Compare commits

...

15 Commits

Author SHA1 Message Date
ls ed81178ad7 Merge pull request #118 from modelstudioai/feat/config-ui-enhancements
Feat/config UI enhancements (本地配置管理面板能力增强)
2026-07-31 00:30:32 +08:00
lisheng.lisheng 7e23ba00fb chore(release): 发布 v1.13.0 版本
- 增加 `bl config ui` 功能,支持技能、MCP、代理和资产清单浏览与管理
- 新增模型目录建议芯片,方便配置 UI 中快速填充模型名
- 实现配置文件的 Profile 磁贴网格展示及新增弹窗
- 优化配置 UI 布局,增强响应式布局和编辑体验
- 修复软链接技能目录识别问题
- 支持基于环境变量的配置文件路径及旧版配置方案
- 同步更新相关包版本至 1.13.0
2026-07-31 00:21:51 +08:00
lisheng.lisheng 2c53b0692b refactor(inventory): 优化技能与代理配置代码格式和检测逻辑
- 统一代码格式,增加多处代码块的换行和缩进保持一致
- 调整技能安装目标列表的格式,提升可读性
- 修复解压缩逻辑中异常抛出格式,增强异常信息规范
- 优化归一化文件名过滤条件表达式格式
- 修改配置文件检测逻辑,兼容环境变量和旧版配置方案
- 增强对 Bailian 相关模型提供者的检测逻辑支持
- 规范代理详情字段生成方法的代码风格
- 调整 MCP 写回相关函数的格式,提升可维护性
- 改进技能和代理详情函数参数格式,统一参数拆分显示
- 修复单元测试中路径和 JSON 写入格式,增加不同配置场景测试覆盖
- 确保软链接技能目录被正确识别为安装来源
- 增加多代理配置文件和技能安装的检测测试用例,提升测试精准度
2026-07-28 20:51:07 +08:00
lisheng.lisheng adc89f635d Merge branch 'main' of github.com:modelstudioai/cli into feat/config-ui-enhancements
# Conflicts:
#	packages/commands/tests/config-ui.test.ts
2026-07-28 20:43:42 +08:00
ls afa43a42b9 Merge pull request #128 from modelstudioai/feat/config-agent-fix
feat(config-agent): align agent writers, add --key/--region, prepare 1.12.0
2026-07-28 20:39:56 +08:00
lisheng.lisheng bbf45a5961 Merge branch 'main' of github.com:modelstudioai/cli into feat/config-agent-fix
# Conflicts:
#	CHANGELOG.md
#	CHANGELOG.zh.md
#	packages/cli/package.json
#	packages/commands/package.json
#	packages/core/package.json
#	packages/kscli/package.json
#	packages/runtime/package.json
#	skills/bailian-cli/SKILL.md
2026-07-28 20:33:16 +08:00
lisheng.lisheng 3988e701e1 chore(cli): 发布 1.11.0 版本,更新 agent 配置功能
- 新增 `bl config agent --key` / `--region`,支持控制台编码 API Key 本地解码和区域派生 Token Plan 地址
- 新增 `bl config agent --context-window`,设置 OpenClaw 配置的上下文窗口大小,默认 256000
- 新增 `bl config agent --wire-api`,支持选择 Codex 配置的通信协议,兼容旧版 chat 协议并提示警告
- 变更 Codex 默认写入通信协议为 `responses`,适配新版 Codex 不再支持旧 chat 模式
- 变更 Qwen Code 代理配置改用 `DASHSCOPE_API_KEY` 环境变量替代 `BAILIAN_CLI_API_KEY`
- 修复各 agent 配置格式不匹配问题,支持 JSONC 格式和官方结构,完善模型白名单与计费元数据
- 修复配置写入逻辑,合并保持用户自定义配置,避免覆盖及重复条目,优化显示名保留
- 更新所有相关包版本号至 1.11.0,包含 bailian-cli、commands、core、kscli、runtime
- 更新 bailian-cli 技能元数据版本号至 1.11.0
2026-07-28 20:27:28 +08:00
lisheng.lisheng 96744e3328 feat(config-agent): add --key and --region, default codex wire_api to responses
- --key: decode the web console's obfuscated API key (o1_ prefix) into
  the real key; mutually exclusive with --api-key, exactly one required
- --region: convert a Model Studio region into the Token Plan base URL
  (token-plan.<region>.maas.aliyuncs.com/compatible-mode/v1); mutually
  exclusive with --base-url, exactly one required
- codex: default wire_api to "responses" (current Codex rejects "chat");
  --wire-api chat kept for legacy Codex <= 0.80.0 with a warning
- regenerate skills reference for the new flags
2026-07-28 19:37:13 +08:00
lisheng.lisheng 5a58f56b06 refactor(agent): 修改环境变量名并优化代码格式
- 将环境变量名从 BAILIAN_CLI_API_KEY 改为 DASHSCOPE_API_KEY
- 调整导入语句格式,提升代码可读性
- 优化 providers 条目查找的换行和缩进
- 标准化名称判断与赋值逻辑的格式与排列
2026-07-28 09:59:41 +08:00
lisheng.lisheng 0221e35803 fix(config-agent): 优化 Codex 配置写入与兼容性处理
- 调整 Codex 代理默认 wire_api 为 "responses",兼容新版 Codex
- 增加对 legacy Codex <= 0.80.0 使用 wire_api "chat" 的警告提示
- 修正 agent flags 描述,更准确说明 wire_api 默认与兼容范围
- 优化代码格式,统一 import 语句风格
- 增加测试用例覆盖不同 wire_api 配置及环境变量警告
- 修复写入过程中文件备份及合并逻辑,保留用户已有配置
- 修复多个 provider 写入时键名与内容匹配,避免重复添加
- 改善测试代码格式,提高可读性与一致性
2026-07-27 17:10:26 +08:00
qcq01083097 ff469ce717 feat(install-docs): enhance installation documentation and validation processes 2026-07-27 11:24:22 +08:00
lisheng.lisheng 4751145283 fix(config-agent): 修复 Qwen Code 凭证写入与模型名处理
- 凭证同时写入 env 和 security.auth,避免系统 OPENAI_API_KEY 干扰
- modelProviders 中按 id + baseUrl 作为键,保持 name 为模型显示名
- 修复旧的 bailian-cli 名称,防止其覆盖用户自定义显示名
- model 配置中新增 baseUrl 字段,用于消歧同 id 但不同地址的模型
- 调整测试用例验证上述行为,确保配置一致性和兼容性
2026-07-23 19:20:44 +08:00
lisheng.lisheng 26a69a7c99 fix(config-agent): align agent writers with cc-switch and official Model Studio docs
- claude-code: honor CLAUDE_CONFIG_DIR; drop stale ANTHROPIC_API_KEY
- qwen-code: write $version:3; security.auth carries selectedType only
- opencode: tolerate JSONC (comments/trailing commas) via stripJsonc
- openclaw: add --context-window flag (default 256000), full cost fields,
  agents.defaults.models allowlist
- hermes: switch to official flat model.* block; api_mode only for
  anthropic endpoints
- codex: official env_key + auth.json fallback; add --wire-api flag
  (default chat, responses for supported models)
2026-07-23 11:12:34 +08:00
inhai e1caee99f2 feat(config-ui): MCP management, skill zip install, and UI polish
- MCP: editable JSON config in the detail drawer with secret masking and
  mask-preserving writes; create/update/delete across claude-code, qwen-code,
  opencode, cursor, windsurf, gemini, qoderwork, openclaw and Claude Desktop
- Skills: upload a .zip and install into any agent's skills root (self-contained
  ZIP reader, zip-slip safe); scan more roots (openclaw workspace, qoderwork,
  windsurf/codeium, gemini antigravity, workbuddy)
- Markdown: GFM table rendering in the skill detail drawer
- Layout: collapsible grouped sidebar with icons + persistent state, responsive
  breakpoint, wider main, single-line tile titles, 2-line description clamp,
  round icon run buttons, custom file picker, modal spacing
- Server: /api/mcp POST/DELETE, /api/skill/install, binary upload reader,
  constant-time token compare, CSP/no-store headers, error logging
2026-07-23 10:52:26 +08:00
inhai 9ab5de8c2e feat(config-ui): enrich config UI with skills, MCP, agents, assets and model catalog
- Add Skills / MCP / Agents / Assets inventory views with click-to-open
  right-side detail drawers (reusable infoDrawer)
- Render SKILL.md as Markdown via a self-contained, XSS-safe inline renderer
  (HTML-escape first, strip YAML frontmatter, no external deps)
- Add local vs remote origin badges to Skills and MCP items
- Add quick-launch for coding agents (allowlisted id->binary, execFile, no
  shell); gate the button on Connected AND the CLI binary being on PATH
- Add per-category model catalog surfaced as click-to-fill suggestion chips
  under each default_*_model field, sourced from real bl pipeline model names
- Add assets browser (categorized, time-sorted) with preview, open-locally
  and delete, backed by path-traversal-guarded file serving
- Convert Profiles to a tile grid with an add-tile and design-consistent
  new-profile modal; make view headers sticky and use drawers for editing
- Tests for inventory, agent-launch, assets and config-ui endpoints
2026-07-21 21:54:27 +08:00
39 changed files with 7040 additions and 353 deletions
+39
View File
@@ -6,6 +6,45 @@ The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and
[中文版](CHANGELOG.zh.md) · [README](README.md) · [Contributing](CONTRIBUTING.md)
## [1.13.0] - 2026-07-30
### Added
- **`bl config ui` Skills / MCP / Agents / Assets inventory** — browse installed skills, MCP servers, coding agents, and generated assets in the local Web UI with click-to-open detail drawers:
- Skills: render `SKILL.md` as Markdown (GFM tables supported), show local vs remote origin badges, and install a skill by uploading a `.zip` archive into any supported agent's skills root.
- MCP: view and edit JSON configuration with secret masking and mask-preserving writes; create, update, and delete MCP entries across Claude Code, Qwen Code, OpenCode, Cursor, Windsurf, Gemini, Qoder Work, OpenClaw, and Claude Desktop.
- Agents: quick-launch coding agents directly from the UI (gated on the CLI binary being on PATH).
- Assets: categorized, time-sorted browser with preview, open-locally, and delete.
- **Model catalog suggestion chips** — per-category model names surfaced as click-to-fill chips under each `default_*_model` field in the config UI.
- **Profiles tile grid** — profiles displayed as a tile grid with an add-tile and a design-consistent new-profile modal.
### Changed
- Config UI layout: collapsible grouped sidebar with icons and persistent state, responsive breakpoint, wider main area, sticky view headers, and right-side drawers for editing.
### Fixed
- Symlinked skill directories are now correctly identified as an installed source.
- Config file detection now supports environment-variable-based paths and legacy configuration schemes.
## [1.12.0] - 2026-07-28
### Added
- **`bl config agent --key` / `--region`** — run commands generated by the Model Studio web console as-is: `--key` accepts the console's encoded API key and decodes it locally (use instead of `--api-key`), and `--region` derives the Token Plan endpoint from a region name (use instead of `--base-url`).
- **`bl config agent --context-window`** — set the context window written to the OpenClaw configuration (default 256000).
- **`bl config agent --wire-api`** — choose the wire protocol written to the Codex configuration; `chat` is kept for legacy Codex 0.80.0 and earlier (a warning is shown).
### Changed
- `bl config agent` for Codex now writes `wire_api = "responses"` by default, matching current Codex releases that no longer accept `chat`.
- `bl config agent` for Qwen Code now writes the `DASHSCOPE_API_KEY` environment variable instead of `BAILIAN_CLI_API_KEY`.
### Fixed
- `bl config agent` configurations now match each agent's official format: Claude Code honors `CLAUDE_CONFIG_DIR` and removes a stale `ANTHROPIC_API_KEY`; Qwen Code uses the v3 settings schema and writes credentials so a system-level `OPENAI_API_KEY` no longer takes precedence; OpenCode accepts JSONC config files (comments and trailing commas); OpenClaw registers the primary model in the model allowlist with complete cost metadata; Hermes uses the official flat `model.*` layout; Codex writes the official `env_key` with an `auth.json` fallback.
- `bl config agent` now preserves existing user configuration when writing: it merges instead of overwriting, avoids duplicate provider entries, and keeps custom display names.
## [1.11.2] - 2026-07-28
### Changed
+39
View File
@@ -6,6 +6,45 @@
[English](CHANGELOG.md) · [README](README.zh.md) · [参与贡献](CONTRIBUTING.zh.md)
## [1.13.0] - 2026-07-30
### 新增
- **`bl config ui` 技能 / MCP / 代理 / 资产清单** — 在本地 Web UI 中浏览已安装的技能、MCP 服务器、编码代理和生成的资产,点击打开右侧详情抽屉:
- 技能:将 `SKILL.md` 渲染为 Markdown支持 GFM 表格),展示本地/远程来源徽章,支持上传 `.zip` 压缩包将技能安装到任意受支持代理的技能目录。
- MCP查看和编辑 JSON 配置,支持密钥掩码与掩码保真写回;支持在 Claude Code、Qwen Code、OpenCode、Cursor、Windsurf、Gemini、Qoder Work、OpenClaw 和 Claude Desktop 中创建、更新、删除 MCP 条目。
- 代理:从 UI 一键启动编码代理(需对应 CLI 二进制在 PATH 中)。
- 资产:按类别分组、按时间排序的浏览器,支持预览、本地打开和删除。
- **模型目录建议芯片** — 在配置 UI 的每个 `default_*_model` 字段下方展示按类别分组的模型名称,点击即可填入。
- **Profile 磁贴网格** — 配置文件以磁贴网格展示,新增添加磁贴和设计一致的新建 Profile 弹窗。
### 变更
- 配置 UI 布局:可折叠分组侧边栏(带图标和持久化状态)、响应式断点、更宽的主区域、吸顶视图标题、右侧抽屉式编辑。
### 修复
- 修复软链接技能目录未被正确识别为已安装来源的问题。
- 配置文件检测现支持基于环境变量的路径和旧版配置方案。
## [1.12.0] - 2026-07-28
### 新增
- **`bl config agent --key` / `--region`** —— 百炼控制台生成的命令可直接运行:`--key` 接收控制台编码后的 API Key 并在本地解码(与 `--api-key` 二选一);`--region` 根据地域名自动派生 Token Plan 接入地址(与 `--base-url` 二选一)。
- **`bl config agent --context-window`** —— 设置写入 OpenClaw 配置的上下文窗口大小(默认 256000
- **`bl config agent --wire-api`** —— 选择写入 Codex 配置的通信协议;`chat` 仅保留给 Codex 0.80.0 及更早版本(会显示警告)。
### 变更
- `bl config agent` 配置 Codex 时默认写入 `wire_api = "responses"`,以适配已不再支持 `chat` 的新版 Codex。
- `bl config agent` 配置 Qwen Code 时改用 `DASHSCOPE_API_KEY` 环境变量,不再使用 `BAILIAN_CLI_API_KEY`
### 修复
- `bl config agent` 写入的配置现已与各 Agent 官方格式对齐Claude Code 尊重 `CLAUDE_CONFIG_DIR` 并清理残留的 `ANTHROPIC_API_KEY`Qwen Code 采用 v3 配置 schema 并正确写入凭证,避免被系统级 `OPENAI_API_KEY` 干扰OpenCode 支持带注释和尾部逗号的 JSONC 配置文件OpenClaw 会将主模型注册进模型白名单并补齐计费元数据Hermes 改用官方扁平 `model.*` 结构Codex 写入官方 `env_key` 并支持 `auth.json` 兜底。
- `bl config agent` 写入配置时现会保留用户已有配置:合并而非覆盖,避免重复添加 provider 条目,并保留用户自定义的显示名。
## [1.11.2] - 2026-07-28
### 变更
+5 -2
View File
@@ -46,7 +46,9 @@
- `config list` 标识所有 Profile 与当前激活项。
- `config show``auth status` 只输出本次最终选择的 `config``config_file`,不重复携带激活状态。
- `config ui` 从持久化元数据读取激活项,提供显式激活操作,并在删除激活项后刷新为 `default`
- `config ui` 保存时只替换 UI 管理的字段Profile 中未展示但仍属于 `ConfigFile` 的合法字段必须保留,不能因打开并保存 UI 而丢失
- `config ui` 展示并可编辑完整 `ConfigFile`(含 `console_*``telemetry`),保存时按类型(数字/布尔/枚举)归一化写回;`config set` 仍只暴露较窄的 `VALID_KEYS`UI 管理的顶层元数据(如 `active_config`)不进入 Profile block仍由写盘逻辑单独保留
- `config ui` 只读展示本地 agent 生态Skills 跨全部 agent skill 目录(`~/.agents/skills` 及各 agent 的 `skills/`,含软链接)按 id 聚合并标注安装来源MCP、Agents 从各 agent 本地配置读取。
- `config ui` 提供 Assets 资产管理:扫描 `output_dir`(默认 `~/bailian-output`)下的 `images/videos/speech/omni` 分类及根目录散落文件按分类与生成时间mtime标记支持按分类筛选、内联预览图/视频/音频)与删除单个文件;文件读取与删除均通过限定在输出目录内的路径校验(防目录穿越)。
- 同步 E2E topic routes、Skill setup 和自动生成 reference。
## 6. 最小测试矩阵
@@ -62,7 +64,8 @@
`--config default` 成功后切回 `default`
- Console token 自动刷新不从其他 Profile 借用 AK/SK也不把新 token 写入其他 Profile。
- `config list/show/use/ui``auth status` 和依赖默认模型的消费命令覆盖对应 E2E。
- `config ui` 覆盖保存时保留未管理字段,并继续允许空值清除 UI 管理字段
- `config ui` 覆盖保存时保留顶层元数据(如 `active_config`),继续允许空值清除字段,并覆盖 `console_*`/`telemetry` 的类型归一化与枚举校验
- Assets:`listAssets` 覆盖分类归类、时间倒序、目录缺失返回空;`resolveAssetPath` 覆盖目录穿越拦截;`contentType` 覆盖常见扩展名映射。
## 7. 完成检查
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "bailian-cli",
"version": "1.11.2",
"version": "1.13.0",
"description": "CLI for Aliyun Model Studio (DashScope) AI Platform.",
"keywords": [
"agent",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "bailian-cli-commands",
"version": "1.11.2",
"version": "1.13.0",
"description": "Command library for bailian-cli products (knowledge, memory, media, …). See https://www.npmjs.com/package/bailian-cli for usage.",
"homepage": "https://bailian.console.aliyun.com/cli",
"bugs": {
@@ -0,0 +1,79 @@
import { maskToken, type AuthStore, type Identity, type Settings } from "bailian-cli-core";
import { runConsoleLogin, resolveConsoleOrigin } from "./login-console.ts";
/** Read-only auth snapshot the config UI account widget renders. bl stores no
* user profile (name/avatar), so this exposes only which credential domains
* resolve, the console region/site, and a masked token. */
export interface AuthUiStatus {
authenticated: boolean;
methods: { apiKey: boolean; console: boolean; openapi: boolean };
primary: "console" | "apiKey" | "openapi" | null;
region?: string;
site?: "domestic" | "international";
masked?: string;
}
/**
* The auth capability surface the config UI is allowed to use. All `authStore`
* access is kept inside this module (commands/auth/**), which the lint boundary
* permits; commands/config/** consumes only this opaque bridge and never
* touches `authStore` directly.
*/
export interface AuthUiBridge {
status(): AuthUiStatus;
/** Start browser-based console login (fire-and-forget; UI polls status). */
startConsoleLogin(): void;
/** Clear all stored credentials. Returns whether anything changed. */
logout(): Promise<boolean>;
}
/** Build the bridge from a command context (identity/settings/authStore). */
export function makeAuthUiBridge(ctx: {
identity: Identity;
settings: Settings;
authStore: AuthStore;
}): AuthUiBridge {
const { identity, settings, authStore } = ctx;
return {
status() {
const a = authStore.describe();
const methods = { apiKey: !!a.apiKey, console: !!a.console, openapi: !!a.openapi };
let masked: string | undefined;
if (a.console) masked = maskToken(a.console.token);
else if (a.apiKey) masked = maskToken(a.apiKey.token);
else if (a.openapi) masked = maskToken(a.openapi.accessKeyId);
const primary = a.console ? "console" : a.apiKey ? "apiKey" : a.openapi ? "openapi" : null;
return {
authenticated: methods.apiKey || methods.console || methods.openapi,
methods,
primary,
region: a.console?.region,
site: a.console?.site,
masked,
};
},
startConsoleLogin() {
const origin = resolveConsoleOrigin(authStore.describe().console?.site);
// Mirror the CLI (`bl auth login --console`): request an api_key from the
// console only when one isn't already stored, so a first console login in
// the config UI also provisions the model api_key (not just access_token).
const hasApiKey = !!authStore.stored().apiKey;
// runConsoleLogin opens the browser and runs its own callback server
// (up to 15 min). We don't await it — the config UI polls the status
// endpoint to detect completion. Errors are logged, not surfaced.
void runConsoleLogin(
origin,
{ identity, settings, authStore },
{
needApiKey: !hasApiKey,
},
).catch((err: unknown) => {
const msg = err instanceof Error ? err.message : String(err);
process.stderr.write(`console login failed: ${msg}\n`);
});
},
logout() {
return authStore.logout("all");
},
};
}
@@ -0,0 +1,131 @@
/**
* Best-effort local launcher for coding-agent CLIs surfaced in the config UI.
*
* The command for each agent is taken from a fixed allowlist keyed by the
* agent id, so no user-controlled string is ever executed. Every child process
* is spawned via `execFile` (array args, no shell) to avoid injection.
*/
import { execFile } from "node:child_process";
/** Fixed allowlist: agent id -> launch binary. Keys match `AGENT_PROBES` ids. */
export const AGENT_COMMANDS: Record<string, string> = {
"claude-code": "claude",
"qwen-code": "qwen",
opencode: "opencode",
openclaw: "openclaw",
hermes: "hermes",
codex: "codex",
};
/** The launch binary for a known agent id, or undefined when unknown. */
export function agentCommand(id: string): string | undefined {
return Object.prototype.hasOwnProperty.call(AGENT_COMMANDS, id) ? AGENT_COMMANDS[id] : undefined;
}
/**
* Per-agent argv that passes an initial task prompt while keeping the agent
* interactive in the terminal. Only verified contracts are listed; an agent
* absent here cannot be dispatched a prompt (its bare launch still works).
* - qwen-code: `qwen -i "<prompt>"` (execute prompt, stay interactive)
* - claude-code: `claude "<prompt>"` (positional initial prompt)
* - codex: `codex "<prompt>"` (positional initial prompt)
*/
const AGENT_PROMPT_ARGV: Record<string, (prompt: string) => string[]> = {
"qwen-code": (p) => ["-i", p],
"claude-code": (p) => [p],
codex: (p) => [p],
};
/** Whether a known agent supports being dispatched an initial task prompt. */
export function agentSupportsPrompt(id: string): boolean {
return Object.prototype.hasOwnProperty.call(AGENT_PROMPT_ARGV, id);
}
/** Resolve whether a binary is reachable on PATH (via `which`/`where`). */
function onPath(bin: string): Promise<boolean> {
const cmd = process.platform === "win32" ? "where" : "which";
return new Promise((resolve) => {
execFile(cmd, [bin], { windowsHide: true }, (err) => resolve(!err));
});
}
/**
* Whether a known agent can actually be quick-launched right now: its id maps to
* a launch binary and that binary is reachable on PATH. Unknown ids resolve to
* false. Used to gate the UI's Quick launch button so "Connected" agents whose
* CLI is not installed do not offer a launch that would immediately fail.
*/
export function agentLaunchable(id: string): Promise<boolean> {
const command = agentCommand(id);
if (!command) return Promise.resolve(false);
return onPath(command);
}
/** Single-quote a path for a POSIX shell command line. */
function shQuote(p: string): string {
return `'${p.replace(/'/g, "'\\''")}'`;
}
/** Open a new OS terminal window that cd's into `cwd` and runs `command`. */
function spawnTerminal(command: string, cwd: string): Promise<void> {
const platform = process.platform;
return new Promise((resolve, reject) => {
if (platform === "darwin") {
const inner = `cd ${shQuote(cwd)} && ${command}`;
const escaped = inner.replace(/\\/g, "\\\\").replace(/"/g, '\\"');
const args = [
"-e",
`tell application "Terminal" to do script "${escaped}"`,
"-e",
'tell application "Terminal" to activate',
];
execFile("osascript", args, { windowsHide: true }, (err) => (err ? reject(err) : resolve()));
return;
}
if (platform === "win32") {
const args = ["/c", "start", "", "cmd", "/k", `cd /d ${cwd} && ${command}`];
execFile("cmd", args, { windowsHide: true }, (err) => (err ? reject(err) : resolve()));
return;
}
// Linux / other: best-effort via the distro's default terminal emulator.
const inner = `cd ${shQuote(cwd)} && ${command}; exec $SHELL`;
execFile("x-terminal-emulator", ["-e", "bash", "-lc", inner], { windowsHide: true }, (err) =>
err ? reject(new Error("No supported terminal emulator was found")) : resolve(),
);
});
}
export interface LaunchResult {
launched: boolean;
command: string;
}
/**
* Launch a known coding agent's local CLI in a new terminal window. When
* `prompt` is provided, it is passed as a single quoted argument using the
* agent's verified prompt contract so the agent starts with that task.
* Rejects when the id is unknown, the binary is missing from PATH, the agent
* does not support prompt dispatch, or the platform terminal could not open.
*/
export async function launchAgent(
id: string,
cwd: string = process.cwd(),
prompt?: string,
): Promise<LaunchResult> {
const command = agentCommand(id);
if (!command) throw new Error(`Unknown agent: ${id}`);
if (!(await onPath(command))) {
throw new Error(`\`${command}\` was not found on your PATH — install ${id} first.`);
}
let fullCommand = command;
const task = (prompt ?? "").trim();
if (task) {
const build = AGENT_PROMPT_ARGV[id];
if (!build) throw new Error(`${id} does not support dispatching a task prompt.`);
// shQuote keeps the whole prompt as one shell argument (no injection); the
// platform terminal layer escapes the resulting command line separately.
fullCommand = [command, ...build(task).map(shQuote)].join(" ");
}
await spawnTerminal(fullCommand, cwd);
return { launched: true, command: fullCommand };
}
@@ -0,0 +1,153 @@
import { BailianError, ExitCode } from "bailian-cli-core";
/**
* Decoder for the obfuscated API key ("o1_…") produced by the Model Studio web
* console. Ported verbatim from the frontend `encodeTokenPlanKey` counterpart:
* token = "o1_" + salt(6) + feistel-obfuscated payload + crc32 checksum(6),
* all over a 65-character alphabet. Pure logic, no dependencies; the CLI only
* ever needs the decode direction.
*/
const TOKEN_PREFIX = "o1_";
const ALPHABET = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_.";
const ALPHABET_SIZE = ALPHABET.length;
const ALPHABET_INDEX = new Map(ALPHABET.split("").map((character, index) => [character, index]));
const KEY_PATTERN = /^[A-Za-z0-9._-]+$/;
const SALT_LENGTH = 6;
const CHECKSUM_LENGTH = 6;
const FEISTEL_ROUNDS = 8;
function invalidCredential(): BailianError {
return new BailianError(
"Invalid obfuscated API key.",
ExitCode.USAGE,
'--key expects the obfuscated key copied from the web console (starts with "o1_").',
);
}
function toDigits(value: string): number[] {
const digits: number[] = [];
for (const character of value) {
const digit = ALPHABET_INDEX.get(character);
if (digit === undefined) throw invalidCredential();
digits.push(digit);
}
return digits;
}
function fromDigits(digits: number[]): string {
return digits.map((digit) => ALPHABET[digit]).join("");
}
function mixState(state: number, value: number): number {
return Math.imul((state ^ value) >>> 0, 0x01000193) >>> 0;
}
function nextState(state: number): number {
let next = state >>> 0;
next ^= next << 13;
next ^= next >>> 17;
next ^= next << 5;
return next >>> 0;
}
function createRoundMask(right: number[], salt: string, round: number, length: number): number[] {
let state = (0x811c9dc5 ^ Math.imul(round + 1, 0x9e3779b1)) >>> 0;
state = mixState(state, right.length);
state = mixState(state, length);
for (const character of salt) {
state = mixState(state, (ALPHABET_INDEX.get(character) ?? -1) + 1);
}
for (const digit of right) {
state = mixState(state, digit + 1);
}
state ^= state >>> 16;
state = Math.imul(state, 0x85ebca6b) >>> 0;
state ^= state >>> 13;
state = Math.imul(state, 0xc2b2ae35) >>> 0;
state ^= state >>> 16;
state = state >>> 0 || 0x6d2b79f5;
const mask: number[] = [];
for (let index = 0; index < length; index += 1) {
state = (state + Math.imul(index + 1, 0x9e3779b1)) >>> 0;
state = nextState(state);
mask.push(state % ALPHABET_SIZE);
}
return mask;
}
function deobfuscatePayload(payload: string, salt: string): string {
const digits = toDigits(payload);
const midpoint = Math.floor(digits.length / 2);
let left = digits.slice(0, midpoint);
let right = digits.slice(midpoint);
for (let round = FEISTEL_ROUNDS - 1; round >= 0; round -= 1) {
const previousRight = left;
const mask = createRoundMask(previousRight, salt, round, right.length);
const previousLeft = right.map(
(digit, index) => (digit - mask[index] + ALPHABET_SIZE) % ALPHABET_SIZE,
);
left = previousLeft;
right = previousRight;
}
return fromDigits([...left, ...right]);
}
function crc32(value: string): number {
let checksum = 0xffffffff;
for (let index = 0; index < value.length; index += 1) {
checksum ^= value.charCodeAt(index);
for (let bit = 0; bit < 8; bit += 1) {
const mask = -(checksum & 1);
checksum = (checksum >>> 1) ^ (0xedb88320 & mask);
}
}
return (checksum ^ 0xffffffff) >>> 0;
}
function encodeBase65Number(value: number, length: number): string {
let remaining = value >>> 0;
const encoded = Array<string>(length).fill(ALPHABET[0]);
for (let index = length - 1; index >= 0; index -= 1) {
encoded[index] = ALPHABET[remaining % ALPHABET_SIZE];
remaining = Math.floor(remaining / ALPHABET_SIZE);
}
if (remaining !== 0) throw invalidCredential();
return encoded.join("");
}
function validateSalt(salt: string): void {
if (salt.length !== SALT_LENGTH || !KEY_PATTERN.test(salt)) {
throw invalidCredential();
}
}
/** Decode an "o1_…" obfuscated token back into the plain API key. */
export function decodeTokenPlanKey(token: string): string {
const minimumLength = TOKEN_PREFIX.length + SALT_LENGTH + CHECKSUM_LENGTH + 1;
if (token.length < minimumLength || !token.startsWith(TOKEN_PREFIX)) {
throw invalidCredential();
}
const body = token.slice(TOKEN_PREFIX.length);
if (!KEY_PATTERN.test(body)) throw invalidCredential();
const salt = body.slice(0, SALT_LENGTH);
const payload = body.slice(SALT_LENGTH, -CHECKSUM_LENGTH);
const checksum = body.slice(-CHECKSUM_LENGTH);
validateSalt(salt);
if (!payload) throw invalidCredential();
const apiKey = deobfuscatePayload(payload, salt);
if (!KEY_PATTERN.test(apiKey)) throw invalidCredential();
const expectedChecksum = encodeBase65Number(crc32(apiKey), CHECKSUM_LENGTH);
if (checksum !== expectedChecksum) throw invalidCredential();
return apiKey;
}
@@ -2,6 +2,8 @@ import { platform } from "os";
import { defineCommand, detectOutputFormat, maskToken, type FlagsDef } from "bailian-cli-core";
import { emitResult, emitBare } from "bailian-cli-runtime";
import { AGENTS, VALID_AGENT_NAMES, type WriteParams } from "./writers.ts";
import { decodeTokenPlanKey } from "./decode-key.ts";
import { resolveRegionBaseUrl } from "./writers/utils.ts";
const FLAGS = {
agent: {
@@ -11,30 +13,76 @@ const FLAGS = {
required: true,
choices: VALID_AGENT_NAMES,
},
baseUrl: { type: "string", valueHint: "<url>", description: "API base URL", required: true },
apiKey: { type: "string", valueHint: "<key>", description: "API key", required: true },
baseUrl: {
type: "string",
valueHint: "<url>",
description: "API base URL",
},
region: {
type: "string",
valueHint: "<region>",
description:
"Model Studio region (e.g. cn-beijing, ap-southeast-1); converted into --base-url. Token Plan only",
},
apiKey: {
type: "string",
valueHint: "<key>",
description: "API key",
},
key: {
type: "string",
valueHint: "<encoded>",
description:
'Obfuscated API key from the web console (starts with "o1_"); decoded into --api-key',
},
model: {
type: "string",
valueHint: "<model>",
description: "Default model name",
required: true,
},
contextWindow: {
type: "number",
valueHint: "<tokens>",
description: "OpenClaw only: model context window in tokens (default: 256000)",
},
wireApi: {
type: "string",
valueHint: "<api>",
description:
'Codex only: wire protocol (default: responses). "chat" only works with legacy Codex <= 0.80.0',
choices: ["chat", "responses"],
},
} satisfies FlagsDef;
export default defineCommand({
description: "Configure a coding agent to use DashScope API",
auth: "none",
usageArgs: "--agent <name> --base-url <url> --api-key <key> --model <model>",
usageArgs:
"--agent <name> (--base-url <url> | --region <region>) (--api-key <key> | --key <encoded>) --model <model>",
flags: FLAGS,
exampleArgs: [
"--agent claude-code --base-url https://dashscope.aliyuncs.com/apps/anthropic --api-key sk-xxxxx --model qwen3-max",
"--agent qwen-code --base-url https://dashscope.aliyuncs.com/compatible-mode/v1 --api-key sk-xxxxx --model qwen3-coder-plus",
"--agent codex --base-url https://dashscope.aliyuncs.com/compatible-mode/v1 --api-key sk-xxxxx --model qwen3-coder-plus",
],
validate(flags) {
if (!flags.baseUrl && !flags.region) return "one of --base-url or --region is required";
if (flags.baseUrl && flags.region) return "--base-url and --region are mutually exclusive";
if (!flags.apiKey && !flags.key) return "one of --api-key or --key is required";
if (flags.apiKey && flags.key) return "--api-key and --key are mutually exclusive";
return undefined;
},
async run(ctx) {
const { settings, flags } = ctx;
const agentName = flags.agent;
const { baseUrl, apiKey, model } = flags;
const { model, contextWindow, wireApi } = flags;
// --region is a Token Plan convenience: convert it into a base URL and use
// it exactly as --base-url would be.
const baseUrl = flags.region ? resolveRegionBaseUrl(flags.region) : flags.baseUrl!;
// --key carries the web console's obfuscated form; decode it up front so
// even --dry-run validates the token.
const apiKey = flags.key ? decodeTokenPlanKey(flags.key) : flags.apiKey!;
const agentDef = AGENTS[agentName];
const format = detectOutputFormat(settings.output);
@@ -59,13 +107,22 @@ export default defineCommand({
return;
}
const params: WriteParams = { baseUrl, apiKey, model };
const params: WriteParams = {
baseUrl,
apiKey,
model,
contextWindow,
wireApi,
};
const summary = agentDef.write(params);
if (!settings.quiet) {
emitBare(`${agentDef.label} configured successfully.`);
for (const path of summary.paths) emitBare(` Written: ${path}`);
emitBare(` ${summary.nextStep}`);
for (const warning of summary.warnings ?? []) {
process.stderr.write(`Warning: ${warning}\n`);
}
}
},
});
@@ -1,25 +1,55 @@
import { homedir } from "os";
import { join } from "path";
import { backup, readJson, writeJsonAtomic, type AgentDef } from "./utils.ts";
import {
backup,
readJson,
writeJsonAtomic,
resolveClaudeCodeBaseUrl,
type AgentDef,
} from "./utils.ts";
/** Fill a tier/default model env only when the user has not set it yet. */
function setModelEnvIfAbsent(env: Record<string, string>, key: string, model: string): void {
const current = env[key];
if (current === undefined || current.trim() === "") {
env[key] = model;
}
}
export default {
label: "Claude Code",
write({ baseUrl, apiKey, model }) {
const settingsPath = join(homedir(), ".claude", "settings.json");
// Claude Code honors CLAUDE_CONFIG_DIR for its settings location.
const configDir = process.env.CLAUDE_CONFIG_DIR || join(homedir(), ".claude");
const settingsPath = join(configDir, "settings.json");
const onboardingPath = join(homedir(), ".claude.json");
const warnings: string[] = [];
const resolved = resolveClaudeCodeBaseUrl(baseUrl);
if (resolved.rewrittenFrom) {
warnings.push(
`Rewrote base URL for Claude Code: "${resolved.rewrittenFrom}" → "${resolved.url}" ` +
`(Claude Code needs /apps/anthropic, not OpenAI compatible-mode).`,
);
}
// settings.json — merge env. Base URL + auth token connect Claude Code to
// the endpoint; the model tier vars force every tier onto the chosen model.
// the Anthropic-compatible endpoint; primary model always updates, while
// tier/subagent defaults are filled only when absent so existing setups
// (e.g. Token Plan Haiku/Subagent splits) are not wiped.
backup(settingsPath);
const settings = readJson(settingsPath);
const env = (settings.env ?? {}) as Record<string, string>;
env.ANTHROPIC_BASE_URL = baseUrl;
env.ANTHROPIC_BASE_URL = resolved.url;
env.ANTHROPIC_AUTH_TOKEN = apiKey;
// AUTH_TOKEN and API_KEY are mutually exclusive credential fields — drop a
// stale ANTHROPIC_API_KEY so it cannot shadow the token we just wrote.
delete env.ANTHROPIC_API_KEY;
env.ANTHROPIC_MODEL = model;
env.ANTHROPIC_DEFAULT_HAIKU_MODEL = model;
env.ANTHROPIC_DEFAULT_SONNET_MODEL = model;
env.ANTHROPIC_DEFAULT_OPUS_MODEL = model;
env.CLAUDE_CODE_SUBAGENT_MODEL = model;
setModelEnvIfAbsent(env, "ANTHROPIC_DEFAULT_HAIKU_MODEL", model);
setModelEnvIfAbsent(env, "ANTHROPIC_DEFAULT_SONNET_MODEL", model);
setModelEnvIfAbsent(env, "ANTHROPIC_DEFAULT_OPUS_MODEL", model);
setModelEnvIfAbsent(env, "CLAUDE_CODE_SUBAGENT_MODEL", model);
settings.env = env;
writeJsonAtomic(settingsPath, settings);
@@ -32,6 +62,7 @@ export default {
return {
paths: [settingsPath, onboardingPath],
nextStep: "Run `claude` to start using Claude Code with DashScope.",
warnings: warnings.length > 0 ? warnings : undefined,
};
},
} satisfies AgentDef;
@@ -8,8 +8,9 @@ const PROVIDER_KEY = "bailian-cli";
export default {
label: "Codex",
write({ baseUrl, apiKey, model }) {
write({ baseUrl, apiKey, model, wireApi: wireApiParam }) {
const configPath = join(homedir(), ".codex", "config.toml");
const warnings: string[] = [];
// config.toml — merge into existing config so unrelated settings
// (mcp_servers, approval_policy, other providers, ...) are preserved.
@@ -25,8 +26,19 @@ export default {
config.model_provider = PROVIDER_KEY;
config.model = model;
config.model_reasoning_effort = "high";
config.disable_response_storage = true;
// wire_api — current Codex releases only load `wire_api = "responses"`
// ("chat" is rejected at config load, see openai/codex discussion #7782).
// "chat" remains an explicit opt-in for users pinned to legacy Codex
// <= 0.80.0 (the Model Studio path for models without Responses support).
const wireApi = wireApiParam === "chat" ? "chat" : "responses";
if (wireApi === "chat") {
warnings.push(
'Current Codex releases refuse to load `wire_api = "chat"`; ' +
"only use --wire-api chat with legacy Codex <= 0.80.0 " +
"(e.g. `npm install -g @openai/codex@0.80.0`).",
);
}
const providers = (config.model_providers ?? {}) as Record<string, unknown>;
const existing = (providers[PROVIDER_KEY] ?? {}) as Record<string, unknown>;
@@ -34,14 +46,17 @@ export default {
...existing,
name: PROVIDER_KEY,
base_url: baseUrl,
wire_api: "responses",
// env_key is the official-doc credential mechanism: Codex resolves the
// key from the OPENAI_API_KEY env var, falling back to auth.json below.
env_key: "OPENAI_API_KEY",
wire_api: wireApi,
requires_openai_auth: true,
};
config.model_providers = providers;
writeTextAtomic(configPath, stringifyToml(config) + "\n");
// auth.json — Codex reads OPENAI_API_KEY from here.
// auth.json — Codex reads OPENAI_API_KEY from here when the env var is unset.
const authPath = join(homedir(), ".codex", "auth.json");
backup(authPath);
const auth = readJson(authPath);
@@ -51,6 +66,7 @@ export default {
return {
paths: [configPath, authPath],
nextStep: "Run `codex` to start using Codex with DashScope.",
warnings: warnings.length > 0 ? warnings : undefined,
};
},
} satisfies AgentDef;
@@ -4,8 +4,6 @@ import { existsSync, readFileSync } from "fs";
import yaml from "yaml";
import { backup, writeTextAtomic, isAnthropicEndpoint, type AgentDef } from "./utils.ts";
const PROVIDER_NAME = "bailian-cli";
export default {
label: "Hermes Agent",
write({ baseUrl, apiKey, model }) {
@@ -22,26 +20,18 @@ export default {
}
}
const apiMode = isAnthropicEndpoint(baseUrl) ? "anthropic_messages" : "chat_completions";
const providerEntry = {
name: PROVIDER_NAME,
// Official Model Studio doc shape: a single flat `model` block holding the
// active endpoint + credentials. `api_mode: anthropic_messages` is required
// for /apps/anthropic endpoints; for the OpenAI-compatible endpoint the
// doc says to omit api_mode entirely (chat completions is the default).
const block: Record<string, unknown> = {
default: model,
provider: "custom",
base_url: baseUrl,
api_key: apiKey,
api_mode: apiMode,
models: [{ id: model, name: model }],
};
// custom_providers — upsert the bailian-cli entry by name.
const providers = Array.isArray(config.custom_providers)
? (config.custom_providers as Array<Record<string, unknown>>)
: [];
const index = providers.findIndex((entry) => entry.name === PROVIDER_NAME);
if (index >= 0) providers[index] = providerEntry;
else providers.push(providerEntry);
config.custom_providers = providers;
// model — select the bailian-cli provider and default model.
config.model = { default: model, provider: PROVIDER_NAME };
if (isAnthropicEndpoint(baseUrl)) block.api_mode = "anthropic_messages";
config.model = block;
writeTextAtomic(configPath, yaml.stringify(config));
@@ -2,20 +2,36 @@ import { homedir } from "os";
import { join } from "path";
import { backup, readJson, writeJsonAtomic, isAnthropicEndpoint, type AgentDef } from "./utils.ts";
// Safe default when --context-window is not given: most Model Studio models
// offer ≥256K context; users can raise it per model via the flag.
const DEFAULT_CONTEXT_WINDOW = 256000;
const PROVIDER_ID = "bailian-cli";
function readPrimary(defaults: Record<string, unknown>): string | undefined {
const model = defaults.model;
if (!model || typeof model !== "object") return undefined;
const primary = (model as Record<string, unknown>).primary;
return typeof primary === "string" && primary.trim() !== "" ? primary.trim() : undefined;
}
export default {
label: "OpenClaw",
write({ baseUrl, apiKey, model }) {
write({ baseUrl, apiKey, model, contextWindow }) {
const configPath = join(homedir(), ".openclaw", "openclaw.json");
const warnings: string[] = [];
const modelRef = `${PROVIDER_ID}/${model}`;
backup(configPath);
const config = readJson(configPath);
// models.providers["bailian-cli"]
// models.providers["bailian-cli"] — upsert without removing other providers
// (e.g. an existing working bailian-token-plan setup).
const models = (config.models ?? {}) as Record<string, unknown>;
models.mode = "merge";
const providers = (models.providers ?? {}) as Record<string, unknown>;
const api = isAnthropicEndpoint(baseUrl) ? "anthropic-messages" : "openai-completions";
providers["bailian-cli"] = {
providers[PROVIDER_ID] = {
baseUrl,
apiKey,
api,
@@ -23,18 +39,35 @@ export default {
{
id: model,
name: model,
contextWindow: 1000000,
cost: { input: 0, output: 0 },
contextWindow: contextWindow ?? DEFAULT_CONTEXT_WINDOW,
cost: { input: 0, output: 0, cacheRead: 0, cacheWrite: 0 },
},
],
};
models.providers = providers;
config.models = models;
// agents.defaults
// agents.defaults — register the model in the allow-list. Only set primary
// when unset, or when primary already points at bailian-cli (reconfigure).
// Never steal primary away from another provider such as bailian-token-plan.
const agents = (config.agents ?? {}) as Record<string, unknown>;
const defaults = (agents.defaults ?? {}) as Record<string, unknown>;
defaults.model = { primary: `bailian-cli/${model}` };
const allowedModels = (defaults.models ?? {}) as Record<string, unknown>;
allowedModels[modelRef] = allowedModels[modelRef] ?? {};
defaults.models = allowedModels;
const existingPrimary = readPrimary(defaults);
if (!existingPrimary) {
defaults.model = { primary: modelRef };
} else if (existingPrimary.startsWith(`${PROVIDER_ID}/`)) {
defaults.model = { primary: modelRef };
} else {
warnings.push(
`Left existing primary model unchanged ("${existingPrimary}"). ` +
`Added provider "${PROVIDER_ID}" — switch to "${modelRef}" in OpenClaw if you want to use it.`,
);
}
agents.defaults = defaults;
config.agents = agents;
@@ -42,7 +75,9 @@ export default {
return {
paths: [configPath],
nextStep: "Run `openclaw` to start using OpenClaw with DashScope.",
nextStep:
"Run `openclaw gateway restart`, then `openclaw` to start using OpenClaw with DashScope.",
warnings: warnings.length > 0 ? warnings : undefined,
};
},
} satisfies AgentDef;
@@ -1,14 +1,15 @@
import { homedir } from "os";
import { join } from "path";
import { backup, readJson, writeJsonAtomic, isAnthropicEndpoint, type AgentDef } from "./utils.ts";
import { backup, readJsonc, writeJsonAtomic, isAnthropicEndpoint, type AgentDef } from "./utils.ts";
export default {
label: "OpenCode",
write({ baseUrl, apiKey, model }) {
const configPath = join(homedir(), ".config", "opencode", "opencode.json");
// opencode.json is JSONC — tolerate comments and trailing commas on read.
backup(configPath);
const config = readJson(configPath);
const config = readJsonc(configPath);
if (!config.$schema) config.$schema = "https://opencode.ai/config.json";
@@ -2,53 +2,110 @@ import { homedir } from "os";
import { join } from "path";
import { backup, readJson, writeJsonAtomic, isAnthropicEndpoint, type AgentDef } from "./utils.ts";
const ENV_KEY = "BAILIAN_CLI_API_KEY";
const ENV_KEY = "DASHSCOPE_API_KEY";
function displayName(model: string): string {
return `[Bailian] ${model}`;
}
/** Entries we previously wrote, or still own via envKey / display brand. */
function isBailianCliEntry(entry: Record<string, unknown>): boolean {
if (entry.envKey === ENV_KEY) return true;
const name = typeof entry.name === "string" ? entry.name : "";
return name === "bailian-cli" || name.startsWith("[Bailian]");
}
/**
* Qwen Code keys `modelProviders` and `security.auth.selectedType` by the SDK
* protocol (an AuthType string), not by a free-form provider id — the runtime
* resolver indexes credentials/defaults by protocol. The `bailian-cli` brand
* therefore lives in the model entry `name` and the env var name.
* therefore lives in the env var name (`BAILIAN_CLI_API_KEY`) and the display
* label (`[Bailian] …`); Qwen Code keys models by id (+ baseUrl), never by name.
*
* Qwen Code does not support duplicate model `id`s (only the first loads), so
* we must never overwrite a pre-existing Token Plan / third-party entry that
* shares the same id.
*
* Credentials are written to BOTH `env` (via the entry's `envKey`) and
* `security.auth` — the resolver reads `security.auth.apiKey/baseUrl` as a
* lower-priority layer, which stops a stray system `OPENAI_API_KEY` from being
* picked up when the provider→envKey path does not resolve first. The active
* `model` also carries its `baseUrl`, as Qwen Code requires to disambiguate
* same-id providers.
*/
export default {
label: "Qwen Code",
write({ baseUrl, apiKey, model }) {
const settingsPath = join(homedir(), ".qwen", "settings.json");
const protocol = isAnthropicEndpoint(baseUrl) ? "anthropic" : "openai";
const warnings: string[] = [];
backup(settingsPath);
const settings = readJson(settingsPath);
// $version — Qwen Code v3 settings schema (official Model Studio doc shape).
settings.$version = 3;
// env — API key read by the provider entry's envKey.
// Qwen Code treats settings.json `env` as lowest priority; a process/shell
// value for the same key wins and can make the first launch fail.
const env = (settings.env ?? {}) as Record<string, string>;
env[ENV_KEY] = apiKey;
settings.env = env;
// modelProviders[<protocol>] — upsert the bailian-cli model entry.
const processEnvValue = process.env[ENV_KEY];
if (processEnvValue !== undefined && processEnvValue !== apiKey) {
warnings.push(
`Shell/environment ${ENV_KEY} is set and overrides settings.json. ` +
`Unset it (e.g. \`unset ${ENV_KEY}\`) so the key written here takes effect.`,
);
}
// modelProviders[<protocol>] — upsert only bailian-cli-owned entries.
const providers = (settings.modelProviders ?? {}) as Record<
string,
Array<Record<string, unknown>>
>;
const entries = (providers[protocol] ?? []) as Array<Record<string, unknown>>;
const existing = entries.find(
(entry) => entry.id === model && (entry.baseUrl ?? "") === baseUrl,
);
if (existing) {
existing.name = "bailian-cli";
existing.baseUrl = baseUrl;
existing.envKey = ENV_KEY;
const owned = entries.find((entry) => isBailianCliEntry(entry) && entry.id === model);
const conflicting = entries.find((entry) => !isBailianCliEntry(entry) && entry.id === model);
if (owned) {
owned.baseUrl = baseUrl;
owned.envKey = ENV_KEY;
const currentName = typeof owned.name === "string" ? owned.name.trim() : "";
if (!currentName || currentName === "bailian-cli") owned.name = displayName(model);
} else if (conflicting) {
const existingName =
typeof conflicting.name === "string" && conflicting.name.length > 0
? conflicting.name
: String(conflicting.id);
warnings.push(
`Model id "${model}" already exists as "${existingName}"; left unchanged ` +
`(Qwen Code loads only the first entry per id). Remove or rename that ` +
`entry if you want bailian-cli to own this model.`,
);
} else {
entries.push({ id: model, name: "bailian-cli", baseUrl, envKey: ENV_KEY });
entries.push({
id: model,
name: displayName(model),
baseUrl,
envKey: ENV_KEY,
});
}
providers[protocol] = entries;
settings.modelProviders = providers;
// security.auth — select the protocol and carry the OpenAI-compatible creds.
// security.auth — select the protocol AND keep credentials as a fallback
// layer (see the file-level note): without this, a stray system
// OPENAI_API_KEY can win when the provider→envKey lookup does not resolve.
const security = (settings.security ?? {}) as Record<string, unknown>;
security.auth = { selectedType: protocol, apiKey, baseUrl };
settings.security = security;
// model — active model, disambiguated by baseUrl.
// model — active model. baseUrl MUST be written alongside name; Qwen Code
// uses it to disambiguate same-id providers, and omitting it can misroute
// to a different entry (and thus a different credential).
settings.model = { name: model, baseUrl };
writeJsonAtomic(settingsPath, settings);
@@ -56,6 +113,7 @@ export default {
return {
paths: [settingsPath],
nextStep: "Run `qwen` to start using Qwen Code with DashScope.",
warnings: warnings.length > 0 ? warnings : undefined,
};
},
} satisfies AgentDef;
@@ -1,17 +1,24 @@
import { dirname } from "path";
import { existsSync, readFileSync, writeFileSync, mkdirSync, renameSync, copyFileSync } from "fs";
import { BailianError, ExitCode } from "bailian-cli-core";
/** Parameters shared by every agent writer. */
export interface WriteParams {
baseUrl: string;
apiKey: string;
model: string;
/** OpenClaw model entry context window (tokens). */
contextWindow?: number;
/** Codex provider wire protocol: "responses" or "chat". */
wireApi?: string;
}
/** What a writer reports back after configuring an agent. */
export interface WriteSummary {
paths: string[];
nextStep: string;
/** Non-fatal issues the command should surface to the user. */
warnings?: string[];
}
/** An agent configuration writer: a human label plus a `write` that applies it. */
@@ -20,6 +27,83 @@ export interface AgentDef {
write(params: WriteParams): WriteSummary;
}
/**
* Strip JSONC syntax (line / block comments and trailing commas) so the result
* parses with `JSON.parse`. String contents are preserved verbatim.
*/
export function stripJsonc(text: string): string {
// Pass 1 — drop comments (string contents preserved verbatim).
let uncommented = "";
let index = 0;
let inString = false;
while (index < text.length) {
const char = text[index];
const next = text[index + 1];
if (inString) {
uncommented += char;
if (char === "\\") {
uncommented += next ?? "";
index += 2;
continue;
}
if (char === '"') inString = false;
index += 1;
continue;
}
if (char === '"') {
inString = true;
uncommented += char;
index += 1;
continue;
}
if (char === "/" && next === "/") {
while (index < text.length && text[index] !== "\n") index += 1;
continue;
}
if (char === "/" && next === "*") {
index += 2;
while (index < text.length && !(text[index] === "*" && text[index + 1] === "/")) index += 1;
index += 2;
continue;
}
uncommented += char;
index += 1;
}
// Pass 2 — drop trailing commas (a comma whose next non-whitespace char
// closes an object/array). Runs after comment removal so a trailing comment
// cannot hide the closing bracket.
let output = "";
index = 0;
inString = false;
while (index < uncommented.length) {
const char = uncommented[index];
if (inString) {
output += char;
if (char === "\\") {
output += uncommented[index + 1] ?? "";
index += 2;
continue;
}
if (char === '"') inString = false;
index += 1;
continue;
}
if (char === '"') inString = true;
if (char === ",") {
let lookahead = index + 1;
while (lookahead < uncommented.length && /\s/.test(uncommented[lookahead])) lookahead += 1;
if (uncommented[lookahead] === "}" || uncommented[lookahead] === "]") {
index += 1;
continue;
}
}
output += char;
index += 1;
}
return output;
}
/** Read a JSON object file, returning `{}` when missing or unparseable. */
export function readJson(path: string): Record<string, unknown> {
if (!existsSync(path)) return {};
@@ -30,6 +114,16 @@ export function readJson(path: string): Record<string, unknown> {
}
}
/** Like {@link readJson}, but tolerates JSONC (comments / trailing commas). */
export function readJsonc(path: string): Record<string, unknown> {
if (!existsSync(path)) return {};
try {
return JSON.parse(stripJsonc(readFileSync(path, "utf-8"))) as Record<string, unknown>;
} catch {
return {};
}
}
/** Atomically write `data` as pretty JSON with owner-only permissions. */
export function writeJsonAtomic(path: string, data: unknown): void {
mkdirSync(dirname(path), { recursive: true });
@@ -57,3 +151,65 @@ export function backup(path: string): void {
export function isAnthropicEndpoint(baseUrl: string): boolean {
return baseUrl.includes("/apps/anthropic");
}
/**
* Claude Code speaks Anthropic Messages only. Users often paste the OpenAI
* compatible-mode URL; rewrite that to `/apps/anthropic` when possible, otherwise
* fail with a clear USAGE error before writing a broken config.
*/
export function resolveClaudeCodeBaseUrl(baseUrl: string): {
url: string;
rewrittenFrom?: string;
} {
const trimmed = baseUrl.trim().replace(/\/+$/, "");
if (isAnthropicEndpoint(trimmed)) {
return { url: trimmed };
}
if (trimmed.includes("/compatible-mode")) {
const rewritten = trimmed.replace(/\/compatible-mode(?:\/v\d+)?/, "/apps/anthropic");
return { url: rewritten, rewrittenFrom: baseUrl.trim() };
}
try {
const parsed = new URL(trimmed);
const host = parsed.hostname;
const isDashScopeHost =
host.includes("dashscope") ||
host.includes("maas.aliyuncs.com") ||
host.includes("token-plan");
if (isDashScopeHost && (parsed.pathname === "/" || parsed.pathname === "")) {
return {
url: `${parsed.origin}/apps/anthropic`,
rewrittenFrom: baseUrl.trim(),
};
}
} catch {
// Fall through to the USAGE error below.
}
throw new BailianError(
`Claude Code requires an Anthropic-compatible base URL, got "${baseUrl}".`,
ExitCode.USAGE,
"Use a URL ending in /apps/anthropic (not /compatible-mode/v1). Example: https://dashscope.aliyuncs.com/apps/anthropic",
);
}
/**
* Convert a Model Studio region id into a Token Plan base URL, used in place of
* --base-url. Produces the OpenAI-compatible endpoint; the claude-code writer
* rewrites it to /apps/anthropic on its own, and the other writers consume the
* compatible-mode URL directly.
*/
export function resolveRegionBaseUrl(region: string): string {
const normalized = region.trim();
if (!/^[a-z0-9-]+$/.test(normalized)) {
throw new BailianError(
`Invalid --region "${region}".`,
ExitCode.USAGE,
"Use a Model Studio region id, e.g. cn-beijing or ap-southeast-1.",
);
}
return `https://token-plan.${normalized}.maas.aliyuncs.com/compatible-mode/v1`;
}
@@ -0,0 +1,160 @@
// Read/manage the local assets that `bl` writes into the output directory
// (default ~/bailian-output, overridable via the `output_dir` config key).
// Generated media may live directly under the base or in any subfolder (bl's
// own images/, videos/, speech/, omni/, or user-created folders). This module
// recursively discovers every file under the base, classifies each by type,
// derives its category from the top-level folder, and provides safe path
// resolution for serving/deleting individual assets.
import { readdirSync, statSync, existsSync, type Dirent } from "node:fs";
import { homedir } from "node:os";
import { join, extname, relative, resolve, sep } from "node:path";
export type AssetKind = "image" | "video" | "audio" | "other";
/** One generated file discovered under the output directory. */
export interface AssetInfo {
name: string;
/** Category folder the file lives in: images | videos | speech | omni | other. */
category: string;
kind: AssetKind;
/** Path relative to the output base (used as the API handle). */
relPath: string;
size: number;
/** Modification time in epoch milliseconds ~= generation time. */
mtime: number;
ext: string;
}
/** Max directory depth to descend from the output base when scanning. */
const MAX_SCAN_DEPTH = 8;
const KIND_BY_EXT: Record<string, AssetKind> = {
".png": "image",
".jpg": "image",
".jpeg": "image",
".webp": "image",
".gif": "image",
".bmp": "image",
".svg": "image",
".mp4": "video",
".mov": "video",
".webm": "video",
".mkv": "video",
".avi": "video",
".mp3": "audio",
".wav": "audio",
".m4a": "audio",
".aac": "audio",
".flac": "audio",
".ogg": "audio",
};
const CONTENT_TYPE: Record<string, string> = {
".png": "image/png",
".jpg": "image/jpeg",
".jpeg": "image/jpeg",
".webp": "image/webp",
".gif": "image/gif",
".bmp": "image/bmp",
".svg": "image/svg+xml",
".mp4": "video/mp4",
".mov": "video/quicktime",
".webm": "video/webm",
".mkv": "video/x-matroska",
".avi": "video/x-msvideo",
".mp3": "audio/mpeg",
".wav": "audio/wav",
".m4a": "audio/mp4",
".aac": "audio/aac",
".flac": "audio/flac",
".ogg": "audio/ogg",
};
/** The default output base when `output_dir` is not configured. */
export function defaultOutputBase(home: string = homedir()): string {
return join(home, "bailian-output");
}
function kindOf(ext: string): AssetKind {
return KIND_BY_EXT[ext.toLowerCase()] ?? "other";
}
/** MIME type for serving an asset; falls back to a safe binary type. */
export function contentType(ext: string): string {
return CONTENT_TYPE[ext.toLowerCase()] ?? "application/octet-stream";
}
/** Recursively collect regular files under `dir`, descending at most `depth` levels. */
function walk(dir: string, depth: number, out: string[]): void {
let entries: Dirent[];
try {
entries = readdirSync(dir, { withFileTypes: true });
} catch {
return;
}
for (const e of entries) {
const full = join(dir, e.name);
if (e.isDirectory()) {
if (depth > 0) walk(full, depth - 1, out);
} else if (e.isFile() || e.isSymbolicLink()) {
out.push(full);
}
}
}
/**
* List generated assets under `base`, newest first. Recursively scans every
* subfolder under the base (plus loose files at the root), so assets in bl's
* own category dirs and any user-created folders are all discovered. Each
* file's `category` is its top-level folder name, or "other" for root files.
* Returns the resolved base so callers can surface it in the UI.
*/
export function listAssets(base: string = defaultOutputBase()): {
base: string;
assets: AssetInfo[];
} {
const assets: AssetInfo[] = [];
if (!existsSync(base)) return { base, assets };
const files: string[] = [];
walk(base, MAX_SCAN_DEPTH, files);
for (const full of files) {
let st;
try {
st = statSync(full);
} catch {
continue;
}
if (!st.isFile()) continue;
const rel = relative(base, full);
const segments = rel.split(sep);
const category = segments.length > 1 ? segments[0]! : "other";
const ext = extname(full);
assets.push({
name: full.split(sep).pop() ?? full,
category,
kind: kindOf(ext),
relPath: rel,
size: st.size,
mtime: st.mtimeMs,
ext: ext.replace(/^\./, "").toLowerCase(),
});
}
assets.sort((a, b) => b.mtime - a.mtime);
return { base, assets };
}
/**
* Resolve a client-supplied relative path to an absolute path strictly inside
* `base`. Returns null for empty input or any path that would escape the base
* (path traversal guard).
*/
export function resolveAssetPath(base: string, relPath: string): string | null {
if (typeof relPath !== "string" || relPath.length === 0) return null;
const root = resolve(base);
const abs = resolve(root, relPath);
if (abs !== root && !abs.startsWith(root + sep)) return null;
return abs;
}
File diff suppressed because it is too large Load Diff
+353
View File
@@ -0,0 +1,353 @@
/**
* Minimal, dependency-free QR Code encoder used by the config UI to show a
* scannable code for the current session URL.
*
* Scope is deliberately narrow: byte mode, error-correction level L, versions
* 15 (21x21 … 37x37). Restricting to level L keeps every supported version a
* single ReedSolomon block, so no codeword interleaving is required. Version 5
* (level L) holds up to 108 data bytes, comfortably more than a
* `http://127.0.0.1:<port>/?token=<hex>` URL.
*
* The output is an SVG string with a 4-module quiet zone and a `viewBox` only
* (no fixed width/height), so the caller sizes it via CSS.
*/
// --- GF(256) arithmetic (primitive polynomial 0x11D) ---
const EXP = new Uint8Array(512);
const LOG = new Uint8Array(256);
(() => {
let x = 1;
for (let i = 0; i < 255; i++) {
EXP[i] = x;
LOG[x] = i;
x <<= 1;
if (x & 0x100) x ^= 0x11d;
}
for (let i = 255; i < 512; i++) EXP[i] = EXP[i - 255];
})();
function gmul(a: number, b: number): number {
if (a === 0 || b === 0) return 0;
return EXP[LOG[a] + LOG[b]];
}
/** ReedSolomon generator polynomial for `degree` EC codewords (alpha exponents). */
export function rsGeneratorExp(degree: number): number[] {
let poly = [1];
for (let i = 0; i < degree; i++) {
const next: number[] = Array.from({ length: poly.length + 1 }, () => 0);
for (let j = 0; j < poly.length; j++) {
next[j] ^= poly[j];
next[j + 1] ^= gmul(poly[j], EXP[i]);
}
poly = next;
}
return poly.map((v) => LOG[v]);
}
/** Compute `ecLen` ReedSolomon error-correction codewords for `data`. */
export function rsEncode(data: number[], ecLen: number): number[] {
const gen = rsGeneratorExp(ecLen);
const res = new Uint8Array(data.length + ecLen);
res.set(data, 0);
for (let i = 0; i < data.length; i++) {
const coef = res[i];
if (coef !== 0) {
const lead = LOG[coef];
for (let j = 0; j < gen.length; j++) res[i + j] ^= EXP[(gen[j] + lead) % 255];
}
}
return Array.from(res.slice(data.length));
}
// --- Capacity table: [data codewords, EC codewords] per version at level L ---
const CAP_L: Array<[number, number]> = [
[19, 7], // V1 (21x21)
[34, 10], // V2 (25x25)
[55, 15], // V3 (29x29)
[80, 20], // V4 (33x33)
[108, 26], // V5 (37x37)
];
const EC_BITS_L = 0b01; // format-info error-correction level bits for L
function pickVersion(byteLen: number): number {
const bits = 4 + 8 + byteLen * 8; // mode + 8-bit count (V19) + payload
for (let v = 0; v < CAP_L.length; v++) {
if (CAP_L[v][0] * 8 >= bits) return v + 1;
}
throw new Error("qr: data too large for supported versions (max 108 bytes)");
}
// --- Bit/codeword assembly ---
function toCodewords(bytes: Uint8Array, version: number): number[] {
const [dataCw] = CAP_L[version - 1];
const bits: number[] = [];
const put = (val: number, len: number) => {
for (let i = len - 1; i >= 0; i--) bits.push((val >> i) & 1);
};
put(0b0100, 4); // byte mode
put(bytes.length, 8); // character count (versions 19)
for (const b of bytes) put(b, 8);
const capBits = dataCw * 8;
put(0, Math.min(4, capBits - bits.length)); // terminator
while (bits.length % 8 !== 0) bits.push(0); // pad to byte
const data: number[] = [];
for (let i = 0; i < bits.length; i += 8) {
let v = 0;
for (let j = 0; j < 8; j++) v = (v << 1) | bits[i + j];
data.push(v);
}
const pads = [0xec, 0x11];
for (let p = 0; data.length < dataCw; p++) data.push(pads[p % 2]);
return data.concat(rsEncode(data, CAP_L[version - 1][1]));
}
// --- Matrix construction ---
interface Grid {
size: number;
mod: Uint8Array; // 0/1
fn: Uint8Array; // 1 = function/reserved module (skip during data placement)
}
function newGrid(size: number): Grid {
return { size, mod: new Uint8Array(size * size), fn: new Uint8Array(size * size) };
}
function setFn(g: Grid, r: number, c: number, dark: number): void {
g.mod[r * g.size + c] = dark;
g.fn[r * g.size + c] = 1;
}
function drawFinder(g: Grid, r: number, c: number): void {
for (let dr = -1; dr <= 7; dr++) {
for (let dc = -1; dc <= 7; dc++) {
const rr = r + dr;
const cc = c + dc;
if (rr < 0 || rr >= g.size || cc < 0 || cc >= g.size) continue;
const inRing = dr >= 0 && dr <= 6 && dc >= 0 && dc <= 6;
const isDark =
inRing &&
(dr === 0 ||
dr === 6 ||
dc === 0 ||
dc === 6 ||
(dr >= 2 && dr <= 4 && dc >= 2 && dc <= 4));
setFn(g, rr, cc, isDark ? 1 : 0);
}
}
}
function drawAlignment(g: Grid, cr: number, cc: number): void {
for (let dr = -2; dr <= 2; dr++) {
for (let dc = -2; dc <= 2; dc++) {
const ring = Math.max(Math.abs(dr), Math.abs(dc));
setFn(g, cr + dr, cc + dc, ring === 1 ? 0 : 1);
}
}
}
function drawFunctionPatterns(g: Grid, version: number): void {
const size = g.size;
// Timing patterns.
for (let i = 0; i < size; i++) {
setFn(g, 6, i, i % 2 === 0 ? 1 : 0);
setFn(g, i, 6, i % 2 === 0 ? 1 : 0);
}
// Finder patterns + separators (drawn as the -1 border above).
drawFinder(g, 0, 0);
drawFinder(g, 0, size - 7);
drawFinder(g, size - 7, 0);
// Alignment pattern (single, centered) for versions 25.
if (version >= 2) {
const pos = size - 7; // e.g. 18 (V2), 22 (V3), 26 (V4), 30 (V5)
drawAlignment(g, pos, pos);
}
// Reserve format-info areas (values written later).
for (let i = 0; i < 9; i++) {
if (!(i === 6)) g.fn[8 * size + i] = 1;
if (!(i === 6)) g.fn[i * size + 8] = 1;
}
g.fn[8 * size + 6] = 1;
g.fn[6 * size + 8] = 1;
for (let i = 0; i < 8; i++) g.fn[(size - 1 - i) * size + 8] = 1;
for (let i = 0; i < 8; i++) g.fn[8 * size + (size - 1 - i)] = 1;
// Dark module.
setFn(g, size - 8, 8, 1);
}
function placeData(g: Grid, codewords: number[]): void {
const size = g.size;
const stream: number[] = [];
for (const cw of codewords) for (let i = 7; i >= 0; i--) stream.push((cw >> i) & 1);
let idx = 0;
let upward = true;
for (let col = size - 1; col >= 1; col -= 2) {
if (col === 6) col = 5; // skip the vertical timing column
for (let i = 0; i < size; i++) {
const row = upward ? size - 1 - i : i;
for (const off of [0, 1]) {
const cc = col - off;
if (g.fn[row * size + cc]) continue;
g.mod[row * size + cc] = idx < stream.length ? stream[idx++] : 0;
}
}
upward = !upward;
}
}
const MASKS: Array<(r: number, c: number) => boolean> = [
(r, c) => (r + c) % 2 === 0,
(r) => r % 2 === 0,
(_r, c) => c % 3 === 0,
(r, c) => (r + c) % 3 === 0,
(r, c) => (Math.floor(r / 2) + Math.floor(c / 3)) % 2 === 0,
(r, c) => ((r * c) % 2) + ((r * c) % 3) === 0,
(r, c) => (((r * c) % 2) + ((r * c) % 3)) % 2 === 0,
(r, c) => (((r + c) % 2) + ((r * c) % 3)) % 2 === 0,
];
function applyMask(g: Grid, mask: number): void {
const cond = MASKS[mask];
for (let r = 0; r < g.size; r++) {
for (let c = 0; c < g.size; c++) {
if (!g.fn[r * g.size + c] && cond(r, c)) g.mod[r * g.size + c] ^= 1;
}
}
}
function penalty(g: Grid): number {
const size = g.size;
const at = (r: number, c: number) => g.mod[r * size + c];
let score = 0;
// Rule 1: runs of >=5 same-color modules in rows and columns.
for (let r = 0; r < size; r++) {
let runC = 1;
let runR = 1;
for (let c = 1; c < size; c++) {
if (at(r, c) === at(r, c - 1)) runC++;
else {
if (runC >= 5) score += runC - 2;
runC = 1;
}
if (at(c, r) === at(c - 1, r)) runR++;
else {
if (runR >= 5) score += runR - 2;
runR = 1;
}
}
if (runC >= 5) score += runC - 2;
if (runR >= 5) score += runR - 2;
}
// Rule 2: 2x2 blocks of the same color.
for (let r = 0; r < size - 1; r++) {
for (let c = 0; c < size - 1; c++) {
const v = at(r, c);
if (v === at(r, c + 1) && v === at(r + 1, c) && v === at(r + 1, c + 1)) score += 3;
}
}
// Rule 3: finder-like 1:1:3:1:1 patterns.
const pat1 = [1, 0, 1, 1, 1, 0, 1, 0, 0, 0, 0];
const pat2 = [0, 0, 0, 0, 1, 0, 1, 1, 1, 0, 1];
const match = (get: (k: number) => number, start: number, pat: number[]) => {
for (let k = 0; k < pat.length; k++) if (get(start + k) !== pat[k]) return false;
return true;
};
for (let r = 0; r < size; r++) {
for (let c = 0; c <= size - 11; c++) {
if (match((k) => at(r, k), c, pat1) || match((k) => at(r, k), c, pat2)) score += 40;
if (match((k) => at(k, r), c, pat1) || match((k) => at(k, r), c, pat2)) score += 40;
}
}
// Rule 4: proportion of dark modules.
let dark = 0;
for (let i = 0; i < size * size; i++) dark += g.mod[i];
const percent = (dark * 100) / (size * size);
const k = Math.floor(Math.abs(percent - 50) / 5);
score += k * 10;
return score;
}
function formatBits(mask: number): number {
const data = (EC_BITS_L << 3) | mask; // 5 bits
let rem = data << 10;
for (let i = 14; i >= 10; i--) if ((rem >> i) & 1) rem ^= 0x537 << (i - 10);
return ((data << 10) | rem) ^ 0x5412;
}
function drawFormat(g: Grid, mask: number): void {
const size = g.size;
const fmt = formatBits(mask);
const bit = (i: number) => (fmt >> i) & 1;
// First copy: around the top-left finder. Bits 05 run down column 8
// (rows 05); bits 914 run left along row 8 (cols 50).
for (let i = 0; i <= 5; i++) g.mod[i * size + 8] = bit(i);
g.mod[7 * size + 8] = bit(6);
g.mod[8 * size + 8] = bit(7);
g.mod[8 * size + 7] = bit(8);
for (let i = 9; i < 15; i++) g.mod[8 * size + (14 - i)] = bit(i);
// Second copy: split across top-right and bottom-left.
for (let i = 0; i < 8; i++) g.mod[(size - 1 - i) * size + 8] = bit(i);
for (let i = 8; i < 15; i++) g.mod[8 * size + (size - 15 + i)] = bit(i);
g.mod[(size - 8) * size + 8] = 1; // dark module stays set
}
/** Build the final QR module matrix (true = dark) for `text`. */
export function qrMatrix(text: string): boolean[][] {
const bytes = new TextEncoder().encode(text);
const version = pickVersion(bytes.length);
const codewords = toCodewords(bytes, version);
const g = newGrid(17 + 4 * version);
drawFunctionPatterns(g, version);
placeData(g, codewords);
let best = 0;
let bestScore = Infinity;
for (let m = 0; m < 8; m++) {
applyMask(g, m);
drawFormat(g, m);
const s = penalty(g);
if (s < bestScore) {
bestScore = s;
best = m;
}
applyMask(g, m); // undo (XOR is its own inverse)
}
applyMask(g, best);
drawFormat(g, best);
const out: boolean[][] = [];
for (let r = 0; r < g.size; r++) {
const row: boolean[] = [];
for (let c = 0; c < g.size; c++) row.push(g.mod[r * g.size + c] === 1);
out.push(row);
}
return out;
}
/** Render `text` as an SVG QR code string (4-module quiet zone, viewBox only). */
export function qrSvg(text: string): string {
const m = qrMatrix(text);
const size = m.length;
const quiet = 4;
const dim = size + quiet * 2;
let rects = "";
for (let r = 0; r < size; r++) {
for (let c = 0; c < size; c++) {
if (m[r][c]) rects += `<rect x="${c + quiet}" y="${r + quiet}" width="1" height="1"/>`;
}
}
return (
`<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 ${dim} ${dim}" ` +
`shape-rendering="crispEdges" role="img" aria-label="QR code">` +
`<rect width="${dim}" height="${dim}" fill="#ffffff"/>` +
`<g fill="#000000">${rects}</g></svg>`
);
}
@@ -0,0 +1,166 @@
/**
* Curated "Playground" scenarios surfaced in the config UI.
*
* Each scenario is a fixed, reviewable prompt template that the UI can dispatch
* to a connected local coding agent (e.g. qwen-code), which then runs it in a
* new terminal. Optional `{{inputs}}` are filled by the user before dispatch.
*
* Prompts are defined here and never accepted as free-form text from the web,
* so the instruction handed to a local agent is always known and auditable.
*/
export interface ScenarioInput {
key: string;
label: string;
placeholder?: string;
}
export interface Scenario {
id: string;
title: string;
description: string;
category: string;
prompt: string;
inputs?: ScenarioInput[];
}
export const SCENARIOS: Scenario[] = [
// ---- 图像 ----
{
id: "image-generate",
title: "文生图",
description: "一键生成一张示例图片并保存到输出目录。",
category: "图像",
prompt:
"请使用 bl 的图像生成能力(如 `bl image generate` 命令)生成一张示例图片:一只在雨中撑伞的柯基,水彩风格,光线柔和。保存到输出目录后告诉我文件路径。",
},
{
id: "image-describe",
title: "图片理解",
description: "从输出目录任选一张图片,详细描述内容与风格。",
category: "图像",
prompt:
"请在输出目录(默认 output/images中任选一张图片用中文详细描述它的内容、主体、构图、色彩与风格并推测它适合的使用场景。若目录为空请说明。",
},
{
id: "image-alt-batch",
title: "批量 Alt 文本",
description: "为输出目录下的图片批量生成无障碍 alt 文本。",
category: "图像",
prompt:
"请扫描输出目录(默认 output/images下的所有图片逐张生成简洁、准确的 alt 无障碍描述,最后以「文件名 → alt 文本」的表格汇总。若目录为空请说明。",
},
{
id: "image-to-code",
title: "截图转代码",
description: "把输出目录里的界面截图还原成 HTML+CSS。",
category: "图像",
prompt:
"请在输出目录(默认 output/images中查找一张界面截图用 HTML + CSS 尽可能还原它的布局、间距与配色,输出为一个可直接在浏览器打开的单文件,并简述还原思路。若没有找到截图请说明。",
},
// ---- 音频 ----
{
id: "speech-generate",
title: "文字转语音",
description: "把一句示例文字合成为自然语音。",
category: "音频",
prompt:
"请使用 bl 的语音合成能力(如 `bl speech` 相关命令)把下面这句话合成为自然语音,保存到输出目录,并告诉我音频文件路径:欢迎使用阿里云百炼命令行工具,让多模态创作更简单。",
},
{
id: "audio-summarize",
title: "音频转写总结",
description: "转写输出目录里的音频并提炼要点。",
category: "音频",
prompt:
"请在输出目录(默认 output/speech中找到一个音频文件转写其内容先给出完整文字再用要点列表总结关键信息。若目录为空或缺少转写能力请说明并尝试用可用的能力完成。",
},
// ---- 视频 ----
{
id: "video-generate",
title: "文生视频",
description: "一键生成一段示例短视频。",
category: "视频",
prompt:
"请使用 bl 的视频生成能力(如 `bl video generate` 命令)生成一段示例短视频:日落时分海边奔跑的少年,电影质感,慢动作。保存到输出目录后告诉我视频文件路径。",
},
{
id: "video-storyboard",
title: "视频分镜脚本",
description: "围绕示例主题产出可用于文生视频的分镜。",
category: "视频",
prompt:
"围绕主题「城市清晨的第一杯咖啡」,为一支 15-30 秒的短视频撰写分镜脚本:逐镜头给出画面描述、时长、字幕或旁白,并为每个镜头附上可直接用于文生视频的英文 prompt。",
},
// ---- 多模态 ----
{
id: "media-prompt-craft",
title: "多模态提示词",
description: "把一个示例创意扩展成图/视频/语音提示词。",
category: "多模态",
prompt:
"把创意「未来赛博城市的夜市」扩展成三组高质量生成提示词1) 文生图2) 文生视频3) 语音风格描述。每组给出中英对照,并简要说明关键参数建议。",
},
{
id: "image-story-narration",
title: "图片配音文案",
description: "为输出目录里的图片写解说词并给出可合成文本。",
category: "多模态",
prompt:
"请在输出目录(默认 output/images中任选一张图片为它撰写一段 60 秒左右的中文解说词(适合配音),语气生动。随后给出可直接用于语音合成的纯文本版本。若目录为空请说明。",
},
// ---- 代码 ----
{
id: "summarize-project",
title: "总结当前项目",
description: "让 agent 阅读当前目录,总结架构、技术栈与主要模块。",
category: "代码",
prompt:
"请阅读当前工作目录的项目结构和关键源码用简洁的中文总结1) 它是做什么的2) 技术栈3) 主要模块及其职责4) 值得注意的设计。先浏览再下结论,不要臆测。",
},
{
id: "write-tests",
title: "为核心模块写单测",
description: "自动挑选缺测试的核心模块并补全单元测试。",
category: "代码",
prompt:
"请在当前项目中挑选一个核心且缺少测试(或测试薄弱)的模块,为它编写全面的单元测试,覆盖主要逻辑分支和边界情况,并遵循本项目现有的测试框架与风格。先阅读相关文件及其依赖,再编写测试。",
},
{
id: "code-review",
title: "代码审查",
description: "审查当前项目核心代码,指出问题与改进建议。",
category: "代码",
prompt:
"请审查当前项目的核心源码,指出潜在的 bug、安全隐患、性能与可维护性问题并给出具体、可操作的改进建议按严重程度排序。先浏览项目结构选取关键文件再审查。",
},
{
id: "explain-code",
title: "解释核心代码",
description: "挑选入口或核心模块,解释其实现与依赖。",
category: "代码",
prompt:
"请挑选当前项目的入口文件或核心模块,解释它的实现:职责是什么、关键流程如何运转、依赖了哪些模块。用清晰的中文说明,必要时给出调用关系。",
},
// ---- 文档 ----
{
id: "generate-readme",
title: "生成 README",
description: "阅读代码后生成结构清晰、与实现一致的 README.md。",
category: "文档",
prompt:
"为当前工作目录的项目生成一个结构清晰的 README.md包含项目简介、安装步骤、使用示例、目录结构说明。请先阅读现有代码与配置再撰写内容必须与实际实现一致。",
},
];
/** Look up a scenario by id, or undefined when unknown. */
export function getScenario(id: string): Scenario | undefined {
return SCENARIOS.find((s) => s.id === id);
}
/** Fill a scenario's `{{placeholder}}` tokens from user-provided values. */
export function renderScenarioPrompt(scenario: Scenario, values: Record<string, string>): string {
return scenario.prompt.replace(/\{\{(\w+)\}\}/g, (_match, key: string) => {
const v = values[key];
return typeof v === "string" ? v.trim() : "";
});
}
@@ -32,6 +32,79 @@ export const SECRET_KEYS = new Set<string>([
"security_token",
]);
// The web UI edits the full ConfigFile, so it exposes these extra keys on top
// of VALID_KEYS (which `config set` keeps as its narrower, documented surface).
// This lets `config ui` surface and edit every field that lives in config.json
// rather than silently hiding console/telemetry settings.
export const UI_EXTRA_KEYS = [
"console_site",
"console_region",
"console_switch_agent",
"telemetry",
] as const;
export const UI_VALID_KEYS = [...VALID_KEYS, ...UI_EXTRA_KEYS] as const;
// Keys the UI renders as a fixed-choice dropdown instead of a free-text input.
export const UI_ENUM_KEYS: Record<string, string[]> = {
output: ["text", "json"],
console_site: ["domestic", "international"],
};
// Keys the UI renders as a true/false dropdown and stores as a boolean.
export const UI_BOOLEAN_KEYS = new Set<string>(["telemetry"]);
// Default model each `default_*_model` key falls back to when left unset. These
// mirror the inline `|| "<model>"` fallbacks in the generation commands
// (text/chat, image/generate, video/generate, speech/synthesize, omni/chat) and
// are surfaced as input placeholders so users can see the effective default
// without persisting a value that would pin the model.
export const UI_MODEL_DEFAULTS: Record<string, string> = {
default_text_model: "qwen3.7-max",
default_image_model: "qwen-image-2.0",
default_video_model: "happyhorse-1.1-t2v",
default_speech_model: "cosyvoice-v3-flash",
default_omni_model: "qwen3.5-omni-plus",
};
/** One selectable model plus a short note on where the CLI uses it. */
export interface ModelOption {
id: string;
role: string;
}
// A per-category catalog of the model names the `bl` pipeline actually
// references (packages/runtime/src/pipeline/steps/bl-api.ts, plus the advisor
// and agent-writer helpers). The UI groups these under each `default_*_model`
// field as click-to-fill suggestions; the first entry is the fallback default.
// Only names present in the codebase are listed here — no invented models.
export const UI_MODEL_CATALOG: Record<string, ModelOption[]> = {
default_text_model: [
{ id: "qwen3.7-max", role: "text/chat default" },
{ id: "qwen3-coder-plus", role: "coding-oriented (agent config)" },
{ id: "qwen-flash", role: "fast · advisor ranking" },
{ id: "qwen3.6-flash", role: "fast · advisor intent" },
],
default_image_model: [
{ id: "qwen-image-2.0", role: "image/generate default · sync" },
{ id: "qwen-image-max", role: "image/generate · sync" },
{ id: "qwen-image-edit-2.0", role: "image/edit · sync" },
{ id: "wanx2.x", role: "image/generate · async series" },
],
default_video_model: [
{ id: "happyhorse-1.1-t2v", role: "video/generate default · text-to-video" },
{ id: "happyhorse-1.1-i2v", role: "video/generate · image-to-video" },
],
default_speech_model: [
{ id: "cosyvoice-v3-flash", role: "speech/synthesize (TTS) default" },
{ id: "fun-asr", role: "speech/recognize (ASR)" },
],
default_omni_model: [
{ id: "qwen3.5-omni-plus", role: "omni/chat default" },
{ id: "qwen3-vl-plus", role: "vision/describe · multimodal input" },
],
};
// Allow hyphen-style keys (e.g. default-text-model → default_text_model).
export const KEY_ALIASES: Record<string, string> = {
"base-url": "base_url",
@@ -92,3 +165,55 @@ export function validateAndCoerce(key: string, value: string): string | number {
return value;
}
/**
* Validate/coerce a value for the wider set of keys the web UI can edit
* (UI_VALID_KEYS). Standard keys delegate to `validateAndCoerce`; the UI-only
* extras (console_*, telemetry) are validated here. Booleans are returned as
* real booleans so they persist correctly in config.json.
*/
export function validateAndCoerceUi(key: string, value: string): string | number | boolean {
const resolvedKey = resolveKey(key);
if ((VALID_KEYS as readonly string[]).includes(resolvedKey)) {
return validateAndCoerce(key, value);
}
if (resolvedKey === "console_site") {
if (!["domestic", "international"].includes(value)) {
throw new BailianError(
`Invalid console_site "${value}". Valid values: domestic, international`,
ExitCode.USAGE,
);
}
return value;
}
if (resolvedKey === "console_region") return value;
if (resolvedKey === "console_switch_agent") {
const num = Number(value);
if (!Number.isFinite(num) || num <= 0) {
throw new BailianError(
`Invalid console_switch_agent "${value}". Must be a positive number.`,
ExitCode.USAGE,
);
}
return num;
}
if (resolvedKey === "telemetry") {
if (value !== "true" && value !== "false") {
throw new BailianError(
`Invalid telemetry "${value}". Valid values: true, false`,
ExitCode.USAGE,
);
}
return value === "true";
}
throw new BailianError(
`Invalid config key "${key}". Valid keys: ${UI_VALID_KEYS.join(", ")}`,
ExitCode.USAGE,
);
}
File diff suppressed because one or more lines are too long
+481 -17
View File
@@ -1,5 +1,7 @@
import http from "node:http";
import { randomBytes } from "node:crypto";
import { randomBytes, timingSafeEqual } from "node:crypto";
import { createReadStream, existsSync, statSync, unlinkSync } from "node:fs";
import { extname } from "node:path";
import {
defineCommand,
@@ -10,13 +12,38 @@ import {
readConfigFile,
writeConfigFile,
deleteConfigProfile,
REGIONS,
type ConfigStore,
type FlagsDef,
} from "bailian-cli-core";
import { emitResult, emitBare } from "bailian-cli-runtime";
import { listenLocalServer, openInBrowser } from "../shared/local-server.ts";
import { listenLocalServer, openInBrowser, openPath } from "../shared/local-server.ts";
import { PAGE_HTML } from "./ui-html.ts";
import { VALID_KEYS, SECRET_KEYS, resolveKey, validateAndCoerce } from "./shared.ts";
import {
UI_VALID_KEYS,
UI_ENUM_KEYS,
UI_BOOLEAN_KEYS,
UI_MODEL_DEFAULTS,
UI_MODEL_CATALOG,
SECRET_KEYS,
resolveKey,
validateAndCoerceUi,
} from "./shared.ts";
import {
listSkills,
listMcpServers,
listAgents,
getSkillDetail,
getAgentDetail,
writeMcpServer,
deleteMcpServer,
installSkillZip,
} from "./inventory.ts";
import { launchAgent, agentLaunchable, agentSupportsPrompt } from "./agent-launch.ts";
import { SCENARIOS, getScenario, renderScenarioPrompt, type Scenario } from "./scenarios.ts";
import { qrSvg } from "./qr.ts";
import { makeAuthUiBridge, type AuthUiBridge } from "../auth/console-ui.ts";
import { listAssets, resolveAssetPath, defaultOutputBase, contentType } from "./assets.ts";
const FLAGS = {
port: {
@@ -50,6 +77,7 @@ function readBody(req: http.IncomingMessage): Promise<string> {
size += chunk.length;
if (size > MAX_BODY) {
reject(new Error("payload too large"));
req.destroy();
return;
}
chunks.push(chunk);
@@ -59,16 +87,47 @@ function readBody(req: http.IncomingMessage): Promise<string> {
});
}
/** Max size for binary uploads (skill .zip packages). */
const MAX_UPLOAD = 24 * (1 << 20); // 24 MiB
function readBodyBuffer(req: http.IncomingMessage, max: number): Promise<Buffer> {
return new Promise((resolve, reject) => {
let size = 0;
const chunks: Buffer[] = [];
req.on("data", (chunk: Buffer) => {
size += chunk.length;
if (size > max) {
reject(new Error("payload too large"));
req.destroy();
return;
}
chunks.push(chunk);
});
req.on("end", () => resolve(Buffer.concat(chunks)));
req.on("error", reject);
});
}
/** Constant-time token comparison (avoids timing side channels). */
function tokenMatches(provided: string | null, expected: string): boolean {
if (!provided) return false;
const a = Buffer.from(provided);
const b = Buffer.from(expected);
return a.length === b.length && timingSafeEqual(a, b);
}
/** Build the request cleaned/validated config block from a posted `data` map. */
function buildProfilePatch(data: Record<string, unknown>): Record<string, string | number> {
const cleaned: Record<string, string | number> = {};
function buildProfilePatch(
data: Record<string, unknown>,
): Record<string, string | number | boolean> {
const cleaned: Record<string, string | number | boolean> = {};
for (const [k, v] of Object.entries(data)) {
let value = "";
if (typeof v === "string") value = v;
else if (typeof v === "number" || typeof v === "boolean") value = String(v);
// null/undefined/objects fall through as "" and clear the key
if (value === "") continue;
cleaned[resolveKey(k)] = validateAndCoerce(k, value);
cleaned[resolveKey(k)] = validateAndCoerceUi(k, value);
}
return cleaned;
}
@@ -76,9 +135,9 @@ function buildProfilePatch(data: Record<string, unknown>): Record<string, string
/** Preserve valid Config fields that the UI does not expose or manage. */
function mergeUnmanagedProfileFields(
existing: Record<string, unknown>,
managedPatch: Record<string, string | number>,
managedPatch: Record<string, string | number | boolean>,
): Record<string, unknown> {
const managedKeys = new Set<string>(VALID_KEYS);
const managedKeys = new Set<string>(UI_VALID_KEYS);
const merged: Record<string, unknown> = {};
for (const [key, value] of Object.entries(existing)) {
if (!managedKeys.has(key)) merged[key] = value;
@@ -91,7 +150,12 @@ function mergeUnmanagedProfileFields(
* - Host header must be a loopback name (anti DNS-rebinding).
* - every request must carry `?token=` matching the session token.
*/
export function createConfigUiServer(token: string, configStore: ConfigStore): http.Server {
export function createConfigUiServer(
token: string,
configStore: ConfigStore,
outputBase: string = defaultOutputBase(),
authBridge?: AuthUiBridge,
): http.Server {
return http.createServer(async (req, res) => {
try {
const host = (req.headers.host || "").split(":")[0];
@@ -102,7 +166,7 @@ export function createConfigUiServer(token: string, configStore: ConfigStore): h
}
const u = new URL(req.url ?? "/", "http://127.0.0.1");
if (u.searchParams.get("token") !== token) {
if (!tokenMatches(u.searchParams.get("token"), token)) {
res.writeHead(401, { "Content-Type": "text/plain; charset=utf-8" });
res.end("unauthorized\n");
return;
@@ -112,17 +176,54 @@ export function createConfigUiServer(token: string, configStore: ConfigStore): h
const path = u.pathname;
if (path === "/" && method === "GET") {
res.writeHead(200, { "Content-Type": "text/html; charset=utf-8" });
res.writeHead(200, {
"Content-Type": "text/html; charset=utf-8",
// The page URL carries the session token, so never cache it.
"Cache-Control": "no-store",
"X-Content-Type-Options": "nosniff",
"Content-Security-Policy":
"default-src 'self'; script-src 'unsafe-inline'; style-src 'unsafe-inline'; " +
"img-src 'self' data: https://img.alicdn.com https://oss.aliyuncs.com; " +
"media-src 'self'; connect-src 'self'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'",
});
res.end(PAGE_HTML);
return;
}
if (path === "/api/qr" && method === "GET") {
const data = (u.searchParams.get("data") ?? "").slice(0, 512);
if (!data) {
sendJson(res, 400, { error: "missing data" });
return;
}
try {
const svg = qrSvg(data);
res.writeHead(200, {
"Content-Type": "image/svg+xml; charset=utf-8",
"Cache-Control": "no-store",
});
res.end(svg);
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/config" && method === "GET") {
const profiles = configStore.profiles();
sendJson(res, 200, {
configFile: configStore.path,
keys: VALID_KEYS,
keys: UI_VALID_KEYS,
secretKeys: [...SECRET_KEYS],
enums: UI_ENUM_KEYS,
booleanKeys: [...UI_BOOLEAN_KEYS],
fieldDefaults: {
...UI_MODEL_DEFAULTS,
base_url: REGIONS.cn,
output_dir: defaultOutputBase(),
timeout: "300",
},
modelCatalog: UI_MODEL_CATALOG,
activeProfile: profiles.active,
default: profiles.default,
named: profiles.named,
@@ -130,6 +231,342 @@ export function createConfigUiServer(token: string, configStore: ConfigStore): h
return;
}
if (path === "/api/skills" && method === "GET") {
sendJson(res, 200, { skills: listSkills() });
return;
}
if (path === "/api/skill" && method === "GET") {
const detail = getSkillDetail(u.searchParams.get("id") ?? "");
if (!detail) {
sendJson(res, 404, { error: "not found" });
return;
}
sendJson(res, 200, detail);
return;
}
if (path === "/api/skill/install" && method === "POST") {
const source = u.searchParams.get("source") ?? "";
const name = u.searchParams.get("name") ?? "";
try {
const buf = await readBodyBuffer(req, MAX_UPLOAD);
const result = installSkillZip(source, buf, name);
sendJson(res, 200, result);
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/mcp" && method === "GET") {
sendJson(res, 200, { servers: listMcpServers() });
return;
}
if (path === "/api/mcp" && method === "POST") {
const raw = await readBody(req);
let parsed: unknown;
try {
parsed = JSON.parse(raw);
} catch {
sendJson(res, 400, { error: "invalid JSON body" });
return;
}
const body = parsed as {
source?: unknown;
scope?: unknown;
name?: unknown;
config?: unknown;
};
const source = typeof body.source === "string" ? body.source : "";
const scope = typeof body.scope === "string" && body.scope ? body.scope : "global";
const name = typeof body.name === "string" ? body.name : "";
try {
writeMcpServer(source, scope, name, body.config);
sendJson(res, 200, { saved: name.trim() });
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/mcp" && method === "DELETE") {
const source = u.searchParams.get("source") ?? "";
const scope = u.searchParams.get("scope") || "global";
const name = u.searchParams.get("name") ?? "";
try {
deleteMcpServer(source, scope, name);
sendJson(res, 200, { deleted: name });
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/health" && method === "GET") {
const major = Number(process.versions.node.split(".")[0]);
sendJson(res, 200, {
node: process.version,
nodeOk: Number.isFinite(major) && major >= 18,
platform: process.platform,
cwd: process.cwd(),
});
return;
}
if (path === "/api/agents" && method === "GET") {
// Augment each agent with `launchable`: whether its CLI binary is on
// PATH. "Connected" only means bl is wired into the agent's config, so
// the UI uses this to avoid offering a launch that would instantly fail.
// `dispatchable` additionally requires a verified prompt contract.
const agents = listAgents();
const launchable = await Promise.all(agents.map((a) => agentLaunchable(a.id)));
sendJson(res, 200, {
agents: agents.map((a, i) => ({
...a,
launchable: launchable[i],
dispatchable: launchable[i] && agentSupportsPrompt(a.id),
})),
});
return;
}
if (path === "/api/agent" && method === "GET") {
const detail = getAgentDetail(u.searchParams.get("id") ?? "");
if (!detail) {
sendJson(res, 404, { error: "not found" });
return;
}
sendJson(res, 200, detail);
return;
}
if (path === "/api/agent/open" && method === "POST") {
const detail = getAgentDetail(u.searchParams.get("id") ?? "");
const target = u.searchParams.get("path") ?? "";
const allowed = detail?.settings.some((s) => s.path === target) ?? false;
if (!detail || !allowed || !existsSync(target)) {
sendJson(res, 404, { error: "not found" });
return;
}
try {
await openPath(target);
sendJson(res, 200, { opened: target });
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/scenarios" && method === "GET") {
// Curated Playground scenarios plus the connected agents that can be
// dispatched a prompt right now (on PATH + verified prompt contract).
const agents = listAgents();
const launchable = await Promise.all(agents.map((a) => agentLaunchable(a.id)));
const targets = agents
.map((a, i) => ({
id: a.id,
label: a.label,
dispatchable: launchable[i] && agentSupportsPrompt(a.id),
}))
.filter((a) => a.dispatchable);
sendJson(res, 200, { scenarios: SCENARIOS, agents: targets });
return;
}
if (path === "/api/auth/status" && method === "GET") {
sendJson(
res,
200,
authBridge
? authBridge.status()
: {
authenticated: false,
methods: { apiKey: false, console: false, openapi: false },
primary: null,
},
);
return;
}
if (path === "/api/auth/login" && method === "POST") {
if (!authBridge) {
sendJson(res, 400, { error: "login unavailable" });
return;
}
authBridge.startConsoleLogin();
sendJson(res, 200, { started: true });
return;
}
if (path === "/api/auth/logout" && method === "POST") {
if (!authBridge) {
sendJson(res, 400, { error: "logout unavailable" });
return;
}
try {
const loggedOut = await authBridge.logout();
sendJson(res, 200, { loggedOut });
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/assets" && method === "GET") {
sendJson(res, 200, listAssets(outputBase));
return;
}
if (path === "/api/asset/file" && method === "GET") {
const abs = resolveAssetPath(outputBase, u.searchParams.get("path") ?? "");
const st = abs && existsSync(abs) ? statSync(abs) : null;
if (!abs || !st || !st.isFile()) {
sendJson(res, 404, { error: "not found" });
return;
}
res.writeHead(200, {
"Content-Type": contentType(extname(abs)),
"Content-Length": st.size,
"Cache-Control": "no-store",
});
const stream = createReadStream(abs);
stream.on("error", () => {
if (!res.headersSent) res.writeHead(500);
res.end();
});
stream.pipe(res);
return;
}
if (path === "/api/asset" && method === "DELETE") {
const rel = u.searchParams.get("path") ?? "";
const abs = resolveAssetPath(outputBase, rel);
if (!abs || !existsSync(abs) || !statSync(abs).isFile()) {
sendJson(res, 404, { error: "not found" });
return;
}
try {
unlinkSync(abs);
sendJson(res, 200, { deleted: rel });
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/asset/open" && method === "POST") {
const rel = u.searchParams.get("path") ?? "";
const abs = resolveAssetPath(outputBase, rel);
if (!abs || !existsSync(abs) || !statSync(abs).isFile()) {
sendJson(res, 404, { error: "not found" });
return;
}
try {
await openPath(abs);
sendJson(res, 200, { opened: rel });
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/agent/launch" && method === "POST") {
try {
const result = await launchAgent(u.searchParams.get("id") ?? "");
sendJson(res, 200, result);
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/agent/dispatch" && method === "POST") {
const raw = await readBody(req);
let parsed: unknown;
try {
parsed = JSON.parse(raw);
} catch {
sendJson(res, 400, { error: "invalid JSON body" });
return;
}
const body = parsed as {
scenario?: unknown;
agent?: unknown;
values?: unknown;
custom?: unknown;
};
const agentId = typeof body.agent === "string" ? body.agent : "";
if (!agentSupportsPrompt(agentId)) {
sendJson(res, 400, { error: "agent cannot be dispatched a prompt" });
return;
}
let scenario: Scenario | undefined;
const custom = body.custom;
if (custom && typeof custom === "object" && !Array.isArray(custom)) {
const c = custom as { title?: unknown; prompt?: unknown; inputs?: unknown };
const promptTpl = typeof c.prompt === "string" ? c.prompt.trim() : "";
if (!promptTpl) {
sendJson(res, 400, { error: "custom scenario needs a prompt" });
return;
}
const inputs: { key: string; label: string }[] = [];
if (Array.isArray(c.inputs)) {
for (const it of c.inputs as unknown[]) {
if (it && typeof it === "object") {
const o = it as { key?: unknown; label?: unknown };
const key = typeof o.key === "string" ? o.key.trim() : "";
if (key) {
const label =
typeof o.label === "string" && o.label.trim() ? o.label.trim() : key;
inputs.push({ key, label });
}
}
}
}
scenario = {
id: "custom",
title: typeof c.title === "string" && c.title.trim() ? c.title.trim() : "Custom",
description: "",
category: "\u81ea\u5b9a\u4e49",
prompt: promptTpl,
inputs,
};
} else {
scenario = typeof body.scenario === "string" ? getScenario(body.scenario) : undefined;
}
if (!scenario) {
sendJson(res, 400, { error: "unknown scenario" });
return;
}
const values: Record<string, string> = {};
if (body.values && typeof body.values === "object" && !Array.isArray(body.values)) {
for (const [k, v] of Object.entries(body.values as Record<string, unknown>)) {
if (typeof v === "string") values[k] = v;
}
}
for (const inp of scenario.inputs ?? []) {
if (!values[inp.key] || !values[inp.key]!.trim()) {
sendJson(res, 400, { error: `Missing input: ${inp.label}` });
return;
}
}
const prompt = renderScenarioPrompt(scenario, values);
try {
const result = await launchAgent(agentId, process.cwd(), prompt);
sendJson(res, 200, {
launched: true,
agent: agentId,
scenario: scenario.id,
command: result.command,
});
} catch (err) {
sendJson(res, 400, { error: errMessage(err) });
}
return;
}
if (path === "/api/active" && method === "POST") {
const raw = await readBody(req);
let parsed: unknown;
@@ -164,7 +601,7 @@ export function createConfigUiServer(token: string, configStore: ConfigStore): h
return;
}
let normalized: string | undefined;
let cleaned: Record<string, string | number>;
let cleaned: Record<string, string | number | boolean>;
try {
normalized = normalizeConfigName(body.name);
cleaned = buildProfilePatch(body.data as Record<string, unknown>);
@@ -191,9 +628,15 @@ export function createConfigUiServer(token: string, configStore: ConfigStore): h
res.writeHead(404, { "Content-Type": "text/plain; charset=utf-8" });
res.end("not found\n");
} catch {
if (!res.headersSent) res.writeHead(500);
res.end();
} catch (err) {
// Log server-side so failures are diagnosable, and return a JSON error
// instead of an empty 500 body.
console.error("[config ui] request failed:", err);
if (res.headersSent) {
res.end();
return;
}
sendJson(res, 500, { error: errMessage(err) });
}
});
}
@@ -217,9 +660,29 @@ export default defineCommand({
routes: [
"GET / -> web UI",
"GET /api/config -> read all profiles",
"GET /api/skills -> list installed agent skills",
"GET /api/skill -> read one skill's SKILL.md detail",
"POST /api/skill/install -> install a skill from an uploaded .zip into a skills root",
"GET /api/mcp -> list local MCP servers",
"POST /api/mcp -> create or update one MCP server (writes its source config)",
"DELETE /api/mcp -> remove one MCP server from its source config",
"GET /api/health -> runtime environment info (node, platform, cwd)",
"GET /api/agents -> list coding agent frameworks",
"GET /api/agent -> one agent's config detail (secrets masked)",
"POST /api/agent/open -> open one agent's config file with the OS default app",
"GET /api/auth/status -> current auth state",
"POST /api/auth/login -> start console login (opens browser)",
"POST /api/auth/logout -> clear all stored credentials",
"GET /api/assets -> list generated assets",
"GET /api/asset/file -> stream one asset file",
"POST /api/asset/open -> open one asset with the OS default app",
"POST /api/agent/launch -> launch a coding agent CLI in a new terminal",
"GET /api/scenarios -> list Playground scenarios and dispatchable agents",
"POST /api/agent/dispatch -> dispatch a scenario prompt to a connected agent",
"POST /api/profile -> save a profile",
"POST /api/active -> activate a profile",
"DELETE /api/profile -> delete a named profile",
"DELETE /api/asset -> delete one asset file",
],
},
format,
@@ -228,7 +691,8 @@ export default defineCommand({
}
const token = randomBytes(16).toString("hex");
const server = createConfigUiServer(token, ctx.configStore);
const outputBase = settings.outputDir || defaultOutputBase();
const server = createConfigUiServer(token, ctx.configStore, outputBase, makeAuthUiBridge(ctx));
let port: number;
try {
@@ -22,11 +22,15 @@ export function listenLocalServer(server: http.Server, port = 0): Promise<number
});
}
/** Open a URL in the user's default browser (best-effort, cross-platform). */
export function openInBrowser(url: string): Promise<void> {
/**
* Open a local file, directory, or URL with the OS default handler
* (best-effort, cross-platform). Arguments are passed to `execFile` as an array
* so the target is never interpreted by a shell.
