Skip to content

Salvage: OpenRouter attribution headers and honest --mobile help - #6609

Merged
Hmbown merged 3 commits into
mainfrom
salv/openrouter-attribution-mobile-help
Sep 26, 2026
Merged

Hmbown merged 3 commits into
mainfrom
salv/openrouter-attribution-mobile-help

Conversation

@Hmbown

@Hmbown Hmbown commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Salvages two small pieces from the closed tui-redesign branch (#6222).

OpenRouter attribution (8299b3e4, clean cherry-pick). OpenRouter routes now send X-OpenRouter-Title: Codewhale next to the legacy X-Title, plus X-OpenRouter-Categories: cli-agent,personal-agent. HTTP-Referer is unchanged. Other providers get none of these headers, and a user-configured header with the same name still wins.

Accurate --mobile help (296fc88c + 98f290d6, help and docs only). The CLI help said --mobile binds 0.0.0.0. The code does the opposite: resolve_serve_bind_host defaults to 127.0.0.1 and ignores mobile, and runtime_api rejects a non-loopback mobile bind. This PR fixes the help, the --host doc comment, a stale test comment, and docs/rfcs/REMOTE_SETUP_DESIGN.md. The 0.0.0.0 literals left in crates/cli/src/lib.rs belong to a parse test of an explicit app-server --host 0.0.0.0 without --mobile, which is still correct.

deny.toml: the windows-* skips are now pinned to the versions cargo-deny actually sees, so a new duplicate gets flagged. The 0.42.x pins from the original commit are left out because they show up as unmatched skips on this tree.

Not ported:

Verification:

  • scripts/dev-cargo.sh test -p codewhale-tui --lib openrouter_routes_carry_app_attribution: 1 passed, 0 failed
  • scripts/dev-cargo.sh test -p codewhale-cli --lib: 405 passed, 0 failed
  • target/debug/codewhale app-server --help: prints the loopback-only text and no 0.0.0.0
  • cargo deny check bans: bans ok, with the same warning set before and after
  • blocking-calls, dead-code, command-crate-boundaries, module_graph --check, and cargo fmt --check all pass

No-Issue: salvage of closed PR #6222 (triage packet SALV-1); no tracking issue exists.

🤖 Generated with Claude Code

CodeWhale Bot and others added 2 commits September 25, 2026 22:36
Salvaged from the closed tui-redesign branch (PR #6222), commit 8299b3e4,
which applies cleanly to main.

We already sent `HTTP-Referer` and `X-Title`. `X-OpenRouter-Title` is the
header OpenRouter documents today; `X-Title` is kept for backwards
compatibility with OpenRouter-compatible gateways behind a base-URL override.
`X-OpenRouter-Categories` was not sent at all; it now claims
`cli-agent,personal-agent` (max two per request; unrecognised values are
dropped silently, so the test pins the exact strings). `HTTP-Referer` stays
`https://codewhale.net`, the app's identifier.

The four-category rotation from fa4911d7 is not ported (it conflicts with
main and is optional).

  CARGO_BUILD_JOBS=4 scripts/dev-cargo.sh test -p codewhale-tui --lib \
    openrouter_routes_carry_app_attribution   1 passed, 0 failed

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Salvaged from the closed tui-redesign branch (PR #6222), commits 296fc88c
and 98f290d6. The constant-time compare part of 296fc88c is dropped; #6601
covers it.

--mobile help: `codewhale app-server --help` and the forwarded serve options
claimed "--mobile defaults to 0.0.0.0" / "(binds 0.0.0.0)" and that --mobile
with no host binds 0.0.0.0 for LAN access. The code does the opposite:
`resolve_serve_bind_host` (crates/tui/src/lib.rs) ignores `mobile` and
defaults to 127.0.0.1, and runtime_api.rs rejects a non-loopback mobile bind.
The help, the `--host` doc comment, a stale test comment, and the same claim
in docs/rfcs/REMOTE_SETUP_DESIGN.md now say what the code does. The remaining
0.0.0.0 literals in crates/cli/src/lib.rs are a parse test of an explicit
`app-server --host 0.0.0.0` (mobile: false), which is still valid.

deny.toml: the windows-* family was skipped unpinned, so any new duplicate
passed silently. Now pinned to the versions cargo-deny actually encounters.
The 0.42.x pins from the original commit are omitted: cargo-deny reports them
as unmatched skips on this tree.

  CARGO_BUILD_JOBS=4 scripts/dev-cargo.sh test -p codewhale-cli --lib
    405 passed, 0 failed
  target/debug/codewhale app-server --help   no 0.0.0.0; says loopback-only
  cargo deny check bans   bans ok; warning set identical before/after
  check-blocking-calls-budget, check-dead-code-budget,
  check-command-crate-boundaries, split/module_graph.py --check,
  cargo fmt --all -- --check   all pass

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Hmbown Hmbown added this to the v0.10.1 milestone Sep 26, 2026
Copilot AI lite review requested due to automatic review settings September 26, 2026 05:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

A user who set only the legacy `X-Title` in extra headers kept
`X-OpenRouter-Title: Codewhale` on the request, so OpenRouter (which
prefers the current header) would still show "Codewhale" rather than
their name. Resolve one title up front -- user's X-OpenRouter-Title,
else user's X-Title, else "Codewhale" -- and send it on both headers.

The override test now asserts both headers follow a user title set on
either name, and non-OpenRouter routes get no x-openrouter-title.

Tests: scripts/dev-cargo.sh test -p codewhale-tui --lib client::tests::
212 passed, 0 failed. cargo fmt --check, blocking-calls, dead-code,
command-crate-boundaries and module_graph --check all pass.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Hmbown
Hmbown merged commit bb6548a into main Sep 26, 2026
35 checks passed
@Hmbown
Hmbown deleted the salv/openrouter-attribution-mobile-help branch September 26, 2026 09:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants