Skip to content

feat(sse): add kimi web token lifecycle manager, rolling auto-refresh and 401 recovery - #10944

Merged
diegosouzapw merged 7 commits into
diegosouzapw:release/v3.8.50from
MeRezaRezaei:feat/kimi-web-token-manager
Aug 21, 2026
Merged

diegosouzapw merged 7 commits into
diegosouzapw:release/v3.8.50from
MeRezaRezaei:feat/kimi-web-token-manager

Conversation

@MeRezaRezaei

Copy link
Copy Markdown
Contributor

Summary

Implements autonomous rolling token refresh, JWT lifecycle tracking, and proactive background/on-demand renewal for Kimi Web (kimi.ai) provider connections.

Changes

  • JWT Lifecycle Analyzer (open-sse/utils/kimiJwt.ts): Lightweight base64 decoder parsing iat, exp, sub, region, and space_id without external dependencies.
  • Dual Credential Extractor (src/lib/providers/webCookieAuth.ts): Auto-extracts both access_token and refresh_token from raw tokens, key-value pairs, or full localStorage JSON dumps.
  • Token Exchange & Persistence (src/lib/kimi/tokenRefresh.ts): Exchanges refresh_token at GET /api/auth/token/refresh and updates connection records in SQLite in a single atomic update.
  • Proactive Health Sweep (src/lib/tokenHealthCheckKimi.ts): Hooks into OmniRoute's background health sweep to auto-refresh expiring Kimi tokens 1 to 4 minutes before expiry (with randomized anti-thundering jitter).
  • On-Demand 401 Recovery (open-sse/executors/kimi-web.ts): Catches upstream 401s during live chat completions and transparently rotates credentials with retry.
  • Manual Refresh Route (src/app/api/providers/[id]/refresh-token/route.ts): Exposes endpoint for manual dashboard refresh triggers.
  • Unit Tests: Full coverage across tests/unit/kimi-jwt.test.ts, tests/unit/kimi-credentials-extract.test.ts, tests/unit/kimi-token-refresh.test.ts, tests/unit/token-health-check-kimi.test.ts, tests/unit/kimi-web-401-retry.test.ts, and tests/unit/provider-refresh-token-route.test.ts.

@diegosouzapw
diegosouzapw merged commit 6efb01a into diegosouzapw:release/v3.8.50 Aug 21, 2026
9 of 16 checks passed
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…diegosouzapw#10944

PR diegosouzapw#10944 intentionally moved the Kimi Web executor's default base URL
from www.kimi.com to www.kimi.ai (env-overridable via KIMI_WEB_BASE_URL)
but left two test files asserting the old domain, so every unit shard
failed on release/v3.8.50:

- tests/unit/executor-kimi-web.test.ts — 'execute targets www.kimi.com'
  and its capturedUrl.startsWith assertion
- tests/unit/web-cookie-providers-new.test.ts — 'Kimi Web: targets
  www.kimi.com' hostname equality

Both domains serve the same Connect-RPC endpoint (verified live: POST
/apiv2/kimi.gateway.chat.v1.ChatService/Chat returns the identical
unauthenticated JSON on each), so the executor change stands; only the
stale assertions needed updating. Verified: both suites green locally.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…NDALONE_DIR vars

Three merged features read env vars that were never added to
.env.example / ENVIRONMENT.md, breaking the env-doc contract gate
(check-env-doc-sync + issue-7793 repro test) on release/v3.8.50:

- KIMI_WEB_BASE_URL / KIMI_WEB_CHAT_URL — Kimi Web executor overrides
  (diegosouzapw#10944 moved the default to www.kimi.ai but never documented the
  override knobs)
- OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN (+ bare alias
  OIDC_DISABLE_PASSWORD_LOGIN) — OIDC-only login flag (diegosouzapw#10889)
- OMNIROUTE_STANDALONE_DIR — build-time standalone output override
  (scripts/build/colocate-standalone.mjs, diegosouzapw#10936)

check-env-doc-sync.mjs now reports "✓ Env / docs contract is in sync"
and both sync tests pass 15/15.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…call sites

