mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-02 13:22:11 +03:00
* chore(release): open v3.8.34 development cycle * chore(quality): release-green pre-flight validator + nightly signal (C+D) (#4622) C — scripts/quality/validate-release-green.mjs (npm run check:release-green): reproduces the release-equivalent validation (typecheck, eslint, db-rules, public-creds, full unit, vitest, ratchets, optional --with-build package-artifact) against the current working tree and classifies each red as HARD (real defect, exit 1) vs DRIFT (ratchet — reported, never affects exit / never blocks). Pure helpers exported + orchestration behind a direct-run guard; unit-tested. D — .github/workflows/nightly-release-green.yml: runs C on the active release branch nightly (and on workflow_dispatch) and opens/updates a single tracking issue on HARD failures. Never a required check, never touches a contributor PR. Closes the gap where the full gate (ci.yml) only ran on the release PR, so reds accrued silently on release/** and surfaced in 40-min layers at release time. Non-blocking by construction; drift is the maintainer's to rebaseline at release. Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br> * fix(providers): show revealed connection API keys (#4583) Integrated into release/v3.8.34 * fix(resilience): respect upstream retry hint toggle (#4585) Integrated into release/v3.8.34 * feat(settings): expose stream recovery feature flags (#4586) Integrated into release/v3.8.34 * fix(logs): make active request stale sweep configurable (#4599) Integrated into release/v3.8.34 * fix(plugin): auto-prefix providerId with 'opencode-' for OC 1.17.8+ native gate (#4527) Integrated into release/v3.8.34 (supersedes #4445) * fix(models): treat unknown output caps as unset (#4584) Integrated into release/v3.8.34 * fix(executors): strip temperature for GitHub Copilot gpt-5.4 family (#4564) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(oauth): update Qwen OAuth URLs from chat.qwen.ai to qwen.ai (#4561) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(api/settings): prevent cached /api/settings responses (port from 9router#951) (#4566) Integrated into release/v3.8.34 (rebuilt onto tip) * feat(audio): MiniMax T2A v2 TTS dispatch in audioSpeech (port #1043) (#4553) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(dashboard): surface manual config CTA when Open Claw CLI auto-detect fails (#4562) Integrated into release/v3.8.34 (rebuilt onto tip) * feat(providers): optional model ID for custom API-key validation (#4555) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(cli): align data dir and env loading with runtime (#4607) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(quota): expose Bailian quota windows (#4610) Integrated into release/v3.8.34 (rebuilt onto tip) * fix: retain provider cooldowns for configured max window (#4588) Integrated into release/v3.8.34 (rebuilt — bundled commits stripped) * fix: reject invalid provider cooldown bounds (#4589) Integrated into release/v3.8.34 (rebuilt — bundled commits stripped) * fix: preserve production combo metrics on shadow eviction (#4590) Integrated into release/v3.8.34 (rebuilt — bundled commits stripped) * fix(stream): estimate input tokens when upstream reports prompt_tokens=0 (#4615) Integrated into release/v3.8.34 (rebuilt onto tip) * fix(catalog): shorten no-thinking gateway prefix to no-think/ (#4525) Integrated into release/v3.8.34 (rebuilt — kept only the prefix rename, dropped stale-base reverts) * fix(relay): apply IP rate limit to bifrost sidecar (#4593) Integrated into release/v3.8.34 (rebuilt onto tip; merge before #4612) * fix(bifrost): finalize SSE relay usage after stream (#4612) Integrated into release/v3.8.34 (rebuilt + reconciled with #4593) * feat(compression): per-request `x-omniroute-compression` header (Phase 3) (#4645) * docs(compression): Phase 3 per-request header design spec Approved brainstorming output for the x-omniroute-compression header: header-first precedence, name-first combo matching (Decision A), explicit value bypasses auto-trigger (Decision B), DerivedPlan.source, and the X-OmniRoute-Compression response header. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * docs(compression): Phase 3 per-request header implementation plan 4-task TDD plan (resolver header-first + source, parser, chatCore wiring + response header, docs/file-size) with full code and exact commands. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(compression): header-first resolver + plan source (Phase 3 core) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(compression): resolveCompressionHeader parser (Phase 3) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(compression): wire x-omniroute-compression header + response header (Phase 3) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * refactor(compression): extract plan-resolution leaf (planResolution.ts) under size cap (Phase 3) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * docs(compression): document x-omniroute-compression header (Phase 3) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(compression): harden named-combo map + trim engine: header id (Phase 3 review) Addresses gemini-code-assist review on #4645: - Extract buildNamedComboLookup (pure) so a blank/whitespace/null combo name contributes only its id key (no '' key, no throw that disables all combos). - Trim the engine:<id> header value so 'engine: rtk' resolves. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> * fix: exclude exhausted connections from auto scoring (#4592) Integrated into release/v3.8.34 (rebuilt + opt-in gate fix) * fix(dashboard): memoize compatible provider groups (#4613) Integrated into release/v3.8.34 (rebuilt + test added) * fix(dashboard): isolate quota widget refresh clock (#4611) Integrated into release/v3.8.34 (rebuilt + jsdom test) * fix(dashboard): gate topology side effects behind widget visibility (#4606) Integrated into release/v3.8.34 (rebuilt + jsdom test) * fix(dashboard): keep play_arrow spinning on provider Test All buttons (#4563) Integrated into release/v3.8.34 (rebuilt onto tip; UI-cosmetic per owner) * fix(db): schedule retention cleanup + fix cleanup table/column names (extracted from #4428) (#4691) Integrated into release/v3.8.34 (cleanup core extracted from #4428, credit @oyi77) * fix(telemetry): back off live-WS event forwarding when the sidecar is unreachable (#4604) (#4687) Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> * fix(api): serve GET /v1/models/{model} as JSON, not the HTML dashboard (#4674) (#4677) Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> * feat(opencode): add go deepseek reasoning variants (#4647) Integrated into release/v3.8.34 * fix(executors): robust deepseek-web tool-call parsing and agentic context retention (#4644) Integrated into release/v3.8.34 * fix(cli): authenticate `omniroute logs` and honor active context (#4638) Integrated into release/v3.8.34 (authored by Rahul Sharma, AI co-author trailer stripped per project policy) * fix(proxy): apply pipelining:0 + connections cap to the direct dispatcher (#4580) (#4684) Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> * fix(executors): Firecrawl web_fetch 500 with include_metadata=true (#4692) Integrated into release/v3.8.34 * fix(routing): include all noAuth models in auto-combos + add reka-flash + best-free template (#4621) Integrated into release/v3.8.34 (dead getFirstRegistryModelId dropped, rebuilt onto tip) * fix(dashboard): gate home topology live-WS networking (#4596) (#4618) Integrated into release/v3.8.34 (adapted onto #4606's extracted topology section: default-hidden flip + enabled gate on useLiveDashboard) * fix(cli): align `omniroute` env loading with the runtime data dir (#4597) (#4619) Integrated into release/v3.8.34 (data-dir.mjs refactor reconciled with #4607; loadEnvFile aligned to getDefaultDataDir) * chore(quality): reconcile file-size baseline for #4644 (deepseek-web.ts 1117->1125) (#4695) file-size reconcile for #4644 * Support quota scraping for OpenCode Go and Ollama Cloud (#4642) Integrated into release/v3.8.34 (Ollama Cloud + OpenCode Go dashboard quota scraping; rebuilt onto tip, gates green: typecheck/public-creds/file-size/lint/docs-sync + 31 tests) * feat(executors): land M365 Copilot pure framing + connection helpers (#4042) (#4696) Land M365 pure modules ahead of draft #4400 * deps: bump production + development groups; migrate js-yaml to v5 ESM (#4697) Incorporates Dependabot #4667 + #4668 + js-yaml v5 ESM migration into release/v3.8.34 * fix: noAuth provider validation + kimi executor routing (#4699) Integrated into release/v3.8.34 (noAuth in NOAUTH_PROVIDERS dynamic check + remove misrouted kimi web alias; 9 