
View File
@@ -50,6 +50,7 @@ export interface OAuthProcessOptions {
verbose: boolean;
isCLI: boolean;
nickname?: string;
expectedAccountId?: string;
}
/** Internal state for OAuth process */
@@ -276,6 +277,7 @@ async function handleTokenNotFound(
callbackPort: number | null,
tokenDir: string,
nickname: string | undefined,
expectedAccountId: string | undefined,
verbose: boolean,
failureReason?: string
): Promise<AccountInfo | null> {
@@ -289,7 +291,7 @@ async function handleTokenNotFound(
if (result.success) {
const providerInfo = result.provider ? ` (Provider: ${result.provider})` : '';
console.log(ok(`Imported Kiro token from IDE${providerInfo}`));
return registerAccountFromToken(provider, tokenDir, nickname);
return registerAccountFromToken(provider, tokenDir, nickname, verbose, expectedAccountId);
}
console.log(fail(`Auto-import failed: ${result.error}`));
@@ -376,6 +378,7 @@ export function executeOAuthProcess(options: OAuthProcessOptions): Promise<Accou
headless,
verbose,
nickname,
expectedAccountId,
} = options;
const log = (msg: string) => {
@@ -538,7 +541,9 @@ export function executeOAuthProcess(options: OAuthProcessOptions): Promise<Accou
deviceCodeEvents.emit('deviceCode:completed', state.sessionId);
}
resolve(registerAccountFromToken(provider, tokenDir, nickname));
resolve(
registerAccountFromToken(provider, tokenDir, nickname, verbose, expectedAccountId)
);
} else {
const failureReason = extractLikelyAuthFailureFromStderr(provider, state.stderrData);
@@ -556,6 +561,7 @@ export function executeOAuthProcess(options: OAuthProcessOptions): Promise<Accou
callbackPort,
tokenDir,
nickname,
expectedAccountId,
verbose,
failureReason || undefined
);
+77 -28
View File
@@ -11,6 +11,7 @@ import { CLIProxyProvider } from '../types';
import { CLIPROXY_PROFILES } from '../../auth/profile-detector';
import { getProviderAuthDir } from '../config-generator';
import { getProviderAccounts, getDefaultAccount } from '../account-manager';
import { deleteTokenFile, extractAccountIdFromTokenFile } from '../accounts/token-file-ops';
import {
AuthStatus,
PROVIDER_AUTH_PREFIXES,
@@ -202,50 +203,98 @@ export function registerAccountFromToken(
provider: CLIProxyProvider,
tokenDir: string,
nickname?: string,
verbose = false
verbose = false,
expectedAccountId?: string
): import('../account-manager').AccountInfo | null {
const { registerAccount, generateNickname } = require('../account-manager');
type TokenCandidate = {
file: string;
filePath: string;
email?: string;
projectId?: string;
accountId: string;
mtimeMs: number;
alreadyRegistered: boolean;
};
const { registerAccount } = require('../account-manager');
let selectedCandidate: Omit<TokenCandidate, 'mtimeMs'> | null = null;
try {
const files = fs.readdirSync(tokenDir);
const jsonFiles = files.filter((f: string) => f.endsWith('.json'));
const existingAccounts = getProviderAccounts(provider);
const candidates: TokenCandidate[] = jsonFiles
.map((file): TokenCandidate | null => {
const filePath = path.join(tokenDir, file);
if (!isTokenFileForProvider(filePath, provider)) return null;
let newestFile: string | null = null;
let newestMtime = 0;
const content = fs.readFileSync(filePath, 'utf-8');
const data = JSON.parse(content) as { email?: string; project_id?: string };
const email = data.email || undefined;
const projectId = data.project_id || undefined;
const accountId = extractAccountIdFromTokenFile(file, email);
const stats = fs.statSync(filePath);
return {
file,
filePath,
email,
projectId,
accountId,
mtimeMs: stats.mtimeMs,
alreadyRegistered: existingAccounts.some((account) => account.tokenFile === file),
};
})
.filter((candidate): candidate is TokenCandidate => candidate !== null)
.sort((a, b) => b.mtimeMs - a.mtimeMs);
for (const file of jsonFiles) {
const filePath = path.join(tokenDir, file);
if (!isTokenFileForProvider(filePath, provider)) continue;
const stats = fs.statSync(filePath);
if (stats.mtimeMs > newestMtime) {
newestMtime = stats.mtimeMs;
newestFile = file;
}
if (expectedAccountId) {
selectedCandidate =
candidates.find((candidate) => candidate.accountId === expectedAccountId) ||
candidates.find((candidate) => {
const existingAccount = existingAccounts.find(
(account) => account.id === expectedAccountId
);
return !!existingAccount && existingAccount.tokenFile === candidate.file;
}) ||
null;
} else {
selectedCandidate = candidates[0] || null;
}
if (!newestFile) {
if (!selectedCandidate) {
if (verbose && expectedAccountId) {
console.error(
`[auth] No token matched the expected account ${expectedAccountId}; refusing ambiguous registration`
);
}
return null;
}
const tokenPath = path.join(tokenDir, newestFile);
const content = fs.readFileSync(tokenPath, 'utf-8');
const data = JSON.parse(content);
const email = data.email || undefined;
const projectId = data.project_id || undefined;
const account = registerAccount(
provider,
newestFile,
email,
nickname || generateNickname(email),
projectId
selectedCandidate.file,
selectedCandidate.email,
nickname,
selectedCandidate.projectId
);
// Upload token to remote server if configured (async, don't block)
uploadTokenToRemoteAsync(tokenPath, verbose);
uploadTokenToRemoteAsync(selectedCandidate.filePath, verbose);
return account;
} catch {
} catch (error) {
const message = error instanceof Error ? error.message : String(error);
if (verbose) {
console.error(`[auth] Failed to register token-backed account: ${message}`);
}
if (selectedCandidate && !selectedCandidate.alreadyRegistered && !expectedAccountId) {
deleteTokenFile(selectedCandidate.file);
}
if (expectedAccountId && verbose) {
console.error(
`[auth] Reauthentication target ${expectedAccountId} did not resolve cleanly from the new token`
);
}
return null;
}
}
+1 -1
View File
@@ -418,7 +418,7 @@ export async function execClaudeWithCLIProxy(
const nickname = acct.nickname ? `[${acct.nickname}]` : '';
console.log(` ${nickname.padEnd(12)} ${acct.email || acct.id}${defaultMark}`);
}
console.log(`\n Use "ccs ${provider} --use <nickname>" to switch accounts`);
console.log(`\n Use "ccs ${provider} --use <nickname-or-id>" to switch accounts`);
}
process.exit(0);
}
+45 -44
View File
@@ -10,7 +10,7 @@ import {
} from '../../config/unified-config-types';
import {
loadOrCreateUnifiedConfig,
saveUnifiedConfig,
mutateUnifiedConfig,
isUnifiedMode,
} from '../../config/unified-config-loader';
import { CLIPROXY_DEFAULT_PORT } from '../config-generator';
@@ -171,21 +171,20 @@ export function listVariantsFromConfig(): Record<string, VariantConfig> {
}
export function saveCompositeVariantUnified(name: string, config: CompositeVariantConfig): void {
const unifiedConfig = loadOrCreateUnifiedConfig();
mutateUnifiedConfig((unifiedConfig) => {
if (!unifiedConfig.cliproxy) {
unifiedConfig.cliproxy = {
oauth_accounts: {},
providers: [...CLIPROXY_SUPPORTED_PROVIDERS],
variants: {},
};
}
if (!unifiedConfig.cliproxy.variants) {
unifiedConfig.cliproxy.variants = {};
}
if (!unifiedConfig.cliproxy) {
unifiedConfig.cliproxy = {
oauth_accounts: {},
providers: [...CLIPROXY_SUPPORTED_PROVIDERS],
variants: {},
};
}
if (!unifiedConfig.cliproxy.variants) {
unifiedConfig.cliproxy.variants = {};
}
unifiedConfig.cliproxy.variants[name] = config;
saveUnifiedConfig(unifiedConfig);
unifiedConfig.cliproxy.variants[name] = config;
});
}
export function saveVariantUnified(
@@ -196,28 +195,26 @@ export function saveVariantUnified(
port?: number,
target: TargetType = 'claude'
): void {
const config = loadOrCreateUnifiedConfig();
mutateUnifiedConfig((config) => {
if (!config.cliproxy) {
config.cliproxy = {
oauth_accounts: {},
providers: [...CLIPROXY_SUPPORTED_PROVIDERS],
variants: {},
};
}
if (!config.cliproxy.variants) {
config.cliproxy.variants = {};
}
if (!config.cliproxy) {
config.cliproxy = {
oauth_accounts: {},
providers: [...CLIPROXY_SUPPORTED_PROVIDERS],
variants: {},
config.cliproxy.variants[name] = {
provider,
account,
settings: settingsPath,
port,
...(target !== 'claude' && { target }),
};
}
if (!config.cliproxy.variants) {
config.cliproxy.variants = {};
}
config.cliproxy.variants[name] = {
provider,
account,
settings: settingsPath,
port,
...(target !== 'claude' && { target }),
};
saveUnifiedConfig(config);
});
}
export function saveVariantLegacy(
@@ -268,18 +265,22 @@ export function saveVariantLegacy(
}
export function removeVariantFromUnifiedConfig(name: string): VariantConfig | null {
const config = loadOrCreateUnifiedConfig();
let removedVariant: CLIProxyVariantConfig | CompositeVariantConfig | null = null;
mutateUnifiedConfig((config) => {
if (!config.cliproxy?.variants || !(name in config.cliproxy.variants)) {
return;
}
if (!config.cliproxy?.variants || !(name in config.cliproxy.variants)) {
removedVariant = config.cliproxy.variants[name];
delete config.cliproxy.variants[name];
});
if (!removedVariant) {
return null;
}
const variant = config.cliproxy.variants[name];
delete config.cliproxy.variants[name];
saveUnifiedConfig(config);
if ('type' in variant && variant.type === 'composite') {
const composite = variant as CompositeVariantConfig;
const composite = removedVariant as CompositeVariantConfig;
if (composite.type === 'composite') {
return {
provider: composite.tiers[composite.default_tier].provider,
settings: composite.settings,
@@ -290,7 +291,7 @@ export function removeVariantFromUnifiedConfig(name: string): VariantConfig | nu
tiers: composite.tiers,
};
}
const singleVariant = variant as CLIProxyVariantConfig;
const singleVariant = removedVariant as CLIProxyVariantConfig;
return {
provider: singleVariant.provider,
settings: singleVariant.settings,
+14 -4
View File
@@ -366,12 +366,18 @@ export async function handleApiCreateCommand(args: string[]): Promise<void> {
` ${color(`ccs ${result.name} "your prompt"`, 'command')} ${dim('# uses droid by default')}`
);
console.log(
` ${color(`ccsd ${result.name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
` ${color(`ccs-droid ${result.name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
);
console.log(
` ${color(`ccsd ${result.name} "your prompt"`, 'command')} ${dim('# legacy shortcut')}`
);
} else {
console.log(` ${color(`ccs ${result.name} "your prompt"`, 'command')}`);
console.log(
` ${color(`ccs ${result.name} --target droid "your prompt"`, 'command')} ${dim('# optional target override')}`
` ${color(`ccs-droid ${result.name} "your prompt"`, 'command')} ${dim('# explicit one-off droid alias')}`
);
console.log(
` ${color(`ccs ${result.name} --target droid "your prompt"`, 'command')} ${dim('# target flag alternative')}`
);
}
console.log('');
@@ -447,8 +453,9 @@ export async function handleApiCreateCommand(args: string[]): Promise<void> {
` ${color(`ccs ${name} "your prompt"`, 'command')} ${dim('# uses droid by default')}`
);
console.log(
` ${color(`ccsd ${name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
` ${color(`ccs-droid ${name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
);
console.log(` ${color(`ccsd ${name} "your prompt"`, 'command')} ${dim('# legacy shortcut')}`);
console.log(
` ${color(`ccs ${name} --target claude "your prompt"`, 'command')} ${dim('# override to Claude')}`
);
@@ -457,7 +464,10 @@ export async function handleApiCreateCommand(args: string[]): Promise<void> {
` ${color(`ccs ${name} "your prompt"`, 'command')} ${dim('# uses claude by default')}`
);
console.log(
` ${color(`ccs ${name} --target droid "your prompt"`, 'command')} ${dim('# run on droid for this call')}`
` ${color(`ccs-droid ${name} "your prompt"`, 'command')} ${dim('# explicit one-off droid alias')}`
);
console.log(
` ${color(`ccs ${name} --target droid "your prompt"`, 'command')} ${dim('# target flag alternative')}`
);
}
console.log('');
@@ -11,17 +11,7 @@
import { initUI, header, color, dim, ok, warn, info } from '../../utils/ui';
import { getProxyStatus, startProxy, stopProxy } from '../../cliproxy/services';
import { detectRunningProxy } from '../../cliproxy/proxy-detector';
import { CLIPROXY_DEFAULT_PORT, validatePort } from '../../cliproxy/config/port-manager';
import { loadOrCreateUnifiedConfig } from '../../config/unified-config-loader';
/**
* Resolve the local CLIProxy lifecycle port from unified config.
* Falls back to default port when unset/invalid.
*/
export function resolveLifecyclePort(): number {
const config = loadOrCreateUnifiedConfig();
return validatePort(config.cliproxy_server?.local?.port ?? CLIPROXY_DEFAULT_PORT);
}
import { resolveLifecyclePort } from './resolve-lifecycle-port';
export async function handleStart(verbose = false): Promise<void> {
await initUI();
@@ -0,0 +1,11 @@
import { CLIPROXY_DEFAULT_PORT, validatePort } from '../../cliproxy/config/port-manager';
import { loadOrCreateUnifiedConfig } from '../../config/unified-config-loader';
/**
* Resolve the local CLIProxy lifecycle port from unified config.
* Falls back to default port when unset/invalid.
*/
export function resolveLifecyclePort(): number {
const config = loadOrCreateUnifiedConfig();
return validatePort(config.cliproxy_server?.local?.port ?? CLIPROXY_DEFAULT_PORT);
}
+22 -6
View File
@@ -290,7 +290,10 @@ export async function handleCreate(
` ${color(`ccs ${name} "your prompt"`, 'command')} ${dim('# uses droid by default')}`
);
console.log(
` ${color(`ccsd ${name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
` ${color(`ccs-droid ${name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
);
console.log(
` ${color(`ccsd ${name} "your prompt"`, 'command')} ${dim('# legacy shortcut')}`
);
console.log(
` ${color(`ccs ${name} --target claude "your prompt"`, 'command')} ${dim('# override to Claude')}`
@@ -300,7 +303,10 @@ export async function handleCreate(
` ${color(`ccs ${name} "your prompt"`, 'command')} ${dim('# uses claude by default')}`
);
console.log(
` ${color(`ccs ${name} --target droid "your prompt"`, 'command')} ${dim('# run on droid for this call')}`
` ${color(`ccs-droid ${name} "your prompt"`, 'command')} ${dim('# explicit one-off droid alias')}`
);
console.log(
` ${color(`ccs ${name} --target droid "your prompt"`, 'command')} ${dim('# target flag alternative')}`
);
}
console.log('');
@@ -452,8 +458,9 @@ export async function handleCreate(
` ${color(`ccs ${name} "your prompt"`, 'command')} ${dim('# uses droid by default')}`
);
console.log(
` ${color(`ccsd ${name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
` ${color(`ccs-droid ${name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
);
console.log(` ${color(`ccsd ${name} "your prompt"`, 'command')} ${dim('# legacy shortcut')}`);
console.log(
` ${color(`ccs ${name} --target claude "your prompt"`, 'command')} ${dim('# override to Claude')}`
);
@@ -462,7 +469,10 @@ export async function handleCreate(
` ${color(`ccs ${name} "your prompt"`, 'command')} ${dim('# uses claude by default')}`
);
console.log(
` ${color(`ccs ${name} --target droid "your prompt"`, 'command')} ${dim('# run on droid for this call')}`
` ${color(`ccs-droid ${name} "your prompt"`, 'command')} ${dim('# explicit one-off droid alias')}`
);
console.log(
` ${color(`ccs ${name} --target droid "your prompt"`, 'command')} ${dim('# target flag alternative')}`
);
}
console.log('');
@@ -697,7 +707,10 @@ export async function handleEdit(
` ${color(`ccs ${name} "your prompt"`, 'command')} ${dim('# uses droid by default')}`
);
console.log(
` ${color(`ccsd ${name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
` ${color(`ccs-droid ${name} "your prompt"`, 'command')} ${dim('# explicit droid alias')}`
);
console.log(
` ${color(`ccsd ${name} "your prompt"`, 'command')} ${dim('# legacy shortcut')}`
);
console.log(
` ${color(`ccs ${name} --target claude "your prompt"`, 'command')} ${dim('# override to Claude')}`
@@ -707,7 +720,10 @@ export async function handleEdit(
` ${color(`ccs ${name} "your prompt"`, 'command')} ${dim('# uses claude by default')}`
);
console.log(
` ${color(`ccs ${name} --target droid "your prompt"`, 'command')} ${dim('# run on droid for this call')}`
` ${color(`ccs-droid ${name} "your prompt"`, 'command')} ${dim('# explicit one-off droid alias')}`
);
console.log(
` ${color(`ccs ${name} --target droid "your prompt"`, 'command')} ${dim('# target flag alternative')}`
);
}
console.log('');
+9 -14
View File
@@ -5,11 +5,7 @@
*/
import { InteractivePrompt } from '../../utils/prompt';
import {
getDashboardAuthConfig,
loadOrCreateUnifiedConfig,
saveUnifiedConfig,
} from '../../config/unified-config-loader';
import { getDashboardAuthConfig, mutateUnifiedConfig } from '../../config/unified-config-loader';
import { initUI, header, ok, info, warn, dim } from '../../utils/ui';
/**
@@ -57,15 +53,14 @@ export async function handleDisable(): Promise<void> {
}
// Disable auth
const fullConfig = loadOrCreateUnifiedConfig();
fullConfig.dashboard_auth = {
enabled: false,
username: fullConfig.dashboard_auth?.username ?? '',
password_hash: fullConfig.dashboard_auth?.password_hash ?? '',
session_timeout_hours: fullConfig.dashboard_auth?.session_timeout_hours ?? 24,
};
saveUnifiedConfig(fullConfig);
mutateUnifiedConfig((fullConfig) => {
fullConfig.dashboard_auth = {
enabled: false,
username: fullConfig.dashboard_auth?.username ?? '',
password_hash: fullConfig.dashboard_auth?.password_hash ?? '',
session_timeout_hours: fullConfig.dashboard_auth?.session_timeout_hours ?? 24,
};
});
console.log('');
console.log(ok('Dashboard authentication disabled'));
+12 -13
View File
@@ -8,7 +8,7 @@
import bcrypt from 'bcrypt';
import { InteractivePrompt } from '../../utils/prompt';
import { loadOrCreateUnifiedConfig, saveUnifiedConfig } from '../../config/unified-config-loader';
import { mutateUnifiedConfig } from '../../config/unified-config-loader';
import { initUI, header, subheader, ok, fail, info, warn, dim } from '../../utils/ui';
import type { AuthSetupResult } from './types';
@@ -99,24 +99,23 @@ export async function handleSetup(): Promise<AuthSetupResult> {
// Hash password
const passwordHash = await bcrypt.hash(password, BCRYPT_ROUNDS);
// Load existing config and update
const config = loadOrCreateUnifiedConfig();
config.dashboard_auth = {
enabled: true,
username,
password_hash: passwordHash,
session_timeout_hours: config.dashboard_auth?.session_timeout_hours ?? 24,
};
// Save config
saveUnifiedConfig(config);
const config = mutateUnifiedConfig((currentConfig) => {
currentConfig.dashboard_auth = {
enabled: true,
username,
password_hash: passwordHash,
session_timeout_hours: currentConfig.dashboard_auth?.session_timeout_hours ?? 24,
};
});
console.log('');
console.log(ok('Dashboard authentication configured'));
console.log('');
console.log(info('Settings saved to ~/.ccs/config.yaml'));
console.log(info(`Username: ${username}`));
console.log(info(`Session timeout: ${config.dashboard_auth.session_timeout_hours} hours`));
console.log(
info(`Session timeout: ${config.dashboard_auth?.session_timeout_hours ?? 24} hours`)
);
console.log('');
console.log(dim(' Start dashboard: ccs config'));
console.log(dim(' Show status: ccs config auth show'));
+12 -14
View File
@@ -15,7 +15,7 @@ import {
normalizeCopilotConfigWithWarnings,
} from '../copilot';
import type { CopilotModel } from '../copilot';
import { loadOrCreateUnifiedConfig, saveUnifiedConfig } from '../config/unified-config-loader';
import { loadOrCreateUnifiedConfig, mutateUnifiedConfig } from '../config/unified-config-loader';
import { DEFAULT_COPILOT_CONFIG } from '../config/unified-config-types';
import { ok, fail, info, color, warn } from '../utils/ui';
import { normalizeCopilotSubcommand } from '../copilot/constants';
@@ -361,14 +361,13 @@ async function handleStop(): Promise<number> {
* Handle enable subcommand.
*/
async function handleEnable(): Promise<number> {
const config = loadOrCreateUnifiedConfig();
mutateUnifiedConfig((config) => {
if (!config.copilot) {
config.copilot = { ...DEFAULT_COPILOT_CONFIG };
}
if (!config.copilot) {
config.copilot = { ...DEFAULT_COPILOT_CONFIG };
}
config.copilot.enabled = true;
saveUnifiedConfig(config);
config.copilot.enabled = true;
});
console.log(ok('Copilot integration enabled'));
console.log('');
@@ -384,12 +383,11 @@ async function handleEnable(): Promise<number> {
* Handle disable subcommand.
*/
async function handleDisable(): Promise<number> {
const config = loadOrCreateUnifiedConfig();
if (config.copilot) {
config.copilot.enabled = false;
saveUnifiedConfig(config);
}
mutateUnifiedConfig((config) => {
if (config.copilot) {
config.copilot.enabled = false;
}
});
console.log(ok('Copilot integration disabled'));
+12 -18
View File
@@ -15,11 +15,7 @@ import {
getAvailableModels,
getDefaultModel,
} from '../cursor';
import {
getCursorConfig,
loadOrCreateUnifiedConfig,
saveUnifiedConfig,
} from '../config/unified-config-loader';
import { getCursorConfig, mutateUnifiedConfig } from '../config/unified-config-loader';
import { DEFAULT_CURSOR_CONFIG } from '../config/unified-config-types';
import { renderCursorHelp, renderCursorModels, renderCursorStatus } from './cursor-command-display';
import { ok, fail, info } from '../utils/ui';
@@ -239,14 +235,13 @@ async function handleStop(): Promise<number> {
* Handle enable subcommand.
*/
async function handleEnable(): Promise<number> {
const config = loadOrCreateUnifiedConfig();
mutateUnifiedConfig((config) => {
if (!config.cursor) {
config.cursor = { ...DEFAULT_CURSOR_CONFIG };
}
if (!config.cursor) {
config.cursor = { ...DEFAULT_CURSOR_CONFIG };
}
config.cursor.enabled = true;
saveUnifiedConfig(config);
config.cursor.enabled = true;
});
console.log(ok('Cursor integration enabled'));
console.log('');
@@ -262,12 +257,11 @@ async function handleEnable(): Promise<number> {
* Handle disable subcommand.
*/
async function handleDisable(): Promise<number> {
const config = loadOrCreateUnifiedConfig();
if (config.cursor) {
config.cursor.enabled = false;
saveUnifiedConfig(config);
}
mutateUnifiedConfig((config) => {
if (config.cursor) {
config.cursor.enabled = false;
}
});
console.log(ok('Cursor integration disabled'));
return 0;
+10 -8
View File
@@ -209,7 +209,7 @@ Run ${color('ccs config', 'command')} for web dashboard`.trim();
'Show auth URL and prompt for callback paste (cross-browser)',
],
['ccs <provider> --accounts', 'List all accounts'],
['ccs <provider> --use <name>', 'Switch to account'],
['ccs <provider> --use <nickname-or-id>', 'Switch to account'],
['ccs <provider> --config', 'Change model (agy, gemini)'],
[
'ccs agy --accept-agr-risk',
@@ -355,22 +355,24 @@ Run ${color('ccs config', 'command')} for web dashboard`.trim();
// Aliases
printSubSection('Aliases', [
['ccsd <profile> [args]', 'Shorthand for: ccs <profile> --target droid'],
['ccs-droid <profile> [args]', 'Explicit Droid runtime alias'],
['ccsd <profile> [args]', 'Legacy shortcut for: ccs-droid <profile> [args]'],
]);
// Multi-target examples
printSubSection('Multi-Target', [
['ccs glm --target droid', 'Run GLM profile on Droid CLI'],
['ccsd glm', 'Same as above (alias)'],
['ccsd codex', 'Run built-in CLIProxy Codex profile on Droid'],
['ccsd agy', 'Run built-in CLIProxy Antigravity profile on Droid'],
['ccs-droid glm', 'Same as above (explicit alias)'],
['ccsd glm', 'Legacy shortcut for ccs-droid'],
['ccs-droid codex', 'Run built-in CLIProxy Codex profile on Droid'],
['ccs-droid agy', 'Run built-in CLIProxy Antigravity profile on Droid'],
[
'ccsd codex exec --skip-permissions-unsafe "fix failing tests"',
'ccs-droid codex exec --skip-permissions-unsafe "fix failing tests"',
'Pass through Droid exec mode',
],
['ccsd codex -m custom:gpt-5.3-codex "fix failing tests"', 'Auto-routes short exec flags'],
['ccs-droid codex -m custom:gpt-5.3-codex "fix failing tests"', 'Auto-routes short exec flags'],
[
'ccsd codex --skip-permissions-unsafe "fix failing tests"',
'ccs-droid codex --skip-permissions-unsafe "fix failing tests"',
'Auto-routes to Droid exec when exec-only flags are detected',
],
[
+5 -4
View File
@@ -19,7 +19,7 @@ import { initUI, header, ok, info, warn } from '../utils/ui';
import {
loadOrCreateUnifiedConfig,
loadUnifiedConfig,
saveUnifiedConfig,
mutateUnifiedConfig,
hasUnifiedConfig,
} from '../config/unified-config-loader';
import { DEFAULT_CLIPROXY_SERVER_CONFIG } from '../config/unified-config-types';
@@ -377,9 +377,10 @@ async function runSetupWizard(force: boolean = false): Promise<void> {
console.log(' After creating, edit the settings file to add your API key.');
}
// Save config
config.setup_completed = true;
saveUnifiedConfig(config);
mutateUnifiedConfig((currentConfig) => {
currentConfig.setup_completed = true;
currentConfig.cliproxy_server = config.cliproxy_server;
});
// Final summary
console.log('');
+107 -47
View File
@@ -7,6 +7,7 @@
import * as fs from 'fs';
import * as path from 'path';
import * as crypto from 'crypto';
import * as yaml from 'js-yaml';
import { getCcsDir } from '../utils/config-manager';
import {
@@ -64,65 +65,73 @@ function getLockFilePath(): string {
/**
* Acquire lockfile for config write operations.
* Returns true if lock acquired, false if already locked by another process.
* Returns a lock token if acquired, null if already locked by another process.
* Cleans up stale locks (older than LOCK_STALE_MS).
*/
function acquireLock(): boolean {
function acquireLock(): string | null {
const lockPath = getLockFilePath();
const lockData = `${process.pid}\n${Date.now()}`;
const lockToken = crypto.randomUUID();
const lockData = `${process.pid}\n${Date.now()}\n${lockToken}`;
try {
// Check if lock exists
if (fs.existsSync(lockPath)) {
const content = fs.readFileSync(lockPath, 'utf8');
const [pidStr, timestampStr] = content.trim().split('\n');
const timestamp = parseInt(timestampStr, 10);
const pid = Number.parseInt(pidStr, 10);
const timestamp = Number.parseInt(timestampStr, 10);
const hasLiveOwner = Number.isInteger(pid) && pid > 0 && processExists(pid);
const isStale = !Number.isFinite(timestamp) || Date.now() - timestamp > LOCK_STALE_MS;
// Check if lock is stale
if (Date.now() - timestamp > LOCK_STALE_MS) {
// Stale lock - remove and acquire
if (hasLiveOwner) {
return null;
}
if (isStale || !hasLiveOwner) {
fs.unlinkSync(lockPath);
} else {
// Check if process still exists
try {
process.kill(parseInt(pidStr, 10), 0); // Signal 0 checks if process exists
// Process exists - lock is valid
return false;
} catch {
// Process doesn't exist - remove stale lock
fs.unlinkSync(lockPath);
}
}
}
// Acquire lock
fs.writeFileSync(lockPath, lockData, { flag: 'wx', mode: 0o600 });
return true;
return lockToken;
} catch (error) {
// EEXIST means another process acquired the lock between our check and write
if ((error as NodeJS.ErrnoException).code === 'EEXIST') {
return false;
return null;
}
return false;
return null;
}
}
/**
* Release lockfile after config write operation.
*/
function releaseLock(): void {
function releaseLock(lockToken: string): void {
const lockPath = getLockFilePath();
try {
if (fs.existsSync(lockPath)) {
fs.unlinkSync(lockPath);
const content = fs.readFileSync(lockPath, 'utf8');
const fileToken = content.trim().split('\n')[2];
if (fileToken === lockToken) {
fs.unlinkSync(lockPath);
}
}
} catch {
// Ignore cleanup errors
}
}
function processExists(pid: number): boolean {
try {
process.kill(pid, 0);
return true;
} catch {
return false;
}
}
/**
* Check if unified config.yaml exists
*/
@@ -152,7 +161,7 @@ export function getConfigFormat(): 'yaml' | 'json' | 'none' {
/**
* Load unified config from YAML file.
* Returns null if file doesn't exist or format check fails.
* Returns null if file doesn't exist.
* Auto-upgrades config if version is outdated (regenerates comments).
*/
export function loadUnifiedConfig(): UnifiedConfig | null {
@@ -168,8 +177,7 @@ export function loadUnifiedConfig(): UnifiedConfig | null {
const parsed = yaml.load(content);
if (!isUnifiedConfig(parsed)) {
console.error(`[!] Invalid config format in ${yamlPath}`);
return null;
throw new Error(`Invalid config format in ${yamlPath}`);
}
// Auto-upgrade if version is outdated (regenerates YAML with new comments and fields)
@@ -208,7 +216,7 @@ export function loadUnifiedConfig(): UnifiedConfig | null {
const error = err instanceof Error ? err.message : 'Unknown error';
console.error(`[X] Failed to load config: ${error}`);
}
return null;
throw err;
}
}
@@ -329,11 +337,27 @@ function mergeWithDefaults(partial: Partial<UnifiedConfig>): UnifiedConfig {
websearch: {
enabled: partial.websearch?.enabled ?? defaults.websearch?.enabled ?? true,
providers: {
exa: {
enabled: partial.websearch?.providers?.exa?.enabled ?? false,
max_results: partial.websearch?.providers?.exa?.max_results ?? 5,
},
tavily: {
enabled: partial.websearch?.providers?.tavily?.enabled ?? false,
max_results: partial.websearch?.providers?.tavily?.max_results ?? 5,
},
duckduckgo: {
enabled: partial.websearch?.providers?.duckduckgo?.enabled ?? true,
max_results: partial.websearch?.providers?.duckduckgo?.max_results ?? 5,
},
brave: {
enabled: partial.websearch?.providers?.brave?.enabled ?? false,
max_results: partial.websearch?.providers?.brave?.max_results ?? 5,
},
gemini: {
enabled:
partial.websearch?.providers?.gemini?.enabled ??
partial.websearch?.gemini?.enabled ?? // Legacy fallback
true,
false,
model: partial.websearch?.providers?.gemini?.model ?? 'gemini-2.5-flash',
timeout:
partial.websearch?.providers?.gemini?.timeout ??
@@ -610,25 +634,25 @@ function generateYamlWithComments(config: UnifiedConfig): string {
// WebSearch section
if (config.websearch) {
lines.push('# ----------------------------------------------------------------------------');
lines.push('# WebSearch: CLI-based web search for third-party profiles');
lines.push('# WebSearch: real search backends for third-party profiles');
lines.push('# Dashboard (`ccs config`) is the source of truth for provider selection.');
lines.push('#');
lines.push('# Third-party providers (gemini, codex, agy, etc.) do not have access to');
lines.push("# Anthropic's WebSearch tool. These CLI tools provide fallback web search.");
lines.push('#');
lines.push('# Fallback chain: Gemini -> OpenCode -> Grok (tries in order until success)');
lines.push("# Anthropic's WebSearch tool. CCS intercepts that tool and runs local search.");
lines.push('#');
lines.push(
'# Gemini models: gemini-2.5-flash (default), gemini-2.5-pro, gemini-2.5-flash-lite'
);
lines.push(
'# OpenCode models: opencode/grok-code (default), opencode/gpt-4o, opencode/claude-3.5-sonnet'
'# Priority: Exa -> Tavily -> Brave -> DuckDuckGo -> optional legacy AI CLI fallbacks'
);
lines.push('#');
lines.push('# Install commands:');
lines.push('# gemini: npm i -g @google/gemini-cli (FREE - 1000 req/day)');
lines.push('# opencode: curl -fsSL https://opencode.ai/install | bash (FREE via Zen)');
lines.push('# grok: npm i -g @vibe-kit/grok-cli (requires GROK_API_KEY)');
lines.push('# Exa requires EXA_API_KEY in your environment.');
lines.push('# Tavily requires TAVILY_API_KEY in your environment.');
lines.push('# Brave requires BRAVE_API_KEY in your environment.');
lines.push('# DuckDuckGo works with zero extra setup and is enabled by default.');
lines.push('#');
lines.push('# Legacy LLM fallbacks remain optional if you still want them:');
lines.push('# gemini: npm i -g @google/gemini-cli');
lines.push('# opencode: curl -fsSL https://opencode.ai/install | bash');
lines.push('# grok: npm i -g @vibe-kit/grok-cli');
lines.push('# ----------------------------------------------------------------------------');
lines.push(
yaml
@@ -808,16 +832,17 @@ function withConfigWriteLock<T>(callback: () => T): T {
// Acquire lock (retry for up to 1 second)
const maxRetries = 10;
const retryDelayMs = 100;
let lockAcquired = false;
let lockToken: string | null = null;
for (let i = 0; i < maxRetries; i++) {
if (acquireLock()) {
lockAcquired = true;
const acquiredToken = acquireLock();
if (acquiredToken) {
lockToken = acquiredToken;
break;
}
sleepSync(retryDelayMs);
}
if (!lockAcquired) {
if (!lockToken) {
throw new Error('Config file is locked by another process. Wait a moment and try again.');
}
@@ -825,7 +850,7 @@ function withConfigWriteLock<T>(callback: () => T): T {
return callback();
} finally {
// Always release lock
releaseLock();
releaseLock(lockToken);
}
}
@@ -969,6 +994,10 @@ export interface GeminiWebSearchInfo {
export function getWebSearchConfig(): {
enabled: boolean;
providers?: {
exa?: { enabled?: boolean; max_results?: number };
tavily?: { enabled?: boolean; max_results?: number };
duckduckgo?: { enabled?: boolean; max_results?: number };
brave?: { enabled?: boolean; max_results?: number };
gemini?: GeminiWebSearchInfo;
opencode?: { enabled?: boolean; model?: string; timeout?: number };
grok?: { enabled?: boolean; timeout?: number };
@@ -979,9 +1008,29 @@ export function getWebSearchConfig(): {
const config = loadOrCreateUnifiedConfig();
// Build provider configs
const exaConfig = {
enabled: config.websearch?.providers?.exa?.enabled ?? false,
max_results: config.websearch?.providers?.exa?.max_results ?? 5,
};
const tavilyConfig = {
enabled: config.websearch?.providers?.tavily?.enabled ?? false,
max_results: config.websearch?.providers?.tavily?.max_results ?? 5,
};
const duckDuckGoConfig = {
enabled: config.websearch?.providers?.duckduckgo?.enabled ?? true,
max_results: config.websearch?.providers?.duckduckgo?.max_results ?? 5,
};
const braveConfig = {
enabled: config.websearch?.providers?.brave?.enabled ?? false,
max_results: config.websearch?.providers?.brave?.max_results ?? 5,
};
const geminiConfig: GeminiWebSearchInfo = {
enabled:
config.websearch?.providers?.gemini?.enabled ?? config.websearch?.gemini?.enabled ?? true,
config.websearch?.providers?.gemini?.enabled ?? config.websearch?.gemini?.enabled ?? false,
model: config.websearch?.providers?.gemini?.model ?? 'gemini-2.5-flash',
timeout:
config.websearch?.providers?.gemini?.timeout ?? config.websearch?.gemini?.timeout ?? 55,
@@ -999,12 +1048,23 @@ export function getWebSearchConfig(): {
};
// Auto-enable master switch if ANY provider is enabled
const anyProviderEnabled = geminiConfig.enabled || opencodeConfig.enabled || grokConfig.enabled;
const anyProviderEnabled =
exaConfig.enabled ||
tavilyConfig.enabled ||
duckDuckGoConfig.enabled ||
braveConfig.enabled ||
geminiConfig.enabled ||
opencodeConfig.enabled ||
grokConfig.enabled;
const enabled = anyProviderEnabled && (config.websearch?.enabled ?? true);
return {
enabled,
providers: {
exa: exaConfig,
tavily: tavilyConfig,
duckduckgo: duckDuckGoConfig,
brave: braveConfig,
gemini: geminiConfig,
opencode: opencodeConfig,
grok: grokConfig,
+77 -11
View File
@@ -22,8 +22,10 @@ import { CLIPROXY_PROVIDER_IDS } from '../cliproxy/provider-capabilities';
* Version 6 = Customizable auth tokens (API key and management secret)
* Version 7 = Quota management for hybrid auto+manual account control
* Version 8 = Thinking/reasoning budget configuration
* Version 9 = Real WebSearch backends (DuckDuckGo/Brave) with legacy CLI fallback
* Version 10 = Exa + Tavily WebSearch backends
*/
export const UNIFIED_CONFIG_VERSION = 8;
export const UNIFIED_CONFIG_VERSION = 10;
/**
* Supported CLIProxy providers.
@@ -235,11 +237,51 @@ export interface PreferencesConfig {
auto_update?: boolean;
}
/**
* DuckDuckGo WebSearch configuration.
*/
export interface DuckDuckGoWebSearchConfig {
/** Enable DuckDuckGo HTML search fallback (default: true) */
enabled?: boolean;
/** Number of results to fetch (default: 5) */
max_results?: number;
}
/**
* Brave WebSearch configuration.
*/
export interface BraveWebSearchConfig {
/** Enable Brave Search when BRAVE_API_KEY is available (default: false) */
enabled?: boolean;
/** Number of results to fetch (default: 5) */
max_results?: number;
}
/**
* Exa WebSearch configuration.
*/
export interface ExaWebSearchConfig {
/** Enable Exa Search when EXA_API_KEY is available (default: false) */
enabled?: boolean;
/** Number of results to fetch (default: 5) */
max_results?: number;
}
/**
* Tavily WebSearch configuration.
*/
export interface TavilyWebSearchConfig {
/** Enable Tavily Search when TAVILY_API_KEY is available (default: false) */
enabled?: boolean;
/** Number of results to fetch (default: 5) */
max_results?: number;
}
/**
* Gemini CLI WebSearch configuration.
*/
export interface GeminiWebSearchConfig {
/** Enable Gemini CLI for WebSearch (default: true) */
/** Enable Gemini CLI legacy fallback (default: false) */
enabled?: boolean;
/** Model to use (default: gemini-2.5-flash) */
model?: string;
@@ -251,7 +293,7 @@ export interface GeminiWebSearchConfig {
* Grok CLI WebSearch configuration.
*/
export interface GrokWebSearchConfig {
/** Enable Grok CLI for WebSearch (default: false - requires GROK_API_KEY) */
/** Enable Grok CLI legacy fallback (default: false - requires GROK_API_KEY) */
enabled?: boolean;
/** Timeout in seconds (default: 55) */
timeout?: number;
@@ -261,7 +303,7 @@ export interface GrokWebSearchConfig {
* OpenCode CLI WebSearch configuration.
*/
export interface OpenCodeWebSearchConfig {
/** Enable OpenCode CLI for WebSearch (default: false) */
/** Enable OpenCode CLI legacy fallback (default: false) */
enabled?: boolean;
/** Model to use (default: opencode/grok-code) */
model?: string;
@@ -271,14 +313,22 @@ export interface OpenCodeWebSearchConfig {
/**
* WebSearch providers configuration.
* Supports Gemini CLI, Grok CLI, and OpenCode.
* Uses deterministic search backends first, with optional legacy CLI fallback.
*/
export interface WebSearchProvidersConfig {
/** Gemini CLI - uses google_web_search tool (FREE tier: 1000 req/day) */
/** Exa Search API - API-backed search with strong relevance and content extraction */
exa?: ExaWebSearchConfig;
/** Tavily Search API - API-backed search optimized for agent/tool usage */
tavily?: TavilyWebSearchConfig;
/** DuckDuckGo HTML search - zero setup default backend */
duckduckgo?: DuckDuckGoWebSearchConfig;
/** Brave Search API - higher quality results when BRAVE_API_KEY is set */
brave?: BraveWebSearchConfig;
/** Gemini CLI - optional legacy LLM fallback */
gemini?: GeminiWebSearchConfig;
/** Grok CLI - xAI web search (requires GROK_API_KEY) */
/** Grok CLI - optional legacy LLM fallback */
grok?: GrokWebSearchConfig;
/** OpenCode - built-in web search (FREE via OpenCode Zen) */
/** OpenCode - optional legacy LLM fallback */
opencode?: OpenCodeWebSearchConfig;
}
@@ -441,8 +491,8 @@ export const DEFAULT_GLOBAL_ENV: Record<string, string> = {
/**
* WebSearch configuration.
* Uses CLI tools (Gemini CLI, Grok CLI, OpenCode) for third-party profiles.
* Third-party providers don't have server-side WebSearch access.
* Uses deterministic local backends for third-party profiles.
* Legacy AI CLI fallbacks remain available for compatibility only.
*/
export interface WebSearchConfig {
/** Master switch - enable/disable WebSearch (default: true) */
@@ -825,8 +875,24 @@ export function createEmptyUnifiedConfig(): UnifiedConfig {
websearch: {
enabled: true,
providers: {
gemini: {
exa: {
enabled: false,
max_results: 5,
},
tavily: {
enabled: false,
max_results: 5,
},
duckduckgo: {
enabled: true,
max_results: 5,
},
brave: {
enabled: false,
max_results: 5,
},
gemini: {
enabled: false,
model: 'gemini-2.5-flash',
timeout: 55,
},
+88 -19
View File
@@ -3,8 +3,8 @@
*
* Resolves which CLI target to use based on:
* 1. --target flag (highest priority)
* 2. Per-profile config
* 3. argv[0] detection (busybox/symlink pattern)
* 2. Runtime alias entrypoint / argv[0] detection
* 3. Per-profile config
* 4. Default: 'claude'
*/
@@ -12,32 +12,97 @@ import * as path from 'path';
import { TargetType } from './target-adapter';
/**
* Map of binary names to target types (busybox pattern).
* When CCS is invoked as `ccsd`, it auto-selects the droid target.
* Built-in argv[0] aliases for explicit runtime entrypoints.
* `ccs-droid` is the transparent alias; `ccsd` remains as a legacy shortcut.
*/
const ARGV0_TARGET_MAP: Record<string, TargetType> = {
const BUILTIN_ARGV0_TARGET_MAP: Record<string, TargetType> = {
'ccs-droid': 'droid',
ccsd: 'droid',
};
const ALIAS_NAME_REGEX = /^[a-z0-9._-]+$/;
const INTERNAL_ENTRY_TARGET_ENV_VAR = 'CCS_INTERNAL_ENTRY_TARGET';
const GENERIC_TARGET_ALIAS_ENV_VAR = 'CCS_TARGET_ALIASES';
const LEGACY_TARGET_ALIAS_ENV_VARS: Partial<Record<TargetType, string>> = {
droid: 'CCS_DROID_ALIASES',
};
const RESERVED_BIN_NAMES = new Set<string>(['ccs', ...Object.keys(BUILTIN_ARGV0_TARGET_MAP)]);
function buildArgv0TargetMap(): Record<string, TargetType> {
const map: Record<string, TargetType> = { ...ARGV0_TARGET_MAP };
const envAliases = process.env['CCS_DROID_ALIASES'];
if (!envAliases) {
return map;
function addAliasToMap(map: Record<string, TargetType>, alias: string, target: TargetType): void {
const normalizedAlias = alias.trim().toLowerCase();
if (
!normalizedAlias ||
!ALIAS_NAME_REGEX.test(normalizedAlias) ||
RESERVED_BIN_NAMES.has(normalizedAlias)
) {
return;
}
for (const rawAlias of envAliases.split(',')) {
const alias = rawAlias.trim().toLowerCase();
if (!alias || !ALIAS_NAME_REGEX.test(alias)) {
map[normalizedAlias] = target;
}
function addAliasListToMap(
map: Record<string, TargetType>,
target: TargetType,
rawAliases: string
): void {
for (const rawAlias of rawAliases.split(',')) {
addAliasToMap(map, rawAlias, target);
}
}
function parseGenericTargetAliasConfig(map: Record<string, TargetType>, rawConfig: string): void {
for (const rawEntry of rawConfig.split(';')) {
const entry = rawEntry.trim();
if (!entry) {
continue;
}
map[alias] = 'droid';
const separatorIndex = entry.indexOf('=');
if (separatorIndex <= 0 || separatorIndex === entry.length - 1) {
continue;
}
const rawTarget = entry.slice(0, separatorIndex).trim().toLowerCase();
const rawAliases = entry.slice(separatorIndex + 1).trim();
if (!rawAliases || !isValidTarget(rawTarget)) {
continue;
}
addAliasListToMap(map, rawTarget, rawAliases);
}
}
function buildArgv0TargetMap(): Record<string, TargetType> {
const map: Record<string, TargetType> = { ...BUILTIN_ARGV0_TARGET_MAP };
const genericAliasConfig = process.env[GENERIC_TARGET_ALIAS_ENV_VAR];
if (genericAliasConfig) {
parseGenericTargetAliasConfig(map, genericAliasConfig);
}
for (const [target, envVar] of Object.entries(LEGACY_TARGET_ALIAS_ENV_VARS) as Array<
[TargetType, string]
>) {
const rawAliases = process.env[envVar];
if (!rawAliases) {
continue;
}
addAliasListToMap(map, target, rawAliases);
}
return map;
}
function resolveEntrypointTarget(): TargetType | null {
const rawTarget = process.env[INTERNAL_ENTRY_TARGET_ENV_VAR];
if (!rawTarget) {
return null;
}
const normalizedTarget = rawTarget.trim().toLowerCase();
return isValidTarget(normalizedTarget) ? normalizedTarget : null;
}
/**
* Valid target types for --target flag validation.
*/
@@ -123,13 +188,12 @@ export function resolveTargetType(
return parsed.targetOverride;
}
// 2. Check per-profile config
if (profileConfig?.target !== undefined) {
return isValidTarget(profileConfig.target) ? profileConfig.target : 'claude';
// 2. Check runtime alias entrypoint / argv[0]
const entrypointTarget = resolveEntrypointTarget();
if (entrypointTarget) {
return entrypointTarget;
}
// 3. Check argv[0] (busybox pattern)
// Strip common wrapper extensions for Windows shims/wrappers
const rawBin = path.basename(process.argv[1] || process.argv0 || '');
const binName = rawBin.replace(/\.(cmd|bat|ps1|exe)$/i, '').toLowerCase();
const argv0TargetMap = buildArgv0TargetMap();
@@ -138,6 +202,11 @@ export function resolveTargetType(
return argv0Target;
}
// 3. Check per-profile config
if (profileConfig?.target !== undefined) {
return isValidTarget(profileConfig.target) ? profileConfig.target : 'claude';
}
// 4. Default
return 'claude';
}
+5 -4
View File
@@ -3,12 +3,13 @@
*
* WebSearch is a server-side tool executed by Anthropic's API.
* Third-party providers (gemini, agy, codex, qwen) don't have access.
* This manager installs a hook that uses CLI tools (Gemini CLI) as fallback.
* This manager installs a hook that uses deterministic local search backends,
* with legacy AI CLI tools kept only as optional fallback.
*
* Simplified Architecture:
* - No MCP complexity
* - Uses CLI tools (currently Gemini CLI)
* - Easy to extend for future CLI tools (opencode, etc.)
* - No MCP dependency for the default path
* - Uses real search providers first (DuckDuckGo, Brave)
* - Keeps Gemini/OpenCode/Grok as compatibility fallback only
*
* @module utils/websearch-manager
*/
+23 -1
View File
@@ -29,7 +29,29 @@ export function getWebSearchHookEnv(): Record<string, string> {
env.CCS_WEBSEARCH_ENABLED = '1';
// Pass individual provider enabled states
// Hook will only use providers that are BOTH enabled AND installed
// Hook will only use providers that are BOTH enabled AND ready.
if (wsConfig.providers?.exa?.enabled) {
env.CCS_WEBSEARCH_EXA = '1';
env.CCS_WEBSEARCH_EXA_MAX_RESULTS = String(wsConfig.providers.exa.max_results || 5);
}
if (wsConfig.providers?.tavily?.enabled) {
env.CCS_WEBSEARCH_TAVILY = '1';
env.CCS_WEBSEARCH_TAVILY_MAX_RESULTS = String(wsConfig.providers.tavily.max_results || 5);
}
if (wsConfig.providers?.duckduckgo?.enabled) {
env.CCS_WEBSEARCH_DUCKDUCKGO = '1';
env.CCS_WEBSEARCH_DUCKDUCKGO_MAX_RESULTS = String(
wsConfig.providers.duckduckgo.max_results || 5
);
}
if (wsConfig.providers?.brave?.enabled) {
env.CCS_WEBSEARCH_BRAVE = '1';
env.CCS_WEBSEARCH_BRAVE_MAX_RESULTS = String(wsConfig.providers.brave.max_results || 5);
}
if (wsConfig.providers?.gemini?.enabled) {
env.CCS_WEBSEARCH_GEMINI = '1';
if (wsConfig.providers.gemini.model) {
+139 -90
View File
@@ -8,70 +8,164 @@
import { ok, warn, fail, info } from '../ui';
import { getWebSearchConfig } from '../../config/unified-config-loader';
import { getGeminiCliStatus, hasGeminiCli, isGeminiAuthenticated } from './gemini-cli';
import { getGrokCliStatus, hasGrokCli } from './grok-cli';
import { getOpenCodeCliStatus, hasOpenCodeCli } from './opencode-cli';
import { getGeminiCliStatus, isGeminiAuthenticated } from './gemini-cli';
import { getGrokCliStatus } from './grok-cli';
import { getOpenCodeCliStatus } from './opencode-cli';
import type { WebSearchCliInfo, WebSearchStatus } from './types';
/**
* Get all WebSearch CLI providers with their status
*/
export function getWebSearchCliProviders(): WebSearchCliInfo[] {
function hasEnvValue(name: string): boolean {
return (process.env[name] || '').trim().length > 0;
}
function hasAnyEnvValue(names: string[]): boolean {
return names.some((name) => hasEnvValue(name));
}
function getLegacyProviderStatuses(): WebSearchCliInfo[] {
const wsConfig = getWebSearchConfig();
const geminiStatus = getGeminiCliStatus();
const grokStatus = getGrokCliStatus();
const opencodeStatus = getOpenCodeCliStatus();
const geminiAuthed = geminiStatus.installed && isGeminiAuthenticated();
return [
{
id: 'gemini',
kind: 'legacy-cli',
name: 'Gemini CLI',
command: 'gemini',
installed: geminiStatus.installed,
enabled: wsConfig.providers?.gemini?.enabled ?? false,
available: geminiAuthed,
version: geminiStatus.version ?? null,
installCommand: 'npm install -g @google/gemini-cli',
docsUrl: 'https://github.com/google-gemini/gemini-cli',
requiresApiKey: false,
description: 'Google Gemini with web search (FREE tier: 1000 req/day)',
freeTier: true,
description: 'Optional legacy LLM fallback with Google web search.',
detail: geminiStatus.installed
? geminiAuthed
? 'Authenticated'
: "Run 'gemini' to login"
: 'Not installed',
},
{
id: 'opencode',
kind: 'legacy-cli',
name: 'OpenCode',
command: 'opencode',
installed: opencodeStatus.installed,
enabled: wsConfig.providers?.opencode?.enabled ?? false,
available: opencodeStatus.installed,
version: opencodeStatus.version ?? null,
installCommand: 'curl -fsSL https://opencode.ai/install | bash',
docsUrl: 'https://github.com/sst/opencode',
requiresApiKey: false,
description: 'OpenCode with built-in web search (FREE via Zen)',
freeTier: true,
description: 'Optional legacy LLM fallback via OpenCode.',
detail: opencodeStatus.installed ? 'Installed' : 'Not installed',
},
{
id: 'grok',
kind: 'legacy-cli',
name: 'Grok CLI',
command: 'grok',
installed: grokStatus.installed,
enabled: wsConfig.providers?.grok?.enabled ?? false,
available: grokStatus.installed && hasEnvValue('GROK_API_KEY'),
version: grokStatus.version ?? null,
installCommand: 'npm install -g @vibe-kit/grok-cli',
docsUrl: 'https://github.com/superagent-ai/grok-cli',
requiresApiKey: true,
apiKeyEnvVar: 'GROK_API_KEY',
description: 'xAI Grok CLI with AI coding agent capabilities',
freeTier: false,
description: 'Optional legacy LLM fallback with xAI Grok.',
detail: grokStatus.installed
? hasEnvValue('GROK_API_KEY')
? 'Ready'
: 'Set GROK_API_KEY'
: 'Not installed',
},
];
}
/**
* Check if any WebSearch CLI is available
* Get all WebSearch providers with their current status.
*/
export function hasAnyWebSearchCli(): boolean {
return hasGeminiCli() || hasGrokCli() || hasOpenCodeCli();
export function getWebSearchCliProviders(): WebSearchCliInfo[] {
const wsConfig = getWebSearchConfig();
const providers: WebSearchCliInfo[] = [
{
id: 'exa',
kind: 'backend',
name: 'Exa',
enabled: wsConfig.providers?.exa?.enabled ?? false,
available:
(wsConfig.providers?.exa?.enabled ?? false) &&
hasAnyEnvValue(['EXA_API_KEY', 'CCS_WEBSEARCH_EXA_API_KEY']),
version: null,
docsUrl: 'https://docs.exa.ai/reference/search',
requiresApiKey: true,
apiKeyEnvVar: 'EXA_API_KEY',
description: 'API-backed search with strong relevance and content extraction.',
detail: hasAnyEnvValue(['EXA_API_KEY', 'CCS_WEBSEARCH_EXA_API_KEY'])
? `API key detected (${wsConfig.providers?.exa?.max_results ?? 5} results)`
: 'Set EXA_API_KEY',
},
{
id: 'tavily',
kind: 'backend',
name: 'Tavily',
enabled: wsConfig.providers?.tavily?.enabled ?? false,
available:
(wsConfig.providers?.tavily?.enabled ?? false) &&
hasAnyEnvValue(['TAVILY_API_KEY', 'CCS_WEBSEARCH_TAVILY_API_KEY']),
version: null,
docsUrl: 'https://docs.tavily.com/documentation/api-reference/endpoint/search',
requiresApiKey: true,
apiKeyEnvVar: 'TAVILY_API_KEY',
description: 'Search API optimized for agent workflows and concise web result synthesis.',
detail: hasAnyEnvValue(['TAVILY_API_KEY', 'CCS_WEBSEARCH_TAVILY_API_KEY'])
? `API key detected (${wsConfig.providers?.tavily?.max_results ?? 5} results)`
: 'Set TAVILY_API_KEY',
},
{
id: 'duckduckgo',
kind: 'backend',
name: 'DuckDuckGo',
enabled: wsConfig.providers?.duckduckgo?.enabled ?? true,
available: wsConfig.providers?.duckduckgo?.enabled ?? true,
version: null,
docsUrl: 'https://duckduckgo.com',
requiresApiKey: false,
description: 'Default built-in HTML search backend. Zero setup.',
detail: `Built-in (${wsConfig.providers?.duckduckgo?.max_results ?? 5} results)`,
},
{
id: 'brave',
kind: 'backend',
name: 'Brave Search',
enabled: wsConfig.providers?.brave?.enabled ?? false,
available:
(wsConfig.providers?.brave?.enabled ?? false) &&
hasAnyEnvValue(['BRAVE_API_KEY', 'CCS_WEBSEARCH_BRAVE_API_KEY']),
version: null,
docsUrl: 'https://brave.com/search/api/',
requiresApiKey: true,
apiKeyEnvVar: 'BRAVE_API_KEY',
description: 'API-backed web search with cleaner result metadata.',
detail: hasAnyEnvValue(['BRAVE_API_KEY', 'CCS_WEBSEARCH_BRAVE_API_KEY'])
? `API key detected (${wsConfig.providers?.brave?.max_results ?? 5} results)`
: 'Set BRAVE_API_KEY',
},
];
return [...providers, ...getLegacyProviderStatuses()];
}
/**
* Get install hints for CLI-only users when no WebSearch CLI is installed
* Returns raw message strings (without indicator prefix) for display
* Check if any WebSearch provider is currently ready.
*/
export function hasAnyWebSearchCli(): boolean {
return getWebSearchCliProviders().some((provider) => provider.enabled && provider.available);
}
/**
* Get setup hints when no providers are ready.
*/
export function getCliInstallHints(): string[] {
if (hasAnyWebSearchCli()) {
@@ -79,95 +173,58 @@ export function getCliInstallHints(): string[] {
}
return [
'WebSearch: No CLI tools installed',
' Gemini CLI (FREE): npm i -g @google/gemini-cli',
' OpenCode (FREE): curl -fsSL https://opencode.ai/install | bash',
' Grok CLI (paid): npm i -g @vibe-kit/grok-cli',
'WebSearch: no ready providers',
' Enable DuckDuckGo in Settings > WebSearch for zero-setup search',
' Or export EXA_API_KEY, TAVILY_API_KEY, or BRAVE_API_KEY for API-backed search',
' Optional legacy fallback: npm i -g @google/gemini-cli',
];
}
/**
* Get WebSearch readiness status for display
*
* Called on third-party profile startup to inform user.
* Checks both installation AND authentication status for Gemini CLI.
* Get WebSearch readiness status for display.
*/
export function getWebSearchReadiness(): WebSearchStatus {
const wsConfig = getWebSearchConfig();
const providers = getWebSearchCliProviders();
// Check if WebSearch is disabled entirely
if (!wsConfig.enabled) {
return {
readiness: 'unavailable',
geminiCli: false,
geminiAuthenticated: false,
grokCli: false,
opencodeCli: false,
message: 'Disabled in config',
providers,
};
}
// Check all CLIs
const geminiInstalled = hasGeminiCli();
const geminiAuthed = geminiInstalled && isGeminiAuthenticated();
const grokInstalled = hasGrokCli();
const opencodeInstalled = hasOpenCodeCli();
const enabledProviders = providers.filter((provider) => provider.enabled);
const readyProviders = enabledProviders.filter((provider) => provider.available);
// Build message based on installed + authenticated CLIs
const readyClis: string[] = [];
const needsAuthClis: string[] = [];
// Gemini requires auth check
if (geminiInstalled) {
if (geminiAuthed) {
readyClis.push('Gemini');
} else {
needsAuthClis.push('Gemini');
}
}
// Other CLIs don't require auth check (for now)
if (grokInstalled) readyClis.push('Grok');
if (opencodeInstalled) readyClis.push('OpenCode');
// Determine overall status
if (readyClis.length > 0) {
if (readyProviders.length > 0) {
return {
readiness: 'ready',
geminiCli: geminiInstalled,
geminiAuthenticated: geminiAuthed,
grokCli: grokInstalled,
opencodeCli: opencodeInstalled,
message: `Ready (${readyClis.join(' + ')})`,
message: `Ready (${readyProviders.map((provider) => provider.name).join(' + ')})`,
providers,
};
}
if (needsAuthClis.length > 0) {
if (enabledProviders.length > 0) {
return {
readiness: 'needs_auth',
geminiCli: geminiInstalled,
geminiAuthenticated: false,
grokCli: grokInstalled,
opencodeCli: opencodeInstalled,
message: `Gemini: run 'gemini' to login`,
readiness: 'needs_setup',
message: enabledProviders
.map((provider) => `${provider.name}: ${provider.detail}`)
.join(' | '),
providers,
};
}
return {
readiness: 'unavailable',
geminiCli: false,
geminiAuthenticated: false,
grokCli: false,
opencodeCli: false,
message: 'Install: npm i -g @google/gemini-cli',
message: 'Enable at least one provider in Settings > WebSearch',
providers,
};
}
/**
* Display WebSearch status (single line, equilibrium UX)
*
* Only call for third-party profiles.
* Shows detailed install hints when no CLI is installed.
* Display WebSearch status (single line, equilibrium UX).
*/
export function displayWebSearchStatus(): void {
const status = getWebSearchReadiness();
@@ -176,21 +233,13 @@ export function displayWebSearchStatus(): void {
case 'ready':
console.error(ok(`WebSearch: ${status.message}`));
break;
case 'needs_auth':
case 'needs_setup':
console.error(warn(`WebSearch: ${status.message}`));
break;
case 'unavailable':
console.error(fail(`WebSearch: ${status.message}`));
const hints = getCliInstallHints();
if (hints.length > 0) {
// First line gets [i] prefix, rest are continuation (indented, no prefix)
for (let i = 0; i < hints.length; i++) {
if (i === 0) {
console.error(info(hints[i]));
} else {
console.error(hints[i]);
}
}
for (const [index, hint] of getCliInstallHints().entries()) {
console.error(index === 0 ? info(hint) : hint);
}
break;
}
+46 -23
View File
@@ -1,7 +1,7 @@
/**
* WebSearch Type Definitions
*
* Contains all type definitions for WebSearch CLI providers and status.
* Contains all type definitions for WebSearch providers and status.
*
* @module utils/websearch/types
*/
@@ -29,46 +29,64 @@ export type OpenCodeCliStatus = ComponentStatus;
/**
* WebSearch availability status for third-party profiles
*/
export type WebSearchReadiness = 'ready' | 'needs_auth' | 'unavailable';
export type WebSearchReadiness = 'ready' | 'needs_setup' | 'unavailable';
/**
* WebSearch status for display
* WebSearch provider identifier
*/
export interface WebSearchStatus {
readiness: WebSearchReadiness;
geminiCli: boolean;
geminiAuthenticated: boolean;
grokCli: boolean;
opencodeCli: boolean;
message: string;
}
export type WebSearchProviderId =
| 'exa'
| 'tavily'
| 'duckduckgo'
| 'brave'
| 'gemini'
| 'grok'
| 'opencode';
/**
* WebSearch CLI provider information for health checks and UI
* Provider execution class.
*/
export type WebSearchProviderKind = 'backend' | 'legacy-cli';
/**
* WebSearch provider information for health checks and UI
*/
export interface WebSearchCliInfo {
/** Provider ID */
id: 'gemini' | 'grok' | 'opencode';
id: WebSearchProviderId;
/** Backend vs legacy CLI */
kind: WebSearchProviderKind;
/** Display name */
name: string;
/** CLI command name */
command: string;
/** Whether CLI is installed */
installed: boolean;
/** CLI version if installed */
/** Command name for legacy providers */
command?: string;
/** Whether the provider is enabled in config */
enabled: boolean;
/** Whether the provider is ready right now */
available: boolean;
/** CLI version if applicable */
version: string | null;
/** Install command */
installCommand: string;
/** Install or setup command when applicable */
installCommand?: string;
/** Docs URL */
docsUrl: string;
docsUrl?: string;
/** Whether this provider requires an API key */
requiresApiKey: boolean;
/** API key environment variable name */
apiKeyEnvVar?: string;
/** Brief description */
description: string;
/** Free tier available? */
freeTier: boolean;
/** Summary detail shown in status UIs */
detail: string;
}
/**
* WebSearch status for display
*/
export interface WebSearchStatus {
readiness: WebSearchReadiness;
message: string;
providers: WebSearchCliInfo[];
}
/**
@@ -78,6 +96,7 @@ export interface WebSearchProviderConfig {
enabled?: boolean;
model?: string;
timeout?: number;
max_results?: number;
}
/**
@@ -86,6 +105,10 @@ export interface WebSearchProviderConfig {
export interface WebSearchConfig {
enabled: boolean;
providers?: {
exa?: WebSearchProviderConfig;
tavily?: WebSearchProviderConfig;
duckduckgo?: WebSearchProviderConfig;
brave?: WebSearchProviderConfig;
gemini?: WebSearchProviderConfig;
opencode?: WebSearchProviderConfig;
grok?: WebSearchProviderConfig;
+2 -6
View File
@@ -145,12 +145,8 @@ export function fixHealthIssue(checkId: string): { success: boolean; message: st
// Use appropriate config based on unified mode
const { isUnifiedMode } = require('../config/unified-config-loader');
if (isUnifiedMode()) {
const {
loadOrCreateUnifiedConfig,
saveUnifiedConfig,
} = require('../config/unified-config-loader');
const config = loadOrCreateUnifiedConfig();
saveUnifiedConfig(config);
const { mutateUnifiedConfig } = require('../config/unified-config-loader');
mutateUnifiedConfig(() => {});
return { success: true, message: 'Created/updated config.yaml' };
}
const configPath = getConfigPath();
+9 -11
View File
@@ -1,7 +1,7 @@
/**
* WebSearch CLI Health Checks
* WebSearch Health Checks
*
* Check WebSearch CLI providers (Gemini CLI, Grok CLI).
* Check WebSearch providers (real backends + legacy fallback).
*/
import { getWebSearchCliProviders, hasAnyWebSearchCli } from '../../utils/websearch-manager';
@@ -15,37 +15,35 @@ export function checkWebSearchClis(): HealthCheck[] {
const checks: HealthCheck[] = [];
for (const provider of providers) {
if (provider.installed) {
const freeTag = provider.freeTier ? ' (FREE)' : '';
if (provider.enabled && provider.available) {
checks.push({
id: `websearch-${provider.id}`,
name: provider.name,
status: 'ok',
message: `v${provider.version || 'unknown'}${freeTag}`,
message: provider.detail,
details: provider.description,
});
} else {
const keyNote = provider.requiresApiKey ? ` (needs ${provider.apiKeyEnvVar})` : ' (FREE)';
checks.push({
id: `websearch-${provider.id}`,
name: provider.name,
status: 'info',
message: `Not installed${keyNote}`,
message: provider.enabled ? provider.detail : 'Disabled',
fix: provider.installCommand,
details: provider.description,
});
}
}
// Add summary check if no providers installed
// Add summary check if no providers are ready
if (!hasAnyWebSearchCli()) {
checks.push({
id: 'websearch-summary',
name: 'WebSearch Status',
status: 'warning',
message: 'No CLI tools installed',
fix: 'npm install -g @google/gemini-cli (FREE)',
details: 'Install a WebSearch CLI for real-time web access',
message: 'No ready provider',
fix: 'Enable DuckDuckGo or set EXA_API_KEY, TAVILY_API_KEY, or BRAVE_API_KEY',
details: 'Third-party profiles need a local WebSearch backend.',
});
}
@@ -132,3 +132,32 @@ export function authMiddleware(req: Request, res: Response, next: NextFunction):
// Unauthorized
res.status(401).json({ error: 'Authentication required' });
}
export function isLoopbackRemoteAddress(value: string | undefined): boolean {
if (!value) return false;
const normalized = value.trim().replace(/^\[|\]$/g, '');
return (
normalized === '::1' ||
normalized === '127.0.0.1' ||
normalized.startsWith('127.') ||
normalized === '::ffff:127.0.0.1' ||
normalized.startsWith('::ffff:127.')
);
}
export function requireLocalAccessWhenAuthDisabled(
req: Request,
res: Response,
error = 'This endpoint requires localhost access when dashboard auth is disabled.'
): boolean {
if (getDashboardAuthConfig().enabled) {
return true;
}
if (isLoopbackRemoteAddress(req.socket.remoteAddress)) {
return true;
}
res.status(403).json({ error });
return false;
}
+26 -13
View File
@@ -8,9 +8,22 @@ import {
type AiProviderFamilyId,
type UpsertAiProviderEntryInput,
} from '../../cliproxy/ai-providers';
import { requireLocalAccessWhenAuthDisabled } from '../middleware/auth-middleware';
const router = Router();
router.use((req: Request, res: Response, next) => {
if (
requireLocalAccessWhenAuthDisabled(
req,
res,
'AI provider endpoints require localhost access when dashboard auth is disabled.'
)
) {
next();
}
});
function isAiProviderFamilyId(value: string): value is AiProviderFamilyId {
return AI_PROVIDER_FAMILY_IDS.includes(value as AiProviderFamilyId);
}
@@ -24,13 +37,13 @@ function parseFamily(req: Request, res: Response): AiProviderFamilyId | null {
return family;
}
function parseIndex(req: Request, res: Response): number | null {
const index = Number.parseInt(req.params.index || '', 10);
if (!Number.isInteger(index) || index < 0) {
res.status(400).json({ error: 'Invalid entry index' });
function parseEntryId(req: Request, res: Response): string | null {
const entryId = req.params.entryId?.trim();
if (!entryId) {
res.status(400).json({ error: 'Invalid entry id' });
return null;
}
return index;
return entryId;
}
function parseInput(body: unknown): UpsertAiProviderEntryInput {
@@ -95,14 +108,14 @@ router.post('/:family', async (req: Request, res: Response) => {
}
});
router.put('/:family/:index', async (req: Request, res: Response) => {
router.put('/:family/:entryId', async (req: Request, res: Response) => {
const family = parseFamily(req, res);
if (!family) return;
const index = parseIndex(req, res);
if (index === null) return;
const entryId = parseEntryId(req, res);
if (!entryId) return;
try {
await updateAiProviderEntry(family, index, parseInput(req.body));
await updateAiProviderEntry(family, entryId, parseInput(req.body));
res.json({ success: true });
} catch (error) {
const message = (error as Error).message;
@@ -110,14 +123,14 @@ router.put('/:family/:index', async (req: Request, res: Response) => {
}
});
router.delete('/:family/:index', async (req: Request, res: Response) => {
router.delete('/:family/:entryId', async (req: Request, res: Response) => {
const family = parseFamily(req, res);
if (!family) return;
const index = parseIndex(req, res);
if (index === null) return;
const entryId = parseEntryId(req, res);
if (!entryId) return;
try {
await deleteAiProviderEntry(family, index);
await deleteAiProviderEntry(family, entryId);
res.json({ success: true });
} catch (error) {
const message = (error as Error).message;
+301 -36
View File
@@ -1,3 +1,5 @@
import * as fs from 'fs';
import * as path from 'path';
import { Router, Request, Response } from 'express';
import {
getAllAuthStatus,
@@ -22,6 +24,8 @@ import {
pauseAccount as pauseAccountFn,
resumeAccount as resumeAccountFn,
touchAccount,
extractAccountIdFromTokenFile,
hasAccountNameConflict,
PROVIDERS_WITHOUT_EMAIL,
validateNickname,
} from '../../cliproxy/account-manager';
@@ -33,7 +37,11 @@ import {
import { fetchRemoteAuthStatus } from '../../cliproxy/remote-auth-fetcher';
import { loadOrCreateUnifiedConfig } from '../../config/unified-config-loader';
import { tryKiroImport } from '../../cliproxy/auth/kiro-import';
import { getProviderTokenDir } from '../../cliproxy/auth/token-manager';
import {
getProviderTokenDir,
isTokenFileForProvider,
registerAccountFromToken,
} from '../../cliproxy/auth/token-manager';
import {
CLIPROXY_CALLBACK_PROVIDER_MAP,
CLIPROXY_AUTH_URL_PROVIDER_MAP,
@@ -51,14 +59,141 @@ import {
isAntigravityResponsibilityBypassEnabled,
} from '../../cliproxy/antigravity-responsibility';
import { createRouteErrorHelpers } from './route-helpers';
import { requireLocalAccessWhenAuthDisabled } from '../middleware/auth-middleware';
const router = Router();
const MANUAL_AUTH_STATE_TTL_MS = 10 * 60 * 1000;
type ProviderTokenSnapshot = {
file: string;
mtimeMs: number;
email?: string;
};
const pendingManualAuthState = new Map<
string,
{
nickname?: string;
expectedAccountId?: string;
createdAt: number;
knownTokenFiles: ProviderTokenSnapshot[];
}
>();
// Valid providers list - derived from canonical CLIPROXY_PROFILES
const validProviders: CLIProxyProvider[] = [...CLIPROXY_PROFILES];
const { respondInternalError } = createRouteErrorHelpers('cliproxy-auth-routes');
router.use((req: Request, res: Response, next) => {
if (
requireLocalAccessWhenAuthDisabled(
req,
res,
'CLIProxy auth endpoints require localhost access when dashboard auth is disabled.'
)
) {
next();
}
});
function pruneExpiredManualAuthState(now = Date.now()): void {
for (const [state, pending] of pendingManualAuthState.entries()) {
if (now - pending.createdAt > MANUAL_AUTH_STATE_TTL_MS) {
pendingManualAuthState.delete(state);
}
}
}
function rememberManualAuthState(
state: string,
pending: {
nickname?: string;
expectedAccountId?: string;
knownTokenFiles: ProviderTokenSnapshot[];
}
): void {
pruneExpiredManualAuthState();
pendingManualAuthState.set(state, {
...pending,
createdAt: Date.now(),
});
}
function getManualAuthState(state: string | undefined): {
nickname?: string;
expectedAccountId?: string;
createdAt: number;
knownTokenFiles: ProviderTokenSnapshot[];
} | null {
if (!state) {
return null;
}
pruneExpiredManualAuthState();
const pending = pendingManualAuthState.get(state);
if (!pending) {
return null;
}
return {
nickname: pending.nickname,
expectedAccountId: pending.expectedAccountId,
createdAt: pending.createdAt,
knownTokenFiles: pending.knownTokenFiles,
};
}
function listProviderTokenSnapshots(provider: CLIProxyProvider): ProviderTokenSnapshot[] {
const tokenDir = getProviderTokenDir(provider);
if (!fs.existsSync(tokenDir)) {
return [];
}
return fs
.readdirSync(tokenDir)
.filter((file) => file.endsWith('.json'))
.map((file): ProviderTokenSnapshot | null => {
const filePath = path.join(tokenDir, file);
if (!isTokenFileForProvider(filePath, provider)) {
return null;
}
let email: string | undefined;
try {
const content = fs.readFileSync(filePath, 'utf8');
const parsed = JSON.parse(content) as { email?: string };
email = typeof parsed.email === 'string' ? parsed.email : undefined;
} catch {
email = undefined;
}
const stats = fs.statSync(filePath);
return {
file,
mtimeMs: stats.mtimeMs,
email,
};
})
.filter((snapshot): snapshot is ProviderTokenSnapshot => snapshot !== null)
.sort((left, right) => right.mtimeMs - left.mtimeMs);
}
function findNewTokenSnapshotForPendingAuth(
provider: CLIProxyProvider,
pending: { knownTokenFiles: ProviderTokenSnapshot[] }
): ProviderTokenSnapshot | null {
const knownTokenMtimes = new Map(
pending.knownTokenFiles.map((snapshot) => [snapshot.file, snapshot.mtimeMs])
);
return (
listProviderTokenSnapshots(provider).find((snapshot) => {
const knownMtime = knownTokenMtimes.get(snapshot.file);
return knownMtime === undefined || snapshot.mtimeMs > knownMtime + 1;
}) || null
);
}
function parseKiroMethod(raw: unknown): { method: KiroAuthMethod; invalid: boolean } {
if (raw === undefined || raw === null) {
return { method: normalizeKiroAuthMethod(), invalid: false };
@@ -104,6 +239,41 @@ export function getStartAuthFailureMessage(provider: CLIProxyProvider): string {
return 'Authentication failed or was cancelled';
}
function getManualCallbackRegistrationError(provider: CLIProxyProvider): string {
if (PROVIDERS_WITHOUT_EMAIL.includes(provider)) {
return 'Authenticated token could not be matched to a new account. Retry the flow and choose a different nickname if needed.';
}
return 'Authenticated token could not be registered. Retry the flow.';
}
export function getStartAuthNicknameError(
provider: CLIProxyProvider,
nickname: string | undefined,
existingAccounts: Array<{ id: string; nickname?: string }>,
allowExistingAccountId?: string
): { error: string; code: 'INVALID_NICKNAME' | 'NICKNAME_EXISTS' } | null {
if (!PROVIDERS_WITHOUT_EMAIL.includes(provider) || !nickname) {
return null;
}
const validationError = validateNickname(nickname);
if (validationError) {
return {
error: validationError,
code: 'INVALID_NICKNAME',
};
}
if (hasAccountNameConflict(existingAccounts, nickname, allowExistingAccountId)) {
return {
error: `Nickname "${nickname}" is already in use. Choose a different one.`,
code: 'NICKNAME_EXISTS',
};
}
return null;
}
/**
* GET /api/cliproxy/auth - Get auth status for built-in CLIProxy profiles
* Also fetches CLIProxyAPI stats to update lastUsedAt for active providers
@@ -430,37 +600,15 @@ router.post('/:provider/start', async (req: Request, res: Response): Promise<voi
}
}
// For kiro/ghcp: nickname is required
if (PROVIDERS_WITHOUT_EMAIL.includes(provider as CLIProxyProvider)) {
if (!nickname) {
res.status(400).json({
error: `Nickname is required for ${provider} accounts. Please provide a unique nickname.`,
code: 'NICKNAME_REQUIRED',
});
return;
}
const validationError = validateNickname(nickname);
if (validationError) {
res.status(400).json({
error: validationError,
code: 'INVALID_NICKNAME',
});
return;
}
// Check uniqueness
const existingAccounts = getProviderAccounts(provider as CLIProxyProvider);
const existingNicknames = existingAccounts.map(
(a) => a.nickname?.toLowerCase() || a.id.toLowerCase()
);
if (existingNicknames.includes(nickname.toLowerCase())) {
res.status(400).json({
error: `Nickname "${nickname}" is already in use. Choose a different one.`,
code: 'NICKNAME_EXISTS',
});
return;
}
const existingAccounts = getProviderAccounts(provider as CLIProxyProvider);
const nicknameError = getStartAuthNicknameError(
provider as CLIProxyProvider,
nickname,
existingAccounts
);
if (nicknameError) {
res.status(400).json(nicknameError);
return;
}
// Check Kiro no-incognito setting from config (or request body)
@@ -625,7 +773,12 @@ router.post('/kiro/import', async (_req: Request, res: Response): Promise<void>
*/
router.post('/:provider/start-url', async (req: Request, res: Response): Promise<void> => {
const { provider } = req.params;
const { kiroMethod: kiroMethodRaw, riskAcknowledgement } = req.body ?? {};
const requestBody =
req.body && typeof req.body === 'object' ? (req.body as Record<string, unknown>) : {};
const nicknameRaw = typeof requestBody.nickname === 'string' ? requestBody.nickname : undefined;
const kiroMethodRaw = requestBody.kiroMethod;
const riskAcknowledgement = requestBody.riskAcknowledgement;
const nickname = nicknameRaw?.trim();
const { method: kiroMethod, invalid: invalidKiroMethod } = parseKiroMethod(kiroMethodRaw);
// Check remote mode
@@ -668,6 +821,17 @@ router.post('/:provider/start-url', async (req: Request, res: Response): Promise
return;
}
const existingAccounts = getProviderAccounts(provider as CLIProxyProvider);
const nicknameError = getStartAuthNicknameError(
provider as CLIProxyProvider,
nickname,
existingAccounts
);
if (nicknameError) {
res.status(400).json(nicknameError);
return;
}
try {
const authUrlProvider =
CLIPROXY_AUTH_URL_PROVIDER_MAP[provider as CLIProxyProvider] || provider;
@@ -696,19 +860,27 @@ router.post('/:provider/start-url', async (req: Request, res: Response): Promise
method?: string;
};
const authUrl = data.url || data.auth_url;
const oauthState = data.state || parseAuthUrlState(authUrl);
// Some upstream flows return state first and provide auth_url in subsequent status polling.
if (!authUrl && !data.state) {
if (!authUrl && !oauthState) {
res
.status(500)
.json({ error: 'No OAuth state or authorization URL received from CLIProxyAPI' });
return;
}
if (oauthState) {
rememberManualAuthState(oauthState, {
nickname: nickname || undefined,
knownTokenFiles: listProviderTokenSnapshots(provider as CLIProxyProvider),
});
}
res.json({
success: true,
authUrl: authUrl || null,
state: data.state || null,
state: oauthState,
method: data.method || null,
});
} catch (error) {
@@ -745,6 +917,59 @@ router.get('/:provider/status', async (req: Request, res: Response): Promise<voi
);
const data = (await response.json()) as { status?: string; error?: string };
if (data.status === 'ok') {
const localProvider = provider as CLIProxyProvider;
const pendingAuth = getManualAuthState(state);
if (!pendingAuth) {
res.status(409).json({
status: 'error',
error:
'Authentication completed upstream, but CCS could not match it to the active add-account session. Retry the flow from the dashboard.',
});
return;
}
const tokenSnapshot = findNewTokenSnapshotForPendingAuth(localProvider, pendingAuth);
if (!tokenSnapshot) {
res.status(409).json({
status: 'error',
error:
'Authentication completed upstream, but no new local token was saved for this account. Update CCS/CLIProxy and retry.',
});
return;
}
const account = registerAccountFromToken(
localProvider,
getProviderTokenDir(localProvider),
pendingAuth.nickname,
false,
extractAccountIdFromTokenFile(tokenSnapshot.file, tokenSnapshot.email)
);
if (!account) {
res.status(409).json({
status: 'error',
error: getManualCallbackRegistrationError(localProvider),
});
return;
}
pendingManualAuthState.delete(state);
res.json({
status: 'ok',
account: {
id: account.id,
email: account.email,
nickname: account.nickname,
provider: account.provider,
isDefault: account.isDefault,
},
});
return;
}
res.json(data);
} catch {
res.status(503).json({ status: 'error', error: 'CLIProxyAPI not reachable' });
@@ -768,6 +993,18 @@ function parseCallbackUrl(url: string): { code?: string; state?: string } {
}
}
function parseAuthUrlState(url: string | null | undefined): string | null {
if (!url) {
return null;
}
try {
return new URL(url).searchParams.get('state');
} catch {
return null;
}
}
/**
* POST /api/cliproxy/auth/:provider/submit-callback - Submit OAuth callback URL manually
* For cross-browser OAuth flows where callback cannot redirect directly
@@ -800,6 +1037,7 @@ router.post('/:provider/submit-callback', async (req: Request, res: Response): P
res.status(400).json({ error: 'Invalid callback URL: missing code parameter' });
return;
}
const pendingAuth = getManualAuthState(parsed.state);
try {
const callbackProvider =
@@ -824,7 +1062,34 @@ router.post('/:provider/submit-callback', async (req: Request, res: Response): P
return;
}
res.json({ success: true });
const account = registerAccountFromToken(
provider as CLIProxyProvider,
getProviderTokenDir(provider as CLIProxyProvider),
pendingAuth?.nickname,
false,
pendingAuth?.expectedAccountId
);
if (parsed.state) {
pendingManualAuthState.delete(parsed.state);
}
if (!account) {
res.status(409).json({
error: getManualCallbackRegistrationError(provider as CLIProxyProvider),
});
return;
}
res.json({
success: true,
account: {
id: account.id,
email: account.email,
nickname: account.nickname,
provider: account.provider,
isDefault: account.isDefault,
},
});
} catch (error) {
respondInternalError(res, error, 'CLIProxyAPI not reachable.', 503);
}
@@ -53,6 +53,7 @@ import {
getDeniedModelIdReasonForProvider,
} from '../../cliproxy/model-id-normalizer';
import { installDashboardCliproxyVersion } from '../services/cliproxy-dashboard-install-service';
import { requireLocalAccessWhenAuthDisabled } from '../middleware/auth-middleware';
const router = Router();
@@ -66,6 +67,18 @@ interface QuotaRateLimitEntry {
const quotaRateLimits = new Map<string, QuotaRateLimitEntry>();
router.use((req: Request, res: Response, next) => {
if (
requireLocalAccessWhenAuthDisabled(
req,
res,
'CLIProxy management endpoints require localhost access when dashboard auth is disabled.'
)
) {
next();
}
});
function buildQuotaRateLimitKey(req: Request, provider: string): string {
const clientIp = req.ip || req.socket.remoteAddress || 'unknown';
return `${clientIp}:${provider}`;
+7 -13
View File
@@ -3,7 +3,7 @@
*/
import { Router, Request, Response } from 'express';
import { loadOrCreateUnifiedConfig } from '../../config/unified-config-loader';
import { mutateUnifiedConfig } from '../../config/unified-config-loader';
import {
generateSyncPayload,
generateSyncPreview,
@@ -12,7 +12,6 @@ import {
syncToLocalConfig,
getLocalSyncStatus,
} from '../../cliproxy/sync';
import { saveUnifiedConfig } from '../../config/unified-config-loader';
const router = Router();
@@ -130,18 +129,13 @@ router.put('/auto-sync', async (req: Request, res: Response): Promise<void> => {
return;
}
// Update config
const config = loadOrCreateUnifiedConfig();
if (!config.cliproxy) {
// Should not happen as loadOrCreate initializes it, but handle gracefully
res.status(500).json({ error: 'CLIProxy config not initialized' });
return;
}
// Save config
try {
config.cliproxy.auto_sync = enabled;
saveUnifiedConfig(config);
mutateUnifiedConfig((config) => {
if (!config.cliproxy) {
throw new Error('CLIProxy config not initialized');
}
config.cliproxy.auto_sync = enabled;
});
} catch (error) {
res.status(500).json({ error: `Failed to save config: ${(error as Error).message}` });
return;
+42 -44
View File
@@ -9,11 +9,7 @@ import { promises as fsp } from 'fs';
import * as path from 'path';
import { getCcsDir } from '../../utils/config-manager';
import { DEFAULT_CURSOR_CONFIG } from '../../config/unified-config-types';
import {
loadOrCreateUnifiedConfig,
saveUnifiedConfig,
getCursorConfig,
} from '../../config/unified-config-loader';
import { mutateUnifiedConfig, getCursorConfig } from '../../config/unified-config-loader';
import type { CursorConfig } from '../../config/unified-config-types';
const router = Router();
@@ -184,36 +180,38 @@ router.put('/', async (req: Request, res: Response): Promise<void> => {
return;
}
const config = loadOrCreateUnifiedConfig();
const normalizedModel = parseRequiredModel(updates.model);
const config = mutateUnifiedConfig((currentConfig) => {
currentConfig.cursor = {
enabled: updates.enabled ?? currentConfig.cursor?.enabled ?? DEFAULT_CURSOR_CONFIG.enabled,
port: updates.port ?? currentConfig.cursor?.port ?? DEFAULT_CURSOR_CONFIG.port,
auto_start:
updates.auto_start ??
currentConfig.cursor?.auto_start ??
DEFAULT_CURSOR_CONFIG.auto_start,
ghost_mode:
updates.ghost_mode ??
currentConfig.cursor?.ghost_mode ??
DEFAULT_CURSOR_CONFIG.ghost_mode,
model: normalizedModel ?? currentConfig.cursor?.model ?? DEFAULT_CURSOR_CONFIG.model,
opus_model:
'opus_model' in updates
? parseOptionalModel(updates.opus_model)
: currentConfig.cursor?.opus_model,
sonnet_model:
'sonnet_model' in updates
? parseOptionalModel(updates.sonnet_model)
: currentConfig.cursor?.sonnet_model,
haiku_model:
'haiku_model' in updates
? parseOptionalModel(updates.haiku_model)
: currentConfig.cursor?.haiku_model,
};
});
// Merge updates with existing config
// Only known fields are merged — unknown properties are ignored
config.cursor = {
enabled: updates.enabled ?? config.cursor?.enabled ?? DEFAULT_CURSOR_CONFIG.enabled,
port: updates.port ?? config.cursor?.port ?? DEFAULT_CURSOR_CONFIG.port,
auto_start:
updates.auto_start ?? config.cursor?.auto_start ?? DEFAULT_CURSOR_CONFIG.auto_start,
ghost_mode:
updates.ghost_mode ?? config.cursor?.ghost_mode ?? DEFAULT_CURSOR_CONFIG.ghost_mode,
model: normalizedModel ?? config.cursor?.model ?? DEFAULT_CURSOR_CONFIG.model,
opus_model:
'opus_model' in updates
? parseOptionalModel(updates.opus_model)
: config.cursor?.opus_model,
sonnet_model:
'sonnet_model' in updates
? parseOptionalModel(updates.sonnet_model)
: config.cursor?.sonnet_model,
haiku_model:
'haiku_model' in updates
? parseOptionalModel(updates.haiku_model)
: config.cursor?.haiku_model,
};
saveUnifiedConfig(config);
await syncRawSettingsFromCursorConfig(config.cursor);
res.json({ success: true, cursor: config.cursor });
const cursorConfig = config.cursor ?? DEFAULT_CURSOR_CONFIG;
await syncRawSettingsFromCursorConfig(cursorConfig);
res.json({ success: true, cursor: cursorConfig });
} catch (error) {
res.status(500).json({ error: (error as Error).message });
}
@@ -295,19 +293,19 @@ router.put('/raw', (req: Request, res: Response): void => {
// Keep unified config aligned with raw settings edits (parity with Copilot raw editor).
const parsedPort = parseLocalCursorPort(settings);
const config = loadOrCreateUnifiedConfig();
const env = (settings as { env?: Record<string, unknown> }).env ?? {};
const model = parseRequiredModel(env.ANTHROPIC_MODEL) ?? config.cursor?.model;
mutateUnifiedConfig((config) => {
const model = parseRequiredModel(env.ANTHROPIC_MODEL) ?? config.cursor?.model;
config.cursor = {
...(config.cursor ?? DEFAULT_CURSOR_CONFIG),
...(parsedPort !== null ? { port: parsedPort } : {}),
...(model ? { model } : {}),
opus_model: parseOptionalModel(env.ANTHROPIC_DEFAULT_OPUS_MODEL),
sonnet_model: parseOptionalModel(env.ANTHROPIC_DEFAULT_SONNET_MODEL),
haiku_model: parseOptionalModel(env.ANTHROPIC_DEFAULT_HAIKU_MODEL),
};
saveUnifiedConfig(config);
config.cursor = {
...(config.cursor ?? DEFAULT_CURSOR_CONFIG),
...(parsedPort !== null ? { port: parsedPort } : {}),
...(model ? { model } : {}),
opus_model: parseOptionalModel(env.ANTHROPIC_DEFAULT_OPUS_MODEL),
sonnet_model: parseOptionalModel(env.ANTHROPIC_DEFAULT_SONNET_MODEL),
haiku_model: parseOptionalModel(env.ANTHROPIC_DEFAULT_HAIKU_MODEL),
};
});
const stat = fs.statSync(settingsPath);
res.json({ success: true, mtime: stat.mtimeMs });
+40 -29
View File
@@ -8,8 +8,6 @@ import * as path from 'path';
import { getCcsDir } from '../../utils/config-manager';
import { expandPath } from '../../utils/helpers';
import {
loadOrCreateUnifiedConfig,
saveUnifiedConfig,
mutateUnifiedConfig,
getGlobalEnvConfig,
getThinkingConfig,
@@ -24,9 +22,22 @@ import {
THINKING_OFF_VALUES,
} from '../../cliproxy';
import { validateFilePath } from './route-helpers';
import { requireLocalAccessWhenAuthDisabled } from '../middleware/auth-middleware';
const router = Router();
router.use((req: Request, res: Response, next) => {
if (
requireLocalAccessWhenAuthDisabled(
req,
res,
'Local configuration endpoints require localhost access when dashboard auth is disabled.'
)
) {
next();
}
});
export function resolveThinkingProviderOverridesForSave(
currentProviderOverrides: ThinkingConfig['provider_overrides'] | undefined,
updatesProviderOverrides: Record<string, Partial<ThinkingConfig['tier_defaults']>> | undefined,
@@ -304,14 +315,10 @@ router.put('/thinking', (req: Request, res: Response): void => {
}
}
const config = loadOrCreateUnifiedConfig();
const shouldClearOverride = clearOverrideFlag === true || updates.override === null;
const shouldClearProviderOverrides =
clearProviderOverridesFlag === true || updates.provider_overrides === null;
let normalizedOverride: string | number | undefined = config.thinking?.override as
| string
| number
| undefined;
let normalizedOverride: string | number | undefined;
let normalizedProviderOverrides:
| Record<string, Partial<ThinkingConfig['tier_defaults']>>
| undefined;
@@ -438,28 +445,32 @@ router.put('/thinking', (req: Request, res: Response): void => {
Object.keys(sanitizedOverrides).length > 0 ? sanitizedOverrides : undefined;
}
// Update thinking section
config.thinking = {
mode: updates.mode ?? config.thinking?.mode ?? 'auto',
override: shouldClearOverride
? undefined
: updates.override !== undefined
? normalizedOverride
: config.thinking?.override,
tier_defaults: {
opus: updates.tier_defaults?.opus ?? config.thinking?.tier_defaults?.opus ?? 'high',
sonnet: updates.tier_defaults?.sonnet ?? config.thinking?.tier_defaults?.sonnet ?? 'medium',
haiku: updates.tier_defaults?.haiku ?? config.thinking?.tier_defaults?.haiku ?? 'low',
},
provider_overrides: resolveThinkingProviderOverridesForSave(
config.thinking?.provider_overrides,
updates.provider_overrides !== undefined ? normalizedProviderOverrides : undefined,
shouldClearProviderOverrides
),
show_warnings: updates.show_warnings ?? config.thinking?.show_warnings ?? true,
};
saveUnifiedConfig(config);
const config = mutateUnifiedConfig((currentConfig) => {
currentConfig.thinking = {
mode: updates.mode ?? currentConfig.thinking?.mode ?? 'auto',
override: shouldClearOverride
? undefined
: updates.override !== undefined
? normalizedOverride
: currentConfig.thinking?.override,
tier_defaults: {
opus:
updates.tier_defaults?.opus ?? currentConfig.thinking?.tier_defaults?.opus ?? 'high',
sonnet:
updates.tier_defaults?.sonnet ??
currentConfig.thinking?.tier_defaults?.sonnet ??
'medium',
haiku:
updates.tier_defaults?.haiku ?? currentConfig.thinking?.tier_defaults?.haiku ?? 'low',
},
provider_overrides: resolveThinkingProviderOverridesForSave(
currentConfig.thinking?.provider_overrides,
updates.provider_overrides !== undefined ? normalizedProviderOverrides : undefined,
shouldClearProviderOverrides
),
show_warnings: updates.show_warnings ?? currentConfig.thinking?.show_warnings ?? true,
};
});
// W4: Return new mtime for subsequent requests
let newMtime: number | undefined;
+13
View File
@@ -17,9 +17,22 @@ import {
CliproxyServerConfig,
} from '../../config/unified-config-types';
import { CLIPROXY_PROVIDER_IDS } from '../../cliproxy/provider-capabilities';
import { requireLocalAccessWhenAuthDisabled } from '../middleware/auth-middleware';
const router = Router();
router.use((req: Request, res: Response, next) => {
if (
requireLocalAccessWhenAuthDisabled(
req,
res,
'CLIProxy server endpoints require localhost access when dashboard auth is disabled.'
)
) {
next();
}
});
/**
* GET /api/cliproxy-server - Get proxy configuration
*/
+175 -132
View File
@@ -6,6 +6,7 @@ import { Router, Request, Response } from 'express';
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
import * as lockfile from 'proper-lockfile';
import { getCcsDir, loadSettings } from '../../utils/config-manager';
import { isSensitiveKey, maskSensitiveValue } from '../../utils/sensitive-keys';
import { listVariants } from '../../cliproxy/services/variant-service';
@@ -20,11 +21,8 @@ import {
import { regenerateConfig } from '../../cliproxy/config-generator';
import { deduplicateCcsHooks } from '../../utils/websearch/hook-utils';
import { resolveCliproxyBridgeMetadata } from '../../api/services';
import {
getDashboardAuthConfig,
loadOrCreateUnifiedConfig,
mutateUnifiedConfig,
} from '../../config/unified-config-loader';
import { loadOrCreateUnifiedConfig, mutateUnifiedConfig } from '../../config/unified-config-loader';
import { requireLocalAccessWhenAuthDisabled } from '../middleware/auth-middleware';
import type { Settings } from '../../types/config';
import type { CLIProxyProvider } from '../../cliproxy/types';
import { mapExternalProviderName } from '../../cliproxy/provider-capabilities';
@@ -43,40 +41,25 @@ const MODEL_ENV_KEYS = [
'ANTHROPIC_DEFAULT_HAIKU_MODEL',
] as const;
const PRESET_MODEL_KEYS = ['default', 'opus', 'sonnet', 'haiku'] as const;
const SETTINGS_IDENTIFIER_PATTERN = /^[a-zA-Z][a-zA-Z0-9._-]*$/;
const { logRouteError, respondInternalError } = createRouteErrorHelpers('settings-routes');
function isLoopbackAddress(value: string | undefined): boolean {
if (!value) return false;
const normalized = value.trim().replace(/^\[|\]$/g, '');
return (
normalized === '::1' ||
normalized === '127.0.0.1' ||
normalized.startsWith('127.') ||
normalized === '::ffff:127.0.0.1' ||
normalized.startsWith('::ffff:127.')
);
function resolvePathWithin(basePath: string, targetPath: string): string {
const resolvedBase = path.resolve(basePath);
const resolvedTarget = path.resolve(targetPath);
if (resolvedTarget !== resolvedBase && !resolvedTarget.startsWith(`${resolvedBase}${path.sep}`)) {
throw new Error('Invalid settings path');
}
return resolvedTarget;
}
function requireSensitiveLocalAccess(req: Request, res: Response): boolean {
const dashboardAuth = getDashboardAuthConfig();
if (dashboardAuth.enabled) {
return true;
}
// Use only socket-level address for security decisions.
// X-Forwarded-For is trivially spoofable and must NOT be trusted
// without an explicit trust proxy configuration.
const candidateAddress = req.socket.remoteAddress;
if (isLoopbackAddress(candidateAddress)) {
return true;
}
res.status(403).json({
error: 'Sensitive settings endpoints require localhost access when dashboard auth is disabled.',
});
return false;
return requireLocalAccessWhenAuthDisabled(
req,
res,
'Sensitive settings endpoints require localhost access when dashboard auth is disabled.'
);
}
function classifyConfigSaveFailure(error: unknown): { statusCode: number; message: string } {
@@ -100,18 +83,26 @@ function classifyConfigSaveFailure(error: unknown): { statusCode: number; messag
* Variants have settings paths in config, regular profiles use {name}.settings.json
*/
function resolveSettingsPath(profileOrVariant: string): string {
if (!SETTINGS_IDENTIFIER_PATTERN.test(profileOrVariant)) {
throw new Error('Invalid profile name');
}
const ccsDir = getCcsDir();
const resolvedCcsDir = path.resolve(ccsDir);
// Check if this is a variant
const variants = listVariants();
const variant = variants[profileOrVariant];
if (variant?.settings) {
// Variant settings path (e.g., ~/.ccs/agy-g3.settings.json)
return variant.settings.replace(/^~/, os.homedir());
return resolvePathWithin(resolvedCcsDir, variant.settings.replace(/^~/, os.homedir()));
}
// Regular profile settings
return path.join(ccsDir, `${profileOrVariant}.settings.json`);
return resolvePathWithin(
resolvedCcsDir,
path.join(resolvedCcsDir, `${profileOrVariant}.settings.json`)
);
}
function resolveProviderForProfile(profileOrVariant: string): CLIProxyProvider | null {
@@ -261,11 +252,29 @@ function canonicalizeProfileSettings(profileOrVariant: string, settings: Setting
}
function writeSettingsAtomically(settingsPath: string, settings: Settings): void {
const tempPath = settingsPath + '.tmp';
const tempPath = `${settingsPath}.tmp.${process.pid}`;
fs.writeFileSync(tempPath, JSON.stringify(settings, null, 2) + '\n');
fs.renameSync(tempPath, settingsPath);
}
function withSettingsFileLock<T>(settingsPath: string, callback: () => T): T {
const lockTarget = fs.existsSync(settingsPath) ? settingsPath : path.dirname(settingsPath);
let release: (() => void) | undefined;
try {
release = lockfile.lockSync(lockTarget, { stale: 10000 }) as () => void;
return callback();
} finally {
if (release) {
try {
release();
} catch {
// Best-effort release
}
}
}
}
function loadCanonicalProfileSettings(
profileOrVariant: string,
settingsPath: string,
@@ -339,6 +348,8 @@ router.get('/:profile', (req: Request, res: Response): void => {
* GET /api/settings/:profile/raw - Get full settings (for editing)
*/
router.get('/:profile/raw', (req: Request, res: Response): void => {
if (!requireSensitiveLocalAccess(req, res)) return;
try {
const { profile } = req.params;
const settingsPath = resolveSettingsPath(profile);
@@ -379,6 +390,8 @@ function checkRequiredEnvVars(settings: Settings): string[] {
* PUT /api/settings/:profile - Update settings with conflict detection and backup
*/
router.put('/:profile', (req: Request, res: Response): void => {
if (!requireSensitiveLocalAccess(req, res)) return;
try {
const { profile } = req.params;
const { settings, expectedMtime } = req.body;
@@ -407,53 +420,56 @@ router.put('/:profile', (req: Request, res: Response): void => {
const missingFields = checkRequiredEnvVars(normalizedSettings);
const settingsPath = resolveSettingsPath(profile);
const fileExists = fs.existsSync(settingsPath);
// Only check conflict if file exists and expectedMtime was provided
if (fileExists && expectedMtime) {
const stat = fs.statSync(settingsPath);
if (stat.mtime.getTime() !== expectedMtime) {
res.status(409).json({
error: 'File modified externally',
currentMtime: stat.mtime.getTime(),
});
return;
}
}
// Create backup only if file exists AND content actually changed
let backupPath: string | undefined;
const newContent = JSON.stringify(normalizedSettings, null, 2) + '\n';
if (fileExists) {
const existingContent = fs.readFileSync(settingsPath, 'utf8');
// Only create backup if content differs
if (existingContent !== newContent) {
const backupDir = path.join(ccsDir, 'backups');
if (!fs.existsSync(backupDir)) {
fs.mkdirSync(backupDir, { recursive: true });
let created = false;
let newMtime = 0;
withSettingsFileLock(settingsPath, () => {
const fileExists = fs.existsSync(settingsPath);
if (fileExists && expectedMtime) {
const stat = fs.statSync(settingsPath);
if (stat.mtime.getTime() !== expectedMtime) {
res.status(409).json({
error: 'File modified externally',
currentMtime: stat.mtime.getTime(),
});
return;
}
const timestamp = new Date().toISOString().replace(/[:.]/g, '-');
backupPath = path.join(backupDir, `${profile}.${timestamp}.settings.json`);
fs.copyFileSync(settingsPath, backupPath);
}
const newContent = JSON.stringify(normalizedSettings, null, 2) + '\n';
if (fileExists) {
const existingContent = fs.readFileSync(settingsPath, 'utf8');
if (existingContent !== newContent) {
const backupDir = path.join(ccsDir, 'backups');
if (!fs.existsSync(backupDir)) {
fs.mkdirSync(backupDir, { recursive: true });
}
const timestamp = new Date().toISOString().replace(/[:.]/g, '-');
backupPath = path.join(backupDir, `${profile}.${timestamp}.settings.json`);
fs.copyFileSync(settingsPath, backupPath);
}
} else {
created = true;
fs.mkdirSync(path.dirname(settingsPath), { recursive: true });
}
const tempPath = `${settingsPath}.tmp.${process.pid}`;
fs.writeFileSync(tempPath, newContent);
fs.renameSync(tempPath, settingsPath);
newMtime = fs.statSync(settingsPath).mtime.getTime();
});
if (res.headersSent) {
return;
}
// Ensure directory exists for new files
if (!fileExists) {
fs.mkdirSync(path.dirname(settingsPath), { recursive: true });
}
// Write new settings atomically
const tempPath = settingsPath + '.tmp';
fs.writeFileSync(tempPath, newContent);
fs.renameSync(tempPath, settingsPath);
const newStat = fs.statSync(settingsPath);
res.json({
profile,
mtime: newStat.mtime.getTime(),
mtime: newMtime,
backupPath,
created: !fileExists,
created,
// Include warning if fields missing (runtime will use defaults)
...(missingFields.length > 0 && {
warning: `Missing fields will use defaults: ${missingFields.join(', ')}`,
@@ -491,6 +507,8 @@ router.get('/:profile/presets', (req: Request, res: Response): void => {
* POST /api/settings/:profile/presets - Create a new preset
*/
router.post('/:profile/presets', (req: Request, res: Response): void => {
if (!requireSensitiveLocalAccess(req, res)) return;
try {
const { profile } = req.params;
const { name, default: defaultModel, opus, sonnet, haiku } = req.body;
@@ -502,56 +520,65 @@ router.post('/:profile/presets', (req: Request, res: Response): void => {
const settingsPath = resolveSettingsPath(profile);
// Create settings file if it doesn't exist
if (!fs.existsSync(settingsPath)) {
fs.mkdirSync(path.dirname(settingsPath), { recursive: true });
fs.writeFileSync(settingsPath, JSON.stringify({ env: {}, presets: [] }, null, 2) + '\n');
}
let persistedPreset:
| {
name: string;
default: string;
opus: string;
sonnet: string;
haiku: string;
}
| undefined;
const settings = loadCanonicalProfileSettings(profile, settingsPath, false);
settings.presets = settings.presets || [];
withSettingsFileLock(settingsPath, () => {
if (!fs.existsSync(settingsPath)) {
fs.mkdirSync(path.dirname(settingsPath), { recursive: true });
fs.writeFileSync(settingsPath, JSON.stringify({ env: {}, presets: [] }, null, 2) + '\n');
}
// Check for duplicate name
if (settings.presets.some((p) => p.name === name)) {
res.status(409).json({ error: 'Preset with this name already exists' });
const settings = loadCanonicalProfileSettings(profile, settingsPath, false);
settings.presets = settings.presets || [];
if (settings.presets.some((p) => p.name === name)) {
res.status(409).json({ error: 'Preset with this name already exists' });
return;
}
const normalizePresetModel = (modelId: string): string =>
canonicalizeProfileModelId(profile, modelId, settings);
for (const modelId of [
defaultModel,
opus || defaultModel,
sonnet || defaultModel,
haiku || defaultModel,
]) {
const deniedReason = findDeniedProfileModel(profile, modelId, settings);
if (deniedReason) {
res.status(400).json({ error: deniedReason });
return;
}
}
const preset = {
name,
default: normalizePresetModel(defaultModel),
opus: normalizePresetModel(opus || defaultModel),
sonnet: normalizePresetModel(sonnet || defaultModel),
haiku: normalizePresetModel(haiku || defaultModel),
};
settings.presets.push(preset);
const canonicalizedSettings = canonicalizeProfileSettings(profile, settings);
writeSettingsAtomically(settingsPath, canonicalizedSettings);
persistedPreset =
canonicalizedSettings.presets?.find((entry) => entry.name === name) || preset;
});
if (res.headersSent) {
return;
}
const normalizePresetModel = (modelId: string): string =>
canonicalizeProfileModelId(profile, modelId, settings);
for (const modelId of [
defaultModel,
opus || defaultModel,
sonnet || defaultModel,
haiku || defaultModel,
]) {
const deniedReason = findDeniedProfileModel(profile, modelId, settings);
if (deniedReason) {
res.status(400).json({ error: deniedReason });
return;
}
}
const normalizedDefaultModel = normalizePresetModel(defaultModel);
const normalizedOpusModel = normalizePresetModel(opus || defaultModel);
const normalizedSonnetModel = normalizePresetModel(sonnet || defaultModel);
const normalizedHaikuModel = normalizePresetModel(haiku || defaultModel);
const preset = {
name,
default: normalizedDefaultModel,
opus: normalizedOpusModel,
sonnet: normalizedSonnetModel,
haiku: normalizedHaikuModel,
};
settings.presets.push(preset);
const canonicalizedSettings = canonicalizeProfileSettings(profile, settings);
writeSettingsAtomically(settingsPath, canonicalizedSettings);
const persistedPreset =
canonicalizedSettings.presets?.find((entry) => entry.name === name) || preset;
res.status(201).json({ preset: persistedPreset });
} catch (error) {
respondInternalError(res, error, 'Internal server error.');
@@ -562,25 +589,33 @@ router.post('/:profile/presets', (req: Request, res: Response): void => {
* DELETE /api/settings/:profile/presets/:name - Delete a preset
*/
router.delete('/:profile/presets/:name', (req: Request, res: Response): void => {
if (!requireSensitiveLocalAccess(req, res)) return;
try {
const { profile, name } = req.params;
const settingsPath = resolveSettingsPath(profile);
if (!fs.existsSync(settingsPath)) {
res.status(404).json({ error: 'Settings not found' });
withSettingsFileLock(settingsPath, () => {
if (!fs.existsSync(settingsPath)) {
res.status(404).json({ error: 'Settings not found' });
return;
}
const settings = loadCanonicalProfileSettings(profile, settingsPath, false);
if (!settings.presets || !settings.presets.some((p) => p.name === name)) {
res.status(404).json({ error: 'Preset not found' });
return;
}
settings.presets = settings.presets.filter((p) => p.name !== name);
const canonicalizedSettings = canonicalizeProfileSettings(profile, settings);
writeSettingsAtomically(settingsPath, canonicalizedSettings);
});
if (res.headersSent) {
return;
}
const settings = loadCanonicalProfileSettings(profile, settingsPath, false);
if (!settings.presets || !settings.presets.some((p) => p.name === name)) {
res.status(404).json({ error: 'Preset not found' });
return;
}
settings.presets = settings.presets.filter((p) => p.name !== name);
const canonicalizedSettings = canonicalizeProfileSettings(profile, settings);
writeSettingsAtomically(settingsPath, canonicalizedSettings);
res.json({ success: true });
} catch (error) {
respondInternalError(res, error, 'Internal server error.');
@@ -642,6 +677,8 @@ router.put('/auth/antigravity-risk', (req: Request, res: Response): void => {
* GET /api/settings/auth/tokens - Get current auth token status (masked)
*/
router.get('/auth/tokens', (_req: Request, res: Response): void => {
if (!requireSensitiveLocalAccess(_req, res)) return;
try {
const summary = getAuthSummary();
@@ -692,6 +729,8 @@ router.get('/auth/tokens/raw', (req: Request, res: Response): void => {
* PUT /api/settings/auth/tokens - Update auth tokens
*/
router.put('/auth/tokens', (req: Request, res: Response): void => {
if (!requireSensitiveLocalAccess(req, res)) return;
try {
const { apiKey, managementSecret } = req.body;
@@ -728,6 +767,8 @@ router.put('/auth/tokens', (req: Request, res: Response): void => {
* POST /api/settings/auth/tokens/regenerate-secret - Generate new management secret
*/
router.post('/auth/tokens/regenerate-secret', (_req: Request, res: Response): void => {
if (!requireSensitiveLocalAccess(_req, res)) return;
try {
const newSecret = generateSecureToken(32);
setGlobalManagementSecret(newSecret);
@@ -752,6 +793,8 @@ router.post('/auth/tokens/regenerate-secret', (_req: Request, res: Response): vo
* POST /api/settings/auth/tokens/reset - Reset auth tokens to defaults
*/
router.post('/auth/tokens/reset', (_req: Request, res: Response): void => {
if (!requireSensitiveLocalAccess(_req, res)) return;
try {
resetAuthToDefaults();
+81 -85
View File
@@ -3,24 +3,15 @@
*/
import { Router, Request, Response } from 'express';
import {
loadUnifiedConfig,
saveUnifiedConfig,
getWebSearchConfig,
} from '../../config/unified-config-loader';
import { mutateUnifiedConfig, getWebSearchConfig } from '../../config/unified-config-loader';
import type { WebSearchConfig } from '../../config/unified-config-types';
import {
getWebSearchReadiness,
getGeminiCliStatus,
getGrokCliStatus,
getOpenCodeCliStatus,
} from '../../utils/websearch-manager';
import { getWebSearchReadiness, getWebSearchCliProviders } from '../../utils/websearch-manager';
const router = Router();
/**
* GET /api/websearch - Get WebSearch configuration
* Returns: WebSearchConfig with enabled, provider, fallback
* Returns: normalized WebSearch configuration
*/
router.get('/', (_req: Request, res: Response): void => {
try {
@@ -34,7 +25,6 @@ router.get('/', (_req: Request, res: Response): void => {
/**
* PUT /api/websearch - Update WebSearch configuration
* Body: WebSearchConfig fields (enabled, providers)
* Dashboard is the source of truth for provider selection.
*/
router.put('/', (req: Request, res: Response): void => {
const { enabled, providers } = req.body as Partial<WebSearchConfig>;
@@ -52,59 +42,81 @@ router.put('/', (req: Request, res: Response): void => {
}
try {
// Load existing config and update websearch section
const existingConfig = loadUnifiedConfig();
if (!existingConfig) {
res.status(500).json({ error: 'Failed to load config' });
return;
}
// Merge updates - supports Gemini CLI and Grok CLI
existingConfig.websearch = {
enabled: enabled ?? existingConfig.websearch?.enabled ?? true,
providers: providers
? {
gemini: {
enabled:
providers.gemini?.enabled ??
existingConfig.websearch?.providers?.gemini?.enabled ??
true,
model:
providers.gemini?.model ??
existingConfig.websearch?.providers?.gemini?.model ??
'gemini-2.5-flash',
timeout:
providers.gemini?.timeout ??
existingConfig.websearch?.providers?.gemini?.timeout ??
55,
},
grok: {
enabled:
providers.grok?.enabled ??
existingConfig.websearch?.providers?.grok?.enabled ??
false,
timeout:
providers.grok?.timeout ?? existingConfig.websearch?.providers?.grok?.timeout ?? 55,
},
opencode: {
enabled:
providers.opencode?.enabled ??
existingConfig.websearch?.providers?.opencode?.enabled ??
false,
model:
providers.opencode?.model ??
existingConfig.websearch?.providers?.opencode?.model ??
'opencode/grok-code',
timeout:
providers.opencode?.timeout ??
existingConfig.websearch?.providers?.opencode?.timeout ??
60,
},
}
: existingConfig.websearch?.providers,
};
saveUnifiedConfig(existingConfig);
const existingConfig = mutateUnifiedConfig((config) => {
config.websearch = {
enabled: enabled ?? config.websearch?.enabled ?? true,
providers: providers
? {
exa: {
enabled:
providers.exa?.enabled ?? config.websearch?.providers?.exa?.enabled ?? false,
max_results:
providers.exa?.max_results ?? config.websearch?.providers?.exa?.max_results ?? 5,
},
tavily: {
enabled:
providers.tavily?.enabled ??
config.websearch?.providers?.tavily?.enabled ??
false,
max_results:
providers.tavily?.max_results ??
config.websearch?.providers?.tavily?.max_results ??
5,
},
duckduckgo: {
enabled:
providers.duckduckgo?.enabled ??
config.websearch?.providers?.duckduckgo?.enabled ??
true,
max_results:
providers.duckduckgo?.max_results ??
config.websearch?.providers?.duckduckgo?.max_results ??
5,
},
brave: {
enabled:
providers.brave?.enabled ?? config.websearch?.providers?.brave?.enabled ?? false,
max_results:
providers.brave?.max_results ??
config.websearch?.providers?.brave?.max_results ??
5,
},
gemini: {
enabled:
providers.gemini?.enabled ??
config.websearch?.providers?.gemini?.enabled ??
false,
model:
providers.gemini?.model ??
config.websearch?.providers?.gemini?.model ??
'gemini-2.5-flash',
timeout:
providers.gemini?.timeout ?? config.websearch?.providers?.gemini?.timeout ?? 55,
},
grok: {
enabled:
providers.grok?.enabled ?? config.websearch?.providers?.grok?.enabled ?? false,
timeout:
providers.grok?.timeout ?? config.websearch?.providers?.grok?.timeout ?? 55,
},
opencode: {
enabled:
providers.opencode?.enabled ??
config.websearch?.providers?.opencode?.enabled ??
false,
model:
providers.opencode?.model ??
config.websearch?.providers?.opencode?.model ??
'opencode/grok-code',
timeout:
providers.opencode?.timeout ??
config.websearch?.providers?.opencode?.timeout ??
60,
},
}
: config.websearch?.providers,
};
});
res.json({
success: true,
@@ -117,31 +129,15 @@ router.put('/', (req: Request, res: Response): void => {
/**
* GET /api/websearch/status - Get WebSearch status
* Returns: { geminiCli, grokCli, opencodeCli, readiness }
* Returns: provider readiness + normalized provider status list
*/
router.get('/status', (_req: Request, res: Response): void => {
try {
const geminiCli = getGeminiCliStatus();
const grokCli = getGrokCliStatus();
const opencodeCli = getOpenCodeCliStatus();
const readiness = getWebSearchReadiness();
const providers = getWebSearchCliProviders();
res.json({
geminiCli: {
installed: geminiCli.installed,
path: geminiCli.path,
version: geminiCli.version,
},
grokCli: {
installed: grokCli.installed,
path: grokCli.path,
version: grokCli.version,
},
opencodeCli: {
installed: opencodeCli.installed,
path: opencodeCli.path,
version: opencodeCli.version,
},
providers,
readiness: {
status: readiness.readiness,
message: readiness.message,
+13
View File
@@ -10,9 +10,22 @@ import * as path from 'path';
import * as yaml from 'js-yaml';
import { getCcsDir } from '../utils/config-manager';
import { getClaudeConfigDir } from '../utils/claude-config-path';
import { requireLocalAccessWhenAuthDisabled } from './middleware/auth-middleware';
export const sharedRoutes = Router();
sharedRoutes.use((req: Request, res: Response, next) => {
if (
requireLocalAccessWhenAuthDisabled(
req,
res,
'Shared-content endpoints require localhost access when dashboard auth is disabled.'
)
) {
next();
}
});
const MAX_DIRECTORY_TRAVERSAL_DEPTH = 10;
const MAX_DESCRIPTION_LENGTH = 140;
const MAX_MARKDOWN_FILE_BYTES = 1024 * 1024; // 1 MiB
+17 -1
View File
@@ -129,7 +129,23 @@ describe('cross-platform', () => {
assert(packageJson.bin, 'package.json should have bin field');
assert(packageJson.bin.ccs, 'bin field should specify ccs command');
assert(packageJson.bin['ccs-droid'], 'bin field should specify ccs-droid command');
assert(packageJson.bin.ccsd, 'bin field should specify ccsd command');
assert.notStrictEqual(
packageJson.bin['ccs-droid'],
packageJson.bin.ccs,
'ccs-droid should use a dedicated runtime entrypoint'
);
assert.strictEqual(
packageJson.bin['ccs-droid'],
packageJson.bin.ccsd,
'legacy ccsd alias should share the dedicated droid runtime entrypoint'
);
assert(
fs.existsSync(path.join(__dirname, '..', '..', packageJson.bin['ccs-droid'])),
'dedicated droid runtime entrypoint should exist'
);
assert(packageJson.scripts, 'package.json should have scripts field');
});
});
});
});
@@ -0,0 +1,102 @@
import { describe, expect, it } from 'bun:test';
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
import { runWithScopedCcsHome } from '../../../src/utils/config-manager';
async function withIsolatedHome<T>(fn: (homeDir: string) => Promise<T> | T): Promise<T> {
const homeDir = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-account-registry-'));
try {
return await runWithScopedCcsHome(homeDir, () => fn(homeDir));
} finally {
fs.rmSync(homeDir, { recursive: true, force: true });
}
}
async function loadRegistryModule() {
return import(`../../../src/cliproxy/accounts/registry?registry-integrity=${Date.now()}`);
}
async function loadAccountManager() {
return import(`../../../src/cliproxy/account-manager?account-registry-integrity=${Date.now()}`);
}
describe('account registry integrity', () => {
it('does not create accounts.json during no-op discovery', async () => {
await withIsolatedHome(async (homeDir) => {
const authDir = path.join(homeDir, '.ccs', 'cliproxy', 'auth');
const registryPath = path.join(homeDir, '.ccs', 'cliproxy', 'accounts.json');
fs.mkdirSync(authDir, { recursive: true });
const { discoverExistingAccounts } = await loadRegistryModule();
discoverExistingAccounts();
expect(fs.existsSync(registryPath)).toBe(false);
});
});
it('does not write accounts.json during provider account reads', async () => {
await withIsolatedHome(async (homeDir) => {
const authDir = path.join(homeDir, '.ccs', 'cliproxy', 'auth');
const registryPath = path.join(homeDir, '.ccs', 'cliproxy', 'accounts.json');
fs.mkdirSync(authDir, { recursive: true });
const { getProviderAccounts } = await loadAccountManager();
expect(getProviderAccounts('kiro')).toEqual([]);
expect(fs.existsSync(registryPath)).toBe(false);
});
});
it('removes stale accounts before choosing the next default during registration', async () => {
await withIsolatedHome(async (homeDir) => {
const cliproxyDir = path.join(homeDir, '.ccs', 'cliproxy');
const authDir = path.join(cliproxyDir, 'auth');
const registryPath = path.join(cliproxyDir, 'accounts.json');
fs.mkdirSync(authDir, { recursive: true });
fs.writeFileSync(path.join(authDir, 'kiro-github-ABC123.json'), JSON.stringify({ type: 'kiro' }));
fs.writeFileSync(
registryPath,
JSON.stringify({
version: 1,
providers: {
kiro: {
default: 'github-OLD999',
accounts: {
'github-OLD999': {
nickname: 'old',
tokenFile: 'kiro-github-OLD999.json',
createdAt: '2025-01-01T00:00:00.000Z',
lastUsedAt: '2025-01-01T00:00:00.000Z',
},
},
},
},
}),
'utf8'
);
const { registerAccount } = await loadAccountManager();
const account = registerAccount('kiro', 'kiro-github-ABC123.json');
const { loadAccountsRegistry } = await loadRegistryModule();
const registry = loadAccountsRegistry();
const kiroAccounts = registry.providers.kiro;
expect(account.id).toBe('github-ABC123');
expect(kiroAccounts?.default).toBe('github-ABC123');
expect(kiroAccounts?.accounts['github-OLD999']).toBeUndefined();
expect(Object.keys(kiroAccounts?.accounts ?? {})).toEqual(['github-ABC123']);
});
});
it('fails closed on corrupted accounts.json', async () => {
await withIsolatedHome(async (homeDir) => {
const registryPath = path.join(homeDir, '.ccs', 'cliproxy', 'accounts.json');
fs.mkdirSync(path.dirname(registryPath), { recursive: true });
fs.writeFileSync(registryPath, '{not-valid-json', 'utf8');
const { loadAccountsRegistry } = await loadRegistryModule();
expect(() => loadAccountsRegistry()).toThrow(/corrupted/i);
});
});
});
@@ -0,0 +1,119 @@
import { describe, expect, it } from 'bun:test';
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
import { runWithScopedCcsHome } from '../../../src/utils/config-manager';
async function loadAccountManager() {
return import(`../../../src/cliproxy/account-manager?optional-nickname=${Date.now()}`);
}
function writeTokenFile(homeDir: string, tokenFile: string): void {
const authDir = path.join(homeDir, '.ccs', 'cliproxy', 'auth');
fs.mkdirSync(authDir, { recursive: true });
fs.writeFileSync(path.join(authDir, tokenFile), '{}', 'utf8');
}
async function withIsolatedHome<T>(fn: (homeDir: string) => Promise<T> | T): Promise<T> {
const testDir = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-optional-nickname-'));
try {
return await runWithScopedCcsHome(testDir, () => fn(testDir));
} finally {
fs.rmSync(testDir, { recursive: true, force: true });
}
}
describe('registerAccount optional nickname flow', () => {
it('uses a filename-derived id when Kiro/GHCP nickname is omitted', async () => {
const account = await withIsolatedHome(async (homeDir) => {
writeTokenFile(homeDir, 'kiro-github-ABC123.json');
const { registerAccount } = await loadAccountManager();
return registerAccount('kiro', 'kiro-github-ABC123.json');
});
expect(account.id).toBe('github-ABC123');
expect(account.nickname).toBe('github-ABC123');
});
it('falls back to provider-scoped sequential ids when the filename is not descriptive', async () => {
const { first, second } = await withIsolatedHome(async (homeDir) => {
writeTokenFile(homeDir, 'kiro-nomail.json');
writeTokenFile(homeDir, 'kiro-second.json');
const { registerAccount } = await loadAccountManager();
return {
first: registerAccount('kiro', 'kiro-nomail.json'),
second: registerAccount('kiro', 'kiro-second.json'),
};
});
expect(first.id).toBe('kiro-1');
expect(first.nickname).toBe('kiro-1');
expect(second.id).toBe('kiro-2');
expect(second.nickname).toBe('kiro-2');
});
it('keeps user nicknames optional metadata separate from internal ids', async () => {
const account = await withIsolatedHome(async (homeDir) => {
writeTokenFile(homeDir, 'ghcp-amazon-XYZ789.json');
const { registerAccount } = await loadAccountManager();
return registerAccount('ghcp', 'ghcp-amazon-XYZ789.json', undefined, 'work');
});
expect(account.id).toBe('amazon-XYZ789');
expect(account.nickname).toBe('work');
});
it('preserves an existing custom nickname when the same token file is re-registered', async () => {
const reauthenticated = await withIsolatedHome(async (homeDir) => {
writeTokenFile(homeDir, 'kiro-github-ABC123.json');
const { registerAccount } = await loadAccountManager();
registerAccount('kiro', 'kiro-github-ABC123.json', undefined, 'work');
return registerAccount('kiro', 'kiro-github-ABC123.json');
});
expect(reauthenticated.id).toBe('github-ABC123');
expect(reauthenticated.nickname).toBe('work');
});
it('rejects nickname collisions against existing account ids and nicknames', async () => {
await withIsolatedHome(async (homeDir) => {
writeTokenFile(homeDir, 'kiro-github-ABC123.json');
writeTokenFile(homeDir, 'kiro-google-XYZ789.json');
writeTokenFile(homeDir, 'kiro-google-NEW123.json');
const { registerAccount, renameAccount } = await loadAccountManager();
registerAccount('kiro', 'kiro-github-ABC123.json');
const second = registerAccount('kiro', 'kiro-google-XYZ789.json', undefined, 'personal');
expect(() =>
registerAccount('kiro', 'kiro-google-NEW123.json', undefined, 'github-ABC123')
).toThrow(/already exists/i);
expect(() => renameAccount('kiro', second.id, 'github-ABC123')).toThrow(/already used/i);
});
});
it('avoids auto-generated ids that would collide with an existing nickname', async () => {
const added = await withIsolatedHome(async (homeDir) => {
writeTokenFile(homeDir, 'kiro-github-ABC123.json');
writeTokenFile(homeDir, 'kiro-google-XYZ789.json');
const { registerAccount } = await loadAccountManager();
registerAccount('kiro', 'kiro-github-ABC123.json', undefined, 'google-XYZ789');
return registerAccount('kiro', 'kiro-google-XYZ789.json');
});
expect(added.id).toBe('kiro-1');
expect(added.nickname).toBe('kiro-1');
});
it('does not resolve ambiguous nickname prefixes to the first generated account', async () => {
const match = await withIsolatedHome(async (homeDir) => {
writeTokenFile(homeDir, 'kiro-github-ABC123.json');
writeTokenFile(homeDir, 'kiro-github-DEF456.json');
const { registerAccount, findAccountByQuery } = await loadAccountManager();
registerAccount('kiro', 'kiro-github-ABC123.json');
registerAccount('kiro', 'kiro-github-DEF456.json');
return findAccountByQuery('kiro', 'github');
});
expect(match).toBeNull();
});
});
@@ -0,0 +1,147 @@
import { afterEach, beforeEach, describe, expect, it } from 'bun:test';
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
import * as yaml from 'js-yaml';
function getCliproxyConfigPath(homeDir: string): string {
return path.join(homeDir, '.ccs', 'cliproxy', 'config.yaml');
}
function writeCliproxyConfig(homeDir: string, value: Record<string, unknown>): void {
const configPath = getCliproxyConfigPath(homeDir);
fs.mkdirSync(path.dirname(configPath), { recursive: true });
fs.writeFileSync(configPath, yaml.dump(value), 'utf8');
}
function readCliproxyConfig(homeDir: string): Record<string, any> {
return (
(yaml.load(fs.readFileSync(getCliproxyConfigPath(homeDir), 'utf8')) as Record<string, any>) || {}
);
}
async function loadAiProviderService() {
return import(`../../../src/cliproxy/ai-providers/service?stable-id=${Date.now()}`);
}
describe('ai-provider service stable ids', () => {
let tempHome = '';
let originalCcsHome: string | undefined;
beforeEach(() => {
tempHome = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-ai-provider-ids-'));
originalCcsHome = process.env.CCS_HOME;
process.env.CCS_HOME = tempHome;
});
afterEach(() => {
if (originalCcsHome !== undefined) {
process.env.CCS_HOME = originalCcsHome;
} else {
delete process.env.CCS_HOME;
}
if (tempHome && fs.existsSync(tempHome)) {
fs.rmSync(tempHome, { recursive: true, force: true });
}
});
it('backfills and persists stable ids for api-key provider entries', async () => {
const { listAiProviders } = await loadAiProviderService();
writeCliproxyConfig(tempHome, {
'gemini-api-key': [{ 'api-key': 'alpha' }, { 'api-key': 'beta' }],
});
const listed = await listAiProviders();
const family = listed.families.find((entry) => entry.id === 'gemini-api-key');
expect(family).toBeDefined();
expect(family?.entries).toHaveLength(2);
expect(family?.entries[0]?.id).toBeTruthy();
expect(family?.entries[1]?.id).toBeTruthy();
expect(family?.entries[0]?.id).not.toBe(family?.entries[1]?.id);
const persisted = readCliproxyConfig(tempHome)['gemini-api-key'] as Array<Record<string, unknown>>;
expect(persisted[0]?.id).toBe(family?.entries[0]?.id);
expect(persisted[1]?.id).toBe(family?.entries[1]?.id);
});
it('updates and deletes api-key entries by stable id while preserving the id', async () => {
const { updateAiProviderEntry, deleteAiProviderEntry } = await loadAiProviderService();
writeCliproxyConfig(tempHome, {
'gemini-api-key': [
{ 'api-key': 'alpha', id: 'gemini-a' },
{ 'api-key': 'beta', id: 'gemini-b' },
],
});
await updateAiProviderEntry('gemini-api-key', 'gemini-a', {
apiKey: 'gamma',
baseUrl: 'https://example.test/gemini',
});
let persisted = readCliproxyConfig(tempHome)['gemini-api-key'] as Array<Record<string, unknown>>;
expect(persisted[0]?.id).toBe('gemini-a');
expect(persisted[0]?.['api-key']).toBe('gamma');
expect(persisted[0]?.['base-url']).toBe('https://example.test/gemini');
await deleteAiProviderEntry('gemini-api-key', 'gemini-a');
persisted = readCliproxyConfig(tempHome)['gemini-api-key'] as Array<Record<string, unknown>>;
expect(persisted).toHaveLength(1);
expect(persisted[0]?.id).toBe('gemini-b');
});
it('keeps legacy numeric index updates working during the route transition', async () => {
const { updateAiProviderEntry } = await loadAiProviderService();
writeCliproxyConfig(tempHome, {
'gemini-api-key': [{ 'api-key': 'alpha', id: 'gemini-a' }],
});
await updateAiProviderEntry('gemini-api-key', '0', {
apiKey: 'legacy-index-update',
});
const persisted = readCliproxyConfig(tempHome)['gemini-api-key'] as Array<Record<string, unknown>>;
expect(persisted[0]?.id).toBe('gemini-a');
expect(persisted[0]?.['api-key']).toBe('legacy-index-update');
});
it('backfills and preserves stable ids for openai-compatible connectors', async () => {
const { listAiProviders, updateAiProviderEntry } = await loadAiProviderService();
writeCliproxyConfig(tempHome, {
'openai-compatibility': [
{
name: 'openrouter',
'base-url': 'https://openrouter.ai/api/v1',
'api-key-entries': [{ 'api-key': 'sk-openrouter' }],
},
],
});
const listed = await listAiProviders();
const family = listed.families.find((entry) => entry.id === 'openai-compatibility');
const connectorId = family?.entries[0]?.id;
expect(connectorId).toBeTruthy();
await updateAiProviderEntry('openai-compatibility', connectorId!, {
name: 'openrouter',
baseUrl: 'https://router.example/v1',
preserveSecrets: true,
});
const persisted = readCliproxyConfig(tempHome)['openai-compatibility'] as Array<
Record<string, unknown>
>;
expect(persisted[0]?.id).toBe(connectorId);
expect(persisted[0]?.['base-url']).toBe('https://router.example/v1');
expect((persisted[0]?.['api-key-entries'] as Array<Record<string, unknown>>)[0]?.['api-key']).toBe(
'sk-openrouter'
);
});
});
@@ -102,3 +102,54 @@ describe('resolvePasteCallbackAuthUrl', () => {
expect(request.headers['Authorization']).toBe('Bearer test-mgmt-key');
});
});
describe('getCliAuthNicknameError', () => {
it('allows omitted nicknames for no-email providers', async () => {
const { getCliAuthNicknameError } = await import(
`../../../src/cliproxy/auth/oauth-handler?cli-nickname-empty=${Date.now()}`
);
expect(getCliAuthNicknameError('kiro', undefined, [])).toBeNull();
expect(getCliAuthNicknameError('ghcp', undefined, [])).toBeNull();
});
it('rejects invalid supplied nicknames before OAuth starts', async () => {
const { getCliAuthNicknameError } = await import(
`../../../src/cliproxy/auth/oauth-handler?cli-nickname-invalid=${Date.now()}`
);
expect(getCliAuthNicknameError('kiro', 'bad nickname', [])).toBe(
'Nickname cannot contain whitespace'
);
});
it('rejects supplied nicknames that collide with existing ids or nicknames', async () => {
const { getCliAuthNicknameError } = await import(
`../../../src/cliproxy/auth/oauth-handler?cli-nickname-conflict=${Date.now()}`
);
const existingAccounts = [
{ id: 'github-ABC123', nickname: 'work' },
{ id: 'ghcp-2', nickname: 'personal' },
];
expect(getCliAuthNicknameError('ghcp', 'github-ABC123', existingAccounts)).toBe(
'Nickname "github-ABC123" is already in use. Choose a different one.'
);
expect(getCliAuthNicknameError('ghcp', 'work', existingAccounts)).toBe(
'Nickname "work" is already in use. Choose a different one.'
);
});
it('allows reauth when the supplied nickname already belongs to the same account', async () => {
const { getCliAuthNicknameError } = await import(
`../../../src/cliproxy/auth/oauth-handler?cli-nickname-reauth=${Date.now()}`
);
const existingAccounts = [
{ id: 'github-ABC123', nickname: 'work' },
{ id: 'amazon-XYZ789', nickname: 'personal' },
];
expect(getCliAuthNicknameError('kiro', 'work', existingAccounts, 'github-ABC123')).toBeNull();
expect(getCliAuthNicknameError('kiro', 'github-ABC123', existingAccounts, 'github-ABC123')).toBeNull();
});
});
@@ -1,64 +1,62 @@
import { describe, it, expect, beforeEach, afterEach } from 'bun:test';
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
import { resolveLifecyclePort } from '../../../src/commands/cliproxy/proxy-lifecycle-subcommand';
import { afterEach, describe, expect, it, mock } from 'bun:test';
import { CLIPROXY_DEFAULT_PORT } from '../../../src/cliproxy/config/port-manager';
import { runWithScopedConfigDir } from '../../../src/utils/config-manager';
let tempDir: string;
type MockUnifiedConfig = {
cliproxy_server?: {
local?: {
port?: number;
};
};
};
function writeUnifiedConfig(localPort: number): void {
const configPath = path.join(tempDir, 'config.yaml');
const yaml = `version: 2
accounts: {}
profiles: {}
preferences:
theme: system
telemetry: false
auto_update: true
cliproxy:
oauth_accounts: {}
providers:
- gemini
- codex
- agy
variants: {}
cliproxy_server:
local:
port: ${localPort}
`;
fs.writeFileSync(configPath, yaml, 'utf8');
function mockUnifiedConfig(config: MockUnifiedConfig): void {
mock.module('../../../src/config/unified-config-loader', () => ({
loadOrCreateUnifiedConfig: () => config,
}));
}
async function loadResolveLifecyclePort() {
const mod = await import(
`../../../src/commands/cliproxy/resolve-lifecycle-port?proxy-lifecycle-port=${Date.now()}-${Math.random()}`
);
return mod.resolveLifecyclePort;
}
describe('resolveLifecyclePort', () => {
beforeEach(() => {
tempDir = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-proxy-lifecycle-'));
});
afterEach(() => {
if (tempDir && fs.existsSync(tempDir)) {
fs.rmSync(tempDir, { recursive: true, force: true });
}
mock.restore();
});
it('uses configured cliproxy_server.local.port', async () => {
writeUnifiedConfig(9456);
await runWithScopedConfigDir(tempDir, () => {
expect(resolveLifecyclePort()).toBe(9456);
mockUnifiedConfig({
cliproxy_server: {
local: {
port: 9456,
},
},
});
const resolveLifecyclePort = await loadResolveLifecyclePort();
expect(resolveLifecyclePort()).toBe(9456);
});
it('falls back to default port when configured local port is invalid', async () => {
writeUnifiedConfig(70000);
await runWithScopedConfigDir(tempDir, () => {
expect(resolveLifecyclePort()).toBe(CLIPROXY_DEFAULT_PORT);
mockUnifiedConfig({
cliproxy_server: {
local: {
port: 70000,
},
},
});
const resolveLifecyclePort = await loadResolveLifecyclePort();
expect(resolveLifecyclePort()).toBe(CLIPROXY_DEFAULT_PORT);
});
it('falls back to default port when config file is missing', async () => {
await runWithScopedConfigDir(tempDir, () => {
expect(resolveLifecyclePort()).toBe(CLIPROXY_DEFAULT_PORT);
});
mockUnifiedConfig({});
const resolveLifecyclePort = await loadResolveLifecyclePort();
expect(resolveLifecyclePort()).toBe(CLIPROXY_DEFAULT_PORT);
});
});
@@ -0,0 +1,54 @@
import { describe, expect, it } from 'bun:test';
const hook = require('../../../lib/hooks/websearch-transformer.cjs') as {
extractDuckDuckGoResults: (html: string, count: number) => Array<{
title: string;
url: string;
description: string;
}>;
formatStructuredSearchResults: (
query: string,
providerName: string,
results: Array<{ title: string; url: string; description: string }>
) => string;
};
describe('websearch-transformer hook helpers', () => {
it('extracts DuckDuckGo results and unwraps uddg redirect URLs', () => {
const html = `
<a class="result__a" href="/l/?uddg=https%3A%2F%2Fexample.com%2Farticle">Example title</a>
<a class="result__snippet">Example snippet</a>
<a class="result__a" href="https://second.example.com/post">Second title</a>
<a class="result__snippet">Second snippet</a>
`;
const results = hook.extractDuckDuckGoResults(html, 2);
expect(results).toHaveLength(2);
expect(results[0]).toEqual({
title: 'Example title',
url: 'https://example.com/article',
description: 'Example snippet',
});
expect(results[1]).toEqual({
title: 'Second title',
url: 'https://second.example.com/post',
description: 'Second snippet',
});
});
it('formats structured search results for hook deny output', () => {
const formatted = hook.formatStructuredSearchResults('ccs websearch', 'DuckDuckGo', [
{
title: 'Result title',
url: 'https://example.com',
description: 'Result snippet',
},
]);
expect(formatted).toContain('Search results for "ccs websearch" via DuckDuckGo');
expect(formatted).toContain('1. Result title');
expect(formatted).toContain('https://example.com');
expect(formatted).toContain('Result snippet');
});
});
@@ -62,11 +62,22 @@ describe('ccsd alias integration', () => {
expect(path.basename(argvPath)).toBe('ccsd');
});
it('should preserve ccs-droid symlink basename in argv[1] under node', () => {
if (process.platform === 'win32') {
return;
}
const argvPath = probeArgvPath('ccs-droid');
expect(path.basename(argvPath)).toBe('ccs-droid');
});
it('should preserve extension-style alias basenames for wrapper compatibility', () => {
const cmdArgvPath = probeArgvPathDirect('ccsd.cmd');
const ps1ArgvPath = probeArgvPathDirect('ccsd.ps1');
const explicitCmdArgvPath = probeArgvPathDirect('ccs-droid.cmd');
expect(path.basename(cmdArgvPath)).toBe('ccsd.cmd');
expect(path.basename(ps1ArgvPath)).toBe('ccsd.ps1');
expect(path.basename(explicitCmdArgvPath)).toBe('ccs-droid.cmd');
});
});
+92 -2
View File
@@ -7,6 +7,8 @@ import { resolveTargetType, stripTargetFlag } from '../../../src/targets/target-
describe('resolveTargetType', () => {
const originalArgv = process.argv;
const originalDroidAliases = process.env.CCS_DROID_ALIASES;
const originalTargetAliases = process.env.CCS_TARGET_ALIASES;
const originalInternalEntryTarget = process.env.CCS_INTERNAL_ENTRY_TARGET;
afterEach(() => {
process.argv = originalArgv;
@@ -15,6 +17,18 @@ describe('resolveTargetType', () => {
} else {
process.env.CCS_DROID_ALIASES = originalDroidAliases;
}
if (originalTargetAliases === undefined) {
delete process.env.CCS_TARGET_ALIASES;
} else {
process.env.CCS_TARGET_ALIASES = originalTargetAliases;
}
if (originalInternalEntryTarget === undefined) {
delete process.env.CCS_INTERNAL_ENTRY_TARGET;
} else {
process.env.CCS_INTERNAL_ENTRY_TARGET = originalInternalEntryTarget;
}
});
it('should return claude as default', () => {
@@ -52,18 +66,52 @@ describe('resolveTargetType', () => {
expect(resolveTargetType([])).toBe('droid');
});
it('should detect built-in ccs-droid argv[0] alias', () => {
process.argv = ['node', 'ccs-droid'];
expect(resolveTargetType([])).toBe('droid');
});
it('should detect custom target aliases from CCS_TARGET_ALIASES', () => {
process.env.CCS_TARGET_ALIASES = 'droid=droidx,my-droid';
process.argv = ['node', 'my-droid'];
expect(resolveTargetType([])).toBe('droid');
});
it('should ignore unsupported targets in CCS_TARGET_ALIASES', () => {
process.env.CCS_TARGET_ALIASES = 'codex=ccsx;droid=ccs-droid-custom';
process.argv = ['node', 'ccsx'];
expect(resolveTargetType([])).toBe('claude');
});
it('should detect custom argv[0] aliases from CCS_DROID_ALIASES', () => {
process.env.CCS_DROID_ALIASES = 'droidx,my-droid';
process.argv = ['node', 'my-droid'];
expect(resolveTargetType([])).toBe('droid');
});
it('should merge CCS_TARGET_ALIASES and CCS_DROID_ALIASES', () => {
process.env.CCS_TARGET_ALIASES = 'droid=team-droid';
process.env.CCS_DROID_ALIASES = 'legacy-droid';
process.argv = ['node', 'team-droid'];
expect(resolveTargetType([])).toBe('droid');
process.argv = ['node', 'legacy-droid'];
expect(resolveTargetType([])).toBe('droid');
});
it('should ignore invalid custom alias entries', () => {
process.env.CCS_DROID_ALIASES = 'valid_alias,../bad,';
process.argv = ['node', '../bad'];
expect(resolveTargetType([])).toBe('claude');
});
it('should detect internal entry target for dedicated package bin entrypoints', () => {
process.env.CCS_INTERNAL_ENTRY_TARGET = 'droid';
process.argv = ['node', 'ccs'];
expect(resolveTargetType([])).toBe('droid');
});
it('should normalize argv[0] and custom aliases case-insensitively', () => {
process.env.CCS_DROID_ALIASES = 'DroidCaps';
process.argv = ['node', 'DROIDCAPS'];
@@ -75,6 +123,11 @@ describe('resolveTargetType', () => {
expect(resolveTargetType([])).toBe('droid');
});
it('should strip .cmd extension on built-in explicit alias', () => {
process.argv = ['node', 'ccs-droid.cmd'];
expect(resolveTargetType([])).toBe('droid');
});
it('should strip .bat extension on Windows argv[0]', () => {
process.argv = ['node', 'ccsd.bat'];
expect(resolveTargetType([])).toBe('droid');
@@ -95,14 +148,51 @@ describe('resolveTargetType', () => {
expect(resolveTargetType([])).toBe('droid');
});
it('should handle full path argv[0] for ccs-droid', () => {
process.argv = ['node', '/usr/local/bin/ccs-droid'];
expect(resolveTargetType([])).toBe('droid');
});
it('should prioritize --target over argv[0]', () => {
process.argv = ['node', 'ccsd'];
expect(resolveTargetType(['--target', 'claude'])).toBe('claude');
});
it('should prioritize profile config over argv[0]', () => {
it('should prioritize --target over internal entry target', () => {
process.env.CCS_INTERNAL_ENTRY_TARGET = 'droid';
process.argv = ['node', 'ccs'];
expect(resolveTargetType(['--target', 'claude'])).toBe('claude');
});
it('should prioritize runtime alias over profile config', () => {
process.argv = ['node', 'ccsd'];
expect(resolveTargetType([], { target: 'claude' })).toBe('claude');
expect(resolveTargetType([], { target: 'claude' })).toBe('droid');
});
it('should prioritize internal entry target over profile config', () => {
process.env.CCS_INTERNAL_ENTRY_TARGET = 'droid';
process.argv = ['node', 'ccs'];
expect(resolveTargetType([], { target: 'claude' })).toBe('droid');
});
it('should keep reserved command names authoritative', () => {
process.env.CCS_TARGET_ALIASES = 'claude=ccs,ccs-droid,ccsd;droid=mydroid';
process.env.CCS_DROID_ALIASES = 'ccs,ccs-droid,ccsd,legacy-droid';
process.argv = ['node', 'ccs'];
expect(resolveTargetType([])).toBe('claude');
process.argv = ['node', 'ccs-droid'];
expect(resolveTargetType([])).toBe('droid');
process.argv = ['node', 'ccsd'];
expect(resolveTargetType([])).toBe('droid');
process.argv = ['node', 'mydroid'];
expect(resolveTargetType([])).toBe('droid');
process.argv = ['node', 'legacy-droid'];
expect(resolveTargetType([])).toBe('droid');
});
it('should throw for invalid --target value', () => {
+127
View File
@@ -0,0 +1,127 @@
import { afterEach, beforeEach, describe, expect, it } from 'bun:test';
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
import { getWebSearchReadiness } from '../../../../src/utils/websearch/status';
function writeWebSearchConfig(tempRoot: string, lines: string[]): void {
fs.writeFileSync(path.join(tempRoot, '.ccs', 'config.yaml'), lines.join('\n'), 'utf8');
}
describe('websearch readiness', () => {
const originalCcsHome = process.env.CCS_HOME;
const originalBraveKey = process.env.BRAVE_API_KEY;
const originalExaKey = process.env.EXA_API_KEY;
const originalTavilyKey = process.env.TAVILY_API_KEY;
let tempRoot = '';
beforeEach(() => {
tempRoot = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-websearch-status-'));
process.env.CCS_HOME = tempRoot;
delete process.env.BRAVE_API_KEY;
delete process.env.EXA_API_KEY;
delete process.env.TAVILY_API_KEY;
fs.mkdirSync(path.join(tempRoot, '.ccs'), { recursive: true });
});
afterEach(() => {
if (originalCcsHome !== undefined) process.env.CCS_HOME = originalCcsHome;
else delete process.env.CCS_HOME;
if (originalBraveKey !== undefined) process.env.BRAVE_API_KEY = originalBraveKey;
else delete process.env.BRAVE_API_KEY;
if (originalExaKey !== undefined) process.env.EXA_API_KEY = originalExaKey;
else delete process.env.EXA_API_KEY;
if (originalTavilyKey !== undefined) process.env.TAVILY_API_KEY = originalTavilyKey;
else delete process.env.TAVILY_API_KEY;
fs.rmSync(tempRoot, { recursive: true, force: true });
});
it('is ready by default because DuckDuckGo is enabled', () => {
const readiness = getWebSearchReadiness();
expect(readiness.readiness).toBe('ready');
expect(readiness.message).toContain('DuckDuckGo');
});
it('reports setup required when only Tavily is enabled without an API key', () => {
writeWebSearchConfig(tempRoot, [
'version: 10',
'websearch:',
' enabled: true',
' providers:',
' exa:',
' enabled: false',
' max_results: 5',
' tavily:',
' enabled: true',
' max_results: 5',
' duckduckgo:',
' enabled: false',
' max_results: 5',
' brave:',
' enabled: false',
' max_results: 5',
' gemini:',
' enabled: false',
' model: "gemini-2.5-flash"',
' timeout: 55',
' opencode:',
' enabled: false',
' model: "opencode/grok-code"',
' timeout: 90',
' grok:',
' enabled: false',
' timeout: 55',
'',
]);
const readiness = getWebSearchReadiness();
expect(readiness.readiness).toBe('needs_setup');
expect(readiness.message).toContain('Tavily');
expect(readiness.message).toContain('TAVILY_API_KEY');
});
it('prefers API-backed readiness when Exa is enabled and configured', () => {
process.env.EXA_API_KEY = 'exa-test-key';
writeWebSearchConfig(tempRoot, [
'version: 10',
'websearch:',
' enabled: true',
' providers:',
' exa:',
' enabled: true',
' max_results: 5',
' tavily:',
' enabled: false',
' max_results: 5',
' duckduckgo:',
' enabled: false',
' max_results: 5',
' brave:',
' enabled: false',
' max_results: 5',
' gemini:',
' enabled: false',
' model: "gemini-2.5-flash"',
' timeout: 55',
' opencode:',
' enabled: false',
' model: "opencode/grok-code"',
' timeout: 90',
' grok:',
' enabled: false',
' timeout: 55',
'',
]);
const readiness = getWebSearchReadiness();
expect(readiness.readiness).toBe('ready');
expect(readiness.message).toContain('Exa');
});
});
@@ -0,0 +1,173 @@
import { afterAll, afterEach, beforeAll, beforeEach, describe, expect, it, mock } from 'bun:test';
import express from 'express';
import type { Server } from 'http';
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
const listCalls: string[] = [];
const updateCalls: Array<{ family: string; entryId: string; data: Record<string, unknown> }> = [];
mock.module('../../../src/cliproxy/ai-providers', () => ({
AI_PROVIDER_FAMILY_DEFINITIONS: {
'gemini-api-key': {
id: 'gemini-api-key',
displayName: 'Gemini',
description: 'Mock Gemini family',
authMode: 'hybrid',
supportsNamedEntries: false,
routePath: '/api/provider/gemini',
},
'openai-compatibility': {
id: 'openai-compatibility',
displayName: 'OpenAI-Compatible',
description: 'Mock connector family',
authMode: 'connector',
supportsNamedEntries: true,
routePath: '/api/provider/openai-compat',
},
},
AI_PROVIDER_FAMILY_IDS: ['gemini-api-key', 'openai-compatibility'],
listAiProviders: async () => {
listCalls.push('list');
return {
source: {
mode: 'local',
label: 'Local CLIProxy',
target: 'http://127.0.0.1:8317',
managementAuth: 'configured',
},
families: [],
};
},
createAiProviderEntry: async () => {},
updateAiProviderEntry: async (family: string, entryId: string, data: Record<string, unknown>) => {
updateCalls.push({ family, entryId, data });
},
deleteAiProviderEntry: async () => {},
}));
describe('ai-provider-routes', () => {
let router: typeof import('../../../src/web-server/routes/ai-provider-routes').default;
let server: Server;
let baseUrl = '';
let forcedRemoteAddress = '127.0.0.1';
let tempHome = '';
let originalDashboardAuthEnabled: string | undefined;
let originalCcsHome: string | undefined;
beforeAll(async () => {
({ default: router } = await import(
`../../../src/web-server/routes/ai-provider-routes?ai-provider-routes=${Date.now()}`
));
const app = express();
app.use(express.json());
app.use((req, _res, next) => {
Object.defineProperty(req.socket, 'remoteAddress', {
value: forcedRemoteAddress,
configurable: true,
});
next();
});
app.use('/api/cliproxy/ai-providers', router);
await new Promise<void>((resolve, reject) => {
server = app.listen(0, '127.0.0.1');
server.once('error', reject);
server.once('listening', () => resolve());
});
const address = server.address();
if (!address || typeof address === 'string') {
throw new Error('Unable to resolve test server port');
}
baseUrl = `http://127.0.0.1:${address.port}`;
});
afterAll(async () => {
await new Promise<void>((resolve) => server.close(() => resolve()));
});
beforeEach(() => {
originalDashboardAuthEnabled = process.env.CCS_DASHBOARD_AUTH_ENABLED;
originalCcsHome = process.env.CCS_HOME;
if (tempHome && fs.existsSync(tempHome)) {
fs.rmSync(tempHome, { recursive: true, force: true });
}
tempHome = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-ai-provider-routes-'));
process.env.CCS_HOME = tempHome;
forcedRemoteAddress = '127.0.0.1';
process.env.CCS_DASHBOARD_AUTH_ENABLED = 'false';
listCalls.length = 0;
updateCalls.length = 0;
});
afterEach(() => {
if (originalDashboardAuthEnabled !== undefined) {
process.env.CCS_DASHBOARD_AUTH_ENABLED = originalDashboardAuthEnabled;
} else {
delete process.env.CCS_DASHBOARD_AUTH_ENABLED;
}
if (originalCcsHome !== undefined) {
process.env.CCS_HOME = originalCcsHome;
} else {
delete process.env.CCS_HOME;
}
if (tempHome && fs.existsSync(tempHome)) {
fs.rmSync(tempHome, { recursive: true, force: true });
tempHome = '';
}
});
it('blocks remote access when dashboard auth is disabled', async () => {
forcedRemoteAddress = '10.10.0.24';
const response = await fetch(`${baseUrl}/api/cliproxy/ai-providers`);
expect(response.status).toBe(403);
expect(await response.json()).toEqual({
error: 'AI provider endpoints require localhost access when dashboard auth is disabled.',
});
expect(listCalls).toHaveLength(0);
});
it('allows non-local access when dashboard auth is enabled', async () => {
forcedRemoteAddress = '10.10.0.24';
process.env.CCS_DASHBOARD_AUTH_ENABLED = 'true';
const response = await fetch(`${baseUrl}/api/cliproxy/ai-providers`);
expect(response.status).toBe(200);
expect(listCalls).toHaveLength(1);
});
it('passes stable entry ids through update routes', async () => {
const response = await fetch(
`${baseUrl}/api/cliproxy/ai-providers/gemini-api-key/entry-alpha-123`,
{
method: 'PUT',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ apiKey: 'sk-test' }),
}
);
expect(response.status).toBe(200);
expect(updateCalls).toEqual([
{
family: 'gemini-api-key',
entryId: 'entry-alpha-123',
data: {
apiKey: 'sk-test',
apiKeys: undefined,
baseUrl: undefined,
excludedModels: undefined,
headers: undefined,
models: undefined,
name: undefined,
prefix: undefined,
preserveSecrets: false,
proxyUrl: undefined,
},
},
]);
});
});
@@ -0,0 +1,298 @@
import { afterAll, afterEach, beforeAll, beforeEach, describe, expect, it } from 'bun:test';
import express from 'express';
import * as fs from 'fs';
import * as os from 'os';
import * as path from 'path';
import * as http from 'http';
import type { Server } from 'http';
import cliproxyAuthRoutes from '../../../src/web-server/routes/cliproxy-auth-routes';
import { restoreFetch, mockFetch } from '../../mocks';
describe('cliproxy-auth-routes manual callback nickname persistence', () => {
let server: Server;
let baseUrl = '';
let tempHome = '';
let originalCcsHome: string | undefined;
beforeAll(async () => {
const app = express();
app.use(express.json());
app.use('/api/cliproxy/auth', cliproxyAuthRoutes);
await new Promise<void>((resolve, reject) => {
server = app.listen(0, '127.0.0.1');
const onError = (error: Error) => reject(error);
server.once('error', onError);
server.once('listening', () => {
server.off('error', onError);
resolve();
});
});
const address = server.address();
if (!address || typeof address === 'string') {
throw new Error('Unable to resolve test server port');
}
baseUrl = `http://127.0.0.1:${address.port}`;
});
afterAll(async () => {
await new Promise<void>((resolve) => server.close(() => resolve()));
});
beforeEach(() => {
tempHome = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-cliproxy-manual-callback-'));
originalCcsHome = process.env.CCS_HOME;
process.env.CCS_HOME = tempHome;
});
afterEach(() => {
restoreFetch();
if (originalCcsHome === undefined) {
delete process.env.CCS_HOME;
} else {
process.env.CCS_HOME = originalCcsHome;
}
fs.rmSync(tempHome, { recursive: true, force: true });
});
async function postJson(route: string, body: Record<string, unknown>) {
return await new Promise<{ status: number; body: unknown }>((resolve, reject) => {
const payload = JSON.stringify(body);
const url = new URL(`${baseUrl}${route}`);
const request = http.request(
{
method: 'POST',
hostname: url.hostname,
port: url.port,
path: url.pathname,
headers: {
'Content-Type': 'application/json',
'Content-Length': Buffer.byteLength(payload),
},
},
(response) => {
let responseBody = '';
response.setEncoding('utf8');
response.on('data', (chunk) => {
responseBody += chunk;
});
response.on('end', () => {
resolve({
status: response.statusCode || 0,
body: responseBody ? JSON.parse(responseBody) : null,
});
});
}
);
request.on('error', reject);
request.write(payload);
request.end();
});
}
async function getJson(route: string) {
return await new Promise<{ status: number; body: unknown }>((resolve, reject) => {
const url = new URL(`${baseUrl}${route}`);
const request = http.request(
{
method: 'GET',
hostname: url.hostname,
port: url.port,
path: `${url.pathname}${url.search}`,
},
(response) => {
let responseBody = '';
response.setEncoding('utf8');
response.on('data', (chunk) => {
responseBody += chunk;
});
response.on('end', () => {
resolve({
status: response.statusCode || 0,
body: responseBody ? JSON.parse(responseBody) : null,
});
});
}
);
request.on('error', reject);
request.end();
});
}
it('persists the supplied nickname for Kiro social start-url flows after callback submission', async () => {
mockFetch([
{
url: /\/v0\/management\/kiro-auth-url\?is_webui=true&method=google$/,
response: {
auth_url: 'https://auth.example.com/authorize?state=state-123',
state: 'state-123',
},
},
{
url: /\/v0\/management\/oauth-callback$/,
method: 'POST',
response: { status: 'ok' },
},
]);
const startResponse = await postJson('/api/cliproxy/auth/kiro/start-url', {
nickname: 'work',
kiroMethod: 'google',
});
expect(startResponse.status).toBe(200);
const tokenDir = path.join(tempHome, '.ccs', 'cliproxy', 'auth');
fs.mkdirSync(tokenDir, { recursive: true });
fs.writeFileSync(
path.join(tokenDir, 'kiro-github-ABC123.json'),
JSON.stringify({ type: 'kiro' }),
'utf8'
);
const callbackResponse = await postJson('/api/cliproxy/auth/kiro/submit-callback', {
redirectUrl: 'http://localhost/callback?code=abc123&state=state-123',
});
expect(callbackResponse.status).toBe(200);
const registryPath = path.join(tempHome, '.ccs', 'cliproxy', 'accounts.json');
const registry = JSON.parse(fs.readFileSync(registryPath, 'utf8')) as {
providers: {
kiro: {
accounts: Record<string, { nickname?: string }>;
};
};
};
expect(registry.providers.kiro.accounts['github-ABC123']?.nickname).toBe('work');
});
it('returns 409 when callback completes upstream but no account can be registered locally', async () => {
mockFetch([
{
url: /\/v0\/management\/kiro-auth-url\?is_webui=true&method=google$/,
response: {
auth_url: 'https://auth.example.com/authorize?state=state-409',
state: 'state-409',
},
},
{
url: /\/v0\/management\/oauth-callback$/,
method: 'POST',
response: { status: 'ok' },
},
]);
const startResponse = await postJson('/api/cliproxy/auth/kiro/start-url', {
nickname: 'work',
kiroMethod: 'google',
});
expect(startResponse.status).toBe(200);
const callbackResponse = await postJson('/api/cliproxy/auth/kiro/submit-callback', {
redirectUrl: 'http://localhost/callback?code=abc123&state=state-409',
});
expect(callbackResponse.status).toBe(409);
expect(callbackResponse.body).toEqual({
error:
'Authenticated token could not be matched to a new account. Retry the flow and choose a different nickname if needed.',
});
});
it('returns 409 when status polling completes upstream but no new local token was written', async () => {
const tokenDir = path.join(tempHome, '.ccs', 'cliproxy', 'auth');
fs.mkdirSync(tokenDir, { recursive: true });
fs.writeFileSync(
path.join(tokenDir, 'codex-existing@example.com.json'),
JSON.stringify({ type: 'codex', email: 'existing@example.com' }),
'utf8'
);
mockFetch([
{
url: /\/v0\/management\/codex-auth-url\?is_webui=true$/,
response: {
auth_url: 'https://auth.example.com/authorize?state=state-status-missing',
state: 'state-status-missing',
},
},
{
url: /\/v0\/management\/get-auth-status\?state=state-status-missing$/,
response: { status: 'ok' },
},
]);
const startResponse = await postJson('/api/cliproxy/auth/codex/start-url', {});
expect(startResponse.status).toBe(200);
const statusResponse = await getJson(
'/api/cliproxy/auth/codex/status?state=state-status-missing'
);
expect(statusResponse.status).toBe(409);
expect(statusResponse.body).toEqual({
status: 'error',
error:
'Authentication completed upstream, but no new local token was saved for this account. Update CCS/CLIProxy and retry.',
});
});
it('registers the new account before reporting polled auth success', async () => {
mockFetch([
{
url: /\/v0\/management\/codex-auth-url\?is_webui=true$/,
response: {
auth_url: 'https://auth.example.com/authorize?state=state-status-ok',
state: 'state-status-ok',
},
},
{
url: /\/v0\/management\/get-auth-status\?state=state-status-ok$/,
response: { status: 'ok' },
},
]);
const startResponse = await postJson('/api/cliproxy/auth/codex/start-url', {});
expect(startResponse.status).toBe(200);
const tokenDir = path.join(tempHome, '.ccs', 'cliproxy', 'auth');
fs.mkdirSync(tokenDir, { recursive: true });
fs.writeFileSync(
path.join(tokenDir, 'codex-new@example.com.json'),
JSON.stringify({ type: 'codex', email: 'new@example.com' }),
'utf8'
);
const statusResponse = await getJson('/api/cliproxy/auth/codex/status?state=state-status-ok');
expect(statusResponse.status).toBe(200);
expect(statusResponse.body).toEqual({
status: 'ok',
account: {
id: 'new@example.com',
email: 'new@example.com',
nickname: 'new',
provider: 'codex',
isDefault: true,
},
});
const registryPath = path.join(tempHome, '.ccs', 'cliproxy', 'accounts.json');
const registry = JSON.parse(fs.readFileSync(registryPath, 'utf8')) as {
providers: {
codex: {
accounts: Record<string, { email?: string }>;
};
};
};
expect(registry.providers.codex.accounts['new@example.com']?.email).toBe('new@example.com');
});
});
@@ -1,6 +1,7 @@
import { describe, expect, it } from 'bun:test';
import {
getStartAuthFailureMessage,
getStartAuthNicknameError,
getStartUrlUnsupportedReason,
} from '../../../src/web-server/routes/cliproxy-auth-routes';
@@ -43,3 +44,44 @@ describe('cliproxy-auth-routes start failure messaging', () => {
expect(getStartAuthFailureMessage('kiro')).toBe('Authentication failed or was cancelled');
});
});
describe('cliproxy-auth-routes nickname validation', () => {
it('allows Kiro and GHCP start requests without a nickname', () => {
expect(getStartAuthNicknameError('kiro', undefined, [])).toBeNull();
expect(getStartAuthNicknameError('ghcp', undefined, [])).toBeNull();
});
it('rejects invalid supplied nicknames for no-email providers', () => {
expect(getStartAuthNicknameError('kiro', 'bad nickname', [])).toEqual({
error: 'Nickname cannot contain whitespace',
code: 'INVALID_NICKNAME',
});
});
it('rejects nicknames that collide with an existing account id or nickname', () => {
const existingAccounts = [
{ id: 'github-ABC123', nickname: 'work' },
{ id: 'ghcp-2', nickname: 'personal' },
];
expect(getStartAuthNicknameError('ghcp', 'github-ABC123', existingAccounts)).toEqual({
error: 'Nickname "github-ABC123" is already in use. Choose a different one.',
code: 'NICKNAME_EXISTS',
});
expect(getStartAuthNicknameError('ghcp', 'work', existingAccounts)).toEqual({
error: 'Nickname "work" is already in use. Choose a different one.',
code: 'NICKNAME_EXISTS',
});
});
it('allows reauth when the nickname already belongs to the same account', () => {
const existingAccounts = [
{ id: 'github-ABC123', nickname: 'work' },
{ id: 'ghcp-2', nickname: 'personal' },
];
expect(getStartAuthNicknameError('kiro', 'work', existingAccounts, 'github-ABC123')).toBeNull();
expect(getStartAuthNicknameError('kiro', 'github-ABC123', existingAccounts, 'github-ABC123')).toBeNull();
});
});
@@ -41,7 +41,6 @@ import {
DEFAULT_KIRO_AUTH_METHOD,
getKiroAuthMethodOption,
isDeviceCodeProvider,
isNicknameRequiredProvider,
KIRO_AUTH_METHOD_OPTIONS,
} from '@/lib/provider-config';
import type { KiroAuthMethod } from '@/lib/provider-config';
@@ -89,7 +88,6 @@ export function AddAccountDialog({
const isAgyRiskChecklistComplete = isAntigravityRiskChecklistComplete(agyRiskChecklist);
const isGeminiRiskAcknowledged = normalizeRiskPhrase(riskAcknowledgementText) === RISK_ACK_PHRASE;
const defaultDeviceCode = isDeviceCodeProvider(provider);
const requiresNickname = isNicknameRequiredProvider(provider);
const kiroMethodOption = getKiroAuthMethodOption(kiroAuthMethod);
const isDeviceCode = isKiro ? kiroMethodOption.flowType === 'device_code' : defaultDeviceCode;
const isPending = authFlow.isAuthenticating || kiroImportMutation.isPending;
@@ -266,10 +264,6 @@ export function AddAccountDialog({
);
return;
}
if (requiresNickname && !nicknameTrimmed) {
setLocalError(`Nickname is required for ${displayName} accounts.`);
return;
}
setLocalError(null);
wasAuthenticatingRef.current = true;
authFlow.startAuth(provider, {
@@ -394,11 +388,7 @@ export function AddAccountDialog({
{/* Nickname input - only show before auth starts */}
{!showAuthUI && (
<div className="space-y-2">
<Label htmlFor="nickname">
{requiresNickname
? t('addAccountDialog.nicknameRequired')
: t('addAccountDialog.nicknameOptional')}
</Label>
<Label htmlFor="nickname">{t('addAccountDialog.nicknameOptional')}</Label>
<div className="flex items-center gap-2">
<User className="w-4 h-4 text-muted-foreground" />
<Input
@@ -414,9 +404,7 @@ export function AddAccountDialog({
/>
</div>
<p className="text-xs text-muted-foreground">
{requiresNickname
? t('addAccountDialog.nicknameRequiredHint')
: t('addAccountDialog.nicknameOptionalHint')}
{t('addAccountDialog.nicknameOptionalHint')}
</p>
</div>
)}
@@ -554,7 +542,6 @@ export function AddAccountDialog({
disabled={
isPending ||
isAgyBypassStatePending ||
(requiresNickname && !nicknameTrimmed) ||
(requiresAgyResponsibilityFlow && !isAgyRiskChecklistComplete) ||
(requiresSafetyAcknowledgement && !isGeminiRiskAcknowledged)
}
@@ -90,15 +90,11 @@ export function ProviderInfoTab({
<UsageCommand label="Run with prompt" command={`ccs ${provider} "your prompt"`} />
<UsageCommand
label={isDroidTarget ? 'Droid alias (explicit)' : 'Run on Droid'}
command={
isDroidTarget
? `ccsd ${provider} "your prompt"`
: `ccs ${provider} --target droid "your prompt"`
}
command={`ccs-droid ${provider} "your prompt"`}
/>
<UsageCommand
label={isDroidTarget ? 'Override to Claude' : 'Override target'}
command={`ccs ${provider} --target claude "your prompt"`}
label={isDroidTarget ? 'Override to Claude' : 'Run on Droid (--target)'}
command={`ccs ${provider} --target ${isDroidTarget ? 'claude' : 'droid'} "your prompt"`}
/>
<UsageCommand label="Change model" command={`ccs ${provider} --config`} />
<UsageCommand label="Add account" command={`ccs ${provider} --add`} />
@@ -90,16 +90,10 @@ export function InfoSection({ profileName, target, data }: InfoSectionProps) {
</Label>
<div className="mt-1 flex gap-2">
<code className="flex-1 px-2 py-1.5 bg-muted rounded text-xs font-mono truncate">
{isDroidTarget
? `ccsd ${profileName} "prompt"`
: `ccs ${profileName} --target droid "prompt"`}
{`ccs-droid ${profileName} "prompt"`}
</code>
<CopyButton
value={
isDroidTarget
? `ccsd ${profileName} "prompt"`
: `ccs ${profileName} --target droid "prompt"`
}
value={`ccs-droid ${profileName} "prompt"`}
size="icon"
className="h-6 w-6"
/>
@@ -109,14 +103,14 @@ export function InfoSection({ profileName, target, data }: InfoSectionProps) {
<Label className="text-xs text-muted-foreground">
{isDroidTarget
? t('profileEditor.overrideToClaude')
: t('profileEditor.overrideToClaudeExplicit')}
: t('profileEditor.runOnDroidWithFlag')}
</Label>
<div className="mt-1 flex gap-2">
<code className="flex-1 px-2 py-1.5 bg-muted rounded text-xs font-mono truncate">
ccs {profileName} --target claude "prompt"
ccs {profileName} --target {isDroidTarget ? 'claude' : 'droid'} "prompt"
</code>
<CopyButton
value={`ccs ${profileName} --target claude "prompt"`}
value={`ccs ${profileName} --target ${isDroidTarget ? 'claude' : 'droid'} "prompt"`}
size="icon"
className="h-6 w-6"
/>
@@ -1,32 +1,92 @@
/**
* OpenRouter Quick Start Card
* Prominent CTA for new users to create OpenRouter profile
*/
import type { ReactNode } from 'react';
import { Button } from '@/components/ui/button';
import { Card, CardContent, CardDescription, CardHeader, CardTitle } from '@/components/ui/card';
import { Badge } from '@/components/ui/badge';
import { Separator } from '@/components/ui/separator';
import { useOpenRouterReady } from '@/hooks/use-openrouter-models';
import { cn } from '@/lib/utils';
import {
Sparkles,
ExternalLink,
ArrowRight,
Zap,
CloudCog,
ExternalLink,
KeyRound,
SlidersHorizontal,
Sparkles,
Zap,
} from 'lucide-react';
import { useTranslation } from 'react-i18next';
interface OpenRouterQuickStartProps {
hasProfiles: boolean;
profileCount: number;
onOpenRouterClick: () => void;
onAlibabaCodingPlanClick: () => void;
onCliproxyClick: () => void;
onCustomClick: () => void;
}
interface QuickStartCardProps {
badge: string;
badgeClassName?: string;
className?: string;
title: string;
description: string;
visual: ReactNode;
highlights: Array<{ icon: ReactNode; label: string }>;
actionLabel: string;
actionClassName: string;
onAction: () => void;
footer?: ReactNode;
}
function QuickStartCard({
badge,
badgeClassName,
className,
title,
description,
visual,
highlights,
actionLabel,
actionClassName,
onAction,
footer,
}: QuickStartCardProps) {
return (
<Card className={cn('flex h-full flex-col border shadow-sm', className)}>
<CardHeader className="space-y-3 pb-3">
<div className="flex items-center gap-3">
{visual}
<Badge variant="secondary" className={badgeClassName}>
{badge}
</Badge>
</div>
<div className="space-y-1.5">
<CardTitle className="text-base">{title}</CardTitle>
<CardDescription className="text-sm leading-6">{description}</CardDescription>
</div>
</CardHeader>
<CardContent className="mt-auto flex flex-1 flex-col gap-4 pt-0">
<div className="space-y-2 text-xs text-muted-foreground">
{highlights.map((item) => (
<div key={item.label} className="flex items-center gap-2">
{item.icon}
<span>{item.label}</span>
</div>
))}
</div>
<Button onClick={onAction} className={actionClassName}>
{actionLabel}
<ArrowRight className="ml-2 h-4 w-4" />
</Button>
{footer ? <div className="text-xs text-muted-foreground">{footer}</div> : null}
</CardContent>
</Card>
);
}
export function OpenRouterQuickStart({
hasProfiles,
profileCount,
onOpenRouterClick,
onAlibabaCodingPlanClick,
onCliproxyClick,
@@ -34,185 +94,151 @@ export function OpenRouterQuickStart({
}: OpenRouterQuickStartProps) {
const { t } = useTranslation();
const { modelCount, isLoading } = useOpenRouterReady();
const modelCountLabel = isLoading ? '300+' : `${modelCount}+`;
const profileSummaryLabel = hasProfiles
? t('openrouterQuickStart.profileCount', { count: profileCount })
: t('openrouterQuickStart.recommended');
const summaryTitle = hasProfiles
? t('openrouterQuickStart.selectProfileTitle')
: t('apiProfiles.noProfilesYet');
const summaryDescription = hasProfiles
? t('openrouterQuickStart.summaryDescriptionWithProfiles', { count: profileCount })
: t('openrouterQuickStart.summaryDescriptionNoProfiles');
return (
<div className="flex-1 flex items-center justify-center bg-muted/20 p-8">
<div className="max-w-lg w-full space-y-6">
{/* Main OpenRouter Card */}
<Card className="border-accent/30 dark:border-accent/40 bg-gradient-to-br from-accent/5 to-background dark:from-accent/10">
<CardHeader className="pb-3">
<div className="flex items-center gap-3 mb-2">
<div className="p-2 rounded-lg bg-accent/10 dark:bg-accent/20">
<img src="/icons/openrouter.svg" alt="OpenRouter" className="w-6 h-6" />
<div className="flex h-full min-h-0 flex-col overflow-auto bg-muted/20 p-4 sm:p-6">
<div className="mx-auto flex w-full max-w-7xl flex-col gap-4">
<Card className="border-dashed bg-background/90 shadow-sm">
<CardContent className="flex flex-col gap-4 p-5 lg:flex-row lg:items-center lg:justify-between">
<div className="space-y-2">
<div className="flex flex-wrap items-center gap-2">
<Badge variant="secondary">{profileSummaryLabel}</Badge>
<Badge variant="outline">
{t('openrouterQuickStart.openrouterModelsBadge', { modelCountLabel })}
</Badge>
</div>
<Badge
variant="secondary"
className="bg-accent/10 text-accent dark:bg-accent/20 dark:text-accent-foreground"
>
{t('openrouterQuickStart.recommended')}
</Badge>
</div>
<CardTitle className="text-xl">{t('openrouterQuickStart.title')}</CardTitle>
<CardDescription className="text-base">
{t('openrouterQuickStart.description', {
modelCountLabel: isLoading ? '300+' : `${modelCount}+`,
})}
</CardDescription>
</CardHeader>
<CardContent className="space-y-4">
{/* Key Features */}
<div className="grid grid-cols-2 gap-3 text-sm">
<div className="flex items-center gap-2 text-muted-foreground">
<Zap className="w-4 h-4 text-accent" />
<span>{t('openrouterQuickStart.featureOneApi')}</span>
</div>
<div className="flex items-center gap-2 text-muted-foreground">
<Sparkles className="w-4 h-4 text-accent" />
<span>{t('openrouterQuickStart.featureTierMapping')}</span>
<div className="space-y-1">
<h2 className="text-xl font-semibold">{summaryTitle}</h2>
<p className="max-w-3xl text-sm leading-6 text-muted-foreground">
{summaryDescription}
</p>
</div>
</div>
<Button
onClick={onOpenRouterClick}
className="w-full bg-accent hover:bg-accent/90 text-white"
size="lg"
>
{t('openrouterQuickStart.createOpenRouterProfile')}
<ArrowRight className="w-4 h-4 ml-2" />
<Button variant="outline" onClick={onCustomClick} className="shrink-0">
{t('openrouterQuickStart.createCustomProfile')}
</Button>
<p className="text-xs text-center text-muted-foreground">
{t('openrouterQuickStart.getApiKeyAt')}{' '}
<a
href="https://openrouter.ai/keys"
target="_blank"
rel="noopener noreferrer"
className="text-accent hover:underline inline-flex items-center gap-1"
>
openrouter.ai/keys
<ExternalLink className="w-3 h-3" />
</a>
</p>
</CardContent>
</Card>
{/* Alibaba Coding Plan Card */}
<Card className="border-orange-500/30 dark:border-orange-500/40 bg-gradient-to-br from-orange-500/5 to-background dark:from-orange-500/10">
<CardHeader className="pb-3">
<div className="flex items-center gap-3 mb-2">
<div className="p-2 rounded-lg bg-orange-500/10 dark:bg-orange-500/20">
<div className="grid gap-4 lg:grid-cols-2">
<QuickStartCard
badge={t('openrouterQuickStart.recommended')}
title={t('openrouterQuickStart.title')}
description={t('openrouterQuickStart.description', { modelCountLabel })}
visual={
<div className="rounded-lg bg-accent/10 p-2">
<img src="/icons/openrouter.svg" alt="OpenRouter" className="h-5 w-5" />
</div>
}
highlights={[
{
icon: <Zap className="h-3.5 w-3.5 text-accent" />,
label: t('openrouterQuickStart.featureOneApi'),
},
{
icon: <Sparkles className="h-3.5 w-3.5 text-accent" />,
label: t('openrouterQuickStart.featureTierMapping'),
},
]}
actionLabel={t('openrouterQuickStart.createOpenRouterProfile')}
actionClassName="w-full bg-accent text-white hover:bg-accent/90"
onAction={onOpenRouterClick}
footer={
<>
{t('openrouterQuickStart.getApiKeyAt')}{' '}
<a
href="https://openrouter.ai/keys"
target="_blank"
rel="noopener noreferrer"
className="inline-flex items-center gap-1 text-accent hover:underline"
>
openrouter.ai/keys
<ExternalLink className="h-3 w-3" />
</a>
</>
}
/>
<QuickStartCard
badge={t('openrouterQuickStart.runtimeProviderBadge')}
badgeClassName="bg-emerald-500/10 text-emerald-700 dark:bg-emerald-500/20 dark:text-emerald-200"
title={t('openrouterQuickStart.runtimeProviderTitle')}
description={t('openrouterQuickStart.runtimeProviderDescription')}
visual={
<div className="rounded-lg bg-emerald-500/10 p-2">
<SlidersHorizontal className="h-5 w-5 text-emerald-700 dark:text-emerald-300" />
</div>
}
highlights={[
{
icon: <SlidersHorizontal className="h-3.5 w-3.5 text-emerald-600" />,
label: t('openrouterQuickStart.runtimeProviderFeatureConnectors'),
},
{
icon: <KeyRound className="h-3.5 w-3.5 text-emerald-600" />,
label: t('openrouterQuickStart.runtimeProviderFeatureSecrets'),
},
]}
actionLabel={t('openrouterQuickStart.runtimeProviderTitle')}
actionClassName="w-full bg-emerald-600 text-white hover:bg-emerald-600/90"
onAction={onCliproxyClick}
footer={<span>{t('openrouterQuickStart.runtimeProviderFooter')}</span>}
/>
<QuickStartCard
badge={t('alibabaCodingPlanQuickStart.recommended')}
badgeClassName="bg-orange-500/10 text-orange-700 dark:bg-orange-500/20 dark:text-orange-200"
className="lg:col-span-2"
title={t('alibabaCodingPlanQuickStart.title')}
description={t('alibabaCodingPlanQuickStart.description')}
visual={
<div className="rounded-lg bg-orange-500/10 p-2">
<img
src="/assets/providers/alibabacloud-color.svg"
alt="Alibaba Coding Plan"
className="w-6 h-6"
className="h-5 w-5"
/>
</div>
<Badge
variant="secondary"
className="bg-orange-500/10 text-orange-700 dark:bg-orange-500/20 dark:text-orange-200"
>
{t('alibabaCodingPlanQuickStart.recommended')}
</Badge>
</div>
<CardTitle className="text-xl">{t('alibabaCodingPlanQuickStart.title')}</CardTitle>
<CardDescription className="text-base">
{t('alibabaCodingPlanQuickStart.description')}
</CardDescription>
</CardHeader>
<CardContent className="space-y-4">
<div className="grid grid-cols-2 gap-3 text-sm">
<div className="flex items-center gap-2 text-muted-foreground">
<CloudCog className="w-4 h-4 text-orange-600" />
<span>{t('alibabaCodingPlanQuickStart.featureEndpoint')}</span>
</div>
<div className="flex items-center gap-2 text-muted-foreground">
<KeyRound className="w-4 h-4 text-orange-600" />
<span>{t('alibabaCodingPlanQuickStart.featureKeyFormat')}</span>
</div>
</div>
<Button
onClick={onAlibabaCodingPlanClick}
className="w-full bg-orange-600 hover:bg-orange-600/90 text-white"
size="lg"
>
{t('alibabaCodingPlanQuickStart.createAlibabaProfile')}
<ArrowRight className="w-4 h-4 ml-2" />
</Button>
<p className="text-xs text-center text-muted-foreground">
{t('alibabaCodingPlanQuickStart.readGuideAt')}{' '}
<a
href="https://www.alibabacloud.com/help/en/model-studio/coding-plan"
target="_blank"
rel="noopener noreferrer"
className="text-orange-700 dark:text-orange-400 hover:underline inline-flex items-center gap-1"
>
Alibaba Cloud Model Studio
<ExternalLink className="w-3 h-3" />
</a>
</p>
</CardContent>
</Card>
<Card className="border-emerald-500/30 dark:border-emerald-500/40 bg-gradient-to-br from-emerald-500/5 to-background dark:from-emerald-500/10">
<CardHeader className="pb-3">
<div className="flex items-center gap-3 mb-2">
<div className="p-2 rounded-lg bg-emerald-500/10 dark:bg-emerald-500/20">
<SlidersHorizontal className="w-6 h-6 text-emerald-700 dark:text-emerald-300" />
</div>
<Badge
variant="secondary"
className="bg-emerald-500/10 text-emerald-700 dark:bg-emerald-500/20 dark:text-emerald-200"
>
Configure in AI Providers
</Badge>
</div>
<CardTitle className="text-xl">Manage CLIProxy AI providers</CardTitle>
<CardDescription className="text-base">
Configure Gemini, Codex, Claude, Vertex, and OpenAI-compatible connectors directly in
the dedicated CLIProxy AI Providers page.
</CardDescription>
</CardHeader>
<CardContent className="space-y-4">
<div className="grid grid-cols-2 gap-3 text-sm">
<div className="flex items-center gap-2 text-muted-foreground">
<SlidersHorizontal className="w-4 h-4 text-emerald-600" />
<span>Dedicated /cliproxy/ai-providers workspace</span>
</div>
<div className="flex items-center gap-2 text-muted-foreground">
<KeyRound className="w-4 h-4 text-emerald-600" />
<span>Manage provider secrets outside API Profiles</span>
</div>
</div>
<Button
onClick={onCliproxyClick}
className="w-full bg-emerald-600 hover:bg-emerald-600/90 text-white"
size="lg"
>
Open AI Providers
<ArrowRight className="w-4 h-4 ml-2" />
</Button>
<p className="text-xs text-center text-muted-foreground">
Keep runtime provider configuration in CLIProxy, then create API Profiles only when
you need standalone Anthropic-compatible endpoints.
</p>
</CardContent>
</Card>
{/* Divider */}
<div className="flex items-center gap-4">
<Separator className="flex-1" />
<span className="text-xs text-muted-foreground">{t('openrouterQuickStart.or')}</span>
<Separator className="flex-1" />
}
highlights={[
{
icon: <CloudCog className="h-3.5 w-3.5 text-orange-600" />,
label: t('alibabaCodingPlanQuickStart.featureEndpoint'),
},
{
icon: <KeyRound className="h-3.5 w-3.5 text-orange-600" />,
label: t('alibabaCodingPlanQuickStart.featureKeyFormat'),
},
]}
actionLabel={t('alibabaCodingPlanQuickStart.createAlibabaProfile')}
actionClassName="w-full bg-orange-600 text-white hover:bg-orange-600/90"
onAction={onAlibabaCodingPlanClick}
footer={
<>
{t('alibabaCodingPlanQuickStart.readGuideAt')}{' '}
<a
href="https://www.alibabacloud.com/help/en/model-studio/coding-plan"
target="_blank"
rel="noopener noreferrer"
className="inline-flex items-center gap-1 text-orange-700 hover:underline dark:text-orange-400"
>
Alibaba Cloud Model Studio
<ExternalLink className="h-3 w-3" />
</a>
</>
}
/>
</div>
{/* Custom Option */}
<Button variant="outline" onClick={onCustomClick} className="w-full">
{t('openrouterQuickStart.createCustomProfile')}
</Button>
</div>
</div>
);
@@ -524,11 +524,25 @@ export function ProfileCreateDialog({
</SelectContent>
</Select>
<p className="text-xs text-muted-foreground">
Run with{' '}
<code className="bg-muted px-1 rounded text-[10px]">
{targetValue === 'droid' ? 'ccsd' : 'ccs'}
</code>{' '}
by default. You can still override each run with{' '}
{targetValue === 'droid' ? (
<>
{t('profileEditor.targetHintPreferredAlias')}{' '}
<code className="bg-muted px-1 rounded text-[10px]">ccs-droid</code>.
</>
) : (
<>
{t('profileEditor.targetHintClaudeDefault')}{' '}
<code className="bg-muted px-1 rounded text-[10px]">ccs</code>.
</>
)}
{targetValue === 'droid' ? (
<>
{' '}
{t('profileEditor.targetHintLegacyAlias')}{' '}
<code className="bg-muted px-1 rounded text-[10px]">ccsd</code>.
</>
) : null}{' '}
{t('profileEditor.targetHintOverride')}{' '}
<code className="bg-muted px-1 rounded text-[10px]">--target</code>.
