Port upstream 0.66.0: import Kimi web access tokens from Chromium local storage (stacked on #646) - #649
Conversation
…0260923' into port/micro-0.66.0-kimi-local-storage-tokens
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude Thermo-nuclear review findings:
|
|
Fixes landed at head 2542a90: all 4 findings fixed (also fixed a compile error and 4 clippy lints in the applied changes). Nothing left. Commands run: cargo +1.98.0 fmt --all, clippy -D warnings (rust crate, all targets), cargo test --lib leveldb (24 passed) and kimi (66 passed). Tauri crate clippy skipped: no changes outside the rust crate. |
# Conflicts: # rust/src/providers/kimi/mod.rs
# Conflicts: # rust/src/browser/leveldb/local_storage.rs # rust/src/browser/leveldb/log.rs # rust/src/browser/leveldb/mod.rs # rust/src/browser/leveldb/table.rs
Adversarial validation (lane-A) at e68a698 — CONFLICTING note resolvedReview verdict: the branch matches the 0.66.0 audit row-22 spec: CONFLICTING resolution (the LANE-A note): the "which profile directories the importer walks" gap is closed by the fresh stack, not a code edit on the branch. The original head ( Merge outcome: merged the finished #646 head ( Checks at e68a698 (CARGO_TARGET_DIR=W:\cargo-target\lane-a, jobs=4, RUST_TEST_THREADS=4):
Fast-forward pushed |
Summary
Kimi web fetch and the Kimi Code monthly enrichment now also read the web
access_tokenfrom Chromium browsers' Local Storage for the selected Kimi region (https://www.kimi.comorhttps://www.kimi.ai). It is the last step of the token chain: manual cookie header, Kimi Desktop session, browser cookies, then local-storage tokens. Only unexpired three-segment ASCII JWTs (expin the future) are used, deduplicated across profiles. Refresh tokens are never read. Manual credentials stay authoritative and Cookie source Off/Manual skips the step, so manual and saved-account credentials stay isolated. Because local storage is not App-Bound encrypted, this can work when cookie decryption is blocked.Dependencies (stacked):
port/micro-0.66.0-browser-leveldb-reader, the shared LevelDB + Snappy reader). This PR is based on that branch.codex/integrate-reviewed-ports-20260923) for the Kimi region work (KimiRegion,web_base_url).origin/codex/integrate-reviewed-ports-20260923is merged into this branch (clean merge, no conflicts), so the diff against Port upstream 0.66.0: shared Chromium LevelDB + Snappy reader #646 also shows Integrate reviewed provider, history, and tray ports #610's content until Integrate reviewed provider, history, and tray ports #610 lands. The new work is the single commitPort upstream 0.66.0: import Kimi web access tokens from Chromium local storage(4 files:rust/src/providers/kimi/local_storage.rs,web.rs,mod.rs,docs/COOKIES.md).Upstream reference
49e7ff3e.Sources/CodexBarCore/Providers/Kimi/KimiCookieImporter.swift(localStorageTokens(region:):access_tokenkey, JSON-string or trimmed value, three.segments, ASCII letters/digits/-_.,expfinite and in the future, dedupe),Sources/CodexBarCore/Providers/Kimi/KimiProviderDescriptor.swift(KimiWebEnrichmentTokenResolver,browserTokensappend after cookie sessions),Tests/CodexBarTests/KimiLocalStorageTests.swift(token fixtureeyJhbGciOiJIUzI1NiJ9.eyJleHAiOjE4MDAwMDM2MDB9.signature, expired/a.b.c/refresh-token/suffix cases),docs/kimi.md(order item 7).Ported / Deferred
Ported: the token filter and ordering, region-bound origin, integration into both
fetch_via_web(lazy: read only after every cookie source was rejected with an auth error) andweb_auth_tokens(Code API / CLI enrichment), docs note indocs/COOKIES.md.Deferred / differences:
BrowserDetector(Chrome, Edge, Brave, Arc, Chromium; profilesDefaultandProfile N). Upstream's shared catalog also coversuser-*profiles and more Chromium browsers (Comet, Yandex, ...) and reads profile display names; those belong with the MiniMax storage-discovery item and are not done here.Validation
Toolchain
cargo +1.98.0, slot-4 target dir, E-core wrappers.cargo +1.98.0 fmt --all: cleancargo +1.98.0 clippy --workspace --all-targets -- -D warnings: passcargo +1.98.0 test -p codexbar kimi -- --test-threads=4: 66 passed, 0 failed (includes 3 newkimi::local_storagetests and 2 newkimi::webchain-order tests)New tests cover: refresh-token key ignored; expired, malformed (
not-a-token,a.b.c), and cookie-suffixed values rejected; JSON-quoted and whitespace-padded values accepted; expiry boundary (now + 3600); non-numeric or missingexprejected; end-to-end read of profileLocal Storage/leveldblogs with region-exact origin, cross-profile dedupe, and profiles without local storage; chain order desktop, browser cookie, local storage with dedupe; manual credential and Cookie source Off/Manual never reach local storage. Fullcargo test -p codexbarwas not run (only the Kimi provider changed).Affected areas
rust/src/providers/kimi/,docs/COOKIES.md)web.rs601,mod.rs892).UI proof
Not applicable