mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-05 14:52:09 +03:00
* chore(release): open v3.8.22 development cycle * refactor(dashboard): extract ProviderDetailPageClient — #3501 Phase 0 (#3633) #3501 Phase 0: extract ProviderDetailPageClient + smoke test. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * refactor(dashboard): extract auth-import modals — #3501 Phase 1a (#3634) #3501 Phase 1a: extract 3 auth-import modal clusters. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * fix(db): reclassify localDb unexported modules as intentionally-internal (#3499) (#3635) Closes #3499 — reclassify localDb unexported modules as intentionally-internal (audit + honest gate framing). * refactor(db): move call_logs aggregations into callLogStats db module (#3500) (#3636) #3500 slice 1: call_logs aggregations → src/lib/db/callLogStats.ts (Rule #5). Byte-identical queries; TDD 6/6. * refactor(dashboard): extract EditCompatibleNodeModal — #3501 Phase 1b (#3638) #3501 Phase 1b: extract EditCompatibleNodeModal (cycle-safe via leaf constants module). Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * refactor(db): move community_servers SQL into gamification db module (#3500 slice 3) (#3639) #3500 slice 3: community_servers SQL → gamification db module. * refactor(db): move usage_history SQL into usageAnalytics module (#3500 slice 2) (#3644) #3500 slice 2: usage_history/daily_usage_summary SQL → usageAnalytics db module. * refactor(db): move skills UPDATE + db-backups SQL into db modules (#3500 slice 5) (#3647) #3500 slice 5: skills UPDATE (allowlist) + db-backups SQL → db modules. * refactor(db): move usage_logs/semantic_cache/proxy_logs SQL into db modules (#3500 slice 4) (#3648) #3500 slice 4: usage_logs/semantic_cache/proxy_logs SQL → db modules. All internal routes done (2 external by-design remain). * chore(db-gate): reclassify external-DB reads, fully close #3500 (#3649) Closes #3500: reclassify external-DB reads; all internal raw-SQL migrated to db/ modules. * refactor(dashboard): extract pure helpers to providerPageHelpers — #3501 Phase 2 (#3653) #3501 Phase 2: extract pure helpers to providerPageHelpers (leaf, cycle-safe). Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * refactor(dashboard): extract remaining shared helpers to providerPageHelpers — #3501 Phase 2b (#3658) #3501 Phase 2b: extract remaining shared helpers to providerPageHelpers (leaf, cycle-safe). Heavy modals unblocked. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * fix(reasoning): replay reasoning_content on plain DeepSeek turns (#1682) (#3632) Integrated into release/v3.8.22 * fix(kiro): route enterprise IAM Identity Center accounts to their regional endpoint (#3631) Integrated into release/v3.8.22 * refactor: small code cleanup (#3523) Integrated into release/v3.8.22 * fix(combo): skip same-provider targets on 408/500/502/503/504/524 errors (#3637) Integrated into release/v3.8.22 — circuit-breaker guard added in review (#1731v2) * feat(providers): add MiMoCode free-tier provider with bootstrap JWT auth (#3659) Integrated into release/v3.8.22 — page.tsx conflict resolved + NoAuthAccountCard re-applied to ProviderDetailPageClient in review. MiMoCode endpoint validated live. * Log Responses WebSocket calls in history (#3616) Integrated into release/v3.8.22 — Codex Responses WebSocket call history logging. * Add Claude Code routing preference for unprefixed Claude models (#3540) Integrated into release/v3.8.22 — page.tsx conflict resolved (re-applied toggle to ProviderDetailPageClient) + disable-test updated for catalog drift in review. * docs(changelog): credit #3632/#3631/#3637/#3659/#3540/#3616/#3523 (v3.8.22 targeted review round) * fix(mimocode): add required authHeader:"none" to registry entry (#3659 follow-up) The mimocode RegistryEntry omitted the required authHeader field, which broke typecheck:core (TS2741). Match the no-auth convention (authType:"none" + authHeader:"none") used by veoaifree-web and other free providers. Follow-up to #3659 (@pizzav-xyz). * fix(responses): detect stream readiness for tool-call-only and object-less chunks (#3612) (#3661) Closes #3612 * fix(mitm): remove duplicated 'Command failed:' error prefix (#3641) (#3662) Closes #3641 * fix(cli): honor HERMES_HOME for Hermes Agent config path (#3628) (#3663) Closes #3628 * fix(api): fetch live OpenCode model catalog for no-auth model picker (#3611) (#3664) Closes #3611 * fix(api): flag provider topology error state by current status, not stale history (#3619) (#3666) Closes #3619 * fix(electron): launch peer-stamping server-ws.mjs entrypoint to avoid 403 LOCAL_ONLY (#3386) (#3665) Closes #3386 * fix(dashboard): restore home topology live in-flight pulse (#3507) (#3667) Closes #3507 * fix(oauth): name Kiro/AWS auto-imported accounts and dedupe by profileArn (#3615) (#3671) Closes #3615 * fix(resilience): clear stale transient connection cooldowns on startup (#3625) (#3672) Closes #3625 * fix(i18n): use logical CSS direction utilities for sidebar and key overlays (RTL #3541) (#3670) Closes #3541 * fix(dashboard): honor auto-hide and switch to visible filter on passthrough Test-all (#3610) (#3669) Closes #3610 * refactor(dashboard): extract AddApiKeyModal + EditConnectionModal — #3501 Phase 1c (#3674) #3501 Phase 1c: extract AddApiKeyModal, EditConnectionModal, WebSessionCredentialGuide into components/; god-component 10,166->8,092 LOC. Reconciles the v3.8.22 file-size drift for this file. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * docs(changelog): reconcile v3.8.22 — credit #3621/#3622 + MiMoCode follow-up roll-up * refactor(dashboard): extract ConnectionRow + ModelCompatPopover + SiliconFlowEndpointModal — #3501 Phase 1d (#3676) #3501 Phase 1d: god-component 8,092->6,838 LOC. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * feat(obsidian): add WebDAV config route + encrypt creds at rest (#3485 part 1) (#3677) Part 1 of #3485. Adds /api/settings/obsidian/webdav (GET/POST/DELETE) wiring the ready obsidianSync lib, encrypts webdav password + obsidian token at rest, removes the duplicate UI block, drops the KNOWN_MISSING entry. WebDAV file server is part 2. * feat(obsidian): add /api/v1/webdav file server for Obsidian vault sync (#3485 part 2) (#3678) Part 2 of #3485. WebDAV server (PROPFIND/GET/PUT/DELETE/MKCOL/MOVE/OPTIONS) handled in the custom server layer (standalone-server-ws.mjs) since the App Router cannot export WebDAV methods. Basic-Auth (constant-time), path-traversal hardened, password decrypt ported from encryption.ts (parity-tested), DATA_DIR resolution parity-tested against dataPaths.ts. End-to-end Obsidian-over-Tailscale validation is a live VPS step (Rule #18). * fix(combo): stop premature context compaction — real auto-combo windows + per-target compression limit (#3680) Integrated into release/v3.8.22 * feat(dashboard): deactivate/activate accounts from the quota overview (#3675) Integrated into release/v3.8.22 * fix(dashboard): close review gaps in bulk provider connection actions (#3271 follow-up) (#3673) Integrated into release/v3.8.22 — page.tsx conflict (god-component split #3501) resolved by re-applying the bulk-action deltas to ProviderDetailPageClient.tsx * refactor(dashboard): extract useModelCompatState hook + model sections — #3501 Phase 1e (#3683) #3501 Phase 1e: extract useModelCompatState hook (unblocks the model sections) + ModelRow/PassthroughModelsSection/PassthroughModelRow/CustomModelsSection/CompatibleModelsSection. god-component 6,838->4,921 LOC. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * refactor(dashboard): extract useProviderConnections/Settings/Models hooks — #3501 Phase 1f (#3684) #3501 Phase 1f: god-component 4,948->4,062 LOC. Connection state+handlers, settings, and model metadata moved into hooks/. Co-authored-by: oyi77 <oyi77@users.noreply.github.com> * chore(release): v3.8.22 CHANGELOG + env-doc sync - Set release date in CHANGELOG [3.8.22] to 2026-06-11 - Add HERMES_HOME to .env.example (from #3628/#3663) - Add HERMES_HOME + OMNIROUTE_PREFER_CLAUDE_CODE_FOR_UNPREFIXED_CLAUDE_MODELS to ENVIRONMENT.md (#3628/#3540) * docs(changelog): credit #3673 + #3675 — leninejunior bulk-actions + quota-toggle --------- Co-authored-by: oyi77 <oyi77@users.noreply.github.com> Co-authored-by: Abhishek Divekar <adivekar@utexas.edu> Co-authored-by: NOXX - Commiter <artur1992123@mail.ru> Co-authored-by: Nicolas Lorin <androw95220@gmail.com> Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: kkkayye <98376609+kkkayye@users.noreply.github.com> Co-authored-by: Witroch4 <witalo_rocha@hotmail.com> Co-authored-by: Lenine Júnior <lenine@engrene.com.br>
202 lines
6.9 KiB
TypeScript
202 lines
6.9 KiB
TypeScript
import { execFile, spawn } from "child_process";
|
|
import fs from "fs";
|
|
import os from "os";
|
|
import path from "path";
|
|
import crypto from "crypto";
|
|
|
|
export function getErrorMessage(error: unknown): string {
|
|
return error instanceof Error ? error.message : String(error);
|
|
}
|
|
|
|
export function isRoot(): boolean {
|
|
try {
|
|
return !!(process.getuid && process.getuid() === 0);
|
|
} catch {
|
|
return false;
|
|
}
|
|
}
|
|
|
|
export function execFileText(command: string, args: string[]): Promise<string> {
|
|
return new Promise((resolve, reject) => {
|
|
execFile(command, args, { encoding: "utf8" }, (error, stdout, stderr) => {
|
|
if (error) {
|
|
// Node's execFile already sets error.message to "Command failed: <cmd>"
|
|
// (for non-zero exit) or "spawn <cmd> ENOENT" (for missing binary).
|
|
// Re-prefixing with "Command failed: " would double the prefix for the
|
|
// non-zero exit case. Surface Node's message directly and only append
|
|
// stderr when it contains additional context. (#3641)
|
|
reject(new Error(getErrorMessage(error) + (stderr ? `\n${stderr}` : "")));
|
|
return;
|
|
}
|
|
resolve(stdout);
|
|
});
|
|
});
|
|
}
|
|
|
|
export function execFileWithPassword(
|
|
command: string,
|
|
args: string[],
|
|
password: string,
|
|
stdinAfterPassword = ""
|
|
): Promise<string> {
|
|
// When running as root, skip sudo -S and run the target command directly
|
|
const root = isRoot();
|
|
const needsPassword = !root || command !== "sudo";
|
|
let finalCommand = command;
|
|
let finalArgs = args;
|
|
|
|
if (root && command === "sudo") {
|
|
const realCmdIndex = args.findIndex((arg) => !arg.startsWith("-"));
|
|
if (realCmdIndex !== -1) {
|
|
finalCommand = args[realCmdIndex];
|
|
finalArgs = args.slice(realCmdIndex + 1);
|
|
}
|
|
}
|
|
|
|
return new Promise((resolve, reject) => {
|
|
// `command` and `args` are never user-controlled. This helper is a
|
|
// controlled wrapper called only from src/mitm/cert/install.ts with a
|
|
// fixed allowlist of executables: "sudo", "certutil", "security",
|
|
// "update-ca-certificates", "update-ca-trust", "cp", "mkdir", "rm".
|
|
// `spawn` is used (not `exec`) so each arg is a separate argv entry and
|
|
// shell metacharacters do not expand. See docs/security/SOCKET_DEV_FINDINGS.md §3.
|
|
// nosemgrep
|
|
const child = spawn(finalCommand, finalArgs, { // nosemgrep
|
|
stdio: ["pipe", "pipe", "pipe"],
|
|
});
|
|
let stdout = "";
|
|
let stderr = "";
|
|
let settled = false;
|
|
|
|
const settle = (error: Error | null) => {
|
|
if (settled) return;
|
|
settled = true;
|
|
if (error) {
|
|
reject(error);
|
|
return;
|
|
}
|
|
resolve(stdout);
|
|
};
|
|
|
|
child.stdout?.on("data", (chunk) => {
|
|
stdout += chunk.toString();
|
|
});
|
|
child.stderr?.on("data", (chunk) => {
|
|
stderr += chunk.toString();
|
|
});
|
|
child.on("error", (error) => {
|
|
settle(new Error(`Command failed: ${getErrorMessage(error)}\n${stderr}`));
|
|
});
|
|
child.on("close", (code) => {
|
|
if (code === 0) {
|
|
settle(null);
|
|
return;
|
|
}
|
|
settle(new Error(`Command failed with code ${code}\n${stderr}`));
|
|
});
|
|
|
|
const stdinInput = needsPassword
|
|
? `${password}\n${stdinAfterPassword}`
|
|
: stdinAfterPassword || "";
|
|
if (stdinInput) {
|
|
child.stdin?.write(stdinInput);
|
|
}
|
|
child.stdin?.end();
|
|
});
|
|
}
|
|
|
|
export function quotePowerShell(value: string): string {
|
|
return `'${value.replace(/'/g, "''")}'`;
|
|
}
|
|
|
|
export function runPowerShell(script: string): Promise<string> {
|
|
return execFileText("powershell", [
|
|
"-NoProfile",
|
|
"-NonInteractive",
|
|
"-ExecutionPolicy",
|
|
"Bypass",
|
|
"-Command",
|
|
script,
|
|
]);
|
|
}
|
|
|
|
/**
|
|
* Build the outer (non-elevated) wrapper script that triggers UAC and spawns
|
|
* the elevated powershell with `-File <scriptPath>`. Exported separately so
|
|
* regression tests can assert the textbook `-EncodedCommand` fingerprint is
|
|
* absent without needing to monkey-patch the child_process spawn path.
|
|
*/
|
|
export function buildElevatedScriptWrapper(scriptPath: string): string {
|
|
return `
|
|
$proc = Start-Process powershell -ArgumentList @(
|
|
'-NoProfile',
|
|
'-NonInteractive',
|
|
'-ExecutionPolicy',
|
|
'Bypass',
|
|
'-File',
|
|
${quotePowerShell(scriptPath)}
|
|
) -Verb RunAs -Wait -PassThru;
|
|
if ($proc.ExitCode -ne 0) {
|
|
throw "Elevated command exited with code $($proc.ExitCode)"
|
|
}
|
|
`;
|
|
}
|
|
|
|
// SECURITY-AUDITOR-NOTE: This function is referenced by Socket.dev finding
|
|
// `21843.js` (AI-detected potential malware) on the published npm artifact.
|
|
// Mitigation applied in v3.8.6:
|
|
// - The elevated payload is written to a per-call temp .ps1 file owned by the
|
|
// local user (mode 0o600) and referenced via `-File`. We no longer use
|
|
// `-EncodedCommand <base64utf16le>`, which is the textbook fingerprint
|
|
// pattern-matched by heuristic AV/AI scanners.
|
|
// - Each call uses a fresh `crypto.randomUUID()` filename inside a private
|
|
// `mkdtempSync` directory so concurrent calls cannot collide and a third
|
|
// party cannot guess the path.
|
|
// - The temp file is unlinked in `finally` even if the UAC prompt is denied
|
|
// or the elevated command throws.
|
|
// - This function is only invoked from `installCertWindows` and
|
|
// `uninstallCertWindows` (src/mitm/cert/install.ts) which themselves only
|
|
// run when a user explicitly enables or disables the MITM proxy from the
|
|
// local dashboard at /dashboard/cli-tools/mitm.
|
|
// See docs/security/SOCKET_DEV_FINDINGS.md §3 for the full attestation.
|
|
export async function runElevatedPowerShell(script: string): Promise<string> {
|
|
const tempDir = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-elevate-"));
|
|
const scriptName = `omniroute-elevate-${crypto.randomUUID()}.ps1`;
|
|
const scriptPath = path.join(tempDir, scriptName);
|
|
fs.writeFileSync(scriptPath, script, { encoding: "utf8", mode: 0o600 });
|
|
try {
|
|
return await runPowerShell(buildElevatedScriptWrapper(scriptPath));
|
|
} finally {
|
|
try {
|
|
fs.rmSync(tempDir, { recursive: true, force: true });
|
|
} catch {
|
|
// Best-effort cleanup: leftover files in $TMPDIR are owned by the local
|
|
// user and the OS cleans them on next reboot.
|
|
}
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Test-only helper that mirrors `runElevatedPowerShell`'s temp-file lifecycle
|
|
* but lets the caller substitute the spawn path. Used by the regression test
|
|
* for the `-EncodedCommand` removal — production code must NOT call this.
|
|
*/
|
|
export async function _runElevatedPowerShellForTest(
|
|
script: string,
|
|
runner: (wrapper: string, scriptPath: string) => Promise<string>
|
|
): Promise<string> {
|
|
const tempDir = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-elevate-"));
|
|
const scriptName = `omniroute-elevate-${crypto.randomUUID()}.ps1`;
|
|
const scriptPath = path.join(tempDir, scriptName);
|
|
fs.writeFileSync(scriptPath, script, { encoding: "utf8", mode: 0o600 });
|
|
try {
|
|
return await runner(buildElevatedScriptWrapper(scriptPath), scriptPath);
|
|
} finally {
|
|
try {
|
|
fs.rmSync(tempDir, { recursive: true, force: true });
|
|
} catch {
|
|
// Best-effort cleanup.
|
|
}
|
|
}
|
|
}
|