Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
59 commits
Select commit Hold shift + click to select a range
18aba9b
fix(streaming): #1211 greedy strip omniModel tags to prevent literal …
diegosouzapw Apr 14, 2026
a1ffbc4
fix: 3 bugs found during issue triage (#1175, #1187/#1218, #1202)
diegosouzapw Apr 14, 2026
b6e8597
fix(providers): update Xiaomi MiMo token-plan endpoints (#1238)
hijak Apr 14, 2026
ff183f8
fix(cc-compatible): trim beta flags and preserve cache passthrough (#…
rdself Apr 14, 2026
711812a
feat(memory+skills): full-featured memory & skills systems with tests…
oyi77 Apr 14, 2026
5acb40c
fix: forward client x-initiator header to GitHub Copilot upstream (#1…
cedrugs Apr 14, 2026
2a84d79
feat(bailian-quota): add Alibaba Coding Plan quota monitoring (#1235)
diegosouzapw Apr 14, 2026
a26b3ee
fix: resolve v3.6.6 backlog bugs (#1206, #1211, #1220, #1231)
diegosouzapw Apr 14, 2026
9949fad
fix(tests): resolve memory migration and skills route pagination bugs…
diegosouzapw Apr 14, 2026
d675c8f
docs: Update CHANGELOG.md with v3.6.6 features (#1182, #1165, #1177)
diegosouzapw Apr 14, 2026
de050be
chore(release): bump version to 3.6.6
diegosouzapw Apr 14, 2026
07b2810
feat(core): harden outbound provider calls and add cooldown retries
diegosouzapw Apr 14, 2026
9952a6c
feat(models): add glmt preset and hybrid token counting
diegosouzapw Apr 14, 2026
cc27bdd
feat(api): add sync tokens and v1 websocket bridge
diegosouzapw Apr 15, 2026
935c36f
docs: Update all documentation for v3.6.6
diegosouzapw Apr 15, 2026
7fc758c
fix: use api64 for proxy test (#1255)
mgarmash Apr 15, 2026
08a2a15
fix(page): update custom models section to include all providers #120…
hartmark Apr 15, 2026
00a4b45
fix: provide default client_id fallbacks to prevent broken OAuth requ…
Gi99lin Apr 15, 2026
678298f
fix: translate max_tokens/max_completion_tokens → max_output_tokens i…
Gi99lin Apr 15, 2026
da9af4a
feat(oauth): support cursor-agent CLI as Cursor credential source (#1…
payne0420 Apr 15, 2026
a17b723
fix(cc-compatible): restore upstream SSE and correct stream/combo tim…
rdself Apr 15, 2026
d89e38e
fix(cli-tools): resolve API key resolution and model mapping bugs in …
benzntech Apr 15, 2026
bc0ad6a
feat(cli-tools): add Qwen Code CLI integration (#1266)
benzntech Apr 15, 2026
ca21f51
fix(i18n): add missing zh-CN translations and fix logger imports (#1269)
clousky2020 Apr 15, 2026
69e46ca
fix(i18n): add Chinese i18n support to dashboard components (#1274)
clousky2020 Apr 15, 2026
2a175ec
feat: update Pollinations to require API key, remove free tier flag (…
diegosouzapw Apr 15, 2026
e860df1
feat: friendly error messages for crypto/encryption failures (#1165)
diegosouzapw Apr 15, 2026
915341a
feat: add TPS (tokens per second) metric column to request logs (#1182)
diegosouzapw Apr 15, 2026
efeafce
feat: merge custom/imported models into filter list for all providers…
diegosouzapw Apr 15, 2026
18604ac
feat(fallback): Fix provider-profile-driven lockouts (#1267)
diegosouzapw Apr 15, 2026
fdb8c10
fix(claude): proper Anthropic SDK integration (#1271)
diegosouzapw Apr 15, 2026
bd1a06d
fix(healthcheck): use correct proxy wrapper format for getAccessToken…
diegosouzapw Apr 15, 2026
699d746
chore(release): v3.6.6 — skills registry stability fix + final integr…
diegosouzapw Apr 15, 2026
de44f3b
fix(auth): harden bootstrap auth and memory dashboard behavior
diegosouzapw Apr 15, 2026
a158014
fix(codex): remove max_output_tokens from body for compatibility
diegosouzapw Apr 15, 2026
18fec5d
chore(release): v3.6.6 — include PR 1274 fixes in changelog
diegosouzapw Apr 15, 2026
0c0e530
chore: exclude additional build artifacts and internal directories fr…
diegosouzapw Apr 15, 2026
001310e
fix: update Gemini OAuth test to match registry defaults + codex UI i…
diegosouzapw Apr 15, 2026
288c35c
fix: restore .mjs refs for scripts/ in test imports after ts migration
diegosouzapw Apr 15, 2026
4e924db
fix: restore next.config.mjs ref in dev-origins test
diegosouzapw Apr 15, 2026
5bbe645
fix: implement db migration safety checks and codex config format
diegosouzapw Apr 15, 2026
419f4c6
fix: disable mass-migration abort during unit tests based on auto-bac…
diegosouzapw Apr 15, 2026
8f86907
fix: update script regex in auto-update tests to use .mjs
diegosouzapw Apr 15, 2026
66ace45
feat: Add Perplexity Web (Session) provider (#1289)
RaviTharuma Apr 15, 2026
497014d
fix(cli): resolve codex routing config parsing, standardize select mo…
diegosouzapw Apr 15, 2026
e1b19c0
docs(changelog): record recent cli, provider, and test updates
diegosouzapw Apr 15, 2026
058422c
chore(release): merge #1286 minor improvements manually to avoid test…
diegosouzapw Apr 15, 2026
33c6c43
chore(test): rename perplexity-web.test.mjs to .ts to maintain 100% T…
diegosouzapw Apr 15, 2026
77e4ce1
chore(docs): update CHANGELOG.md for perplexity-web provider
diegosouzapw Apr 15, 2026
5768e76
fix(security): resolve CodeQL incomplete URL substring sanitization v…
diegosouzapw Apr 15, 2026
b73d235
fix: integrate compressContext() into chatCore.ts request pipeline
oyi77 Apr 15, 2026
5791904
fix(tests): align reasoning expectations with GLM thinking structure
diegosouzapw Apr 15, 2026
9ae1a80
fix: prevent orphaned tool_result messages in purifyHistory()
oyi77 Apr 15, 2026
8b21c7b
Merge release/v3.6.6 into branch
diegosouzapw Apr 15, 2026
16e6fd8
Merge branch 'release/v3.6.6' into fix/compress-context-integration-1290
diegosouzapw Apr 15, 2026
0437592
fix(tests): supply tool_use in mock so it is not dropped
diegosouzapw Apr 15, 2026
327b06e
chore: convert remaining test to TypeScript
diegosouzapw Apr 15, 2026
674eada
fix(tests): restore compatibility with compressContext threshold test…
diegosouzapw Apr 15, 2026
05ef24d
fix: increase timeout and add error logging for context summarization
oyi77 Apr 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 2 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -242,6 +242,7 @@ NEXT_PUBLIC_ENABLE_SOCKS5_PROXY=true
# CLI_CLINE_BIN=cline
# CLI_CONTINUE_BIN=cn
# CLI_QODER_BIN=qoder
# CLI_QWEN_BIN=qwen


# ═══════════════════════════════════════════════════════════════════════════════
Expand Down Expand Up @@ -354,6 +355,7 @@ QODER_OAUTH_CLIENT_SECRET=4Z3YjXycVsQvyGF1etiNlIBB4RsqSDtW
# QODER_OAUTH_TOKEN_URL=
# QODER_OAUTH_USERINFO_URL=
# QODER_OAUTH_CLIENT_ID=
# QODER_OAUTH_CLIENT_SECRET=

# ── Qoder Personal Access Token (direct API key fallback) ──
# Used by: open-sse/executors/qoder.ts — bypasses OAuth when set.
Expand Down
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -165,7 +165,7 @@ body:
description: "Which commands or tests should prove this bug is fixed?"
placeholder: |
Example:
- node --import tsx/esm --test tests/unit/my-file.test.mjs
- node --import tsx/esm --test tests/unit/my-file.test.ts
- npm run test:coverage
validations:
required: false
4 changes: 2 additions & 2 deletions .github/ISSUE_TEMPLATE/test_coverage_task.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ body:
Example:
- open-sse/handlers/chatCore.ts
- open-sse/services/combo.ts
- tests/integration/chat-pipeline.test.mjs
- tests/integration/chat-pipeline.test.ts
validations:
required: true

Expand Down Expand Up @@ -59,7 +59,7 @@ body:
description: "List the commands that must pass before this issue can be closed."
placeholder: |
Example:
- node --import tsx/esm --test tests/unit/my-suite.test.mjs
- node --import tsx/esm --test tests/unit/my-suite.test.ts
- npm run test:coverage
validations:
required: true
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -169,3 +169,4 @@ docs/superpowers/

# GitNexus local index
.gitnexus
.worktrees
4 changes: 4 additions & 0 deletions .npmignore
Original file line number Diff line number Diff line change
Expand Up @@ -72,3 +72,7 @@ vscode-extension/

# Root-level underscore-prefixed directories (private/draft — never publish)
/_*/
app/_*/
app/coverage/
app/logs/
app/tests/
10 changes: 5 additions & 5 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,13 +44,13 @@ with **MCP Server** (25 tools), **A2A v0.3 Protocol**, and **Electron desktop ap
npm run test:all

# Single test file (Node.js native test runner — most tests use this)
node --import tsx/esm --test tests/unit/your-file.test.mjs
node --import tsx/esm --test tests/unit/plan3-p0.test.mjs
node --import tsx/esm --test tests/unit/fixes-p1.test.mjs
node --import tsx/esm --test tests/unit/security-fase01.test.mjs
node --import tsx/esm --test tests/unit/your-file.test.ts
node --import tsx/esm --test tests/unit/plan3-p0.test.ts
node --import tsx/esm --test tests/unit/fixes-p1.test.ts
node --import tsx/esm --test tests/unit/security-fase01.test.ts

# Integration tests
node --import tsx/esm --test tests/integration/*.test.mjs
node --import tsx/esm --test tests/integration/*.test.ts

# Vitest (MCP server, autoCombo)
npm run test:vitest
Expand Down
44 changes: 44 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,50 @@

---

## [3.6.6] — 2026-04-15

### ✨ New Features

- **feat(providers):** Add Freepik Pikaso image generation provider with support for cookie/subscription-based auth modes (#1277)
- **feat(providers): Add Perplexity Web (Session) Provider** — Routes through Perplexity's internal SSE API using a session cookie, giving native proxy access without separate API costs to GPT-5.4, Claude Opus, Gemini 3.1 Pro, and Nemotron via preferences mapping (#1289)
- **feat(api): Sync Tokens & V1 WebSocket Bridge** — Dedicated sync token storage, issuance, revocation, and bundle download routes backed by stable config bundle versioning with ETag support. Exposes `/v1/ws` WebSocket upgrade route and a custom Next.js server bridge (`scripts/v1-ws-bridge.mjs`) so OpenAI-compatible WebSocket traffic can be proxied through the gateway. Compliance auditing expanded with structured metadata, pagination, request context, auth/provider credential events, and SSRF-blocked validation logging. New migrations: `024_create_sync_tokens.sql`. New modules: `syncTokens.ts`, `src/lib/sync/bundle.ts`, `src/lib/sync/tokens.ts`, `src/lib/ws/handshake.ts`, `src/lib/apiBridgeServer.ts`, `src/lib/compliance/providerAudit.ts`.
- **feat(models): GLM Thinking Preset & Hybrid Token Counting** — GLM Thinking (`glmt`) registered as a first-class provider preset with shared GLM model metadata, pricing, per-connection usage sync, dashboard support, and `maxTokens: 65536 / thinkingBudgetTokens: 24576` request defaults with 900s extended timeout. Provider-side `/messages/count_tokens` endpoint used when a Claude-compatible upstream supports it; gracefully falls back to estimation on missing models, missing credentials, or upstream failures. Startup seeding of default model aliases (`src/lib/modelAliasSeed.ts`) normalizes common cross-proxy model dialects so canonical slash-based model IDs are not misrouted. New file `open-sse/config/glmProvider.ts`.
- **feat(core): Hardened Outbound Provider Calls & Cooldown Retries** — Guarded outbound fetch helpers (`src/shared/network/safeOutboundFetch.ts`, `src/shared/network/outboundUrlGuard.ts`) blocking private/local URLs with configurable retry, timeout normalisation, and route-level status propagation for provider validation and model discovery. Cooldown-aware chat retries (`src/sse/services/cooldownAwareRetry.ts`) with configurable `requestRetry` and `maxRetryIntervalSec` settings and model-scoped cooldown responses. Improved rate-limit learning from headers and error bodies so short upstream lockouts can recover automatically. Runtime environment validation (`src/lib/env/runtimeEnv.ts`) checks env at startup. Pollinations now requires an API key. Antigravity and Codex header handling aligned via `open-sse/config/antigravityUpstream.ts` and `open-sse/config/codexClient.ts`. Gemini tool names restored in translated responses; synthetic Claude text block injected when upstream SSE completes empty.
- **feat(logs):** Add TPS (Tokens Per Second) metric to log details modal metadata grid (#1182)
- **feat(memory+skills):** Full-featured Memory & Skills systems with FTS5 SQLite search, dynamic UI pagination, backend observability, and extensive test coverage (#1228)
- **feat(bailian-quota):** Add Alibaba Coding Plan quota monitoring, multi-window quota extraction, and UI credential validation (#1235)

### 🐛 Bug Fixes

- **fix(cli):** Resolve codex routing config parsing by strictly quoting section keys array, enforcing responses wire_api with fallback, and standardizing select-model button positioning mirroring Claude UI
- **fix(providers):** Correct Lobehub provider icons rendering by removing unsupported local references ensuring local SVG/PNG fallback mechanism invokes natively
- **fix(db):** Implement Database migration tracking safety abort safeguards (pre-migration backups via `VACUUM INTO` and mass renumbering warnings) to protect existing database structures on startup upgrades (#1281)
- **fix(dashboard):** Cleaned up target codex `config.toml` structure preventing recursive section rendering by enforcing quotes on section dot paths and mapping correct UI `OMNIROUTE_API_KEY` names.
- **fix(mcp):** Add dedicated explicit timeout constraint overrides for search handlers (#1280)
- **fix(crypto):** Add validation guard to encryption layer to surface clear UI errors when cryptographic environment variables are missing, replacing raw Node.js TypeErrors. Legacy env vars `OMNIROUTE_CRYPT_KEY` and `OMNIROUTE_API_KEY_BASE64` now also accepted as fallbacks (#1165)
- **fix(providers):** Update Pollinations provider definition to require API keys and specify their new limited pollen/hour free tier (#1177)
- **Streaming `\n\n` Artifact Fix (#1211):** Changed `<omniModel>` tag-stripping regex from `?` to `*` quantifier across `combo.ts`, `comboAgentMiddleware.ts`, and `contextHandoff.ts` to greedily strip all accumulated JSON-escaped newline sequences surrounding the tag. This prevents literal `\n\n` prefix artifacts from appearing in consumer streaming responses
- **E2E Combo Test Locator:** Fixed Playwright strict-mode violation in `combo-unification.spec.ts` by replacing ambiguous `getByRole` locator with a compound filter locator for the "All" strategy tab
- **fix(cc-compatible):** Trim beta flags and preserve cache passthrough for third-party HTTP proxy compatibility (#1230)
- **fix(providers):** Update Xiaomi MiMo endpoints to the live token-plan, migrating away from dead API URLs (#1238)
- **fix:** Forward client `x-initiator` header to GitHub Copilot upstream to accurately distinguish agent vs user turns (#1227)
- **fix:** Resolve backlog bugs including streaming edge cases, unhandled rejections, and quota parse failures (#1206, #1220, #1231, #1175, #1187, #1218, #1202)
- **fix(tests):** Resolve memory migration and skills route pagination bugs arising from PR overlaps
- **fix(i18n):** Add missing Chinese i18n support to dashboard components (`DataTable`, `EmptyState`, etc), update `en.json/zh-CN.json` routing keys, and natively resolve JSX defaults via `next-intl` (#1274)

### 🔧 Internal Improvements

- **Compliance Audit Expansion:** `src/lib/compliance/index.ts` expanded with structured metadata, pagination support, request context enrichment, and new `providerAudit.ts` module logging auth and provider credential events, SSRF-blocked validation attempts, and provider CRUD operations
- **Config Sync Bundle:** `src/lib/sync/bundle.ts` exports `buildConfigBundle()` generating a versioned JSON snapshot of settings, provider connections, nodes, model aliases, combos, and API keys (passwords redacted) with ETag support for bandwidth-efficient polling
- **Codex Client Constants:** Centralized `CODEX_CLIENT_VERSION`, `CODEX_USER_AGENT_PLATFORM`, and pattern-validated env overrides (`CODEX_CLIENT_VERSION`, `CODEX_USER_AGENT`) in `open-sse/config/codexClient.ts`
- **Antigravity Upstream Constants:** `open-sse/config/antigravityUpstream.ts` consolidates all Antigravity base URLs and model/fetchAvailableModels discovery path builders
- **Model Alias Seed:** `src/lib/modelAliasSeed.ts` seeds 30+ cross-proxy model dialect aliases (e.g. `openai/gpt-5` → `gpt-5`, `anthropic/claude-opus-4-6` → `cc/claude-opus-4-6`) at startup via idempotent `upsert`
- **Test Coverage:** 15+ new unit test suites covering sync routes, WebSocket bridge, compliance index, GLM provider config, cooldown-aware retry, safe outbound fetch, stream utilities, Codex executor, provider validation branches, model cross-proxy compatibility, and model alias seeding
- **TypeScript Migration:** Finalized migration of remaining JS tests (`proxy-load` and `testFromFile`) to TypeScript ES modules, ensuring a fully synchronized TS stack.
- **Reliability & Resilience:** Added exponential backoff to `models.dev` auto-sync to combat transient network failures, raised interval floor to 1 hour, and added LKGP debug logging for enhanced observability during routing. (#1286)

---

## [3.6.5] — 2026-04-13

### ✨ New Features
Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,7 +119,7 @@ Scopes: `db`, `sse`, `oauth`, `dashboard`, `api`, `cli`, `docker`, `ci`, `mcp`,
npm run test:all

# Single test file (Node.js native test runner — most tests use this)
node --import tsx/esm --test tests/unit/your-file.test.mjs
node --import tsx/esm --test tests/unit/your-file.test.ts

# Vitest (MCP server, autoCombo, cache)
npm run test:vitest
Expand Down
Loading