mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-31 04:12:10 +03:00
* chore(release): open v3.8.34 development cycle * chore(quality): release-green pre-flight validator + nightly signal (C+D) (#4622) C — scripts/quality/validate-release-green.mjs (npm run check:release-green): reproduces the release-equivalent validation (typecheck, eslint, db-rules, public-creds, full unit, vitest, ratchets, optional --with-build package-artifact) against the current working tree and classifies each red as HARD (real defect, exit 1) vs DRIFT (ratchet — reported, never affects exit / never blocks). Pure helpers exported + orchestration behind a direct-run guard; unit-tested. D — .github/workflows/nightly-release-green.yml: runs C on the active release branch nightly (and on workflow_dispatch) and opens/updates a single tracking issue on HARD failures. Never a required check, never touches a contributor PR. Closes the gap where the full gate (ci.yml) only ran on the release PR, so reds accrued silently on release/** and surfaced in 40-min layers at release time. Non-blocking by construction; drift is the maintainer's to rebaseline at release. Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br> * fix(providers): show revealed connection API keys (#4583) Integrated into release/v3.8.34 * fix(resilience): respect upstream retry hint toggle (#4585) Integrated into release/v3.8.34 * feat(settings): expose stream recovery feature flags (#4586) Integrated into release/v3.8.34 * fix(logs): make active request stale sweep configurable (#4599) Integrated into release/v3.8.34 * fix(plugin): auto-prefix providerId with 'opencode-' for OC 1.17.8+ native gate (#4527) Integrated into release/v3.8.34 (supersedes #4445) * fix(models): treat unknown output caps as unset (#4584) Integrated into release/v3.8.34 * fix(executors): strip temperature for GitHub Copilot gpt-5.4 family (#4564) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(oauth): update Qwen OAuth URLs from chat.qwen.ai to qwen.ai (#4561) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(api/settings): prevent cached /api/settings responses (port from 9router#951) (#4566) Integrated into release/v3.8.34 (rebuilt onto tip) * feat(audio): MiniMax T2A v2 TTS dispatch in audioSpeech (port #1043) (#4553) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(dashboard): surface manual config CTA when Open Claw CLI auto-detect fails (#4562) Integrated into release/v3.8.34 (rebuilt onto tip) * feat(providers): optional model ID for custom API-key validation (#4555) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(cli): align data dir and env loading with runtime (#4607) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(quota): expose Bailian quota windows (#4610) Integrated into release/v3.8.34 (rebuilt onto tip) * fix: retain provider cooldowns for configured max window (#4588) Integrated into release/v3.8.34 (rebuilt — bundled commits stripped) * fix: reject invalid provider cooldown bounds (#4589) Integrated into release/v3.8.34 (rebuilt — bundled commits stripped) * fix: preserve production combo metrics on shadow eviction (#4590) Integrated into release/v3.8.34 (rebuilt — bundled commits stripped) * fix(stream): estimate input tokens when upstream reports prompt_tokens=0 (#4615) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(catalog): shorten no-thinking gateway prefix to no-think/ (#4525) Integrated into release/v3.8.34 (rebuilt — kept only the prefix rename, dropped stale-base reverts) * fix(relay): apply IP rate limit to bifrost sidecar (#4593) Integrated into release/v3.8.34 (rebuilt onto tip; merge before #4612) * fix(bifrost): finalize SSE relay usage after stream (#4612) Integrated into release/v3.8.34 (rebuilt + reconciled with #4593) * feat(compression): per-request `x-omniroute-compression` header (Phase 3) (#4645) * docs(compression): Phase 3 per-request header design spec Approved brainstorming output for the x-omniroute-compression header: header-first precedence, name-first combo matching (Decision A), explicit value bypasses auto-trigger (Decision B), DerivedPlan.source, and the X-OmniRoute-Compression response header. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * docs(compression): Phase 3 per-request header implementation plan 4-task TDD plan (resolver header-first + source, parser, chatCore wiring + response header, docs/file-size) with full code and exact commands. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(compression): header-first resolver + plan source (Phase 3 core) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(compression): resolveCompressionHeader parser (Phase 3) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(compression): wire x-omniroute-compression header + response header (Phase 3) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * refactor(compression): extract plan-resolution leaf (planResolution.ts) under size cap (Phase 3) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * docs(compression): document x-omniroute-compression header (Phase 3) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(compression): harden named-combo map + trim engine: header id (Phase 3 review) Addresses gemini-code-assist review on #4645: - Extract buildNamedComboLookup (pure) so a blank/whitespace/null combo name contributes only its id key (no '' key, no throw that disables all combos). - Trim the engine:<id> header value so 'engine: rtk' resolves. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> * fix: exclude exhausted connections from auto scoring (#4592) Integrated into release/v3.8.34 (rebuilt + opt-in gate fix) * fix(dashboard): memoize compatible provider groups (#4613) Integrated into release/v3.8.34 (rebuilt + test added) * fix(dashboard): isolate quota widget refresh clock (#4611) Integrated into release/v3.8.34 (rebuilt + jsdom test) * fix(dashboard): gate topology side effects behind widget visibility (#4606) Integrated into release/v3.8.34 (rebuilt + jsdom test) * fix(dashboard): keep play_arrow spinning on provider Test All buttons (#4563) Integrated into release/v3.8.34 (rebuilt onto tip; UI-cosmetic per owner) * fix(db): schedule retention cleanup + fix cleanup table/column names (extracted from #4428) (#4691) Integrated into release/v3.8.34 (cleanup core extracted from #4428, credit @oyi77) * fix(telemetry): back off live-WS event forwarding when the sidecar is unreachable (#4604) (#4687) Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> * fix(api): serve GET /v1/models/{model} as JSON, not the HTML dashboard (#4674) (#4677) Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> * feat(opencode): add go deepseek reasoning variants (#4647) Integrated into release/v3.8.34 * fix(executors): robust deepseek-web tool-call parsing and agentic context retention (#4644) Integrated into release/v3.8.34 * fix(cli): authenticate `omniroute logs` and honor active context (#4638) Integrated into release/v3.8.34 (authored by Rahul Sharma, AI co-author trailer stripped per project policy) * fix(proxy): apply pipelining:0 + connections cap to the direct dispatcher (#4580) (#4684) Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> * fix(executors): Firecrawl web_fetch 500 with include_metadata=true (#4692) Integrated into release/v3.8.34 * fix(routing): include all noAuth models in auto-combos + add reka-flash + best-free template (#4621) Integrated into release/v3.8.34 (dead getFirstRegistryModelId dropped, rebuilt onto tip) * fix(dashboard): gate home topology live-WS networking (#4596) (#4618) Integrated into release/v3.8.34 (adapted onto #4606's extracted topology section: default-hidden flip + enabled gate on useLiveDashboard) * fix(cli): align `omniroute` env loading with the runtime data dir (#4597) (#4619) Integrated into release/v3.8.34 (data-dir.mjs refactor reconciled with #4607; loadEnvFile aligned to getDefaultDataDir) * chore(quality): reconcile file-size baseline for #4644 (deepseek-web.ts 1117->1125) (#4695) file-size reconcile for #4644 * Support quota scraping for OpenCode Go and Ollama Cloud (#4642) Integrated into release/v3.8.34 (Ollama Cloud + OpenCode Go dashboard quota scraping; rebuilt onto tip, gates green: typecheck/public-creds/file-size/lint/docs-sync + 31 tests) * feat(executors): land M365 Copilot pure framing + connection helpers (#4042) (#4696) Land M365 pure modules ahead of draft #4400 * deps: bump production + development groups; migrate js-yaml to v5 ESM (#4697) Incorporates Dependabot #4667 + #4668 + js-yaml v5 ESM migration into release/v3.8.34 * fix: noAuth provider validation + kimi executor routing (#4699) Integrated into release/v3.8.34 (noAuth in NOAUTH_PROVIDERS dynamic check + remove misrouted kimi web alias; 9 tests) * refactor(imageGeneration): extract 8 provider families to co-located files (#4609) Integrated into release/v3.8.34 (extraction completed: added missing imports/exports per module, main imports handlers locally; 145 image-gen tests pass, typecheck/cycles/file-size green) * chore(release): v3.8.34 — finalize changelog, rebaseline drift, fix release-green reds - Finalize CHANGELOG [3.8.34] (43 bullets, full contributor attribution) + seed i18n mirrors - Rebaseline inherited cycle drift surfaced by release-green pre-flight: eslint warnings 3900->3907, cognitive-complexity 797->801 (release-finalize touches no prod code; all drift is from this cycle's contributor merges) - fix(providers): keep reka-flash-3 as the Reka provider default. #4621 inserted reka-flash at the head of the model list, silently changing the default from reka-flash-3 (the free-tier model) to reka-flash; reorder so reka-flash-3 stays default, reka-flash retained. - test: align provider-models-config / provider-models-route / web-cookie-providers-new with #4621 (reka-flash now in the Reka catalog) and #4699 (the `kimi` API-key provider correctly falls through to DefaultExecutor instead of KimiWebExecutor) - chore(quality): allowlist the COMPRESSION_GUIDE doc name in check-fabricated-docs (false-positive env-var match; docs/compression/COMPRESSION_GUIDE.md exists) * fix(release-green): resolve release-PR full-CI reds for v3.8.34 Surfaced only on the release PR (these gates don't run on PR->release fast-gates): - fix(quota): complete HTML-comment sanitization in opencodeOllamaUsage SSR reset-time parsing — strip any <!--...--> generically instead of the two literal React hydration markers, so no partial "<!--" can survive (CodeQL js/incomplete-multi-character- sanitization, HIGH, introduced by #4642). Regression test added. - test(codex): correct the Codex-fingerprint body key order assertion to match the canonical bodyFieldOrder (prompt_cache_key precedes include); #4584 flipped the two and integration tests don't run on fast-gates so it never executed until the release PR. - chore(quality): rebaseline inherited cycle drift surfaced by full CI — zizmorFindings 152->155 (+3 unpinned-uses in nightly-release-green.yml from #4622, same @vN convention as ci.yml) and openapiCoverage.pct 38.4->37.8 (-0.6, contributor routes added faster than openapi docs). Release-finalize touches no prod routes. * fix(release-green): complete CodeQL sanitization + rebaseline complexity drift - fix(quota): handle unterminated HTML comments in opencodeOllamaUsage SSR reset-time parsing — the `(?:-->|$)` arm consumes a trailing "<!--" with no closing "-->", so no partial "<!--" can survive (CodeQL js/incomplete-multi-character-sanitization persisted with the plain <!--...--> form because an unclosed comment could still leave "<!--"). - chore(quality): rebaseline cyclomatic complexity 1915->1916 (+1) — inherited v3.8.34 cycle drift (contributor feature branches); check:complexity does not run on PR->release fast-gates so it surfaced only on the release PR. Release-finalize adds 0 complexity (measured 1916 with/without the regex tweak). dead-code/cognitive/type-coverage/ compression-budget/codeql ratchets all pass. --------- Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com> Co-authored-by: KooshaPari <42529354+KooshaPari@users.noreply.github.com> Co-authored-by: Abhishek Divekar <adivekar@utexas.edu> Co-authored-by: Rahul sharma <sharmaR0810@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> Co-authored-by: Ronald Estacion <DevEstacion@users.noreply.github.com> Co-authored-by: Igor <60442260+BugsBag@users.noreply.github.com> Co-authored-by: Oonishi <275808243+ponkcore@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Jan Leon <Jan.gaschler@gmail.com>
217 lines
7.4 KiB
TypeScript
217 lines
7.4 KiB
TypeScript
/**
|
|
* Tests for /api/cli-tools/logs route (fix #2756).
|
|
*
|
|
* Verifies:
|
|
* - GET returns 200 with valid JSON array body.
|
|
* - `filter` param filters log lines by text.
|
|
* - Error responses do NOT leak stack traces (hard rule #12).
|
|
* - log-streamer.ts points to the correct URL (/api/cli-tools/logs).
|
|
* - Non-numeric `limit` param does NOT bypass the 2000-entry cap.
|
|
*/
|
|
|
|
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import fs from "node:fs";
|
|
import os from "node:os";
|
|
import path from "node:path";
|
|
|
|
import { updateSettings } from "../../src/lib/db/settings";
|
|
|
|
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-cli-logs-route-"));
|
|
process.env.DATA_DIR = TEST_DATA_DIR;
|
|
|
|
// Write a small pino-format log file before route is imported
|
|
const logDir = path.join(process.cwd(), "logs", "application");
|
|
fs.mkdirSync(logDir, { recursive: true });
|
|
const logPath = path.join(logDir, "app.log");
|
|
process.env.APP_LOG_FILE_PATH = logPath;
|
|
|
|
const now = Date.now();
|
|
const lines = [
|
|
JSON.stringify({ level: 30, msg: "provider connected", component: "router", time: now }),
|
|
JSON.stringify({ level: 40, msg: "rate limit hit", component: "rateLimit", time: now }),
|
|
JSON.stringify({ level: 20, msg: "debug trace output", component: "debug", time: now }),
|
|
"not-valid-json-should-be-skipped",
|
|
];
|
|
fs.writeFileSync(logPath, lines.join("\n") + "\n", "utf-8");
|
|
|
|
const { GET } = await import("../../src/app/api/cli-tools/logs/route.ts");
|
|
|
|
test.before(async () => {
|
|
await updateSettings({ requireLogin: false });
|
|
});
|
|
|
|
test.after(async () => {
|
|
await updateSettings({ requireLogin: true });
|
|
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
|
|
try {
|
|
fs.unlinkSync(logPath);
|
|
} catch {
|
|
// best effort
|
|
}
|
|
});
|
|
|
|
// Helper — make a request; auth passes because requireLogin is set to false in test.before
|
|
function makeReq(queryString = "") {
|
|
const url = `http://localhost/api/cli-tools/logs${queryString ? `?${queryString}` : ""}`;
|
|
return new Request(url);
|
|
}
|
|
|
|
test("GET /api/cli-tools/logs returns 200 with JSON array when log file exists", async () => {
|
|
const res = await GET(makeReq());
|
|
assert.equal(res.status, 200);
|
|
|
|
const body = await res.json();
|
|
assert.ok(Array.isArray(body), "body should be an array");
|
|
assert.ok(body.length >= 3, `expected at least 3 entries, got ${body.length}`);
|
|
});
|
|
|
|
test("GET /api/cli-tools/logs respects filter param", async () => {
|
|
const res = await GET(makeReq("filter=rateLimit"));
|
|
assert.equal(res.status, 200);
|
|
|
|
const body = await res.json();
|
|
assert.ok(Array.isArray(body));
|
|
// Only the "rate limit hit" entry matches component=rateLimit
|
|
assert.ok(
|
|
body.every((e: { component?: string; msg?: string }) => {
|
|
const comp = (e.component || "").toLowerCase();
|
|
const msg = (e.msg || "").toLowerCase();
|
|
return comp.includes("ratelimit") || msg.includes("ratelimit") || comp.includes("rate");
|
|
}),
|
|
"filter should restrict results to matching component/message"
|
|
);
|
|
});
|
|
|
|
test("GET /api/cli-tools/logs returns empty array when log file does not exist", async () => {
|
|
const origPath = process.env.APP_LOG_FILE_PATH;
|
|
process.env.APP_LOG_FILE_PATH = "/tmp/omniroute-nonexistent-cli-logs-test.log";
|
|
|
|
const res = await GET(makeReq());
|
|
assert.equal(res.status, 200);
|
|
const body = await res.json();
|
|
assert.ok(Array.isArray(body));
|
|
assert.equal(body.length, 0);
|
|
|
|
process.env.APP_LOG_FILE_PATH = origPath;
|
|
});
|
|
|
|
test("GET /api/cli-tools/logs error response does not leak stack traces (hard rule #12)", async () => {
|
|
// Simulate an internal error path by temporarily breaking the log path to a dir
|
|
const origPath = process.env.APP_LOG_FILE_PATH;
|
|
// Point to a directory so readFileSync throws
|
|
process.env.APP_LOG_FILE_PATH = TEST_DATA_DIR;
|
|
|
|
const res = await GET(makeReq());
|
|
// Should respond with 500 or empty (route may handle gracefully), but must NOT leak stack
|
|
const text = await res.text();
|
|
assert.ok(!text.includes(" at "), "Response must not contain stack trace frames");
|
|
|
|
process.env.APP_LOG_FILE_PATH = origPath;
|
|
});
|
|
|
|
test("GET /api/cli-tools/logs limit=abc does not bypass the 2000-entry cap", async () => {
|
|
// Write more than 2000 entries so we can verify the cap is applied
|
|
const manyLines: string[] = [];
|
|
for (let i = 0; i < 2100; i++) {
|
|
manyLines.push(JSON.stringify({ level: 30, msg: `entry ${i}`, component: "test", time: now }));
|
|
}
|
|
const origPath = process.env.APP_LOG_FILE_PATH;
|
|
const bigLogPath = path.join(logDir, "big.log");
|
|
fs.writeFileSync(bigLogPath, manyLines.join("\n") + "\n", "utf-8");
|
|
process.env.APP_LOG_FILE_PATH = bigLogPath;
|
|
|
|
try {
|
|
const res = await GET(makeReq("limit=abc"));
|
|
assert.equal(res.status, 200);
|
|
const body = await res.json();
|
|
assert.ok(Array.isArray(body), "body should be an array");
|
|
// Non-numeric limit must fall back to default (500), not bypass the cap with NaN
|
|
assert.ok(
|
|
body.length <= 500,
|
|
`Non-numeric limit=abc should fall back to default 500, got ${body.length}`
|
|
);
|
|
} finally {
|
|
process.env.APP_LOG_FILE_PATH = origPath;
|
|
fs.unlinkSync(bigLogPath);
|
|
}
|
|
});
|
|
|
|
test("log-streamer.ts calls /api/cli-tools/logs (correct URL, not the missing route)", async () => {
|
|
const { createLogStream } = await import("../../src/lib/cli-helper/log-streamer.ts");
|
|
// Inspect the source to verify the URL used; we mock fetch to capture it
|
|
const captured: string[] = [];
|
|
const origFetch = globalThis.fetch;
|
|
|
|
globalThis.fetch = (async (url: string) => {
|
|
captured.push(typeof url === "string" ? url : String(url));
|
|
// Return a mock Response with a body so the stream doesn't error immediately
|
|
return new Response(
|
|
new ReadableStream({
|
|
start(c) {
|
|
c.close();
|
|
},
|
|
}),
|
|
{ status: 200 }
|
|
);
|
|
}) as typeof fetch;
|
|
|
|
try {
|
|
const { stream, stop } = createLogStream({ baseUrl: "http://localhost:20128" });
|
|
const reader = stream.getReader();
|
|
// Consume until done (mock stream closes immediately)
|
|
await reader.read().catch(() => {});
|
|
stop();
|
|
} finally {
|
|
globalThis.fetch = origFetch;
|
|
}
|
|
|
|
assert.ok(captured.length > 0, "fetch should have been called");
|
|
assert.ok(
|
|
captured.some((u) => u.includes("/api/cli-tools/logs")),
|
|
`Expected /api/cli-tools/logs in fetched URL, got: ${captured[0]}`
|
|
);
|
|
assert.ok(
|
|
!captured.some((u) => u.includes("/api/logs/console")),
|
|
"log-streamer should not call /api/logs/console"
|
|
);
|
|
});
|
|
|
|
test("log-streamer forwards auth headers to fetch (regression: 401 against authed servers)", async () => {
|
|
const { createLogStream } = await import("../../src/lib/cli-helper/log-streamer.ts");
|
|
let capturedInit: RequestInit | undefined;
|
|
const origFetch = globalThis.fetch;
|
|
|
|
globalThis.fetch = (async (_url: string, init?: RequestInit) => {
|
|
capturedInit = init;
|
|
return new Response(
|
|
new ReadableStream({
|
|
start(c) {
|
|
c.close();
|
|
},
|
|
}),
|
|
{ status: 200 }
|
|
);
|
|
}) as typeof fetch;
|
|
|
|
try {
|
|
const { stream, stop } = createLogStream({
|
|
baseUrl: "http://localhost:20128",
|
|
headers: { authorization: "Bearer test-token" },
|
|
});
|
|
const reader = stream.getReader();
|
|
await reader.read().catch(() => {});
|
|
stop();
|
|
} finally {
|
|
globalThis.fetch = origFetch;
|
|
}
|
|
|
|
assert.ok(capturedInit, "fetch should receive an init object");
|
|
const headers = new Headers(capturedInit!.headers);
|
|
assert.equal(
|
|
headers.get("authorization"),
|
|
"Bearer test-token",
|
|
"createLogStream must forward the provided auth headers to fetch"
|
|
);
|
|
});
|