mirror of
https://github.com/OpenHands/OpenHands.git
synced 2026-10-07 15:18:09 +08:00
* feat: seed automation API key into agent-server secrets - Add seedAutomationSecret() that calls PUT /api/settings/secrets after agent-server is ready, storing the automation API key as OPENHANDS_AUTOMATION_API_KEY - This makes the key available to agents during conversations so they can authenticate with the automation backend - Add sessionApiKey to config for optional auth header - Update help text and documentation Co-authored-by: openhands <openhands@all-hands.dev> * test: add tests for seed automation secret and fix CI failure - Add tests for localApiKey and sessionApiKey config in buildConfig - Add tests for secrets documentation in help output - Fix root-layout-refetch.test.tsx unhandled rejection from framer-motion by adding async cleanup with microtask flush Co-authored-by: openhands <openhands@all-hands.dev> * fix: detect SESSION_API_KEY when seeding automation secret The seedAutomationSecret() function was failing with 401 Unauthorized because it wasn't detecting the SESSION_API_KEY environment variable that the agent-server uses by default (V0 config). The agent-server checks these env vars for session API keys: - SESSION_API_KEY (V0 config, picked up by default factory) - OH_SESSION_API_KEYS_0 (V1 config) The original code only checked OH_SESSION_API_KEY and VITE_SESSION_API_KEY, missing the actual env vars the server reads. In OpenHands Cloud environments, SESSION_API_KEY is set automatically, causing the 401. This fix adds SESSION_API_KEY and OH_SESSION_API_KEYS_0 to the fallback chain, with SESSION_API_KEY taking highest precedence since it matches the agent-server's default behavior. Adds tests verifying: - SESSION_API_KEY detection - OH_SESSION_API_KEYS_0 detection - Precedence order (SESSION_API_KEY > OH_SESSION_API_KEYS_0 > others) Co-authored-by: openhands <openhands@all-hands.dev> * fix: add retry logic and longer timeout for secret seeding On slower systems, the agent-server may take longer to start up, causing the secret seeding to fail with 'fetch failed' errors. This fix adds: 1. Increased initial wait timeout from 30s to 60s for agent-server startup 2. Retry logic in seedAutomationSecret (5 retries with 2s delay) 3. Better error logging showing elapsed time and last error 4. AbortSignal.timeout on fetch requests to avoid hanging 5. Skip seeding if server fails to start (with warning message) The retry logic handles transient failures during server warmup but immediately fails on 401/403 auth errors (no point retrying). Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev>