Commit Graph

13 Commits

Author SHA1 Message Date
teknium1
d3dcc064df fix(cli): detect ssl.SSLError by type in the Codex login hint; trim tests; add the openssl.cnf snippet to docs
- _ssl_interop_hint: also match ssl.SSLError instances (and one level of
  __cause__/__context__) plus the bare UNEXPECTED_EOF marker, so an
  SSLEOFError whose text httpx did not repeat still gets the hint. The
  hint now names the TLS 1.2 diagnostic and links the providers docs
  note instead of an issue number.
- tests: 3 -> 2 invariants (parametrized login_post/poll SSL case keeps
  the raw text + hint + cause; a plain httpx timeout gets no hint).
- docs: providers.md Codex note carries the reporter's exact openssl.cnf
  classic-groups snippet (EN + existing zh-Hans copy).

Refs #106384. The TLS max-version cap itself stays PR #44392's scope.
2026-09-09 10:14:58 -07:00
liuhao1024
d8eb177c93 fix(cli): keep SSL detail and add middlebox hint on Codex device-login transport errors
Device-login requests on networks whose middlebox rejects the larger
TLS 1.3 ClientHello sent by OpenSSL 3.5+ (post-quantum hybrid groups)
fail with SSLEOFError / handshake timeouts while curl still works, so
they masquerade as a Codex outage (#106384). The polling loop let the
raw httpx error escape unshaped, and _codex_login_post dropped the
exception chain and gave no actionable hint.

- add _ssl_interop_hint() applied to both device-login transport paths
- re-raise _codex_login_post failures with 'from exc' to preserve cause
- wrap the poll POST so transport failures become a shaped AuthError
  (device_code_poll_error) carrying the SSL detail and OPENSSL_CONF
  workaround hint; KeyboardInterrupt handling is unchanged

(cherry picked from commit 8cd94c36ce8437db5b00290b9edbedcd2116c02c)
2026-09-09 10:14:58 -07:00
Teknium
00a3cfe5c9 simplify(compat): hermes_cli split-module docstrings — drop 're-exported there' compat pointers (9 files, comments only) 2026-09-03 13:08:40 -07:00
Teknium
e83816a4d1 review-fix(comments): restore lost #NNNN rationale comments across non-test source (mechanical sweep, condensed, code unchanged)
For each issue anchor present in BASE 63279301bc non-test .py and absent on HEAD, the BASE comment/docstring block was re-attached at the HEAD location of the code it explained (matched by the distinctive code line / enclosing def). Sentences already covered by an existing HEAD comment were deduped; the issue number always survives. Insert-only: no code lines changed.
2026-09-03 09:44:26 -07:00
Teknium
45bce4faef refactor(hermes_cli): auth_codex — collapse guard ladders, reuse _codex_pool_dicts in pool sync, drop dead resp-None branches 2026-09-02 23:15:03 -07:00
Teknium
55a4b75347 refactor(hermes_cli): auth group B — squeeze body blanks, fold repeated AuthError ctor 2026-09-02 22:27:46 -07:00
Teknium
31e6c6fab4 refactor(hermes_cli): auth_nous/codex — unify refresh_nous_oauth_pure into from_state, codex login POST helper 2026-09-02 22:18:03 -07:00
Teknium
856fd5613c refactor(hermes_cli): auth group B — pack signatures, move heal notice into _HealPass 2026-09-02 21:35:49 -07:00
Teknium
34a6f963f8 refactor(hermes_cli): auth_nous/codex/device_flow/oauth_grants — AST-neutral layout compaction 2026-09-02 21:02:27 -07:00
Teknium
c86e74550a refactor(hermes_cli): auth_codex — dedupe pool reads, reuse _parse_absolute_timestamp, collapse guards 2026-09-02 20:30:06 -07:00
Teknium
7b30652d8f refactor(auth): explicit-config check table, _store_section helper, docstring repairs, move orphaned section comments to their modules 2026-09-02 16:20:00 -07:00
Teknium
c990225fa0 refactor(auth): relocate single-consumer helpers next to their users; _decode_jwt_claims to constants leaf 2026-09-02 16:09:47 -07:00
Teknium
2abf70aa90 refactor(auth): split Spotify, Codex, xAI and MiniMax OAuth flows into per-provider modules 2026-09-02 15:29:14 -07:00