Skip to content

feat(plugins): support reviewed OAuth AI providers - #6805

Merged
Hmbown merged 5 commits into
codewhale-hq:wave/0.10.1-nextfrom
LIghtJUNction:feat/plugin-oauth-providers
Oct 6, 2026
Merged

Hmbown merged 5 commits into
codewhale-hq:wave/0.10.1-nextfrom
LIghtJUNction:feat/plugin-oauth-providers

Conversation

@LIghtJUNction

Copy link
Copy Markdown

Summary

Reviewed plugin bundles can now declare named OpenAI-compatible AI providers and public OAuth clients through extensions.net.codewhale.providers. The existing provider route, model catalog, Chat Completions client and streaming path consume these declarations; no companion proxy process or provider-specific host patch is required.

The host owns PKCE authorization, ephemeral loopback callbacks, state/issuer validation, secure credential storage and serialized token rotation. Plugin code never receives token material. Credentials bind the exact provider, endpoint and complete OAuth descriptor. Each actual request rechecks the review receipt, binds the effective endpoint/OAuth/public headers to that reviewed declaration, resolves the current bearer and refuses redirects. Candidate routes and in-memory overrides cannot borrow another declaration’s authorization. Disabled/revoked plugins invalidate already-built clients. Runtime API key writes cannot replace plugin OAuth. Client construction and generic config-key reads never expose the bearer. Read-only readiness and diagnostic probes never refresh credentials; reviewed public headers do not inherit global connection headers. Model-only chooser preferences persist through the existing selection owner without persisting plugin authority.

Includes auth plugin-login --provider <id> / plugin-logout, provider/model declarations, an example bundle and authoring documentation. This is a declarative standard public-client PKCE/OpenAI Chat extension; arbitrary executable auth/transport callbacks, device grants, confidential clients and remote revocation are explicitly outside its scope. The provider capability changes the activation policy to 5/6, intentionally requiring fresh review of older plugin receipts.

No-Issue: standalone provider-neutral plugin integration requested by an external integrator.

Testing

421 distinct tests passed on the actual TUI unit-test binary (filters overlap; counts are not additive):

Filter Passed Failed Ignored
plugin_oauth 10 0 0
plugins:: 243 0 1
config_persistence:: 35 0 0
oauth:: 106 0 0
provider_readiness:: 26 0 0
runtime_api::secrets:: 8 0 0
from_candidate 2 0 0

The host fixture loads an installed, trusted, enabled manifest, stores an expired bound credential, then exercises real HTTP token refresh, model discovery, Chat Completions and SSE with the actual client. It also checks readonly diagnostics, isolation from ambient headers, valid-token endpoint tampering, revocation during a delayed refresh and cached-client/recovery-probe revocation. Plugin tests cover manifest validation, trust/staging, declaration binding and save/reload of model selection.

For this <16 GiB host, the documented package-local low-memory approach was used. For the first four filters:

CARGO_BUILD_JOBS=1 scripts/dev-cargo.sh test -p codewhale-tui --lib --locked \
  --config 'profile.test.package.codewhale-tui.incremental=false' \
  --config 'profile.test.package.codewhale-tui.codegen-units=4' \
  --config 'profile.test.package.codewhale-tui.debug=0' \
  <filter> -- --test-threads=1

The remaining filters reused that same compiled TUI test binary directly with <filter> --test-threads=1. The cold target took 30m06s; the real host OAuth test executed successfully, rather than being inferred from compilation. Runtime tests preceded a final Clippy-only equivalent let-chain cleanup; final static checks cover the cleaned source.

Final static checks passed:

cargo fmt --all -- --check
CARGO_BUILD_JOBS=1 scripts/dev-cargo.sh clippy -p codewhale-tui --lib --tests --locked -- \
  -D warnings -A clippy::uninlined_format_args \
  -A clippy::too_many_arguments -A clippy::unnecessary_map_or
CARGO_BUILD_JOBS=1 scripts/dev-cargo.sh clippy -p codewhale-cli -p codewhale-app-server --locked -- \
  -D warnings -A clippy::uninlined_format_args \
  -A clippy::too_many_arguments -A clippy::unnecessary_map_or
python3 scripts/check-blocking-calls-budget.py
python3 -m json.tool docs/examples/plugins/oauth-provider/plugin.json
git diff --check

Both Clippy runs use the current CI's three allowances (rather than the older five documented in CONTRIBUTING). The blocking-call budget remains 755 sites across 209 files. The compiler invocations also used process-local jemalloc retention settings for this memory-constrained host; no product or system configuration changed.

Full workspace/all-features gates and interactive browser/production authorization were not run locally. These results demonstrate hermetic host integration, not an authorization grant against a live third-party issuer.