</p>
</div>
+5 -5
View File
@@ -42,13 +42,13 @@ export function useUpdateCliproxyAiProviderEntry() {
return useMutation({
mutationFn: ({
family,
index,
entryId,
data,
}: {
family: AiProviderFamilyId;
index: number;
entryId: string;
data: UpsertAiProviderEntryInput;
}) => api.cliproxy.aiProviders.update(family, index, data),
}) => api.cliproxy.aiProviders.update(family, entryId, data),
onSuccess: () => {
queryClient.invalidateQueries({ queryKey: QUERY_KEY });
toast.success('Provider entry updated');
@@ -63,8 +63,8 @@ export function useDeleteCliproxyAiProviderEntry() {
const queryClient = useQueryClient();
return useMutation({
mutationFn: ({ family, index }: { family: AiProviderFamilyId; index: number }) =>
api.cliproxy.aiProviders.delete(family, index),
mutationFn: ({ family, entryId }: { family: AiProviderFamilyId; entryId: string }) =>
api.cliproxy.aiProviders.delete(family, entryId),
onSuccess: () => {
queryClient.invalidateQueries({ queryKey: QUERY_KEY });
toast.success('Provider entry removed');
+118 -18
View File
@@ -41,6 +41,8 @@ interface StartAuthOptions {
const POLL_INTERVAL = 3000;
/** Maximum polling duration (5 minutes) */
const MAX_POLL_DURATION = 5 * 60 * 1000;
/** Fail visibly after repeated poll transport errors instead of retrying forever */
const MAX_POLL_FAILURES = 3;
async function parseResponseBody(response: Response): Promise<Record<string, unknown>> {
const text = await response.text();
@@ -69,18 +71,26 @@ const INITIAL_STATE: AuthFlowState = {
export function useCliproxyAuthFlow() {
const [state, setState] = useState<AuthFlowState>(INITIAL_STATE);
const attemptIdRef = useRef(0);
const abortControllerRef = useRef<AbortController | null>(null);
const pollIntervalRef = useRef<ReturnType<typeof setInterval> | null>(null);
const pollStartRef = useRef<number>(0);
const pollFailureCountRef = useRef(0);
const openedAuthUrlRef = useRef(false);
const queryClient = useQueryClient();
const isActiveAttempt = useCallback(
(attemptId: number) => attemptId === attemptIdRef.current,
[]
);
// Clear polling
const stopPolling = useCallback(() => {
if (pollIntervalRef.current) {
clearInterval(pollIntervalRef.current);
pollIntervalRef.current = null;
}
pollFailureCountRef.current = 0;
}, []);
// Cleanup on unmount
@@ -94,15 +104,21 @@ export function useCliproxyAuthFlow() {
// Poll OAuth status
const pollStatus = useCallback(
async (provider: string, oauthState: string) => {
async (provider: string, oauthState: string, attemptId: number) => {
if (!isActiveAttempt(attemptId)) {
return;
}
// Check timeout
if (Date.now() - pollStartRef.current > MAX_POLL_DURATION) {
stopPolling();
setState((prev) => ({
...prev,
isAuthenticating: false,
error: 'Authentication timed out. Please try again.',
}));
if (isActiveAttempt(attemptId)) {
setState((prev) => ({
...prev,
isAuthenticating: false,
error: 'Authentication timed out. Please try again.',
}));
}
return;
}
@@ -110,18 +126,38 @@ export function useCliproxyAuthFlow() {
const response = await fetch(
`/api/cliproxy/auth/${provider}/status?state=${encodeURIComponent(oauthState)}`
);
if (!isActiveAttempt(attemptId)) {
return;
}
const data = (await response.json()) as {
status?: string;
error?: string;
account?: unknown;
url?: string;
auth_url?: string;
verification_url?: string;
user_code?: string;
};
pollFailureCountRef.current = 0;
if (data.status === 'ok') {
const hasAccount = typeof data.account === 'object' && data.account !== null;
if (!hasAccount) {
stopPolling();
const errorMsg = 'Authenticated account could not be registered';
toast.error(errorMsg);
setState((prev) => ({
...prev,
isAuthenticating: false,
error: errorMsg,
}));
return;
}
stopPolling();
queryClient.invalidateQueries({ queryKey: ['cliproxy-auth'] });
queryClient.invalidateQueries({ queryKey: ['cliproxy-accounts'] });
queryClient.invalidateQueries({ queryKey: ['account-quota'] });
toast.success(`${provider} authentication successful`);
openedAuthUrlRef.current = false;
@@ -161,11 +197,30 @@ export function useCliproxyAuthFlow() {
}));
}
// status === 'wait' (or pending) means continue polling
} catch {
// Network error - continue polling
} catch (error) {
if (!isActiveAttempt(attemptId)) {
return;
}
pollFailureCountRef.current += 1;
if (pollFailureCountRef.current < MAX_POLL_FAILURES) {
return;
}
stopPolling();
const message =
error instanceof Error && error.message.trim().length > 0
? error.message
: 'Lost contact with the auth status endpoint';
toast.error(message);
setState((prev) => ({
...prev,
isAuthenticating: false,
error: message,
}));
}
},
[queryClient, stopPolling]
[isActiveAttempt, queryClient, stopPolling]
);
const startAuth = useCallback(
@@ -182,9 +237,12 @@ export function useCliproxyAuthFlow() {
abortControllerRef.current?.abort();
stopPolling();
openedAuthUrlRef.current = false;
pollFailureCountRef.current = 0;
// Create fresh controller and capture locally to avoid race with cancelAuth
const controller = new AbortController();
const attemptId = attemptIdRef.current + 1;
attemptIdRef.current = attemptId;
abortControllerRef.current = controller;
const flowType =
@@ -219,10 +277,18 @@ export function useCliproxyAuthFlow() {
signal: controller.signal,
})
.then(async (response) => {
if (!isActiveAttempt(attemptId)) {
return;
}
const data = await parseResponseBody(response);
if (!isActiveAttempt(attemptId)) {
return;
}
const success = data.success === true;
if (response.ok && success) {
const hasAccount = typeof data.account === 'object' && data.account !== null;
if (response.ok && success && hasAccount) {
queryClient.invalidateQueries({ queryKey: ['cliproxy-auth'] });
queryClient.invalidateQueries({ queryKey: ['cliproxy-accounts'] });
queryClient.invalidateQueries({ queryKey: ['account-quota'] });
// Note: No toast here - DeviceCodeDialog's useDeviceCode hook handles success toast
// via deviceCodeCompleted WebSocket event to avoid duplicate toasts
@@ -230,7 +296,11 @@ export function useCliproxyAuthFlow() {
setState(INITIAL_STATE);
} else {
const errorMsg =
typeof data.error === 'string' ? data.error : 'Authentication failed';
typeof data.error === 'string'
? data.error
: success
? 'Authenticated account could not be registered'
: 'Authentication failed';
toast.error(errorMsg);
setState((prev) => ({
...prev,
@@ -240,6 +310,9 @@ export function useCliproxyAuthFlow() {
}
})
.catch((error) => {
if (!isActiveAttempt(attemptId)) {
return;
}
if (error instanceof Error && error.name === 'AbortError') {
// Cancelled - state already reset by cancelAuth
return;
@@ -261,8 +334,14 @@ export function useCliproxyAuthFlow() {
body: JSON.stringify(payload),
signal: controller.signal,
});
if (!isActiveAttempt(attemptId)) {
return;
}
const data = await parseResponseBody(response);
if (!isActiveAttempt(attemptId)) {
return;
}
const success = data.success === true;
if (!response.ok || !success) {
@@ -290,11 +369,14 @@ export function useCliproxyAuthFlow() {
if (oauthState) {
pollStartRef.current = Date.now();
pollIntervalRef.current = setInterval(() => {
pollStatus(provider, oauthState);
void pollStatus(provider, oauthState, attemptId);
}, POLL_INTERVAL);
}
}
} catch (error) {
if (!isActiveAttempt(attemptId)) {
return;
}
if (error instanceof Error && error.name === 'AbortError') {
openedAuthUrlRef.current = false;
setState(INITIAL_STATE);
@@ -309,11 +391,12 @@ export function useCliproxyAuthFlow() {
}));
}
},
[pollStatus, stopPolling, queryClient]
[isActiveAttempt, pollStatus, stopPolling, queryClient]
);
const cancelAuth = useCallback(() => {
const currentProvider = state.provider;
attemptIdRef.current += 1;
abortControllerRef.current?.abort();
stopPolling();
openedAuthUrlRef.current = false;
@@ -329,37 +412,54 @@ export function useCliproxyAuthFlow() {
const submitCallback = useCallback(
async (redirectUrl: string) => {
if (!state.provider) return;
const attemptId = attemptIdRef.current;
const currentProvider = state.provider;
setState((prev) => ({ ...prev, isSubmittingCallback: true, error: null }));
try {
const response = await fetch(`/api/cliproxy/auth/${state.provider}/submit-callback`, {
const response = await fetch(`/api/cliproxy/auth/${currentProvider}/submit-callback`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ redirectUrl }),
});
if (!isActiveAttempt(attemptId)) {
return;
}
const data = await parseResponseBody(response);
if (!isActiveAttempt(attemptId)) {
return;
}
const success = data.success === true;
const hasAccount = typeof data.account === 'object' && data.account !== null;
if (response.ok && success) {
if (response.ok && success && hasAccount) {
stopPolling();
queryClient.invalidateQueries({ queryKey: ['cliproxy-auth'] });
queryClient.invalidateQueries({ queryKey: ['cliproxy-accounts'] });
queryClient.invalidateQueries({ queryKey: ['account-quota'] });
toast.success(`${state.provider} authentication successful`);
toast.success(`${currentProvider} authentication successful`);
setState(INITIAL_STATE);
} else {
const errorMsg =
typeof data.error === 'string' ? data.error : 'Callback submission failed';
typeof data.error === 'string'
? data.error
: success
? 'Authenticated account could not be registered'
: 'Callback submission failed';
throw new Error(errorMsg);
}
} catch (error) {
if (!isActiveAttempt(attemptId)) {
return;
}
const message = error instanceof Error ? error.message : 'Failed to submit callback';
toast.error(message);
setState((prev) => ({ ...prev, isSubmittingCallback: false, error: message }));
}
},
[state.provider, queryClient, stopPolling]
[isActiveAttempt, state.provider, queryClient, stopPolling]
);
return useMemo(
+15 -9
View File
@@ -854,15 +854,21 @@ export const api = {
method: 'POST',
body: JSON.stringify(data),
}),
update: (family: AiProviderFamilyId, index: number, data: UpsertAiProviderEntryInput) =>
request(`/cliproxy/ai-providers/${encodeURIComponent(family)}/${index}`, {
method: 'PUT',
body: JSON.stringify(data),
}),
delete: (family: AiProviderFamilyId, index: number) =>
request(`/cliproxy/ai-providers/${encodeURIComponent(family)}/${index}`, {
method: 'DELETE',
}),
update: (family: AiProviderFamilyId, entryId: string, data: UpsertAiProviderEntryInput) =>
request(
`/cliproxy/ai-providers/${encodeURIComponent(family)}/${encodeURIComponent(entryId)}`,
{
method: 'PUT',
body: JSON.stringify(data),
}
),
delete: (family: AiProviderFamilyId, entryId: string) =>
request(
`/cliproxy/ai-providers/${encodeURIComponent(family)}/${encodeURIComponent(entryId)}`,
{
method: 'DELETE',
}
),
},
// Config YAML for Config tab
+97 -4
View File
@@ -241,6 +241,25 @@ const resources = {
'Access {{modelCountLabel}} models from OpenAI, Anthropic, Google, Meta and more - all through one API.',
featureOneApi: 'One API, all providers',
featureTierMapping: 'Model tier mapping',
profileCount: '{{count}} profile',
profileCount_other: '{{count}} profiles',
selectProfileTitle: 'Select an API profile',
summaryDescriptionWithProfiles:
'You already have {{count}} profile in this workspace. Select one from the left rail to edit it, or create another profile from here.',
summaryDescriptionWithProfiles_other:
'You already have {{count}} profiles in this workspace. Select one from the left rail to edit it, or create another profile from here.',
summaryDescriptionNoProfiles:
'Use API Profiles for Anthropic-compatible endpoints. Use AI Providers for Gemini, Codex, Claude, Vertex, and OpenAI-compatible connectors.',
openrouterModelsBadge: '{{modelCountLabel}} OpenRouter models',
runtimeProviderBadge: 'Runtime provider setup',
runtimeProviderTitle: 'Open AI Providers',
runtimeProviderDescription:
'Manage shared provider keys and runtime connectors before creating standalone API Profiles.',
runtimeProviderFeatureConnectors:
'Gemini, Codex, Claude, Vertex, and OpenAI-compatible connectors',
runtimeProviderFeatureSecrets: 'Shared secrets stay outside individual API profiles',
runtimeProviderFooter:
'Best when multiple profiles should share one provider configuration.',
createOpenRouterProfile: 'Create OpenRouter Profile',
getApiKeyAt: 'Get your API key at',
or: 'or',
@@ -473,7 +492,7 @@ const resources = {
nicknameRequiredHint:
'Required for this provider. Use a unique friendly name (e.g., work, personal).',
nicknameOptionalHint:
'A friendly name to identify this account. Auto-generated from email if left empty.',
'A friendly name to identify this account. Leave blank to use a safe generated identifier.',
waitingForAuth: 'Waiting for authentication...',
deviceCodeHint:
'A verification code dialog will appear shortly. Enter the code on the provider website.',
@@ -600,9 +619,14 @@ const resources = {
quickUsage: 'Quick Usage',
runWithProfile: 'Run with profile',
runOnDroid: 'Run on Droid',
runOnDroidWithFlag: 'Run on Droid (--target)',
droidAliasExplicit: 'Droid alias (explicit)',
overrideToClaude: 'Override to Claude',
overrideToClaudeExplicit: 'Override to Claude (explicit)',
targetHintPreferredAlias: 'Preferred explicit alias:',
targetHintClaudeDefault: 'Default command:',
targetHintLegacyAlias: 'Legacy shortcut still works:',
targetHintOverride: 'You can still override each run with',
setAsDefault: 'Set as default',
provider: 'Provider',
custom: 'Custom',
@@ -1420,6 +1444,22 @@ const resources = {
'通过一个 API 即可访问来自 OpenAI、Anthropic、Google、Meta 等的 {{modelCountLabel}} 个模型。',
featureOneApi: '一个 API,接入全部提供商',
featureTierMapping: '模型档位映射',
profileCount: '{{count}} 个 API 配置',
profileCount_other: '{{count}} 个 API 配置',
selectProfileTitle: '选择一个 API 配置',
summaryDescriptionWithProfiles:
'此工作区中已存在 {{count}} 个 API 配置。请从左侧栏选择一个进行编辑,或在此继续创建新的配置。',
summaryDescriptionWithProfiles_other:
'此工作区中已存在 {{count}} 个 API 配置。请从左侧栏选择一个进行编辑,或在此继续创建新的配置。',
summaryDescriptionNoProfiles:
'API 配置适用于 Anthropic 兼容端点。AI Providers 适用于 Gemini、Codex、Claude、Vertex 以及 OpenAI 兼容连接器。',
openrouterModelsBadge: '{{modelCountLabel}} 个 OpenRouter 模型',
runtimeProviderBadge: '运行时提供商设置',
runtimeProviderTitle: '打开 AI Providers',
runtimeProviderDescription: '先管理共享的提供商密钥和运行时连接器,再创建独立的 API 配置。',
runtimeProviderFeatureConnectors: 'Gemini、Codex、Claude、Vertex 以及 OpenAI 兼容连接器',
runtimeProviderFeatureSecrets: '共享密钥与单个 API 配置分离存放',
runtimeProviderFooter: '当多个配置需要共享同一提供商设置时最适合使用。',
createOpenRouterProfile: '创建 OpenRouter 配置',
getApiKeyAt: '在此获取 API Key:',
or: '或',
@@ -1632,7 +1672,7 @@ const resources = {
nicknameOptional: '昵称(选填)',
nicknamePlaceholder: '例如:工作、个人',
nicknameRequiredHint: '该提供商必填。请使用唯一易记名称(如工作、个人)。',
nicknameOptionalHint: '用于区分账号的友好名称。留空将根据邮箱自动生成。',
nicknameOptionalHint: '用于区分账号的友好名称。留空将自动生成安全标识。',
waitingForAuth: '等待认证中...',
deviceCodeHint: '验证码对话框即将出现,请在提供商网站输入验证码。',
browserHint: '在浏览器中完成认证后,本对话框将自动关闭。',
@@ -1755,9 +1795,14 @@ const resources = {
quickUsage: '快速使用',
runWithProfile: '使用配置运行',
runOnDroid: '在 Droid 上运行',
runOnDroidWithFlag: '通过 --target 在 Droid 上运行',
droidAliasExplicit: 'Droid 别名(显式)',
overrideToClaude: '切换为 Claude',
overrideToClaudeExplicit: '切换为 Claude(显式)',
targetHintPreferredAlias: '推荐显式别名:',
targetHintClaudeDefault: '默认命令:',
targetHintLegacyAlias: '旧快捷方式仍可用:',
targetHintOverride: '你仍可在每次运行时用',
setAsDefault: '设为默认',
provider: '提供商',
custom: '自定义',
@@ -2566,6 +2611,25 @@ const resources = {
'Truy cập các mô hình {{modelCountLabel}} từ OpenAI, Anthropic, Google, Meta, v.v. - tất cả đều thông qua một API.',
featureOneApi: 'Một API cho mọi nhà cung cấp',
featureTierMapping: 'Ánh xạ tầng mô hình',
profileCount: '{{count}} hồ sơ',
profileCount_other: '{{count}} hồ sơ',
selectProfileTitle: 'Chọn một hồ sơ API',
summaryDescriptionWithProfiles:
'Bạn đã có {{count}} hồ sơ trong workspace này. Chọn một hồ sơ ở thanh bên trái để chỉnh sửa, hoặc tạo thêm hồ sơ mới tại đây.',
summaryDescriptionWithProfiles_other:
'Bạn đã có {{count}} hồ sơ trong workspace này. Chọn một hồ sơ ở thanh bên trái để chỉnh sửa, hoặc tạo thêm hồ sơ mới tại đây.',
summaryDescriptionNoProfiles:
'Dùng API Profiles cho các endpoint tương thích Anthropic. Dùng AI Providers cho Gemini, Codex, Claude, Vertex và các connector tương thích OpenAI.',
openrouterModelsBadge: '{{modelCountLabel}} mô hình OpenRouter',
runtimeProviderBadge: 'Thiết lập nhà cung cấp runtime',
runtimeProviderTitle: 'Mở AI Providers',
runtimeProviderDescription:
'Quản lý khóa nhà cung cấp dùng chung và các connector runtime trước khi tạo API Profiles độc lập.',
runtimeProviderFeatureConnectors:
'Gemini, Codex, Claude, Vertex và các connector tương thích OpenAI',
runtimeProviderFeatureSecrets: 'Khóa dùng chung tách biệt khỏi từng API Profile',
runtimeProviderFooter:
'Phù hợp nhất khi nhiều hồ sơ cần dùng chung một cấu hình nhà cung cấp.',
createOpenRouterProfile: 'Tạo hồ sơ OpenRouter',
getApiKeyAt: 'Nhận khóa API của bạn tại',
or: 'hoặc',
@@ -2804,7 +2868,7 @@ const resources = {
nicknameRequiredHint:
'Bắt buộc với nhà cung cấp này. Dùng tên thân thiện duy nhất (ví dụ: work, personal).',
nicknameOptionalHint:
'Một cái tên thân thiện để xác định tài khoản này. Tự động tạo từ email nếu để trống.',
'Tên thân thiện để nhận biết tài khoản này. Để trống để dùng mã nhận dạng an toàn do hệ thống tạo.',
waitingForAuth: 'Đang chờ xác thực...',
deviceCodeHint:
'Hộp thoại mã xác minh sẽ sớm xuất hiện. Nhập mã trên trang web của nhà cung cấp.',
@@ -2932,9 +2996,14 @@ const resources = {
quickUsage: 'Sử dụng nhanh',
runWithProfile: 'Chạy với hồ sơ',
runOnDroid: 'Chạy trên Droid',
runOnDroidWithFlag: 'Chạy trên Droid (--target)',
droidAliasExplicit: 'Bí danh Droid (rõ ràng)',
overrideToClaude: 'Ghi đè lên Claude',
overrideToClaudeExplicit: 'Ghi đè lên Claude (rõ ràng)',
targetHintPreferredAlias: 'Bí danh rõ ràng nên dùng:',
targetHintClaudeDefault: 'Lệnh mặc định:',
targetHintLegacyAlias: 'Lối tắt cũ vẫn dùng được:',
targetHintOverride: 'Bạn vẫn có thể ghi đè mỗi lần chạy bằng',
setAsDefault: 'Đặt làm mặc định',
provider: 'Nhà cung cấp',
custom: 'Tùy chỉnh',
@@ -3767,6 +3836,25 @@ const resources = {
'OpenAI、Anthropic、Google、Meta などの {{modelCountLabel}} モデルを、1 つの API で利用できます。',
featureOneApi: '1 つの API で全プロバイダー',
featureTierMapping: 'モデルティアマッピング',
profileCount: '{{count}} 個の API プロファイル',
profileCount_other: '{{count}} 個の API プロファイル',
selectProfileTitle: 'API プロファイルを選択',
summaryDescriptionWithProfiles:
'このワークスペースには既に {{count}} 個の API プロファイルがあります。左側レールから 1 つ選んで編集するか、ここから新しいプロファイルを作成してください。',
summaryDescriptionWithProfiles_other:
'このワークスペースには既に {{count}} 個の API プロファイルがあります。左側レールから 1 つ選んで編集するか、ここから新しいプロファイルを作成してください。',
summaryDescriptionNoProfiles:
'API Profiles は Anthropic 互換エンドポイント向けです。AI Providers は Gemini、Codex、Claude、Vertex、OpenAI 互換コネクタ向けです。',
openrouterModelsBadge: '{{modelCountLabel}} 個の OpenRouter モデル',
runtimeProviderBadge: 'ランタイムプロバイダー設定',
runtimeProviderTitle: 'AI Providers を開く',
runtimeProviderDescription:
'個別の API プロファイルを作成する前に、共有プロバイダーキーとランタイムコネクタを管理します。',
runtimeProviderFeatureConnectors: 'Gemini、Codex、Claude、Vertex、OpenAI 互換コネクタ',
runtimeProviderFeatureSecrets:
'共有シークレットを個別の API プロファイルから切り離して管理',
runtimeProviderFooter:
'複数のプロファイルで 1 つのプロバイダー設定を共有したい場合に最適です。',
createOpenRouterProfile: 'OpenRouter プロファイルを作成',
getApiKeyAt: 'API キー取得:',
or: 'または',
@@ -4004,7 +4092,7 @@ const resources = {
nicknameRequiredHint:
'このプロバイダーでは必須です。重複しないわかりやすい名前を付けてください(例: work, personal)。',
nicknameOptionalHint:
'このアカウントを識別しやすい名前です。空欄ならメールアドレスから自動生成されます。',
'このアカウントを識別しやすい名前です。空欄の場合は安全な識別子を自動生成します。',
waitingForAuth: '認証を待機中...',
deviceCodeHint:
'確認コードのダイアログがまもなく表示されます。プロバイダーのサイトでコードを入力してください。',
@@ -4133,9 +4221,14 @@ const resources = {
quickUsage: 'クイック実行',
runWithProfile: 'このプロファイルで実行',
runOnDroid: 'Droid で実行',
runOnDroidWithFlag: '--target で Droid 実行',
droidAliasExplicit: 'Droid エイリアス(明示)',
overrideToClaude: 'Claude に切り替え',
overrideToClaudeExplicit: 'Claude に切り替え(明示)',
targetHintPreferredAlias: '推奨の明示エイリアス:',
targetHintClaudeDefault: 'デフォルトコマンド:',
targetHintLegacyAlias: '従来ショートカットも利用可能:',
targetHintOverride: '実行ごとに次でも上書きできます',
setAsDefault: 'デフォルトに設定',
provider: 'プロバイダー',
custom: 'カスタム',
-9
View File
@@ -233,15 +233,6 @@ export function getDeviceCodeProviderInstruction(provider: unknown): string {
return 'Complete the authorization in your browser.';
}
/** Providers that require nickname because token payload may not include email. */
export const NICKNAME_REQUIRED_PROVIDERS: CLIProxyProvider[] = ['ghcp', 'kiro'];
/** Check if provider requires user-supplied nickname in auth flow */
export function isNicknameRequiredProvider(provider: unknown): boolean {
const normalized = normalizeProviderInput(provider);
return isValidProvider(normalized) && NICKNAME_REQUIRED_PROVIDERS.includes(normalized);
}
/** Kiro auth methods exposed in CCS UI (aligned with CLIProxyAPIPlus support). */
export const KIRO_AUTH_METHODS = ['aws', 'aws-authcode', 'google', 'github'] as const;
export type KiroAuthMethod = (typeof KIRO_AUTH_METHODS)[number];
+8 -8
View File
@@ -68,7 +68,7 @@ export const SUPPORT_NOTICES: SupportNotice[] = [
highlights: [
'Set default target to Droid when creating or editing API Profiles.',
'Set default target to Droid for CLIProxy variants, including Codex and Antigravity flows.',
'Use ccsd alias or --target droid for one-off target overrides.',
'Use ccs-droid as the explicit alias, with ccsd kept as the legacy shortcut.',
],
actions: [
{
@@ -88,11 +88,11 @@ export const SUPPORT_NOTICES: SupportNotice[] = [
path: '/cliproxy',
},
{
id: 'copy-ccsd-command',
label: 'Run once with Droid alias',
description: 'Use ccsd to force Droid target with your current profile.',
id: 'copy-ccs-droid-command',
label: 'Run once with explicit Droid alias',
description: 'Use ccs-droid to force the Droid target with your current profile.',
type: 'command',
command: 'ccsd glm',
command: 'ccs-droid glm',
},
{
id: 'copy-target-override',
@@ -107,7 +107,7 @@ export const SUPPORT_NOTICES: SupportNotice[] = [
{ label: 'CLIProxy', path: '/cliproxy' },
],
commands: [
'ccsd glm',
'ccs-droid glm',
'ccs codex --target droid "your prompt"',
'ccs cliproxy create mycodex --provider codex --target droid',
],
@@ -182,8 +182,8 @@ export const CLI_SUPPORT_ENTRIES: CliSupportEntry[] = [
{ label: 'API Profiles', path: '/providers' },
{ label: 'CLIProxy', path: '/cliproxy' },
],
commands: ['ccsd glm', 'ccs km --target droid', 'ccs codex --target droid'],
notes: 'Use ccsd alias for automatic Droid target selection.',
commands: ['ccs-droid glm', 'ccs km --target droid', 'ccs codex --target droid'],
notes: 'Use ccs-droid as the explicit runtime alias. Legacy ccsd still works.',
},
{
id: 'codex-cliproxy',
+1 -1
View File
@@ -55,7 +55,7 @@ export function AccountsPage() {
return (
<>
<div className="h-[calc(100vh-100px)] hidden lg:flex">
<div className="hidden h-full min-h-0 lg:flex">
{/* Left action column */}
<div className="w-80 border-r flex flex-col bg-muted/20 shrink-0">
<div className="p-4 border-b bg-background space-y-2">
+6 -4
View File
@@ -206,9 +206,9 @@ export function ApiPage() {
};
return (
<div className="h-[calc(100vh-100px)] flex flex-col">
<div className="flex h-full min-h-0 flex-col overflow-hidden">
<OpenRouterBanner onCreateClick={() => setCreateDialogOpen(true)} />
<div className="flex-1 flex min-h-0">
<div className="flex-1 flex min-h-0 overflow-hidden">
<div className="w-80 border-r flex flex-col bg-muted/30">
<div className="p-4 border-b bg-background">
<div className="flex items-center justify-between mb-3">
@@ -262,7 +262,7 @@ export function ApiPage() {
</div>
</div>
<ScrollArea className="flex-1">
<ScrollArea className="flex-1 min-h-0">
{isLoading ? (
<div className="p-4 text-sm text-muted-foreground">
{t('apiProfiles.loadingProfiles')}
@@ -354,7 +354,7 @@ export function ApiPage() {
/>
</div>
<div className="flex-1 flex flex-col min-w-0">
<div className="flex-1 flex flex-col min-w-0 overflow-hidden">
{selectedProfileData ? (
<>
<div className="px-4 py-2 border-b bg-background flex items-center justify-end gap-2">
@@ -387,6 +387,8 @@ export function ApiPage() {
</>
) : (
<OpenRouterQuickStart
hasProfiles={profiles.length > 0}
profileCount={profiles.length}
onCliproxyClick={() => {
navigate('/cliproxy/ai-providers');
}}
+1 -1
View File
@@ -405,7 +405,7 @@ export function ClaudeExtensionPage() {
}
return (
<div className="flex h-[calc(100vh-100px)] min-h-0">
<div className="flex h-full min-h-0 overflow-hidden">
<div className="flex w-[348px] shrink-0 flex-col border-r bg-muted/30 xl:w-[372px]">
<div className="border-b bg-background p-4">
<div className="flex items-start justify-between gap-3">
+6 -6
View File
@@ -1462,7 +1462,7 @@ export function CliproxyAiProvidersPage() {
if (isLoading) {
return (
<div className="flex h-[calc(100vh-100px)] min-h-0">
<div className="flex h-full min-h-0 overflow-hidden">
<Skeleton className="h-full w-80 rounded-none" />
<Skeleton className="h-full flex-1 rounded-none" />
</div>
@@ -1476,7 +1476,7 @@ export function CliproxyAiProvidersPage() {
: 'Failed to load CLIProxy AI providers. Check the local server and try again.';
return (
<div className="flex h-[calc(100vh-100px)] min-h-0 items-center justify-center bg-muted/10 p-6">
<div className="flex h-full min-h-0 items-center justify-center bg-muted/10 p-6">
<div className="w-full max-w-2xl rounded-xl border bg-card p-6 shadow-sm">
<div className="flex items-start gap-4">
<div className="flex h-11 w-11 items-center justify-center rounded-lg bg-destructive/10">
@@ -1549,7 +1549,7 @@ export function CliproxyAiProvidersPage() {
</div>
);
return (
<div className="flex h-[calc(100vh-100px)] min-h-0">
<div className="flex h-full min-h-0 overflow-hidden">
<div className="flex w-80 flex-col border-r bg-muted/30">
<div className="border-b bg-background p-4">
<div className="mb-1 flex items-center justify-between">
@@ -1759,7 +1759,7 @@ export function CliproxyAiProvidersPage() {
onSave={async (payload) => {
await updateMutation.mutateAsync({
family: selectedFamily,
index: selectedEntry.index,
entryId: selectedEntry.id,
data: payload,
});
void refetch();
@@ -1793,7 +1793,7 @@ export function CliproxyAiProvidersPage() {
if (editingEntry) {
await updateMutation.mutateAsync({
family: selectedFamily,
index: editingEntry.index,
entryId: editingEntry.id,
data: payload,
});
} else {
@@ -1820,7 +1820,7 @@ export function CliproxyAiProvidersPage() {
if (!deleteEntry) return;
await deleteMutation.mutateAsync({
family: selectedFamily,
index: deleteEntry.index,
entryId: deleteEntry.id,
});
setDeleteEntry(null);
}}
+1 -1
View File
@@ -8,7 +8,7 @@ import { ControlPanelEmbed } from '@/components/cliproxy/control-panel-embed';
export function CliproxyControlPanelPage() {
return (
<div className="h-[calc(100vh-100px)] flex flex-col">
<div className="flex h-full min-h-0 flex-col overflow-hidden">
<ControlPanelEmbed />
</div>
);
+1 -1
View File
@@ -338,7 +338,7 @@ export function CliproxyPage() {
};
return (
<div className="h-[calc(100vh-100px)] flex">
<div className="flex h-full min-h-0 overflow-hidden">
{/* Left Sidebar */}
<div className="w-80 border-r flex flex-col bg-muted/30">
{/* Header */}
+1 -1
View File
@@ -116,7 +116,7 @@ export function CopilotPage() {
} = useCopilot();
return (
<div className="h-[calc(100vh-100px)] flex">
<div className="flex h-full min-h-0 overflow-hidden">
{/* Left Sidebar - Status Overview */}
<div className="w-80 border-r flex flex-col bg-muted/30 shrink-0">
{/* Header */}
+1 -1
View File
@@ -633,7 +633,7 @@ export function CursorPage() {
return (
<>
<div className="h-[calc(100vh-100px)] flex">
<div className="flex h-full min-h-0 overflow-hidden">
<div className="w-80 border-r flex flex-col bg-muted/30 shrink-0">
<div className="p-4 border-b bg-background">
<div className="flex items-center justify-between mb-1">
+1 -1
View File
@@ -694,7 +694,7 @@ export function DroidPage() {
};
return (
<div className="h-[calc(100vh-100px)] overflow-hidden">
<div className="h-full min-h-0 overflow-hidden">
<PanelGroup direction="horizontal" className="h-full">
<Panel defaultSize={45} minSize={35}>
<div className="h-full border-r bg-muted/20">{renderOverview()}</div>
Loaded 100 of 109 files, more files were not shown because too many files have changed in this diff. Show more