mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-26 09:52:11 +03:00
* chore(release): open v3.8.10 development cycle Bump 3.8.9 → 3.8.10 across package.json, lockfile, electron, open-sse, and docs/reference/openapi.yaml; add the [3.8.10] CHANGELOG section (root + 41 i18n mirrors) as the integration target for the cycle. Entries land here as work merges into release/v3.8.10; finalized by the release flow. * fix(providers): resolve web provider alias collisions Assign unique aliases to HuggingChat, Kimi Web, and Qwen Web so they no longer shadow primary providers or trigger startup warnings. Add a unit test to enforce provider alias uniqueness and prevent future collisions. Also expand local ignore and VS Code exclude rules for agent, build, and worktree artifacts. * fix(responses): normalize image_url parts across input paths (#3150) Normalize image_url parts across all Responses input paths. Integrated into release/v3.8.10. * fix(api-manager): preserve API key expiration local time (#3146) Preserve API key expiration local time + clear button. Integrated into release/v3.8.10. * Strip previous_response_id for stateless Responses upstreams (#3143) Strip previous_response_id for stateless Responses upstreams (auto/strip/preserve). Integrated into release/v3.8.10. * fix(opencode-plugin): map thinking cap to interleaved in model+combo (#3138) Map caps.thinking to ModelV2.capabilities.interleaved for opencode-plugin. Integrated into release/v3.8.10. * fix(providers): use synced models as fallback for all providers (#3148) Use synced models as authoritative local catalog for all providers (+regression test). Integrated into release/v3.8.10. * fix(qoder): bifurcate validation by token type — PAT→Cosy, regular API key→dashscope (#3149) Bifurcate Qoder validation by token type (PAT→Cosy, regular→dashscope) +regression test. Integrated into release/v3.8.10. * fix(antigravity): dynamic model resolution via MITM alias table (#3144) Dynamic antigravity MITM model resolution in the executor (+bug fix +regression test; DB import dropped from client-reachable config). Integrated into release/v3.8.10. * Feature/batch allow big (#3128) Podman deployment options + larger upload body-size limits (+CONTAINER_HOST docs). Integrated into release/v3.8.10. * fix(fireworks): preserve fully-qualified router/model IDs (#3133) (#3160) Fireworks router IDs (accounts/fireworks/routers/...) were double-prefixed with accounts/fireworks/models/ → upstream 404. Add optional acceptedModelIdPrefixes to the registry entry and skip the prepend when the model already starts with an accepted prefix. Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com> * fix(llama-cpp): route to configured local baseUrl instead of OpenAI (#3136) (#3161) llama-cpp was missing from the local-provider group in buildUrl(), so it fell through to the OpenAI baseUrl and returned an OpenAI 401. Add the case to resolve the connection's providerSpecificData.baseUrl. Co-authored-by: tjengbudi <tjengbudi@users.noreply.github.com> * fix(t3-chat-web): parse cookies + convexSessionId from stored credential (#3007) (#3162) The executor read credentials.cookies/convexSessionId, but the pipeline only stores the pasted string under apiKey → t3.chat always 400'd. Parse both values from apiKey (fallback accessToken), mirroring validation.ts. Co-authored-by: minhtran162 <minhtran162@users.noreply.github.com> * fix(minimax): stop capping MiniMax-M3 / M2.7 max_tokens at 8192 (#3141) (#3163) MiniMax-M3 had no MODEL_SPECS entry and capitalized MiniMax-M2.7 missed its lowercase spec (case-sensitive lookup) → both fell to the 8192 default cap. Add the M3 spec (512K output), alias the capitalized ids, and make getModelSpec lookups case-insensitive. Co-authored-by: totaltube <totaltube@users.noreply.github.com> * fix(github-copilot): discover model catalog live from api.githubcopilot.com (#3120, #3121) (#3164) The github (Copilot) provider had a static hardcoded catalog with no discovery source, so Import Models never refreshed (#3120) and advertised non-entitled models that 400 on use (#3121). Add a live /models fetch with fallback to the static list. Co-authored-by: gabrielmoreira <gabrielmoreira@users.noreply.github.com> * fix(combo): invalidate nested-combo cache on edits + log DATA_DIR (#3147) (#3165) Editing a combo did not invalidate the 10s nested-combo expansion caches (chat.ts getCombosCachedForChat + chatCore.ts getCombosCached; the exported clearCombosCache was dead code), so a removed nested target/model could be served as a phantom for up to 10s. Wire a shared monotonic combos-cache version in readCache (bumped by invalidateDbCache("combos") on every combo write); both cache layers treat a version mismatch as a miss. Also log the resolved DATA_DIR/SQLITE_FILE absolute path at DB init so the reporter's 'persists across restart + volume wipe' symptom (a multi-replica Docker volume/DATA_DIR mismatch, not a routing bug) is diagnosable from logs. Includes consolidated CHANGELOG entries for #3133/#3136/#3007/#3141/#3120/#3121. Co-authored-by: ViFigueiredo <ViFigueiredo@users.noreply.github.com> * fix(web-tools): parse bare JSON tool calls (#3157) Parse bare JSON tool calls for deepseek-web (#2820) + fuzzy tool-name matching. Integrated into release/v3.8.10. * fix(misc): minor fixes across reasoning cache, account fallback, binary manager (#3177) Misc: ProviderProfile export, DeepSeek reasoning regex, binary guard. Integrated into release/v3.8.10. * fix(kiro): minor OAuth social exchange tweaks (#3176) Kiro social OAuth: optional targetProvider passthrough. Integrated into release/v3.8.10. * deps: bump hono from 4.12.18 to 4.12.23 (#3179) Bump hono to 4.12.23. Integrated into release/v3.8.10. * fix(providerRegistry): update kilocode format and executor (#3166) kilocode: openai format + default executor (matches kilo-gateway) + registry test. Integrated into release/v3.8.10. * feat(metrics): cross-request TTFT and gap latency after tool calls (#3173) Cross-request TTFT + gap-after-tool latency metrics (+test). Integrated into release/v3.8.10. * feat(dashboard): provider stats API endpoint and dashboard page (#3175) Provider stats dashboard + API (SQL moved to db module per Hard Rule #5, +test). Integrated into release/v3.8.10. * fix(usage): sequential+spaced OAuth quota sync, reactive force-refresh, actionable 401 (#3156) Sequential+spaced OAuth quota sync, reactive force-refresh on 401, actionable 401 in UI. Integrated into release/v3.8.10. * fix(healthcheck): per-provider proactive-refresh skip list (rescue short-TTL OAuth) (#3159) Per-provider proactive-refresh skip list (OMNIROUTE_HEALTHCHECK_SKIP_PROVIDERS) to rescue short-TTL OAuth. Integrated into release/v3.8.10. * feat(quota): show OAuth token expiry on provider cards (small, blue, informative) (#3178) Show OAuth token expiry on provider cards (small, blue, informative). Integrated into release/v3.8.10. * fix(providers): empty refresh must not resurface just-cleared synced models (#3181) Empty refresh must not resurface just-cleared synced models (fixes the release-blocking provider-models-route test). Integrated into release/v3.8.10. * chore(release): v3.8.10 — 2026-06-04 (finalize CHANGELOG) --------- Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Xiangzhe <32761048+xz-dev@users.noreply.github.com> Co-authored-by: Jan Leon <Jan.gaschler@gmail.com> Co-authored-by: M.M <mr.maatoug@gmail.com> Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com> Co-authored-by: Markus Hartung <mail@hartmark.se> Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com> Co-authored-by: tjengbudi <tjengbudi@users.noreply.github.com> Co-authored-by: minhtran162 <minhtran162@users.noreply.github.com> Co-authored-by: totaltube <totaltube@users.noreply.github.com> Co-authored-by: gabrielmoreira <gabrielmoreira@users.noreply.github.com> Co-authored-by: ViFigueiredo <ViFigueiredo@users.noreply.github.com> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Nicolas Lorin <androw95220@gmail.com>
381 lines
12 KiB
TypeScript
381 lines
12 KiB
TypeScript
/**
|
|
* Session Fingerprinting — Phase 5
|
|
*
|
|
* Generates stable session IDs for sticky routing,
|
|
* prompt caching, and per-session tracking.
|
|
*/
|
|
|
|
import { createHash } from "node:crypto";
|
|
|
|
interface SessionEntry {
|
|
createdAt: number;
|
|
lastActive: number;
|
|
requestCount: number;
|
|
connectionId: string | null;
|
|
/** Timestamp when the last tool_calls finish_reason was emitted (cross-request TTFT tracking) */
|
|
lastToolFinishAt?: number;
|
|
}
|
|
|
|
interface SessionFingerprintOptions {
|
|
provider?: string;
|
|
connectionId?: string;
|
|
}
|
|
|
|
interface SessionMessage {
|
|
role?: string;
|
|
content?: unknown;
|
|
}
|
|
|
|
interface SessionBody {
|
|
model?: string;
|
|
system?: unknown;
|
|
tools?: Array<{ name?: string; function?: { name?: string } }>;
|
|
messages?: SessionMessage[];
|
|
input?: SessionMessage[];
|
|
}
|
|
|
|
// In-memory session store with metadata
|
|
// key: sessionId → { createdAt, lastActive, requestCount, connectionId? }
|
|
const sessions = new Map<string, SessionEntry>();
|
|
|
|
// Hard cap on active sessions to prevent memory exhaustion
|
|
const MAX_SESSIONS = 200;
|
|
|
|
// Auto-cleanup sessions older than 15 minutes (reduced from 30)
|
|
const SESSION_TTL_MS = 15 * 60 * 1000;
|
|
const _cleanupTimer = setInterval(() => {
|
|
const now = Date.now();
|
|
// Evict expired sessions
|
|
for (const [key, entry] of sessions) {
|
|
if (now - entry.lastActive > SESSION_TTL_MS) {
|
|
sessions.delete(key);
|
|
const keysToDelete: string[] = [];
|
|
for (const [apiKeyId, sessionSet] of activeSessionsByKey) {
|
|
sessionSet.delete(key);
|
|
if (sessionSet.size === 0) keysToDelete.push(apiKeyId);
|
|
}
|
|
for (const k of keysToDelete) {
|
|
activeSessionsByKey.delete(k);
|
|
}
|
|
}
|
|
}
|
|
// Hard cap: evict oldest if over limit
|
|
while (sessions.size > MAX_SESSIONS) {
|
|
let oldestKey: string | null = null;
|
|
let oldestTime = Infinity;
|
|
for (const [key, entry] of sessions) {
|
|
if (entry.lastActive < oldestTime) {
|
|
oldestTime = entry.lastActive;
|
|
oldestKey = key;
|
|
}
|
|
}
|
|
if (oldestKey === null) break;
|
|
sessions.delete(oldestKey);
|
|
const evictionKeys: string[] = [];
|
|
for (const [apiKeyId, sessionSet] of activeSessionsByKey) {
|
|
sessionSet.delete(oldestKey);
|
|
if (sessionSet.size === 0) evictionKeys.push(apiKeyId);
|
|
}
|
|
for (const k of evictionKeys) {
|
|
activeSessionsByKey.delete(k);
|
|
}
|
|
}
|
|
}, 60_000);
|
|
if (typeof _cleanupTimer === "object" && "unref" in _cleanupTimer) {
|
|
(_cleanupTimer as { unref?: () => void }).unref?.();
|
|
}
|
|
|
|
/**
|
|
* Generate a stable session fingerprint from request characteristics.
|
|
* Same client + same conversation → same session ID.
|
|
*
|
|
* Fingerprint factors:
|
|
* - System prompt hash (stable per conversation/tool)
|
|
* - First user message hash (stable per conversation)
|
|
* - Model name
|
|
* - Provider (optional)
|
|
* - Tools signature (sorted tool names)
|
|
*
|
|
* @param {object} body - Request body
|
|
* @param {object} [options] - Extra context
|
|
* @returns {string} Session ID (hex hash)
|
|
*/
|
|
export function generateSessionId(
|
|
body: SessionBody | null | undefined,
|
|
options: SessionFingerprintOptions = {}
|
|
): string | null {
|
|
if (!body || typeof body !== "object") return null;
|
|
const parts: string[] = [];
|
|
|
|
// Model contributes to fingerprint
|
|
if (body.model) parts.push(`model:${body.model}`);
|
|
|
|
// Provider binding
|
|
if (options.provider) parts.push(`provider:${options.provider}`);
|
|
|
|
// System prompt hash (first 32 chars of system content)
|
|
const systemPrompt = extractSystemPrompt(body);
|
|
if (systemPrompt) {
|
|
parts.push(`sys:${hashShort(systemPrompt)}`);
|
|
}
|
|
|
|
// First user message hash (identifies the conversation)
|
|
const firstUser = extractFirstUserMessage(body);
|
|
if (firstUser) {
|
|
parts.push(`user0:${hashShort(firstUser)}`);
|
|
}
|
|
|
|
// Tools signature (sorted names)
|
|
if (body.tools && Array.isArray(body.tools) && body.tools.length > 0) {
|
|
const toolNames = body.tools
|
|
.map((t) => t.name || t.function?.name || "")
|
|
.filter(Boolean)
|
|
.sort()
|
|
.join(",");
|
|
if (toolNames) parts.push(`tools:${hashShort(toolNames)}`);
|
|
}
|
|
|
|
// Connection ID for sticky routing
|
|
if (options.connectionId) parts.push(`conn:${options.connectionId}`);
|
|
|
|
if (parts.length === 0) return null;
|
|
|
|
const fingerprint = parts.join("|");
|
|
return createHash("sha256").update(fingerprint).digest("hex").slice(0, 16);
|
|
}
|
|
|
|
/**
|
|
* Touch or create a session
|
|
*/
|
|
export function touchSession(sessionId: string | null, connectionId: string | null = null): void {
|
|
if (!sessionId) return;
|
|
const existing = sessions.get(sessionId);
|
|
if (existing) {
|
|
existing.lastActive = Date.now();
|
|
existing.requestCount++;
|
|
if (connectionId) existing.connectionId = connectionId;
|
|
} else {
|
|
sessions.set(sessionId, {
|
|
createdAt: Date.now(),
|
|
lastActive: Date.now(),
|
|
requestCount: 1,
|
|
connectionId,
|
|
});
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Persist the tool-finish timestamp so Request 2 (the follow-up after tool execution)
|
|
* can measure cross-request TTFT.
|
|
*/
|
|
export function markToolFinish(sessionId: string | null): void {
|
|
if (!sessionId) return;
|
|
const session = sessions.get(sessionId);
|
|
if (session) session.lastToolFinishAt = Date.now();
|
|
}
|
|
|
|
/**
|
|
* Consume the previously persisted tool-finish timestamp (one-shot: clears after read).
|
|
* Returns null if no pending timestamp or session not found.
