Skip to content

fix: allow agents to inherit OAuth-backed host models - #841

Merged
LivXue merged 3 commits into
EverMind-AI:mainfrom
knqiufan:fix/agents_oauth_host_inheritance
Oct 3, 2026
Merged

LivXue merged 3 commits into
EverMind-AI:mainfrom
knqiufan:fix/agents_oauth_host_inheritance

Conversation

@knqiufan

@knqiufan knqiufan commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Summary

Allow all five shipped agents to inherit an OAuth-backed host model, including OpenAI Codex, by validating the inherited model binding with the runtime credential check after parent session overrides.

  • Reuse the launcher's inheritance decision in setup and update its English/Chinese message.
  • Preserve raw provider settings, routing, reasoning effort and product limits. OAuth tokens remain in the host credential store.
  • Cover OAuth aliases, access/refresh tokens, missing or malformed credentials, custom token paths, parent bindings and independent agent keys. Remove the old API-key-only gate exemptions from the auth contract test.

Type

  • Fix
  • Feature
  • Docs
  • CI / tooling
  • Refactor
  • Other

Verification

Selected regression tests: 321 passed, 48 deselected on Windows with Python 3.12. The selection focuses on inheritance and excludes untouched POSIX permission/pruning scenarios.

uv run --no-sync pytest tests/test_config_product_render.py tests/test_subagent_vendored_agents.py tests/test_cli_subagent_setup.py tests/test_provider_auth_method.py tests/test_providers_factory.py tests/test_openai_codex_provider.py tests/test_providers_oauth_login.py tests/test_i18n_prompts.py tests/test_i18n_boundary.py -q -o addopts='' -p no:cacheprovider -k '(not test_config_product_render or inherit_llm or launchers_inherit_oauth or launchers_own_keys or secret_slots or env_wins or dig_and_put) and not prune and not backup and not locks_it_down and not test_a_page_sign_in_runs_the_real_driver_and_leaves_the_token_owner_only' --cov=raven.config.product_render --cov=raven.agent.subagent.vendored_agents --cov=raven.cli.subagent_setup --cov=raven.i18n --cov-branch --cov-report=json:C:/Users/Administrator/AppData/Local/Temp/raven_issue809_coverage_final.json --cov-report=term-missing:skip-covered

The following checks passed: Ruff across the repository, formatting (2149 files), relevant type checks, all 10 import contracts, commit messages, source language and file/asset checks.

uv run --no-sync ruff check raven evolver agents plugins-dist tests scripts docs-site
uv run --no-sync ruff format --check raven evolver agents plugins-dist tests scripts docs-site
uv run --no-sync ty check raven/config/product_render.py raven/agent/subagent/vendored_agents.py raven/cli/subagent_setup.py
uv run --no-sync lint-imports
uv run --no-sync python scripts/check_commit_messages.py main..HEAD
uv run --no-sync python scripts/check_source_language.py main..HEAD
uv run --no-sync python scripts/check_large_files.py main..HEAD

Changed-line coverage: 100% (22/22 executable lines) after normalizing the Windows report's path separators.

uv run --no-sync python -c "import json,pathlib; p=pathlib.Path('C:/Users/Administrator/AppData/Local/Temp/raven_issue809_coverage_final.json'); d=json.loads(p.read_text(encoding='utf-8')); d['files']={k.replace(chr(92), '/'):v for k,v in d['files'].items()}; p.with_name('raven_issue809_coverage_posix.json').write_text(json.dumps(d), encoding='utf-8')"
uv run --no-sync python scripts/coverage_gate.py --coverage-json C:/Users/Administrator/AppData/Local/Temp/raven_issue809_coverage_posix.json diff --base-ref main --head HEAD --threshold 90

Full local CI remains unverified: make ci could not run because make is unavailable. Existing POSIX file-permission tests fail on Windows. uv run --no-sync deptry raven reports 12 missing optional channel dependencies in this environment.

  • Relevant tests pass locally
  • Relevant lint / type checks pass locally
  • User-facing docs or screenshots are updated when needed

Risk

Inheritance now refuses an unavailable selected model even when an unrelated provider has an API key. API-key and independent-agent-key paths remain covered. Credential validation only reads stored OAuth credentials; it does not sign in or serialize tokens. Revert this change to restore the previous inheritance gate.

  • Security impact considered
  • Backward compatibility considered
  • Rollback path is clear for risky changes

Related Issues

Fixes #809

@knqiufan
knqiufan requested a review from LivXue as a code owner October 3, 2026 03:54
knqiufan and others added 2 commits October 3, 2026 12:33
Use the runtime credential check for the inherited model binding, including
stored OAuth credentials and parent session overrides. Reuse the same
inheritance decision in setup while preserving raw provider settings and
keeping OAuth tokens outside rendered agent configs.

Cover every shipped launcher, independent keys, missing credentials,
provider aliases, custom token paths, and setup readiness.

Co-authored-by: Codex <noreply@openai.com>
Select the configured OpenRouter chat model in the custom image test so
its image-credential assertions run with a usable inherited host binding.
Add a regression proving that an unrelated provider key cannot authenticate
the selected host model.

Co-authored-by: Codex <noreply@openai.com>
@knqiufan
knqiufan force-pushed the fix/agents_oauth_host_inheritance branch from a699451 to a918fde Compare October 3, 2026 04:35
@LivXue
LivXue merged commit d90b6de into EverMind-AI:main Oct 3, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(agents): built-in agents cannot inherit an OAuth-backed host LLM

3 participants