Fix OpenCode Go messages authentication - #1717
kevincodex1 merged 3 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📜 Recent review details🧰 Additional context used📓 Path-based instructions (13)src/**/*.{ts,tsx}📄 CodeRabbit inference engine (AGENTS.md)
Files:
{src/commands/**/*.ts,src/services/**/*.ts,src/entrypoints/**/*.ts}📄 CodeRabbit inference engine (AGENTS.md)
Files:
{src/services/**/*.ts,src/utils/**/*.ts}📄 CodeRabbit inference engine (AGENTS.md)
Files:
{src/integrations/**/*.ts,src/services/**/*.ts}📄 CodeRabbit inference engine (AGENTS.md)
Files:
**/*.{ts,tsx,js,jsx,py,json,md}📄 CodeRabbit inference engine (CONTRIBUTING.md)
Files:
**/*.{ts,tsx,js,jsx,py}📄 CodeRabbit inference engine (CONTRIBUTING.md)
Files:
**/*.{ts,tsx}📄 CodeRabbit inference engine (CONTRIBUTING.md)
Files:
**/*⚙️ CodeRabbit configuration file
Files:
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}⚙️ CodeRabbit configuration file
Files:
**⚙️ CodeRabbit configuration file
Files:
**/*.test.{ts,tsx,js,jsx}📄 CodeRabbit inference engine (CONTRIBUTING.md)
Files:
**/*.test.{ts,tsx,js}📄 CodeRabbit inference engine (CONTRIBUTING.md)
Files:
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}⚙️ CodeRabbit configuration file
Files:
🔇 Additional comments (3)
📝 WalkthroughWalkthroughFive ChangesOpenCode Go Anthropic Messages API configuration
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Suggested reviewers
Suggested labels
🚥 Pre-merge checks | ✅ 6 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (6 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
jatmn
left a comment
There was a problem hiding this comment.
I found an issue that needs to be addressed before this is ready.
Findings
- [P2] Complete the OpenCode Go endpoint migration
src/integrations/gateways/opencode-go.ts:48
If these OpenCode Go models now require the OpenAI-compatible/chat/completionsendpoint, this change is only part of the migration. The current OpenCode Go API docs still list MiniMax M3, MiniMax M2.7, MiniMax M2.5, and Qwen3.6 Plus onhttps://opencode.ai/zen/go/v1/messageswith the Anthropic SDK package, and the adjacent model descriptor section in this repo still groups these Go MiniMax/Qwen entries under the Anthropic messages endpoint. As written, the PR leaves reviewers and future maintainers with contradictory source-of-truth signals and only tests that the override is absent, not that the effective request is correctly chat-completions shaped. Please complete the migration by updating the local model metadata/comments, documenting or linking the live OpenCode evidence that these specific models moved to/chat/completions, and adding a regression that proves the effective OpenAI shim request for the affected models uses the chat-completions endpoint/body shape.
|
Thanks for catching the source-of-truth mismatch. I rechecked both the documented route and the live behavior, and my original endpoint-migration diagnosis was incorrect: these models have not moved to The actual failure was authentication. OpenClaude already generated an Anthropic-shaped body for I updated the patch to:
Official model/endpoint table: https://opencode.ai/docs/go/ Validation includes the full |
jatmn
left a comment
There was a problem hiding this comment.
Thanks for the update. I rechecked the changed paths and found one issue that still needs to be addressed.
Findings
- [P2] Handle stale custom auth before relying on the x-api-key override
src/services/api/openaiShim.test.ts:2463
The new request regression covers the clean environment, but it does not cover the stale custom-auth path that users can carry from another OpenAI-compatible provider.OPENAI_AUTH_HEADERis global,applyProviderFlag('opencode-go')falls through the descriptor-backed default branch without clearing it, and_doOpenAIRequestgives that custom header precedence over the newshimConfig.defaultAuthHeader. I reproduced this by settingOPENCODE_API_KEY=fake-opencode-keyplusOPENAI_AUTH_HEADER=Authorization, selectingopencode-gowithminimax-m3, and capturing the outgoing/zen/go/v1/messagesrequest: it sentAuthorization: Bearer fake-opencode-keyand nox-api-key, so the OpenCode Go Messages route still hits the 401 path this PR is meant to fix. Please complete the effective-request regression from the earlier review by covering this stale custom-auth case and ensuring these model-levelx-api-keyoverrides cannot be bypassed by leftover OpenAI-compatible auth-header env when the user selects OpenCode Go.
A global OPENAI_AUTH_HEADER left over from another OpenAI-compatible route took precedence over the model-level x-api-key in _doOpenAIRequest, so OpenCode Go /messages models still sent Authorization: Bearer and hit the 401 this PR fixes. Ignore the global custom-auth env when the selected model's catalog entry defines an openaiShim.defaultAuthHeader, so the model-level x-api-key contract cannot be bypassed. Adds a stale-custom-auth regression for all five models via the direct-env path.
|
Thanks for the careful re-review — you're right, and I reproduced the exact case you described. With Root of it: the custom auth-header env is global and took precedence in Regression coverage now includes the stale-custom-auth scenario for all five models via the direct-env path, asserting the effective request still goes to Validation:
|
jatmn
left a comment
There was a problem hiding this comment.
Thanks for the update. I rechecked the previously discussed paths and do not see any remaining actionable issues from my side.
@kevincodex1 LGTM
* fix opencode go open model endpoints * fix(opencode): use x-api-key for Go messages * fix(opencode): keep Go x-api-key over stale auth A global OPENAI_AUTH_HEADER left over from another OpenAI-compatible route took precedence over the model-level x-api-key in _doOpenAIRequest, so OpenCode Go /messages models still sent Authorization: Bearer and hit the 401 this PR fixes. Ignore the global custom-auth env when the selected model's catalog entry defines an openaiShim.defaultAuthHeader, so the model-level x-api-key contract cannot be bypassed. Adds a stale-custom-auth regression for all five models via the direct-env path.
Summary
Keep the affected OpenCode Go MiniMax/Qwen models on the Anthropic Messages endpoint and authenticate those requests with a raw
x-api-keyheader instead ofAuthorization: Bearer.This also aligns the local metadata comments and adds request-level regressions for the effective URL, auth headers, and Anthropic body shape.
Root cause
The original PR diagnosis was incorrect: these models did not move to
/chat/completions.OpenClaude already selected
https://opencode.ai/zen/go/v1/messagesand generated an Anthropic-shaped request body, but the OpenAI shim used its default Bearer authentication. OpenCode Go's Messages route treated that request as unauthenticated.OpenCode's current model table documents MiniMax M3, MiniMax M2.7, MiniMax M2.5, and Qwen3.6 Plus on
/zen/go/v1/messageswith@ai-sdk/anthropic:https://opencode.ai/docs/go/
Live verification on 2026-06-18 with the same valid credential:
/messages+Authorization: Bearer401 Missing API key/messages+ rawx-api-key200The existing legacy
qwen3.5-pluscatalog entry was also verified through the live/modelsresponse and/messages+x-api-keyrequest path.Changes
/messagesrouting for the five existing MiniMax/Qwen catalog entries.x-api-keyauthentication override./zen/go/v1/messagesURL;x-api-keyvalue;Authorization;model,messages,system,max_tokens, andstreambody fields;max_completion_tokensandstorefields.Validation
bun run check— 4,612 passed, 0 failedbun run typecheck— passedbun test src/integrations/gateways/opencode.test.ts— 59 passedbun test src/services/api/openaiShim.test.ts --test-name-pattern 'opencode go'— 5 passedbun run integrations:check— artifacts up to datebun run security:pr-scan— no suspicious additionsminimax-m3—OKqwen3.6-plus—OKScope
The current OpenCode Go catalog also needs a separate refresh for newly advertised model IDs such as GLM-5.2, Kimi K2.7 Code, and Qwen3.7 Max/Plus. That additive catalog update is intentionally kept out of this focused authentication fix.
Summary by CodeRabbit
Chores
/messagesendpoint and usex-api-keyauthentication.Tests
https://opencode.ai/zen/go/v1/messageswithx-api-keyauth (noauthorizationheader), send the correct Anthropic Messages body (system,messages,max_tokens,stream: false), and omit unsupported fields.