Files
OmniRoute/src/shared/schemas/validation.ts
Diego Rodrigues de Sa e Souza bf8b56b29f Release v3.8.20 (#3547)
* chore(release): open v3.8.20 development cycle

* fix(images): prefer bare combos over image aliases (#3527)

Integrated into release/v3.8.20

* fix(translator): map Codex local_shell tool (#3534)

Integrated into release/v3.8.20

* fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (#3522)

Integrated into release/v3.8.20

* Fix Runtime page breaker state rendering (#3533)

Integrated into release/v3.8.20

* Expose provider breaker degradation threshold setting (#3535)

Integrated into release/v3.8.20

* fix(executor): strip provider prefix from versioned built-in tool model field (#3532)

Integrated into release/v3.8.20

* feat(providers): add Claude Fable 5 support (#3524)

Integrated into release/v3.8.20

* feat(resilience): add global provider cooldown tracking to prevent combo re-walking (#3556)

Integrated into release/v3.8.20 (default OFF, opt-in)

* fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (#3560)

Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com>

* fix(routing): normalize thinking:disabled for combo-substituted models that reject it (#3554) (#3563)

Integrated into release/v3.8.20

* fix(usage): accept 0/empty budget limits so the dashboard can save and clear (#3537) (#3564)

Integrated into release/v3.8.20

* docs(changelog): credit @Six7Day for #3560 thoughtSignature fix (#3414)

The #3560 squash co-author trailer landed inline (unparsed by GitHub), so add
an explicit CHANGELOG credit ensuring @Six7Day (original #3414) and @oyi77 are
on the public record for the Gemini thoughtSignature fix.

* fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (#3472) (#3565)

Integrated into release/v3.8.20

* fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (#3509) (#3566)

Integrated into release/v3.8.20

* fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (#3552) (#3567)

Integrated into release/v3.8.20

* fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (#3558) (#3568)

Integrated into release/v3.8.20

* fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (#3516) (#3570)

Integrated into release/v3.8.20

* fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule #12) (#3494, #3495) (#3573)

Integrated into release/v3.8.20

* fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (#3486, #3487) (#3574)

Integrated into release/v3.8.20

* chore(providers): remove dead krutrim entry (#3483) + docs(api): fix agent-bridge per-agent state route (#3489) (#3575)

Integrated into release/v3.8.20

* docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (#3497) (#3577)

Integrated into release/v3.8.20

* fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (#3508) (#3579)

Integrated into release/v3.8.20

* fix(playground): filter playground models by node prefix so custom-endpoint models appear (#3505) (#3581)

Integrated into release/v3.8.20

* fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (#3506) (#3582)

Integrated into release/v3.8.20

* docs(changelog): add the #3506 Kiro quota entry (missed in #3582 due to a stale-base CHANGELOG anchor) (#3583)

Integrated into release/v3.8.20

* fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (#3561)

Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver.

* fix: address PR #3518 review comments (lifecycle hooks, regex, indentation, route params) (#3562)

Integrated into release/v3.8.20. Addresses #3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule #18 regression test.

* docs(changelog): credit @ViFigueiredo (#3423) for PROJECT_ROOT + log #3561/#3562 (v3.8.20)

* fix: openai to gemini incorrectly translates historical tool calls into text (#3569)

Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule #18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (#3560) untouched.

* docs(changelog)+test: reconcile standard-Gemini native mode (#3569) — update round-2 rationale comment + log VPS validation

* docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section

* docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors

---------

Co-authored-by: Alexander Averyanov <alex@averyan.ru>
Co-authored-by: Hakan Kurşun <bykamaka@gmail.com>
Co-authored-by: Wilson <pedbookmed@gmail.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr>
Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Markus Hartung <mail@hartmark.se>
2026-06-10 13:49:08 -03:00

