fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (#3508) - #3579
Conversation
…not build-time NEXT_PUBLIC (#3508)
There was a problem hiding this comment.
Code Review
This pull request updates the SOCKS5 proxy option to follow the runtime ENABLE_SOCKS5_PROXY environment variable instead of the build-time NEXT_PUBLIC_ENABLE_SOCKS5_PROXY variable, ensuring that prebuilt Docker images respect runtime configuration. It exposes socks5Enabled via the proxy settings API and dynamically determines the available proxy types in the UI. Feedback on the changes includes a recommendation to return a copy of the proxy types array to prevent potential shared mutation, and a request to rewrite the newly added unit tests using Vitest instead of the native Node.js test runner to align with the repository's style guide.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
| export function buildProxyTypes(socks5Enabled: boolean) { | ||
| return socks5Enabled ? ALL_PROXY_TYPES : ALL_PROXY_TYPES.filter((type) => type.value !== "socks5"); | ||
| } |
There was a problem hiding this comment.
Returning ALL_PROXY_TYPES directly when socks5Enabled is true exposes the module-level constant to potential mutation by callers. To prevent accidental shared mutation, return a new array copy (e.g., using the spread operator).
| export function buildProxyTypes(socks5Enabled: boolean) { | |
| return socks5Enabled ? ALL_PROXY_TYPES : ALL_PROXY_TYPES.filter((type) => type.value !== "socks5"); | |
| } | |
| export function buildProxyTypes(socks5Enabled: boolean) { | |
| return socks5Enabled ? [...ALL_PROXY_TYPES] : ALL_PROXY_TYPES.filter((type) => type.value !== "socks5"); | |
| } |
| import { describe, it } from "node:test"; | ||
| import assert from "node:assert/strict"; | ||
| import { buildProxyTypes } from "../../src/shared/components/ProxyConfigModal.tsx"; | ||
|
|
||
| describe("buildProxyTypes — #3508 runtime socks5 flag", () => { | ||
| it("includes socks5 when socks5Enabled is true", () => { | ||
| const types = buildProxyTypes(true); | ||
| const values = types.map((t) => t.value); | ||
| assert.ok(values.includes("socks5"), "socks5 should be present when enabled"); | ||
| assert.ok(values.includes("http"), "http should always be present"); | ||
| assert.ok(values.includes("https"), "https should always be present"); | ||
| }); | ||
|
|
||
| it("excludes socks5 when socks5Enabled is false", () => { | ||
| const types = buildProxyTypes(false); | ||
| const values = types.map((t) => t.value); | ||
| assert.ok(!values.includes("socks5"), "socks5 should be absent when disabled"); | ||
| assert.ok(values.includes("http"), "http should always be present"); | ||
| assert.ok(values.includes("https"), "https should always be present"); | ||
| }); | ||
|
|
||
| it("returns a new array each call (no shared mutation)", () => { | ||
| const a = buildProxyTypes(true); | ||
| const b = buildProxyTypes(false); | ||
| assert.notStrictEqual(a, b); | ||
| assert.equal(a.length, 3); | ||
| assert.equal(b.length, 2); | ||
| }); | ||
| }); |
There was a problem hiding this comment.
To maintain consistency with the repository's standard testing framework (Vitest) and ensure proper integration with test execution and coverage reporting, please use vitest instead of the native Node.js node:test runner and assert module. Also, omit the .tsx extension in the import to follow standard TypeScript module resolution. Finally, update the mutation test to compare two calls with true to verify that a new array reference is indeed returned each time.
