50 Commits
Author SHA1 Message Date
Tam Nhu Tran 0ddeb09955 chore(dev): merge v8.8.1-dev.20 for issue 1686 2026-08-08 22:09:27 -04:00
Tam Nhu Tran d8210cf011 fix(proxy): stabilize upstream fetch transport
Refs #1686
2026-08-08 21:17:13 -04:00
Tam Nhu Tran c621241a2e test(proxy): harden system message ordering
Cover supported late-system and tool-result ordering invariants.

Refs #1687
2026-08-08 20:59:37 -04:00
sn4p.dev b720231077 fix(proxy): hoist duplicate system messages before coalescing
Claude Code sends the system prompt as the top-level `system` field and,
separately, sends skill/plugin listings as `role: "system"` entries inside
`messages` (#1459 made the transformer accept those). `transform()`
unconditionally prepends the top-level field, so once both are present the
OpenAI-compat payload ends up with two `system` messages that are not
adjacent. `coalesceMessages` only merges consecutive same-role messages and
explicitly skips `system`, so it cannot fix this.

Strict OpenAI-compatible backends (LiteLLM among them) reject that shape with:
  400 A 'system' message can only appear at index 0 of the messages array.

Add `hoistSystemMessages`, run before `coalesceMessages`, which extracts every
`system` message in encounter order and reinserts a single merged one at
index 0. Content-preserving, no behavior change when at most one system
message is present.
2026-08-06 11:28:18 +02:00
Kai (Tam Nhu) Tran 2e702b1d35 Merge pull request #1574 from ReWiG/fix/stream-options-include-usage
fix(proxy): forward stream_options.include_usage to OpenAI-compatible upstreams
2026-06-22 16:16:40 -04:00
ReWiG 2aaad43fd7 fix(proxy): forward stream_options.include_usage to OpenAI-compatible upstreams
Claude Code's status line and the session log showed 0 tokens for every
streaming response routed through the OpenAI-compatible proxy. The root
cause was that the upstream request did not include
`stream_options: { include_usage: true }`, so the provider (LiteLLM and
other OpenAI-compatible endpoints) never emitted the final SSE chunk
that carries `usage`. The proxy's stream parser was already wired to
forward that chunk into an Anthropic-shaped `message_delta` event but
had nothing to forward.

Set `stream_options.include_usage` whenever the incoming Anthropic
request is streamed. Non-streamed requests are unaffected.

Ref: https://platform.openai.com/docs/api-reference/chat-streaming
     (search 'include_usage')
2026-06-19 21:45:47 +03:00
Tam Nhu Tran 87aeb8f193 feat(logging): P3 hotpath console.error migration + redaction gate (928->267)
Epic P3. Migrates hotpath console.error/warn to the structured logger
(diagnostics) or process.stderr.write (user-facing), and adds a redaction
safety gate so the migration cannot leak credentials.

Redaction gate (MR1):
- log-redaction: scrub known credential token shapes (sk-ant, sk-, xoxb,
  ghp, glpat, AIza, JWT bodies, api_key=, Bearer/Basic/Token scheme) in
  string values, Error.message, AND the log message string (defense-in-depth).
- logger: message now passes through maskSecretTokens.

tool-sanitization-proxy: deleted the private file-logging subsystem
(initLogFile/writeLog/log/warn, logFilePath, debugMode); 13 call sites now
route through the existing createLogger('cliproxy:tool-sanitization-proxy').

Sweep (~120 diagnostic -> structured createLogger; ~540 user-facing -> stderr):
- diagnostics converted across proxy, web-server/routes, glmt pipeline, quota
  fetchers, executors, delegation, session-bridge, https-tunnel-proxy.
- user-facing CLI output (flows, arg-parser usage, installers, prompts, adapter
  launch errors, error display) moved to process.stderr.write (preserves stderr).
- src/utils/error-manager.ts reclassified CLI-UX-exempt (user-facing display).

Metric: hotpath console.error 928 -> 267 (71%); createLogger files 35 -> 64.
Residual 267 is user-facing CLI output (not diagnostics); documented in
docs/hardening-debt-burndown.md. Redaction gate makes further conversion safe.

Tests: hotpath-redaction-regression (12 token shapes); updated delegation-handler,
arg-parser, model-warnings spies (console.error -> process.stderr.write).
validate + validate:ci-parity green.
2026-06-18 18:48:12 -04:00
kcfang 8f9795bce2 fix(proxy): keep undici timeouts above the upstream request timeout (#1524)
Sets undici headersTimeout/bodyTimeout to request_timeout+30s so the AbortController is the single authority on upstream request lifetime, preventing premature socket closes on slow self-hosted upstreams. Verified undici v5 ProxyAgent object-signature compat.
2026-06-15 21:57:23 -04:00
Tam Nhu Tran bb9d23ad6a fix(proxy): route Anthropic passthrough by upstream profile 2026-06-14 11:19:58 -04:00
Sanskar Singh b98b0df084 fix(proxy): add Anthropic passthrough mode for coding-agent-only endpoints
Some providers (e.g. Kimi, Anthropic-API mirrors) reject OpenAI-format
chat-completions requests and/or only accept requests from a recognized
coding-agent User-Agent (e.g. Claude Code, Roo Code, Kilo Code). The
OpenAI-compat proxy previously translated every profile's request to
OpenAI format and overwrote the User-Agent with a fixed sentinel,
which made these providers unreachable.

This change adds an opt-in Anthropic passthrough mode:

- New CCS_OPENAI_PROXY_PASSTHROUGH=1 env var on a profile opts it in.
- The base URL is auto-detected as Anthropic-style for known hosts
  (api.kimi.com, api.minimax.com, api.anthropic.com) or any base URL
  ending in /v1.
- In passthrough mode the proxy forwards the incoming Anthropic body
  verbatim to the upstream /v1/messages endpoint, preserving the
  original User-Agent (or x-stainless-user-agent) so coding-agent
  provider checks pass.
- The Anthropic-format response is streamed back unchanged.

Adds:
- isAnthropicPassthroughProfile() + passthrough option on
  resolveOpenAIChatCompletionsUrl/resolveOpenAIModelsUrl
- CCS_OPENAI_PROXY_PASSTHROUGH env var on OpenAICompatProfileConfig
- readRawBody() helper for the passthrough path
- Preserved User-Agent (or x-stainless-user-agent) on the upstream
  request, falling back to CCS-OpenAI-Compat-Proxy/1.0
- Skip SSE response transformation in passthrough mode (upstream
  already returns Anthropic-format bytes)

Tests:
- 9 new tests in upstream-url.test.ts covering auto-detection and the
  passthrough URL contract
- 2 new tests in profile-router.test.ts covering the env var

Verified end-to-end against api.kimi.com: a request through the
modified proxy returned a real Kimi response (model kimi-k2p7-coding)
with the original claude-cli/2.1.170 User-Agent preserved.
2026-06-13 01:39:49 +05:30
Tam Nhu Tran 8282ff68a1 fix(proxy): support opt-in OpenAI reasoning shaping 2026-06-03 11:08:41 -04:00
Kai (Tam Nhu) Tran 5619f32651 Merge pull request #1447 from kaitranntt/codex/fix-pid-only-proxy-cleanup-issue
fix(proxy): load pid-only profile daemon state
2026-05-30 15:45:50 -04:00
Kai (Tam Nhu) Tran 216fae7d57 fix(proxy): load pid-only profile daemon state 2026-05-30 14:56:46 -04:00
Halil Ertekin f42aee9a20 fix: handle system messages in OpenAI proxy (#1403) 2026-05-28 22:08:07 -04:00
Kai (Tam Nhu) Tran 24478135dc fix(proxy): scope insecure TLS to routed profile
Squash merge PR #1299 into dev.
2026-05-19 08:13:40 -04:00
Kai (Tam Nhu) Tran fa31bea672 fix(proxy): require owned daemon PID before reusing legacy/profile proxy session
Squash merge PR #1298 into dev.
2026-05-19 08:05:45 -04:00
Tam Nhu Tran 1932b2ca61 fix(proxy): strip stale encoding from upstream error responses 2026-05-13 09:13:28 -04:00
Kai (Tam Nhu) Tran a840793a9b fix(proxy): avoid exposing local auth token in daemon argv (#1230) 2026-05-12 18:13:20 -04:00
Tam Nhu Tran dc8bbd85e7 fix: route OpenRouter profiles through v1 API 2026-05-05 11:44:58 -04:00
Tam Nhu Tran 4f6e61739c refactor(config): adopt config-loader-facade across the codebase
Issue #1161. Sweeps 127 files to import from
src/config/config-loader-facade.ts instead of unified-config-loader or
utils/config-manager directly.

WRITE callers (32 files): replaced raw saveUnifiedConfig /
mutateUnifiedConfig / updateUnifiedConfig calls with the facade's
cache-coherent wrappers saveConfig / mutateConfig / updateConfig. This
fixes a latent stale-cache window where direct writes through the
underlying loader bypassed the facade's memoization.

READ callers (95 files): mechanical import-path migration only —
function names unchanged because the facade re-exports them. No
behavior change.

Also updated:
- tests/unit/utils/browser/browser-setup.test.ts (DI interface rename)
- src/management/checks/image-analysis-check.ts (dynamic import rename)
- src/web-server/health-service.ts (dynamic require rename)
- src/ccs.ts (path prefix fix from sweep script)

After sweep: zero raw write callers remain outside src/config/. Direct
imports of config-manager remain only for symbols not in the facade
(getConfigPath, getCcsDirSource, etc). Behavior unchanged; full suite
passes 1824/1824.

Out of scope: switching loadOrCreateUnifiedConfig() callers to
getCachedConfig() — needs per-callsite cache-safety analysis. Tracked
as follow-up.

Refs #1161
2026-05-03 01:42:53 -04:00
Tam Nhu Tran 4700727915 feat(proxy,cli): emit lifecycle stages with x-ccs-request-id propagation
Wrap proxy server entry edge in withRequestContext so every inbound request
gets a requestId (reused from x-ccs-request-id header when valid UUID-ish,
freshly minted otherwise). messages-route emits 7 stages: intake / auth /
transform / route / dispatch / upstream / respond, each with latencyMs and
structured error metadata on failure.

CCS CLI entry (ccs.ts) wraps main() in runWithRequestId and emits
cli.command.start / complete / failed stages so command lifecycle is
correlatable end-to-end.

Refs #1141, #1138
2026-04-30 13:00:00 -04:00
Tam Nhu Tran d9ace607e5 fix(proxy): shape direct OpenAI reasoning chat payloads 2026-04-30 12:33:02 -04:00
seilk 83c16e216a fix(proxy): avoid leaking tool_result image URLs 2026-04-30 02:18:22 +09:00
seilk f6bb31c956 fix(proxy): stringify tool_result images for OpenAI upstreams 2026-04-30 00:55:45 +09:00
Chris Weller 1c91c46326 fix(proxy): avoid settings override and nested reasoning for openai-compat 2026-04-26 14:53:25 -06:00
Tam Nhu Tran d5591913ef fix(proxy): clarify shared port fallback and legacy 3456 handling 2026-04-23 15:00:50 -04:00
Tam Nhu Tran 15751e2db5 feat(proxy): add adaptive local port selection for OpenAI-compatible profiles 2026-04-23 14:47:01 -04:00
Tam Nhu Tran 71deda553a fix(cliproxy): preserve adaptive thinking on opus 4.7 paths 2026-04-22 21:43:11 -04:00
Tam Nhu Tran 399f403322 fix(transformers): preserve tool ordering across proxy streams
- reject pending tool_result layouts that cannot be translated without reordering user content

- keep interleaved GLMT tool_use blocks open until finalization instead of stopping early

- cover leading/interleaved tool_result regressions and interleaved streaming tool fragments
2026-04-20 13:17:30 -04:00
Grandis SYF a0f91761ed feat(glmt): fix sequential tool_use block handling 2026-04-20 13:06:00 -04:00
Grandis SYF baa58c9543 feat(proxy): add HEAD method support for health probe endpoints 2026-04-20 13:06:00 -04:00
Tam Nhu Tran 1cfed73ca5 fix(proxy): harden stale daemon ownership checks 2026-04-20 12:44:30 -04:00
Wooseong Kim afcb1abf9e fix(proxy): retain explicit profile names in status 2026-04-20 15:30:51 +09:00
Wooseong Kim 391bdddc22 fix(proxy): handle legacy stop and preferred ports 2026-04-20 15:25:16 +09:00
Wooseong Kim c0c119867a fix(proxy): persist daemon state after startup 2026-04-20 15:04:24 +09:00
Wooseong Kim 8ad2763942 fix(proxy): retry candidate ports on bind conflict 2026-04-20 14:59:59 +09:00
Wooseong Kim db32d15d86 fix(proxy): preserve running daemons on restart failure 2026-04-20 14:51:32 +09:00
Wooseong Kim 7cf555356a fix(proxy): retry raced dynamic port binds 2026-04-20 14:33:44 +09:00
Wooseong Kim f345cf441e fix(proxy): ignore legacy singleton session file 2026-04-20 14:09:50 +09:00
Wooseong Kim 24c24847f7 fix(proxy): preserve legacy state and exact ports 2026-04-20 14:03:12 +09:00
Wooseong Kim 630a493cca fix(proxy): disambiguate activate without profile 2026-04-20 13:28:25 +09:00
Wooseong Kim 94bf1fbfe9 feat(proxy): support profile-scoped local proxy ports 2026-04-20 13:14:19 +09:00
Tam Nhu Tran ebc92194bb fix(proxy): harden Anthropic request transformation semantics
- enforce strict tool_result ordering and pairing against assistant tool_use ids
- reject tool_result image payloads that cannot map to OpenAI tool messages
- preserve raw tool schemas on the /v1/messages proxy path instead of silently tightening them
- forward Anthropic tool_choice semantics and cover adaptive routing plus upstream payload checks
2026-04-18 19:39:13 -04:00
Tam Nhu Tran 32d6bfdda7 fix(proxy): restore strict Anthropic message validation 2026-04-18 19:02:38 -04:00
Grandis SYF 2672e35362 feat(proxy): enhance Anthropic-to-OpenAI message transformation and schema sanitization 2026-04-18 13:49:20 +07:00
Tam Nhu Tran 841eeb497c fix(proxy): keep stream guards active through sse piping 2026-04-15 02:52:29 -04:00
Tam Nhu Tran a3407093d7 refactor(proxy): internalize sse translation and cleanup handlers 2026-04-15 01:44:01 -04:00
Tam Nhu Tran 17187c4abd feat(proxy): complete openai routing scope 2026-04-15 00:55:11 -04:00
Tam Nhu Tran a6aa576d5a fix(proxy): detect dashscope compatible-mode profiles 2026-04-14 23:49:34 -04:00
Tam Nhu Tran 074e900557 feat(proxy): add openai-compatible local proxy runtime 2026-04-14 19:26:59 -04:00