Repository navigation
Conversation
…ouzapw#16004) Upstream already removed token_ledger from RESET_TARGETS; this adds the missing regression coverage: a ledger row must survive resetUsageHistory('all') and deletedTokenLedger must stay 0.
…iegosouzapw#15930) encrypt() stores enc:v1:-prefixed values verbatim, so a ciphertext blob produced by another tool or under a different STORAGE_ENCRYPTION_KEY persisted undecryptable and failed on first use. POST /api/providers and PATCH /api/providers/[id] now 400 any enc:v1: apiKey this deployment cannot decrypt; envelopes still decryptable stay allowed. Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
…gosouzapw#15928) Generated omniroute api commands sent the literal '{id}' placeholder and accepted no argument for it. The generator was already fixed to emit --id + url.replace(); this regenerates bin/cli/api-commands/*.mjs. Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
…iegosouzapw#15665) The omniroute-* capability/CLI skills were aggregated into the omni-* and cli-* sets; omni-auth, cli-serve, cli-providers and cli-eval still linked to the old 404 paths. Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
…souzapw#14574) The root docs and mirrors are now in sync, but the gate still only checked README.md/AGENTS.md/llm.txt — mirrors drifted undetected before. check-docs-counts-sync now validates every docs/i18n/*/README.md that carries a claim, with a localisation-tolerant extractor (numeral adjacent to the 'migrat' stem).
A pt- PAT (or QODER_PERSONAL_ACCESS_TOKEN) spawns the local qodercli per request: no tool calling, no streaming, 45s cap — useless for agent clients. Point users at OAuth or an API key for those paths. Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
6612c13 to
27468d7
Compare
|
@diegosouzapw PR rebaseado em Notas rápidas do rebase: a base já trouxe as correções de #16004 ( Ficamos à disposição se precisar de ajuste em qualquer commit. |
|
Thanks @afonsoft for putting this together. I'm closing it because nearly all of it has already landed on
One more note: every commit here is authored by the Devin AI bot account, and this repo doesn't accept AI/bot authorship metadata in commits (Hard Rule #16 in AGENTS.md). For future PRs, please commit under your own identity. Thanks again, and the link fix will carry your credit. |
…6109) Follow-up to #15676 (thanks @Poid-ZA) carrying the CLI-table remaps from #16016 (credited to @afonsoft via Co-authored-by). Every `skills/<dir>/SKILL.md` reference inside the skills now resolves, enforced by a new check in skillManifestsLint.test.ts (4/4; fails with the fix reverted). Cloud-agent rows stay on cli-backup-sync, because the skill generator assigns the `omniroute cloud` command group there (cliRegistryParser.ts:78). Protected surface (skills/**/SKILL.md) approved by the owner. check:docs-all's only red is the inherited provider-count drift, fixed by #15799.
Summary
Correções simples de issues abertas, rebaseado em
release/v3.8.52(977d006). Um commit por issue:enc:v1:estrangeiro salvo verbatim (fix(security): credentials that already carry theenc:v1:prefix are stored verbatim — foreign ciphertext fails later as a confusing "Missing API key" #15930) —encrypt()pula valores já prefixados, então um blob cifrado por outra tool/outra key persistia sem nunca decriptar.POST /api/providersePATCH /api/providers/[id]agora devolvem 400 paraapiKeycom prefixoenc:v1:que este deploy não consegue decriptar; envelope ainda decriptável continua permitido.omniroute apienviava{id}literal (fix(cli): generatedomniroute apicommands never substitute{id}path params — every get/patch/delete/test-by-id command is broken #15928) — os comandos gerados não substituíam path params. O gerador já emitia--id+url.replaceAll();bin/cli/api-commands/*.mjsfoi regenerado (npm run build:cli-api).omni-auth,cli-serve,cli-providersecli-evalapontavam paraskills/omniroute-*/SKILL.md(migrados para os conjuntosomni-*/cli-*). Links repontados para os skills atuais.skill:custom-*— sobrevivem à regeração, mas podem precisar de aprovação do operador por serem superfície de instrução de agente.pt-*spawnaqoderclilocal por request: sem tool calling, sem streaming, cap de 45s — inútil para clientes agentes. Nota no PROVIDERS-GUIDE apontando OAuth/API key.token_ledgersobrevive ao reset de uso (fix(backend): preserve token balances when resetting usage data #16004) e o gatecheck-docs-countsagora valida TODOdocs/i18n/*/README.mdque carregue a contagem de migrations (extrator tolerante à tradução, radicalmigrat) — o drift de docs: 65 README mirrors still say 178 migrations, and the docs-counts gate does not cover them #14574 não volta.Related Issues
enc:v1:prefix are stored verbatim — foreign ciphertext fails later as a confusing "Missing API key" #15930, fix(cli): generatedomniroute apicommands never substitute{id}path params — every get/patch/delete/test-by-id command is broken #15928, [bug] skills/omni-auth and cli-providers link to skills/omniroute-*/SKILL.md that no longer exist (404) #15665, docs(providers): Qoder PAT path has no tool calling, no streaming and a 45s cap — undocumented, breaks agent combos (499) #13697Prepare isolated runtime state), 🔴 Release branch not green: release/v3.8.52 #15306 (base-red herdado)Validation
tests/unit/usage-history-reset.test.ts(3/3, incl. novo casotoken_ledger survives 'all'),tests/unit/providers-enc-v1-guard.test.ts(3/3, novo)npm run lint(eslint nos arquivos alterados — limpo)release/v3.8.52(977d006)check-docs-counts-sync.mjs: 0 STRICT drift; mirrors cobertoscheck-api-typecheck.mjs: 272 erros, todos dentro do baseline (rebaixado em 9 mortos)Tests Added Or Updated
tests/unit/usage-history-reset.test.ts— novo caso:token_ledgersobrevive ao reset'all'.tests/unit/providers-enc-v1-guard.test.ts— novo arquivo: guardenc:v1:no POST/PATCH + invariante doencrypt().Coverage Notes
src/app/api/providers*/route.ts: guard coberto por teste de fonte + invariante noproviders-enc-v1-guard.test.ts.tests/escripts/check/: nova cobertura de regressão.Reviewer Notes
bin/cli/api-commands/*.mjsé 100% gerado — revisar o diff do gerador, não os arquivos.RESET_TARGETS, docs: 65 README mirrors still say 178 migrations, and the docs-counts gate does not cover them #14574 nos mirrors, fix(ci): nightly Schemathesis job fuzzes a server that never starts #15988 no workflow); ficaram só a cobertura de teste e a extensão do gate que faltavam.