feat: OpenCode Go usage, model refresh, and macOS panel layout - #81
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Refresh Models publishes the saved catalog without interrupting ChatGPT. A running Codex worker can continue using its previously loaded roster; the panel then explains the restart step. The dashboard's guarded worker restart remains an advanced option.
Security considerations
The OpenCode Go quota probe sends the configured Go API key as a Bearer token only to the fixed canonical Go usage endpoint. Redirects are rejected, the request has a timeout, and the token and response body are not logged. The live probe falls back to local observations on an invalid or unavailable response. Independent security review under
MAINTAINERS.mdverified these credential-destination, redirect, timeout, and fallback boundaries. Regression tests assert zero network requests for custom destinations and OAuth mode, and safe local fallback for rejected or invalid usage responses. First-party endpoint behavior was checked against OpenCode’susage.tsandsubscription.ts; model IDs and transports were checked against https://opencode.ai/v2/docs/console/go and https://models.opencode.ai/api.json (verified 2026-10-01).Review fixes and release version
Verification
bun run typecheck— passed.bun run test:parallel— all 631 test files passed on the revised tree.bun run test:macos— 90 passed.cd gui && bun run test— 888 passed on the revised tree; GUI lint, i18n lint, and build passed.cd docs-site && bun install --frozen-lockfile && bun run build— passed.bun run privacy:scan,bun run build:macos, andgit diff --check— passed.macOS panel screenshots
Rendered from safe UI test data; no account identifiers or keys are included.
The revised backend and UI fixes received independent review. All local checks above passed; aggregate CI on the revised head must pass before merge. The 0.1.20 release will additionally require the signed-asset and installed-app update qualifications described in
structure/06_docs-and-release.md.