feat(kiro): headless API-key auth + direct Claude/Kiro route
Adds long-lived API-key (ksk_) authentication for Kiro/AWS CodeWhisperer and a direct claude:kiro / kiro:claude translation route that avoids the lossy OpenAI two-hop pivot. - translator: claude-to-kiro request + kiro-to-claude response translators, registered on the exact source:target pair (direct route ahead of the OpenAI pivot in index.js). claude-to-kiro uses shared schema constants (ROLE/CLAUDE_BLOCK/DEFAULT_IMAGE_MIME) per app convention. - auth: POST /api/oauth/kiro/api-key imports + validates a key via ListAvailableProfiles, persists authMethod="api_key" (no refresh token). - executor: send tokentype: API_KEY header and try *.amazonaws.com hosts first for api-key creds; OAuth keeps kiro.dev first. - fix: never inject the default placeholder profileArn for api-key auth (CodeWhisperer 403s an ARN not owned by the key's account). - ui: API Key method in the Kiro connect modal; surface api-key accounts on the Quota Tracker and provider count. - stream: env-overridable TTFT vs stall timeouts + Kiro keepalive frame. - tests: claude-kiro-direct + kiro-profile-arn (11 tests). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -524,8 +524,16 @@ export function openaiToKiroRequest(model, body, stream, credentials) {
|
||||
|
||||
const { history, currentMessage } = convertMessages(messages, tools, upstreamModel);
|
||||
|
||||
const profileArn = credentials?.providerSpecificData?.profileArn
|
||||
|| resolveDefaultProfileArn(credentials?.providerSpecificData?.authMethod);
|
||||
// API-key (headless) auth uses a raw CodeWhisperer credential whose profile is
|
||||
// account-specific. Injecting the shared builder-id/social *default* placeholder
|
||||
// ARN makes CodeWhisperer reject the request with 403 "bearer token invalid"
|
||||
// (the ARN doesn't belong to the key's account). So for api_key, only send a
|
||||
// profileArn that was actually resolved for this connection — never the default.
|
||||
// OAuth/social keep the default fallback (their tokens accept it).
|
||||
const authMethod = credentials?.providerSpecificData?.authMethod;
|
||||
const profileArn = authMethod === "api_key"
|
||||
? (credentials?.providerSpecificData?.profileArn || "")
|
||||
: (credentials?.providerSpecificData?.profileArn || resolveDefaultProfileArn(authMethod));
|
||||
|
||||
let finalContent = currentMessage?.userInputMessage?.content || "";
|
||||
|
||||
|
||||
Reference in New Issue
Block a user