Files
OmniRoute/open-sse/services/adobeFireflySecurity.ts
Praveen K Palaniswamy 65e81158ab fix(ollama): route models by advertised capability (#11088)
Landed with the design call resolved per the owner's pick — **option 1**: the synced store is now endpoint-agnostic (persistDiscoveredModels and managedModelImport no longer drop non-chat models at write time), and chat selectability moved to read time (auto-pool expansion in autoStrategy applies filterChatSelectableModels; the models-route projection already had its chatOnly filter). Your discovery test now passes end-to-end (3/3): /api/show capabilities persist per connection and image/embedding requests route through the advertising host.

Reconciliation notes: conflicted areas merged onto the current tip (adobe discovery import, requestedModel preflight signature, resolvedProvider fast-path coexists with the synced-route override — explicit resolution wins); carried base-red drains (#10055 memoization, #11071 test variants) dropped as already-landed; the managed-model-import exclusion test was propagated to the new contract (image/video models persist; the read filter still hides them from chat pickers — pinned by a new assertion). Full battery: 205/206 focused (the one red is a confirmed periodic-timer timing flake on the loaded devbox — 20/20 isolated), autoCombo vitest 30/30, combo suites 46/46, gates + typecheck clean.

Thank you @yourspraveen — the capability probe + routing design was right; it just needed the store contract opened up. Fixes #11087.
2026-08-23 11:45:01 -03:00

55 lines
1.9 KiB
TypeScript

const ADOBE_JWT_IN_TEXT_REGEX =
/eyJ[A-Za-z0-9_-]{1,4096}\.[A-Za-z0-9_-]{1,4096}\.[A-Za-z0-9_-]{1,4096}/;
const ADOBE_JWT_IN_TEXT_GLOBAL_REGEX =
/eyJ[A-Za-z0-9_-]{1,4096}\.[A-Za-z0-9_-]{1,4096}\.[A-Za-z0-9_-]{1,4096}/g;
const ADOBE_JWT_EXACT_REGEX =
/^eyJ[A-Za-z0-9_-]{1,4096}\.[A-Za-z0-9_-]{1,4096}\.[A-Za-z0-9_-]{1,4096}$/;
const FIREFLY_3P_HOST_SUFFIX = "firefly-3p.ff.adobe.io";
export function decodeAdobeJwtPayload(token: string): Record<string, unknown> | null {
try {
let raw = String(token || "")
.trim()
.replace(/^bearer\s+/i, "")
.trim();
const match = raw.match(ADOBE_JWT_IN_TEXT_REGEX);
if (match) raw = match[0];
const part = raw.split(".")[1];
if (!part) return null;
const json = Buffer.from(part.replace(/-/g, "+").replace(/_/g, "/"), "base64").toString("utf8");
const value: unknown = JSON.parse(json);
return value && typeof value === "object" ? (value as Record<string, unknown>) : null;
} catch {
return null;
}
}
export function findAllAdobeJwts(value: string): string[] {
return value.match(ADOBE_JWT_IN_TEXT_GLOBAL_REGEX) ?? [];
}
export function isExactAdobeJwt(value: string): boolean {
return ADOBE_JWT_EXACT_REGEX.test(value);
}
export function stripAdobeJwts(value: string, replacement = ""): string {
return value.replace(ADOBE_JWT_IN_TEXT_GLOBAL_REGEX, replacement);
}
function hostnameMatches(hostname: string, expected: string): boolean {
const normalized = hostname.toLowerCase().replace(/\.$/, "");
return normalized === expected || normalized.endsWith(`.${expected}`);
}
export function isAdobeFireflyApiUrl(rawUrl: string): boolean {
try {
return hostnameMatches(new URL(rawUrl).hostname, FIREFLY_3P_HOST_SUFFIX);
} catch {
return false;
}
}
export function isAdobeLoginCookieDomain(domain: string): boolean {
return hostnameMatches(domain.replace(/^\./, ""), "adobelogin.com");
}