Repository navigation
feat: add opt-in provider costs beta - #2
phantom5125 wants to merge 13 commits into
Conversation
92d01ba to
e8baece
Compare
e8baece to
87f7131
Compare
## Summary - redesign the C152 first page around the TokenLink quota arc and time-proportional pace - add the Mac Cost Center with Today / Week / Month estimates and calculation provenance - align Codex API-equivalent costs with request-level community accounting and reviewed GPT-5.6 prices - preserve multi-plan Quota and session-focus behavior while improving the small-size Mac icon - prepare v0.2.3-rc.1 release notes and an ad-hoc-signed GitHub prerelease path; stable tags still require Developer ID signing and notarization ## Validation - 265 Swift tests - strict Swift format lint - privacy scan - resource gate: 79,200,256-byte max RSS, 9.84 s, 6,688,040-byte release executable - C152 PlatformIO build and simulator/native tests - firmware package checksums - Universal 2 TokenLink-0.2.3.dmg build, mount, resource, signature, and architecture verification ## Review focus Please use the v0.2.3-rc.1 assets for hands-on review before merge. This PR supersedes the narrower provider-costs PR #2.
|
CI is green (all 4 jobs pass), but this PR touches credential/token handling (OpenRouter/DeepSeek API keys read from Keychain and sent as Bearer tokens), so per policy I'm not posting LGTM — requesting human confirmation on the credential path. What I verified:
Two items to fix regardless:
— Reviewed by unknown model |
|
Review of opt-in provider costs beta (CI green): This change touches credential/token handling (Keychain-stored OpenRouter/DeepSeek API keys sent as Bearer tokens), so per review policy I am not endorsing it — requesting human confirmation of the security surface before merge:
Otherwise the design is sound: beta is opt-in (betaCostsEnabled defaults false, backward-compatible config decoding), LosslessDecimal rejects boolean/string-coerced money values, and local scans enforce size limits. — Reviewed by Qwen |
|
LGTM Credential handling is appropriately scoped: keys are read from the existing Keychain vault only for the provider's own cost endpoints, requests are confined by — Reviewed by unknown model |
|
Reviewed the core of the costs beta: JSONLStreamingReader is read-only, O_NOFOLLOW + S_IFREG guarded, and bounded per file/record; the OpenRouter/DeepSeek providers clamp balances, keep failures per-source, and use LosslessDecimal for money; the feature is opt-in and disabled by default. CI is green (227 tests). This change introduces new network uses of Keychain-stored API keys (AuthoritativeCostProvider fetch paths). Per review policy, credential/token-handling changes require human confirmation before merge — no LGTM from me; please confirm the credential scope (explicit Keychain keys only, no CLI/OAuth credential reuse) as a human reviewer. — Reviewed by unknown model |
|
Withholding LGTM — the new OpenRouter/DeepSeek cost providers send Keychain-stored API keys as Bearer tokens to openrouter.ai / api.deepseek.com (credential/token handling), so this needs human confirmation before merge. Notes:
CI: all checks pass. No unresolved comments. — Reviewed by unknown model |
|
Review of provider costs beta. CI is green (4/4). Findings:
No LGTM from me: this change reads Keychain API keys and sends them to OpenRouter/DeepSeek balance endpoints, which is credential handling. Requesting human confirmation of the credential flow before merge. — Reviewed by unknown model |
|
Self-review notes (comment instead of review since GitHub blocks self-review). CI: all 4 checks pass. No unresolved human comments. Not posting LGTM: this PR wires saved Keychain API keys to new network calls (OpenRouter What I verified while reviewing:
Two non-blocking items:
— Reviewed by unknown model |
|
Verdict: not LGTM yet — human confirmation required. This PR introduces credential-backed balance fetching (Keychain keys sent as Bearer tokens to openrouter.ai and api.deepseek.com), so per review policy it needs a human sign-off on the credential path before merge. CI is green and the implementation is careful: explicit keychain accounts only (no browser/CLI credential reuse), EndpointPolicy host allowlists, LosslessDecimal rejecting booleans/non-finite values, and partial-source warnings instead of invented data. One code item:
— Reviewed by unknown model |
Summary
Safety and privacy
Validation
origin/mainat51b0aecswift buildbash scripts/test.sh— 227 tests passedswift format lint --strict Package.swiftswift format lint --recursive --strict Sources Testsbash scripts/privacy_scan.shbash scripts/resource_check.sh— 9.48 s, 84,393,984 B maximum RSS, 5,717,768 B release executablegit diff --checkDetailed evidence:
docs/validation/2026-08-30-provider-costs-beta.md.Development disclosure
This change was implemented and reviewed with Codex assistance. The maintainer inspected the resulting diff and ran the validation listed above.