Skip to content

Add Command Code backend and caller-supplied endpoints; release 0.8.0 - #20

Merged
DevMortimer merged 3 commits into
mainfrom
carvel/deckhand-b/configurable-backend
Sep 28, 2026
Merged

DevMortimer merged 3 commits into
mainfrom
carvel/deckhand-b/configurable-backend

Conversation

@DevMortimer

Copy link
Copy Markdown
Owner

What changed

  • New commandcode backend: judgments go to api.commandcode.ai under /provider/v1/systemone with the model typesafe/jev and the key from COMMANDCODE_API_KEY; its public model list does not verify a key.
  • backend now accepts a caller-supplied endpoint object (BackendEndpoint) wherever a backend name is accepted (createTypeSafe, keySituation, resolveApiKey, authState, ensureApiKey, safeError). An endpoint names its own label, host, keyEnv, and optionally path, defaultModel, and model-list fields; it is validated on every call and never added to the registry.
  • New exports resolveBackend(nameOrEndpoint) and backendHost(nameOrEndpoint), plus the BackendEndpoint, BackendSpec, and ResolvedBackend types. TypeSafeBackend gains "commandcode", which a consumer with an exhaustive switch will see as a new member.
  • Documentation and changelog updated; release 0.8.0.

Why

DevMortimer/pi-warden#134 needs to pass a user-configured endpoint to this package and name the real destination host in its consent text. The same Jev decisions protocol is served by more hosts than the two hardcoded ones. This is about which host serves Jev; it is not a different model or protocol.

Key isolation

A registry backend other than typesafe, and every endpoint object, reads only its own keyEnv environment variable. It never reads TYPESAFE_API_KEY or the login store, and a keyEnv of TYPESAFE_API_KEY is refused — a TypeSafe key can no longer travel to another host. The auth record is still one file shared by every backend.

How it was verified

  • npm run check on the base commit: build and typecheck pass, tests 104 pass / 0 fail. On this branch: build and typecheck pass, tests 133 pass / 0 fail.
  • New offline tests (injected transport, fake keys) cover the Command Code request, endpoint objects and the loopback http: case, every validation refusal, key isolation, non-verifying model lists, malformed replies, 401 advice, and the new helpers.
  • npm run test:live was not run: it needs a paid key.

The same Jev decisions protocol is served by more hosts than the two
registry names. `backend` now also accepts a validated BackendEndpoint
object everywhere a backend name is accepted, resolved through the new
resolveBackend() and backendHost() exports, and the registry gains a
`commandcode` entry that sends to api.commandcode.ai with the model
typesafe/jev and the key from COMMANDCODE_API_KEY.

Key isolation is the invariant: a registry backend other than typesafe,
and every endpoint object, reads only its own keyEnv variable and never
TYPESAFE_API_KEY or the login store, so a TypeSafe key can no longer
travel to another host. A public model list (commandcode, OpenRouter,
or an endpoint without modelsVerifyKey: true) never records
verification.
@DevMortimer
DevMortimer marked this pull request as ready for review September 28, 2026 03:28
Both resolve the backend they are given, so an unknown name or an
endpoint object that fails validation throws the same configuration
error as resolveBackend instead of producing a status. The docs said
they never throw; they now say that holds for a valid backend and
point callers at resolveBackend for user-supplied endpoints.
@DevMortimer
DevMortimer marked this pull request as draft September 28, 2026 03:35
@DevMortimer
DevMortimer marked this pull request as ready for review September 28, 2026 03:38
@DevMortimer
DevMortimer merged commit ed439f8 into main Sep 28, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant