feat(web): mount the config plane in dsh web and pin the Models page keyless

apps/cli/cordis.yml gains settings-local, credentials-local, and the bare
dormant llm-pi-ai row (manifest deps added for the resolver contract);
llm-deepseek drops its !!js apiKey inline for per-request credential
resolution. Both adapters tag apiKeyEnv role('credential-ref') so the
form mounts the credential control. The web e2e scaffold isolates a
harness home per run — an in-process boot must never touch the
developer's real ~/.dsh — and the new models-settings scenario pins the
whole loop through the shipped app: dormant directory as add vocabulary,
schema-driven editor apply landing in settings.yaml, the route
registering live (topology frame), and a write-only key landing in the
temp .env with the configured badge converging. A hermetic test-owned
reference name keeps a developer's real provider keys from flipping the
badge. schema-form joins the platform module table (seed + externals)
so client bundles share one instance.
This commit is contained in:
Yichen Jiang
2026-07-30 09:29:40 +08:00
parent 686e40ebf6
commit 0d96676f35
19 changed files with 347 additions and 36 deletions

View File

@@ -76,7 +76,7 @@ const catalogModel: z<DeepSeekCatalogModel> = z.object({
export const Config: z<Config> = z.object({
apiKey: z.string().role('secret'),
apiKeyEnv: z.string().default(DEFAULT_API_KEY_ENV),
apiKeyEnv: z.string().role('credential-ref').default(DEFAULT_API_KEY_ENV),
baseURL: z.string(),
thinking: z.union(['enabled', 'disabled']),
reasoningEffort: z.union(['off', 'high', 'max']),

View File

@@ -77,7 +77,7 @@ const thinkingBudgets = z.object({
const profile = z.object({
apiKey: z.string().role('secret'),
apiKeyEnv: z.string(),
apiKeyEnv: z.string().role('credential-ref'),
baseURL: z.string(),
headers: z.dict(z.string()),
reasoning: z.union(['off', 'minimal', 'low', 'medium', 'high', 'xhigh', 'max']),