tests) * refactor(imageGeneration): extract 8 provider families to co-located files (#4609) Integrated into release/v3.8.34 (extraction completed: added missing imports/exports per module, main imports handlers locally; 145 image-gen tests pass, typecheck/cycles/file-size green) * chore(release): v3.8.34 — finalize changelog, rebaseline drift, fix release-green reds - Finalize CHANGELOG [3.8.34] (43 bullets, full contributor attribution) + seed i18n mirrors - Rebaseline inherited cycle drift surfaced by release-green pre-flight: eslint warnings 3900->3907, cognitive-complexity 797->801 (release-finalize touches no prod code; all drift is from this cycle's contributor merges) - fix(providers): keep reka-flash-3 as the Reka provider default. #4621 inserted reka-flash at the head of the model list, silently changing the default from reka-flash-3 (the free-tier model) to reka-flash; reorder so reka-flash-3 stays default, reka-flash retained. - test: align provider-models-config / provider-models-route / web-cookie-providers-new with #4621 (reka-flash now in the Reka catalog) and #4699 (the `kimi` API-key provider correctly falls through to DefaultExecutor instead of KimiWebExecutor) - chore(quality): allowlist the COMPRESSION_GUIDE doc name in check-fabricated-docs (false-positive env-var match; docs/compression/COMPRESSION_GUIDE.md exists) * fix(release-green): resolve release-PR full-CI reds for v3.8.34 Surfaced only on the release PR (these gates don't run on PR->release fast-gates): - fix(quota): complete HTML-comment sanitization in opencodeOllamaUsage SSR reset-time parsing — strip any <!--...--> generically instead of the two literal React hydration markers, so no partial "<!--" can survive (CodeQL js/incomplete-multi-character- sanitization, HIGH, introduced by #4642). Regression test added. - test(codex): correct the Codex-fingerprint body key order assertion to match the canonical bodyFieldOrder (prompt_cache_key precedes include); #4584 flipped the two and integration tests don't run on fast-gates so it never executed until the release PR. - chore(quality): rebaseline inherited cycle drift surfaced by full CI — zizmorFindings 152->155 (+3 unpinned-uses in nightly-release-green.yml from #4622, same @vN convention as ci.yml) and openapiCoverage.pct 38.4->37.8 (-0.6, contributor routes added faster than openapi docs). Release-finalize touches no prod routes. * fix(release-green): complete CodeQL sanitization + rebaseline complexity drift - fix(quota): handle unterminated HTML comments in opencodeOllamaUsage SSR reset-time parsing — the `(?:-->|$)` arm consumes a trailing "<!--" with no closing "-->", so no partial "<!--" can survive (CodeQL js/incomplete-multi-character-sanitization persisted with the plain <!--...--> form because an unclosed comment could still leave "<!--"). - chore(quality): rebaseline cyclomatic complexity 1915->1916 (+1) — inherited v3.8.34 cycle drift (contributor feature branches); check:complexity does not run on PR->release fast-gates so it surfaced only on the release PR. Release-finalize adds 0 complexity (measured 1916 with/without the regex tweak). dead-code/cognitive/type-coverage/ compression-budget/codeql ratchets all pass. --------- Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com> Co-authored-by: KooshaPari <42529354+KooshaPari@users.noreply.github.com> Co-authored-by: Abhishek Divekar <adivekar@utexas.edu> Co-authored-by: Rahul sharma <sharmaR0810@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com> Co-authored-by: Ronald Estacion <DevEstacion@users.noreply.github.com> Co-authored-by: Igor <60442260+BugsBag@users.noreply.github.com> Co-authored-by: Oonishi <275808243+ponkcore@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Jan Leon <Jan.gaschler@gmail.com>
322 lines
12 KiB
TypeScript
322 lines
12 KiB
TypeScript
import { BaseExecutor, ExecuteInput, type ProviderCredentials } from "./base.ts";
|
|
import { PROVIDERS, OAUTH_ENDPOINTS } from "../config/constants.ts";
|
|
import { getModelTargetFormat } from "../config/providerModels.ts";
|
|
import {
|
|
getGitHubCopilotChatHeaders,
|
|
getGitHubCopilotRefreshHeaders,
|
|
} from "../config/providerHeaderProfiles.ts";
|
|
import { sanitizeResponsesInputItems } from "../services/responsesInputSanitizer.ts";
|
|
|
|
export class GithubExecutor extends BaseExecutor {
|
|
constructor() {
|
|
super("github", PROVIDERS.github);
|
|
}
|
|
|
|
getCopilotToken(credentials: Record<string, any> | null | undefined) {
|
|
return credentials?.copilotToken || credentials?.providerSpecificData?.copilotToken || null;
|
|
}
|
|
|
|
getCopilotTokenExpiresAt(credentials: Record<string, any> | null | undefined) {
|
|
return (
|
|
credentials?.copilotTokenExpiresAt ||
|
|
credentials?.providerSpecificData?.copilotTokenExpiresAt ||
|
|
null
|
|
);
|
|
}
|
|
|
|
buildUrl(model: string, _stream: boolean, _urlIndex = 0) {
|
|
const targetFormat = getModelTargetFormat("gh", model);
|
|
if (targetFormat === "openai-responses") {
|
|
return (
|
|
this.config.responsesBaseUrl ||
|
|
this.config.baseUrl?.replace(/\/chat\/completions\/?$/, "/responses") ||
|
|
"https://api.githubcopilot.com/responses"
|
|
);
|
|
}
|
|
return this.config.baseUrl;
|
|
}
|
|
|
|
injectResponseFormat(messages: Array<Record<string, any>>, responseFormat: any) {
|
|
if (!responseFormat) return messages;
|
|
|
|
let formatInstruction = "";
|
|
if (responseFormat.type === "json_object") {
|
|
formatInstruction =
|
|
"Respond only with valid JSON. Do not include any text before or after the JSON object.";
|
|
} else if (responseFormat.type === "json_schema" && responseFormat.json_schema) {
|
|
formatInstruction = `Respond only with valid JSON matching this schema:\n${JSON.stringify(
|
|
responseFormat.json_schema.schema,
|
|
null,
|
|
2
|
|
)}\nDo not include any text before or after the JSON.`;
|
|
}
|
|
|
|
if (!formatInstruction) return messages;
|
|
|
|
const systemIdx = messages.findIndex((m) => m.role === "system");
|
|
if (systemIdx >= 0) {
|
|
return messages.map((m, i: number) =>
|
|
i === systemIdx ? { ...m, content: `${m.content}\n\n${formatInstruction}` } : m
|
|
);
|
|
}
|
|
|
|
return [{ role: "system", content: formatInstruction }, ...messages];
|
|
}
|
|
|
|
transformRequest(model: string, body: any, stream: boolean, credentials: any): any {
|
|
void stream;
|
|
void credentials;
|
|
|
|
const sourceBody = body && typeof body === "object" ? body : {};
|
|
const modifiedBody = { ...sourceBody };
|
|
|
|
if (Array.isArray(sourceBody.input)) {
|
|
modifiedBody.input = sanitizeResponsesInputItems(sourceBody.input, false);
|
|
}
|
|
|
|
if (Array.isArray(sourceBody.messages)) {
|
|
modifiedBody.messages = sourceBody.messages.map((msg) => {
|
|
if (!msg || typeof msg !== "object") return msg;
|
|
const role = typeof msg.role === "string" ? msg.role.toLowerCase() : "";
|
|
if (role !== "assistant") return msg;
|
|
if (msg.reasoning_text === undefined && msg.reasoning_content === undefined) return msg;
|
|
const next = { ...msg };
|
|
delete next.reasoning_text;
|
|
delete next.reasoning_content;
|
|
return next;
|
|
});
|
|
}
|
|
|
|
if (modifiedBody.response_format && model.toLowerCase().includes("claude")) {
|
|
modifiedBody.messages = this.injectResponseFormat(
|
|
Array.isArray(modifiedBody.messages) ? modifiedBody.messages : [],
|
|
modifiedBody.response_format
|
|
);
|
|
delete modifiedBody.response_format;
|
|
}
|
|
|
|
if (Array.isArray(modifiedBody.tools) && modifiedBody.tools.length > 128) {
|
|
modifiedBody.tools = modifiedBody.tools.slice(0, 128);
|
|
}
|
|
|
|
// GitHub Copilot's gpt-5.4 family rejects requests carrying `temperature` with HTTP 400:
|
|
// "Unsupported parameter: 'temperature' is not supported with this model."
|
|
// OmniRoute's existing `stripGpt5SamplingWhenReasoning` guard only fires for
|
|
// provider==="openai" (raw api.openai.com Chat Completions), so GitHub Copilot routes
|
|
// never hit it. Strip temperature here unconditionally for gpt-5.4 so the 400 cannot
|
|
// reach the user. Port from 9router#612 (closes upstream #536).
|
|
if (
|
|
typeof model === "string" &&
|
|
/gpt-5\.4/i.test(model) &&
|
|
modifiedBody.temperature !== undefined
|
|
) {
|
|
delete modifiedBody.temperature;
|
|
}
|
|
|
|
// GitHub Copilot /chat/completions only accepts {type:'text'} or {type:'image_url'}
|
|
// content parts. Clients like Cursor IDE pass through Anthropic-shape parts
|
|
// (tool_use, tool_result, thinking) untouched when using Claude models, which makes
|
|
// the endpoint return: "type has to be either 'image_url' or 'text'" (HTTP 400).
|
|
// Serialize unknown part types as text, drop empty parts, and collapse to null when
|
|
// every part is stripped (assistant messages whose only content was tool_calls).
|
|
// Port from 9router#220 (fixes 9router#219).
|
|
if (Array.isArray(modifiedBody.messages)) {
|
|
modifiedBody.messages = modifiedBody.messages.map((msg: any) =>
|
|
this.sanitizeChatCompletionsMessage(msg)
|
|
);
|
|
}
|
|
|
|
return modifiedBody;
|
|
}
|
|
|
|
private sanitizeChatCompletionsMessage(msg: any): any {
|
|
if (!msg || typeof msg !== "object") return msg;
|
|
// String content and missing content (e.g. assistant w/ only tool_calls) pass through.
|
|
if (typeof msg.content === "string" || msg.content == null) return msg;
|
|
if (!Array.isArray(msg.content)) return msg;
|
|
|
|
const cleanContent = msg.content
|
|
.map((part: any) => {
|
|
if (!part || typeof part !== "object") return part;
|
|
if (part.type === "text") return part;
|
|
if (part.type === "image_url") return part;
|
|
// Serialize any unsupported part (tool_use, tool_result, thinking, etc.) as text.
|
|
// Try common text-carrying fields first; fall back to a JSON dump so nothing is
|
|
// silently dropped from the model's context.
|
|
const raw =
|
|
(typeof part.text === "string" && part.text) ||
|
|
(typeof part.thinking === "string" && part.thinking) ||
|
|
(typeof part.content === "string" && part.content) ||
|
|
(part.content != null && JSON.stringify(part.content)) ||
|
|
JSON.stringify(part);
|
|
return { type: "text", text: typeof raw === "string" ? raw : JSON.stringify(raw) };
|
|
})
|
|
.filter((part: any) => !(part && part.type === "text" && part.text === ""));
|
|
|
|
// If every part stripped to empty (e.g. tool_use with no text), collapse to null so
|
|
// GitHub does not reject an empty-array body. tool_calls ride alongside content.
|
|
return { ...msg, content: cleanContent.length > 0 ? cleanContent : null };
|
|
}
|
|
|
|
async execute(input: ExecuteInput) {
|
|
const result = await super.execute(input);
|
|
if (!result || !result.response) return result;
|
|
|
|
if (!input.stream) {
|
|
// wreq-js clone/text semantics consume the original response body. Materialize
|
|
// non-streaming responses immediately so downstream code always sees a native
|
|
// fetch Response with a readable body.
|
|
const status = result.response.status;
|
|
const statusText = result.response.statusText;
|
|
const headers = new Headers(result.response.headers);
|
|
const payload = await result.response.text();
|
|
result.response = new Response(payload, { status, statusText, headers });
|
|
return result;
|
|
}
|
|
|
|
return result;
|
|
}
|
|
|
|
buildHeaders(
|
|
credentials: ProviderCredentials,
|
|
stream = true,
|
|
clientHeaders?: Record<string, string> | null
|
|
): Record<string, string> {
|
|
const token = this.getCopilotToken(credentials) || credentials.accessToken;
|
|
|
|
// Forward the client's x-initiator header when present. OpenCode and other
|
|
// Copilot-aware clients use this to distinguish user-initiated turns
|
|
// (x-initiator: user) from autonomous tool-call continuations
|
|
// (x-initiator: agent). GitHub Copilot's billing treats "agent" turns as
|
|
// free, so forwarding the value avoids burning a premium request on every
|
|
// tool-call round-trip. Fall back to "user" when the header is absent to
|
|
// preserve the existing default behaviour.
|
|
let clientInitiator = clientHeaders?.["x-initiator"] || clientHeaders?.["X-Initiator"];
|
|
if (!clientInitiator && clientHeaders) {
|
|
for (const key in clientHeaders) {
|
|
if (key.toLowerCase() === "x-initiator") {
|
|
clientInitiator = clientHeaders[key];
|
|
break;
|
|
}
|
|
}
|
|
}
|
|
const initiator =
|
|
clientInitiator === "agent" || clientInitiator === "user" ? clientInitiator : "user";
|
|
|
|
return {
|
|
...getGitHubCopilotChatHeaders(stream ? "text/event-stream" : "application/json", initiator),
|
|
Authorization: `Bearer ${token}`,
|
|
"x-request-id":
|
|
crypto.randomUUID?.() || `${Date.now()}-${Math.random().toString(36).slice(2)}`,
|
|
};
|
|
}
|
|
|
|
async refreshCopilotToken(githubAccessToken, log) {
|
|
try {
|
|
const response = await fetch("https://api.github.com/copilot_internal/v2/token", {
|
|
headers: getGitHubCopilotRefreshHeaders(`token ${githubAccessToken}`),
|
|
});
|
|
if (!response.ok) return null;
|
|
const data = await response.json();
|
|
log?.info?.("TOKEN", "Copilot token refreshed");
|
|
return { token: data.token, expiresAt: data.expires_at };
|
|
} catch (error) {
|
|
log?.error?.("TOKEN", `Copilot refresh error: ${error.message}`);
|
|
return null;
|
|
}
|
|
}
|
|
|
|
async refreshGitHubToken(refreshToken, log) {
|
|
try {
|
|
// GitHub Copilot is a public device-flow client: send the public client_id, and
|
|
// only attach client_secret when one is actually configured — never the literal
|
|
// "undefined" that new URLSearchParams produces for a missing value (9router#442).
|
|
const params = new URLSearchParams({
|
|
grant_type: "refresh_token",
|
|
refresh_token: refreshToken,
|
|
client_id: this.config.clientId,
|
|
});
|
|
if (this.config.clientSecret) {
|
|
params.set("client_secret", this.config.clientSecret);
|
|
}
|
|
const response = await fetch(OAUTH_ENDPOINTS.github.token, {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-Type": "application/x-www-form-urlencoded",
|
|
Accept: "application/json",
|
|
},
|
|
body: params,
|
|
});
|
|
if (!response.ok) return null;
|
|
const tokens = await response.json();
|
|
log?.info?.("TOKEN", "GitHub token refreshed");
|
|
return {
|
|
accessToken: tokens.access_token,
|
|
refreshToken: tokens.refresh_token || refreshToken,
|
|
expiresIn: tokens.expires_in,
|
|
};
|
|
} catch (error) {
|
|
log?.error?.("TOKEN", `GitHub refresh error: ${error.message}`);
|
|
return null;
|
|
}
|
|
}
|
|
|
|
async refreshCredentials(credentials, log) {
|
|
let copilotResult = await this.refreshCopilotToken(credentials.accessToken, log);
|
|
|
|
if (!copilotResult && credentials.refreshToken) {
|
|
const githubTokens = await this.refreshGitHubToken(credentials.refreshToken, log);
|
|
if (githubTokens?.accessToken) {
|
|
copilotResult = await this.refreshCopilotToken(githubTokens.accessToken, log);
|
|
if (copilotResult) {
|
|
return {
|
|
...githubTokens,
|
|
copilotToken: copilotResult.token,
|
|
copilotTokenExpiresAt: copilotResult.expiresAt,
|
|
providerSpecificData: {
|
|
copilotToken: copilotResult.token,
|
|
copilotTokenExpiresAt: copilotResult.expiresAt,
|
|
},
|
|
};
|
|
}
|
|
return githubTokens;
|
|
}
|
|
}
|
|
|
|
if (copilotResult) {
|
|
return {
|
|
accessToken: credentials.accessToken,
|
|
refreshToken: credentials.refreshToken,
|
|
copilotToken: copilotResult.token,
|
|
copilotTokenExpiresAt: copilotResult.expiresAt,
|
|
providerSpecificData: {
|
|
copilotToken: copilotResult.token,
|
|
copilotTokenExpiresAt: copilotResult.expiresAt,
|
|
},
|
|
};
|
|
}
|
|
|
|
return null;
|
|
}
|
|
|
|
needsRefresh(credentials) {
|
|
// Always refresh if no copilotToken
|
|
if (!this.getCopilotToken(credentials)) return true;
|
|
|
|
const copilotTokenExpiresAt = this.getCopilotTokenExpiresAt(credentials);
|
|
if (copilotTokenExpiresAt) {
|
|
// Handle both Unix timestamp (seconds) and ISO string
|
|
let expiresAtMs = copilotTokenExpiresAt;
|
|
if (typeof expiresAtMs === "number" && expiresAtMs < 1e12) {
|
|
expiresAtMs = expiresAtMs * 1000; // Convert seconds to ms
|
|
} else if (typeof expiresAtMs === "string") {
|
|
expiresAtMs = new Date(expiresAtMs).getTime();
|
|
}
|
|
if (expiresAtMs - Date.now() < 5 * 60 * 1000) return true;
|
|
}
|
|
return super.needsRefresh(credentials);
|
|
}
|
|
}
|
|
|
|
export default GithubExecutor;
|