mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-26 09:52:11 +03:00
feat: add ChatGPT Web (Plus/Pro) session provider
Adds a new chatgpt-web provider that routes through chatgpt.com's internal backend-api using a Plus/Pro subscription session cookie, enabling access to GPT-5.x models without an OpenAI API key. Heavier than perplexity-web/grok-web because chatgpt.com layers more bot protection — this PR builds out the full pipeline needed to look like a real browser session. ## New executor: open-sse/executors/chatgpt-web.ts Auth/request pipeline (per chat completion): 1. exchangeSession() GET /api/auth/session cookie -> JWT (cached ~5min) 2. fetchDpl() GET / scrape data-build + script src 3. runSessionWarmup() GET /backend-api/me, /conversations, /models 4. POST /sentinel/chat-requirements/prepare -> prepare_token 5. POST /sentinel/chat-requirements -> chat-requirements-token + PoW seed/diff 6. solveProofOfWork() SHA3-512 loop -> "gAAAAAB..." sentinel proof token 7. POST /backend-api/f/conversation with all sentinel headers 8. parse SSE stream -> OpenAI chat.completion[.chunk] format Notable details: - 18-element prekey config matching chat2api/openai-sentinel (browser fingerprint values, U+2212 MINUS SIGN in `webdriver−false`). Thin shapes get escalated to mandatory Turnstile. - Two-stage Sentinel handshake (/prepare + /chat-requirements) — sending only the prepare result returns a 403 "Unusual activity" response. - `turnstile.required: true` from Sentinel is treated as advisory; the conv endpoint accepts requests without a Turnstile token as long as PoW + chat- requirements-token are valid. Optional bring-your-own Turnstile via `providerSpecificData.turnstileToken` for accounts that hard-require it. - SSE parser tracks message_id and resets the accumulator on a new turn — chatgpt.com echoes prior assistant messages (with status finished_successfully) before sending the new turn. - entity["...","value", ...] internal markup stripped from output (browser renders these client-side). - Conversation-continuity cache disabled by default: we send history_and_training_disabled: true (Temporary Chat mode) and those conversation_ids expire too fast to reuse — re-using returned 404. Each request now sends conversation_id: null and replays full history, matching what Open WebUI and OpenAI-API-style clients send anyway. ## TLS impersonation: open-sse/services/chatgptTlsClient.ts ChatGPT's Cloudflare config pins cf_clearance to JA3/JA4 TLS fingerprint + HTTP/2 SETTINGS frame. Plain Node Undici fetch always returns cf-mitigated: challenge regardless of cookies. The wrapper module loads `tls-client-node` (Firefox 148 fingerprint) in native runtime mode (.so via koffi) — managed mode spawns a sidecar that conflicts with OmniRoute's global fetch proxy patch. - Lazy singleton TLSClient with process exit hooks - Streaming-capable (file tail) and non-streaming modes - Test injection point: __setTlsFetchOverrideForTesting() lets unit tests mock the client without touching globalThis.fetch ## Provider wiring - open-sse/executors/index.ts — register ChatGptWebExecutor with cgpt-web alias - open-sse/config/providerRegistry.ts — registry entry, format=openai, authHeader=cookie, model gpt-5.3-instant - src/shared/constants/providers.ts — WEB_COOKIE_PROVIDERS UI metadata (icon, color, authHint) - src/lib/providers/validation.ts — validateChatGptWebProvider hits /api/auth/session via the TLS client, detects cf-mitigated/HTML responses and returns a clear "paste full Cookie line" hint instead of a generic "Invalid" - next.config.mjs — mark tls-client-node, koffi, tough-cookie as external packages (Turbopack can't bundle the native .so) ## Cookie format Validator and executor accept any of: - bare value: "eyJhbGc..." - unchunked cookie line: "__Secure-next-auth.session-token=eyJ..." - chunked cookie line: "__Secure-next-auth.session-token.0=...; __Secure-next-auth.session-token.1=..." - full DevTools Cookie header line: "Cookie: __Secure-next-auth.session-token.0=...; cf_clearance=...; ..." NextAuth chunks the JWE when it exceeds 4KB; chunked cookies pass through verbatim (NextAuth reassembles server-side). Recommend pasting the full DevTools Cookie line so cf_clearance, __cf_bm, _cfuvid, _puid travel along — without cf_clearance, Cloudflare blocks the request before NextAuth sees it. ## Tests tests/unit/chatgpt-web.test.ts — 27 tests, all passing: - Registration + alias resolution - Token exchange (cookie -> Bearer flow) - Token cache TTL - Refreshed cookie surfaced via onCredentialsRefreshed callback - Sentinel call ordering (session -> prepare -> chat-requirements -> conv) - Sentinel chat-requirements-token forwarded on conv request - PoW token has gAAAAAB prefix - Turnstile.required: true does NOT block conv (passes through) - Non-streaming chat.completion JSON - Streaming SSE chunks ending with [DONE] - Cumulative-parts diffing yields non-overlapping deltas - Errors: 401 session, 403 sentinel, 429 conv rate-limit - Empty messages -> 400 without any fetch - Missing apiKey -> 401 without any fetch - Cookie format: bare value, unchunked, chunked, "Cookie: ..." DevTools line - Conversation continuity: each call starts a fresh conversation - Browser-like headers on conv POST (UA, Origin, Sec-Fetch-Site, Accept) - Payload shape (action, model=gpt-5-3, history_and_training_disabled) - Provider registry contains chatgpt-web with gpt-5.3-instant model Verification: typecheck:core clean, lint clean (no new warnings), end-to-end manually verified across single-turn, multi-turn (memory preserved), streaming, and Open WebUI-style sequential growing-history flows. ## References - bogdanfinn/tls-client (Go) — TLS impersonation upstream - fatihkabakk/tls-client-node — Node bindings - lanqian528/chat2api — Sentinel/PoW/prekey reference impl (Python) - leetanshaj/openai-sentinel — Prekey config + SHA3-512 solver Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -38,6 +38,9 @@ const nextConfig = {
|
||||
"keytar",
|
||||
"wreq-js",
|
||||
"zod",
|
||||
"tls-client-node",
|
||||
"koffi",
|
||||
"tough-cookie",
|
||||
"child_process",
|
||||
"fs",
|
||||
"path",
|
||||
|
||||
Reference in New Issue
Block a user