Skip to content

feat(providers): publish web-session credential contract - #11340

Merged
diegosouzapw merged 6 commits into
diegosouzapw:release/v3.8.51from
Zartharas:feat/web-session-contract-v1-r3851
Aug 25, 2026
Merged

diegosouzapw merged 6 commits into
diegosouzapw:release/v3.8.51from
Zartharas:feat/web-session-contract-v1-r3851

Conversation

@Zartharas

Copy link
Copy Markdown
Contributor

Summary

Publish a management-authenticated, versioned web-session credential contract at /api/providers/web-session-contract.

The contract is derived from OmniRoute's canonical browser-session metadata:

  • listExtractionConfigs()
  • getWebSessionCredentialRequirement()

Only non-secret metadata is returned. Credential values, placeholders, instructions, polling configuration, and operator-only guidance are excluded.

Why

External credential brokers otherwise need to duplicate OmniRoute's browser-session credential schema and can drift as provider requirements change.

This is the narrow upstream-suitable contract-publication portion remaining after aggregate Auth Keeper integration work was separated into independent upstream fixes.

Scope

  • src/lib/providers/webSessionContract.ts
  • src/app/api/providers/web-session-contract/route.ts
  • tests/unit/web-session-contract.test.ts

No executor, routing, inference, scheduler, recovery, database, provider-asset, dashboard, CLI, or credential-value behavior changes.

Validation

Against active release/v3.8.51 base 3192eb88d5550de4c3fd9985564f6b5641e9d681:

  • contract/canonical regression: 22/22 PASS
  • post-format contract regression: 4/4 PASS
  • formatter-only correction: byte-for-byte Prettier proof PASS
  • provider consistency: PASS
  • translate-path golden regression: PASS
  • Prettier contract surface: PASS
  • scoped ESLint on all changed TS files: PASS
  • core typecheck: PASS
  • explicit-any budget: PASS
  • tracked-artifact policy: PASS
  • diff whitespace validation: PASS
  • release reconciliation: PASS

Existing base-red full-repository lint

The active release base currently reports the known 22-error lint set across:

  • FirstRunReadinessCard.tsx
  • EndpointPageClient.tsx
  • CommandPalette.tsx
  • cli-mcp-call-commands.test.ts
  • cli-resilience-commands.test.ts
  • cli-skills-commands.test.ts

plus the existing stale-directive warning in EditConnectionModal.tsx.

All seven source blobs and the lint configuration are identical between the active release base and this PR head. This patch changes none of those files.

The exact 22-error set is the same release baseline tracked and fixed independently by merged upstream PR #11317.

Existing base-red provider asset gate

npm run check:provider-assets reports:

freebuff.png: 512x512 exceeds 256px max dimension

This is also inherited from the release base:

  • pristine base reproduces exactly this single asset failure;
  • base and PR head contain the same freebuff.png blob;
  • base and PR head contain the same asset-checker blob;
  • this PR changes no provider asset.

Broad PR CI remains authoritative for the repository-wide matrix.

@diegosouzapw

Copy link
Copy Markdown
Owner

Clean, narrowly-scoped addition — we verified on the current release/v3.8.51 tip that the route sits behind requireManagementAuth before serialization, publishes only non-secret metadata (cookie/localStorage key names, never values), and that all 4 tests pass. Two suggestions, neither blocking: (1) the auth regression test greps the route source for the auth call — a behavioral test asserting GET without a management token returns 401/403 would survive refactors; (2) consider adding the endpoint to docs/openapi.yaml / API_REFERENCE.md so external broker integrators have a stable reference. Good separation from the larger Auth Keeper work.

@diegosouzapw
diegosouzapw merged commit 613fc71 into diegosouzapw:release/v3.8.51 Aug 25, 2026
14 of 16 checks passed
arminanton added a commit to arminanton/OmniRoute that referenced this pull request Aug 26, 2026
The uc persona is registered as a web-cookie provider, so the web-session
credential contract (diegosouzapw#11340) requires it to declare its credential requirement
in WEB_SESSION_CREDENTIAL_REQUIREMENTS; without it the create-connection UI
can't describe what to paste and the coverage test (web-session-credentials)
fails 'uc should declare its required web-session credential'.

uc auth is the durable Clerk __client cookie plus session id + user id, all
kept in providerSpecificData (kind: cookie, apiKey stays null). The storageKeys
mirror the aliases resolveUcCredential() accepts so a seeded/imported
connection is recognized as having a usable credential.
@Zartharas
Zartharas deleted the feat/web-session-contract-v1-r3851 branch September 24, 2026 13:26
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…w#11340)

Merged into release/v3.8.51 via batch validation: node:test web-session-contract suite green on the combined tree, static gates green (file-size/complexity/cognitive/changelog/typecheck). Clean credential-contract surface — thanks @Zartharas!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants