Repository navigation
feat(plugins): add CLI installation and in-app OAuth sign-in - #6950
Merged
Hmbown merged 14 commits intoOct 11, 2026
Merged
Conversation
Reuse the existing reviewed installer and host OAuth owner. Add codewhale install, pinned npm/GitHub sources, /login provider and /logout provider; remove API-key entry for plugin OAuth. Keep plugin catalogs account-scoped. Local baseline plugin checks: 62 passed; upstream compile receipt is recorded by this workflow.
The registry requires a one-line summary of at most 120 characters and only the tui/desktop/web/api surfaces. plugin-oauth-providers had a 132-character summary and plugin-shell-install named a cli surface; the CLI install is covered by its tui row. Fixes the feature_registry_matches_code failure on this PR (Test ubuntu-latest). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Hmbown
pushed a commit
that referenced
this pull request
Oct 11, 2026
… with /disconnect; /login and /logout stay Codewhale-account only Follow-up to merged PR #6950 (@LIghtJUNction). /login reverts to status|account|key and points plugin sign-in at /connect <provider>; /logout no longer takes a provider. New /connect [provider] opens the provider picker or starts plugin PKCE; /disconnect <provider> removes the local grant. Both are protected built-ins. Picker, OAuth hints and English strings say connected/disconnected; CmdConnectDescription and CmdDisconnectDescription added to all 15 locales; docs/PLUGIN_PROVIDERS.md and features.toml rows updated. Evidence: nextest of the command, locale and plugin tests 236 run, 236 passed; feature_registry 2 passed; check-tui-locale-parity PASS (2525 keys). Not run: clippy, PTY tests, a real browser OAuth flow, hosted CI. Refs #6950 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Hmbown
pushed a commit
that referenced
this pull request
Oct 11, 2026
…isconnect - The CHANGELOG 0.10.2 section gains Added (`/connect` and `/disconnect`, #6950) and Fixed lines for the slices on this branch: - git 2.43 /undo, shell cancel, the 30 s background notice and the todo_write receipt; - goal usage, pet live rows and crisp sprites, #6931 and /constitution; - the fixes that already landed on main for #6953, #6954, #6955, #6923, #6947 and #6945, plus the Auto-Review guardian budget, skills, MCP reconnect, the pet owner idle exit, tool headers, /jobs and the one-row gap. - Contributors: @LIghtJUNction for #6950, #6947 added to @SparkofSpike, and #6952 added to @Lstarsky0. - crates/tui/CHANGELOG.md was regenerated with scripts/sync-changelog.sh; the tui crate include_str!s it. - docs/features.toml: the plugin-oauth-providers summary names /disconnect next to /connect (111 characters, under the 120 limit). Evidence: ./scripts/release/check-versions.sh --require-dated-release prints "Version state OK: workspace=0.10.2, npm=0.10.2, npm-binary=0.10.2, lockfile in sync" and "Feature release-note receipts OK: 8 linked issue reference(s) checked in v0.10.1..HEAD". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BsXVvReYca2UxzimQtj7Mj
Hmbown
pushed a commit
that referenced
this pull request
Oct 11, 2026
…ibutor page CI on 054b122 failed "Lint & Type Check": web/lib/public-copy.test.ts:167 compares the 0.10.2 CHANGELOG contributor handles with the website credit arrays and the docs/CONTRIBUTORS.md band. The previous commit (49bd217) added @LIghtJUNction (#6950) to the CHANGELOG. The website still listed them under UNRELEASED_CONTRIBUTORS, which RELEASE_CONTRIBUTORS does not include. - web/lib/release-credits.ts moves @LIghtJUNction from UNRELEASED_CONTRIBUTORS to RELEASE_CONTRIBUTORS, as its own comment describes for the release that carries the work. UNRELEASED_CONTRIBUTORS is now empty. - The docs/CONTRIBUTORS.md v0.10.2 band gains the #6950 line, and adds #6947 to SparkofSpike's entry and #6952 to Lstarsky0's, matching the CHANGELOG. Evidence: a python3 re-implementation of the test's three handle extractions gives the same 8 sorted handles for the CHANGELOG, the website arrays and the doc band (@BX166 @LIghtJUNction @Lstarsky0 @SparkofSpike @asto18089 @dajiaohuang @gaord @jayanthvee). `python3 scripts/check-contributor-credit.py`: "Every contributor in the window is credited on all three surfaces." The vitest run itself is CI's job on this PR. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BsXVvReYca2UxzimQtj7Mj
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
"PR #6805" (#6805) introduced reviewed, host-managed OAuth AI providers. However, users still need a separate terminal command to sign in, and installing plugins from source lacks a simple CLI entry point.
This PR improves both workflows, taking inspiration from Pi's plugin installation experience while preserving Codewhale's existing security model.
Add "codewhale install" using the existing plugin installer.
Supported sources include:
codewhale install git:github.com/owner/repo
codewhale install git:github.com/owner/repo@v1.0.0
codewhale install npm:package@1.0.0
codewhale install npm:@scope/package@1.0.0
codewhale install ./local-plugin
This adopts Pi-style source syntax, not Pi's executable extension runtime.
Integrate plugin authentication into the existing "/login" and "/provider" interfaces.
The existing "codewhale auth plugin-login --provider " remains available for terminal use. Both entry points reuse the same host-owned OAuth implementation.
No separate token store or authentication implementation is introduced.
The intended user flow becomes:
Users no longer need to leave the TUI to run a separate plugin login command.
The changes preserve existing security boundaries:
Git shorthand supports GitHub repositories only. Npm sources require exact versions. Mutable Git tags are not integrity guarantees.
No device-code login or remote token revocation is added.
Documentation
Updated:
Issue
No-Issue: Improve native plugin installation and OAuth usability following #6805.
How I tested it
Added regression tests covering:
Verification status: Upstream GitHub Actions currently report "action_required" for this fork PR, not passing CI results. The full upstream test suite and interactive browser OAuth flow have not been verified here.
Checklist