Files
openclaw/apps/macos/Tests/OpenClawIPCTests/OnboardingProviderIconTests.swift
Peter Steinberger 00854a7002 fix(macos): proper provider brand icons + softer contrast in onboarding AI setup (#120907)
* fix(macos): let AI setup proceed when the login keychain is unavailable

A missing/locked login keychain made GatewayActivationBindingKeyStore
unable to mint the activation binding key, and onboarding refused every
candidate and manual-key activation with 'Secure storage is unavailable'.
The fingerprint only protects the crash/relaunch resume receipt, so
degrade instead of refusing: write an ownerless pending record (still
matched exactly, never as a wildcard), keep the full activation-ambiguity
window, and skip only restart reconciliation, which needs fingerprint
proof by design. A relaunch then repeats activation rather than trusting
the receipt.

Reported by Peter Steinberger.

* fix(macos): render proper provider brand icons in onboarding AI setup

Nearly every provider icon URL the gateway sends is a simpleicons.org
SVG, which AsyncImage cannot decode, so the Connect your AI page fell
back to generic symbols for every tool and provider; the two GitHub
avatar PNGs that did render clashed as full-color rasters.

Bundle nine monochrome template marks (Simple Icons CC0; xAI from
LobeHub icons, MIT) and resolve them local-first by brand id/kind,
including composed choice ids like xai-oauth. Remote icons now load via
NSImage(data:), which decodes SVG, with vector payloads tinted as
templates so plugin-supplied icons blend too. Every glyph sits in a
uniform rounded well; install cards show host-only links, hover states,
and a softer translucent surface shared by all setup sections instead
of controlBackgroundColor.

Requested by Peter Steinberger.

* fix(macos): use failable UTF-8 decode in icon vector sniffing (swiftlint)

* fix(macos): address ClawSweeper review of onboarding icon/keychain changes

- Refuse relaunch handoff from ownerless (keychain-unavailable) completed
  receipts at the reconciliation trust boundary; such receipts can belong
  to replaced credentials, so setup repeats a fresh activation instead.
- Decode and pass the canonical brandId the gateway sends for candidates,
  auth options, and manual providers so bundled marks resolve for opaque
  choice ids.
- Scan the bounded XML prolog (comments, declarations, doctype) when
  sniffing remote SVG payloads; comment-prefixed vectors now tint as
  templates.

* refactor(macos): move setup error enum to support file (swiftlint file length)

* chore(i18n): refresh native source inventory

* fix(macos): give keychain-unavailable activations attempt-specific unbound leases

A nil owner made concurrent unbound attempts indistinguishable: a stale
attempt's delayed response could complete or clear a newer attempt's
record. Unbound attempts now mint a random per-attempt lease id with a
sentinel fingerprint — live matching stays attempt-exact, restart
reconciliation's fingerprint guard rejects them, and relaunch
verification refuses unbound receipts before any handoff.

* chore(macos): ship third-party artwork notices with provider icons

Simple Icons (CC0) attribution and the LobeHub Icons MIT license text
for the xAI mark now travel inside the bundled ProviderIcons directory.

* fix(ci): refresh plugin-sdk API manifest for private-type hashing

#120975 changed the baseline generator to hash private types but landed
without regenerating the manifest; the check-plugin-sdk-api-baseline
lane was gated off on that PR and first failed here. Regenerated via
pnpm plugin-sdk:api:gen with no SDK surface change in this branch.
2026-08-09 01:49:50 -07:00

72 lines
3.5 KiB
Swift

import AppKit
import Foundation
import Testing
@testable import OpenClaw
@MainActor
struct OnboardingProviderIconTests {
@Test func `provider aliases resolve to bundled artwork`() throws {
let aliases = [
("claude", ["claude-cli", "claude-code", "anthropic"]),
("codex", ["codex-cli", "openai"]),
("kimi", ["kimi-code"]),
("xai", ["grok-build", "xai"]),
]
for (brand, candidates) in aliases {
let expected = try #require(OnboardingProviderIcon.resourceURL(for: brand))
for candidate in candidates {
#expect(OnboardingProviderIcon.resourceURL(for: candidate) == expected)
}
}
#expect(OnboardingProviderIcon.resourceURL(for: "Ollama") ==
OnboardingProviderIcon.resourceURL(for: "ollama"))
// Composed choice ids resolve via their leading brand token.
#expect(OnboardingProviderIcon.resourceURL(for: "xai-oauth") ==
OnboardingProviderIcon.resourceURL(for: "xai"))
#expect(OnboardingProviderIcon.resourceURL(for: "anthropic-vertex") ==
OnboardingProviderIcon.resourceURL(for: "claude"))
#expect(OnboardingProviderIcon.resourceURL(for: "unknown") == nil)
#expect(OnboardingProviderIcon.resourceURL(for: "unknown-oauth") == nil)
}
@Test func `every mapped brand has decodable vector artwork`() throws {
for brand in ["claude", "codex", "gemini", "ollama", "lmstudio", "pi", "opencode", "kimi", "xai"] {
let url = try #require(OnboardingProviderIcon.resourceURL(for: brand))
#expect(url.pathExtension == "svg")
#expect(try #require(OnboardingProviderIcon.image(for: brand)).isTemplate)
}
}
@Test func `remote artwork distinguishes vector and raster payloads`() throws {
// Leading whitespace exercises the sniffer; an XML declaration after
// whitespace would be invalid XML, so the fixture uses a bare root.
let svg = Data(
" \n<svg xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 1 1\"><path d=\"M0 0h1v1H0z\"/></svg>"
.utf8)
let vector = try #require(OnboardingRemoteProviderIcon.decode(svg))
#expect(vector.isVector)
#expect(vector.nsImage.isTemplate)
// Bundled assets lead with a license comment; the sniffer must scan the
// prolog instead of expecting <svg> as the first non-whitespace token.
let commented = try #require(OnboardingProviderIcon.resourceURL(for: "ollama"))
let commentedData = try Data(contentsOf: commented)
#expect(String(bytes: commentedData.prefix(4), encoding: .utf8) == "<!--")
let commentedVector = try #require(OnboardingRemoteProviderIcon.decode(commentedData))
#expect(commentedVector.isVector)
let png = try #require(Data(base64Encoded:
"iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mNk+A8AAQUBAScY42YAAAAASUVORK5CYII="))
let raster = try #require(OnboardingRemoteProviderIcon.decode(png))
#expect(!raster.isVector)
#expect(!raster.nsImage.isTemplate)
}
@Test func `provider website host is concise and validated`() {
#expect(OnboardingProviderAuthLink.displayHost("https://www.kimi.com/code") == "kimi.com")
#expect(OnboardingProviderAuthLink.displayHost("https://ollama.com/download") == "ollama.com")
#expect(OnboardingProviderAuthLink.displayHost("not a url") == nil)
#expect(OnboardingProviderAuthLink.displayHost(nil) == nil)
}
}