Commit Graph

18 Commits

Author SHA1 Message Date
can1357 7f9a2777f9 Merge PR #5170: fix(ai): scope Anthropic credential identity by organization, not just email (@chan1103) 2026-07-14 18:29:14 +02:00
can1357 6bb0878b63 feat(ai): added cache invalidation command for usage reports
- Added an `invalidate` action to the usage CLI to clear cached usage reports for specific or all providers.
- Updated `invalidateUsageCache` in `AuthStorage` to be asynchronous and notify the underlying store of invalidations.
2026-07-11 20:55:19 +02:00
chan1103 e095af3be0 fix(ai): require member identity within a shared org for report routing, overlays, and coverage
Codex review round 7 on e90a72bdd flagged that broker usage-report
matching, header-overlay keying, and omp-usage coverage all treated a
matching organization as a sufficient match. Two Team members share the
org id while drawing on per-user pools, so the first same-org report
(or a lone sibling report) was handed to the wrong member. The org is
now a gate: within the same-org subset the member's own base identity
(account/email/project) must still match, with org-only entities (no
base identifiers) matching on the org alone when unambiguous. The
overlay merger (findMatchingReportIndex) had the identical same-org
flaw and receives the symmetric fix. Org-presence-mismatch semantics
are unchanged: org-scoped vs org-less stays fall-through/unreported,
and both-org-less keeps the legacy base-identity fallback.
2026-07-11 22:49:12 +09:00
chan1103 c2456d882f fix(ai): org-qualify account/project fallback identities; org-decisive routing on either side
Addresses the fourth review round (Codex no-email finding on d37e3992c,
confirmed and scoped by internal review):

- resolveProviderCredentialIdentityKey: the anthropic org qualifier now
  rides on whichever base identity exists (email > account > project),
  not only email. The account UUID is identical across the orgs of one
  login account, so the bare account fallback let a second subscription
  replace the first whenever the email could not be recovered (token
  response omits it AND bootstrap fails). Org-only credentials key on
  the org alone instead of losing identity entirely.
- matchesReplacementCredential: the one-way legacy claim strips a
  trailing |org: from ANY anthropic base key (account/project included);
  only anthropic keys carry the qualifier, so other providers are
  unaffected.
- Usage-report dedupe falls back to the org-qualified account for
  no-email anthropic reports instead of returning no identifiers.
- Broker report/overlay routing (matchUsageReport/findMatchingReportIndex)
  is org-decisive on EITHER side: an org-less legacy credential no longer
  receives an org-attributed sibling's pool via the lone-candidate or
  email/account fallback, and an org-less overlay only merges into
  org-less reports.
- omp usage unreported-account attribution follows the same either-side
  rule, so a legacy row whose fetch failed surfaces as 'no usage data'
  instead of being hidden by a sibling's report.
- Regression tests: no-email identity coexistence/replace/claim, no-email
  report dedupe, org-less broker routing, either-side unreported
  attribution.
2026-07-11 22:49:12 +09:00
chan1103 044d722a36 fix(ai): scope Anthropic credential identity by organization
One Anthropic account email can hold multiple organizations (a Team seat
plus a personal Max plan), each with its own org-scoped OAuth token and
independent 5h/7d limit pools. Credentials were deduped by bare email, so
logging in with the second subscription silently replaced the first, and
usage reports from the two pools merged into one row with mixed numbers.

- capture organization uuid/name at login (token exchange response, with
  a claude_cli/bootstrap fallback); token refreshes never rewrite it
- key anthropic credential identity as email + org; a legacy email-keyed
  row is claimed in place by the first org-scoped login with the same
  email, and org-less credentials never clobber org-scoped rows
- partition usage-report dedupe and the per-credential usage cache by
  org so the two subscriptions' limit pools stay distinct for rotation
- show the organization in omp usage (redaction-safe) and name the
  stored account/org in the login success message
2026-07-11 22:49:12 +09:00
can1357 8c648e4d02 fix(cli): enabled consistent reporting for sibling provider limits
- Added collectProviderLimitTemplates to aggregate limit IDs across all reports.
- Updated formatUsageBreakdown to render placeholders for limits missing from specific providers.
- Standardized label widths across sibling providers to align status bars.
2026-07-03 04:53:28 +02:00
can1357 a515c24735 Fix Codex reset expiry integration 2026-06-27 01:39:33 +02:00
can1357 393d068a22 Merge PR #3343: feat(usage): show expiry dates for banked Codex resets (@oldschoola) 2026-06-27 01:39:33 +02:00
can1357 3e1d5fce12 feat(coding-agent): filtered out non-reportable accounts in usage CLI
- Add `usageProviderFor` helper to `AuthStorage` to distinguish between providers without usage endpoints and missing data.
- Implement account filtering in the usage CLI to exclude providers that do not support usage reporting unless explicitly requested.
- Improve CLI diagnostic messages when no usage data is retrieved by differentiating between missing credentials and unsupported providers.
2026-06-25 04:44:36 +02:00
oldschoola cbbdfda2ce fix: normalize tabs in usage notes rendering
Address P2 review: sanitizeText preserves \t which can create visual
holes in rendered output. Add .replace(/\t/g, '  ') to provider-wide
and per-limit notes in usage-report.ts and usage-cli.ts, matching the
TUI path which already uses replaceTabs().
2026-06-23 16:02:26 -07:00
oldschoola 04c3199511 fix(usage): normalize newlines in provider notes before rendering
sanitizeText preserves newlines (\n) which break TUI line layout when
injected into a single rendered row. All notes rendering sites now
replace \r\n sequences with spaces before sanitization:

- command-controller.ts: provider-wide notes (line 1591) + per-group
  notes (line 1666)
- usage-report.ts: provider-wide notes (line 58) + per-limit notes
  (line 90, previously completely unsanitized)
- usage-cli.ts: provider-wide notes (line 455)
2026-06-23 16:02:26 -07:00
oldschoola 12511ca004 fix(usage): sanitize provider notes in usage-report and usage-cli
Apply sanitizeText to provider notes in the shared usage-report
renderer and the CLI usage output, matching the sanitization added
to command-controller.ts. Prevents tabs/newlines/control characters
in provider notes from breaking terminal rendering.
2026-06-23 16:02:25 -07:00
oldschoola 6c3f35dfef fix(usage): dedup provider-wide notes and add report-level notes field
Provider-wide disclaimers (e.g. OpenCode Go's "OMP-observed spend
only") were duplicated onto every UsageLimit, then repeated N times
in the TUI aggregate renderer (once per account × window). With
2 accounts × 3 windows, the same disclaimer appeared 6 times
bullet-joined.

Structural fix:
- Add notes?: string[] to UsageReport (interface + both schema
  copies: usage.ts and auth-broker/wire-schemas.ts) so the field
  survives the broker client's "+": "reject" deserialization gate.
- Move opencode-go's disclaimer from per-limit notes to
  provider-level notes.

Defensive fix:
- Dedup identical per-limit notes in the TUI aggregate renderer
  (command-controller.ts) via [...new Set(...)].
- Render provider-level notes once above per-account sections in
  all three rendering paths: TUI (command-controller), CLI
  (usage-cli), and ACP (usage-report helper).

Regression tests:
- usage-cli.test.ts: provider-level notes render once, not
  duplicated per account or limit; positioned above per-account rows.
- usage-report-notes-schema.test.ts: wire-schema round-trip proving
  notes survives usageResponseSchema validation.

Fixes #3268
2026-06-23 16:02:25 -07:00
oldschoola 639b6195fa feat(usage): show expiry dates for banked Codex rate-limit resets (#3339)
The /usage display (TUI, ACP text, and omp usage CLI) now shows when
banked Codex rate-limit resets expire, so users can plan when to redeem
them before the 30-day window lapses.

Changes:
- Added UsageResetCreditDetail interface (grantedAt, expiresAt, status)
  and optional credits field to UsageResetCredits in packages/ai
- Updated both ArkType schema copies (usage.ts + wire-schemas.ts)
- The OpenAI Codex usage provider now calls listCodexResetCredits to
  fetch individual credit details when availableCount > 0, filtering
  out redeemed credits. Errors are logged and swallowed (graceful
  degradation: count shows without expiry dates)
- TUI (command-controller.ts): shows per-credit expiry as relative time
  + absolute date under each account line
- ACP text (usage-report.ts): same per-credit expiry rendering
- CLI (usage-cli.ts): shows the soonest expiry date in the account header
- 2 new tests: credit detail fetching with expiry dates, and no extra
  API call when availableCount is 0
2026-06-23 11:58:29 -07:00
can1357 579a005a04 feat(ai): added usage history tracking and trend reporting for account limits
- Added usage snapshot persistence in sqlite with hour-bucket upsert behavior.
- Added listUsageHistory query support with optional provider and sinceMs filters.
- Added usage CLI history mode with `--history` and `--days` and trend rendering.
- Added changelog documentation for usage trend inspection and no-history exit behavior.
2026-06-12 05:27:59 +02:00
can1357 212e05dbbb feat: added Codex saved reset-credit redemption flow to usage tooling
- Added Codex reset-credit models, endpoints, and redemption methods.
- Added reset-credit usage data and cache invalidation for successful redemption.
- Added `/reset-usage` slash command and interactive account selector flow.
- Added contract tests for reset-credit listing, fallback, and consume outcomes.
2026-06-12 05:20:08 +02:00
can1357 1610882151 ux(coding-agent/cli): updated usage CLI to report per-window quota capacity remaining
- Updated usage-window reporting to track remaining account quota instead of required-account counts.
- Replaced the computed "needed" metric with a non-negative remaining-quota value derived from each window's total minus used fraction.
- Changed usage output lines from "need" to "capacity" and now show used/total accounts with remaining quota multiplier.
2026-06-10 04:39:57 +02:00
can1357 dbbf7ffac5 feat(cli): added per-account omp usage reporting with provider/json/redact flags
- Added per-account usage reporting in the `omp usage` command.
- Added `provider`, `json`, and `redact` options to customize usage output.
- Updated CLI wiring to route usage commands to the new per-account behavior.
2026-06-10 01:21:57 +02:00