fabro/lib/apps/fabro-server/src
Bryan Helmkamp 6dfc96d3fd
Resolve provider secrets through lithos conventional credentials
lithos-llm now owns which named secrets each provider reads and how they
shape into its auth scheme, including a derived `<PROVIDER>_API_KEY` for
operator-defined providers. Fabro's job shrinks to supplying the store:
`VaultCredentialSource` hands lithos a lookup that reads the process
environment, then the vault, under the same conventional names.

What Fabro still adds on top: the Codex OAuth credential in the vault,
refreshed and persisted when it expires; `{{ secrets.NAME }}` tokens in a
provider's `default_headers`, resolved against the vault and re-sent as
credential headers; and OpenAI organization and project headers from the
environment.

Deleted with the `metadata.fabro.credentials` list: `CredentialRef`,
`CredentialResolver`, `EnvCredentialSource` (now
`VaultCredentialSource::environment_only`), and the `env_var_names` /
`expected_vault_secret_name` helpers, replaced by `secret_names` and
`expected_secret_name` over the lithos table. `openai-codex` joins the
first-party provider id constants.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-09 23:00:08 -06:00
..
auth Keep auth code store naming consistent 2026-08-24 17:26:17 -04:00
demo Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
prompts Render the run title prompt with Jinja instead of string replacement 2026-07-27 17:23:16 -04:00
server Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
worker_control refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
automation_materializer.rs Tighten automation Git validation types 2026-08-31 18:02:08 -04:00
canonical_host.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
canonical_origin.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
csp.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
diagnostics.rs Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
error.rs Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
git_checkout.rs Tighten automation Git validation types 2026-08-31 18:02:08 -04:00
github_webhooks.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
install.rs Resolve provider secrets through lithos conventional credentials 2026-09-09 23:00:08 -06:00
interp.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
jwt_auth.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
lib.rs Remove expired startup secret migrations 2026-09-05 14:05:48 -04:00
manifest_validation.rs Simplify local RunIntent producer support 2026-08-31 14:08:35 -04:00
migrations.rs Remove expired startup secret migrations 2026-09-05 14:05:48 -04:00
principal_middleware.rs Unify blob hash vocabulary 2026-08-17 13:56:19 -04:00
request_id.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
run_compiler.rs Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
run_files.rs Load inactive run projections on demand 2026-09-01 16:06:54 -04:00
run_files_security.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
run_intent.rs Reject automatic pull requests for Local runs 2026-09-02 17:15:52 -04:00
run_manifest.rs Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
run_selector.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
run_title_generation.rs Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
run_tool_manifest.rs Remove run IDs from create manifest producers 2026-08-01 11:47:11 -04:00
security_headers.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
serve.rs Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
server.rs Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
server_secrets.rs Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
spawn_env.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00
startup.rs Remove expired startup secret migrations 2026-09-05 14:05:48 -04:00
static_files.rs feat(web): tell open tabs when a new build ships 2026-07-25 14:45:26 -04:00
test_support.rs Expose lithos request and response shapes through the API, server, CLI, and web 2026-09-09 17:26:57 -06:00
web_auth.rs Serve CLI auth sessions from SQLite 2026-07-26 00:00:15 -04:00
worker_runtime.rs refactor: simplify cancellation lifecycle code from review 2026-07-23 21:15:35 -04:00
worker_token.rs refactor: organize crates into three layers 2026-07-23 17:59:34 -04:00