The Sep 2026 decomposition (PR #102117) makes internal import paths a non-API: names now live in the focused modules that define them. This commit is the ONLY thing keeping the old paths alive, so external plugins have time to update. It is deliberately a single, unsquashed commit: git revert <this sha> removes every shim, stub and manifest at once on the announced date. Nothing in-tree may depend on these pointers: scripts/check_compat_pointers.py (wired into lint.yml) fails CI if it does. What it adds (see COMPAT_MANIFEST.md, compat_manifest.json): - 332 facade modules get one delimited `PLUGIN-COMPAT` block appended at the end of the file - 1,172 moved names resolved lazily via a module `__getattr__` (PEP 562) — never a top-level import, so no import cycles; facades that already had `__getattr__` get a chained one - 592 third-party/stdlib names the old modules used to expose, with their original import statements - 266 public definitions that had been deleted as unused, restored byte-for-byte from the pre-decomposition tree (+40 private helpers and 16 imports pulled in only because a restored definition needs them) - 3 deleted modules recreated as re-export stubs (gateway/startup_watchdog, hermes_cli/observability/ relay_runtime, tools/environments/modal_utils) - private names (`_x`) get no pointer: they were never API (3,792 skipped) Verified: all 335 touched modules import under a fresh HERMES_HOME and every manifest name resolves; the lint reports zero in-tree uses; ruff clean; targeted suites unchanged.
63 lines
2.6 KiB
Python
63 lines
2.6 KiB
Python
"""ACP auth helpers — detect and advertise Hermes authentication methods."""
|
|
|
|
from __future__ import annotations
|
|
|
|
from typing import Any, Optional
|
|
|
|
|
|
TERMINAL_SETUP_AUTH_METHOD_ID = "hermes-setup"
|
|
|
|
|
|
def detect_provider() -> Optional[str]:
|
|
"""Resolve the active Hermes runtime provider, or None if unavailable.
|
|
|
|
A callable ``api_key`` (Azure Foundry Entra ID bearer-token provider, see
|
|
:mod:`agent.azure_identity_adapter`) counts as a valid credential; otherwise
|
|
Entra-configured Foundry deployments would default to ``"openrouter"`` and
|
|
the ACP auth handshake would reject the legitimate provider."""
|
|
try:
|
|
from hermes_cli.runtime_provider import resolve_runtime_provider
|
|
runtime = resolve_runtime_provider()
|
|
api_key, provider = runtime.get("api_key"), runtime.get("provider")
|
|
if isinstance(provider, str) and provider.strip() and (
|
|
(isinstance(api_key, str) and api_key.strip()) or callable(api_key)):
|
|
return provider.strip().lower()
|
|
except Exception:
|
|
pass
|
|
return None
|
|
|
|
|
|
def build_auth_methods() -> list[Any]:
|
|
"""Return registry-compatible ACP auth methods for Hermes.
|
|
|
|
The ACP registry requires at least one usable auth method in the initial
|
|
handshake. A fresh Zed install may have no Hermes credentials yet, so the
|
|
terminal setup method is always advertised; when credentials resolve, the
|
|
provider is also advertised as the default agent-managed runtime method."""
|
|
from acp.schema import AuthMethodAgent, TerminalAuthMethod
|
|
|
|
methods: list[Any] = []
|
|
provider = detect_provider()
|
|
if provider:
|
|
methods.append(AuthMethodAgent(
|
|
id=provider, name=f"{provider} runtime credentials",
|
|
description=f"Authenticate Hermes using the currently configured {provider} runtime credentials.",
|
|
))
|
|
methods.append(TerminalAuthMethod(
|
|
id=TERMINAL_SETUP_AUTH_METHOD_ID, name="Configure Hermes provider", type="terminal", args=["--setup"],
|
|
description=("Open Hermes' interactive model/provider setup in a terminal. "
|
|
"Use this when Hermes has not been configured on this machine yet."),
|
|
))
|
|
return methods
|
|
|
|
|
|
# ---- BEGIN PLUGIN-COMPAT (revert-scheduled; see COMPAT_MANIFEST.md) ----
|
|
# Names external plugins imported from this module before the Sep 2026 decomposition.
|
|
# Internal code MUST NOT use these (scripts/check_compat_pointers.py fails CI if it does).
|
|
# The whole block is removed by reverting the commit that added it.
|
|
|
|
def has_provider() -> bool:
|
|
"""Return True if Hermes can resolve any runtime provider credentials."""
|
|
return detect_provider() is not None
|
|
# ---- END PLUGIN-COMPAT ----
|