155 lines
5.9 KiB
TypeScript

/**
* Zod Validation Schemas — Shared request schemas for API routes
*
* Provides runtime input validation for provider, combo, and settings APIs.
*
* @module shared/schemas/validation
*/
import { z } from "zod";
import { ROUTING_STRATEGY_VALUES } from "@/shared/constants/routingStrategies";
// ─── Provider Connection ──────────────────────────────────────────
export const providerConnectionSchema = z.object({
provider: z.string().min(1, "Provider name is required"),
authType: z.enum(["oauth", "apikey", "free"]).optional(),
name: z.string().optional(),
email: z.string().email().optional().or(z.literal("")),
apiKey: z.string().optional(),
accessToken: z.string().optional(),
refreshToken: z.string().optional(),
isActive: z.boolean().default(true),
priority: z.number().int().min(0).default(0),
defaultModel: z.string().optional(),
globalPriority: z.number().int().min(0).optional().nullable(),
rateLimitProtection: z.boolean().default(false),
displayName: z.string().optional(),
});
// ─── Combo / Routing Rule ─────────────────────────────────────────
export const comboNodeSchema = z.object({
connectionId: z.string().uuid("Invalid connection ID"),
weight: z.number().int().min(0).max(100).default(1),
priority: z.number().int().min(0).default(0),
});
export const comboSchema = z.object({
name: z.string().min(1, "Combo name is required").max(100),
model: z.string().min(1, "Model pattern is required"),
endpoint: z.enum(["chat", "embeddings", "images"]).default("chat"),
strategy: z.enum(ROUTING_STRATEGY_VALUES).default("priority"),
nodes: z.array(comboNodeSchema).min(1, "At least one node is required"),
isActive: z.boolean().default(true),
maxRetries: z.number().int().min(0).max(10).default(2),
retryDelay: z.number().int().min(0).max(30000).default(1000),
});
// ─── API Key ──────────────────────────────────────────────────────
export const apiKeyCreateSchema = z.object({
label: z.string().min(1, "Label is required").max(64),
});
// ─── Settings ─────────────────────────────────────────────────────
export const settingsSchema = z
.object({
requireLogin: z.boolean().optional(),
password: z.string().min(6, "Password must be at least 6 characters").optional(),
defaultModel: z.string().optional(),
rateLimitEnabled: z.boolean().optional(),
rateLimitPerMinute: z.number().int().min(0).optional(),
})
.partial();
// ─── Proxy Settings ───────────────────────────────────────────────
export const proxySettingsSchema = z.object({
enabled: z.boolean(),
url: z.string().url("Invalid proxy URL").optional().or(z.literal("")),
username: z.string().optional(),
password: z.string().optional(),
bypassList: z.array(z.string()).optional(),
});
// ─── Resilience Profile ───────────────────────────────────────────
export const resilienceProfileSchema = z.object({
provider: z.string().min(1),
circuitBreaker: z
.object({
failureThreshold: z.number().int().min(1).max(1000).default(5),
degradationThreshold: z.number().int().min(1).max(1000).default(3),
resetTimeoutMs: z.number().int().min(1000).max(600000).default(30000),
halfOpenMax: z.number().int().min(1).max(10).default(1),
})
.superRefine((value, ctx) => {
if (value.failureThreshold > 1 && value.degradationThreshold >= value.failureThreshold) {
ctx.addIssue({
code: z.ZodIssueCode.custom,
message: "degradationThreshold must be lower than failureThreshold",
path: ["degradationThreshold"],
});
}
})
.optional(),
backoff: z
.object({
initialDelayMs: z.number().int().min(100).max(60000).default(1000),
maxDelayMs: z.number().int().min(1000).max(600000).default(60000),
multiplier: z.number().min(1).max(10).default(2),
})
.optional(),
rateLimit: z
.object({
requestsPerMinute: z.number().int().min(0).optional(),
tokensPerMinute: z.number().int().min(0).optional(),
})
.optional(),
});
// ─── Chat Completion Request (basic validation) ───────────────────
export const chatCompletionSchema = z.object({
model: z.string().min(1, "Model is required"),
messages: z
.array(
z.object({
role: z.enum(["system", "user", "assistant", "tool"]),
content: z.union([z.string(), z.array(z.any())]),
})
)
.min(1, "At least one message is required"),
stream: z.boolean().optional(),
temperature: z.number().min(0).max(2).optional(),
max_tokens: z.number().int().min(1).optional(),
top_p: z.number().min(0).max(1).optional(),
});
// ─── Helper ───────────────────────────────────────────────────────
/**
* Validate data against a schema and format errors for API responses.
*
* @template T
* @param {z.ZodSchema<T>} schema
* @param {unknown} data
* @returns {{ success: true, data: T } | { success: false, errors: Array<{ path: string, message: string }> }}
*/
export function validateSchema(schema, data) {
const result = schema.safeParse(data);
if (result.success) {
return { success: true, data: result.data };
}
return {
success: false,
errors: result.error.issues.map((issue) => ({
path: issue.path.join("."),
message: issue.message,
})),
};
}