Skip to content

Add the LithosAI provider - #821

Open
Finesssee wants to merge 18 commits into
mainfrom
feat/provider-lithosai
Open

Finesssee wants to merge 18 commits into
mainfrom
feat/provider-lithosai

Conversation

@Finesssee

@Finesssee Finesssee commented Oct 11, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked on #819; merge in order 808 → 810 → 818 → 819 → 821 → 814 → 817; the diff shows predecessors until they merge.

What users get

A new LithosAI provider (console.lithosai.cloud) for the prepaid USD balance. It is disabled by default and has no API key.

Cookie source. Settings → Providers → LithosAI has a cookie-source picker that defaults to Automatic, as upstream does:

  • Automatic and Manual first use a header imported under Browser Cookies (from the browser you choose) or pasted there.
  • Without a stored header, Automatic reads the console.lithosai.cloud cookies from the detected browsers, and Manual fails closed without reading a browser.
  • Off reads nothing.

Both console cookies, __Host-console_session and __Host-console_csrf, are required. A header missing either one never sends a request.

The card shows:

  • The balance as an informational lane ("Balance: $42.37") and a "Prepaid credits" cost block. There is no quota bar.
  • A Billing section: Balance, Payment card (Added / Not added), Account status (Active / On hold), Today (UTC) and This month (UTC) spend.
  • The account email as identity, and "Browser session" as the login method.

Port and requests. Ported from upstream CodexBar v0.73.0 Resources/Plugins/lithosai.ts and Providers/LithosAI/LithosAIProviderDescriptor.swift. Each refresh makes three GETs, each carrying the session cookies and the CSRF value echoed as X-Console-Csrf:

  1. /api/me for the active organization and email. The organization ID must match ^[A-Za-z0-9_-]{1,128}$.
  2. /api/billing with X-Organization-Id. Money is in nanos and must be a JavaScript safe integer.
  3. /api/billing/spend?start=YYYY-MM-01&end=YYYY-MM-DD (UTC month to date) with X-Organization-Id. The echoed range and every day must match the query.

Errors and safety.

  • Spend is optional. A failed or malformed report shows "Spend: Unavailable" and keeps the balance; a 401 there still reports an expired session.
  • 401 anywhere reports an expired session. 403, 429, 5xx and other statuses use upstream's messages.
  • Redirects are not followed, and responses are capped at 512 KiB.
  • Response bodies and cookies are never echoed in errors or logged.

Files

  • rust/src/providers/lithosai/{mod.rs,model.rs,tests.rs}: fetch, session cookies, parse and card mapping

  • Wiring per the new-provider recipe:

    • core/provider.rs: ProviderId::LithosAI (cli lithosai, cookie domain console.lithosai.cloud, colour #6B7280)
    • core/provider_factory.rs: factory arm
    • core/token_accounts.rs: None arm
    • providers/mod.rs
  • Frontend: ProviderIcon-lithosai.svg, providerIcons.ts, test/providerCatalog.ts

  • Docs: docs/PROVIDERS.md (new "LithosAI prepaid balance" section), README.md (provider table row)

  • Cookie-source picker (second commit, following the Groq precedent in 5a44b63):

    • commands/provider_settings.rs: Automatic / Manual / Off options and the id mapping
    • rust/src/settings.rs: the default cookie source is "auto"
    • providers/lithosai/mod.rs: an empty Manual source fails closed (ManualEmptyCookiePolicy::FailClosedWeb)
    • tests in rust/src/settings/tests.rs and commands/session_cookie_scope_tests.rs

No i18n or dependency changes; the picker reuses the existing option labels.

Tests

18 tests in lithosai/tests.rs (13 against a local HTTP server, 5 without one). They use fixed fixtures and assert literal values.

  • Card mapping:
    • Upstream's fixture with sparse spend days maps to the balance and spend rows.
    • The parity-pack payload maps to Balance $42.37, Added, Active, $1.84 and $7.84, with the email and organization.
    • Zero, debt and sub-cent balances render as "$0.00", "-$1.00" and "Less than $0.01" without inventing a quota.
    • The billing flags render "Not added" and "On hold".
    • Missing identity fields stay empty.
  • Parsing:
    • A malformed required balance fails closed; an integral float balance counts as a safe integer.
    • A malformed optional spend report keeps the balance and shows "Spend: Unavailable" instead of a false zero.
    • The active organization ID is validated before billing is requested.
  • Requests and errors:
    • The cookies, X-Console-Csrf and X-Organization-Id are sent as upstream sends them; /api/me has no organization header.
    • Spend HTTP failures keep the balance, except an expired session.
    • A 401 at any of the three requests is an expired session; other statuses map to upstream messages.
    • Errors don't echo cookies or bodies.
  • No requests: a header missing either console cookie, the Off source and OAuth never fetch.
  • Helpers and metadata: the UTC month-to-date range, upstream money formatting, and the descriptor metadata.

Two more tests cover the picker:

  • lithosai_cookie_source_defaults_to_automatic_session_import (settings): the default is "auto".
  • lithosai_exposes_a_cookie_source_picker_and_routes_each_choice (tauri): the options are [auto, manual, off]; a stored header is used under Automatic and Manual; an empty Manual source is Web with manual_cookie_missing; Off reaches the provider as Cli with no header.

Commands

Command Result
cargo fmt --all -- --check pass
cargo test --manifest-path rust/Cargo.toml pass (3821 passed, 1 ignored)
cargo clippy --manifest-path rust/Cargo.toml --all-targets -- -D warnings pass
cargo test --manifest-path apps/desktop-tauri/src-tauri/Cargo.toml pass (638)
cargo clippy --manifest-path apps/desktop-tauri/src-tauri/Cargo.toml --all-targets -- -D warnings pass
pnpm test pass (107 files, 831 tests)
pnpm run lint pass (13 existing warnings, none in changed lines)
pnpm run build pass

The cargo rows ran on the head commit (e200608). The pnpm rows ran on the first commit (58eea49); the picker commit touches no frontend files.

The first filtered run failed one test that expected the cost block to carry a -$1.00 balance. The shared CostSnapshot::with_balance floors balances at zero, so the test now asserts that and keeps the "-$1.00" Billing row.

The branch is based on 44d5de3, and the checks ran on that base. Main has moved since; in particular it predates #813 (the Mac card anatomy), so the panel proof and the card-layout gaps below describe the card before #813. Main's later Providers-pane changes (the usage-details section and #816's Settings panes) don't touch the cookie-source or API-key sections, and cookie_source_options_for and the API-key catalog are unchanged on main.

Proof (Windows, synthetic data only)

  • Build: a debug build of this branch's commit (58eea49), made through the parity rig (build-proof.sh). The proof-shim patch is never committed.
  • Capture: win_run.py with the LithosAI scenario pack. It uses a synthetic Manual header with both console cookies and a mocked console.lithosai.cloud. All three GETs returned 200; the mock answers billing only when X-Organization-Id is present, and the spend query was start=2026-10-01&end=2026-10-11.
  • Files:
    • Windows panel: W:/mac-parity/report/provider-lithosai/panel.png
    • comparison: W:/mac-parity/report/provider-lithosai/COMPARISON.md
    • result.json and mock.log, in the same folder
  • Result: the card shows "LithosAI", parity.user@example.com, "Browser session", "Balance: $42.37", the Billing rows (Balance $42.37, Payment card Added, Account status Active, Today (UTC) $1.84, This month (UTC) $7.84) and "Prepaid credits $42.37". These match the values the pack derives from lithosai.ts.
  • Settings picker: win_run.py --mode settings:providers --target settings with a copy of the pack that lists this provider first (W:/mac-parity/report/provider-lithosai/settings-pack/).
    • Before, on the first commit (58eea49): the provider pane has no "Cookie source" section. W:/mac-parity/report/provider-lithosai/settings-proof/settings-before.png and .json
    • After, on the head commit (e200608): the pane shows "Cookie source" with Automatic, Manual (selected, from the pack's settings) and Disabled. W:/mac-parity/report/provider-lithosai/settings-proof/settings-after.png and .json
    • The panel proof above still holds: the pack sets the Manual source with a synthetic header, so the picker commit does not change its routing or the card.

Gaps vs the Mac card

  • No Mac capture exists. LithosAI arrived upstream in 0.71.0, after the 0.70.0 Mac baseline. The comparison is against the pack's expected values.
  • Organization not shown. "Parity Labs" is parsed into the account organization, but the shared card header shows only the email.
  • No prepaidCredits card style. Upstream shows a "Credits" block with "Balance: $42.37". Windows shows an informational primary lane plus a "Prepaid credits" cost block, because a Windows UsageSnapshot always carries a primary window.
  • Debt in the cost block. The shared cost block floors balances at zero, so a debt shows $0.00 there; the Billing row keeps "-$1.00".
  • Cookie source differs from upstream. Upstream's Automatic imports from Chrome only. On Windows, an explicit import under Browser Cookies (any supported browser) or a pasted header comes first, and Automatic otherwise reads the detected browsers. A Windows refresh uses one session, so a 401 is reported as expired at once.
  • Detail rows render as "Label: value" lines rather than Mac's two-column rows (shared card rendering).
  • English only. Detail strings are not translated.

Sibling PR conflicts

This is one of seven provider PRs: Synthetic (#808), ClawRouter (#810), IBM Bob (#818), Langdock (#819), LithosAI (#821), MuseAI (#814) and WorkBuddy (#817). They all add lines at the same anchors, so expect trivial textual conflicts once one of them merges. Keep both sides. The shared anchors are:

  • ProviderId lists in core/provider.rs (after Vercel), including the all().len() count in its test
  • the factory arm and providers/mod.rs
  • token_accounts.rs
  • providerCatalog.ts and the providerIcons.ts registry
  • the docs/PROVIDERS.md section and README table rows

The four cookie providers (Langdock #819, LithosAI #821, MuseAI #814 and WorkBuddy #817) also share the picker commit's anchors, so they conflict with each other there:

  • rust/src/settings.rs: each PR rewrites the default cookie-source arm Kimi | Hyper | Groq => "auto" to add its variant. Keep every variant in the arm.
  • commands/provider_settings.rs: each PR adds lines after the groq entries in cookie_source_provider and cookie_source_options_for.
  • rust/src/settings/tests.rs: each PR adds a default test after the Groq default test.
  • commands/session_cookie_scope_tests.rs: each PR appends a test at the end of the file.

@coderabbitai

coderabbitai Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: nesszer/Win-CodexBar/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: a0fe24af-10e5-4bc8-9cc5-9daeea12d3c0






📥 Commits

Reviewing files that changed from the base of the PR and between 0a3a10a and e200608.







⛔ Files ignored due to path filters (1)
  • apps/desktop-tauri/src/components/providers/icons/ProviderIcon-lithosai.svg is excluded by !**/*.svg






📒 Files selected for processing (15)
  • README.md
  • apps/desktop-tauri/src-tauri/src/commands/provider_settings.rs
  • apps/desktop-tauri/src-tauri/src/commands/session_cookie_scope_tests.rs
  • apps/desktop-tauri/src/components/providers/providerIcons.ts
  • apps/desktop-tauri/src/test/providerCatalog.ts
  • docs/PROVIDERS.md
  • rust/src/core/provider.rs
  • rust/src/core/provider_factory.rs
  • rust/src/core/token_accounts.rs
  • rust/src/providers/lithosai/mod.rs
  • rust/src/providers/lithosai/model.rs
  • rust/src/providers/lithosai/tests.rs
  • rust/src/providers/mod.rs
  • rust/src/settings.rs
  • rust/src/settings/tests.rs






Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 0 remain after this review.








📝 Walkthrough
📝 Walkthrough
📝 Walkthrough
📝 Walkthrough
📝 Walkthrough
📝 Walkthrough

Walkthrough

This change adds LithosAI as a provider. It registers the provider, configures cookie-source options, and retrieves prepaid balance and UTC spend data from the LithosAI console.

Changes

LithosAI provider

Layer / File(s) Summary
Register LithosAI
rust/src/core/*, rust/src/providers/mod.rs, rust/src/core/token_accounts.rs
Adds LithosAI provider identifiers and mappings, provider construction and exports, and its token-account support classification.
Configure cookie sources and provider surfaces
rust/src/settings.rs, rust/src/settings/tests.rs, apps/desktop-tauri/src-tauri/src/commands/*, apps/desktop-tauri/src/components/providers/providerIcons.ts, apps/desktop-tauri/src/test/providerCatalog.ts, README.md, docs/PROVIDERS.md
Sets the cookie-source default to auto and adds auto, manual, and off options. Adds desktop catalog and icon entries, plus documentation for LithosAI.
Parse billing data and build results
rust/src/providers/lithosai/model.rs, rust/src/providers/lithosai/tests.rs
Validates account, billing, and spend data. Builds result rows for prepaid balance, account status, and available or unavailable UTC spend.
Fetch console data with session cookies
rust/src/providers/lithosai/mod.rs, rust/src/providers/lithosai/tests.rs
Adds session-cookie handling and console requests. Applies response limits and HTTP status handling; spend retrieval failures preserve balance except for expired-session errors.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant CookieSource
  participant LithosAIProvider
  participant LithosAIConsole
  participant LithosAIModel
  CookieSource->>LithosAIProvider: Provide session and CSRF cookies
  LithosAIProvider->>LithosAIConsole: Request account and billing data
  LithosAIConsole-->>LithosAIProvider: Return account and billing responses
  LithosAIProvider->>LithosAIModel: Parse account and billing data
  LithosAIProvider->>LithosAIConsole: Request spend for the UTC date range
  LithosAIConsole-->>LithosAIProvider: Return spend response
  LithosAIProvider->>LithosAIModel: Parse spend and build provider result
Loading
















Merge Risk: ⚪ Minimal · up to e2006

No identified issue remains that should delay merging after normal checks.


