Files
OmniRoute/open-sse/utils/proxyFallback.ts
Diego Rodrigues de Sa e Souza 7db430a352 Release v3.8.14 (#3340)
* chore(release): open v3.8.14 development cycle

Version bump 3.8.13 -> 3.8.14 (root + electron + open-sse + openapi + lockfiles).
Seed the v3.8.14 changelog with the four post-tag hotfixes that shipped to
Docker/Electron in v3.8.13 but missed the immutable npm 3.8.13 (#3336 SSRF /
CodeQL #323, #3334/#3335/#3339 Electron packaging). i18n CHANGELOG mirrors get
the in-progress placeholder section.

* feat: add per-provider custom headers support for OpenAI/Anthropic-compatible nodes (#3338)

Integrated into release/v3.8.14

* fix: Kiro Builder ID token import fails with Bad credentials (#3333)

Integrated into release/v3.8.14 — adds Builder ID cached-creds + OIDC refresh path for Kiro token import, with regression tests (#3333).

* Improve code quality: auto-pr/docstrings-1780792063 (#3337)

Integrated into release/v3.8.14 — docstring for context analytics route re-export.

* fix(catalog): remove minimaxai/minimax-m3 from NVIDIA NIM tier (404 upstream) (#3329) (#3341)

NVIDIA NIM does not host minimaxai/minimax-m3 — every request returns
404 page not found, while sibling minimaxai/minimax-m2.7 on the same provider
works. Advertising a model that 404s is a catalog bug; remove it from the nvidia
tier (it remains on the tiers that actually serve MiniMax M3). Re-add only once
NVIDIA serves it.

Co-authored-by: mikmaneggahommie <mikmaneggahommie@users.noreply.github.com>

* fix(cli): write OpenCode config to ~/.config on all platforms incl. Windows (#3330) (#3343)

resolveOpencodeConfigDir used %APPDATA% on Windows, but OpenCode reads its
config from XDG ~/.config/opencode/ on every platform (on Windows:
%USERPROFILE%\.config\opencode\, NOT %APPDATA%). So a Windows user who
configured OpenCode via the dashboard had the file written where OpenCode never
looks — it silently had no effect.

Use the XDG path (XDG_CONFIG_HOME || ~/.config) unconditionally. Update the UI
note + route JSDoc, and flip the three tests that encoded the old %APPDATA%
behavior (t40 per-platform + card-note, cli-runtime-extended getCliConfigPaths).

Co-authored-by: abdulkadirozyurt <abdulkadirozyurt@users.noreply.github.com>

* fix(proxy): make auto-selection fallback opt-in (#3332) (#3344)

selectWorkingProxyFallback (Step 11 of resolveProxyForConnection) listed ALL
registry proxies, ignoring assignments and per-connection proxy_enabled, and
returned the first working one with level:'autoSelect'. So a single proxy added
to the registry silently became a global fallback for every connection's traffic.

Gate it behind a new PROXY_AUTO_SELECT_ENABLED feature flag (default off): the
fallback now no-ops unless the operator opts in. No registry proxy becomes a
silent global default anymore.

Co-authored-by: hertznsk <hertznsk@users.noreply.github.com>

* fix(sse): treat MiniMax M3 as multimodal so vision isn't stripped (#3328) (#3342)

MiniMax M3 via the opencode provider (oc/minimax-m3-free) appeared blind:
image inputs didn't reach the model, while the same model in Cline could
see them. Verified empirically that MiniMax M3 on the opencode upstream IS
multimodal -- a base64 image is described correctly (it returns 403 only
for remote image URLs, which it doesn't accept).

Root cause: OmniRoute treated MiniMax M3 as a non-vision model in two
places, so when compression was active the image was replaced with a text
placeholder before dispatch:
- compression's modelSupportsVision() heuristic (lite.ts) only matched
  gpt-4/4o/claude-3/gemini/vision -- minimax was absent -> replaceImageUrls
  stripped the image.
- the opencode minimax-m3-free catalog entry lacked supportsVision, so the
  combo vision-capability gate could also exclude/mishandle it.

Add 'minimax-m3' to the vision heuristic and supportsVision: true to the
opencode minimax-m3-free entry. TDD: a failing-then-passing test in
compression/lite.test.ts proves replaceImageUrls now keeps images for
minimax-m3 ids, plus a registry assertion mirroring the #2822 qwen test.

Reported-by: @mikmaneggahommie

* docs(i18n): translate 25 core documentation files to Indonesian (#3348)

Integrated into release/v3.8.14 — Indonesian i18n docs.

* fix(review): resolve /review-reviews battery findings (LEDGER-1..11) on v3.8.14 (#3350)

Integrated into release/v3.8.14 — /review-reviews battery hardening (LEDGER-1..11) for #3338 custom-headers + #3333 kiro, plus cycle-test drift fixes (#3329/#3330/#3332).

* fix(provider-proxy): honor per-account proxy toggles (#3349)

Integrated into release/v3.8.14 — honor per-account proxy toggles + auto-fallback opt-in via PROXY_AUTO_SELECT_ENABLED.

* fix(dashboard): remove duplicate Distribute Proxies button on provider page (#3352)

* fix(providers): reduce proxy label noise (#3346)

Integrated into release/v3.8.14 — reduce proxy label noise + a11y (aria-label/sr-only).

* fix(duckduckgo): restore bare Response contract and rebase onto release/v3.8.14 (#3323)

Integrated into release/v3.8.14 — browser-backed cookie providers (duckduckgo/claude-web) with restored executor contract + unit tests.

* fix(noauth): expose only usable model aliases (#3345)

Integrated into release/v3.8.14 — noauth usable-alias filtering + registry alias plumbing (veo-free).

* fix(dashboard): stop infinite config-load loop on Hermes Agent detail page (#3353)

* fix(electron): tree-kill the server on exit/update to release the omniroute.exe lock (#3347) (#3354)

* chore(release): finalize v3.8.14 changelog + clear release-gate drift

- CHANGELOG: finalize the v3.8.14 section (date, full New Features/Bug Fixes/
  Maintenance coverage of all 16 cycle commits, Contributors hall of 12).
- docs: document OMNIROUTE_BROWSER_POOL + WEB_COOKIE_USE_BROWSER (#3323) in
  .env.example + ENVIRONMENT.md; regenerate the id/llm.txt strict mirror (#3348
  had translated it; llm.txt mirrors must match root).
- test(proxy-fetch): #3323 made tlsClient.available a computed getter — stub it
  via Object.defineProperty instead of assignment (5 tests were red on the base).

* fix(translator): coerce Gemini functionDeclaration parameters to an OBJECT schema (#3357) (#3360)

* fix(gemini): resolve truncation/suppression of false positive textual tool call markers in backticks (#3358)

Integrated into release/v3.8.14 — Gemini/Antigravity textual tool-call marker normalization (no false-positive suppression + split-chunk buffering).

* docs(changelog): add #3358 Gemini textual tool-call normalization to v3.8.14

* fix(dashboard): surface real analytics error instead of generic placeholder (#3356) (#3361)

The Analytics page discarded the server's error body on a non-OK response and
rendered a generic "An error occurred", so users (and maintainers) could not see
why /api/usage/analytics 500'd after an upgrade. Now the route returns the real
reason via buildErrorBody (sanitized, Hard Rule #12) and the page surfaces it via
a new readFetchErrorMessage helper that handles both the OpenAI-style and legacy
error shapes.

Reported-by: @superti4r

---------

Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com>
Co-authored-by: Someres <168349709+quanturbo@users.noreply.github.com>
Co-authored-by: Dong Mengzhe <154944819+Lang-Qiu@users.noreply.github.com>
Co-authored-by: mikmaneggahommie <mikmaneggahommie@users.noreply.github.com>
Co-authored-by: abdulkadirozyurt <abdulkadirozyurt@users.noreply.github.com>
Co-authored-by: hertznsk <hertznsk@users.noreply.github.com>
Co-authored-by: Krisna Santosa <54174372+KrisnaSantosa15@users.noreply.github.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Wilson <pedbookmed@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Ardem2025 <ardemb22@gmail.com>
2026-06-07 07:20:02 -03:00

386 lines
12 KiB
TypeScript

/**
* proxyFallback.ts — Smart Proxy Fallback for Provider Validation
*
* When a direct fetch to a provider fails and no explicit proxy was configured,
* this module automatically gathers proxy candidates from all available sources,
* tests them in parallel against the provider URL, and returns the first working one.
* Results are cached per hostname to avoid repeated probing.
*/
import { fetch as undiciFetch } from "undici";
import { createProxyDispatcher, normalizeProxyUrl } from "./proxyDispatcher.ts";
import { resolveProxyForScopeFromRegistry, listProxies, listOneproxyProxies } from "@/lib/localDb";
import { isFeatureFlagEnabled } from "@/shared/utils/featureFlags";
// ---------------------------------------------------------------------------
// Types
// ---------------------------------------------------------------------------
interface CacheEntry {
proxyUrl: string;
expiresAt: number;
}
interface ProxyShape {
type: string;
host: string;
port: number;
username?: string;
password?: string;
}
// ---------------------------------------------------------------------------
// Cache
// ---------------------------------------------------------------------------
const PROXY_FALLBACK_CACHE = new Map<string, CacheEntry>();
const CACHE_TTL_MS = 5 * 60 * 1000; // 5 minutes
/**
* Clear the in-memory proxy fallback cache.
* Useful for testing or admin operations.
*/
export function clearProxyFallbackCache(): void {
PROXY_FALLBACK_CACHE.clear();
}
// ---------------------------------------------------------------------------
// Helpers
// ---------------------------------------------------------------------------
/**
* Build a full proxy URL string from a proxy record's fields.
*/
function proxyRecordToUrl(proxy: ProxyShape): string {
const auth =
proxy.username
? `${encodeURIComponent(proxy.username)}:${encodeURIComponent(proxy.password || "")}@`
: "";
return `${proxy.type}://${auth}${proxy.host}:${proxy.port}`;
}
/**
* Resolve the environment proxy URL (HTTP_PROXY / HTTPS_PROXY / ALL_PROXY)
* for the given target URL. Returns null if no env proxy is configured or
* the target matches NO_PROXY.
*/
function resolveEnvProxyUrl(targetUrl: string): string | null {
// Honour NO_PROXY
const noProxy = process.env.NO_PROXY || process.env.no_proxy;
if (noProxy) {
let hostname: string | undefined;
try {
hostname = new URL(targetUrl).hostname.toLowerCase();
} catch {
return null;
}
const patterns = noProxy
.split(",")
.map((p) => p.trim().toLowerCase())
.filter(Boolean);
const match = patterns.some((pattern) => {
if (pattern === "*") return true;
if (pattern.includes("*")) {
const re = new RegExp(
"^" +
pattern
.split("*")
.map((s) => s.replace(/[.*+?^${}()|[\]\\]/g, "\\$&"))
.join(".*") +
"$"
);
return re.test(hostname!);
}
return hostname === pattern || hostname!.endsWith(`.${pattern}`);
});
if (match) return null;
}
let protocol: string;
try {
protocol = new URL(targetUrl).protocol;
} catch {
return null;
}
const proxyUrl =
protocol === "https:"
? process.env.HTTPS_PROXY ||
process.env.https_proxy ||
process.env.ALL_PROXY ||
process.env.all_proxy
: process.env.HTTP_PROXY ||
process.env.http_proxy ||
process.env.ALL_PROXY ||
process.env.all_proxy;
