Skip to content

feat(services): expose sanitized CLIProxyAPI account health - #11314

Merged
diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.50from
RaviTharuma:fix/6342-cpa-account-visibility
Aug 24, 2026
Merged

diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.50from
RaviTharuma:fix/6342-cpa-account-visibility

Conversation

@RaviTharuma

@RaviTharuma RaviTharuma commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • query CLIProxyAPI GET /v0/management/auth-files through a 5-second timeout-bounded, read-only client
  • expose only an explicit health allowlist through an OmniRoute management-authenticated API
  • show account state and aggregate success/failure counts in the existing CLIProxyAPI service tab
  • provision embedded CLIProxyAPI management auth from OmniRoute's encrypted service key; require CLIPROXYAPI_MANAGEMENT_KEY for external instances
  • document the external management-key contract in .env.example and the environment reference

The response intentionally excludes names, filesystem paths, email/account identifiers, tokens, status messages, raw metadata, and every unknown upstream field. This is visibility only: account attribution and per-account routing remain blocked by CLIProxyAPI's current data-plane contract and are tracked separately in #6340.

Closes #6342
Related #6340

  • Focused tests and category gates from the golden path

Tests Added Or Updated

  • client contract: allowlist redaction, management auth, timeout, and disabled/missing/unreachable/unauthorized/unsupported/invalid response states
  • API contract: OmniRoute management authentication and no-store response
  • embedded service: management password injection without config-file persistence
  • dashboard: CLIProxyAPI tab exports and mounts the read-only account card

Verification

  • focused Node test run: 16/16 passed after rebase
  • focused ESLint: passed after rebase
  • npm run check:env-doc-sync: passed
  • git diff --check: passed
  • full tsc --noEmit: attempted; blocked by pre-existing errors in tray typings, stream Transformer cancel typings, and an unrelated ad-hoc script

@RaviTharuma
RaviTharuma force-pushed the fix/6342-cpa-account-visibility branch from 886d900 to 2818fda Compare August 24, 2026 02:01
@RaviTharuma

Copy link
Copy Markdown
Contributor Author

Implementation evidence:

  • rebased onto current release/v3.8.50 (ac02c5b42)
  • 16 focused client/API/service/UI tests pass
  • focused ESLint and env-doc sync pass
  • PR is mergeable; required CI is running

Security boundary: the OmniRoute response is constructed from a strict allowlist and never forwards CPA names, paths, email/account identifiers, tokens, status messages, raw metadata, or unknown fields. The management secret is only sent server-to-server and is never returned.

@diegosouzapw
diegosouzapw merged commit c3cd1f9 into diegosouzapw:release/v3.8.50 Aug 24, 2026
14 of 16 checks passed
@RaviTharuma
RaviTharuma deleted the fix/6342-cpa-account-visibility branch September 23, 2026 19:37
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…zapw#11314)

Validated on a 17-PR combined board: cliproxy-accounts + cliproxy-tab + cliproxy-account-health + cliproxy-resolve-spawn-args-6877 (16/16) within the board's 287/287, typecheck:core clean, env-doc-sync clean. Exposes a sanitized read-only CLIProxyAPI account health view (5s-bounded client, explicit allowlist excluding names/paths/emails/tokens/status messages) through a management-authenticated API + dashboard card. Closes diegosouzapw#6342. Thank you @RaviTharuma!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(providers): consume CLIProxyAPI /v0/management for account-aware routing and quota display

2 participants