Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
35 commits
Select commit Hold shift + click to select a range
dff215e
feat(reborn): add OpenAI-compatible API contracts
hanakannzashi Jun 4, 2026
035a265
fix(reborn): tighten OpenAI-compatible response contracts
hanakannzashi Jun 5, 2026
9a5d9a6
fix(reborn): address OpenAI compat contract review
hanakannzashi Jun 6, 2026
a2c2ee0
Merge origin/main into OpenAI compat contracts
think-in-universe Jun 7, 2026
4222ac5
Merge remote-tracking branch 'origin/main' into issue-4442-reborn-ope…
hanakannzashi Jun 8, 2026
5264f35
fix(reborn): satisfy merged main clippy
hanakannzashi Jun 8, 2026
9af95ed
Merge remote-tracking branch 'origin/main' into issue-4442-reborn-ope…
hanakannzashi Jun 8, 2026
f9611c7
feat(reborn): add OpenAI-compatible product refs
hanakannzashi Jun 5, 2026
3d5249b
fix(reborn): validate OpenAI-compatible ref mappings
hanakannzashi Jun 5, 2026
f02dab6
fix(reborn): address OpenAI product refs review
hanakannzashi Jun 6, 2026
6abf732
feat(reborn): route chat completions through ProductWorkflow
hanakannzashi Jun 5, 2026
b054561
fix(reborn): simplify chat completion timestamps
hanakannzashi Jun 5, 2026
d7d07ac
fix(reborn): use explicit ProductWorkflow submit door
hanakannzashi Jun 8, 2026
b96fda5
test(reborn): stabilize subagent cancellation propagation
hanakannzashi Jun 8, 2026
89f68e7
Validate durable OpenAI compat ref records
think-in-universe Jun 8, 2026
1e12d6c
Fix chat completions idempotency validation
think-in-universe Jun 8, 2026
63cfd9b
Format OpenAI compat storage review fixes
think-in-universe Jun 8, 2026
4a66e1a
Merge branch 'issue-4443-reborn-openai-product-refs' into issue-4444-…
think-in-universe Jun 8, 2026
68730db
feat(reborn): add OpenAI-compatible product refs (#4489)
hanakannzashi Jun 8, 2026
a4ea2e9
Address chat completions review comments
think-in-universe Jun 8, 2026
2d0aeb9
Persist chat completion idempotency replay metadata
think-in-universe Jun 8, 2026
4ccbe4a
Export OpenAI compat ack recording request
think-in-universe Jun 8, 2026
caf632c
Persist OpenAI compat accepted workflow acks
think-in-universe Jun 8, 2026
1a2789c
Merge main into OpenAI compatibility contracts
think-in-universe Jun 8, 2026
801d1e8
Merge OpenAI API contracts base into chat completions workflow
think-in-universe Jun 8, 2026
fa6f010
fix(reborn): resolve chat completions review feedback
think-in-universe Jun 8, 2026
84e4882
fix(reborn): resolve chat completions review feedback
think-in-universe Jun 8, 2026
5aed75d
fix(reborn): update chat completions workflow stack
think-in-universe Jun 8, 2026
09f22e8
merge remote chat completions review fix
think-in-universe Jun 8, 2026
d6b4d17
fix(openai-compat): address chat workflow review comments
think-in-universe Jun 8, 2026
b1e0a26
fix(openai-compat): address chat ref store review
think-in-universe Jun 9, 2026
7b16121
fix(reborn): resolve chat projections through workflow
hanakannzashi Jun 9, 2026
d0bd5ea
Merge remote-tracking branch 'origin/main' into issue-4444-reborn-cha…
hanakannzashi Jun 9, 2026
d572dd4
feat(reborn): wire OpenAI chat completions route
hanakannzashi Jun 9, 2026
3505eee
fix(reborn): centralize chat body validation
hanakannzashi Jun 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 4 additions & 0 deletions crates/ironclaw_reborn_cli/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,10 @@ slack-v2-host-beta = [
"webui-v2-beta",
"ironclaw_reborn_composition/slack-v2-host-beta",
]
openai-compat-beta = [
"webui-v2-beta",
"ironclaw_reborn_composition/openai-compat-beta",
]
[dependencies]
anyhow = "1"
async-trait = { version = "0.1", optional = true }
Expand Down
19 changes: 17 additions & 2 deletions crates/ironclaw_reborn_cli/src/commands/serve.rs
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ use std::sync::Arc;

use anyhow::{Context, anyhow};
use clap::Args;
#[cfg(feature = "openai-compat-beta")]
use ironclaw_reborn_composition::build_openai_compat_route_mount;
#[cfg(not(feature = "slack-v2-host-beta"))]
use ironclaw_reborn_composition::build_webui_services;
use ironclaw_reborn_composition::host_api::{AgentId, ProjectId, TenantId, UserId};
Expand Down Expand Up @@ -379,6 +381,15 @@ impl ServeCommand {
)?;
#[cfg(not(feature = "slack-v2-host-beta"))]
let bundle: RebornWebuiBundle = build_webui_services(&runtime, None)?;
#[cfg(feature = "openai-compat-beta")]
let openai_compat_mount = build_openai_compat_route_mount(
&runtime,
tenant_id.clone(),
default_agent_id.clone(),
default_project_id.clone(),
)
.await
.context("failed to compose OpenAI-compatible Reborn routes")?;

// Open the canonical Reborn identity resolver on the runtime's
// existing substrate handle (the same `reborn-local-dev.db` the
Expand Down Expand Up @@ -436,10 +447,14 @@ impl ServeCommand {
);

let mut serve_config = WebuiServeConfig::new(tenant_id, authenticator, allowed_origins)
.with_default_agent_id(default_agent_id);
if let Some(project_id) = default_project_id {
.with_default_agent_id(default_agent_id.clone());
if let Some(project_id) = default_project_id.clone() {
serve_config = serve_config.with_default_project_id(project_id);
}
#[cfg(feature = "openai-compat-beta")]
{
serve_config = serve_config.with_protected_route_mount(openai_compat_mount);
}
if let Some(google_oauth) = resolve_google_oauth_config_from_env()
.context("failed to resolve Google OAuth setup config for WebUI")?
{
Expand Down
4 changes: 4 additions & 0 deletions crates/ironclaw_reborn_composition/CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,7 @@ middleware with v1's `src/channels/web/`.
| `WebuiAuthenticator` trait | Host-supplied bearer-token verifier; returns `Option<UserId>` |
| `WebuiServeConfig { tenant_id, authenticator, max_body_bytes, allowed_origins, csp_header }` | Required config for `webui_v2_app`; no defaults that silently disable security |
| `webui_v2_app(bundle, config) -> Router` | Build the fully-composed axum `Router`. This is the seam between this product/API crate and host-owned HTTP ingress: tests drive it via `tower::ServiceExt::oneshot`; the `ironclaw-reborn serve` subcommand (follow-up PR) hands it to `axum::serve` from a host-owned listener |
| `ProtectedRouteMount` | Host-supplied protected API route fragment merged inside the WebUI bearer-auth layer with descriptor-driven body/rate limits. Reborn OpenAI-compatible routes use this seam; do not use it for v1 gateway routers. |

### Middleware stack composed by `webui_v2_app`

Expand Down Expand Up @@ -108,6 +109,9 @@ Inbound order (outer → inner → handler):
timeline reads stay bearer-only. On success the middleware inserts
a `WebUiAuthenticatedCaller` extension built from
`config.tenant_id` plus the authenticator's `UserId`.
When `openai-compat-beta` is enabled, the same verified bearer result also
inserts an `OpenAiCompatAuthenticatedCaller` extension for protected
OpenAI-compatible route mounts; route crates must not mint this evidence.
8. **Descriptor-driven per-route rate limit**
(`webui_rate_limit::enforce_rate_limit`) — reads
`ironclaw_webui_v2::webui_v2_routes()` plus mounted product-auth
Expand Down
12 changes: 12 additions & 0 deletions crates/ironclaw_reborn_composition/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,16 @@ slack-v2-host-beta = [
"dep:ironclaw_wasm_product_adapters",
"dep:ironclaw_product_workflow_storage",
]
openai-compat-beta = [
"webui-v2-beta",
"dep:ironclaw_reborn_openai_compat",
"ironclaw_reborn_openai_compat/openai-compat-beta",
"dep:ironclaw_reborn_openai_compat_storage",
"dep:ironclaw_product_workflow_storage",
"ironclaw_product_workflow_storage/libsql",
"ironclaw_reborn_openai_compat_storage/libsql",
"ironclaw_product_adapters/host-auth-mint",
]
libsql = [
"dep:libsql",
"ironclaw_filesystem/libsql",
Expand Down Expand Up @@ -112,6 +122,8 @@ ironclaw_reborn = { path = "../ironclaw_reborn" }
ironclaw_reborn_config = { path = "../ironclaw_reborn_config" }
ironclaw_reborn_identity = { path = "../ironclaw_reborn_identity", optional = true }
ironclaw_reborn_event_store = { path = "../ironclaw_reborn_event_store" }
ironclaw_reborn_openai_compat = { path = "../ironclaw_reborn_openai_compat", optional = true }
ironclaw_reborn_openai_compat_storage = { path = "../ironclaw_reborn_openai_compat_storage", optional = true }
ironclaw_first_party_extension_ports = { path = "../ironclaw_first_party_extension_ports" }
ironclaw_resources = { path = "../ironclaw_resources" }
ironclaw_run_state = { path = "../ironclaw_run_state" }
Expand Down
9 changes: 7 additions & 2 deletions crates/ironclaw_reborn_composition/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,8 @@ mod oauth_dcr;
mod oauth_dcr_protocol;
mod oauth_gate;
mod oauth_provider_client;
#[cfg(feature = "openai-compat-beta")]
mod openai_compat_serve;
mod outbound_preferences;
mod product_auth_durable;
mod product_auth_providers;
Expand Down Expand Up @@ -179,6 +181,8 @@ pub use local_runtime_profile::{
local_dev_yolo_runtime_policy, local_runtime_build_input,
local_runtime_build_input_with_options,
};
#[cfg(feature = "openai-compat-beta")]
pub use openai_compat_serve::build_openai_compat_route_mount;
pub use product_live_adapters::{
ProductLiveCapabilityAuthorityResolver, ProductLiveCapabilityIo, ProductLiveModelRouteSettings,
ProductLivePlannedRuntimeAdapterConfig, ProductLivePlannedRuntimeAdapterError,
Expand Down Expand Up @@ -283,8 +287,9 @@ pub use webui::{RebornWebuiBundle, build_webui_services};
pub use webui_rate_limit::RateLimitConfigError;
#[cfg(feature = "webui-v2-beta")]
pub use webui_serve::{
PublicRouteDrain, PublicRouteDrains, PublicRouteMount, WebuiAuthenticator, WebuiServeConfig,
WebuiServeConfigError, WebuiServeError, WebuiV2App, webui_v2_app, webui_v2_app_with_lifecycle,
ProtectedRouteMount, PublicRouteDrain, PublicRouteDrains, PublicRouteMount, WebuiAuthenticator,
WebuiServeConfig, WebuiServeConfigError, WebuiServeError, WebuiV2App, webui_v2_app,
webui_v2_app_with_lifecycle,
};

/// Re-exported identity vocabulary host binaries need to construct
Expand Down
Loading
Loading