feat(opencode): add MiniMax OAuth device code flow plugin#27011
feat(opencode): add MiniMax OAuth device code flow plugin#27011jiemu-minimax wants to merge 13 commits into
Conversation
- Implement MinimaxAuthPlugin with full device authorization grant flow - PKCE (code_verifier + code_challenge via SHA-256) for security - State parameter generated and verified to prevent CSRF - Polls /oauth/token at server-specified interval until authorized - Proactive token refresh 60s before expiry with refresh_token rotation - Stores resource_url in enterpriseUrl field for AI API base URL
Match mmx-cli's 5-minute refresh buffer for consistency across all MiniMax OAuth clients. 60s was too tight — network latency could cause mid-request token expiry.
- Content-Type: JSON → application/x-www-form-urlencoded (OAuth standard) - grant_type: user_code → device_code (RFC 8628 standard) - Add scope parameter to device code request - Add polling timeout based on expired_in (was infinite loop) - Remove response_type from device code request (unused by server)
- OAuth: "Log in with MiniMax (OAuth)" - API key: "Manually enter Token Plan key"
|
Hey! Your PR title Please update it to start with one of:
Where See CONTRIBUTING.md for details. |
|
Thanks for updating your PR! It now meets our contributing guidelines. 👍 |
|
Automated PR Cleanup Thank you for contributing to opencode. Due to the high volume of PRs from users and AI agents, we periodically close older PRs using automated criteria so maintainers can focus review time on the most active and community-supported contributions. This PR was closed because it matched the following cleanup criteria:
PRs created within the last month are not affected by this cleanup. If you believe this PR was closed incorrectly, or if you are still actively working on it, please leave a comment explaining why it should be reopened. A maintainer can review and reopen it if appropriate. Thanks again for taking the time to contribute. |
Issue for this PR
N/A — New provider integration
Type of change
What does this PR do?
Add MiniMax (MiniMax) as an OAuth provider, supporting both global (api.minimax.io) and China domestic (api.minimaxi.com) regions.
How did you verify your code works?
Tested OAuth login flow end-to-end in both global and CN regions, verified token refresh and API calls with the obtained access token.
Checklist