Commit Graph

4688 Commits

Author SHA1 Message Date
WITALO ROCHA
cfb2db8261 fix: restore om-usage HTTP endpoint (#5859)
Integrated into release/v3.8.43
2026-07-01 22:03:17 -03:00
Nguyen Minh
9358eeada9 [codex] Tune adaptive stream readiness timeouts (#5767)
Integrated into release/v3.8.43
2026-07-01 22:02:51 -03:00
Nguyen Minh
19703cd6ec Harden provider node URL validation (#5760)
Integrated into release/v3.8.43
2026-07-01 22:02:36 -03:00
PizzaV
36167d7bb7 refactor(executors): deduplicate shared utilities and add comprehensive tests (#5720)
Integrated into release/v3.8.43
2026-07-01 22:02:22 -03:00
Markus Hartung
9bd0211da7 extracted CorrelationId observability changes from #5275 (#5834)
Integrated into release/v3.8.43
2026-07-01 22:02:08 -03:00
Isha Tiwari
a98b29e8be Show startup time in ready banner (#5799)
Integrated into release/v3.8.43
2026-07-01 22:01:54 -03:00
Aris
cc260c9459 fix(cli): correct rootDir resolution in doctor.mjs on Windows (#5844) (#5845)
Integrated into release/v3.8.43
2026-07-01 22:01:40 -03:00
Chewji
e5e47eb61c fix(antigravity): 429 hang on credit exhaustion and precise reset time lockout (Cleaned) (#5846)
Integrated into release/v3.8.43
2026-07-01 22:01:26 -03:00
janeza2
057dc3abf3 fix(qwen-web): unblock validator + chat completion (retired endpoint + missing SPA version header) (#5855)
Integrated into release/v3.8.43
2026-07-01 22:01:11 -03:00
janeza2
b708aa7e75 fix(kimi-web): migrate to www.kimi.com Connect-RPC API (kimi.moonshot.cn retired) (#5858)
Integrated into release/v3.8.43
2026-07-01 22:00:57 -03:00
Randi
103a0ee2a2 fix: unify dashboard csrf origin fallback (#5856)
Integrated into release/v3.8.43
2026-07-01 22:00:43 -03:00
Yuan Li
7d7626151b fix(db): preserve healthCheckInterval=0 across create/update (#5822)
Integrated into release/v3.8.43
2026-07-01 22:00:18 -03:00
Diego Rodrigues de Sa e Souza
e38c1ca9fc fix(usage): keep tool definitions visible when request log is truncated (#5829)
Integrated into release/v3.8.43
2026-07-01 21:59:33 -03:00
Diego Rodrigues de Sa e Souza
8bba88cd30 fix(translator): prevent doubled tool args in OpenAI-to-Claude (#5828)
Integrated into release/v3.8.43
2026-07-01 21:58:48 -03:00
Diego Rodrigues de Sa e Souza
08dbf6f58a fix(mitm): clean up privileged hosts entries on exit when possible (#5808)
Integrated into release/v3.8.43
2026-07-01 21:58:01 -03:00
Diego Rodrigues de Sa e Souza
59de75cc45 fix(kiro): stop injecting placeholder user turn on tool-result turns (#5807)
Integrated into release/v3.8.43
2026-07-01 21:57:14 -03:00
Diego Rodrigues de Sa e Souza
ace6479d5f fix(translator): strip orphaned tool results across request formats (#5805)
Integrated into release/v3.8.43
2026-07-01 21:56:25 -03:00
Diego Rodrigues de Sa e Souza
b55a330dc5 fix(oauth): disambiguate OAuth connections on username to prevent cross-IdP overwrites (#5803)
Integrated into release/v3.8.43
2026-07-01 21:55:30 -03:00
Diego Rodrigues de Sa e Souza
e7ae29d607 fix(github): drop trailing assistant prefill for Copilot chat (#5802)
Integrated into release/v3.8.43
2026-07-01 21:54:43 -03:00
Diego Rodrigues de Sa e Souza
3323b5b617 fix(dashboard): guard null modelAliases values in model picker (#5792)
Integrated into release/v3.8.43
2026-07-01 21:53:56 -03:00
Diego Rodrigues de Sa e Souza
4d7f36015a fix(sse): stop reasoning-summary drop + duplicated deltas on claude→codex streaming (#5786) (#5832)
Integrated into release/v3.8.43
2026-07-01 21:52:10 -03:00
Diego Rodrigues de Sa e Souza
2955927b06 fix(db): allowlist modelContextOverrides as intentionally-internal to green release DB-rules gate (#5798) (#5827)
Integrated into release/v3.8.43
2026-07-01 21:51:35 -03:00
Diego Rodrigues de Sa e Souza
dcefed0d99 fix(kiro): bound Claude id dash->dot minor group to protect date-suffixed ids (#5825)
Integrated into release/v3.8.43
2026-07-01 21:51:21 -03:00
Diego Rodrigues de Sa e Souza
eadd7338f6 fix(providers): add claude-sonnet-5 to Kiro model catalog (#5796)
Integrated into release/v3.8.43
2026-07-01 21:50:13 -03:00
Diego Rodrigues de Sa e Souza
12ac520014 fix(cli): rename process title to omniroute (#5791)
Integrated into release/v3.8.43
2026-07-01 21:49:48 -03:00
Diego Rodrigues de Sa e Souza
512844710c fix(dashboard): add error boundaries for Combos and MITM Proxy pages (#5788)
Integrated into release/v3.8.43
2026-07-01 21:49:34 -03:00
Diego Rodrigues de Sa e Souza
2abd35b0dc chore(release): rebaseline deadExports 225->227 (v3.8.43 cycle drift) 2026-07-01 16:44:21 -03:00
Diego Rodrigues de Sa e Souza
4635076eb4 chore(release): rebaseline complexity 1981->1982 + cognitive-complexity 842->845 (v3.8.43 cycle drift) 2026-07-01 16:09:23 -03:00
Diego Rodrigues de Sa e Souza
6d7060e21c chore(release): rebaseline eslintWarnings ratchet 4121->4158 (v3.8.43 cycle drift) 2026-07-01 15:51:41 -03:00
Diego Rodrigues de Sa e Souza
5f3b99819e fix(ci): register mark-account-unavailable test in stryker tap.testFiles
check:mutation-test-coverage --strict (Fast Quality Gates) flagged
tests/unit/mark-account-unavailable-numeric-epoch-guard.test.ts as a
covering unit test missing from stryker.conf.json tap.testFiles, so its
mutant kills would not count (--strict). Add it. Pre-existing tap.testFiles
drift on the release tip that fails Fast Quality Gates on every PR into
release/v3.8.43, not just this branch.
2026-07-01 15:34:55 -03:00
Diego Rodrigues de Sa e Souza
948d2d7f21 fix(security): explicit http(s) scheme allowlist in linkifyText href
CodeQL flagged the <a href> in LinkifiedText (#5486) with js/xss (high)
and js/client-side-unvalidated-url-redirection (medium) because href
traces back to user-provided text. URL_RE already requires an http(s)://
prefix, so a javascript:/data: scheme can never reach href — but that
guarantee was only implied by the regex. Validate the scheme explicitly
via new URL().protocol before exposing href (non-http(s) degrades to
plain text): defense-in-depth that also makes the sink provably safe to
static analysis. Regression test added.
2026-07-01 13:10:49 -03:00
Diego Rodrigues de Sa e Souza
31fd6dddbf test(e2e): anchor compression-studio smoke on play-input, not async play-lane
The T03 smoke asserted `play-lane` visible on mount, but those per-lane
buttons only render after a preview-compression run populates
`batch.lanes` (usePreviewCompression keeps batch null until run(); there
is no mount auto-run). The smoke intentionally does not drive a
compression cascade, so `play-lane` can never appear -> the E2E added in
 #5727 failed all 3 retries (E2E Tests 4/9). Anchor on the always-present
`play-input` panel, which proves the studio body mounted without needing
async lane data.
2026-07-01 12:58:43 -03:00
Diego Rodrigues de Sa e Souza
b5b7f09838 test(compression): de-flake rtk_discover sample seeding
seedSamples() persisted two byte-identical raw outputs. The raw-output
filename is keyed on Date.now() (ms) + a content hash (rawOutput.ts), so
two identical captures landing in the same millisecond collapse to one
file (the 2nd write overwrites the 1st) -> sampleCount 1 instead of 2.
Reproduced at ~25% (501/2000 trials), matching the intermittent
Coverage Shard (5/8) failure on fast CI runners. Seed two DISTINCT
captures so the store deterministically holds 2 samples regardless of
timing (0/2000 collisions after the change).
2026-07-01 12:58:43 -03:00
Diego Rodrigues de Sa e Souza
fce85136ca test(shared): align t3-web web-session expected metadata with hintKey (#5835)
The t3-web provider metadata intentionally carries `hintKey: "t3ChatWebCookieHint"`
(#5465 — the generic cookie hint reads circular for t3.chat), but the metadata
assertion in web-session-credentials was never updated, so it deep-equals against
an object missing the field. This is a stale-test base-red on release/v3.8.43 that
turns the whole PR queue's "Unit Tests fast-path (1/2)" red. Align the expected
object to the shipped source of truth.
2026-07-01 11:38:44 -03:00
Diego Rodrigues de Sa e Souza
077b4bdb70 test: align 3 stale release tests to landed behavior (#5609)
Base-reds surfaced on the release PR (fast-gate PR->release skips these shards):
- api-manager-page-static: Self-service Visibility now has 5 switches (added the
  API-key provider quota-policy bypass toggle, #5731); bump inventory 4->5 while
  keeping the invariant that every switch declares type=button (verified 5/5 typed).
- security-hardening (callLogs PII): #5725 extracted sanitizeErrorForLog into
  callLogs/format.ts; assert the new wiring (callLogs imports it + format.ts imports
  piiSanitizer) instead of the removed direct import — PII sanitization still intact.
- memory-glm-injection: #5610 made GLM 5.1+ ACCEPT the system role (z.ai docs), so
  glm-5.1 must PRESERVE system, not fold it. Flip the stale #1701-era assertion.
2026-07-01 11:23:30 -03:00
Diego Rodrigues de Sa e Souza
c5b123fd02 test(discovery): wire tests/unit/memory into node runner glob (#5609)
typed-decay.test.ts (TV6 typed memory decay, 15 asserts) sat in
tests/unit/memory/ which no runner glob collected -> orphan (never ran).
Adds 'memory' to the subdir brace-glob in all runner sources (package.json
scripts + ci.yml shards) and the COLLECTORS mirror in check-test-discovery.mjs
(drift-check keeps them in sync). Passes standalone (15/15); DATA_DIR isolation
handled per-file by tests/_setup/isolateDataDir.ts.
2026-07-01 10:26:41 -03:00
Diego Rodrigues de Sa e Souza
66c5b718cd fix(db): re-export modelContextOverrides from localDb (check:db-rules #5609) 2026-07-01 10:22:15 -03:00
Diego Rodrigues de Sa e Souza
6cff67e6ac refactor(sse): extract openai-to-gemini pure helpers into a leaf (#5824)
Split open-sse/translator/request/openai-to-gemini.ts (873 -> 756 LOC, back under
the 800-line cap) by moving the module-private pure helpers — the historical-tool-
context string builders (stringifyHistoricalToolArguments, buildInertHistorical*,
escapeHistoricalContext*, buildHistoricalToolResultContext), deepCleanUndefined,
extractClientThoughtSignature, buildChangedToolNameMap, isVertexGeminiProvider, and
applyAntigravityGenerationDefaults (with its GeminiGenerationConfig shape) — into
openai-to-gemini/helpers.ts.