if (!proxyUrl) return null;
try {
return normalizeProxyUrl(proxyUrl, "environment proxy");
} catch {
return null;
}
}
// ---------------------------------------------------------------------------
// Candidate collection
// ---------------------------------------------------------------------------
/**
* Collect all available proxy candidates from every source:
* 1. Global proxy from registry
* 2. All user-configured proxies from the proxy registry
* 3. Top 5 1proxy marketplace proxies
* 4. Environment proxy (HTTP_PROXY / HTTPS_PROXY / ALL_PROXY)
*
* @param targetUrl Optional. When provided, the env proxy is resolved for this URL.
* @returns Deduplicated array of normalized proxy URLs.
*/
export async function getProxyCandidates(targetUrl?: string): Promise<string[]> {
const candidates = new Set<string>();
// 1. Global proxy from registry
try {
const globalProxy = await resolveProxyForScopeFromRegistry("global");
if (globalProxy?.proxy) {
candidates.add(proxyRecordToUrl(globalProxy.proxy as ProxyShape));
}
} catch {
// Table may not exist yet
}
// 2. All user-configured proxies (include secrets for auth)
try {
const allProxies = await listProxies({ includeSecrets: true });
for (const p of allProxies) {
if (p.host && p.port) {
candidates.add(proxyRecordToUrl(p as unknown as ProxyShape));
}
}
} catch {
// Table may not exist yet
}
// 3. Top 5 1proxy marketplace proxies
try {
const oneproxyProxies = await listOneproxyProxies({ limit: 5 });
for (const p of oneproxyProxies) {
if (p.host && p.port) {
candidates.add(proxyRecordToUrl(p as unknown as ProxyShape));
}
}
} catch {
// Table may not exist yet
}
// 4. Environment proxy (needs targetUrl to determine protocol)
if (targetUrl) {
try {
const envProxy = resolveEnvProxyUrl(targetUrl);
if (envProxy) candidates.add(envProxy);
} catch {
// Ignore env proxy errors
}
}
return Array.from(candidates);
}
// ---------------------------------------------------------------------------
// Proxy testing
// ---------------------------------------------------------------------------
/**
* Test a single proxy against a target URL.
* Makes a lightweight HEAD request through the proxy with a short timeout.
*
* @param proxyUrl The proxy URL (e.g. "http://1.2.3.4:8080")
* @param targetUrl The provider URL to test reachability to
* @param timeoutMs Timeout in milliseconds (default 3000)
* @returns Object with success status and latency in ms
*/
export async function testSingleProxy(
proxyUrl: string,
targetUrl: string,
timeoutMs = 3000
): Promise<{ ok: boolean; latencyMs: number | null }> {
const start = Date.now();
try {
const controller = new AbortController();
const timeout = setTimeout(() => controller.abort(), timeoutMs);
const dispatcher = createProxyDispatcher(proxyUrl);
await undiciFetch(targetUrl, {
method: "HEAD",
signal: controller.signal,
dispatcher,
headers: {
"User-Agent": "OmniRoute/1.0",
},
});
clearTimeout(timeout);
const latencyMs = Date.now() - start;
// Any response (including 4xx) means the proxy can reach the target
return { ok: true, latencyMs };
} catch {
return { ok: false, latencyMs: null };
}
}
/**
* Bulk test multiple proxies against a target URL.
* Does NOT cache results (for manual API use).
*
* @param targetUrl The provider URL to test reachability to
* @param proxyUrls Array of proxy URLs to test
* @returns Array of results, one per proxy
*/
export async function testProxiesAgainstTarget(
targetUrl: string,
proxyUrls: string[]
): Promise<Array<{ proxyUrl: string; ok: boolean; latencyMs: number | null }>> {
if (proxyUrls.length === 0) return [];
const results = await Promise.allSettled(
proxyUrls.map(async (proxyUrl) => {
const result = await testSingleProxy(proxyUrl, targetUrl);
return { proxyUrl, ...result };
})
);
return results.map((r) =>
r.status === "fulfilled"
? r.value
: { proxyUrl: "unknown", ok: false, latencyMs: null }
);
}
// ---------------------------------------------------------------------------
// Find working proxy (with caching)
// ---------------------------------------------------------------------------
/**
* Find a working proxy for the given target hostname and URL.
*
* Collects all proxy candidates, tests them in parallel against the provider
* URL, and returns the first one that responds. Results are cached per
* hostname for 5 minutes to avoid repeated probing.
*
* @param targetHostname The provider hostname (used as cache key)
* @param targetUrl The full provider URL to test against
* @returns A working proxy URL, or null if none found
*/
export async function findWorkingProxy(
targetHostname: string,
targetUrl: string
): Promise<string | null> {
if (!targetHostname) return null;
// Check cache first
const cached = PROXY_FALLBACK_CACHE.get(targetHostname);
if (cached) {
if (cached.expiresAt > Date.now()) {
// Cached hit — return the proxy (or null if previously all failed)
return cached.proxyUrl || null;
}
// Expired entry — remove it and re-probe
PROXY_FALLBACK_CACHE.delete(targetHostname);
}
// Collect candidates
const candidates = await getProxyCandidates(targetUrl);
if (candidates.length === 0) {
return null;
}
// Test all in parallel, return first that works
const results = await Promise.allSettled(
candidates.map(async (proxyUrl) => {
const { ok } = await testSingleProxy(proxyUrl, targetUrl);
return { proxyUrl, ok };
})
);
const working = results.find(
(r) => r.status === "fulfilled" && r.value.ok
);
if (working && working.status === "fulfilled") {
const proxyUrl = working.value.proxyUrl;
// Cache the working proxy
PROXY_FALLBACK_CACHE.set(targetHostname, {
proxyUrl,
expiresAt: Date.now() + CACHE_TTL_MS,
});
return proxyUrl;
}
// All failed — cache the negative result to avoid re-probing too often
PROXY_FALLBACK_CACHE.set(targetHostname, {
proxyUrl: "",
expiresAt: Date.now() + CACHE_TTL_MS,
});
return null;
}
// ---------------------------------------------------------------------------
// Auto-selection fallback (used by resolveProxyForConnection as step 11)
// ---------------------------------------------------------------------------
/**
* Try to auto-select a working proxy as a last-resort fallback when no
* explicit proxy was configured. This wraps getProxyCandidates() and
* findWorkingProxy() into a single call that returns a result compatible
* with resolveProxyForConnection()'s return type.
*
* @param _connectionId Optional connection ID (reserved for future use).
* @returns A proxy resolution result with level "autoSelect", or null.
*/
export async function selectWorkingProxyFallback(
_connectionId?: string
): Promise<{
proxy: { type: string; host: string; port: number; username: string; password: string } | null;
level: string;
levelId: string | null;
source: string;
} | null> {
// #3332: auto-selection is opt-in. Without this gate, any single proxy in the
// registry silently becomes a global fallback for ALL connections (ignoring
// assignments / per-connection proxy_enabled). Default OFF — only run when the
// operator explicitly enables PROXY_AUTO_SELECT_ENABLED.
if (!isFeatureFlagEnabled("PROXY_AUTO_SELECT_ENABLED")) return null;
const candidates = await getProxyCandidates();
if (candidates.length === 0) return null;
// Use a well-known AI API endpoint as the test target. If a proxy can
// reach this, it is likely suitable for routing AI traffic.
const targetUrl = "https://api.openai.com/v1/models";
const targetHostname = "api.openai.com";
const workingUrl = await findWorkingProxy(targetHostname, targetUrl);
if (!workingUrl) return null;
try {
const url = new URL(workingUrl);
return {
proxy: {
type: url.protocol.replace(":", "") || "http",
host: url.hostname,
port: parseInt(url.port, 10) || (url.protocol === "https:" ? 443 : 80),
username: url.username ? decodeURIComponent(url.username) : "",
password: url.password ? decodeURIComponent(url.password) : "",
},
level: "autoSelect",
levelId: null,
source: "automatic",
};
} catch {
return null;
}
}