Repository navigation
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude Thermo-nuclear reviewScope: Behavior check against spec: the Auto-mode web fallback is retained; the guidance message replaces the web error only when the CLI credential is stale or rejected ( Findings:
No other valid findings. Validation (pinned Rust 1.98.0, E-cores): |
|
Fixes landed at current head 7d0742f Finding 1 (redact the CLI token in |
…0260923' into port/micro-0.69.0-kimi-stale-cli-guidance
Lane A review: fixes at 73307e9Reviewed the whole branch against its base ( Upstream reports the error of the last strategy that was available. The web strategy is available only when it has a token to send (a manual override, an environment token, or a desktop or browser token while import is allowed). So the CLI guidance appears only when web auth had nothing to try. Defects found at 7d0742f
What changed (merge of the base at 15f1091, then 73307e9)
Tests (all new)
Mutation checks (reverted afterwards). I applied six mutations together:
Six new tests failed. Each mutation targets at least one of them (both 403 mutations target the exact-message status test). Not changed here (pre-existing or outside steipete#4086; for follow-up)
Commands and results (toolchain 1.98.0, run in the lane-a worktree through the build gate)
No frontend, locale or bridge change, and no new dependencies. Changed files stay under 1000 lines ( |
… guidance (stacked on nesszer#610) # Conflicts: # CHANGELOG.md
… by an exhausted monthly limit (stacked on nesszer#691)
Summary
In Auto mode, a Kimi Code CLI credential that is stale (expired or inside the 60 s safety margin) or rejected by the Code API (401) no longer disappears silently. Web auth still runs next. If web auth has no token to try (no manual token, and the Kimi Desktop session and browser import yield none, or Cookie Source is Off or Manual without a token), the fetch fails with:
This follows upstream's rule of reporting the last strategy that was available:
Unchanged:
device_id).Implementation:
kimi/auto.rs(new):fetch_cli_then_webruns the CLI credential, then web auth. It picks the reported failure fromWebFetchFailure::had_token. Both fetches are closures, so the order is unit-tested without network or settings.kimi/web.rsfetch_web_sessionreturnsWebFetchFailure { error, had_token }.fetch_with_web_tokenswith an injected fetch. Its behavior is unchanged, except that the HTTP client is built at the first token.fetch_via_webkeeps its signature.kimi/code_api.rskimi_code_cli_credentialreturnsKimiCliCredential { Unavailable, Stale, Fresh(token) }. A refresh-only file isStale.code_api_status_errormaps 401 and 403 the way upstreamcodeAPIError(statusCode:)does.kimi_cli_credential_error()holds the guidance text.kimi/mod.rs: the Auto path after the API-key attempt callsauto::fetch_cli_then_web.Upstream reference
kimior configure an API key in Settings, while retaining web fallback and leaving rotating CLI credentials read-only (Kimi provider: CLI credential goes stale ~14 min after kimi-code CLI quits (refresh_token never used) steipete/CodexBar#4063)".v0.69.0, read through GET only:Sources/CodexBarCore/Providers/Kimi/KimiAPIError.swiftKimiUsageFetcher.swift(codeAPIError(statusCode:))KimiProviderDescriptor.swift(KimiCLICredentialFetchStrategy,KimiWebFetchStrategy.isAvailable,KimiCodeAPIFallbackPolicy)ProviderFetchPlan.swift(last-available-error rule)Tests/CodexBarTests/KimiAPIErrorTests.swift,Tests/CodexBarTests/KimiCLICredentialLifecycleTests.swiftcodex/integrate-reviewed-ports-20260923), which changeskimi/code_api.rsandkimi/mod.rs.Ported / Deferred
Ported:
hasKimiCodeCredential(access or refresh token).KimiCLICredentialLifecycleTests: stale or rejected CLI falls back to web auth, CLI-only Auto explains renewal and the API key setting, the next read recovers after the CLI replaces its credential, and the 839/840/900 s boundary with file bytes unchanged.KimiAPIErrorTests: guidance contents.Deferred or different (not changed here):
invalidRequest(400) and parse failures. This is pre-existing.device_idis written for CLI requests (upstream mints one when it sends a request). The CLI home stays read-only.ProviderError::Other, so the provider state is Unknown rather than Needs authentication.refresh_tokenfails the credential decode. Upstream reads it as "". The field type is pre-existing.kimi.api,kimi.cli,kimi.web) to assert;kimi/auto.rstests cover the same order and outcomes.docs/kimi.mdhas no local counterpart; a CHANGELOG entry is added instead.Validation
Lane A review at 73307e9 (toolchain 1.98.0, lane-a worktree, build gate):
cargo +1.98.0 fmt --all --check: cleancargo +1.98.0 clippy --workspace --all-targets -- -D warnings: passcargo +1.98.0 test -p codexbar --lib kimi: 86 passed, 0 failedcargo +1.98.0 test -p codexbar: 2254 passed, 0 failed, 1 ignoredcargo +1.98.0 test -p codexbar-desktop-tauri: 477 passed, 1 failed. The failure isbootstrap_payload_exposes_every_provider_variant, the known catalog-size drift (Isolate bootstrap payload test from real settings #684, fixed by Make the bootstrap catalog test hermetic (#684) #711); it is also on the base.AuthRequired, andhad_tokenforced to false. Each fails at least one new test.Review comment: #691 (comment)
Affected areas
rust/src/providers/kimi/:auto.rs(new),code_api.rs,mod.rs,web.rs)No changed file crosses 1000 lines (
mod.rs883,code_api.rs753,web.rs722,auto.rs262).UI proof
Not applicable (backend only: error text and fetch order; no UI surface changed).