Skip to content

fix(cli): stop pre-filling the secrets the server owns - #11436

Merged
diegosouzapw merged 91 commits into
diegosouzapw:release/v3.8.51from
maxmad64bis:fix/postinstall-stop-prefilling-server-secrets
Aug 24, 2026
Merged

diegosouzapw merged 91 commits into
diegosouzapw:release/v3.8.51from
maxmad64bis:fix/postinstall-stop-prefilling-server-secrets

Conversation

@maxmad64bis

@maxmad64bis maxmad64bis commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ base-red inherited: #9985

Summary

.env.example ships JWT_SECRET= and API_KEY_SECRET= blank on purpose. The server owns both: ensureSecrets() in src/instrumentation-node.ts restores each one from the durable store — the secrets namespace of the database under DATA_DIR — or generates it and persists it there on first use.

Postinstall filled them in anyway, and that defeated the mechanism. The file it writes lives inside the installed package, so npm i -g replaces it and postinstall writes different values, while ensureSecrets() — which only acts on an empty variable — never gets to restore the real ones. Both secrets rotate silently on every update: dashboard sessions are invalidated, and API-key CRCs stop matching the keys that produced them.

STORAGE_ENCRYPTION_KEY left this same list for this same reason in #1622, when it cost users their encrypted credentials. This does the same for the two that stayed behind. Its comment pointed at bin/omniroute.mjs:ensureStorageEncryptionKey(), a function that exists nowhere in the tree; it now names the real provisioning path.

Related Issues

Validation

  • Change type: CLI — install-time env sync only
  • Focused tests and category gates from the golden path (CLI)
  • npm run lint
  • Reconciled with the current active release base; focused checks rerun afterward
  • Production-code changes include a new or updated automated test in this PR
$ node --test tests/unit/sync-env.test.ts tests/unit/sync-env-bundled-require-5006.test.ts \
    tests/unit/bootstrap-env.test.ts tests/unit/cli-storage-key-bootstrap.test.ts
# tests 15
# pass 15
# fail 0

$ npm run check:cli-i18n
[cli-i18n] PASS — CLI i18n is consistent

$ npx eslint scripts/dev/sync-env.mjs tests/unit/sync-env.test.ts
(clean, no errors)

Tests Added Or Updated

  • tests/unit/sync-env.test.ts — two assertions inverted. They asserted that syncEnv fills JWT_SECRET and API_KEY_SECRET; they now assert both stay blank, joining STORAGE_ENCRYPTION_KEY, which the same test already asserted blank. The rest of the file is untouched, including the added counts, which do not change: the keys are still written, just empty.

Coverage Notes

The only production file is scripts/dev/sync-env.mjs, and both of its write paths go through the same CRYPTO_SECRETS object — the create path (syncEnv) and the append path (getEnvSyncPlan). The test file above exercises both, on a fresh .env and on an existing one.

Reviewer Notes

  • This inverts a deliberate assertion, so it deserves the argument stated plainly: the behaviour it asserted is what breaks the durability the rest of the code is built for. The same test already expected the target shape for STORAGE_ENCRYPTION_KEY.
  • MACHINE_ID_SALT stays in the list and is untouched. Its .env.example value is not blank, so replaceBlankSecret never rewrites it in practice.
  • persistSecret() writes with INSERT OR IGNORE, so the first value persisted wins for good. An install that has been running with a value from the package .env has nothing in the store yet: at its next start it generates one and freezes it. The rotation therefore happens one last time, then never again. Worth deciding whether that deserves a migration or just a release note.
  • This does not help an install whose package .env is already filled — it stops creating the trap, it doesn't empty the ones already set. A separate PR adds a warning for that case.
  • Leaving the two blank doesn't replay the fix(docker): empty .env secret placeholders override persisted server.env keys → restart crash loop #6824 crash loop. The Next path treats a blank as absent (instrumentation-node.ts:125 and :138), and fix(bootstrap): filter empty process.env values to prevent Docker env crash loop #6828 already filters blank values out of the bootstrap merge.
  • scripts/build/bootstrap-env.mjs generates the same two keys, and is deliberately left alone: it persists to DATA_DIR/server.env, which updates do not touch, and it ships with neither its callers nor itself in the published package.

diegosouzapw and others added 30 commits August 23, 2026 22:35
…11300) (diegosouzapw#11309)

Merging --admin: only fails are ESLint warnings ratchet drift (inherited) and dast-smoke (advisory, isRequired:null). Zero overlap with this PR's file scope (src/app/api/v1/models/catalog.ts).
…ota_exhausted errors (diegosouzapw#11277) (diegosouzapw#11310)

Merging --admin: only fails are ESLint warnings ratchet drift (inherited base-red) and dast-smoke (advisory, isRequired:null). Zero overlap with this PR's scope (src/lib/usage/providerLimits.ts).
…stream ids (diegosouzapw#11326)

Merging --admin with red discrimination (merge-gates §4). Fails: ESLint warnings ratchet drift (inherited base-red), Unit Tests shards containing stream-timing.test.ts (CPU-contention timing flake, assert.ok(total >= 15)ms — unrelated to this PR's scope, open-sse/handlers/imageGeneration.ts), and dast-smoke (advisory, isRequired:null).
…rtener (diegosouzapw#11329)

Validated on a 17-PR combined board: TSX parses clean, eslint clean. Adapta tutorial CTA href now points at the branded shortener (link.omniroute.online/adapta) while keeping the visible link text as the real domain. Completes diegosouzapw#11196's shortener rollout.
…ream (diegosouzapw#11328)

Validated on a 17-PR combined board: upstream-headers-proxy-auth within the board's 287/287, typecheck:core clean, gates within baseline. proxy-authorization and proxy-authenticate join the FORBIDDEN denylist — forwarding proxy-authorization to a model provider would hand that provider the operator's own proxy credential. Thank you @ntdat812!
… 3 DB-state tests (diegosouzapw#11327)

Validated on a 17-PR combined board: capture-critical-db-state 7/7 (all three previously-skipped tests now run) within the board's 287/287, typecheck:core clean. Fixes the racy DATA_DIR-after-dynamic-import isolation and removes a duplicate type declaration. Thank you @pacocartones!
…iegosouzapw#11325)

Validated on a 17-PR combined board: i18n-placeholder-parity within the board's 287/287, typecheck:core clean. Restores 3 dropped placeholders in pt.json (the visible one: the cache tile's subtitle was repeating its own label instead of showing the total) and adds a 42-locale placeholder-set gate so this class of drift can't recur silently. Thank you @ntdat812!
…diegosouzapw#11322)

Validated on a 17-PR combined board: typecheck:core clean, gates within baseline. Restores 3 missing pt-BR CLI keys (setup.opencode, serve.tls_cert, serve.tls_key) — parity restored, 823/823. Thank you @pacocartones!
…i.yml gates (diegosouzapw#11321)

Validated on a 17-PR combined board: validate-release-green within the board's 287/287, typecheck:core clean. Two accuracy bugs in the release-green verdict tool: an unanchored regex blamed a passing test line (matching a filename containing 'fail'), and 6 gates were double-recorded as both hard-failure and drift due to an id-format mismatch (ci.yml script name vs curated id). Found while reading the diegosouzapw#9985 verdict — good catch.
…11320)

Validated on a 17-PR combined board: token-health-check + token-health-no-refresh-token-expired-5326 + token-refresh-service within the board's 287/287, typecheck:core clean. GitHub access-token-only connections are now actively verified on each due health interval (via the existing Copilot token exchange); the parent credential is marked expired only on a confirmed 401, never on 403/429/5xx/network failures; response bodies and transport messages no longer enter token-refresh logs. Closes diegosouzapw#10352. Thank you @RaviTharuma!
…ouzapw#11319)

Validated on a 17-PR combined board: upstream-proxy-host-spelling 8/8 within the board's 287/287, typecheck:core clean. Routes src/lib/db/upstreamProxy.ts through the shared outbound-guard helpers instead of a private dotted-quad regex copy that had drifted since diegosouzapw#10843 — closes the IPv4-mapped IPv6, ULA, link-local and CGNAT bypasses while preserving the deliberate loopback allow (CLIProxyAPI on localhost:8317). Multicast widened from /224\. to the full 224.0.0.0/4, called out explicitly. Thank you @ntdat812!
…souzapw#11318)

Validated on a 17-PR combined board: compression-worker + colocate-standalone-esm-scope within the board's 287/287, typecheck:core clean, env-doc-sync clean. Offloads eligible sync compression engines into a bounded worker_threads pool with a strict serializable DTO boundary and fail-open on spawn/worker/timeout failure. Closes diegosouzapw#11023. Thank you @RaviTharuma!
Validated on a 17-PR combined board: gemini-tts + vertex-media + audio-speech-handler (41/41) within the board's 287/287, typecheck:core clean. Registers public google/gemini-*-tts speech models and translates OpenAI-compatible /v1/audio/speech to the AI Studio generateContent audio contract, reusing the Vertex inline-audio/PCM/WAV conversion path. Batch TTS only, Gemini Live is out of scope. Thank you @RaviTharuma!
…osouzapw#9985) (diegosouzapw#11317)

Validated on the resolved merge against the current release tip: pack-artifact-policy + cli-mcp-call-commands + cli-resilience-commands + cli-skills-commands + model-hide-multikey-11300 39/39, typecheck:core clean, eslint clean. Resolved a pt-BR.json wording conflict against diegosouzapw#11322 (kept the tip's wording, semantically identical). Drains the real lint-fallout from the wave that was blocking the release-green verdict — dead code + newly-enforced React-Compiler hook rules. Thank you @jonlwheat2-gif!
…zapw#11314)

Validated on a 17-PR combined board: cliproxy-accounts + cliproxy-tab + cliproxy-account-health + cliproxy-resolve-spawn-args-6877 (16/16) within the board's 287/287, typecheck:core clean, env-doc-sync clean. Exposes a sanitized read-only CLIProxyAPI account health view (5s-bounded client, explicit allowlist excluding names/paths/emails/tokens/status messages) through a management-authenticated API + dashboard card. Closes diegosouzapw#6342. Thank you @RaviTharuma!
…uzapw#11312)

Validated on a 17-PR combined board: elevenlabs-native-routes + hard-session-lease-bypass-inventory (9/9) within the board's 287/287, typecheck:core clean. Native ElevenLabs compatibility routes (voices, TTS, STT) reusing the stored credential via quota-preflight, sent only as xi-api-key; client authorization headers never forwarded. Closes diegosouzapw#10556. Thank you @RaviTharuma!
…uzapw#11311)

Validated on a 17-PR combined board: group-model-pattern-regex-escape within the board's 287/287, typecheck:core clean. matchesModelPattern() only substituted * before compiling to RegExp — every other metacharacter kept its regex meaning, so a malformed group pattern (unbalanced parens/brackets) threw uncaught and broke EVERY request for keys in that group, not just the malformed rule (isModelAllowedForKey has no try/catch and runs on the chat completion path and the /v1/models catalog). Thank you @ntdat812!
)

Validated on a 17-PR combined board: models-catalog-combo-metadata + ollama-cloud-reasoning-effort-tiers-10788 within the board's 287/287, typecheck:core clean, check:open-sse-typecheck clean, vitest 405/405. Publishes Ollama Cloud's native none/low/medium/high/max effort vocabulary for reasoning-capable passthrough/tagged models with no exact registry declaration, adds none to DeepSeek V4/GLM 5.x, and preserves narrower exact-model vocabularies (GPT-OSS) via intersection. Refs diegosouzapw#10788. Thank you @ekinnee!
* fix(deps): keep unused pnpm peers out of production

* docs(changelog): link dependency policy fix to PR 11342
…1367)

Merged via consolidated batch validation (worktree `.claude/worktrees/batch-0824d`, 11-PR video-bridge/catalog/ops batch, tip `dafb4ae8`). Fixes the diegosouzapw#9147 catalog-scale event-loop regression: reuses one build-local capability snapshot, yields cooperatively during catalog/virtual-pool construction, reads only persisted TTL settings. Static gates: typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity all green. Own regression test (tests/unit/9147-catalog-eventloop-yield.test.ts) reproduced the RED→GREEN transition in isolated runs per the PR's own evidence; under current shared-devbox load (10-15, multiple parallel sessions) the test intermittently reports INFRA-RED exactly as the PR body pre-disclosed (documented starvation signature, not a code defect). Thanks for the careful RED/GREEN + INFRA-RED discipline.
hartmark and others added 13 commits August 24, 2026 12:24
…apw#11344/diegosouzapw#11381/diegosouzapw#11362/diegosouzapw#11382/diegosouzapw#11383 growth

These entries were already validated in an earlier merge-batch worktree but
never reached origin (worktree discarded before pushing). Re-adding them
here since diegosouzapw#11355's test/route.ts growth (1215->1237) is now live on
origin/release/v3.8.50 and fails the frozen cap otherwise.
…n recheck return shape

The retry-loop recheck returned a non-conforming {ok:false, reason} object
that breaks typecheck against the established {ok, response?} contract used
everywhere else in this function. Aligns with the pre-dispatch skip pattern
(return null after fallbackCount++), matching the PR's own intent: skip this
target and move to the next, not error the whole attempt.

This is a live fix — the broken shape reached origin/release/v3.8.50 via
diegosouzapw#11360's own squash-merge and was breaking typecheck:core until now.
Validado em lote combinado (batch-0824f, junto de diegosouzapw#11400/diegosouzapw#11402/diegosouzapw#11407) contra o tip de release/v3.8.50: typecheck:core limpo, file-size/changelog/complexity/cognitive-complexity OK (abaixo do baseline), 56/56 testes focados passando incluindo os deste PR (tests/unit/8370-priority-affinity-reorder.test.ts).

Aditivo e coerente: protege a ordem já decidida pelo `auto` contra reordenação pelo pós-processamento de prompt-cache-affinity — mesma linha do diegosouzapw#11400. Obrigado pela contribuição!
Validado em lote combinado (batch-0824f, junto de diegosouzapw#11399/diegosouzapw#11402/diegosouzapw#11407) contra o tip de release/v3.8.50: typecheck:core limpo, file-size/changelog/complexity/cognitive-complexity OK, 56/56 testes focados passando incluindo os deste PR (tests/unit/combo-task-aware.test.ts).

Remove `auto` da lista de estratégias task-routing genéricas — coerente com o diegosouzapw#11399, que também protege a ordem já computada pelo `auto` contra reordenação por outro pós-processamento. Obrigado pela contribuição!
Validado em lote combinado (batch-0824f, junto de diegosouzapw#11399/diegosouzapw#11400/diegosouzapw#11407) contra o tip de release/v3.8.50: typecheck:core limpo, file-size/changelog/complexity/cognitive-complexity OK, 56/56 testes focados passando incluindo os deste PR (tests/unit/combo-scoring-inspector.test.ts).

Baixo risco: normaliza pesos parciais/não-unitários no inspector de diagnóstico (`comboScoringInspector.ts`) reutilizando o normalizador já existente do motor real de scoring, mantendo diagnósticos consistentes com o runtime. Obrigado pela contribuição!
Validado em lote combinado (batch-0824f, junto de diegosouzapw#11399/diegosouzapw#11400/diegosouzapw#11402) contra o tip de release/v3.8.50: typecheck:core limpo, file-size/changelog/complexity/cognitive-complexity OK, 56/56 testes focados passando incluindo os deste PR (tests/unit/autocombo-unification.test.ts).

Baixo risco: expõe a opção "custom" já suportada em runtime (`getModePack("custom") === undefined`, cai de volta para os pesos explícitos dos sliders) no seletor compartilhado de mode-pack da UI. Obrigado pela contribuição!
…souzapw#11417)

`isPublicApiRoute()` matched every entry of PUBLIC_API_ROUTE_PREFIXES with
`startsWith()`, but 11 of the 15 entries name ONE route, not a subtree. As a
prefix each also marked every adjacent path sharing its leading characters as
PUBLIC, which skips the MANAGEMENT auth gate.

That is reachable today: Next resolves `/api/usage/om-usage<anything>` to the
dynamic route `/api/usage/[connectionId]`, and that handler carries no auth of
its own — it relies entirely on being classified MANAGEMENT. An unauthenticated
caller therefore reaches `fetchAndPersistProviderLimits()`, which is an
existence oracle over connection ids (409/404/400/200) and, for a connection id
actually starting with `om-usage`, discloses live quota JSON and can drive an
OAuth token refresh (a write side effect) with no credentials.

Split the allowlist by shape:

- PUBLIC_API_ROUTE_PREFIXES keeps only genuine subtrees, every entry ending in
  "/" (asserted by a unit test, so the class cannot come back silently).
- PUBLIC_API_ROUTES_EXACT holds the single routes, matched exactly in both
  spellings.
- The three read-only "prefixes" were single routes too and move to
  PUBLIC_READONLY_CORS_API_ROUTES, matched exactly. classify.ts now asks
  `isPublicReadonlyCorsRoute()` instead of scanning the raw list, so the CORS
  origin relaxation pipeline.ts keys on cannot be inherited by a sibling either
  (`/api/monitoring/health-detail` was taking it).
- `/api/health` deliberately stays in its own set so it keeps classifying as
  `public_prefix`; folding it into the read-only set would widen CORS on it.

dashboardCsrf.ts had a second copy of the prefix scan; it now shares
`isPublicApiRoute()` so the client CSRF exemption and the server classification
cannot disagree. Side effect in the safe direction: the three LOCAL_ONLY oauth
auto-import routes were CSRF-exempt on the client while the server already
required the token — the client now attaches it.

Reported by @ntdat812 (GHSA-74g9-q8f6-793h), with the shape of the fix and the
two gotchas above called out in the report.

Closes GHSA-74g9-q8f6-793h

Co-authored-by: Xiangzhe <bakryun0718@proton.me>
Co-authored-by: Nguyen Thanh Dat <ntdat812.dev@gmail.com>
…osouzapw#11419)

Every "Publish to Docker Hub" run has failed since 2026-08-22 23:14 UTC — 96 of
the last 100. The builder stage dies with:

  ERROR: failed to solve: ResourceExhausted: process "/bin/sh -c ... npm run
  build ..." did not complete successfully: cannot allocate memory

That is the kernel, not V8. The log puts it precisely: the compile phase always
finishes ("✓ Compiled successfully in 4.2min") and the build is killed right
after "Collecting page data using 7 workers".

Each page-data worker is its own process and inherits NODE_OPTIONS, so the
--max-old-space-size ceiling is per PROCESS, not per build. CIRCLE_NODE_TOTAL=8
means 7 workers, and 7 of them alongside the parent no longer fit the 16 GB /
4 vCPU GitHub-hosted runners the pipeline builds on. It was intermittent for a
while before going 100%, which is what a threshold crossed by ordinary codebase
growth looks like — 7 was also oversubscribing a 4 vCPU runner.

Lower the pool to 3 (2 workers) and make it a build arg, so a big builder can
raise it back with `--build-arg OMNIROUTE_BUILD_WORKERS=8`.

tests/unit/docker-build-memory-budget.test.ts pins the budget: it reads the two
ARG defaults out of the Dockerfile and fails if `parent heap + workers × peak`
outgrows the runner, or if the pool oversubscribes its CPUs. Red on the base
(3/3), green here (3/3). The per-worker peak it budgets with is documented as an
inference from this failure, not a measurement.

DOCKER_GUIDE's build-arg table was stale (it still listed the pre-diegosouzapw#10060 4096 MB
default); updated and given the new knob plus the symptom to recognize.
CIRCLE_NODE_TOTAL and OMNIROUTE_BUILD_WORKERS are allowlisted in the
fabricated-docs gate with the reason: neither is read via process.env here — one
is a Dockerfile ARG, the other is read by Next itself.

Note: the real proof is the next publish run. This failure mode only reproduces
on a memory-constrained host, so it cannot be reproduced by the unit suite; the
test guards the arithmetic, not the outcome.

Co-authored-by: Xiangzhe <bakryun0718@proton.me>
…gosouzapw#11380)

Validado em lote combinado (batch-0824g, junto de diegosouzapw#11388/diegosouzapw#11397/diegosouzapw#11415/diegosouzapw#11418) contra o tip de release/v3.8.50: typecheck:core limpo, file-size/changelog/complexity/cognitive-complexity OK, 62/62 testes focados passando.

Diagnóstico correto e bem documentado: a falha do nightly Node 26 era um teste que sorteia um número e depende do resultado, não uma quebra de compatibilidade. Comportamento de produção inalterado (a janela de jitter continua aleatória; só o teste ganhou controle sobre ela). Obrigado pela investigação detalhada!
…iegosouzapw#11331) (diegosouzapw#11388)

Validado em lote combinado (batch-0824g) contra o tip de release/v3.8.50: typecheck:core limpo, gates estáticos OK, 62/62 testes focados passando (incluindo tests/unit/live-ws-url-11331.test.ts, 11 casos + mutation-check).

Resolve o incidente real do diegosouzapw#11331: o handshake já reportava a porta live real, mas o cliente descartava esse campo e ficava preso na porta compilada no bundle. Precedência clara (wsUrl explícito > publicUrl completo > porta/path do handshake aplicados ao default). Obrigado pela contribuição!
Validado em lote combinado (batch-0824g) contra o tip de release/v3.8.50: typecheck:core limpo, gates estáticos OK, 62/62 testes focados passando (endpoint/parser/schema/static-model + catálogo).

Canonicaliza metadados de endpoint legados (video/audio) para IDs específicos por operação, mantendo compatibilidade retroativa via `normalizeModelSupportedEndpoints` (valores antigos `audio`/`video` continuam válidos como entrada e são normalizados na escrita). Obrigado pela contribuição, primeira PR bem-vinda!
Validado em lote combinado (batch-0824g) contra o tip de release/v3.8.50: typecheck:core limpo, gates estáticos OK, 62/62 testes focados passando (23/23 do PR entre glm-5.3-catalog-and-effort-tiers.test.ts e zai-catalog-glm52.test.ts).

Aditivo, espelha exatamente o padrão já existente glm-5.2-max. Obrigado pela contribuição, primeira PR bem-vinda!
…mit peer IP, and add 429 Retry-After (#S1 #S2 #S4) (diegosouzapw#11418)

Validado em lote combinado (batch-0824g) contra o tip de release/v3.8.50: typecheck:core limpo, gates estáticos OK, 62/62 testes focados passando (S1/S2/S4, tests/unit/security-s1-s2-s4.test.ts, 9/9).

Boa integração com o padrão já existente de peer IP stamped por HMAC (resolveStampedPeer/OMNIROUTE_PEER_STAMP_TOKEN) — reusa em vez de reimplementar, e o header confiável só é honrado quando o stamp token está configurado. S2 remove corretamente a disclosure de topologia hardcoded do agent-card. Obrigado pela contribuição!
.env.example ships JWT_SECRET and API_KEY_SECRET blank on purpose: the server
restores each from its durable store, or generates and persists it there, in
instrumentation-node's ensureSecrets(). Postinstall filled them in anyway.

That defeated the mechanism. The file it writes lives inside the installed
package, so npm i -g replaced it and postinstall wrote different values, while
ensureSecrets() — which only acts on an empty variable — never got to restore
the real ones. Both secrets rotated silently on every update: dashboard
sessions were invalidated and API-key CRCs stopped matching.

STORAGE_ENCRYPTION_KEY left this same list for this same reason in diegosouzapw#1622. Its
comment pointed at bin/omniroute.mjs:ensureStorageEncryptionKey(), a function
that exists nowhere in the tree; it now names the real provisioning path.
@maxmad64bis
maxmad64bis force-pushed the fix/postinstall-stop-prefilling-server-secrets branch from 310f909 to af2df57 Compare August 24, 2026 21:28
@diegosouzapw
diegosouzapw changed the base branch from release/v3.8.50 to release/v3.8.51 August 24, 2026 22:50
hartmark and others added 3 commits August 24, 2026 19:57
… and translate-mode replies (diegosouzapw#11434)

Retargetado para release/v3.8.51 (release/v3.8.50 está congelada — freeze issue diegosouzapw#11439). Validado em lote combinado (batch-0824h2, junto de diegosouzapw#11435/diegosouzapw#11436/diegosouzapw#11437) contra o tip de release/v3.8.51: typecheck:core limpo, gates estáticos OK, 127/127 testes focados passando.

Investigação sólida com repro real via container isolado, três causas independentes identificadas e corrigidas com testes de regressão dedicados para cada uma. Obrigado pela contribuição!
…zapw#11435)

Retargetado para release/v3.8.51 (release/v3.8.50 está congelada — freeze issue diegosouzapw#11439). Validado em lote combinado (batch-0824h2) contra o tip de release/v3.8.51: typecheck:core limpo, gates estáticos + migration-numbering OK, 127/127 testes focados passando (8/8 do PR entre migration-163 e radar-feed-cache-generated-at).

Migração limpa (ADD COLUMN nullable, sem backfill necessário), aditiva na API, mantém "unknown" honesto para linhas antigas. Obrigado pela contribuição!
@diegosouzapw
diegosouzapw merged commit 6e8fc94 into diegosouzapw:release/v3.8.51 Aug 24, 2026
4 of 7 checks passed
diegosouzapw pushed a commit that referenced this pull request Aug 24, 2026
Retargetado para release/v3.8.51 (release/v3.8.50 está congelada — freeze issue #11439). Resolvido o mesmo conflito não-relacionado em src/shared/utils/wsPath.ts (mesma causa do #11436 — refactor já mergeado na branch depois do fork deste PR; o diff real deste PR — bin/cli/utils/volatileEnvPath.mjs + bin/omniroute.mjs — ficou intacto) e revalidado: typecheck:core limpo, 12/12 testes focados passando.

Companion do #11436, decisão pura testável isoladamente, sem mudança de comportamento fora do caso volátil. Obrigado pela contribuição!
MumuTW added a commit to MumuTW/OmniRoute that referenced this pull request Aug 25, 2026
… as TS2367 on release/v3.8.51

Before diegosouzapw#11436, catalog.ts derived `modelType` as a local `string | undefined` that
was only ever assigned "embedding" | "rerank" | "image" | "audio" — "chat" was
never produced, and chat models were represented by `undefined`. diegosouzapw#11436 replaced
that block with classifyModelSupportedEndpoints(), whose literal return union
makes the same comparison a TS2367 (baseline 0 → live 2) and reds
check:open-sse-typecheck. `!modelType || modelType === "chat"` is therefore
exactly `!modelType`; behaviour is unchanged at both sites.

Verification: npm run check:open-sse-typecheck → OK (5 pre-existing errors, all
within the frozen baseline); the 8 unit files importing the catalog route 61/61.
@maxmad64bis
maxmad64bis deleted the fix/postinstall-stop-prefilling-server-secrets branch September 24, 2026 21:15
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
… and translate-mode replies (diegosouzapw#11434)

Retargetado para release/v3.8.51 (release/v3.8.50 está congelada — freeze issue diegosouzapw#11439). Validado em lote combinado (batch-0824h2, junto de diegosouzapw#11435/diegosouzapw#11436/diegosouzapw#11437) contra o tip de release/v3.8.51: typecheck:core limpo, gates estáticos OK, 127/127 testes focados passando.

Investigação sólida com repro real via container isolado, três causas independentes identificadas e corrigidas com testes de regressão dedicados para cada uma. Obrigado pela contribuição!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…11436)

Retargetado para release/v3.8.51 (release/v3.8.50 está congelada — freeze issue diegosouzapw#11439). Resolvido um conflito de merge não-relacionado em src/shared/utils/wsPath.ts (originado de um refactor já mergeado nessa branch depois do fork deste PR; o diff real deste PR — scripts/dev/sync-env.mjs + tests/unit/sync-env.test.ts — ficou intacto) e revalidado: typecheck:core limpo, 13/13 testes focados passando.

Segue o precedente correto do diegosouzapw#1622 (STORAGE_ENCRYPTION_KEY) para os dois secrets restantes que a postinstall preenchia por engano, defeituando o mecanismo de ensureSecrets(). Obrigado pela contribuição!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…ouzapw#11437)

Retargetado para release/v3.8.51 (release/v3.8.50 está congelada — freeze issue diegosouzapw#11439). Resolvido o mesmo conflito não-relacionado em src/shared/utils/wsPath.ts (mesma causa do diegosouzapw#11436 — refactor já mergeado na branch depois do fork deste PR; o diff real deste PR — bin/cli/utils/volatileEnvPath.mjs + bin/omniroute.mjs — ficou intacto) e revalidado: typecheck:core limpo, 12/12 testes focados passando.

Companion do diegosouzapw#11436, decisão pura testável isoladamente, sem mudança de comportamento fora do caso volátil. Obrigado pela contribuição!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.