Luigit
repositories / smith

smith

There are many coding harnesses - but this one is fast

owned by admin

.system/plans/SMH-PLAN-AIAGD002-provider-and-oauth-plugins/index.md

Raw
Rendered preview

id: SMH-PLAN-AIAGD002 type: plan title: "Provider and OAuth Plugins" spec: SMH-SPEC-PLUG0001 status: draft depends_on: []

Provider and OAuth Plugins

Outcome

Every supported vendor ships as an unprivileged per-family plugin. Users log in with a Z.ai key and with OpenAI, Anthropic, and Google subscriptions; provider-specific code is gone from the core.

Scope

Per-family provider plugins, the shared OAuth plugin, plugin-to-plugin dependencies, and core adapter removal. Host surface and scaffolding come from the harness plan.

Behaviors

Ordered by delivery value.

  1. Z.ai provider plugin: key credential from the auth store, OpenAI-compatible stream behind the plugin boundary; one eval turn runs end to end with the core adapter absent from the dispatch path.
  2. OAuth plugin: device or localhost-redirect flows through net-scope effects; tokens cross the secret-proxy boundary to the auth store; renewal refreshes before dispatch.
  3. Plugin dependency: provider plugins declare a dependency on the OAuth plugin's major-versioned module contract; the harness validates the complete set before publication; missing or ambiguous bindings fail at consumption with sorted candidates.
  4. OpenAI plugin: subscription login via the OAuth plugin plus key support; provider registration advertises models with capabilities.
  5. Anthropic plugin: subscription login plus key support; wire format and model catalog live in the plugin.
  6. Google plugin: subscription login plus key support; same registration path.
  7. Core adapter removal: native vendor decoders and vendor catalogs are deleted; mux routes plugin-registered providers; conformance fixtures validate plugin streams against recorded transcripts.

Login surface

flowchart LR
  U["smith login --provider VENDOR"] --> O{"flow?"}
  O -- key --> K["auth store (stdin secret)"]
  O -- subscription --> P["oauth plugin flow"]
  P --> N["net-scope http"]
  N --> SP["secret-proxy exchange"]
  SP --> S["auth store"]
  K --> R["resolve before dispatch"]
  S --> R

Plan dependencies

flowchart LR
  PLUG["PLUG0001 harness + scaffolding"] --> Z["zai plugin"]
  Z --> OA["oauth plugin"]
  OA --> DEP["plugin dependency validation"]
  DEP --> OAI["openai"]
  DEP --> ANT["anthropic"]
  DEP --> GOO["google"]
  OAI --> RM["remove core adapters"]
  ANT --> RM
  GOO --> RM

Interfaces

  • plugins/provider-zai, plugins/provider-openai, plugins/provider-anthropic, plugins/provider-google.
  • plugins/oauth: exports the credential-source module contract.
  • smith login: vendor login command over key or subscription flows.

Verification

  • Each vendor completes one eval round using only its plugin-registered provider.
  • Subscription credentials renew before expiry without re-login.
  • A provider plugin missing its OAuth dependency fails at consumption with the consumer and candidates named.
  • No native vendor decoder remains; conformance validates each plugin stream against recorded transcripts.
  • Credential plaintext never appears in logs, traces, replay, or plugin diagnostics.
  • Embedded built-in provider artifacts update without a smith rebuild in dev configurations.

Stop conditions

  • A vendor requires an effect absent from the public world.
  • OAuth flows cannot complete without ambient capabilities beyond net-scope and secret-proxy.
  • Plugin dependency validation cannot reject incomplete sets atomically.
---
id: SMH-PLAN-AIAGD002
type: plan
title: "Provider and OAuth Plugins"
spec: SMH-SPEC-PLUG0001
status: draft
depends_on: []
---

# Provider and OAuth Plugins

## Outcome

Every supported vendor ships as an unprivileged per-family plugin.
Users log in with a Z.ai key and with OpenAI, Anthropic, and Google subscriptions; provider-specific code is gone from the core.

## Scope

Per-family provider plugins, the shared OAuth plugin, plugin-to-plugin dependencies, and core adapter removal.
Host surface and scaffolding come from the harness plan.

## Behaviors

Ordered by delivery value.

1. **Z.ai provider plugin**: key credential from the auth store, OpenAI-compatible stream behind the plugin boundary; one eval turn runs end to end with the core adapter absent from the dispatch path.
2. **OAuth plugin**: device or localhost-redirect flows through net-scope effects; tokens cross the secret-proxy boundary to the auth store; renewal refreshes before dispatch.
3. **Plugin dependency**: provider plugins declare a dependency on the OAuth plugin's major-versioned module contract; the harness validates the complete set before publication; missing or ambiguous bindings fail at consumption with sorted candidates.
4. **OpenAI plugin**: subscription login via the OAuth plugin plus key support; provider registration advertises models with capabilities.
5. **Anthropic plugin**: subscription login plus key support; wire format and model catalog live in the plugin.
6. **Google plugin**: subscription login plus key support; same registration path.
7. **Core adapter removal**: native vendor decoders and vendor catalogs are deleted; mux routes plugin-registered providers; conformance fixtures validate plugin streams against recorded transcripts.

## Login surface

```mermaid
flowchart LR
  U["smith login --provider VENDOR"] --> O{"flow?"}
  O -- key --> K["auth store (stdin secret)"]
  O -- subscription --> P["oauth plugin flow"]
  P --> N["net-scope http"]
  N --> SP["secret-proxy exchange"]
  SP --> S["auth store"]
  K --> R["resolve before dispatch"]
  S --> R
```

## Plan dependencies

```mermaid
flowchart LR
  PLUG["PLUG0001 harness + scaffolding"] --> Z["zai plugin"]
  Z --> OA["oauth plugin"]
  OA --> DEP["plugin dependency validation"]
  DEP --> OAI["openai"]
  DEP --> ANT["anthropic"]
  DEP --> GOO["google"]
  OAI --> RM["remove core adapters"]
  ANT --> RM
  GOO --> RM
```

## Interfaces

- `plugins/provider-zai`, `plugins/provider-openai`, `plugins/provider-anthropic`, `plugins/provider-google`.
- `plugins/oauth`: exports the credential-source module contract.
- `smith login`: vendor login command over key or subscription flows.

## Verification

- Each vendor completes one eval round using only its plugin-registered provider.
- Subscription credentials renew before expiry without re-login.
- A provider plugin missing its OAuth dependency fails at consumption with the consumer and candidates named.
- No native vendor decoder remains; conformance validates each plugin stream against recorded transcripts.
- Credential plaintext never appears in logs, traces, replay, or plugin diagnostics.
- Embedded built-in provider artifacts update without a smith rebuild in dev configurations.

## Stop conditions

- A vendor requires an effect absent from the public world.
- OAuth flows cannot complete without ambient capabilities beyond net-scope and secret-proxy.
- Plugin dependency validation cannot reject incomplete sets atomically.