Skip to content

fix(auth): let a combo pin to the synthetic noauth connection resolve - #14905

Merged
diegosouzapw merged 5 commits into
diegosouzapw:release/v3.8.51from
TrippyEngineer:fix/noauth-combo-pin-allowlist
Sep 29, 2026
Merged

diegosouzapw merged 5 commits into
diegosouzapw:release/v3.8.51from
TrippyEngineer:fix/noauth-combo-pin-allowlist

Conversation

@TrippyEngineer

Copy link
Copy Markdown
Contributor

Summary

Related Issues

Validation

  • Change type: routing
  • Focused tests: tests/unit/api-key-policy-noauth-allowed-connections.test.ts (5/5), plus combo-pin-implicit-allowlist, combo-restricted-key-target-policy-12886 and 7993-noauth-proxy-routing — all pass
  • eslint + prettier on changed files (lint-staged pre-commit, with repo suppressions)
  • npm run typecheck:core — clean
  • Production-code changes include a new automated test in this PR
  • Live check: npm run dev, model: "auto" now dispatches to oc/big-pickle (attempted: 1) instead of skipping all targets before dispatch

Tests Added Or Updated

  • tests/unit/api-key-policy-noauth-allowed-connections.test.ts
    • allowlist that names the synthetic noauth id still gets credentials (fails on base, passes with fix)
    • allowlist mixing a real UUID and noauth still gets synthetic credentials (fails on base, passes with fix)
    • The existing restricted key gets NO synthetic credentials test still passes.

Coverage Notes

  • The new helper and both call sites are exercised by the tests above.

Reviewer Notes

  • Independent of fix(sse): rebuild deadline-wrapped request from public accessors #14904 (the withDeadlineSignal fix); to observe it live on release/v3.8.51, fix(sse): rebuild deadline-wrapped request from public accessors #14904 is needed first, because chat routes currently 500 before reaching routing.
  • Heads-up, not changed here: the OpenCode Free upstream currently answers 403 FreeTierError — "OpenCode's free tier can only be used from within OpenCode", so even with this fix the README's zero-config model: auto claim does not produce a reply today.
  • Local test note: on Windows, executor-devin-cli-agentic-acp fails with spawn EFTYPE and a few autoCombo/strict-zero-cost-* / subscription-ladder / opencode-429-park-resume tests fail on the unmodified base too; unrelated to this change.

The auto combo pins every keyless OpenCode Free target to the synthetic
connection id "noauth", and pin-fail-closed (implicitPinAllowlist) turns
that pin into the allowlist ["noauth"]. The diegosouzapw#9057 guards in
getProviderCredentials() and maybeSyntheticNoAuthFallback() refused the
synthetic credential for ANY non-empty allowlist, so on a fresh install
every oc/* target was skipped before dispatch with reason "availability"
and model "auto" returned 503 ALL_TARGETS_SKIPPED.

Allow the synthetic credential when the allowlist is empty or explicitly
names "noauth". A key restricted to real connection ids is still denied,
so the diegosouzapw#9057 protection is unchanged. Adds tests for ["noauth"] and a
mixed allowlist next to the existing restricted-key test.
@diegosouzapw
diegosouzapw merged commit a8fefa2 into diegosouzapw:release/v3.8.51 Sep 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants