Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
60 changes: 60 additions & 0 deletions .coderabbit.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
# CodeRabbit configuration
# Docs: https://docs.coderabbit.ai/getting-started/configure-coderabbit-overview
language: "en-GB"
early_access: false

reviews:
profile: "assertive"
request_changes_workflow: false
high_level_summary: true
poem: false
review_status: true
commit_status: true
collapse_walkthrough: false
auto_review:
enabled: true
drafts: false
path_instructions:
- path: "converter.py"
instructions: |
Review with thermo-nuclear standards: implementation quality, abstraction quality and codebase health, not just local nits. Prioritise in this order: structural regressions, missed dramatic simplifications ("code judo" reframings that delete whole branches or layers), spaghetti/branching growth, boundary and type-contract problems, file-size and decomposition, modularity, legibility.

This file is the whole proxy and sits near the 1000-line threshold. Flag any change that pushes it past 1000 lines, and ask whether the code should be decomposed into modules first.

Flag: ad-hoc conditionals bolted onto unrelated flows, one-off flags that complicate control flow, feature logic leaking into shared paths, thin wrappers that add indirection without clarity, unnecessary casts or Optional plumbing, duplicated logic where a canonical helper exists, unnecessary sequential orchestration or non-atomic updates.

Domain-specific checks:
- Credential handling must not put secrets in argv, log output, error responses, or crash output. Any change that touches key or token resolution gets this check explicitly.
- The translation layer between the OpenAI request shape and the upstream shape must preserve exact wire semantics. A change described as a refactor that alters a verb, a header, a field name, or a streaming frame boundary is not a refactor.
- Streaming reassembly and tool_calls mapping are the highest-risk paths. Confirm a change there has a test that exercises partial frames and out-of-order chunks, not only the happy path.
- Error handling must sit at the layer that owns the invariant. A widened except clause that swallows a domain error one layer too deep is a defect even when it makes a test pass.

A test suite that has never been observed failing is not a safety net. Where a change relies on existing tests for behaviour preservation, ask whether those tests were seen red against the old code.

Do not approve merely because behaviour seems correct: the bar is no structural regression, no obvious missed simplification, no spaghetti growth, and no credential exposure. Prefer a few high-conviction comments over cosmetic nits. Be direct and demanding about quality, but not rude.
- path: "tests/**"
instructions: |
Tests assert behaviour, not the shape of the source. Reject a test that reads a source file's text, that freezes a current count or version, or that passes both before and after the change it claims to cover.

For a change described as a refactor, the test must exercise the old code path as well, so a regression is observable. Assert exact wire tuples (verb, path, params, body) for anything touching transport, not a loose shape match.

Prefer assertion lists over sets unless order genuinely does not matter.
- path: "**/*.md"
instructions: |
Documentation is reviewed for accuracy against the code, not for style alone. Any sentence naming a flag, a path, an endpoint, an exit code or a count must match the implementation. Flag a claim the code contradicts.

Spelling is en-GB. Identifiers, commands and JSON keys keep their original form.
- path: "*.sh"
instructions: |
Shell scripts are executable text, not prose. Do not suggest typography changes to quoting; a double quote in shell is an operator.

Check that no secret reaches argv, that the script fails loudly rather than continuing on a missing dependency, and that interpreter resolution cannot silently select a system Python that lacks the project dependencies.
- path: "*.bat"
instructions: |
Windows launchers must resolve the same interpreter and the same dependency set as start.sh. Flag any divergence in behaviour between a .bat launcher and the shell equivalent.
- path: ".gitignore"
instructions: |
Confirm secrets stay ignored (.env, tokens, keys) and that no build or cache artifact is newly tracked.

chat:
auto_reply: true
21 changes: 21 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Copy to .env and fill in the values you need.
#
# The launcher loads this file automatically. Nothing here is required if you
# pass the equivalent command line flag instead.

# API key the proxy requires from its clients.
# Equivalent to --api-key. Leave unset to run with no authentication.
# WORKBUDDY2OPENAI_KEY=c2o-local-1

# WorkBuddy / CodeBuddy API key, for the direct-key mode that skips the desktop
# session entirely.
# Equivalent to --direct-key.
# Generate one at https://www.codebuddy.ai/profile/keys
# WORKBUDDY_DIRECT_KEY=ck_yourkeyhere

# Path to write the proxy log to.
# Equivalent to --log. Leave unset to log to the console only.
# WORKBUDDY2OPENAI_LOG=c2o.log

# The CODEBUDDY_* spellings of the three variables above still work, so an
# existing .env file needs no changes.
28 changes: 28 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# Normalise line endings so the shell and Windows launchers stay runnable.
* text=auto

*.sh text eol=lf
*.bat text eol=crlf
*.py text eol=lf
*.md text eol=lf
*.yaml text eol=lf
*.yml text eol=lf
*.toml text eol=lf
*.ini text eol=lf
*.txt text eol=lf
.env.example text eol=lf
.gitattributes text eol=lf
.gitignore text eol=lf

# Binary assets, never diffed or merged as text.
*.png binary
*.jpg binary
*.jpeg binary
*.gif binary
*.ico binary
*.pdf binary

# Generated and dependency artifacts, excluded from language statistics.
.venv/** linguist-vendored
__pycache__/** linguist-generated
*.pyc linguist-generated
46 changes: 46 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
---
name: Bug report
about: Something does not work
labels: bug
---

## What happens

<!-- The behaviour you see. -->

## What you expected

<!-- The behaviour you expected instead. -->

## Steps to reproduce

1.
2.
3.

## Environment

- OS and version:
- Python version (`python --version`):
- Install method (git clone, pipx, other):
- Commit or version:

## Proxy output

<!-- Paste the console output from startup, with your API key redacted. -->

```

```

## Request and response

<!-- If an endpoint misbehaved, paste the request and the response body. -->

```

```

## Anything else

<!-- Model in use, client you are connecting from, relevant log lines. Redact tokens. -->
17 changes: 17 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
name: Feature request
about: Suggest a change
labels: enhancement
---

## The problem

<!-- What you cannot do today. -->

## What you would like

<!-- The behaviour you want instead. -->

## Alternatives you considered

<!-- Including working around it yourself, if you found one. -->
17 changes: 17 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
## What this changes

<!-- One or two sentences. -->

## Why

<!-- The problem it solves, or the issue it closes. -->

## How you verified it

<!--
Tests you ran, plus anything you exercised by hand. A note that you sent a real
request to a running proxy is worth more than a note that the suite passed.
-->

- [ ] Full suite passes
- [ ] Exercised against a running proxy (if this touches request handling, streaming, or credential resolution)
6 changes: 6 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,9 @@ Thumbs.db
*.token
*.key
secrets.*
.env
.env.*
!.env.example

# tests
.pytest_cache/
40 changes: 40 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
# Changelog

Notable changes to this fork. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); versions follow [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

This fork is maintained at https://github.com/leonid-dalin/codebuddy2openai and is not released in step with the upstream project.

## [Unreleased]

### Added

- `SECURITY.md`, with the threat model for a proxy that holds a live account credential and binds to loopback by default.
- `CONTRIBUTING.md`, covering setup, tests, end-to-end verification, and commit conventions.
- `THIRD_PARTY_NOTICES.md`, listing the declared dependencies with their licences.
- `CODE_OF_CONDUCT.md`, adapted from Contributor Covenant 3.0.
- `.env.example`, documenting every environment variable the code reads.
- `.gitattributes`, pinning line endings per file type.
- `.coderabbit.yaml`, configuring automated review with maintainability and credential-safety checks.
- `pyproject.toml`, so the project installs with `pip install .` and exposes a `workbuddy2openai` console command.
- Issue and pull request templates.

### Changed

- The project is licensed under GPL-3.0-or-later. The upstream MIT terms stay in force for the upstream code and are reproduced in `LICENSE`.
- The README is split by language: `README.md` holds the English documentation and `README.zh-CN.md` holds the Chinese documentation, each linking to the other.
- Environment variables accept the `WORKBUDDY_*` names. The `CODEBUDDY_*` names still work, so existing `.env` files keep running.

### Fixed

- `.gitignore` covered only a bare `.env`, leaving `.env.local` and similar files untracked-but-committable. It now ignores `.env.*` and keeps `.env.example`.

## [2.0.0]

### Added

- API key mode (`--direct-key`), which skips the desktop session and calls the international backend with a `CK_*` key. This is the path for WorkBuddy international accounts, where the desktop token path returns 401.
- `/health` endpoint reporting platform, Python version, and mode.

### Notes

- Streaming is always used upstream; non-streaming client requests are aggregated by the proxy.
83 changes: 83 additions & 0 deletions CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
# Contributor Covenant 3.0 Code of Conduct

## Our pledge

We pledge to make our community welcoming, safe, and equitable for all.

We are committed to fostering an environment that respects and promotes the dignity, rights, and contributions of all individuals, regardless of characteristics including race, ethnicity, caste, colour, age, physical characteristics, neurodiversity, disability, sex or gender, gender identity or expression, sexual orientation, language, philosophy or religion, national or social origin, socio-economic position, level of education, or other status. The same privileges of participation are extended to everyone who participates in good faith and in accordance with this Covenant.

## Encouraged behaviours

While acknowledging differences in social norms, we all strive to meet our community's expectations for positive behaviour. We also understand that our words and actions may be interpreted differently than we intend based on culture, background, or native language.

With these considerations in mind, we agree to behave mindfully toward each other and act in ways that centre our shared values, including:

1. Respecting the **purpose of our community**, our activities, and our ways of gathering.
2. Engaging **kindly and honestly** with others.
3. Respecting **different viewpoints** and experiences.
4. **Taking responsibility** for our actions and contributions.
5. Gracefully giving and accepting **constructive feedback**.
6. Committing to **repairing harm** when it occurs.
7. Behaving in other ways that promote and sustain the **well-being of our community**.

## Restricted behaviours

We agree to restrict the following behaviours in our community. Instances, threats, and promotion of these behaviours are violations of this Code of Conduct.

1. **Harassment.** Violating explicitly expressed boundaries or engaging in unnecessary personal attention after any clear request to stop.
2. **Character attacks.** Making insulting, demeaning, or pejorative comments directed at a community member or group of people.
3. **Stereotyping or discrimination.** Characterising anyone's personality or behaviour on the basis of immutable identities or traits.
4. **Sexualisation.** Behaving in a way that would generally be considered inappropriately intimate in the context or purpose of the community.
5. **Violating confidentiality.** Sharing or acting on someone's personal or private information without their permission.
6. **Endangerment.** Causing, encouraging, or threatening violence or other harm toward any person or group.
7. Behaving in other ways that **threaten the well-being** of our community.

### Other restrictions

1. **Misleading identity.** Impersonating someone else for any reason, or pretending to be someone else to evade enforcement actions.
2. **Failing to credit sources.** Not properly crediting the sources of content you contribute.
3. **Promotional materials.** Sharing marketing or other commercial content in a way that is outside the norms of the community.
4. **Irresponsible communication.** Failing to responsibly present content which includes, links or describes any other restricted behaviours.

## Reporting an issue

Tensions can occur between community members even when they are trying their best to collaborate. Not every conflict represents a code of conduct violation, and this Code of Conduct reinforces encouraged behaviours and norms that can help avoid conflicts and minimise harm.

When an incident does occur, it is important to report it promptly. To report a possible violation, email **infoleonid@protonmail.com**. Reports are read by the project maintainer.

Community moderators take reports of violations seriously and will make every effort to respond in a timely manner. They will investigate all reports of code of conduct violations, reviewing messages, logs, and recordings, or interviewing witnesses and other participants. Community moderators will keep investigation and enforcement actions as transparent as possible while prioritising safety and confidentiality. To honour these values, enforcement actions are carried out in private with the involved parties, but communicating to the whole community may be part of a mutually agreed upon resolution.

## Addressing and repairing harm

If an investigation by the community moderators finds that this Code of Conduct has been violated, the following enforcement ladder may be used to determine how best to repair harm, based on the incident's impact on the individuals involved and the community as a whole. Depending on the severity of a violation, lower rungs on the ladder may be skipped.

1. Warning
1. Event: A violation involving a single incident or series of incidents.
2. Consequence: A private, written warning from the community moderators.
3. Repair: Examples of repair include a private written apology, acknowledgement of responsibility, and seeking clarification on expectations.
2. Temporarily limited activities
1. Event: A repeated incidence of a violation that previously resulted in a warning, or the first incidence of a more serious violation.
2. Consequence: A private, written warning with a time-limited cooldown period designed to underscore the seriousness of the situation and give the community members involved time to process the incident. The cooldown period may be limited to particular communication channels or interactions with particular community members.
3. Repair: Examples of repair may include making an apology, using the cooldown period to reflect on actions and impact, and being thoughtful about re-entering community spaces after the period is over.
3. Temporary suspension
1. Event: A pattern of repeated violation which the community moderators have tried to address with warnings, or a single serious violation.
2. Consequence: A private written warning with conditions for return from suspension. In general, temporary suspensions give the person being suspended time to reflect upon their behaviour and possible corrective actions.
3. Repair: Examples of repair include respecting the spirit of the suspension, meeting the specified conditions for return, and being thoughtful about how to reintegrate with the community when the suspension is lifted.
4. Permanent ban
1. Event: A pattern of repeated code of conduct violations that other steps on the ladder have failed to resolve, or a violation so serious that the community moderators determine there is no way to keep the community safe with this person as a member.
2. Consequence: Access to all community spaces, tools, and communication channels is removed. In general, permanent bans should be rarely used, should have strong reasoning behind them, and should only be resorted to if working through other remedies has failed to change the behaviour.
3. Repair: There is no possible repair in cases of this severity.

This enforcement ladder is intended as a guideline. It does not limit the ability of community managers to use their discretion and judgment, in keeping with the best interests of our community.

## Scope

This Code of Conduct applies within all community spaces, and also applies when an individual is officially representing the community in public or other spaces. Examples of representing our community include using an official email address, posting via an official social media account, or acting as an appointed representative at an online or offline event.

## Attribution

This Code of Conduct is adapted from the Contributor Covenant, version 3.0, permanently available at [https://www.contributor-covenant.org/version/3/0/](https://www.contributor-covenant.org/version/3/0/).

Contributor Covenant is stewarded by the Organization for Ethical Source and licensed under CC BY-SA 4.0. To view a copy of this licence, visit [https://creativecommons.org/licenses/by-sa/4.0/](https://creativecommons.org/licenses/by-sa/4.0/)

For answers to common questions about Contributor Covenant, see the FAQ at [https://www.contributor-covenant.org/faq](https://www.contributor-covenant.org/faq). Translations are provided at [https://www.contributor-covenant.org/translations](https://www.contributor-covenant.org/translations). Additional enforcement and community guideline resources can be found at [https://www.contributor-covenant.org/resources](https://www.contributor-covenant.org/resources). The enforcement ladder was inspired by the work of [Mozilla's code of conduct team](https://github.com/mozilla/inclusion).
Loading