Three getProviderConnectionById sites landed on release/v3.8.50 without
updating the frozen inventory:
- src/app/api/providers/[id]/refresh-token/route.ts (diegosouzapw#10910 TLS factory)
- src/lib/kimi/tokenRefresh.ts (diegosouzapw#10944 kimi web-token lifecycle)
- src/app/api/usage/utilization/route.ts (4226382, this PR's fix)
and diegosouzapw#10920 added a fourth sibling re-read inside src/sse/services/auth.ts
(3 → 4). All are classified B (connection-query, lease-checked) per the
existing classification table. 3/3 green.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…diegosouzapw#10944

PR diegosouzapw#10944 intentionally moved the Kimi Web executor's default base URL
from www.kimi.com to www.kimi.ai (env-overridable via KIMI_WEB_BASE_URL)
but left two test files asserting the old domain, so every unit shard
failed on release/v3.8.50:

- tests/unit/executor-kimi-web.test.ts — 'execute targets www.kimi.com'
  and its capturedUrl.startsWith assertion
- tests/unit/web-cookie-providers-new.test.ts — 'Kimi Web: targets
  www.kimi.com' hostname equality

Both domains serve the same Connect-RPC endpoint (verified live: POST
/apiv2/kimi.gateway.chat.v1.ChatService/Chat returns the identical
unauthenticated JSON on each), so the executor change stands; only the
stale assertions needed updating. Verified: both suites green locally.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…NDALONE_DIR vars

Three merged features read env vars that were never added to
.env.example / ENVIRONMENT.md, breaking the env-doc contract gate
(check-env-doc-sync + issue-7793 repro test) on release/v3.8.50:

- KIMI_WEB_BASE_URL / KIMI_WEB_CHAT_URL — Kimi Web executor overrides
  (diegosouzapw#10944 moved the default to www.kimi.ai but never documented the
  override knobs)
- OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN (+ bare alias
  OIDC_DISABLE_PASSWORD_LOGIN) — OIDC-only login flag (diegosouzapw#10889)
- OMNIROUTE_STANDALONE_DIR — build-time standalone output override
  (scripts/build/colocate-standalone.mjs, diegosouzapw#10936)

check-env-doc-sync.mjs now reports "✓ Env / docs contract is in sync"
and both sync tests pass 15/15.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…call sites

Three getProviderConnectionById sites landed on release/v3.8.50 without
updating the frozen inventory:
- src/app/api/providers/[id]/refresh-token/route.ts (diegosouzapw#10910 TLS factory)
- src/lib/kimi/tokenRefresh.ts (diegosouzapw#10944 kimi web-token lifecycle)
- src/app/api/usage/utilization/route.ts (4226382, this PR's fix)
and diegosouzapw#10920 added a fourth sibling re-read inside src/sse/services/auth.ts
(3 → 4). All are classified B (connection-query, lease-checked) per the
existing classification table. 3/3 green.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…diegosouzapw#10944

PR diegosouzapw#10944 intentionally moved the Kimi Web executor's default base URL
from www.kimi.com to www.kimi.ai (env-overridable via KIMI_WEB_BASE_URL)
but left two test files asserting the old domain, so every unit shard
failed on release/v3.8.50:

- tests/unit/executor-kimi-web.test.ts — 'execute targets www.kimi.com'
  and its capturedUrl.startsWith assertion
- tests/unit/web-cookie-providers-new.test.ts — 'Kimi Web: targets
  www.kimi.com' hostname equality

Both domains serve the same Connect-RPC endpoint (verified live: POST
/apiv2/kimi.gateway.chat.v1.ChatService/Chat returns the identical
unauthenticated JSON on each), so the executor change stands; only the
stale assertions needed updating. Verified: both suites green locally.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 21, 2026
…NDALONE_DIR vars

