Skip to content

Forge 0.5.1

Choose a tag to compare

@windingcreek windingcreek released this 26 Sep 00:32
· 67 commits to main since this release

Forge 0.5.1

A patch release. Three bugs, each of which stopped work rather than slowed it.

macOS is the supported platform for this release. Windows and Linux are
next; see Platforms for what has
been verified per component.

ChatGPT Codex authentication

Signing in worked and then requests failed with Incorrect API key provided: sk-svcacct… — naming a credential you never supplied and cannot find in any
config file. You didn't supply it: Forge exchanged your OAuth id_token for an
API key on login, on every token refresh and on every token check, wrote it into
chatgpt_auth.json, and then preferred it over the OAuth token for one request.
The backend that accepts the token rejects that key.

It only broke when the mint succeeded, which is why it came and went rather
than failing consistently, and why signing in again did not help — a fresh login
minted a fresh key.

Nothing mints it now, and a key left behind by an older build is dropped when
the token file is read, so it leaves disk on the next save. A credential nobody
asked for should not be sitting in a file.

An approved plan could leave the agent with no legal move

Approving a plan without clearing context cleared the plan-mode flag but left
the PLAN MODE ACTIVE — you CANNOT modify files directive standing in the
transcript. Those are two halves of one state: the flag decides which tools are
offered, the directive is what the model reads. With the flag down,
exit_plan_mode was no longer offered — so the agent was told it must not write
anything, while the one tool that would have let it say so was gone.

It refused to implement the plan it had just written and asked to be switched
out of a mode it was no longer in. Both correct, and no move left that made
progress. Every exit path goes through one place now.

When a credential is rejected, the error says where it came from

A 401 named the key the provider disliked and nothing about which of the several
paths that can supply it had run. It now reports the endpoint, the model,
whether the account header was sent, and the credential's shape — kind, length
and a six-character prefix, which is no more than the provider already echoes
back. Never the secret. FORGE_AUTH_DEBUG=1 traces the same line on every
request, for catching a credential that works now and stops later.

The model-catalog fetch used to swallow every failure and merely look like an
empty catalog. That silence is why the minted key went unseen; it reports auth
failures now.

Editor

forge-ide --version and --help now exist and are answered before any window
opens. An unrecognised argument is taken for a path, so asking the editor its
version used to launch it on a workspace called --version. It reports the
build commit as well as the number, since every build between two releases
reports the same number.

The "newer build is installed" banner wrapped its own dismiss button onto an
empty row once the message filled the first line.


The terminal client has no changes of its own this release and is
version-matched.