惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Jina AI
Jina AI
Hugging Face - Blog
Hugging Face - Blog
博客园 - 三生石上(FineUI控件)
博客园 - 【当耐特】
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家
宝玉的分享
宝玉的分享
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
酷 壳 – CoolShell
酷 壳 – CoolShell
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
爱范儿
爱范儿
小众软件
小众软件
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
S
SegmentFault 最新的问题
博客园 - Franky
博客园_首页
T
Tailwind CSS Blog
雷峰网
雷峰网
罗磊的独立博客

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(models): avoid externalizing Claude CLI auth · opencl...
neeravmakwan · 2026-04-26 · via Recent Commits to openclaw:main

@@ -1,4 +1,5 @@

11

import type { OpenClawConfig } from "../config/types.openclaw.js";

2+

import { CLAUDE_CLI_PROFILE_ID } from "./auth-profiles/constants.js";

23

import {

34

DEFAULT_OAUTH_REFRESH_MARGIN_MS,

45

type AuthCredentialReasonCode,

@@ -8,6 +9,7 @@ import {

89

import { resolveAuthProfileDisplayLabel } from "./auth-profiles/display.js";

910

import { resolveEffectiveOAuthCredential } from "./auth-profiles/effective-oauth.js";

1011

import type { AuthProfileCredential, AuthProfileStore } from "./auth-profiles/types.js";

12+

import { readClaudeCliCredentialsCached } from "./cli-credentials.js";

1113

import { normalizeProviderId } from "./provider-id.js";

12141315

export type AuthProfileSource = "store";

@@ -101,6 +103,34 @@ function resolveOAuthStatus(

101103

return { status: "ok", remainingMs };

102104

}

103105106+

function resolveClaudeCliStatusCredential(params: {

107+

profileId: string;

108+

credential: AuthProfileCredential;

109+

}): AuthProfileCredential {

110+

if (params.profileId !== CLAUDE_CLI_PROFILE_ID) {

111+

return params.credential;

112+

}

113+

const cliCredential = readClaudeCliCredentialsCached({ allowKeychainPrompt: false });

114+

if (!cliCredential) {

115+

return params.credential;

116+

}

117+

if (cliCredential.type === "oauth") {

118+

return {

119+

type: "oauth",

120+

provider: params.credential.provider,

121+

access: cliCredential.access,

122+

refresh: cliCredential.refresh,

123+

expires: cliCredential.expires,

124+

};

125+

}

126+

return {

127+

type: "token",

128+

provider: params.credential.provider,

129+

token: cliCredential.token,

130+

expires: cliCredential.expires,

131+

};

132+

}

133+104134

function buildProfileHealth(params: {

105135

profileId: string;

106136

credential: AuthProfileCredential;

@@ -112,9 +142,10 @@ function buildProfileHealth(params: {

112142

const { profileId, credential, store, cfg, now, warnAfterMs } = params;

113143

const label = resolveAuthProfileDisplayLabel({ cfg, store, profileId });

114144

const source = resolveAuthProfileSource(profileId);

115-

const provider = normalizeProviderId(credential.provider);

145+

const healthCredential = resolveClaudeCliStatusCredential({ profileId, credential });

146+

const provider = normalizeProviderId(healthCredential.provider);

116147117-

if (credential.type === "api_key") {

148+

if (healthCredential.type === "api_key") {

118149

return {

119150

profileId,

120151

provider,

@@ -125,9 +156,9 @@ function buildProfileHealth(params: {

125156

};

126157

}

127158128-

if (credential.type === "token") {

159+

if (healthCredential.type === "token") {

129160

const eligibility = evaluateStoredCredentialEligibility({

130-

credential,

161+

credential: healthCredential,

131162

now,

132163

});

133164

if (!eligibility.eligible) {

@@ -143,8 +174,8 @@ function buildProfileHealth(params: {

143174

label,

144175

};

145176

}

146-

const expiryState = resolveTokenExpiryState(credential.expires, now);

147-

const expiresAt = expiryState === "valid" ? credential.expires : undefined;

177+

const expiryState = resolveTokenExpiryState(healthCredential.expires, now);

178+

const expiresAt = expiryState === "valid" ? healthCredential.expires : undefined;

148179

if (!expiresAt) {

149180

return {

150181

profileId,

@@ -171,7 +202,7 @@ function buildProfileHealth(params: {

171202172203

const effectiveCredential = resolveEffectiveOAuthCredential({

173204

profileId,

174-

credential,

205+

credential: healthCredential,

175206

});

176207

const oauthWarnAfterMs = Math.max(warnAfterMs, DEFAULT_OAUTH_REFRESH_MARGIN_MS);

177208

const { status: rawStatus, remainingMs } = resolveOAuthStatus(