feat(services): expose sanitized CLIProxyAPI account health - #11314
Merged
diegosouzapw merged 2 commits intoAug 24, 2026
Merged
diegosouzapw merged 2 commits into
diegosouzapw merged 2 commits into
Conversation
RaviTharuma
force-pushed
the
fix/6342-cpa-account-visibility
branch
from
August 24, 2026 02:01
886d900 to
2818fda
Compare
Contributor
Author
|
Implementation evidence:
Security boundary: the OmniRoute response is constructed from a strict allowlist and never forwards CPA names, paths, email/account identifiers, tokens, status messages, raw metadata, or unknown fields. The management secret is only sent server-to-server and is never returned. |
diegosouzapw
merged commit Aug 24, 2026
c3cd1f9
into
diegosouzapw:release/v3.8.50
14 of 16 checks passed
This was referenced Aug 26, 2026
5 tasks
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…zapw#11314) Validated on a 17-PR combined board: cliproxy-accounts + cliproxy-tab + cliproxy-account-health + cliproxy-resolve-spawn-args-6877 (16/16) within the board's 287/287, typecheck:core clean, env-doc-sync clean. Exposes a sanitized read-only CLIProxyAPI account health view (5s-bounded client, explicit allowlist excluding names/paths/emails/tokens/status messages) through a management-authenticated API + dashboard card. Closes diegosouzapw#6342. Thank you @RaviTharuma!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
GET /v0/management/auth-filesthrough a 5-second timeout-bounded, read-only clientCLIPROXYAPI_MANAGEMENT_KEYfor external instances.env.exampleand the environment referenceThe response intentionally excludes names, filesystem paths, email/account identifiers, tokens, status messages, raw metadata, and every unknown upstream field. This is visibility only: account attribution and per-account routing remain blocked by CLIProxyAPI's current data-plane contract and are tracked separately in #6340.
Closes #6342
Related #6340
Tests Added Or Updated
Verification
npm run check:env-doc-sync: passedgit diff --check: passedtsc --noEmit: attempted; blocked by pre-existing errors in tray typings, stream Transformercanceltypings, and an unrelated ad-hoc script