Skip to content

feat(xai): add Grok 4.6/4.5 to catalog, xAI provider, and gateways - #2117

Merged
kevincodex1 merged 13 commits into
mainfrom
feat/xai-grok-46
Aug 13, 2026
Merged

kevincodex1 merged 13 commits into
mainfrom
feat/xai-grok-46

Conversation

@jatmn

@jatmn jatmn commented Aug 12, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Add shared catalog descriptors for Grok 4.6 (xhigh effort, 500k context) and Grok 4.5, and make grok-4.6 the xAI default.
  • Switch the xAI catalog to hybrid /v1/models discovery, allowing later compatible Grok chat IDs to appear without another catalog release.
  • Add the corresponding Grok mappings for OpenRouter, Atlas Cloud, and Hicap.
  • Use stored xAI OAuth credentials for discovery and cached runtime metadata only on canonical https://api.x.ai routes.

Official aliases grok-latest, grok-4, and grok-3 remain on Grok 4.3. This PR does not introduce an invented grok-4.6-fast model ID.

Scope

This PR is limited to xAI catalog/model discovery and its metadata integration. Request-executor credential-boundary work is tracked separately in #2118.

Impact

  • New xAI and mapped gateway sessions can select Grok 4.6.
  • /model can surface compatible later chat models returned by xAI discovery.
  • Uncataloged discovered models use the API's context_length when provided.

Validation

  • bun run build
  • bun run smoke
  • bun run typecheck
  • Focused catalog, discovery, runtime-metadata, model-picker, and provider tests
  • bun run integrations:check

No live xAI credential is used in CI.

Summary by CodeRabbit

  • New Features

    • Added support for xAI Grok 4.6 and Grok 4.5 across supported model catalogs and providers.
    • Grok 4.6 is now the default xAI model.
    • Added reasoning controls, vision support, aliases, and expanded 500,000-token context support.
    • Improved model discovery with xAI OAuth credentials, caching, refresh behavior, and safer endpoint handling.
    • Updated model selection and refresh flows to show current model information.
  • Bug Fixes

    • Improved reliability of asynchronous credential retrieval and secure-storage access.
    • Preserved discovery access across credential refreshes without unnecessary cache invalidation.

jatmn added 3 commits August 12, 2026 10:37
xAI's current flagship is Grok 4.6; keep shared capability flags so gateways can reference the new models, and let /v1/models surface later Grok IDs without another catalog bump.
…iases aligned

OAuth xAI sessions had no /v1/models credential, so hybrid refresh failed; also drop curated alias IDs from discovery and map grok-build-latest on Atlas/Hicap to Grok 4.5.
OAuth-only xAI sessions hashed the access token into discovery writes, but
runtime limit lookups only used env credentials, so uncataloged Grok IDs
fell back to default windows. Mirror stored OAuth on cache reads and isolate
discovery tests from the shared config home.
@coderabbitai

coderabbitai Bot commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 5a89834b-cf1f-482b-90a6-748b889b964e

📥 Commits

Reviewing files that changed from the base of the PR and between 3d43636 and 449a3c7.

📒 Files selected for processing (2)
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
📜 Recent review details
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/integrations/discoveryService.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/integrations/discoveryService.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/integrations/discoveryService.test.ts
🧠 Learnings (4)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/* : Update documentation when setup, commands, or user-facing behavior changes.
📚 Learning: 2026-06-17T03:03:34.545Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T03:03:34.545Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.

Applied to files:

  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
📚 Learning: 2026-06-17T02:55:16.537Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T02:55:16.537Z
Learning: If the PR touches auth, provider routing, permissions, outbound network behavior, background execution, startup/config-home behavior, skills/plugins/MCP, CI permissions, or release scripts, verify that the review calls out the risk surface and whether it introduces a blocker.

Applied to files:

  • src/integrations/discoveryService.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/services/**/*.ts : Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Applied to files:

  • src/integrations/discoveryService.ts
🔇 Additional comments (6)
src/integrations/discoveryService.ts (4)

1-1: 🔒 Security & Privacy

Confirm that FNV-1a meets the cache privacy contract.

The new fingerprint hides the literal credential, but FNV-1a is not a cryptographic hash. It does not provide cryptographic preimage or collision resistance. If cache names can be read or custom credentials can have low entropy, the result is not opaque as described. Use a cryptographic digest, or document and verify that only local accidental collisions matter.

As per path instructions, provider integrations require high scrutiny for authentication and token handling.

Also applies to: 123-163

Source: Path instructions


18-18: LGTM!

Also applies to: 37-41


210-251: 📐 Maintainability & Code Quality

Confirm the documentation update for user-visible discovery.

This change enables stored xAI OAuth discovery and account-specific model results. Update the relevant integration overview or how-to guide, or confirm that an existing documentation change covers this behavior. The supplied cohort contains no documentation file.

As per coding guidelines, “Update documentation when setup, commands, or user-facing behavior changes.”

Source: Coding guidelines


421-428: LGTM!

Also applies to: 469-476, 530-533

src/integrations/discoveryService.test.ts (2)

1-12: LGTM!

Also applies to: 224-240, 310-311, 630-708


81-94: 🩺 Stability & Availability

No xAI credential-cache teardown change is needed. The xAI tests stub readXaiCredentialsAsync() and do not call credential-writing functions, so they do not populate the module cache with these tokens.

			> Likely an incorrect or invalid review comment.

📝 Walkthrough

Walkthrough

Changes

xAI Grok support

Layer / File(s) Summary
Grok model catalog contracts
src/integrations/brands/xai.ts, src/integrations/models/xai.ts, src/integrations/gateways/*
Adds Grok 4.6 and 4.5 metadata, aliases, capabilities, limits, reasoning settings, and gateway mappings.
Hybrid xAI discovery
src/integrations/vendors/xai.ts, src/integrations/vendors/xai.test.ts, src/integrations/discoveryService.ts, src/commands/model/model.tsx
Adds curated and OpenAI-compatible hybrid discovery with filtering, context-window mapping, caching, refresh behavior, canonical endpoint validation, OAuth resolution, and stable cache identities.
Canonical xAI credential routing
src/utils/xaiCredentials.ts, src/integrations/runtimeMetadata.ts, related tests
Adds credential caching, concurrent-read protection, stable discovery identities, token-refresh identity preservation, and runtime metadata coverage.
Asynchronous secure-storage reads
src/utils/secureStorage/*, related tests
Adds asynchronous Linux and Windows credential reads, shared PowerShell parsing, DPAPI-first fallback behavior, and process-path tests.
Grok 4.6 defaults and validation
src/utils/model/*, src/utils/provider*.ts, src/components/ProviderManager.tsx, src/utils/*test.ts, web/src/data/providers.ts
Updates xAI defaults to Grok 4.6 and validates aliases, limits, reasoning metadata, vision support, provider catalogs, runtime metadata, and model-picker output.

Estimated code review effort: 4 (Complex) | ~60 minutes

Mergeability Score: 🟡 Moderate · up to 449a3

The PR adds xAI discovery and cached model metadata, but credentialless discovery can still fail while deriving its cache key, preventing model discovery and related functionality. Fix or explicitly accept this issue before merging.

Possibly related PRs

  • Gitlawb/openclaude#2084: Modifies OpenRouter discovery, gateway mappings, and model-picker coverage.
  • Gitlawb/openclaude#2118: Overlaps with xAI OAuth discovery, credential resolution, canonical URL validation, and cache identity handling.

Suggested labels: enhancement, new: provider/gateway

Suggested reviewers: lookoff-aimlapi, kevincodex1

🚥 Pre-merge checks | ✅ 4 | ❌ 3

❌ Failed checks (2 warnings, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 13.21% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
No Hidden Policy Change ⚠️ Warning The PR diff deletes the local /changelog/ page, redirects it to GitHub Releases, and changes site navigation; this unmentioned product policy is outside the stated xAI-only scope. Split the website and release-notes policy into a separate PR, or document explicit maintainer approval and rationale for bundling it here.
Risk Surface Disclosed ❓ Inconclusive Investigation is still in progress; no final assessment submitted. Inspect the PR diff and review text for the required auth, routing, network, background, and startup/config-home risk disclosures.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title is concise, scoped to xAI and Grok catalog changes, and matches the main changes in the pull request.
Description check ✅ Passed The description clearly covers the summary, scope, impact, and validation, with only minor deviations from the template headings and checkbox format.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/xai-grok-46

Comment @coderabbitai help to get the list of available commands.

Move OAuth /v1/models auth and cache-key alignment out of this branch so the catalog, xAI hybrid vendor, and gateway references stay reviewable on their own.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/integrations/discoveryService.ts`:
- Around line 193-209: Restrict stored xAI OAuth token reuse to a shared
endpoint predicate requiring canonical https://api.x.ai, including the implicit
default, and reject overridden, proxy, or HTTP endpoints. Apply this rule in
withXaiDiscoveryCredentials in src/integrations/discoveryService.ts (193-209),
the model command’s apiKey handling in src/commands/model/model.tsx (371-390),
and runtime metadata cache-key logic in src/integrations/runtimeMetadata.ts
(459-473). In src/integrations/vendors/xai.test.ts (115-154), add proxy and HTTP
endpoint cases asserting no OAuth Authorization header while retaining the
canonical HTTPS case.

In `@src/integrations/vendors/xai.ts`:
- Around line 159-185: Update mapModel to validate raw is a non-null object and
model.id is a string before calling trim(), returning null for malformed entries
such as null or { id: 1 }. Preserve the existing filtering and model mapping
behavior for valid entries.
- Around line 16-17: Remove the maxOutputTokens value from the Grok 4.6 catalog
entry and its matching descriptor in the xAI model definitions, leaving
contextWindow unchanged. Ensure runtime resolution no longer receives a default
or upper output limit from these descriptors.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 45e6fb65-2847-46e5-becc-d9e862fd1e64

📥 Commits

Reviewing files that changed from the base of the PR and between 6277bfa and 8cd7905.

📒 Files selected for processing (27)
  • src/commands/model/model.test.tsx
  • src/commands/model/model.tsx
  • src/components/ProviderManager.tsx
  • src/integrations/brands/xai.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/integrations/gateways/atlas-cloud.ts
  • src/integrations/gateways/hicap.ts
  • src/integrations/gateways/openrouter.ts
  • src/integrations/models/xai.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/vendors/xai.ts
  • src/services/api/client.test.ts
  • src/utils/context.test.ts
  • src/utils/effort.codex.test.ts
  • src/utils/model/configs.ts
  • src/utils/model/model.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/visionUtils.test.ts
  • web/src/data/providers.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: smoke-and-tests (24.11.x)
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (13)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/integrations/brands/xai.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/gateways/hicap.ts
  • web/src/data/providers.ts
  • src/utils/providerProfile.test.ts
  • src/integrations/gateways/openrouter.ts
  • src/components/ProviderManager.tsx
  • src/utils/providerFlag.ts
  • src/utils/context.test.ts
  • src/integrations/gateways/atlas-cloud.ts
  • src/utils/visionUtils.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/commands/model/model.test.tsx
  • src/utils/effort.codex.test.ts
  • src/integrations/models/xai.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/commands/model/model.tsx
  • src/integrations/vendors/xai.test.ts
  • src/utils/model/model.ts
  • src/integrations/vendors/xai.ts
  • src/utils/model/configs.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/integrations/brands/xai.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/gateways/hicap.ts
  • web/src/data/providers.ts
  • src/utils/providerProfile.test.ts
  • src/integrations/gateways/openrouter.ts
  • src/components/ProviderManager.tsx
  • src/utils/providerFlag.ts
  • src/utils/context.test.ts
  • src/integrations/gateways/atlas-cloud.ts
  • src/utils/visionUtils.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/commands/model/model.test.tsx
  • src/utils/effort.codex.test.ts
  • src/integrations/models/xai.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/commands/model/model.tsx
  • src/integrations/vendors/xai.test.ts
  • src/utils/model/model.ts
  • src/integrations/vendors/xai.ts
  • src/utils/model/configs.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/integrations/brands/xai.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/gateways/hicap.ts
  • src/utils/providerProfile.test.ts
  • src/integrations/gateways/openrouter.ts
  • src/utils/providerFlag.ts
  • src/utils/context.test.ts
  • src/integrations/gateways/atlas-cloud.ts
  • src/utils/visionUtils.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/utils/effort.codex.test.ts
  • src/integrations/models/xai.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/utils/model/model.ts
  • src/integrations/vendors/xai.ts
  • src/utils/model/configs.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/integrations/brands/xai.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/gateways/hicap.ts
  • web/src/data/providers.ts
  • src/utils/providerProfile.test.ts
  • src/integrations/gateways/openrouter.ts
  • src/components/ProviderManager.tsx
  • src/utils/providerFlag.ts
  • src/utils/context.test.ts
  • src/integrations/gateways/atlas-cloud.ts
  • src/utils/visionUtils.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/commands/model/model.test.tsx
  • src/utils/effort.codex.test.ts
  • src/integrations/models/xai.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/commands/model/model.tsx
  • src/integrations/vendors/xai.test.ts
  • src/utils/model/model.ts
  • src/integrations/vendors/xai.ts
  • src/utils/model/configs.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/integrations/brands/xai.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/gateways/hicap.ts
  • web/src/data/providers.ts
  • src/utils/providerProfile.test.ts
  • src/integrations/gateways/openrouter.ts
  • src/components/ProviderManager.tsx
  • src/utils/providerFlag.ts
  • src/utils/context.test.ts
  • src/integrations/gateways/atlas-cloud.ts
  • src/utils/visionUtils.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/commands/model/model.test.tsx
  • src/utils/effort.codex.test.ts
  • src/integrations/models/xai.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/commands/model/model.tsx
  • src/integrations/vendors/xai.test.ts
  • src/utils/model/model.ts
  • src/integrations/vendors/xai.ts
  • src/utils/model/configs.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/integrations/brands/xai.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/gateways/hicap.ts
  • web/src/data/providers.ts
  • src/utils/providerProfile.test.ts
  • src/integrations/gateways/openrouter.ts
  • src/components/ProviderManager.tsx
  • src/utils/providerFlag.ts
  • src/utils/context.test.ts
  • src/integrations/gateways/atlas-cloud.ts
  • src/utils/visionUtils.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/commands/model/model.test.tsx
  • src/utils/effort.codex.test.ts
  • src/integrations/models/xai.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/commands/model/model.tsx
  • src/integrations/vendors/xai.test.ts
  • src/utils/model/model.ts
  • src/integrations/vendors/xai.ts
  • src/utils/model/configs.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/brands/xai.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/gateways/hicap.ts
  • src/utils/providerProfile.test.ts
  • src/integrations/gateways/openrouter.ts
  • src/utils/providerFlag.ts
  • src/integrations/gateways/atlas-cloud.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/integrations/models/xai.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/utils/model/model.ts
  • src/integrations/vendors/xai.ts
  • src/utils/model/configs.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/context.test.ts
  • src/utils/visionUtils.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/commands/model/model.test.tsx
  • src/utils/effort.codex.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/vendors/xai.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/context.test.ts
  • src/utils/visionUtils.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/commands/model/model.test.tsx
  • src/utils/effort.codex.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/vendors/xai.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/context.test.ts
  • src/utils/visionUtils.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/utils/model/modelOptions.gateways.test.ts
  • src/commands/model/model.test.tsx
  • src/utils/effort.codex.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/vendors/xai.test.ts
web/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

When changing the web application, run the web typecheck and build checks.

Files:

  • web/src/data/providers.ts
web/**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

When changing files under web/, run bun run web:typecheck and bun run web:build.

Files:

  • web/src/data/providers.ts
web/**

⚙️ CodeRabbit configuration file

web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.

Files:

  • web/src/data/providers.ts
src/services/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Files:

  • src/services/api/client.test.ts
🧠 Learnings (7)
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: When modifying provider behavior, test the exact provider/model path changed when possible and avoid breaking third-party providers.

Applied to files:

  • src/utils/providerFlag.test.ts
  • src/utils/providerProfiles.test.ts
  • src/commands/model/model.test.tsx
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Applied to files:

  • src/utils/visionUtils.test.ts
  • src/commands/model/model.test.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Add or update tests when a code change affects behavior.

Applied to files:

  • src/utils/visionUtils.test.ts
  • src/commands/model/model.test.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: When changing provider behavior, explicitly identify the affected provider path and test the exact provider/model path when possible.

Applied to files:

  • src/utils/providerProfiles.test.ts
  • src/commands/model/model.test.tsx
📚 Learning: 2026-06-04T22:10:36.124Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: .github/pull_request_template.md:0-0
Timestamp: 2026-06-04T22:10:36.124Z
Learning: Pull request descriptions should include a Notes section documenting provider/model paths tested, screenshots (if UI changed), and follow-up work or known limitations

Applied to files:

  • src/commands/model/model.test.tsx
📚 Learning: 2026-06-17T02:55:08.727Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: .github/pull_request_template.md:0-0
Timestamp: 2026-06-17T02:55:08.727Z
Learning: Pull request descriptions should include a Notes section documenting provider/model paths tested, screenshots if UI changed, and follow-up work or known limitations

Applied to files:

  • src/commands/model/model.test.tsx
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.

Applied to files:

  • src/integrations/runtimeMetadata.test.ts
🔇 Additional comments (22)
src/integrations/brands/xai.ts (1)

16-17: LGTM!

src/integrations/models/xai.ts (1)

13-56: LGTM!

src/integrations/gateways/openrouter.ts (1)

38-39: LGTM!

src/integrations/gateways/atlas-cloud.ts (1)

54-55: LGTM!

src/integrations/gateways/hicap.ts (1)

66-67: LGTM!

src/components/ProviderManager.tsx (1)

244-244: LGTM!

src/utils/model/configs.ts (1)

56-56: LGTM!

Also applies to: 72-72, 88-88, 104-104, 120-120, 136-136, 152-152, 168-168, 184-184, 200-200, 216-216, 232-232, 248-248

src/utils/model/model.ts (1)

94-96: LGTM!

Also applies to: 232-232, 282-282, 330-330, 415-417

src/utils/effort.codex.test.ts (1)

813-840: 📐 Maintainability & Code Quality

Verify the focused provider checks.

The supplied context does not include test output. Run and report these commands:

bun test ./src/utils/effort.codex.test.ts
bun test ./src/commands/model/model.test.tsx
bun run typecheck
bun run typecheck:type-tests

As per coding guidelines, “Add or update tests when behavior changes” and “Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.” As per path instructions, “Run narrow focused tests plus applicable validation ... and report exact commands in the PR.”

Also applies to: 912-945

Sources: Coding guidelines, Path instructions

src/commands/model/model.test.tsx (1)

1310-1321: LGTM!

Also applies to: 1586-1597

web/src/data/providers.ts (1)

239-239: 📐 Maintainability & Code Quality

Verify the web checks.

The supplied context does not include web-check output. Run and report these commands:

bun run web:typecheck
bun run web:build

As per coding guidelines, “When changing files under web/, run bun run web:typecheck and bun run web:build.” As per path instructions, “Run narrow focused tests plus applicable validation ... and report exact commands in the PR.”

Sources: Coding guidelines, Path instructions

src/utils/providerFlag.ts (1)

571-571: LGTM!

src/utils/providerProfile.ts (1)

1079-1079: LGTM!

Also applies to: 1228-1228

src/utils/providerProfiles.test.ts (1)

2774-2774: LGTM!

src/services/api/client.test.ts (1)

945-945: LGTM!

src/utils/context.test.ts (1)

528-534: LGTM!

src/integrations/runtimeMetadata.test.ts (1)

5-5: LGTM!

Also applies to: 167-225, 526-535, 720-746, 762-790

src/utils/model/modelOptions.gateways.test.ts (1)

164-165: LGTM!

Also applies to: 179-180

src/utils/providerFlag.test.ts (1)

1121-1121: LGTM!

src/utils/visionUtils.test.ts (1)

66-73: LGTM!

src/utils/providerProfile.test.ts (1)

919-919: LGTM!

src/integrations/discoveryService.test.ts (1)

11-11: LGTM!

Also applies to: 80-80, 93-93, 291-292

Comment thread src/integrations/discoveryService.ts Outdated
Comment thread src/integrations/vendors/xai.ts Outdated
Comment thread src/integrations/vendors/xai.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
src/integrations/runtimeMetadata.test.ts (1)

5-5: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Preserve stored xAI OAuth credentials for discovery and runtime limits.

Without XAI_API_KEY, xAI OAuth users lose authenticated model discovery and matching cached runtime limits. Restore the OAuth credential path in src/integrations/discoveryService.ts and src/integrations/runtimeMetadata.ts, and restore the regression test.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/integrations/runtimeMetadata.test.ts` at line 5, Restore the xAI OAuth
credential flow in discoveryService and runtimeMetadata so stored OAuth
credentials are used when XAI_API_KEY is absent, preserving authenticated model
discovery and cached runtime-limit matching. Reinstate the regression coverage
in runtimeMetadata.test.ts alongside the existing Bun test imports.

Sources: Path instructions, Learnings

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@src/integrations/runtimeMetadata.test.ts`:
- Line 5: Restore the xAI OAuth credential flow in discoveryService and
runtimeMetadata so stored OAuth credentials are used when XAI_API_KEY is absent,
preserving authenticated model discovery and cached runtime-limit matching.
Reinstate the regression coverage in runtimeMetadata.test.ts alongside the
existing Bun test imports.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 5a6b6264-5b73-481a-9242-92ab774ad35f

📥 Commits

Reviewing files that changed from the base of the PR and between 8cd7905 and b71c9af.

📒 Files selected for processing (2)
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.test.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
  • GitHub Check: smoke-and-tests (24.11.x)
  • GitHub Check: smoke-and-tests (22)
  • GitHub Check: typecheck
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
🧠 Learnings (4)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T03:03:34.545Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-08-12T00:35:47.617Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Applied to files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Add or update tests when a code change affects behavior.

Applied to files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.

Applied to files:

  • src/integrations/vendors/xai.test.ts
🔇 Additional comments (1)
src/integrations/vendors/xai.test.ts (1)

1-1: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Reuse the xAI OAuth token for model discovery.

When XAI_API_KEY is unset, discovery sends no authorization header even though openaiShim resolves the stored OAuth token. Add the OAuth fallback and focused authenticated /v1/models coverage.

⛔ Skipped due to learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.

Source: Path instructions

coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 12, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/integrations/discoveryService.test.ts`:
- Around line 912-929: Update the authorization assertion in the
discoverModelsForRoute test to require that the captured authorization value is
null, matching the insecure-URL test’s toBeNull behavior. Keep the existing
tokenSpy assertion and request setup unchanged.

In `@src/integrations/discoveryService.ts`:
- Around line 249-281: Pair the permissive isCanonicalXaiInferenceBaseUrl check
with explicit route/URL validation at all three credential sites: in
src/integrations/discoveryService.ts:249-281, require routeId === 'xai' before
attaching the discovery apiKey; in src/integrations/runtimeMetadata.ts:459-475,
require routeId === 'xai' when deriving the cache key; and in
src/services/api/openaiShim/requestExecutor.ts:256-259, require a non-blank
trimmed request.baseUrl before setting isXaiRoute. Add focused blank-base-URL
regression tests in src/integrations/discoveryService.test.ts and
src/services/api/openaiShim/requestExecutor.test.ts, while leaving
resolveRouteCredentialValue’s permissive predicate behavior unchanged.
- Around line 124-149: Update hashDiscoveryCachePartition to derive the
partition with a single keyed HMAC-SHA256 operation instead of PBKDF2, using the
existing partition salt and serialized credential input without caching raw
serialized values. Remove DISCOVERY_CACHE_PARTITION_ITERATIONS,
DISCOVERY_CACHE_PARTITION_CACHE_LIMIT, and discoveryCachePartitions, and ensure
getDiscoveryCacheKey continues using the new partition derivation so existing
partitions naturally invalidate.

In `@src/integrations/vendors/xai.test.ts`:
- Around line 132-147: Update the mocked discovery payload in the xAI test to
use context_length instead of context_window, matching mapModel’s expected
field. Add an assertion that the grok-4.7 model returned by the test has
contextWindow equal to 500000, then validate with the specified test command.

In `@src/services/api/openaiShim/requestExecutor.test.ts`:
- Around line 444-448: The test cases in the request executor table need
coverage for an unset OPENAI_BASE_URL. Add an empty baseUrl case expecting
sendsOAuth to be false, delete process.env.OPENAI_BASE_URL instead of assigning
an empty string for that case, and update any toHaveBeenCalledTimes(1) assertion
to account for the added case. Validate with the specified test command.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 1668812e-afbf-42ec-b1d3-77739ae7f769

📥 Commits

Reviewing files that changed from the base of the PR and between ed9c38c and 14772d6.

📒 Files selected for processing (12)
  • src/commands/model/model.tsx
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/integrations/routeMetadata.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/vendors/xai.ts
  • src/services/api/openaiShim.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/xaiCredentials.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: smoke-and-tests (22)
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/services/api/openaiShim.ts
  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/discoveryService.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/services/api/openaiShim.ts
  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/discoveryService.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/services/api/openaiShim.ts
  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/discoveryService.ts
src/services/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Files:

  • src/services/api/openaiShim.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/services/api/openaiShim.ts
  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/discoveryService.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/services/api/openaiShim.ts
  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/discoveryService.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/services/api/openaiShim.ts
  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/discoveryService.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/services/api/openaiShim.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/discoveryService.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
🧠 Learnings (3)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-08-12T00:35:47.617Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T03:03:34.545Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
📚 Learning: 2026-06-05T05:29:23.353Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.

Applied to files:

  • src/integrations/vendors/xai.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.

Applied to files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
🔇 Additional comments (12)
src/integrations/vendors/xai.ts (1)

158-188: LGTM!

src/integrations/vendors/xai.test.ts (1)

91-93: LGTM!

Also applies to: 117-131, 148-174

src/integrations/discoveryService.test.ts (2)

958-989: LGTM!

Also applies to: 991-1020, 1022-1056


940-956: 📐 Maintainability & Code Quality

No change needed. The file-level afterEach restores CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC with restoreEnvValue.

			> Likely an incorrect or invalid review comment.
src/integrations/discoveryService.ts (1)

182-199: LGTM!

Also applies to: 227-230, 452-456, 497-504, 558-561

src/integrations/routeMetadata.ts (1)

279-296: LGTM!

Also applies to: 1035-1042

src/utils/xaiCredentials.ts (1)

113-125: LGTM!

src/services/api/openaiShim.ts (1)

56-56: LGTM!

Also applies to: 526-526

src/services/api/openaiShim/requestExecutor.ts (1)

295-305: LGTM!

Also applies to: 324-335

src/commands/model/model.tsx (1)

20-20: LGTM!

Also applies to: 370-395, 507-509, 573-573, 894-909, 1236-1246

src/integrations/runtimeMetadata.test.ts (1)

5-5: LGTM!

Also applies to: 19-19, 28-28, 38-38, 169-228

src/services/api/openaiShim/requestExecutor.test.ts (1)

2-2: LGTM!

Also applies to: 15-15, 57-57, 450-477, 479-497, 538-538, 585-585

Comment thread src/integrations/discoveryService.test.ts Outdated
Comment thread src/integrations/discoveryService.ts Outdated
Comment thread src/integrations/discoveryService.ts
Comment thread src/integrations/vendors/xai.test.ts Outdated
Comment thread src/services/api/openaiShim/requestExecutor.test.ts Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/integrations/runtimeMetadata.ts`:
- Around line 466-470: Cache the result of readXaiCredentials before the
synchronous OAuth injection branch in the runtime metadata flow, then reuse that
cached credential when resolving the xAI access token. Ensure the cache covers
the blocking credential read for all platforms while preserving the existing
apiKey, routeId, and canonical base URL conditions.

In `@src/services/api/openaiShim/requestExecutor.ts`:
- Around line 264-282: Add a debug log in the credential-filtering flow around
withoutUntrustedXaiCredential when mirrored XAI credentials are removed for a
noncanonical route, including enough context to diagnose the resulting missing
authorization header without logging any credential values. Preserve the
existing filtering behavior and validate with the requestExecutor tests.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 74cd8a0b-3b52-4bb0-8785-3bc898a3617f

📥 Commits

Reviewing files that changed from the base of the PR and between 14772d6 and 1a04f25.

📒 Files selected for processing (7)
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/xaiCredentials.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
  • GitHub Check: smoke-and-tests (24.11.x)
  • GitHub Check: smoke-and-tests (22)
  • GitHub Check: typecheck
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/utils/xaiCredentials.ts
  • src/integrations/runtimeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/runtimeMetadata.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.ts
src/services/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Files:

  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/discoveryService.test.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
🧠 Learnings (4)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-08-12T00:35:47.617Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T03:03:34.545Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.
📚 Learning: 2026-06-17T03:03:34.545Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T03:03:34.545Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.

Applied to files:

  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
📚 Learning: 2026-06-17T02:55:16.537Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T02:55:16.537Z
Learning: If the PR touches auth, provider routing, permissions, outbound network behavior, background execution, startup/config-home behavior, skills/plugins/MCP, CI permissions, or release scripts, verify that the review calls out the risk surface and whether it introduces a blocker.

Applied to files:

  • src/integrations/discoveryService.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/services/**/*.ts : Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Applied to files:

  • src/integrations/discoveryService.ts
🔇 Additional comments (7)
src/integrations/vendors/xai.test.ts (1)

139-139: LGTM!

Also applies to: 157-160

src/integrations/discoveryService.test.ts (1)

929-929: LGTM!

Also applies to: 958-973, 1039-1068

src/integrations/discoveryService.ts (1)

1-1: LGTM!

Also applies to: 126-135, 250-250

src/utils/xaiCredentials.ts (1)

123-124: LGTM!

src/services/api/openaiShim/requestExecutor.ts (2)

256-268: Blocking-issue check: none. The blank base-URL regression is fixed here.

Line 259 now requires a non-blank request.baseUrl before isCanonicalXaiInferenceBaseUrl, so an unset base URL no longer marks the request as an xAI route. This also scopes x-grok-conv-id at Line 465 to the canonical host.


289-296: LGTM!

Also applies to: 314-345

src/services/api/openaiShim/requestExecutor.test.ts (1)

448-457: LGTM!

Also applies to: 504-535

Comment thread src/integrations/runtimeMetadata.ts Outdated
Comment thread src/services/api/openaiShim/requestExecutor.ts Outdated
Comment thread src/integrations/discoveryService.ts Fixed
@jatmn
jatmn force-pushed the feat/xai-grok-46 branch from a6121c5 to 063238c Compare August 12, 2026 23:17
coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 12, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/commands/model/model.tsx`:
- Around line 507-510: Add focused regression coverage in model.test.tsx for the
model discovery flows around getOpenAIDiscoveryRequestOptions and
getDiscoveryCacheKey: verify initial loading uses the stable cache with
refreshXaiOAuth disabled, and each manual refresh clears then replaces that same
cache entry. Cover the related code paths at the referenced discovery and
refresh sections while preserving existing model-picker/provider behavior.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 01e5fd2f-fe40-4baa-aa07-b329381cd286

📥 Commits

Reviewing files that changed from the base of the PR and between 1a04f25 and 3bb0cd1.

📒 Files selected for processing (7)
  • src/commands/model/model.tsx
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/vendors/xai.test.ts
  • src/integrations/vendors/xai.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: smoke-and-tests (24.11.x)
  • GitHub Check: smoke-and-tests (22)
  • GitHub Check: typecheck
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/runtimeMetadata.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/runtimeMetadata.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/runtimeMetadata.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/runtimeMetadata.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/runtimeMetadata.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/commands/model/model.tsx
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/runtimeMetadata.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/vendors/xai.ts
  • src/integrations/discoveryService.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/runtimeMetadata.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/integrations/vendors/xai.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
🧠 Learnings (7)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/* : Update documentation when setup, commands, or user-facing behavior changes.
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Applied to files:

  • src/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Add or update tests when a code change affects behavior.

Applied to files:

  • src/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Use focused tests such as `bun test ./path/to/test-file.test.ts` when validating a narrowly scoped change.

Applied to files:

  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.test.ts
📚 Learning: 2026-06-05T05:29:23.353Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.

Applied to files:

  • src/integrations/vendors/xai.ts
  • src/integrations/discoveryService.ts
📚 Learning: 2026-06-17T02:55:16.537Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T02:55:16.537Z
Learning: If the PR touches auth, provider routing, permissions, outbound network behavior, background execution, startup/config-home behavior, skills/plugins/MCP, CI permissions, or release scripts, verify that the review calls out the risk surface and whether it introduces a blocker.

Applied to files:

  • src/integrations/discoveryService.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/services/**/*.ts : Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Applied to files:

  • src/integrations/discoveryService.ts
🔇 Additional comments (6)
src/integrations/runtimeMetadata.ts (1)

462-466: Avoid a blocking credential read on the runtime-limit path.

resolveModelRuntimeLimits reaches this synchronous function during request planning. readXaiCredentials() can perform synchronous secure-storage I/O on some platforms. Cache the credential result outside this path or add caching inside the credential reader.

src/integrations/vendors/xai.ts (1)

6-7: LGTM!

src/integrations/vendors/xai.test.ts (1)

58-60: LGTM!

src/integrations/discoveryService.test.ts (1)

1-5: LGTM!

Also applies to: 612-652

src/integrations/discoveryService.ts (1)

218-252: 📐 Maintainability & Code Quality

Provide the required validation results.

The supplied context contains no command output. Run and report the focused discovery tests, bun run typecheck, bun run typecheck:type-tests, and the documented build, smoke, and bun run integrations:check commands.

As per coding guidelines, “Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.” As per path instructions, “Run the narrowest relevant checks plus the documented validation suite ... report exact commands in the PR.”

Also applies to: 424-430, 472-479, 533-536

Sources: Coding guidelines, Path instructions

src/integrations/runtimeMetadata.test.ts (1)

5-5: LGTM!

Also applies to: 76-119

Comment thread src/commands/model/model.tsx

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/integrations/discoveryService.ts`:
- Around line 223-233: Update the discovery credential flow around the token
resolution to use await readXaiCredentialsAsync() for both the initial
credentials read and the post-refresh reread, replacing synchronous
readXaiCredentials() calls while preserving the fallback behavior. Update
discoveryService.test.ts mocks to provide the asynchronous credential reader.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 55b97b03-81c6-474e-88d4-fd41a23841e3

📥 Commits

Reviewing files that changed from the base of the PR and between 3bb0cd1 and 9cc9daf.

📒 Files selected for processing (4)
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/integrations/runtimeMetadata.ts
  • src/utils/xaiCredentials.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
  • GitHub Check: typecheck
  • GitHub Check: smoke-and-tests (24.11.x)
  • GitHub Check: smoke-and-tests (22)
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/integrations/discoveryService.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/integrations/discoveryService.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/integrations/discoveryService.test.ts
🧠 Learnings (5)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/* : Update documentation when setup, commands, or user-facing behavior changes.
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Applied to files:

  • src/integrations/discoveryService.test.ts
📚 Learning: 2026-06-05T05:29:23.353Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.

Applied to files:

  • src/integrations/discoveryService.ts
📚 Learning: 2026-06-17T02:55:16.537Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T02:55:16.537Z
Learning: If the PR touches auth, provider routing, permissions, outbound network behavior, background execution, startup/config-home behavior, skills/plugins/MCP, CI permissions, or release scripts, verify that the review calls out the risk surface and whether it introduces a blocker.

Applied to files:

  • src/integrations/discoveryService.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/services/**/*.ts : Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Applied to files:

  • src/integrations/discoveryService.ts
🔇 Additional comments (4)
src/integrations/discoveryService.test.ts (1)

654-690: LGTM!

src/integrations/discoveryService.ts (1)

38-38: LGTM!

Also applies to: 125-131, 235-239

src/integrations/runtimeMetadata.ts (1)

31-34: LGTM!

Also applies to: 469-469

src/utils/xaiCredentials.ts (1)

28-30: LGTM!

Also applies to: 45-46, 64-64, 87-104, 130-153, 181-181, 197-200, 215-225, 265-265

Comment thread src/integrations/discoveryService.ts Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/integrations/discoveryService.ts`:
- Around line 124-132: The hashDiscoveryCachePartition function passes
JSON.stringify(value) directly to Hmac.update even though serialization may
return undefined; coalesce or validate the serialized result before calling
update while preserving the defined partition behavior. Then run the focused
test and TypeScript checks.

In `@src/utils/secureStorage/platformStorage.test.ts`:
- Around line 388-399: Add a focused test alongside the existing asynchronous
read test that enables OPENCLAUDE_ENABLE_LEGACY_WINDOWS_PASSWORDVAULT, makes the
DPAPI read path reject or fail, and mocks the asynchronous Password Vault
fallback to return stored data. Assert that windowsCredentialStorage.readAsync()
returns that data and verifies the asynchronous fallback invocation.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 8a3995b0-5903-41ed-ba9e-67272a6adf91

📥 Commits

Reviewing files that changed from the base of the PR and between 9cc9daf and 3d43636.

