feat(xiaomi-mimo): merge MiMo Desktop support into xiaomi-mimo as dual auth
Adds the Desktop-exclusive Preview models and the Xiaomi account-session
route to the existing xiaomi-mimo provider instead of a separate
xiaomi-desktop provider, so the dashboard shows one MiMo entry rather than
three overlapping ones.
Dual auth, same pattern as kimi — API key (sk-) covers the cloud API,
Desktop/OAuth adds the account session used by the Preview models:
- registry: category oauth, authModes [oauth, apikey], oauth block, the two
mimo-x-*-preview models, and the invite signupUrl
- executor: routes Preview models to the account-service route with a Cookie
session, everything else keeps the sourceFormat-matched transport
- oauth: custom ECDH encrypted-callback flow (X25519 -> SHA256 -> AES-256-GCM)
with a loopback callback proxy, plus one-click import of the local Desktop
auth.json
- usage: weekly quota from the account session
Fixes found while merging:
- the OAuth browser flow was dead: poll-status cleared the session before the
client could POST /exchange, so every exchange returned 400
- a Claude-format client was sent to /v1/chat/completions instead of the
declared /anthropic/v1/messages transport, because buildUrl ignored
runtimeTransport
- stopXiaomiMimoProxy leaked every pending session (each holding an X25519
private key) for the process lifetime
- the OAuth exchange did not persist the Desktop passToken, so the Preview
models could never work after a browser sign-in
Removes dead code: the local engine token minting (mimoEngine, never called
on the request path), the model-catalog and usage routes, engineToken/
engineUrl plumbing, and an unread top-level usage block.
Adds tests/unit/xiaomi-mimo-{executor,oauth-session,oauth-proxy}.test.js —
the provider previously had none.
This commit is contained in:
@@ -1,11 +1,19 @@
|
||||
import { CLAUDE_API_HEADERS } from "../shared.js";
|
||||
|
||||
// Dual auth (same pattern as kimi):
|
||||
// - API key (sk-...) → cloud API on api.xiaomimimo.com
|
||||
// - Desktop account/OAuth → same cloud host, plus the Desktop-exclusive Preview
|
||||
// models served by the account-service route on mimo-server-cn.xiaomimimo.com
|
||||
// (authorized by a Xiaomi account session cookie, not the key).
|
||||
// Endpoint is picked per model in the executor, same as opencode-go's /responses split.
|
||||
export default {
|
||||
id: "xiaomi-mimo",
|
||||
priority: 290,
|
||||
alias: "xiaomi-mimo",
|
||||
aliases: [
|
||||
"mimo",
|
||||
"mimo-desktop",
|
||||
"xmd",
|
||||
],
|
||||
uiAlias: "mimo",
|
||||
display: {
|
||||
@@ -16,9 +24,12 @@ export default {
|
||||
website: "https://xiaomimimo.com",
|
||||
notice: {
|
||||
apiKeyUrl: "https://platform.xiaomimimo.com/console/api-keys",
|
||||
signupUrl: "https://mimo.xiaomimimo.com/desktop/invite/",
|
||||
},
|
||||
},
|
||||
category: "apikey",
|
||||
category: "oauth",
|
||||
authModes: ["oauth", "apikey"],
|
||||
hasOAuth: true,
|
||||
serviceKinds: ["llm", "tts"],
|
||||
transport: {
|
||||
baseUrl: "https://api.xiaomimimo.com/v1/chat/completions",
|
||||
@@ -39,6 +50,11 @@ export default {
|
||||
},
|
||||
],
|
||||
models: [
|
||||
// Desktop-exclusive — served by the account-service route, which only accepts
|
||||
// OpenAI format, so supportedFormats pins them to the openai transport.
|
||||
{ id: "mimo-x-pro-preview", name: "MiMo-X-Pro-Preview", upstreamModelId: "xiaomi/mimo-x-pro-preview", supportedFormats: ["openai"] },
|
||||
{ id: "mimo-x-flash-preview", name: "MiMo-X-Flash-Preview", upstreamModelId: "xiaomi/mimo-x-flash-preview", supportedFormats: ["openai"] },
|
||||
// Cloud API models (api.xiaomimimo.com/v1)
|
||||
{ id: "mimo-v2.5-pro", name: "MiMo V2.5 Pro" },
|
||||
{ id: "mimo-v2.5", name: "MiMo V2.5" },
|
||||
{ id: "mimo-v2-omni", name: "MiMo V2 Omni" },
|
||||
@@ -51,4 +67,18 @@ export default {
|
||||
authHeader: "bearer",
|
||||
format: "xiaomi-mimo-tts",
|
||||
},
|
||||
features: {
|
||||
usage: true,
|
||||
usageApikey: true,
|
||||
},
|
||||
// Custom OAuth — non-standard ECDH encrypted-callback flow.
|
||||
// Handled by the Xiaomi MiMo OAuth service, not the generic PKCE pipeline.
|
||||
oauth: {
|
||||
custom: true,
|
||||
authorizeUrl: "https://platform.xiaomimimo.com/authorize",
|
||||
// The callback carries ?u=<ECDH-encrypted payload> instead of ?code=.
|
||||
// Decryption yields { uid, sk, url }.
|
||||
callbackParam: "u",
|
||||
kn: "mimocode",
|
||||
},
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user