mirror of
https://github.com/openclaw/openclaw.git
synced 2026-07-25 18:51:12 +00:00
95 lines
3.1 KiB
TypeScript
95 lines
3.1 KiB
TypeScript
/**
|
|
* Auth-profile forwarding shared by normal and narrow CLI-backed agent runs.
|
|
*/
|
|
import type { OpenClawConfig } from "../config/types.openclaw.js";
|
|
import { resolveAuthProfileOrder } from "./auth-profiles/order.js";
|
|
import { loadAuthProfileStoreForRuntime } from "./auth-profiles/store.js";
|
|
import { resolveCliBackendConfig } from "./cli-backends.js";
|
|
|
|
const GOOGLE_GEMINI_CLI_PROVIDER_ID = "google-gemini-cli";
|
|
const GOOGLE_PROVIDER_ID = "google";
|
|
|
|
type CliExecutionAuthProfileSelection = {
|
|
authProfileId?: string;
|
|
authProfileIdSource?: "auto" | "user";
|
|
};
|
|
|
|
export function cliBackendAcceptsAuthProfileForwarding(params: {
|
|
provider: string;
|
|
config: OpenClawConfig;
|
|
agentId?: string;
|
|
}): boolean {
|
|
const backend = resolveCliBackendConfig(params.provider, params.config, {
|
|
agentId: params.agentId,
|
|
});
|
|
return backend?.id === GOOGLE_GEMINI_CLI_PROVIDER_ID;
|
|
}
|
|
|
|
/**
|
|
* Resolve the profile a CLI backend may consume. Gemini CLI prefers its own
|
|
* OAuth identity, then bridges a canonical Google API key when that model is
|
|
* explicitly routed through the CLI runtime. A user-locked profile must fail
|
|
* closed here; falling through would silently run the request as another user.
|
|
*/
|
|
export function resolveCliExecutionAuthProfileId(params: {
|
|
cliExecutionProvider: string;
|
|
authProfileProvider: string;
|
|
config: OpenClawConfig;
|
|
agentDir: string;
|
|
selected?: CliExecutionAuthProfileSelection;
|
|
}): string | undefined {
|
|
const store = loadAuthProfileStoreForRuntime(params.agentDir, {
|
|
readOnly: true,
|
|
allowKeychainPrompt: false,
|
|
externalCliProviderIds: [params.cliExecutionProvider],
|
|
});
|
|
const selectedAuthProfileId = params.selected?.authProfileId?.trim();
|
|
if (selectedAuthProfileId) {
|
|
const credential = store.profiles[selectedAuthProfileId];
|
|
if (credential?.provider === params.cliExecutionProvider) {
|
|
return selectedAuthProfileId;
|
|
}
|
|
if (
|
|
params.cliExecutionProvider === GOOGLE_GEMINI_CLI_PROVIDER_ID &&
|
|
credential?.provider === GOOGLE_PROVIDER_ID &&
|
|
credential.type === "api_key" &&
|
|
params.selected?.authProfileIdSource !== "auto"
|
|
) {
|
|
return selectedAuthProfileId;
|
|
}
|
|
if (params.selected?.authProfileIdSource !== "auto") {
|
|
if (!credential) {
|
|
throw new Error(`No credentials found for profile "${selectedAuthProfileId}".`);
|
|
}
|
|
throw new Error(
|
|
`CLI backend "${params.cliExecutionProvider}" cannot use auth profile "${selectedAuthProfileId}" owned by "${credential.provider}".`,
|
|
);
|
|
}
|
|
}
|
|
|
|
const cliProfileId = resolveAuthProfileOrder({
|
|
cfg: params.config,
|
|
store,
|
|
provider: params.cliExecutionProvider,
|
|
})[0];
|
|
if (cliProfileId) {
|
|
return cliProfileId;
|
|
}
|
|
|
|
if (
|
|
params.cliExecutionProvider !== GOOGLE_GEMINI_CLI_PROVIDER_ID ||
|
|
params.authProfileProvider !== GOOGLE_PROVIDER_ID
|
|
) {
|
|
return undefined;
|
|
}
|
|
|
|
return resolveAuthProfileOrder({
|
|
cfg: params.config,
|
|
store,
|
|
provider: GOOGLE_PROVIDER_ID,
|
|
}).find((profileId) => {
|
|
const credential = store.profiles[profileId];
|
|
return credential?.provider === GOOGLE_PROVIDER_ID && credential.type === "api_key";
|
|
});
|
|
}
|