fix(auth): let a combo pin to the synthetic noauth connection resolve - #14905
Merged
diegosouzapw merged 5 commits intoSep 29, 2026
Merged
diegosouzapw merged 5 commits into
diegosouzapw merged 5 commits into
Conversation
The auto combo pins every keyless OpenCode Free target to the synthetic connection id "noauth", and pin-fail-closed (implicitPinAllowlist) turns that pin into the allowlist ["noauth"]. The diegosouzapw#9057 guards in getProviderCredentials() and maybeSyntheticNoAuthFallback() refused the synthetic credential for ANY non-empty allowlist, so on a fresh install every oc/* target was skipped before dispatch with reason "availability" and model "auto" returned 503 ALL_TARGETS_SKIPPED. Allow the synthetic credential when the allowlist is empty or explicitly names "noauth". A key restricted to real connection ids is still denied, so the diegosouzapw#9057 protection is unchanged. Adds tests for ["noauth"] and a mixed allowlist next to the existing restricted-key test.
… module Keeps src/sse/services/auth.ts within its frozen file-size ceiling; no behavior change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
model: "auto"returned503 ALL_TARGETS_SKIPPED, with every OpenCode Free target (oc/*) skipped before dispatch with reasonavailability."noauth"(open-sse/services/autoCombo/virtualFactory.ts), and pin-fail-closed (implicitPinAllowlistinsrc/lib/combos/steps.ts) turns that pin into the allowlist["noauth"]. The fix(api): auto/* routing aliases bypass API-key allowedConnections/disableNonPublicModels #9057 guards ingetProviderCredentials()andmaybeSyntheticNoAuthFallback()(src/sse/services/auth.ts) refused the synthetic credential for any non-empty allowlist, so it could never resolve.allowlistPermitsSyntheticNoAuth()allows the synthetic credential when the allowlist is empty or explicitly names"noauth". A key restricted to real connection ids is still denied, so the fix(api): auto/* routing aliases bypass API-key allowedConnections/disableNonPublicModels #9057 protection is unchanged. The [bug] No-auth providers (opencode / opencode-zen) infinite account-fallback loop on persistent upstream error → unbounded DB growth / disk exhaustion #3061 exclusion, fix(auth): Model-only lockout for no-auth providers is recorded but never enforced — locked member is retried on every request #13483 model-lockout and fix(): Opencode free models no longer working #14313 free-tier-pause checks still run first.Related Issues
Validation
tests/unit/api-key-policy-noauth-allowed-connections.test.ts(5/5), pluscombo-pin-implicit-allowlist,combo-restricted-key-target-policy-12886and7993-noauth-proxy-routing— all passeslint+prettieron changed files (lint-staged pre-commit, with repo suppressions)npm run typecheck:core— cleannpm run dev,model: "auto"now dispatches tooc/big-pickle(attempted: 1) instead of skipping all targets before dispatchTests Added Or Updated
tests/unit/api-key-policy-noauth-allowed-connections.test.tsallowlist that names the synthetic noauth id still gets credentials(fails on base, passes with fix)allowlist mixing a real UUID and noauth still gets synthetic credentials(fails on base, passes with fix)restricted key gets NO synthetic credentialstest still passes.Coverage Notes
Reviewer Notes
withDeadlineSignalfix); to observe it live onrelease/v3.8.51, fix(sse): rebuild deadline-wrapped request from public accessors #14904 is needed first, because chat routes currently 500 before reaching routing.403 FreeTierError — "OpenCode's free tier can only be used from within OpenCode", so even with this fix the README's zero-configmodel: autoclaim does not produce a reply today.executor-devin-cli-agentic-acpfails withspawn EFTYPEand a fewautoCombo/strict-zero-cost-*/subscription-ladder/opencode-429-park-resumetests fail on the unmodified base too; unrelated to this change.