Commit Graph

876 Commits

Author SHA1 Message Date
diegosouzapw
fec6164e92 fix(security): resolve CodeQL alerts #243/#244/#245
#243 (js/request-forgery, high) — providers/bulk/route.ts
- Replace `fetch(\${origin}/api/providers/validate)` (where origin came from
  spoofable `new URL(request.url).origin`) with a direct in-process call to
  validateProviderApiKey. Eliminates the SSRF vector and the HTTP round-trip
  through the same app.
- Resolve proxy once outside the loop and reuse via runWithProxyContext.
- Drop now-unused passthroughAuthHeaders helper.

#244 (js/resource-exhaustion, warn) — copilot-web.ts::solveHashcash
- Clamp upstream-supplied `difficulty` to [1, 8] before `"0".repeat(difficulty)`
  so a malicious/buggy server can't force a huge prefix allocation or push the
  10M-iteration loop into effectively unbounded work.

#245 (js/insufficient-password-hash, warn) — copilot-web.ts::getSession
- Dedupe the inline `createHash("sha256").update(accessToken)` call by reusing
  the existing sessionPoolKey helper.
- Rename its parameter from `accessToken` to `token` and document that the
  input is a high-entropy OAuth bearer used only as an in-memory Map key —
  bcrypt/scrypt/argon2 would be incorrect here, and SHA-256:16 is an
  appropriate fingerprint per docs/security/PUBLIC_CREDS.md.

Tests
- Export solveHashcash and add unit tests asserting it returns null for
  out-of-range / non-integer difficulty and produces a numeric nonce for the
  common difficulty=1 case.
- All 26 tests in copilot-web-executor.test.ts and providers-bulk-route.test.ts
  continue to pass; sessionPoolKey contract (SHA-256:16) preserved.
2026-05-18 23:27:34 -03:00
Diego Rodrigues de Sa e Souza
fa3ee31f06 fix(dashboard): address PR #2384 follow-up review issues (#2389)
- BudgetTab: compute projectionOverBudget per key (HIGH)
- ProviderLimits: convert outer button to div role=button to fix invalid HTML nesting
- Runtime: externalize all strings via next-intl (runtime namespace)
- QuotaShare: externalize all strings via next-intl (quotaShare namespace)
- Add /api/usage/budget/bulk endpoint and switch BudgetTab to single fetch (avoid N+1)

Co-authored-by: diegosouzapw <diego.souza.pw@gmail.com>
2026-05-18 22:52:13 -03:00
diegosouzapw
c9dc205c74 fix(ci): add Zod validation to cli-tools routes and refresh i18n translations for CLAUDE.md
Adds `.safeParse()` to cli-tools/apply and cli-tools/config POST handlers to
satisfy the check:route-validation:t06 CI gate. Regenerates all 41 locale
translations of CLAUDE.md to clear the i18n strict-drift check failure.
2026-05-18 19:19:30 -03:00
Diego Rodrigues de Sa e Souza
eb83eaf25f refactor(dashboard): nav, providers, endpoint, runtime, quota, pricing, budget redesign + quota sharing preview (#2384)
* refactor(dashboard): sidebar subtitles, providers UX, monaco self-host

Sidebar:
- Add subtitleKey to all ~50 menu items so every entry shows a short
  description line (previously only 7 had subtitles).
- Inject 50 new sidebar.*Subtitle keys across all 42 i18n locales
  (en/pt-BR translated; remaining locales fall back to English).
- Fix DATA_÷IC glitch: replace invalid Material Symbols icon
  "data_compression" with "compress" on analytics-compression.
- Rename "Compression Combos" -> "Engine Combos" to avoid truncation
  and disambiguate from the OmniProxy Combos item.

Auto-routing banner:
- Move AutoRoutingBanner from DashboardLayout (rendered on every page)
  to /home only, so it no longer follows the user across the dashboard.

Monaco editor:
- Add shared MonacoEditor wrapper that calls loader.config({ monaco })
  to load Monaco from the bundled monaco-editor package instead of the
  jsdelivr CDN (blocked by CSP script-src 'self'), fixing the
  "Monaco initialization: error" runtime error.
- Migrate the 5 direct dynamic imports of @monaco-editor/react to the
  wrapper (playground, search-tools, translator).

Providers page UX:
- Replace the static legend + 4-stat divider + duplicate filter chips
  with a single row of clickable category pills with embedded counters
  (All, Free, OAuth, API Key, IDE, Compatible, Web Cookie, Search,
  Audio, Local, Cloud Agent).
- Remove redundant per-section Free only / Configured only toggles and
  the Zed Import button from the OAuth section header.
- Introduce a dedicated "IDE Providers" section (Cursor, Zed, Trae)
  rendered under OAuth Providers; exclude IDE_PROVIDER_IDS from OAuth
  to avoid duplication.
- Add zed and trae providers, plus IDE_PROVIDER_IDS set.
- Move the Zed keychain import to /dashboard/providers/zed as a
  contextual Card, instead of cluttering every OAuth section header.
- Extend test-batch route and validation schema with mode: "ide".

* feat(dashboard): add token saver controls to endpoint and context pages

Expose the Token Saver master settings from the endpoint page and
surface its disabled state across the Caveman and RTK context pages.

Update default compression behavior to start disabled with lighter
intensity presets, and add Caveman input compression controls so users
can configure input and output modes separately.

Tighten provider page section rendering by gating compatible, free,
oauth, and api key blocks behind their visibility checks and simplify
several summary labels.

* feat(dashboard): add runtime page and rename limits to quota

Introduce a dedicated runtime observability page for circuit
breakers, cooldowns, lockouts, sessions, and quota alerts.

Split provider quota out of the old limits route, add a redirect from
`/dashboard/limits` to `/dashboard/quota`, and update sidebar/header
labels and i18n keys to match the new navigation.

Enhance provider quota filtering state and remove the tier coverage
widget from the dashboard home view.

* feat(dashboard): redesign budget page and add quota sharing preview

Budget (/dashboard/costs/budget) gets a full rewrite:
- Hero with 6 KPIs (today, month, projected EOM, blocked, at-risk, active)
- Status pills with counts (blocked/alerting/warning/safe/no-limit)
- Templates row (localStorage) with bulk-apply to selected keys
- Multi-key table with checkbox selection and colored progress bar
- Expandable rows with projection card and per-provider cost breakdown
  (last 30d via /api/usage/analytics?apiKeyIds=) plus inline edit form

Quota sharing (/dashboard/costs/quota-share) is new and ships as a beta
UI preview backed by localStorage. Pool persistence in the DB and
request-pipeline enforcement are intentionally deferred to a follow-up.
The page lets operators:
- Create pools from a provider connection + quota window
- Edit allocations per API key with % split and equal-split helper
- Toggle hard/soft/burst policy intent
Donut chart rendered with inline SVG; allocation editor in a modal.

Sidebar gets the new "Quota Sharing" entry under Costs Parameters; i18n
keys propagated across all 41 locales with PT-BR translation.

---------

Co-authored-by: diegosouzapw <diego.souza.pw@gmail.com>
2026-05-18 18:53:00 -03:00
diegosouzapw
04d44f6262 fix(security): sanitize error messages, fix ReDoS patterns, harden OAuth callback
Error message sanitization (Hard Rule #12):
- claude-auth/export, codex-auth/export, gemini-cli-auth/export routes: replace
  raw err.message with sanitizeErrorMessage() from open-sse/utils/error.ts
- imageGeneration, musicGeneration, videoGeneration handlers: import
  sanitizeErrorMessage and replace all err.message in return values
- veoaifree-web executor: replace raw upstream response data in errResp() calls
  with static strings

OAuth callback page (callback/page.tsx):
- Remove useSearchParams/Suspense dependency that caused hydration failures in
  popup windows navigating back from Google OAuth (COOP header severs opener)
- Use window.location.search directly in useEffect with three send methods:
  postMessage, BroadcastChannel, localStorage
- Fix postMessage target from "*" to window.location.origin (semgrep finding)
- Move setCurrentUrl call to manual-only branch to avoid unnecessary renders

copilot-web executor:
- Move accessToken from WebSocket URL query string to Authorization header
  (avoids credential exposure in server logs)
- Add MAX_POOL_SIZE=100 cap to sessionPool with LRU eviction of oldest entry

CodeQL ReDoS fixes (js/polynomial-redos #233-240):
- Replace while(s.endsWith("/")) s=s.slice(0,-1) pattern (O(n²) allocations)
  with index-based loop (O(n) time, single final slice) in:
  bin/cli/api.mjs, all 6 cli-helper config generators, opencode-provider

Gemini OAuth:
- mapTokens: add idToken field to fix "missing id_token" export error
2026-05-18 17:42:09 -03:00
diegosouzapw
5ce3f7f4d6 chore: merge release/v3.8.0 into PR branch 2026-05-18 15:48:43 -03:00
diegosouzapw
f2e368830a fix(combo): guard target.modelStr against non-string before .startsWith (#2359)
Combo dispatch and the combo test button used to crash with
'TypeError: e.startsWith is not a function' when a step's modelStr
failed to resolve (regression after #2338 added per-account LKGP
routing for local/Docker providers). The TypeScript annotation says
the field is always a string, but malformed combo rows leaked through
to the dispatch path.

Two defensive boundary guards:

1. open-sse/services/combo.ts LKGP fallback findIndex — type-check
   target.modelStr before calling startsWith.

2. src/app/api/combos/test/route.ts testComboTarget — coerce
   target.modelStr at the entry, surface a clean 'Combo step is
   missing a model id' error instead of crashing.

Regression test parses the source and asserts no unguarded
target.modelStr.<string-method> usages remain in combo.ts, so a
future refactor that reintroduces the pattern fails loudly.
2026-05-18 10:56:27 -03:00
Mrinal Joshi
400dbc386a fix(claude-oauth): enable system-transforms pipeline for native claude executor
The native claude OAuth path (base.ts:794 applySystemTransformPipeline)
early-exited because DEFAULT_SYSTEM_TRANSFORMS_CONFIG.providers[claude]
was {enabled:false, pipeline:[]}. Result: third-party-agent fingerprints
(github.com/anomalyco/opencode, 'You are OpenCode', 'Here is some useful
information about the environment...') leaked into /v1/messages system
blocks, triggering Anthropic billing-gate:
  [400] Third-party apps now draw from extra usage, not plan limits.

Mirror the cc-bridge defaults:
- DEFAULT_PARAGRAPH_REMOVAL_ANCHORS + OPENWEBUI_PARAGRAPH_ANCHORS
- DEFAULT_IDENTITY_PREFIXES   + OPENWEBUI_IDENTITY_PREFIXES
- DEFAULT_TEXT_REPLACEMENTS as replace_text ops (allOccurrences:true)
- obfuscate_words

Omit prepend_system_block + inject_billing_header — base.ts:759-784
already handles those on the native claude OAuth path.

UI mirror RoutingTab.tsx and snapshot in system-transforms.test.ts
updated for parity. 56/56 transform-related tests pass.

Verified end-to-end 2026-05-18 after npm run build:cli + restart:
- request v8tq04 -> 200 in 1.84s
- request shape {max_tokens:32000, reasoning_effort:high} -> 200 in 1.99s
- x-omniroute-provider=cc (claude-code OAuth pool, account 62875e01)
- telemetry: [SystemTransforms] claude-native: drop_paragraph_if_contains,
  drop_paragraph_if_starts_with, replace_text, replace_text, obfuscate_words
2026-05-18 13:25:30 +01:00
diegosouzapw
2bbd0fff45 Merge feat/gemini-auth-ui (PR3 Gemini) into release/v3.8.0
# Conflicts:
#	src/app/(dashboard)/dashboard/providers/[id]/page.tsx
#	src/i18n/messages/en.json
2026-05-18 03:21:56 -03:00
diegosouzapw
1dae73cfef Merge feat/gemini-auth-api-routes (PR2 Gemini) into release/v3.8.0
# Conflicts:
#	src/shared/validation/schemas.ts
2026-05-18 03:01:51 -03:00
diegosouzapw
b3cb5b68d8 feat(dashboard): add Gemini CLI auth import/export UI + i18n (PR3) 2026-05-18 02:43:15 -03:00
diegosouzapw
75c1d2ead2 feat(dashboard): add Claude Code auth import/export UI + i18n (PR3) 2026-05-18 02:26:08 -03:00
diegosouzapw
877aafdb99 feat(api): add Gemini CLI auth import/export API routes + schemas (PR2) 2026-05-18 01:46:07 -03:00
diegosouzapw
3786e929d6 feat(api): add Claude Code auth import/export API routes + schemas (PR2) 2026-05-18 01:45:54 -03:00
Michael
b191173ae1 Fix Providers empty state blocking first provider setup 2026-05-17 19:47:42 -03:00
backryun
1f27c344d4 chore: improve huggingface provider support (#2322)
Integrated into release/v3.8.0 — migrates HuggingFace to router.huggingface.co/v1 endpoint, adds dynamic model discovery, refreshes ASR/TTS catalog
2026-05-17 19:44:53 -03:00
Diego Rodrigues de Sa e Souza
891a9e4125 Merge pull request #2337 from diegosouzapw/worktree-fix+providers-missing-button-i18n
fix(providers): fix missing i18n keys and add 'Add Provider' button to empty state
2026-05-17 17:51:43 -03:00
diegosouzapw
3748b0238d chore(merge): resolve conflicts for bulk import — keep both schemas and all i18n keys 2026-05-17 17:28:41 -03:00
diegosouzapw
3227c9ffe3 chore(merge): resolve page.tsx conflict — keep ImportCodexAuthModal and ApplyCodexAuthModal 2026-05-17 17:13:50 -03:00
diegosouzapw
25f3fe1ac5 feat(codex): bulk import Codex auth.json — multi-file, paste, ZIP
Adds three input modes for importing multiple Codex accounts at once,
all feeding a single partial-failure backend endpoint.

- `codexAuthZipExtract.ts`: safe ZIP extraction via fflate — rejects
  path traversal (../ and absolute paths), per-file 256 KB cap, 10 MB
  total cap, max 50 .json entries
- `POST /api/providers/codex-auth/zip-extract`: server-side ZIP
  extraction returning [{name, json, parseError}] to the client
- `POST /api/providers/codex-auth/import-bulk`: iterates entries,
  partial-failure semantics (always 200), per-entry audit log
  `provider.credentials.imported` + summary `bulk_imported`
- `importCodexAuthBulkSchema`: max 50 entries, email validation
- `<ImportCodexAuthModal>`: Single/Bulk top tabs; Bulk has Upload
  files, Paste list (JSON array or --- separator), ZIP sub-modes;
  live entry preview list; overwrite checkbox; result panel
- Install `fflate@0.8.3` (pure TypeScript, zero native deps)
- 29 unit tests: 12 ZIP safety cases + 17 schema/parser/shape cases
2026-05-17 16:52:43 -03:00
diegosouzapw
8a6d681c15 feat(codex): import single Codex auth.json as OAuth connection
Adds an import flow that lets users bring an existing Codex auth.json
into OmniRoute without a fresh OAuth login. Both a file-upload tab and
a paste-JSON tab are supported.

- `codexAuthImport.ts`: pure parser + createConnectionFromAuthFile
  (conflict detection, overwriteExisting, JWT email/exp extraction)
- `POST /api/providers/codex-auth/import`: Zod-validated endpoint with
  audit log (`provider.credentials.imported`)
- `importCodexAuthSchema` in schemas.ts (discriminated union json/text,
  256 KB cap on paste source)
- `<ImportCodexAuthModal>` in providers/[id]/page.tsx with upload/paste
  tabs, email auto-detection, name/email/overwrite fields
- "Import auth" toolbar button shown only on the Codex provider page
- 29 unit tests (17 parser + 12 schema) — all passing
2026-05-17 14:04:48 -03:00
diegosouzapw
de5434a0a6 fix(providers): fix missing i18n keys and add 'Add Provider' button to empty state
- Add addFirstProvider, addFirstProviderDesc, learnMore to providers namespace in en.json
  (keys existed only in common namespace, causing raw key display on fresh installs)
- Add primary 'Add Provider' button to empty state that reveals provider grid
  (only 'Learn more' external link existed, leaving users with no way to add a provider)
- Remove || fallback strings now that i18n keys are correctly placed
2026-05-17 13:53:06 -03:00
diegosouzapw
634f50a04e feat(codex-auth): rename export to auth-{email}.json and gate Apply Local behind confirmation modal
Export filename change:
- Drop the redundant `codex-` prefix; embed the account email so multiple
  exported files can coexist in the same downloads folder.
- Email is extracted from the id_token JWT `email` claim, with fallback
  to connection.email and finally to the sanitized connection label.
- sanitizeFileNamePart now preserves @ so addresses survive intact
  (e.g. `auth-diego@example.com.json`).

Apply Local refinement:
- ApplyCodexAuthModal: confirmation modal showing the resolved target
  path, the side-by-side .bak location, and the centralized backup
  trail. User must tick a confirmation checkbox before Apply enables.
- writeCodexAuthFileToLocalCli now writes a side-by-side
  `auth-<timestamp>.bak` inside the .codex/ directory before replacing
  the live file, in addition to the existing centralized backup. Both
  inputs to the .bak path are server-controlled (dirname from the
  static CLI_TOOLS table; basename from a server-generated ISO
  timestamp), so no user input touches path APIs.
- apply-local route now emits a `provider.credentials.applied` audit
  event with the resolved authPath and savedBakPath, and routes all
  errors through sanitizeErrorMessage() per the security guide.

Tests: tests/unit/codexAuthFile.test.ts covers sanitization, JWT email
extraction, filename format for both branches (email/label), and the
ISO-timestamp .bak basename safety.

Scope: this is PR1 of the import/export work tracked under
_tasks/features-v3.8.0/importexport/. PR2 (import single) and PR3
(import bulk) will follow.
2026-05-17 13:32:29 -03:00
diegosouzapw
fc9f8d91f7 feat(providers): bulk add API keys with Single/Bulk tabs
Mirrors the 9router UX (one textarea, name|apiKey per line) but goes
further: dedicated server-side endpoint with Zod validation, partial-
failure semantics, audit log, and provider whitelist.

UI (src/app/(dashboard)/dashboard/providers/[id]/page.tsx):
- AddApiKeyModal now switches between Single (existing behaviour) and
  Bulk Add via tab strip. Tabs hide for providers that don't support
  bulk (Vertex, web-session, OAuth, multi-field).
- Bulk pane: textarea, shared Priority + "validate each key" checkbox,
  result panel with per-line errors (truncated at 10).

Backend:
- POST /api/providers/bulk: iterates entries through createProviderConnection
  with the same provider-specific normalization as the single endpoint.
  Returns {success, failed, total, created, errors[]}. Optional pre-save
  validation via /api/providers/validate when validateKeys=true. Each
  entry succeeds/fails independently — no transaction rollback.
- Bulk audit event logged once per request plus per-entry success events.

Schemas:
- bulkCreateProviderSchema (src/shared/validation/schemas.ts): max 200
  entries, mandatory name+apiKey per entry, google-pse-search cx guard.
- supportsBulkApiKey() helper (src/shared/constants/providers.ts) with
  explicit deny-list for OAuth/web-session/multi-field providers.

Parser:
- parseBulkApiKeys() (src/shared/utils/bulkApiKeyParser.ts) handles
  CRLF, # comments, blank lines, pipe inside apiKey, empty-name fallback,
  and caps input at BULK_API_KEY_MAX_LINES (200) with a warning.

Tests:
- tests/unit/bulkApiKeyParser.test.ts: 12 cases (format, edge cases, cap)
- tests/unit/providers-bulk-route.test.ts: 12 cases (schema, whitelist,
  response shape, apiKey leak guard)

i18n:
- en.json: bulkTabSingle, bulkTabBulkAdd, bulkAddFormatHint,
  bulkValidateKeys, bulkAddAllKeys, bulkAddedCount, bulkFailedCount,
  adding
2026-05-17 11:30:49 -03:00
diegosouzapw
440ca8e3cc Merge pull request #2314 from oyi77/feat/gitlawb-opengateway
feat: gitlawb opengateway provider + providers page filter chips

Three independent contributions from oyi77 bundled in this PR:

1. Gitlawb Opengateway provider (b83d1a0fc):
   - gitlawb (alias glb) — xiaomi-mimo endpoint with 5 MiMo models
   - gitlawb-gmi (alias glb-gmi) — gmi-cloud endpoint with 40+ models
   - Both flagged free tier, CLI-mimicking headers to avoid upstream
     rate limiting
   - 9 unit tests in tests/unit/gitlawb-provider.test.ts (all green)

2. hasFree flag (d7dcd233a): friendliai, chutes, featherless-ai now
   correctly surface free tier badge in the providers page.

3. UI additions (debf7cb28):
   - CollapsibleSection.tsx (coexists with our existing Collapsible.tsx —
     different API for different use cases)
   - Category filter chips bar on /dashboard/providers (auto-merged)
   - Free-only toggle on /dashboard/providers (auto-merged)
   - Extended filterConfiguredProviderEntries with showFreeOnly param
   - i18n tooltip keys for Caveman/RTK settings (union with our
     simpleMode/advancedMode/filterCatalog keys)
   - InfoTooltip + PresetSlider identical to PR #2316 versions
     (silent dedup by auto-merge)

Conflict resolution:
- src/shared/components/index.tsx: union — added CollapsibleSection
  export alongside our NoAuthProviderCard.
- src/i18n/messages/en.json: union — kept all our keys from #2316
  (simpleMode/advancedMode/filterCatalog/filterCatalogDesc) and added
  PR's tooltip keys (searchFilters, tooltipDedup, tooltipMaxChars,
  tooltipMaxLines, tooltipAutoTrigger, tooltipCompressionRate,
  tooltipMaxTokens, tooltipMinLength, tooltipMinSavings, ultraSettings,
  ultraSettingsDesc).

Closes #2314
2026-05-17 02:37:05 -03:00
diegosouzapw
43d4ea092c Merge pull request #2316 from oyi77/feat/ui-rework
feat(ui): simple/advanced mode for Caveman & RTK + newbie UX improvements

Adapts oyi77's UX rework on top of our refactor/pages overhaul. Layout
priority: our 9-section sidebar restructure stays; PR's additions
(subtitles, intros, simple/advanced toggles, empty states, error labels)
are integrated into our structure.

Conflict resolution:

- index.tsx: union — exports InfoTooltip, PresetSlider (new shared
  components from PR) alongside our NoAuthProviderCard.
- en.json: union — kept our "OmniSkills"/"AgentSkills" labels and
  "API Key Manager" naming; added PR's subtitleKey strings, settings
  intro keys, and empty state keys.
- sidebarVisibility.ts: kept our 9-section structure; added subtitleKey?:
  string to SidebarItemDefinition and mapped subtitle keys onto the 7
  matching items (endpoints, api-manager, combos, batch, context-caveman,
  context-rtk, webhooks).
- Sidebar.tsx: kept our collapsible-section rendering; integrated PR's
  subtitle support into resolveItem() and renderNavLink() label area.
- CavemanContextPageClient.tsx: took PR's version — adds SegmentedControl
  for simple/advanced mode (gates full settings tab in advanced).
- RtkContextPageClient.tsx: took PR's version — adds SegmentedControl +
  Collapsible filter catalog.
- settings/page.tsx: kept our redirect (we converted tabs→pages). Ported
  PR's intro text paragraphs to /settings/ai, /settings/routing, and
  /settings/resilience subpages using the auto-merged i18n keys.
- HomePageClient.tsx: kept ours — we removed Providers Overview card in
  the refactor, and PR's empty state for that card is now redundant.
  PR's equivalent empty state at /dashboard/providers (in
  providers/page.tsx) auto-merged cleanly and serves the same purpose.

Closes #2316
2026-05-17 02:13:22 -03:00
diegosouzapw
317d146302 Merge release/v3.8.0 into refactor/pages
Resolves conflicts in 9 files to bring 181 commits from release/v3.8.0 into
the dashboard refactor branch ahead of merging back to release.

Layout strategy: our pages overhaul (tabs→pages, restructured sidebar,
removed redundant headers, OpenCode Free no-auth card) is the source of
truth. Release's functional additions are adapted into our layout.

Conflict resolution:

- package.json/package-lock.json: take release's deps (axios bump, CLI v4
  deps, tls-client-node/wreq-js move to optionalDependencies); re-add our
  @xyflow/react addition; regenerate lockfile.
- src/shared/constants/sidebarVisibility.ts: keep our 9-section restructure
  — release's new IDs (limits, media, cli-tools, agents, cloud-agents,
  memory, skills, agent-skills, context-*) are all already present in our
  groups.
- src/i18n/messages/en.json: auto-merge picked up all release's new keys
  (autoCatalog*, quotaCutoffs*, systemTransforms*, schema-coercion, vision);
  only naming conflict was OmniSkills/AgentSkills — kept ours (no space).
- src/app/(dashboard)/dashboard/HomePageClient.tsx: kept our Provider
  Topology card; ported release's TierCoverageWidget (placed before
  topology).
- src/app/(dashboard)/dashboard/settings/page.tsx: kept our redirect to
  /settings/general (we moved tabs to separate pages); release's sticky
  tab CSS change is moot in our structure.
- src/app/(dashboard)/dashboard/skills/page.tsx: rerere applied — release
  hardcoded "OmniSkills" h1 was already removed by our header-cleanup
  refactor.
- src/app/(dashboard)/dashboard/agent-skills/page.tsx: both branches
  created this file independently with identical data source; kept our
  Tailwind-themed 2-column grid (release's version used inline styles).
- src/app/(dashboard)/dashboard/batch/page.tsx: kept our single-tab
  structure (FilesListTab moved to /batch/files page); ported release's
  onRefresh prop addition.
- src/app/(dashboard)/dashboard/batch/files/page.tsx (not in conflict but
  updated): added batches fetch + batches prop to preserve release's
  feature of showing related batches in the file detail modal.

Pre-existing typecheck errors in open-sse/services/contextManager.ts
(lines 141, 154, 167) come from release/v3.8.0 and are not introduced by
this merge.
2026-05-17 01:14:21 -03:00
oyi77
a4a870cda3 feat(ui): add newbie-friendly UX improvements across dashboard
- Providers page: empty state with guided 'Add your first provider' card
- Providers page: home page shows only configured providers by default
- Settings: add intro text to Routing, Resilience, and AI tabs
- i18n: fix 'Api Key Mgmt' to 'API Key Management', remove duplicate key
- i18n: add keys for empty state, settings intros, free-only filter
2026-05-17 07:56:22 +07:00
backryun
926ff2b5db chore(providers): refresh provider metadata and ordering (#2318)
Integrated into release/v3.8.0 — refreshes provider model metadata, sorts dashboard provider entries by display name, and fixes docs generator relative links.
2026-05-16 21:48:01 -03:00
Raxxoor
5a7df8ac29 fix: harden stream readiness and build output (#2317)
Integrated into release/v3.8.0 — fixes stream readiness detection for OpenAI Responses API lifecycle events, GLM timeout, Provider Limits UI, and build output cleanup.
2026-05-16 21:47:40 -03:00
diegosouzapw
7fdcba9e05 fix(auth): return synthetic credentials for noAuth free providers
Requests to opencode (noAuth: true) were failing with "No credentials for
provider: opencode" because getProviderCredentials found no DB connections and
returned null — triggering the 400 error path in chatHelpers.

Inject a synthetic credential object (connectionId: "noauth", no apiKey/token)
before the regular connection lookup so the executor receives valid credentials
and skips the Authorization header. Also enable model import for noAuth providers
(canImportModels = true when isFreeNoAuth).
2026-05-16 21:31:03 -03:00
diegosouzapw
fd28e772a8 fix(dashboard): show no-auth card for free providers instead of OAuth modal
OpenCode Free (noAuth: true) was routed through OAuthModal which tried to call
a non-existent /api/oauth/opencode/authorize endpoint, resulting in a 500 error.

Detect noAuth free providers via FREE_PROVIDERS[id]?.noAuth and render a
NoAuthProviderCard (lock_open + description) instead of the connections section
with the "+ Add" button that triggered the broken flow.
2026-05-16 21:05:49 -03:00
oyi77
8a23c5527e feat(ui): replace cryptic error badges with human-readable labels
Replace AUTH/429/5XX/NET/RUNTIME with Auth/Rate limited/Server
error/Network/Runtime in provider error badges.
2026-05-17 05:58:41 +07:00
oyi77
3757e6dc30 feat(ui): add simple/advanced mode switch to RTK page
Simple mode shows stats, config, and collapsible filter catalog.
Advanced mode adds filter testing with raw JSON preview.
2026-05-17 05:38:04 +07:00
oyi77
801f3c9c22 feat(ui): add simple/advanced mode switch to Caveman page
Simple mode shows stats, language packs, and output mode only.
Advanced mode reveals the full CompressionSettingsTab with all
engine internals, thresholds, and tool strategies.
2026-05-17 05:35:41 +07:00
oyi77
debf7cb283 feat(ui): add shared components + providers page category filter
- Add CollapsibleSection, InfoTooltip, PresetSlider shared components
- Add category filter chips bar to providers page
- Add free-only toggle to providers page
- Extend filterConfiguredProviderEntries with showFreeOnly param
- Add i18n keys for Caveman/RTK tooltips and labels
2026-05-17 05:25:47 +07:00
diegosouzapw
56b0ea91c9 fix(endpoint): replace nested <button> with <div role=button> in tunnel toggle rows
Tailscale and ngrok expandable rows used <button> as outer container while also
containing inner <button> elements (copy URL, action buttons). Nested buttons are
invalid HTML and caused a React hydration error that prevented the app from
loading in the browser (stuck on Loading... spinner).
2026-05-16 17:46:50 -03:00
Markus Hartung
dae0501d75 fix: remove count from batch removal (#2309)
Integrated into release/v3.8.0
2026-05-16 17:39:50 -03:00
diegosouzapw
4913439d91 fix(dashboard): fix search icon alignment and widen search field in providers page
- Use Input's built-in icon prop so the search icon renders inside the correct
  positioned context (Input's internal div.relative) instead of misaligned outside
- Switch from className to inputClassName so padding applies to the actual <input>
  element, not the outer wrapper div
- Remove flex-1 spacer; make search container flex-1 so it fills available width
2026-05-16 17:21:55 -03:00
diegosouzapw
789a263967 feat(dashboard): provider summary card, free test btn, sidebar order, i18n fix
- sidebarVisibility: move endpoints before api-manager
- en.json: add freeTierProviders/Label/Desc + providerSummaryAll to providers namespace
- page.tsx: apply showConfiguredOnly filter to free tier section (was hardcoded false)
- page.tsx: replace search bar with summary Card containing:
    search (25%) + configured-only toggle + test-all button / dot legend / stats row
    stats show Total / Free / OAuth / API Key configured/total counts
- page.tsx: add batch test button to Free Tier Providers section header
- page.tsx: remove duplicate configured-only toggle from OAuth section header
- page.tsx: import Card component
2026-05-16 15:53:37 -03:00
diegosouzapw
f224b9f104 fix(dashboard): correct dot colors per provider type + search/legend bar
- ProviderCard: add cloud-agent dot (violet) to DOT_COLORS
- page.tsx: web-cookie/search/audio/cloud-agent/local/upstream-proxy
  sections now pass their actual type as authType instead of displayAuthType
  (which was always "apikey" for all static catalog groups)
- page.tsx: split search bar row into 25% input + 75% dot-type legend
  showing all 10 auth types with their colors and translated labels
2026-05-16 13:53:18 -03:00
diegosouzapw
b3b006b630 fix(dashboard): compact empty state, remove free badges, shrink toggle
- ProviderCard: remove Free Tier badge (dots already indicate type/free)
- ProviderCard: add dual-dot for providers with hasFree + paid authType
- ProviderCard: font-size xs for name, Toggle shrunk to size xs
- Toggle: add xs size variant (w-6 h-3 track, 8px thumb)
- page.tsx: compact Compatible Providers empty state (single inline line)
2026-05-16 12:25:02 -03:00
Mourad Maatoug
2af6923e6e fix(ui): v3.8.0 polish — connections border, sticky tabs, EN translations, save toasts, auto-combo catalog (#2305)
Integrated into release/v3.8.0
2026-05-16 12:06:12 -03:00
diegosouzapw
9ccb7b1c1e fix(dashboard,sse): correct opencode free provider and free section dot color
Add passthroughModels: true to the opencode registry entry so that unknown
model IDs trigger model lockout instead of connection cooldown. Fix dot color
for FREE_PROVIDERS in the Free Tier section by using toggleAuthType === "free"
to select the green dot instead of the blue oauth dot.
2026-05-16 12:01:31 -03:00
diegosouzapw
51918cb5d4 feat(dashboard): providers page — custom section to top, smaller cards, free tier section
Moves Compatible Providers to the top (before Expiration Banner) so users can
add custom OpenAI/Anthropic compatible providers without scrolling. Reduces
ProviderCard icon from 32px to 28px and increases grid density by one column at
each breakpoint (gap-4→gap-3). Adds a curated Free Tier Providers section with
27 providers (OAuth/noAuth group + API-key free-tier group), positioned between
Expiration Banner and OAuth Providers. Cards in the free section suppress the
hasFree badge since context makes it implicit.
2026-05-16 11:31:02 -03:00
diegosouzapw
367497958f feat(endpoints): grid layout for Available Endpoints card, add 4 missing endpoints
Layout change:
- Replace accordion (EndpointSection) with compact grid cards (EndpointCard)
  showing icon, title, model count badge, path, and copy URL in 2–4 columns
- All 17 endpoints now visible at once without expand/collapse

Missing endpoints added:
- /v1/messages — Anthropic Messages API native format (badge: Anthropic)
- /v1/images/edits — Image editing/inpainting (shares image models)
- /v1/batches — OpenAI-compatible Batch API (badge: OpenAI)
- /v1/files — Files API for batch job management

Counter fix:
- Remove hardcoded +2 hack; compute count precisely:
  chat×4 (chat/responses/completions/messages) + image×2 (gen+edits)
  + per-category media + 3 fixed utility (batch/files/list-models)
  + model-based utility + search

i18n: add messagesApi, imageEdits, batchApi, filesApi keys to endpoint namespace
2026-05-16 10:27:15 -03:00
diegosouzapw
124ed82f02 fix(api/combos): add API-key-safe GET /v1/combos endpoint (#2300)
The existing /api/combos GET requires a management token, which broke
read-only integrations (opencode-omniroute-auth plugin and similar) that
need to enrich combo capabilities from a normal Bearer API key. Those
clients got 403 AUTH_001 'Invalid management token' even though the same
API key could list models via /v1/models.

This adds GET /v1/combos with the same auth model as /v1/models:
- Accepts valid Bearer API key OR dashboard session cookie.
- Falls back to anonymous when REQUIRE_API_KEY=false (single-user local).
- Projects ONLY public metadata: name, strategy, description, model id,
  providerId, comboName (for combo-refs). Internal routing details
  (connectionId, weights, labels, sortOrder, config) are stripped.

/api/combos (management writes) is unchanged.
2026-05-16 10:14:06 -03:00
diegosouzapw
beb43a8bea feat(dashboard): add A2A audit page, stats bar on MCP audit, fix sidebar duplicates
- Add /dashboard/audit/a2a page with A2aAuditTab: lists tasks with skill/state
  filters, colored state badges, duration, events and artifacts counts
- Add "A2A Audit" item to Audit sidebar group (Monitoring section)
- Remove duplicate "MCP Audit" from MCP Server sidebar group — it stays
  only in the Audit group under Monitoring
- Improve McpAuditTab: fetch /api/mcp/audit/stats and show 4-card stat bar
  (calls 24h, success rate, avg duration, top tool) above the filters
- Add audit-a2a to HIDEABLE_SIDEBAR_ITEM_IDS
- Add i18n keys: auditA2a in sidebar + header sections, a2a* in compliance namespace
2026-05-16 09:57:40 -03:00
diegosouzapw
06bdc31a50 refactor(dashboard): rename MCP/A2A pages to *Server, wrap headers in Card, add MCP sidebar group
- Rename sidebar/page titles: "mcp" → "MCP Server", "a2a" → "A2A Server" (en.json)
- Wrap top header section in <Card> on both MCP and A2A pages for consistent styling
- Remove redundant "hub MCP Server" / "group_work A2A Server" headings from page body
- Add MCP_GROUP collapsible sidebar group (MCP Server + MCP Audit) in Agentic Features
- Update AGENTIC_FEATURES_ITEMS type to SidebarSectionChild[] to support groups
2026-05-16 09:38:07 -03:00
diegosouzapw
6a51b96a47 refactor(dashboard): remove Integration Surface card, move Cloud OmniRoute to tunnels, inline quick-start
- Remove Integration Surface card (tab switcher + Protocols tab card)
- API endpoints list always visible (no tab toggle needed)
- Cloud OmniRoute moved to first position inside Tunnels accordion section
- Tunnels header always visible (was conditional on tunnel flags)
- Cloudflare row: no longer collapsible — flat row with inline notice/error
- Remove leading comma from LAN IP and Tailscale IP inline displays
- Remove Cloudflare URL notice text (always-shown description removed)
- Remove double border between Tunnels header and Cloud OmniRoute row
- ngrok authtoken label: "not set in environment" (was "not set")
- MCP page: description + 3-step quick start merged into header area
- A2A page: description + 3-step quick start merged into header area
2026-05-16 09:15:47 -03:00