mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-18 21:22:28 +03:00
* feat(api): add provider quota telemetry, adaptive routing, and status inventory Adds a read-only OmniRoute status/inventory surface plus supporting resilience and usage-tracking infrastructure: - src/lib/quota/providerQuotaTelemetry.ts, providerCapabilities.ts: provider quota state and capability signals, sourced from configured metadata rather than invented values; unknown stays unknown. - src/lib/resilience/adaptiveCircuit.ts, failureClassification.ts: circuit state with lazy recovery and explicit failure classification. - src/lib/usage/usageLedger.ts, budgetGuard.ts, modelPricingRegistry.ts: internal usage tracking and budget allow/warn/deny decisions, kept separate from upstream-reported quota (never conflated). - src/lib/routing/adaptiveRouting.ts: excludes exhausted-quota and open-circuit candidates from routing, penalizes approaching-limit. - src/lib/omnirouteStatus.ts + src/app/api/omniroute/status, route/preview: read-only status endpoint; never issues a live upstream model request (asserted via liveRequestExecuted: false). - src/lib/db/quotaPools.ts: adds ensurePool() for idempotent pool management by automation/CLI callers, following the existing group-demo default-group convention. - scripts/omniroute-verify.mjs (+ omniroute:verify script): local verification against the running gateway. 9 new unit tests, all passing. typecheck:core clean relative to base (release/v3.8.50) -- the 2 pre-existing gateways.ts errors are tracked separately in #9985 and untouched by this change. * test(cli): align cli-machine-token assertions with HMAC-SHA256 64-char format The quota-telemetry feature hardens cliToken to HMAC-SHA256(machineId, SALT) (64-char hex, pristine machine id). Update the regression test to the new format and mirror the production derivation in the different-machine-id check. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> --------- Co-authored-by: adevwithpurpose <adevwithpurpose@users.noreply.github.com> Co-authored-by: desamours-hub <desamours-hub@users.noreply.github.com> Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
40 lines
1.7 KiB
JavaScript
40 lines
1.7 KiB
JavaScript
import crypto from "node:crypto";
|
|
|
|
const BUILTIN_DEFAULT_SALT = "omniroute-cli-auth-v1";
|
|
export const CLI_TOKEN_HEADER = "x-omniroute-cli-token";
|
|
|
|
let _cached = null;
|
|
let _cachedSalt = null;
|
|
|
|
/** Mirrors getActiveSalt() in src/lib/machineToken.ts so a rotated
|
|
* OMNIROUTE_CLI_SALT reaches the CLI too (docs/security/CLI_TOKEN.md). */
|
|
function getActiveSalt() {
|
|
return process.env.OMNIROUTE_CLI_SALT || BUILTIN_DEFAULT_SALT;
|
|
}
|
|
|
|
export async function getCliToken() {
|
|
const salt = getActiveSalt();
|
|
if (_cached !== null && _cachedSalt === salt) return _cached;
|
|
try {
|
|
// node-machine-id is CommonJS: under `await import()` its exports land on
|
|
// `.default`, so destructuring `machineIdSync` off the namespace yields
|
|
// undefined and calling it throws — which the catch below turned into an
|
|
// empty token, silently disabling CLI auth for every management request.
|
|
// Same resolution order as src/lib/machineToken.ts.
|
|
const mod = await import("node-machine-id");
|
|
const machineIdSync = mod.machineIdSync ?? mod.default?.machineIdSync;
|
|
if (typeof machineIdSync !== "function") throw new Error("machine-id API unavailable");
|
|
// machineIdSync(true) returns the original unhashed hardware ID — mirrors
|
|
// getMachineTokenSync() in src/lib/machineToken.ts (#10148 cliToken hardening).
|
|
const mid = machineIdSync(true);
|
|
_cached = crypto.createHmac("sha256", mid).update(salt).digest("hex");
|
|
} catch (e) {
|
|
// Swallowing here changes control flow (every management call goes out
|
|
// unauthenticated and 401s), so leave a breadcrumb rather than failing mute.
|
|
console.debug("[CLI_TOKEN] machine-id resolution failed, CLI auth disabled:", e);
|
|
_cached = "";
|
|
}
|
|
_cachedSalt = salt;
|
|
return _cached;
|
|
}
|