Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueComment |
vqt123
approved these changes
Sep 22, 2026
vqt123
left a comment
Contributor
There was a problem hiding this comment.
Checks:
- The key goes out in the shape the servers read.
BuilderClient.from_sessionandDeployClient.from_session(comfy_cli/deploy_api.py:90) now takeresolve_cloud_credential(purpose="cloud")and send its value asAuthorization: Bearer; theWithIdentitychange in cloud#10161 (comfy-builder and comfy-deployhttpkit/identity.go) branches on aBearer comfyui-token, so the two sides match. deploy runworks with a key too:comfy_cli/command/deploy_run.py:201reuses the control-plane credential for the deployment endpoint, and the gateway on main already acceptsBearer comfyui-(services/platform-gateway/server/auth.go:146).- Only a stored session refreshes:
_refreshes_on_401 = credential.source == "session", so a key or a forwardedCOMFY_CLOUD_AUTH_TOKENis never swapped after a 401.COMFY_BUILDER_TOKENstill wins in_builder_client. - The red GPU-runner job is
tests/e2e/test_e2e_uv_compile.py(Manager's uv-compile conflict message), not this diff; the three-platform test matrix passes.
Findings: none. Shipping this before cloud#10161 is deployed is harmless: a key-only caller gets a 401 whose hint already names the key.
~6.0M effective tokens for this review (41.8M raw; cache reads weighted 0.1x, cache writes 1.25-2x)
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
comfy buildandcomfy deploycan useCOMFY_CLOUD_API_KEYor a key saved withcomfy cloud set-keywithout an OAuth login. Both clients use the existing shared credential resolver and send the selected credential as a bearer token.OAuth retains its existing precedence and refresh behavior. API keys and forwarded bearer tokens are never refreshed or replaced after a 401. Authentication errors and the README now describe the key-based workflow.
Depends on the server support in cloud#10161 being deployed. Companion draft for BE-11394.
Validation
uv run ruff check .anduv run ruff format --check .: passed.022andTERM=xterm-256color: 7,900 passed, 37 skipped, 1 failed. The existingtest_edited_content_is_hashed_again[identical size]digest-cache test also fails on untouchedorigin/main(aec5220); no unrelated code was changed.