diegosouzapw
ff01e9edaa
fix(oauth): show manual paste mode for LAN IP access
...
When accessing OmniRoute via LAN IP (192.168.x), the OAuth popup
callback can't resolve localhost back to the VPS. Now shows manual
paste input with warning banner instead of waiting indefinitely.
v1.4.3
2026-02-23 20:51:52 -03:00
diegosouzapw
168b17adc7
fix(oauth): hardcode desktop OAuth client secrets to fix build-time inlining
...
Next.js inlines process.env at build time, causing clientSecret defaults to
be baked as empty strings. Desktop/CLI OAuth secrets are not confidential
per Google's documentation.
Fixes: client_secret is missing error on VPS deployment
v1.4.2
2026-02-23 20:14:28 -03:00
diegosouzapw
7e0c6f0307
chore(release): v1.4.1 — endpoint page cleanup, deploy workflow
2026-02-23 19:00:30 -03:00
Diego Rodrigues de Sa e Souza
dd573aed6f
Merge pull request #120 from diegosouzapw/dependabot/npm_and_yarn/development-94fcb5e3b6
...
deps: bump the development group with 6 updates
2026-02-23 17:28:19 -03:00
diegosouzapw
b87af5d053
chore: add VPS auto-deploy workflow, remove API key section from Endpoint page
...
- Add deploy-vps.yml: auto-deploys via SSH after Docker Hub publish
- Remove API key management section from Endpoint page (now in API Manager)
- Remove unused Link import from EndpointPageClient.tsx
2026-02-23 17:20:26 -03:00
dependabot[bot]
29b3e59d23
deps: bump the development group with 6 updates
...
Bumps the development group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss ) | `4.1.18` | `4.2.1` |
| [@types/bcryptjs](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/bcryptjs ) | `2.4.6` | `3.0.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `25.2.3` | `25.3.0` |
| [eslint](https://github.com/eslint/eslint ) | `9.39.2` | `9.39.3` |
| [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss ) | `4.1.18` | `4.2.1` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ) | `8.56.0` | `8.56.1` |
Updates `@tailwindcss/postcss` from 4.1.18 to 4.2.1
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases )
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md )
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.2.1/packages/@tailwindcss-postcss )
Updates `@types/bcryptjs` from 2.4.6 to 3.0.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/bcryptjs )
Updates `@types/node` from 25.2.3 to 25.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `eslint` from 9.39.2 to 9.39.3
- [Release notes](https://github.com/eslint/eslint/releases )
- [Commits](https://github.com/eslint/eslint/compare/v9.39.2...v9.39.3 )
Updates `tailwindcss` from 4.1.18 to 4.2.1
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases )
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md )
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.2.1/packages/tailwindcss )
Updates `typescript-eslint` from 8.56.0 to 8.56.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.1/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: "@tailwindcss/postcss"
dependency-version: 4.2.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: development
- dependency-name: "@types/bcryptjs"
dependency-version: 3.0.0
dependency-type: direct:development
update-type: version-update:semver-major
dependency-group: development
- dependency-name: "@types/node"
dependency-version: 25.3.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: development
- dependency-name: eslint
dependency-version: 9.39.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: development
- dependency-name: tailwindcss
dependency-version: 4.2.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: development
- dependency-name: typescript-eslint
dependency-version: 8.56.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: development
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-02-23 20:19:21 +00:00
diegosouzapw
ce6d7dc6bf
feat(api-manager): enhance with usage stats, status badges, and stats dashboard ( #118 )
...
- Add stats summary cards (total keys, restricted, total requests, models available)
- Add per-key usage statistics (total requests, last used timestamp)
- Add copy button on each key row
- Add color-coded lock/unlock status icons per key
- Bump version to 1.4.0
v1.4.0
2026-02-23 17:01:32 -03:00
Diego Rodrigues de Sa e Souza
19eeebae95
Merge pull request #118 from nyatoru/feat/api-key-manager
...
feat(api-manager): implement API key management with new endpoints and UI
2026-02-23 16:58:20 -03:00
diegosouzapw
1dd05bffe8
fix: proxy support for connection tests, compatible provider display ( #119 , #113 )
...
- Connection tests now route through configured proxy (key → combo → provider → global → direct)
- Compatible providers show friendly labels (OAI-COMPAT, ANT-COMPAT) in request logger
- 26 new unit tests for error classification, token expiry, and display labels
- Version bump to 1.3.1
v1.3.1
2026-02-23 16:50:48 -03:00
nyatoru
ac3d251a1a
fix(db): clear prepared statements on backup restore
2026-02-24 00:35:29 +07:00
nyatoru
238e080928
refactor(api-manager): improve type safety in client component
2026-02-24 00:20:42 +07:00
nyatoru
7ed40c2139
fix(db): enforce stricter validation for api key model access
2026-02-24 00:14:50 +07:00
nyatoru
d2bee37e76
feat(api-manager): implement API key management with new endpoints and UI
...
- Add GET/PATCH endpoints for retrieving and updating API key permissions
- Move API key management from Endpoint page to dedicated API Manager page
- Add allowed_models column to database schema for model-specific access
- Implement caching layer for improved API key validation performance
2026-02-23 23:59:34 +07:00
diegosouzapw
343e6c50e3
chore(release): v1.3.0 — iFlow HMAC fix, health check logs toggle, kilocode models, model dedup
...
✨ New Features:
- Hide Health Check Logs toggle (PR #111 by @nyatoru)
- Kilocode custom models endpoint + 26 models (PR #115 by @benzntech)
🐛 Bug Fixes:
- iFlow 406 error fixed with IFlowExecutor HMAC-SHA256 signature (#114 )
- Filter parent model duplicates from endpoint lists (PR #112 by @nyatoru)
🧪 Tests:
- 11 new IFlowExecutor unit tests
- All 379 tests passing
v1.3.0
2026-02-23 03:50:01 -03:00
Diego Rodrigues de Sa e Souza
90d2dcac97
Merge pull request #115 from benzntech/feat/enhance-kilocode-provider
...
feat(kilocode): add custom models endpoint and expanded model list
2026-02-23 03:44:32 -03:00
Diego Rodrigues de Sa e Souza
631ed4d97f
Merge pull request #112 from nyatoru/feat/fix-models
...
fix(endpoint): filter out parent models to avoid duplicates in lists
2026-02-23 03:44:29 -03:00
Diego Rodrigues de Sa e Souza
9485985608
Merge pull request #111 from nyatoru/feature/hide-health-check
...
feat(settings): add toggle to hide health check logs with caching
2026-02-23 03:44:20 -03:00
Diego Rodrigues de Sa e Souza
b32db28a3d
Update src/app/(dashboard)/dashboard/endpoint/EndpointPageClient.tsx
...
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
2026-02-23 03:34:22 -03:00
Diego Rodrigues de Sa e Souza
1516429b87
Update src/app/(dashboard)/dashboard/settings/components/AppearanceTab.tsx
...
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
2026-02-23 03:33:51 -03:00
benzntech
5668e16fbf
feat(kilocode): add custom models endpoint and expanded model list
...
- Add modelsUrl field to RegistryEntry interface for custom models endpoints
- Configure kilocode provider with dedicated models URL (https://api.kilo.ai/api/openrouter/models )
- Expand kilocode model list from 8 to 26 models including free options:
- openrouter/free (Free Models Router)
- stepfun/step-3.5-flash:free
- arcee-ai/trinity-large-preview:free
- Additional Qwen, DeepSeek, Llama, Mistral, Grok, and Kimi models
- Update validateOpenAILikeProvider to accept custom modelsUrl parameter
- Fix models URL derivation for base URLs ending with /chat/completions
- Add kilocode config to PROVIDER_MODELS_CONFIG
2026-02-23 10:31:56 +05:30
nyatoru
bd4a076942
Add HTTP error handling to settings API fetch
2026-02-23 06:38:45 +07:00
nyatoru
f0a0c97b5e
feat(tokenHealthCheck): add request coalescing to shouldHideLogs
2026-02-23 06:36:39 +07:00
nyatoru
7ffe21e23d
fix(endpoint): filter out parent models to avoid duplicates in lists
2026-02-23 06:32:49 +07:00
nyatoru
4b137d8e72
feat(settings): add toggle to hide health check logs with caching
2026-02-23 06:21:53 +07:00
diegosouzapw
6ba48241fe
fix(test): align test script with test:unit — add tsx/esm loader
...
The 'test' script was missing '--import tsx/esm', causing 25 failures
from Node ESM being unable to resolve extensionless TypeScript imports.
The 'test:unit' script already had the loader and passed 368/368.
2026-02-22 19:00:04 -03:00
diegosouzapw
a17583d3fc
feat(api): JWT session auth for models endpoint + refactor (v1.2.0)
...
- Merged PR #110 by @nyatoru: JWT session auth fallback for /v1/models
- Refactored: removed ~60 lines of same-origin detection (sameSite:lax already prevents CSRF)
- Changed auth failure response: 404 Not Found -> 401 Unauthorized (OpenAI format)
- Version bumped to v1.2.0
Closes #110
v1.2.0
2026-02-22 18:36:57 -03:00
diegosouzapw
62c634ae78
Merge PR #110 : feat(api): add JWT session auth fallback for models endpoint
2026-02-22 18:34:41 -03:00
nyatoru
02dc8ea0f3
fix(api): enhance authentication for /models endpoint with stricter checks
2026-02-23 04:00:22 +07:00
nyatoru
a40c463a87
feat(api): add JWT session auth fallback for models endpoint
2026-02-23 03:46:09 +07:00
diegosouzapw
5e0376c6c9
fix(test): correct JWT_SECRET assertion — required:false means missing is valid
...
The secretsValidator marks JWT_SECRET as required:false (auto-generated
at startup), but the test asserted valid:false when JWT_SECRET was missing.
This caused CI to fail with 367/368 tests passing.
v1.1.1
2026-02-22 16:42:09 -03:00
diegosouzapw
2bad777541
Merge PR #109 : feat(codex): add workspace binding via chatgpt-account-id header
...
Adds strict workspace binding via persisted chatgpt-account-id for Team Plan support.
Includes code_review_rate_limit (3rd window) parsing.
Fixes #106
2026-02-22 16:34:04 -03:00
diegosouzapw
10793a7e65
Merge branch 'main' into feat/codex-teamplan
...
# Conflicts:
# open-sse/services/usage.ts
2026-02-22 16:33:31 -03:00
diegosouzapw
5dab4058c8
fix(issues): API key creation crash ( #108 ) & Codex code review quota ( #106 )
...
- Fix API_KEY_SECRET undefined crash with deterministic fallback
- Add code_review_rate_limit parsing for Team/Plus/Pro plan support
- Move feature-81 doc to completed/
- Bump version to v1.1.1
2026-02-22 16:28:44 -03:00
nyatoru
b26cc2a82e
feat(codex): enhance base64 decoding for UTF-8 compatibility in JWT parsing
2026-02-23 01:32:48 +07:00
nyatoru
0610909116
feat(codex): add workspace binding via chatgpt-account-id header
2026-02-23 01:11:53 +07:00
Diego Rodrigues de Sa e Souza
f8a401da4b
Merge pull request #107 from nyatoru/feat/deletedebugqwen
...
chore(qwen): remove debug console log from mapTokens
2026-02-22 11:41:51 -03:00
nyatoru
3b70e9f786
chore(qwen): remove debug console log from mapTokens
2026-02-22 20:23:37 +07:00
diegosouzapw
39f992a2a8
chore(release): bump version to v1.1.0
v1.1.0
2026-02-21 18:41:31 -03:00
Diego Rodrigues de Sa e Souza
0df1d46ae5
Merge pull request #104 from diegosouzapw/fix-issues-101-103
...
Fix OAuth client_secret issues (#103 ) & Codex Business quotas (#101 )
2026-02-21 18:38:17 -03:00
diegosouzapw
28c7e0d62f
Fix OAuth client_secret issues ( #103 ) & Codex Business quotas ( #101 )
2026-02-21 18:24:56 -03:00
diegosouzapw
03965bf768
fix(db): remove OAuth fallback overwrite when email is missing to natively support multiple accounts
2026-02-21 13:04:06 -03:00
diegosouzapw
6b34a39f6e
chore(release): bump version to v1.0.10 and update changelog
v1.0.10
2026-02-21 12:35:37 -03:00
diegosouzapw
f0513683e5
fix(qwen): extract email from id_token to allow multiple accounts
2026-02-21 12:22:56 -03:00
diegosouzapw
b3e53ca250
chore(release): bump version to v1.0.9 and update changelog
v1.0.9
2026-02-21 10:00:53 -03:00
diegosouzapw
7a3b21eff8
fix(settings): add blockedProviders and requireAuthForModels to Zod schema
2026-02-21 09:49:15 -03:00
diegosouzapw
f8c8501036
chore(release): bump version to v1.0.8
v1.0.8
2026-02-21 09:31:10 -03:00
Diego Rodrigues de Sa e Souza
4e1b5a5253
Merge pull request #102 from diegosouzapw/feat/issue-fixes-and-security
...
Release v1.0.8
2026-02-21 09:30:54 -03:00
diegosouzapw
1aa27ceefe
chore(workflows): move agent workflows to global dir
2026-02-21 09:11:14 -03:00
diegosouzapw
340dcf9515
feat(core): api key protection, provider blocking, windows fix, ui and docs
2026-02-21 09:05:59 -03:00
Adarsh
1bd5d552c1
fix: extract email from id_token for Codex OAuth to allow multiple accounts ( #97 )
...
- Parse JWT id_token to extract email in mapTokens function
- Allows database to distinguish between different Codex accounts
- Fixes issue where adding 3rd+ Codex account would update existing connection instead of creating new one
2026-02-21 07:00:37 -03:00