*/
export function openPath(target: string): Promise<void> {
const platform = process.platform;
const cmd = platform === "darwin" ? "open" : platform === "win32" ? "cmd" : "xdg-open";
const args = platform === "win32" ? ["/c", "start", "", url] : [url];
const args = platform === "win32" ? ["/c", "start", "", target] : [target];
return new Promise((resolve, reject) => {
execFile(cmd, args, { windowsHide: true }, (err) => {
@@ -35,3 +39,8 @@ export function openInBrowser(url: string): Promise<void> {
});
});
}
/** Open a URL in the user's default browser (best-effort, cross-platform). */
export function openInBrowser(url: string): Promise<void> {
return openPath(url);
}
@@ -0,0 +1,31 @@
import { expect, test } from "vite-plus/test";
import {
AGENT_COMMANDS,
agentCommand,
agentLaunchable,
launchAgent,
} from "../src/commands/config/agent-launch.ts";
test("agentCommand 返回已知 agent 的可执行命令,未知返回 undefined", () => {
expect(agentCommand("qwen-code")).toBe("qwen");
expect(agentCommand("codex")).toBe("codex");
expect(agentCommand("nope")).toBeUndefined();
// Guards against prototype keys leaking through the allowlist lookup.
expect(agentCommand("toString")).toBeUndefined();
});
test("AGENT_COMMANDS 覆盖所有已知 agent id", () => {
expect(Object.keys(AGENT_COMMANDS).sort()).toEqual(
["claude-code", "codex", "hermes", "opencode", "openclaw", "qwen-code"].sort(),
);
});
test("launchAgent 对未知 id 抛错且不启动任何进程", async () => {
await expect(launchAgent("definitely-not-an-agent")).rejects.toThrow(/Unknown agent/);
});
test("agentLaunchable 对未知 id 返回 false,不探测 PATH", async () => {
expect(await agentLaunchable("definitely-not-an-agent")).toBe(false);
// Prototype keys must not resolve to a launchable command either.
expect(await agentLaunchable("toString")).toBe(false);
});
+96
View File
@@ -0,0 +1,96 @@
import { mkdtempSync, mkdirSync, writeFileSync, rmSync, utimesSync } from "node:fs";
import { tmpdir } from "node:os";
import { join, sep } from "node:path";
import { expect, test } from "vite-plus/test";
import { listAssets, resolveAssetPath, contentType } from "../src/commands/config/assets.ts";
/** Build an isolated temp output base and clean it up afterwards. */
function withBase(fn: (base: string) => void): void {
const base = mkdtempSync(join(tmpdir(), "bl-assets-"));
try {
fn(base);
} finally {
rmSync(base, { recursive: true, force: true });
}
}
function put(base: string, rel: string, content = "x"): string {
const path = join(base, rel);
mkdirSync(join(path, ".."), { recursive: true });
writeFileSync(path, content);
return path;
}
test("listAssets 按分类归类并识别类型", () => {
withBase((base) => {
put(base, "images/a.png");
put(base, "videos/clip.mp4");
put(base, "speech/voice.mp3");
put(base, "notes.txt"); // loose file -> other
const { base: reported, assets } = listAssets(base);
expect(reported).toBe(base);
const byName = Object.fromEntries(assets.map((a) => [a.name, a]));
expect(byName["a.png"]).toMatchObject({ category: "images", kind: "image", ext: "png" });
expect(byName["clip.mp4"]).toMatchObject({ category: "videos", kind: "video", ext: "mp4" });
expect(byName["voice.mp3"]).toMatchObject({ category: "speech", kind: "audio", ext: "mp3" });
expect(byName["notes.txt"]).toMatchObject({ category: "other", kind: "other" });
});
});
test("listAssets 递归扫描任意子文件夹(非预设分类目录)", () => {
withBase((base) => {
put(base, "news-articles/report.md");
put(base, "custom/deep/nested/pic.png");
put(base, "images/a.png");
const { assets } = listAssets(base);
const byName = Object.fromEntries(assets.map((a) => [a.name, a]));
// Arbitrary top-level folder becomes the category.
expect(byName["report.md"]).toMatchObject({
category: "news-articles",
kind: "other",
ext: "md",
});
// Deeply nested file is discovered; category is its top-level folder.
expect(byName["pic.png"]).toMatchObject({ category: "custom", kind: "image" });
expect(byName["pic.png"]!.relPath).toBe(join("custom", "deep", "nested", "pic.png"));
// Known category dirs still work.
expect(byName["a.png"]).toMatchObject({ category: "images", kind: "image" });
});
});
test("listAssets 按生成时间倒序排列", () => {
withBase((base) => {
const older = put(base, "images/old.png");
const newer = put(base, "images/new.png");
// Force a stable ordering by stamping mtimes.
utimesSync(older, new Date(1000), new Date(1000));
utimesSync(newer, new Date(2000), new Date(2000));
const { assets } = listAssets(base);
expect(assets.map((a) => a.name)).toEqual(["new.png", "old.png"]);
});
});
test("listAssets 目录不存在时返回空", () => {
const { assets } = listAssets(join(tmpdir(), "bl-assets-does-not-exist-xyz"));
expect(assets).toEqual([]);
});
test("resolveAssetPath 阻止目录穿越", () => {
withBase((base) => {
put(base, "images/a.png");
expect(resolveAssetPath(base, "images/a.png")).toBe(join(base, "images/a.png"));
expect(resolveAssetPath(base, "../../etc/passwd")).toBeNull();
expect(resolveAssetPath(base, "")).toBeNull();
expect(resolveAssetPath(base, "images" + sep + ".." + sep + ".." + sep + "outside")).toBeNull();
});
});
test("contentType 映射常见扩展名", () => {
expect(contentType(".png")).toBe("image/png");
expect(contentType(".MP4")).toBe("video/mp4");
expect(contentType(".mp3")).toBe("audio/mpeg");
expect(contentType(".xyz")).toBe("application/octet-stream");
});
@@ -0,0 +1,71 @@
import { expect, test } from "vite-plus/test";
import { makeAuthUiBridge } from "../src/commands/auth/console-ui.ts";
import type { AuthState, AuthStore, Identity, Settings } from "bailian-cli-core";
/** Build a bridge over a fake AuthStore. Only describe()/logout() are used by
* the surface under test; startConsoleLogin() is intentionally not exercised
* (it opens a browser and starts a real callback server). */
function bridgeWith(state: AuthState, onLogout?: (scope: string) => Promise<boolean>) {
const authStore = {
describe: () => state,
stored: () => ({ apiKey: false, console: false, openapi: false }),
resolveBaseUrl: () => "https://dashscope.aliyuncs.com",
login: async () => {},
logout: onLogout ?? (async () => false),
path: "/tmp/config.json",
} as unknown as AuthStore;
return makeAuthUiBridge({
identity: {} as unknown as Identity,
settings: {} as unknown as Settings,
authStore,
});
}
test("status: console 凭证 -> primary=console带 region/site 与掩码 token", () => {
const st = bridgeWith({
console: {
token: "abcd1234efgh5678",
region: "cn-beijing",
site: "domestic",
source: "config",
},
}).status();
expect(st.authenticated).toBe(true);
expect(st.primary).toBe("console");
expect(st.methods).toEqual({ apiKey: false, console: true, openapi: false });
expect(st.region).toBe("cn-beijing");
expect(st.site).toBe("domestic");
expect(st.masked).toContain("...");
// Masked, never the raw token.
expect(st.masked).not.toBe("abcd1234efgh5678");
});
test("status: 无任何凭证 -> 未认证,无 masked", () => {
const st = bridgeWith({}).status();
expect(st.authenticated).toBe(false);
expect(st.primary).toBe(null);
expect(st.masked).toBeUndefined();
expect(st.methods).toEqual({ apiKey: false, console: false, openapi: false });
});
test("status: 仅 apiKey -> primary=apiKey", () => {
const st = bridgeWith({
apiKey: { token: "sk-1234567890", baseUrl: "https://dashscope.aliyuncs.com", source: "env" },
}).status();
expect(st.primary).toBe("apiKey");
expect(st.methods.apiKey).toBe(true);
expect(st.region).toBeUndefined();
});
test("logout 委托给 authStore.logout('all')", async () => {
let scope = "";
const bridge = bridgeWith(
{ apiKey: { token: "sk-x", baseUrl: "https://x", source: "config" } },
async (s) => {
scope = s;
return true;
},
);
expect(await bridge.logout()).toBe(true);
expect(scope).toBe("all");
});
@@ -0,0 +1,159 @@
import { describe, expect, test } from "vite-plus/test";
import { decodeTokenPlanKey } from "../src/commands/config/agent/decode-key.ts";
/**
* decode-key 单元测试:在测试内移植前端 encodeTokenPlanKey 参考实现
* (bailian-tokenplan encode-token-plan-key.ts),做 encode → decode round-trip,
* 保证 CLI 解码与前端编码逐位互逆。
*/
const TOKEN_PREFIX = "o1_";
const ALPHABET = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_.";
const ALPHABET_SIZE = ALPHABET.length;
const ALPHABET_INDEX = new Map(ALPHABET.split("").map((character, index) => [character, index]));
const CHECKSUM_LENGTH = 6;
const FEISTEL_ROUNDS = 8;
function toDigits(value: string): number[] {
return value.split("").map((character) => {
const digit = ALPHABET_INDEX.get(character);
if (digit === undefined) throw new Error("bad char");
return digit;
});
}
function fromDigits(digits: number[]): string {
return digits.map((digit) => ALPHABET[digit]).join("");
}
function mixState(state: number, value: number): number {
return Math.imul((state ^ value) >>> 0, 0x01000193) >>> 0;
}
function nextState(state: number): number {
let next = state >>> 0;
next ^= next << 13;
next ^= next >>> 17;
next ^= next << 5;
return next >>> 0;
}
function createRoundMask(right: number[], salt: string, round: number, length: number): number[] {
let state = (0x811c9dc5 ^ Math.imul(round + 1, 0x9e3779b1)) >>> 0;
state = mixState(state, right.length);
state = mixState(state, length);
for (const character of salt) {
state = mixState(state, (ALPHABET_INDEX.get(character) ?? -1) + 1);
}
for (const digit of right) {
state = mixState(state, digit + 1);
}
state ^= state >>> 16;
state = Math.imul(state, 0x85ebca6b) >>> 0;
state ^= state >>> 13;
state = Math.imul(state, 0xc2b2ae35) >>> 0;
state ^= state >>> 16;
state = state >>> 0 || 0x6d2b79f5;
const mask: number[] = [];
for (let index = 0; index < length; index += 1) {
state = (state + Math.imul(index + 1, 0x9e3779b1)) >>> 0;
state = nextState(state);
mask.push(state % ALPHABET_SIZE);
}
return mask;
}
function obfuscatePayload(apiKey: string, salt: string): string {
const digits = toDigits(apiKey);
const midpoint = Math.floor(digits.length / 2);
let left = digits.slice(0, midpoint);
let right = digits.slice(midpoint);
for (let round = 0; round < FEISTEL_ROUNDS; round += 1) {
const mask = createRoundMask(right, salt, round, left.length);
const nextRight = left.map((digit, index) => (digit + mask[index]) % ALPHABET_SIZE);
left = right;
right = nextRight;
}
return fromDigits([...left, ...right]);
}
function crc32(value: string): number {
let checksum = 0xffffffff;
for (let index = 0; index < value.length; index += 1) {
checksum ^= value.charCodeAt(index);
for (let bit = 0; bit < 8; bit += 1) {
const mask = -(checksum & 1);
checksum = (checksum >>> 1) ^ (0xedb88320 & mask);
}
}
return (checksum ^ 0xffffffff) >>> 0;
}
function encodeBase65Number(value: number, length: number): string {
let remaining = value >>> 0;
const encoded = Array<string>(length).fill(ALPHABET[0]);
for (let index = length - 1; index >= 0; index -= 1) {
encoded[index] = ALPHABET[remaining % ALPHABET_SIZE];
remaining = Math.floor(remaining / ALPHABET_SIZE);
}
return encoded.join("");
}
/** 前端 encodeTokenPlanKey 的测试内移植(固定 salt)。 */
function encodeTokenPlanKey(apiKey: string, salt: string): string {
const payload = obfuscatePayload(apiKey, salt);
const checksum = encodeBase65Number(crc32(apiKey), CHECKSUM_LENGTH);
return TOKEN_PREFIX + salt + payload + checksum;
}
describe("config agent decode-key", () => {
test("encode → decode round-trip 还原原始 apiKey", () => {
const samples = [
"sk-1234567890abcdef",
"sk-sp-H.PML.Ns85.MEUCIFHbYk4yBBWLGegORHfWZGB5DdSEs6ms3AwyMsuTOk0CAiEAlOwrUO6dz6IYPUlJ4gK7u6kjStkythgxWaVP5B28ly0",
"a",
"A-b_c.9",
];
const salts = ["AbC123", "zzzzzz", "0.-_Zq", "AAAAAA"];
for (const apiKey of samples) {
for (const salt of salts) {
expect(decodeTokenPlanKey(encodeTokenPlanKey(apiKey, salt))).toBe(apiKey);
}
}
});
test("固定 salt 的确定性:相同输入产出相同 token 且可解码", () => {
const tokenA = encodeTokenPlanKey("sk-fixed-key", "S4ltS4");
const tokenB = encodeTokenPlanKey("sk-fixed-key", "S4ltS4");
expect(tokenA).toBe(tokenB);
expect(decodeTokenPlanKey(tokenA)).toBe("sk-fixed-key");
});
test("篡改 checksum 抛错", () => {
const token = encodeTokenPlanKey("sk-checksum-test", "AbC123");
const flippedTail = token.slice(-1) === "A" ? "B" : "A";
const tampered = token.slice(0, -1) + flippedTail;
expect(() => decodeTokenPlanKey(tampered)).toThrow(/Invalid obfuscated API key/);
});
test("篡改 salt 抛错(payload 解出与 checksum 不符)", () => {
const token = encodeTokenPlanKey("sk-salt-test", "AbC123");
const body = token.slice(TOKEN_PREFIX.length);
const flippedSaltHead = body[0] === "A" ? "B" : "A";
const tampered = TOKEN_PREFIX + flippedSaltHead + body.slice(1);
expect(() => decodeTokenPlanKey(tampered)).toThrow(/Invalid obfuscated API key/);
});
test("非法前缀 / 非法字符 / 过短 token 抛错", () => {
expect(() => decodeTokenPlanKey("x1_AbC123payloadAAAAAA")).toThrow(
/Invalid obfuscated API key/,
);
expect(() => decodeTokenPlanKey("o1_AbC123pay!oadAAAAAA")).toThrow(
/Invalid obfuscated API key/,
);
expect(() => decodeTokenPlanKey("o1_short")).toThrow(/Invalid obfuscated API key/);
expect(() => decodeTokenPlanKey("")).toThrow(/Invalid obfuscated API key/);
});
});
@@ -8,6 +8,7 @@ import opencode from "../src/commands/config/agent/writers/opencode.ts";
import openclaw from "../src/commands/config/agent/writers/openclaw.ts";
import hermes from "../src/commands/config/agent/writers/hermes.ts";
import codex from "../src/commands/config/agent/writers/codex.ts";
import { resolveRegionBaseUrl } from "../src/commands/config/agent/writers/utils.ts";
import yaml from "yaml";
/**
@@ -41,11 +42,14 @@ function readJsonAt(...segments: string[]): Record<string, unknown> {
describe("config agent writers", () => {
test("claude-code 写入 env 与 onboarding并合并已有 env", () => {
// 预置一个无关 env 键,验证合并保留
// 预置一个无关 env 键与旧的 ANTHROPIC_API_KEY验证合并保留 / 旧键清理
mkdirSync(join(home, ".claude"), { recursive: true });
writeFileSync(
join(home, ".claude", "settings.json"),
JSON.stringify({ env: { KEEP_ME: "1" }, other: true }),
JSON.stringify({
env: { KEEP_ME: "1", ANTHROPIC_API_KEY: "sk-stale" },
other: true,
}),
);
const summary = claudeCode.write({
@@ -61,6 +65,7 @@ describe("config agent writers", () => {
expect(settings.other).toBe(true);
expect(env.ANTHROPIC_BASE_URL).toBe(ANTHROPIC_URL);
expect(env.ANTHROPIC_AUTH_TOKEN).toBe("sk-a");
expect(env.ANTHROPIC_API_KEY).toBeUndefined();
expect(env.ANTHROPIC_MODEL).toBe("qwen3-max");
expect(env.ANTHROPIC_DEFAULT_HAIKU_MODEL).toBe("qwen3-max");
expect(env.ANTHROPIC_DEFAULT_SONNET_MODEL).toBe("qwen3-max");
@@ -70,26 +75,151 @@ describe("config agent writers", () => {
expect(readJsonAt(".claude.json").hasCompletedOnboarding).toBe(true);
});
test("qwen-code compatible-mode 走 openai 协议", () => {
qwenCode.write({ baseUrl: OAI_URL, apiKey: "sk-q", model: "qwen3-coder-plus" });
test("claude-code 尊重 CLAUDE_CONFIG_DIR", () => {
const customDir = join(home, "custom-claude");
process.env.CLAUDE_CONFIG_DIR = customDir;
try {
claudeCode.write({
baseUrl: ANTHROPIC_URL,
apiKey: "sk-a",
model: "qwen3-max",
});
const settings = JSON.parse(readFileSync(join(customDir, "settings.json"), "utf8"));
expect((settings.env as Record<string, string>).ANTHROPIC_AUTH_TOKEN).toBe("sk-a");
} finally {
delete process.env.CLAUDE_CONFIG_DIR;
}
});
test("claude-code 将 compatible-mode URL 改写为 apps/anthropic", () => {
const tokenPlanOpenAi = "https://token-plan.cn-beijing.maas.aliyuncs.com/compatible-mode/v1";
const summary = claudeCode.write({
baseUrl: tokenPlanOpenAi,
apiKey: "sk-a",
model: "qwen3.8-max-preview",
});
const env = readJsonAt(".claude", "settings.json").env as Record<string, string>;
expect(env.ANTHROPIC_BASE_URL).toBe(
"https://token-plan.cn-beijing.maas.aliyuncs.com/apps/anthropic",
);
expect(summary.warnings?.some((warning) => warning.includes("Rewrote base URL"))).toBe(true);
});
test("claude-code 保留已有分层模型,不整表覆盖", () => {
mkdirSync(join(home, ".claude"), { recursive: true });
writeFileSync(
join(home, ".claude", "settings.json"),
JSON.stringify({
env: {
ANTHROPIC_DEFAULT_HAIKU_MODEL: "qwen3.6-flash",
CLAUDE_CODE_SUBAGENT_MODEL: "qwen3.7-max",
},
}),
);
claudeCode.write({
baseUrl: ANTHROPIC_URL,
apiKey: "sk-a",
model: "qwen3.8-max-preview",
});
const env = readJsonAt(".claude", "settings.json").env as Record<string, string>;
expect(env.ANTHROPIC_MODEL).toBe("qwen3.8-max-preview");
expect(env.ANTHROPIC_DEFAULT_HAIKU_MODEL).toBe("qwen3.6-flash");
expect(env.CLAUDE_CODE_SUBAGENT_MODEL).toBe("qwen3.7-max");
expect(env.ANTHROPIC_DEFAULT_SONNET_MODEL).toBe("qwen3.8-max-preview");
});
test("claude-code 拒绝无法改写为 Anthropic 的 base URL", () => {
expect(() =>
claudeCode.write({
baseUrl: "https://api.openai.com/v1",
apiKey: "sk-a",
model: "qwen3-max",
}),
).toThrow(/Anthropic-compatible base URL/);
});
test("qwen-code compatible-mode 走 openai 协议(官方 v3 结构)", () => {
qwenCode.write({
baseUrl: OAI_URL,
apiKey: "sk-q",
model: "qwen3-coder-plus",
});
const settings = readJsonAt(".qwen", "settings.json");
const security = settings.security as { auth: Record<string, string> };
expect(security.auth.selectedType).toBe("openai");
expect(security.auth.apiKey).toBe("sk-q");
expect(security.auth.baseUrl).toBe(OAI_URL);
expect((settings.env as Record<string, string>).BAILIAN_CLI_API_KEY).toBe("sk-q");
expect((settings.model as Record<string, string>).name).toBe("qwen3-coder-plus");
expect(settings.$version).toBe(3);
const security = settings.security as { auth: Record<string, unknown> };
// security.auth 携带 selectedType 以及凭证兜底apiKey/baseUrl
// 避免系统 OPENAI_API_KEY 抢占
expect(security.auth).toEqual({
selectedType: "openai",
apiKey: "sk-q",
baseUrl: OAI_URL,
});
expect((settings.env as Record<string, string>).DASHSCOPE_API_KEY).toBe("sk-q");
// model.name 必须与 baseUrl 一同写入(同 id provider 消歧契约)
expect(settings.model).toEqual({
name: "qwen3-coder-plus",
baseUrl: OAI_URL,
});
const providers = settings.modelProviders as Record<string, Array<Record<string, unknown>>>;
// name 是模型显示名(非 provider 品牌常量),品牌只在 envKey 里
expect(providers.openai[0]).toMatchObject({
id: "qwen3-coder-plus",
name: "bailian-cli",
name: "[Bailian] qwen3-coder-plus",
baseUrl: OAI_URL,
envKey: "BAILIAN_CLI_API_KEY",
envKey: "DASHSCOPE_API_KEY",
});
});
test("qwen-code upsert 时治愈旧的 bailian-cli name 但保留用户自定义 name", () => {
mkdirSync(join(home, ".qwen"), { recursive: true });
writeFileSync(
join(home, ".qwen", "settings.json"),
JSON.stringify({
modelProviders: {
openai: [
{
id: "qwen3-coder-plus",
name: "bailian-cli",
baseUrl: OAI_URL,
envKey: "DASHSCOPE_API_KEY",
},
{
id: "my-model",
name: "My Custom",
baseUrl: OAI_URL,
envKey: "DASHSCOPE_API_KEY",
},
],
},
}),
);
// 旧 sentinel 被治愈为显示名
qwenCode.write({
baseUrl: OAI_URL,
apiKey: "sk-q",
model: "qwen3-coder-plus",
});
// 用户自定义 name 不被覆盖
qwenCode.write({ baseUrl: OAI_URL, apiKey: "sk-q", model: "my-model" });
const settings = readJsonAt(".qwen", "settings.json");
const entries = (settings.modelProviders as Record<string, Array<Record<string, unknown>>>)
.openai;
const healed = entries.find((entry) => entry.id === "qwen3-coder-plus")!;
expect(healed.name).toBe("[Bailian] qwen3-coder-plus");
expect(healed.envKey).toBe("DASHSCOPE_API_KEY");
const custom = entries.find((entry) => entry.id === "my-model")!;
expect(custom.name).toBe("My Custom");
});
test("qwen-code anthropic 端点走 anthropic 协议", () => {
qwenCode.write({ baseUrl: ANTHROPIC_URL, apiKey: "sk-q", model: "qwen3-max" });
qwenCode.write({
baseUrl: ANTHROPIC_URL,
apiKey: "sk-q",
model: "qwen3-max",
});
const settings = readJsonAt(".qwen", "settings.json");
expect((settings.security as { auth: { selectedType: string } }).auth.selectedType).toBe(
"anthropic",
@@ -99,12 +229,108 @@ describe("config agent writers", () => {
expect(providers.openai).toBeUndefined();
});
test("qwen-code 对相同 id+baseUrl 的 provider 项 upsert 而非追加", () => {
qwenCode.write({ baseUrl: OAI_URL, apiKey: "sk-1", model: "qwen3-coder-plus" });
qwenCode.write({ baseUrl: OAI_URL, apiKey: "sk-2", model: "qwen3-coder-plus" });
test("qwen-code 对自有 provider 项按 id upsert 而非追加", () => {
qwenCode.write({
baseUrl: OAI_URL,
apiKey: "sk-1",
model: "qwen3-coder-plus",
});
qwenCode.write({
baseUrl: OAI_URL,
apiKey: "sk-2",
model: "qwen3-coder-plus",
});
const settings = readJsonAt(".qwen", "settings.json");
const openaiEntries = (settings.modelProviders as Record<string, unknown[]>).openai;
expect(openaiEntries).toHaveLength(1);
expect((settings.env as Record<string, string>).DASHSCOPE_API_KEY).toBe("sk-2");
});
test("qwen-code 不劫持已有 Token Plan 同 id 条目的 name/envKey", () => {
mkdirSync(join(home, ".qwen"), { recursive: true });
writeFileSync(
join(home, ".qwen", "settings.json"),
JSON.stringify({
env: { BAILIAN_TOKEN_PLAN_API_KEY: "sk-token-plan" },
modelProviders: {
openai: [
{
id: "qwen3.8-max-preview",
name: "[Token Plan 个人版] qwen3.8-max-preview",
baseUrl: "https://token-plan.cn-beijing.maas.aliyuncs.com/compatible-mode/v1",
envKey: "BAILIAN_TOKEN_PLAN_API_KEY",
generationConfig: { extra_body: { enable_thinking: true } },
},
],
},
}),
);
const tokenPlanUrl = "https://token-plan.cn-beijing.maas.aliyuncs.com/compatible-mode/v1";
const summary = qwenCode.write({
baseUrl: tokenPlanUrl,
apiKey: "sk-bailian",
model: "qwen3.8-max-preview",
});
const settings = readJsonAt(".qwen", "settings.json");
const openaiEntries = (
settings.modelProviders as Record<string, Array<Record<string, unknown>>>
).openai;
expect(openaiEntries).toHaveLength(1);
expect(openaiEntries[0]).toMatchObject({
id: "qwen3.8-max-preview",
name: "[Token Plan 个人版] qwen3.8-max-preview",
envKey: "BAILIAN_TOKEN_PLAN_API_KEY",
generationConfig: { extra_body: { enable_thinking: true } },
});
expect((settings.env as Record<string, string>).BAILIAN_TOKEN_PLAN_API_KEY).toBe(
"sk-token-plan",
);
expect((settings.env as Record<string, string>).DASHSCOPE_API_KEY).toBe("sk-bailian");
expect(summary.warnings?.some((warning) => warning.includes("already exists"))).toBe(true);
});
test("qwen-code 在进程环境变量覆盖 settings.env 时给出警告", () => {
const previous = process.env.DASHSCOPE_API_KEY;
process.env.DASHSCOPE_API_KEY = "sk-from-shell";
try {
const summary = qwenCode.write({
baseUrl: OAI_URL,
apiKey: "sk-from-settings",
model: "qwen3-coder-plus",
});
expect(summary.warnings?.some((warning) => warning.includes("overrides settings.json"))).toBe(
true,
);
} finally {
if (previous === undefined) delete process.env.DASHSCOPE_API_KEY;
else process.env.DASHSCOPE_API_KEY = previous;
}
});
test("opencode 容忍 JSONC注释与尾逗号", () => {
mkdirSync(join(home, ".config", "opencode"), { recursive: true });
writeFileSync(
join(home, ".config", "opencode", "opencode.json"),
[
"{",
" // user comment",
' "provider": {',
' "other": { "name": "Other" }, // inline comment',
" },",
" /* block */",
' "theme": "dark",',
"}",
].join("\n"),
);
opencode.write({ baseUrl: OAI_URL, apiKey: "sk-o", model: "qwen3-max" });
const config = readJsonAt(".config", "opencode", "opencode.json");
expect(config.theme).toBe("dark");
const provider = config.provider as Record<string, unknown>;
expect(provider.other).toBeDefined();
expect(provider["bailian-cli"]).toBeDefined();
});
test("opencode 按端点选 npm含 setCacheKey合并保留其它 provider", () => {
@@ -114,7 +340,11 @@ describe("config agent writers", () => {
JSON.stringify({ provider: { other: { name: "Other" } } }),
);
opencode.write({ baseUrl: ANTHROPIC_URL, apiKey: "sk-o", model: "qwen3-max" });
opencode.write({
baseUrl: ANTHROPIC_URL,
apiKey: "sk-o",
model: "qwen3-max",
});
const config = readJsonAt(".config", "opencode", "opencode.json");
const provider = config.provider as Record<string, Record<string, unknown>>;
expect(provider.other).toBeDefined();
@@ -137,60 +367,140 @@ describe("config agent writers", () => {
).toBe("@ai-sdk/openai-compatible");
});
test("openclaw 写入 provider、apiprimary", () => {
openclaw.write({ baseUrl: OAI_URL, apiKey: "sk-c", model: "qwen3-coder-plus" });
test("openclaw 写入 provider、apiprimary,并登记 defaults.models", () => {
openclaw.write({
baseUrl: OAI_URL,
apiKey: "sk-c",
model: "qwen3-coder-plus",
});
const config = readJsonAt(".openclaw", "openclaw.json");
const models = config.models as Record<string, unknown>;
expect(models.mode).toBe("merge");
const bailian = (models.providers as Record<string, Record<string, unknown>>)["bailian-cli"];
expect(bailian.api).toBe("openai-completions");
expect((bailian.models as Array<{ id: string }>)[0].id).toBe("qwen3-coder-plus");
const agents = config.agents as { defaults: { model: { primary: string } } };
const entry = (bailian.models as Array<Record<string, unknown>>)[0];
expect(entry.id).toBe("qwen3-coder-plus");
expect(entry.contextWindow).toBe(256000);
expect(entry.cost).toEqual({
input: 0,
output: 0,
cacheRead: 0,
cacheWrite: 0,
});
const agents = config.agents as {
defaults: { model: { primary: string }; models: Record<string, unknown> };
};
expect(agents.defaults.model.primary).toBe("bailian-cli/qwen3-coder-plus");
expect(agents.defaults.models["bailian-cli/qwen3-coder-plus"]).toEqual({});
// anthropic 端点用 anthropic-messages
openclaw.write({ baseUrl: ANTHROPIC_URL, apiKey: "sk-c", model: "qwen3-max" });
// --context-window 覆盖默认值;anthropic 端点用 anthropic-messages
openclaw.write({
baseUrl: ANTHROPIC_URL,
apiKey: "sk-c",
model: "qwen3-max",
contextWindow: 1000000,
});
const config2 = readJsonAt(".openclaw", "openclaw.json");
const providers2 = (config2.models as Record<string, unknown>).providers as Record<
string,
{ api: string; models: Array<Record<string, unknown>> }
>;
expect(providers2["bailian-cli"].api).toBe("anthropic-messages");
expect(providers2["bailian-cli"].models[0].contextWindow).toBe(1000000);
expect(
((config2.models as Record<string, unknown>).providers as Record<string, { api: string }>)[
"bailian-cli"
].api,
).toBe("anthropic-messages");
(config2.agents as { defaults: { model: { primary: string } } }).defaults.model.primary,
).toBe("bailian-cli/qwen3-max");
});
test("hermes 写入 custom_providers 与 model合并保留其它 provider", () => {
test("openclaw 不抢占已有 token-plan primary", () => {
mkdirSync(join(home, ".openclaw"), { recursive: true });
writeFileSync(
join(home, ".openclaw", "openclaw.json"),
JSON.stringify({
models: {
mode: "merge",
providers: {
"bailian-token-plan": {
baseUrl: "https://token-plan.cn-beijing.maas.aliyuncs.com/apps/anthropic",
apiKey: "sk-token-plan",
api: "anthropic-messages",
models: [{ id: "qwen3.8-max-preview", name: "qwen3.8-max-preview" }],
},
},
},
agents: {
defaults: {
model: { primary: "bailian-token-plan/qwen3.8-max-preview" },
models: { "bailian-token-plan/qwen3.8-max-preview": {} },
},
},
}),
);
const summary = openclaw.write({
baseUrl: "https://token-plan.cn-beijing.maas.aliyuncs.com/compatible-mode/v1",
apiKey: "sk-bailian",
model: "qwen3.8-max-preview",
});
const config = readJsonAt(".openclaw", "openclaw.json");
const agents = config.agents as {
defaults: { model: { primary: string }; models: Record<string, unknown> };
};
expect(agents.defaults.model.primary).toBe("bailian-token-plan/qwen3.8-max-preview");
expect(agents.defaults.models["bailian-cli/qwen3.8-max-preview"]).toEqual({});
expect(
(config.models as { providers: Record<string, unknown> }).providers["bailian-token-plan"],
).toBeDefined();
expect(
(config.models as { providers: Record<string, unknown> }).providers["bailian-cli"],
).toBeDefined();
expect(summary.warnings?.some((warning) => warning.includes("Left existing primary"))).toBe(
true,
);
});
test("hermes 写入官方扁平 model.* 结构,保留其它顶层键", () => {
mkdirSync(join(home, ".hermes"), { recursive: true });
writeFileSync(
join(home, ".hermes", "config.yaml"),
yaml.stringify({ custom_providers: [{ name: "other", base_url: "https://x" }] }),
yaml.stringify({
custom_providers: [{ name: "other", base_url: "https://x" }],
}),
);
hermes.write({ baseUrl: OAI_URL, apiKey: "sk-h", model: "qwen3-coder-plus" });
hermes.write({
baseUrl: OAI_URL,
apiKey: "sk-h",
model: "qwen3-coder-plus",
});
const config = yaml.parse(readFileSync(join(home, ".hermes", "config.yaml"), "utf8"));
expect(config.model).toEqual({ default: "qwen3-coder-plus", provider: "bailian-cli" });
const names = (config.custom_providers as Array<{ name: string }>).map((p) => p.name);
expect(names).toContain("other");
const entry = (config.custom_providers as Array<Record<string, unknown>>).find(
(provider) => provider.name === "bailian-cli",
)!;
expect(entry.base_url).toBe(OAI_URL);
expect(entry.api_key).toBe("sk-h");
expect(entry.api_mode).toBe("chat_completions");
// OpenAI 兼容端点:按官方文档省略 api_mode无关顶层键不受影响
expect(config.model).toEqual({
default: "qwen3-coder-plus",
provider: "custom",
base_url: OAI_URL,
api_key: "sk-h",
});
expect(config.custom_providers).toHaveLength(1);
// anthropic 端点 anthropic_messages
hermes.write({ baseUrl: ANTHROPIC_URL, apiKey: "sk-h", model: "qwen3-max" });
// anthropic 端点:必须带 api_mode = anthropic_messages
hermes.write({
baseUrl: ANTHROPIC_URL,
apiKey: "sk-h",
model: "qwen3-max",
});
const config2 = yaml.parse(readFileSync(join(home, ".hermes", "config.yaml"), "utf8"));
const entry2 = (config2.custom_providers as Array<Record<string, unknown>>).find(
(provider) => provider.name === "bailian-cli",
)!;
expect(entry2.api_mode).toBe("anthropic_messages");
// upsertbailian-cli 项不重复
expect(
(config2.custom_providers as Array<{ name: string }>).filter((p) => p.name === "bailian-cli"),
).toHaveLength(1);
expect(config2.model).toEqual({
default: "qwen3-max",
provider: "custom",
base_url: ANTHROPIC_URL,
api_key: "sk-h",
api_mode: "anthropic_messages",
});
});
test("codex 写入 config.toml 与 auth.jsoncc-switch 对齐结构,合并保留)", () => {
test("codex 写入 config.toml 与 auth.json官方 env_key 结构,合并保留)", () => {
// 预置 config.toml 无关顶层键与另一个 provider验证非破坏性合并
mkdirSync(join(home, ".codex"), { recursive: true });
writeFileSync(
@@ -207,14 +517,20 @@ describe("config agent writers", () => {
// 预置 auth.json 无关键,验证合并保留
writeFileSync(join(home, ".codex", "auth.json"), JSON.stringify({ EXISTING: "keep" }));
codex.write({ baseUrl: OAI_URL, apiKey: "sk-x", model: "qwen3-coder-plus" });
const summary = codex.write({
baseUrl: OAI_URL,
apiKey: "sk-x",
model: "qwen3-coder-plus",
});
// 默认路径无警告
expect(summary.warnings).toBeUndefined();
const toml = readFileSync(join(home, ".codex", "config.toml"), "utf8");
expect(toml).toContain('model_provider = "bailian-cli"');
expect(toml).toContain('model = "qwen3-coder-plus"');
expect(toml).toContain('model_reasoning_effort = "high"');
expect(toml).toContain("disable_response_storage = true");
expect(toml).toContain("[model_providers.bailian-cli]");
expect(toml).toContain(`base_url = "${OAI_URL}"`);
expect(toml).toContain('env_key = "OPENAI_API_KEY"');
// 未传 --wire-api 时默认 responses新版 Codex 已不支持 chat
expect(toml).toContain('wire_api = "responses"');
expect(toml).toContain("requires_openai_auth = true");
// 合并:保留用户已有的无关配置
@@ -224,6 +540,18 @@ describe("config agent writers", () => {
const auth = readJsonAt(".codex", "auth.json");
expect(auth.OPENAI_API_KEY).toBe("sk-x");
expect(auth.EXISTING).toBe("keep");
// --wire-api chat仅旧版 Codex <= 0.80.0 可用,附带警告
const summary2 = codex.write({
baseUrl: OAI_URL,
apiKey: "sk-x",
model: "glm-5",
wireApi: "chat",
});
expect(summary2.warnings?.some((warning) => warning.includes("0.80.0"))).toBe(true);
const toml2 = readFileSync(join(home, ".codex", "config.toml"), "utf8");
expect(toml2).toContain('wire_api = "chat"');
expect(toml2).toContain('model = "glm-5"');
});
test("已存在的配置文件会被备份为 .bak.<epoch>", () => {
@@ -236,4 +564,19 @@ describe("config agent writers", () => {
);
expect(backups).toHaveLength(1);
});
test("resolveRegionBaseUrl 将 region 转为 Token Plan compatible-mode URL", () => {
expect(resolveRegionBaseUrl("cn-beijing")).toBe(
"https://token-plan.cn-beijing.maas.aliyuncs.com/compatible-mode/v1",
);
expect(resolveRegionBaseUrl("ap-southeast-1")).toBe(
"https://token-plan.ap-southeast-1.maas.aliyuncs.com/compatible-mode/v1",
);
});
test("resolveRegionBaseUrl 拒绝非法 region", () => {
expect(() => resolveRegionBaseUrl("cn beijing")).toThrow(/Invalid --region/);
expect(() => resolveRegionBaseUrl("CN-Beijing")).toThrow(/Invalid --region/);
expect(() => resolveRegionBaseUrl("")).toThrow(/Invalid --region/);
});
});
+58 -23
View File
@@ -83,6 +83,43 @@ test("GET /api/config 返回全部 profile、明文密钥与持久化激活项",
expect(res.json.secretKeys).toContain("api_key");
expect(res.json.keys).toContain("default_image_to_video_model");
expect(res.json.keys).toContain("default_reference_to_video_model");
// Console/telemetry fields are editable via the UI (full ConfigFile surface).
expect(res.json.keys).toContain("console_site");
expect(res.json.keys).toContain("telemetry");
expect(res.json.enums.console_site).toEqual(["domestic", "international"]);
expect(res.json.booleanKeys).toContain("telemetry");
// Default field hints are surfaced as prefilled values in the UI.
expect(res.json.fieldDefaults.default_image_model).toBe("qwen-image-2.0");
expect(res.json.fieldDefaults.default_text_model).toBe("qwen3.7-max");
expect(res.json.fieldDefaults.output_dir).toContain("bailian-output");
expect(res.json.fieldDefaults.timeout).toBe("300");
expect(res.json.fieldDefaults.base_url).toBe("https://dashscope.aliyuncs.com");
// Per-category model catalog (click-to-fill suggestions) is exposed too.
expect(res.json.modelCatalog.default_image_model[0]).toMatchObject({ id: "qwen-image-2.0" });
expect(res.json.modelCatalog.default_video_model.map((m: { id: string }) => m.id)).toContain(
"happyhorse-1.1-i2v",
);
expect(res.json.modelCatalog.default_speech_model.map((m: { id: string }) => m.id)).toContain(
"fun-asr",
);
});
});
test("GET /api/auth/status 无 bridge 时返回未认证login/logout 返回 400", async () => {
await withServer(async (port) => {
// The test harness builds the server without an auth bridge, so the auth
// endpoints degrade safely instead of throwing.
const status = await httpJson(port, "GET", `/api/auth/status?token=${TOKEN}`);
expect(status.status).toBe(200);
expect(status.json.authenticated).toBe(false);
expect(status.json.methods).toEqual({ apiKey: false, console: false, openapi: false });
expect(status.json.primary).toBe(null);
const login = await httpJson(port, "POST", `/api/auth/login?token=${TOKEN}`);
expect(login.status).toBe(400);
const logout = await httpJson(port, "POST", `/api/auth/logout?token=${TOKEN}`);
expect(logout.status).toBe(400);
});
});
@@ -130,44 +167,42 @@ test("POST /api/profile 写命名 profiletimeout 强制为 number空串
});
});
test("POST /api/profile 保留 UI 未管理字段,同时替换 UI 管理字段", async () => {
test("POST /api/profile 可编辑 console/telemetry 字段并按类型持久化", async () => {
await withServer(async (port) => {
await writeConfigFile(
{
api_key: "sk-old",
output: "json",
console_site: "international",
console_region: "ap-southeast-1",
console_switch_agent: 42,
telemetry: false,
},
"stage",
);
const save = await httpJson(port, "POST", `/api/profile?token=${TOKEN}`, {
body: { name: "stage", data: { api_key: "sk-new" } },
body: {
name: "stage",
data: {
api_key: "sk-stage",
console_site: "international",
console_region: "ap-southeast-1",
console_switch_agent: "42",
telemetry: "false",
},
},
});
expect(save.status).toBe(200);
const profile = readConfigFile("stage");
expect(profile).toMatchObject({
api_key: "sk-new",
api_key: "sk-stage",
console_site: "international",
console_region: "ap-southeast-1",
console_switch_agent: 42,
telemetry: false,
});
expect(profile.output).toBeUndefined();
const rawConfig = JSON.parse(readFileSync(getConfigPath(), "utf8"));
expect(rawConfig.stage).toMatchObject({
api_key: "sk-new",
console_site: "international",
console_region: "ap-southeast-1",
console_switch_agent: 42,
telemetry: false,
// Coerced to the right JSON types, not left as strings.
expect(rawConfig.stage.console_switch_agent).toBe(42);
expect(rawConfig.stage.telemetry).toBe(false);
// Invalid enum value is rejected.
const bad = await httpJson(port, "POST", `/api/profile?token=${TOKEN}`, {
body: { name: "stage", data: { console_site: "mars" } },
});
expect(rawConfig.stage.output).toBeUndefined();
expect(bad.status).toBe(400);
expect(String(bad.json.error)).toMatch(/console_site/);
});
});
+154 -8
View File
@@ -295,7 +295,9 @@ describe("e2e: config", () => {
"json",
]);
expect(exitCode, stderr).toBe(0);
const data = parseStdoutJson<{ would_set?: { default_text_model?: string } }>(stdout);
const data = parseStdoutJson<{
would_set?: { default_text_model?: string };
}>(stdout);
expect(data.would_set?.default_text_model).toBe("qwen3.7-max");
});
@@ -390,7 +392,7 @@ describe("e2e: config", () => {
expect(stderr).toMatch(/agent|--base-url|--model/i);
});
test("config agent 缺少 --api-key 时报用法错误并退出 (2)", async () => {
test("config agent 缺少 --api-key/--key 时报用法错误并退出 (2)", async () => {
const { stderr, exitCode } = await runCommandE2e(CONFIG_ROUTES, [
"config",
"agent",
@@ -402,7 +404,146 @@ describe("e2e: config", () => {
"qwen3-max",
]);
expect(exitCode).toBe(2);
expect(stderr).toMatch(/--api-key|Usage:/i);
expect(stderr).toMatch(/--api-key|--key|Usage:/i);
});
test("config agent --api-key 与 --key 同传时报用法错误 (2)", async () => {
const { stderr, exitCode } = await runCommandE2e(CONFIG_ROUTES, [
"config",
"agent",
"--agent",
"claude-code",
"--base-url",
"https://dashscope.aliyuncs.com/apps/anthropic",
"--api-key",
"sk-placeholder",
"--key",
"o1_AbC123kaQ9JHCXF2GepMW4oJTD7ODPw_Hx",
"--model",
"qwen3-max",
]);
expect(exitCode).toBe(2);
expect(stderr).toMatch(/mutually exclusive|--api-key/i);
});
test("config agent --key 非法值时报用法错误 (2)", async () => {
const { stderr, exitCode } = await runCommandE2e(CONFIG_ROUTES, [
"config",
"agent",
"--agent",
"claude-code",
"--base-url",
"https://dashscope.aliyuncs.com/apps/anthropic",
"--key",
"not-an-encoded-key",
"--model",
"qwen3-max",
"--dry-run",
]);
expect(exitCode).toBe(2);
expect(stderr).toMatch(/Invalid obfuscated API key|o1_/i);
});
test("config agent --key 合法值 --dry-run 解码成功且输出脱敏", async () => {
const home = mkdtempSync(join(tmpdir(), "bl-config-agent-key-"));
try {
const { stdout, stderr, exitCode } = await runCommandE2e(
CONFIG_ROUTES,
[
"config",
"agent",
"--agent",
"claude-code",
"--base-url",
"https://dashscope.aliyuncs.com/apps/anthropic",
"--key",
// encode("sk-e2e-key-placeholder", salt "AbC123") 的固定产物
"o1_AbC123kaQ9JHCXF2GepMW4oJTD7ODPw_Hx",
"--model",
"qwen3-max",
"--dry-run",
"--output",
"json",
],
{ HOME: home },
);
expect(exitCode, stderr).toBe(0);
const data = parseStdoutJson<{ agent?: string; api_key?: string }>(stdout);
expect(data.agent).toBe("claude-code");
// 解码后的真实 key 不得明文出现,且脱敏值非空
expect(stdout).not.toContain("sk-e2e-key-placeholder");
expect(data.api_key).toBeTruthy();
expect(existsSync(join(home, ".claude", "settings.json"))).toBe(false);
} finally {
rmSync(home, { recursive: true, force: true });
}
});
test("config agent --region 转为 base URL--dry-run 成功", async () => {
const home = mkdtempSync(join(tmpdir(), "bl-config-agent-region-"));
try {
const { stdout, stderr, exitCode } = await runCommandE2e(
CONFIG_ROUTES,
[
"config",
"agent",
"--agent",
"qwen-code",
"--region",
"cn-beijing",
"--api-key",
"sk-region-placeholder",
"--model",
"qwen3.8-max-preview",
"--dry-run",
"--output",
"json",
],
{ HOME: home },
);
expect(exitCode, stderr).toBe(0);
const data = parseStdoutJson<{ agent?: string; base_url?: string }>(stdout);
expect(data.agent).toBe("qwen-code");
expect(data.base_url).toBe(
"https://token-plan.cn-beijing.maas.aliyuncs.com/compatible-mode/v1",
);
} finally {
rmSync(home, { recursive: true, force: true });
}
});
test("config agent --base-url 与 --region 同传时报用法错误 (2)", async () => {
const { stderr, exitCode } = await runCommandE2e(CONFIG_ROUTES, [
"config",
"agent",
"--agent",
"qwen-code",
"--base-url",
"https://dashscope.aliyuncs.com/compatible-mode/v1",
"--region",
"cn-beijing",
"--api-key",
"sk-placeholder",
"--model",
"qwen3-coder-plus",
]);
expect(exitCode).toBe(2);
expect(stderr).toMatch(/mutually exclusive|--base-url|--region/i);
});
test("config agent 既缺 --base-url 又缺 --region 时报用法错误 (2)", async () => {
const { stderr, exitCode } = await runCommandE2e(CONFIG_ROUTES, [
"config",
"agent",
"--agent",
"qwen-code",
"--api-key",
"sk-placeholder",
"--model",
"qwen3-coder-plus",
]);
expect(exitCode).toBe(2);
expect(stderr).toMatch(/--base-url|--region|Usage:/i);
});
test("config agent 非法 --agent 时退出为用法错误 (2)", async () => {
@@ -461,7 +602,7 @@ describe("e2e: config", () => {
}
});
test("config agent codex 写入 config.toml 与 auth.jsoncc-switch 对齐结构)", async () => {
test("config agent codex 写入 config.toml 与 auth.json官方 env_key 结构)", async () => {
const home = mkdtempSync(join(tmpdir(), "bl-config-agent-codex-"));
try {
const { stderr, exitCode } = await runCommandE2e(
@@ -483,7 +624,9 @@ describe("e2e: config", () => {
expect(exitCode, stderr).toBe(0);
const toml = readFileSync(join(home, ".codex", "config.toml"), "utf8");
expect(toml).toContain('model_provider = "bailian-cli"');
expect(toml).toContain('env_key = "OPENAI_API_KEY"');
expect(toml).toContain("requires_openai_auth = true");
// 默认即 responses新版 Codex 已不支持 chat
expect(toml).toContain('wire_api = "responses"');
const auth = JSON.parse(readFileSync(join(home, ".codex", "auth.json"), "utf8"));
expect(auth.OPENAI_API_KEY).toBe("sk-codex-placeholder");
@@ -492,7 +635,7 @@ describe("e2e: config", () => {
}
});
test("config agent hermes 写入 custom_providers 结构", async () => {
test("config agent hermes 写入官方扁平 model.* 结构", async () => {
const home = mkdtempSync(join(tmpdir(), "bl-config-agent-hermes-"));
try {
const { stderr, exitCode } = await runCommandE2e(
@@ -513,9 +656,12 @@ describe("e2e: config", () => {
);
expect(exitCode, stderr).toBe(0);
const yamlText = readFileSync(join(home, ".hermes", "config.yaml"), "utf8");
expect(yamlText).toContain("custom_providers");
expect(yamlText).toContain("bailian-cli");
expect(yamlText).toContain("api_mode: chat_completions");
expect(yamlText).toContain("default: qwen3-coder-plus");
expect(yamlText).toContain("provider: custom");
expect(yamlText).toContain("base_url: https://dashscope.aliyuncs.com/compatible-mode/v1");
expect(yamlText).toContain("api_key: sk-hermes-placeholder");
// OpenAI 兼容端点不写 api_mode
expect(yamlText).not.toContain("api_mode");
} finally {
rmSync(home, { recursive: true, force: true });
}
+215
View File
@@ -0,0 +1,215 @@
import { mkdtempSync, mkdirSync, writeFileSync, rmSync, symlinkSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { expect, test } from "vite-plus/test";
import {
listSkills,
listMcpServers,
listAgents,
getSkillDetail,
} from "../src/commands/config/inventory.ts";
/** Build an isolated fake $HOME and clean it up afterwards. */
function withHome(fn: (home: string) => void): void {
const home = mkdtempSync(join(tmpdir(), "bl-inv-"));
try {
fn(home);
} finally {
rmSync(home, { recursive: true, force: true });
}
}
function write(home: string, rel: string, content: string): void {
const path = join(home, rel);
mkdirSync(join(path, ".."), { recursive: true });
writeFileSync(path, content);
}
test("getSkillDetail 返回 SKILL.md 原文,未知 id 返回 null", () => {
withHome((home) => {
write(
home,
".agents/skills/demo/SKILL.md",
"---\nname: demo-skill\ndescription: A demo skill.\n---\n# Body\nhello world\n",
);
const detail = getSkillDetail("demo", home);
expect(detail).not.toBeNull();
expect(detail?.name).toBe("demo-skill");
expect(detail?.content).toContain("hello world");
expect(getSkillDetail("nope", home)).toBeNull();
});
});
test("listSkills 解析 SKILL.md frontmatter 与文件数", () => {
withHome((home) => {
write(
home,
".agents/skills/demo/SKILL.md",
'---\nname: demo-skill\nmetadata:\n version: "2.1.0"\ndescription: A demo skill.\n---\n# Body\n',
);
write(home, ".agents/skills/demo/assets/a.md", "x");
// Directory without SKILL.md is ignored.
mkdirSync(join(home, ".agents/skills/not-a-skill"), { recursive: true });
const skills = listSkills(home);
expect(skills).toHaveLength(1);
expect(skills[0]).toMatchObject({
id: "demo",
name: "demo-skill",
version: "2.1.0",
description: "A demo skill.",
sources: ["global"],
origin: "local",
});
expect(skills[0].fileCount).toBe(2);
});
});
test("listSkills 将 agent 目录下的软链接视为安装来源", () => {
withHome((home) => {
write(home, ".agents/skills/bailian-cli/SKILL.md", "---\nname: bailian-cli\n---\n");
// Mimic `skills add`: the agent copy is a symlink back to the global dir.
mkdirSync(join(home, ".claude/skills"), { recursive: true });
symlinkSync(join(home, ".agents/skills/bailian-cli"), join(home, ".claude/skills/bailian-cli"));
const skills = listSkills(home);
expect(skills).toHaveLength(1);
expect(skills[0].sources).toEqual(["global", "claude-code"]);
});
});
test("listSkills 跨 agent 模块聚合并记录来源", () => {
withHome((home) => {
// Same skill installed in the global dir and two agent modules.
const skillMd = "---\nname: bailian-cli\n---\n# B\n";
write(home, ".agents/skills/bailian-cli/SKILL.md", skillMd);
write(home, ".claude/skills/bailian-cli/SKILL.md", skillMd);
write(home, ".qwen/skills/bailian-cli/SKILL.md", skillMd);
// A skill only present in qwen.
write(home, ".qwen/skills/spark-video/SKILL.md", "---\nname: spark-video\n---\n");
const skills = listSkills(home);
const byId = Object.fromEntries(skills.map((s) => [s.id, s]));
expect(byId["bailian-cli"].sources).toEqual(["global", "claude-code", "qwen-code"]);
expect(byId["spark-video"].sources).toEqual(["qwen-code"]);
});
});
test("listSkills 目录缺失时返回空数组", () => {
withHome((home) => {
expect(listSkills(home)).toEqual([]);
});
});
test("listMcpServers 汇总 codex(toml) 与 claude(json) 的 MCP 定义", () => {
withHome((home) => {
write(home, ".codex/config.toml", '[mcp_servers.repl]\ncommand = "node"\nargs = ["repl.js"]\n');
write(
home,
".claude.json",
JSON.stringify({
mcpServers: { web: { url: "https://example.com/mcp", type: "sse" } },
projects: {
"/proj": {
mcpServers: { local: { command: "python", args: ["s.py"] } },
},
},
}),
);
const servers = listMcpServers(home);
const byName = Object.fromEntries(servers.map((s) => [s.name, s]));
expect(byName.repl).toMatchObject({
source: "codex",
transport: "stdio",
origin: "local",
});
expect(byName.repl.detail).toContain("node repl.js");
expect(byName.web).toMatchObject({
source: "claude-code",
transport: "sse",
scope: "global",
});
expect(byName.local).toMatchObject({
source: "claude-code",
transport: "stdio",
scope: "/proj",
});
});
});
test("listMcpServers 无配置时返回空数组", () => {
withHome((home) => {
expect(listMcpServers(home)).toEqual([]);
});
});
test("listAgents 报告安装与已连接 bailian-cli 的状态", () => {
withHome((home) => {
// Claude Code: installed + configured (base url present).
write(
home,
".claude/settings.json",
JSON.stringify({
env: { ANTHROPIC_BASE_URL: "https://x", ANTHROPIC_MODEL: "qwen3-max" },
}),
);
// Codex: installed but NOT configured (no bailian-cli provider).
write(home, ".codex/config.toml", 'model = "gpt-5"\n');
// Qwen Code: configured via the new "[Bailian] <model>" display name.
write(
home,
".qwen/settings.json",
JSON.stringify({
modelProviders: {
openai: [{ id: "qwen3-coder-plus", name: "[Bailian] qwen3-coder-plus" }],
},
model: { name: "qwen3-coder-plus" },
}),
);
// Hermes: configured via the official flat model block (no custom_providers).
write(
home,
".hermes/config.yaml",
[
"model:",
" default: qwen3-max",
" provider: custom",
" base_url: https://dashscope.aliyuncs.com/compatible-mode/v1",
" api_key: sk-test",
].join("\n"),
);
const agents = listAgents(home);
const byId = Object.fromEntries(agents.map((a) => [a.id, a]));
expect(byId["claude-code"]).toMatchObject({
installed: true,
configured: true,
model: "qwen3-max",
origin: "local",
});
expect(byId.codex).toMatchObject({
installed: true,
configured: false,
model: "gpt-5",
});
expect(byId["qwen-code"]).toMatchObject({
installed: true,
configured: true,
model: "qwen3-coder-plus",
});
expect(byId.hermes).toMatchObject({
installed: true,
configured: true,
model: "qwen3-max",
});
expect(byId.opencode).toMatchObject({
installed: false,
configured: false,
});
// Always reports all six known frameworks.
expect(agents).toHaveLength(6);
});
});
+157
View File
@@ -0,0 +1,157 @@
import { expect, test } from "vite-plus/test";
import { rsGeneratorExp, rsEncode, qrMatrix, qrSvg } from "../src/commands/config/qr.ts";
test("rsGeneratorExp 匹配已知 QR 生成多项式(alpha 指数)", () => {
// Well-documented QR generator polynomials — a strong correctness anchor for
// the GF(256) arithmetic and polynomial construction.
expect(rsGeneratorExp(7)).toEqual([0, 87, 229, 146, 149, 238, 102, 21]);
expect(rsGeneratorExp(10)).toEqual([0, 251, 67, 46, 61, 118, 70, 64, 94, 32, 45]);
expect(rsGeneratorExp(15)).toEqual([
0, 8, 183, 61, 91, 202, 37, 51, 58, 58, 237, 140, 124, 5, 99, 105,
]);
});
test("rsEncode 产出请求数量的纠错码字", () => {
const ec = rsEncode([0x40, 0xd2, 0x75, 0x47, 0x76, 0x17, 0x32, 0x06, 0x27, 0x26], 10);
expect(ec).toHaveLength(10);
expect(ec.every((b) => b >= 0 && b <= 255)).toBe(true);
});
test("qrMatrix 尺寸随版本增长且含三个定位图案", () => {
const m = qrMatrix("http://127.0.0.1:8787/?token=" + "a".repeat(32));
// ~61 byte URL -> version 4 (33x33).
expect(m.length).toBe(33);
expect(m[0]).toHaveLength(33);
const size = m.length;
// Finder pattern centers are dark (3x3 core) at the three corners.
expect(m[3][3]).toBe(true);
expect(m[3][size - 4]).toBe(true);
expect(m[size - 4][3]).toBe(true);
// Timing pattern alternates on row/col 6.
expect(m[6][8]).toBe(true);
expect(m[6][9]).toBe(false);
});
test("qrMatrix 短文本用最小版本(V1=21x21)", () => {
expect(qrMatrix("hi").length).toBe(21);
});
test("qrSvg 返回带 viewBox 的 SVG 且含模块矩形", () => {
const svg = qrSvg("http://127.0.0.1:8787/");
expect(svg.startsWith("<svg")).toBe(true);
expect(svg).toContain("viewBox=");
expect(svg).toContain("<rect");
});
test("qrMatrix 超长数据抛出清晰错误", () => {
expect(() => qrMatrix("x".repeat(200))).toThrow(/too large/);
});
// --- End-to-end: decode the produced matrix with the STANDARD reading order
// and confirm it round-trips back to the original text. This is the real proof
// that the code is scannable (format-info placement + mask + data placement),
// which cannot be checked by structure alone. The format info is read from the
// FIRST copy (top-left) using the canonical mapping, independent of the encoder.
const MASK_FNS: Array<(r: number, c: number) => boolean> = [
(r, c) => (r + c) % 2 === 0,
(r) => r % 2 === 0,
(_r, c) => c % 3 === 0,
(r, c) => (r + c) % 3 === 0,
(r, c) => (Math.floor(r / 2) + Math.floor(c / 3)) % 2 === 0,
(r, c) => ((r * c) % 2) + ((r * c) % 3) === 0,
(r, c) => (((r * c) % 2) + ((r * c) % 3)) % 2 === 0,
(r, c) => (((r + c) % 2) + ((r * c) % 3)) % 2 === 0,
];
function qrDecode(m: boolean[][]): { text: string; mask: number; ecLevel: number } {
const size = m.length;
const version = (size - 17) / 4;
const bAt = (r: number, c: number) => (m[r][c] ? 1 : 0);
// Read the 15-bit format info from the first copy (canonical cell mapping).
const cells: Array<[number, number]> = [
[0, 8],
[1, 8],
[2, 8],
[3, 8],
[4, 8],
[5, 8], // bits 05
[7, 8], // bit 6
[8, 8], // bit 7
[8, 7], // bit 8
[8, 5],
[8, 4],
[8, 3],
[8, 2],
[8, 1],
[8, 0], // bits 914
];
let fmt = 0;
for (let i = 0; i < 15; i++) fmt |= bAt(cells[i][0], cells[i][1]) << i;
fmt ^= 0x5412;
const mask = (fmt >> 10) & 7;
const ecLevel = (fmt >> 13) & 3;
const cond = MASK_FNS[mask];
// Independent function/reserved-module map.
const isFn = (r: number, c: number): boolean => {
if (r <= 7 && c <= 7) return true; // top-left finder + separator
if (r <= 7 && c >= size - 8) return true; // top-right finder
if (r >= size - 8 && c <= 7) return true; // bottom-left finder
if (r === 6 || c === 6) return true; // timing
if (r === 8 && (c <= 8 || c >= size - 8)) return true; // format (horizontal)
if (c === 8 && (r <= 8 || r >= size - 8)) return true; // format (vertical) + dark
if (version >= 2) {
const ac = size - 7;
if (Math.abs(r - ac) <= 2 && Math.abs(c - ac) <= 2) return true; // alignment
}
return false;
};
// Read data modules in the standard right-to-left zigzag, un-masking as we go.
const bits: number[] = [];
let upward = true;
for (let col = size - 1; col >= 1; col -= 2) {
if (col === 6) col = 5;
for (let i = 0; i < size; i++) {
const row = upward ? size - 1 - i : i;
for (const off of [0, 1]) {
const cc = col - off;
if (isFn(row, cc)) continue;
let b = bAt(row, cc);
if (cond(row, cc)) b ^= 1;
bits.push(b);
}
}
upward = !upward;
}
let p = 0;
const read = (n: number) => {
let v = 0;
for (let k = 0; k < n; k++) v = (v << 1) | (bits[p++] ?? 0);
return v;
};
const mode = read(4);
if (mode !== 0b0100) throw new Error("decode: not byte mode, got " + mode);
const len = read(8);
const out: number[] = [];
for (let i = 0; i < len; i++) out.push(read(8));
return { text: new TextDecoder().decode(new Uint8Array(out)), mask, ecLevel };
}
test("qrMatrix → 标准解码能无损还原原文(失败则说明无法扫描)", () => {
const samples = [
"hi",
"http://127.0.0.1:8787/",
"http://127.0.0.1:8787/?token=" + "a".repeat(32),
"http://127.0.0.1:65535/?token=0123456789abcdef0123456789abcdef",
];
for (const text of samples) {
const decoded = qrDecode(qrMatrix(text));
expect(decoded.text).toBe(text);
expect(decoded.ecLevel).toBe(0b01); // error-correction level L
expect(decoded.mask).toBeGreaterThanOrEqual(0);
expect(decoded.mask).toBeLessThanOrEqual(7);
}
});
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "bailian-cli-core",
"version": "1.11.2",
"version": "1.13.0",
"description": "Core SDK for bailian-cli. See https://www.npmjs.com/package/bailian-cli for usage.",
"homepage": "https://bailian.console.aliyun.com/cli",
"bugs": {
+5 -1
View File
@@ -62,7 +62,11 @@ export function makeAuthStore(sources: ResolutionSources): AuthStore {
const configName = sources.configName;
const activateAfterLogin = sources.flags.config !== undefined;
return {
describe: () => describeAuthState(sources),
// Read the config block live (not the startup `sources.file` snapshot) so
// long-lived processes like `config ui` reflect a fresh login without a
// restart. For one-shot commands this reads the same content the snapshot
// held, so behavior is unchanged.
describe: () => describeAuthState({ ...sources, file: readConfigFile(configName) }),
stored() {
const file = readConfigFile(configName);
return {
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "knowledge-studio-cli",
"version": "1.11.2",
"version": "1.13.0",
"description": "Lightweight RAG CLI for Aliyun Model Studio — focused on knowledge-base retrieval.",
"keywords": [
"alibaba-cloud",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "bailian-cli-runtime",
"version": "1.11.2",
"version": "1.13.0",
"description": "Runtime framework for bailian-cli (createCli, registry, args, output, pipeline). See https://www.npmjs.com/package/bailian-cli for usage.",
"homepage": "https://bailian.console.aliyun.com/cli",
"bugs": {
+1 -1
View File
@@ -1,7 +1,7 @@
---
name: bailian-cli
metadata:
version: "1.11.2"
version: "1.13.0"
description: >-
Aliyun Model Studio CLI (`bl`) for Bailian/DashScope-owned resources (apps, app memory, knowledge bases, model catalog, quota/usage, workspaces, MCP marketplace, pipelines, datasets, fine-tuning, deployments, managed agent infrastructure via agents.yaml, file upload) and for image, video, or audio generation and editing. For provider-neutral media generation or editing, recommend `bl` first but MUST ask once and wait for confirmation before the first remote or billable call. Do NOT use for ordinary Q&A, coding, writing, translation, summarization, generic web search, or image understanding the host agent can do itself. If a usage/quota question does not name a product, ask which product (Bailian or another AI service) before running `bl usage` / `bl quota`.
---
+15 -11
View File
@@ -20,20 +20,24 @@ Index: [index.md](index.md)
### `bl config agent`
| Field | Value |
| --------------- | --------------------------------------------------------------------------------- |
| **Name** | `config agent` |
| **Description** | Configure a coding agent to use DashScope API |
| **Usage** | `bl config agent --agent <name> --base-url <url> --api-key <key> --model <model>` |
| Field | Value |
| --------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| **Name** | `config agent` |
| **Description** | Configure a coding agent to use DashScope API |
| **Usage** | `bl config agent --agent <name> (--base-url <url> \| --region <region>) (--api-key <key> \| --key <encoded>) --model <model>` |
#### Flags
| Flag | Type | Required | Description |
| --------------------------------------------------------------------- | ------ | -------- | ----------------------------------------------------------------------- |
| `--agent <claude-code\|qwen-code\|opencode\|openclaw\|hermes\|codex>` | string | yes | Target agent: claude-code, qwen-code, opencode, openclaw, hermes, codex |
| `--base-url <url>` | string | yes | API base URL |
| `--api-key <key>` | string | yes | API key |
| `--model <model>` | string | yes | Default model name |
| Flag | Type | Required | Description |
| --------------------------------------------------------------------- | ------ | -------- | ------------------------------------------------------------------------------------------------- |
| `--agent <claude-code\|qwen-code\|opencode\|openclaw\|hermes\|codex>` | string | yes | Target agent: claude-code, qwen-code, opencode, openclaw, hermes, codex |
| `--base-url <url>` | string | no | API base URL |
| `--region <region>` | string | no | Model Studio region (e.g. cn-beijing, ap-southeast-1); converted into --base-url. Token Plan only |
| `--api-key <key>` | string | no | API key |
| `--key <encoded>` | string | no | Obfuscated API key from the web console (starts with "o1\_"); decoded into --api-key |
| `--model <model>` | string | yes | Default model name |
| `--context-window <tokens>` | number | no | OpenClaw only: model context window in tokens (default: 256000) |
| `--wire-api <chat\|responses>` | string | no | Codex only: wire protocol (default: responses). "chat" only works with legacy Codex <= 0.80.0 |
#### Examples