These were module-private, so the translator's public API is unchanged; the host
imports them back internally. Bodies are verbatim: the code-line multiset of host +
leaf equals the original. Adds tests/unit/openai-to-gemini-helpers-split.test.ts
pinning the leaf's pure behaviour (escaping, undefined-pruning, signature extraction,
antigravity generation-config defaults) and the host wiring.
2026-07-01 10:10:14 -03:00
Diego Rodrigues de Sa e Souza
ec457e264d chore(release): rebaseline file-size + test-masking ratchets for v3.8.43 (#5609)
DRIFT acumulado dos 109 commits do ciclo v3.8.43 (fast-gate PR->release
nao roda check:file-size/test-masking; base-reds so afloram na release-PR):
- file-size: 8 god-files existentes cresceram + 2 arquivos novos acima do cap
  + 4 test files cresceram -> frozen ajustado ao estado atual.
- test-masking: chatgpt-web.test.ts 281->280 asserts allowlisted (#5549
  consolidou 2 assert.equal num unico map-driven; refactor legitimo, nao masking).
Modularizacao dos god-files deferida (#3501).
2026-07-01 10:01:13 -03:00
Diego Rodrigues de Sa e Souza
cded5146f0 fix(model-aliases): back custom-alias store with globalThis (#5777 follow-up) (#5821)
#5777 self-healed the GET /api/settings/model-aliases symptom at the route layer,
but the root cause remained: modelDeprecation.ts held _customAliases in a plain
module-level let, which webpack duplicates across the startup and app-route module
graphs (same class as #5312). Startup hydration landed on one copy; the API route
read the other (empty) one.

Back the store with globalThis (__omniroute_customAliases__) so both instances share
one store — the exact pattern already used by thinkingBudget.ts/backgroundTaskDetector.ts
(#5312). The route-layer DB self-heal from #5777 stays as a harmless fallback.

Extends #5777 (thanks @jleonar2). Regression: tests/unit/model-aliases-globalthis-5777.test.ts
(fails on the plain-let store: never populates globalThis, never reads a sibling
instance's write).
2026-07-01 09:11:13 -03:00
Diego Rodrigues de Sa e Souza
7d07be9b20 fix(oauth): clamp grok-cli expired-token expiresIn to a positive value (#5775 follow-up) (#5820)
An already-expired grok-cli token (real expires_at/exp in the past) produced a
negative expiresIn, which is truthy in the import-token route and maps to a PAST
expiresAt — AutoCombo then reads that as 'already expired' and excludes the
connection instead of refreshing it. Clamp with Math.max(1, expiresIn) so an
expired token is treated as due-for-refresh. Extends #5775 (thanks @Chewji9875).

Regression: 2 new cases in tests/unit/grok-cli-oauth.test.ts (expired JWT exp +
expired JSON expires_at), both failing-then-passing.
2026-07-01 09:06:07 -03:00
Diego Rodrigues de Sa e Souza
057ca116db chore(release): reconcile main into release/v3.8.43 (README #5738 grammar) 2026-07-01 09:02:47 -03:00
Chirag Singhal
3e88fc0921 fix(deps): add missing runtime deps @toon-format/toon and safe-regex (#5771)
Both packages are imported at runtime but were only declared for their
type shims (safe-regex was via @types/safe-regex; @toon-format/toon
had no declaration at all). Missing runtime deps mean:

- open-sse/services/compression/engines/headroom/toon.ts imports
  @toon-format/toon → MODULE_NOT_FOUND on cold pnpm/npm install
- open-sse/services/compression/engines/ccr/ccrQuery.ts imports
  safe-regex → MODULE_NOT_FOUND

Both engines are wired into the stacked compression pipeline (default
enabled), so a fresh clone that does not have a stale node_modules
from a previous version crashes as soon as the pipeline runs.

Verified with pnpm ls / grep before/after.
2026-07-01 08:59:48 -03:00
Diego Rodrigues de Sa e Souza
7522f6efa1 test(runtime): guard tsx/esm→esbuild transform path on boot (#5757) (#5773)
#5757 reported that a fresh `npm install omniroute` pulls `esbuild@0.28.1`
transitively via `tsx` (a runtime dependency the CLI registers at boot in
`bin/omniroute.mjs`), and proposed forcing `esbuild@0.27.4`.

That override is unsafe: `tsx@4.22.4` requires `esbuild@~0.28.0` and
`fumadocs-mdx@15` (also a runtime dep) requires `esbuild@^0.28.0`; forcing 0.27.x
pushes esbuild below both, and 0.28.1 is currently the latest release. The
reported transform failure also does not reproduce — OmniRoute targets ES2022,
its minimum supported Node is 22.2 (destructuring is native), and tsx targets the
running Node, so esbuild never lowers to an unsupported target.

Instead of an unsafe version pin, add two regression guards:
- functional: spawn the real `node --import tsx/esm` loader on a fixture packed
  with modern syntax (destructuring/spread, class+private fields, optional
  chaining, nullish, logical assignment, async + top-level await) and assert it
  transforms + runs correctly. Fails if a future esbuild regresses the boot path.
- dependency-shape: assert the resolved esbuild stays within tsx's declared
  range, so nobody reintroduces the out-of-range override this issue proposed.

No production code changed; no esbuild version pinned.
2026-07-01 08:54:24 -03:00
Diego Rodrigues de Sa e Souza
a00e0acbb7 refactor(sse): extract cursor protobuf wire primitives into a leaf (#5794)
Split open-sse/utils/cursorAgentProtobuf.ts (1520 -> 1400 LOC) by moving the
low-level protobuf wire-format primitives — varint/tag/length-delimited encode+
decode + the generic field walker (encodeVarint, encodeTag, encodeBytes,
encodeString, encodeMessage, encode{UInt32,Bool,Double}Field, decodeVarint,
checkedLen, decodeFields, findField, decode{String,Varint}Field, the Field type
and the WT_VARINT/WT_LEN wire-type constants) — into cursorAgentProtobuf/wire.ts.

These primitives were module-private, so the host's public API is unchanged; the
host imports them back internally. Bodies are verbatim: the code-line multiset of
host + wire.ts equals the original. First layer of the codec decomposition — the
value/framing codec and the message encoders/decoders build on this and stay in
the host (they share host-retained helpers; splitting them is a separate step).

Adds tests/unit/cursor-protobuf-wire-split.test.ts pinning the leaf surface, the
encode/decode round-trip invariants, the buffer-overrun guard, and the host wiring.
2026-07-01 05:10:33 -03:00
Diego Rodrigues de Sa e Souza
10f00ef274 fix(system): route in-app auto-update npm calls through the win32 shell helper (#5542) (#5797)
The in-app auto-update flow called execFileAsync("npm", ...) directly for the
version lookup (versionCheck.getLatestVersionFromNpmCli), dependency install,
global install, and native rebuild. On Windows npm is npm.cmd and Node >=24
refuses to execFile a .cmd without a shell (nodejs/node#52554), so those calls
threw 'spawn npm ENOENT'. Route them through buildNpmExecOptions (the same
win32-shell helper the embedded-services installer uses, fix #5379). The global
install spec is validated with SERVICE_VERSION_PATTERN before it is shell-joined
(Hard Rule #13). Not the pnpm/npx swap the issue proposed — that is the wrong
direction for an 'npm install -g' flow already solved elsewhere in-repo.

Regression guard: tests/unit/autoupdate-npm-win32-5542.test.ts.
2026-07-01 04:37:28 -03:00
Diego Rodrigues de Sa e Souza
b9d717f3c9 fix(dashboard): neutral badge for unsupported validation + clickable OAuth error links (#5442, #5486) (#5795)
- #5442 LMArena (and any provider with no live validator) returns
  { unsupported: true } from /api/providers/validate and Save succeeds, but the
  Add-API-Key modal only had success/failed states so it rendered a red 'Invalid'
  badge. Add an 'unsupported' result → neutral info 'N/A' badge via the pure leaf
  validationBadgeProps(); both validate handlers now map data.unsupported to it.
- #5486 GitLab Duo's OAuth setup error embeds a registration URL
  (gitlab.com/-/profile/applications) but the OAuth error step rendered it as dead
  red text. New LinkifiedText component (+ pure ReDoS-safe linkify util) makes any
  http(s) URL in an OAuth error clickable; the GitLab Duo backend message already
  carries the full setup steps.

Regression guards: tests/unit/validation-badge-unsupported-5442.test.ts,
tests/unit/oauth-error-linkify-5486.test.ts. Frozen god-files kept within cap
(AddApiKeyModal 868/868, OAuthModal 968/969).
2026-07-01 04:34:22 -03:00
Diego Rodrigues de Sa e Souza
1c4c7caf06 fix(providers): correct stale/broken provider metadata (#5487, #5461, #5534, #5470) (#5790)
- #5487 Qoder: replace the untranslated i18n stubs (personalAccessTokenLabel,
  qoderPatHint, qoderPatPlaceholder) with real copy; extend the STUB_KEYS guard.
- #5461 Scaleway: website pointed at scaleway.com/en/ai/generative-apis (HTTP 404);
  repoint at the live docs URL /en/docs/ai-data/generative-apis/.
- #5534 Microsoft 365 Copilot: rewrite the vague authHint with concrete DevTools
  WebSocket steps (the token lives on the Chathub WS URL, not an Authorization header).
- #5470 Together AI: retired the $25 signup credit and is now fully prepaid (min $5);
  hasFree false + a prepaid notice instead of the stale free-tier freeNote (verified live).

Regression guards: tests/unit/provider-metadata-5461-5470-5534.test.ts + Qoder keys
added to tests/unit/provider-add-ux-i18n-import-warning.test.ts.
2026-07-01 04:26:23 -03:00
Diego Rodrigues de Sa e Souza
3ef5f271d7 chore(docs): sync i18n CHANGELOG mirrors with root [3.8.43] section (#5789)
Regenerate the docs/i18n/<locale>/CHANGELOG.md [3.8.43] blocks from the root
CHANGELOG so the mirror body size returns within the 25% docs-sync tolerance.
Clears a pre-existing release-time drift (mirrors were ~26% smaller than root)
that was failing check-docs-sync and blocking every local commit on the
release branch.
2026-07-01 04:17:51 -03:00
Diego Rodrigues de Sa e Souza
d372a9af69 refactor(usage): extract 5 provider usage families into leaves (#5782)
Split open-sse/services/usage.ts (1723 -> 901 LOC) by moving the Cursor, Kimi,
Codex, Claude and Kiro usage-fetcher families into cohesive leaves under
open-sse/services/usage/ (mirroring the existing glm/minimax/antigravity/quota/
scalars leaves):

- usage/cursor.ts   getCursorUsage (+ CURSOR_USAGE_CONFIG, decodeCursorJwtSub)
- usage/kimi.ts     getKimiUsage (+ KIMI_CONFIG, getKimiPlanName)
- usage/codex.ts    getCodexUsage (+ CODEX_CONFIG)
- usage/claude.ts   getClaudeUsage / getClaudePlanLabel (+ CLAUDE_CONFIG, legacy)
- usage/kiro.ts     getKiroUsage / buildKiroUsageResult / discoverKiroProfileArn (+ helpers)

The host keeps the getUsageForProvider dispatcher and imports the fetchers back;
the public export set is unchanged — buildKiroUsageResult + discoverKiroProfileArn
are re-exported from the kiro leaf (the kiro-* tests import them from
services/usage) and __testing stays wired to the moved claude/kiro internals.
Bodies are verbatim: the code-line multiset of host + leaves equals the original.

Adds tests/unit/usage-families-split.test.ts pinning the leaf surface, the kiro
re-export identity, the __testing wiring, and getClaudePlanLabel's pure logic.
2026-07-01 04:13:17 -03:00