Commit Graph

3828 Commits

Author SHA1 Message Date
Luis Pater
cca35aee93 fix(devin): use loopback callback endpoint for oauth redirect uri
- Enforce `http://127.0.0.1:<port>/callback` redirect URI to satisfy Devin authorization validation requirements.
- Register `/callback` route while preserving `/devin/callback` handler.
2026-09-14 09:37:35 +08:00
Luis Pater
8c5f6e185f fix(openai): convert responses tool choice to chat completions format
- Normalize responses named and custom tool choices to chat completions function format.
- Resolve namespaced and canonical tool names for tool choice.

Closes: #5794
2026-09-14 08:24:06 +08:00
Supra4E8C
44e62bc8ac feat(devin): implement Devin OAuth flow with callback handling and session management v7.3.1 2026-09-14 01:04:20 +08:00
Luis Pater
7e864ace4d Merge pull request #5797 from router-for-me/feat/cpa-web-search-catalog
feat(models): expose CPA web search capability
2026-09-14 00:59:20 +08:00
Supra4E8C
678da56193 chore(models): sync verified native search capability metadata 2026-09-14 00:04:41 +08:00
Supra4E8C
4311ae8747 feat(models): require explicit per-model native search support 2026-09-14 00:04:41 +08:00
sususu
30b2ac8996 refactor(devin): deduplicate auth credentials extraction, filter sparse tool calls, and optimize model lookup v7.3.0 2026-09-13 23:34:43 +08:00
sususu
9d190f309c feat(devin): integrate global signature detector for cross-provider signature detection 2026-09-13 23:34:43 +08:00
sususu
fb2c1c1afa fix(devin): transport reuse, interleaved stream steps, strings.Builder panic, and updater URL 2026-09-13 23:34:43 +08:00
sususu
926450e87b fix(devin): dynamic catalog-driven chat_model_uid resolution and effort clamping 2026-09-13 23:34:43 +08:00
sususu
1604cb0334 fix(devin): normalize upstream internal errors to 502 Bad Gateway 2026-09-13 23:34:43 +08:00
sususu
98b106f0e8 fix(devin): store transient quota metrics strictly in Quota.Signals and keep Metadata static 2026-09-13 23:34:43 +08:00
sususu
6a239f5715 fix(devin): propagate stream chunk errors, fix truncated protobuf infinite loop, respect ctx roundtripper, and limit auth response body reads 2026-09-13 23:34:43 +08:00
sususu
86de823daa perf(devin): cache Devin HTTP transports per proxy URL to reuse connection pools 2026-09-13 23:34:43 +08:00
sususu
6df8f32278 perf(devin): eliminate O(K^2) tool call argument string allocations using strings.Builder 2026-09-13 23:34:43 +08:00
sususu
6c7d2d57f7 perf(devin): cache sensitive word regex matcher, preallocate request bytes and frame decompression buffer 2026-09-13 23:34:43 +08:00
sususu
5d0c77cf3f fix(devin): enforce Connect-RPC EOS trailer invariant, validate frame flag, and bind OAuth callback to ctx 2026-09-13 23:34:43 +08:00
sususu
50dd582641 fix(devin): update streaming tool call step metadata if arriving in subsequent frames 2026-09-13 23:34:43 +08:00
sususu
d754298a8b fix(devin): bound tool call indices against OOM, set Refresh timeout, and check manual callback state 2026-09-13 23:34:43 +08:00
sususu
2f2f9b4381 fix(devin): guard against reopening thought step on late-arriving signatures 2026-09-13 23:34:43 +08:00
sususu
a5ea971f35 fix(devin): sort streaming tool call stop events and normalize prompt CRLF 2026-09-13 23:34:43 +08:00
sususu
f1f5506c0b fix(devin): align wire protocol, harden streaming, and resolve multi-turn tool/signature parity
- Wire parity: align Connect-RPC Sentry-Trace, User-Agent suppression, float32 double pattern, and dynamic 732-char hex device fingerprint
- Session ordinal & cache: implement process-scoped Field 15.2 with bounded LRU (5000 entries) and Field 15.4=14 user boundary; prioritize stable session_id over previous_interaction_id to preserve prompt caching
- Streaming robustness: unblock hung TCP reads on client cancellation via context watcher; accurately propagate stream read errors and trailer errors instead of swallowing truncated frames
- Thought signature & reasoning: emit raw delta signatures directly in active thought steps; eliminate redundant tail base64 re-encoding; ensure 1:1 assistant signature and thinking alignment across multi-turn history
- Tool call de-multiplexing: route parallel tool calls by tc.Index in both streaming step events and non-streaming aggregations
- Security & transport: escape OAuth callback error HTML against reflected XSS, enforce strict state validation, and isolate Devin HTTP transport with tr.Clone()
2026-09-13 23:34:43 +08:00
sususu
ca159b303d fix(util): enforce strict devin/ prefix requirement for devin provider 2026-09-13 23:34:43 +08:00
sususu
a0ccc3a414 Revert "feat(registry): transparently resolve un-prefixed devin models in auth selection"
This reverts commit 6eb8ed7f88.
2026-09-13 23:34:43 +08:00
sususu
fbabc2740f feat(registry): transparently resolve un-prefixed devin models in auth selection 2026-09-13 23:34:43 +08:00
sususu
85ddf3aeb5 fix(devin): calculate total_input_tokens and total_tokens correctly 2026-09-13 23:34:43 +08:00
sususu
0aedd05d31 feat(registry): auto-populate Gemini token limits and generation methods for Devin models 2026-09-13 23:34:43 +08:00
sususu
bf06746d42 feat(devin): map model aliases and swe-1-7/haiku/sonnet/gpt-4-1 UIDs 2026-09-13 23:34:43 +08:00
sususu
ca664c6ede feat(devin): clamp maxTokens to model MaxCompletionTokens 2026-09-13 23:34:43 +08:00
sususu
2683ec201d feat(cmd): add fetch_devin_models CLI tool for dynamic model catalog extraction 2026-09-13 23:34:43 +08:00
sususu
469aa3678f feat(devin): parse protobuf timestamp and harden partial failure logging 2026-09-13 23:34:43 +08:00
sususu
16cb6c0b02 feat(devin): add symmetric decoded upstream response in request log 2026-09-13 23:34:43 +08:00
sususu
6174174488 feat(devin): auto-namespace model IDs from clean devin_models.json 2026-09-13 23:34:43 +08:00
sususu
982cd124f9 feat(devin): add standalone devin_models.json catalog and remote updater 2026-09-13 23:34:43 +08:00
sususu
59df75d20c docs(devin): update DevinExecutor comment with verbatim reconstructed cloud system prompt 2026-09-13 23:34:43 +08:00
sususu
0c2351bb89 feat(devin): support none thinking level for glm-5-2 2026-09-13 23:34:43 +08:00
sususu
308e5ad3b1 feat(devin): add deepseek-v4-flash and deepseek-v4-1-flash models 2026-09-13 23:34:43 +08:00
sususu
8a3770710e docs(devin): document cloud-side system instructions baseline in DevinExecutor 2026-09-13 23:34:43 +08:00
sususu
2caab7dbf9 feat(devin): enhance request-log with intermediate interactions and decoded upstream body 2026-09-13 23:34:43 +08:00
sususu
ea2f29feec feat(devin): add devin/gemini-3-8-flash and devin/grok-4-6 model definitions and signature recognition
- Register static model definitions for devin/gemini-3-8-flash (1M context, Google) and devin/grok-4-6 (500k context, xAI).
- Support gemini38Efforts (low/medium/high) and grok46Efforts (low/medium/high/xhigh) in ResolveDevinChatModelUID, supporting both colon and parenthesis suffix parsing.
- Recognize Gemini Tink thought signatures (AY-prefix / 0x01 Tink header) in detectSignatureType and parseSignatureBytes.
- Add unit tests for both models in registry and devin_models.
2026-09-13 23:34:43 +08:00
sususu
5b8e3821b1 fix(devin): strip system prompt lines matching configured sensitive words to evade unicode normalization bypass 2026-09-13 23:34:43 +08:00
sususu
7b5741c639 feat(devin): support credential quota and seat status query via GetUserStatus
- Implement Connect-RPC GetUserStatus serialization and response parsing in internal/auth/devin/user_status.go.
- Extract user email, plan, username, user_id, team_id, org_id, daily/weekly quota percentages, and reset timestamps.
- Wire user status into DevinExecutor.Refresh to update auth metadata and Quota.Signals.
- Add devin to ProviderSupportsQuotaObservation so CPA management endpoints surface quota observations.
- Enrich Devin OAuth login flow with user status, email, and quota information, and add CSRF state verification.
- Support base_url override in DevinAuthService for mock testing and custom gateways.
2026-09-13 23:34:43 +08:00
sususu
c0b76c2d09 refactor(devin): keep sensitive words strictly external in config.yaml without hardcoding 2026-09-13 23:34:43 +08:00
sususu
c0b86059c4 fix(devin): sanitize claude subagent identity and emoji directives to prevent content policy 403 2026-09-13 23:34:43 +08:00
sususu
d115fe2c45 refactor(devin): align sensitive-words with antigravity to config.yaml only 2026-09-13 23:34:43 +08:00
sususu
1b6948513d feat(devin): support sensitive-words in auth json metadata and attributes 2026-09-13 23:34:43 +08:00
sususu
f5247e496f fix(devin): restrict sensitive word obfuscation strictly to system prompt only 2026-09-13 23:34:43 +08:00
sususu
02fd1bde78 feat(devin): restrict glm-5-2 to free tier, remove static swe-1-7-lightning, and harden cloak 2026-09-13 23:34:43 +08:00
sususu
eed249072d feat(devin): prefix all Devin model IDs with devin/ namespace 2026-09-13 23:34:43 +08:00
sususu
cbe800aa28 feat(devin): bind upstream session_id and cascade_id to CPA canonical session 2026-09-13 23:34:43 +08:00