Skip to content

feat: add Cheaper Inference LLM provider - #132

Open
aiapienthusiast wants to merge 1 commit into
0xMassi:mainfrom
aiapienthusiast:cheaperinference-provider
Open

aiapienthusiast wants to merge 1 commit into
0xMassi:mainfrom
aiapienthusiast:cheaperinference-provider

Conversation

@aiapienthusiast

@aiapienthusiast aiapienthusiast commented Oct 5, 2026 •

Copy link
Copy Markdown

This PR adds Cheaper Inference as an opt-in provider in the LLM chain.
It uses the same pattern as #116.

Cheaper Inference is an OpenAI-compatible LLM gateway.
One API key gives access to models from several labs.

Usage:

export CHEAPER_INFERENCE_API_KEY=your-key
webclaw https://example.com --summarize --llm-provider cheaperinference

The provider joins the default chain only when the key is set.
It is added last, after OrcaRouter.

Details

Files:

  • crates/webclaw-llm/src/providers/cheaperinference.rs: provider that wraps OpenAiProvider, with unit tests.
  • crates/webclaw-llm/src/providers/mod.rs, crates/webclaw-llm/src/chain.rs: register the provider at the end of the chain.
  • crates/webclaw-cli/src/main.rs: --llm-provider cheaperinference and error text.
  • crates/webclaw-server/src/routes/extract.rs, summarize.rs: error text.
  • README.md, README_zh-CN.md, env.example, CHANGELOG.md: env vars and changelog entry.

Env vars: CHEAPER_INFERENCE_API_KEY, CHEAPER_INFERENCE_BASE_URL (default https://api.cheaperinference.com/v1), CHEAPER_INFERENCE_MODEL (default gpt-5.4-mini).

Tests:

  • cargo fmt --check --all passes.
  • cargo clippy -p webclaw-llm --all-targets -- -D warnings passes.
  • cargo clippy -p webclaw-cli -p webclaw-server -- -D warnings passes.
  • cargo test -p webclaw-llm passes (65 passed).

Live check: gpt-5.4-mini returned a summary through ProviderChain::cloud_default() and summarize(), with only CHEAPER_INFERENCE_API_KEY set.

Summary by CodeRabbit

  • New Features
    • Added Cheaper Inference as an optional provider for extraction and summarization. It’s used when configured and follows OrcaRouter in the provider chain.
    • Added support for configuring its API key, endpoint, and model, with defaults provided for the endpoint and model.
    • Added cheaperinference as an available CLI provider option.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
CLAUDE.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 0dcd5f6c-ad53-4749-9bcc-cd30c58b229c
📥 Commits

Reviewing files that changed from the base of the PR and between 3c32041 and 9e93fe1.

📒 Files selected for processing (10)
  • CHANGELOG.md
  • README.md
  • README_zh-CN.md
  • crates/webclaw-cli/src/main.rs
  • crates/webclaw-llm/src/chain.rs
  • crates/webclaw-llm/src/providers/cheaperinference.rs
  • crates/webclaw-llm/src/providers/mod.rs
  • crates/webclaw-server/src/routes/extract.rs
  • crates/webclaw-server/src/routes/summarize.rs
  • env.example

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The change adds Cheaper Inference as an optional LLM provider. It supports configurable credentials, endpoint, and model settings. The default provider chain and CLI can use it, and setup guidance now documents its configuration.

Changes

Cheaper Inference provider

Layer / File(s) Summary
Provider implementation and configuration
crates/webclaw-llm/src/providers/cheaperinference.rs, crates/webclaw-llm/src/providers/mod.rs, env.example, README.md, README_zh-CN.md, CHANGELOG.md
Adds an OpenAI-compatible provider that resolves its API key, base URL, and model from overrides, environment variables, and defaults. Tests cover missing keys, defaults, and explicit overrides. Environment and documentation files describe the provider settings.
Default-chain and CLI integration
crates/webclaw-llm/src/chain.rs, crates/webclaw-cli/src/main.rs, crates/webclaw-server/src/routes/extract.rs, crates/webclaw-server/src/routes/summarize.rs
The default chain adds the provider after OrcaRouter when configured. The CLI accepts cheaperinference; CLI and server error messages list its API key as a configuration option.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant ProviderChain
  participant CheaperInferenceProvider
  participant Environment
  participant OpenAiProvider
  ProviderChain->>CheaperInferenceProvider: Construct optional provider
  CheaperInferenceProvider->>Environment: Read key and setting variables
  CheaperInferenceProvider->>OpenAiProvider: Create provider with resolved settings
Loading

Suggested reviewers: 0xmassi

Merge Risk: ⚪ Minimal · up to 9e93f

This change adds an opt-in Cheaper Inference provider. The provider is used only when its API key is configured, and it is consistent with the existing providers. No outstanding issues block merging.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 9e93f

The integration is opt-in, uses HTTPS by default, and preserves existing provider priority. However, endpoint overrides can send the new provider’s API key and request content over unencrypted HTTP. The risk is conditional on configuration, rather than an endpoint that ordinary API callers can directly choose.

Retained concerns

  • High · security · observed: The new adapter accepts an HTTP endpoint override and forwards its API key and completion content to the shared transport, which attaches the Bearer credential without requiring HTTPS. When such an endpoint is configured and completion reaches this provider, a network observer can capture those credentials and data. The transport weakness predates the PR, but this integration extends its exposure to the Cheaper Inference key and requests. The HTTPS default and configuration-controlled reachability materially limit the attack path.
Security review details

Security Blast Radius

  • inferred — The supported exposure is the Cheaper Inference credential and completion content sent by instances using the affected endpoint configuration. Multiple callers sharing that configuration can share the exposure. Downstream account permissions, tenant distribution, and environment-wide reach are not established, so broader compromise cannot be quantified.

Security Findings and Attack Paths

  • observed — The retained sensitive-data-exposure finding is supported by the constructor-to-POST trace. A configured HTTP base URL reaches a request carrying the API key and messages without a scheme guard. Exploitation requires that insecure configuration plus access to the transport path; the inspected HTTP request payloads do not themselves supply the LLM endpoint. The insecure transport mechanism is inherited, while this provider-specific exposure is newly reachable.

Trust Boundaries and Controls

  • observed — Content and model choices cross from caller input into completion requests, but endpoint and credential selection remain separate application configuration paths. Explicit CLI selection permits a base-URL override; automatic chains read provider environment settings. Nonempty-key gating controls activation, not endpoint trust. Public-page URL validation protects a different boundary from the credential-bearing LLM POST.

Resilience and Maintainability Implications

  • inferred — Fallback is a sequence of independent external requests, not an atomic transaction. Repetition or concurrent invocations can send content again, and a timeout does not establish that an earlier recipient received nothing. These semantics predate the PR; the new integration adds another possible recipient without changing local ordering or terminal-state handling.

Hardening Proposals

  • proposed — Require HTTPS for credential-bearing cloud-provider endpoints before attaching credentials, with any intentional insecure local-development mode made explicit. Define endpoint-configuration authority and permitted recipients separately from caller-controlled content, and verify rejection before transmission for both explicit selection and fallback.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 46.15% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 13 functions across 6 files. (4 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding the Cheaper Inference LLM provider.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 46.15% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 13 functions across 6 files. (4 skipped: 4 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant