From 951ee86ae647207713bb7ba35ecfeebac43442f6 Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Wed, 2 Sep 2026 22:28:12 -0700 Subject: [PATCH] =?UTF-8?q?refactor(hermes=5Fcli):=20backends/custom=20?= =?UTF-8?q?=E2=80=94=20flatten=20entra=20branch,=20registry=20via=20origin?= =?UTF-8?q?,=20canonical=5Fcustom=5Fidentity=20tail=20via=20custom=5Fprovi?= =?UTF-8?q?der=5Fslug?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- hermes_cli/runtime_provider_backends.py | 21 +++++++++---------- hermes_cli/runtime_provider_custom.py | 28 ++++++++++++------------- 2 files changed, 23 insertions(+), 26 deletions(-) diff --git a/hermes_cli/runtime_provider_backends.py b/hermes_cli/runtime_provider_backends.py index bbe8c30acd..7115961c71 100644 --- a/hermes_cli/runtime_provider_backends.py +++ b/hermes_cli/runtime_provider_backends.py @@ -91,19 +91,18 @@ def _resolve_azure_foundry_runtime( if cfg_api_mode == "anthropic_messages": base_url = re.sub(r"/v1/?$", "", base_url) if cfg_auth_mode == "entra_id": + # --api-key on the CLI while config says entra_id: honour the explicit string (escape hatch + # for one-off testing). if explicit_api_key: - # --api-key on the CLI while config says entra_id: honour the explicit string - # (escape hatch for one-off testing). - api_key, source, auth_mode = explicit_api_key, "explicit", "api_key" + api_key, source, auth_mode, entra = explicit_api_key, "explicit", "api_key", {} else: - api_key, source, auth_mode = _azure_entra_credentials(cfg_entra), "entra_id", "entra_id" - clean_entra = {} - configured_scope = str(cfg_entra.get("scope") or "").strip() - if auth_mode == "entra_id" and configured_scope: - clean_entra["scope"] = configured_scope + scope = str(cfg_entra.get("scope") or "").strip() + api_key, source, auth_mode, entra = _azure_entra_credentials(cfg_entra), "entra_id", "entra_id", ( + {"scope": scope} if scope else {} + ) return rp._runtime( "azure-foundry", cfg_api_mode, base_url, api_key, - auth_mode=auth_mode, entra=clean_entra, source=source, requested_provider=requested_provider, + auth_mode=auth_mode, entra=entra, source=source, requested_provider=requested_provider, ) return rp._runtime( "azure-foundry", cfg_api_mode, base_url, _azure_foundry_api_key(rp, explicit_api_key), @@ -258,14 +257,14 @@ def _is_external_process_provider(provider: str) -> bool: if not name: return False try: - from hermes_cli.auth import PROVIDER_REGISTRY - pconfig = PROVIDER_REGISTRY.get(name) + pconfig = _rp().PROVIDER_REGISTRY.get(name) if pconfig is not None: return pconfig.auth_type == "external_process" except Exception: pass try: from providers import get_provider_profile + profile = get_provider_profile(name) except Exception: return False diff --git a/hermes_cli/runtime_provider_custom.py b/hermes_cli/runtime_provider_custom.py index f1e04c1267..442ab2eaba 100644 --- a/hermes_cli/runtime_provider_custom.py +++ b/hermes_cli/runtime_provider_custom.py @@ -136,10 +136,8 @@ def _match_new_style_provider(requested_norm: str, providers: Dict[str, Any]) -> if not base_url: continue result: Dict[str, Any] = { - "name": entry.get("name", ep_name), - "base_url": base_url.strip(), - "api_key": api_key or _clean(entry.get("api_key", "")), - "model": entry.get("default_model", ""), + "name": entry.get("name", ep_name), "base_url": base_url.strip(), + "api_key": api_key or _clean(entry.get("api_key", "")), "model": entry.get("default_model", ""), } # Command that PRINTS a short-lived credential; wrapped in a per-request token provider. key_cmd = _clean(entry.get("key_cmd", "")) @@ -310,20 +308,20 @@ def canonical_custom_identity( if not candidate_norm or candidate_norm in {"custom", "auto", "openrouter"}: return None # Only when it resolves to a configured entry — never invent a ``custom:`` resolution - # can't honor. + # can't honor. ``candidate`` may be the entry's DISPLAY NAME, not the durable identity of a + # keyed ``providers:`` entry — re-resolve via its endpoint so every path returns the same + # config-key slug. try: entry = rp._get_named_custom_provider(candidate) - if entry is not None: - # ``candidate`` may be the entry's DISPLAY NAME, not the durable identity of a keyed - # ``providers:`` entry — re-resolve via its endpoint so every path returns the same - # config-key slug. - identity = find_custom_provider_identity(str(entry.get("base_url") or "")) - if identity: - return identity - return candidate_norm if candidate_norm.startswith("custom:") else f"custom:{candidate_norm}" except Exception: - pass - return None + return None + if entry is None: + return None + try: + identity = find_custom_provider_identity(str(entry.get("base_url") or "")) + except Exception: + return None + return identity or custom_provider_slug(candidate_norm) def is_routable_provider(provider: Optional[str]) -> bool: