Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
173 changes: 173 additions & 0 deletions desktop/app_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -535,6 +535,102 @@ status_bar_items = ["cost", "balance"]
}
}

func TestSettingsLoadsActiveWorkspaceCredentialsWithUserConfig(t *testing.T) {
isolateDesktopUserDirs(t)

project := robustTempDir(t)
launch := robustTempDir(t)
if err := os.WriteFile(filepath.Join(project, ".env"), []byte("WORKSPACE_ONLY_KEY=from-project\n"), 0o600); err != nil {
t.Fatalf("write project env: %v", err)
}
userCfg := config.LoadForEdit(config.UserConfigPath())
if err := userCfg.UpsertProvider(config.ProviderEntry{
Name: "workspace-provider",
Kind: "openai",
BaseURL: "https://workspace.example/v1",
Model: "workspace-model",
APIKeyEnv: "WORKSPACE_ONLY_KEY",
}); err != nil {
t.Fatalf("upsert provider: %v", err)
}
userCfg.Desktop.ProviderAccess = []string{"workspace-provider"}
if err := userCfg.SaveTo(config.UserConfigPath()); err != nil {
t.Fatalf("save user config: %v", err)
}
t.Setenv("WORKSPACE_ONLY_KEY", "")
os.Unsetenv("WORKSPACE_ONLY_KEY")
orig, _ := os.Getwd()
defer func() { _ = os.Chdir(orig) }()
if err := os.Chdir(launch); err != nil {
t.Fatalf("chdir launch: %v", err)
}

app := NewApp()
app.tabs = map[string]*WorkspaceTab{"project": {ID: "project", WorkspaceRoot: project}}
app.activeTabID = "project"
got := app.Settings()
for _, p := range got.Providers {
if p.Name == "workspace-provider" {
if !p.KeySet {
t.Fatalf("workspace provider keySet = false, want true from active workspace .env: %+v", p)
}
return
}
}
t.Fatalf("workspace provider missing from settings: %+v", got.Providers)
}

func TestSettingsShowsGlobalCredentialWithoutMutatingWorkspaceEnv(t *testing.T) {
isolateDesktopUserDirs(t)

project := robustTempDir(t)
launch := robustTempDir(t)
if err := os.WriteFile(filepath.Join(project, ".env"), []byte("SHARED_SETTINGS_KEY=from-project\n"), 0o600); err != nil {
t.Fatalf("write project env: %v", err)
}
if _, err := config.SetCredential("SHARED_SETTINGS_KEY", "from-credentials"); err != nil {
t.Fatalf("SetCredential: %v", err)
}
userCfg := config.LoadForEditWithoutCredentials(config.UserConfigPath())
if err := userCfg.UpsertProvider(config.ProviderEntry{
Name: "settings-provider",
Kind: "openai",
BaseURL: "https://settings.example/v1",
Model: "settings-model",
APIKeyEnv: "SHARED_SETTINGS_KEY",
}); err != nil {
t.Fatalf("upsert provider: %v", err)
}
userCfg.Desktop.ProviderAccess = []string{"settings-provider"}
if err := userCfg.SaveTo(config.UserConfigPath()); err != nil {
t.Fatalf("save user config: %v", err)
}
t.Setenv("SHARED_SETTINGS_KEY", "from-project")
orig, _ := os.Getwd()
defer func() { _ = os.Chdir(orig) }()
if err := os.Chdir(launch); err != nil {
t.Fatalf("chdir launch: %v", err)
}

app := NewApp()
app.tabs = map[string]*WorkspaceTab{"project": {ID: "project", WorkspaceRoot: project}}
app.activeTabID = "project"
got := app.Settings()
for _, p := range got.Providers {
if p.Name != "settings-provider" {
continue
}
if !p.KeySet || p.KeySource != "Reasonix credentials" {
t.Fatalf("settings-provider key = set:%v source:%q, want Reasonix credentials: %+v", p.KeySet, p.KeySource, p)
}
if env := os.Getenv("SHARED_SETTINGS_KEY"); env != "from-project" {
t.Fatalf("Settings mutated SHARED_SETTINGS_KEY = %q, want existing project env", env)
}
return
}
t.Fatalf("settings provider missing from settings: %+v", got.Providers)
}

func TestSettingsSeedsMissingUserConfigFromLegacyProjectConfig(t *testing.T) {
isolateDesktopUserDirs(t)

Expand Down Expand Up @@ -866,6 +962,83 @@ api_key_env = "DEEPSEEK_API_KEY"
}
}

func TestSetProviderKeyRestoresOfficialProviderAccess(t *testing.T) {
isolateDesktopUserDirs(t)
t.Setenv("DEEPSEEK_API_KEY", "")
os.Unsetenv("DEEPSEEK_API_KEY")
if err := os.MkdirAll(filepath.Dir(config.UserConfigPath()), 0o755); err != nil {
t.Fatalf("mkdir config dir: %v", err)
}
if err := os.WriteFile(config.UserConfigPath(), []byte(`
default_model = "deepseek/deepseek-v4-flash"

[desktop]
provider_access = []

[[providers]]
name = "deepseek"
kind = "openai"
base_url = "https://api.deepseek.com"
models = ["deepseek-v4-flash", "deepseek-v4-pro"]
default = "deepseek-v4-flash"
api_key_env = "DEEPSEEK_API_KEY"
`), 0o644); err != nil {
t.Fatalf("write config: %v", err)
}

if _, err := NewApp().SetProviderKey("DEEPSEEK_API_KEY", "sk-test"); err != nil {
t.Fatalf("SetProviderKey: %v", err)
}
cfg := config.LoadForEdit(config.UserConfigPath())
if !providerAccessSet(cfg.Desktop.ProviderAccess)["deepseek"] {
t.Fatalf("provider_access = %+v, want deepseek restored", cfg.Desktop.ProviderAccess)
}
got := NewApp().Settings()
for _, p := range got.Providers {
if p.Name == "deepseek" {
if !p.Added || !p.KeySet {
t.Fatalf("deepseek settings = %+v, want added and key-set", p)
}
return
}
}
t.Fatalf("settings providers missing deepseek: %+v", got.Providers)
}

func TestSetProviderKeyKeepsCustomAliasProviderAccess(t *testing.T) {
isolateDesktopUserDirs(t)
t.Setenv("PROXY_DEEPSEEK_KEY", "")
os.Unsetenv("PROXY_DEEPSEEK_KEY")
if err := os.MkdirAll(filepath.Dir(config.UserConfigPath()), 0o755); err != nil {
t.Fatalf("mkdir config dir: %v", err)
}
if err := os.WriteFile(config.UserConfigPath(), []byte(`
[desktop]
provider_access = []

[[providers]]
name = "deepseek-flash"
kind = "openai"
base_url = "https://proxy.example/v1"
model = "deepseek-v4-flash"
api_key_env = "PROXY_DEEPSEEK_KEY"
`), 0o644); err != nil {
t.Fatalf("write config: %v", err)
}

if _, err := NewApp().SetProviderKey("PROXY_DEEPSEEK_KEY", "sk-test"); err != nil {
t.Fatalf("SetProviderKey: %v", err)
}
cfg := config.LoadForEditWithoutCredentials(config.UserConfigPath())
access := providerAccessSet(cfg.Desktop.ProviderAccess)
if !access["deepseek-flash"] {
t.Fatalf("provider_access = %+v, want custom alias deepseek-flash", cfg.Desktop.ProviderAccess)
}
if access["deepseek"] {
t.Fatalf("provider_access = %+v, should not canonicalize custom proxy to deepseek", cfg.Desktop.ProviderAccess)
}
}

func TestAddOfficialProviderAccessUsesDesktopLanguagePricing(t *testing.T) {
isolateDesktopUserDirs(t)
if err := os.MkdirAll(filepath.Dir(config.UserConfigPath()), 0o755); err != nil {
Expand Down
90 changes: 88 additions & 2 deletions desktop/settings_app.go
Original file line number Diff line number Diff line change
Expand Up @@ -284,7 +284,7 @@ func providerViewFromEntryForRoot(p config.ProviderEntry, builtIn, added bool, r
if p.Vision {
visionModels = models
}
key := config.ResolveCredentialForRoot(root, p.APIKeyEnv)
key := config.ResolveCredentialForRootGlobalFirst(root, p.APIKeyEnv)
return ProviderView{
Name: p.Name, BuiltIn: builtIn, Added: added, Kind: p.Kind, BaseURL: p.BaseURL,
Models: nonNil(models), VisionModels: nonNil(providerVisionModels(models, visionModels)), VisionModelsSet: visionModelsSet, ModelsURL: p.ModelsURL, Default: p.DefaultModel(),
Expand Down Expand Up @@ -338,7 +338,7 @@ func officialProviderAddedSet(cfg *config.Config) map[string]bool {

