fix: address PR #3518 review comments (lifecycle hooks, regex, indentation, route params) - #3562
Conversation
…egex, indentation, route params) - Add try/catch around onDeactivate and onUninstall lifecycle hooks in manager.ts to prevent plugin bugs from bricking deactivation/uninstall - Remove redundant RegExp() wrappers around regex literals in accountFallback.ts (8 occurrences) - Fix indentation in requestLogger.ts (closing brace and appendBoundedChunk) - Use Next.js params.id instead of manual pathname parsing in logs route Addresses gemini-code-assist review comments on PR diegosouzapw#3518.
- Add onInstall/onActivate/onDeactivate/onUninstall to Plugin interface - Add lifecycle hook proxy methods in loader.ts that forward via callHook() IPC (same pattern as onRequest/onResponse/onError) - Lifecycle hooks are fire-and-forget: errors are logged but don't block deactivation/uninstall - Remove TODO comment — hooks are now functional for isolated plugins
There was a problem hiding this comment.
Code Review
This pull request refactors regex declarations in the account fallback service, fixes indentation in the request logger, and introduces lifecycle hooks (onInstall, onActivate, onDeactivate, onUninstall) to the plugin system. It also refactors the log retrieval route to use route parameters. However, because 'params' is asynchronous in Next.js 15, accessing 'params.id' directly will fail at runtime; you should await 'params' to resolve this issue.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
| try { | ||
| const url = new URL(req.url); | ||
| const id = url.pathname.split("/").pop(); | ||
| const id = params?.id; |
There was a problem hiding this comment.
In Next.js 15, params in route handlers is an asynchronous Promise. Accessing params?.id directly without awaiting it will evaluate to undefined at runtime, causing the API to fail with a 400 Missing id error.\n\nTo ensure compatibility with both Next.js 14 and Next.js 15, you should await params before accessing its properties.
| const id = params?.id; | |
| const id = (await params)?.id; |
|
Kilo Code Review could not run — your account is out of credits. Add credits or switch to a free model to enable reviews on this change. |
Awaiting params avoids undefined ID at runtime in Next.js 15.
Regression guard for the loader change in this PR: loadPlugin must build the plugin.onInstall/onActivate/onDeactivate/onUninstall methods when the manifest declares them (and skip undeclared ones), since manager.ts registers exactly those methods with emitHook. Without the wiring they were undefined and the lifecycle hooks were declared-but-dead. Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
|
Thanks @oyi77 — merged into The cleanups are solid (redundant I added one regression test on your branch ( Note: there's a separate pre-existing ordering quirk in |
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (#3554) (#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (#3537) (#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for #3560 thoughtSignature fix (#3414) The #3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original #3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (#3472) (#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (#3509) (#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (#3552) (#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (#3558) (#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (#3516) (#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule #12) (#3494, #3495) (#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (#3486, #3487) (#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (#3483) + docs(api): fix agent-bridge per-agent state route (#3489) (#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (#3497) (#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (#3508) (#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (#3505) (#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (#3506) (#3582) Integrated into release/v3.8.20 * docs(changelog): add the #3506 Kiro quota entry (missed in #3582 due to a stale-base CHANGELOG anchor) (#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR #3518 review comments (lifecycle hooks, regex, indentation, route params) (#3562) Integrated into release/v3.8.20. Addresses #3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule #18 regression test. * docs(changelog): credit @ViFigueiredo (#3423) for PROJECT_ROOT + log #3561/#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule #18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (diegosouzapw#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (diegosouzapw#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (diegosouzapw#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (diegosouzapw#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (diegosouzapw#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (diegosouzapw#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (diegosouzapw#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (diegosouzapw#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (diegosouzapw#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (diegosouzapw#3554) (diegosouzapw#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (diegosouzapw#3537) (diegosouzapw#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for diegosouzapw#3560 thoughtSignature fix (diegosouzapw#3414) The diegosouzapw#3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original diegosouzapw#3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (diegosouzapw#3472) (diegosouzapw#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (diegosouzapw#3509) (diegosouzapw#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (diegosouzapw#3552) (diegosouzapw#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (diegosouzapw#3558) (diegosouzapw#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (diegosouzapw#3516) (diegosouzapw#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule diegosouzapw#12) (diegosouzapw#3494, diegosouzapw#3495) (diegosouzapw#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (diegosouzapw#3486, diegosouzapw#3487) (diegosouzapw#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (diegosouzapw#3483) + docs(api): fix agent-bridge per-agent state route (diegosouzapw#3489) (diegosouzapw#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (diegosouzapw#3497) (diegosouzapw#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (diegosouzapw#3508) (diegosouzapw#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (diegosouzapw#3505) (diegosouzapw#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (diegosouzapw#3506) (diegosouzapw#3582) Integrated into release/v3.8.20 * docs(changelog): add the diegosouzapw#3506 Kiro quota entry (missed in diegosouzapw#3582 due to a stale-base CHANGELOG anchor) (diegosouzapw#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (diegosouzapw#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR diegosouzapw#3518 review comments (lifecycle hooks, regex, indentation, route params) (diegosouzapw#3562) Integrated into release/v3.8.20. Addresses diegosouzapw#3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule diegosouzapw#18 regression test. * docs(changelog): credit @ViFigueiredo (diegosouzapw#3423) for PROJECT_ROOT + log diegosouzapw#3561/diegosouzapw#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (diegosouzapw#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule diegosouzapw#18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (diegosouzapw#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (diegosouzapw#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
PR entries diegosouzapw#3560, diegosouzapw#3561, diegosouzapw#3562, diegosouzapw#3569 and Fable 5 feat appeared in both [Unreleased] and [3.8.20] sections after the merge. Merged into [3.8.20] which has the canonical entries with proper PR links.
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (diegosouzapw#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (diegosouzapw#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (diegosouzapw#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (diegosouzapw#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (diegosouzapw#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (diegosouzapw#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (diegosouzapw#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (diegosouzapw#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (diegosouzapw#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (diegosouzapw#3554) (diegosouzapw#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (diegosouzapw#3537) (diegosouzapw#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for diegosouzapw#3560 thoughtSignature fix (diegosouzapw#3414) The diegosouzapw#3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original diegosouzapw#3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (diegosouzapw#3472) (diegosouzapw#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (diegosouzapw#3509) (diegosouzapw#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (diegosouzapw#3552) (diegosouzapw#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (diegosouzapw#3558) (diegosouzapw#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (diegosouzapw#3516) (diegosouzapw#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule diegosouzapw#12) (diegosouzapw#3494, diegosouzapw#3495) (diegosouzapw#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (diegosouzapw#3486, diegosouzapw#3487) (diegosouzapw#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (diegosouzapw#3483) + docs(api): fix agent-bridge per-agent state route (diegosouzapw#3489) (diegosouzapw#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (diegosouzapw#3497) (diegosouzapw#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (diegosouzapw#3508) (diegosouzapw#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (diegosouzapw#3505) (diegosouzapw#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (diegosouzapw#3506) (diegosouzapw#3582) Integrated into release/v3.8.20 * docs(changelog): add the diegosouzapw#3506 Kiro quota entry (missed in diegosouzapw#3582 due to a stale-base CHANGELOG anchor) (diegosouzapw#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (diegosouzapw#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR diegosouzapw#3518 review comments (lifecycle hooks, regex, indentation, route params) (diegosouzapw#3562) Integrated into release/v3.8.20. Addresses diegosouzapw#3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule diegosouzapw#18 regression test. * docs(changelog): credit @ViFigueiredo (diegosouzapw#3423) for PROJECT_ROOT + log diegosouzapw#3561/diegosouzapw#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (diegosouzapw#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule diegosouzapw#18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (diegosouzapw#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (diegosouzapw#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (diegosouzapw#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (diegosouzapw#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (diegosouzapw#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (diegosouzapw#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (diegosouzapw#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (diegosouzapw#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (diegosouzapw#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (diegosouzapw#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (diegosouzapw#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (diegosouzapw#3554) (diegosouzapw#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (diegosouzapw#3537) (diegosouzapw#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for diegosouzapw#3560 thoughtSignature fix (diegosouzapw#3414) The diegosouzapw#3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original diegosouzapw#3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (diegosouzapw#3472) (diegosouzapw#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (diegosouzapw#3509) (diegosouzapw#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (diegosouzapw#3552) (diegosouzapw#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (diegosouzapw#3558) (diegosouzapw#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (diegosouzapw#3516) (diegosouzapw#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule diegosouzapw#12) (diegosouzapw#3494, diegosouzapw#3495) (diegosouzapw#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (diegosouzapw#3486, diegosouzapw#3487) (diegosouzapw#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (diegosouzapw#3483) + docs(api): fix agent-bridge per-agent state route (diegosouzapw#3489) (diegosouzapw#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (diegosouzapw#3497) (diegosouzapw#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (diegosouzapw#3508) (diegosouzapw#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (diegosouzapw#3505) (diegosouzapw#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (diegosouzapw#3506) (diegosouzapw#3582) Integrated into release/v3.8.20 * docs(changelog): add the diegosouzapw#3506 Kiro quota entry (missed in diegosouzapw#3582 due to a stale-base CHANGELOG anchor) (diegosouzapw#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (diegosouzapw#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR diegosouzapw#3518 review comments (lifecycle hooks, regex, indentation, route params) (diegosouzapw#3562) Integrated into release/v3.8.20. Addresses diegosouzapw#3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule diegosouzapw#18 regression test. * docs(changelog): credit @ViFigueiredo (diegosouzapw#3423) for PROJECT_ROOT + log diegosouzapw#3561/diegosouzapw#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (diegosouzapw#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule diegosouzapw#18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (diegosouzapw#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (diegosouzapw#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
…egex, indentation, route params) (diegosouzapw#3562) Integrated into release/v3.8.20. Addresses diegosouzapw#3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule diegosouzapw#18 regression test.
…_ROOT + log diegosouzapw#3561/diegosouzapw#3562 (v3.8.20)
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (diegosouzapw#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (diegosouzapw#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (diegosouzapw#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (diegosouzapw#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (diegosouzapw#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (diegosouzapw#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (diegosouzapw#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (diegosouzapw#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (diegosouzapw#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (diegosouzapw#3554) (diegosouzapw#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (diegosouzapw#3537) (diegosouzapw#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for diegosouzapw#3560 thoughtSignature fix (diegosouzapw#3414) The diegosouzapw#3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original diegosouzapw#3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (diegosouzapw#3472) (diegosouzapw#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (diegosouzapw#3509) (diegosouzapw#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (diegosouzapw#3552) (diegosouzapw#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (diegosouzapw#3558) (diegosouzapw#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (diegosouzapw#3516) (diegosouzapw#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule diegosouzapw#12) (diegosouzapw#3494, diegosouzapw#3495) (diegosouzapw#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (diegosouzapw#3486, diegosouzapw#3487) (diegosouzapw#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (diegosouzapw#3483) + docs(api): fix agent-bridge per-agent state route (diegosouzapw#3489) (diegosouzapw#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (diegosouzapw#3497) (diegosouzapw#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (diegosouzapw#3508) (diegosouzapw#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (diegosouzapw#3505) (diegosouzapw#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (diegosouzapw#3506) (diegosouzapw#3582) Integrated into release/v3.8.20 * docs(changelog): add the diegosouzapw#3506 Kiro quota entry (missed in diegosouzapw#3582 due to a stale-base CHANGELOG anchor) (diegosouzapw#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (diegosouzapw#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR diegosouzapw#3518 review comments (lifecycle hooks, regex, indentation, route params) (diegosouzapw#3562) Integrated into release/v3.8.20. Addresses diegosouzapw#3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule diegosouzapw#18 regression test. * docs(changelog): credit @ViFigueiredo (diegosouzapw#3423) for PROJECT_ROOT + log diegosouzapw#3561/diegosouzapw#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (diegosouzapw#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule diegosouzapw#18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (diegosouzapw#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (diegosouzapw#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
Summary
Re-submits the PR #3518 review-comment fixes as a focused 5-file PR per @diegosouzapw's review on #3525. The previous PR was 130+ files (i18n dump + unrelated incidental edits from a stale rebase) with the lifecycle hook forwarding change reverted. This PR is a clean 5-file change off current
release/v3.8.20.What's included (5 files, +45 / -15)
Plugin review fixes (2 files)
src/lib/plugins/manager.ts—onDeactivateandonUninstallnow wrapped in try/catch so a buggy plugin handler can't brick deactivation/uninstall. Redundant outer try/catch aroundemitHookwas removed (the loader's proxy method is the canonical one).src/lib/plugins/loader.ts— added lifecycle hook proxy methods (onInstall,onActivate,onDeactivate,onUninstall) that forward viacallHook()IPC, same pattern asonRequest/onResponse/onError. Lifecycle hooks are fire-and-forget: errors are logged but don't block deactivation/uninstall.src/lib/plugins/hooks.ts— added the four lifecycle hook methods to thePlugininterface.Other review fixes (3 files)
open-sse/services/accountFallback.ts— removed 8 redundantRegExp()wrappers around regex literals.open-sse/utils/requestLogger.ts— fixed indentation inappend()(6 spaces → 4).src/app/api/logs/[id]/route.ts— use Next.jsparamsfor dynamic route, instead of manualpathnameparsing.What's NOT included (per review)
docs/i18n/*/CHANGELOG.mddumppackage.json× 3 bumps from stale rebaseindex.ts150-line refactor with@deprecatedredirect (split out per maintainer request)chatCore/requestLogger/combo/providerunrelated changesVerification
npx tsx --test tests/unit/plugins-loader-ipc.test.ts tests/unit/plugins-loader.test.ts tests/unit/plugins-manager-lifecycle.test.ts tests/unit/plugins-manager.test.ts tests/unit/plugins-edge-cases.test.ts→ 95/95 pass (includingPlugin interface supports lifecycle hooks)npm run check:any-budget:t11→ PASSprettier --check→ all 5 files passplugins-loader-ipc.test.ts