Commit Graph
100 Commits
Author SHA1 Message Date
Tam Nhu Tran eadcef2289 fix(docs): update star history chart with encrypted sealed_token 2026-08-26 23:01:11 -04:00
Tam Nhu Tran 78ad297e30 ci(docker): allow cold-start healthcheck window 2026-08-09 00:09:52 -04:00
Tam Nhu Tran 54efb82055 fix(auth): guard shared linking against instance replacement 2026-08-08 23:06:29 -04:00
Tam Nhu Tran 5f9db033e7 chore: merge origin/dev into issue #1688
# Conflicts:
#	docs/reports/hardening-inventory.json
#	docs/reports/hardening-inventory.md
2026-08-08 22:29:46 -04:00
Tam Nhu Tran 0ddeb09955 chore(dev): merge v8.8.1-dev.20 for issue 1686 2026-08-08 22:09:27 -04:00
Tam Nhu Tran ce8ad269f0 chore(merge): sync dev release v8.8.1-dev.19 2026-08-08 21:48:56 -04:00
Tam Nhu Tran 4d5449a493 Merge remote-tracking branch 'origin/dev' into kai/review/pr-1691
# Conflicts:
#	docs/reports/hardening-inventory.json
#	docs/reports/hardening-inventory.md
2026-08-08 21:31:32 -04:00
Tam Nhu Tran 1a80717f99 fix(bar): harden lifecycle process handling 2026-08-08 21:17:51 -04:00
Tam Nhu Tran 6841025bb4 feat(auth): share canonical Claude memory
Refs #1688
2026-08-08 21:17:32 -04:00
Tam Nhu Tran 3e38208b37 docs(readme): clarify supported proxy runtimes
Refs #1686
2026-08-08 21:17:24 -04:00
Tam Nhu Tran d8210cf011 fix(proxy): stabilize upstream fetch transport
Refs #1686
2026-08-08 21:17:13 -04:00
Tam Nhu Tran 379008383e chore(reports): refresh hardening inventory
Refs #1685
2026-08-08 21:17:12 -04:00
Tam Nhu Tran 6721d47502 fix(auth): preserve explicit resume session continuity
Refs #1685
2026-08-08 21:17:01 -04:00
Tam Nhu Tran 59eec74f40 chore: merge released dev into PR #1690 2026-08-08 21:14:50 -04:00
Tam Nhu Tran da2de60015 fix(bar): bound native credential and quota waits 2026-08-08 21:12:28 -04:00
Tam Nhu Tran c621241a2e test(proxy): harden system message ordering
Cover supported late-system and tool-result ordering invariants.

Refs #1687
2026-08-08 20:59:37 -04:00
Tam Nhu Tran b022d362dd chore(hardening): refresh filesystem inventory 2026-08-02 20:21:19 -04:00
Tam Nhu Tran 7ae617f0ee fix(shared-manager): preserve diverged files safely 2026-08-02 20:21:09 -04:00
Tam Nhu Tran 26c1393c16 ci(review): configure explicit reasoning effort 2026-07-31 10:32:32 -04:00
Tam Nhu Tran 8d7446e3ff chore(hardening): refresh Gemini auth inventory 2026-07-29 14:24:20 -04:00
Tam Nhu Tran c4fc5e8985 test(cliproxy): cover Gemini OAuth capabilities 2026-07-29 14:24:13 -04:00
Tam Nhu Tran 19c6c3f457 fix(cliproxy): probe Gemini OAuth support 2026-07-29 14:24:12 -04:00
Tam Nhu Tran 32c8c7b767 chore(hardening): refresh routing inventory 2026-07-29 14:02:52 -04:00
Tam Nhu Tran 2ce3bfca26 test(cliproxy): cover routing rule preservation 2026-07-29 14:02:40 -04:00
Tam Nhu Tran 9fb2016f90 feat(cliproxy): persist scoped routing rules 2026-07-29 14:02:40 -04:00
Tam Nhu Tran cd9569e726 chore(hardening): refresh context window inventory 2026-07-29 13:46:53 -04:00
Tam Nhu Tran c107a6752c test(cliproxy): cover auto compact windows 2026-07-29 13:46:53 -04:00
Tam Nhu Tran b0732613a3 feat(cliproxy): expose model context windows 2026-07-29 13:46:53 -04:00
Tam Nhu Tran d6346f0663 chore(hardening): refresh source inventory 2026-07-29 13:28:57 -04:00
Tam Nhu Tran 92fb66c47b test(cliproxy): cover Claude quota probe 429s 2026-07-29 13:22:21 -04:00
Tam Nhu Tran f89f136a1b docs: clarify disabled WebSearch launch behavior 2026-07-29 13:22:21 -04:00
Tam Nhu Tran bdcfc20c0f fix(cliproxy): classify Claude quota probe 429s 2026-07-29 13:22:21 -04:00
Tam Nhu Tran 7786258cb2 chore(lint): refresh throw error baseline 2026-07-29 13:22:21 -04:00
Tam Nhu Tran 9f5706c275 test(websearch): cover disabled launch snapshots 2026-07-29 13:22:21 -04:00
Tam Nhu Tran abc3002e89 fix(websearch): honor disabled steering per launch 2026-07-29 13:22:21 -04:00
Tam Nhu Tran 348d230298 docs: document Brazilian Portuguese locale 2026-07-29 12:56:42 -04:00
Tam Nhu Tran 0a80dddb9c fix(i18n): complete Brazilian Portuguese locale 2026-07-29 12:54:35 -04:00
Tam Nhu Tran 794983ca13 chore(reports): refresh hardening inventory 2026-07-29 12:53:00 -04:00
Tam Nhu Tran d700030018 test(cliproxy): cover concurrent state writers 2026-07-29 12:52:03 -04:00
Tam Nhu Tran 66794e0732 fix(cliproxy): retry contended state locks 2026-07-29 12:52:03 -04:00
Tam Nhu Tran 0629b4a405 test(ui): cover Claude Opus 5 catalog visibility 2026-07-29 12:36:42 -04:00
Tam Nhu Tran af4e4fb353 fix(cliproxy): correct Claude Opus 5 metadata 2026-07-29 12:36:25 -04:00
Tam Nhu Tran 8dc6b817b2 test(docs): enforce documentation freshness 2026-07-26 09:36:01 -04:00
Tam Nhu Tran 306a8276b3 fix(metrics): enforce exact runtime inventory 2026-07-26 09:36:00 -04:00
Tam Nhu Tran 426dc541a9 docs(roadmap): replace historical trackers with live guidance 2026-07-26 09:36:00 -04:00
Tam Nhu Tran 75e715eebd docs(hygiene): remove superseded local guides 2026-07-26 09:35:42 -04:00
Tam Nhu Tran 4485fd6406 docs(macos): consolidate CCS Bar maintainer guidance 2026-07-26 09:35:42 -04:00
Tam Nhu Tran fd0d4362b3 docs(config): preserve active developer contracts 2026-07-26 09:35:42 -04:00
Tam Nhu Tran deb1ed0e67 docs(readme): route user guides to canonical docs 2026-07-26 09:35:42 -04:00
Tam Nhu Tran 51e8062995 docs(operations): refresh runtime contracts 2026-07-26 09:35:10 -04:00
Tam Nhu Tran ebe1746459 docs(architecture): reconcile provider and target contracts 2026-07-26 09:35:00 -04:00
Tam Nhu Tran b918783293 docs(product): refresh product and release contracts 2026-07-26 09:34:48 -04:00
Tam Nhu Tran 1e11335348 docs(contributing): align test and UI guidance 2026-07-26 09:34:18 -04:00
Tam Nhu Tran 721ca5fc33 docs(architecture): replace volatile maintainer snapshots 2026-07-26 09:34:09 -04:00
Tam Nhu Tran 3bb2d56778 docs(ai): define documentation truth hierarchy 2026-07-26 09:33:56 -04:00
Tam Nhu Tran 2d909a162f Merge remote-tracking branch 'origin/dev' into kai/review/pr-1655-retry-followup 2026-07-22 15:08:11 -04:00
Tam Nhu Tran 480b79551b fix: apply cliproxy retry settings safely 2026-07-22 15:08:06 -04:00
Tam Nhu Tran f7241d0874 fix: propagate fable model mapping across runtime paths 2026-07-22 14:58:57 -04:00
Tam Nhu Tran c23b6bee19 fix(ui): preserve untrusted origins in dev proxy 2026-07-22 10:36:38 -04:00
Tam Nhu Tran 003342f604 hotfix(docker): select Alpine-compatible CLIProxy asset 2026-07-18 19:55:07 -04:00
Tam Nhu Tran 44718e98ef fix(auth): preserve xAI profile compatibility 2026-07-18 19:04:37 -04:00
Tam Nhu Tran 4e4c949967 fix(cliproxy): harden xAI provider contracts 2026-07-18 19:04:07 -04:00
Tam Nhu Tran 90c0409aac Merge remote-tracking branch 'origin/dev' into kai/review/1641-xai-grok 2026-07-18 18:14:56 -04:00
Tam Nhu Tran 6dc199a038 fix(ci): isolate Bar command fast tests 2026-07-18 17:46:53 -04:00
Tam Nhu Tran 8996c92fda fix(bar): preserve quota cache and reset semantics 2026-07-18 17:28:36 -04:00
Tam Nhu Tran f77ed33cc7 fix(bar): show Claude and Codex pool quota 2026-07-18 17:13:40 -04:00
Tam Nhu Tran 234dce3150 fix(codex-auth): reject aliased plugin cache paths 2026-07-15 11:36:15 -04:00
Tam Nhu Tran 3103af5355 docs(codex-auth): document shared plugin cache 2026-07-15 10:24:13 -04:00
Tam Nhu Tran 960d6e23a0 test(codex-auth): cover profile cache repair entry points 2026-07-15 10:24:13 -04:00
Tam Nhu Tran e5d4d860b3 fix(codex-auth): share plugin cache across profiles 2026-07-15 10:24:13 -04:00
Tam Nhu Tran 72f00bac1f Merge remote-tracking branch 'origin/dev' into kai/review/pr-1634 2026-07-13 09:26:00 -04:00
Tam Nhu Tran b52e42eba4 Merge remote-tracking branch 'origin/dev' into kai/review/pr-1634 2026-07-13 09:16:46 -04:00
Tam Nhu Tran 5943c8fa3c fix: strip stale Gemini extended context suffixes 2026-07-13 09:14:04 -04:00
Tam Nhu Tran 24eae8ae8f feat(codex): add GPT-5.6 model catalog
Closes #1633
2026-07-10 08:54:48 -04:00
Tam Nhu Tran 77e73dd091 fix(codex): preview joined migration TOML repair
Closes #1635
2026-07-10 08:54:18 -04:00
Tam Nhu Tran c8a4b42990 feat: add Sonnet 5 to Claude provider catalog 2026-07-02 10:31:42 -04:00
Tam Nhu Tran 631a515986 feat: support custom GHCP model selection 2026-07-02 10:10:28 -04:00
Tam Nhu Tran 8c05bf5d67 Merge remote-tracking branch 'origin/dev' into kai/review/pr-1611-thinking-signature 2026-06-29 12:59:09 -04:00
Tam Nhu Tran 045fc93285 test(glmt): align thinking signature coverage 2026-06-29 12:58:38 -04:00
Tam Nhu Tran 13e23e0fc5 docs(cliproxy): document strip-vs-overlay launch-settings siblings and model-key superset
Cross-reference the two helpers that solve the persisted-settings-env
override (overlay in launch-settings.ts, strip in
openai-compat-launch-settings.ts) and mark shell-executor's
ANTHROPIC_MODEL_ENV_KEYS as the intentional superset distinct from the
4-key list in extended-context-utils. See issue #1609.
2026-06-27 10:55:11 -04:00
Tam Nhu Tran e5db374e98 test(cliproxy): cover launch-settings corrupt-JSON fallback and overlay permissions
Add a test for the env-only overlay fallback when the persisted settings
file is corrupt (the existing 'missing file' test skips JSON.parse), and
a POSIX-gated assertion that the overlay is written 0600 inside a 0700
dir, since it carries an auth token.
2026-06-27 10:55:00 -04:00
Tam Nhu Tran 454e1555a7 fix(cliproxy): clean up launch-settings overlay on synchronous spawn failure
The runtime settings overlay cleanup was registered only on the child
'exit'/'error' events, which run after spawn() returns. A synchronous
spawn() throw (e.g. invalid arg/env) propagated out of launchClaude
before those handlers were wired, orphaning the secret-bearing 0600
overlay file in os.tmpdir(). Wrap the spawn in try/catch and run the
idempotent cleanup before rethrowing.
2026-06-27 10:54:50 -04:00
Tam Nhu Tran c70a73a139 Merge pull request #1606 from juwain/fix/codex-in-array-system-messages
fix(codex): keep proxy chain authoritative over --settings env
2026-06-27 10:20:25 -04:00
Tam Nhu Tran b514986ddd fix(bar): short-TTL parked rows + keep valid codex subs active
Addresses two review focus areas:

- Stale Parked Rows: profiles with no on-disk credentials cached their parked
  row for the full quota TTL, so a fresh login stayed dimmed for up to 10 min.
  Parked rows (quotaStatus 'unsupported') now use a 30s TTL so a new login is
  picked up within seconds.
- Codex Fallback: a named codex profile whose token authenticated but whose
  response lacked core windows was downgraded to a parked/needsAuth row, hiding
  a real subscription. It now emits an active (quota-less) row; only the bare
  default still falls back to global local session data.

Also fixes a latent coalescing bug the short TTL exposed: a synchronous return
inside the pending IIFE cleared state.pending during its own assignment, leaving
a stale resolved promise that the next call reused. The IIFE now yields once so
the assignment lands before the finally clears it.
2026-06-24 00:52:55 -04:00
Tam Nhu Tran a1a565177e fix(codex): route codex CLI to /backend-api/codex on original CLIProxy backend
The Codex CLI provider config uses wire_api = "responses", so the Codex CLI
appends "/responses" to its base_url. buildCodexCliproxyProviderBaseUrl derived
the base URL from the backend-aware route helper, which returns the bare root for
the original backend. Codex then called http://127.0.0.1:<port>/responses, which
the original CLIProxy binary does not serve, producing a 404 on every request.

The original backend serves the Codex Responses API only at /v1/responses and the
chatgpt_base_url-compatible alias /backend-api/codex/responses. Use that alias for
the original backend; keep the provider-scoped alias for the Plus backend.

Closes #1597
2026-06-24 00:08:02 -04:00
Tam Nhu Tran 7b610f0e82 fix(bar): keep is_default on cache-fallback rows
The collector cached each row before the default profile was resolved, so the
cache-fallback path (getCachedNativeAccountRows) served the default account with
is_default:false -- the UI then lost default ordering/tagging when /summary
served from cache. Write the resolved default flag back onto the cached copy so
the fallback stays consistent with a fresh collection.
2026-06-24 00:03:20 -04:00
Tam Nhu Tran f57eed8c34 feat(bar): make the profile carousel mouse-navigable
The horizontal paging carousel only responded to trackpad swipe; a mouse could
not move it. Add clickable prev/next arrows and make the page dots tappable --
each sets the scrollPosition binding (animated), so mouse users can page through
a provider's profiles. Trackpad swipe is unchanged.
2026-06-23 23:49:11 -04:00
Tam Nhu Tran a0a2dd00fa fix(bar): cache expired profiles and gate codex local fallback to the default
Addresses two review focus areas:

- Reauth polling: a 401/expired profile now caches its dimmed reauth row and
  opens a cooldown, so it is shown parked and re-checked at most every 10 min
  instead of being re-polled (and re-401'd) on every /summary refresh.
- Wrong fallback: the global ~/.codex session-log fallback now applies ONLY to
  the bare default account. A named codex profile with no on-disk auth parks
  instead of borrowing the default's local usage (no misattribution).