Checklist

  • plugins/providers.rs adapts the existing manifest/activation owner to the existing named route/model catalog; OAuth extends the current secure-store owner
  • Updated docs and a runnable declaration example
  • Added tests for protocol, credential rotation and revocation boundaries
  • Manual interactive TUI / production OAuth acceptance
  • Full workspace Clippy and full workspace suite (upstream CI)

Signed-off-by: LIghtJUNction <lightjunction.me@gmail.com>
@LIghtJUNction
LIghtJUNction requested a review from Hmbown as a code owner October 1, 2026 02:44
Copilot AI balanced review requested due to automatic review settings October 1, 2026 02:44
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions github-actions Bot added the contribution-gate Author not yet in .github/APPROVED_CONTRIBUTORS; a maintainer grants access with /lgtm label Oct 1, 2026

@Hmbown Hmbown left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is awesome thank you so much for this!

Box the plugin provider snapshot so the runtime route remains small enough for async test stacks, and add the contributor credit required by CI.

Local checks:
- cargo check -p codewhale-tui --lib --locked
- cargo fmt --all -- --check
- python3 scripts/check-contributor-credit.py
- git diff --check
Restore the two large source files after the GitHub API upload truncated their first update. The resulting tree contains only the intended boxed provider snapshot and contributor credit changes.
@Hmbown Hmbown added this to the v0.11 milestone Oct 5, 2026
@Hmbown
Hmbown changed the base branch from main to wave/0.10.1-next October 6, 2026 05:52
@Hmbown
Hmbown merged commit 2ce6672 into codewhale-hq:wave/0.10.1-next Oct 6, 2026
2 checks passed
Hmbown pushed a commit that referenced this pull request Oct 6, 2026
Reconcile the complete contributions from #6832 (@aboimpinto), #6867
(@hodeswildsmith455-boop), and #6805 (@LIghtJUNction) with the current
Engine, provider identities, reviewed-plugin policy, and task lifecycle.
Original contributor histories are recorded by subsequent resolved merges.

Fix the already integrated contributor cases: snapshot corruption is an
explicit unavailable/error result (#6817), malformed locales cannot select
an incidental script (#6860), image metadata uses the exact uploaded bytes
and respects available decoders (#6858), automation deletion waits for
actual scheduler reconciliation (#6864), and blocking trust/skill reads stay
off the async executor (#6869). Preserve #6857's compaction regression.

Extend #6872's human-wait lifecycle guard to approval/elevation cards;
retire only the matching ended parent request and refresh activity only
after a delivered decision. Enforce configured finite approval deadlines in
the Engine, including deadline/cancellation races and durable receipts.

Serialize Native Windows ACL admission/retirement across Core processes
with a logon-scoped kernel mutex, preserving exact SID/object validation.
Add an actual child-process lock test; serialize DSH host tests in the
existing extension-host lane. Windows execution proof remains hosted CI.

Reconcile the vendored computer-use plugin with canonical main a656f67455fc
while preserving Core's 0.12.1 embedding contract. Canonical b47/a656 tree
passed Ubuntu/macOS/Windows source and package gates, including 28/28
Windows-focused tests and the controlled desktop fixture; this is separate
from the new Engine head's CI verdict.

Partial adaptation of the discovery-cache priority portion from PR #6393
by @AdityaVG13 (original ac33dd4). Preserve the best match under count
and byte limits without importing the unfinished echolocation/fork design;
the broader draft remains open.

Validation:
- npm test: 1286 passed, 0 failed, 7 skipped; web 767/767.
- npm run check:web: lint, typecheck and production build passed.
- Affected Rust selection: 801/803 initially passed; the two fixture/lifecycle
  expectation failures were corrected and each passed a focused rerun.
- Additional focused Rust: approval 28/28, discovery cache 11/11,
  OrcaRouter synthetic catalog 3/3, and 33/33 lifecycle/API/routing checks.
- Final CI-repair selection: 37/39 initially passed; the BMP feature-proxy
  and feature-registry summary failures were corrected; both corrected tests passed (2/2, 0 failures).
- Qualified Clippy: six packages, all targets/all features, passed with
  the CI style allowances. Portable no-default-feature check passed;
  portable policy verifier 6/6 passed; formatting and diff checks passed.
- Runtime contract: 55 measured metrics passed after explicit remeasurement;
  all 21 structural identities were unchanged. Twelve byte/token-estimate
  budgets account for bounded child-wait disclosure and contributor locale
  descriptions; no runtime field/prompt was removed to lower the budget.
- Persistence budget was not qualified locally: the checker requires a
  clean tree and this shared checkout retains an unrelated operator file.
  Clean hosted CI, fresh stamped build and real DeepSeek TUI acceptance
  remain required before the integration PR can merge to main.

Refs #6872, #6843, #6795.

Co-authored-by: Paulo Aboim Pinto <paulo.aboim.pinto@gmail.com>
Co-authored-by: hodeswildsmith455-boop <hodeswildsmith455-boop@users.noreply.github.com>
Co-authored-by: LIghtJUNction <lightjunction.me@gmail.com>
Co-authored-by: AdityaVG13 <adityavgcode@gmail.com>
Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contribution-gate Author not yet in .github/APPROVED_CONTRIBUTORS; a maintainer grants access with /lgtm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants