Fix empty Bearer on netx__* by waiting for credentials.

Inject credentials before publish, read the live token per HTTP request, and surface netx_token_missing instead of a silent 401.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-05 02:11:20 +08:00
parent 02cc68bee3
commit 027f83dd00
7 changed files with 77 additions and 37 deletions

View file

@ -27,6 +27,7 @@ function publishNetxConnection(next) {
// src/index.ts
var name = "netxops";
var inject = ["credentials"];
var NETXOPS_SETTINGS_NAMESPACE = "netxops";
var NETXOPS_PRESET_ID = "netxops";
var DEFAULT_TOKEN_REF = "NETX_API_TOKEN";
@ -69,10 +70,7 @@ function ensureAgentPresetInstalled(logger) {
}
}
async function resolveToken(ctx, refName) {
const credentials = ctx.get("credentials");
if (credentials === undefined)
return "";
const hit = await credentials.resolve(credentialRef(refName));
const hit = await ctx.credentials.resolve(credentialRef(refName));
return hit?.value ?? "";
}
function installNetxopsSettings(ctx, entry, hooks) {
@ -99,13 +97,19 @@ function apply(ctx, config = Config({})) {
const token = await resolveToken(ctx, current.tokenCredentialRef);
if (gen !== generation)
return;
const apiUrl = current.apiUrl.replace(/\/$/, "");
const tokenConfigured = token.trim().length > 0;
publishNetxConnection({
apiUrl: current.apiUrl.replace(/\/$/, ""),
apiUrl,
token,
lang: current.lang,
toolCallTimeoutMs: current.toolCallTimeoutMs
});
ctx.logger.info("netxops: published connection → %s", current.apiUrl.replace(/\/$/, ""));
if (!tokenConfigured) {
ctx.logger.warn("netxops: published connection → %s tokenConfigured=false (set credential %s)", apiUrl, current.tokenCredentialRef);
} else {
ctx.logger.info("netxops: published connection → %s tokenConfigured=true", apiUrl);
}
}).catch((error) => {
ctx.logger.error("netxops: connection publish error: %s", error);
});
@ -129,6 +133,7 @@ function apply(ctx, config = Config({})) {
}
export {
name,
inject,
ensureAgentPresetInstalled,
apply,
NETXOPS_SETTINGS_NAMESPACE,