Conversation
…private-network HTTP
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Personal and team budgets fill the primary and secondary lanes, amounts are detail lines, Automatic prefers the team budget unless one is exhausted, and the private-network HTTP check matches upstream isPrivateNetworkHost.
UI proof (browser-use)Result: PASS on build At the maintainer's direction, this proof drove the app's WebView2 over CDP with the browser-use CLI instead of CUA. It used no keyboard, mouse or focus. All proof windows stayed on the second display, the foreground window was never part of the proof process tree, and the kit settings turned the global shortcut off. Setup
Results
Validation at
|
| Command | Result |
|---|---|
cargo fmt --all --check |
clean |
cargo clippy --workspace --all-targets -- -D warnings |
pass |
cargo test -p codexbar litellm |
26 passed |
cargo test -p codexbar |
2191 passed, 0 failed, 1 ignored |
cargo test -p codexbar-desktop-tauri |
466 passed, 0 failed. bootstrap_payload_exposes_every_provider_variant was skipped because it reads host settings on this base; #711 fixes it. |
| Frontend | Not changed by this PR. The proof build ran the frozen install, check-locale, tsc and vite build. |
Screenshots
All paths are under C:\Users\FSOS\AppData\Local\Win-CodexBar\port-audit\proof\702\shots\. The float bar window is transparent, so its captures are RGBA. Each -on-dark.png copy composites the capture onto #1c1c1e at 4x so the white pill text is readable.
702-s1-tray-personal-and-team.png: the overview card with both budgets.702-s1-tray-litellm-detail.png: the LiteLLM card with the amounts, the team reset and the cost line.702-s1-floatbar-automatic-on-dark.png: Automatic shows the team budget, 22%.702-s2-tray-personal-exhausted.pngand702-s2-floatbar-automatic-on-dark.png: the exhausted personal budget, 100%.702-s3-tray-team-only.pngand702-s3-floatbar-automatic-on-dark.png: the team-only key, 25%.702-s4-tray-spend-only.pngand702-s4-floatbar-automatic-on-dark.png: "No budget set" with the spend line, and the "0%" pill frommain.702-s5-tray-user-mismatch.pngand702-s5-floatbar-on-dark.png: the single-prefix parse error.702-settings-litellm-automatic.png,702-settings-litellm-explicit-personal.pngand702-settings-explicit-personal-floatbar-on-dark.png: the Settings detail and the metric picker round trip.
Seen during this proof (on main or the base, not caused by this PR)
- A reset more than about 24.8 days away makes the tray refresh in a loop. In
s3, the team budget resets on 2026-11-01, about 30.6 days out. Between 16:14:29 and 16:15:00 local time the mock logged 836/key/inforequests, each followed by/team/info. The loop stopped whens4(no reset) loaded. This is theuseProviderstimer overflow that Fix reset refresh timer for resets over 24.8 days away #720 fixes. A 30-day LiteLLM budget is more than 24.8 days from its reset for the first 5 days of every period, so Fix reset refresh timer for resets over 24.8 days away #720 should merge together with this PR. - The float bar renders an informational metric as a quota. In
s4the pill read "0%" and the tooltip readLiteLLM: 0% usedfollowed byResets No budget set. Fix float bar pills for informational metrics #733 fixes this for every provider. Merging Fix float bar pills for informational metrics #733 into this chain conflicts in oneFloatBar.tsxhunk from Port upstream 0.68.0: show Mistral plan amounts as detail lines (stacked on #647) #657. Resolve it withinformational ? null : resetDescriptionFallback(rateWindow). - Settings uses generic lane names. The Usage section labels the lanes "Session" and "Weekly", and the metric picker offers "Automatic / Session / Weekly". Yet the bridge sends
primaryLabel"Personal budget" andsecondaryLabel"Team budget", and the Options toggles already use those names.UsageSection.tsxandMenuBarMetricSection.tsxonmainuse fixed locale keys. The same gap shows for Kimi (Port upstream 0.69.0: mark Kimi windows blocked by an exhausted monthly limit (stacked on #691) #697, Port upstream 0.60.5: Kimi accepts monthly-only and partial ratio-pool Code API responses (stacked on #697) #730) and StepFun (Port upstream 0.63.0: StepFun credit plans (Credit label, no invented reset) #710). - Notification wording. Crossing the budget thresholds raised the generic "High Usage Warning", "Usage Limit Reached" and "Session Depleted" toasts. They were not dispatched here ("program not found") because the proof kit runs with a reduced
PATH. - An empty global shortcut logs a warning. The kit turns the shortcut off with
global_shortcut: "", andshortcut_bridgelogs "Could not parse global shortcut:" instead of treating the empty value as off.
…ets, private-network HTTP (stacked on #657)
Stacked on #657 (detail-line usage windows), so merge #657 first. Found by the 0.60.4-0.69.0 port gap audit (gap G6, 0.64.0).
Summary
LiteLLM now reads the key-bound identity and budgets the way upstream 0.64.0 does, instead of reading
/key/infoonly.GET /key/infonames the key'suser_idandteam_id. A user-bound key then callsGET /user/info?user_id=…, and a team-only key callsGET /team/info?team_id=…. A response whose user or team ID differs from the key's is rejected. A key with neither ID fails with "Parse error: LiteLLM key info did not include a user_id or team_id."team_idmatches the key is the secondary lane ("Team budget"). Other teams in the/user/inforesponse are ignored. When only the team budget exists, it takes the primary lane as "Team budget". A key without any budget shows an informational "No budget set" lane.with_description_as_detail, so they never read as reset text, and a real reset date stays visible beside them.Provider::automatic_metric_prefers_secondary_window()hook (defaultfalse,truefor LiteLLM) is read by the shell'susage_metric.rs, so shared code has no LiteLLM branch.user_email, thenuser_alias, thenmetadata.preferred_username. The organization is the matching team's alias. The key'sexpiresbecomes the subscription expiry.https-or-private-network-http). HTTPS works anywhere. Plain HTTP works only forlocalhost,.localnames, and loopback, RFC 1918, link-local or IPv6 unique-local literals. Embedded credentials and encoded delimiters (%2f %5c %3f %23 %40 %3a) are rejected, because the key is sent as a bearer token. The same validator checks the base URL saved in Settings, and the en-US help text states the rule./v1is dropped and other base path segments are kept, sohttps://host/litellm/v1becomeshttps://host/litellm/key/info. The oldUrl::joindropped the last segment.docs/PROVIDERS.md.Upstream reference
Sources/CodexBarCore/Resources/Plugins/litellm.ts,docs/litellm.mdandTests/CodexBarTests/LiteLLMUsageFetcherTests.swift.Ported
Everything in the summary. Also ported: upstream's ID cross-checks, the "missing team_id" and wrong-type failures, the required
infoenvelope on/key/info, the tolerant date parsing (a date-only value is UTC midnight), and the USD formatting with thousands separators.Deferred or different
ProviderError::Parsealready displays as "Parse error: …", so the port reads "Parse error: LiteLLM X" instead of doubling the prefix.Datereads them in local time./key/infoand replaced for/user/infoand/team/info.providers/litellm/endpoint.rsso it stays provider-local. The two can be unified once Port upstream 0.66.0: llmman provider #650 lands.mainand also affects Kimi and StepFun. The tray, the float bar and the Options toggles use "Personal budget" and "Team budget".Validation
At
f376f5ae, all withcargo +1.98.0through the E-core wrapper:cargo fmt --all --check: cleancargo clippy --workspace --all-targets -- -D warnings: passcargo test -p codexbar litellm: 26 passedcargo test -p codexbar: 2191 passed, 0 failed, 1 ignoredcargo test -p codexbar-desktop-tauri: 466 passed, 0 failed, including the three newlitellm_automatic_*tests.bootstrap_payload_exposes_every_provider_variantwas skipped because it reads host settings on this base; Make the bootstrap catalog test hermetic (#684) #711 fixes it.pnpm install --frozen-lockfile,check-locale(879 keys),tscandvite build.Affected areas
rust/src/providers/litellm/:mod.rs, the newendpoint.rsandinfo.rs, andtests.rs)Provider::automatic_metric_prefers_secondary_window(rust/src/core/provider.rs)apps/desktop-tauri/src-tauri/src/usage_metric.rs), which drives the tray icon, the tray menu and the float barrust/src/settings/provider_workspace.rs) and the en-USLiteLlmBaseUrlHelptextdocs/PROVIDERS.mdMerge notes
main, a budget reset more than about 24.8 days away puts the tray into a refresh loop, and the proof hit it with a 30-day team budget.FloatBar.tsxhunk. Resolve it withinformational ? null : resetDescriptionFallback(rateWindow). Until Fix float bar pills for informational metrics #733 lands, a spend-only key's float bar reads "0%".UI proof
PASS at
f376f5ae(browser-use over WebView2 CDP, no keyboard, mouse or focus): #702 (comment)