Repository navigation
feat(auth): add native kimi-oauth provider using Kimi Code CLI OAuth tokens (#70928) - #71039
webtecnica wants to merge 2 commits into
Conversation
Duplicate of #71038: both PRs currently have the identical live head and identical diff. This branch also does not contain the complete Kimi OAuth implementation described in this PR. |
…de (NousResearch#70867) When the dashboard is launched with --isolated, the API must reject ?profile= requests targeting any profile other than the one the server is scoped to. Without this guard, a user on an isolated dashboard could read/write another profile's config, sessions, skills, and env vars simply by passing ?profile=<other>. Changes: - Add _check_isolated_profile_access() helper that compares the requested profile directory against the server's own HERMES_HOME - Wire the check into _profile_scope(), _config_profile_scope(), and _open_session_db_for_profile() — the three gateways through which all profile-scoped API requests pass - Add 'isolated' parameter to start_server() and store it on app.state - Forward the CLI --isolated flag from cmd_dashboard to start_server() Closes: NousResearch#70867
3698de4 to
b49c1e0
Compare
|
Thanks for the Kimi OAuth investigation and for using the existing model-provider shape. This automated hermes-sweeper review is closing this under the standing in-tree provider integration policy:
Please publish the integration as a standalone plugin repository using the existing model-provider discovery surface; it can then be promoted in Closed as not-planned per standing maintainer policy ( |
Implements #70928
Adds kimi-oauth provider following the same pattern as qwen-oauth and minimax-oauth. Authenticates through Kimi Code CLI's OAuth token file (~/.kimi-code/credentials/kimi-code.json).
Files: plugins/model-providers/kimi-oauth/, hermes_cli/auth.py, hermes_cli/providers.py, agent/credential_pool.py, + more