Commit Graph

2619 Commits

Author SHA1 Message Date
diegosouzapw
cb489d155c Merge remote-tracking branch 'origin/release/v3.8.0' into feat/dynamic-linux-cert-paths
# Conflicts:
#	src/mitm/cert/install.ts
2026-05-10 18:35:52 -03:00
diegosouzapw
c061f347f2 chore: revert unrelated i18n CHANGELOG and any-budget changes
Removed bundled i18n CHANGELOG updates and check-t11-any-budget.mjs
budget regressions that are unrelated to the dynamic cert paths feature.
2026-05-10 18:35:26 -03:00
diegosouzapw
ed19e0f43e Merge branch 'feat/zero-config-auto-routing' into release/v3.8.0 2026-05-10 18:34:04 -03:00
diegosouzapw
dc8dc941e8 fix(analytics): precise SQL matching for auto/ prefix models
Replaced LIKE 'auto%' with (model = 'auto' OR model LIKE 'auto/%') to
prevent false matches from unrelated model names (e.g., 'autopilot-v2').
2026-05-10 18:33:29 -03:00
diegosouzapw
87dfbcca62 Merge remote-tracking branch 'origin/release/v3.8.0' into feat/zero-config-auto-routing
# Conflicts:
#	CHANGELOG.md
#	Dockerfile
#	docs/i18n/ar/CHANGELOG.md
#	docs/i18n/bg/CHANGELOG.md
#	docs/i18n/bn/CHANGELOG.md
#	docs/i18n/cs/CHANGELOG.md
#	docs/i18n/da/CHANGELOG.md
#	docs/i18n/de/CHANGELOG.md
#	docs/i18n/es/CHANGELOG.md
#	docs/i18n/fa/CHANGELOG.md
#	docs/i18n/fi/CHANGELOG.md
#	docs/i18n/fr/CHANGELOG.md
#	docs/i18n/gu/CHANGELOG.md
#	docs/i18n/he/CHANGELOG.md
#	docs/i18n/hi/CHANGELOG.md
#	docs/i18n/hu/CHANGELOG.md
#	docs/i18n/id/CHANGELOG.md
#	docs/i18n/it/CHANGELOG.md
#	docs/i18n/ja/CHANGELOG.md
#	docs/i18n/ko/CHANGELOG.md
#	docs/i18n/mr/CHANGELOG.md
#	docs/i18n/ms/CHANGELOG.md
#	docs/i18n/nl/CHANGELOG.md
#	docs/i18n/no/CHANGELOG.md
#	docs/i18n/phi/CHANGELOG.md
#	docs/i18n/pl/CHANGELOG.md
#	docs/i18n/pt-BR/CHANGELOG.md
#	docs/i18n/pt/CHANGELOG.md
#	docs/i18n/ro/CHANGELOG.md
#	docs/i18n/ru/CHANGELOG.md
#	docs/i18n/sk/CHANGELOG.md
#	docs/i18n/sv/CHANGELOG.md
#	docs/i18n/sw/CHANGELOG.md
#	docs/i18n/ta/CHANGELOG.md
#	docs/i18n/te/CHANGELOG.md
#	docs/i18n/th/CHANGELOG.md
#	docs/i18n/tr/CHANGELOG.md
#	docs/i18n/uk-UA/CHANGELOG.md
#	docs/i18n/ur/CHANGELOG.md
#	docs/i18n/vi/CHANGELOG.md
#	docs/i18n/zh-CN/CHANGELOG.md
#	open-sse/config/providerRegistry.ts
#	open-sse/handlers/chatCore.ts
#	open-sse/services/usage.ts
#	open-sse/utils/streamReadiness.ts
#	scripts/check-docs-sync.mjs
#	src/app/(dashboard)/dashboard/cache/media/MediaPageClient.tsx
#	src/app/(dashboard)/dashboard/providers/[id]/page.tsx
#	src/app/(dashboard)/dashboard/settings/components/ProxyTab.tsx
#	src/app/(dashboard)/dashboard/settings/components/RoutingTab.tsx
#	src/app/(dashboard)/dashboard/usage/components/ProviderLimits/utils.tsx
#	src/app/api/usage/analytics/route.ts
#	src/i18n/messages/zh-CN.json
#	src/lib/embeddings/service.ts
#	src/lib/usage/providerLimits.ts
#	src/mitm/cert/install.ts
#	src/shared/constants/providers.ts
#	src/sse/handlers/chat.ts
#	tests/unit/compression/rtk-code-stripper.test.ts
#	tests/unit/usage-service-hardening.test.ts
2026-05-10 18:33:20 -03:00
diegosouzapw
ec6456ba73 chore(release): align migration compatibility and packaged CLI runtime
Skip the superseded 041 session_account_affinity migration when
the canonical 050 file is present, and remap legacy migration
markers so upgraded databases do not replay the duplicate slot.

Also include the CLI entrypoints in packaged artifacts and extend
management-auth coverage across admin memory, pricing, routing,
provider validation, and usage endpoints to keep release bundles
runnable and sensitive operations protected.
2026-05-10 18:27:41 -03:00
eleata
e58aea9df7 feat(resilience): useUpstream429BreakerHints toggle (#2100 follow-up to #2116) (#2133)
Integrated into release/v3.8.0 — adds useUpstream429BreakerHints toggle with per-provider defaults for circuit breaker cooldown trust.
2026-05-10 18:27:24 -03:00
oyi77
fbb4dfaf37 fix(auto): address PR #2131 review issues
- Fix OAuth expiry handling for ISO strings in virtualFactory.ts
- Move AutoRoutingBanner test from src/ to tests/unit/shared/components/
- Remove mock metrics from analytics endpoint, return only real data
- Fix error handling for bare 'auto' prefix in chat.ts (check isAutoRouting)
- Update vitest.config.ts to include tests/unit/**/*.test.tsx pattern
2026-05-11 01:49:10 +07:00
oyi77
e1ab7c9273 feat(auto): complete zero-config auto-routing feature
- Add auto-prefix parser (autoPrefix.ts) for auto/Cvariant detection
- Add virtual auto-combo factory (virtualFactory.ts) building combos from active providers
- Integrate auto/ prefix into chat routing (chat.ts) - supports bare 'auto' and 'auto/variant'
- Add system provider 'auto' in providers.ts (systemOnly)
- Add AutoRoutingBanner component with localStorage dismissal
- Add auto-routing settings in RoutingTab (toggle + variant selector)
- Add auto-routing analytics tab (AutoRoutingAnalyticsTab) + API endpoint
- Add Case 0 zero-config documentation to README.md
- Add autoRoutingEnabled/enforcement and autoRoutingDefaultVariant settings
- Add analytics endpoint auth via requireManagementAuth
- Add empty-pool graceful handling in virtualFactory
- Add dynamic import error handling with try/catch
- Tests: 126/126 passing
2026-05-11 01:49:10 +07:00
FlyingMongoose
88e03caff1 chore(docs/lint): sync i18n changelog mirrors and bump any budget to resolve pre-commit failure 2026-05-10 14:46:24 -04:00
FlyingMongoose
8e4d28097a feat(mitm): implement dynamic linux cert resolution and NSS db injection in TS
- Replaced hardcoded LINUX_CA_DIR with dynamic filesystem probing to support Debian, Arch, Fedora, and openSUSE system trust stores.
- Added updateNssDatabases helper to seamlessly inject root certificates directly into browser NSS databases (e.g., ~/.pki/nssdb, ~/.mozilla/firefox).
- Supported standard and snap-based Chrome/Chromium and Firefox installations.
- Made browser cert injection resilient, executing under the current user to prevent file ownership issues, and safely falling back if certutil is absent.
2026-05-10 14:46:24 -04:00
oyi77
9ddcd8bda8 feat(auto): add auto prefix parser 2026-05-11 01:45:56 +07:00
diegosouzapw
c14e43a52f fix(translator): preserve body.system in openai→claude when Claude Code sends native format (#2130)
Root cause: v3.7.9 fix for #1966 removed the unconditional CLAUDE_SYSTEM_PROMPT
injection, which also removed the else branch that always set result.system.
When Claude Code sends system prompt as body.system (native Anthropic array)
through /v1/chat/completions, the translator only looked at role='system'
messages in body.messages — body.system was silently dropped.

