Skip to content

fix(providers): remove the chipotle/pepper provider (#13131) - #13913

Merged
diegosouzapw merged 3 commits into
release/v3.8.51from
fix/13131-remove-chipotle-provider
Sep 17, 2026
Merged

diegosouzapw merged 3 commits into
release/v3.8.51from
fix/13131-remove-chipotle-provider

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Closes #13131
Closes #4037

Root cause (short)

chipotle/pepper-1 is a reverse-engineered integration against Chipotle's public "Amelia"
customer-service chat widget (amelia.chipotle.com), not an official API. AmeliaClient.init()
(open-sse/executors/chipotle.ts) bootstraps a CSRF token/session cookie via
GET /Amelia/api/init before opening the SockJS/STOMP WebSocket. That endpoint — and every other
route on the host, including root / — now returns 404 from an Azure Application Gateway with
no backend route configured (verified live 2026-09-15). This is a regression from #4037
(June 2026, a WS handshake timeout) to a fully decommissioned backend: there is no protocol left
to fix.

Fix

Owner decision: retire the chipotle/pepper provider entirely (Option B), following the
phind/kluster quiet-removal precedent — not a docs/reference/REMOVED_PROVIDERS.md entry
(that page is reserved for operator-requested takedowns), just a one-line note under
docs/reference/FREE_TIERS.md → "Removed / no free tier".

Removed every surface (found via grep -rl chipotle src/ open-sse/ tests/ docs/ bin/, ~30
non-generated files after excluding the historical i18n CHANGELOG mirrors, which are left
untouched as a historical record):

  • open-sse/executors/chipotle.ts (deleted) + its registry entry
    open-sse/config/providers/registry/chipotle/index.ts (deleted)
  • Wiring: open-sse/config/providers/index.ts, open-sse/executors/index.ts
  • src/shared/constants/providers/noauth.ts (NOAUTH_PROVIDERS entry)
  • src/shared/components/ProviderIcon.tsx (GENERIC_PROVIDER_IDS entry)
  • open-sse/services/autoCombo/virtualFactory.ts (exclusion-list comment only — the actual
    AUTO_COMBO_NOAUTH_ALLOWLIST never listed chipotle)
  • open-sse/utils/error.ts (dropped the now-dead chipotle_error code from the public-error
    allowlist) + the matching fixture entry in
    tests/unit/fixtures/error-public-boundaries-hardening.fixture.ts
  • open-sse/utils/streamHandler.ts (comment)
  • docs/reference/PROVIDER_REFERENCE.md — regenerated (npm run gen:provider-reference)
  • docs/reference/API_REFERENCE.md, docs/reference/FREE_TIERS.md (new removal note)
  • Provider-count corrections (358, down from 359 after this removal): README.md,
    package.json description, and the 6 README-referenced SVGs that spell it out in visible
    <text>/aria-label (docs/diagrams/{readme-hero,promise-pillars,comparison-table,cli-terminal}.svg,
    public/images/tier-flow-{dark,light}.svg)
  • Dedicated test tests/unit/chipotle-executor.test.ts (deleted)
  • Golden snapshots tests/snapshots/executors/executor-map.json and
    tests/snapshots/provider/translate-path.json — regenerated (UPDATE_GOLDEN=1)

⚠️ Known, deliberate gap — AGENTS.md and llm.txt still say 359 providers. Both are on this
repo's explicit "never touch as a bug-fix worker" list (agent-instruction surfaces). Everywhere
else the live provider count (358, confirmed by check:provider-consistency) is now in sync;
npm run check:docs-counts is red on exactly these 2 files
(AGENTS.md does NOT mention "358" for providers, llm.txt does NOT mention "358" for providers)
as a direct, expected consequence of this PR. This needs a trivial one-number follow-up edit to
those two files by someone authorized to touch them — I did not make it in this PR.

Regression test

tests/unit/issue-13131-chipotle-provider-removed.test.ts — not a live-network repro (would be
flaky/slow/third-party-dependent in CI); it's the permanent guard that the provider is fully gone:

RED (unfixed code):
✖ issue #13131: chipotle executor is no longer registered
  actual: true, expected: false
✖ issue #13131: chipotle is no longer in the provider registry
  actual: true, expected: false
✖ issue #13131: chipotle is no longer in the noauth provider catalog
  actual: true, expected: false
✖ issue #13131: the chipotle executor module no longer exists
  AssertionError [ERR_ASSERTION]: Missing expected rejection.

