Skip to content

Port upstream 0.64.0: ElevenLabs endpoint override, XI_API_KEY alias, tier casing - #726

Draft
Finesssee wants to merge 3 commits into
port/upstream-0.64.0from
port/micro-0.64.0-elevenlabs-parity
Draft

Finesssee wants to merge 3 commits into
port/upstream-0.64.0from
port/micro-0.64.0-elevenlabs-parity

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

Ports three upstream CodexBar v0.70.0 ElevenLabs behaviors (upstream commit d8d0f33). Closes audit GAP-27.

  • Endpoint override: ELEVENLABS_API_URL is validated (HTTPS or a bare host, no userinfo, no encoded or decoded host delimiters, IPv6 brackets allowed). An invalid value fails before any HTTP request with "ElevenLabs endpoint override ELEVENLABS_API_URL must use HTTPS or a bare host." The path is user/subscription when the last base segment is v1, otherwise v1/user/subscription; the query string is kept. The default stays https://api.elevenlabs.io/v1/user/subscription.
  • XI_API_KEY alias: environment lookup is ELEVENLABS_API_KEY first, then XI_API_KEY, blank values skipped. The explicit key and keyring still win over the environment. The Preferences env label now reads ELEVENLABS_API_KEY / XI_API_KEY (same pattern as the Ollama row).
  • Tier display: tier is trimmed, underscores become spaces, lowercased and title-cased per word; a status other than "active" (case-insensitive) is appended as · <status>; with no tier the raw status is shown; with neither, no plan is set (the old "Subscription" fallback and - separator are gone).

Tests

New unit tests port the upstream URL table, rejected overrides, key precedence and tier table. snapshot_surfaces_credit_and_voice_usage now expects "Creator".

  • cargo +1.98.0 fmt --all --check, cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: clean
  • cargo test -p codexbar: 2165 passed
  • Shell crate untouched (the known bootstrap_payload_exposes_every_provider_variant failure exists on the base branch).

Not ported (outside GAP-27)

Other upstream deltas noted for a later pass: current_overage validation, "ElevenLabs API error: HTTP n" messages for non-auth errors, signed 64-bit counters with clamped percent, and the dashboard URL https://elevenlabs.io/app/developers/usage.

UI proof

No layout change; the plan label text and the env-var label string change. No CUA run was needed for a string-only change, but the main worker can spot-check the plan label.

Written by the codex-2 lane (Codex gpt-6-luna xhigh, reviewed and validated by Claude).

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at 287a1d6

Validator findings, both confirmed against upstream v0.70.0 ProviderEndpointOverrideValidator.swift:

  1. has_explicit_scheme now mirrors upstream hasExplicitURLScheme exactly (no host-shape check): a <name>:<digits> value is a bare host:port whenever the text between the first ':' and the next '/', '?' or '#' is non-empty and all digits. ELEVENLABS_API_URL=myproxy:8443, proxy:8443/v1 and mock-elevenlabs:8443 now resolve to https://<host>:8443/.../v1/user/subscription. Tests added for all three.
  2. https:elevenlabs.test (explicit scheme without //) is now rejected with the upstream invalid-override message, because Foundation's URL(string:) has no host for it. The "https:" fallback in normalized_https_url was removed, the test case that pinned the old behavior was moved to the rejection list (also https:/elevenlabs.test, https:).

Commands: cargo +1.98.0 fmt --all --check; cargo +1.98.0 clippy --workspace --all-targets -- -D warnings; cargo test -p codexbar (2165 passed, 0 failed); cargo test -p codexbar-desktop-tauri (461 passed, 1 failed: the existing base failure commands::tests::bootstrap_payload_exposes_every_provider_variant, unrelated).

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at c8f874a (round 3 validator findings).

  • normalized_https_url (rust/src/providers/elevenlabs/mod.rs): the explicit-scheme guard now requires // directly after the first : (split_once(':') then rest.starts_with("//")) instead of raw.contains("://"). https:elevenlabs.test/v1?next=https://x, https:/elevenlabs.test/x://y and https:elevenlabs.test#://frag are now rejected with the upstream invalid-override message, matching Foundation's URL(string:) host-less result.
  • invalid_endpoint_overrides_are_rejected_with_the_upstream_message now also lists https:elevenlabs.test, https:/elevenlabs.test, https: and the three inputs above. Mutation check: restoring the raw.contains("://") guard makes this test fail (left Ok("https://elevenlabs.test/v1/user/subscription?next=https://x")).

