Repository navigation
feat(xai): add Grok 4.6/4.5 to catalog, xAI provider, and gateways - #2117
Conversation
xAI's current flagship is Grok 4.6; keep shared capability flags so gateways can reference the new models, and let /v1/models surface later Grok IDs without another catalog bump.
…iases aligned OAuth xAI sessions had no /v1/models credential, so hybrid refresh failed; also drop curated alias IDs from discovery and map grok-build-latest on Atlas/Hicap to Grok 4.5.
OAuth-only xAI sessions hashed the access token into discovery writes, but runtime limit lookups only used env credentials, so uncataloged Grok IDs fell back to default windows. Mirror stored OAuth on cache reads and isolate discovery tests from the shared config home.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (2)
📜 Recent review details🧰 Additional context used📓 Path-based instructions (9)**/*.{ts,tsx}📄 CodeRabbit inference engine (AGENTS.md)
Files:
**/*.{tsx,ts}📄 CodeRabbit inference engine (AGENTS.md)
Files:
src/**/*.ts📄 CodeRabbit inference engine (AGENTS.md)
Files:
**/*.{test,spec}.{ts,tsx}📄 CodeRabbit inference engine (AGENTS.md)
Files:
**/*.{ts,tsx,js,jsx}📄 CodeRabbit inference engine (AGENTS.md)
Files:
**/*.{test,spec}.{ts,tsx,js,jsx}📄 CodeRabbit inference engine (CONTRIBUTING.md)
Files:
**/*📄 CodeRabbit inference engine (CONTRIBUTING.md)
Files:
⚙️ CodeRabbit configuration file
Files:
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}⚙️ CodeRabbit configuration file
Files:
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}⚙️ CodeRabbit configuration file
Files:
🧠 Learnings (4)📓 Common learnings📚 Learning: 2026-06-17T03:03:34.545ZApplied to files:
📚 Learning: 2026-06-17T02:55:16.537ZApplied to files:
📚 Learning: 2026-08-07T01:57:07.096ZApplied to files:
🔇 Additional comments (6)
📝 WalkthroughWalkthroughChangesxAI Grok support
Estimated code review effort: 4 (Complex) | ~60 minutes Mergeability Score: 🟡 Moderate · up to The PR adds xAI discovery and cached model metadata, but credentialless discovery can still fail while deriving its cache key, preventing model discovery and related functionality. Fix or explicitly accept this issue before merging. Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 3❌ Failed checks (2 warnings, 1 inconclusive)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
Move OAuth /v1/models auth and cache-key alignment out of this branch so the catalog, xAI hybrid vendor, and gateway references stay reviewable on their own.
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/integrations/discoveryService.ts`:
- Around line 193-209: Restrict stored xAI OAuth token reuse to a shared
endpoint predicate requiring canonical https://api.x.ai, including the implicit
default, and reject overridden, proxy, or HTTP endpoints. Apply this rule in
withXaiDiscoveryCredentials in src/integrations/discoveryService.ts (193-209),
the model command’s apiKey handling in src/commands/model/model.tsx (371-390),
and runtime metadata cache-key logic in src/integrations/runtimeMetadata.ts
(459-473). In src/integrations/vendors/xai.test.ts (115-154), add proxy and HTTP
endpoint cases asserting no OAuth Authorization header while retaining the
canonical HTTPS case.
In `@src/integrations/vendors/xai.ts`:
- Around line 159-185: Update mapModel to validate raw is a non-null object and
model.id is a string before calling trim(), returning null for malformed entries
such as null or { id: 1 }. Preserve the existing filtering and model mapping
behavior for valid entries.
- Around line 16-17: Remove the maxOutputTokens value from the Grok 4.6 catalog
entry and its matching descriptor in the xAI model definitions, leaving
contextWindow unchanged. Ensure runtime resolution no longer receives a default
or upper output limit from these descriptors.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 45e6fb65-2847-46e5-becc-d9e862fd1e64
📒 Files selected for processing (27)
src/commands/model/model.test.tsxsrc/commands/model/model.tsxsrc/components/ProviderManager.tsxsrc/integrations/brands/xai.tssrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/integrations/gateways/atlas-cloud.tssrc/integrations/gateways/hicap.tssrc/integrations/gateways/openrouter.tssrc/integrations/models/xai.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.test.tssrc/integrations/vendors/xai.tssrc/services/api/client.test.tssrc/utils/context.test.tssrc/utils/effort.codex.test.tssrc/utils/model/configs.tssrc/utils/model/model.tssrc/utils/model/modelOptions.gateways.test.tssrc/utils/providerFlag.test.tssrc/utils/providerFlag.tssrc/utils/providerProfile.test.tssrc/utils/providerProfile.tssrc/utils/providerProfiles.test.tssrc/utils/visionUtils.test.tsweb/src/data/providers.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
- GitHub Check: smoke-and-tests (24.11.x)
- GitHub Check: Analyze (javascript-typescript)
- GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (13)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.
Files:
src/integrations/brands/xai.tssrc/utils/providerFlag.test.tssrc/integrations/gateways/hicap.tsweb/src/data/providers.tssrc/utils/providerProfile.test.tssrc/integrations/gateways/openrouter.tssrc/components/ProviderManager.tsxsrc/utils/providerFlag.tssrc/utils/context.test.tssrc/integrations/gateways/atlas-cloud.tssrc/utils/visionUtils.test.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/providerProfile.tssrc/utils/model/modelOptions.gateways.test.tssrc/commands/model/model.test.tsxsrc/utils/effort.codex.test.tssrc/integrations/models/xai.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/commands/model/model.tsxsrc/integrations/vendors/xai.test.tssrc/utils/model/model.tssrc/integrations/vendors/xai.tssrc/utils/model/configs.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
src/integrations/brands/xai.tssrc/utils/providerFlag.test.tssrc/integrations/gateways/hicap.tsweb/src/data/providers.tssrc/utils/providerProfile.test.tssrc/integrations/gateways/openrouter.tssrc/components/ProviderManager.tsxsrc/utils/providerFlag.tssrc/utils/context.test.tssrc/integrations/gateways/atlas-cloud.tssrc/utils/visionUtils.test.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/providerProfile.tssrc/utils/model/modelOptions.gateways.test.tssrc/commands/model/model.test.tsxsrc/utils/effort.codex.test.tssrc/integrations/models/xai.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/commands/model/model.tsxsrc/integrations/vendors/xai.test.tssrc/utils/model/model.tssrc/integrations/vendors/xai.tssrc/utils/model/configs.ts
src/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Usechalkfor terminal color andexecafor child-process execution when those capabilities are needed.
Files:
src/integrations/brands/xai.tssrc/utils/providerFlag.test.tssrc/integrations/gateways/hicap.tssrc/utils/providerProfile.test.tssrc/integrations/gateways/openrouter.tssrc/utils/providerFlag.tssrc/utils/context.test.tssrc/integrations/gateways/atlas-cloud.tssrc/utils/visionUtils.test.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/providerProfile.tssrc/utils/model/modelOptions.gateways.test.tssrc/utils/effort.codex.test.tssrc/integrations/models/xai.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/integrations/vendors/xai.test.tssrc/utils/model/model.tssrc/integrations/vendors/xai.tssrc/utils/model/configs.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.
Files:
src/integrations/brands/xai.tssrc/utils/providerFlag.test.tssrc/integrations/gateways/hicap.tsweb/src/data/providers.tssrc/utils/providerProfile.test.tssrc/integrations/gateways/openrouter.tssrc/components/ProviderManager.tsxsrc/utils/providerFlag.tssrc/utils/context.test.tssrc/integrations/gateways/atlas-cloud.tssrc/utils/visionUtils.test.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/providerProfile.tssrc/utils/model/modelOptions.gateways.test.tssrc/commands/model/model.test.tsxsrc/utils/effort.codex.test.tssrc/integrations/models/xai.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/commands/model/model.tsxsrc/integrations/vendors/xai.test.tssrc/utils/model/model.tssrc/integrations/vendors/xai.tssrc/utils/model/configs.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when setup, commands, or user-facing behavior changes.
Files:
src/integrations/brands/xai.tssrc/utils/providerFlag.test.tssrc/integrations/gateways/hicap.tsweb/src/data/providers.tssrc/utils/providerProfile.test.tssrc/integrations/gateways/openrouter.tssrc/components/ProviderManager.tsxsrc/utils/providerFlag.tssrc/utils/context.test.tssrc/integrations/gateways/atlas-cloud.tssrc/utils/visionUtils.test.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/providerProfile.tssrc/utils/model/modelOptions.gateways.test.tssrc/commands/model/model.test.tsxsrc/utils/effort.codex.test.tssrc/integrations/models/xai.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/commands/model/model.tsxsrc/integrations/vendors/xai.test.tssrc/utils/model/model.tssrc/integrations/vendors/xai.tssrc/utils/model/configs.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
src/integrations/brands/xai.tssrc/utils/providerFlag.test.tssrc/integrations/gateways/hicap.tsweb/src/data/providers.tssrc/utils/providerProfile.test.tssrc/integrations/gateways/openrouter.tssrc/components/ProviderManager.tsxsrc/utils/providerFlag.tssrc/utils/context.test.tssrc/integrations/gateways/atlas-cloud.tssrc/utils/visionUtils.test.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/providerProfile.tssrc/utils/model/modelOptions.gateways.test.tssrc/commands/model/model.test.tsxsrc/utils/effort.codex.test.tssrc/integrations/models/xai.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/commands/model/model.tsxsrc/integrations/vendors/xai.test.tssrc/utils/model/model.tssrc/integrations/vendors/xai.tssrc/utils/model/configs.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}
⚙️ CodeRabbit configuration file
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.
Files:
src/integrations/brands/xai.tssrc/utils/providerFlag.test.tssrc/integrations/gateways/hicap.tssrc/utils/providerProfile.test.tssrc/integrations/gateways/openrouter.tssrc/utils/providerFlag.tssrc/integrations/gateways/atlas-cloud.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/providerProfile.tssrc/utils/model/modelOptions.gateways.test.tssrc/integrations/models/xai.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/integrations/vendors/xai.test.tssrc/utils/model/model.tssrc/integrations/vendors/xai.tssrc/utils/model/configs.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
src/utils/providerFlag.test.tssrc/utils/providerProfile.test.tssrc/utils/context.test.tssrc/utils/visionUtils.test.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/model/modelOptions.gateways.test.tssrc/commands/model/model.test.tsxsrc/utils/effort.codex.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/vendors/xai.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such asbun test ./path/to/test-file.test.tswhen validating a narrowly scoped change.
Files:
src/utils/providerFlag.test.tssrc/utils/providerProfile.test.tssrc/utils/context.test.tssrc/utils/visionUtils.test.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/model/modelOptions.gateways.test.tssrc/commands/model/model.test.tsxsrc/utils/effort.codex.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/vendors/xai.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
src/utils/providerFlag.test.tssrc/utils/providerProfile.test.tssrc/utils/context.test.tssrc/utils/visionUtils.test.tssrc/utils/providerProfiles.test.tssrc/services/api/client.test.tssrc/utils/model/modelOptions.gateways.test.tssrc/commands/model/model.test.tsxsrc/utils/effort.codex.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/vendors/xai.test.ts
web/**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
When changing the web application, run the web typecheck and build checks.
Files:
web/src/data/providers.ts
web/**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
When changing files under
web/, runbun run web:typecheckandbun run web:build.
Files:
web/src/data/providers.ts
web/**
⚙️ CodeRabbit configuration file
web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.
Files:
web/src/data/providers.ts
src/services/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.
Files:
src/services/api/client.test.ts
🧠 Learnings (7)
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: When modifying provider behavior, test the exact provider/model path changed when possible and avoid breaking third-party providers.
Applied to files:
src/utils/providerFlag.test.tssrc/utils/providerProfiles.test.tssrc/commands/model/model.test.tsx
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Applied to files:
src/utils/visionUtils.test.tssrc/commands/model/model.test.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Add or update tests when a code change affects behavior.
Applied to files:
src/utils/visionUtils.test.tssrc/commands/model/model.test.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: When changing provider behavior, explicitly identify the affected provider path and test the exact provider/model path when possible.
Applied to files:
src/utils/providerProfiles.test.tssrc/commands/model/model.test.tsx
📚 Learning: 2026-06-04T22:10:36.124Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: .github/pull_request_template.md:0-0
Timestamp: 2026-06-04T22:10:36.124Z
Learning: Pull request descriptions should include a Notes section documenting provider/model paths tested, screenshots (if UI changed), and follow-up work or known limitations
Applied to files:
src/commands/model/model.test.tsx
📚 Learning: 2026-06-17T02:55:08.727Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: .github/pull_request_template.md:0-0
Timestamp: 2026-06-17T02:55:08.727Z
Learning: Pull request descriptions should include a Notes section documenting provider/model paths tested, screenshots if UI changed, and follow-up work or known limitations
Applied to files:
src/commands/model/model.test.tsx
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.
Applied to files:
src/integrations/runtimeMetadata.test.ts
🔇 Additional comments (22)
src/integrations/brands/xai.ts (1)
16-17: LGTM!src/integrations/models/xai.ts (1)
13-56: LGTM!src/integrations/gateways/openrouter.ts (1)
38-39: LGTM!src/integrations/gateways/atlas-cloud.ts (1)
54-55: LGTM!src/integrations/gateways/hicap.ts (1)
66-67: LGTM!src/components/ProviderManager.tsx (1)
244-244: LGTM!src/utils/model/configs.ts (1)
56-56: LGTM!Also applies to: 72-72, 88-88, 104-104, 120-120, 136-136, 152-152, 168-168, 184-184, 200-200, 216-216, 232-232, 248-248
src/utils/model/model.ts (1)
94-96: LGTM!Also applies to: 232-232, 282-282, 330-330, 415-417
src/utils/effort.codex.test.ts (1)
813-840: 📐 Maintainability & Code QualityVerify the focused provider checks.
The supplied context does not include test output. Run and report these commands:
bun test ./src/utils/effort.codex.test.ts bun test ./src/commands/model/model.test.tsx bun run typecheck bun run typecheck:type-testsAs per coding guidelines, “Add or update tests when behavior changes” and “Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.” As per path instructions, “Run narrow focused tests plus applicable validation ... and report exact commands in the PR.”Also applies to: 912-945
Sources: Coding guidelines, Path instructions
src/commands/model/model.test.tsx (1)
1310-1321: LGTM!Also applies to: 1586-1597
web/src/data/providers.ts (1)
239-239: 📐 Maintainability & Code QualityVerify the web checks.
The supplied context does not include web-check output. Run and report these commands:
bun run web:typecheck bun run web:buildAs per coding guidelines, “When changing files under
web/, runbun run web:typecheckandbun run web:build.” As per path instructions, “Run narrow focused tests plus applicable validation ... and report exact commands in the PR.”Sources: Coding guidelines, Path instructions
src/utils/providerFlag.ts (1)
571-571: LGTM!src/utils/providerProfile.ts (1)
1079-1079: LGTM!Also applies to: 1228-1228
src/utils/providerProfiles.test.ts (1)
2774-2774: LGTM!src/services/api/client.test.ts (1)
945-945: LGTM!src/utils/context.test.ts (1)
528-534: LGTM!src/integrations/runtimeMetadata.test.ts (1)
5-5: LGTM!Also applies to: 167-225, 526-535, 720-746, 762-790
src/utils/model/modelOptions.gateways.test.ts (1)
164-165: LGTM!Also applies to: 179-180
src/utils/providerFlag.test.ts (1)
1121-1121: LGTM!src/utils/visionUtils.test.ts (1)
66-73: LGTM!src/utils/providerProfile.test.ts (1)
919-919: LGTM!src/integrations/discoveryService.test.ts (1)
11-11: LGTM!Also applies to: 80-80, 93-93, 291-292
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
src/integrations/runtimeMetadata.test.ts (1)
5-5: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winPreserve stored xAI OAuth credentials for discovery and runtime limits.
Without
XAI_API_KEY, xAI OAuth users lose authenticated model discovery and matching cached runtime limits. Restore the OAuth credential path insrc/integrations/discoveryService.tsandsrc/integrations/runtimeMetadata.ts, and restore the regression test.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/integrations/runtimeMetadata.test.ts` at line 5, Restore the xAI OAuth credential flow in discoveryService and runtimeMetadata so stored OAuth credentials are used when XAI_API_KEY is absent, preserving authenticated model discovery and cached runtime-limit matching. Reinstate the regression coverage in runtimeMetadata.test.ts alongside the existing Bun test imports.Sources: Path instructions, Learnings
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@src/integrations/runtimeMetadata.test.ts`:
- Line 5: Restore the xAI OAuth credential flow in discoveryService and
runtimeMetadata so stored OAuth credentials are used when XAI_API_KEY is absent,
preserving authenticated model discovery and cached runtime-limit matching.
Reinstate the regression coverage in runtimeMetadata.test.ts alongside the
existing Bun test imports.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 5a6b6264-5b73-481a-9242-92ab774ad35f
📒 Files selected for processing (2)
src/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.test.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
- GitHub Check: smoke-and-tests (24.11.x)
- GitHub Check: smoke-and-tests (22)
- GitHub Check: typecheck
- GitHub Check: Analyze (javascript-typescript)
- GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
src/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Usechalkfor terminal color andexecafor child-process execution when those capabilities are needed.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such asbun test ./path/to/test-file.test.tswhen validating a narrowly scoped change.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when setup, commands, or user-facing behavior changes.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}
⚙️ CodeRabbit configuration file
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
🧠 Learnings (4)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T03:03:34.545Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-08-12T00:35:47.617Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Applied to files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Add or update tests when a code change affects behavior.
Applied to files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.
Applied to files:
src/integrations/vendors/xai.test.ts
🔇 Additional comments (1)
src/integrations/vendors/xai.test.ts (1)
1-1: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winReuse the xAI OAuth token for model discovery.
When
XAI_API_KEYis unset, discovery sends no authorization header even thoughopenaiShimresolves the stored OAuth token. Add the OAuth fallback and focused authenticated/v1/modelscoverage.⛔ Skipped due to learnings
Learnt from: CR Repo: Gitlawb/openclaude PR: 0 File: CONTRIBUTING.md:0-0 Timestamp: 2026-08-07T01:57:16.417Z Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.Source: Path instructions
There was a problem hiding this comment.
Actionable comments posted: 5
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/integrations/discoveryService.test.ts`:
- Around line 912-929: Update the authorization assertion in the
discoverModelsForRoute test to require that the captured authorization value is
null, matching the insecure-URL test’s toBeNull behavior. Keep the existing
tokenSpy assertion and request setup unchanged.
In `@src/integrations/discoveryService.ts`:
- Around line 249-281: Pair the permissive isCanonicalXaiInferenceBaseUrl check
with explicit route/URL validation at all three credential sites: in
src/integrations/discoveryService.ts:249-281, require routeId === 'xai' before
attaching the discovery apiKey; in src/integrations/runtimeMetadata.ts:459-475,
require routeId === 'xai' when deriving the cache key; and in
src/services/api/openaiShim/requestExecutor.ts:256-259, require a non-blank
trimmed request.baseUrl before setting isXaiRoute. Add focused blank-base-URL
regression tests in src/integrations/discoveryService.test.ts and
src/services/api/openaiShim/requestExecutor.test.ts, while leaving
resolveRouteCredentialValue’s permissive predicate behavior unchanged.
- Around line 124-149: Update hashDiscoveryCachePartition to derive the
partition with a single keyed HMAC-SHA256 operation instead of PBKDF2, using the
existing partition salt and serialized credential input without caching raw
serialized values. Remove DISCOVERY_CACHE_PARTITION_ITERATIONS,
DISCOVERY_CACHE_PARTITION_CACHE_LIMIT, and discoveryCachePartitions, and ensure
getDiscoveryCacheKey continues using the new partition derivation so existing
partitions naturally invalidate.
In `@src/integrations/vendors/xai.test.ts`:
- Around line 132-147: Update the mocked discovery payload in the xAI test to
use context_length instead of context_window, matching mapModel’s expected
field. Add an assertion that the grok-4.7 model returned by the test has
contextWindow equal to 500000, then validate with the specified test command.
In `@src/services/api/openaiShim/requestExecutor.test.ts`:
- Around line 444-448: The test cases in the request executor table need
coverage for an unset OPENAI_BASE_URL. Add an empty baseUrl case expecting
sendsOAuth to be false, delete process.env.OPENAI_BASE_URL instead of assigning
an empty string for that case, and update any toHaveBeenCalledTimes(1) assertion
to account for the added case. Validate with the specified test command.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 1668812e-afbf-42ec-b1d3-77739ae7f769
📒 Files selected for processing (12)
src/commands/model/model.tsxsrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/integrations/routeMetadata.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.test.tssrc/integrations/vendors/xai.tssrc/services/api/openaiShim.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/services/api/openaiShim/requestExecutor.tssrc/utils/xaiCredentials.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
- GitHub Check: smoke-and-tests (22)
- GitHub Check: Analyze (javascript-typescript)
- GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.
Files:
src/services/api/openaiShim.tssrc/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/routeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/discoveryService.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
src/services/api/openaiShim.tssrc/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/routeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/discoveryService.ts
src/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Usechalkfor terminal color andexecafor child-process execution when those capabilities are needed.
Files:
src/services/api/openaiShim.tssrc/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/routeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/discoveryService.ts
src/services/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.
Files:
src/services/api/openaiShim.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/services/api/openaiShim/requestExecutor.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.
Files:
src/services/api/openaiShim.tssrc/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/routeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/discoveryService.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when setup, commands, or user-facing behavior changes.
Files:
src/services/api/openaiShim.tssrc/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/routeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/discoveryService.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
src/services/api/openaiShim.tssrc/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/routeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/discoveryService.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}
⚙️ CodeRabbit configuration file
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.
Files:
src/services/api/openaiShim.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.tssrc/integrations/routeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/discoveryService.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
src/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such asbun test ./path/to/test-file.test.tswhen validating a narrowly scoped change.
Files:
src/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
src/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.ts
🧠 Learnings (3)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-08-12T00:35:47.617Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T03:03:34.545Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
📚 Learning: 2026-06-05T05:29:23.353Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Applied to files:
src/integrations/vendors/xai.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.
Applied to files:
src/services/api/openaiShim/requestExecutor.test.tssrc/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.ts
🔇 Additional comments (12)
src/integrations/vendors/xai.ts (1)
158-188: LGTM!src/integrations/vendors/xai.test.ts (1)
91-93: LGTM!Also applies to: 117-131, 148-174
src/integrations/discoveryService.test.ts (2)
958-989: LGTM!Also applies to: 991-1020, 1022-1056
940-956: 📐 Maintainability & Code QualityNo change needed. The file-level
afterEachrestoresCLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFICwithrestoreEnvValue.> Likely an incorrect or invalid review comment.src/integrations/discoveryService.ts (1)
182-199: LGTM!Also applies to: 227-230, 452-456, 497-504, 558-561
src/integrations/routeMetadata.ts (1)
279-296: LGTM!Also applies to: 1035-1042
src/utils/xaiCredentials.ts (1)
113-125: LGTM!src/services/api/openaiShim.ts (1)
56-56: LGTM!Also applies to: 526-526
src/services/api/openaiShim/requestExecutor.ts (1)
295-305: LGTM!Also applies to: 324-335
src/commands/model/model.tsx (1)
20-20: LGTM!Also applies to: 370-395, 507-509, 573-573, 894-909, 1236-1246
src/integrations/runtimeMetadata.test.ts (1)
5-5: LGTM!Also applies to: 19-19, 28-28, 38-38, 169-228
src/services/api/openaiShim/requestExecutor.test.ts (1)
2-2: LGTM!Also applies to: 15-15, 57-57, 450-477, 479-497, 538-538, 585-585
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/integrations/runtimeMetadata.ts`:
- Around line 466-470: Cache the result of readXaiCredentials before the
synchronous OAuth injection branch in the runtime metadata flow, then reuse that
cached credential when resolving the xAI access token. Ensure the cache covers
the blocking credential read for all platforms while preserving the existing
apiKey, routeId, and canonical base URL conditions.
In `@src/services/api/openaiShim/requestExecutor.ts`:
- Around line 264-282: Add a debug log in the credential-filtering flow around
withoutUntrustedXaiCredential when mirrored XAI credentials are removed for a
noncanonical route, including enough context to diagnose the resulting missing
authorization header without logging any credential values. Preserve the
existing filtering behavior and validate with the requestExecutor tests.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 74cd8a0b-3b52-4bb0-8785-3bc898a3617f
📒 Files selected for processing (7)
src/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.test.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/services/api/openaiShim/requestExecutor.tssrc/utils/xaiCredentials.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
- GitHub Check: smoke-and-tests (24.11.x)
- GitHub Check: smoke-and-tests (22)
- GitHub Check: typecheck
- GitHub Check: Analyze (javascript-typescript)
- GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.
Files:
src/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/discoveryService.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
src/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/discoveryService.ts
src/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Usechalkfor terminal color andexecafor child-process execution when those capabilities are needed.
Files:
src/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/discoveryService.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.
Files:
src/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/discoveryService.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when setup, commands, or user-facing behavior changes.
Files:
src/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/discoveryService.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
src/utils/xaiCredentials.tssrc/integrations/runtimeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/discoveryService.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}
⚙️ CodeRabbit configuration file
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.
Files:
src/integrations/runtimeMetadata.tssrc/services/api/openaiShim/requestExecutor.tssrc/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.tssrc/integrations/discoveryService.ts
src/services/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.