|
|
*/
|
|
export function consumeToolFinishTime(sessionId: string | null): number | null {
|
|
if (!sessionId) return null;
|
|
const session = sessions.get(sessionId);
|
|
if (!session?.lastToolFinishAt) return null;
|
|
const ts = session.lastToolFinishAt;
|
|
session.lastToolFinishAt = undefined;
|
|
return ts;
|
|
}
|
|
|
|
/**
|
|
* Get session info (for sticky routing decisions)
|
|
*/
|
|
export function getSessionInfo(sessionId: string | null): SessionEntry | null {
|
|
if (!sessionId) return null;
|
|
const entry = sessions.get(sessionId);
|
|
if (!entry) return null;
|
|
if (Date.now() - entry.lastActive > SESSION_TTL_MS) {
|
|
sessions.delete(sessionId);
|
|
return null;
|
|
}
|
|
return { ...entry };
|
|
}
|
|
|
|
/**
|
|
* Get the bound connection for a session (sticky routing)
|
|
*/
|
|
export function getSessionConnection(sessionId: string | null): string | null {
|
|
const info = getSessionInfo(sessionId);
|
|
return info?.connectionId || null;
|
|
}
|
|
|
|
/**
|
|
* Get session count (for dashboard)
|
|
*/
|
|
export function getActiveSessionCount(): number {
|
|
return sessions.size;
|
|
}
|
|
|
|
/**
|
|
* Get all active sessions (for dashboard)
|
|
*/
|
|
export function getActiveSessions(): Array<SessionEntry & { sessionId: string; ageMs: number }> {
|
|
const now = Date.now();
|
|
const result: Array<SessionEntry & { sessionId: string; ageMs: number }> = [];
|
|
for (const [id, entry] of sessions) {
|
|
if (now - entry.lastActive <= SESSION_TTL_MS) {
|
|
result.push({ sessionId: id, ...entry, ageMs: now - entry.createdAt });
|
|
}
|
|
}
|
|
return result;
|
|
}
|
|
|
|
/**
|
|
* Clear all sessions (for testing)
|
|
*/
|
|
export function clearSessions(): void {
|
|
sessions.clear();
|
|
activeSessionsByKey.clear();
|
|
}
|
|
|
|
// ─── T08: Per-API-Key Session Limit ─────────────────────────────────────────
|
|
// Tracks concurrent sticky sessions per API key and enforces max_sessions limits.
|
|
// Ref: sub2api PR #634 (fix: stabilize session hash + add user-level session limit)
|
|
|
|
// Map: apiKeyId → Set<sessionId>
|
|
const activeSessionsByKey = new Map<string, Set<string>>();
|
|
|
|
/**
|
|
* T08: Get the number of currently active sessions for an API key.
|
|
* @param apiKeyId - The API key's UUID from the database
|
|
*/
|
|
export function getActiveSessionCountForKey(apiKeyId: string): number {
|
|
return activeSessionsByKey.get(apiKeyId)?.size ?? 0;
|
|
}
|
|
|
|
/**
|
|
* Snapshot of active session counts per API key.
|
|
*/
|
|
export function getAllActiveSessionCountsByKey(): Record<string, number> {
|
|
const out: Record<string, number> = {};
|
|
for (const [apiKeyId, sessionIds] of activeSessionsByKey) {
|
|
out[apiKeyId] = sessionIds.size;
|
|
}
|
|
return out;
|
|
}
|
|
|
|
/**
|
|
* T08: Register a session as belonging to an API key.
|
|
* Call this after session creation is allowed (i.e., limit check passed).
|
|
*/
|
|
export function registerKeySession(apiKeyId: string, sessionId: string): void {
|
|
if (!activeSessionsByKey.has(apiKeyId)) {
|
|
activeSessionsByKey.set(apiKeyId, new Set());
|
|
}
|
|
activeSessionsByKey.get(apiKeyId)!.add(sessionId);
|
|
}
|
|
|
|
/**
|
|
* Check whether a given session is already registered for an API key.
|
|
*/
|
|
export function isSessionRegisteredForKey(apiKeyId: string, sessionId: string): boolean {
|
|
return activeSessionsByKey.get(apiKeyId)?.has(sessionId) === true;
|
|
}
|
|
|
|
/**
|
|
* T08: Unregister a session from an API key's active set.
|
|
* Call this when the request closes or the session TTL expires.
|
|
*/
|
|
export function unregisterKeySession(apiKeyId: string, sessionId: string): void {
|
|
activeSessionsByKey.get(apiKeyId)?.delete(sessionId);
|
|
// Clean up empty sets to avoid memory leaks
|
|
if (activeSessionsByKey.get(apiKeyId)?.size === 0) {
|
|
activeSessionsByKey.delete(apiKeyId);
|
|
}
|
|
}
|
|
|
|
/**
|
|
* T08: Check whether adding a new session would exceed the key's max_sessions limit.
|
|
* Returns null if allowed, or an error object to return as a 429 response.
|
|
*
|
|
* @param apiKeyId - The API key's UUID
|
|
* @param maxSessions - The limit from the DB (0 = unlimited)
|
|
*/
|
|
export function checkSessionLimit(
|
|
apiKeyId: string,
|
|
maxSessions: number
|
|
): { code: "SESSION_LIMIT_EXCEEDED"; message: string; limit: number; current: number } | null {
|
|
if (!maxSessions || maxSessions <= 0) return null; // unlimited
|
|
const current = getActiveSessionCountForKey(apiKeyId);
|
|
if (current < maxSessions) return null;
|
|
return {
|
|
code: "SESSION_LIMIT_EXCEEDED",
|
|
message:
|
|
`You have reached the maximum number of active sessions (${maxSessions}). ` +
|
|
`Please close unused sessions or wait for them to expire.`,
|
|
limit: maxSessions,
|
|
current,
|
|
};
|
|
}
|
|
|
|
/**
|
|
* T04: Extract an external session ID from request headers.
|
|
* Accepts both hyphenated and underscore forms for Nginx compatibility.
|
|
* Nginx drops headers with underscores by default — use `underscores_in_headers on`
|
|
* in nginx.conf, or use X-Session-Id (hyphenated) which passes cleanly.
|
|
*
|
|
* Ref: sub2api README + PR #634
|
|
*
|
|
* @param headers - Request headers (Headers object or plain object with .get())
|
|
* @returns External session ID with "ext:" prefix, or null
|
|
*/
|
|
export function extractExternalSessionId(
|
|
headers: Headers | { get?: (n: string) => string | null } | null | undefined
|
|
): string | null {
|
|
if (!headers || typeof (headers as Headers).get !== "function") return null;
|
|
const h = headers as Headers;
|
|
const raw =
|
|
h.get("x-session-id") ?? // Preferred: hyphenated (passes through Nginx)
|
|
h.get("x_session_id") ?? // Underscore variant (direct HTTP / custom clients)
|
|
h.get("x-omniroute-session") ?? // OmniRoute-specific form
|
|
h.get("session-id") ?? // Bare session-id
|
|
null;
|
|
if (!raw || !raw.trim()) return null;
|
|
// Prefix "ext:" to ensure no collision with internal SHA-256 hash IDs
|
|
return `ext:${raw.trim().slice(0, 64)}`; // max 64 chars to avoid abuse
|
|
}
|
|
|
|
// ─── Internal Helpers ───────────────────────────────────────────────────────
|
|
|
|
function hashShort(text: string): string {
|
|
return createHash("sha256").update(text).digest("hex").slice(0, 8);
|
|
}
|
|
|
|
function extractSystemPrompt(body: SessionBody | null | undefined): string | null {
|
|
if (!body || typeof body !== "object") return null;
|
|
// Claude format: body.system
|
|
if (body.system) {
|
|
return typeof body.system === "string" ? body.system : JSON.stringify(body.system);
|
|
}
|
|
// OpenAI format: messages[0].role === "system"
|
|
if (Array.isArray(body.messages)) {
|
|
const sys = body.messages.find((m) => m.role === "system" || m.role === "developer");
|
|
if (sys) {
|
|
return typeof sys.content === "string" ? sys.content : JSON.stringify(sys.content);
|
|
}
|
|
}
|
|
return null;
|
|
}
|
|
|
|
function extractFirstUserMessage(body: SessionBody | null | undefined): string | null {
|
|
if (!body || typeof body !== "object") return null;
|
|
const messages = body.messages || body.input || [];
|
|
if (!Array.isArray(messages)) return null;
|
|
for (const msg of messages) {
|
|
if (msg.role === "user") {
|
|
return typeof msg.content === "string" ? msg.content : JSON.stringify(msg.content);
|
|
}
|
|
}
|
|
return null;
|
|
}
|