Skip to content

Commit ba7673f

Browse files
author
CodeWhale Bot
committed
fix(client): keep codex env-token auth working on custom endpoints
PR #5716 diverted OpenaiCodex credential resolution to the generic key resolver whenever provider_uses_custom_endpoint() is true, which dropped an explicit OPENAI_CODEX_ACCESS_TOKEN for custom-base-url setups. The shared-seam wiremock test proves the regression: the mock only answers Bearer test-token, so the request came back 404 on all three CI OSes (client::responses::tests::responses_stream_open_preserves_wire_headers_ through_shared_seam). The manual if-condition formatting also failed the Lint job's cargo fmt --check. Restore the pre-PR precedence by trying codex_credentials() first: env credentials still win on custom endpoints (codex_credentials checks env before the official-endpoint consent grant), the official endpoint keeps propagating OAuth errors, and only a custom endpoint with no env token falls back to deepseek_api_key() — preserving the contributor's goal of letting a custom endpoint authenticate with its own configured key. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
1 parent 20ac186 commit ba7673f

1 file changed

Lines changed: 23 additions & 13 deletions

File tree

‎crates/tui/src/client.rs‎

Lines changed: 23 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1195,15 +1195,27 @@ impl DeepSeekClient {
11951195
if api_provider == ApiProvider::OpencodeGo {
11961196
validate_route(api_provider, &default_model).map_err(anyhow::Error::msg)?;
11971197
}
1198-
let (api_key, codex_account_id) =
1199-
if api_provider == ApiProvider::OpenaiCodex
1200-
&& !config.provider_uses_custom_endpoint(ApiProvider::OpenaiCodex)
1201-
{
1202-
let credentials = config.codex_credentials()?;
1203-
(credentials.access_token, credentials.account_id)
1204-
} else {
1205-
(config.deepseek_api_key()?, None)
1206-
};
1198+
let (api_key, codex_account_id) = if api_provider == ApiProvider::OpenaiCodex {
1199+
// The official endpoint requires Codex OAuth credentials. A custom
1200+
// endpoint prefers its own configured key, but an explicit
1201+
// `OPENAI_CODEX_ACCESS_TOKEN` still wins (`codex_credentials`
1202+
// checks env before enforcing the official-endpoint consent
1203+
// grant), so existing token-plus-custom-base-url setups keep
1204+
// working. Only when no env token exists does the custom endpoint
1205+
// fall back to the generic provider-scoped key resolver.
1206+
match config.codex_credentials() {
1207+
Ok(credentials) => (credentials.access_token, credentials.account_id),
1208+
Err(error) => {
1209+
if config.provider_uses_custom_endpoint(ApiProvider::OpenaiCodex) {
1210+
(config.deepseek_api_key()?, None)
1211+
} else {
1212+
return Err(error);
1213+
}
1214+
}
1215+
}
1216+
} else {
1217+
(config.deepseek_api_key()?, None)
1218+
};
12071219
let model_bound_secret_values =
12081220
Arc::new(configured_model_bound_secret_values(config, &api_key));
12091221
validate_base_url_security(&base_url)?;
@@ -1700,9 +1712,7 @@ fn provider_wire_format_for_config(
17001712
config: Option<&crate::config::Config>,
17011713
) -> WireFormat {
17021714
let catalog = api_provider.catalog_identity();
1703-
let wire = config
1704-
.and_then(|cfg| cfg.provider_config_for(catalog))
1705-
.and_then(|entry| entry.wire.as_deref());
1715+
let wire = config.and_then(|cfg| cfg.provider_wire_dialect(catalog));
17061716
let prefers_anthropic = matches!(
17071717
api_provider,
17081718
ApiProvider::DeepseekAnthropic
@@ -1790,7 +1800,7 @@ fn wire_config_prefers_responses(wire: Option<&str>) -> bool {
17901800
| "response-api"
17911801
| "openai-responses-compat"
17921802
| "responses-compat"
1793-
) || normalized.contains("responses")
1803+
)
17941804
}
17951805

17961806
fn api_provider_skips_models_probe(api_provider: ApiProvider) -> bool {

0 commit comments

Comments
 (0)