Files:
src/services/api/openaiShim/requestExecutor.tssrc/services/api/openaiShim/requestExecutor.test.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such asbun test ./path/to/test-file.test.tswhen validating a narrowly scoped change.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/discoveryService.test.tssrc/services/api/openaiShim/requestExecutor.test.ts
🧠 Learnings (4)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-08-12T00:35:47.617Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T03:03:34.545Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
📚 Learning: 2026-06-17T03:03:34.545Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T03:03:34.545Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Applied to files:
src/integrations/discoveryService.test.tssrc/integrations/discoveryService.ts
📚 Learning: 2026-06-17T02:55:16.537Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T02:55:16.537Z
Learning: If the PR touches auth, provider routing, permissions, outbound network behavior, background execution, startup/config-home behavior, skills/plugins/MCP, CI permissions, or release scripts, verify that the review calls out the risk surface and whether it introduces a blocker.
Applied to files:
src/integrations/discoveryService.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/services/**/*.ts : Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.
Applied to files:
src/integrations/discoveryService.ts
🔇 Additional comments (7)
src/integrations/vendors/xai.test.ts (1)
139-139: LGTM!Also applies to: 157-160
src/integrations/discoveryService.test.ts (1)
929-929: LGTM!Also applies to: 958-973, 1039-1068
src/integrations/discoveryService.ts (1)
1-1: LGTM!Also applies to: 126-135, 250-250
src/utils/xaiCredentials.ts (1)
123-124: LGTM!src/services/api/openaiShim/requestExecutor.ts (2)
256-268: Blocking-issue check: none. The blank base-URL regression is fixed here.Line 259 now requires a non-blank
request.baseUrlbeforeisCanonicalXaiInferenceBaseUrl, so an unset base URL no longer marks the request as an xAI route. This also scopesx-grok-conv-idat Line 465 to the canonical host.
289-296: LGTM!Also applies to: 314-345
src/services/api/openaiShim/requestExecutor.test.ts (1)
448-457: LGTM!Also applies to: 504-535
a6121c5 to
063238c
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/commands/model/model.tsx`:
- Around line 507-510: Add focused regression coverage in model.test.tsx for the
model discovery flows around getOpenAIDiscoveryRequestOptions and
getDiscoveryCacheKey: verify initial loading uses the stable cache with
refreshXaiOAuth disabled, and each manual refresh clears then replaces that same
cache entry. Cover the related code paths at the referenced discovery and
refresh sections while preserving existing model-picker/provider behavior.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 01e5fd2f-fe40-4baa-aa07-b329381cd286
📒 Files selected for processing (7)
src/commands/model/model.tsxsrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/vendors/xai.test.tssrc/integrations/vendors/xai.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
- GitHub Check: Analyze (javascript-typescript)
- GitHub Check: Analyze (javascript-typescript)
- GitHub Check: smoke-and-tests (24.11.x)
- GitHub Check: smoke-and-tests (22)
- GitHub Check: typecheck
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.
Files:
src/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/integrations/runtimeMetadata.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
src/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/integrations/runtimeMetadata.ts
src/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Usechalkfor terminal color andexecafor child-process execution when those capabilities are needed.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/integrations/runtimeMetadata.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.
Files:
src/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/integrations/runtimeMetadata.ts
**/*.{test,spec}.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such asbun test ./path/to/test-file.test.tswhen validating a narrowly scoped change.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when setup, commands, or user-facing behavior changes.
Files:
src/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/integrations/runtimeMetadata.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
src/integrations/vendors/xai.test.tssrc/commands/model/model.tsxsrc/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/integrations/runtimeMetadata.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}
⚙️ CodeRabbit configuration file
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/vendors/xai.tssrc/integrations/discoveryService.tssrc/integrations/discoveryService.test.tssrc/integrations/runtimeMetadata.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
src/integrations/vendors/xai.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.ts
🧠 Learnings (7)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/* : Update documentation when setup, commands, or user-facing behavior changes.
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Applied to files:
src/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Add or update tests when a code change affects behavior.
Applied to files:
src/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.
Applied to files:
src/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.test.ts
📚 Learning: 2026-06-05T05:29:23.353Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Applied to files:
src/integrations/vendors/xai.tssrc/integrations/discoveryService.ts
📚 Learning: 2026-06-17T02:55:16.537Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T02:55:16.537Z
Learning: If the PR touches auth, provider routing, permissions, outbound network behavior, background execution, startup/config-home behavior, skills/plugins/MCP, CI permissions, or release scripts, verify that the review calls out the risk surface and whether it introduces a blocker.
Applied to files:
src/integrations/discoveryService.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/services/**/*.ts : Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.
Applied to files:
src/integrations/discoveryService.ts
🔇 Additional comments (6)
src/integrations/runtimeMetadata.ts (1)
462-466: Avoid a blocking credential read on the runtime-limit path.
resolveModelRuntimeLimitsreaches this synchronous function during request planning.readXaiCredentials()can perform synchronous secure-storage I/O on some platforms. Cache the credential result outside this path or add caching inside the credential reader.src/integrations/vendors/xai.ts (1)
6-7: LGTM!src/integrations/vendors/xai.test.ts (1)
58-60: LGTM!src/integrations/discoveryService.test.ts (1)
1-5: LGTM!Also applies to: 612-652
src/integrations/discoveryService.ts (1)
218-252: 📐 Maintainability & Code QualityProvide the required validation results.
