fix(oidc): 恢复 grok-cli:access 并支持批量重铸
补回 mint scope 中的 grok-cli:access,铸造后校验 JWT scope, 避免 cli-chat-proxy 返回 grok-cli-token-auth-required。 新增 remint_cli_scope.py,基于已有 sso 覆盖写回缺 scope 的 CPA auth; 同步更新 cpa/schema 文档说明 referrer 与 scope 双重要求。
This commit is contained in:
1 parent
7d6d52ac5d
commit
bc5ad63755
4 files changed
+324
-5
No files matched your search
+5
-1
@@ -5,7 +5,11 @@ internal/auth/xai/token.go 的 TokenStorage 结构。
|
||||
自带 x-grok-client-version 头(xai_executor.go 硬编码 0.2.93),免费 Build 账号
|
||||
不会 426。
|
||||
|
||||
2026-07:AccessToken 必须含 referrer=grok-build,否则 cli-chat-proxy 拒用。
|
||||
2026-07:AccessToken 必须同时满足:
|
||||
1) claim referrer=grok-build
|
||||
2) scope 含 grok-cli:access
|
||||
否则 cli-chat-proxy 会返回:
|
||||
WKE=unauthorized:grok-cli-token-auth-required
|
||||
铸造请走 oidc_mint.oauth_code(SSO→Authorization Code + PKCE)。
|
||||
"""
|
||||
|
||||
|
||||
Reference in new issue
Block a user