mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-26 09:52:11 +03:00
Release v3.8.21 (#3593)
* chore(release): open v3.8.21 development cycle
* fix: pass through valid max_tokens-truncated responses instead of fake 502 (#3572) (#3595)
* fix: /v1/completions returns legacy text-completion format, not chat (#3571) (#3596)
* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (#3580) (#3597)
* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (#3498) (#3599)
* fix(agent-bridge): add validate-only upstream-ca/test route (#3488) (#3600)
* fix(gamification): add level/badges/badges-earned profile routes (#3484)
* security(oauth): migrate 5 public client_ids to resolvePublicCred (#3493)
* fix(mcp): ship MCP server source closure in npm files + coverage gate (#3578)
* fix: add reasoning token buffer for combo routing (fixes #3587) (#3588)
Integrated into release/v3.8.21
* Refactor: Extract chatCore phases into modular files (#3598)
Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!
* docs(changelog): credit #3598 (chatCore modularization) + #3588 (combo reasoning buffer)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (#3496) (#3602)
Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
* fix(gemini): isolate textual reasoning wrappers (#3605)
Split-out PR C from #3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the #3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!
* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (#3603)
Split-out PR A from #3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!
* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (#3606) (#3608)
Integrated into release/v3.8.21 (#3606)
* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (#3589) (#3609)
Integrated into release/v3.8.21 (#3589)
* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (#3419) (#3613)
Integrated into release/v3.8.21 (#3419)
* fix(usage): normalize Antigravity and agy provider quotas (#3604)
Split-out PR B from #3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!
* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (#3331) (#3614)
Integrated into release/v3.8.21 (#3331)
* docs(changelog): credit #3603 (Flash tier IDs) + #3604 (provider quotas) + #3605 (reasoning wrappers)
Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (#3618)
Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 797de433f.
* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync
---------
Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
This commit is contained in:
committed by
GitHub
parent
4bfd9e2845
commit
c315a2394c
@@ -50,17 +50,14 @@ function isFileRef(p) {
|
||||
// o path na doc, ou remover a menção. NÃO adicione novas aqui sem justificativa — esse
|
||||
// é o ponto do gate. Issues de tracking devem ser abertas para cada cluster.
|
||||
export const KNOWN_STALE_DOC_REFS = new Set([
|
||||
// docs/reference/API_REFERENCE.md — guardrails/shadow entries fixed in separate issues:
|
||||
"/api/guardrails", // sem dir de API guardrails (feature server-side, sem rota REST) — #3496
|
||||
"/api/guardrails/[id]/disable",
|
||||
"/api/guardrails/[id]/enable",
|
||||
"/api/guardrails/logs",
|
||||
"/api/guardrails/test",
|
||||
"/api/shadow", // sem dir de API shadow (shadow routing não tem rota REST) — #3498
|
||||
"/api/shadow/[id]",
|
||||
"/api/shadow/[id]/results",
|
||||
"/api/shadow/metrics",
|
||||
// docs/research/DISCOVERY_TOOL_DESIGN.md — design doc de feature NÃO implementada: — #3498
|
||||
// docs/reference/API_REFERENCE.md — guardrails/shadow doc-fiction RESOLVED in #3496:
|
||||
// GET /api/guardrails + POST /api/guardrails/test are now REAL routes (wrapping the
|
||||
// existing guardrailRegistry); the fictional enable/disable/logs rows and the entire
|
||||
// shadow table were removed from the doc (shadow A-B comparison is combo-config +
|
||||
// /api/combos/metrics). No allowlist entries needed for these anymore.
|
||||
// docs/research/DISCOVERY_TOOL_DESIGN.md — design doc de feature NÃO implementada
|
||||
// (Phase 2). Refs INTENCIONAIS: o doc agora traz um banner "⚠️ Not yet implemented
|
||||
// — Phase 2" acima da tabela de endpoints. Mantidos aqui até a feature existir. — #3498
|
||||
"/api/discovery/results",
|
||||
"/api/discovery/results/:id",
|
||||
"/api/discovery/scan",
|
||||
|
||||
@@ -24,11 +24,7 @@ const IGNORE = [
|
||||
// inventada. CADA UM precisa de triagem: criar a rota, corrigir o path, ou remover a
|
||||
// chamada morta. NÃO adicione novos aqui sem justificativa — esse é o ponto do gate.
|
||||
const KNOWN_MISSING = new Set([
|
||||
"/api/gamification/level", // profile/page.tsx — rota inexistente (gamification tem transfer/leaderboard/… mas não level)
|
||||
"/api/gamification/badges", // profile/page.tsx — idem
|
||||
"/api/gamification/badges/earned", // profile/page.tsx — idem
|
||||
"/api/settings/obsidian/webdav", // ObsidianSourceCard.tsx — só existe /api/settings/obsidian
|
||||
"/api/tools/agent-bridge/upstream-ca/test", // UpstreamCaField.tsx — rota inexistente
|
||||
]);
|
||||
|
||||
function walk(dir, acc = []) {
|
||||
|
||||
@@ -52,25 +52,12 @@ const ENV_KEY_RE = /(clientId|clientSecret|apiKey)Env\s*:/;
|
||||
// arquivos, então congelar por valor cobre ambas as cópias). Para congelar um valor
|
||||
// só num arquivo:linha específico, use a chave "arquivo:linha:valor".
|
||||
//
|
||||
// Tracking: estes 5 valores (9 call-sites) devem virar uma issue de segurança e
|
||||
// migrar para resolvePublicCred() — Gemini/Antigravity já seguem o padrão correto.
|
||||
export const KNOWN_LITERAL_CREDS = new Set([
|
||||
// Claude — CLAUDE_OAUTH_CLIENT_ID (public, PKCE auth-code flow)
|
||||
// providerRegistry.ts:659 + oauth.ts:37
|
||||
"9d1c250a-e61b-44d9-88ed-5944d1962f5e",
|
||||
// Codex (OpenAI) — CODEX_OAUTH_CLIENT_ID (public, PKCE)
|
||||
// providerRegistry.ts:831 + oauth.ts:54
|
||||
"app_EMoamEEZ73f0CkXaXp7hrann",
|
||||
// Qwen — QWEN_OAUTH_CLIENT_ID (public, device-code + PKCE)
|
||||
// providerRegistry.ts:925 + oauth.ts:101
|
||||
"f0304373b74a44d2b584a3fb70ca9e56",
|
||||
// Kimi Coding — KIMI_CODING_OAUTH_CLIENT_ID (public, device-code)
|
||||
// providerRegistry.ts:1961 + oauth.ts:136
|
||||
"17e5f671-d194-4dfb-9706-5516cb48c098",
|
||||
// GitHub Copilot — GITHUB_OAUTH_CLIENT_ID (public, device-code)
|
||||
// oauth.ts:238
|
||||
"Iv1.b507a08c87ecfe98",
|
||||
]);
|
||||
// All five public client_ids (9 call-sites) were migrated to resolvePublicCred() in
|
||||
// #3493 (embedded as claude_id/codex_id/qwen_id/kimi_id/github_copilot_id in
|
||||
// open-sse/utils/publicCreds.ts), matching the Gemini/Antigravity pattern. The
|
||||
// allowlist is now empty — any new literal public client_id must be embedded via
|
||||
// resolvePublicCred(), not frozen here.
|
||||
export const KNOWN_LITERAL_CREDS = new Set([]);
|
||||
|
||||
/**
|
||||
* Encontra atribuições de uma chave de credencial a uma string literal não-vazia.
|
||||
|
||||
Reference in New Issue
Block a user