The supplied context contains no command output. Run and report the focused discovery tests,
bun run typecheck,bun run typecheck:type-tests, and the documented build, smoke, andbun run integrations:checkcommands.As per coding guidelines, “Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.” As per path instructions, “Run the narrowest relevant checks plus the documented validation suite ... report exact commands in the PR.”Also applies to: 424-430, 472-479, 533-536
Sources: Coding guidelines, Path instructions
src/integrations/runtimeMetadata.test.ts (1)
5-5: LGTM!Also applies to: 76-119
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/integrations/discoveryService.ts`:
- Around line 223-233: Update the discovery credential flow around the token
resolution to use await readXaiCredentialsAsync() for both the initial
credentials read and the post-refresh reread, replacing synchronous
readXaiCredentials() calls while preserving the fallback behavior. Update
discoveryService.test.ts mocks to provide the asynchronous credential reader.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 55b97b03-81c6-474e-88d4-fd41a23841e3
📒 Files selected for processing (4)
src/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/integrations/runtimeMetadata.tssrc/utils/xaiCredentials.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
- GitHub Check: typecheck
- GitHub Check: smoke-and-tests (24.11.x)
- GitHub Check: smoke-and-tests (22)
- GitHub Check: Analyze (javascript-typescript)
- GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.
Files:
src/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
src/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
src/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Usechalkfor terminal color andexecafor child-process execution when those capabilities are needed.
Files:
src/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.
Files:
src/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when setup, commands, or user-facing behavior changes.
Files:
src/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
src/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}
⚙️ CodeRabbit configuration file
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.
Files:
src/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/integrations/discoveryService.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
src/integrations/discoveryService.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such asbun test ./path/to/test-file.test.tswhen validating a narrowly scoped change.
Files:
src/integrations/discoveryService.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
src/integrations/discoveryService.test.ts
🧠 Learnings (5)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/* : Update documentation when setup, commands, or user-facing behavior changes.
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Applied to files:
src/integrations/discoveryService.test.ts
📚 Learning: 2026-06-05T05:29:23.353Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Applied to files:
src/integrations/discoveryService.ts
📚 Learning: 2026-06-17T02:55:16.537Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T02:55:16.537Z
Learning: If the PR touches auth, provider routing, permissions, outbound network behavior, background execution, startup/config-home behavior, skills/plugins/MCP, CI permissions, or release scripts, verify that the review calls out the risk surface and whether it introduces a blocker.
Applied to files:
src/integrations/discoveryService.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/services/**/*.ts : Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.
Applied to files:
src/integrations/discoveryService.ts
🔇 Additional comments (4)
src/integrations/discoveryService.test.ts (1)
654-690: LGTM!src/integrations/discoveryService.ts (1)
38-38: LGTM!Also applies to: 125-131, 235-239
src/integrations/runtimeMetadata.ts (1)
31-34: LGTM!Also applies to: 469-469
src/utils/xaiCredentials.ts (1)
28-30: LGTM!Also applies to: 45-46, 64-64, 87-104, 130-153, 181-181, 197-200, 215-225, 265-265
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/integrations/discoveryService.ts`:
- Around line 124-132: The hashDiscoveryCachePartition function passes
JSON.stringify(value) directly to Hmac.update even though serialization may
return undefined; coalesce or validate the serialized result before calling
update while preserving the defined partition behavior. Then run the focused
test and TypeScript checks.
In `@src/utils/secureStorage/platformStorage.test.ts`:
- Around line 388-399: Add a focused test alongside the existing asynchronous
read test that enables OPENCLAUDE_ENABLE_LEGACY_WINDOWS_PASSWORDVAULT, makes the
DPAPI read path reject or fail, and mocks the asynchronous Password Vault
fallback to return stored data. Assert that windowsCredentialStorage.readAsync()
returns that data and verifies the asynchronous fallback invocation.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 8a3995b0-5903-41ed-ba9e-67272a6adf91
📒 Files selected for processing (9)
src/integrations/discoveryService.test.tssrc/integrations/discoveryService.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/runtimeMetadata.tssrc/utils/secureStorage/linuxSecretStorage.tssrc/utils/secureStorage/platformStorage.test.tssrc/utils/secureStorage/windowsCredentialStorage.tssrc/utils/xaiCredentials.test.tssrc/utils/xaiCredentials.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
- GitHub Check: smoke-and-tests (22)
- GitHub Check: smoke-and-tests (24.11.x)
- GitHub Check: typecheck
- GitHub Check: Analyze (javascript-typescript)
- GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.
Files:
src/utils/xaiCredentials.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/utils/secureStorage/platformStorage.test.tssrc/integrations/runtimeMetadata.test.tssrc/utils/secureStorage/linuxSecretStorage.tssrc/utils/secureStorage/windowsCredentialStorage.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
src/utils/xaiCredentials.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/utils/secureStorage/platformStorage.test.tssrc/integrations/runtimeMetadata.test.tssrc/utils/secureStorage/linuxSecretStorage.tssrc/utils/secureStorage/windowsCredentialStorage.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
src/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Usechalkfor terminal color andexecafor child-process execution when those capabilities are needed.
Files:
src/utils/xaiCredentials.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/utils/secureStorage/platformStorage.test.tssrc/integrations/runtimeMetadata.test.tssrc/utils/secureStorage/linuxSecretStorage.tssrc/utils/secureStorage/windowsCredentialStorage.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
src/utils/xaiCredentials.test.tssrc/integrations/discoveryService.test.tssrc/utils/secureStorage/platformStorage.test.tssrc/integrations/runtimeMetadata.test.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.
Files:
src/utils/xaiCredentials.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/utils/secureStorage/platformStorage.test.tssrc/integrations/runtimeMetadata.test.tssrc/utils/secureStorage/linuxSecretStorage.tssrc/utils/secureStorage/windowsCredentialStorage.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
**/*.{test,spec}.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such asbun test ./path/to/test-file.test.tswhen validating a narrowly scoped change.
Files:
src/utils/xaiCredentials.test.tssrc/integrations/discoveryService.test.tssrc/utils/secureStorage/platformStorage.test.tssrc/integrations/runtimeMetadata.test.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when setup, commands, or user-facing behavior changes.
Files:
src/utils/xaiCredentials.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/utils/secureStorage/platformStorage.test.tssrc/integrations/runtimeMetadata.test.tssrc/utils/secureStorage/linuxSecretStorage.tssrc/utils/secureStorage/windowsCredentialStorage.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
src/utils/xaiCredentials.test.tssrc/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/utils/secureStorage/platformStorage.test.tssrc/integrations/runtimeMetadata.test.tssrc/utils/secureStorage/linuxSecretStorage.tssrc/utils/secureStorage/windowsCredentialStorage.tssrc/integrations/discoveryService.tssrc/utils/xaiCredentials.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
src/utils/xaiCredentials.test.tssrc/integrations/discoveryService.test.tssrc/utils/secureStorage/platformStorage.test.tssrc/integrations/runtimeMetadata.test.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}
⚙️ CodeRabbit configuration file
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.
Files:
src/integrations/runtimeMetadata.tssrc/integrations/discoveryService.test.tssrc/integrations/runtimeMetadata.test.tssrc/integrations/discoveryService.ts
🧠 Learnings (7)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/* : Update documentation when setup, commands, or user-facing behavior changes.
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Applied to files:
src/utils/xaiCredentials.test.tssrc/integrations/discoveryService.test.tssrc/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Add or update tests when a code change affects behavior.
Applied to files:
src/utils/xaiCredentials.test.tssrc/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/**/*.ts : Use `chalk` for terminal color and `execa` for child-process execution when those capabilities are needed.
Applied to files:
src/utils/secureStorage/platformStorage.test.tssrc/utils/secureStorage/linuxSecretStorage.tssrc/utils/secureStorage/windowsCredentialStorage.ts
📚 Learning: 2026-06-05T05:29:23.353Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Applied to files:
src/integrations/discoveryService.ts
📚 Learning: 2026-06-17T02:55:16.537Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T02:55:16.537Z
Learning: If the PR touches auth, provider routing, permissions, outbound network behavior, background execution, startup/config-home behavior, skills/plugins/MCP, CI permissions, or release scripts, verify that the review calls out the risk surface and whether it introduces a blocker.
Applied to files:
src/integrations/discoveryService.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/services/**/*.ts : Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.
Applied to files:
src/integrations/discoveryService.ts
🔇 Additional comments (9)
src/utils/secureStorage/linuxSecretStorage.ts (1)
1-1: LGTM!Also applies to: 38-55
src/utils/secureStorage/windowsCredentialStorage.ts (1)
1-1: LGTM!Also applies to: 40-40, 51-71, 88-88, 103-121, 130-149, 151-186, 188-200
src/utils/secureStorage/platformStorage.test.ts (1)
40-57: LGTM!Also applies to: 102-102, 120-123, 415-427
src/utils/xaiCredentials.test.ts (1)
1-99: LGTM!src/integrations/discoveryService.test.ts (1)
615-615: LGTM!Also applies to: 667-669
src/integrations/discoveryService.ts (1)
224-224: LGTM!Also applies to: 234-234
src/integrations/runtimeMetadata.ts (1)
32-32: LGTM!Also applies to: 467-472
src/utils/xaiCredentials.ts (1)
24-24: LGTM!Also applies to: 47-50, 91-112, 149-188
src/integrations/runtimeMetadata.test.ts (1)
19-19: LGTM!Also applies to: 28-28, 41-41, 83-83
Summary
xhigheffort, 500k context) and Grok 4.5, and makegrok-4.6the xAI default./v1/modelsdiscovery, allowing later compatible Grok chat IDs to appear without another catalog release.https://api.x.airoutes.Official aliases
grok-latest,grok-4, andgrok-3remain on Grok 4.3. This PR does not introduce an inventedgrok-4.6-fastmodel ID.Scope
This PR is limited to xAI catalog/model discovery and its metadata integration. Request-executor credential-boundary work is tracked separately in #2118.
Impact
/modelcan surface compatible later chat models returned by xAI discovery.context_lengthwhen provided.Validation
bun run buildbun run smokebun run typecheckbun run integrations:checkNo live xAI credential is used in CI.
Summary by CodeRabbit
New Features
Bug Fixes