GREEN (after removal):
✔ issue #13131: chipotle executor is no longer registered
✔ issue #13131: chipotle is no longer in the provider registry
✔ issue #13131: chipotle is no longer in the noauth provider catalog
✔ issue #13131: the chipotle executor module no longer exists
ℹ tests 4, pass 4, fail 0

Existing tests aligned

~15 existing tests used "chipotle" only as a generic example noAuth-provider id (proxy-scope
isolation #6272, error classification #6315, fallback-text classification #4976, free-provider
onboarding, #3200 imported-models, provider-icon generic-fallback inventories, autoCombo
allowlist-exclusion lists) — nothing chipotle-specific was under test in any of them. Re-pointed at
another still-existing noAuth provider (mostly cloudflare-playground, duckduckgo-web) rather
than weakening any assertion:

  • tests/unit/proxy-noauth-provider-6272.test.ts, tests/unit/errorClassifier-noauth-403-6315.test.ts,
    tests/unit/accountfallback-ratelimit-400-4976.test.ts,
    tests/unit/free-provider-onboarding-{selector,setup}.test.ts,
    tests/unit/noauth-provider-validation.test.ts, tests/unit/noauth-imported-models-3200.test.ts,
    tests/unit/base-executor-buildheaders-extra-keys-8493.test.ts (comment only)
  • tests/unit/noauth-autocombo-allowlist.test.ts, tests/unit/virtual-auto-combo.test.ts,
    tests/integration/combo-matrix/auto.test.ts — dropped chipotle from exclusion/blocklist arrays
    (it can no longer appear in the pool either way; these just stop asserting the absence of
    something that no longer exists)
  • tests/unit/ui/ProviderIcon-icon-url.test.tsx, tests/unit/provider-assets-generic-fallback.test.mjs
    — dropped chipotle from the "no local asset provenance" inventory (mirrors the
    GENERIC_PROVIDER_IDS change) and updated the hardcoded inventory-length assertions
    (79 → 78 both places)

Gates run

  • npx eslint --suppressions-location config/quality/eslint-suppressions.json <every changed file> — clean, 0 errors/warnings
  • npm run typecheck:core — 0 errors
  • npm run check:open-sse-typecheck — 0 errors (0 pre-existing, within frozen baseline)
  • node scripts/check/check-file-size.mjs — no new violations; the 4 pre-existing ✗ (src/sse/handlers/chatHelpers.ts, open-sse/handlers/imageGeneration.ts, open-sse/services/combo/roundRobinCombo.ts, open-sse/utils/stream.ts) are base-tip drift, none of them touched here
  • node scripts/check/check-complexity.mjs — OK, 2835 violations (baseline 3218)
  • node scripts/check/check-cognitive-complexity.mjs — OK, 1276 violations (baseline 1437)
  • node scripts/check/check-test-discovery.mjs — OK, new test file discovered
  • DATA_DIR=$(mktemp -d) npm run check:provider-consistency — OK, 358 canonical providers, 0 registry-only exceptions
  • npm run check:docs-sync, check:fabricated-docs, check:doc-links — all PASS
  • npm run check:docs-counts — 2 STRICT drifts remain: AGENTS.md/llm.txt still say 359 (see "Known, deliberate gap" above — both files are off-limits for this worker)
  • Regression test + ~90 related existing tests (autoCombo/noauth suites, onboarding, proxy scoping, error classification, provider-icon inventories, the integration auto.test.ts) — all green

⚠️ base-red inherited: #13866

Notes — the two flagged provider-count assertions

Both tests/unit/providers-constants-split.test.ts:70 and
tests/unit/provider-node-reserved-prefix.test.ts:185 were already red on the base tip
(241≠240, 414≠412) because of the agnes-cn provider added in #13399 — not this PR. Measured the
truth after this removal for each, as instructed:

  • providers-constants-split.test.ts (APIKEY_PROVIDERS family count) — still red, unaffected.
    chipotle was a NOAUTH_PROVIDERS entry, never an APIKEY_PROVIDERS one, so removing it cannot
    change this count. Measured after this PR: still 241 actual vs. 240 expected — pure agnes-cn
    drift (agnes-cn is authType: "apikey", regional family), left untouched here since fixing it
    is out of this issue's scope and the instruction was to record the measured truth, not silently
    bump an unrelated assertion.
  • provider-node-reserved-prefix.test.ts (open-sse REGISTRY id+alias walk) — now GREEN, and I
    documented why rather than leaving it unexplained.
    agnes-cn added REGISTRY id "agnes-cn" +
    alias "agnescn" (412 → 414, feat(providers): add Agnes AI (China) as agnes-cn on api.agnes-ai.cn #13399, not mine). This PR's chipotle removal drops REGISTRY
    id "chipotle" + alias "pepper" (414 → 412, this PR) — the two deltas net back to the
    existing 412 the test already asserts, so no numeric edit was needed; I added a one-line
    comment in the test recording both deltas so a future reader doesn't mistake the coincidence for
    an untracked drift.

amelia.chipotle.com (the reverse-engineered Amelia chat-widget backend
chipotle/pepper-1 talked to) now returns 404 on every route, including
root, from its Azure Application Gateway — confirmed live 2026-09-15.
This regressed from a WS handshake timeout (#4037, June 2026) to a
fully decommissioned host, so the upstream protocol cannot be fixed.
Owner decided to retire the provider entirely (Option B), following
the phind/kluster quiet-removal precedent: no REMOVED_PROVIDERS.md
entry (reserved for operator takedowns), just a one-line note under
FREE_TIERS.md "Removed / no free tier".

Removed every surface: executor, registry entry, executors/index.ts
and providers/index.ts wiring, noauth provider catalog entry,
ProviderIcon generic-fallback set, the autoCombo exclusion-list
comment, the chipotle_error code from the sanitizer allowlist,
PROVIDER_REFERENCE.md (regenerated), and every doc/test reference.

Regression test: tests/unit/issue-13131-chipotle-provider-removed.test.ts
asserts the provider is fully gone from the executor registry, the
provider REGISTRY and the noauth catalog, and that the executor module
no longer resolves — not a live-network repro (flaky/third-party).

Several existing tests used "chipotle" only as a generic noAuth-provider
example (proxy scoping, error classification, onboarding, fallback
text) with no chipotle-specific behavior under test; those were
re-pointed at another still-existing noAuth provider
(cloudflare-playground / duckduckgo-web) rather than weakened.
…3131)

provider-node-reserved-prefix.test.ts's REGISTRY id+alias walk was
already red on the base tip (414 vs. expected 412) from agnes-cn
(#13399, +id/+alias). Removing chipotle's REGISTRY id/alias in this
PR nets it back to 412, making the test pass again without a numeric
edit — record why in a comment so it doesn't read as an untracked
coincidence later.
# Conflicts:
#	tests/unit/provider-node-reserved-prefix.test.ts
@diegosouzapw
diegosouzapw merged commit b697553 into release/v3.8.51 Sep 17, 2026
7 of 11 checks passed
diegosouzapw added a commit that referenced this pull request Sep 17, 2026
The branch merged the release tip twice: the first pass carried a stale
origin/release/v3.8.51 that predated #13913, so every derived count was
computed against a provider that had already been retired.

Reconciled against the current tip:

- Provider count is 359 (tip 358 after the chipotle/pepper removal, plus
  xKiro). README, AGENTS.md, llm.txt and its 65 locale mirrors, package.json
  and the six count-bearing SVGs now carry that number; check:docs-counts
  passes with no strict drift.
- docs/reference/PROVIDER_REFERENCE.md regenerated from the live modules.
- RESERVED_PREFIX_COUNT 412 -> 413: xKiro registers id "xkiro" with no
  separate alias, so it adds exactly one REGISTRY member.
diegosouzapw added a commit that referenced this pull request Sep 17, 2026
Merge the current release tip into the security hardening branch and reconcile
57 conflicting files.

Most of this PR's original scope landed on the tip while it sat: #12506/#12945/
#13635 shipped a stricter public error boundary (allowlist-based
`isSafePublicErrorIdentifier`, `errorSanitization.ts`, `errorPathRedaction.ts`,
`upstreamErrorResponse.ts`), #12429 migrated the web-cookie TLS transport to
wreq-js, and #11754 retired the common ChatGPT Web executor. Those parts are
resolved to the tip, which is strictly more restrictive in every case, and the
now-dead tls-client provenance stream is dropped (the tip's
`tls-client-wreq-residue` guard forbids reintroducing `tls-client-node`).

What survives is the part the tip does not cover:

- chatCore reads rejection metadata through `getSafeErrorMetadata`, wraps
  `isLocalStreamLifecycleError`/`formatProviderError` so a hostile Proxy cannot
  escape the boundary, sanitizes the failure message before call logs and
  console, projects the failure-usage code through the bounded vocabulary, and
  sanitizes the upstream body before it reaches the persisted attempt logs.
- Perplexity's non-streaming quota/upstream error body sanitizes the upstream
  message and projects the provider-supplied code (`toPublicPerplexityErrorCode`).
- Arena (lmarena) maps every public failure onto a fixed vocabulary instead of
  echoing upstream text; `lmarena_stream_error` is registered in the public
  identifier allowlist.
- Notion keeps the tip's fail-closed transport (no plain-fetch proxy bypass) and
  sanitizes the transport error before the response body.
- `chatgptWebTools` returns a non-ok buffered response untouched.

Tests for superseded behaviour are dropped; the surviving contributions keep
their tests, split into `lmarena-public-error-boundary-11742` and
`perplexity-web-public-error-boundary-11742` to stay under the test size cap.

Prunes three now-stale eslint suppression entries: notion-web.ts no longer has
an unused var after this merge, and the two chipotle entries were left behind by
the tip's own provider removal (#13913).
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…) (diegosouzapw#13913)

* fix(providers): remove the chipotle/pepper provider (diegosouzapw#13131)

amelia.chipotle.com (the reverse-engineered Amelia chat-widget backend
chipotle/pepper-1 talked to) now returns 404 on every route, including
root, from its Azure Application Gateway — confirmed live 2026-09-15.
This regressed from a WS handshake timeout (diegosouzapw#4037, June 2026) to a
fully decommissioned host, so the upstream protocol cannot be fixed.
Owner decided to retire the provider entirely (Option B), following
the phind/kluster quiet-removal precedent: no REMOVED_PROVIDERS.md
entry (reserved for operator takedowns), just a one-line note under
FREE_TIERS.md "Removed / no free tier".

Removed every surface: executor, registry entry, executors/index.ts
and providers/index.ts wiring, noauth provider catalog entry,
ProviderIcon generic-fallback set, the autoCombo exclusion-list
comment, the chipotle_error code from the sanitizer allowlist,
PROVIDER_REFERENCE.md (regenerated), and every doc/test reference.

Regression test: tests/unit/issue-13131-chipotle-provider-removed.test.ts
asserts the provider is fully gone from the executor registry, the
provider REGISTRY and the noauth catalog, and that the executor module
no longer resolves — not a live-network repro (flaky/third-party).

Several existing tests used "chipotle" only as a generic noAuth-provider
example (proxy scoping, error classification, onboarding, fallback
text) with no chipotle-specific behavior under test; those were
re-pointed at another still-existing noAuth provider
(cloudflare-playground / duckduckgo-web) rather than weakened.

* test(providers): document the agnes-cn/chipotle count coincidence (diegosouzapw#13131)

provider-node-reserved-prefix.test.ts's REGISTRY id+alias walk was
already red on the base tip (414 vs. expected 412) from agnes-cn
(diegosouzapw#13399, +id/+alias). Removing chipotle's REGISTRY id/alias in this
PR nets it back to 412, making the test pass again without a numeric
edit — record why in a comment so it doesn't read as an untracked
coincidence later.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Chipotle pepper-1 not working [BUG] Multiple No-Auth AI Providers failing (Chipotle Pepper AI [502], DuckDuckGo [400])

1 participant