Skip to content

feat(web): add Pi-native provider setup, reasoning controls, and OpenPI settings #348

Description

@sowen1023

Parent

Problem

The Web model picker can select an already available provider/model pair, but the browser cannot:

  • inspect provider authentication availability without leaking credentials;
  • start or complete a supported Pi-native provider login flow;
  • view or set the current thinking/reasoning level;
  • enter the canonical OpenPI setup episode;
  • inspect package setup status or runtime provenance.

Users must leave the Web workbench to understand or change these settings, and unavailable models provide limited recovery guidance.

Value

  • Make model configuration usable from the browser while keeping Pi authoritative.
  • Preserve the single OpenPI setup entry point and typed persistence boundary.
  • Give users enough provenance to diagnose which runtime/configuration they are operating.

Approach constraints

  • Pi remains the source of truth for provider credentials, available models, and reasoning state.
  • Credentials, tokens, and secrets must never enter snapshots, SSE events, browser storage, or logs.
  • Model and reasoning changes bind to the expected Session and return exact accepted/stale/failed receipts.
  • OpenPI configuration must continue through the canonical /openpi-setup episode and episode-scoped typed writer.
  • Do not add a browser parser, direct preference-file writes, or an extension-specific setup command.
  • Package-owned settings must keep setup config, status output, SETUP.md, README defaults, and tests synchronized.
  • Authentication UI must use a reviewed Pi/provider seam; unsupported providers get explicit external instructions.

Acceptance criteria

  • Web reports bounded provider/model availability and authentication status without secret material.
  • Supported provider login uses Pi-owned authentication and reports success, denial, expiry, and failure.
  • Users can inspect and change the thinking/reasoning level supported by the selected model.
  • Model plus reasoning updates are atomic for the expected active Session.
  • Web exposes the canonical /openpi-setup flow rather than a second configuration path.
  • No-argument setup status and Web status agree on package-owned values.
  • A read-only diagnostics view shows OpenPI version, checkout/package source, Pi version, active Session source, and relevant bounded capability provenance.
  • Reconnect cannot repeat a login or configuration write.
  • Tests prove secrets never enter serialized protocol state.
  • Setup/config documentation and drift guards are updated.
  • bun run check and bun run test pass.

Related work

Out of scope

  • A second provider stack.
  • Browser-managed credential storage.
  • Hardcoded default providers or models.

Activity

  1. testikun commented on Sep 4, 2026

    @testikun
    Collaborator

    I am taking a focused read-only provider authentication availability slice. I will project provider ids/names, supported Pi-owned auth methods, configured/unconfigured state, and a bounded non-secret source category from ModelRuntime, then expose it through an authenticated endpoint. Credentials, tokens, environment values, and login/logout writes remain outside the response. This is distinct from #367 runtime diagnostics and #375 thinking-state inspection; provider login and UI remain follow-ups. No UI changes are planned, so a real-browser screenshot is not applicable to this slice.

  2. tt-a1i commented on Sep 8, 2026

    @tt-a1i
    Collaborator

    补充本 Issue 的一个具体断点:Web 的无参 /openpi-setup 引导会在询问偏好后关闭 episode,用户下一轮回答时已经没有配置 writer。

    检查日期:2026-09-08;OpenPI 固定源码:ed9dbc1018f890fd54375f5371990ddfee8af5df。

    路径如下:

    1. 用户在 Web 输入不带参数的 /openpi-setup,希望逐项选择初始设置或修改类别。
    2. setup prompt 要求解释当前配置并通过 ask_user 收集选择。
    3. Web extensions 没有 UI context,所以 ask_user 不展示问题,返回 “Ask the user in plain text instead”。
    4. 模型按此提示发出文字问题、结束回合等待用户回答时,agent_settled handler 立即隐藏 writer 并追加持久关闭回执。
    5. 用户下一轮回复想改什么时,episode 已结束;关闭说明 要求重新执行 /openpi-setup <request>。

    两个机制各自合理,但组合后,交互引导无法沿普通文字问答自然完成。浏览器的 配置面板又直接提示使用 /openpi-setup,用户容易反复进入同一流程。

    证据边界:这是固定源码的静态生命周期分析,没有执行真实模型、Pi 或 Web 配置变更,也没有观测到用户偏好被错误写入。不代表所有 Web setup 都失败:带有足够信息的定向请求,例如 /openpi-setup Web 使用深色主题,可能在一个 episode 内直接成功。

    现有单次写入、writer 来源校验和明确重新进入的授权边界应保留。建议优先验收下面的具体配置路径,而不是只增加一个设置入口:

    • Web 无参 setup 能完成“展示当前设置 → 选择类别/偏好 → 明确提交 → 一次写入”,无需复制另一条 slash 命令重启。
    • 首选复用可在同一 episode 内等待答复的原生 UI seam;如暂不支持,进入前给出明确限制与完整定向请求入口。
    • 未回答、取消、断线、过期或切换 Session 时不推断用户选择,也不自动写配置。
    • 原有一次成功 apply 后隐藏 writer、普通回合无法重新调用 writer、来源不匹配 fail closed 的边界保持。
    • 对照测试证明信息完整的定向一轮 setup 仍可成功,避免将交互缺口误写成整个功能不可用。

    相关 #39 讨论模型提议 setup 的确认入口;这里讨论的是用户已经进入 setup 后,Web 问答与 episode 收尾之间的断裂。

  3. Matt-qwq commented on Sep 10, 2026

    @Matt-qwq
    Contributor

    Planning a PR that completes the change thinking/reasoning-level half of this issue: a Pi-native runtime setter, a lease-sensitive POST /api/thinking, a bounded optional thinking projection with a monotonic revision, and an icon-only composer picker beside the model picker.

    It continues the read-only GET /api/thinking inspection landed via #375/#444 and preserves its unknown fallback. Levels come from Pi's getAvailableThinkingLevels()/supportsThinking(); session-only, so no persisted config and no second config source (no extensions/setup/, setup-config.ts, SETUP.md, or README default changes). Validation includes a hermetic browser e2e proving the selected level reaches the next provider request as reasoning_effort.

    Will link this as Related (not Closes), since provider login, the /openpi-setup Web flow, and diagnostics remain open here.

  4. Matt-qwq commented on Sep 10, 2026

    @Matt-qwq
    Contributor

    Opened #531 for the change thinking/reasoning-level half described above (setter + composer picker; Related, not Closes).

  5. testikun commented on Sep 17, 2026

    @testikun
    Collaborator

    我想认领 #348 的 Pi-native Provider 登录切片,请维护者确认是否已有并行实现。基于已有的只读 auth-status 投影与 Pi/provider 原生登录 seam,仅对明确支持的 provider 提供控制者发起、精确 Session/epoch 绑定的一次登录交互和成功/拒绝/过期/失败回执;不支持的 provider 给出外部操作指引。凭据、token 和 callback 值不得进入 snapshot、SSE、浏览器存储或日志;不改 Pi 凭据来源、不重做已合入的 thinking selector (#531)、也不把 /openpi-setup 变成第二配置入口。实现前核对最新 Pi API,测试覆盖秘密不外泄和断线重连;本切片不关闭整个 Issue。

  6. testikun commented on Sep 17, 2026

    @testikun
    Collaborator

    技术方案(研究/提案,尚未实现;依赖 #549 的 Web 控制者身份,不抢 #531 的 thinking 控件):

    Pi 0.85.1 的 ModelRuntime.login(providerId, type, AuthInteraction) 是唯一写凭据的入口。AuthInteraction.notify 可能交付 auth_url(含 OAuth state)、device_code、info、progress;prompt 可要求 text/secret/select/manual_code,并有每次 prompt 的 AbortSignal。Models.login 在 provider login 之后还会修改凭据存储;若此时取消/切会话,不能仅凭 HTTP 超时宣称“未写入”。

    1. 仅提供 provider 明确实现的登录方法。沿现有只读 auth-status 补一项有界 login capability;ambient-only API key 不伪装为可登录。模型选择/思考设置、/openpi-setup 与 Trust 都不并入本切片。
    2. 登录 start 精确绑定 canonical workspace、Session、runtime generation、provider/method、一次性 loginId 和发起标签的控制者 ID;同一 Session 同时只运行有界数量的登录操作。Host 的 start/answer/cancel 均验证原控制者与当前代际,重复 start 不重复调用 Pi。切换 Session/Host shutdown 先请求 abort,再等待 Pi 的持久化结果或返回 uncertain,不能推断未写入。
    3. SSE/普通 snapshot 仅播报无私有内容的 login_changed;授权 URL、device code、prompt 描述/选项仅由控制者鉴权的 private GET 读取(严格长度/URL scheme 上限),绝不进入日志/普通快照/SSE。secret/manual_code/text 仅通过明确的 POST 答复,浏览器内存中短暂持有,禁止 localStorage/sessionStorage 持久化、URL 查询参数或日志;对不支持的交互类型 fail closed。
    4. 回执区分 accepted、awaiting-input、success、denied/cancelled、expired、failed、uncertain、stale/already-settled;刷新同一标签只恢复 canonical in-memory operation,不重播 Pi login 或秘密答复。成功后从 Pi auth-status 重新投影,不回传 Credential/token/callback 值。
    5. 测试使用 fake provider 覆盖 OAuth URL/设备码、密钥 prompt、取消/超时/写入竞态、跨控制者/跨 Session、断线重连和 Host 停止;对序列化 snapshot/SSE/日志做秘密标记断言,再用真实浏览器验证交互与可访问性。

    这仍需结合 #549 合并/审查结论确认控制者合同。暂不提交一个和它重复身份实现的独立 main-base PR;这里是可复核的设计边界,不是已验收结果。

  7. testikun commented on Sep 17, 2026

    @testikun
    Collaborator

    Pi-native Provider 登录切片已实现并提交堆叠草稿 PR:https://github.com/testikun/openpi/pull/1(commit 608b698)。该 PR 以 #549 的控制者身份分支为基底,仅含 #348 的增量;#549 尚待上游评审/合并,因此暂不提交包含重复 #343 改动的 main-base PR。待 #549 合并后再开干净的上游 PR,并继续保持本 Issue 其它验收范围开放。

    验证:bun run check 通过;bun run test Node 1669 通过、1 项平台跳过、Vitest 220/220;Chrome Provider 面板/刷新恢复用例通过。全套 Chrome 34/35,原有移动侧栏 Escape/焦点用例在全套中超时,独立复跑 1/1 通过。未使用真实生产凭据或执行现场 OAuth 交换。实现遵循本 Issue 上方技术方案:Pi 原生 ModelRuntime.login() 独占凭据写入,私有控制者交互与无载荷 SSE,取消/超时后的持久化不确定性显式保留。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions