Skip to content

fix: match Hermes provider grants to pinned source - #70

Merged
ak5 merged 1 commit into
devfrom
fix/hermes-provider-inventory
Oct 3, 2026
Merged

ak5 merged 1 commit into
devfrom
fix/hermes-provider-inventory

Conversation

@ak5

@ak5 ak5 commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Summary

Correct the exact synthetic Hermes provider profile before its production release. Grant only GET chatgpt.com/backend-api/wham/usage for the pinned Hermes Codex quota probe, and remove /oauth/code and /oauth/token from Nous because the source uses those paths for a different provider.

Motivation and scope

Final source inventory review of pinned hermes_cli/auth.py found the Codex quota URL helper and distinguished Nous's /api/oauth/* calls from another provider's /oauth/* flow. No new host, wildcard, infrastructure or runtime behavior is introduced.

Security impact

  • Trust boundary changed: no.
  • Credential flow changed: no; the new exact GET grant forwards caller-owned Codex credentials without provider lookup.
  • Threat model: existing exact-grant boundary applies; the profile narrows unused Nous operations and explicitly declares required Codex traffic.

Documentation

The owning exact destination inventory and schema-valid example are updated together. Review found no remaining grant/source mismatch within this pinned provider profile.

Verification

  • mise run check.
  • Actual CLI validates examples/hermes-gateway.toml.
  • Configuration overlap/schema test and documentation parity.

Risk and rollback

  • Risk: client/Infra deployment proof remains required before convergence; custom providers and URLs still require reviewed exact grants.
  • Rollback: restore the installed policy revision while preserving egress isolation.

Release PR #69 must refresh its source SHA and checks after this dev correction merges.

@ak5 ak5 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 3622680 against the pinned Hermes auth source: Codex usage helper resolves to GET /backend-api/wham/usage; Nous uses /api/oauth/device/code and /api/oauth/token, while /oauth/* belongs to another provider. No new hosts or trust/credential boundaries. Final mise run check and CLI schema validation pass. Awaiting the final image gate before dev merge and refreshing release #69.

@ak5
ak5 merged commit f1d11bb into dev Oct 3, 2026
8 checks passed
@ak5
ak5 deleted the fix/hermes-provider-inventory branch October 3, 2026 17:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant