- Migrated 288 lines of scattered error classification logic from `utils/error-id.ts` into a cohesive `packages/ai/src/error/` module with 13 specialized submodules covering flags, classes, OAuth, providers, rate-limiting, and finalization.
- Replaced 100+ generic `Error` throws across 60+ provider and registry files with semantic `AIError.*` classes (e.g., `AIError.MissingApiKeyError`, `AIError.OAuthError`, `AIError.ProviderResponseError`), improving error diagnostics and retry logic.
- Consolidated error utility imports from `pi-utils` and scattered classification functions into a single `AIError` namespace, reducing coupling and simplifying error handling across all packages.
Reconcile the friendlyName secret feature with upstream's secret-obfuscation
refactor (7302a7ae96):
- obfuscator.ts: keep upstream's typed message-transformer layer
(deobfuscateAgentMessages/AssistantContent/ToolArguments, obfuscateMessages,
narrow obfuscateProviderContext, obfuscateToolArguments, mapJsonStrings) as
the canonical API; retain the PR's SecretObfuscator class internals
(friendlyName + keyed-hash placeholders, case hints, legacy aliases,
idempotent re-obfuscation, replace-mode hardening).
- Integrate upstream's <8-char secret toning + hasRealSec into the class.
- Thread allowLegacyAliases through the typed deobfuscation transformers so
display-only transcripts still restore legacy index-derived aliases while
agent-feeding paths stay keyed-only.
- Lengthen friendlyName test secrets to >=8 chars to satisfy toning; tool-result
content is no longer deobfuscated (typed transformers walk assistant/summary
roles only).
- Refined obfuscation logic to use granular, typed transformations instead of generic object traversal.
- Enforced an 8-character minimum for secret patterns and restricted redaction to user-authored content to prevent false positives.
- Preserved system prompts, tool schemas, and opaque remote replay data to maintain provider context and data integrity.
- Integrated protected snapshot exports with targeted redaction to safeguard sensitive information in shared sessions.
Move bundled models, model cache/manager, thinking metadata, effort helpers,
provider descriptors/discovery, wire constants, and model identity utilities
into the new @oh-my-pi/pi-catalog package.
Update pi-ai to keep provider runtime/auth concerns, move catalog provider
metadata into CATALOG_PROVIDERS, and migrate coding-agent, agent, stats, docs,
and tests to import catalog values from pi-catalog.
Split coding-agent model registry helpers into discovery, roles, and models
config modules while preserving registry orchestration.
BREAKING CHANGE: @oh-my-pi/pi-ai no longer exports catalog subpaths such as
/models, /model-cache, /model-manager, /model-thinking, /effort,
/provider-models*, discovery helpers, and provider wire constants; use the
matching @oh-my-pi/pi-catalog subpaths instead.
- Fixed root `cli --help` startup by preventing the config/model-registry initialization cycle.
- Extracted config validation, migration, and loading logic from config.ts into config/config-file.ts.
- Added ConfigFile helpers for migration, validated JSON/JSONC/YAML loading, status caching, and reset.
- Added a regression test that runs `cli.ts --help` with temp HOME/XDG env paths and expects exit code 0.