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (1 error, 1 inconclusive)

Check name Status Explanation Resolution
Provider Data Stays Siloed Error The PR adds provider-specific branching outside the allowed locations. In rust/src/settings.rs, Settings::cookie_source now matches ProviderId::LithosAI to select "auto". In `rust/src/core/tok… Remove the ProviderId::LithosAI branches from shared settings.rs and core/token_accounts.rs. Provide these provider-specific behaviors through provider-local capability or metadata mechanisms under rust/src/providers/lithosai/, or t…
Ui Changes Include Windows Proof Inconclusive The PR changes visible UI code: it adds the LithosAI icon and registry entry in apps/desktop-tauri/src/components/providers/providerIcons.ts. The supplied objectives mention Windows proof with synth… Provide the complete PR description, or add an explicit note or screenshots showing proof from a fresh Windows build.
✅ Passed checks (6 passed)
Check name Status Explanation
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Secrets Handled Safely Passed No changed code exposes a real credential. rust/src/providers/lithosai/mod.rs:197-228 obtains cookies through the shared browser-cookie and cookie-normalization helpers, then keeps them in memory fo…
No Unapproved Dependencies Passed The pull-request diff changes 16 source, documentation, test, and icon files. It does not change any Cargo.toml, package.json, package-lock.json, yarn.lock, or pnpm-lock.yaml file. It also does not ch…
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title is a short imperative summary that directly describes the main change: adding the LithosAI provider.

Full details: Provider Data Stays Siloed

Explanation

The PR adds provider-specific branching outside the allowed locations. In rust/src/settings.rs, Settings::cookie_source now matches ProviderId::LithosAI to select "auto". In rust/src/core/token_accounts.rs, TokenAccountSupport::for_provider now matches ProviderId::LithosAI to return None. Both files are shared code outside rust/src/providers/lithosai/ and rust/src/core/provider_factory.rs. No separate cross-account data leak is shown, but this explicit custom-check condition is violated.

Resolution

Remove the ProviderId::LithosAI branches from shared settings.rs and core/token_accounts.rs. Provide these provider-specific behaviors through provider-local capability or metadata mechanisms under rust/src/providers/lithosai/, or through a generic shared mechanism that does not match on a specific ProviderId.


Full details: Ui Changes Include Windows Proof

Explanation

The PR changes visible UI code: it adds the LithosAI icon and registry entry in apps/desktop-tauri/src/components/providers/providerIcons.ts. The supplied objectives mention Windows proof with synthetic data, but the authored PR description is truncated before the Commands/proof section. The available text does not establish whether the proof used a fresh Windows build or included screenshots.


  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR







🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR











  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pre-merge checks failed. Please resolve the failing checks before merging.

# Conflicts:
#	apps/desktop-tauri/src/components/providers/providerIcons.ts
#	apps/desktop-tauri/src/test/providerCatalog.ts
#	docs/PROVIDERS.md
#	rust/src/core/provider.rs
#	rust/src/core/provider_factory.rs
#	rust/src/core/token_accounts.rs
#	rust/src/settings/api_keys.rs
# Conflicts:
#	apps/desktop-tauri/src/components/providers/providerIcons.ts
#	apps/desktop-tauri/src/test/providerCatalog.ts
#	docs/PROVIDERS.md
#	rust/src/core/provider.rs
#	rust/src/core/provider_factory.rs
#	rust/src/settings/api_keys.rs
# Conflicts:
#	README.md
#	apps/desktop-tauri/src/components/providers/providerIcons.ts
#	apps/desktop-tauri/src/test/providerCatalog.ts
#	rust/src/core/provider.rs
#	rust/src/core/provider_factory.rs
#	rust/src/core/token_accounts.rs
# Conflicts:
#	README.md
#	apps/desktop-tauri/src-tauri/src/commands/provider_settings.rs
#	apps/desktop-tauri/src-tauri/src/commands/session_cookie_scope_tests.rs
#	apps/desktop-tauri/src/components/providers/providerIcons.ts
#	apps/desktop-tauri/src/test/providerCatalog.ts
#	docs/PROVIDERS.md
#	rust/src/core/provider.rs
#	rust/src/core/provider_factory.rs
#	rust/src/core/token_accounts.rs
#	rust/src/settings.rs
#	rust/src/settings/tests.rs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant