Files
OmniRoute/tests/unit/db-core-init.test.ts
Diego Rodrigues de Sa e Souza 7b139fdb5e Release v3.8.38 (#5078)
* chore(release): open v3.8.38 development cycle

* fix(executors): strip client_metadata for cerebras and mistral (#4727)

Integrated into release/v3.8.38 (leva 5)

* fix(codebuddy): only send reasoning params when client requests reasoning (#5019)

Integrated into release/v3.8.38 (leva 5)

* fix(sse): keep streaming for forceStream providers when client requests JSON (#5021)

Integrated into release/v3.8.38 (leva 5)

* fix(sse): guard non-JSON SSE lines and duplicate [DONE] (#4937)

Integrated into release/v3.8.38 (leva 5)

* feat(blackbox): refresh provider model catalog (#4935)

Integrated into release/v3.8.38 (leva 5)

* fix(sse): dedupe case-variant Anthropic version/beta headers (#4846)

Integrated into release/v3.8.38 (leva 5)

* feat(sse): Kiro inline <thinking> stream splitter (#4911)

Integrated into release/v3.8.38 (leva 5)

* feat(cursor): parse Composer DeepSeek-style inline tool calls (#4912)

Integrated into release/v3.8.38 (leva 5)

* feat(proxy): auth-less host:port batch import (#4938)

Integrated into release/v3.8.38 (leva 5)

* fix(oauth): support Kiro IDC (organization) token import (#4944)

Integrated into release/v3.8.38 (leva 5)

* fix(translator): preserve cache_control for DashScope OpenAI-compat providers (port from 9router#2069) (#5013)

Integrated into release/v3.8.38 (leva 5)

* fix(tts): resolve Gemini TTS models from catalog (#4934)

Integrated into release/v3.8.38 (leva 5)

* fix(sse): don't cool down the connection on a self-inflicted upstream timeout (504) (#5064)

Integrated into release/v3.8.38 (leva 5)

* fix(sse): robust Anthropic /v1/messages streaming — real ping keepalive + client-disconnect guard (#5063)

Integrated into release/v3.8.38 (leva 5)

* feat(video): add Alibaba DashScope (wan2.7-t2v) provider (#5051)

Integrated into release/v3.8.38 (leva 5)

* fix: preserve model hidden flags (isHidden) across model sync (#5086)

Integrated into release/v3.8.38 (leva 5)

* fix(models): derive model discovery config from registry modelsUrl (#5087)

Integrated into release/v3.8.38 (leva 5)

* fix(compression): replace fileURLToPath(import.meta.url) with runtime anchors for standalone bundle (#5089)

Integrated into release/v3.8.38 (leva 5)

* feat(cc): add summarized thinking display toggle (#5055)

Integrated into release/v3.8.38 (leva 5)

* Harden selected API error responses (#5032)

Integrated into release/v3.8.38 (leva 5)

* chore(quality): rebaseline file-size for leva 5 PR batch drift

6 frozen files grew from merged leva-5 PRs (cursor #4912, kiro #4911,
videoGeneration #5051, default #4727, base #4846, chat #5064); all covered
by per-PR tests. See _rebaseline_2026_06_26_leva5 in the baseline.

* feat(compression): compression playground (Play + Compare tabs) in the studio (#5080)

Integrated into release/v3.8.38

* fix(combo): fail over on empty-content 502 instead of exhausting the provider (#5085) (#5104)

* fix(dashboard): surface detailed credential-validation error in add-connection modal (#5088) (#5106)

* feat(providers): allow local/private provider URLs by default with scoped metadata-safe guard (#5066) (#5107)

* fix(diagnostics): treat non-streaming Claude messages shape as valid output (#5108) (#5116)

* fix(db): translate pt-BR SQLite driver-fallback log lines to English (#5103) (#5115)

* fix(sse): repair release base-reds — malformed-response false positives + header casing + stale tests (#5117)

Repairs the release/v3.8.38 base-reds; unblocks #5078.

* chore(quality): rebaseline file-size for responseSanitizer (#5117) + AddApiKeyModal drift

* fix(translator): forward image tool_result blocks as image_url (#5100)

Base-reds fixed (#5117); image tool_result→image_url. Integrated into release/v3.8.38.

* fix(responses): default text.format for openai-compatible responses providers (#5101)

Base-reds fixed (#5117); default text.format + file-size rebaseline. Integrated into release/v3.8.38.

* feat(dashboard): expose Fusion judgeModel + fusionTuning in the combo editor (#5074)

Base-reds fixed (#5117); Fusion editor + file-size rebaseline. Integrated into release/v3.8.38.

* feat(quota): add opt-in Codex/Claude auto-ping keepalive (#5102)

Base-reds fixed (#5117); auto-ping keepalive + file-size rebaseline. Integrated into release/v3.8.38.

* test(release): relocate 2 orphan test files into the collected flat tests/unit dir (#5120)

Unblocks Lint (test-discovery) on #5078. Integrated into release/v3.8.38.

* fix(translator): preserve reasoning-replay reasoning_content + repair 3 release-green test reds (#5122)

Repairs 3 release-green test reds + test-masking; unblocks #5078.

* test(golden): redact live Node version from provider translate-path snapshot (#5125)

Final golden unblock for #5078.

* test(golden): redact OmniRoute app version from translate-path snapshot (#5126)

Coverage shard golden unblock for #5078.

* Ignore disconnect races during in-band stream error handling (#5007)

Integrated into release/v3.8.38

* Track final connection IDs in failover logs (#5016)

Integrated into release/v3.8.38

* fix(sse): convert Gemini body to OpenAI format in antigravity MITM handler (#4845)

Integrated into release/v3.8.38 (rebased on tip, CHANGELOG re-injected)

* feat(providers): add ZenMux Free session-cookie provider (#5105)

Integrated into release/v3.8.38 (rebased on tip, CHANGELOG re-injected)

* feat(dashboard): click-to-edit model alias in provider page (#5119)

Integrated into release/v3.8.38 (rebased on tip, i18n scope verified, CHANGELOG re-injected)

* feat(mcp): web-session robustness — cookie dedup (PR6) + browser-pool observability (PR7) (#3368) (#5121)

Integrated into release/v3.8.38 (rebased on tip; cookie-dedup branch extracted to findExistingCookieConnection helper → complexity-neutral; CHANGELOG added)

* fix(usage): dedupe request-usage logging and debounce stats (#4940)

Integrated into release/v3.8.38 (rebased on tip; DB-handle hang was stale-base artifact — resetDbInstance already closes the handle, test green 5/5; file-size drift consolidated at release; CHANGELOG re-injected)

* fix(dashboard): key model visibility toggle on canonical providerId (#5091)

Integrated into release/v3.8.38 (retargeted main→release; .tsx visibility-key test green 2/2)

* chore(deps): bump actions/cache from 5.0.5 to 6.0.0 (#5112)

Integrated into release/v3.8.38 (retargeted main→release; workflow-only actions/cache bump — unit failures were stale main base-reds)

* fix(streaming): harden long OpenAI-compatible SSE streams (#5124)

Integrated into release/v3.8.38 (rebased on tip; streamHandler conflict with #5007 disconnect-guard resolved — both coexist, stream-handler 22/22 green)

* feat: Add Grok Build (xAI) provider with OAuth import-token flow (#5020)

Integrated into release/v3.8.38 (rebased on tip; Hard Rule #11 fix — Grok public client_id now via resolvePublicCred(grok_id), 3 literals removed; grok-oauth 7/7 + check:public-creds green)

* feat(providers): add Factory (factory.ai) as a subscription gateway provider (#5065)

Integrated into release/v3.8.38 (rebased on tip; added factory registry test for PR Test Policy + fixed check:env-doc-sync phantom FACTORY_API_KEY; factory loads in PROVIDERS, no Zod issue — that flag was a false positive)

* chore(test): reconcile golden snapshot + apikey count for new providers

#5020 (grok-cli), #5065 (factory), #5105 (zenmux-free) added providers but did
not regenerate tests/snapshots/provider/translate-path.json (now +3 entries) nor
bump the APIKEY_PROVIDERS count (159->160 for the factory gateway). Test-only
reconciliation; no production change.

* fix(resilience): harden quota and model lockout edge cases (#5093)

Integrated into release/v3.8.38 (rebased on tip). TRUST-BUT-VERIFY: dropped the PR's 0dd7df641 'fix unit gates' commit which reverted #5122 reasoning-replay (preserveReasoningContent) + re-introduced #4849 O(n^2) growth, and restored 5 tests it had realigned. Kept only the 3 declared resilience fixes (quota cutoff guard, gemini MIME, model-lockout maxCooldownMs); 23/23 green.

* Hydrate quota cache and scope auto combo candidates (#5015)

Integrated into release/v3.8.38 (rebased on tip). Kept core quota-cache hydration + auto-combo candidate scoping + combos UI; dropped out-of-scope toolCloaking refactor (conflicted with #4813 stripEnumDescriptions — took tip) and the unrelated sse-auth test split. Added quota-cache-hydrate-5015 regression test (Rule #18); combo-account-allowlist 8/8 + hydration 2/2 green.

* chore(quality): reconcile complexity + file-size baselines for v3.8.38 owner-PR batch

complexity 1972->1978 (+6) and file-size providers.ts 1093->1107 / usageHistory.ts
934->983 — drift from the /review-prs merge batch (#4845/#5105/#5020/#4940/#5093/
#5015 + #5121 cookie-dedup helper extraction). check:complexity/check:file-size do
not run on the PR->release fast-path, so the branch accrued unmeasured; all legit
feature/fix growth, not regression. See per-key justifications in each baseline.

* fix(security): exact-host Anthropic baseUrl check (CodeQL js/incomplete-url-substring-sanitization #674) (#5130)

The anthropic-compatible Bearer-fallback gate decided whether a configured baseUrl
targeted the official api.anthropic.com host via a substring `.includes("api.anthropic.com")`.
A look-alike upstream such as `https://api.anthropic.com.evil.test` or
`https://evil.test/?x=api.anthropic.com` matched the substring and was wrongly treated as
official, suppressing the Bearer fallback meant for third-party gateways
(CodeQL #674, js/incomplete-url-substring-sanitization, high).

Replace the substring test with an exported `isOfficialAnthropicBaseUrl()` helper that
parses the URL and compares the hostname for exact equality. Empty baseUrl stays official;
scheme-less hosts are parsed with an assumed https://; an unparseable baseUrl falls back to
third-party (Bearer emitted) as the safer default. Behavior for legitimate official/third-party
baseUrls is unchanged.

Adds tests/unit/anthropic-official-baseurl-host.test.ts covering official, look-alike,
scheme-less, and unparseable inputs plus a static guard that the substring pattern is gone.

* fix(proxy): repair one-click Deno & Cloudflare relay deployments (#5128) (#5132)

* fix(services): embed WS proxy honours LIVE_WS_HOST; reject empty messages early (#5110) (#5133)

* fix(api): resolve /v1/models/{id} case-insensitively (#5082) (#5135)

* fix(providers): add MiniMax M3 & Nemotron 3 Ultra to Cline catalog (#3321) (#5136)

* fix(proxy): make SOCKS5 handshake timeout tunable via SOCKS_HANDSHAKE_TIMEOUT_MS (#5109) (#5137)

* feat(sidebar): add support for colored menu icons (#3812)

Integrated into release/v3.8.38 (recreated on tip — fork had unrelated history; added getSidebarIconAccent regression test, Rule #18). Clean 2-file UI feature.

* fix(providers): complete grok-cli OAuth wiring + zenmux-free web-session metadata

Base-red repair for #5020 (grok-cli) and #5105 (zenmux-free), surfaced by the
full CI on the release PR (#5078) — the PR->release fast-path does not run the
oauth-providers-config / web-session-credentials / provider-consistency gates.

- grok-cli: register in OAUTH_PROVIDERS (providers.ts canonical list, fixes
  check:provider-consistency), add OAUTH_PROVIDER_IDS.GROK_CLI + GROK_CLI_CONFIG
  in oauth constants (provider config now sourced there, not a local literal),
  align oauth-providers-config.test.ts (EXPECTED_PROVIDER_KEYS + config map).
- zenmux-free: declare its web-session credential requirement (full Cookie header)
  in WEB_SESSION_CREDENTIAL_REQUIREMENTS.

Local: oauth-providers-config 27/27, web-session-credentials 4/4, grok-cli-oauth
7/7, check:provider-consistency OK, +115 OAUTH_PROVIDERS tests green.

* Fix resilience settings page response mapping (#5139)

Integrated into release/v3.8.38. Thanks @rdself for the fix and the regression test.

* fix(kiro): retire claude-sonnet-4.5 from catalog + pin 400 model-unavailable test (#5140)

Extracted the real change from #5140 (the bot PR regenerated the entire
freeModelCatalog.data.ts + touched package-lock.json; only the targeted
edits are kept here):
- remove claude-sonnet-4.5 from the Kiro registry entry
- remove the matching kiro free-model catalog row
- pin Kiro's verbatim 400 "Invalid model..." to isModelUnavailableError

Closes #4484

* fix(sidebar): drop orphan `settings` accent color (typecheck:core red) (#5142)

SIDEBAR_ICON_ACCENTS is typed Partial<Record<HideableSidebarItemId, string>>,
but `settings` is not a hideable item id (only `settings-general`,
`settings-appearance`, … and `context-settings` exist; there is no item with
`id: "settings"`), so the accent was unreachable. It broke `typecheck:core`
on the release tip ("'settings' does not exist in type …", introduced by
#3812 colored menu icons). Removing the orphan key restores a clean
typecheck:core (rc=0).

* feat: salvage batch 2 — diagnostics null-guard (#5096) + observed quota reset windows (#5025) (#5141)

* fix(diagnostics): null-guard content blocks in detectMalformedNonStream

A null (or non-object) entry in a Claude-native `content` array made the
non-stream classifier throw `TypeError: Cannot read properties of null
(reading 'type')`, crashing the malformed-response detection path. Guard
before type-asserting each block: a null/non-object block is simply skipped.

Two regression tests added (null block among valid blocks → null; only-null
blocks → empty_choices).

Salvaged from closed PR #5096 (base-stale; only the defensive guard — the
Claude-shape recognition it also carried already landed via #5108).

Co-authored-by: herjarsa <herjarsa@users.noreply.github.com>

* feat(quota): persist observed provider quota reset windows

Adds `provider_quota_reset_events` (migration 108) + `db/quotaResetEvents.ts`
to record real upstream weekly-quota window transitions whenever a quota
refresh shows the reset rolling to a new cycle (different day, later resetAt).
`apiKeyUsageLimits` now prefers the observed window start over the inferred
`resetAt − 7d`, falling back to snapshot inference when no event is recorded
yet. `quotaCache.setQuotaCache` records the transition opportunistically.

`recordProviderQuotaResetEventIfChanged` only fires for the primary weekly
window (not daily/sonnet), is idempotent (INSERT OR IGNORE on the unique
window key), and no-ops when the reset didn't actually roll. 4 unit tests
(tests/unit/lib/quota-reset-events.test.ts).

Salvaged from closed PR #5025 (which bundled this with two unrelated
features + a colliding migration 104). Renumbered to 108; module re-exported
from localDb (Rule #2).

Co-authored-by: Witroch4 <175152067+Witroch4@users.noreply.github.com>

---------

Co-authored-by: herjarsa <herjarsa@users.noreply.github.com>
Co-authored-by: Witroch4 <175152067+Witroch4@users.noreply.github.com>

* docs(i18n): sync 3.8.38 CHANGELOG section to 41 mirrors (unblock docs-accuracy) (#5144)

The root CHANGELOG [3.8.38] section grew with this cycle's merged PRs, but the
docs/i18n/<lang>/CHANGELOG.md mirrors were not re-synced — drifting >25% in body
size and failing check:docs-sync (the "Docs accuracy" fast-gate step) for every
open PR against the release.

Ran scripts/release/sync-changelog-i18n.mjs 3.8.38 3.8.37 to copy the root
[3.8.38] section into all 41 mirrors. check:docs-all now passes (exit 0).

Sections are copied verbatim; the per-language translation pass runs at release
time via i18n:run — this only restores the size-sync the gate enforces.

* feat(compression): pure per-step fidelity checker (4 invariants, fail-open)

* feat(compression): fidelityGate config + rejected breakdown fields

* feat(compression): wire per-step fidelity gate into stacked pipeline (opt-in)

* feat(compression): preview route accepts fidelityGate flag (playground)

* feat(compression): playground fidelity-gate toggle + lane rejection display

* docs(compression): note fidelityGate advanced thresholds are intentionally API-omitted

* refactor(compression): extract fidelity-gate step helpers to shrink strategySelector (file-size gate)

bodyToText and gateAdvance moved to fidelityGateStep.ts; StackAccumulator exported.
strategySelector: 889->854 (-35). Residual +6 vs pre-Milestone-B frozen 848 is the
irreducible StackOptions.fidelityGate field + two stacked-loop dispatch reads + import.
Baseline updated to 854 with justification. No cycle introduced (import type only).
940 compression tests pass; typecheck clean.

* test(usage): wire usageHistoryDedup under unit runner brace-list (#5145)

Integrated into release/v3.8.38.

* feat: salvage batch from closed stale PRs (#5038, #5057, #5076) (#5138)

Integrated into release/v3.8.38.

* test(combo): deterministic routing-decision matrix for all 17 strategies (#5146)

Integrated into release/v3.8.38.

* feat(compression): fuzzy near-duplicate dedup (session-dedup 2nd pass + playground toggle) (#5143)

Integrated into release/v3.8.38.

* chore(quality): rebaseline file-size for sidebarVisibility.ts + chat.ts drift (#5147)

Mid-cycle drift on release/v3.8.38 from already-merged PRs that the fast-path
(PR->release skips check:file-size) let accumulate without a bump:

- src/shared/constants/sidebarVisibility.ts 1100->1198 (#3812 colored menu
  icons, per-item accent map; #5142 dropped one orphan, net still above frozen)
- src/sse/handlers/chat.ts 1560->1575 (#5064 self-inflicted-timeout cooldown
  skip + #5124 long OpenAI-compatible SSE hardening + #5110 embed-WS
  LIVE_WS_HOST honour / early empty-message reject)

Each covered by its own PR tests; structural shrink of chat.ts tracked in #3501.
Unblocks the Fast Quality Gates for PRs targeting release/v3.8.38.

* chore(release): finalize v3.8.38 CHANGELOG + cycle reconciliation

- Reconcile [3.8.38]: +18 bullets (compression fidelity-gate/fuzzy-dedup #5143,
  quota keepalive #5102, web-session robustness #5121, MiniMax/Nemotron #5136,
  model-visibility #5091, failover logs #5016, disconnect races #5007, sidebar
  orphan #5142, SRE playbooks salvage #5138, new Security #5130 + Maintenance roll-up)
- Credit salvaged-PR authors (@JxnLexn / @KooshaPari / @herjarsa / @Witroch4)
- Remove phantom bullet for CLOSED-not-merged #5092 (setup aggregator never landed)
- Fix isHidden bullet PR citation #4389 -> #5086 (@herjarsa)
- Back-fill forgotten v3.8.36 bullet: #5026 crypto.randomUUID ID-gen (@hamsa0x7)
- Sync 41 i18n CHANGELOG mirrors; README What's New -> v3.8.38
- Rebaseline cycle drift: eslint 3987->4002, cognitive 833->841, dead-exports
  345->346, cyclomatic 1978->1980 (file-size handled by #5147)

* fix(i18n): add missing English UI labels (#5153)

Integrated into release/v3.8.38

* Preserve non-stream reasoning fields for compatible clients (#5155)

Integrated into release/v3.8.38

* feat(compression): ionizer engine — lossy JSON-array sampling reversible via CCR (#5148)

Integrated into release/v3.8.38

* test(combo): gated live smoke for combo strategies (in-process + VPS HTTP) (#5151)

Integrated into release/v3.8.38

* test: refresh release expectations to match current code (#5150)

Integrated into release/v3.8.38 (test-only base-red alignment extracted from #5150)

---------

Co-authored-by: Éder Costa <eder.almeida.costa@gmail.com>
Co-authored-by: José Victor Ferreira <root@josevictor.me>
Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: fulorgnas <46461624+fulorgnas@users.noreply.github.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Jan Leon <Jan.gaschler@gmail.com>
Co-authored-by: R. Beltran <rbeltran8000@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: KooshaPari <42529354+KooshaPari@users.noreply.github.com>
Co-authored-by: Ramel Tecnologia - Rafa Martins <146174365+rafacpti23@users.noreply.github.com>
Co-authored-by: herjarsa <herjarsa@users.noreply.github.com>
Co-authored-by: Witroch4 <175152067+Witroch4@users.noreply.github.com>
2026-06-27 09:07:12 -03:00

877 lines
26 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
import { pathToFileURL } from "node:url";
import Database from "better-sqlite3";
const serial = { concurrency: false };
const originalEnv = {
DATA_DIR: process.env.DATA_DIR,
NEXT_PHASE: process.env.NEXT_PHASE,
HOME: process.env.HOME,
XDG_CONFIG_HOME: process.env.XDG_CONFIG_HOME,
APPDATA: process.env.APPDATA,
};
function restoreEnv() {
for (const [key, value] of Object.entries(originalEnv)) {
if (value === undefined) {
delete process.env[key];
} else {
process.env[key] = value;
}
}
}
function cleanupGlobalDb() {
try {
if (globalThis.__omnirouteDb?.open) {
globalThis.__omnirouteDb.close();
}
} catch {}
delete globalThis.__omnirouteDb;
}
function makeTempDir(prefix) {
return fs.mkdtempSync(path.join(os.tmpdir(), prefix));
}
function removePath(targetPath) {
fs.rmSync(targetPath, { recursive: true, force: true });
}
async function importFresh(modulePath) {
const url = pathToFileURL(path.resolve(modulePath)).href;
return import(`${url}?test=${Date.now()}-${Math.random().toString(16).slice(2)}`);
}
async function withEnv(overrides, fn) {
const snapshot = {};
for (const key of Object.keys(overrides)) {
snapshot[key] = process.env[key];
const value = overrides[key];
if (value === undefined) {
delete process.env[key];
} else {
process.env[key] = value;
}
}
try {
return await fn();
} finally {
for (const [key, value] of Object.entries(snapshot)) {
if (value === undefined) {
delete process.env[key];
} else {
process.env[key] = value as string;
}
}
}
}
function createLegacySchemaDb(sqliteFile, { withData = false } = {}) {
const seedDb = new Database(sqliteFile);
seedDb.exec(`
CREATE TABLE schema_migrations (version TEXT);
CREATE TABLE provider_connections (
id TEXT PRIMARY KEY,
provider TEXT NOT NULL,
auth_type TEXT,
name TEXT,
email TEXT,
priority INTEGER DEFAULT 0,
is_active INTEGER DEFAULT 1,
access_token TEXT,
refresh_token TEXT,
expires_at TEXT,
token_expires_at TEXT,
scope TEXT,
project_id TEXT,
test_status TEXT,
error_code TEXT,
last_error TEXT,
last_error_at TEXT,
last_error_type TEXT,
last_error_source TEXT,
backoff_level INTEGER DEFAULT 0,
rate_limited_until TEXT,
health_check_interval INTEGER,
last_health_check_at TEXT,
last_tested TEXT,
api_key TEXT,
id_token TEXT,
provider_specific_data TEXT,
expires_in INTEGER,
display_name TEXT,
global_priority INTEGER,
default_model TEXT,
token_type TEXT,
consecutive_use_count INTEGER DEFAULT 0,
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX idx_pc_provider ON provider_connections(provider);
CREATE INDEX idx_pc_active ON provider_connections(is_active);
CREATE INDEX idx_pc_priority ON provider_connections(provider, priority);
`);
if (withData) {
const now = new Date().toISOString();
seedDb
.prepare(
"INSERT INTO provider_connections (id, provider, auth_type, name, is_active, created_at, updated_at) VALUES (?, ?, ?, ?, ?, ?, ?)"
)
.run("legacy-openai", "openai", "apikey", "Legacy", 1, now, now);
}
seedDb.close();
}
function createLegacyCallLogsDb(sqliteFile) {
const seedDb = new Database(sqliteFile);
seedDb.exec(`
CREATE TABLE provider_connections (
id TEXT PRIMARY KEY,
provider TEXT NOT NULL,
auth_type TEXT,
name TEXT,
email TEXT,
priority INTEGER DEFAULT 0,
is_active INTEGER DEFAULT 1,
access_token TEXT,
refresh_token TEXT,
expires_at TEXT,
token_expires_at TEXT,
scope TEXT,
project_id TEXT,
test_status TEXT,
error_code TEXT,
last_error TEXT,
last_error_at TEXT,
last_error_type TEXT,
last_error_source TEXT,
backoff_level INTEGER DEFAULT 0,
rate_limited_until TEXT,
health_check_interval INTEGER,
last_health_check_at TEXT,
last_tested TEXT,
api_key TEXT,
id_token TEXT,
provider_specific_data TEXT,
expires_in INTEGER,
display_name TEXT,
global_priority INTEGER,
default_model TEXT,
token_type TEXT,
consecutive_use_count INTEGER DEFAULT 0,
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE INDEX idx_pc_provider ON provider_connections(provider);
CREATE INDEX idx_pc_active ON provider_connections(is_active);
CREATE INDEX idx_pc_priority ON provider_connections(provider, priority);
CREATE TABLE call_logs (
id TEXT PRIMARY KEY,
timestamp TEXT NOT NULL,
method TEXT,
path TEXT,
status INTEGER,
model TEXT,
provider TEXT,
account TEXT,
connection_id TEXT,
duration INTEGER DEFAULT 0,
tokens_in INTEGER DEFAULT 0,
tokens_out INTEGER DEFAULT 0,
source_format TEXT,
target_format TEXT,
api_key_id TEXT,
api_key_name TEXT,
combo_name TEXT,
request_body TEXT,
response_body TEXT,
error TEXT
);
CREATE INDEX idx_cl_timestamp ON call_logs(timestamp);
CREATE INDEX idx_cl_status ON call_logs(status);
`);
seedDb.close();
}
function createRecoverableDb(sqliteFile) {
const seedDb = new Database(sqliteFile);
const now = new Date().toISOString();
seedDb.exec(`
CREATE TABLE provider_connections (
id TEXT PRIMARY KEY,
provider TEXT NOT NULL,
auth_type TEXT,
name TEXT,
is_active INTEGER DEFAULT 1,
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE TABLE provider_nodes (
id TEXT PRIMARY KEY,
type TEXT NOT NULL,
name TEXT NOT NULL,
prefix TEXT,
api_type TEXT,
base_url TEXT,
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE TABLE key_value (
namespace TEXT NOT NULL,
key TEXT NOT NULL,
value TEXT NOT NULL,
PRIMARY KEY (namespace, key)
);
CREATE TABLE combos (
id TEXT PRIMARY KEY,
name TEXT NOT NULL UNIQUE,
data TEXT NOT NULL,
sort_order INTEGER NOT NULL DEFAULT 0,
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE TABLE api_keys (
id TEXT PRIMARY KEY,
name TEXT NOT NULL,
key TEXT NOT NULL UNIQUE,
machine_id TEXT,
allowed_models TEXT DEFAULT '[]',
no_log INTEGER NOT NULL DEFAULT 0,
created_at TEXT NOT NULL
);
`);
seedDb
.prepare(
"INSERT INTO provider_connections (id, provider, auth_type, name, is_active, created_at, updated_at) VALUES (?, ?, ?, ?, ?, ?, ?)"
)
.run("recover-openai", "openai", "apikey", "Recover Me", 1, now, now);
seedDb
.prepare(
"INSERT INTO provider_nodes (id, type, name, prefix, api_type, base_url, created_at, updated_at) VALUES (?, ?, ?, ?, ?, ?, ?, ?)"
)
.run(
"recover-node",
"custom",
"Recover Node",
"recover",
"openai",
"https://example.com",
now,
now
);
seedDb
.prepare("INSERT INTO key_value (namespace, key, value) VALUES (?, ?, ?)")
.run("settings", "globalFallbackModel", JSON.stringify("openai/gpt-4o-mini"));
seedDb
.prepare("INSERT INTO key_value (namespace, key, value) VALUES (?, ?, ?)")
.run("modelAliases", "fast-default", JSON.stringify("openai/gpt-4o-mini"));
seedDb
.prepare(
"INSERT INTO combos (id, name, data, sort_order, created_at, updated_at) VALUES (?, ?, ?, ?, ?, ?)"
)
.run(
"recover-combo",
"Recover Combo",
JSON.stringify({
id: "recover-combo",
name: "Recover Combo",
models: ["openai/gpt-4o-mini"],
}),
1,
now,
now
);
seedDb
.prepare(
"INSERT INTO api_keys (id, name, key, machine_id, allowed_models, no_log, created_at) VALUES (?, ?, ?, ?, ?, ?, ?)"
)
.run(
"recover-key",
"Recover Key",
"sk-recover-key",
"machine-recover",
JSON.stringify(["openai/gpt-4o-mini"]),
1,
now
);
seedDb.close();
}
function createLegacySchemaDbWithName(sqliteFile, name) {
createLegacySchemaDb(sqliteFile, { withData: true });
const db = new Database(sqliteFile);
db.prepare("UPDATE provider_connections SET name = ? WHERE id = ?").run(name, "legacy-openai");
db.close();
}
function listProbeFailedBackups(sqliteFile) {
const directory = path.dirname(sqliteFile);
const prefix = `${path.basename(sqliteFile)}.probe-failed-`;
return fs
.readdirSync(directory)
.filter((name) => name.startsWith(prefix))
.map((name) => path.join(directory, name))
.sort();
}
test.beforeEach(() => {
restoreEnv();
cleanupGlobalDb();
});
test.afterEach(() => {
cleanupGlobalDb();
restoreEnv();
});
test.after(() => {
cleanupGlobalDb();
restoreEnv();
});
test("getDbInstance creates sqlite schema, metadata and applies migrations", serial, async () => {
const dataDir = makeTempDir("omniroute-db-core-");
try {
await withEnv({ DATA_DIR: dataDir, NEXT_PHASE: undefined }, async () => {
const core = await importFresh("src/lib/db/core.ts");
const db = core.getDbInstance();
assert.equal(fs.existsSync(core.SQLITE_FILE), true);
assert.ok(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'table' AND name = ?")
.get("provider_connections")
);
assert.deepEqual(db.prepare("SELECT value FROM db_meta WHERE key = 'schema_version'").get(), {
value: "1",
});
const versions = db
.prepare("SELECT version FROM _omniroute_migrations ORDER BY version")
.all()
.map((row) => row.version);
assert.equal(versions[0], "001");
assert.ok(versions.includes("017"));
assert.ok(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'table' AND name = ?")
.get("version_manager")
);
core.resetDbInstance();
});
} finally {
removePath(dataDir);
}
});
test("getDbInstance reuses the singleton and closeDbInstance resets it", serial, async () => {
const dataDir = makeTempDir("omniroute-db-core-");
try {
await withEnv({ DATA_DIR: dataDir, NEXT_PHASE: undefined }, async () => {
const core = await importFresh("src/lib/db/core.ts");
const firstDb = core.getDbInstance();
const secondDb = core.getDbInstance();
assert.strictEqual(secondDb, firstDb);
assert.equal(core.closeDbInstance(), true);
assert.equal(firstDb.open, false);
assert.equal(core.closeDbInstance(), false);
const reopenedDb = core.getDbInstance();
assert.notStrictEqual(reopenedDb, firstDb);
core.resetDbInstance();
});
} finally {
removePath(dataDir);
}
});
test("local sqlite configuration enables WAL and sane pragmas", serial, async () => {
const dataDir = makeTempDir("omniroute-db-core-");
try {
await withEnv({ DATA_DIR: dataDir, NEXT_PHASE: undefined }, async () => {
const core = await importFresh("src/lib/db/core.ts");
const db = core.getDbInstance();
assert.equal(db.pragma("journal_mode", { simple: true }), "wal");
// v3.8.32 intentionally capped busy_timeout at 2s (was 5s) so a contended
// synchronous write cannot park the Node event loop past the host watchdog's
// 6s liveness probe — see src/lib/db/core.ts.
assert.equal(db.pragma("busy_timeout", { simple: true }), 2000);
assert.equal(db.pragma("synchronous", { simple: true }), 1);
assert.equal(core.closeDbInstance({ checkpointMode: null }), true);
});
} finally {
removePath(dataDir);
}
});
test("module exports honor DATA_DIR from the environment", serial, async () => {
const dataDir = makeTempDir("omniroute-db-core-env-");
try {
await withEnv({ DATA_DIR: dataDir }, async () => {
const core = await importFresh("src/lib/db/core.ts");
assert.equal(core.DATA_DIR, path.resolve(dataDir));
assert.equal(core.SQLITE_FILE, path.join(path.resolve(dataDir), "storage.sqlite"));
assert.equal(core.DB_BACKUPS_DIR, path.join(path.resolve(dataDir), "db_backups"));
});
} finally {
removePath(dataDir);
}
});
test(
"module falls back to the default home data directory when DATA_DIR is absent",
serial,
async () => {
const fakeHome = makeTempDir("omniroute-home-");
try {
await withEnv(
{
DATA_DIR: undefined,
XDG_CONFIG_HOME: undefined,
HOME: fakeHome,
USERPROFILE: fakeHome,
APPDATA: undefined,
},
async () => {
const core = await importFresh("src/lib/db/core.ts");
const expectedDir =
process.platform === "win32"
? path.join(fakeHome, "AppData", "Roaming", "omniroute")
: path.join(fakeHome, ".omniroute");
assert.equal(core.DATA_DIR, expectedDir);
assert.equal(core.SQLITE_FILE, path.join(expectedDir, "storage.sqlite"));
}
);
} finally {
removePath(fakeHome);
}
}
);
test("build phase uses an in-memory database without creating sqlite files", serial, async () => {
const dataDir = makeTempDir("omniroute-db-build-");
try {
await withEnv(
{
DATA_DIR: dataDir,
NEXT_PHASE: "phase-production-build",
},
async () => {
const core = await importFresh("src/lib/db/core.ts");
const db = core.getDbInstance();
assert.ok(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'table' AND name = ?")
.get("provider_connections")
);
assert.equal(fs.existsSync(path.join(dataDir, "storage.sqlite")), false);
assert.equal(db.pragma("journal_mode", { simple: true }), "memory");
core.resetDbInstance();
}
);
} finally {
removePath(dataDir);
}
});
test("invalid DATA_DIR (a file where a dir is expected) surfaces as a startup failure", serial, async () => {
const sandboxDir = makeTempDir("omniroute-db-bad-path-");
const fileAsDir = path.join(sandboxDir, "not-a-directory");
fs.writeFileSync(fileAsDir, "blocked");
try {
// Since #4767, db/core.ts resolves a writable data dir at module load via
// resolveWritableDataDir() → mkdirSync(recursive). Pointing DATA_DIR at a
// regular file is a non-permission misconfiguration (EEXIST/ENOTDIR), which
// resolveWritableDataDir rethrows by design (only EACCES/EPERM fall back), so
// the failure now surfaces at import time, not lazily from getDbInstance().
let caught: unknown;
await withEnv({ DATA_DIR: fileAsDir }, () => importFresh("src/lib/db/core.ts")).then(
() => {
throw new Error("expected importing db/core with an invalid DATA_DIR to reject");
},
(err) => {
caught = err;
}
);
assert.ok(caught instanceof Error, "an invalid DATA_DIR must surface as a thrown Error");
assert.match(
String((caught as Error).message),
/unable to open database file|ENOTDIR|EEXIST|not a directory|file already exists/i
);
} finally {
removePath(sandboxDir);
}
});
test(
"legacy empty schema databases are renamed before a fresh sqlite database is created",
serial,
async () => {
const dataDir = makeTempDir("omniroute-db-legacy-empty-");
const sqliteFile = path.join(dataDir, "storage.sqlite");
createLegacySchemaDb(sqliteFile);
try {
await withEnv({ DATA_DIR: dataDir }, async () => {
const core = await importFresh("src/lib/db/core.ts");
const db = core.getDbInstance();
assert.equal(fs.existsSync(`${sqliteFile}.old-schema`), true);
assert.ok(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'table' AND name = ?")
.get("_omniroute_migrations")
);
assert.equal(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'table' AND name = ?")
.get("schema_migrations"),
undefined
);
core.resetDbInstance();
});
} finally {
removePath(dataDir);
}
}
);
test(
"legacy databases with data preserve rows while removing the old migration table",
serial,
async () => {
const dataDir = makeTempDir("omniroute-db-legacy-data-");
const sqliteFile = path.join(dataDir, "storage.sqlite");
createLegacySchemaDb(sqliteFile, { withData: true });
try {
await withEnv({ DATA_DIR: dataDir }, async () => {
const core = await importFresh("src/lib/db/core.ts");
const db = core.getDbInstance();
assert.deepEqual(
db
.prepare("SELECT id, provider FROM provider_connections WHERE id = ?")
.get("legacy-openai"),
{ id: "legacy-openai", provider: "openai" }
);
assert.equal(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'table' AND name = ?")
.get("schema_migrations"),
undefined
);
assert.ok(
db
.prepare("SELECT name FROM pragma_table_info('provider_connections') WHERE name = ?")
.get("rate_limit_protection")
);
assert.ok(
db
.prepare("SELECT name FROM pragma_table_info('provider_connections') WHERE name = ?")
.get("last_used_at")
);
core.resetDbInstance();
});
} finally {
removePath(dataDir);
}
}
);
test(
"provider connection max_concurrent column is healed even if migration 029 was already recorded",
serial,
async () => {
const dataDir = makeTempDir("omniroute-db-missing-max-concurrent-");
const sqliteFile = path.join(dataDir, "storage.sqlite");
const seedDb = new Database(sqliteFile);
const now = new Date().toISOString();
seedDb.exec(`
CREATE TABLE provider_connections (
id TEXT PRIMARY KEY,
provider TEXT NOT NULL,
auth_type TEXT,
name TEXT,
priority INTEGER DEFAULT 0,
is_active INTEGER DEFAULT 1,
created_at TEXT NOT NULL,
updated_at TEXT NOT NULL
);
CREATE TABLE _omniroute_migrations (
version TEXT PRIMARY KEY,
name TEXT NOT NULL,
applied_at TEXT NOT NULL DEFAULT (datetime('now'))
);
INSERT INTO _omniroute_migrations (version, name) VALUES ('001', 'initial_schema');
INSERT INTO _omniroute_migrations (version, name) VALUES ('029', 'webhooks_templates');
`);
seedDb
.prepare(
"INSERT INTO provider_connections (id, provider, auth_type, name, priority, is_active, created_at, updated_at) VALUES (?, ?, ?, ?, ?, ?, ?, ?)"
)
.run("missing-max-openai", "openai", "apikey", "Missing max", 0, 1, now, now);
seedDb.close();
try {
await withEnv({ DATA_DIR: dataDir }, async () => {
const core = await importFresh("src/lib/db/core.ts");
const db = core.getDbInstance();
assert.ok(
db
.prepare("SELECT name FROM pragma_table_info('provider_connections') WHERE name = ?")
.get("max_concurrent")
);
assert.ok(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'index' AND name = ?")
.get("idx_pc_max_concurrent")
);
db.prepare(
"INSERT INTO provider_connections (id, provider, auth_type, name, priority, is_active, max_concurrent, created_at, updated_at) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?)"
).run("healed-openai", "openai", "apikey", "Healed", 0, 1, 2, now, now);
assert.deepEqual(
db
.prepare(
"SELECT max_concurrent AS maxConcurrent FROM provider_connections WHERE id = ?"
)
.get("healed-openai"),
{ maxConcurrent: 2 }
);
core.resetDbInstance();
});
} finally {
removePath(dataDir);
}
}
);
test(
"legacy call_logs schemas are upgraded before combo target indexes are created",
serial,
async () => {
const dataDir = makeTempDir("omniroute-db-legacy-call-logs-");
const sqliteFile = path.join(dataDir, "storage.sqlite");
createLegacyCallLogsDb(sqliteFile);
try {
await withEnv({ DATA_DIR: dataDir }, async () => {
const core = await importFresh("src/lib/db/core.ts");
const db = core.getDbInstance();
assert.ok(
db
.prepare("SELECT name FROM pragma_table_info('call_logs') WHERE name = ?")
.get("requested_model")
);
assert.ok(
db
.prepare("SELECT name FROM pragma_table_info('call_logs') WHERE name = ?")
.get("request_type")
);
assert.ok(
db
.prepare("SELECT name FROM pragma_table_info('call_logs') WHERE name = ?")
.get("combo_step_id")
);
assert.ok(
db
.prepare("SELECT name FROM pragma_table_info('call_logs') WHERE name = ?")
.get("combo_execution_key")
);
assert.ok(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'index' AND name = ?")
.get("idx_call_logs_requested_model")
);
assert.ok(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'index' AND name = ?")
.get("idx_call_logs_request_type")
);
assert.ok(
db
.prepare("SELECT name FROM sqlite_master WHERE type = 'index' AND name = ?")
.get("idx_cl_combo_target")
);
core.resetDbInstance();
});
} finally {
removePath(dataDir);
}
}
);
test(
"probe failures restore preserved critical state instead of booting with an empty database",
serial,
async () => {
const dataDir = makeTempDir("omniroute-db-probe-recover-");
const sqliteFile = path.join(dataDir, "storage.sqlite");
createRecoverableDb(sqliteFile);
const originalPrepare = Database.prototype.prepare;
try {
Database.prototype.prepare = function patchedPrepare(sql, ...args) {
if (String(sql).includes("schema_migrations")) {
throw new Error("forced probe failure");
}
return originalPrepare.call(this, sql, ...args);
};
await withEnv({ DATA_DIR: dataDir }, async () => {
const core = await importFresh("src/lib/db/core.ts");
const db = core.getDbInstance();
assert.deepEqual(
db
.prepare("SELECT id, provider, name FROM provider_connections WHERE id = ?")
.get("recover-openai"),
{ id: "recover-openai", provider: "openai", name: "Recover Me" }
);
assert.deepEqual(
db.prepare("SELECT id, name FROM provider_nodes WHERE id = ?").get("recover-node"),
{ id: "recover-node", name: "Recover Node" }
);
assert.deepEqual(
db.prepare("SELECT id, name FROM combos WHERE id = ?").get("recover-combo"),
{ id: "recover-combo", name: "Recover Combo" }
);
assert.deepEqual(
db.prepare("SELECT id, name, no_log FROM api_keys WHERE id = ?").get("recover-key"),
{ id: "recover-key", name: "Recover Key", no_log: 1 }
);
assert.deepEqual(
db
.prepare("SELECT value FROM key_value WHERE namespace = 'settings' AND key = ?")
.get("globalFallbackModel"),
{ value: JSON.stringify("openai/gpt-4o-mini") }
);
assert.equal(listProbeFailedBackups(sqliteFile).length >= 1, true);
core.resetDbInstance();
});
} finally {
Database.prototype.prepare = originalPrepare;
removePath(dataDir);
}
}
);
test(
"auto-restore picks latest probe-failed timestamp instead of latest mtime",
serial,
async () => {
const dataDir = makeTempDir("omniroute-db-probe-latest-");
const sqliteFile = path.join(dataDir, "storage.sqlite");
const olderBackup = `${sqliteFile}.probe-failed-1000`;
const newerBackup = `${sqliteFile}.probe-failed-2000`;
createLegacySchemaDbWithName(olderBackup, "Older Backup");
createLegacySchemaDbWithName(newerBackup, "Newer Backup");
fs.utimesSync(
olderBackup,
new Date("2030-01-01T00:00:00.000Z"),
new Date("2030-01-01T00:00:00.000Z")
);
fs.utimesSync(
newerBackup,
new Date("2020-01-01T00:00:00.000Z"),
new Date("2020-01-01T00:00:00.000Z")
);
try {
await withEnv({ DATA_DIR: dataDir }, async () => {
const core = await importFresh("src/lib/db/core.ts");
const db = core.getDbInstance();
assert.deepEqual(
db
.prepare("SELECT id, provider, name FROM provider_connections WHERE id = ?")
.get("legacy-openai"),
{ id: "legacy-openai", provider: "openai", name: "Newer Backup" }
);
assert.equal(fs.existsSync(sqliteFile), true);
assert.equal(fs.existsSync(newerBackup), false);
assert.equal(fs.existsSync(olderBackup), true);
core.resetDbInstance();
});
} finally {
removePath(dataDir);
}
}
);
test(
"probe failures without a safe snapshot abort startup and keep manual recovery explicit",
serial,
async () => {
const dataDir = makeTempDir("omniroute-db-probe-abort-");
const sqliteFile = path.join(dataDir, "storage.sqlite");
fs.writeFileSync(sqliteFile, "not-a-valid-sqlite-database");
try {
await withEnv({ DATA_DIR: dataDir }, async () => {
const core = await importFresh("src/lib/db/core.ts");
assert.throws(() => core.getDbInstance(), /Manual recovery required after probe failure/i);
assert.equal(fs.existsSync(sqliteFile), false);
assert.equal(listProbeFailedBackups(sqliteFile).length >= 1, true);
const restartedCore = await importFresh("src/lib/db/core.ts");
assert.throws(
() => restartedCore.getDbInstance(),
/Manual recovery required after probe failure/i
);
assert.equal(fs.existsSync(sqliteFile), false);
core.resetDbInstance();
});
} finally {
removePath(dataDir);
}
}
);