Repository navigation
fix(combos): PUT /api/combos/{id} rejects empty / no-op bodies with 400 - #5077
KooshaPari wants to merge 140 commits into
Conversation
) (diegosouzapw#4826) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 1/13)
…iegosouzapw#3501) (diegosouzapw#4824) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 2/13)
… (diegosouzapw#4811) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 3/13)
… completo, diegosouzapw#3501) (diegosouzapw#4817) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 4/13)
…diegosouzapw#4827) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 5/13)
… usage non-streaming, diegosouzapw#3501) (diegosouzapw#4832) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 6/13)
…ardrail post-call, diegosouzapw#3501) (diegosouzapw#4831) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 7/13)
…n-streaming, diegosouzapw#3501) (diegosouzapw#4828) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 8/13)
…de resposta non-streaming, diegosouzapw#3501) (diegosouzapw#4835) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 9/13)
… JSON→SSE streaming, diegosouzapw#3501) (diegosouzapw#4833) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 10/13)
…de resposta streaming, diegosouzapw#3501) (diegosouzapw#4836) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 11/13)
…-store streaming, diegosouzapw#3501) (diegosouzapw#4829) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 12/13)
…orms streaming, diegosouzapw#3501) (diegosouzapw#4837) Integrated into release/v3.8.36 (diegosouzapw#3501 chatCore extraction stack 13/13)
…ease-acceleration) (diegosouzapw#4857) * feat(quality): add check:test-runner-api gate (vitest-only dirs must use vitest API) * feat(release): reusable CHANGELOG i18n-mirror sync script * chore(ops): add prune-stale-worktrees.sh (dry-run by default) * ci(quality): run test-runner-api + docs-all + vitest + full unit suite on PR->release fast-path --------- Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…) + limite EPSILON não bloqueia (diegosouzapw#4830) Integrated into release/v3.8.36 — quota-exclusive qtSd/ listing (diegosouzapw#4806) + EPSILON placeholder no longer blocks; rebuilt from stale base (3 defining commits cherry-picked clean over release tip)
…) (diegosouzapw#4769) Integrated into release/v3.8.36 — Google Flow video-generation provider (diegosouzapw#4569), release-green validated (typecheck + 21 tests + file-size)
…_CREDENTIALS (diegosouzapw#4694, diegosouzapw#4720) (diegosouzapw#4796) Integrated into release/v3.8.36 — auth on compression run-telemetry + OMNIROUTE_EVAL_CREDENTIALS doc, release-green validated (typecheck + 3 tests + env-doc-sync)
…rough (port from 9router#1157) (diegosouzapw#4624) Integrated into release/v3.8.36 — port (rebuilt from stale base; defining commit cherry-picked clean over release tip, release-green validated)
…rmat providers (diegosouzapw#4625) Integrated into release/v3.8.36 — port (rebuilt from stale base; defining commit cherry-picked clean over release tip, release-green validated)
…ocks (diegosouzapw#4633) Integrated into release/v3.8.36 — port (rebuilt from stale base; defining commit cherry-picked clean over release tip, release-green validated)
…thropic providers (diegosouzapw#4650) Integrated into release/v3.8.36 — port (rebuilt from stale base; defining commit cherry-picked clean over release tip, release-green validated)
…iegosouzapw#4651) Integrated into release/v3.8.36 — port (rebuilt from stale base; defining commit cherry-picked clean over release tip, release-green validated)
…apw#4654) Integrated into release/v3.8.36 — port (rebuilt from stale base; defining commit cherry-picked clean over release tip, release-green validated)
…iegosouzapw#4656) Integrated into release/v3.8.36 — port (rebuilt from stale base; defining commit cherry-picked clean over release tip, release-green validated)
…ttings (diegosouzapw#4659) Integrated into release/v3.8.36 — port (rebuilt from stale base; defining commit cherry-picked clean over release tip, release-green validated)
) (diegosouzapw#4629) Integrated into release/v3.8.36 — kiro region SSRF guard (GHSA-6mwv-4mrm-5p3m), port rebuilt clean over release tip
…egosouzapw#4628) Integrated into release/v3.8.36 — port rebuilt clean over release tip, release-green validated
…sages (diegosouzapw#4657) Integrated into release/v3.8.36 — anthropic-compat validation via POST /v1/messages (port 584cf66a), rebuilt clean + baseline; release-green
…diegosouzapw#4658) Integrated into release/v3.8.36 — port rebuilt clean over release tip, release-green validated
…ariante A) (diegosouzapw#4967) Integrated into release/v3.8.36
…k-aware router precedence (diegosouzapw#4973) Dois base-reds pré-existentes que reprovavam o CI da release v3.8.36 (Fast Quality Gates + Unit Tests fast-path), independentes de qualquer feature em voo: 1. check:db-rules / allowlist: os módulos db-internal caseMapping (diegosouzapw#4947) e schemaColumns (diegosouzapw#4948), extraídos de db/core.ts e importados só por ele, não estavam em INTENTIONALLY_INTERNAL. Registrados na allowlist (correção canônica — são internos legítimos, não re-exportados pelo localDb). 2. auto-strategy honra LKGP/cost (combo-routing-engine.test.ts, 2 testes): o task-aware reordering (diegosouzapw#4945, reorderByTaskWeight) roda para strategy "auto" e era aplicado DEPOIS do router explícito (selectWithStrategy: lkgp/cost), sobrescrevendo o orderedTargets[0] que o operador escolheu. Instrumentação provou: post-filter [0]=claude (LKGP) → post-task [0]=gpt-oss. Correção: quando o auto usa router explícito, preserva o [0] dele e deixa o task-aware refinar só a cauda de fallback. gpt-oss-120b PERMANECE tool-capable (não é mudança de catálogo; o model-capabilities-registry test segue verde). Validado: 121 testes (combo-routing-engine + combo-task-aware + registry) verdes, red-check confirmado, db-rules/file-size/typecheck/lint/prettier OK. Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…e (FASE 2.1) (diegosouzapw#4970) O gating de quota-share em selectQuotaShareTarget é fail-open: uma conexão at-cap só é despriorizada, nunca bloqueada. Com 1 conexão por conta de assinatura (caso comum), chamadas concorrentes ainda floodam a conta (→ 429 + cooldown) — provado live na .15: 3 chamadas concorrentes com max_concurrent=1 despacharam todas em 94ms. Adiciona um semáforo POR CONEXÃO em torno do dispatch quota-share: chamadas excedentes esperam na fila em vez de floodar (key qsconn:<connectionId>, cap = max_concurrent da conexão). Fail-open em fila saturada/timeout para nunca piorar disponibilidade. Gated por strategy===quota-share + kill-switch resilienceSettings.quotaShareConcurrencyLimit (default on; UI no ResilienceTab). Lógica extraível isolada no leaf puro combo/quotaShareConcurrency.ts (unit-testado: estabilidade da key, no-op sem cap, serialização real, fail-open). Settings + schema + UI espelham comboCooldownWait. Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…rrent + serialization + cooldown-wait) (diegosouzapw#4980) Documents the v3.8.36 quota-share concurrency layers in RESILIENCE_GUIDE.md: per-connection max_concurrent cap, the quota-share request serialization semaphore (FASE 2.1, qsconn:<connectionId>, fail-open, kill-switch), and the combo cooldown-aware retry — so operators know how to cap a subscription account's concurrency and why the routing gate alone cannot contain a single-connection flood. Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…is (diegosouzapw#4878) (diegosouzapw#4988) Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…ouzapw#4976) (diegosouzapw#4986) * fix(sse): fail over on 400 responses carrying rate-limit text (diegosouzapw#4976) * chore(quality): rebaseline accountFallback.ts file-size for diegosouzapw#4976 fix --------- Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…egosouzapw#4559) (diegosouzapw#4987) * fix(compression): stop RTK over-truncating file-read tool results (diegosouzapw#4559) * chore(quality): trim diegosouzapw#4559 comment to keep rtk/index.ts within size cap --------- Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…ode executor (diegosouzapw#4954) (diegosouzapw#4989) * fix(sse): honor per-account proxies and fingerprint rotation in opencode executor (diegosouzapw#4954) * chore(quality): rebaseline auth.ts file-size for diegosouzapw#4954 (+39: synthetic no-auth providerSpecificData hydration of fingerprints/accountProxies; irreducible credential-path wiring, covered by opencode-proxy-rotation-4954.test.ts + 159 auth/noauth regression) --------- Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…egosouzapw#4540) (diegosouzapw#4990) * fix(sse): soft-penalize exhausted providers in auto-combo scoring (diegosouzapw#4540) * chore(quality): document STATUS_SOFT_DEPRIORITIZE_FACTOR + rebaseline combo.ts for diegosouzapw#4540 --------- Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…els in test-all (diegosouzapw#4887) (diegosouzapw#4991) * fix(dashboard): switch to visible filter after auto-hiding failed models in OAuth provider test-all (diegosouzapw#4887) * test(dashboard): move diegosouzapw#4887 test into tests/unit/ui so a CI runner collects it --------- Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…diegosouzapw#3981) (diegosouzapw#5009) Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…ative Gemini paths (diegosouzapw#5003) (diegosouzapw#5008) * fix(antigravity): default safetySettings to all-OFF for parity with native Gemini paths (diegosouzapw#5003) * docs(changelog): restore diegosouzapw#3981 pollinations entry eaten by merge --------- Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…vent silent model substitution (diegosouzapw#4665) (diegosouzapw#5010) * fix(chatgpt-web): map advertised gpt-5.5/5.4-pro/5.2-pro slugs to prevent silent model substitution (diegosouzapw#4665) MODEL_MAP was missing the advertised catalog ids gpt-5.5, gpt-5.5-pro, gpt-5.4-pro and gpt-5.2-pro, so MODEL_MAP[model] ?? model sent the dot-form id verbatim to the ChatGPT backend-api, which silently rejected it and served the default Plus model. Map each to its dash-form slug. gpt-4-5 is already dash-form and falls through correctly, so it is intentionally left unmapped. Extends the executor MODEL_MAP test with the four ids and adds a drift guard asserting every advertised dot-form catalog id reaches the backend in dash-form (never verbatim), guarding future catalog<->map drift. file-size: tests/unit/chatgpt-web.test.ts frozen baseline 2809->2855 (+46) for the added test cases and drift-guard test; executor source unchanged in baseline. * docs(changelog): restore diegosouzapw#3981/diegosouzapw#5003 entries eaten by merge --------- Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
…/api/combos (diegosouzapw#5005) (diegosouzapw#5011) * feat(combos): add editable per-combo description field persisted via /api/combos (diegosouzapw#5005) * docs(changelog): restore diegosouzapw#3981/diegosouzapw#5003/diegosouzapw#4665 entries eaten by merge --------- Co-authored-by: Diego Rodrigues de Sa e Souza <souzamiriamrodrigues790@gmail.com>
Integrated into release/v3.8.36
…tion (diegosouzapw#5024) Integrated into release/v3.8.36
…iegosouzapw#5027) Integrated into release/v3.8.36
…zapw#5022) Integrated into release/v3.8.36
…mpression (diegosouzapw#5023) Integrated into release/v3.8.36
…diegosouzapw#5027 (release notes credit)
…ouzapw#5006) (diegosouzapw#5028) * fix(api): stop /api/system/env/repair 500 on packaged install — lazy createRequire in sync-env.mjs (diegosouzapw#5006) scripts/dev/sync-env.mjs ran createRequire(import.meta.url) at module top-level. When webpack bundles it into the standalone env-repair route, import.meta.url is frozen to the build-machine path (file:///home/runner/...) and createRequire throws during module evaluation, so the whole route module fails to load and every GET returns HTTP 500 — breaking the onboarding wizard on packaged/global installs. - Move createRequire into the guarded better-sqlite3 block (only place that needs it); a bad import.meta.url now returns the safe default. - resolveRootDir() falls back to process.cwd() when fileURLToPath throws. - route.ts passes an explicit rootDir (process.cwd()) so the helper never derives the root from the frozen import.meta.url, matching the .env target used by createEnvBackup(). - Regression guard: assert sync-env.mjs has no top-level createRequire + getEnvSyncPlan(oauth) works with explicit rootDir without throwing. * docs(changelog): restore diegosouzapw#4993/diegosouzapw#5023/diegosouzapw#5024/diegosouzapw#5027 + custom-system-prompt/headroom entries eaten by release merge * chore(quality): rebaseline 3 inherited base-reds from release merge Files NOT touched by this PR — grew on release/v3.8.36 via --admin merges and inherited here through 'git merge origin/release': - open-sse/executors/base.ts 1414->1416 (diegosouzapw#4993 Ollama Cloud max-effort) - src/lib/db/settings.ts 1149->1151 (diegosouzapw#5023 custom system prompt) - src/app/(dashboard)/.../endpoint/EndpointPageClient.tsx 2570->2612 (custom system prompt UI)
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
Thanks for this work, @KooshaPari 🙏 — closing after a maintainer review of all 46 open refactor PRs in this batch (yours included). This is not a rejection of the effort. Why closed (applies to the whole batch): every branch here is 44–50 commits behind This PR specifically: ✅ SOUND — surgical guard rejecting empty/no-op What happens to it: ✅ Sound — going into the "salvage" batch. We will reimplement it cleanly on top of the current release (with tests per our Rule #18), crediting you as co-author ( We ran a full case-by-case triage. The approaches worth keeping are being recorded internally with author credit, so when we pick them up the attribution travels with the code. Thank you for pushing on this. 🙌 |
Summary
PUT /api/combos/{id}with{}or with only undefined fields was a no-op that still triggered the cloud-sync path. It also made "stuck toggle" bugs invisible: the API returned 200 with the unchanged combo, the dashboard thought it succeeded, and the user had no signal.This is a re-ship of the closed PR #4904 on the current
release/v3.8.36base.Changes
Tests
PUT /api/combos rejects an empty body {} with 400PUT /api/combos rejects a body of only undefined fields with 400PUT /api/combos still accepts a single-field update (regression guard)11/11 tests pass. All pre-commit hooks pass.