Files
OmniRoute/open-sse/executors/qoder.ts
Diego Rodrigues de Sa e Souza bf8b56b29f Release v3.8.20 (#3547)
* chore(release): open v3.8.20 development cycle

* fix(images): prefer bare combos over image aliases (#3527)

Integrated into release/v3.8.20

* fix(translator): map Codex local_shell tool (#3534)

Integrated into release/v3.8.20

* fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (#3522)

Integrated into release/v3.8.20

* Fix Runtime page breaker state rendering (#3533)

Integrated into release/v3.8.20

* Expose provider breaker degradation threshold setting (#3535)

Integrated into release/v3.8.20

* fix(executor): strip provider prefix from versioned built-in tool model field (#3532)

Integrated into release/v3.8.20

* feat(providers): add Claude Fable 5 support (#3524)

Integrated into release/v3.8.20

* feat(resilience): add global provider cooldown tracking to prevent combo re-walking (#3556)

Integrated into release/v3.8.20 (default OFF, opt-in)

* fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (#3560)

Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com>

* fix(routing): normalize thinking:disabled for combo-substituted models that reject it (#3554) (#3563)

Integrated into release/v3.8.20

* fix(usage): accept 0/empty budget limits so the dashboard can save and clear (#3537) (#3564)

Integrated into release/v3.8.20

* docs(changelog): credit @Six7Day for #3560 thoughtSignature fix (#3414)

The #3560 squash co-author trailer landed inline (unparsed by GitHub), so add
an explicit CHANGELOG credit ensuring @Six7Day (original #3414) and @oyi77 are
on the public record for the Gemini thoughtSignature fix.

* fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (#3472) (#3565)

Integrated into release/v3.8.20

* fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (#3509) (#3566)

Integrated into release/v3.8.20

* fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (#3552) (#3567)

Integrated into release/v3.8.20

* fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (#3558) (#3568)

Integrated into release/v3.8.20

* fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (#3516) (#3570)

Integrated into release/v3.8.20

* fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule #12) (#3494, #3495) (#3573)

Integrated into release/v3.8.20

* fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (#3486, #3487) (#3574)

Integrated into release/v3.8.20

* chore(providers): remove dead krutrim entry (#3483) + docs(api): fix agent-bridge per-agent state route (#3489) (#3575)

Integrated into release/v3.8.20

* docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (#3497) (#3577)

Integrated into release/v3.8.20

* fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (#3508) (#3579)

Integrated into release/v3.8.20

* fix(playground): filter playground models by node prefix so custom-endpoint models appear (#3505) (#3581)

Integrated into release/v3.8.20

* fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (#3506) (#3582)

Integrated into release/v3.8.20

* docs(changelog): add the #3506 Kiro quota entry (missed in #3582 due to a stale-base CHANGELOG anchor) (#3583)

Integrated into release/v3.8.20

* fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (#3561)

Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver.

* fix: address PR #3518 review comments (lifecycle hooks, regex, indentation, route params) (#3562)

Integrated into release/v3.8.20. Addresses #3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule #18 regression test.

* docs(changelog): credit @ViFigueiredo (#3423) for PROJECT_ROOT + log #3561/#3562 (v3.8.20)

* fix: openai to gemini incorrectly translates historical tool calls into text (#3569)

Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule #18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (#3560) untouched.

* docs(changelog)+test: reconcile standard-Gemini native mode (#3569) — update round-2 rationale comment + log VPS validation

* docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section

* docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors

---------

Co-authored-by: Alexander Averyanov <alex@averyan.ru>
Co-authored-by: Hakan Kurşun <bykamaka@gmail.com>
Co-authored-by: Wilson <pedbookmed@gmail.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr>
Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Markus Hartung <mail@hartmark.se>
2026-06-10 13:49:08 -03:00

249 lines
8.4 KiB
TypeScript

import {
BaseExecutor,
mergeUpstreamExtraHeaders,
setUserAgentHeader,
type ExecuteInput,
type ProviderCredentials,
} from "./base.ts";
import { PROVIDERS } from "../config/constants.ts";
import {
getQoderDashscopeCompatHeaders,
QODER_DEFAULT_USER_AGENT,
} from "../config/providerHeaderProfiles.ts";
import { sanitizeQwenThinkingToolChoice } from "../services/qwenThinking.ts";
import { buildCosyHeadersForValidation } from "../services/qoderCli.ts";
import { sanitizeErrorMessage } from "../utils/error.ts";
function getAuthToken(credentials: ProviderCredentials): string {
if (typeof credentials.apiKey === "string" && credentials.apiKey.trim()) {
return credentials.apiKey.trim();
}
if (typeof credentials.accessToken === "string" && credentials.accessToken.trim()) {
return credentials.accessToken.trim();
}
if (typeof credentials.refreshToken === "string" && credentials.refreshToken.trim()) {
return credentials.refreshToken.trim();
}
// Fallback: QODER_PERSONAL_ACCESS_TOKEN env var (#966)
const envToken = String(process.env.QODER_PERSONAL_ACCESS_TOKEN || "").trim();
if (envToken) return envToken;
return "";
}
export class QoderExecutor extends BaseExecutor {
constructor() {
super("qoder", PROVIDERS.qoder);
}
buildHeaders(
credentials: ProviderCredentials,
stream = true,
clientHeaders?: Record<string, string> | null,
model?: string
): Record<string, string> {
const headers = super.buildHeaders(credentials, stream, clientHeaders, model);
setUserAgentHeader(headers, QODER_DEFAULT_USER_AGENT);
return headers;
}
transformRequest(model: string, body: unknown): Record<string, unknown> {
const payload = {
...(typeof body === "object" && body !== null ? body : {}),
model,
};
return sanitizeQwenThinkingToolChoice(payload, "QoderExecutor");
}
async execute({ model, body, stream, credentials, signal, upstreamExtraHeaders }: ExecuteInput) {
const token = getAuthToken(credentials);
if (!token) {
return {
response: new Response(
JSON.stringify({
error: {
message: "Qoder access token or API Key is required. Please sign in or set a PAT.",
type: "authentication_error",
code: "token_required",
},
}),
{ status: 401, headers: { "Content-Type": "application/json" } }
),
url: "https://dashscope.aliyuncs.com",
headers: { "Content-Type": "application/json" },
transformedBody: body,
};
}
const resolvedModel = model || "qwen3-coder-plus";
// Detect token type: PAT (Personal Access Token) starts with "pt-"
const isPatToken = token.startsWith("pt-");
let mappedModel = resolvedModel;
let endpointUrl: string;
if (isPatToken) {
endpointUrl = "https://api.qoder.com/v1/chat/completions";
} else {
if (resolvedModel === "qwen3.5-plus" || resolvedModel === "qwen3.6-plus") {
mappedModel = "coder-model";
} else if (resolvedModel === "vision-model") {
mappedModel = "qwen3-vl-plus";
}
endpointUrl = "https://dashscope.aliyuncs.com/compatible-mode/v1/chat/completions";
}
// Check for custom API base via credentials (overrides the default)
let credentialsApiBase: unknown;
if (typeof credentials === "object" && credentials !== null) {
const credsObj = credentials as Record<string, unknown>;
credentialsApiBase = credsObj.customApiBase || credsObj.resourceUrl;
}
if (typeof credentialsApiBase === "string" && credentialsApiBase.trim()) {
let base = credentialsApiBase.trim();
if (!base.startsWith("http")) base = `https://${base}`;
if (!base.endsWith("/v1")) base = base.endsWith("/") ? `${base}v1` : `${base}/v1`;
endpointUrl = `${base}/chat/completions`;
}
const headers: Record<string, string> = {
"Content-Type": "application/json",
Authorization: `Bearer ${token}`,
...(isPatToken ? {} : getQoderDashscopeCompatHeaders()),
};
mergeUpstreamExtraHeaders(headers, upstreamExtraHeaders);
const payload = this.transformRequest(mappedModel, body, stream, credentials);
const bodyStr = JSON.stringify(payload);
try {
let response = await fetch(endpointUrl, {
method: "POST",
headers,
body: bodyStr,
signal,
});
// PAT tokens (pt-*) are not accepted as Bearer tokens by api.qoder.com/v1/chat/completions.
// They return 401 TOKEN_INVALID. Fallback to Cosy auth against api1.qoder.sh.
if (!response.ok && response.status === 401 && isPatToken) {
const cosyHeaders = buildCosyHeadersForValidation(bodyStr, token);
const cosyEndpoint =
"https://api1.qoder.sh/algo/api/v2/service/pro/sse/agent_chat_generation?AgentId=agent_common";
const cosyRes = await fetch(cosyEndpoint, {
method: "POST",
headers: cosyHeaders,
body: bodyStr,
signal,
});
if (cosyRes.ok || cosyRes.status === 200) {
// Cosy SSE response - read full body and parse
const rawText = await cosyRes.text();
const lines = rawText.split("\n").filter((l) => l.startsWith("data: "));
let fullContent = "";
for (const line of lines) {
try {
const jsonData = JSON.parse(line.slice(6));
const { extractTextFromQoderEnvelope } = await import("../services/qoderCli.ts");
const chunkText = extractTextFromQoderEnvelope(jsonData);
if (chunkText) fullContent += chunkText;
} catch {
// skip unparseable chunks
}
}
const { buildQoderCompletionPayload } = await import("../services/qoderCli.ts");
const cosyPayload = buildQoderCompletionPayload({
model: mappedModel || resolvedModel,
text: fullContent,
});
return {
response: new Response(JSON.stringify(cosyPayload), {
status: 200,
headers: { "Content-Type": "application/json" },
}),
url: cosyEndpoint,
headers: cosyHeaders,
transformedBody: payload,
};
}
// Cosy also failed - return the original 401 error
let errText = await cosyRes.text();
return {
response: new Response(
JSON.stringify({
error: {
message:
`Qoder API (Cosy) failed with status ${cosyRes.status}: ${errText}. Your PAT token may not be valid for the chat API.` +
" Try using an OAuth token or a different auth method.",
type: "authentication_error",
code: "token_invalid",
},
}),
{ status: 401, headers: { "Content-Type": "application/json" } }
),
url: cosyEndpoint,
headers: cosyHeaders,
transformedBody: payload,
};
}
if (!response.ok) {
let errText = await response.text();
return {
response: new Response(
JSON.stringify({
error: {
message: `Qoder API failed with status ${response.status}: ${errText}`,
type: response.status === 401 ? "authentication_error" : "provider_error",
},
}),
{ status: response.status, headers: { "Content-Type": "application/json" } }
),
url: endpointUrl,
headers,
transformedBody: payload,
};
}
const newHeaders = new Headers(response.headers);
return {
response: new Response(response.body, {
status: response.status,
statusText: response.statusText,
headers: newHeaders,
}),
url: endpointUrl,
headers,
transformedBody: payload,
};
} catch (e: unknown) {
const error = e as Error;
if (error.name === "AbortError") {
throw error;
}
return {
response: new Response(
JSON.stringify({
error: {
message: `Qoder fetch error: ${sanitizeErrorMessage(error.message)}`,
type: "provider_error",
},
}),
{ status: 502, headers: { "Content-Type": "application/json" } }
),
url: endpointUrl,
headers,
transformedBody: payload,
};
}
}
}
export default QoderExecutor;