import { describe, it, expect } from "vitest";
import { buildProxyTypes } from "../../src/shared/components/ProxyConfigModal";
describe("buildProxyTypes — #3508 runtime socks5 flag", () => {
it("includes socks5 when socks5Enabled is true", () => {
const types = buildProxyTypes(true);
const values = types.map((t) => t.value);
expect(values).toContain("socks5");
expect(values).toContain("http");
expect(values).toContain("https");
});
it("excludes socks5 when socks5Enabled is false", () => {
const types = buildProxyTypes(false);
const values = types.map((t) => t.value);
expect(values).not.toContain("socks5");
expect(values).toContain("http");
expect(values).toContain("https");
});
it("returns a new array each call (no shared mutation)", () => {
const a = buildProxyTypes(true);
const b = buildProxyTypes(true);
expect(a).not.toBe(b);
expect(a).toHaveLength(3);
expect(b).toHaveLength(3);
});
});References
- The repository style guide specifies Vitest as the standard testing framework (referencing 'Vitest files' and 'vitest.config.ts'). Tests should use Vitest instead of the native Node.js test runner for consistency. (link)
|
Kilo Code Review could not run — your account is out of credits. Add credits or switch to a free model to enable reviews on this change. |
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (#3554) (#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (#3537) (#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for #3560 thoughtSignature fix (#3414) The #3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original #3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (#3472) (#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (#3509) (#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (#3552) (#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (#3558) (#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (#3516) (#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule #12) (#3494, #3495) (#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (#3486, #3487) (#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (#3483) + docs(api): fix agent-bridge per-agent state route (#3489) (#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (#3497) (#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (#3508) (#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (#3505) (#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (#3506) (#3582) Integrated into release/v3.8.20 * docs(changelog): add the #3506 Kiro quota entry (missed in #3582 due to a stale-base CHANGELOG anchor) (#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR #3518 review comments (lifecycle hooks, regex, indentation, route params) (#3562) Integrated into release/v3.8.20. Addresses #3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule #18 regression test. * docs(changelog): credit @ViFigueiredo (#3423) for PROJECT_ROOT + log #3561/#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule #18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (diegosouzapw#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (diegosouzapw#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (diegosouzapw#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (diegosouzapw#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (diegosouzapw#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (diegosouzapw#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (diegosouzapw#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (diegosouzapw#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (diegosouzapw#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (diegosouzapw#3554) (diegosouzapw#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (diegosouzapw#3537) (diegosouzapw#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for diegosouzapw#3560 thoughtSignature fix (diegosouzapw#3414) The diegosouzapw#3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original diegosouzapw#3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (diegosouzapw#3472) (diegosouzapw#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (diegosouzapw#3509) (diegosouzapw#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (diegosouzapw#3552) (diegosouzapw#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (diegosouzapw#3558) (diegosouzapw#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (diegosouzapw#3516) (diegosouzapw#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule diegosouzapw#12) (diegosouzapw#3494, diegosouzapw#3495) (diegosouzapw#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (diegosouzapw#3486, diegosouzapw#3487) (diegosouzapw#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (diegosouzapw#3483) + docs(api): fix agent-bridge per-agent state route (diegosouzapw#3489) (diegosouzapw#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (diegosouzapw#3497) (diegosouzapw#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (diegosouzapw#3508) (diegosouzapw#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (diegosouzapw#3505) (diegosouzapw#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (diegosouzapw#3506) (diegosouzapw#3582) Integrated into release/v3.8.20 * docs(changelog): add the diegosouzapw#3506 Kiro quota entry (missed in diegosouzapw#3582 due to a stale-base CHANGELOG anchor) (diegosouzapw#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (diegosouzapw#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR diegosouzapw#3518 review comments (lifecycle hooks, regex, indentation, route params) (diegosouzapw#3562) Integrated into release/v3.8.20. Addresses diegosouzapw#3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule diegosouzapw#18 regression test. * docs(changelog): credit @ViFigueiredo (diegosouzapw#3423) for PROJECT_ROOT + log diegosouzapw#3561/diegosouzapw#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (diegosouzapw#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule diegosouzapw#18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (diegosouzapw#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (diegosouzapw#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (diegosouzapw#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (diegosouzapw#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (diegosouzapw#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (diegosouzapw#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (diegosouzapw#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (diegosouzapw#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (diegosouzapw#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (diegosouzapw#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (diegosouzapw#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (diegosouzapw#3554) (diegosouzapw#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (diegosouzapw#3537) (diegosouzapw#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for diegosouzapw#3560 thoughtSignature fix (diegosouzapw#3414) The diegosouzapw#3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original diegosouzapw#3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (diegosouzapw#3472) (diegosouzapw#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (diegosouzapw#3509) (diegosouzapw#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (diegosouzapw#3552) (diegosouzapw#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (diegosouzapw#3558) (diegosouzapw#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (diegosouzapw#3516) (diegosouzapw#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule diegosouzapw#12) (diegosouzapw#3494, diegosouzapw#3495) (diegosouzapw#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (diegosouzapw#3486, diegosouzapw#3487) (diegosouzapw#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (diegosouzapw#3483) + docs(api): fix agent-bridge per-agent state route (diegosouzapw#3489) (diegosouzapw#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (diegosouzapw#3497) (diegosouzapw#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (diegosouzapw#3508) (diegosouzapw#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (diegosouzapw#3505) (diegosouzapw#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (diegosouzapw#3506) (diegosouzapw#3582) Integrated into release/v3.8.20 * docs(changelog): add the diegosouzapw#3506 Kiro quota entry (missed in diegosouzapw#3582 due to a stale-base CHANGELOG anchor) (diegosouzapw#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (diegosouzapw#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR diegosouzapw#3518 review comments (lifecycle hooks, regex, indentation, route params) (diegosouzapw#3562) Integrated into release/v3.8.20. Addresses diegosouzapw#3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule diegosouzapw#18 regression test. * docs(changelog): credit @ViFigueiredo (diegosouzapw#3423) for PROJECT_ROOT + log diegosouzapw#3561/diegosouzapw#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (diegosouzapw#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule diegosouzapw#18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (diegosouzapw#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (diegosouzapw#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (diegosouzapw#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (diegosouzapw#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (diegosouzapw#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (diegosouzapw#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (diegosouzapw#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (diegosouzapw#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (diegosouzapw#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (diegosouzapw#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (diegosouzapw#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (diegosouzapw#3554) (diegosouzapw#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (diegosouzapw#3537) (diegosouzapw#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for diegosouzapw#3560 thoughtSignature fix (diegosouzapw#3414) The diegosouzapw#3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original diegosouzapw#3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (diegosouzapw#3472) (diegosouzapw#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (diegosouzapw#3509) (diegosouzapw#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (diegosouzapw#3552) (diegosouzapw#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (diegosouzapw#3558) (diegosouzapw#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (diegosouzapw#3516) (diegosouzapw#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule diegosouzapw#12) (diegosouzapw#3494, diegosouzapw#3495) (diegosouzapw#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (diegosouzapw#3486, diegosouzapw#3487) (diegosouzapw#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (diegosouzapw#3483) + docs(api): fix agent-bridge per-agent state route (diegosouzapw#3489) (diegosouzapw#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (diegosouzapw#3497) (diegosouzapw#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (diegosouzapw#3508) (diegosouzapw#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (diegosouzapw#3505) (diegosouzapw#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (diegosouzapw#3506) (diegosouzapw#3582) Integrated into release/v3.8.20 * docs(changelog): add the diegosouzapw#3506 Kiro quota entry (missed in diegosouzapw#3582 due to a stale-base CHANGELOG anchor) (diegosouzapw#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (diegosouzapw#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR diegosouzapw#3518 review comments (lifecycle hooks, regex, indentation, route params) (diegosouzapw#3562) Integrated into release/v3.8.20. Addresses diegosouzapw#3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule diegosouzapw#18 regression test. * docs(changelog): credit @ViFigueiredo (diegosouzapw#3423) for PROJECT_ROOT + log diegosouzapw#3561/diegosouzapw#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (diegosouzapw#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule diegosouzapw#18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (diegosouzapw#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (diegosouzapw#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
…not build-time NEXT_PUBLIC (diegosouzapw#3508) (diegosouzapw#3579) Integrated into release/v3.8.20
* chore(release): open v3.8.20 development cycle * fix(images): prefer bare combos over image aliases (diegosouzapw#3527) Integrated into release/v3.8.20 * fix(translator): map Codex local_shell tool (diegosouzapw#3534) Integrated into release/v3.8.20 * fix(usage): make opencode-go quota fetcher fail-open instead of throwing 500 (diegosouzapw#3522) Integrated into release/v3.8.20 * Fix Runtime page breaker state rendering (diegosouzapw#3533) Integrated into release/v3.8.20 * Expose provider breaker degradation threshold setting (diegosouzapw#3535) Integrated into release/v3.8.20 * fix(executor): strip provider prefix from versioned built-in tool model field (diegosouzapw#3532) Integrated into release/v3.8.20 * feat(providers): add Claude Fable 5 support (diegosouzapw#3524) Integrated into release/v3.8.20 * feat(resilience): add global provider cooldown tracking to prevent combo re-walking (diegosouzapw#3556) Integrated into release/v3.8.20 (default OFF, opt-in) * fix(translator): scope thoughtSignature bypass to Antigravity/CLI only (diegosouzapw#3560) Integrated into release/v3.8.20. Co-authored-by: Six7Day <six7day@gmail.com> * fix(routing): normalize thinking:disabled for combo-substituted models that reject it (diegosouzapw#3554) (diegosouzapw#3563) Integrated into release/v3.8.20 * fix(usage): accept 0/empty budget limits so the dashboard can save and clear (diegosouzapw#3537) (diegosouzapw#3564) Integrated into release/v3.8.20 * docs(changelog): credit @Six7Day for diegosouzapw#3560 thoughtSignature fix (diegosouzapw#3414) The diegosouzapw#3560 squash co-author trailer landed inline (unparsed by GitHub), so add an explicit CHANGELOG credit ensuring @Six7Day (original diegosouzapw#3414) and @oyi77 are on the public record for the Gemini thoughtSignature fix. * fix(gamification): dedup badge unlock via user_badges so events don't re-fire every request (diegosouzapw#3472) (diegosouzapw#3565) Integrated into release/v3.8.20 * fix(routing): pass through 'auto' keyword on codex /v1/responses instead of rewriting to codex/auto (diegosouzapw#3509) (diegosouzapw#3566) Integrated into release/v3.8.20 * fix(cli-tools): normalize apiKey null in guide-settings schema so cloud-mode config saves (diegosouzapw#3552) (diegosouzapw#3567) Integrated into release/v3.8.20 * fix(catalog): reclassify PublicAI from keyless to one-time-initial (requires API key) (diegosouzapw#3558) (diegosouzapw#3568) Integrated into release/v3.8.20 * fix(gemini-web): surface missing Playwright browser as actionable 503 + cooldown hint, not a retryable 500 loop (diegosouzapw#3516) (diegosouzapw#3570) Integrated into release/v3.8.20 * fix(security): sanitize raw err.message in web executors + embeddings/search response bodies (Rule diegosouzapw#12) (diegosouzapw#3494, diegosouzapw#3495) (diegosouzapw#3573) Integrated into release/v3.8.20 * fix(dashboard): point CustomHostsManager + FeatureFlagsGrid at real routes (diegosouzapw#3486, diegosouzapw#3487) (diegosouzapw#3574) Integrated into release/v3.8.20 * chore(providers): remove dead krutrim entry (diegosouzapw#3483) + docs(api): fix agent-bridge per-agent state route (diegosouzapw#3489) (diegosouzapw#3575) Integrated into release/v3.8.20 * docs(api): correct API_REFERENCE.md paths for skills/plugins/admin/cache/acp/system-info (diegosouzapw#3497) (diegosouzapw#3577) Integrated into release/v3.8.20 * fix(proxy): drive SOCKS5 UI option from runtime ENABLE_SOCKS5_PROXY, not build-time NEXT_PUBLIC (diegosouzapw#3508) (diegosouzapw#3579) Integrated into release/v3.8.20 * fix(playground): filter playground models by node prefix so custom-endpoint models appear (diegosouzapw#3505) (diegosouzapw#3581) Integrated into release/v3.8.20 * fix(usage): show an informative message instead of a blank Kiro quota card when no usage breakdown (diegosouzapw#3506) (diegosouzapw#3582) Integrated into release/v3.8.20 * docs(changelog): add the diegosouzapw#3506 Kiro quota entry (missed in diegosouzapw#3582 due to a stale-base CHANGELOG anchor) (diegosouzapw#3583) Integrated into release/v3.8.20 * fix(auto-update): use stable PROJECT_ROOT walker, not frozen process.cwd() (diegosouzapw#3561) Integrated into release/v3.8.20. Auto-update PROJECT_ROOT now uses a stable __dirname-anchored upward walker instead of the no-op process.cwd() resolver. * fix: address PR diegosouzapw#3518 review comments (lifecycle hooks, regex, indentation, route params) (diegosouzapw#3562) Integrated into release/v3.8.20. Addresses diegosouzapw#3518 review: regex literals, logs/[id] route params (Next 16), indentation, and wires plugin lifecycle hooks (onInstall/onActivate/onDeactivate/onUninstall) in the loader so manager.ts can register them. Adds Rule diegosouzapw#18 regression test. * docs(changelog): credit @ViFigueiredo (diegosouzapw#3423) for PROJECT_ROOT + log diegosouzapw#3561/diegosouzapw#3562 (v3.8.20) * fix: openai to gemini incorrectly translates historical tool calls into text (diegosouzapw#3569) Integrated into release/v3.8.20. Standard Gemini direct path now maps historical tool calls to native functionCall/functionResponse parts (signaturelessToolCallMode: native) instead of inert text — validated against the real Gemini API (gemini-2.5-flash returns 200 for signatureless native functionCall, even with tools+thinking; Hard Rule diegosouzapw#18). Eliminates the text-serialization leak. Antigravity/CLI sentinel path (diegosouzapw#3560) untouched. * docs(changelog)+test: reconcile standard-Gemini native mode (diegosouzapw#3569) — update round-2 rationale comment + log VPS validation * docs(changelog): reconcile v3.8.20 — add 9 missing bullets + move [Unreleased] to versioned section * docs(changelog): complete v3.8.20 reconciliation — 27 bullets, 11 contributors --------- Co-authored-by: Alexander Averyanov <alex@averyan.ru> Co-authored-by: Hakan Kurşun <bykamaka@gmail.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com> Co-authored-by: Giorgos Giakoumettis <giorgos@yiakoumettis.gr> Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com> Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com> Co-authored-by: Markus Hartung <mail@hartmark.se>
Closes #3508
Problem: the proxy modal gated the SOCKS5 type on
NEXT_PUBLIC_ENABLE_SOCKS5_PROXY === "true". Next.js inlinesNEXT_PUBLIC_*at build time, so the prebuilt Docker image baked it as false and a runtimeNEXT_PUBLIC_ENABLE_SOCKS5_PROXY=truehad no effect (the server already honoured the runtimeENABLE_SOCKS5_PROXY, creating a confusing split).Fix:
GET /api/settings/proxiesnow returnssocks5Enabled: ENABLE_SOCKS5_PROXY === "true"(runtime). The modal reads it (with the build-time value as a static-deploy fallback) and computes the proxy-type list + the saved-proxy guards from the live value — so settingENABLE_SOCKS5_PROXY=trueat runtime now surfaces SOCKS5 in the UI. Extracted a purebuildProxyTypes()helper.Test (Rule #18):
tests/unit/proxy-types-socks5-runtime-3508.test.ts(buildProxyTypes include/exclude). typecheck clean; existing ProxyConfigModal vitest suite 3/3.