diff --git a/AGENTS.md b/AGENTS.md index a81460e..475347c 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -25,3 +25,18 @@ See the [Host notification guide](https://github.com/cordisx/cordisx/blob/3cfe37 for the interaction contract and older-Host capability boundary. Dependency setup: [notification migration](./.agents/docs/notifications.md). + +## Development and release + +- Requires Node.js 22 or newer. Install dependencies with `npm ci`. +- Run `npm run check`, `npm pack --dry-run`, and `git diff --check` before a + release checkpoint. +- Keep public READMEs focused on installation and use. Architecture, migration + history, source layout, local development, tests, and release operations + belong here or in indexed maintainer documentation. +- Releases use a GitHub prerelease, not npm. Build the exact merged main commit, + package with `npm pack`, attach the archive with `SHA256SUMS`, then download + and verify both assets. The archive must contain `cordisx-package.json`, the + browser entry, both service entries, and every declared runtime resource. +- Marketplace artifact URLs and digests are updated separately by the catalog + owner after verification. Do not copy older trust records. diff --git a/README.md b/README.md index 9cac37a..14c0573 100644 --- a/README.md +++ b/README.md @@ -1,47 +1,82 @@ # CLIProxy Providers -This public repository is the standalone owner of the CordisX CLIProxyAPI -provider sessions plugin. +CLIProxy Providers connects CordisX to models and sessions exposed by a +CLIProxyAPI runtime. Use it to browse provider models, create and continue +sessions, inspect session content, and manage reported upstream accounts from +the CordisX interface. -## Delivery status +## Install -This version contains the standalone renderer, executable `platform-provider` -service, and package-v14 managed gateway runtime. The renderer uses only public -Host React, UI, and service contracts. The Node services use only public -Protocol and Host-managed service APIs; CLIProxy method declarations, response -projection, lifecycle, upstream composition, and account controls live here. +Plugin ID: `cli-proxy-api`. Current release: `0.1.1`. -The Host owns endpoint and credential resolution, process startup, opaque -workspace handles, method/schema policy, configuration persistence, and the -single Provider Fleet. The plugin receives no endpoint, credential, process, -filesystem path, raw transport, or Fleet handle. +The CordisX Community Marketplace feed must already be configured and enabled +before `--source` can select it: -The plugin currently pins the experimental Protocol review head -`a1127780513b76f0c3b1acee70cd638b5348c6a5` and Host review head -`204d7a59e800c27258fb41435390a72cee1c5e9e`. These dependencies are public but -unmerged and unpublished. The package remains `private` to prevent npm -publication; its manifest declares explicit local source distribution, and no -packaged installer is available yet. +```sh +FEED_URL=https://raw.githubusercontent.com/cordisx/marketplace/main/marketplace.json +npx cordisx@beta source add "$FEED_URL" --yes +npx cordisx@beta plugin install cli-proxy-api --source "$FEED_URL" --version 0.1.1 +``` -## Development +Skip `source add` when that exact feed is already enabled. For another profile, +add the same `--profile ` argument to both commands. `--yes` confirms +the source change only; it does not approve plugin permissions. A discovery +source is not a trust root. -Requires Node.js 22 or newer. +The install command becomes available after the Marketplace v3 entry lists the +verified `0.1.1` artifact. Until then, download the archive and `SHA256SUMS` +from the +[GitHub release](https://github.com/cordisx/plugin-cli-proxy-api/releases/tag/v0.1.1). -```sh -npm ci -npm run check -npm run dev:dry-run -``` +## Use + +Open CLIProxy Providers in CordisX to select a provider and model, create a +session, or open a previously reported session. Available controls can include +continue, fork, archive, restore, delete, send, steer, and interrupt; the plugin +shows only operations permitted for the exact request. + +The Upstream Subscriptions page lists CLIProxyAPI accounts, their status and +models, and configured CordisX upstreams. Supported OAuth actions can be +started or cancelled there. This release can manage accounts reported by +CLIProxyAPI but cannot add or import account files in CordisX. + +## Configuration + +Use the CordisX plugin configuration to limit visible providers with +`providerIds`; leave it empty to show all reported providers. Configuration +applies after a plugin restart. The managed gateway reads its packaged YAML and +JSON schemas under Host control. + +CLIProxyAPI accounts and endpoints must be configured in the external runtime. +The Host resolves credentials, starts managed processes, persists configuration, +and owns the Provider Fleet. The plugin never receives raw credentials, +filesystem paths, process handles, or transport handles. + +## Permissions and limits + +All model, task, and turn capabilities are optional. Task content, creation, +control, turn submission, and turn control are scoped to the exact request. +Review requested permissions before enabling them. -`npm run dev:dry-run` validates the local source graph without launching Codex -Desktop. The package remains `private`; use the explicit local source distribution described by the package manifest. +Availability depends on a compatible Host managed-service runtime and a working +CLIProxyAPI configuration. The plugin does not silently substitute another +provider or model when an exact identity is unavailable. -## Provenance and license +## Troubleshooting -[HISTORY.md](HISTORY.md) records the filtered owner history from the original -Host-owned implementation. This repository is licensed under -[AGPL-3.0-or-later](LICENSE). +- **Install cannot find version `0.1.1`:** confirm the Marketplace v3 entry + lists the verified artifact. `--source` does not add or repair a feed. +- **No models or sessions appear:** confirm CLIProxyAPI is running, its accounts + are enabled, and model/catalog read permissions are granted. +- **Account controls are unavailable:** configure the account outside CordisX + or verify that the Host managed service exposes the requested operation. +- **A session action is disabled:** grant the matching exact-request permission + and confirm the selected provider still reports that session. -## Notification feedback +## License -See [operation notifications and development dependencies](./.agents/docs/notifications.md). +CLIProxy Providers is licensed under +[AGPL-3.0-or-later](LICENSE). Provenance is recorded in +[HISTORY.md](HISTORY.md), and third-party notices are in +[THIRD_PARTY_NOTICES.md](THIRD_PARTY_NOTICES.md). Maintainer setup, checks, and +release instructions are in [AGENTS.md](AGENTS.md). diff --git a/README.zh-Hans.md b/README.zh-Hans.md index 2c42e7c..3698235 100644 --- a/README.zh-Hans.md +++ b/README.zh-Hans.md @@ -1,37 +1,71 @@ # CLIProxy Providers -此公开仓是 CordisX CLIProxyAPI Provider 会话插件的独立 owner。 +CLIProxy Providers 将 CordisX 连接到 CLIProxyAPI runtime 提供的模型与会话。可以用它 +浏览 Provider 模型、创建和继续会话、查看会话内容,并在 CordisX 中管理 runtime +上报的 upstream 账号。 -## 交付状态 +## 安装 -本版本包含独立 renderer、可执行的 `platform-provider` 服务和 package-v14 托管网关 -runtime。Renderer 只使用公开的 Host React、UI 和服务合同;Node 服务只使用公开 -Protocol 与 Host 托管服务 API。CLIProxy 的方法声明、响应投影、生命周期、上游组合和 -账号控制均由本仓库维护。 +插件 ID:`cli-proxy-api`。当前版本:`0.1.1`。 -Host 负责 endpoint 与凭据解析、进程启动、不透明 workspace handle、方法/Schema -策略、配置持久化和唯一的 Provider Fleet。插件不会获得 endpoint、凭据、进程、 -文件系统路径、原始 transport 或 Fleet handle。 +CordisX Community Marketplace feed 必须先完成配置并启用,`--source` 才能选择它: -插件当前固定实验性 Protocol review head -`a1127780513b76f0c3b1acee70cd638b5348c6a5` 和 Host review head -`204d7a59e800c27258fb41435390a72cee1c5e9e`。这些公开依赖尚未合并或发布。包继续保持 -`private` 以阻止 npm 发布;manifest 声明显式本地源码分发,目前仍未提供安装包。 +```sh +FEED_URL=https://raw.githubusercontent.com/cordisx/marketplace/main/marketplace.json +npx cordisx@beta source add "$FEED_URL" --yes +npx cordisx@beta plugin install cli-proxy-api --source "$FEED_URL" --version 0.1.1 +``` -## 开发 +若该 feed 已启用,可跳过 `source add`。使用其他 profile 时,两条命令都要添加 +相同的 `--profile `。`--yes` 只确认来源变更,不会批准插件权限;发现来源 +也不等同于 trust root。 -需要 Node.js 22 或更新版本。 +Marketplace v3 条目列出已验证的 `0.1.1` artifact 后,安装命令才可用。在此之前, +可从 +[GitHub Release](https://github.com/cordisx/plugin-cli-proxy-api/releases/tag/v0.1.1) +下载压缩包与 `SHA256SUMS`。 -```sh -npm ci -npm run check -npm run dev:dry-run -``` +## 使用 + +在 CordisX 中打开 CLIProxy Providers,选择 Provider 和模型,然后创建会话或打开 +runtime 已上报的会话。可用操作可能包括继续、分叉、归档、恢复、删除、发送、引导 +和中断;插件只显示当前精确请求获准执行的操作。 + +Upstream Subscriptions 页面显示 CLIProxyAPI 账号、状态、模型和已配置的 CordisX +upstream。可在此启动或取消支持的 OAuth 操作。本版本可以管理 CLIProxyAPI 已上报的 +账号,但不能在 CordisX 中新增或导入账号文件。 + +## 配置 + +通过 CordisX 插件配置中的 `providerIds` 限制可见 Provider;留空表示显示全部上报的 +Provider。配置在插件重启后生效。托管 gateway 在 Host 控制下读取包内 YAML 和 JSON +schema。 + +CLIProxyAPI 账号与 endpoint 必须在外部 runtime 中配置。Host 负责解析凭据、启动托管 +进程、持久化配置和维护唯一的 Provider Fleet。插件不会获得原始凭据、文件系统路径、 +进程 handle 或 transport handle。 + +## 权限与限制 + +模型、task 和 turn 能力全部为可选权限。Task 内容、创建、控制、turn 提交与控制都 +限定在精确请求范围内。启用前请检查插件请求的权限。 + +功能可用性取决于兼容的 Host managed-service runtime 和正常工作的 CLIProxyAPI +配置。精确 Provider 或模型不可用时,插件不会静默替换为其他对象。 + +## 排错 -`npm run dev:dry-run` 只验证本地 source graph,不会启动 Codex Desktop。迁移未完成 -期间 package 保持 `private`。 +- **找不到 `0.1.1`:**确认 Marketplace v3 条目已列出验证后的 artifact;`--source` + 不会添加或修复 feed。 +- **没有模型或会话:**确认 CLIProxyAPI 正在运行、账号已启用,并授予模型和 catalog + 读取权限。 +- **账号控制不可用:**在 CordisX 外配置账号,或确认 Host managed service 已开放 + 所需操作。 +- **会话操作被禁用:**授予对应的精确请求权限,并确认所选 Provider 仍上报该会话。 -## 来源与许可证 +## 许可证 -[HISTORY.md](HISTORY.md) 记录原 Host-owned 实现筛选后的 owner 历史。本仓采用 -[AGPL-3.0-or-later](LICENSE) 许可证。 +CLIProxy Providers 使用 [AGPL-3.0-or-later](LICENSE)。来源记录见 +[HISTORY.md](HISTORY.md),第三方声明见 +[THIRD_PARTY_NOTICES.md](THIRD_PARTY_NOTICES.md)。维护者环境、检查和发布步骤见 +[AGENTS.md](AGENTS.md)。 diff --git a/cordisx-package.json b/cordisx-package.json index 59c0d61..5a65647 100644 --- a/cordisx-package.json +++ b/cordisx-package.json @@ -2,7 +2,7 @@ "$schema": "https://raw.githubusercontent.com/cordisx/cordisx-protocol/main/schemas/plugin-package.v14.schema.json", "schemaVersion": 14, "id": "cli-proxy-api", - "version": "0.1.0", + "version": "0.1.1", "entry": "./dist/runtime/module.js", "readme": "./README.md", "canonicalSource": "https://github.com/cordisx/plugin-cli-proxy-api", diff --git a/package-lock.json b/package-lock.json index 280a929..ae7b8ed 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@cordisx/plugin-cli-proxy-api", - "version": "0.1.0", + "version": "0.1.1", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@cordisx/plugin-cli-proxy-api", - "version": "0.1.0", + "version": "0.1.1", "license": "AGPL-3.0-or-later", "devDependencies": { "@cordisx/eslint-config": "github:cordisx/cordisxmono#c63c2e8c2ba7e11502934a52ad2ce3734e804cdc", diff --git a/package.json b/package.json index 985f773..abfd20c 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@cordisx/plugin-cli-proxy-api", - "version": "0.1.0", + "version": "0.1.1", "private": true, "license": "AGPL-3.0-or-later", "description": "CLIProxyAPI provider sessions plugin for CordisX",