fix(providers): remove the chipotle/pepper provider (#13131) - #13913
Merged
diegosouzapw merged 3 commits intoSep 17, 2026
Merged
Conversation
amelia.chipotle.com (the reverse-engineered Amelia chat-widget backend chipotle/pepper-1 talked to) now returns 404 on every route, including root, from its Azure Application Gateway — confirmed live 2026-09-15. This regressed from a WS handshake timeout (#4037, June 2026) to a fully decommissioned host, so the upstream protocol cannot be fixed. Owner decided to retire the provider entirely (Option B), following the phind/kluster quiet-removal precedent: no REMOVED_PROVIDERS.md entry (reserved for operator takedowns), just a one-line note under FREE_TIERS.md "Removed / no free tier". Removed every surface: executor, registry entry, executors/index.ts and providers/index.ts wiring, noauth provider catalog entry, ProviderIcon generic-fallback set, the autoCombo exclusion-list comment, the chipotle_error code from the sanitizer allowlist, PROVIDER_REFERENCE.md (regenerated), and every doc/test reference. Regression test: tests/unit/issue-13131-chipotle-provider-removed.test.ts asserts the provider is fully gone from the executor registry, the provider REGISTRY and the noauth catalog, and that the executor module no longer resolves — not a live-network repro (flaky/third-party). Several existing tests used "chipotle" only as a generic noAuth-provider example (proxy scoping, error classification, onboarding, fallback text) with no chipotle-specific behavior under test; those were re-pointed at another still-existing noAuth provider (cloudflare-playground / duckduckgo-web) rather than weakened.
…3131) provider-node-reserved-prefix.test.ts's REGISTRY id+alias walk was already red on the base tip (414 vs. expected 412) from agnes-cn (#13399, +id/+alias). Removing chipotle's REGISTRY id/alias in this PR nets it back to 412, making the test pass again without a numeric edit — record why in a comment so it doesn't read as an untracked coincidence later.
# Conflicts: # tests/unit/provider-node-reserved-prefix.test.ts
diegosouzapw
added a commit
that referenced
this pull request
Sep 17, 2026
The branch merged the release tip twice: the first pass carried a stale origin/release/v3.8.51 that predated #13913, so every derived count was computed against a provider that had already been retired. Reconciled against the current tip: - Provider count is 359 (tip 358 after the chipotle/pepper removal, plus xKiro). README, AGENTS.md, llm.txt and its 65 locale mirrors, package.json and the six count-bearing SVGs now carry that number; check:docs-counts passes with no strict drift. - docs/reference/PROVIDER_REFERENCE.md regenerated from the live modules. - RESERVED_PREFIX_COUNT 412 -> 413: xKiro registers id "xkiro" with no separate alias, so it adds exactly one REGISTRY member.
diegosouzapw
added a commit
that referenced
this pull request
Sep 17, 2026
Merge the current release tip into the security hardening branch and reconcile 57 conflicting files. Most of this PR's original scope landed on the tip while it sat: #12506/#12945/ #13635 shipped a stricter public error boundary (allowlist-based `isSafePublicErrorIdentifier`, `errorSanitization.ts`, `errorPathRedaction.ts`, `upstreamErrorResponse.ts`), #12429 migrated the web-cookie TLS transport to wreq-js, and #11754 retired the common ChatGPT Web executor. Those parts are resolved to the tip, which is strictly more restrictive in every case, and the now-dead tls-client provenance stream is dropped (the tip's `tls-client-wreq-residue` guard forbids reintroducing `tls-client-node`). What survives is the part the tip does not cover: - chatCore reads rejection metadata through `getSafeErrorMetadata`, wraps `isLocalStreamLifecycleError`/`formatProviderError` so a hostile Proxy cannot escape the boundary, sanitizes the failure message before call logs and console, projects the failure-usage code through the bounded vocabulary, and sanitizes the upstream body before it reaches the persisted attempt logs. - Perplexity's non-streaming quota/upstream error body sanitizes the upstream message and projects the provider-supplied code (`toPublicPerplexityErrorCode`). - Arena (lmarena) maps every public failure onto a fixed vocabulary instead of echoing upstream text; `lmarena_stream_error` is registered in the public identifier allowlist. - Notion keeps the tip's fail-closed transport (no plain-fetch proxy bypass) and sanitizes the transport error before the response body. - `chatgptWebTools` returns a non-ok buffered response untouched. Tests for superseded behaviour are dropped; the surviving contributions keep their tests, split into `lmarena-public-error-boundary-11742` and `perplexity-web-public-error-boundary-11742` to stay under the test size cap. Prunes three now-stale eslint suppression entries: notion-web.ts no longer has an unused var after this merge, and the two chipotle entries were left behind by the tip's own provider removal (#13913).
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…) (diegosouzapw#13913) * fix(providers): remove the chipotle/pepper provider (diegosouzapw#13131) amelia.chipotle.com (the reverse-engineered Amelia chat-widget backend chipotle/pepper-1 talked to) now returns 404 on every route, including root, from its Azure Application Gateway — confirmed live 2026-09-15. This regressed from a WS handshake timeout (diegosouzapw#4037, June 2026) to a fully decommissioned host, so the upstream protocol cannot be fixed. Owner decided to retire the provider entirely (Option B), following the phind/kluster quiet-removal precedent: no REMOVED_PROVIDERS.md entry (reserved for operator takedowns), just a one-line note under FREE_TIERS.md "Removed / no free tier". Removed every surface: executor, registry entry, executors/index.ts and providers/index.ts wiring, noauth provider catalog entry, ProviderIcon generic-fallback set, the autoCombo exclusion-list comment, the chipotle_error code from the sanitizer allowlist, PROVIDER_REFERENCE.md (regenerated), and every doc/test reference. Regression test: tests/unit/issue-13131-chipotle-provider-removed.test.ts asserts the provider is fully gone from the executor registry, the provider REGISTRY and the noauth catalog, and that the executor module no longer resolves — not a live-network repro (flaky/third-party). Several existing tests used "chipotle" only as a generic noAuth-provider example (proxy scoping, error classification, onboarding, fallback text) with no chipotle-specific behavior under test; those were re-pointed at another still-existing noAuth provider (cloudflare-playground / duckduckgo-web) rather than weakened. * test(providers): document the agnes-cn/chipotle count coincidence (diegosouzapw#13131) provider-node-reserved-prefix.test.ts's REGISTRY id+alias walk was already red on the base tip (414 vs. expected 412) from agnes-cn (diegosouzapw#13399, +id/+alias). Removing chipotle's REGISTRY id/alias in this PR nets it back to 412, making the test pass again without a numeric edit — record why in a comment so it doesn't read as an untracked coincidence later.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #13131
Closes #4037
Root cause (short)
chipotle/pepper-1is a reverse-engineered integration against Chipotle's public "Amelia"customer-service chat widget (
amelia.chipotle.com), not an official API.AmeliaClient.init()(
open-sse/executors/chipotle.ts) bootstraps a CSRF token/session cookie viaGET /Amelia/api/initbefore opening the SockJS/STOMP WebSocket. That endpoint — and every otherroute on the host, including root
/— now returns404from an Azure Application Gateway withno backend route configured (verified live 2026-09-15). This is a regression from #4037
(June 2026, a WS handshake timeout) to a fully decommissioned backend: there is no protocol left
to fix.
Fix
Owner decision: retire the
chipotle/pepperprovider entirely (Option B), following thephind/klusterquiet-removal precedent — not adocs/reference/REMOVED_PROVIDERS.mdentry(that page is reserved for operator-requested takedowns), just a one-line note under
docs/reference/FREE_TIERS.md→ "Removed / no free tier".Removed every surface (found via
grep -rl chipotle src/ open-sse/ tests/ docs/ bin/, ~30non-generated files after excluding the historical i18n CHANGELOG mirrors, which are left
untouched as a historical record):
open-sse/executors/chipotle.ts(deleted) + its registry entryopen-sse/config/providers/registry/chipotle/index.ts(deleted)open-sse/config/providers/index.ts,open-sse/executors/index.tssrc/shared/constants/providers/noauth.ts(NOAUTH_PROVIDERS entry)src/shared/components/ProviderIcon.tsx(GENERIC_PROVIDER_IDS entry)open-sse/services/autoCombo/virtualFactory.ts(exclusion-list comment only — the actualAUTO_COMBO_NOAUTH_ALLOWLISTnever listed chipotle)open-sse/utils/error.ts(dropped the now-deadchipotle_errorcode from the public-errorallowlist) + the matching fixture entry in
tests/unit/fixtures/error-public-boundaries-hardening.fixture.tsopen-sse/utils/streamHandler.ts(comment)docs/reference/PROVIDER_REFERENCE.md— regenerated (npm run gen:provider-reference)docs/reference/API_REFERENCE.md,docs/reference/FREE_TIERS.md(new removal note)README.md,package.jsondescription, and the 6 README-referenced SVGs that spell it out in visible<text>/aria-label(docs/diagrams/{readme-hero,promise-pillars,comparison-table,cli-terminal}.svg,public/images/tier-flow-{dark,light}.svg)tests/unit/chipotle-executor.test.ts(deleted)tests/snapshots/executors/executor-map.jsonandtests/snapshots/provider/translate-path.json— regenerated (UPDATE_GOLDEN=1)AGENTS.mdandllm.txtstill say 359 providers. Both are on thisrepo's explicit "never touch as a bug-fix worker" list (agent-instruction surfaces). Everywhere
else the live provider count (
358, confirmed bycheck:provider-consistency) is now in sync;npm run check:docs-countsis red on exactly these 2 files(
AGENTS.md does NOT mention "358" for providers,llm.txt does NOT mention "358" for providers)as a direct, expected consequence of this PR. This needs a trivial one-number follow-up edit to
those two files by someone authorized to touch them — I did not make it in this PR.
Regression test
tests/unit/issue-13131-chipotle-provider-removed.test.ts— not a live-network repro (would beflaky/slow/third-party-dependent in CI); it's the permanent guard that the provider is fully gone:
Existing tests aligned
~15 existing tests used
"chipotle"only as a generic example noAuth-provider id (proxy-scopeisolation
#6272, error classification#6315, fallback-text classification#4976, free-provideronboarding,
#3200imported-models, provider-icon generic-fallback inventories, autoComboallowlist-exclusion lists) — nothing chipotle-specific was under test in any of them. Re-pointed at
another still-existing noAuth provider (mostly
cloudflare-playground,duckduckgo-web) ratherthan weakening any assertion:
tests/unit/proxy-noauth-provider-6272.test.ts,tests/unit/errorClassifier-noauth-403-6315.test.ts,tests/unit/accountfallback-ratelimit-400-4976.test.ts,tests/unit/free-provider-onboarding-{selector,setup}.test.ts,tests/unit/noauth-provider-validation.test.ts,tests/unit/noauth-imported-models-3200.test.ts,tests/unit/base-executor-buildheaders-extra-keys-8493.test.ts(comment only)tests/unit/noauth-autocombo-allowlist.test.ts,tests/unit/virtual-auto-combo.test.ts,tests/integration/combo-matrix/auto.test.ts— dropped chipotle from exclusion/blocklist arrays(it can no longer appear in the pool either way; these just stop asserting the absence of
something that no longer exists)
tests/unit/ui/ProviderIcon-icon-url.test.tsx,tests/unit/provider-assets-generic-fallback.test.mjs— dropped chipotle from the "no local asset provenance" inventory (mirrors the
GENERIC_PROVIDER_IDSchange) and updated the hardcoded inventory-length assertions(79 → 78 both places)
Gates run
npx eslint --suppressions-location config/quality/eslint-suppressions.json <every changed file>— clean, 0 errors/warningsnpm run typecheck:core— 0 errorsnpm run check:open-sse-typecheck— 0 errors (0 pre-existing, within frozen baseline)node scripts/check/check-file-size.mjs— no new violations; the 4 pre-existing ✗ (src/sse/handlers/chatHelpers.ts,open-sse/handlers/imageGeneration.ts,open-sse/services/combo/roundRobinCombo.ts,open-sse/utils/stream.ts) are base-tip drift, none of them touched herenode scripts/check/check-complexity.mjs— OK, 2835 violations (baseline 3218)node scripts/check/check-cognitive-complexity.mjs— OK, 1276 violations (baseline 1437)node scripts/check/check-test-discovery.mjs— OK, new test file discoveredDATA_DIR=$(mktemp -d) npm run check:provider-consistency— OK, 358 canonical providers, 0 registry-only exceptionsnpm run check:docs-sync,check:fabricated-docs,check:doc-links— all PASSnpm run check:docs-counts— 2 STRICT drifts remain:AGENTS.md/llm.txtstill say 359 (see "Known, deliberate gap" above — both files are off-limits for this worker)auto.test.ts) — all greenNotes — the two flagged provider-count assertions
Both
tests/unit/providers-constants-split.test.ts:70andtests/unit/provider-node-reserved-prefix.test.ts:185were already red on the base tip(241≠240, 414≠412) because of the
agnes-cnprovider added in #13399 — not this PR. Measured thetruth after this removal for each, as instructed:
providers-constants-split.test.ts(APIKEY_PROVIDERS family count) — still red, unaffected.chipotlewas aNOAUTH_PROVIDERSentry, never anAPIKEY_PROVIDERSone, so removing it cannotchange this count. Measured after this PR: still 241 actual vs. 240 expected — pure
agnes-cndrift (
agnes-cnisauthType: "apikey",regionalfamily), left untouched here since fixing itis out of this issue's scope and the instruction was to record the measured truth, not silently
bump an unrelated assertion.
provider-node-reserved-prefix.test.ts(open-sse REGISTRY id+alias walk) — now GREEN, and Idocumented why rather than leaving it unexplained.
agnes-cnadded REGISTRY id"agnes-cn"+alias
"agnescn"(412 → 414, feat(providers): add Agnes AI (China) as agnes-cn on api.agnes-ai.cn #13399, not mine). This PR'schipotleremoval drops REGISTRYid
"chipotle"+ alias"pepper"(414 → 412, this PR) — the two deltas net back to theexisting
412the test already asserts, so no numeric edit was needed; I added a one-linecomment in the test recording both deltas so a future reader doesn't mistake the coincidence for
an untracked drift.