Files
OmniRoute/tests/unit/executor-web-cookie-sweep.test.ts
Diego Rodrigues de Sa e Souza 7db430a352 Release v3.8.14 (#3340)
* chore(release): open v3.8.14 development cycle

Version bump 3.8.13 -> 3.8.14 (root + electron + open-sse + openapi + lockfiles).
Seed the v3.8.14 changelog with the four post-tag hotfixes that shipped to
Docker/Electron in v3.8.13 but missed the immutable npm 3.8.13 (#3336 SSRF /
CodeQL #323, #3334/#3335/#3339 Electron packaging). i18n CHANGELOG mirrors get
the in-progress placeholder section.

* feat: add per-provider custom headers support for OpenAI/Anthropic-compatible nodes (#3338)

Integrated into release/v3.8.14

* fix: Kiro Builder ID token import fails with Bad credentials (#3333)

Integrated into release/v3.8.14 — adds Builder ID cached-creds + OIDC refresh path for Kiro token import, with regression tests (#3333).

* Improve code quality: auto-pr/docstrings-1780792063 (#3337)

Integrated into release/v3.8.14 — docstring for context analytics route re-export.

* fix(catalog): remove minimaxai/minimax-m3 from NVIDIA NIM tier (404 upstream) (#3329) (#3341)

NVIDIA NIM does not host minimaxai/minimax-m3 — every request returns
404 page not found, while sibling minimaxai/minimax-m2.7 on the same provider
works. Advertising a model that 404s is a catalog bug; remove it from the nvidia
tier (it remains on the tiers that actually serve MiniMax M3). Re-add only once
NVIDIA serves it.

Co-authored-by: mikmaneggahommie <mikmaneggahommie@users.noreply.github.com>

* fix(cli): write OpenCode config to ~/.config on all platforms incl. Windows (#3330) (#3343)

resolveOpencodeConfigDir used %APPDATA% on Windows, but OpenCode reads its
config from XDG ~/.config/opencode/ on every platform (on Windows:
%USERPROFILE%\.config\opencode\, NOT %APPDATA%). So a Windows user who
configured OpenCode via the dashboard had the file written where OpenCode never
looks — it silently had no effect.

Use the XDG path (XDG_CONFIG_HOME || ~/.config) unconditionally. Update the UI
note + route JSDoc, and flip the three tests that encoded the old %APPDATA%
behavior (t40 per-platform + card-note, cli-runtime-extended getCliConfigPaths).

Co-authored-by: abdulkadirozyurt <abdulkadirozyurt@users.noreply.github.com>

* fix(proxy): make auto-selection fallback opt-in (#3332) (#3344)

selectWorkingProxyFallback (Step 11 of resolveProxyForConnection) listed ALL
registry proxies, ignoring assignments and per-connection proxy_enabled, and
returned the first working one with level:'autoSelect'. So a single proxy added
to the registry silently became a global fallback for every connection's traffic.

Gate it behind a new PROXY_AUTO_SELECT_ENABLED feature flag (default off): the
fallback now no-ops unless the operator opts in. No registry proxy becomes a
silent global default anymore.

Co-authored-by: hertznsk <hertznsk@users.noreply.github.com>

* fix(sse): treat MiniMax M3 as multimodal so vision isn't stripped (#3328) (#3342)

MiniMax M3 via the opencode provider (oc/minimax-m3-free) appeared blind:
image inputs didn't reach the model, while the same model in Cline could
see them. Verified empirically that MiniMax M3 on the opencode upstream IS
multimodal -- a base64 image is described correctly (it returns 403 only
for remote image URLs, which it doesn't accept).

Root cause: OmniRoute treated MiniMax M3 as a non-vision model in two
places, so when compression was active the image was replaced with a text
placeholder before dispatch:
- compression's modelSupportsVision() heuristic (lite.ts) only matched
  gpt-4/4o/claude-3/gemini/vision -- minimax was absent -> replaceImageUrls
  stripped the image.
- the opencode minimax-m3-free catalog entry lacked supportsVision, so the
  combo vision-capability gate could also exclude/mishandle it.

Add 'minimax-m3' to the vision heuristic and supportsVision: true to the
opencode minimax-m3-free entry. TDD: a failing-then-passing test in
compression/lite.test.ts proves replaceImageUrls now keeps images for
minimax-m3 ids, plus a registry assertion mirroring the #2822 qwen test.

Reported-by: @mikmaneggahommie

* docs(i18n): translate 25 core documentation files to Indonesian (#3348)

Integrated into release/v3.8.14 — Indonesian i18n docs.

* fix(review): resolve /review-reviews battery findings (LEDGER-1..11) on v3.8.14 (#3350)

Integrated into release/v3.8.14 — /review-reviews battery hardening (LEDGER-1..11) for #3338 custom-headers + #3333 kiro, plus cycle-test drift fixes (#3329/#3330/#3332).

* fix(provider-proxy): honor per-account proxy toggles (#3349)

Integrated into release/v3.8.14 — honor per-account proxy toggles + auto-fallback opt-in via PROXY_AUTO_SELECT_ENABLED.

* fix(dashboard): remove duplicate Distribute Proxies button on provider page (#3352)

* fix(providers): reduce proxy label noise (#3346)

Integrated into release/v3.8.14 — reduce proxy label noise + a11y (aria-label/sr-only).

* fix(duckduckgo): restore bare Response contract and rebase onto release/v3.8.14 (#3323)

Integrated into release/v3.8.14 — browser-backed cookie providers (duckduckgo/claude-web) with restored executor contract + unit tests.

* fix(noauth): expose only usable model aliases (#3345)

Integrated into release/v3.8.14 — noauth usable-alias filtering + registry alias plumbing (veo-free).

* fix(dashboard): stop infinite config-load loop on Hermes Agent detail page (#3353)

* fix(electron): tree-kill the server on exit/update to release the omniroute.exe lock (#3347) (#3354)

* chore(release): finalize v3.8.14 changelog + clear release-gate drift

- CHANGELOG: finalize the v3.8.14 section (date, full New Features/Bug Fixes/
  Maintenance coverage of all 16 cycle commits, Contributors hall of 12).
- docs: document OMNIROUTE_BROWSER_POOL + WEB_COOKIE_USE_BROWSER (#3323) in
  .env.example + ENVIRONMENT.md; regenerate the id/llm.txt strict mirror (#3348
  had translated it; llm.txt mirrors must match root).
- test(proxy-fetch): #3323 made tlsClient.available a computed getter — stub it
  via Object.defineProperty instead of assignment (5 tests were red on the base).

* fix(translator): coerce Gemini functionDeclaration parameters to an OBJECT schema (#3357) (#3360)

* fix(gemini): resolve truncation/suppression of false positive textual tool call markers in backticks (#3358)

Integrated into release/v3.8.14 — Gemini/Antigravity textual tool-call marker normalization (no false-positive suppression + split-chunk buffering).

* docs(changelog): add #3358 Gemini textual tool-call normalization to v3.8.14

* fix(dashboard): surface real analytics error instead of generic placeholder (#3356) (#3361)

The Analytics page discarded the server's error body on a non-OK response and
rendered a generic "An error occurred", so users (and maintainers) could not see
why /api/usage/analytics 500'd after an upgrade. Now the route returns the real
reason via buildErrorBody (sanitized, Hard Rule #12) and the page surfaces it via
a new readFetchErrorMessage helper that handles both the OpenAI-style and legacy
error shapes.

Reported-by: @superti4r

---------

Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com>
Co-authored-by: Someres <168349709+quanturbo@users.noreply.github.com>
Co-authored-by: Dong Mengzhe <154944819+Lang-Qiu@users.noreply.github.com>
Co-authored-by: mikmaneggahommie <mikmaneggahommie@users.noreply.github.com>
Co-authored-by: abdulkadirozyurt <abdulkadirozyurt@users.noreply.github.com>
Co-authored-by: hertznsk <hertznsk@users.noreply.github.com>
Co-authored-by: Krisna Santosa <54174372+KrisnaSantosa15@users.noreply.github.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Wilson <pedbookmed@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Ardem2025 <ardemb22@gmail.com>
2026-06-07 07:20:02 -03:00

221 lines
8.4 KiB
TypeScript
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
/**
* Web-Cookie + NoAuth executor wrapper contract sweep.
*
* Why this file exists
* --------------------
* `open-sse/handlers/chatCore.ts` reads `res.response.status`, `res.response.headers`,
* and uses `res.url` / `res.transformedBody` to classify upstream responses
* (see chatCore.ts:39374486, BaseExecutor.execute() at base.ts:1146).
*
* An executor that returns a raw `Response` instead of the wrapper shape
* `{response, url, headers, transformedBody}` causes `res.response.status` to
* throw `Cannot read properties of undefined (reading 'status')`. That JS
* TypeError was then surfaced as a 502 via `formatProviderError` in
* `open-sse/utils/error.ts:496`, and showed up to the client as
* `[502]: Cannot read properties of undefined (reading 'status')`.
*
* The duckduckgo-web executor was the first known case. To prevent any
* future executor from regressing on the same contract, this sweep test
* imports every executor in `WEB_COOKIE_PROVIDERS` + `NOAUTH_PROVIDERS`
* (20 web-cookie + 2 noauth = 22 total), calls `execute()` with a minimal
* but valid input, and asserts the wrapper shape. Tests use the
* pre-aborted signal path or empty-creds path so no real upstream call
* is needed.
*
* If this file ever flags a missing executor, the fix is in the executor
* — the contract is the executor's responsibility.
*/
import { describe, it } from "node:test";
import assert from "node:assert/strict";
import { getExecutor } from "../../open-sse/executors/index.ts";
import {
WEB_COOKIE_PROVIDERS,
NOAUTH_PROVIDERS,
} from "../../src/shared/constants/providers.ts";
type WebCookieId = keyof typeof WEB_COOKIE_PROVIDERS;
type NoauthId = keyof typeof NOAUTH_PROVIDERS;
const WEB_COOKIE_IDS = Object.keys(WEB_COOKIE_PROVIDERS) as WebCookieId[];
const NOAUTH_IDS = Object.keys(NOAUTH_PROVIDERS) as NoauthId[];
/**
* Per-provider fake-credential strings that pass the executor's own
* input-validation gate without making a real upstream call succeed.
* Each executor parses a different cookie/header — the goal is only
* to short-circuit the network call with a synthetic 401/403/4xx/5xx,
* not to actually authenticate.
*/
const FAKE_CREDS: Record<string, string> = {
"chatgpt-web": "__Secure-next-auth.session-token=fake-audit-sweep",
"grok-web": "sso=fake-audit-sweep",
"gemini-web": "__Secure-1PSID=fake-audit-sweep",
"perplexity-web": "__Secure-next-auth.session-token=fake-audit-sweep",
"blackbox-web": "__Secure-authjs.session-token=fake-audit-sweep",
"muse-spark-web": "ecto_1_sess=fake-audit-sweep",
"claude-web": "sessionKey=fake-audit-sweep",
"deepseek-web": "userToken=fake-audit-sweep",
"copilot-web": "fake-audit-sweep",
"t3-web": "fake-audit-sweep",
"inner-ai": "fake-audit-sweep user@example.com",
"adapta-web": "__client=fake-audit-sweep",
huggingchat: "hf-chat=fake-audit-sweep",
phind: "fake-audit-sweep",
"poe-web": "p-b=fake-audit-sweep",
"venice-web": "fake-audit-sweep",
"v0-vercel-web": "fake-audit-sweep",
"kimi-web": "fake-audit-sweep",
"doubao-web": "fake-audit-sweep",
"qwen-web": "fake-audit-sweep",
"duckduckgo-web": "",
"veoaifree-web": "",
};
const VALID_BODY = {
model: "test",
messages: [{ role: "user", content: "ping" }],
};
/**
* Asserts that `result` has the executor wrapper contract shape:
* { response: Response, url: string, headers: object, transformedBody: unknown }
*
* The contract is what `open-sse/handlers/chatCore.ts` and
* `BaseExecutor.execute()` (open-sse/executors/base.ts:1146) depend on.
*/
function assertExecutorWrapperShape(
result: unknown,
provider: string
): asserts result is {
response: Response;
url: string;
headers: Record<string, unknown>;
transformedBody: unknown;
} {
assert.ok(
result && typeof result === "object",
`[${provider}] execute() must return an object, not ${typeof result}`
);
const r = result as Record<string, unknown>;
assert.ok(
r.response instanceof Response,
`[${provider}] result.response must be a Response (got ${typeof r.response})`
);
assert.equal(
typeof r.url,
"string",
`[${provider}] result.url must be a string`
);
assert.ok(
r.headers && typeof r.headers === "object",
`[${provider}] result.headers must be an object`
);
// transformedBody may be null/undefined/object; just check it doesn't
// throw when accessed.
void r.transformedBody;
// Critical: r.response.status must be reachable without throwing
// — this is the exact property read that the duckduckgo-web bug
// (#3106) crashed on.
const status = (r.response as Response).status;
assert.ok(
Number.isInteger(status) && status >= 100 && status < 600,
`[${provider}] result.response.status must be a valid HTTP status, got ${status}`
);
}
describe("web-cookie + noauth executor wrapper contract sweep", () => {
describe("WEB_COOKIE_PROVIDERS (20)", () => {
for (const providerId of WEB_COOKIE_IDS) {
it(`${providerId} executor returns wrapper shape`, async () => {
const executor = getExecutor(providerId);
assert.ok(executor, `[${providerId}] getExecutor must return an executor`);
const result = await executor.execute({
model: providerId,
body: VALID_BODY,
stream: false,
credentials: { apiKey: FAKE_CREDS[providerId] ?? "fake" },
signal: null,
} as never);
assertExecutorWrapperShape(result, providerId);
// Result should never be a JS TypeError. Real executor returns
// a proper Response with a JSON error body for invalid creds.
// If a regression introduces a raw Response return, the shape
// assertion above will fail.
const body = await result.response.text();
// Most executors return JSON error bodies for invalid creds.
// We don't require JSON, but we DO require the body to be a
// non-empty string (not the literal "[object Response]" or
// a TypeError stack trace).
assert.ok(
body.length > 0,
`[${providerId}] response body must be non-empty`
);
// And it must NOT be the duckduckgo-web regression signature.
assert.doesNotMatch(
body,
/Cannot read properties of undefined \(reading 'status'\)/,
`[${providerId}] must not surface the chatCore-side TypeError`
);
});
}
});
describe("NOAUTH_PROVIDERS (4 total; 2 require cookie='') ", () => {
// Only noauth providers that should be probed without creds:
// duckduckgo-web and veoaifree-web. opencode/notice have dedicated
// executor tests already (executor-opencode.test.ts / executor-notice.test.ts).
const TARGETS = NOAUTH_IDS.filter(
(id) => id === "duckduckgo-web" || id === "veoaifree-web"
);
for (const providerId of TARGETS) {
it(`${providerId} noauth executor returns wrapper shape`, async () => {
const executor = getExecutor(providerId);
assert.ok(executor, `[${providerId}] getExecutor must return an executor`);
// Use a pre-aborted signal so the executor short-circuits via
// its AbortError path before any real network call.
const controller = new AbortController();
controller.abort();
const result = await executor.execute({
model: providerId,
body: VALID_BODY,
stream: false,
credentials: { apiKey: "" },
signal: controller.signal,
} as never);
// duckduckgo-web may legitimately short-circuit with a bare
// 499 Response on a pre-aborted signal; chatCore's
// normalizeExecutorResult already accepts both shapes. Only
// insist on the full wrapper for executors that are expected
// to produce one.
if (result instanceof Response) {
assert.ok(
result.status >= 100 && result.status < 600,
`[${providerId}] bare Response must have a valid HTTP status, got ${result.status}`
);
} else {
assertExecutorWrapperShape(result, providerId);
}
const body = await (
result instanceof Response ? result : result.response
).text();
assert.ok(
body.length > 0,
`[${providerId}] response body must be non-empty`
);
assert.doesNotMatch(
body,
/Cannot read properties of undefined \(reading 'status'\)/,
`[${providerId}] must not surface the chatCore-side TypeError`
);
});
}
});
});