Commit Graph

616 Commits

Author SHA1 Message Date
Luis Pater
28743473c1 feat(codex): append (Devin) suffix to Devin model display names
- Detect Devin models by ID prefix, type, ownership, model registry metadata, or provider.
- Append `(Devin)` to model display names in Codex client responses when not already present.
- Set model `type` to `devin` in home Codex model formatting when served by the Devin provider.
2026-09-18 10:37:52 +08:00
Luis Pater
0b55053944 fix(management): reject unresolved token placeholders in api-call
- Return an error when the `$TOKEN$` placeholder cannot be resolved or the credential for `auth_index` is missing.
- Ensure `$TOKEN$` substitutions in headers and request payloads fail fast instead of proceeding with empty values.
- Support resolving and refreshing provider OAuth tokens for API calls.

Closes: #5838
2026-09-17 23:43:04 +08:00
camy-x
76ac75e68a feat(management): paginate auth file listings 2026-09-17 14:37:36 +08:00
Luis Pater
42ca5d3412 Merge PR #5502 feat/meta-provider into cpa/muse
Bring in native Meta (Muse Code) provider support while keeping the
existing Devin integration and original Meta commit history.
2026-09-15 12:05:40 +08:00
Luis Pater
512c453e09 Merge pull request #5803 from anpicasso/feat/plugin-quota-summary
feat(plugin-quota): add typed summary metrics
2026-09-15 08:35:47 +08:00
Luis Pater
e3cbe437d0 feat(auth): add tests to ensure async operations don’t block unrelated actions
- Add tests to verify that runtime hooks, auth modifications, and related updates do not block on unrelated operations such as antigravity probes or plugin virtual models.
- Introduce detailed scenarios, e.g., stale disables, batch operations, and conflict handling during concurrent auth updates.
- Refactor locking mechanisms to avoid unnecessary blocking during hooks and model registrations.

Fixed: #5813
Closes: #5773
2026-09-15 01:23:26 +08:00
Luis Pater
7fa443dc8b Merge pull request #5806 from router-for-me/feat/devin-followups
fix(devin): wire protocol submessage decoding, usage fallbacks, model uniqueness, and APICall body token replacement
2026-09-14 09:39:49 +08:00
Luis Pater
cca35aee93 fix(devin): use loopback callback endpoint for oauth redirect uri
- Enforce `http://127.0.0.1:<port>/callback` redirect URI to satisfy Devin authorization validation requirements.
- Register `/callback` route while preserving `/devin/callback` handler.
2026-09-14 09:37:35 +08:00
sususu
4c331bb953 fix(devin): unwrap repeated field 28 groups, merge partial field 7 usage, and harden APICall escaping 2026-09-14 09:32:05 +08:00
Angello Picasso
07e85de1a4 fix(plugin-quota): preserve valid mapped summaries 2026-09-14 01:26:10 +00:00
sususu
0719520f2a feat(api-call): support $TOKEN$ replacement in request body data 2026-09-14 09:20:03 +08:00
Angello Picasso
6aea72e294 fix(plugin-quota): preserve mapped summaries 2026-09-14 01:10:19 +00:00
Angello Picasso
617b9fd17d fix(plugin-quota): validate summary metadata 2026-09-14 01:04:12 +00:00
Angello Picasso
d3cb685944 fix(plugin-quota): validate summary identifiers 2026-09-14 00:42:52 +00:00
Angello Picasso
782a5cd169 fix(plugin-quota): tolerate malformed summaries 2026-09-14 00:37:21 +00:00
Angello Picasso
7b60be3516 fix(plugin-quota): require summary metric values 2026-09-14 00:30:34 +00:00
Angello Picasso
5cb41e233f fix(plugin-quota): accept summary-only probes 2026-09-14 00:18:20 +00:00
Angello Picasso
acb0eae2eb feat(plugin-quota): add typed summary metrics 2026-09-14 00:12:07 +00:00
Supra4E8C
44e62bc8ac feat(devin): implement Devin OAuth flow with callback handling and session management 2026-09-14 01:04:20 +08:00
Luis Pater
7e864ace4d Merge pull request #5797 from router-for-me/feat/cpa-web-search-catalog
feat(models): expose CPA web search capability
2026-09-14 00:59:20 +08:00
Supra4E8C
4311ae8747 feat(models): require explicit per-model native search support 2026-09-14 00:04:41 +08:00
sususu
f94752762b feat(devin): add Devin/Cognition provider integration and CLI OAuth
Implement the full Devin/Cognition Connect-RPC provider support across all CPA endpoints (/v1/chat/completions, /v1/messages, /v1/responses), complete with binary protobuf wire framing, streaming tools/arguments delta handling, thinking/reasoning replay, and CLI OAuth authentication.

