Skip to content

Port upstream 0.66.0: import Kimi web access tokens from Chromium local storage (stacked on #646) - #649

Open
Finesssee wants to merge 11 commits into
port/micro-0.66.0-browser-leveldb-readerfrom
port/micro-0.66.0-kimi-local-storage-tokens
Open

Finesssee wants to merge 11 commits into
port/micro-0.66.0-browser-leveldb-readerfrom
port/micro-0.66.0-kimi-local-storage-tokens

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

Kimi web fetch and the Kimi Code monthly enrichment now also read the web access_token from Chromium browsers' Local Storage for the selected Kimi region (https://www.kimi.com or https://www.kimi.ai). It is the last step of the token chain: manual cookie header, Kimi Desktop session, browser cookies, then local-storage tokens. Only unexpired three-segment ASCII JWTs (exp in the future) are used, deduplicated across profiles. Refresh tokens are never read. Manual credentials stay authoritative and Cookie source Off/Manual skips the step, so manual and saved-account credentials stay isolated. Because local storage is not App-Bound encrypted, this can work when cookie decryption is blocked.

Dependencies (stacked):

Upstream reference

  • Release bullet (v0.66.0): "Kimi: import web access tokens from Chromium local storage for the selected region, preserving manual and saved-account credential isolation (fix(kimi): import kimi.ai session from browser local storage steipete/CodexBar#3923)", commit 49e7ff3e.
  • Tag-pinned files at v0.66.0: Sources/CodexBarCore/Providers/Kimi/KimiCookieImporter.swift (localStorageTokens(region:): access_token key, JSON-string or trimmed value, three . segments, ASCII letters/digits/-_., exp finite and in the future, dedupe), Sources/CodexBarCore/Providers/Kimi/KimiProviderDescriptor.swift (KimiWebEnrichmentTokenResolver, browserTokens append after cookie sessions), Tests/CodexBarTests/KimiLocalStorageTests.swift (token fixture eyJhbGciOiJIUzI1NiJ9.eyJleHAiOjE4MDAwMDM2MDB9.signature, expired/a.b.c/refresh-token/suffix cases), docs/kimi.md (order item 7).

Ported / Deferred

Ported: the token filter and ordering, region-bound origin, integration into both fetch_via_web (lazy: read only after every cookie source was rejected with an auth error) and web_auth_tokens (Code API / CLI enrichment), docs note in docs/COOKIES.md.

Deferred / differences:

  • Browser and profile discovery reuses the existing BrowserDetector (Chrome, Edge, Brave, Arc, Chromium; profiles Default and Profile N). Upstream's shared catalog also covers user-* profiles and more Chromium browsers (Comet, Yandex, ...) and reads profile display names; those belong with the MiniMax storage-discovery item and are not done here.
  • Firefox and Safari local storage are not read (same as upstream).
  • Not checked against a live Chrome/Edge profile: this agent must not read the real browser profile here. Fixtures are LevelDB write-ahead logs built from the documented format (same as Port upstream 0.66.0: shared Chromium LevelDB + Snappy reader #646). A real-profile smoke check is still worth doing by the coordinator when capturing proof.
  • Upstream wire fixtures and the JWT-check behavior were ported; no new endpoints or field names were introduced.

Validation

Toolchain cargo +1.98.0, slot-4 target dir, E-core wrappers.

  • cargo +1.98.0 fmt --all: clean
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: pass
  • cargo +1.98.0 test -p codexbar kimi -- --test-threads=4: 66 passed, 0 failed (includes 3 new kimi::local_storage tests and 2 new kimi::web chain-order tests)

New tests cover: refresh-token key ignored; expired, malformed (not-a-token, a.b.c), and cookie-suffixed values rejected; JSON-quoted and whitespace-padded values accepted; expiry boundary (now + 3600); non-numeric or missing exp rejected; end-to-end read of profile Local Storage/leveldb logs with region-exact origin, cross-profile dedupe, and profiles without local storage; chain order desktop, browser cookie, local storage with dedupe; manual credential and Cookie source Off/Manual never reach local storage. Full cargo test -p codexbar was not run (only the Kimi provider changed).

Affected areas

  • Rust backend (rust/src/providers/kimi/, docs/COOKIES.md)
  • Tauri shell
  • Frontend
  • Settings / bridge types
  • No new dependencies. No file over 1000 lines (web.rs 601, mod.rs 892).

UI proof

Not applicable

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 84798acf-2ca2-42e1-a684-5332dd575d62

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude

Thermo-nuclear review findings:

  • High: leveldb/mod.rs read paths used a metadata check followed by an unbounded read (bypassable if a file grew), and the scan kept records from every origin. Fixed: hard byte limits, shared Kimi scan budget across profiles, only selected-origin records retained.
  • Medium: leveldb/table.rs and snappy.rs applied the block limit only to Snappy output; Snappy allocation and length arithmetic were unbounded. Fixed: both block types capped, fallible allocation, checked arithmetic.
  • Medium: leveldb/log.rs and table.rs let malformed batches/blocks contribute a valid-looking prefix; sequence numbers could wrap. Fixed: batches validated before apply, entry and restart bounds checked, sequence arithmetic bounded.
  • Low: leveldb/local_storage.rs and kimi/web.rs Debug output could expose stored values and tokens. Fixed: redacted Debug, token size limits.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at head 2542a90: all 4 findings fixed (also fixed a compile error and 4 clippy lints in the applied changes). Nothing left. Commands run: cargo +1.98.0 fmt --all, clippy -D warnings (rust crate, all targets), cargo test --lib leveldb (24 passed) and kimi (66 passed). Tauri crate clippy skipped: no changes outside the rust crate.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Adversarial validation (lane-A) at e68a698 — CONFLICTING note resolved

Review verdict: the branch matches the 0.66.0 audit row-22 spec: local_storage_tokens(region) reads access_token from each Chromium profile's Local Storage/leveldb for the selected region's web origin, keeps only current three-segment ASCII JWTs (deduplicated, browser/profile detection order), never touches refresh tokens, and runs after cookie sources so a manual credential or cookie session always takes precedence (web.rs chain ordering tests).

CONFLICTING resolution (the LANE-A note): the "which profile directories the importer walks" gap is closed by the fresh stack, not a code edit on the branch. The original head (5c37174c/2542a90f) inherited the pre-0.66 profile walk that only enumerated Default + Profile *; user-* Chromium profiles were missing. The merged stack fixes this in browser/detection.rs (f37043a3 via #651's thermo commit): detect_chromium_profiles now filters Default || Profile * || user-* (sorted, guest/system/hidden/file entries dropped), and the Kimi importer consumes those profiles via BrowserDetector::detect_all(), so user-* profiles are covered exactly like the MiniMax importer.

Merge outcome: merged the finished #646 head (347faabf), the #651 head (084719a8), and the remote thermo commit (2542a90f) — 57eaa329, aa27b0c7, 8a39324a, e68a6988. The four leveldb conflicts were resolved toward 2542a90f's strict superset (read_log_until, MAX_LOG_RECORD_BYTES, MAX_SEQUENCE, MAX_RECORDS_PER_DIRECTORY guards); the read_local_storage_entries_for_origins multi-origin variant was restored on top so the MiniMax discovery importer keeps compiling. One module-declaration conflict (kimi/mod.rs) kept both local_storage and ratio_pool.

Checks at e68a698 (CARGO_TARGET_DIR=W:\cargo-target\lane-a, jobs=4, RUST_TEST_THREADS=4):

  • cargo fmt --all --check: pass.
  • cargo clippy both manifests --all-targets -- -D warnings: only the 3 documented pre-existing main-drift findings; 0 in this PR's diff.
  • cargo test rust manifest: 2322 passed / 0 failed / 1 ignored (kimi focused: 75/0; leveldb: 24/0).
  • cargo test desktop manifest: 489 passed / 1 failed — bootstrap_payload_exposes_every_provider_variant, the documented Isolate bootstrap payload test from real settings #684 environment-dependent baseline on branches without Make the bootstrap catalog test hermetic (#684) #711 (expected; hermetic fix lives on release/v0.70.0).

Fast-forward pushed 2542a90f..e68a6988 (ls-remote verified).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant