mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-31 04:12:10 +03:00
Adds a new chatgpt-web provider that routes through chatgpt.com's internal backend-api using a Plus/Pro subscription session cookie, enabling access to GPT-5.x models without an OpenAI API key. Heavier than perplexity-web/grok-web because chatgpt.com layers more bot protection — this PR builds out the full pipeline needed to look like a real browser session. ## New executor: open-sse/executors/chatgpt-web.ts Auth/request pipeline (per chat completion): 1. exchangeSession() GET /api/auth/session cookie -> JWT (cached ~5min) 2. fetchDpl() GET / scrape data-build + script src 3. runSessionWarmup() GET /backend-api/me, /conversations, /models 4. POST /sentinel/chat-requirements/prepare -> prepare_token 5. POST /sentinel/chat-requirements -> chat-requirements-token + PoW seed/diff 6. solveProofOfWork() SHA3-512 loop -> "gAAAAAB..." sentinel proof token 7. POST /backend-api/f/conversation with all sentinel headers 8. parse SSE stream -> OpenAI chat.completion[.chunk] format Notable details: - 18-element prekey config matching chat2api/openai-sentinel (browser fingerprint values, U+2212 MINUS SIGN in `webdriver−false`). Thin shapes get escalated to mandatory Turnstile. - Two-stage Sentinel handshake (/prepare + /chat-requirements) — sending only the prepare result returns a 403 "Unusual activity" response. - `turnstile.required: true` from Sentinel is treated as advisory; the conv endpoint accepts requests without a Turnstile token as long as PoW + chat- requirements-token are valid. Optional bring-your-own Turnstile via `providerSpecificData.turnstileToken` for accounts that hard-require it. - SSE parser tracks message_id and resets the accumulator on a new turn — chatgpt.com echoes prior assistant messages (with status finished_successfully) before sending the new turn. - entity["...","value", ...] internal markup stripped from output (browser renders these client-side). - Conversation-continuity cache disabled by default: we send history_and_training_disabled: true (Temporary Chat mode) and those conversation_ids expire too fast to reuse — re-using returned 404. Each request now sends conversation_id: null and replays full history, matching what Open WebUI and OpenAI-API-style clients send anyway. ## TLS impersonation: open-sse/services/chatgptTlsClient.ts ChatGPT's Cloudflare config pins cf_clearance to JA3/JA4 TLS fingerprint + HTTP/2 SETTINGS frame. Plain Node Undici fetch always returns cf-mitigated: challenge regardless of cookies. The wrapper module loads `tls-client-node` (Firefox 148 fingerprint) in native runtime mode (.so via koffi) — managed mode spawns a sidecar that conflicts with OmniRoute's global fetch proxy patch. - Lazy singleton TLSClient with process exit hooks - Streaming-capable (file tail) and non-streaming modes - Test injection point: __setTlsFetchOverrideForTesting() lets unit tests mock the client without touching globalThis.fetch ## Provider wiring - open-sse/executors/index.ts — register ChatGptWebExecutor with cgpt-web alias - open-sse/config/providerRegistry.ts — registry entry, format=openai, authHeader=cookie, model gpt-5.3-instant - src/shared/constants/providers.ts — WEB_COOKIE_PROVIDERS UI metadata (icon, color, authHint) - src/lib/providers/validation.ts — validateChatGptWebProvider hits /api/auth/session via the TLS client, detects cf-mitigated/HTML responses and returns a clear "paste full Cookie line" hint instead of a generic "Invalid" - next.config.mjs — mark tls-client-node, koffi, tough-cookie as external packages (Turbopack can't bundle the native .so) ## Cookie format Validator and executor accept any of: - bare value: "eyJhbGc..." - unchunked cookie line: "__Secure-next-auth.session-token=eyJ..." - chunked cookie line: "__Secure-next-auth.session-token.0=...; __Secure-next-auth.session-token.1=..." - full DevTools Cookie header line: "Cookie: __Secure-next-auth.session-token.0=...; cf_clearance=...; ..." NextAuth chunks the JWE when it exceeds 4KB; chunked cookies pass through verbatim (NextAuth reassembles server-side). Recommend pasting the full DevTools Cookie line so cf_clearance, __cf_bm, _cfuvid, _puid travel along — without cf_clearance, Cloudflare blocks the request before NextAuth sees it. ## Tests tests/unit/chatgpt-web.test.ts — 27 tests, all passing: - Registration + alias resolution - Token exchange (cookie -> Bearer flow) - Token cache TTL - Refreshed cookie surfaced via onCredentialsRefreshed callback - Sentinel call ordering (session -> prepare -> chat-requirements -> conv) - Sentinel chat-requirements-token forwarded on conv request - PoW token has gAAAAAB prefix - Turnstile.required: true does NOT block conv (passes through) - Non-streaming chat.completion JSON - Streaming SSE chunks ending with [DONE] - Cumulative-parts diffing yields non-overlapping deltas - Errors: 401 session, 403 sentinel, 429 conv rate-limit - Empty messages -> 400 without any fetch - Missing apiKey -> 401 without any fetch - Cookie format: bare value, unchunked, chunked, "Cookie: ..." DevTools line - Conversation continuity: each call starts a fresh conversation - Browser-like headers on conv POST (UA, Origin, Sec-Fetch-Site, Accept) - Payload shape (action, model=gpt-5-3, history_and_training_disabled) - Provider registry contains chatgpt-web with gpt-5.3-instant model Verification: typecheck:core clean, lint clean (no new warnings), end-to-end manually verified across single-turn, multi-turn (memory preserved), streaming, and Open WebUI-style sequential growing-history flows. ## References - bogdanfinn/tls-client (Go) — TLS impersonation upstream - fatihkabakk/tls-client-node — Node bindings - lanqian528/chat2api — Sentinel/PoW/prekey reference impl (Python) - leetanshaj/openai-sentinel — Prekey config + SHA3-512 solver Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
207 lines
7.8 KiB
JSON
207 lines
7.8 KiB
JSON
{
|
|
"name": "omniroute",
|
|
"version": "3.6.9",
|
|
"description": "Smart AI Router with auto fallback — route to FREE & cheap models, zero downtime. Works with Cursor, Cline, Claude Desktop, Codex, and any OpenAI-compatible tool.",
|
|
"type": "module",
|
|
"bin": {
|
|
"omniroute": "bin/omniroute.mjs",
|
|
"omniroute-reset-password": "bin/reset-password.mjs"
|
|
},
|
|
"files": [
|
|
"bin/",
|
|
"app/",
|
|
"open-sse/mcp-server/index.ts",
|
|
"open-sse/mcp-server/server.ts",
|
|
"open-sse/mcp-server/httpTransport.ts",
|
|
"open-sse/mcp-server/audit.ts",
|
|
"open-sse/mcp-server/runtimeHeartbeat.ts",
|
|
"open-sse/mcp-server/scopeEnforcement.ts",
|
|
"open-sse/mcp-server/schemas/",
|
|
"open-sse/mcp-server/tools/",
|
|
"open-sse/mcp-server/README.md",
|
|
"src/shared/contracts/",
|
|
"src/shared/utils/nodeRuntimeSupport.ts",
|
|
".env.example",
|
|
"scripts/postinstall.mjs",
|
|
"scripts/postinstallSupport.mjs",
|
|
"scripts/check-supported-node-runtime.ts",
|
|
"scripts/sync-env.mjs",
|
|
"scripts/native-binary-compat.mjs",
|
|
"scripts/build-next-isolated.mjs",
|
|
"README.md",
|
|
"LICENSE"
|
|
],
|
|
"workspaces": [
|
|
"open-sse"
|
|
],
|
|
"engines": {
|
|
"node": ">=20.20.2 <21 || >=22.22.2 <23 || >=24.0.0 <25"
|
|
},
|
|
"keywords": [
|
|
"ai",
|
|
"router",
|
|
"proxy",
|
|
"openai",
|
|
"claude",
|
|
"anthropic",
|
|
"gemini",
|
|
"fallback",
|
|
"cursor",
|
|
"cline",
|
|
"codex",
|
|
"llm",
|
|
"auto-fallback"
|
|
],
|
|
"license": "MIT",
|
|
"author": "diegosouzapw",
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "https://github.com/diegosouzapw/OmniRoute"
|
|
},
|
|
"homepage": "https://omniroute.online",
|
|
"scripts": {
|
|
"dev": "node scripts/run-next.mjs dev",
|
|
"build": "node scripts/build-next-isolated.mjs",
|
|
"build:cli": "node --import tsx/esm scripts/prepublish.ts",
|
|
"start": "node scripts/run-next.mjs start",
|
|
"lint": "eslint .",
|
|
"electron:dev": "concurrently \"npm run dev\" \"wait-on http://localhost:20128 && cd electron && npm run dev\"",
|
|
"electron:build": "npm run build && cd electron && npm run build",
|
|
"electron:build:win": "npm run build && cd electron && npm run build:win",
|
|
"electron:build:mac": "npm run build && cd electron && npm run build:mac",
|
|
"electron:build:linux": "npm run build && cd electron && npm run build:linux",
|
|
"test": "cross-env DISABLE_SQLITE_AUTO_BACKUP=true node --import tsx/esm --test --test-concurrency=1 tests/unit/*.test.ts",
|
|
"test:unit": "cross-env DISABLE_SQLITE_AUTO_BACKUP=true node --import tsx/esm --test --test-concurrency=1 tests/unit/*.test.ts",
|
|
"test:plan3": "cross-env DISABLE_SQLITE_AUTO_BACKUP=true node --import tsx/esm --test tests/unit/plan3-p0.test.ts",
|
|
"test:fixes": "cross-env DISABLE_SQLITE_AUTO_BACKUP=true node --import tsx/esm --test tests/unit/fixes-p1.test.ts",
|
|
"test:security": "cross-env DISABLE_SQLITE_AUTO_BACKUP=true node --import tsx/esm --test tests/unit/security-fase01.test.ts",
|
|
"check:cycles": "node scripts/check-cycles.mjs",
|
|
"check:route-validation:t06": "node scripts/check-route-validation.mjs",
|
|
"check:any-budget:t11": "node scripts/check-t11-any-budget.mjs",
|
|
"check:docs-sync": "node scripts/check-docs-sync.mjs",
|
|
"check:node-runtime": "node --import tsx/esm scripts/check-supported-node-runtime.ts",
|
|
"check:pack-artifact": "node --import tsx/esm scripts/validate-pack-artifact.ts",
|
|
"typecheck:core": "tsc --pretty false -p tsconfig.typecheck-core.json",
|
|
"typecheck:noimplicit:core": "tsc --pretty false -p tsconfig.typecheck-noimplicit-core.json",
|
|
"env:sync": "node scripts/sync-env.mjs",
|
|
"test:integration": "node --import tsx/esm --test tests/integration/*.test.ts",
|
|
"test:e2e": "node scripts/run-playwright-tests.mjs test tests/e2e/*.spec.ts",
|
|
"test:protocols:e2e": "node scripts/run-protocol-clients-tests.mjs",
|
|
"test:vitest": "vitest run --config vitest.mcp.config.ts",
|
|
"test:ecosystem": "node scripts/run-ecosystem-tests.mjs",
|
|
"test:coverage": "c8 --output-dir coverage --exclude=tests/** --exclude=**/*.test.* --reporter=text-summary --reporter=html --reporter=json-summary --reporter=lcov --check-coverage --statements 60 --lines 60 --functions 60 --branches 60 node --import tsx/esm --test --test-concurrency=1 tests/unit/*.test.ts",
|
|
"test:coverage:legacy": "c8 --output-dir coverage --exclude=open-sse --check-coverage --lines 50 --functions 50 --branches 50 node --import tsx/esm --test tests/unit/*.test.ts",
|
|
"coverage:report": "c8 report --output-dir coverage --exclude=tests/** --exclude=**/*.test.* --reporter=text --reporter=text-summary --reporter=html --reporter=json-summary --reporter=lcov",
|
|
"coverage:summary": "node scripts/test-report-summary.mjs --input coverage/coverage-summary.json --output coverage/coverage-report.md --threshold 60",
|
|
"check:pr-test-policy": "node scripts/check-pr-test-policy.mjs",
|
|
"coverage:report:legacy": "c8 report --output-dir coverage --exclude=open-sse --reporter=text --reporter=text-summary",
|
|
"test:all": "npm run test:unit && npm run test:vitest && npm run test:ecosystem && npm run test:e2e",
|
|
"check": "npm run lint && npm run test",
|
|
"prepublishOnly": "npm run build:cli && npm run check:pack-artifact",
|
|
"postinstall": "node scripts/postinstall.mjs",
|
|
"uninstall": "node scripts/uninstall.mjs",
|
|
"uninstall:full": "node scripts/uninstall.mjs --full",
|
|
"prepare": "husky",
|
|
"system-info": "node scripts/system-info.mjs"
|
|
},
|
|
"dependencies": {
|
|
"@lobehub/icons": "^5.0.1",
|
|
"@modelcontextprotocol/sdk": "^1.27.1",
|
|
"@monaco-editor/react": "^4.7.0",
|
|
"@swc/helpers": "0.5.21",
|
|
"axios": "^1.15.0",
|
|
"bcryptjs": "^3.0.3",
|
|
"better-sqlite3": "^12.6.2",
|
|
"bottleneck": "^2.19.5",
|
|
"dompurify": "^3.4.0",
|
|
"express": "^5.2.1",
|
|
"fetch-socks": "^1.3.2",
|
|
"http-proxy-middleware": "^3.0.5",
|
|
"https-proxy-agent": "^9.0.0",
|
|
"jose": "^6.1.3",
|
|
"js-yaml": "^4.1.0",
|
|
"lowdb": "^7.0.1",
|
|
"monaco-editor": "^0.55.1",
|
|
"next": "^16.2.3",
|
|
"next-intl": "^4.8.3",
|
|
"node-machine-id": "^1.1.12",
|
|
"open": "^11.0.0",
|
|
"ora": "^9.1.0",
|
|
"pino": "^10.3.1",
|
|
"pino-pretty": "^13.1.3",
|
|
"react": "19.2.5",
|
|
"react-dom": "19.2.5",
|
|
"recharts": "^3.7.0",
|
|
"selfsigned": "^5.5.0",
|
|
"tls-client-node": "^0.1.13",
|
|
"tsx": "^4.21.0",
|
|
"undici": "^8.1.0",
|
|
"uuid": "^13.0.0",
|
|
"wreq-js": "^2.0.1",
|
|
"xxhash-wasm": "^1.1.0",
|
|
"yazl": "^3.3.1",
|
|
"zod": "^4.3.6",
|
|
"zustand": "^5.0.10"
|
|
},
|
|
"optionalDependencies": {
|
|
"keytar": "^7.9.0"
|
|
},
|
|
"devDependencies": {
|
|
"@playwright/test": "^1.58.2",
|
|
"@tailwindcss/postcss": "^4.1.18",
|
|
"@testing-library/jest-dom": "^6.9.1",
|
|
"@testing-library/react": "^16.3.2",
|
|
"@types/bcryptjs": "^3.0.0",
|
|
"@types/better-sqlite3": "^7.6.13",
|
|
"@types/keytar": "^4.4.0",
|
|
"@types/node": "^25.2.3",
|
|
"@types/react": "^19.2.14",
|
|
"@types/react-dom": "^19.2.3",
|
|
"@vitejs/plugin-react": "^6.0.1",
|
|
"c8": "^11.0.0",
|
|
"concurrently": "^9.2.1",
|
|
"cross-env": "^10.1.0",
|
|
"eslint": "^9.39.2",
|
|
"eslint-config-next": "16.2.3",
|
|
"husky": "^9.1.7",
|
|
"jsdom": "^29.0.1",
|
|
"lint-staged": "^16.2.7",
|
|
"prettier": "^3.8.1",
|
|
"prop-types": "^15.8.1",
|
|
"tailwindcss": "^4",
|
|
"typescript": "^6.0.2",
|
|
"typescript-eslint": "^8.56.0",
|
|
"vitest": "^4.1.2",
|
|
"wait-on": "^9.0.4",
|
|
"wtfnode": "^0.10.1"
|
|
},
|
|
"lint-staged": {
|
|
"*.{js,jsx,ts,tsx,mjs}": [
|
|
"prettier --write",
|
|
"eslint --fix --no-error-on-unmatched-pattern"
|
|
],
|
|
"*.{json,md,yml,yaml,css}": [
|
|
"prettier --write"
|
|
]
|
|
},
|
|
"pnpm": {
|
|
"onlyBuiltDependencies": [
|
|
"@parcel/watcher",
|
|
"@swc/core",
|
|
"better-sqlite3",
|
|
"esbuild",
|
|
"omniroute",
|
|
"sharp"
|
|
]
|
|
},
|
|
"overrides": {
|
|
"lodash-es": "^4.18.1",
|
|
"dompurify": "^3.4.0",
|
|
"path-to-regexp": "^8.4.0",
|
|
"hono": "^4.12.14",
|
|
"@hono/node-server": "^1.19.13",
|
|
"react": "$react",
|
|
"react-dom": "$react-dom"
|
|
}
|
|
}
|