refactor(secrets): drop scope-aware env shims; runtime_provider and the voice/xai tools read the canonical getters

hermes_cli/runtime_provider._getenv was a 4-line copy of get_secret(name,
default) or default; it becomes agent.secret_scope.get_secret_str (returns
default only when the secret is genuinely unset, still raises
UnscopedSecretError — a child's unscoped read is a spawn-site bug). The
runtime_provider_backends/_custom siblings call it directly instead of via
the origin module.

tools/tts_tool, tools/transcription_tools and tools/xai_http each carried an
identical get_env_value re-export kept "so tests can patch" it; the seam is
hermes_cli.config.get_env_value, read lazily at call time. Callers
(tts_streaming, tts_tool_providers, transcription_cloud, voice_client_config,
tools_config) go there directly; resolve_provider_secret already defaults to
it so the env_getter kwarg is gone. Tests repointed at the canonical; the two
tests that only proved the shim forwarded are deleted.

Behavior change: none.
This commit is contained in:
teknium1
2026-09-12 20:38:02 -07:00
committed by Teknium
parent c849bc383a
commit dd1baee0e4
22 changed files with 75 additions and 203 deletions
+4 -2
View File
@@ -100,7 +100,8 @@ def _resolve_stt_client_config() -> Dict[str, Any]:
return _direct(wire, provider, base_url, api_key, model, language=language)
def env_base_url(env_var: str, default: str) -> str:
return str(section.get("base_url") or tt.get_env_value(env_var) or default).strip().rstrip("/")
from hermes_cli.config import get_env_value
return str(section.get("base_url") or get_env_value(env_var) or default).strip().rstrip("/")
if provider in _STT_KEYED:
env_var, default_model, base = _STT_KEYED[provider]
@@ -120,7 +121,8 @@ def _resolve_stt_client_config() -> Dict[str, Any]:
if provider == "xai":
# API key only: an xAI OAuth bearer refreshes server-side mid-session and
# would strand the client on the first 401.
api_key = str(tt.get_env_value("XAI_API_KEY") or "").strip()
from hermes_cli.config import get_env_value
api_key = str(get_env_value("XAI_API_KEY") or "").strip()
if not api_key:
return _relay("xai oauth (server-managed) or no credentials")
return direct(STT_WIRE_XAI, env_base_url("XAI_STT_BASE_URL", tc.XAI_STT_BASE_URL), api_key, None)