Skip to content

chore: validate Zhipu API keys during onboarding - #335

Merged
qhkm merged 1 commit into
mainfrom
chore/zhipu-key-validation
Mar 14, 2026
Merged

qhkm merged 1 commit into
mainfrom
chore/zhipu-key-validation

Conversation

@qhkm

@qhkm qhkm commented Mar 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • add explicit Zhipu/GLM API key validation through the read-only /models endpoint
  • reuse the bearer /models validation path for OpenAI-compatible key checks and show Zhipu-specific help URLs on auth and billing errors
  • add regression coverage for Zhipu validation and default base URL resolution, and update AGENTS.md and CLAUDE.md

Closes #332

Verification

  • cargo fmt -- --check
  • cargo clippy -- -D warnings
  • cargo test validate_api_key_zhipu -- --nocapture
  • cargo test friendly_api_error_401_zhipu -- --nocapture
  • cargo test zhipu_resolves_with_default_base_url -- --nocapture
  • cargo test --lib
  • cargo test --doc

Notes

  • cargo nextest run --lib could not run in this environment because cargo-nextest is not installed.

Summary by CodeRabbit

  • Documentation

    • Updated provider documentation with onboarding validation details and OpenAI-compatible endpoint support notes.
  • New Features

    • Added support for Zhipu/GLM provider.
    • Enhanced provider error handling with new error types (Auth, RateLimit, Billing, ServerError, InvalidRequest, ModelNotFound, Timeout).
    • Per-provider model override capability.
    • Token-by-token streaming support via StreamEvent.
    • New OutputFormat options (Text, Json, JsonSchema).
  • Tests

    • Added Zhipu provider validation tests.

@coderabbitai

coderabbitai Bot commented Mar 12, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

This PR adds Zhipu (GLM) API key validation during onboarding by implementing a reusable bearer-token validation helper function, registering the zhipu provider with its specific endpoint, extending error messaging for zhipu-specific scenarios, and adding regression tests for provider validation and runtime resolution.

Changes

Cohort / File(s) Summary
Documentation updates
AGENTS.md, CLAUDE.md
Expanded provider documentation to describe onboarding validation support for Anthropic and OpenAI-compatible presets, including Zhipu/GLM, with details on endpoint checks and key validation methods.
Zhipu provider validation
src/cli/common.rs
Introduced private helper validate_bearer_models_key for bearer-token-based providers, refactored OpenAI validation to use the helper, added zhipu provider support with https://open.bigmodel.cn/api/paas/v4 endpoint, extended error messaging with zhipu-specific guidance for 401/402 responses, and added tests for zhipu validation scenarios (429 rate limiting and 401 auth errors).
Provider registry tests
src/providers/registry.rs
Added test_zhipu_resolves_with_default_base_url to validate that zhipu provider resolution correctly yields the default base URL and openai backend.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

  • #293: Introduces KeyValidation::RateLimited return path and broad HTTP 429 handling for key validation; this PR builds on that foundation by implementing zhipu-specific 429 rate-limit handling within the new validate_bearer_models_key helper.

Poem

🐰 A key to Zhipu's glowing door,
Bearer tokens we'll validate once more,
GET /models whispers "all is well,"
While 429s and 401s we gently quell,
Now GLM joins the onboarding way! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the primary change: adding Zhipu API key validation during onboarding, which aligns with the main objective of the PR.
Linked Issues check ✅ Passed The PR fully addresses the requirements from issue #332: implements Zhipu key validation via /models endpoint, adds comprehensive tests, and updates documentation (AGENTS.md, CLAUDE.md).
Out of Scope Changes check ✅ Passed All changes directly support Zhipu API validation scope: validation logic in cli/common.rs, provider registry tests, documentation updates, and error messaging align with the linked issue requirements.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch chore/zhipu-key-validation
📝 Coding Plan for PR comments
  • Generate coding plan

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
src/cli/common.rs (1)

513-515: Consider extracting the default base URL to avoid duplication.

The default URL "https://open.bigmodel.cn/api/paas/v4" is duplicated here and in src/providers/registry.rs:100. While the test test_zhipu_resolves_with_default_base_url guards against drift, consider referencing the PROVIDER_REGISTRY constant to eliminate the duplication:

let spec = zeptoclaw::providers::PROVIDER_REGISTRY
    .iter()
    .find(|s| s.name == "zhipu");
let base = api_base
    .or(spec.and_then(|s| s.default_base_url))
    .unwrap_or("https://open.bigmodel.cn/api/paas/v4");

This is a minor maintenance consideration; the current approach works correctly.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@src/cli/common.rs` around lines 513 - 515, The default base URL string is
duplicated; update the zhipu branch that calls validate_bearer_models_key to
derive base from the provider registry instead of hardcoding the literal. Look
up the provider spec in zeptoclaw::providers::PROVIDER_REGISTRY (find where
s.name == "zhipu"), use spec.default_base_url if present, then fallback to
api_base and finally the original literal; adjust the code around
validate_bearer_models_key to use this resolved base (preserve behavior covered
by test_zhipu_resolves_with_default_base_url).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In `@src/cli/common.rs`:
- Around line 513-515: The default base URL string is duplicated; update the
zhipu branch that calls validate_bearer_models_key to derive base from the
provider registry instead of hardcoding the literal. Look up the provider spec
in zeptoclaw::providers::PROVIDER_REGISTRY (find where s.name == "zhipu"), use
spec.default_base_url if present, then fallback to api_base and finally the
original literal; adjust the code around validate_bearer_models_key to use this
resolved base (preserve behavior covered by
test_zhipu_resolves_with_default_base_url).

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 79438a49-c408-4acb-9304-1c1f78ed9393

📥 Commits

Reviewing files that changed from the base of the PR and between b64cb54 and 86d13e4.

📒 Files selected for processing (4)
  • AGENTS.md
  • CLAUDE.md
  • src/cli/common.rs
  • src/providers/registry.rs

@qhkm
qhkm merged commit 2d39ea2 into main Mar 14, 2026
9 checks passed
@qhkm
qhkm deleted the chore/zhipu-key-validation branch March 14, 2026 16:58
taqtiqa-mark pushed a commit to taqtiqa-mark/zeptoclaw that referenced this pull request Mar 25, 2026
## Summary
- add explicit Zhipu/GLM API key validation through the read-only
/models endpoint
- reuse the bearer /models validation path for OpenAI-compatible key
checks and show Zhipu-specific help URLs on auth and billing errors
- add regression coverage for Zhipu validation and default base URL
resolution, and update AGENTS.md and CLAUDE.md

Closes qhkm#332

## Verification
- cargo fmt -- --check
- cargo clippy -- -D warnings
- cargo test validate_api_key_zhipu -- --nocapture
- cargo test friendly_api_error_401_zhipu -- --nocapture
- cargo test zhipu_resolves_with_default_base_url -- --nocapture
- cargo test --lib
- cargo test --doc

## Notes
- cargo nextest run --lib could not run in this environment because
cargo-nextest is not installed.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated provider documentation with onboarding validation details and
OpenAI-compatible endpoint support notes.

* **New Features**
  * Added support for Zhipu/GLM provider.
* Enhanced provider error handling with new error types (Auth,
RateLimit, Billing, ServerError, InvalidRequest, ModelNotFound,
Timeout).
  * Per-provider model override capability.
  * Token-by-token streaming support via StreamEvent.
  * New OutputFormat options (Text, Json, JsonSchema).

* **Tests**
  * Added Zhipu provider validation tests.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore: add Zhipu API key validation during onboarding

1 participant