Skip to content

feat(integrations): add ApiSmart OpenAI-compatible gateway provider - #2109

Merged
kevincodex1 merged 21 commits into
Twigpine:mainfrom
jatmn:feat/apismart-provider
Aug 11, 2026
Merged

kevincodex1 merged 21 commits into
Twigpine:mainfrom
jatmn:feat/apismart-provider

Conversation

@jatmn

@jatmn jatmn commented Aug 10, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Adds an ApiSmart gateway (https://gw.apismart.ai/v1) with a hybrid catalog: curated LLM model IDs plus authenticated OpenAI-compatible /v1/models discovery.
  • Wires dedicated APISMART_API_KEY / APISMART_MODEL support across route detection, env-only defaults, provider flag/profile flows, request resolution, and shim credential handling.
  • Documents ApiSmart in README and the web providers/configuration lists.

Contributor checklist

  • Reviewed CONTRIBUTING.md and AGENTS.md
  • Focused PR on one provider addition
  • Added/updated tests for changed behavior

User / developer impact

  • Users can select ApiSmart via --provider apismart, saved profiles, or env-only setup with APISMART_API_KEY (and optional APISMART_MODEL).
  • Hybrid discovery keeps curated chat models visible before discovery and filters non-chat image/video model IDs from /v1/models.
  • Dedicated credentials are isolated from generic OPENAI_API_KEY forwarding, matching Atlas Cloud / ClinePass patterns.
  • Shared credential helpers reject dotenv template placeholders (null / undefined / SUA_CHAVE) so ambient template keys cannot hijack ApiSmart routing.

Provider path tested

  • ApiSmart gateway descriptor and mapModel filtering
  • Env-only route resolution (APISMART_API_KEY, base URL refinement, dual-key precedence vs ClinePass/AIMLAPI)
  • APISMART_MODEL resolution in providerConfig, client, providerFlag, and profile env builders
  • Profile apply/persist and launch env carry-over scoped to the apismart route

Test plan

  • bun run build
  • bun run smoke
  • bun run check
  • Focused tests for ApiSmart gateway, route metadata, providerConfig, providerFlag/profile(s), envFile, and credentialPool

Summary by CodeRabbit

  • New Features

    • Added ApiSmart as an OpenAI-compatible provider.
    • Added API-key configuration, default model selection, authenticated model discovery, and provider routing.
    • Added setup guidance to documentation and configuration screens.
  • Bug Fixes

    • Improved credential validation and sanitization for blank, placeholder, and case-variant values.
    • Restricted credentials to approved ApiSmart endpoints and improved provider selection behavior.
    • Updated invalid-credential messaging to avoid exposing placeholder values.
  • Tests

    • Added coverage for ApiSmart integration, discovery, routing, configuration, and credential handling.

@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 7 minutes

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 34812f8b-9a64-42d2-ac17-07852775bc95

📥 Commits

Reviewing files that changed from the base of the PR and between 0137006 and 22bd7bc.

📒 Files selected for processing (5)
  • src/integrations/discoveryService.test.ts
  • src/services/api/client.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerFlag.ts
📝 Walkthrough

Walkthrough

ApiSmart is added as an OpenAI-compatible gateway with hybrid model discovery, curated fallbacks, canonical endpoint validation, API-key handling, route resolution, profile persistence, environment support, web configuration, tests, and documentation. Credential placeholder handling is standardized.

Changes

ApiSmart integration

Layer / File(s) Summary
Gateway catalog and discovery
src/integrations/gateways/apismart.ts, src/integrations/gateways/apismart.test.ts, src/integrations/compatibility.test.ts, web/src/data/providers.ts, README.md
Adds the ApiSmart gateway, curated models, authenticated hybrid discovery, model filtering, OpenAI-compatible routing, provider registration, and documentation.
Canonical routing and credential validation
src/integrations/routeMetadata.ts, src/utils/providerValidation.ts, src/services/api/credentialPool.ts, src/utils/providerSecrets.ts, src/services/api/openaiShim/requestExecutor.ts, related tests
Adds ApiSmart route detection, canonical URL checks, dedicated credential isolation, placeholder rejection, key sanitization, and generic invalid-credential errors.
Discovery and runtime provider configuration
src/integrations/discoveryService.ts, src/services/api/client.ts, src/services/api/providerConfig.ts, src/utils/providerFlag.ts, src/utils/envFile.ts, related tests
Adds ApiSmart defaults, model precedence, OpenAI-shim routing, canonical discovery credentials, environment-file support, and cleanup behavior.
Provider profile persistence and startup isolation
src/utils/providerProfile.ts, src/utils/providerProfiles.ts, related tests
Adds ApiSmart profile construction, route identity, credential sanitization, startup handling, canonical-key migration, and credential isolation for retargeted endpoints.

Estimated code review effort: 4 (Complex) | ~60 minutes

Possibly related PRs

Suggested labels: enhancement

Suggested reviewers: kevincodex1, 0xfandom, gravirei

🚥 Pre-merge checks | ✅ 5 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 14.29% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Risk Surface Disclosed ⚠️ Warning The PR changes auth, route selection, outbound discovery/inference, and profile/startup credential persistence, but its description does not explicitly state the risk surface or blocker status. Add a review note covering credential forwarding, external model discovery, routing, and profile/startup persistence, then state explicitly whether any blocker remains.
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title is concise, scoped to integrations, and accurately describes the ApiSmart gateway addition.
Description check ✅ Passed The description covers the change, impact, provider path, testing, and completed build, smoke, check, and focused tests.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No Hidden Policy Change ✅ Passed The diff confines policy changes to the declared ApiSmart route: endpoint/default model, authenticated discovery, credential boundaries, precedence, and unsupported usage; no telemetry or permissio...
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@jatmn jatmn self-assigned this Aug 10, 2026
@jatmn jatmn added the new: provider/gateway Request to add a new provider or gateway label Aug 10, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
src/utils/envFile.test.ts (1)

73-73: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Restore APISMART_MODEL between tests.

Line 73 restores APISMART_API_KEY but not APISMART_MODEL. loadEnvFile does not overwrite an existing variable. A stale APISMART_MODEL causes the assertion at line 287 to expect a value that loaded correctly omits. Both reported smoke-and-tests checks fail at line 287.

Proposed fix
   'ATLAS_CLOUD_API_KEY',
   'APISMART_API_KEY',
+  'APISMART_MODEL',
   'CLINE_API_KEY',

Run bun test ./src/utils/envFile.test.ts after the fix.

As per coding guidelines, “Add or update tests when behavior changes, and run the narrowest useful focused test checks.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/utils/envFile.test.ts` at line 73, Update the test cleanup around
writeTempEnvFile and the corresponding environment restoration logic to preserve
and restore APISMART_MODEL alongside APISMART_API_KEY. Ensure each test starts
without stale APISMART_MODEL state so the loaded result and assertion remain
accurate, then run the focused envFile test suite.

Sources: Coding guidelines, Path instructions, Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/integrations/routeMetadata.ts`:
- Around line 405-416: Update isApismartBaseUrl to require the parsed URL
protocol to be HTTPS and its port to be the default HTTPS port (or unspecified),
while preserving hostname matching and invalid-input rejection. Add regression
cases covering HTTP URLs and ApiSmart URLs with custom ports, ensuring neither
matches.

In `@src/utils/providerFlag.test.ts`:
- Line 43: Add APISMART_MODEL to the saved environment keys at
src/utils/providerFlag.test.ts:43-43, RESET_KEYS at
src/utils/providerFlag.test.ts:93-93, and ENV_KEYS at
scripts/system-check.test.ts:85-85 so tests isolate and restore the model
setting; then run bun test ./src/utils/providerFlag.test.ts.

In `@src/utils/providerFlag.ts`:
- Around line 586-605: Update the apismart branch around
applyOpenAIBaseUrlDefault so APISMART_API_KEY is mirrored to OPENAI_API_KEY only
when getConfiguredOpenAIBaseUrl() matches isApismartBaseUrl(); otherwise remove
or preserve the generic key without forwarding the ApiSmart credential. Add a
regression test in providerFlag.test.ts covering a stale custom OPENAI_BASE_URL,
then run the specified test file.

---

Outside diff comments:
In `@src/utils/envFile.test.ts`:
- Line 73: Update the test cleanup around writeTempEnvFile and the corresponding
environment restoration logic to preserve and restore APISMART_MODEL alongside
APISMART_API_KEY. Ensure each test starts without stale APISMART_MODEL state so
the loaded result and assertion remain accurate, then run the focused envFile
test suite.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 60d9ed00-aec4-4b74-9bd2-4c32cf36914c

📥 Commits

Reviewing files that changed from the base of the PR and between 54b9cd8 and 56f9110.

⛔ Files ignored due to path filters (2)
  • src/integrations/generated/integrationArtifacts.generated.ts is excluded by !**/*.generated.*, !**/generated/**, !src/integrations/generated/**
  • src/integrations/generated/integrationManifest.generated.ts is excluded by !**/*.generated.*, !**/generated/**, !src/integrations/generated/**
📒 Files selected for processing (19)
  • scripts/system-check.test.ts
  • src/integrations/compatibility.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/client.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/envFile.test.ts
  • src/utils/envFile.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerProfiles.ts
  • web/src/data/providers.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (14)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/integrations/compatibility.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • scripts/system-check.test.ts
  • src/utils/envFile.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/client.ts
  • web/src/data/providers.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/integrations/compatibility.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • scripts/system-check.test.ts
  • src/utils/envFile.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/client.ts
  • web/src/data/providers.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/integrations/compatibility.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/envFile.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/client.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/integrations/compatibility.test.ts
  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/envFile.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/integrations/compatibility.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • scripts/system-check.test.ts
  • src/utils/envFile.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/client.ts
  • web/src/data/providers.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/integrations/compatibility.test.ts
  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/envFile.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/integrations/compatibility.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • scripts/system-check.test.ts
  • src/utils/envFile.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/client.ts
  • web/src/data/providers.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/integrations/compatibility.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • scripts/system-check.test.ts
  • src/utils/envFile.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/client.ts
  • web/src/data/providers.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/compatibility.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/client.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/integrations/compatibility.test.ts
  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/envFile.test.ts
src/services/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Files:

  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}

⚙️ CodeRabbit configuration file

{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.

Files:

  • scripts/system-check.test.ts
web/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

When changing the web application, run the web typecheck and build checks.

Files:

  • web/src/data/providers.ts
web/**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

When changing files under web/, run bun run web:typecheck and bun run web:build.

Files:

  • web/src/data/providers.ts
web/**

⚙️ CodeRabbit configuration file

web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.

Files:

  • web/src/data/providers.ts
🪛 GitHub Check: smoke-and-tests (22)
src/utils/envFile.test.ts

[failure] 287-287: error: expect(received).toEqual(expected)
{
"APISMART_API_KEY": "apismart-key",

  • "APISMART_MODEL": "KIMI_K3",
    }

  • Expected - 1

  • Received + 0

    at <anonymous> (/home/runner/work/openclaude/openclaude/src/utils/envFile.test.ts:287:20)
    
🪛 GitHub Check: smoke-and-tests (24.11.x)
src/utils/envFile.test.ts

[failure] 287-287: error: expect(received).toEqual(expected)
{
"APISMART_API_KEY": "apismart-key",

  • "APISMART_MODEL": "KIMI_K3",
    }

  • Expected - 1

  • Received + 0

    at <anonymous> (/home/runner/work/openclaude/openclaude/src/utils/envFile.test.ts:287:20)
    
🔇 Additional comments (8)
src/integrations/gateways/apismart.ts (1)

1-227: LGTM!

src/integrations/gateways/apismart.test.ts (1)

1-44: LGTM!

src/integrations/compatibility.test.ts (1)

22-22: LGTM!

web/src/data/providers.ts (1)

191-198: LGTM!

src/services/api/providerConfig.ts (1)

27-29: LGTM!

Also applies to: 935-1026

src/services/api/providerConfig.test.ts (1)

317-405: LGTM!

src/services/api/openaiShim/requestExecutor.ts (1)

290-290: LGTM!

src/utils/providerFlag.ts (1)

319-321: LGTM!

Comment thread src/integrations/routeMetadata.ts
Comment thread src/utils/providerFlag.test.ts
Comment thread src/utils/providerFlag.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
src/integrations/routeMetadata.ts (1)

648-648: 🎯 Functional Correctness | 🟠 Major | 🏗️ Heavy lift

Preserve matching competing base URLs.

When APISMART_API_KEY and OPENAI_BASE_URL=https://api.aimlapi.com/v1 are set, both env-only predicates reject the configuration. Resolution falls back to anthropic instead of aimlapi.

Apply ApiSmart precedence only when no compatible competing base URL is configured. Add regression tests and run bun test ./src/integrations/routeMetadata.test.ts.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/integrations/routeMetadata.ts` at line 648, Update the ApiSmart
environment predicate near hasNonEmptyEnvValue so ApiSmart precedence applies
only when no compatible competing base URL, including
OPENAI_BASE_URL=https://api.aimlapi.com/v1, is configured; preserve matching
aimlapi resolution instead of falling back to anthropic. Add regression coverage
in routeMetadata tests for this environment combination and run the specified
test file.

Sources: Coding guidelines, Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@src/integrations/routeMetadata.ts`:
- Line 648: Update the ApiSmart environment predicate near hasNonEmptyEnvValue
so ApiSmart precedence applies only when no compatible competing base URL,
including OPENAI_BASE_URL=https://api.aimlapi.com/v1, is configured; preserve
matching aimlapi resolution instead of falling back to anthropic. Add regression
coverage in routeMetadata tests for this environment combination and run the
specified test file.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: f821f68f-e60d-4c81-9366-385af5ca36c2

📥 Commits

Reviewing files that changed from the base of the PR and between 56f9110 and 5de48bd.

📒 Files selected for processing (6)
  • scripts/system-check.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/envFile.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerFlag.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: smoke-and-tests (24.11.x)
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerFlag.ts
  • src/integrations/routeMetadata.test.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerFlag.ts
  • src/integrations/routeMetadata.test.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerFlag.ts
  • src/integrations/routeMetadata.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerFlag.ts
  • src/integrations/routeMetadata.test.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerFlag.ts
  • src/integrations/routeMetadata.test.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}

⚙️ CodeRabbit configuration file

{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.

Files:

  • scripts/system-check.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.test.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/utils/providerFlag.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerFlag.ts
  • src/integrations/routeMetadata.test.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerFlag.ts
  • src/integrations/routeMetadata.test.ts
🔇 Additional comments (6)
src/integrations/routeMetadata.ts (1)

405-422: LGTM!

Also applies to: 816-816

src/utils/providerFlag.ts (1)

30-30: LGTM!

Also applies to: 320-322, 587-611

src/integrations/routeMetadata.test.ts (1)

9-9: LGTM!

Also applies to: 225-236, 321-334, 469-504

src/utils/envFile.test.ts (1)

21-22: LGTM!

Also applies to: 279-294

src/utils/providerFlag.test.ts (1)

43-44: LGTM!

Also applies to: 94-95, 988-996

scripts/system-check.test.ts (1)

85-86: LGTM!

coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 10, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/integrations/routeMetadata.ts`:
- Around line 626-633: The route resolver must reject placeholder ApiSmart
credentials instead of treating any non-empty APISMART_API_KEY as usable. In
src/integrations/routeMetadata.ts:626-633, update hasCompetingApismartCredential
to use the existing placeholder-aware credential validation; in
src/integrations/routeMetadata.ts:812-827, require the same validation for
ApiSmart env-only intent; and in src/services/api/providerConfig.ts:935, enable
ApiSmart mode only when its dedicated credential is usable. Add placeholder-only
and placeholder-plus-valid-competing-route coverage in
src/integrations/routeMetadata.test.ts:471-477, plus verification in
src/services/api/providerConfig.test.ts:379-390 that a placeholder key does not
override valid OpenAI configuration, then run both specified test files.

In `@src/utils/providerProfiles.ts`:
- Around line 154-155: Update isApismartProfile to classify missing or blank
profile.baseUrl values as ApiSmart, while continuing to reject explicit
non-ApiSmart URLs. Preserve buildApismartProfileEnv’s default-endpoint behavior,
and add runtime and persisted-startup regression tests covering an ApiSmart
profile without baseUrl, including credential handling and startup discovery.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 1b999b50-acd3-4d9f-a65f-5b757026a0df

📥 Commits

Reviewing files that changed from the base of the PR and between 5de48bd and 6b05fda.

📒 Files selected for processing (10)
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerProfiles.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (2)
  • GitHub Check: smoke-and-tests (24.11.x)
  • GitHub Check: typecheck
🧰 Additional context used
📓 Path-based instructions (10)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/utils/providerProfiles.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfile.ts
  • src/integrations/routeMetadata.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/utils/providerProfiles.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfile.ts
  • src/integrations/routeMetadata.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/utils/providerProfiles.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfile.ts
  • src/integrations/routeMetadata.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/utils/providerProfiles.test.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/utils/providerProfiles.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfile.ts
  • src/integrations/routeMetadata.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/utils/providerProfiles.test.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/utils/providerProfiles.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfile.ts
  • src/integrations/routeMetadata.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/utils/providerProfiles.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfile.ts
  • src/integrations/routeMetadata.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/utils/providerProfiles.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfile.ts
  • src/integrations/routeMetadata.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/utils/providerProfiles.test.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
src/services/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Files:

  • src/services/api/providerConfig.ts
  • src/services/api/providerConfig.test.ts

Comment thread src/integrations/routeMetadata.ts
Comment thread src/utils/providerProfiles.ts Outdated
coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 10, 2026
jatmn added 5 commits August 10, 2026 10:31
Add a hybrid-catalog ApiSmart gateway with dedicated APISMART_API_KEY/APISMART_MODEL
env wiring, route detection, profile persistence, and regression tests so the
provider works via --provider, env-only setup, and saved profiles.
@jatmn
jatmn force-pushed the feat/apismart-provider branch from cc818f9 to be559ab Compare August 10, 2026 17:32
coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 10, 2026
coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 10, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (3)
src/utils/providerProfiles.ts (2)

944-949: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Clarify the nested base-URL ternary.

The indentation suggests : profile.baseUrl on Line 949 belongs to the inner ApiSmart ternary. It is the else of the outer Xiaomi condition. The logic is correct, but a reader must count operators to confirm it.

