Port upstream 0.64.0: Hugging Face 12 h identity cache, billing-permission message, API-only without cookies - #725
Conversation
…p API-only off cookies
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ount The shell forced the OAuth (API-only) source for any token account with an environment override, which skipped the prepaid wallet. A new Provider::token_account_preserves_auto_source hook lets Hugging Face keep Auto, matching upstream's base-source resolver; an explicit API source still stays API-only.
|
Fixes landed at 78d8932 Reviewer issue: desktop users with an active Hugging Face token account never got the prepaid wallet. Confirmed: the shell forced Change:
Commands run: |
|
Adversarial validation (Claude Opus 5.5) passed at 78d8932 Scope re-checked (round 2): GAP-11 (12 h token-keyed whoami identity cache), GAP-12 (403 billing-permission message), GAP-18 (no cookie access in API-only mode), plus the new Checks run on this head (detached worktree, gated build):
No frontend, locale, dependency or UI change; no file crosses 1000 lines because of this PR. |
… billing-permission message, API-only without cookies
…nt isolation folds into the Kimi auto seam and the #725 wallet rule)
|
Adversarial validation passed at 417e4fe Scope: Hugging Face 12h identity cache, billing-permission message, API-only without cookies (#725, upstream 0.64.0), validated as merged into release/v0.70.0 (merge 417e4fe = merge of 78d8932 into 5ad2766). Attacks (highest-risk semantics, from the merged tree):
No defects found. READY for the un-draft rule. |
Summary
Three Hugging Face parity fixes on the API/billing lane:
whoami-v2identity is cached for 12 h per token (SHA-256 key, raw token never stored, 32-entry cap). Expired (>= 12 h), clock-skewed (age < 0), failed or empty lookups are never served stale. Switching tokens never reuses another account's identity.AuthRequired("sign in again"). 401 staysAuthRequired; 429 and 5xx messages are unchanged. Optional calls (whoami, ZeroGPU, wallet pages) stay best-effort.SourceMode::OAuth) makes no browser-cookie call and requests no browser billing page. In Auto mode the cookie/wallet step runs only after the token identity is known and has a user id, and the browser identity is still re-verified on every refresh, so a cached identity cannot keep a wallet after the browser account changes.Upstream reference
steipete/CodexBar
v0.70.0:Sources/CodexBarCore/Resources/Plugins/huggingface.ts(whoami-v2:+ token cache, 43200 s / 43200000 ms window, 403 message, wallet gated onidentity.userID),Tests/CodexBarTests/HuggingFacePluginTests.swift(identity cache isolated per token, billing failure classification),HuggingFaceWalletPluginTests.swift(API only never resolves cookies; cached identity cannot retain a wallet),docs/huggingface.md. 0.64.0 audit item G1 (steipete#3399).Ported / Deferred
Ported: all three behaviors above, with deterministic tests (injected clock and counting fakes; a local TCP server proves an HTML 403 body still yields the permission message).
Deferred: upstream also honors a per-provider cookie "Off"/"Manual" policy for the wallet. Win-CodexBar's
FetchContextdoes not carry that policy for Hugging Face (there is no cookie picker), so only the source-mode gate is ported. A plan-only whoami response (isProwithout name/email/id) is no longer cached or shown as an identity, matching upstream'susername || email || userIDcondition.Validation
cargo +1.98.0 fmt --all --check: cleancargo +1.98.0 clippy --workspace --all-targets -- -D warnings: passcargo +1.98.0 test -p codexbar --lib huggingface: 26 passedcargo +1.98.0 test -p codexbar: 2169 passed, 0 failed, 1 ignoredcargo +1.98.0 test -p codexbar-desktop-tauri: 461 passed, 1 failed:commands::tests::bootstrap_payload_exposes_every_provider_variant(79 vs 78) reads the machine's real settings; it is the known environment-dependent test tracked in Isolate bootstrap payload test from real settings #684/Make the bootstrap catalog test hermetic (#684) #711 and does not touch this change.Affected areas
rust/src/providers/huggingface/only (mod.rs,wallet.rs, newidentity_cache.rs). No frontend, locale, tray, settings or dependency changes (sha2is already a dependency).UI proof
Not applicable (backend only).
Implemented by Codex gpt-6-luna (xhigh) via ACPX; reviewed and validated by Claude.