Three merged features read env vars that were never added to
.env.example / ENVIRONMENT.md, breaking the env-doc contract gate
(check-env-doc-sync + issue-7793 repro test) on release/v3.8.50:

- KIMI_WEB_BASE_URL / KIMI_WEB_CHAT_URL — Kimi Web executor overrides
  (diegosouzapw#10944 moved the default to www.kimi.ai but never documented the
  override knobs)
- OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN (+ bare alias
  OIDC_DISABLE_PASSWORD_LOGIN) — OIDC-only login flag (diegosouzapw#10889)
- OMNIROUTE_STANDALONE_DIR — build-time standalone output override
  (scripts/build/colocate-standalone.mjs, diegosouzapw#10936)

check-env-doc-sync.mjs now reports "✓ Env / docs contract is in sync"
and both sync tests pass 15/15.
@MeRezaRezaei
MeRezaRezaei deleted the feat/kimi-web-token-manager branch August 21, 2026 20:15
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 22, 2026
…diegosouzapw#10944

PR diegosouzapw#10944 intentionally moved the Kimi Web executor's default base URL
from www.kimi.com to www.kimi.ai (env-overridable via KIMI_WEB_BASE_URL)
but left two test files asserting the old domain, so every unit shard
failed on release/v3.8.50:

- tests/unit/executor-kimi-web.test.ts — 'execute targets www.kimi.com'
  and its capturedUrl.startsWith assertion
- tests/unit/web-cookie-providers-new.test.ts — 'Kimi Web: targets
  www.kimi.com' hostname equality

Both domains serve the same Connect-RPC endpoint (verified live: POST
/apiv2/kimi.gateway.chat.v1.ChatService/Chat returns the identical
unauthenticated JSON on each), so the executor change stands; only the
stale assertions needed updating. Verified: both suites green locally.
backryun added a commit to backryun/OmniRoute that referenced this pull request Aug 22, 2026
…NDALONE_DIR vars

Three merged features read env vars that were never added to
.env.example / ENVIRONMENT.md, breaking the env-doc contract gate
(check-env-doc-sync + issue-7793 repro test) on release/v3.8.50:

- KIMI_WEB_BASE_URL / KIMI_WEB_CHAT_URL — Kimi Web executor overrides
  (diegosouzapw#10944 moved the default to www.kimi.ai but never documented the
  override knobs)
- OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN (+ bare alias
  OIDC_DISABLE_PASSWORD_LOGIN) — OIDC-only login flag (diegosouzapw#10889)
- OMNIROUTE_STANDALONE_DIR — build-time standalone output override
  (scripts/build/colocate-standalone.mjs, diegosouzapw#10936)

check-env-doc-sync.mjs now reports "✓ Env / docs contract is in sync"
and both sync tests pass 15/15.
Zartharas pushed a commit to Zartharas/OmniRoute that referenced this pull request Aug 24, 2026
… and 401 recovery (diegosouzapw#10944)

Validado no worktree combinado: typecheck:core, changelog-integrity, complexity, cognitive-complexity, file-size, lint e 52 testes focados (kimi-jwt, kimi-credentials-extract, kimi-token-refresh, kimi-web-401-retry, provider-refresh-token-route, token-health-check-kimi) todos verdes. Implementação sólida e bem testada de ciclo de vida de token para Kimi Web. CI vermelho é o base-red já rastreado em diegosouzapw#9985. Obrigado!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
… and 401 recovery (diegosouzapw#10944)

Validado no worktree combinado: typecheck:core, changelog-integrity, complexity, cognitive-complexity, file-size, lint e 52 testes focados (kimi-jwt, kimi-credentials-extract, kimi-token-refresh, kimi-web-401-retry, provider-refresh-token-route, token-health-check-kimi) todos verdes. Implementação sólida e bem testada de ciclo de vida de token para Kimi Web. CI vermelho é o base-red já rastreado em diegosouzapw#9985. Obrigado!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants