fix(auth): stop the API key placeholder from shadowing Oh My Pi /login credentials (#78)
Oh My Pi kept the unresolved $COMMAND_CODE_API_KEY placeholder as a literal config API key that shadowed its /login credential store and was sent as the Bearer token (401). The placeholder is now registered only on pi, where it keeps the API-key auth method and --api-key working next to OAuth; on OMP the provider omits apiKey unless a real key is configured. Host-supplied placeholders are resolved or stripped on every stream path, and the legacy generate transport uses the same rule. Stored /login OAuth and API-key credentials, --api-key, and env keys are now covered end to end on both pi and Oh My Pi, and CI runs the pi suite against a real binary. Co-authored-by: ebreen <ebreen@users.noreply.github.com>
This commit is contained in:
@@ -108,6 +108,21 @@ describe("streamCommandCode — auth", () => {
|
||||
|
||||
assert.equal(server.lastRequestHeaders().authorization, "Bearer option-key")
|
||||
})
|
||||
|
||||
it("treats a blank options.apiKey like a missing one", async () => {
|
||||
server.mockResponse({
|
||||
type: "success",
|
||||
events: [JSON.stringify({ type: "finish", finishReason: "stop" })],
|
||||
})
|
||||
const { streamCommandCode } = createTestDeps({
|
||||
apiBase: server.baseUrl(),
|
||||
env: { COMMAND_CODE_API_KEY: "env-key" },
|
||||
})
|
||||
|
||||
await collectEvents(streamCommandCode(makeModel(), makeContext(), { apiKey: " " }))
|
||||
|
||||
assert.equal(server.lastRequestHeaders().authorization, "Bearer env-key")
|
||||
})
|
||||
})
|
||||
|
||||
describe("streamCommandCode — successful streams", () => {
|
||||
|
||||
Reference in New Issue
Block a user