* chore(release): open v3.8.14 development cycle Version bump 3.8.13 -> 3.8.14 (root + electron + open-sse + openapi + lockfiles). Seed the v3.8.14 changelog with the four post-tag hotfixes that shipped to Docker/Electron in v3.8.13 but missed the immutable npm 3.8.13 (#3336 SSRF / CodeQL #323, #3334/#3335/#3339 Electron packaging). i18n CHANGELOG mirrors get the in-progress placeholder section. * feat: add per-provider custom headers support for OpenAI/Anthropic-compatible nodes (#3338) Integrated into release/v3.8.14 * fix: Kiro Builder ID token import fails with Bad credentials (#3333) Integrated into release/v3.8.14 — adds Builder ID cached-creds + OIDC refresh path for Kiro token import, with regression tests (#3333). * Improve code quality: auto-pr/docstrings-1780792063 (#3337) Integrated into release/v3.8.14 — docstring for context analytics route re-export. * fix(catalog): remove minimaxai/minimax-m3 from NVIDIA NIM tier (404 upstream) (#3329) (#3341) NVIDIA NIM does not host minimaxai/minimax-m3 — every request returns 404 page not found, while sibling minimaxai/minimax-m2.7 on the same provider works. Advertising a model that 404s is a catalog bug; remove it from the nvidia tier (it remains on the tiers that actually serve MiniMax M3). Re-add only once NVIDIA serves it. Co-authored-by: mikmaneggahommie <mikmaneggahommie@users.noreply.github.com> * fix(cli): write OpenCode config to ~/.config on all platforms incl. Windows (#3330) (#3343) resolveOpencodeConfigDir used %APPDATA% on Windows, but OpenCode reads its config from XDG ~/.config/opencode/ on every platform (on Windows: %USERPROFILE%\.config\opencode\, NOT %APPDATA%). So a Windows user who configured OpenCode via the dashboard had the file written where OpenCode never looks — it silently had no effect. Use the XDG path (XDG_CONFIG_HOME || ~/.config) unconditionally. Update the UI note + route JSDoc, and flip the three tests that encoded the old %APPDATA% behavior (t40 per-platform + card-note, cli-runtime-extended getCliConfigPaths). Co-authored-by: abdulkadirozyurt <abdulkadirozyurt@users.noreply.github.com> * fix(proxy): make auto-selection fallback opt-in (#3332) (#3344) selectWorkingProxyFallback (Step 11 of resolveProxyForConnection) listed ALL registry proxies, ignoring assignments and per-connection proxy_enabled, and returned the first working one with level:'autoSelect'. So a single proxy added to the registry silently became a global fallback for every connection's traffic. Gate it behind a new PROXY_AUTO_SELECT_ENABLED feature flag (default off): the fallback now no-ops unless the operator opts in. No registry proxy becomes a silent global default anymore. Co-authored-by: hertznsk <hertznsk@users.noreply.github.com> * fix(sse): treat MiniMax M3 as multimodal so vision isn't stripped (#3328) (#3342) MiniMax M3 via the opencode provider (oc/minimax-m3-free) appeared blind: image inputs didn't reach the model, while the same model in Cline could see them. Verified empirically that MiniMax M3 on the opencode upstream IS multimodal -- a base64 image is described correctly (it returns 403 only for remote image URLs, which it doesn't accept). Root cause: OmniRoute treated MiniMax M3 as a non-vision model in two places, so when compression was active the image was replaced with a text placeholder before dispatch: - compression's modelSupportsVision() heuristic (lite.ts) only matched gpt-4/4o/claude-3/gemini/vision -- minimax was absent -> replaceImageUrls stripped the image. - the opencode minimax-m3-free catalog entry lacked supportsVision, so the combo vision-capability gate could also exclude/mishandle it. Add 'minimax-m3' to the vision heuristic and supportsVision: true to the opencode minimax-m3-free entry. TDD: a failing-then-passing test in compression/lite.test.ts proves replaceImageUrls now keeps images for minimax-m3 ids, plus a registry assertion mirroring the #2822 qwen test. Reported-by: @mikmaneggahommie * docs(i18n): translate 25 core documentation files to Indonesian (#3348) Integrated into release/v3.8.14 — Indonesian i18n docs. * fix(review): resolve /review-reviews battery findings (LEDGER-1..11) on v3.8.14 (#3350) Integrated into release/v3.8.14 — /review-reviews battery hardening (LEDGER-1..11) for #3338 custom-headers + #3333 kiro, plus cycle-test drift fixes (#3329/#3330/#3332). * fix(provider-proxy): honor per-account proxy toggles (#3349) Integrated into release/v3.8.14 — honor per-account proxy toggles + auto-fallback opt-in via PROXY_AUTO_SELECT_ENABLED. * fix(dashboard): remove duplicate Distribute Proxies button on provider page (#3352) * fix(providers): reduce proxy label noise (#3346) Integrated into release/v3.8.14 — reduce proxy label noise + a11y (aria-label/sr-only). * fix(duckduckgo): restore bare Response contract and rebase onto release/v3.8.14 (#3323) Integrated into release/v3.8.14 — browser-backed cookie providers (duckduckgo/claude-web) with restored executor contract + unit tests. * fix(noauth): expose only usable model aliases (#3345) Integrated into release/v3.8.14 — noauth usable-alias filtering + registry alias plumbing (veo-free). * fix(dashboard): stop infinite config-load loop on Hermes Agent detail page (#3353) * fix(electron): tree-kill the server on exit/update to release the omniroute.exe lock (#3347) (#3354) * chore(release): finalize v3.8.14 changelog + clear release-gate drift - CHANGELOG: finalize the v3.8.14 section (date, full New Features/Bug Fixes/ Maintenance coverage of all 16 cycle commits, Contributors hall of 12). - docs: document OMNIROUTE_BROWSER_POOL + WEB_COOKIE_USE_BROWSER (#3323) in .env.example + ENVIRONMENT.md; regenerate the id/llm.txt strict mirror (#3348 had translated it; llm.txt mirrors must match root). - test(proxy-fetch): #3323 made tlsClient.available a computed getter — stub it via Object.defineProperty instead of assignment (5 tests were red on the base). * fix(translator): coerce Gemini functionDeclaration parameters to an OBJECT schema (#3357) (#3360) * fix(gemini): resolve truncation/suppression of false positive textual tool call markers in backticks (#3358) Integrated into release/v3.8.14 — Gemini/Antigravity textual tool-call marker normalization (no false-positive suppression + split-chunk buffering). * docs(changelog): add #3358 Gemini textual tool-call normalization to v3.8.14 * fix(dashboard): surface real analytics error instead of generic placeholder (#3356) (#3361) The Analytics page discarded the server's error body on a non-OK response and rendered a generic "An error occurred", so users (and maintainers) could not see why /api/usage/analytics 500'd after an upgrade. Now the route returns the real reason via buildErrorBody (sanitized, Hard Rule #12) and the page surfaces it via a new readFetchErrorMessage helper that handles both the OpenAI-style and legacy error shapes. Reported-by: @superti4r --------- Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Someres <168349709+quanturbo@users.noreply.github.com> Co-authored-by: Dong Mengzhe <154944819+Lang-Qiu@users.noreply.github.com> Co-authored-by: mikmaneggahommie <mikmaneggahommie@users.noreply.github.com> Co-authored-by: abdulkadirozyurt <abdulkadirozyurt@users.noreply.github.com> Co-authored-by: hertznsk <hertznsk@users.noreply.github.com> Co-authored-by: Krisna Santosa <54174372+KrisnaSantosa15@users.noreply.github.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Ardem2025 <ardemb22@gmail.com>
13 KiB
Berkontribusi ke OmniRoute (Bahasa Indonesia)
🌐 Languages: 🇺🇸 English · 🇸🇦 ar · 🇧🇬 bg · 🇧🇩 bn · 🇨🇿 cs · 🇩🇰 da · 🇩🇪 de · 🇪🇸 es · 🇮🇷 fa · 🇫🇮 fi · 🇫🇷 fr · 🇮🇳 gu · 🇮🇱 he · 🇮🇳 hi · 🇭🇺 hu · 🇮🇩 id · 🇮🇹 it · 🇯🇵 ja · 🇰🇷 ko · 🇮🇳 mr · 🇲🇾 ms · 🇳🇱 nl · 🇳🇴 no · 🇵🇭 phi · 🇵🇱 pl · 🇵🇹 pt · 🇧🇷 pt-BR · 🇷🇴 ro · 🇷🇺 ru · 🇸🇰 sk · 🇸🇪 sv · 🇰🇪 sw · 🇮🇳 ta · 🇮🇳 te · 🇹🇭 th · 🇹🇷 tr · 🇺🇦 uk-UA · 🇵🇰 ur · 🇻🇳 vi · 🇨🇳 zh-CN
Terima kasih atas minat Anda untuk berkontribusi! Panduan ini mencakup semua yang perlu Anda ketahui untuk memulai.
Pengaturan Pengembangan
Persyaratan
- Node.js >= 18 < 24 (recommended: 22 LTS)
- npm 10+
- Git
Kloning & Instalasi
git clone https://github.com/diegosouzapw/OmniRoute.git
cd OmniRoute
npm install
Variabel Lingkungan
# Create your .env from the template
cp .env.example .env
# Generate required secrets
echo "JWT_SECRET=$(openssl rand -base64 48)" >> .env
echo "API_KEY_SECRET=$(openssl rand -hex 32)" >> .env
Variabel-variabel utama untuk pengembangan:
| Variable | Development Default | Deskripsi |
|---|---|---|
PORT |
20128 |
Port server |
NEXT_PUBLIC_BASE_URL |
http://localhost:20128 |
URL dasar untuk frontend |
JWT_SECRET |
(generate above) | Kunci penandatanganan JWT |
INITIAL_PASSWORD |
CHANGEME |
Kata sandi login pertama |
APP_LOG_LEVEL |
info |
Tingkat verbositas log |
Pengaturan Dashboard
Dashboard menyediakan tombol UI untuk fitur-fitur yang juga dapat dikonfigurasi melalui variabel lingkungan:
| Lokasi Pengaturan | Tombol | Deskripsi |
|---|---|---|
| Settings → Advanced | Debug Mode | Aktifkan log permintaan debug (UI) |
| Settings → General | Sidebar Visibility | Tampilkan/sembunyikan bagian sidebar |
Pengaturan ini disimpan di database dan tetap ada setelah restart, menggantikan nilai default variabel lingkungan jika sudah diatur.
Menjalankan Secara Lokal
# Development mode (hot reload)
npm run dev
# Production build
npm run build
npm run start
# Common port configuration
PORT=20128 NEXT_PUBLIC_BASE_URL=http://localhost:20128 npm run dev
URL default:
- Dashboard:
http://localhost:20128/dashboard - API:
http://localhost:20128/v1
Alur Kerja Git
⚠️ JANGAN PERNAH melakukan commit langsung ke
main. Selalu gunakan cabang fitur.
git checkout -b feat/your-feature-name
# ... make changes ...
git commit -m "feat: describe your change"
git push -u origin feat/your-feature-name
# Open a Pull Request on GitHub
Penamaan Cabang
| Awalan | Tujuan |
|---|---|
feat/ |
Fitur baru |
fix/ |
Perbaikan bug |
refactor/ |
Restrukturisasi kode |
docs/ |
Perubahan dokumentasi |
test/ |
Penambahan/perbaikan tes |
chore/ |
Perkakas, CI, dependensi |
Pesan Commit
Ikuti Conventional Commits:
feat: add circuit breaker for provider calls
fix: resolve JWT secret validation edge case
docs: update SECURITY.md with PII protection
test: add observability unit tests
refactor(db): consolidate rate limit tables
Cakupan: db, sse, oauth, dashboard, api, cli, docker, ci, mcp, a2a, memory, skills.
Menjalankan Tes
# All tests (unit + vitest + ecosystem + e2e)
npm run test:all
# Single test file (Node.js native test runner — most tests use this)
node --import tsx/esm --test tests/unit/your-file.test.ts
# Vitest (MCP server, autoCombo, cache)
npm run test:vitest
# E2E tests (requires Playwright)
npm run test:e2e
# Protocol clients E2E (MCP transports, A2A)
npm run test:protocols:e2e
# Ecosystem compatibility tests
npm run test:ecosystem
# Coverage (60% min statements/lines/functions/branches)
npm run test:coverage
npm run coverage:report
# Lint + format check
npm run lint
npm run check
Catatan cakupan:
npm run test:coveragemengukur cakupan kode sumber untuk rangkaian tes unit utama, mengecualikantests/**, dan menyertakanopen-sse/**- Pull request harus menjaga batas cakupan keseluruhan di 60% atau lebih tinggi untuk pernyataan, baris, fungsi, dan cabang
- Jika sebuah PR mengubah kode produksi di
src/,open-sse/,electron/, ataubin/, PR tersebut harus menambahkan atau memperbarui tes otomatis dalam PR yang sama npm run coverage:reportmencetak laporan terperinci per file dari hasil cakupan terbarunpm run test:coverage:legacymempertahankan metrik lama untuk perbandingan historis- Lihat
docs/ops/COVERAGE_PLAN.mduntuk peta jalan peningkatan cakupan bertahap
Persyaratan Pull Request
Sebelum membuka atau menggabungkan sebuah PR:
- Jalankan
npm run test:unit - Jalankan
npm run test:coverage - Pastikan batas cakupan tetap di 60%+ untuk semua metrik
- Sertakan file tes yang diubah atau ditambahkan dalam deskripsi PR ketika kode produksi berubah
- Periksa hasil SonarQube pada PR ketika rahasia proyek dikonfigurasi di CI
Status tes saat ini: 122 file tes unit yang mencakup:
- Penerjemah penyedia dan konversi format
- Pembatasan laju, pemutus sirkuit, dan ketahanan
- Cache semantik, idempoten, pelacakan progres
- Operasi database dan skema (21 modul DB)
- Alur OAuth dan autentikasi
- Validasi endpoint API (Zod v4)
- Alat server MCP dan penegakan cakupan
- Sistem Memory dan Skills
Gaya Kode
- ESLint — Jalankan
npm run lintsebelum melakukan commit - Prettier — Diformat otomatis melalui
lint-stagedsaat commit (2 spasi, titik koma, tanda kutip ganda, lebar 100 karakter, koma trailing es5) - TypeScript — Semua kode
src/menggunakan.ts/.tsx;open-sse/menggunakan.ts/.js; dokumentasi dengan TSDoc (@param,@returns,@throws) - Tanpa
eval()— ESLint menerapkanno-eval,no-implied-eval,no-new-func - Validasi Zod — Gunakan skema Zod v4 untuk semua validasi input API
- Penamaan: File = camelCase/kebab-case, komponen = PascalCase, konstanta = UPPER_SNAKE
Struktur Proyek
src/ # TypeScript (.ts / .tsx)
├── app/ # Next.js 16 App Router
│ ├── (dashboard)/ # Halaman dashboard (23 bagian)
│ ├── api/ # Rute API (51 direktori)
│ └── login/ # Halaman autentikasi (.tsx)
├── domain/ # Mesin kebijakan (policyEngine, comboResolver, costRules, dll.)
├── lib/ # Logika bisnis inti (.ts)
│ ├── a2a/ # Server protokol Agent-to-Agent v0.3
│ ├── acp/ # Registri Agent Communication Protocol
│ ├── compliance/ # Mesin kebijakan kepatuhan
│ ├── db/ # Lapisan database SQLite (21 modul + 16 migrasi)
│ ├── memory/ # Memori percakapan persisten
│ ├── oauth/ # Penyedia, layanan, dan utilitas OAuth
│ ├── skills/ # Kerangka skill yang dapat diperluas
│ ├── usage/ # Pelacakan penggunaan dan kalkulasi biaya
│ └── localDb.ts # Lapisan re-ekspor saja — jangan pernah tambahkan logika di sini
├── middleware/ # Middleware permintaan (promptInjectionGuard)
├── mitm/ # Proxy MITM (sertifikat, DNS, perutean target)
├── shared/
│ ├── components/ # Komponen React (.tsx)
│ ├── constants/ # Definisi penyedia (60+), cakupan MCP, strategi perutean
│ ├── utils/ # Pemutus sirkuit, sanitizer, pembantu autentikasi
│ └── validation/ # Skema Zod v4
└── sse/ # Pipeline proxy SSE
open-sse/ # Workspace @omniroute/open-sse
├── executors/ # 14 eksekutor permintaan khusus penyedia
├── handlers/ # 11 penangan permintaan (chat, responses, embeddings, images, dll.)
