mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-26 09:52:11 +03:00
* chore(release): open v3.8.21 development cycle
* fix: pass through valid max_tokens-truncated responses instead of fake 502 (#3572) (#3595)
* fix: /v1/completions returns legacy text-completion format, not chat (#3571) (#3596)
* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (#3580) (#3597)
* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (#3498) (#3599)
* fix(agent-bridge): add validate-only upstream-ca/test route (#3488) (#3600)
* fix(gamification): add level/badges/badges-earned profile routes (#3484)
* security(oauth): migrate 5 public client_ids to resolvePublicCred (#3493)
* fix(mcp): ship MCP server source closure in npm files + coverage gate (#3578)
* fix: add reasoning token buffer for combo routing (fixes #3587) (#3588)
Integrated into release/v3.8.21
* Refactor: Extract chatCore phases into modular files (#3598)
Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!
* docs(changelog): credit #3598 (chatCore modularization) + #3588 (combo reasoning buffer)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (#3496) (#3602)
Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
* fix(gemini): isolate textual reasoning wrappers (#3605)
Split-out PR C from #3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the #3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!
* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (#3603)
Split-out PR A from #3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!
* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (#3606) (#3608)
Integrated into release/v3.8.21 (#3606)
* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (#3589) (#3609)
Integrated into release/v3.8.21 (#3589)
* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (#3419) (#3613)
Integrated into release/v3.8.21 (#3419)
* fix(usage): normalize Antigravity and agy provider quotas (#3604)
Split-out PR B from #3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!
* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (#3331) (#3614)
Integrated into release/v3.8.21 (#3331)
* docs(changelog): credit #3603 (Flash tier IDs) + #3604 (provider quotas) + #3605 (reasoning wrappers)
Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (#3618)
Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 797de433f.
* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync
---------
Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
108 lines
4.5 KiB
TypeScript
108 lines
4.5 KiB
TypeScript
/**
|
|
* LEDGER-2 (#3821-review) — getSanitizedCachedProviderLimitsMap is polled by the
|
|
* ProviderLimits dashboard on an auto-refresh interval. It used to run an
|
|
* unconditional `SELECT * FROM provider_connections` (decrypting every active
|
|
* connection's credentials) on every poll, even though quota-key sanitization only
|
|
* ever rewrites Antigravity/agy entries. The fix scopes the connection scan to
|
|
* antigravity/agy (and skips it entirely for an empty cache).
|
|
*
|
|
* These tests pin the BEHAVIOR the optimization must preserve:
|
|
* 1. empty cache → {} (no scan needed)
|
|
* 2. non-Antigravity entry → returned verbatim (a junk quota key survives), proving
|
|
* entries whose connection is no longer fetched are still passed through unchanged
|
|
* 3. Antigravity entry → still sanitized (a non-user-callable quota key is dropped),
|
|
* proving the scoped query still feeds the sanitizer
|
|
*
|
|
* (2) is the load-bearing case: with the old code the openai connection was fetched and
|
|
* present in the lookup; with the new code it is NOT fetched at all, yet the output must
|
|
* be identical — which it is, because sanitizeProviderLimitsCacheForConnection returns
|
|
* the entry unchanged when no matching connection is supplied.
|
|
*/
|
|
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import fs from "node:fs";
|
|
import os from "node:os";
|
|
import path from "node:path";
|
|
|
|
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-plimits-scope-"));
|
|
process.env.DATA_DIR = TEST_DATA_DIR;
|
|
process.env.API_KEY_SECRET = "test-plimits-scope-secret";
|
|
|
|
const core = await import("../../src/lib/db/core.ts");
|
|
const providersDb = await import("../../src/lib/db/providers.ts");
|
|
const providerLimitsDb = await import("../../src/lib/db/providerLimits.ts");
|
|
const providerLimits = await import("../../src/lib/usage/providerLimits.ts");
|
|
|
|
test.beforeEach(() => {
|
|
core.resetDbInstance();
|
|
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
|
|
fs.mkdirSync(TEST_DATA_DIR, { recursive: true });
|
|
});
|
|
|
|
test.after(() => {
|
|
core.resetDbInstance();
|
|
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
|
|
});
|
|
|
|
function cacheEntry(quotas: Record<string, unknown>) {
|
|
return {
|
|
quotas,
|
|
plan: null,
|
|
message: null,
|
|
fetchedAt: new Date(0).toISOString(),
|
|
source: null,
|
|
};
|
|
}
|
|
|
|
test("empty provider-limits cache returns {} without any connection scan", async () => {
|
|
const out = await providerLimits.getSanitizedCachedProviderLimitsMap();
|
|
assert.deepEqual(out, {});
|
|
});
|
|
|
|
test("non-Antigravity cache entry is returned verbatim (junk quota key survives)", async () => {
|
|
// An active openai connection whose credentials would be decrypted by the old
|
|
// unconditional scan. Under the fix it is never fetched — the entry must still pass
|
|
// through unchanged.
|
|
const conn = await providersDb.createProviderConnection({
|
|
provider: "openai",
|
|
authType: "api_key",
|
|
name: "OpenAI key",
|
|
apiKey: "sk-test-openai",
|
|
});
|
|
const quotas = { "definitely-not-a-real-model": { used: 1, limit: 10 } };
|
|
providerLimitsDb.setProviderLimitsCache((conn as { id: string }).id, cacheEntry(quotas));
|
|
|
|
const out = await providerLimits.getSanitizedCachedProviderLimitsMap();
|
|
const entry = out[(conn as { id: string }).id];
|
|
assert.ok(entry, "openai cache entry should be present");
|
|
// Sanitization is antigravity/agy-only → the junk key is NOT dropped for openai.
|
|
assert.deepEqual(entry.quotas, quotas);
|
|
});
|
|
|
|
test("Antigravity cache entry is still sanitized (non-user-callable quota key dropped)", async () => {
|
|
const conn = await providersDb.createProviderConnection({
|
|
provider: "antigravity",
|
|
authType: "oauth",
|
|
name: "Antigravity acct",
|
|
email: "antigravity@example.test",
|
|
accessToken: "ag-access",
|
|
refreshToken: "ag-refresh",
|
|
expiresAt: new Date(Date.now() + 3_600_000).toISOString(),
|
|
});
|
|
// `credits` is always allowed; the junk model id is not user-callable → dropped.
|
|
const quotas = {
|
|
credits: { used: 5, limit: 100 },
|
|
"definitely-not-a-real-model": { used: 1, limit: 10 },
|
|
};
|
|
providerLimitsDb.setProviderLimitsCache((conn as { id: string }).id, cacheEntry(quotas));
|
|
|
|
const out = await providerLimits.getSanitizedCachedProviderLimitsMap();
|
|
const entry = out[(conn as { id: string }).id];
|
|
assert.ok(entry?.quotas, "antigravity cache entry should be present");
|
|
assert.ok("credits" in (entry.quotas as Record<string, unknown>), "credits is kept");
|
|
assert.ok(
|
|
!("definitely-not-a-real-model" in (entry.quotas as Record<string, unknown>)),
|
|
"non-user-callable quota key is dropped for antigravity"
|
|
);
|
|
});
|