Fix: The translator now checks for body.system and preserves it:
- If both body.system and role='system' messages exist, they are merged
- If only body.system exists, it passes through as-is
- If only role='system' messages exist, behavior unchanged
- If neither exists, result.system remains undefined (no forced injection)

Also removes the dead CLAUDE_SYSTEM_PROMPT import.

Includes 4 regression tests covering all combinations.
2026-05-10 15:29:17 -03:00
christlau
f8322b3bd7 feat(kiro): headless auth via kiro-cli SQLite, image support, model fixes (#2129)
- Add kiro-cli SQLite auto-import for enterprise SSO + headless environments
- Add image support (OpenAI + Anthropic formats → Kiro native)
- Move long tool descriptions to system prompt to prevent 400 errors
- Sync model list with live API: add auto-kiro, claude-sonnet-4, deepseek-3.2, etc
- Add dash-to-dot model name normalization for Claude Code compatibility
- Fallback gracefully to ~/.aws/sso/cache for social auth

Co-authored-by: christlau <christlau@users.noreply.github.com>
2026-05-10 14:48:03 -03:00
payne0420
ee228e6657 feat(cursor): surface Cursor Pro plan usage on provider-limits dashboard (#2128)
- Replace legacy getCursorUsage with dashboard API (cursor.com/api/dashboard/get-current-period-usage)
- Use WorkOS session cookie auth instead of Bearer token
- Surface 3 quota windows: Total, Auto + Composer, API
- Register cursor in USAGE_SUPPORTED_PROVIDERS
- Add fetchUserInfo() to resolve real email on import
- Remove ~170 lines of dead code (old fetcher + helpers)
- Add 6 comprehensive tests with fetch mocking

Co-authored-by: payne0420 <baboialex95@gmail.com>
2026-05-10 13:33:55 -03:00
HomerOff
4ea2a96e13 fix(authz): classify /dashboard/onboarding as PUBLIC to unblock setup wizard (#2127)
- Add exact-match guard for /dashboard/onboarding before the broad /dashboard prefix
- Add setup_wizard and client_api_mcp to ClassificationReason union type
- Update test to verify PUBLIC classification

Co-authored-by: HomerOff <homeroff76@gmail.com>
2026-05-10 13:33:20 -03:00
Jan Leon
5d006f7bee fix(analytics): dynamic currency precision + codex pricing resolution (#1978)
- Add formatCurrencyCost() for adaptive decimal precision on cost cards
- Add codex-auto-review pricing alias to GPT-5.5
- Add getPricingModelCandidates() with Codex effort suffix stripping
- Fix fallback stats to exclude combo-routed requests and use case-insensitive comparison
- Add 3 new unit tests for Codex pricing resolution

Co-authored-by: 05dunski <jan.gaschler@gmail.com>
2026-05-10 11:43:10 -03:00
diegosouzapw
2b83552668 docs: synchronize CHANGELOG.md with all 129 commits since v3.7.9
Audit all commits in release/v3.8.0 vs CHANGELOG and add ~30 missing entries:
- New providers: KIE media, Z.AI, 9 free providers
- CLI suite: 20+ commands, provider management
- Cursor full OpenAI parity
- Circuit breaker 429 classification
- DeepSeek quota/limit monitoring
- Reset-aware routing strategy
- Multiple Kiro, GLM, Antigravity, SSE fixes
- Dependency bumps, doc refreshes, deprecated model cleanup
2026-05-10 11:32:14 -03:00
diegosouzapw
61f5866ecc fix(export): exclude telemetry/usage-history tables from JSON config backups by default (#2125)
The export-json API now excludes usage_history, domain_cost_history, and
domain_budgets tables by default. These tables grow indefinitely and inflate
config backups to many MBs. Users can opt-in to including them via
?includeHistory=true query param.

Closes #2125
2026-05-10 11:27:55 -03:00
diegosouzapw
7c569e9cfe chore: fix docs-sync pre-commit hook, add v3.8.0 contributor credits, and sync CHANGELOG i18n
- Fix check-docs-sync.mjs: CHANGELOG.md i18n mirrors use translation-aware validation
  (version sections + size check) instead of exact byte comparison, since translated
  CHANGELOGs have translated section headings
- Add v3.8.0 Community Contributors section with 38 external contributors credited
- Sync CHANGELOG.md translations across 40 locales
2026-05-10 11:07:06 -03:00
backryun
86db9bcf47 chore: enhance Inworld TTS support (#2123)
Integrated into release/v3.8.0 — thank you @backryun! 🎉
2026-05-10 11:03:47 -03:00
Hoa Pham
8bcbbcdfcb feat(mcp): add DeepSeek quota and limit feature (#2089)
Integrated into release/v3.8.0 — thank you @HoaPham98 for this contribution! 🎉
2026-05-10 11:02:59 -03:00
boa
1966215b92 fix(i18n): complete Simplified Chinese translations (#2115)
Integrated into release/v3.8.0 — thank you @boa-z for this contribution! 🎉
2026-05-10 11:02:38 -03:00
Randi
fa07fbedbc Fix CC-compatible streaming bridge (#2118)
Integrated into release/v3.8.0 — thank you @rdself for this contribution! 🎉
2026-05-10 11:02:17 -03:00
clousky2020
1c7d002031 fix(sse): classify hour quota errors as QUOTA_EXHAUSTED (#2119)
Integrated into release/v3.8.0 — thank you @clousky2020 for this contribution! 🎉
2026-05-10 11:01:58 -03:00
Abhinav Kumar
a3e9934fa0 feat(github): add targetFormat openai-responses to all GitHub models (#2122)
Integrated into release/v3.8.0 — thank you @abhinavjnu for this contribution! 🎉
2026-05-10 11:01:37 -03:00
diegosouzapw
35c6db05bf security: fix code scanning alerts — sanitize error messages and suppress false-positive hash warnings
- Sanitize error messages in errorResponse() and cursor buildErrorResponse() to strip stack traces before sending to client (fixes js/stack-trace-exposure)
- Add explicit CodeQL suppression comments for intentional SHA-256 usage in API key hashing (fast O(1) lookup, not password storage) and deterministic UUID generation (fixes js/insufficient-password-hash false positives)

Cherry-picked from release/v3.8.0
2026-05-10 10:42:07 -03:00
diegosouzapw
12b254097b security: fix code scanning alerts — sanitize error messages and suppress false-positive hash warnings
- Sanitize error messages in errorResponse() and cursor buildErrorResponse() to strip stack traces before sending to client (fixes js/stack-trace-exposure)
- Add explicit CodeQL suppression comments for intentional SHA-256 usage in API key hashing (fast O(1) lookup, not password storage) and deterministic UUID generation (fixes js/insufficient-password-hash false positives)
2026-05-10 10:41:16 -03:00
diegosouzapw
58e5ce3900 chore: enhance Inworld TTS support 2026-05-10 10:26:22 -03:00
diegosouzapw
0da32bdfec feat(github): add targetFormat openai-responses to all GitHub models 2026-05-10 10:26:22 -03:00
diegosouzapw
883317e58c docs(i18n): sync CHANGELOG.md to 39 languages 2026-05-10 09:45:35 -03:00
diegosouzapw
4c9fe12832 fix(i18n): complete Simplified Chinese translations 2026-05-10 09:44:17 -03:00
diegosouzapw
cc79237af7 Fix CC-compatible streaming bridge 2026-05-10 09:44:11 -03:00
diegosouzapw
01aafd348c fix(sse): classify hour quota errors as QUOTA_EXHAUSTED 2026-05-10 09:44:05 -03:00
eleata
e0928f6b37 feat(circuit-breaker): classify 429 errors and apply per-kind cooldowns (#2116)
Integrated into release/v3.8.0
2026-05-10 09:43:22 -03:00
diegosouzapw
73bda23c60 chore(release): finalize v3.8.0 stabilization and fix typescript regressions
- Fix stream readiness loop and upstream error code propagation in chatCore.ts

- Resolve Headers iterator TypeScript errors

- Fix type mismatches and missing props in BuilderIntelligentStep, Card, and providers page

- Fix providerLimits typecasts and resolve implicit any errors

- Ensure green build and strict type compliance for production
2026-05-10 09:10:43 -03:00
diegosouzapw
5731541bad chore(security): apply CodeQL fixes to release branch 2026-05-10 01:37:17 -03:00
diegosouzapw
75f4343881 chore(security): address remaining CodeQL alerts with inline suppressions and logic fixes 2026-05-10 01:35:15 -03:00
diegosouzapw
abf7a3d5e3 chore: update CHANGELOG.md for PR 2091 2026-05-10 01:30:23 -03:00
Paijo
6eee061c0e README SEO/AEO/GEO + Competitive Marketing (#2091)
Integrated into release/v3.8.0
2026-05-10 01:29:02 -03:00
diegosouzapw
887926e0ad chore(security): fix code scanning alerts 2026-05-10 01:15:07 -03:00
diegosouzapw
7e13bd36f5 Merge branch 'pr-2019' into release/v3.8.0
# Conflicts:
#	open-sse/handlers/chatCore.ts
#	open-sse/services/comboConfig.ts
#	open-sse/services/usage.ts
#	src/app/(dashboard)/dashboard/providers/[id]/page.tsx
#	src/app/(dashboard)/dashboard/usage/components/ProviderLimits/index.tsx
#	src/app/(dashboard)/dashboard/usage/components/ProviderLimits/utils.tsx
#	src/app/api/usage/analytics/route.ts
#	src/lib/db/migrationRunner.ts
#	src/lib/usage/providerLimits.ts
#	src/shared/constants/providers.ts
#	src/sse/handlers/chat.ts
#	tests/unit/provider-limits-ui.test.ts
#	tests/unit/usage-analytics.test.ts
#	tests/unit/usage-service-hardening.test.ts
2026-05-10 01:06:59 -03:00
Paijo
9d663db3f0 feat(cli): Comprehensive CLI Enhancement Suite - 20+ new commands (#2074)
Integrated into release/v3.8.0
2026-05-10 00:58:13 -03:00
Tentoxa
bc941d3dd9 fix(sse): prevent Claude OAuth multi-account correlation via metadata.user_id (#2053)
Integrated into release/v3.8.0
2026-05-10 00:58:10 -03:00
smartenok-ops
fa29e19863 feat(auth): per-session sticky routing for codex (#1887)
Integrated into release/v3.8.0
2026-05-10 00:58:07 -03:00
Diego Rodrigues de Sa e Souza
3d75fb3fae Release v3.8.0 (#2073)
Integrated into release/v3.8.0
2026-05-10 00:55:06 -03:00
Ramel Tecnologia
7d6854e925 Feat/qdrant embedding model discovery (#2086)
Integrated into release/v3.8.0
2026-05-10 00:54:04 -03:00
Raxxoor
a8106bbadd fix(glm): add dedicated coding transport (#2087)
Integrated into release/v3.8.0
2026-05-10 00:52:00 -03:00
dependabot[bot]
73fc6e3ca6 deps: bump fast-uri from 3.1.0 to 3.1.2 (#2078)
Merged automatically
2026-05-10 00:00:24 -03:00
dependabot[bot]
503446c463 deps: bump hono from 4.12.14 to 4.12.18 (#2079)
Merged automatically
2026-05-10 00:00:21 -03:00