Repository navigation
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📝 Walkthrough
Merge Risk: ⚪ Minimal · up to No identified issue remains that should delay merging after normal checks. Caution Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional.
❌ Failed checks (1 error, 1 inconclusive)✅ Passed checks (6 passed)Full details: Provider Data Stays Siloed
Full details: Ui Changes Include Windows Proof
✨ Finishing Touches
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
# Conflicts: # apps/desktop-tauri/src/components/providers/providerIcons.ts # apps/desktop-tauri/src/test/providerCatalog.ts # docs/PROVIDERS.md # rust/src/core/provider.rs # rust/src/core/provider_factory.rs # rust/src/core/token_accounts.rs # rust/src/settings/api_keys.rs
# Conflicts: # apps/desktop-tauri/src/components/providers/providerIcons.ts # apps/desktop-tauri/src/test/providerCatalog.ts # docs/PROVIDERS.md # rust/src/core/provider.rs # rust/src/core/provider_factory.rs # rust/src/settings/api_keys.rs
# Conflicts: # README.md # apps/desktop-tauri/src/components/providers/providerIcons.ts # apps/desktop-tauri/src/test/providerCatalog.ts # rust/src/core/provider.rs # rust/src/core/provider_factory.rs # rust/src/core/token_accounts.rs
# Conflicts: # README.md # apps/desktop-tauri/src-tauri/src/commands/provider_settings.rs # apps/desktop-tauri/src-tauri/src/commands/session_cookie_scope_tests.rs # apps/desktop-tauri/src/components/providers/providerIcons.ts # apps/desktop-tauri/src/test/providerCatalog.ts # docs/PROVIDERS.md # rust/src/core/provider.rs # rust/src/core/provider_factory.rs # rust/src/core/token_accounts.rs # rust/src/settings.rs # rust/src/settings/tests.rs
Stacked on #819; merge in order 808 → 810 → 818 → 819 → 821 → 814 → 817; the diff shows predecessors until they merge.
What users get
A new LithosAI provider (console.lithosai.cloud) for the prepaid USD balance. It is disabled by default and has no API key.
Cookie source. Settings → Providers → LithosAI has a cookie-source picker that defaults to Automatic, as upstream does:
console.lithosai.cloudcookies from the detected browsers, and Manual fails closed without reading a browser.Both console cookies,
__Host-console_sessionand__Host-console_csrf, are required. A header missing either one never sends a request.The card shows:
Port and requests. Ported from upstream CodexBar v0.73.0
Resources/Plugins/lithosai.tsandProviders/LithosAI/LithosAIProviderDescriptor.swift. Each refresh makes three GETs, each carrying the session cookies and the CSRF value echoed asX-Console-Csrf:/api/mefor the active organization and email. The organization ID must match^[A-Za-z0-9_-]{1,128}$./api/billingwithX-Organization-Id. Money is in nanos and must be a JavaScript safe integer./api/billing/spend?start=YYYY-MM-01&end=YYYY-MM-DD(UTC month to date) withX-Organization-Id. The echoed range and every day must match the query.Errors and safety.
Files
rust/src/providers/lithosai/{mod.rs,model.rs,tests.rs}: fetch, session cookies, parse and card mappingWiring per the new-provider recipe:
core/provider.rs:ProviderId::LithosAI(clilithosai, cookie domainconsole.lithosai.cloud, colour #6B7280)core/provider_factory.rs: factory armcore/token_accounts.rs:Nonearmproviders/mod.rsFrontend:
ProviderIcon-lithosai.svg,providerIcons.ts,test/providerCatalog.tsDocs:
docs/PROVIDERS.md(new "LithosAI prepaid balance" section),README.md(provider table row)Cookie-source picker (second commit, following the Groq precedent in 5a44b63):
commands/provider_settings.rs: Automatic / Manual / Off options and the id mappingrust/src/settings.rs: the default cookie source is "auto"providers/lithosai/mod.rs: an empty Manual source fails closed (ManualEmptyCookiePolicy::FailClosedWeb)rust/src/settings/tests.rsandcommands/session_cookie_scope_tests.rsNo i18n or dependency changes; the picker reuses the existing option labels.
Tests
18 tests in
lithosai/tests.rs(13 against a local HTTP server, 5 without one). They use fixed fixtures and assert literal values.X-Console-CsrfandX-Organization-Idare sent as upstream sends them;/api/mehas no organization header.Two more tests cover the picker:
lithosai_cookie_source_defaults_to_automatic_session_import(settings): the default is "auto".lithosai_exposes_a_cookie_source_picker_and_routes_each_choice(tauri): the options are [auto, manual, off]; a stored header is used under Automatic and Manual; an empty Manual source is Web withmanual_cookie_missing; Off reaches the provider as Cli with no header.Commands
cargo fmt --all -- --checkcargo test --manifest-path rust/Cargo.tomlcargo clippy --manifest-path rust/Cargo.toml --all-targets -- -D warningscargo test --manifest-path apps/desktop-tauri/src-tauri/Cargo.tomlcargo clippy --manifest-path apps/desktop-tauri/src-tauri/Cargo.toml --all-targets -- -D warningspnpm testpnpm run lintpnpm run buildThe cargo rows ran on the head commit (e200608). The pnpm rows ran on the first commit (58eea49); the picker commit touches no frontend files.
The first filtered run failed one test that expected the cost block to carry a -$1.00 balance. The shared
CostSnapshot::with_balancefloors balances at zero, so the test now asserts that and keeps the "-$1.00" Billing row.The branch is based on 44d5de3, and the checks ran on that base. Main has moved since; in particular it predates #813 (the Mac card anatomy), so the panel proof and the card-layout gaps below describe the card before #813. Main's later Providers-pane changes (the usage-details section and #816's Settings panes) don't touch the cookie-source or API-key sections, and
cookie_source_options_forand the API-key catalog are unchanged on main.Proof (Windows, synthetic data only)
build-proof.sh). The proof-shim patch is never committed.win_run.pywith the LithosAI scenario pack. It uses a synthetic Manual header with both console cookies and a mockedconsole.lithosai.cloud. All three GETs returned 200; the mock answers billing only whenX-Organization-Idis present, and the spend query wasstart=2026-10-01&end=2026-10-11.W:/mac-parity/report/provider-lithosai/panel.pngW:/mac-parity/report/provider-lithosai/COMPARISON.mdresult.jsonandmock.log, in the same folderwin_run.py --mode settings:providers --target settingswith a copy of the pack that lists this provider first (W:/mac-parity/report/provider-lithosai/settings-pack/).W:/mac-parity/report/provider-lithosai/settings-proof/settings-before.pngand.jsonW:/mac-parity/report/provider-lithosai/settings-proof/settings-after.pngand.jsonGaps vs the Mac card
UsageSnapshotalways carries a primary window.Sibling PR conflicts
This is one of seven provider PRs: Synthetic (#808), ClawRouter (#810), IBM Bob (#818), Langdock (#819), LithosAI (#821), MuseAI (#814) and WorkBuddy (#817). They all add lines at the same anchors, so expect trivial textual conflicts once one of them merges. Keep both sides. The shared anchors are:
ProviderIdlists incore/provider.rs(after Vercel), including theall().len()count in its testproviders/mod.rstoken_accounts.rsproviderCatalog.tsand theproviderIcons.tsregistrydocs/PROVIDERS.mdsection and README table rowsThe four cookie providers (Langdock #819, LithosAI #821, MuseAI #814 and WorkBuddy #817) also share the picker commit's anchors, so they conflict with each other there:
rust/src/settings.rs: each PR rewrites the default cookie-source armKimi | Hyper | Groq => "auto"to add its variant. Keep every variant in the arm.commands/provider_settings.rs: each PR adds lines after thegroqentries incookie_source_providerandcookie_source_options_for.rust/src/settings/tests.rs: each PR adds a default test after the Groq default test.commands/session_cookie_scope_tests.rs: each PR appends a test at the end of the file.