Skip to content

Reuse existing OpenCode credentials for Zen and Go - #18

Merged
shirishpothi merged 3 commits into
mainfrom
feat/opencode-credential-link
Sep 30, 2026
Merged

shirishpothi merged 3 commits into
mainfrom
feat/opencode-credential-link

Conversation

@shirishpothi

@shirishpothi shirishpothi commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Sorty connects to existing OpenCode Zen/Go credentials through a compact authentication panel in Settings and onboarding. Sign in with OpenCode launches opencode auth login in Terminal. The panel detects existing credentials, refreshes when Sorty becomes active, and watches for completion of an explicitly started sign-in. Use API key restores the separate manual-key flow.

Connected mode uses OpenCode’s current API credentials directly instead of copying them into Sorty’s Keychain. This removes the Keychain-save failure blocking connection, prevents pending manual-key writes from replacing the connected credential, and respects key rotation/revocation. Persist only the per-plan credential source, never secrets in defaults. Respect XDG_DATA_HOME, OPENCODE_AUTH_CONTENT, and stored-key precedence over OPENCODE_API_KEY; never import upstream OAuth tokens or share entries across plans.

The panel follows the app’s existing subscription status layout and button styles. Credential/source changes reset connection verification. Onboarding checks the tested configuration and test identity before publishing results. Every new action has a stable accessibility identifier. No credential probe or CLI/server launch is added to app startup. Website sign-in alone does not create local CLI credentials; the panel explains the CLI and manual-key choices.

Research and setup details: docs/agent-guides/opencode-providers.md, with T3 Code references pinned to c18e5ea6ed741443a8ec4a5d22d4b6939b0ecd21. Sorty retains its direct Zen/Go clients.

Validation: focused XCTest coverage for plan isolation, file/environment precedence, malformed/OAuth credentials, live rotation/revocation, persistence without secrets, successful connection when Keychain writes fail, stale configuration, and cancellation. git diff --check passes. Blacksmith macOS CI passed SPM build/tests, the native app build, and the secret scan on 6d3c4202. All four actionable bot review comments have been addressed and resolved. Interactive sign-in on a user’s Mac was not exercised in this Linux workspace.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 07:52

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T08:35:01.677612Z 6d3c420 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: acec22ca35

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread Sources/SortyLib/Views/Onboarding/ProviderSelectionStepView.swift
Comment thread Sources/SortyCore/ViewModels/SettingsViewModel.swift Outdated
Comment thread Sources/SortyCore/ViewModels/SettingsViewModel.swift Outdated
Comment thread Sources/SortyLib/Views/Settings/AIProviderSettingsView.swift Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6d3c42024c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread Sources/SortyCore/ViewModels/SettingsViewModel.swift
Comment thread Sources/SortyAI/ProviderAuthResolver.swift
Comment thread Sources/SortyAI/OpenCodeCredentials.swift
Comment thread Sources/SortyAI/ProviderAuthResolver.swift
@shirishpothi
shirishpothi merged commit 4e64392 into main Sep 30, 2026
2 checks passed
@shirishpothi
shirishpothi deleted the feat/opencode-credential-link branch September 30, 2026 11:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants