Skip to content

fix(cli): send --allow-no-credential to the server - #15416

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.52from
HouMinXi:fix/allow-no-credential
Oct 6, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.52from
HouMinXi:fix/allow-no-credential

Conversation

@HouMinXi

@HouMinXi HouMinXi commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Summary

  • providers add --allow-no-credential only skipped the local prompt. The request never carried the flag, and the server schema did not accept it, so a provider that legitimately has no credential was still rejected.
  • The request now includes the flag when it was set. The server accepts it only for a provider whose catalog says a credential is optional, and rejects it with 400 otherwise. A request without the flag is checked exactly as before.

Related Issues

Validation

  • Change type: other (CLI provider add)
  • Focused tests: node --import tsx/esm --test tests/unit/cli/provider-crud.test.ts (15 pass)
  • eslint on the changed files, with the repo suppression file
  • Reconciled with release/v3.8.52 @ 23a1148486
  • Updated test covers the change
  • Defect injection: removing the line that writes the flag makes the assertion fail, and the change was restored

Tests Added Or Updated

  • tests/unit/cli/provider-crud.test.ts (updated)

Coverage Notes

  • The test asserts the flag is present in the body only when set, and absent otherwise.

Reviewer Notes

  • buildProviderPayload has one production caller, the add command. The schema rejects the flag for a provider that requires a credential, so the flag cannot be used to skip a real requirement.

@HouMinXi
HouMinXi requested a review from diegosouzapw as a code owner October 3, 2026 05:54
The flag only skipped the local prompt. The add-provider request never
carried it, and the server schema did not accept it, so a provider that
legitimately has no credential was still rejected.

The request now includes the flag when it was set, and the server accepts
it only for a provider whose catalog says a credential is optional. A
request without the flag is checked exactly as before.

Signed-off-by: Minxi Hou <houminxi@gmail.com>
@HouMinXi
HouMinXi force-pushed the fix/allow-no-credential branch from ae70ea4 to b4ab56a Compare October 6, 2026 13:48
@diegosouzapw
diegosouzapw merged commit 06090d3 into diegosouzapw:release/v3.8.52 Oct 6, 2026
40 of 51 checks passed
rafiknedir9-star pushed a commit to rafiknedir9-star/OmniRoute that referenced this pull request Oct 7, 2026
diegosouzapw#15416 added the allowNoCredential check without importing
providerAllowsOptionalApiKey, so any request carrying it failed with a
ReferenceError (500). Adds a regression test.

Also renames CursorExecutor's async header builder to buildCursorHeaders: as an
async override of the sync BaseExecutor.buildHeaders it broke the executor
registry types (API Route Typecheck).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants