Skip to content

fix: doctor/exit-code bugs, npx-cache warning, add key wizard (0.1.4) - #10

Merged
ctrlcakepro merged 2 commits into
mainfrom
release/0.1.4-key-wizard-and-bugfixes
Sep 18, 2026
Merged

ctrlcakepro merged 2 commits into
mainfrom
release/0.1.4-key-wizard-and-bugfixes

Conversation

@ctrlcakepro

@ctrlcakepro ctrlcakepro commented Sep 18, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Fix doctor reporting configuration.ready/credentials_ready: true while embedding.base_url/model were still the install template's placeholder values.
  • Fix the CLI entrypoint always exiting 0 — main()'s return value (notably doctor's pass/fail code) was never applied to process.exitCode.
  • Warn when chilon-recall qoder is run from an npx temporary cache, since the generated .qoder/mcp.json embeds that ephemeral path.
  • Add chilon-recall key: hidden-input provider API key prompt that queries /models and suggests embedding/reranker models plus ready-to-run env var commands.
  • Release 0.1.4: bump package/plugin/Python distribution/server version and update pinned npx examples in both READMEs.

Follow-up fixes (this update)

Found by a code review of the key wizard added above:

  • Paste hung the wizard permanently (P0): raw-mode stdin delivers a whole pasted clipboard chunk as one data event, not one event per character. promptSecret's switch only matched single-character strings, so any paste containing a newline (trailing or embedded) fell into default, got spliced into the value, and never resolved or rejected. Now iterates per character so paste behaves like typing.
  • Plaintext key could leak into an error message (P1): a key with an embedded newline made Headers.append throw with the raw key quoted in its own message, which was wrapped straight into the thrown error — leaking the key models.mjs promises is "never ... logged, or echoed back", and mislabeling a bad-credential problem as a network failure. Now validated before the request is made, with a redaction fallback for anything that still slips through.
  • Reranker could be recommended as the embedding model: reranker names matching an embedding hint (e.g. bge-reranker-large matching /bge/i) landed in both buckets; suggestedEmbeddingModel could then pick a reranker. Rerank matches are now excluded from the embedding bucket.
  • Wizard's "never writes the key to a file" note undersold the persistent commands: setx/>> ~/.bashrc do write the plaintext key (registry / disk) if the user runs them, and land in shell history/scrollback regardless. Added an explicit note.
  • base_url could double-concatenate its suffix: a base_url already ending in /embeddings (Python) or /models (Node) no longer gets the suffix appended twice.
  • Raw ZodError JSON reached users: ZodError#message is a JSON dump of .issues; an extra/typo'd config key surfaced that raw dump through MCP tool errors and doctor's report. Added describeConfigError to render it as a sentence.
  • setup/install looked hung: engine setup (venv + pip install) ran silently for up to a minute. Phase announcements and the underlying process output now stream to stderr live, while stdout keeps its single-JSON-object contract for scripts.

Test plan

  • npm test — 46 Node tests + 9 Python tests pass (13 new: paste/newline handling, key redaction, rerank/embedding overlap, URL double-concat, ZodError formatting, setup progress plumbing)
  • Manually ran chilon-recall setup end-to-end: confirmed stdout stays a single clean JSON object while stderr streams live phase/pip output

…e 0.1.4

- Fix `doctor` reporting configuration/credentials as ready while
  embedding.base_url/model were still the install template's
  placeholder values.
- Fix the CLI entrypoint always exiting 0: main()'s return value
  (notably doctor's pass/fail code) was never applied to
  process.exitCode, so scripted checks against the exit code always
  saw success.
- Warn when `chilon-recall qoder` is run from an npx temporary cache,
  since the generated .qoder/mcp.json embeds that ephemeral path and
  breaks silently on the next cache clear or version bump.
- Add `chilon-recall key`: a hidden-input prompt for a provider API
  key that calls the provider's /models endpoint, suggests an
  embedding and reranker model, and prints ready-to-run env var
  commands. The key is used for a single request and never written
  to disk.
- Bump package/plugin/Python distribution/server version to 0.1.4 and
  update the pinned npx examples in both READMEs.
…ZodError output, silent setup

- secretPrompt: onData treated a whole pasted chunk as one character, so a
  paste with any newline (trailing or embedded) fell into the default case
  and hung forever instead of resolving/rejecting. Iterate per character.
- models: a header-unsafe key (e.g. one with an embedded newline) made
  Headers.append throw with the raw key embedded in its own message, which
  was then wrapped straight into the thrown error, leaking the plaintext
  key and mislabeling the failure as a network problem. Validate the key
  before ever calling fetch, and redact it from any error that still slips
  through.
- models: reranker model names matching /bge/i etc. also landed in the
  embedding bucket, so recommendModels could suggest a reranker as the
  embedding model. Exclude rerank matches from the embedding bucket first.
- keyWizard: the "persists" commands (setx / >> ~/.bashrc) write the
  plaintext key to the registry/disk if the user runs them, and land in
  shell history/scrollback either way; the notes didn't say so.
- providers.py / models.mjs: a base_url that already ends with the target
  suffix (e.g. "/embeddings") no longer gets it appended twice.
- config: ZodError#message is a JSON dump of its issues; that was surfacing
  verbatim in MCP tool errors and doctor's report for something as
  ordinary as a typo'd config key. Added describeConfigError to turn it
  into a sentence.
- runtime/cli: setupEngine (venv + pip install) ran silently for up to a
  minute with zero output, looking hung. Stream phase announcements and
  the underlying process output to stderr, keeping stdout's single-JSON
  contract intact.
@ctrlcakepro
ctrlcakepro merged commit db998c6 into main Sep 18, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant