From ea9b36aacf4ba6a9081ae6770d744763e5f779ad Mon Sep 17 00:00:00 2001 From: claude-code Date: Wed, 5 Aug 2026 02:59:19 -0400 Subject: [PATCH] fix(providers): resolve keyring:// keys for CUSTOM providers, not just built-ins v3.3.0. Retires a daily cron that has been patching the installed npm dist since 2026-07-03. initializeFromConfig() blanked any apiKey stored as the `keyring://` marker and left resolution to "the provider's env-var fallback". That works for the BUILT-IN providers in the switch below - anthropic, openai, zai and ollama each register their own well-known variable. A CUSTOM provider (longcat, and anything else added to config by hand) has no such fallback, so it was handed an empty bearer token and every request 401'd. The fix has existed for a month, in the wrong place: NUKE runs scripts/sentinel-cli-repatch.sh from cron EVERY DAY to re-apply it to node_modules/@dirtysouthalpha/sentinel-cli/dist, because `npm update -g` silently reinstalls dist and wipes it. That script's own header documents the bug precisely. A daily cron re-patching a published artifact is a symptom; the patch belongs in source. Resolves the environment variable directly at the point of blanking rather than assuming a downstream fallback exists. Verified: `npm run lint` (tsc --noEmit) clean; full suite 106 files / 844 passed, 11 skipped. Once 3.3.0 is published and installed on NUKE, sentinel-cli-repatch.sh and its crontab entry can be deleted - that is the point of the change. Scope note: this checkout carries unrelated uncommitted work on the secrets backends (file-backend, windows-backend and their tests). That is someone else's in-progress change and is deliberately NOT included here. --- package.json | 2 +- src/ai/provider.ts | 15 ++++++++++++++- 2 files changed, 15 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index b64127b..0946f5b 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@dirtysouthalpha/sentinel-cli", - "version": "3.2.0", + "version": "3.3.0", "description": "AI-powered development CLI with cyberpunk aesthetic", "type": "module", "author": "DirtySouthAlpha", diff --git a/src/ai/provider.ts b/src/ai/provider.ts index f1071e5..d90baa9 100644 --- a/src/ai/provider.ts +++ b/src/ai/provider.ts @@ -61,8 +61,21 @@ class ProviderManager { // runs, so drop the marker here and let the provider's env-var fallback // resolve it. Otherwise the literal "keyring://zai" gets sent as the // bearer token and the API rejects it with 401. + // 2026-08-05: blanking the marker and leaving it to "the provider's env-var + // fallback" only works for the BUILT-IN providers in the switch below - + // anthropic, openai, zai and ollama each register their own well-known + // variable. A CUSTOM provider (longcat, and anything else added to config by + // hand) has no such fallback, so it received an empty bearer token and every + // request 401'd. + // + // This has been patched in the INSTALLED dist on NUKE since 2026-07-03 by + // scripts/sentinel-cli-repatch.sh, re-applied by cron every day because + // `npm update -g` silently reinstalls dist and wipes it. The fix belongs + // here, in source, so that cron can be retired. Resolve the variable + // directly instead of assuming a fallback exists downstream. if (typeof config.apiKey === "string" && config.apiKey.startsWith("keyring://")) { - config.apiKey = ""; + const envName = `${name.toUpperCase().replace(/[^A-Z0-9]/g, "_")}_API_KEY`; + config.apiKey = process.env[envName] || ""; } switch (name) { case "anthropic":