fix(oidc): 恢复 grok-cli:access 并支持批量重铸

补回 mint scope 中的 grok-cli:access,铸造后校验 JWT scope,
避免 cli-chat-proxy 返回 grok-cli-token-auth-required。
新增 remint_cli_scope.py,基于已有 sso 覆盖写回缺 scope 的 CPA auth;
同步更新 cpa/schema 文档说明 referrer 与 scope 双重要求。
This commit is contained in:
chaos committed 2026-07-15 10:12:17 +08:00
1 parent 7d6d52ac5d
commit bc5ad63755
4 files changed
+324 -5

No files matched your search

+2 -2
View File
@@ -20,10 +20,10 @@ CLIENT_ID = "b1a00492-073a-47ea-816f-4c329264a828"
ISSUER = "https://auth.x.ai"
DEVICE_CODE_URL = "https://auth.x.ai/oauth2/device/code"
TOKEN_URL = "https://auth.x.ai/oauth2/token"
# 对齐官方 0.2.101 discovery / docs(去掉二进制中已不出现的 grok-cli:access)
# cli-chat-proxy 要求 token scope 含 grok-cli:access(否则 grok-cli-token-auth-required)
SCOPE = (
"openid profile email offline_access "
"api:access conversations:read conversations:write"
"grok-cli:access api:access conversations:read conversations:write"
)
LogFn = Callable[[str], None]