Reuse existing OpenCode credentials for Zen and Go - #18
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: acec22ca35
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6d3c42024c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Sorty connects to existing OpenCode Zen/Go credentials through a compact authentication panel in Settings and onboarding. Sign in with OpenCode launches
opencode auth loginin Terminal. The panel detects existing credentials, refreshes when Sorty becomes active, and watches for completion of an explicitly started sign-in. Use API key restores the separate manual-key flow.Connected mode uses OpenCode’s current API credentials directly instead of copying them into Sorty’s Keychain. This removes the Keychain-save failure blocking connection, prevents pending manual-key writes from replacing the connected credential, and respects key rotation/revocation. Persist only the per-plan credential source, never secrets in defaults. Respect
XDG_DATA_HOME,OPENCODE_AUTH_CONTENT, and stored-key precedence overOPENCODE_API_KEY; never import upstream OAuth tokens or share entries across plans.The panel follows the app’s existing subscription status layout and button styles. Credential/source changes reset connection verification. Onboarding checks the tested configuration and test identity before publishing results. Every new action has a stable accessibility identifier. No credential probe or CLI/server launch is added to app startup. Website sign-in alone does not create local CLI credentials; the panel explains the CLI and manual-key choices.
Research and setup details:
docs/agent-guides/opencode-providers.md, with T3 Code references pinned toc18e5ea6ed741443a8ec4a5d22d4b6939b0ecd21. Sorty retains its direct Zen/Go clients.Validation: focused XCTest coverage for plan isolation, file/environment precedence, malformed/OAuth credentials, live rotation/revocation, persistence without secrets, successful connection when Keychain writes fail, stale configuration, and cancellation.
git diff --checkpasses. Blacksmith macOS CI passed SPM build/tests, the native app build, and the secret scan on6d3c4202. All four actionable bot review comments have been addressed and resolved. Interactive sign-in on a user’s Mac was not exercised in this Linux workspace.