// Settings returns the current configuration for the Settings panel.
func (a *App) Settings() SettingsView {
cfg, cfgPath, err := a.loadDesktopUserConfigForEdit()
cfg, cfgPath, err := a.loadDesktopUserConfigForView()
if err != nil {
return SettingsView{
Providers: []ProviderView{},
Expand Down Expand Up @@ -576,6 +576,38 @@ func (a *App) loadDesktopUserConfigForEdit() (*config.Config, string, error) {
return legacyCfg, userPath, nil
}

func (a *App) loadDesktopUserConfigForView() (*config.Config, string, error) {
userPath := config.UserConfigPath()
if userPath == "" {
return nil, "", fmt.Errorf("cannot resolve user config directory")
}
if _, err := os.Stat(userPath); err == nil {
cfg := config.LoadForEditWithoutCredentials(userPath)
normalizeLegacyDesktopProviderAccessForSettings(cfg, userPath)
legacyPath := config.SourcePathForRoot(a.activeWorkspaceRoot())
if legacyPath != "" && !sameConfigPath(legacyPath, userPath) {
legacyCfg := config.LoadForEditWithoutCredentials(legacyPath)
if err := migrateLegacyBotConfigToUser(cfg, legacyCfg, userPath); err != nil {
return nil, "", err
}
}
return cfg, userPath, nil
}
cfg := config.LoadForEditWithoutCredentials(userPath)
legacyPath := config.SourcePathForRoot(a.activeWorkspaceRoot())
if legacyPath == "" || sameConfigPath(legacyPath, userPath) {
normalizeLegacyDesktopProviderAccessForSettings(cfg, userPath)
return cfg, userPath, nil
}
legacyCfg := config.LoadForEditWithoutCredentials(legacyPath)
normalizeLegacyDesktopProviderAccessForSettings(legacyCfg, legacyPath)
legacyCfg.ConfigVersion = config.Default().ConfigVersion
if err := migrateLegacyBotConfigToUser(cfg, legacyCfg, userPath); err != nil {
return nil, "", err
}
return legacyCfg, userPath, nil
}

func (a *App) migrateLegacyBotConfigToUser(userCfg *config.Config, userPath string) error {
if userCfg == nil {
return nil
Expand Down Expand Up @@ -1364,12 +1396,66 @@ func (a *App) SetProviderKey(apiKeyEnv, value string) (string, error) {
if err != nil {
return "", err
}
if err := a.ensureProviderAccessForKey(apiKeyEnv); err != nil {
return "", err
}
if err := a.rebuild(); err != nil {
return "", err
}
return warning, nil
}

func (a *App) ensureProviderAccessForKey(apiKeyEnv string) error {
apiKeyEnv = strings.TrimSpace(apiKeyEnv)
if apiKeyEnv == "" {
return nil
}
cfg, path, err := a.loadDesktopUserConfigForEdit()
if err != nil {
return err
}
access := providerAccessSet(cfg.Desktop.ProviderAccess)
changed := false
addAccess := func(name string) {
if name == "" || access[name] {
return
}
addProviderAccess(cfg, name)
access[name] = true
changed = true
}
for i := range cfg.Providers {
p := cfg.Providers[i]
if strings.TrimSpace(p.APIKeyEnv) != apiKeyEnv {
continue
}
if len(p.ModelList()) == 0 {
continue
}
if isOfficialBuiltInProvider(p) {
addAccess(config.CanonicalDesktopOfficialProviderName(p.Name))
} else {
addAccess(strings.TrimSpace(p.Name))
}
}
if !changed && apiKeyEnv == "DEEPSEEK_API_KEY" {
entries, _, err := officialProviderTemplate("deepseek", cfg.DeepSeekOfficialPricingLanguage())
if err != nil {
return err
}
for _, e := range entries {
if err := cfg.UpsertProvider(e); err != nil {
return err
}
addAccess(e.Name)
}
}
if !changed {
return nil
}
return cfg.SaveTo(path)
}

// ClearProviderKey removes a provider secret from the global credential store
// and rebuilds so the provider immediately becomes unauthenticated.
func (a *App) ClearProviderKey(apiKeyEnv string) error {
Expand Down
21 changes: 21 additions & 0 deletions internal/config/backfill_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -135,6 +135,27 @@ func TestNormalizeDesktopOfficialProviderAccessCanonicalizesLegacyIDs(t *testing
}
}

func TestNormalizeDesktopOfficialProviderAccessKeepsCustomAlias(t *testing.T) {
c := &Config{
Desktop: DesktopConfig{ProviderAccess: []string{"deepseek-flash"}},
Providers: []ProviderEntry{{
Name: "deepseek-flash",
Kind: "openai",
BaseURL: "https://proxy.example/v1",
Model: "deepseek-v4-flash",
}},
}

normalizeDesktopOfficialProviderAccess(c)

if len(c.Desktop.ProviderAccess) != 1 || c.Desktop.ProviderAccess[0] != "deepseek-flash" {
t.Fatalf("provider_access = %+v, want custom alias preserved", c.Desktop.ProviderAccess)
}
if _, ok := c.Provider("deepseek"); ok {
t.Fatal("custom deepseek-flash proxy should not create canonical deepseek provider")
}
}

func TestNormalizeOfficialDeepSeekModelsRepairsCanonicalProvider(t *testing.T) {
c := &Config{
DefaultModel: "deepseek-flash/deepseek-v4-flash",
Expand Down
Loading