📒 Files selected for processing (9)
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/utils/secureStorage/linuxSecretStorage.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/utils/secureStorage/windowsCredentialStorage.ts
  • src/utils/xaiCredentials.test.ts
  • src/utils/xaiCredentials.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (5)
  • GitHub Check: smoke-and-tests (22)
  • GitHub Check: smoke-and-tests (24.11.x)
  • GitHub Check: typecheck
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (javascript-typescript)
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/utils/secureStorage/linuxSecretStorage.ts
  • src/utils/secureStorage/windowsCredentialStorage.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/utils/secureStorage/linuxSecretStorage.ts
  • src/utils/secureStorage/windowsCredentialStorage.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/utils/secureStorage/linuxSecretStorage.ts
  • src/utils/secureStorage/windowsCredentialStorage.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/integrations/runtimeMetadata.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/utils/secureStorage/linuxSecretStorage.ts
  • src/utils/secureStorage/windowsCredentialStorage.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/integrations/runtimeMetadata.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/utils/secureStorage/linuxSecretStorage.ts
  • src/utils/secureStorage/windowsCredentialStorage.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/utils/secureStorage/linuxSecretStorage.ts
  • src/utils/secureStorage/windowsCredentialStorage.ts
  • src/integrations/discoveryService.ts
  • src/utils/xaiCredentials.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/secureStorage/platformStorage.test.ts
  • src/integrations/runtimeMetadata.test.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/runtimeMetadata.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/runtimeMetadata.test.ts
  • src/integrations/discoveryService.ts
🧠 Learnings (7)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/* : Update documentation when setup, commands, or user-facing behavior changes.
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to **/*.{test,spec}.{ts,tsx} : Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Applied to files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:16.417Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: CONTRIBUTING.md:0-0
Timestamp: 2026-08-07T01:57:16.417Z
Learning: Applies to **/*.{test,spec}.{ts,tsx,js,jsx} : Add or update tests when a code change affects behavior.

Applied to files:

  • src/utils/xaiCredentials.test.ts
  • src/integrations/runtimeMetadata.test.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/**/*.ts : Use `chalk` for terminal color and `execa` for child-process execution when those capabilities are needed.

Applied to files:

  • src/utils/secureStorage/platformStorage.test.ts
  • src/utils/secureStorage/linuxSecretStorage.ts
  • src/utils/secureStorage/windowsCredentialStorage.ts
📚 Learning: 2026-06-05T05:29:23.353Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-05T05:29:23.353Z
Learning: Verify that product, trust-model, routing-default, telemetry/network, and permission-policy changes are not hidden inside unrelated cleanup. Flag the PR if the policy decision needs explicit maintainer alignment.

Applied to files:

  • src/integrations/discoveryService.ts
📚 Learning: 2026-06-17T02:55:16.537Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: coderabbit-custom-pre-merge-checks-unique-id-file-non-traceable-F7F2B60C-1728-4C9A-8889-4F2235E186CA.txt:0-0
Timestamp: 2026-06-17T02:55:16.537Z
Learning: If the PR touches auth, provider routing, permissions, outbound network behavior, background execution, startup/config-home behavior, skills/plugins/MCP, CI permissions, or release scripts, verify that the review calls out the risk surface and whether it introduces a blocker.

Applied to files:

  • src/integrations/discoveryService.ts
📚 Learning: 2026-08-07T01:57:07.096Z
Learnt from: CR
Repo: Gitlawb/openclaude PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-08-07T01:57:07.096Z
Learning: Applies to src/services/**/*.ts : Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Applied to files:

  • src/integrations/discoveryService.ts
🔇 Additional comments (9)
src/utils/secureStorage/linuxSecretStorage.ts (1)

1-1: LGTM!

Also applies to: 38-55

src/utils/secureStorage/windowsCredentialStorage.ts (1)

1-1: LGTM!

Also applies to: 40-40, 51-71, 88-88, 103-121, 130-149, 151-186, 188-200

src/utils/secureStorage/platformStorage.test.ts (1)

40-57: LGTM!

Also applies to: 102-102, 120-123, 415-427

src/utils/xaiCredentials.test.ts (1)

1-99: LGTM!

src/integrations/discoveryService.test.ts (1)

615-615: LGTM!

Also applies to: 667-669

src/integrations/discoveryService.ts (1)

224-224: LGTM!

Also applies to: 234-234

src/integrations/runtimeMetadata.ts (1)

32-32: LGTM!

Also applies to: 467-472

src/utils/xaiCredentials.ts (1)

24-24: LGTM!

Also applies to: 47-50, 91-112, 149-188

src/integrations/runtimeMetadata.test.ts (1)

19-19: LGTM!

Also applies to: 28-28, 41-41, 83-83

Comment thread src/integrations/discoveryService.ts Outdated
Comment thread src/utils/secureStorage/platformStorage.test.ts
coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 13, 2026
Comment thread src/integrations/discoveryService.ts
@jatmn
jatmn marked this pull request as ready for review August 13, 2026 02:21

@jatmn jatmn left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kevincodex1
kevincodex1 merged commit 7cae408 into main Aug 13, 2026
10 checks passed
@jatmn
jatmn deleted the feat/xai-grok-46 branch August 13, 2026 02:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants