feat(kiro): headless API-key auth + direct Claude/Kiro route
Adds long-lived API-key (ksk_) authentication for Kiro/AWS CodeWhisperer and a direct claude:kiro / kiro:claude translation route that avoids the lossy OpenAI two-hop pivot. - translator: claude-to-kiro request + kiro-to-claude response translators, registered on the exact source:target pair (direct route ahead of the OpenAI pivot in index.js). claude-to-kiro uses shared schema constants (ROLE/CLAUDE_BLOCK/DEFAULT_IMAGE_MIME) per app convention. - auth: POST /api/oauth/kiro/api-key imports + validates a key via ListAvailableProfiles, persists authMethod="api_key" (no refresh token). - executor: send tokentype: API_KEY header and try *.amazonaws.com hosts first for api-key creds; OAuth keeps kiro.dev first. - fix: never inject the default placeholder profileArn for api-key auth (CodeWhisperer 403s an ARN not owned by the key's account). - ui: API Key method in the Kiro connect modal; surface api-key accounts on the Quota Tracker and provider count. - stream: env-overridable TTFT vs stall timeouts + Kiro keepalive frame. - tests: claude-kiro-direct + kiro-profile-arn (11 tests). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -76,21 +76,29 @@ export function translateRequest(sourceFormat, targetFormat, model, body, stream
|
||||
|
||||
// If same format, skip translation steps
|
||||
if (sourceFormat !== targetFormat) {
|
||||
// Step 1: source -> openai (if source is not openai)
|
||||
if (sourceFormat !== FORMATS.OPENAI) {
|
||||
const toOpenAI = requestRegistry.get(`${sourceFormat}:${FORMATS.OPENAI}`);
|
||||
if (toOpenAI) {
|
||||
result = toOpenAI(model, result, stream, credentials);
|
||||
// Log OpenAI intermediate format
|
||||
reqLogger?.logOpenAIRequest?.(result);
|
||||
// Direct route: if a translator is registered for this exact source:target
|
||||
// pair, use it instead of pivoting through OpenAI. This is lossless for
|
||||
// pairs like claude:kiro (avoids the claude->openai->kiro double-hop).
|
||||
const directFn = requestRegistry.get(`${sourceFormat}:${targetFormat}`);
|
||||
if (directFn) {
|
||||
result = directFn(model, result, stream, credentials);
|
||||
} else {
|
||||
// Step 1: source -> openai (if source is not openai)
|
||||
if (sourceFormat !== FORMATS.OPENAI) {
|
||||
const toOpenAI = requestRegistry.get(`${sourceFormat}:${FORMATS.OPENAI}`);
|
||||
if (toOpenAI) {
|
||||
result = toOpenAI(model, result, stream, credentials);
|
||||
// Log OpenAI intermediate format
|
||||
reqLogger?.logOpenAIRequest?.(result);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Step 2: openai -> target (if target is not openai)
|
||||
if (targetFormat !== FORMATS.OPENAI) {
|
||||
const fromOpenAI = requestRegistry.get(`${FORMATS.OPENAI}:${targetFormat}`);
|
||||
if (fromOpenAI) {
|
||||
result = fromOpenAI(model, result, stream, credentials);
|
||||
// Step 2: openai -> target (if target is not openai)
|
||||
if (targetFormat !== FORMATS.OPENAI) {
|
||||
const fromOpenAI = requestRegistry.get(`${FORMATS.OPENAI}:${targetFormat}`);
|
||||
if (fromOpenAI) {
|
||||
result = fromOpenAI(model, result, stream, credentials);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -146,6 +154,16 @@ export function translateResponse(targetFormat, sourceFormat, chunk, state) {
|
||||
let results = [chunk];
|
||||
let openaiResults = null; // Store OpenAI intermediate results
|
||||
|
||||
// Direct route: if a response translator is registered for this exact
|
||||
// target:source pair, use it instead of pivoting through OpenAI. Mirrors the
|
||||
// request-side direct route (e.g. kiro:claude — KiroExecutor already emits
|
||||
// OpenAI-shaped chunks, so this converts them straight to Claude SSE).
|
||||
const directFn = responseRegistry.get(`${targetFormat}:${sourceFormat}`);
|
||||
if (directFn) {
|
||||
const converted = directFn(chunk, state);
|
||||
return converted ? (Array.isArray(converted) ? converted : [converted]) : [];
|
||||
}
|
||||
|
||||
// Step 1: target -> openai (if target is not openai)
|
||||
if (targetFormat !== FORMATS.OPENAI) {
|
||||
const toOpenAI = responseRegistry.get(`${targetFormat}:${FORMATS.OPENAI}`);
|
||||
@@ -251,6 +269,7 @@ import "./request/openai-to-kiro.js";
|
||||
import "./request/openai-to-cursor.js";
|
||||
import "./request/openai-to-ollama.js";
|
||||
import "./request/openai-to-commandcode.js";
|
||||
import "./request/claude-to-kiro.js";
|
||||
import "./response/claude-to-openai.js";
|
||||
import "./response/openai-to-claude.js";
|
||||
import "./response/gemini-to-openai.js";
|
||||
@@ -260,3 +279,4 @@ import "./response/kiro-to-openai.js";
|
||||
import "./response/cursor-to-openai.js";
|
||||
import "./response/ollama-to-openai.js";
|
||||
import "./response/commandcode-to-openai.js";
|
||||
import "./response/kiro-to-claude.js";
|
||||
|
||||
Reference in New Issue
Block a user