- Routed native xAI Responses search through configured provider base URLs and headers.
- Kept endpoint credentials coupled and rejected official OAuth tokens for custom endpoints.
- Added proxy routing and credential-leak regression coverage.
Fixes#5599
Move bundled models, model cache/manager, thinking metadata, effort helpers,
provider descriptors/discovery, wire constants, and model identity utilities
into the new @oh-my-pi/pi-catalog package.
Update pi-ai to keep provider runtime/auth concerns, move catalog provider
metadata into CATALOG_PROVIDERS, and migrate coding-agent, agent, stats, docs,
and tests to import catalog values from pi-catalog.
Split coding-agent model registry helpers into discovery, roles, and models
config modules while preserving registry orchestration.
BREAKING CHANGE: @oh-my-pi/pi-ai no longer exports catalog subpaths such as
/models, /model-cache, /model-manager, /model-thinking, /effort,
/provider-models*, discovery helpers, and provider wire constants; use the
matching @oh-my-pi/pi-catalog subpaths instead.
- Added check to avoid returning DEFAULT_BASE_URL when a custom provider base URL is configured.
- Passed resolvedModel argument to resolveXAIHttpCredentials call in image generation tool.
resolveXAIHttpCredentials honored only \$env.XAI_BASE_URL — every
per-model baseUrl pin (models.yml model.baseUrl) and every provider-
level override (providers.xai-oauth.baseUrl) was silently bypassed for
image and TTS HTTP requests, even when the chat path went through the
override correctly via Model.baseUrl on the Responses request.
Add resolveXAIBaseURL: (1) per-model override when merged.baseUrl
diverges from the bundled default, scoped to (provider, id) so xai and
xai-oauth entries with the same id don't cross-route, (2) provider-level
baseUrl from ModelRegistry.getProviderBaseUrl, (3) XAI_BASE_URL env,
(4) DEFAULT_BASE_URL. resolveXAIHttpCredentials takes an optional
modelId; probes pass undefined and fall through to env/default.
Op: correct
Restores: ref:feat/xai-grok-oauth@2c1abd7fa
The cross-provider env fallback (stream.ts: "xai-oauth" → XAI_OAUTH_TOKEN
|| XAI_API_KEY) lets an XAI_API_KEY-only setup silently satisfy the
xai-oauth credential branch in resolveXAIHttpCredentials. Once the
helper enters that branch it resolves baseURL under xai-oauth instead of
xai, bypassing providers.xai.baseUrl overrides for image/TTS traffic.
Add AuthStorage.hasNonEnvCredential — hasAuth minus the env-fallback
leg — and gate the xai-oauth branch on (dedicated credential source ||
$env.XAI_OAUTH_TOKEN). The XAI_API_KEY borrow now falls through to the
xai branch, preserving back-compat while restoring provider-level
baseUrl precedence for users with a dedicated xai-oauth source.
Op: correct
Restores: ref:feat/xai-grok-oauth@015437534
Five symbols in packages/ai/src/utils/oauth/xai-oauth.ts were exported
but only consumed inside the file itself:
- xaiOAuthDiscovery (used 3x internally)
- XAIOAuthDiscovery (return type of xaiOAuthDiscovery)
- buildXAIAuthorizeUrl (used 1x internally)
- BuildXAIAuthorizeUrlOptions (arg type of buildXAIAuthorizeUrl)
One symbol was both exported and fully unused (zero internal or external
references, no test coupling): XAI_ACCESS_TOKEN_REFRESH_SKEW_SECONDS.
The accompanying comment claimed it was 'used by AuthStorage to refresh
ahead of expiry' but no such call exists; AuthStorage uses the standard
5-minute client-skew baked into the OAuthCredentials.expires field via
ACCESS_TOKEN_CLIENT_SKEW_MS.
packages/coding-agent/src/lib/xai-http.ts exported XAICredentials, but
no consumer imports the type by name (callers use type-inference from
resolveXAIHttpCredentials' return type). Unexporting it keeps the
public surface minimal.
bun check baseline 53 errors preserved; bun test xai-oauth 9/9 passing.
Op: compress
Adds packages/coding-agent/src/lib/xai-http.ts: a shared credential
resolver used by image generation (this commit) and TTS (next commit).
Tries the xai-oauth SuperGrok token first via
ModelRegistry.getApiKeyForProvider (refresh cascade lives there);
falls back to XAI_API_KEY. Ported from NousResearch/hermes-agent (MIT).
Extends imageGenTool with a "xai" provider branch that POSTs to
https://api.x.ai/v1/images/generations with the Grok Imagine surface:
grok-imagine-image (default, $0.02/image) or
grok-imagine-image-quality ($0.05/image). Aspect ratios 1:1, 16:9,
9:16, 4:3, 3:4, 3:2, 2:3. Resolutions 1k/2k. Decoded via the existing
saveImagesToTemp helper — no new image-handling code paths.
Op: extend
- Removed voice control and TTS features from coding-agent package.
- Removed git tool integration and worktree management from coding-agent.
- Deleted entire git-tool package and all git operations.
- Inlined OpenAI Codex prompt utilities and removed provider exports.
- Fixed OAuth callback flows for GitHub Copilot and Google Gemini to handle cancellation and manual input errors.
- Hardened database file permissions to 0o600 and directory creation to 0o700 to prevent credential leakage.
- Fixed cache invalidation for streaming edits and file existence checks for prompt templates.
- Fixed bash output streaming to prevent premature closure and LSP client request handling for aborted signals.
- Reformatted code indentation and spacing across multiple TypeScript files.
- Standardized export statements to single-line format in various modules.
- Fixed async/await precedence and corrected indentation in benchmark files.
- Added benchmark report files for GPT-5.1-codex-mini model performance.
- Added in-memory session storage abstraction with SessionStorage interface and MemorySessionStorage implementation.
- Added configurable bash interceptor rules with pattern-based command interception settings.
- Added AbortSignal support to 80+ web scrapers for request cancellation.
- Changed task tool to require explicit task `id` field and single `agent` parameter at top level.
- Removed `submit_review` tool - reviewers now use `complete` tool with structured output.
- Replaced Date.now() and crypto.randomUUID() with nanoid() for unique ID generation throughout codebase.
- Changed multi-task display to show task descriptions instead of agent names when available.
- Fixed indentation in worktree constants module for consistency.
- Added new @oh-my-pi/pi-git-tool package with 22 git operations, safety guards, caching, and GitHub CLI integration.
- Added /wt slash command for git worktree management with create, list, merge, remove, spawn, and parallel operations.
- Added worktree library with collapse strategies (simple, merge-base, rebase) and session tracking for agent tasks.
- Added structured git tool with TypeBox schema exposing gitTool and createGitTool from SDK.
- Added safety policies blocking force push to protected branches and warning on destructive operations.