Key highlights:
- Wire Protocol & Streaming:
  * Implemented Connect-RPC uncompressed 5-byte framing (0x00 + 4-byte length + protobuf) for ApiServerService/GetChatMessage.
  * Implemented Devin protobuf encoder/decoder in internal/runtime/executor/helps/devin_wire.go, including ClientMetadata, prompts, tools, completion_config, and multimodal image handling (Prompt Field #10).
  * Stream frame consumption via interactions protocol, correctly mapping arguments_delta and tracking multiple sequential tool calls (currentToolCallActive).
  * Streaming thought summary and sealed.v1 signature deltas targeting the thinking step.

- Model Registration & Thinking Clamping:
  * Registered static fallback models in model_definitions.go (swe-2, claude-fable-5-1, gpt-6-astra, swe-1-7-lightning, glm-5-2, glm-5-3).
  * Configured ThinkingSupport with discrete levels per model family.
  * Implemented CPA-standard nearest-neighbor clamping for thinking levels (minimal/low -> medium, xhigh -> max for swe-2).
  * Mapped thinking effort to Devin upstream model UID (e.g. swe-2-medium, swe-2-high, swe-2-max).

- Sensitive Words & System Prompt Sanitization:
  * Added devin.sensitive-words configuration in internal/config/config_types.go and config.go, matching Antigravity conventions.
  * Supported zero-width space (\u200b) obfuscation in prompts, tools, and system instructions via SensitiveWordMatcher.
  * Stripped Claude Code billing headers (x-anthropic-billing-header:) and CLI identity signatures from system instructions and tool descriptions to avoid upstream content filter rejections.

- Signature Compatibility:
  * Added SignatureProviderSWE = "swe" recognizing sealed.v1.* reasoning signatures in internal/signature/provider_compatibility.go.
  * Propagated reasoning.encrypted_content on Responses API and thinking.signature on Messages API.

- Authentication:
  * Implemented Devin PKCE OAuth flow with loopback callback server and headless manual token/code paste (--no-browser).
  * Registered Devin authenticator in SDK and CLI (-devin-login flag).
  * Integrated with management OAuth session endpoints and credentials manager.
2026-09-13 23:34:43 +08:00
Supra4E8C
294b7f5b19 feat(models): expose CPA web search capability 2026-09-13 22:44:19 +08:00
Supra4E8C
d23ba5ee05 Merge pull request #5795 from router-for-me/feat/management-auth-cooldowns
feat(cooldowns): add cooldown snapshot feature for management auth files
2026-09-13 22:17:48 +08:00
Luis Pater
94d6eb535e docs(config): document payload filter examples for codex tools
- Add example payload filter rules in `config.example.yaml` for stripping tools from both flat and nested `additional_tools` Codex request payloads.

Closes: #5792
2026-09-13 22:12:28 +08:00
Supra4E8C
1ca975dfc0 feat(cooldowns): add cooldown snapshot feature for management auth files 2026-09-13 18:50:21 +08:00
Luis Pater
3c3938feb1 feat(plugins): forward query parameters as metadata in auth provider start login
- Accept optional metadata parameters in SDK and internal plugin host `StartLogin` methods.
- Clone and pass metadata to the auth provider's `AuthLoginStartRequest`.
- Convert management auth URL query parameters into metadata before initiating plugin login flows.

Closes: #5760
2026-09-12 20:05:34 +08:00
Luis Pater
b192f6550c feat(management): add plugin quota and declarative probe endpoints
- Add endpoints to list quota providers and fetch or reset credential quotas via plugins.
- Support declarative metadata quota probes with token substitution and response mapping.
- Clear core routing quota state when provider quota reset succeeds.

Closes: #5752
2026-09-12 19:07:43 +08:00
Luis Pater
5b2785617d feat(plugins): expose model list responses to plugin interceptors
- Add `WriteModelListResponse` to `BaseAPIHandler` to apply plugin interceptors and record request lifecycles for model catalog responses.
- Update OpenAI, Claude, Gemini, Grok, and Codex model listing endpoints to route responses through the unified interceptor helper.

Closes: #5742
2026-09-12 00:04:11 +08:00
Luis Pater
456d4c371b fix(auth): clear unauthorized cooldowns on credential changes and sync codex plan type
- Reset unauthorized errors and model cooldowns in lifecycle updates when credentials change.
- Sync `plan_type` attribute from metadata or JWT `id_token` in auth file handlers and synthesizer.
- Invoke `postAuthPersistHook` after auth file upload and field patch operations.

Closes: #5736
2026-09-11 23:31:48 +08:00
Luis Pater
d1702fdffd fix(auth): drop stale auth updates using monotonic watcher revisions
- Track monotonic watcher revisions across persisted auth updates to filter out out-of-order events.
- Validate registration epochs before applying auth updates and deletions to prevent stale state overwrites.
- Synchronize auth status patches through post-persist hooks using detached background contexts.
- Guard auth status modifications with a dedicated handler mutex.

Closes: #5729
2026-09-11 08:18:51 +08:00
Luis Pater
fc96a87fa6 feat(auth): support organization-hashed claude credentials and legacy migration
- Disambiguate Claude credential filenames using organization and account UUID hashes to keep multiple organizations distinct.
- Migrate legacy Claude credentials during login and save flows while preserving existing metadata and deleting obsolete files.
- Introduce `WithAuthCreationIntent` context policy across token stores to allow creating missing disabled credentials during login and migration.
- Preserve existing `disabled` status during auth metadata merges when not explicitly specified.

Closes: #5709
2026-09-11 03:58:23 +08:00
Kenny
c6e076ff41 Merge dev into feat/meta-provider and preserve both registry tests 2026-09-10 14:03:29 +00:00
Luis Pater
d1a024e940 feat(codex): add support for gpt-image-2.5 models
- Register builtin model definitions for `gpt-image-2.5`, `gpt-image-2.5-flare`, and `gpt-image-2.5-sunburst`.
- Update OpenAI image handlers and request routing to recognize GPT Image 2.5 models.
- Support direct image generation and edit execution for GPT Image 2.5 variants in the Codex executor.
- Apply client visibility overrides to hide new builtin image models where appropriate.
2026-09-10 10:40:53 +08:00
Luis Pater
60e5b8bd43 feat(management): add endpoint to refresh auth files
- Add `RefreshAuthFiles` handler to trigger active refresh for single or all auth files.
- Support specifying refresh targets via query parameters or JSON request body.
- Invoke auth manager force refresh operations and return refreshed credential states.

Closes: #5628
2026-09-09 20:05:33 +08:00
Luis Pater
454452d5da Merge pull request #5626 from nichaoshou/fix/healthz-access-log
fix(logging): silence successful health probes while preserving errors
2026-09-09 00:31:32 +08:00
chaoshou
a163c5e7ed fix(logging): silence only successful health probes 2026-09-08 19:17:20 +08:00
chaoshou
e026cbf4e9 fix(api): skip access logging for health probes 2026-09-08 18:41:38 +08:00
Supra4E8C
8c0ad8ccf2 fix(plugin-store): honor shared GitHub API rate-limit cooldowns 2026-09-08 18:18:25 +08:00
Supra4E8C
54b17ce8f7 fix(plugin-store): coalesce and throttle cached release checks 2026-09-08 18:04:29 +08:00
Supra4E8C
1c9d7194e0 fix(plugin-store): only check releases for installed update sources 2026-09-08 17:53:22 +08:00
sususu
d5397905f0 fix(antigravity): default to short connections and harden connection pool lifecycle (fixes #5494)
- Configure upstream connection pool under antigravity.connection-pool with enabled: false by default.
- In short connection mode, set MaxIdleConnsPerHost = -1 with DisableKeepAlives = false, ensuring immediate TCP termination after response body completion without leaking Connection: close request headers.
- When pooling is explicitly enabled (enabled: true), cap idle-conn-timeout at 210s (leaving a 30s safety buffer below Google Frontend's 240s Keep-Alive cutoff) and default max-idle-conns-per-host to 2 (bounded at 100).
- Refactor TransportCache to execute CloseIdleConnections outside the mutex lock during LRU eviction and matching closes.
- Proactively evict and close idle connections on 429 quota exhaustion across Execute, ExecuteStream, and CountTokens.
- Wire hot-reload diff detection and server reload purge hooks for graceful transport pool updates.
2026-09-07 19:15:39 +08:00
sususu
580df36423 feat(usage): propagate session and parent session hierarchy to usage reporting queue
- Reuse coresession.ExtractSessionInfo across HTTP headers and request payloads to unify canonical session prefix namespaces with the scheduler.
- Extract hierarchical session identities in two phases: initial extraction from request headers on entry, and authoritative deep extraction once request payloads and metadata are available.
- Support Claude Code multi-level subagents (X-Claude-Code-Agent-Id, metadata.agent_id) and Codex thread fork lineages.
- Propagate SessionID and ParentSessionID across ClientRequestMetadata, UsageReporter, and coreusage.Record without root_session_id.
- Include session_id and parent_session_id in queuedUsageDetail for Home LPushUsage forwarding and Redis consumption with self-loop guards.
- Add comprehensive test coverage for canonical headers, body extraction, ghost parent elimination, and self-referential loop guards.
2026-09-06 10:45:32 +08:00
Kenny
4a0131c062 fix(meta): unify credential minting and preserve auth lifecycle 2026-09-05 15:17:06 +00:00
Kenny
06660dd6f4 fix(meta): validate catalog section, singleflight management mints, and synchronize singleflight test 2026-09-05 14:36:15 +00:00
Kenny
1144ae707b fix(meta): require OAuth storage for DCA tokens and reject them in config meta-api-key 2026-09-05 14:02:18 +00:00
Kenny
be7323f3bf fix(meta): recover and persist minted credentials correctly 2026-09-05 04:41:42 +00:00
Kenny
21aa46b603 chore(meta): keep provider PR scoped to Meta support 2026-09-05 04:23:06 +00:00
Kenny
cee799f61a fix(meta): address review feedback on credential lifecycle, models, and config loading
- Make optional config loading fail on malformed YAML or validation errors
- Separate DCA token expiry from minted API key expiry in Meta token storage
- Remove global runtime fallbacks from MetaExecutor to prevent cross-account bleed
- Deduplicate inflight DCA minting using singleflight.Group and persist refreshed keys
- Resolve Meta API key in management APICall tool and support DCA minting
- Align models.json with supported chat endpoints and valid thinking levels
- Expand unit tests covering DCA refresh, singleflight, multi-account isolation, and APICall
- Include Meta API key count in client load metrics and diff reporting
2026-09-04 14:00:22 +00:00
Kenny
e475807a96 feat(meta): add Meta API key management handlers, routes, logo, and tests 2026-09-04 13:41:24 +00:00