├── mcp-server/ # Server MCP (25 alat, 3 transport, 10 cakupan)
├── services/ # 36+ layanan (combo, autoCombo, rateLimitManager, dll.)
├── translator/ # Penerjemah format (OpenAI ↔ Claude ↔ Gemini ↔ Responses ↔ Ollama)
├── transformer/ # Transformer Responses API
└── utils/ # 22 modul utilitas (stream, TLS, proxy, logging)
electron/ # Aplikasi desktop Electron (lintas platform)
tests/
├── unit/ # Runner tes Node.js (122 file tes)
├── integration/ # Tes integrasi
├── e2e/ # Tes Playwright
├── security/ # Tes keamanan
├── translator/ # Tes khusus penerjemah
└── load/ # Tes beban
docs/ # Dokumentasi
├── ARCHITECTURE.md # Arsitektur sistem
├── API_REFERENCE.md # Semua endpoint
├── USER_GUIDE.md # Pengaturan penyedia, integrasi CLI
├── TROUBLESHOOTING.md # Masalah umum
├── MCP-SERVER.md # Server MCP (25 alat)
├── A2A-SERVER.md # Protokol agen A2A
├── AUTO-COMBO.md # Mesin auto-combo
├── CLI-TOOLS.md # Integrasi alat CLI
├── COVERAGE_PLAN.md # Rencana peningkatan cakupan tes
├── openapi.yaml # Spesifikasi OpenAPI
└── adr/ # Catatan Keputusan Arsitektur
Menambahkan Penyedia Baru
Langkah 1: Daftarkan Konstanta Penyedia
Tambahkan ke src/shared/constants/providers.ts — divalidasi dengan Zod saat modul dimuat.
Langkah 2: Tambahkan Eksekutor (jika diperlukan logika kustom)
Buat eksekutor di open-sse/executors/your-provider.ts dengan memperluas eksekutor dasar.
Langkah 3: Tambahkan Penerjemah (jika format bukan OpenAI)
Buat penerjemah permintaan/respons di open-sse/translator/.
Langkah 4: Tambahkan Konfigurasi OAuth (jika berbasis OAuth)
Tambahkan kredensial OAuth di src/lib/oauth/constants/oauth.ts dan layanan di src/lib/oauth/services/.
Langkah 5: Daftarkan Model
Tambahkan definisi model di open-sse/config/providerRegistry.ts.
Langkah 6: Tambahkan Tes
Tulis tes unit di tests/unit/ yang mencakup minimal:
- Pendaftaran penyedia
- Terjemahan permintaan/respons
- Penanganan kesalahan
Daftar Periksa Pull Request
- Tes lulus (
npm test) - Linting lulus (
npm run lint) - Build berhasil (
npm run build) - Tipe TypeScript ditambahkan untuk fungsi dan antarmuka publik baru
- Tidak ada rahasia atau nilai fallback yang dikodekan secara keras
- Semua input divalidasi dengan skema Zod
- CHANGELOG diperbarui (jika ada perubahan yang terlihat pengguna)
- Dokumentasi diperbarui (jika berlaku)
Rilis
Rilis dikelola melalui alur kerja /generate-release. Ketika GitHub Release baru dibuat, paket secara otomatis diterbitkan ke npm melalui GitHub Actions.
Mendapatkan Bantuan
- Arsitektur: Lihat
docs/architecture/ARCHITECTURE.md - Referensi API: Lihat
docs/reference/API_REFERENCE.md - Masalah: github.com/diegosouzapw/OmniRoute/issues
- ADR: Lihat
docs/adr/untuk catatan keputusan arsitektur