Commands run: cargo +1.98.0 fmt --all --check (ok); cargo +1.98.0 clippy --workspace --all-targets -- -D warnings (ok); cargo test -p codexbar (2165 passed, 0 failed); cargo test -p codexbar-desktop-tauri (461 passed, 1 failed: commands::tests::bootstrap_payload_exposes_every_provider_variant, which also fails on the unmodified base). No frontend change.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation (Claude Opus 5.5) passed at c8f874a

Scope: GAP-27, ElevenLabs ELEVENLABS_API_URL override, XI_API_KEY alias and tier casing (upstream v0.64.0). The diff against port/upstream-0.64.0 (b585d48) touches rust/src/providers/elevenlabs/mod.rs (696 lines) and rust/src/settings/api_keys.rs (671 lines). The round-3 delta from 287a1d6 is only the explicit-scheme guard plus 6 rejection inputs.

What I checked against upstream v0.64.0 ProviderEndpointOverrideValidator.swift, ElevenLabsSettingsReader.swift, SettingsValue.swift and elevenlabs.ts:

  • Round-3 guard: an explicit-scheme override now needs // directly after the first :. That colon is the scheme colon, so the authority taken from the first :// is always the real one. https:elevenlabs.test, https:/elevenlabs.test, https:, https:elevenlabs.test/v1?next=https://x, https:/elevenlabs.test/x://y and https:elevenlabs.test#://frag are rejected, matching Foundation's host-less URL(string:) result.
  • Mutation check: with the old raw.contains("://") guard restored, invalid_endpoint_overrides_are_rejected_with_the_upstream_message fails (left Ok("https://elevenlabs.test/v1/user/subscription?next=https://x")). The file was restored to blob b37f120e afterwards.
  • Probes at this SHA (temporary tests, not committed):
    • 9 upstream-valid overrides give the same endpoint as upstream: bare host, localhost:8080, https:8443 (host https, port 8443), uppercase scheme, empty port, fragment, a query containing :, and an IPv6 literal.
    • 30 upstream-invalid overrides are rejected with the upstream message: userinfo, encoded delimiters, whitespace, http/wss/file/javascript schemes, https:///host, https:////host, backslash variants, //host, ://host, non-numeric or doubled ports, scoped IPv6 and a BOM prefix.
  • Remaining differences need contrived env values, so they don't block:
    • Rust is stricter on %2e in a host and on ports above 65535.
    • WHATWG drops an embedded tab or newline, so ht\ttps://host is accepted and /v\n1 becomes /v1.
    • A hex IPv4 host is normalized (0x7f.1 becomes 127.0.0.1).
    • An env value of a single " or ' is kept, where upstream SettingsValue.cleaned treats it as unset. The length >= 2 check follows the existing Rust ports, for example factory::clean_factory_secret.
  • Unchanged since round 2 and re-run here:
    • Endpoint build: a v1 suffix gets user/subscription, anything else gets v1/user/subscription, the query and fragment are kept, and the default is https://api.elevenlabs.io.
    • Key lookup: ELEVENLABS_API_KEY, then XI_API_KEY, with cleaned values.
    • Tier: title case, plus · status when the status is not active. With no tier, the raw status is used.
    • Nothing logs the override value or the API key, and the error message doesn't echo the env value.
  • Visible text: the plan label casing and separator change, and the envVar label becomes ELEVENLABS_API_KEY / XI_API_KEY. The bridge carries envVar, but the frontend doesn't render it. The PR body discloses the plan-label change and leaves the UI spot-check to the integration PR.
  • There is no new dependency and no wire-shape, frontend or locale change. Both files are under 1000 lines.

Checks run at this SHA (toolchain 1.98.0, isolated target dir):

  • cargo +1.98.0 fmt --all --check: clean.
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: clean.
  • cargo +1.98.0 test -p codexbar: 2165 passed, 0 failed, 1 ignored. All 8 ElevenLabs tests and settings::api_keys::tests::elevenlabs_lists_both_api_key_environment_names pass.
  • cargo +1.98.0 test -p codexbar-desktop-tauri: 461 passed, 1 failed.
    • The failing test is commands::tests::bootstrap_payload_exposes_every_provider_variant (catalog 79 vs 78).
    • I ran the same test on the unmodified base b585d48 and it fails the same way (tests.rs:1942, 79 vs 78). It depends on the host (get_bootstrap_state() calls Settings::load()), and this PR does not touch the shell crate or the provider list.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Port re-review: ElevenLabs endpoint override, XI_API_KEY alias, tier casing (#726, GAP-27)

Reviewed the branch diff c8f874a7 vs port/upstream-0.64.0 against the upstream sources at the exact port commit d8d0f3394 (upstream v0.70.0-era elevenlabs.js bundled-plugin cutover, ProviderEndpointOverrideValidator.swift, ProviderPluginManifest.swift endpoint-policy machinery, ProviderPluginRuntime.swift pct, ElevenLabsSettingsReader.swift, TestsPlugin/ElevenLabsPluginTests.swift), plus the GAP-27 spec row and the three prior validation rounds recorded in CODEX-2.md.

What I verified at the current head:

  • Endpoint override validation (subscription_url → normalized_https_url + endpoint_from_base): HTTPS-only with bare-host fallback (https:// prefix); explicit-scheme detection is a faithful port of upstream hasExplicitURLScheme (first : wins; :// accepted; an authority char before the colon disqualifies; an all-numeric port-only suffix is a host:port, not a scheme; scheme grammar alpha + alnum/+/−/.), including the validator-round-3 fix that requires // immediately after the first scheme colon so https:elevenlabs.test/v1?next=https://x and https:/elevenlabs.test/x://y are rejected like Foundation's URL(string:) would reject them. Userinfo (@), percent-encoding in the host, backslashes, control/whitespace characters are all rejected before any request, with the exact upstream message "ElevenLabs endpoint override ELEVENLABS_API_URL must use HTTPS or a bare host." Bracketed IPv6 literals stay allowed (upstream security-test case). Path rule: user/subscription appended when the last base segment is v1, else v1/user/subscription; query string preserved (never reset); fragments are impossible on a parsed Url here, matching upstream's fragment == nil gate.
  • XI_API_KEY alias: env lookup ["ELEVENLABS_API_KEY", "XI_API_KEY"], primary first, blank values skipped, quote-stripping via cleaned — matches ElevenLabsSettingsReader.apiKeyEnvironmentKeys order. Explicit key and keyring still win over env (upstream precedence). The Preferences env label is now ELEVENLABS_API_KEY / XI_API_KEY with a regression test in api_keys.rs (4 focused tests pass).
  • Tier display: trim → _→space → lowercase → per-word title-case; non-active status (case-insensitive) appended as · <status>; no tier falls back to the raw status; neither → no plan. The old "Subscription" fallback and - separator are gone. The test table carries all five upstream cases plus the none/none case.
  • Fail-closed / no-secrets: the four upstream auth messages are reproduced exactly, checked code before status, unknown/non-string/blank detail values fall back to the status-appropriate message, and the "messages never expose response body" test asserts the marker stays hidden. The error-body read is bounded (8 KiB).
  • Documented deferrals (in the PR body, outside GAP-27): current_overage validation, ElevenLabs API error: HTTP n classified messages (429/5xx), signed 64-bit counters with clamped percent, dashboard URL. I confirmed these are genuinely absent from the branch (no current_overage, no 429/rateLimited mapping), so the PR body's scope statement is accurate.
  • Validation at this head (this session, W:\wcb-wt\codex-4 at c8f874a): cargo +1.98.0 fmt --all --check clean; cargo +1.98.0 clippy -p codexbar --all-targets -- -D warnings clean; cargo test -p codexbar --lib elevenlabs 9/9 passed; cargo test -p codexbar --lib api_keys 4/4 passed.

Result: no findings. The port matches upstream semantics on all three GAP-27 behaviors; the deviating/deferred deltas are explicitly listed in the PR body and are out of this item's scope. Files under the cap (mod.rs 696, api_keys.rs 671). No dependency, bridge or frontend logic change beyond the env-label string.

Finesssee added a commit that referenced this pull request Oct 2, 2026
@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation passed at f3375b8

Scope: ElevenLabs endpoint override, XI_API_KEY alias, tier casing (#726, GAP-27), validated as merged into release/v0.70.0 (merge f3375b8 = merge of c8f874a into a8a3e96). This supplements the earlier adversarial validation at c8f874a (issuecomment-5942960656) with the merged-content check.

Attacks (merged content, on top of the earlier pass):

No defects found in the merged content. READY for the un-draft rule.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant