Skip to content

fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (#3496) - #3602

Merged
diegosouzapw merged 1 commit into
release/v3.8.21from
fix/3496-guardrails-api
Jun 11, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.21from
fix/3496-guardrails-api

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Closes #3496

Problem

docs/reference/API_REFERENCE.md documented a /api/guardrails* (5 routes) and /api/shadow* (5 routes) surface that did not exist — doc-fiction flagged by the check-docs-symbols quality gate (PR #3471) and frozen in KNOWN_STALE_DOC_REFS.

Fix

The guardrail pipeline is real (src/lib/guardrails/ — pii/promptInjection/visionBridge via guardrailRegistry), so I implemented the two routes that map to actual behavior and removed the fictional rest:

  • GET /api/guardrails — lists the registered guardrails + status (name / enabled / priority), management-scoped via requireManagementAuth.
  • POST /api/guardrails/test — dry-runs the pre-call pipeline (runPreCallHooks) over a sample input, returning the per-guardrail verdict + (possibly masked) payload. Honors disabledGuardrails.
  • Removed the fictional /[id]/enable, /[id]/disable, /logs rows (guardrails are per-request via the x-omniroute-disabled-guardrails header — no persisted enable/disable surface) and the entire /api/shadow* table (shadow A-B comparison is combo-config + the real GET /api/combos/metrics).
  • Dropped all 9 guardrails/shadow entries from KNOWN_STALE_DOC_REFS (allowlist 15 → 6).

Validation (Hard Rule #18 — TDD)

tests/unit/guardrails-api-3496.test.ts (RED → GREEN): route-list, dry-run pipeline, disabledGuardrails skip, 400 on missing input, plus a gate regression asserting the allowlist no longer freezes guardrails/shadow AND API_REFERENCE.md resolves cleanly through findStaleDocApiRefs.

  • ✅ node --test tests/unit/guardrails-api-3496.test.ts (5/5)
  • ✅ node scripts/check/check-docs-symbols.mjs (OK — 6 stale frozen, was 15)
  • ✅ npm run typecheck:core
  • ✅ eslint clean on new files

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@diegosouzapw
diegosouzapw merged commit 43c312a into release/v3.8.21 Jun 11, 2026
2 checks passed
@kilo-code-bot

kilo-code-bot Bot commented Jun 11, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: No Issues Found | Recommendation: Merge

The PR implements GET /api/guardrails and POST /api/guardrails/test to resolve documentation fiction flagged by the check-docs-symbols quality gate. All changes are clean:

  • Route handlers follow existing patterns in the codebase (CORS, management auth, error handling)
  • Zod schema properly validates input with union types for flexible payload
  • Tests cover all expected behaviors including the regression guard for the docs check
  • Documentation updates accurately reflect the implemented surface
Files Reviewed (6 files)
  • src/app/api/guardrails/route.ts — clean
  • src/app/api/guardrails/test/route.ts — clean
  • tests/unit/guardrails-api-3496.test.ts — clean
  • scripts/check/check-docs-symbols.mjs — clean
  • docs/reference/API_REFERENCE.md — clean
  • CHANGELOG.md — clean

Reviewed by laguna-m.1-20260312:free · 1,606,426 tokens

diegosouzapw added a commit that referenced this pull request Jun 11, 2026
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (#3572) (#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (#3571) (#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (#3580) (#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (#3498) (#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (#3488) (#3600)

* fix(gamification): add level/badges/badges-earned profile routes (#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (#3578)

* fix: add reasoning token buffer for combo routing (fixes #3587) (#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit #3598 (chatCore modularization) + #3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (#3496) (#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (#3605)

Split-out PR C from #3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the #3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (#3603)

Split-out PR A from #3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (#3606) (#3608)

Integrated into release/v3.8.21 (#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (#3589) (#3609)

Integrated into release/v3.8.21 (#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (#3419) (#3613)

Integrated into release/v3.8.21 (#3419)

* fix(usage): normalize Antigravity and agy provider quotas (#3604)

Split-out PR B from #3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (#3331) (#3614)

Integrated into release/v3.8.21 (#3331)

* docs(changelog): credit #3603 (Flash tier IDs) + #3604 (provider quotas) + #3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 797de43.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
@diegosouzapw
diegosouzapw deleted the fix/3496-guardrails-api branch June 11, 2026 15:33
oyi77 pushed a commit to oyi77/OmniRoute that referenced this pull request Jun 12, 2026
…drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
oyi77 pushed a commit to oyi77/OmniRoute that referenced this pull request Jun 12, 2026
…drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
oyi77 pushed a commit to oyi77/OmniRoute that referenced this pull request Jun 12, 2026
…drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
oyi77 pushed a commit to oyi77/OmniRoute that referenced this pull request Jun 12, 2026
…drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
oyi77 pushed a commit to oyi77/OmniRoute that referenced this pull request Jun 12, 2026
…drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
oyi77 pushed a commit to oyi77/OmniRoute that referenced this pull request Jun 12, 2026
…drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
oyi77 pushed a commit to oyi77/OmniRoute that referenced this pull request Jun 12, 2026
…drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (diegosouzapw#3572) (diegosouzapw#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (diegosouzapw#3571) (diegosouzapw#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (diegosouzapw#3580) (diegosouzapw#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (diegosouzapw#3498) (diegosouzapw#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (diegosouzapw#3488) (diegosouzapw#3600)

* fix(gamification): add level/badges/badges-earned profile routes (diegosouzapw#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (diegosouzapw#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (diegosouzapw#3578)

* fix: add reasoning token buffer for combo routing (fixes diegosouzapw#3587) (diegosouzapw#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (diegosouzapw#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit diegosouzapw#3598 (chatCore modularization) + diegosouzapw#3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (diegosouzapw#3605)

Split-out PR C from diegosouzapw#3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the diegosouzapw#3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (diegosouzapw#3603)

Split-out PR A from diegosouzapw#3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (diegosouzapw#3606) (diegosouzapw#3608)

Integrated into release/v3.8.21 (diegosouzapw#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (diegosouzapw#3589) (diegosouzapw#3609)

Integrated into release/v3.8.21 (diegosouzapw#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (diegosouzapw#3419) (diegosouzapw#3613)

Integrated into release/v3.8.21 (diegosouzapw#3419)

* fix(usage): normalize Antigravity and agy provider quotas (diegosouzapw#3604)

Split-out PR B from diegosouzapw#3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (diegosouzapw#3331) (diegosouzapw#3614)

Integrated into release/v3.8.21 (diegosouzapw#3331)

* docs(changelog): credit diegosouzapw#3603 (Flash tier IDs) + diegosouzapw#3604 (provider quotas) + diegosouzapw#3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (diegosouzapw#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 6d24708.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (diegosouzapw#3572) (diegosouzapw#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (diegosouzapw#3571) (diegosouzapw#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (diegosouzapw#3580) (diegosouzapw#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (diegosouzapw#3498) (diegosouzapw#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (diegosouzapw#3488) (diegosouzapw#3600)

* fix(gamification): add level/badges/badges-earned profile routes (diegosouzapw#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (diegosouzapw#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (diegosouzapw#3578)

* fix: add reasoning token buffer for combo routing (fixes diegosouzapw#3587) (diegosouzapw#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (diegosouzapw#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit diegosouzapw#3598 (chatCore modularization) + diegosouzapw#3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (diegosouzapw#3605)

Split-out PR C from diegosouzapw#3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the diegosouzapw#3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (diegosouzapw#3603)

Split-out PR A from diegosouzapw#3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (diegosouzapw#3606) (diegosouzapw#3608)

Integrated into release/v3.8.21 (diegosouzapw#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (diegosouzapw#3589) (diegosouzapw#3609)

Integrated into release/v3.8.21 (diegosouzapw#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (diegosouzapw#3419) (diegosouzapw#3613)

Integrated into release/v3.8.21 (diegosouzapw#3419)

* fix(usage): normalize Antigravity and agy provider quotas (diegosouzapw#3604)

Split-out PR B from diegosouzapw#3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (diegosouzapw#3331) (diegosouzapw#3614)

Integrated into release/v3.8.21 (diegosouzapw#3331)

* docs(changelog): credit diegosouzapw#3603 (Flash tier IDs) + diegosouzapw#3604 (provider quotas) + diegosouzapw#3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (diegosouzapw#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 797de43.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (diegosouzapw#3572) (diegosouzapw#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (diegosouzapw#3571) (diegosouzapw#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (diegosouzapw#3580) (diegosouzapw#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (diegosouzapw#3498) (diegosouzapw#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (diegosouzapw#3488) (diegosouzapw#3600)

* fix(gamification): add level/badges/badges-earned profile routes (diegosouzapw#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (diegosouzapw#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (diegosouzapw#3578)

* fix: add reasoning token buffer for combo routing (fixes diegosouzapw#3587) (diegosouzapw#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (diegosouzapw#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit diegosouzapw#3598 (chatCore modularization) + diegosouzapw#3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (diegosouzapw#3605)

Split-out PR C from diegosouzapw#3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the diegosouzapw#3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (diegosouzapw#3603)

Split-out PR A from diegosouzapw#3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (diegosouzapw#3606) (diegosouzapw#3608)

Integrated into release/v3.8.21 (diegosouzapw#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (diegosouzapw#3589) (diegosouzapw#3609)

Integrated into release/v3.8.21 (diegosouzapw#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (diegosouzapw#3419) (diegosouzapw#3613)

Integrated into release/v3.8.21 (diegosouzapw#3419)

* fix(usage): normalize Antigravity and agy provider quotas (diegosouzapw#3604)

Split-out PR B from diegosouzapw#3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (diegosouzapw#3331) (diegosouzapw#3614)

Integrated into release/v3.8.21 (diegosouzapw#3331)

* docs(changelog): credit diegosouzapw#3603 (Flash tier IDs) + diegosouzapw#3604 (provider quotas) + diegosouzapw#3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (diegosouzapw#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 408d91a2c.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant