fix(auth): preserve callable credentials across provider switches - #108039
tudorpastorglencore wants to merge 1 commit into
Conversation
| session["model_override"] = { | ||
| "model": result.new_model, "provider": result.target_provider, | ||
| "base_url": result.base_url, "api_key": result.api_key, "api_mode": result.api_mode} | ||
| "base_url": result.base_url, "api_mode": result.api_mode} |
There was a problem hiding this comment.
Removing api_key here breaks rebuilds after switching to a credential-bearing model_aliases entry. I reproduced this on this head: the initial /model private-alias switch uses the configured alias key, but _resolve_agent_model_runtime(session["model_override"], None) then receives only provider: custom and the base URL and returns no-key-required. The recorded base keeps the in-memory key and rebuilds correctly. sanitize_model_override() already removes api_key before sessions.json persistence, so please retain it in the live override or persist non-secret alias identity and re-resolve it during rebuild.
…olve Azure Foundry Auxiliary tasks on `provider: auto` (title generation, context compression, smart approval) forward the main runtime's api_key into `_resolve_azure_foundry_runtime` as `explicit_api_key`. Under `auth_mode: entra_id` that api_key is the Entra token-provider callable; the resolver's first line stringified it, so the truthy function repr took the "explicit string" escape hatch, was relabelled `auth_mode: api_key` and sent to Azure as a static key -> HTTP 401 on every aux call while the main conversation worked. A forwarded value recognised by `is_token_provider()` now stays the runtime api_key with `auth_mode: entra_id` and the config's Entra metadata. The explicit STRING escape hatch (`--api-key` while config says entra_id) is unchanged, and api_key mode remains string-only: a callable there falls through to the env/.env key as before. Semantic hunk ported from #108039 (reformat/bloat stripped: unrelated callable handling in models.py / runtime_provider_custom.py / tui_gateway.model_switch left out); #72463 by kyssta-exe filed the same fix first against the pre-split runtime_provider.py. Fixes #72421 Co-authored-by: kyssta-exe <kyssta-exe@users.noreply.github.com>
|
Thanks @tudorpastorglencore — the work in this PR has landed on
Your contribution is credited there (cherry-picked authorship / co-author trailer or credit in the PR body; see the linked PR for what was kept and what was trimmed). Closing this one as landed / superseded so the backlog reflects reality. If something in your original diff is still missing on current |
What does this PR do?
Preserves callable provider credentials when Hermes switches between providers and re-resolves runtime credentials on the next turn.
This fixes the Claude -> Azure/OpenAI failure where an Entra token provider was converted to a string API key, causing Azure HTTP 401 responses. It also prevents callable credentials from being persisted in TUI session overrides.
Related Issue
Related to #72421 and #88667. Companion to #107344.
Type of Change
Changes Made
api_keyvalues in TUI model overrides.How to Test
Automated validation:
The full repository suite was started but exceeded the local 10-minute limit; its first failure was an unrelated Pydantic warning-precondition test.