2026-06-23 23:47:06 -04:00
Tam Nhu Tran ae5cd9b98d chore(bar): drop low-value PR screenshot asset 2026-06-23 23:38:52 -04:00
Tam Nhu Tran d9bd5b6f86 fix(bar): tighten subscription carousel spacing
The per-provider carousel reserved more height than a card needs, leaving blank
space between each card and its page dots. Size the paged frame to the tallest
card (title + one bar per window + optional stale footnote) instead of a generous
estimate, and trim the subscriptions section spacing from 8 to 6.
2026-06-23 23:36:06 -04:00
Tam Nhu Tran 74ea8ead6c chore(bar): refresh PR screenshot with live ccs + ccsx defaults 2026-06-23 23:16:45 -04:00
Tam Nhu Tran 54ef5406ce fix(bar): show the active default ccs login as the leading Claude account
The multi-profile path enumerated only named ccs auth profiles, dropping the
bare ~/.claude default login that the shipped Bar showed. Re-add it as the
DEFAULT_PROFILE account read through the standard global credential lookup
(file, falling back to the single global 'Claude Code-credentials' Keychain
item Claude Code itself maintains) -- the one pre-existing global read, not a
per-profile Keychain scan. It leads the Claude carousel as 'ccs' + 'default'.
2026-06-23 23:16:36 -04:00
Tam Nhu Tran 4e6fe6ffbb chore(bar): refresh PR screenshot for default-first carousel 2026-06-23 23:10:25 -04:00
Tam Nhu Tran b9f6837913 fix(bar): lead carousel with default account, label it as the base command
Address UX review: the bare login (e.g. ~/.codex) is the default way of running a
surface, not a profile. Rename it from 'personal' to 'default' and present it as
the base command ('ccsx') with a 'default' badge, while named profiles show their
name ('ck') plus the owning surface tag ('ccsx'). Order each provider carousel so
the default account leads, then by tightest quota window.
2026-06-23 23:10:15 -04:00
Tam Nhu Tran 50893319e5 chore(bar): add PR evidence screenshot for multi-profile carousel 2026-06-23 22:56:58 -04:00
Tam Nhu Tran e8adcb8999 feat(bar): per-provider profile carousel with ccs/ccsx surface tags
Group native subscription rows by provider and render each provider as its own
horizontally paged carousel of profile cards (one profile per page, swipe
between a provider's profiles, page dots indicate count). Add a surface tag
chip (ccs/ccsx) and dim parked profiles. Switch the native-vs-pool split to the
is_subscription flag so pool codex accounts are not misclassified. Raise the
deployment target to macOS 14 for the native scroll paging APIs and bump the
Bar version to 1.9.0.
2026-06-23 22:56:48 -04:00
Tam Nhu Tran ed86a089ba feat(bar): enumerate ccs/ccsx subscription profiles with per-profile quota
Replace single-account native quota collection with per-profile enumeration:
read ccs auth (Claude) and ccsx auth (Codex) profile registries plus the bare
~/.codex login, fetch each profile's quota under the existing TTL cache,
per-profile circuit breaker and 2.5s summary deadline. Emit surface, profile
and is_subscription wire fields; account_id becomes "<surface>:<profile>".

Active profiles (valid token) are live-polled and shown undimmed regardless of
default status; profiles without resolvable on-disk credentials are parked
(cache-only, dimmed). Claude per-profile credentials are read from disk only --
no macOS Keychain access -- so a profile without a credentials file renders as
needs-reauth instead of triggering a keychain prompt.
2026-06-23 22:56:38 -04:00
Tam Nhu Tran 999f130e4b fix(bar): update release target when publishing app 2026-06-23 17:25:10 -04:00
Tam Nhu Tran db40e5bda0 chore(bar): bump CCS Bar to 1.8.1 2026-06-23 17:18:09 -04:00
Tam Nhu Tran 239f83df9d test(bar): cover ccs bar install --await-quit relaunch path 2026-06-22 21:07:13 -04:00