Diego Rodrigues de Sa e Souza
98ebba1801
fix: restore Codex Responses WS TLS profile + apply proxy ( #5591 , #5611 ) ( #5668 )
2026-06-30 12:41:14 -03:00
Diego Rodrigues de Sa e Souza
7c23dab64d
Release v3.8.40
...
v3.8.40 cycle integration → main. All test gates green (Unit/Integration/Coverage/Node-compat/Quality-Ratchet). The only red check, 'PR Test Policy', is the test-masking heuristic firing on the cumulative ~57-commit release diff (legitimate assert consolidations already reviewed per-PR — Gemini CLI removal #5246 , retired GPT models #5280 , provider catalog refreshes); overridden with --admin per the documented release-PR convention. CodeQL/SonarQube advisory scans non-blocking; #5278 's code already passed CodeQL on main. Homologated on VPS 192.168.0.15 (v3.8.40 healthy).
2026-06-29 08:40:06 -03:00
Diego Rodrigues de Sa e Souza
9350a5d6c6
Release v3.8.22 ( #3623 )
...
* chore(release): open v3.8.22 development cycle
* refactor(dashboard): extract ProviderDetailPageClient — #3501 Phase 0 (#3633 )
#3501 Phase 0: extract ProviderDetailPageClient + smoke test.
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
* refactor(dashboard): extract auth-import modals — #3501 Phase 1a (#3634 )
#3501 Phase 1a: extract 3 auth-import modal clusters.
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
* fix(db): reclassify localDb unexported modules as intentionally-internal (#3499 ) (#3635 )
Closes #3499 — reclassify localDb unexported modules as intentionally-internal (audit + honest gate framing).
* refactor(db): move call_logs aggregations into callLogStats db module (#3500 ) (#3636 )
#3500 slice 1: call_logs aggregations → src/lib/db/callLogStats.ts (Rule #5 ). Byte-identical queries; TDD 6/6.
* refactor(dashboard): extract EditCompatibleNodeModal — #3501 Phase 1b (#3638 )
#3501 Phase 1b: extract EditCompatibleNodeModal (cycle-safe via leaf constants module).
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
* refactor(db): move community_servers SQL into gamification db module (#3500 slice 3) (#3639 )
#3500 slice 3: community_servers SQL → gamification db module.
* refactor(db): move usage_history SQL into usageAnalytics module (#3500 slice 2) (#3644 )
#3500 slice 2: usage_history/daily_usage_summary SQL → usageAnalytics db module.
* refactor(db): move skills UPDATE + db-backups SQL into db modules (#3500 slice 5) (#3647 )
#3500 slice 5: skills UPDATE (allowlist) + db-backups SQL → db modules.
* refactor(db): move usage_logs/semantic_cache/proxy_logs SQL into db modules (#3500 slice 4) (#3648 )
#3500 slice 4: usage_logs/semantic_cache/proxy_logs SQL → db modules. All internal routes done (2 external by-design remain).
* chore(db-gate): reclassify external-DB reads, fully close #3500 (#3649 )
Closes #3500 : reclassify external-DB reads; all internal raw-SQL migrated to db/ modules.
* refactor(dashboard): extract pure helpers to providerPageHelpers — #3501 Phase 2 (#3653 )
#3501 Phase 2: extract pure helpers to providerPageHelpers (leaf, cycle-safe).
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
* refactor(dashboard): extract remaining shared helpers to providerPageHelpers — #3501 Phase 2b (#3658 )
#3501 Phase 2b: extract remaining shared helpers to providerPageHelpers (leaf, cycle-safe). Heavy modals unblocked.
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
* fix(reasoning): replay reasoning_content on plain DeepSeek turns (#1682 ) (#3632 )
Integrated into release/v3.8.22
* fix(kiro): route enterprise IAM Identity Center accounts to their regional endpoint (#3631 )
Integrated into release/v3.8.22
* refactor: small code cleanup (#3523 )
Integrated into release/v3.8.22
* fix(combo): skip same-provider targets on 408/500/502/503/504/524 errors (#3637 )
Integrated into release/v3.8.22 — circuit-breaker guard added in review (#1731v2)
* feat(providers): add MiMoCode free-tier provider with bootstrap JWT auth (#3659 )
Integrated into release/v3.8.22 — page.tsx conflict resolved + NoAuthAccountCard re-applied to ProviderDetailPageClient in review. MiMoCode endpoint validated live.
* Log Responses WebSocket calls in history (#3616 )
Integrated into release/v3.8.22 — Codex Responses WebSocket call history logging.
* Add Claude Code routing preference for unprefixed Claude models (#3540 )
Integrated into release/v3.8.22 — page.tsx conflict resolved (re-applied toggle to ProviderDetailPageClient) + disable-test updated for catalog drift in review.
* docs(changelog): credit #3632/#3631/#3637/#3659/#3540/#3616/#3523 (v3.8.22 targeted review round)
* fix(mimocode): add required authHeader:"none" to registry entry (#3659 follow-up)
The mimocode RegistryEntry omitted the required authHeader field, which broke
typecheck:core (TS2741). Match the no-auth convention (authType:"none" + authHeader:"none")
used by veoaifree-web and other free providers. Follow-up to #3659 (@pizzav-xyz).
* fix(responses): detect stream readiness for tool-call-only and object-less chunks (#3612 ) (#3661 )
Closes #3612
* fix(mitm): remove duplicated 'Command failed:' error prefix (#3641 ) (#3662 )
Closes #3641
* fix(cli): honor HERMES_HOME for Hermes Agent config path (#3628 ) (#3663 )
Closes #3628
* fix(api): fetch live OpenCode model catalog for no-auth model picker (#3611 ) (#3664 )
Closes #3611
* fix(api): flag provider topology error state by current status, not stale history (#3619 ) (#3666 )
Closes #3619
* fix(electron): launch peer-stamping server-ws.mjs entrypoint to avoid 403 LOCAL_ONLY (#3386 ) (#3665 )
Closes #3386
* fix(dashboard): restore home topology live in-flight pulse (#3507 ) (#3667 )
Closes #3507
* fix(oauth): name Kiro/AWS auto-imported accounts and dedupe by profileArn (#3615 ) (#3671 )
Closes #3615
* fix(resilience): clear stale transient connection cooldowns on startup (#3625 ) (#3672 )
Closes #3625
* fix(i18n): use logical CSS direction utilities for sidebar and key overlays (RTL #3541 ) (#3670 )
Closes #3541
* fix(dashboard): honor auto-hide and switch to visible filter on passthrough Test-all (#3610 ) (#3669 )
Closes #3610
* refactor(dashboard): extract AddApiKeyModal + EditConnectionModal — #3501 Phase 1c (#3674 )
#3501 Phase 1c: extract AddApiKeyModal, EditConnectionModal, WebSessionCredentialGuide into components/; god-component 10,166->8,092 LOC. Reconciles the v3.8.22 file-size drift for this file.
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
* docs(changelog): reconcile v3.8.22 — credit #3621/#3622 + MiMoCode follow-up roll-up
* refactor(dashboard): extract ConnectionRow + ModelCompatPopover + SiliconFlowEndpointModal — #3501 Phase 1d (#3676 )
#3501 Phase 1d: god-component 8,092->6,838 LOC.
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
* feat(obsidian): add WebDAV config route + encrypt creds at rest (#3485 part 1) (#3677 )
Part 1 of #3485 . Adds /api/settings/obsidian/webdav (GET/POST/DELETE) wiring the ready obsidianSync lib, encrypts webdav password + obsidian token at rest, removes the duplicate UI block, drops the KNOWN_MISSING entry. WebDAV file server is part 2.
* feat(obsidian): add /api/v1/webdav file server for Obsidian vault sync (#3485 part 2) (#3678 )
Part 2 of #3485 . WebDAV server (PROPFIND/GET/PUT/DELETE/MKCOL/MOVE/OPTIONS) handled in the custom server layer (standalone-server-ws.mjs) since the App Router cannot export WebDAV methods. Basic-Auth (constant-time), path-traversal hardened, password decrypt ported from encryption.ts (parity-tested), DATA_DIR resolution parity-tested against dataPaths.ts. End-to-end Obsidian-over-Tailscale validation is a live VPS step (Rule #18 ).
* fix(combo): stop premature context compaction — real auto-combo windows + per-target compression limit (#3680 )
Integrated into release/v3.8.22
* feat(dashboard): deactivate/activate accounts from the quota overview (#3675 )
Integrated into release/v3.8.22
* fix(dashboard): close review gaps in bulk provider connection actions (#3271 follow-up) (#3673 )
Integrated into release/v3.8.22 — page.tsx conflict (god-component split #3501 ) resolved by re-applying the bulk-action deltas to ProviderDetailPageClient.tsx
* refactor(dashboard): extract useModelCompatState hook + model sections — #3501 Phase 1e (#3683 )
#3501 Phase 1e: extract useModelCompatState hook (unblocks the model sections) + ModelRow/PassthroughModelsSection/PassthroughModelRow/CustomModelsSection/CompatibleModelsSection. god-component 6,838->4,921 LOC.
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
* refactor(dashboard): extract useProviderConnections/Settings/Models hooks — #3501 Phase 1f (#3684 )
#3501 Phase 1f: god-component 4,948->4,062 LOC. Connection state+handlers, settings, and model metadata moved into hooks/.
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
* chore(release): v3.8.22 CHANGELOG + env-doc sync
- Set release date in CHANGELOG [3.8.22] to 2026-06-11
- Add HERMES_HOME to .env.example (from #3628/#3663)
- Add HERMES_HOME + OMNIROUTE_PREFER_CLAUDE_CODE_FOR_UNPREFIXED_CLAUDE_MODELS to ENVIRONMENT.md (#3628/#3540)
* docs(changelog): credit #3673 + #3675 — leninejunior bulk-actions + quota-toggle
---------
Co-authored-by: oyi77 <oyi77@users.noreply.github.com >
Co-authored-by: Abhishek Divekar <adivekar@utexas.edu >
Co-authored-by: NOXX - Commiter <artur1992123@mail.ru >
Co-authored-by: Nicolas Lorin <androw95220@gmail.com >
Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com >
Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com >
Co-authored-by: kkkayye <98376609+kkkayye@users.noreply.github.com >
Co-authored-by: Witroch4 <witalo_rocha@hotmail.com >
Co-authored-by: Lenine Júnior <lenine@engrene.com.br >
2026-06-11 18:52:29 -03:00
diegosouzapw
8086d2878b
fix(ws): codex Responses-over-WebSocket upgrade — clean handshake + bridge-secret auth
...
Two bugs made `wscat ws://host/v1/responses` fail with
"Transfer-Encoding can't be present with Content-Length":
1. authz/management policy 401'd the proxy's own internal authenticate/prepare
loopback call to /api/internal/codex-responses-ws (MANAGEMENT-classified, the
per-process bridge secret wasn't recognized one layer up). Added a tightly-scoped
carve-out: isValidWsBridgeRequest() honors a timing-safe sha256 match of
OMNIROUTE_WS_BRIDGE_SECRET (x-omniroute-ws-bridge-secret header) for that exact
internal path; the route still re-validates the secret. → auth now succeeds → 101.
2. On auth failure the proxy spread the internal fetch's response headers onto the
raw upgrade socket — a chunked Transfer-Encoding + Next CSP/route-class headers
collided with writeHttpError's Content-Length framing (and duplicated Content-Type
via a case-mismatched spread). writeHttpError now strips framing + pipeline/security
headers (case-insensitive), and the auth-fail callsite no longer forwards them.
Regression test: tests/unit/responses-ws-proxy-headers.test.mjs (exports writeHttpError;
asserts no TE+CL, single Content-Type, no CSP/route-class leak, safe headers forwarded).
2026-06-02 06:02:49 -03:00
t-way666
4a84ab9c1b
feat(termux): Android/Termux headless support ( #2273 )
...
- Move wreq-js and tls-client-node to optionalDependencies
- Lazy-load wreq-js WS proxy with graceful 503 when unavailable
- Auto-detect Android platform for headless mode (no browser open)
- Set GYP_DEFINES for better-sqlite3 build on Android/ARM
- Extended build timeout to 600s for ARM compilation
- Skip wreq-js binary fix on Android (unsupported platform)
- Platform warnings for unsupported features (WS proxy, TLS, Electron, MITM)
Co-authored-by: t-way666 <t-way666@users.noreply.github.com >
2026-05-15 03:29:18 -03:00
diegosouzapw
f3b944a55a
refactor(scripts): organize into build/dev/check/docs/i18n/ad-hoc subfolders
...
Reorganizes the 29 active scripts under scripts/ into purpose-driven
subfolders:
- scripts/build/ (11) — Build, install, publish, runtime env
- scripts/dev/ (13) — Dev servers, test runners, healthchecks
- scripts/check/ (10) — Lint/validation/coverage checks
- scripts/docs/ (2) — Docs index and provider reference generation
- scripts/i18n/ (+3) — Adds Python translation utilities (check/validate/autotranslate)
- scripts/ad-hoc/ (4) — One-shot maintenance utilities
Updates all references in package.json, electron/package.json,
.husky/pre-commit, .github/workflows/ci.yml, Dockerfile, src/,
tests/, scripts/ internal cross-imports, playwright.config.ts,
and English docs (CODEBASE_DOCUMENTATION, ENVIRONMENT, FEATURES,
RELEASE_CHECKLIST, COVERAGE_PLAN, ELECTRON_GUIDE, I18N, GEMINI).
Also patches scripts/build/pack-artifact-policy.ts so the npm pack
allowlist mirrors the new layout.
Validates with:
- npm run lint (exit 0 — pre-existing minified-bundle errors only)
- npm run typecheck:core (exit 0)
- npm run check:docs-all (exit 0)
- unit tests for moved scripts (57 tests pass)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-05-13 10:14:25 -03:00