-
Notifications
You must be signed in to change notification settings - Fork 1.3k
fix(acp): allow API-key based auth to bypass forced OAuth login #2185
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -74,26 +74,35 @@ async def initialize( | |
| terminal_args = args + ["login"] | ||
|
|
||
| # Build and cache auth methods for reuse in AUTH_REQUIRED errors | ||
| self._auth_methods = [ | ||
| acp.schema.AuthMethod( | ||
| id="login", | ||
| name="Login with Kimi account", | ||
| description=( | ||
| "Run `kimi login` command in the terminal, " | ||
| "then follow the instructions to finish login." | ||
| # Skip login method if user already has API-key based auth configured | ||
| config = load_config() | ||
| has_api_key = any( | ||
| provider.api_key and provider.api_key.get_secret_value() | ||
| for provider in config.providers.values() | ||
| ) | ||
| if has_api_key or self._check_token_usable() is None: | ||
| self._auth_methods = [] | ||
|
Comment on lines
+83
to
+84
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟡 AUTH_REQUIRED error raised with empty authMethods when token expires mid-session When the OAuth token is valid at Prompt for agentsWas this helpful? React with 👍 or 👎 to provide feedback.
Comment on lines
+83
to
+84
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Useful? React with 👍 / 👎. |
||
| else: | ||
| self._auth_methods = [ | ||
| acp.schema.AuthMethod( | ||
| id="login", | ||
| name="Login with Kimi account", | ||
| description=( | ||
| "Run `kimi login` command in the terminal, " | ||
| "then follow the instructions to finish login." | ||
| ), | ||
| # Store auth data in field_meta for building AUTH_REQUIRED error | ||
| field_meta={ | ||
| "terminal-auth": { | ||
| "command": command, | ||
| "args": terminal_args, | ||
| "label": "Kimi Code Login", | ||
| "env": {}, | ||
| "type": "terminal", | ||
| } | ||
| }, | ||
| ), | ||
| # Store auth data in field_meta for building AUTH_REQUIRED error | ||
| field_meta={ | ||
| "terminal-auth": { | ||
| "command": command, | ||
| "args": terminal_args, | ||
| "label": "Kimi Code Login", | ||
| "env": {}, | ||
| "type": "terminal", | ||
| } | ||
| }, | ||
| ), | ||
| ] | ||
| ] | ||
|
|
||
| return acp.InitializeResponse( | ||
| protocol_version=self.negotiated_version.protocol_version, | ||
|
|
@@ -129,6 +138,15 @@ def _check_auth(self) -> None: | |
| """Check if Kimi Code authentication is complete. Raise AUTH_REQUIRED if not.""" | ||
| reason = self._check_token_usable() | ||
| if reason: | ||
| # Allow API-key based authentication as an alternative to OAuth | ||
| config = load_config() | ||
| has_api_key = any( | ||
| provider.api_key and provider.api_key.get_secret_value() | ||
| for provider in config.providers.values() | ||
|
Comment on lines
+143
to
+145
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Useful? React with 👍 / 👎. |
||
| ) | ||
| if has_api_key: | ||
| return | ||
|
|
||
| auth_methods_data: list[dict[str, Any]] = [] | ||
| for m in self._auth_methods: | ||
| if m.field_meta and "terminal-auth" in m.field_meta: | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Avoid clearing
self._auth_methodsininitializewhen auth currently looks usable._check_auth()later builds itsAUTH_REQUIREDpayload from this cached list, so if the token expires (or API-key config is removed) after initialization, the server will returnAUTH_REQUIREDwith an emptyauthMethodsarray and clients lose the terminal login action (kimi login) needed to recover.Useful? React with 👍 / 👎.