Skip to content

Port upstream 0.69.0: Kimi stale CLI credential guidance (stacked on #610) - #691

Open
Finesssee wants to merge 2 commits into
codex/integrate-reviewed-ports-20260923from
port/micro-0.69.0-kimi-stale-cli-guidance
Open

Finesssee wants to merge 2 commits into
codex/integrate-reviewed-ports-20260923from
port/micro-0.69.0-kimi-stale-cli-guidance

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Summary

In Auto mode, a Kimi Code CLI credential that is stale (expired or inside the 60 s safety margin) or rejected by the server (401/403) no longer disappears silently. The web fallback still runs first. If the web fallback then has no usable session (server-rejected, none found, or Cookie Source off/manual without a token), the fetch now fails with:

Kimi Code CLI credential is invalid or expired. Run kimi to renew it, or add a Kimi Code API key in Settings > Providers > Kimi (KIMI_CODE_API_KEY). CodexBar does not refresh CLI-owned credentials.

Unchanged: CLI credential files stay read-only (never refreshed or rewritten), the message never contains token values, transport/parse/HTTP errors from the web fallback are still surfaced as-is, and a working web session still succeeds.

Implementation:

  • kimi/code_api.rs: kimi_code_cli_access_token -> Option<String> becomes kimi_code_cli_credential -> KimiCliCredential { Unavailable, Stale, Fresh(token) } so a stale credential is distinguishable from an absent one; adds kimi_cli_credential_error() with the guidance text.
  • kimi/mod.rs: Auto-mode tracks "CLI credential unusable" (stale, or fresh but rejected with AuthRequired) and maps a session-unavailable web failure to the guidance.
  • kimi/web.rs: is_session_unavailable classifies which web failures mean "no web session" (AuthRequired, NoCookies, or the Cookie Source Off/Manual-without-token error).

Upstream reference

Ported / Deferred

Ported: the unified guidance text, stale/rejected CLI credential handling with retained web fallback, read-only credential guarantee, 14-minute staleness of a 15-minute token (60 s margin), no token values in the message.

Deferred / not applicable:

  • Upstream's docs/kimi.md prose: this repo has no matching Kimi doc page; a CHANGELOG entry is added instead.
  • Upstream's strategy-pipeline attempt list assertions (kimi.api, kimi.cli, kimi.web) have no Windows counterpart (no fetch-plan pipeline); the equivalent behavior is covered by unit tests of the credential state, session classification and message.
  • No end-to-end test of fetch_usage Auto mode: it reads Settings::load() from disk and hits the network, so it cannot be made deterministic without new test seams.

Validation

Run on the pinned toolchain 1.98.0, slot-2 target dir, pinned to E-cores 16-31 at BelowNormal (see note below).

  • cargo +1.98.0 fmt --all and fmt --all -- --check: clean.
  • cargo +1.98.0 clippy --workspace --all-targets -- -D warnings: pass, no warnings.
  • cargo +1.98.0 test -p codexbar kimi -- --test-threads=4: 65 passed, 0 failed (new: stale/fresh boundary at 839/840/900 s with file bytes unchanged, missing credential is Unavailable not Stale, guidance text contents, no token value in message, web session-unavailable classification).

Note: C:\Users\FSOS\AppData\Local\Temp\port-audit\ecargo.sh disappeared mid-task (the directory was wiped by something outside this task), so cargo was run through an equivalent local stand-in: cmd /c start /affinity FFFF0000 /belownormal /wait /b cargo ....

Affected areas

  • Rust backend (rust/src/providers/kimi/)
  • Tauri shell
  • Frontend
  • Settings schema / bridge types
  • Changelog

UI proof

Not applicable (error text only; no UI surface changed).

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 36865f33-c4cd-4607-b77c-3811fab424f7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Reviewed by Codex gpt-6-luna (xhigh); verified and validated by Claude

Thermo-nuclear review

Scope: kimi/code_api.rs, kimi/mod.rs, kimi/web.rs, CHANGELOG. Spec: 0.69.0 kimi-stale-cli-guidance (upstream steipete#4086 / release note steipete#4063).

Behavior check against spec: the Auto-mode web fallback is retained; the guidance message replaces the web error only when the CLI credential is stale or rejected (AuthRequired) and the web failure means "no web session" (AuthRequired, NoCookies, or Cookie Source off/manual without a token); transport, parse and HTTP errors still surface as-is; the credential file is only read (test asserts the bytes are unchanged); the message contains no token values. Provider logic stays in rust/src/providers/kimi/; no new dependencies; no locale, bridge or frontend surface touched; no file crosses 1000 lines (mod.rs 909, code_api.rs 849).

Findings:

# Severity Location Finding Fixed
1 Low rust/src/providers/kimi/code_api.rs (KimiCliCredential) The new enum derived Debug while Fresh(String) holds the CLI access token, so any {:?} of the state would log a secret (AGENTS.md: never log tokens). Yes. Replaced the derive with a manual Debug that prints Fresh([REDACTED]).

No other valid findings.

Validation (pinned Rust 1.98.0, E-cores): cargo fmt --all -- --check clean; clippy -D warnings clean on rust and apps/desktop-tauri/src-tauri; cargo test kimi 65 passed, 0 failed. Frontend and UI unchanged, so no vitest or CUA run was needed.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Fixes landed at current head 7d0742f

Finding 1 (redact the CLI token in KimiCliCredential Debug) is fixed in rust/src/providers/kimi/code_api.rs. Re-validated on Rust 1.98.0: fmt clean, clippy -D warnings clean on both crates, cargo test kimi 65 passed. Rust crate only; no frontend, bridge or UI change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant