openclaw
Version:
Multi-channel AI gateway with extensible messaging integrations
340 lines (339 loc) • 12.4 kB
JavaScript
import { o as coerceSecretRef } from "../../types.secrets-_0JOMGE5.js";
import { s as resolveDefaultSecretProviderAlias } from "../../ref-contract-BAa3qHwr.js";
import { n as ensureAuthProfileStore } from "../../store-C8spD0DG.js";
import { t as normalizeOptionalSecretInput } from "../../normalize-secret-input-OwRUfByL.js";
import { n as listProfilesForProvider } from "../../profile-list-DI8_o0Rw.js";
import { s as upsertAuthProfileWithLock } from "../../profiles-BMWtmBgj.js";
import { t as definePluginEntry } from "../../plugin-entry-C7DUzV0e.js";
import { t as applyAuthProfileConfig } from "../../provider-auth-helpers-BgLOn-Ws.js";
import "../../provider-auth-DAOC_qI9.js";
import { r as resolvePluginConfigObject } from "../../plugin-config-runtime-CpE6DYgJ.js";
import { i as getCachedLiveCatalogValue } from "../../provider-catalog-shared-DZr41kLr.js";
import { t as resolveCopilotExtendedThinkingLevels } from "../../model-metadata-C6_pjeW7.js";
import { n as fetchCopilotModelCatalog, r as resolveCopilotForwardCompatModel, t as PROVIDER_ID } from "../../models-DNfyhFSo.js";
import { t as resolveFirstGithubToken } from "../../auth-D4AgVrpe.js";
import { t as githubCopilotMemoryEmbeddingProviderAdapter } from "../../embeddings-BDrXODYX.js";
import { t as buildGithubCopilotReplayPolicy } from "../../replay-policy-nB0UfIfW.js";
import { o as wrapCopilotProviderStream } from "../../stream-C82YS009.js";
//#region extensions/github-copilot/index.ts
const COPILOT_ENV_VARS = [
"COPILOT_GITHUB_TOKEN",
"GH_TOKEN",
"GITHUB_TOKEN"
];
const DEFAULT_COPILOT_MODEL = "github-copilot/claude-opus-4.7";
const DEFAULT_COPILOT_PROFILE_ID = "github-copilot:github";
async function loadGithubCopilotRuntime() {
return await import("./register.runtime.js");
}
function applyCopilotDefaultModel(cfg) {
const defaults = cfg.agents?.defaults;
const existingModel = defaults?.model;
if (typeof existingModel === "string" ? existingModel.trim() : typeof existingModel === "object" && typeof existingModel?.primary === "string" ? existingModel.primary.trim() : "") return cfg;
const fallbacks = typeof existingModel === "object" && existingModel !== null && "fallbacks" in existingModel ? existingModel.fallbacks : void 0;
return {
...cfg,
agents: {
...cfg.agents,
defaults: {
...defaults,
model: {
...fallbacks ? { fallbacks } : void 0,
primary: DEFAULT_COPILOT_MODEL
},
models: {
...defaults?.models,
[DEFAULT_COPILOT_MODEL]: defaults?.models?.[DEFAULT_COPILOT_MODEL] ?? {}
}
}
}
};
}
function resolveExistingCopilotTokenProfileId(agentDir) {
const authStore = ensureAuthProfileStore(agentDir, { allowKeychainPrompt: false });
return listProfilesForProvider(authStore, PROVIDER_ID).find((profileId) => {
const profile = authStore.profiles[profileId];
if (profile?.type !== "token") return false;
return Boolean(normalizeOptionalSecretInput(profile.token) || coerceSecretRef(profile.tokenRef)?.id.trim());
});
}
function resolveExistingCopilotAuthResult(agentDir) {
const profileId = resolveExistingCopilotTokenProfileId(agentDir);
if (!profileId) return null;
const credential = ensureAuthProfileStore(agentDir, { allowKeychainPrompt: false }).profiles[profileId];
if (!credential || credential.type !== "token") return null;
return {
profiles: [{
profileId,
credential
}],
defaultModel: DEFAULT_COPILOT_MODEL
};
}
async function resolveCopilotNonInteractiveToken(ctx, flagValue) {
const resolveFromEnvChain = async () => {
for (const envVar of COPILOT_ENV_VARS) {
const resolved = await ctx.resolveApiKey({
provider: PROVIDER_ID,
flagName: "--github-copilot-token",
envVar,
envVarName: envVar,
allowProfile: false,
required: false
});
if (resolved) return resolved;
}
return null;
};
if (ctx.opts.secretInputMode === "ref") {
const resolved = await resolveFromEnvChain();
if (resolved) return resolved;
if (flagValue) {
ctx.runtime.error(["--github-copilot-token cannot be used with --secret-input-mode ref unless COPILOT_GITHUB_TOKEN, GH_TOKEN, or GITHUB_TOKEN is set in env.", "Set one of those env vars and omit --github-copilot-token, or use --secret-input-mode plaintext."].join("\n"));
ctx.runtime.exit(1);
}
return null;
}
const primary = await ctx.resolveApiKey({
provider: PROVIDER_ID,
flagValue,
flagName: "--github-copilot-token",
envVar: COPILOT_ENV_VARS[0],
envVarName: COPILOT_ENV_VARS[0],
allowProfile: false,
required: false
});
if (primary || flagValue) return primary;
for (const envVar of COPILOT_ENV_VARS.slice(1)) {
const resolved = await ctx.resolveApiKey({
provider: PROVIDER_ID,
flagName: "--github-copilot-token",
envVar,
envVarName: envVar,
allowProfile: false,
required: false
});
if (resolved) return resolved;
}
return null;
}
async function runGitHubCopilotNonInteractiveAuth(ctx) {
const opts = ctx.opts;
const flagValue = normalizeOptionalSecretInput(opts?.githubCopilotToken);
const resolved = await resolveCopilotNonInteractiveToken(ctx, flagValue);
let profileId = DEFAULT_COPILOT_PROFILE_ID;
if (resolved) {
const useTokenRef = ctx.opts.secretInputMode === "ref" && resolved.source === "env";
if (useTokenRef && !resolved.envVarName) {
ctx.runtime.error(["--secret-input-mode ref requires an explicit environment variable for provider \"github-copilot\".", "Set COPILOT_GITHUB_TOKEN in env and retry, or use --secret-input-mode plaintext."].join("\n"));
ctx.runtime.exit(1);
return null;
}
await upsertAuthProfileWithLock({
profileId,
credential: {
type: "token",
provider: PROVIDER_ID,
...useTokenRef ? { tokenRef: {
source: "env",
provider: resolveDefaultSecretProviderAlias(ctx.baseConfig, "env", { preferFirstProviderForSource: true }),
id: resolved.envVarName
} } : { token: resolved.key }
},
agentDir: ctx.agentDir
});
} else {
if (flagValue && ctx.opts.secretInputMode === "ref") return null;
const existingProfileId = resolveExistingCopilotTokenProfileId(ctx.agentDir);
if (!existingProfileId) {
ctx.runtime.error("Missing --github-copilot-token (or COPILOT_GITHUB_TOKEN / GH_TOKEN / GITHUB_TOKEN env var) for --auth-choice github-copilot.");
ctx.runtime.exit(1);
return null;
}
profileId = existingProfileId;
}
return applyCopilotDefaultModel(applyAuthProfileConfig(ctx.config, {
profileId,
provider: PROVIDER_ID,
mode: "token"
}));
}
var github_copilot_default = definePluginEntry({
id: "github-copilot",
name: "GitHub Copilot Provider",
description: "Bundled GitHub Copilot provider plugin",
register(api) {
const startupPluginConfig = api.pluginConfig ?? {};
function resolveCurrentPluginConfig(config) {
const runtimePluginConfig = resolvePluginConfigObject(config, "github-copilot");
if (runtimePluginConfig) return runtimePluginConfig;
return config ? {} : startupPluginConfig;
}
async function runGithubCopilotCatalog(ctx) {
if (resolveCurrentPluginConfig(ctx.config).discovery?.enabled === false) return null;
const { DEFAULT_COPILOT_API_BASE_URL, resolveCopilotApiToken } = await loadGithubCopilotRuntime();
const { githubToken, hasProfile } = await resolveFirstGithubToken({
agentDir: ctx.agentDir,
config: ctx.config,
env: ctx.env
});
if (!hasProfile && !githubToken) return null;
let baseUrl = DEFAULT_COPILOT_API_BASE_URL;
let copilotApiToken;
if (githubToken) try {
const token = await resolveCopilotApiToken({
githubToken,
env: ctx.env
});
baseUrl = token.baseUrl;
copilotApiToken = token.token;
} catch {
baseUrl = DEFAULT_COPILOT_API_BASE_URL;
}
let discoveredModels = [];
if (copilotApiToken) try {
discoveredModels = await getCachedLiveCatalogValue({
keyParts: [
PROVIDER_ID,
"models",
baseUrl,
copilotApiToken
],
load: async () => await fetchCopilotModelCatalog({
copilotApiToken,
baseUrl
})
});
} catch {
discoveredModels = [];
}
return { provider: {
baseUrl,
models: discoveredModels
} };
}
async function runGithubCopilotUnifiedLiveCatalog(ctx) {
const result = await runGithubCopilotCatalog(ctx);
if (!result || !("provider" in result)) return null;
return (result.provider.models ?? []).map((model) => {
const entry = {
kind: "text",
provider: PROVIDER_ID,
model: model.id,
source: "live"
};
if (model.name) entry.label = model.name;
return entry;
});
}
async function runGitHubCopilotAuth(ctx) {
const existing = resolveExistingCopilotAuthResult(ctx.agentDir);
if (existing) {
if (!await ctx.prompter.confirm({
message: "GitHub Copilot auth already exists. Re-run login?",
initialValue: false
})) return existing;
}
await ctx.prompter.note(["This will open a GitHub device login to authorize Copilot.", "Requires an active GitHub Copilot subscription."].join("\n"), "GitHub Copilot");
const { runGitHubCopilotDeviceFlow } = await import("./login.js");
const result = await runGitHubCopilotDeviceFlow({
showCode: async ({ verificationUrl, userCode, expiresInMs }) => {
const expiresInMinutes = Math.max(1, Math.round(expiresInMs / 6e4));
await ctx.prompter.note([
"Open this URL in your browser and enter the code below.",
`URL: ${verificationUrl}`,
`Code: ${userCode}`,
`Code expires in ${expiresInMinutes} minutes. Never share it.`,
"",
"If a browser does not open automatically after you continue, copy the URL manually."
].join("\n"), "Authorize GitHub Copilot");
},
openUrl: async (url) => {
await ctx.openUrl(url);
}
});
if (result.status === "access_denied") {
await ctx.prompter.note("GitHub Copilot login was cancelled.", "GitHub Copilot");
return { profiles: [] };
}
if (result.status === "expired") {
await ctx.prompter.note("The GitHub device code expired. Retry login to get a new code.", "GitHub Copilot");
return { profiles: [] };
}
return {
profiles: [{
profileId: DEFAULT_COPILOT_PROFILE_ID,
credential: {
type: "token",
provider: PROVIDER_ID,
token: result.accessToken
}
}],
defaultModel: DEFAULT_COPILOT_MODEL
};
}
api.registerMemoryEmbeddingProvider(githubCopilotMemoryEmbeddingProviderAdapter);
api.registerProvider({
id: PROVIDER_ID,
label: "GitHub Copilot",
docsPath: "/providers/models",
envVars: COPILOT_ENV_VARS,
auth: [{
id: "device",
label: "GitHub device login",
hint: "Browser device-code flow",
kind: "device_code",
run: async (ctx) => await runGitHubCopilotAuth(ctx),
runNonInteractive: async (ctx) => await runGitHubCopilotNonInteractiveAuth(ctx)
}],
wizard: { setup: {
choiceId: "github-copilot",
choiceLabel: "GitHub Copilot",
choiceHint: "Device login with your GitHub account",
methodId: "device",
modelSelection: { promptWhenAuthChoiceProvided: true }
} },
catalog: {
order: "late",
run: runGithubCopilotCatalog
},
resolveDynamicModel: (ctx) => resolveCopilotForwardCompatModel(ctx),
wrapStreamFn: wrapCopilotProviderStream,
buildReplayPolicy: ({ modelId }) => buildGithubCopilotReplayPolicy(modelId),
resolveThinkingProfile: ({ modelId, compat }) => {
return { levels: [
{ id: "off" },
{ id: "minimal" },
{ id: "low" },
{ id: "medium" },
{ id: "high" },
...resolveCopilotExtendedThinkingLevels(modelId, compat).map((id) => ({ id }))
] };
},
prepareRuntimeAuth: async (ctx) => {
const { resolveCopilotApiToken } = await loadGithubCopilotRuntime();
const token = await resolveCopilotApiToken({
githubToken: ctx.apiKey,
env: ctx.env
});
return {
apiKey: token.token,
baseUrl: token.baseUrl,
expiresAt: token.expiresAt
};
},
resolveUsageAuth: async (ctx) => await ctx.resolveOAuthToken(),
fetchUsageSnapshot: async (ctx) => {
const { fetchCopilotUsage } = await loadGithubCopilotRuntime();
return await fetchCopilotUsage(ctx.token, ctx.timeoutMs, ctx.fetchFn);
}
});
api.registerModelCatalogProvider({
provider: PROVIDER_ID,
kinds: ["text"],
liveCatalog: runGithubCopilotUnifiedLiveCatalog
});
}
});
//#endregion
export { github_copilot_default as default };