Adds pt-... token auth as an alternative to OAuth device flow. A PAT can't sign COSY requests directly, so it's exchanged for a short-lived job token (jt-...) plus userId via openapi.qoder.sh, then used for signing. Also fixes job-token traffic (jt-...) being rejected by api3.qoder.sh with 403 "Login expired" — the official qodercli serves jt- traffic from api2.qoder.sh instead, so buildUrl/model-list routing now branches on it. Quota usage and the dashboard add-key modal are updated to resolve PAT credentials and label the field correctly, and bulk-add now validates each key so it gets a real testStatus instead of a hardcoded "unknown".
3.2 KiB
3.2 KiB