Extract a small helper or add braces-style formatting so the two independent normalizations read separately.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/utils/providerProfiles.ts` around lines 944 - 949, Clarify the nested
ternary in the base-URL normalization logic by extracting the Xiaomi and
ApiSmart cases into a small helper or using explicit brace-style conditionals.
Update the code around normalizedProfileBaseUrl so each independent
normalization has an unambiguous fallback to profile.baseUrl, while preserving
the existing behavior.

976-1020: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Use profileApiKey consistently inside the credential block.

Line 984 gates the block on profileApiKey, and Line 1019 assigns profileApiKey. The other branches in the same block assign the raw profile.apiKey, including MINIMAX_API_KEY, NVIDIA_API_KEY, XAI_API_KEY, and ATLAS_CLOUD_API_KEY.

Today this is harmless. profileApiKey differs from profile.apiKey only for an ApiSmart profile with an unusable key, and that case skips the whole block. The risk is future: if profileApiKey gains a validator for another route, the raw key would still reach those dedicated variables and bypass the sanitization.

Assign profileApiKey in every branch so one sanitized value feeds all mirrors.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/utils/providerProfiles.ts` around lines 976 - 1020, Within the credential
block guarded by profileApiKey, replace every dedicated environment-variable
assignment that currently uses profile.apiKey with profileApiKey, including
MINIMAX_API_KEY, NVIDIA_API_KEY, BNKR_API_KEY, XAI_API_KEY, AIMLAPI_API_KEY,
VENICE_API_KEY, MIMO_API_KEY, and ATLAS_CLOUD_API_KEY. Keep the existing route
conditions and the APISMART_API_KEY assignment unchanged.
src/integrations/routeMetadata.ts (1)

634-646: 🗄️ Data Integrity & Integration | 🔴 Critical | ⚡ Quick win

Blocking: sentinel base-URL values falsely suppress ApiSmart route selection.

hasConflictingOpenAIBaseUrlForRoute tests the raw env value. hasNonEmptyEnvValue(' UNDEFINED ') returns true and isApismartBaseUrl(' UNDEFINED ') returns false, so the function reports a conflicting endpoint. hasApismartProviderIntent then returns false, resolveEnvOnlyProviderRouteId does not return apismart, and applyApismartEnvOnlyDefaults in src/services/api/client.ts never runs.

This is a contract break between producer and consumer. applyApismartEnvOnlyDefaults already discards null and undefined sentinels through getUsableRouteConfigEnvValue, but this selector treats the same values as a real endpoint. The four failures at src/services/api/client.test.ts Line 1607 match this path: the sentinel survives in OPENAI_BASE_URL, or OPENAI_BASE_URL stays unset when the sentinel is in OPENAI_API_BASE.

Apply one sentinel policy in the selector. The fix is shared by every route that calls this helper.

🐛 Proposed fix to normalize sentinel values before conflict detection
 function hasConflictingOpenAIBaseUrlForRoute(
   processEnv: NodeJS.ProcessEnv,
   isRouteBaseUrl: (value: string | undefined) => boolean,
 ): boolean {
-  if (hasNonEmptyEnvValue(processEnv.OPENAI_BASE_URL)) {
-    return !isRouteBaseUrl(processEnv.OPENAI_BASE_URL)
-  }
-
-  return (
-    hasNonEmptyEnvValue(processEnv.OPENAI_API_BASE) &&
-    !isRouteBaseUrl(processEnv.OPENAI_API_BASE)
-  )
+  const baseUrl = getUsableRouteConfigEnvValue(processEnv.OPENAI_BASE_URL)
+  if (baseUrl !== undefined) {
+    return !isRouteBaseUrl(baseUrl)
+  }
+
+  const apiBase = getUsableRouteConfigEnvValue(processEnv.OPENAI_API_BASE)
+  return apiBase !== undefined && !isRouteBaseUrl(apiBase)
 }

As per path instructions, review provider routing, env precedence, and outbound HTTP behavior with high scrutiny.

Also applies to: 860-890

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/integrations/routeMetadata.ts` around lines 634 - 646, Update
hasConflictingOpenAIBaseUrlForRoute to normalize OPENAI_BASE_URL and
OPENAI_API_BASE through the shared getUsableRouteConfigEnvValue sentinel policy
before checking for non-empty values or route compatibility. Preserve
OPENAI_BASE_URL precedence, fall back to OPENAI_API_BASE only when the
normalized primary value is absent, and ensure null/undefined sentinel values do
not count as conflicting endpoints for every caller.

Sources: Path instructions, Pipeline failures

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/integrations/routeMetadata.test.ts`:
- Around line 73-80: Add null and undefined assertions to the test for
hasUsableRouteCredentialEnvValue with APISMART_API_KEY, ensuring both sentinel
values are rejected alongside the existing placeholder case while retaining the
valid-key assertion. Update the test description to reflect ApiSmart’s stricter
credential rules rather than OpenAI placeholder rules.

In `@src/integrations/routeMetadata.ts`:
- Around line 874-890: The ApiSmart env-only intent uses an inconsistent
credential validator, and its tests omit required placeholder cases. In
src/integrations/routeMetadata.ts lines 874-890, update
hasApismartEnvOnlyProviderIntent to use hasUsableRouteCredentialEnvValue with
APISMART_API_KEY, while leaving hasConfiguredApismartProviderIntent unchanged;
in src/integrations/routeMetadata.test.ts lines 73-80, rename the test to
describe ApiSmart rules and cover sua_chave, null, NULL, whitespace-padded
undefined, and the empty string. Run the specified routeMetadata test.

In `@src/services/api/client.test.ts`:
- Around line 1543-1609: The ApiSmart tests must isolate
CLAUDE_CODE_PROVIDER_ROUTE_ID so external values cannot redirect requests away
from ApiSmart. Update the shared environment snapshot, cleanup helper, and
teardown/restoration logic used by these tests to clear and restore
CLAUDE_CODE_PROVIDER_ROUTE_ID, while preserving the existing nullish-sentinel
assertions.

In `@src/services/api/openaiShim/requestExecutor.ts`:
- Around line 247-265: Extend the existing restricted-route POST test for the
ApiSmart path in client.test.ts by supplying caller custom headers, then assert
those headers are omitted from the request. Also verify the managed client
headers and route credential authorization remain present, preserving the
current restricted-route behavior.

---

Outside diff comments:
In `@src/integrations/routeMetadata.ts`:
- Around line 634-646: Update hasConflictingOpenAIBaseUrlForRoute to normalize
OPENAI_BASE_URL and OPENAI_API_BASE through the shared
getUsableRouteConfigEnvValue sentinel policy before checking for non-empty
values or route compatibility. Preserve OPENAI_BASE_URL precedence, fall back to
OPENAI_API_BASE only when the normalized primary value is absent, and ensure
null/undefined sentinel values do not count as conflicting endpoints for every
caller.

In `@src/utils/providerProfiles.ts`:
- Around line 944-949: Clarify the nested ternary in the base-URL normalization
logic by extracting the Xiaomi and ApiSmart cases into a small helper or using
explicit brace-style conditionals. Update the code around
normalizedProfileBaseUrl so each independent normalization has an unambiguous
fallback to profile.baseUrl, while preserving the existing behavior.
- Around line 976-1020: Within the credential block guarded by profileApiKey,
replace every dedicated environment-variable assignment that currently uses
profile.apiKey with profileApiKey, including MINIMAX_API_KEY, NVIDIA_API_KEY,
BNKR_API_KEY, XAI_API_KEY, AIMLAPI_API_KEY, VENICE_API_KEY, MIMO_API_KEY, and
ATLAS_CLOUD_API_KEY. Keep the existing route conditions and the APISMART_API_KEY
assignment unchanged.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 835eb453-9fff-4a28-b5bd-7994d67ac48f

📥 Commits

Reviewing files that changed from the base of the PR and between 3194fe3 and f8cd975.

📒 Files selected for processing (33)
  • README.md
  • src/components/ProviderManager.test.tsx
  • src/components/ProviderManager.tsx
  • src/components/StartupScreen.test.ts
  • src/components/StartupScreen.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/integrations/index.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/agentRouting.test.ts
  • src/services/api/agentRouting.ts
  • src/services/api/client.test.ts
  • src/services/api/client.ts
  • src/services/api/credentialPool.test.ts
  • src/services/api/openaiShim.ts
  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/model/model.openai-shim-providers.test.ts
  • src/utils/model/model.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerStartupOverrides.test.ts
  • src/utils/providerStartupOverrides.ts
  • src/utils/providerValidation.test.ts
  • src/utils/providerValidation.ts
  • web/src/data/configuration.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (14)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim.ts
  • src/integrations/discoveryService.test.ts
  • src/components/StartupScreen.test.ts
  • src/integrations/index.ts
  • src/services/api/agentRouting.test.ts
  • src/utils/model/model.openai-shim-providers.test.ts
  • web/src/data/configuration.ts
  • src/utils/providerStartupOverrides.ts
  • src/services/api/credentialPool.test.ts
  • src/integrations/discoveryService.ts
  • src/components/ProviderManager.test.tsx
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/components/ProviderManager.tsx
  • src/services/api/agentRouting.ts
  • src/utils/providerValidation.test.ts
  • src/components/StartupScreen.ts
  • src/utils/providerFlag.test.ts
  • src/utils/model/model.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim.ts
  • src/integrations/discoveryService.test.ts
  • src/components/StartupScreen.test.ts
  • src/integrations/index.ts
  • src/services/api/agentRouting.test.ts
  • src/utils/model/model.openai-shim-providers.test.ts
  • web/src/data/configuration.ts
  • src/utils/providerStartupOverrides.ts
  • src/services/api/credentialPool.test.ts
  • src/integrations/discoveryService.ts
  • src/components/ProviderManager.test.tsx
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/components/ProviderManager.tsx
  • src/services/api/agentRouting.ts
  • src/utils/providerValidation.test.ts
  • src/components/StartupScreen.ts
  • src/utils/providerFlag.test.ts
  • src/utils/model/model.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim.ts
  • src/integrations/discoveryService.test.ts
  • src/components/StartupScreen.test.ts
  • src/integrations/index.ts
  • src/services/api/agentRouting.test.ts
  • src/utils/model/model.openai-shim-providers.test.ts
  • src/utils/providerStartupOverrides.ts
  • src/services/api/credentialPool.test.ts
  • src/integrations/discoveryService.ts
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/agentRouting.ts
  • src/utils/providerValidation.test.ts
  • src/components/StartupScreen.ts
  • src/utils/providerFlag.test.ts
  • src/utils/model/model.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.ts
src/services/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim.ts
  • src/services/api/agentRouting.test.ts
  • src/services/api/credentialPool.test.ts
  • src/services/api/agentRouting.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.test.ts
  • src/components/StartupScreen.test.ts
  • src/services/api/agentRouting.test.ts
  • src/utils/model/model.openai-shim-providers.test.ts
  • src/services/api/credentialPool.test.ts
  • src/components/ProviderManager.test.tsx
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerValidation.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim.ts
  • src/integrations/discoveryService.test.ts
  • src/components/StartupScreen.test.ts
  • src/integrations/index.ts
  • src/services/api/agentRouting.test.ts
  • src/utils/model/model.openai-shim-providers.test.ts
  • web/src/data/configuration.ts
  • src/utils/providerStartupOverrides.ts
  • src/services/api/credentialPool.test.ts
  • src/integrations/discoveryService.ts
  • src/components/ProviderManager.test.tsx
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/components/ProviderManager.tsx
  • src/services/api/agentRouting.ts
  • src/utils/providerValidation.test.ts
  • src/components/StartupScreen.ts
  • src/utils/providerFlag.test.ts
  • src/utils/model/model.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.test.ts
  • src/components/StartupScreen.test.ts
  • src/services/api/agentRouting.test.ts
  • src/utils/model/model.openai-shim-providers.test.ts
  • src/services/api/credentialPool.test.ts
  • src/components/ProviderManager.test.tsx
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerValidation.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim.ts
  • src/integrations/discoveryService.test.ts
  • src/components/StartupScreen.test.ts
  • src/integrations/index.ts
  • src/services/api/agentRouting.test.ts
  • README.md
  • src/utils/model/model.openai-shim-providers.test.ts
  • web/src/data/configuration.ts
  • src/utils/providerStartupOverrides.ts
  • src/services/api/credentialPool.test.ts
  • src/integrations/discoveryService.ts
  • src/components/ProviderManager.test.tsx
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/components/ProviderManager.tsx
  • src/services/api/agentRouting.ts
  • src/utils/providerValidation.test.ts
  • src/components/StartupScreen.ts
  • src/utils/providerFlag.test.ts
  • src/utils/model/model.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim.ts
  • src/integrations/discoveryService.test.ts
  • src/components/StartupScreen.test.ts
  • src/integrations/index.ts
  • src/services/api/agentRouting.test.ts
  • README.md
  • src/utils/model/model.openai-shim-providers.test.ts
  • web/src/data/configuration.ts
  • src/utils/providerStartupOverrides.ts
  • src/services/api/credentialPool.test.ts
  • src/integrations/discoveryService.ts
  • src/components/ProviderManager.test.tsx
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/components/ProviderManager.tsx
  • src/services/api/agentRouting.ts
  • src/utils/providerValidation.test.ts
  • src/components/StartupScreen.ts
  • src/utils/providerFlag.test.ts
  • src/utils/model/model.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/services/api/openaiShim.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/index.ts
  • src/services/api/agentRouting.test.ts
  • src/utils/model/model.openai-shim-providers.test.ts
  • src/utils/providerStartupOverrides.ts
  • src/services/api/credentialPool.test.ts
  • src/integrations/discoveryService.ts
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/agentRouting.ts
  • src/utils/providerValidation.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/model/model.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
  • src/utils/providerFlag.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/services/api/openaiShim/requestExecutor.test.ts
  • src/integrations/discoveryService.test.ts
  • src/components/StartupScreen.test.ts
  • src/services/api/agentRouting.test.ts
  • src/utils/model/model.openai-shim-providers.test.ts
  • src/services/api/credentialPool.test.ts
  • src/components/ProviderManager.test.tsx
  • src/utils/providerStartupOverrides.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerValidation.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfiles.test.ts
  • src/services/api/client.test.ts
  • src/services/api/providerConfig.test.ts
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}

⚙️ CodeRabbit configuration file

{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.

Files:

  • README.md
web/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

When changing the web application, run the web typecheck and build checks.

Files:

  • web/src/data/configuration.ts
web/**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

When changing files under web/, run bun run web:typecheck and bun run web:build.

Files:

  • web/src/data/configuration.ts
web/**

⚙️ CodeRabbit configuration file

web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.

Files:

  • web/src/data/configuration.ts
🪛 GitHub Actions: PR Checks / 2_smoke-and-tests (22).txt
src/services/api/client.test.ts

[error] 1587-1587: Test assertion failed: expected the request URL to be "https://gw.apismart.ai/v1/chat/completions", but received "https://api.anthropic.com/v1/messages?beta=true".

🪛 GitHub Actions: PR Checks / 3_smoke-and-tests (24.11.x).txt
src/services/api/client.test.ts

[error] 1587-1587: Test assertion failed: expected request URL https://gw.apismart.ai/v1/chat/completions, but received https://api.anthropic.com/v1/messages?beta=true.

🪛 GitHub Actions: PR Checks / smoke-and-tests (22)
src/services/api/client.test.ts

[error] 1587-1587: Test assertion failed: expected request URL 'https://gw.apismart.ai/v1/chat/completions', but received 'https://api.anthropic.com/v1/messages?beta=true'.

🪛 GitHub Actions: PR Checks / smoke-and-tests (24.11.x)
src/services/api/client.test.ts

[error] 1587-1587: Test assertion failed: expected request URL 'https://gw.apismart.ai/v1/chat/completions', but received 'https://api.anthropic.com/v1/messages?beta=true'.

🪛 GitHub Check: smoke-and-tests (22)
src/services/api/client.test.ts

[failure] 1607-1607: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1"
Received: undefined

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1607:41)

[failure] 1607-1607: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1"
Received: undefined

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1607:41)

[failure] 1607-1607: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1"
Received: " UNDEFINED "

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1607:41)

[failure] 1607-1607: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1"
Received: "null"

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1607:41)

[failure] 1587-1587: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1/chat/completions"
Received: "https://api.anthropic.com/v1/messages?beta=true"

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1587:23)
🪛 GitHub Check: smoke-and-tests (24.11.x)
src/services/api/client.test.ts

[failure] 1607-1607: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1"
Received: undefined

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1607:41)

[failure] 1607-1607: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1"
Received: undefined

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1607:41)

[failure] 1607-1607: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1"
Received: " UNDEFINED "

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1607:41)

[failure] 1607-1607: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1"
Received: "null"

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1607:41)

[failure] 1587-1587: error: expect(received).toBe(expected)
Expected: "https://gw.apismart.ai/v1/chat/completions"
Received: "https://api.anthropic.com/v1/messages?beta=true"

  at <anonymous> (/home/runner/work/openclaude/openclaude/src/services/api/client.test.ts:1587:23)
🔇 Additional comments (45)
src/integrations/discoveryService.test.ts (1)

113-138: LGTM!

src/integrations/discoveryService.ts (1)

184-185: LGTM!

README.md (1)

271-271: LGTM!

web/src/data/configuration.ts (1)

81-82: LGTM!

src/services/api/openaiShim.ts (1)

525-530: LGTM!

src/services/api/openaiShim/requestExecutor.ts (1)

50-51: LGTM!

Also applies to: 186-187, 308-308, 379-379

src/services/api/agentRouting.test.ts (1)

13-14: LGTM!

Also applies to: 737-763

src/services/api/agentRouting.ts (1)

5-9: LGTM!

Also applies to: 52-52, 66-67, 374-383

src/services/api/providerConfig.test.ts (1)

317-504: LGTM!

src/services/api/providerConfig.ts (1)

29-30: LGTM!

Also applies to: 239-265, 938-938, 980-1034

src/integrations/routeMetadata.ts (4)

202-242: LGTM!

Also applies to: 244-249, 256-281


690-707: LGTM!


1181-1196: LGTM!


1198-1237: LGTM!

src/integrations/routeMetadata.test.ts (3)

21-71: LGTM!


82-99: LGTM!

Also applies to: 405-420


555-639: LGTM!

src/integrations/index.ts (1)

145-145: LGTM!

src/services/api/client.ts (3)

381-401: LGTM!


496-506: LGTM!


532-574: LGTM!

Also applies to: 679-679

src/services/api/client.test.ts (3)

9-9: LGTM!

Also applies to: 72-73, 127-128, 170-171, 221-222


321-341: LGTM!


1611-1658: LGTM!

src/utils/model/model.ts (2)

38-62: LGTM!


75-76: LGTM!

Also applies to: 216-217, 268-269, 318-319, 406-407

src/utils/providerProfile.ts (4)

642-686: LGTM!


1394-1402: LGTM!


2015-2067: LGTM!


2119-2139: LGTM!

src/utils/providerProfiles.test.ts (3)

833-849: LGTM!


878-917: LGTM!


3244-3282: LGTM!

Also applies to: 3284-3327, 3329-3361

src/utils/providerProfiles.ts (4)

157-159: LGTM!


299-344: LGTM!


1577-1593: LGTM!


1743-1748: LGTM!

src/components/ProviderManager.tsx (3)

46-47: LGTM!

Also applies to: 340-346


874-897: LGTM!

Also applies to: 1650-1650


1759-1759: LGTM!

Also applies to: 2189-2191

src/components/StartupScreen.ts (2)

84-88: LGTM!


111-125: 🎯 Functional Correctness

No change needed for the ApiSmart banner label. Credential-only APISMART_API_KEY configuration resolves the ApiSmart endpoint and displays ApiSmart. StartupScreen.test.ts covers this case.

			> Likely an incorrect or invalid review comment.
src/utils/providerValidation.ts (3)

130-135: LGTM!

Also applies to: 379-385


244-274: LGTM!


283-283: LGTM!

Also applies to: 292-304, 557-557

Comment thread src/integrations/routeMetadata.test.ts Outdated
Comment thread src/integrations/routeMetadata.ts Outdated
Comment thread src/services/api/client.test.ts Outdated
Comment thread src/services/api/openaiShim/requestExecutor.ts Outdated
jatmn added 2 commits August 10, 2026 15:19
…root

Expand the shared credential usability helpers so dotenv sentinels like
null/undefined cannot win ApiSmart env-only precedence or get mirrored into
OPENAI_API_KEY, and restore focused ApiSmart docs after dropping the
shared routing centralization.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
src/utils/providerFlag.ts (1)

173-175: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Reject null base URL sentinels.

Line 175 treats OPENAI_BASE_URL=null as a configured endpoint. The ApiSmart branch can then retain that invalid value and clear OPENAI_API_KEY because the value is not an ApiSmart URL.

Normalize null and undefined case-insensitively. Add a regression test that sets OPENAI_BASE_URL to null, calls applyProviderFlag('apismart', []), and expects the ApiSmart default endpoint and dedicated credential.

Proposed fix
 function normalizeBaseUrlEnv(value: string | undefined): string | undefined {
   const trimmed = value?.trim()
-  return trimmed && trimmed !== 'undefined' ? trimmed : undefined
+  if (!trimmed) return undefined
+  const normalized = trimmed.toLowerCase()
+  return normalized === 'undefined' || normalized === 'null'
+    ? undefined
+    : trimmed
 }

Run bun test ./src/utils/providerFlag.test.ts.

As per coding guidelines, “Add or update tests when behavior changes.” As per path instructions, “Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/utils/providerFlag.ts` around lines 173 - 175, Update normalizeBaseUrlEnv
to treat trimmed “null” and “undefined” values case-insensitively as unset,
while preserving valid URLs. Add a regression test in the providerFlag tests
that sets OPENAI_BASE_URL to “null”, calls applyProviderFlag('apismart', []),
and verifies the ApiSmart default endpoint and dedicated credential are
retained.

Sources: Coding guidelines, Path instructions

src/utils/providerProfiles.ts (1)

364-364: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Use the shared placeholder rule for ApiSmart credentials.

sanitizeApiKey rejects template values, but these paths retain or accept them. This can mirror null, undefined, or SUA_CHAVE into OpenAI-compatible configuration or allow credential validation to succeed with no usable ApiSmart key.

  • src/utils/providerProfiles.ts#L364-L364: sanitize profile.apiKey with sanitizeApiKey before storing the profile.
  • src/utils/providerValidation.ts#L129-L143: reject ApiSmart placeholder values when checking credential environment variables.

Add regression tests for case-insensitive and whitespace-padded placeholders in both profile and environment flows.

As per coding guidelines, “Add or update tests when behavior changes.” As per path instructions, “Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/utils/providerProfiles.ts` at line 364, Apply the shared sanitizeApiKey
placeholder handling to profile.apiKey in providerProfiles.ts, and update the
ApiSmart environment credential validation in providerValidation.ts to reject
case-insensitive, whitespace-padded placeholders; add regression tests covering
both profile and environment flows.

Sources: Coding guidelines, Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@src/utils/providerFlag.ts`:
- Around line 173-175: Update normalizeBaseUrlEnv to treat trimmed “null” and
“undefined” values case-insensitively as unset, while preserving valid URLs. Add
a regression test in the providerFlag tests that sets OPENAI_BASE_URL to “null”,
calls applyProviderFlag('apismart', []), and verifies the ApiSmart default
endpoint and dedicated credential are retained.

In `@src/utils/providerProfiles.ts`:
- Line 364: Apply the shared sanitizeApiKey placeholder handling to
profile.apiKey in providerProfiles.ts, and update the ApiSmart environment
credential validation in providerValidation.ts to reject case-insensitive,
whitespace-padded placeholders; add regression tests covering both profile and
environment flows.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 106cc2d2-3278-47d4-ae1a-c979fd81dc2a

📥 Commits

Reviewing files that changed from the base of the PR and between f8cd975 and e32ed66.

📒 Files selected for processing (20)
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/client.test.ts
  • src/services/api/client.ts
  • src/services/api/credentialPool.test.ts
  • src/services/api/credentialPool.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerSecrets.test.ts
  • src/utils/providerSecrets.ts
  • src/utils/providerValidation.test.ts
  • src/utils/providerValidation.ts
  • web/src/data/providers.ts
💤 Files with no reviewable changes (3)
  • src/utils/providerValidation.test.ts
  • src/utils/providerProfile.test.ts
  • src/services/api/providerConfig.test.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (13)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/utils/providerSecrets.test.ts
  • web/src/data/providers.ts
  • src/services/api/client.test.ts
  • src/utils/providerSecrets.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerValidation.ts
  • src/services/api/credentialPool.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/utils/providerFlag.ts
  • src/services/api/providerConfig.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/utils/providerSecrets.test.ts
  • web/src/data/providers.ts
  • src/services/api/client.test.ts
  • src/utils/providerSecrets.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerValidation.ts
  • src/services/api/credentialPool.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/utils/providerFlag.ts
  • src/services/api/providerConfig.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/utils/providerSecrets.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerSecrets.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerValidation.ts
  • src/services/api/credentialPool.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/utils/providerFlag.ts
  • src/services/api/providerConfig.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/utils/providerSecrets.test.ts
  • src/services/api/client.test.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/utils/providerSecrets.test.ts
  • web/src/data/providers.ts
  • src/services/api/client.test.ts
  • src/utils/providerSecrets.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerValidation.ts
  • src/services/api/credentialPool.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/utils/providerFlag.ts
  • src/services/api/providerConfig.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/utils/providerSecrets.test.ts
  • src/services/api/client.test.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/utils/providerSecrets.test.ts
  • web/src/data/providers.ts
  • src/services/api/client.test.ts
  • src/utils/providerSecrets.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerValidation.ts
  • src/services/api/credentialPool.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/utils/providerFlag.ts
  • src/services/api/providerConfig.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/utils/providerSecrets.test.ts
  • web/src/data/providers.ts
  • src/services/api/client.test.ts
  • src/utils/providerSecrets.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerValidation.ts
  • src/services/api/credentialPool.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/utils/providerFlag.ts
  • src/services/api/providerConfig.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/utils/providerSecrets.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerSecrets.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerValidation.ts
  • src/services/api/credentialPool.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfile.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/utils/providerFlag.ts
  • src/services/api/providerConfig.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/utils/providerSecrets.test.ts
  • src/services/api/client.test.ts
  • src/services/api/credentialPool.test.ts
  • src/utils/providerFlag.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerProfiles.test.ts
web/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

When changing the web application, run the web typecheck and build checks.

Files:

  • web/src/data/providers.ts
web/**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

When changing files under web/, run bun run web:typecheck and bun run web:build.

Files:

  • web/src/data/providers.ts
web/**

⚙️ CodeRabbit configuration file

web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.

Files:

  • web/src/data/providers.ts
src/services/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Files:

  • src/services/api/client.test.ts
  • src/services/api/credentialPool.test.ts
  • src/services/api/credentialPool.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/services/api/providerConfig.ts
🔇 Additional comments (4)
web/src/data/providers.ts (1)

196-197: LGTM!

src/services/api/openaiShim/requestExecutor.ts (1)

243-247:
Keep the existing restricted-route header-isolation finding.

These lines reintroduce unrestricted default, caller, and custom authentication header forwarding. This matches the existing ApiSmart restricted-route isolation comment.

Also applies to: 332-342

src/services/api/client.test.ts (1)

71-72: Keep CLAUDE_CODE_PROVIDER_ROUTE_ID isolated.

The ApiSmart test cleanup still does not snapshot, clear, and restore CLAUDE_CODE_PROVIDER_ROUTE_ID. A pre-existing non-apismart value can redirect these tests away from ApiSmart and reproduce the reported Anthropic-endpoint failures.

Also applies to: 126-127, 169-170, 220-221

Source: Pipeline failures

src/utils/providerProfiles.ts (1)

155-157: Persist default-route ApiSmart profiles.

isApismartProfile accepts an empty base URL, but sanitizeProfile still returns null for !baseUrl at Line 346. Persisted ApiSmart profiles without baseUrl are discarded before buildApismartProfileEnv can apply the route default.

Treat dotenv `null`/`undefined` OPENAI_BASE_URL sentinels as unset so
--provider apismart can apply defaults, and align profile/validation
credential checks with the shared placeholder contract.
@jatmn

jatmn commented Aug 10, 2026

Copy link
Copy Markdown
Collaborator Author

Review comment disposition (head 37df782f)

Fixed on this head

  • normalizeBaseUrlEnv now rejects dotenv null/undefined sentinels so --provider apismart can apply the ApiSmart default URL and mirror a usable key.
  • sanitizeProfile uses sanitizeApiKey so placeholders are not persisted on profiles.
  • ApiSmart (and AIMLAPI) validation now uses the shared usable-credential predicate, so placeholder APISMART_API_KEY fails startup validation.

Dismissed as no longer valid

  • Inconsistent ApiSmart credential predicates (hasUsableOpenAICredential vs stricter helper): fixed earlier at the shared root; thread resolved.
  • Isolate CLAUDE_CODE_PROVIDER_ROUTE_ID in ApiSmart client tests: those tests/route-id gate were removed with the focus revert; thread resolved.
  • Sentinel base URL suppressing env-only ApiSmart via hasConflictingOpenAIBaseUrlForRoute: already handled by hasNonEmptyEnvValue rejecting null/undefined on this branch.
  • Empty ApiSmart baseUrl discarded by sanitizeProfile: shared profile contract still requires a base URL on save; apply-time default remains for in-memory/empty cases. Not changing shared sanitize rules for this gateway PR.
  • Trivial style notes (nested ternary / profileApiKey consistency): low value / not actionable defects on current focused shape.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 10, 2026
Backfill APISMART_API_KEY on relaunch and keyless canonical profiles, and gate credential forwarding on an exact /v1 inference URL so dedicatedCredentialsOnly auth and ambient keys stay aligned with AIMLAPI.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/utils/providerProfiles.ts`:
- Around line 1095-1103: Stop promoting generic OPENAI_API_KEY values into
ApiSmart credentials: in src/utils/providerProfiles.ts:1095-1103, source ambient
credentials only from sanitized APISMART_API_KEY; in
src/utils/providerProfile.ts:2163-2176, retain legacy migration only for
persisted ApiSmart-shaped profiles, preferring explicit dedicated credentials
and never using shell OPENAI_API_KEY as fallback. Add the requested regression
cases in src/utils/providerProfiles.test.ts:870-903 and
src/utils/providerProfile.test.ts:281-307, then run both specified test
commands.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: e9568b87-ce2f-4548-88c6-ae6b842b5c00

📥 Commits

Reviewing files that changed from the base of the PR and between fdcf668 and bf11b2a.

📒 Files selected for processing (7)
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerProfiles.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: typecheck
  • GitHub Check: smoke-and-tests (24.11.x)
  • GitHub Check: smoke-and-tests (22)
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/utils/providerProfile.test.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.test.ts

Comment thread src/utils/providerProfiles.ts
coderabbitai[bot]
coderabbitai Bot previously approved these changes Aug 11, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (4)
src/integrations/gateways/apismart.test.ts (1)

34-48: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add coverage for the remaining mapper branches.

The mapper also handles vision or other non-chat records and optional ownership labels. The current cases cover image, video, missing-ID, and null records. Add explicit fixtures for a vision record, a chat-capable multimodal record, and an owned_by value.

Run:

bun test ./src/integrations/gateways/apismart.test.ts

As per coding guidelines, behavior changes require focused tests. As per path instructions, changed provider behavior needs meaningful regression coverage.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/integrations/gateways/apismart.test.ts` around lines 34 - 48, Extend the
mapModel test to cover the remaining mapper branches: add fixtures asserting
vision records are excluded, chat-capable multimodal records are retained, and
owned_by contributes the expected ownership label. Keep the existing image,
video, missing-ID, and null cases, then run the focused apismart test command.

Sources: Coding guidelines, Path instructions

src/integrations/routeMetadata.test.ts (1)

324-332: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Add negative ApiSmart resolver cases.

These assertions cover only canonical HTTPS URLs. Add cases for an HTTP URL and a custom port so resolveRouteIdFromBaseUrl cannot regress to host-only matching.

As per coding guidelines, “Add or update tests when a code change affects behavior.” As per path instructions, “Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/integrations/routeMetadata.test.ts` around lines 324 - 332, Extend the
test named “ApiSmart route metadata uses official OpenAI-compatible defaults”
with negative assertions for an HTTP ApiSmart URL and an ApiSmart URL using a
custom port, verifying resolveRouteIdFromBaseUrl returns no ApiSmart match for
both. Keep the existing canonical HTTPS and chat-completions assertions
unchanged.

Sources: Coding guidelines, Path instructions

src/utils/providerProfiles.ts (1)

984-1043: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Preserve the ApiSmart profile contract across apply, relaunch, and routing.

The current profile paths emit generic OpenAI state without proving that ApiSmart credentials and route identity survive environment reconstruction. The related active-route and profile tests are disabled.

  • src/utils/providerProfiles.ts#L984-L1043: emit the required ApiSmart credential and route metadata when applying a profile.
  • src/utils/providerProfiles.ts#L1348-L1395: preserve the same metadata in keyed startup restoration.
  • src/utils/providerProfiles.ts#L1419-L1467: preserve it in fallback startup restoration.
  • src/integrations/routeMetadata.test.ts#L466-L608: restore active regression coverage for environment-only setup, profile refinement, and relaunch behavior.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/utils/providerProfiles.ts` around lines 984 - 1043, Preserve the ApiSmart
credential and route metadata across profile application and startup
restoration: update src/utils/providerProfiles.ts:984-1043, :1348-1395, and
:1419-1467 to emit the same ApiSmart-specific environment values and route
identity using the existing profile/routing contract, rather than only generic
OpenAI state. Restore the disabled regression coverage in
src/integrations/routeMetadata.test.ts:466-608 for environment-only setup,
profile refinement, and relaunch behavior, ensuring all paths retain identical
metadata.

Sources: Coding guidelines, Path instructions

src/integrations/routeMetadata.ts (1)

1005-1008: 🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

Apply one strict ApiSmart URL boundary to route and validation matching.

Host-only matching can accept ApiSmart URLs that are not HTTPS or that use a custom port. Enforce the ApiSmart boundary before route selection and validation-target selection, then pin the behavior with negative tests.

  • src/integrations/routeMetadata.ts#L1005-L1008: reject HTTP and custom-port ApiSmart URLs before the default or host match returns apismart.
  • src/utils/providerValidation.ts#L274-L285: apply the same ApiSmart boundary before selecting the validation target.
  • src/integrations/routeMetadata.test.ts#L324-L332: add HTTP and custom-port resolver regressions.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/integrations/routeMetadata.ts` around lines 1005 - 1008, Apply one strict
HTTPS, standard-port ApiSmart URL boundary before route and validation matching:
update the route-selection logic around the Cloudflare/Longcat checks in
src/integrations/routeMetadata.ts (lines 1005-1008) to reject HTTP and
custom-port ApiSmart URLs before returning apismart; apply the same boundary
before validation-target selection in src/utils/providerValidation.ts (lines
274-285); add negative resolver regressions for HTTP and custom-port URLs in
src/integrations/routeMetadata.test.ts (lines 324-332).

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/utils/providerFlag.test.ts`:
- Around line 501-512: Add APISMART_API_KEY to the test environment keys saved
and reset by the providerFlag test setup, including the RESET_KEYS list, so the
apismart test’s process.env mutation is isolated and cannot affect later
route-selection tests.

In `@src/utils/providerSecrets.ts`:
- Around line 93-95: Centralize the placeholder values and predicate currently
used by providerSecrets and credentialPool in a dependency-neutral utility, then
replace both local implementations with that shared symbol. Preserve trimming,
case-insensitive matching, and rejection of whitespace-only values, and update
focused tests covering those behaviors while keeping provider credential
integration behavior unchanged.

---

Outside diff comments:
In `@src/integrations/gateways/apismart.test.ts`:
- Around line 34-48: Extend the mapModel test to cover the remaining mapper
branches: add fixtures asserting vision records are excluded, chat-capable
multimodal records are retained, and owned_by contributes the expected ownership
label. Keep the existing image, video, missing-ID, and null cases, then run the
focused apismart test command.

In `@src/integrations/routeMetadata.test.ts`:
- Around line 324-332: Extend the test named “ApiSmart route metadata uses
official OpenAI-compatible defaults” with negative assertions for an HTTP
ApiSmart URL and an ApiSmart URL using a custom port, verifying
resolveRouteIdFromBaseUrl returns no ApiSmart match for both. Keep the existing
canonical HTTPS and chat-completions assertions unchanged.

In `@src/integrations/routeMetadata.ts`:
- Around line 1005-1008: Apply one strict HTTPS, standard-port ApiSmart URL
boundary before route and validation matching: update the route-selection logic
around the Cloudflare/Longcat checks in src/integrations/routeMetadata.ts (lines
1005-1008) to reject HTTP and custom-port ApiSmart URLs before returning
apismart; apply the same boundary before validation-target selection in
src/utils/providerValidation.ts (lines 274-285); add negative resolver
regressions for HTTP and custom-port URLs in
src/integrations/routeMetadata.test.ts (lines 324-332).

In `@src/utils/providerProfiles.ts`:
- Around line 984-1043: Preserve the ApiSmart credential and route metadata
across profile application and startup restoration: update
src/utils/providerProfiles.ts:984-1043, :1348-1395, and :1419-1467 to emit the
same ApiSmart-specific environment values and route identity using the existing
profile/routing contract, rather than only generic OpenAI state. Restore the
disabled regression coverage in src/integrations/routeMetadata.test.ts:466-608
for environment-only setup, profile refinement, and relaunch behavior, ensuring
all paths retain identical metadata.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: b88f2339-3fe1-47e3-b142-067a49d24c9e

📥 Commits

Reviewing files that changed from the base of the PR and between bf11b2a and 2a330b4.

⛔ Files ignored due to path filters (1)
  • src/integrations/generated/integrationManifest.generated.ts is excluded by !**/*.generated.*, !**/generated/**, !src/integrations/generated/**
📒 Files selected for processing (18)
  • README.md
  • scripts/system-check.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/client.test.ts
  • src/services/api/credentialPool.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/envFile.test.ts
  • src/utils/envFile.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerSecrets.ts
  • src/utils/providerValidation.test.ts
  • src/utils/providerValidation.ts
  • web/src/data/configuration.ts
  • web/src/data/providers.ts
💤 Files with no reviewable changes (5)
  • scripts/system-check.test.ts
  • src/utils/envFile.ts
  • src/services/api/client.test.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/utils/providerValidation.test.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: typecheck
🧰 Additional context used
📓 Path-based instructions (14)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • src/integrations/gateways/apismart.ts
  • src/utils/envFile.test.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.ts
  • src/services/api/credentialPool.ts
  • src/integrations/routeMetadata.ts
  • web/src/data/configuration.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerSecrets.ts
  • web/src/data/providers.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • src/integrations/gateways/apismart.ts
  • src/utils/envFile.test.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.ts
  • src/services/api/credentialPool.ts
  • src/integrations/routeMetadata.ts
  • web/src/data/configuration.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerSecrets.ts
  • web/src/data/providers.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/integrations/gateways/apismart.ts
  • src/utils/envFile.test.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.ts
  • src/services/api/credentialPool.ts
  • src/integrations/routeMetadata.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerSecrets.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • src/integrations/gateways/apismart.ts
  • src/utils/envFile.test.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.ts
  • src/services/api/credentialPool.ts
  • src/integrations/routeMetadata.ts
  • web/src/data/configuration.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerSecrets.ts
  • web/src/data/providers.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • src/integrations/gateways/apismart.ts
  • src/utils/envFile.test.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.ts
  • README.md
  • src/services/api/credentialPool.ts
  • src/integrations/routeMetadata.ts
  • web/src/data/configuration.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerSecrets.ts
  • web/src/data/providers.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/integrations/gateways/apismart.ts
  • src/utils/envFile.test.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.ts
  • README.md
  • src/services/api/credentialPool.ts
  • src/integrations/routeMetadata.ts
  • web/src/data/configuration.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerSecrets.ts
  • web/src/data/providers.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/integrations/gateways/apismart.ts
  • src/utils/providerValidation.ts
  • src/utils/providerProfiles.ts
  • src/services/api/credentialPool.ts
  • src/integrations/routeMetadata.ts
  • src/integrations/gateways/apismart.test.ts
  • src/utils/providerSecrets.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • src/utils/envFile.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • src/utils/envFile.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • src/utils/envFile.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/utils/providerFlag.test.ts
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}

⚙️ CodeRabbit configuration file

{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.

Files:

  • README.md
src/services/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Files:

  • src/services/api/credentialPool.ts
web/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

When changing the web application, run the web typecheck and build checks.

Files:

  • web/src/data/configuration.ts
  • web/src/data/providers.ts
web/**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

When changing files under web/, run bun run web:typecheck and bun run web:build.

Files:

  • web/src/data/configuration.ts
  • web/src/data/providers.ts
web/**

⚙️ CodeRabbit configuration file

web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.

Files:

  • web/src/data/configuration.ts
  • web/src/data/providers.ts
🔇 Additional comments (12)
src/integrations/gateways/apismart.ts (2)

199-209: LGTM!


170-198: 🎯 Functional Correctness

Run the ApiSmart tests and type checks in an environment with Bun. The source keeps curated models out of readiness, uses the route-resolved credential, and restricts matching to gw.apismart.ai; the requested commands remain unexecuted because bun is unavailable.

src/integrations/gateways/apismart.test.ts (1)

8-32: LGTM!

README.md (1)

271-271: LGTM!

src/services/api/credentialPool.ts (1)

139-145: LGTM!

web/src/data/providers.ts (1)

195-197: 🗄️ Data Integrity & Integration

Keep the ApiSmart environment-variable list unchanged. envVars only renders provider documentation. The runtime already adds OPENAI_API_KEYS and OPENAI_API_KEY for ApiSmart, and the configuration page documents both variables.

			> Likely an incorrect or invalid review comment.
src/utils/providerValidation.ts (1)

137-139: LGTM!

src/integrations/routeMetadata.ts (1)

227-229: LGTM!

src/integrations/routeMetadata.test.ts (1)

224-239: LGTM!

src/utils/providerProfiles.ts (1)

67-67: LGTM!

Also applies to: 357-357

src/utils/envFile.test.ts (1)

21-21: LGTM!

Also applies to: 278-288

web/src/data/configuration.ts (1)

81-81: LGTM!

Comment thread src/utils/providerFlag.test.ts Outdated
Comment thread src/utils/providerSecrets.ts Outdated
@jatmn
jatmn marked this pull request as ready for review August 11, 2026 02:45

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/integrations/discoveryService.test.ts`:
- Around line 116-135: Strengthen the test around discoverModelsForRoute by
tracking whether the mocked fetch is invoked and asserting it ran before
checking credentials. Inspect all headers from the captured request and assert
the configured secret does not appear anywhere, regardless of header name or
authentication scheme, rather than only checking the authorization value.

In `@src/integrations/routeMetadata.ts`:
- Around line 452-457: Update the canonical URL predicate in the route-matching
function around candidate.protocol to also require empty candidate.search and
candidate.hash, while preserving the existing HTTPS, port, hostname, and
pathname checks. Add regression cases in the routeMetadata tests covering
canonical URLs with query strings or fragments and verify they are rejected.

In `@src/services/api/providerConfig.test.ts`:
- Around line 355-366: Add focused coverage in providerConfig.test.ts for
resolveProviderRequest when APISMART_MODEL is the literal "undefined" or "null"
in varying capitalization, verifying each is treated as unset and OPENAI_MODEL
is selected while the ApiSmart base URL remains unchanged; run bun test
./src/services/api/providerConfig.test.ts.

In `@src/utils/providerProfile.ts`:
- Around line 2169-2187: The ApiSmart legacy OPENAI credential currently
overrides a usable dedicated credential. In
src/utils/providerProfile.ts:2169-2187, hoist persistedOpenAICredential out of
the loop and move backfillLegacyApismartProfileKey to the end of the
dedicatedValue fallback chain, after processEnv[dedicatedKey] and
persistedEnv[dedicatedKey]. In src/utils/providerProfile.test.ts:261-279, add
launch cases covering differing persisted OPENAI_API_KEY/APISMART_API_KEY values
and a live shell APISMART_API_KEY rotating the persisted pair, asserting the
dedicated value is retained; run the targeted providerProfile test.
- Around line 2283-2288: Guard persisted.env before accessing
CLAUDE_CODE_PROVIDER_ROUTE_ID or OPENAI_BASE_URL in the persistedApismartProxy
check within buildLaunchEnv. Treat a missing env object as not matching the
Apismart proxy condition, allowing startup to continue through the normal path
without throwing.

In `@src/utils/providerProfiles.ts`:
- Around line 1092-1101: Update the keyless canonical branch in
isApismartProfile handling to sanitize process.env.APISMART_API_KEY with the
existing sanitizeApiKey helper before assigning it to OPENAI_API_KEY and
APISMART_API_KEY, so placeholders such as SUA_CHAVE, null, or undefined are
treated as absent. Add a providerProfiles test covering a keyless canonical
profile with a placeholder ambient key, then run the targeted providerProfiles
test suite.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 7c3640aa-1c25-4c99-811d-d68616803349

📥 Commits

Reviewing files that changed from the base of the PR and between 2a330b4 and 5bd52e8.

⛔ Files ignored due to path filters (1)
  • src/integrations/generated/integrationManifest.generated.ts is excluded by !**/*.generated.*, !**/generated/**, !src/integrations/generated/**
📒 Files selected for processing (27)
  • README.md
  • scripts/system-check.test.ts
  • src/integrations/discoveryService.test.ts
  • src/integrations/discoveryService.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/gateways/apismart.ts
  • src/integrations/routeMetadata.test.ts
  • src/integrations/routeMetadata.ts
  • src/services/api/client.test.ts
  • src/services/api/client.ts
  • src/services/api/credentialPool.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/providerConfig.test.ts
  • src/services/api/providerConfig.ts
  • src/utils/envFile.test.ts
  • src/utils/envFile.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfile.ts
  • src/utils/providerProfiles.test.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerSecrets.ts
  • src/utils/providerValidation.test.ts
  • src/utils/providerValidation.ts
  • web/src/data/configuration.ts
  • web/src/data/providers.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (15)
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Use TypeScript strict mode and ESM imports throughout the source code.

Run bun run typecheck and bun run typecheck:type-tests for TypeScript changes when applicable.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerSecrets.ts
  • src/utils/envFile.test.ts
  • src/utils/envFile.ts
  • src/integrations/routeMetadata.test.ts
  • web/src/data/providers.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/credentialPool.ts
  • src/integrations/discoveryService.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/gateways/apismart.ts
  • src/utils/providerValidation.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.test.ts
  • web/src/data/configuration.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
**/*.{tsx,ts}

📄 CodeRabbit inference engine (AGENTS.md)

Use React and Ink patterns for terminal UI components.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerSecrets.ts
  • src/utils/envFile.test.ts
  • src/utils/envFile.ts
  • src/integrations/routeMetadata.test.ts
  • web/src/data/providers.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/credentialPool.ts
  • src/integrations/discoveryService.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/gateways/apismart.ts
  • src/utils/providerValidation.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.test.ts
  • web/src/data/configuration.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Add or update tests when behavior changes, and run the narrowest useful focused test checks.

Files:

  • scripts/system-check.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerValidation.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfiles.test.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (AGENTS.md)

Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.

**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerSecrets.ts
  • src/utils/envFile.test.ts
  • src/utils/envFile.ts
  • src/integrations/routeMetadata.test.ts
  • web/src/data/providers.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/credentialPool.ts
  • src/integrations/discoveryService.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/gateways/apismart.ts
  • src/utils/providerValidation.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.test.ts
  • web/src/data/configuration.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
**/*.{test,spec}.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such as bun test ./path/to/test-file.test.ts when validating a narrowly scoped change.

Files:

  • scripts/system-check.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerValidation.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfiles.test.ts
**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Update documentation when setup, commands, or user-facing behavior changes.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerSecrets.ts
  • src/utils/envFile.test.ts
  • src/utils/envFile.ts
  • src/integrations/routeMetadata.test.ts
  • web/src/data/providers.ts
  • src/services/api/providerConfig.test.ts
  • README.md
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/credentialPool.ts
  • src/integrations/discoveryService.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/gateways/apismart.ts
  • src/utils/providerValidation.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.test.ts
  • web/src/data/configuration.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • scripts/system-check.test.ts
  • src/utils/providerSecrets.ts
  • src/utils/envFile.test.ts
  • src/utils/envFile.ts
  • src/integrations/routeMetadata.test.ts
  • web/src/data/providers.ts
  • src/services/api/providerConfig.test.ts
  • README.md
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/credentialPool.ts
  • src/integrations/discoveryService.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/gateways/apismart.ts
  • src/utils/providerValidation.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.test.ts
  • web/src/data/configuration.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}

⚙️ CodeRabbit configuration file

{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.

Files:

  • scripts/system-check.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}

⚙️ CodeRabbit configuration file

{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.

Files:

  • scripts/system-check.test.ts
  • src/utils/envFile.test.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/utils/providerValidation.test.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerProfiles.test.ts
src/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

src/**/*.ts: Prefer existing service, provider, settings, permission, and UI patterns over introducing new abstractions.
Use chalk for terminal color and execa for child-process execution when those capabilities are needed.

Files:

  • src/utils/providerSecrets.ts
  • src/utils/envFile.test.ts
  • src/utils/envFile.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/credentialPool.ts
  • src/integrations/discoveryService.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/gateways/apismart.ts
  • src/utils/providerValidation.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.test.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/utils/providerSecrets.ts
  • src/integrations/routeMetadata.test.ts
  • src/services/api/providerConfig.test.ts
  • src/integrations/gateways/apismart.test.ts
  • src/integrations/discoveryService.test.ts
  • src/utils/providerFlag.test.ts
  • src/services/api/credentialPool.ts
  • src/integrations/discoveryService.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/integrations/gateways/apismart.ts
  • src/utils/providerValidation.ts
  • src/services/api/client.ts
  • src/utils/providerValidation.test.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.test.ts
  • src/utils/providerProfile.test.ts
  • src/utils/providerFlag.ts
  • src/utils/providerProfiles.ts
  • src/utils/providerProfiles.test.ts
  • src/integrations/routeMetadata.ts
  • src/utils/providerProfile.ts
web/**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

When changing the web application, run the web typecheck and build checks.

Files:

  • web/src/data/providers.ts
  • web/src/data/configuration.ts
web/**/*

📄 CodeRabbit inference engine (CONTRIBUTING.md)

When changing files under web/, run bun run web:typecheck and bun run web:build.

Files:

  • web/src/data/providers.ts
  • web/src/data/configuration.ts
web/**

⚙️ CodeRabbit configuration file

web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.

Files:

  • web/src/data/providers.ts
  • web/src/data/configuration.ts
src/services/**/*.ts

📄 CodeRabbit inference engine (AGENTS.md)

Use existing service and provider integration patterns when implementing API, MCP, OAuth, wiki, voice, or related integrations.

Files:

  • src/services/api/providerConfig.test.ts
  • src/services/api/credentialPool.ts
  • src/services/api/openaiShim/requestExecutor.ts
  • src/services/api/client.ts
  • src/services/api/providerConfig.ts
  • src/services/api/client.test.ts
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}

⚙️ CodeRabbit configuration file

{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.

Files:

  • README.md
🔇 Additional comments (25)
src/integrations/gateways/apismart.ts (3)

1-37: LGTM!


39-168: LGTM!


170-227: LGTM!

src/integrations/gateways/apismart.test.ts (3)

1-18: LGTM!


20-27: LGTM!


29-44: LGTM!

web/src/data/providers.ts (1)

195-197: LGTM!

README.md (1)

271-271: LGTM!

scripts/system-check.test.ts (1)

85-86: LGTM!

src/utils/providerValidation.test.ts (4)

35-35: LGTM!


189-196: LGTM!


198-212: LGTM!


214-229: LGTM!

web/src/data/configuration.ts (1)

81-82: LGTM!

src/utils/providerSecrets.ts (1)

93-102: Placeholder list is still duplicated with credentialPool.

src/services/api/credentialPool.ts owns isCredentialPlaceholder and its own placeholder set. This file repeats the same three values. If one list changes, profile persistence and runtime credential validation will accept different values.

Move the set and predicate into a dependency-neutral utility and consume it from both modules. Non-blocking for this PR, but the divergence risk is real.

src/services/api/providerConfig.ts (2)

27-32: LGTM!

Also applies to: 244-251, 262-275, 277-285


949-949: LGTM!

Also applies to: 991-1017, 1027-1045

src/services/api/providerConfig.test.ts (1)

317-354: LGTM!

Also applies to: 368-432

src/integrations/discoveryService.test.ts (1)

21-21: LGTM!

Also applies to: 63-63, 98-98

src/utils/envFile.test.ts (1)

22-22: LGTM!

Also applies to: 279-291

src/utils/envFile.ts (1)

19-19: LGTM!

src/utils/providerProfile.test.ts (1)

19-19: LGTM!

Also applies to: 281-332, 334-372, 374-410, 412-441, 1125-1142

src/utils/providerProfile.ts (1)

28-28: LGTM!

Also applies to: 115-116, 202-202, 639-690, 1406-1415, 2065-2085, 2117-2117, 2133-2135, 2145-2168, 2203-2205

src/utils/providerProfiles.ts (1)

31-31: LGTM!

Also applies to: 54-57, 70-70, 156-162, 368-369, 813-816, 973-974, 1002-1016, 1025-1025, 1035-1040, 1086-1091, 1102-1102, 1384-1391, 1416-1418, 1465-1471, 1494-1496, 1686-1697, 1735-1737

src/utils/providerProfiles.test.ts (1)

73-74: LGTM!

Also applies to: 270-279, 815-832, 834-843, 845-854, 856-868, 870-939, 941-953, 955-978, 3304-3355

Comment thread src/integrations/discoveryService.test.ts
Comment thread src/integrations/routeMetadata.ts
Comment thread src/services/api/providerConfig.test.ts
Comment thread src/utils/providerProfile.ts Outdated
Comment thread src/utils/providerProfile.ts
Comment thread src/utils/providerProfiles.ts
@jatmn

jatmn commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator Author

@kevincodex1 LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

new: provider/gateway Request to add a new provider or gateway

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants