fix(mcp): preserve caller identity for internal REST hops - #9260
Merged
diegosouzapw merged 1 commit intoAug 6, 2026
Merged
diegosouzapw merged 1 commit into
diegosouzapw merged 1 commit into
Conversation
diegosouzapw
added a commit
that referenced
this pull request
Aug 6, 2026
The Docs Gates env/docs contract went red on the release tip: #9260 added OMNIROUTE_INTERNAL_SERVICE_TOKEN(_FILE) and #9324 added OPENROUTER_PROVIDER_STATS_ENABLED/_TTL_MS without .env.example entries, and the #9286 Redis sidecar vars (REDIS_BIND_HOST, REDIS_PORT, OMNIROUTE_REDIS_BIND_HOST) never reached ENVIRONMENT.md. Inherited base-red on every open PR. Defaults and descriptions taken from the consuming source files.
diegosouzapw
added a commit
that referenced
this pull request
Aug 6, 2026
…ublish resolver (#9553) * fix(build): resolve npm-cli.js on POSIX layouts in the shim-free prepublish resolver The #8858 resolver only tried <dir(node)>/node_modules/npm/bin — the Windows layout. On POSIX (GitHub hosted runners, nvm, system installs) npm lives at <prefix>/lib/node_modules/npm while node is <prefix>/bin/ node, so resolveBundledNpmEntry returned null and npm run build:cli died installing @omniroute/opencode-plugin deps on every fresh checkout ('npm-cli.js not found next to the running Node binary') — redding Fast Production Build and dast-smoke for the whole PR queue. Extract the resolver to scripts/build/resolveNpmEntry.ts with injectable seams and try, in order: npm_execpath (exported by npm run itself), the Windows beside-the-binary layout, the POSIX <prefix>/lib layout. TDD: tests/unit/build/resolve-npm-entry.test.ts — the POSIX-layout and npm_execpath cases plus a live regression guard fail against the old single-candidate logic (2/5) and pass with the fix (5/5). * docs(env): register the 7 env vars orphaned by the 08-05 merge batch The Docs Gates env/docs contract went red on the release tip: #9260 added OMNIROUTE_INTERNAL_SERVICE_TOKEN(_FILE) and #9324 added OPENROUTER_PROVIDER_STATS_ENABLED/_TTL_MS without .env.example entries, and the #9286 Redis sidecar vars (REDIS_BIND_HOST, REDIS_PORT, OMNIROUTE_REDIS_BIND_HOST) never reached ENVIRONMENT.md. Inherited base-red on every open PR. Defaults and descriptions taken from the consuming source files. --------- Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
diegosouzapw
added a commit
that referenced
this pull request
Aug 6, 2026
…9554) * fix(quality): reconcile inherited file-size drift on the release tip 13 files sit above their frozen LOC on the clean tip 8180b49 (measured by the gate itself). The PR-mode base-relative check (#8522) correctly lets innocent PRs pass, but per-PR rebaselines were lost across successive conflict resolutions of this hot file during the 08-05/06 merge batch — so the absolute mode (nightly, local runs) is permanently red and stops distinguishing real growth from inherited drift. Frozen values updated to the measured tip, each annotated with the merged PR that grew the file (#9024 #9324 #9329 #9193 #9332 #9228 #9236 #9314 #9260 #8934 #9196 #9163); executors default.ts and kiro.ts (above the 1000 cap with no frozen entry) join the frozen set. * fix(quality): prune orphaned ESLint suppressions and clear the 5 unsuppressed errors The 'No new ESLint warnings' job reds the whole queue with exit 2: 'There are suppressions left that do not occur anymore' — the 08-05 merge batch removed code whose violations were frozen in eslint-suppressions.json, leaving orphaned entries (673->670 files, 4338->4333 violations after eslint --prune-suppressions). The full-tree run also surfaced 5 real unsuppressed errors merged with the batch, fixed here instead of suppressed (new violations must be fixed, per policy): 4x no-explicit-any in tests/unit/catalog-order-contract.test.ts ((conn as any).id -> typed cast) and 1x react/no-unescaped-entities in the agent-bridge SetupWizard (#9095). Also restores the _comment policy header the successive hot-file conflict resolutions had dropped (TS7 debt freeze provenance + prune policy). * fix(quality): absorb the two file-size growths merged while this PR was in CI The base kept moving during the reconcile cycle: #9184 grew src/sse/handlers/chat.ts 1857->1877 and #9005 grew open-sse/executors/default.ts 1027->1042. Re-measured on the merged tree; gate back to 0 violations. * fix(tests): move the orphaned RTL ratchet test to a collected path as node:test #8828 added tests/unit/scripts/check-rtl-ratchet.test.ts — a path no runner collects (the node:test globs enumerate an explicit subdir list without scripts/, and vitest.config.ts never included it), so the file NEVER ran and the test-discovery orphan gate reds the queue. Moved to tests/unit/ (collected by node:test) and converted from vitest describe/it/expect to node:test+assert to match the runner and the sibling check-*.test.ts files. 5/5 green under the real runner. --------- Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
10 tasks done
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…pw#9260) Validated in local merge-train (devbox-vm-06-dev002) @ combined-tip (FAST gates green: static + changed tests + vitest — only pre-existing audit.test.ts flake). Evidence: /home/diegosouzapw/dev/proxys/OmniRoute/.claude/worktrees/merge-train-20260805-213228-suite.log
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…ublish resolver (diegosouzapw#9553) * fix(build): resolve npm-cli.js on POSIX layouts in the shim-free prepublish resolver The diegosouzapw#8858 resolver only tried <dir(node)>/node_modules/npm/bin — the Windows layout. On POSIX (GitHub hosted runners, nvm, system installs) npm lives at <prefix>/lib/node_modules/npm while node is <prefix>/bin/ node, so resolveBundledNpmEntry returned null and npm run build:cli died installing @omniroute/opencode-plugin deps on every fresh checkout ('npm-cli.js not found next to the running Node binary') — redding Fast Production Build and dast-smoke for the whole PR queue. Extract the resolver to scripts/build/resolveNpmEntry.ts with injectable seams and try, in order: npm_execpath (exported by npm run itself), the Windows beside-the-binary layout, the POSIX <prefix>/lib layout. TDD: tests/unit/build/resolve-npm-entry.test.ts — the POSIX-layout and npm_execpath cases plus a live regression guard fail against the old single-candidate logic (2/5) and pass with the fix (5/5). * docs(env): register the 7 env vars orphaned by the 08-05 merge batch The Docs Gates env/docs contract went red on the release tip: diegosouzapw#9260 added OMNIROUTE_INTERNAL_SERVICE_TOKEN(_FILE) and diegosouzapw#9324 added OPENROUTER_PROVIDER_STATS_ENABLED/_TTL_MS without .env.example entries, and the diegosouzapw#9286 Redis sidecar vars (REDIS_BIND_HOST, REDIS_PORT, OMNIROUTE_REDIS_BIND_HOST) never reached ENVIRONMENT.md. Inherited base-red on every open PR. Defaults and descriptions taken from the consuming source files. --------- Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…iegosouzapw#9554) * fix(quality): reconcile inherited file-size drift on the release tip 13 files sit above their frozen LOC on the clean tip 30be158 (measured by the gate itself). The PR-mode base-relative check (diegosouzapw#8522) correctly lets innocent PRs pass, but per-PR rebaselines were lost across successive conflict resolutions of this hot file during the 08-05/06 merge batch — so the absolute mode (nightly, local runs) is permanently red and stops distinguishing real growth from inherited drift. Frozen values updated to the measured tip, each annotated with the merged PR that grew the file (diegosouzapw#9024 diegosouzapw#9324 diegosouzapw#9329 diegosouzapw#9193 diegosouzapw#9332 diegosouzapw#9228 diegosouzapw#9236 diegosouzapw#9314 diegosouzapw#9260 diegosouzapw#8934 diegosouzapw#9196 diegosouzapw#9163); executors default.ts and kiro.ts (above the 1000 cap with no frozen entry) join the frozen set. * fix(quality): prune orphaned ESLint suppressions and clear the 5 unsuppressed errors The 'No new ESLint warnings' job reds the whole queue with exit 2: 'There are suppressions left that do not occur anymore' — the 08-05 merge batch removed code whose violations were frozen in eslint-suppressions.json, leaving orphaned entries (673->670 files, 4338->4333 violations after eslint --prune-suppressions). The full-tree run also surfaced 5 real unsuppressed errors merged with the batch, fixed here instead of suppressed (new violations must be fixed, per policy): 4x no-explicit-any in tests/unit/catalog-order-contract.test.ts ((conn as any).id -> typed cast) and 1x react/no-unescaped-entities in the agent-bridge SetupWizard (diegosouzapw#9095). Also restores the _comment policy header the successive hot-file conflict resolutions had dropped (TS7 debt freeze provenance + prune policy). * fix(quality): absorb the two file-size growths merged while this PR was in CI The base kept moving during the reconcile cycle: diegosouzapw#9184 grew src/sse/handlers/chat.ts 1857->1877 and diegosouzapw#9005 grew open-sse/executors/default.ts 1027->1042. Re-measured on the merged tree; gate back to 0 violations. * fix(tests): move the orphaned RTL ratchet test to a collected path as node:test diegosouzapw#8828 added tests/unit/scripts/check-rtl-ratchet.test.ts — a path no runner collects (the node:test globs enumerate an explicit subdir list without scripts/, and vitest.config.ts never included it), so the file NEVER ran and the test-discovery orphan gate reds the queue. Moved to tests/unit/ (collected by node:test) and converted from vitest describe/it/expect to node:test+assert to match the runner and the sibling check-*.test.ts files. 5/5 green under the real runner. --------- Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Related Issues
Validation
npm run typecheck:corerelease/v3.8.50Tests Added Or Updated
open-sse/mcp-server/__tests__/httpAuthContext.test.ts(existing regression retained)tests/unit/internal-service-auth.test.tstests/unit/authz/management-policy.test.tstests/unit/require-management-auth-access-token.test.tsCoverage Notes
The focused tests cover disabled configuration, inline and file-backed tokens, constant-time comparison, trusted-loopback enforcement, remote rejection, and preservation of caller Authorization.
Reviewer Notes
The internal token is deliberately separate from
Authorization; it cannot replace the caller credential or weaken MCP tool-scope enforcement. Deployments should mount the token as a mode-0600 file throughOMNIROUTE_INTERNAL_SERVICE_TOKEN_FILE.