Skip to content

[in progress] Add provider credentials verification - #299

Closed
jorgefilipecosta wants to merge 1 commit into
trunkfrom
fix/verify-provider-credentials
Closed

jorgefilipecosta wants to merge 1 commit into
trunkfrom
fix/verify-provider-credentials

Conversation

@jorgefilipecosta

Copy link
Copy Markdown
Member

What?

Adds a way to verify a provider's credentials that tells credentials the provider rejected apart from failures that say nothing about them.

  • New VerifiesCredentialsInterface with verifyCredentials(): bool.
  • ListModelsApiBasedProviderAvailability implements it.
  • New ProviderRegistry::verifyProviderCredentials(), which falls back to isConfigured() for availability checks that don't implement the interface.

Why?

isConfigured() reports every failure as false and uses the cached model list. WordPress validates connector API keys with it, so a provider outage during a settings save wipes a valid key, and a wrong key passes while the model list is cached: https://core.trac.wordpress.org/ticket/65551

How?

  • verifyCredentials() invalidates the cached model list, lists models, and returns false only for a 4xx response other than 408 or 429 (Google answers a bad key with 400). Network errors, 5xx, 408 and 429 are rethrown.
  • GenerateTextApiBasedProviderAvailability is unchanged, as no official provider uses it. Happy to add it here too.

Testing

Verify unit tests are passing:

composer test

Issue found via AI-assisted code review; fix and tests drafted with AI assistance (Claude Code) and reviewed by me.

ListModelsApiBasedProviderAvailability::isConfigured() reports every
failure as false and relies on the cached model list, so it cannot tell
rejected credentials apart from a network error, and it keeps reporting
success for other credentials while the list is cached.

Add VerifiesCredentialsInterface and
ProviderRegistry::verifyProviderCredentials(). The list models
availability check implements the interface: it invalidates the cached
model list, returns false only when the provider rejects the request,
and throws for network errors, server errors, timeouts and rate limits.
@github-actions

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: jorgefilipecosta <[email protected]>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.62%. Comparing base (77a5995) to head (c6f3f92).

Additional details and impacted files
@@             Coverage Diff              @@
##              trunk     #299      +/-   ##
============================================
+ Coverage     86.58%   86.62%   +0.04%     
- Complexity     1383     1389       +6     
============================================
  Files            69       69              
  Lines          4449     4464      +15     
============================================
+ Hits           3852     3867      +15     
  Misses          597      597              
Flag Coverage Δ
unit 86.62% <100.00%> (+0.04%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@jorgefilipecosta jorgefilipecosta changed the title Add provider credentials verification [in progress] Add provider credentials verification Sep 30, 2026
jorgefilipecosta added a commit to jorgefilipecosta/wordpress-develop that referenced this pull request Sep 30, 2026
…rification.

Stand-in for bundling a php-ai-client release that includes
WordPress/php-ai-client#299. Generated with
tools/php-ai-client/installer.sh from 1.3.1 plus that change.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant