Commit Graph
4593 Commits
Author SHA1 Message Date
github-actions[bot] 1aacbfd2a8 chore(release): 8.7.0-dev.4 2026-07-01 05:30:54 +00:00
Kai (Tam Nhu) Tran 1ee7cac555 fix: reject case-variant symlinked file paths (#1629)
* fix: reject case-variant symlinked file paths

* fix: validate requested case-variant symlink paths
2026-07-01 01:26:48 -04:00
github-actions[bot] 53fe7e1e8d chore(release): 8.7.0-dev.3 2026-07-01 05:20:05 +00:00
Kai (Tam Nhu) Tran 343899f6c1 fix: prevent default profile credential collision (#1628)
* fix: prevent default profile credential collision

* fix: isolate default profile credential fallback
2026-07-01 01:15:45 -04:00
github-actions[bot] 20df3445d9 chore(release): 8.7.0-dev.2 2026-07-01 05:13:16 +00:00
Kai (Tam Nhu) Tran 0f9a87619c fix: cap native quota profile refresh fan-out (#1627)
* fix: cap native quota profile refresh fan-out

* fix: preserve native quota live cache state
2026-07-01 01:09:01 -04:00
github-actions[bot] f2cd076c08 chore(release): 8.7.0-dev.1 2026-07-01 04:54:25 +00:00
Kai (Tam Nhu) Tran 3621f8dcb1 fix: validate CCS Bar launch shim target integrity (#1626)
* fix: validate CCS Bar launch shim target integrity

* fix: execute verified bar shim bytes
2026-07-01 00:49:56 -04:00
Kai (Tam Nhu) Tran 05685d1c21 fix: keep agy websearch permissions enabled (#1625) 2026-07-01 00:45:09 -04:00
semantic-release-bot 99f023fe3d chore(release): 8.7.0 [skip ci]
## [8.7.0](https://github.com/kaitranntt/ccs/compare/v8.6.1...v8.7.0) (2026-07-01)

### Features

* add Requesty as an OpenAI-compatible provider ([#1604](https://github.com/kaitranntt/ccs/issues/1604)) ([a167f94](https://github.com/kaitranntt/ccs/commit/a167f94e1b07ee47f201cdbbc72c6fd0e68a8738))
* **bar:** enumerate ccs/ccsx subscription profiles with per-profile quota ([ed86a08](https://github.com/kaitranntt/ccs/commit/ed86a089ba9102538f2aee07cd47515c7cb498ed))
* **bar:** make the profile carousel mouse-navigable ([f57eed8](https://github.com/kaitranntt/ccs/commit/f57eed8c34817ea77f313d63029fa9e746f8b9c9))
* **bar:** per-provider profile carousel with ccs/ccsx surface tags ([e8adcb8](https://github.com/kaitranntt/ccs/commit/e8adcb89993c3c972691679aee402e7844f58766))
* **bar:** swipeable profile carousel and condensed alerts ([#1603](https://github.com/kaitranntt/ccs/issues/1603)) ([d7933c6](https://github.com/kaitranntt/ccs/commit/d7933c6243b7593eed524b6aa6c9c977f1e16eea)), closes [#1602](https://github.com/kaitranntt/ccs/issues/1602)
* **websearch:** add agy provider and deprecate gemini cli fallback ([#1607](https://github.com/kaitranntt/ccs/issues/1607)) ([9dd9bf2](https://github.com/kaitranntt/ccs/commit/9dd9bf297890c1802fdc491ec6b909e1e5136a84))

### Bug Fixes

* **auth:** honor legacy unified default profiles ([#1619](https://github.com/kaitranntt/ccs/issues/1619)) ([2f1453e](https://github.com/kaitranntt/ccs/commit/2f1453e39785889ba82cb4183dd0a31f32349f45))
* **bar:** align subscription carousel and collapse stale blank space ([#1600](https://github.com/kaitranntt/ccs/issues/1600)) ([62274da](https://github.com/kaitranntt/ccs/commit/62274dabfa62049a4ab0a0249e59b2d5645bc2b8)), closes [#1599](https://github.com/kaitranntt/ccs/issues/1599)
* **bar:** cache expired profiles and gate codex local fallback to the default ([a0a2dd0](https://github.com/kaitranntt/ccs/commit/a0a2dd00face1825aff6fbc4d87b93bd38bf7f9b))
* **bar:** keep is_default on cache-fallback rows ([7b610f0](https://github.com/kaitranntt/ccs/commit/7b610f0e8275c4d61ae3b35a891cd17ef0f8262e))
* **bar:** lead carousel with default account, label it as the base command ([b9f6837](https://github.com/kaitranntt/ccs/commit/b9f68379135afa653f835cd36fef8a6ad515bad9))
* **bar:** short-TTL parked rows + keep valid codex subs active ([b514986](https://github.com/kaitranntt/ccs/commit/b514986ddd947ebd4a67acd41bf6735586a72959))
* **bar:** show the active default ccs login as the leading Claude account ([54ef540](https://github.com/kaitranntt/ccs/commit/54ef5406ce891343ef6bd7fe885ae5db59466763))
* **bar:** tighten subscription carousel spacing ([d9bd5b6](https://github.com/kaitranntt/ccs/commit/d9bd5b6f8683bc279979156b76935fe09da5288b))
* **bar:** use nonce-bound probe auth ([#1623](https://github.com/kaitranntt/ccs/issues/1623)) ([0180b62](https://github.com/kaitranntt/ccs/commit/0180b624539eda3e34155b4ef3adc169282d3c6a))
* bound bar raw socket probes ([#1618](https://github.com/kaitranntt/ccs/issues/1618)) ([396e01a](https://github.com/kaitranntt/ccs/commit/396e01ab6fbaddf74949a1777dc34a0ebbdc9677))
* **ci:** include compose parity in CI Gate ([#1614](https://github.com/kaitranntt/ccs/issues/1614)) ([58a90d3](https://github.com/kaitranntt/ccs/commit/58a90d3633ddac8a932ef71833f9c53723dda7d5))
* **cliproxy:** clean up launch-settings overlay on synchronous spawn failure ([454e155](https://github.com/kaitranntt/ccs/commit/454e1555a7b1d50f77d77c2fd7b6690930e52260))
* **cliproxy:** keep proxy-chain base URL authoritative over --settings env ([3847443](https://github.com/kaitranntt/ccs/commit/3847443da37aa7361b14d7e840b1fe595991cab0))
* **cliproxy:** mask control panel login key ([#1617](https://github.com/kaitranntt/ccs/issues/1617)) ([bb7c3a4](https://github.com/kaitranntt/ccs/commit/bb7c3a4037db6ff14a9511e6638b039437d7d68b))
* close bar launch case bypass ([#1613](https://github.com/kaitranntt/ccs/issues/1613)) ([3f1dce3](https://github.com/kaitranntt/ccs/commit/3f1dce30bc1a9743e3baab2cc479e32762d68cb5))
* **codex:** normalize CLIProxy responses routes ([#1605](https://github.com/kaitranntt/ccs/issues/1605)) ([ba0e768](https://github.com/kaitranntt/ccs/commit/ba0e768fbf5d92d380caf1b8a1eb6cc2cf9d15fc))
* **codex:** route codex CLI to /backend-api/codex on original CLIProxy backend ([a1a5651](https://github.com/kaitranntt/ccs/commit/a1a565177e5118bb06f1e159ee1dcd887c8ed19e)), closes [#1597](https://github.com/kaitranntt/ccs/issues/1597)
* **cursor:** propagate daemon auth token ([#1616](https://github.com/kaitranntt/ccs/issues/1616)) ([4283c46](https://github.com/kaitranntt/ccs/commit/4283c4665c7812a7eda343b31f6ff3359f8294b8))
* fail closed on websearch launch provisioning ([#1621](https://github.com/kaitranntt/ccs/issues/1621)) ([f2843ad](https://github.com/kaitranntt/ccs/commit/f2843ad2ce8f929e46a75ca8692d8f3bb9c0034c))
* **glmt:** emit thinking signature as opaque string ([cbcdb6b](https://github.com/kaitranntt/ccs/commit/cbcdb6ba626ee5438502ea32eb9505735fa0963a))
* **logging:** redact browser debug endpoint ([#1622](https://github.com/kaitranntt/ccs/issues/1622)) ([138ead0](https://github.com/kaitranntt/ccs/commit/138ead0e1ef36f96f7c7b3c515aaa308f27e389c))
* make CCS Bar launch descriptor use private shim ([fb9509d](https://github.com/kaitranntt/ccs/commit/fb9509d9be08187077baf44d2141aadc2518e551))
* restrict bar release workflow to main ([#1612](https://github.com/kaitranntt/ccs/issues/1612)) ([23b2c3d](https://github.com/kaitranntt/ccs/commit/23b2c3d6afd3170920bc00435f5013b7464e2795))
* skip paused codex accounts in bar refresh ([#1620](https://github.com/kaitranntt/ccs/issues/1620)) ([0527e27](https://github.com/kaitranntt/ccs/commit/0527e276b12033a3718e1330120d020e9843188a))

### Documentation

* **cliproxy:** document strip-vs-overlay launch-settings siblings and model-key superset ([13e23e0](https://github.com/kaitranntt/ccs/commit/13e23e0fc5b55c10af16e00a82535ca8c71a161f))

### Tests

* **cliproxy:** cover launch-settings corrupt-JSON fallback and overlay permissions ([e5db374](https://github.com/kaitranntt/ccs/commit/e5db374e98ad25091bc8105acb6c83486c17dbb8))
* **glmt:** align thinking signature coverage ([045fc93](https://github.com/kaitranntt/ccs/commit/045fc932857bdc9c52fa7573ec1bbd81a951b6a0))
* **glmt:** assert thinking signature is a non-empty opaque string ([37d2bae](https://github.com/kaitranntt/ccs/commit/37d2bae001cc52753696c575d86a4889591d8789))
2026-07-01 02:56:15 +00:00
Kai (Tam Nhu) Tran eccb3d1997 Merge pull request #1624 from kaitranntt/dev
feat: promote dev to main
2026-06-30 22:52:18 -04:00
github-actions[bot] 772a9c246e chore(release): 8.6.1-dev.13 2026-06-30 17:16:40 +00:00
Kai (Tam Nhu) Tran 0180b62453 fix(bar): use nonce-bound probe auth (#1623) 2026-06-30 13:10:56 -04:00
Kai (Tam Nhu) Tran 138ead0e1e fix(logging): redact browser debug endpoint (#1622)
* fix(logging): redact browser debug endpoint

* fix(logging): redact prompt argv values
2026-06-30 13:07:46 -04:00
github-actions[bot] a77096ed7c chore(release): 8.6.1-dev.12 2026-06-30 17:06:38 +00:00
Kai (Tam Nhu) Tran f2843ad2ce fix: fail closed on websearch launch provisioning (#1621) 2026-06-30 13:00:41 -04:00
Kai (Tam Nhu) Tran 0527e276b1 fix: skip paused codex accounts in bar refresh (#1620) 2026-06-30 12:59:54 -04:00
Kai (Tam Nhu) Tran 396e01ab6f fix: bound bar raw socket probes (#1618) 2026-06-30 12:53:35 -04:00
Kai (Tam Nhu) Tran 2f1453e397 fix(auth): honor legacy unified default profiles (#1619) 2026-06-30 12:53:03 -04:00
github-actions[bot] b47d502376 chore(release): 8.6.1-dev.11 2026-06-30 16:48:07 +00:00
Kai (Tam Nhu) Tran bb7c3a4037 fix(cliproxy): mask control panel login key (#1617) 2026-06-30 12:40:07 -04:00
Kai (Tam Nhu) Tran 4283c4665c fix(cursor): propagate daemon auth token (#1616)
* fix(cursor): propagate daemon auth token

* fix(cursor): align daemon auth token propagation
2026-06-30 12:37:41 -04:00
Kai (Tam Nhu) Tran 3f1dce30bc fix: close bar launch case bypass (#1613) 2026-06-30 12:33:46 -04:00
github-actions[bot] 0e097f3301 chore(release): 8.6.1-dev.10 2026-06-30 16:25:42 +00:00
Kai (Tam Nhu) Tran 58a90d3633 fix(ci): include compose parity in CI Gate (#1614) 2026-06-30 12:21:41 -04:00
Kai (Tam Nhu) Tran 23b2c3d6af fix: restrict bar release workflow to main (#1612) 2026-06-30 12:21:33 -04:00
github-actions[bot] 2282e15a99 chore(release): 8.6.1-dev.9 2026-06-29 17:09:02 +00:00
Kai (Tam Nhu) Tran 717192748e Merge pull request #1611 from sgaluza/sergey/ccs-3-glmt-thinking-signature-obekt-vmesto-stroki-lomaet-strim
fix(glmt): emit thinking signature as opaque string
2026-06-29 13:04:54 -04:00
Tam Nhu Tran 8c05bf5d67 Merge remote-tracking branch 'origin/dev' into kai/review/pr-1611-thinking-signature 2026-06-29 12:59:09 -04:00
Tam Nhu Tran 045fc93285 test(glmt): align thinking signature coverage 2026-06-29 12:58:38 -04:00
Sergey Galuza cbcdb6ba62 fix(glmt): emit thinking signature as opaque string
generateThinkingSignature() returned an object
({type, hash, length, timestamp}) but Anthropic requires a thinking
block's `signature` to be a non-empty opaque STRING. The object made
the thinking block invalid, breaking the stream against reasoning
backends and surfacing as a false 502 "did not respond within 600s".

Return a deterministic base64 token instead (no Date.now()), and
narrow ThinkingSignature to a string alias so existing imports stay
intact. The signature is only ever assigned, never read as an object,
so consumers are unaffected. Update the existing unit test to the
corrected string contract.

Built [OnSteroids](https://onsteroids.ai)
2026-06-29 13:27:09 +02:00
Sergey Galuza 37d2bae001 test(glmt): assert thinking signature is a non-empty opaque string
Add two contract tests on the public proxy path
createAnthropicProxyResponse: JSON and SSE. Anthropic requires a
thinking block's signature to be a non-empty opaque string, but ccs
currently fabricates the signature as an object via
generateThinkingSignature(), which breaks the stream against reasoning
backends.

Built [OnSteroids](https://onsteroids.ai)
2026-06-29 13:26:16 +02:00
github-actions[bot] 173a72f50c chore(release): 8.6.1-dev.8 2026-06-28 20:23:18 +00:00
Kai (Tam Nhu) Tran 9fc24980a1 Merge pull request #1610 from kaitranntt/kai/fix/1608-launch-settings-hardening
fix(cliproxy): harden launch-settings overlay (cleanup-on-throw, coverage, naming)
2026-06-28 16:19:06 -04:00
Tam Nhu Tran 13e23e0fc5 docs(cliproxy): document strip-vs-overlay launch-settings siblings and model-key superset
Cross-reference the two helpers that solve the persisted-settings-env
override (overlay in launch-settings.ts, strip in
openai-compat-launch-settings.ts) and mark shell-executor's
ANTHROPIC_MODEL_ENV_KEYS as the intentional superset distinct from the
4-key list in extended-context-utils. See issue #1609.
2026-06-27 10:55:11 -04:00
Tam Nhu Tran e5db374e98 test(cliproxy): cover launch-settings corrupt-JSON fallback and overlay permissions
Add a test for the env-only overlay fallback when the persisted settings
file is corrupt (the existing 'missing file' test skips JSON.parse), and
a POSIX-gated assertion that the overlay is written 0600 inside a 0700
dir, since it carries an auth token.
2026-06-27 10:55:00 -04:00
Tam Nhu Tran 454e1555a7 fix(cliproxy): clean up launch-settings overlay on synchronous spawn failure
The runtime settings overlay cleanup was registered only on the child
'exit'/'error' events, which run after spawn() returns. A synchronous
spawn() throw (e.g. invalid arg/env) propagated out of launchClaude
before those handlers were wired, orphaning the secret-bearing 0600
overlay file in os.tmpdir(). Wrap the spawn in try/catch and run the
idempotent cleanup before rethrowing.
2026-06-27 10:54:50 -04:00
github-actions[bot] 97e16d1d1c chore(release): 8.6.1-dev.7 2026-06-27 14:27:47 +00:00
Tam Nhu Tran c70a73a139 Merge pull request #1606 from juwain/fix/codex-in-array-system-messages
fix(codex): keep proxy chain authoritative over --settings env
2026-06-27 10:20:25 -04:00
github-actions[bot] a44978c9c8 chore(release): 8.6.1-dev.6 2026-06-27 14:05:27 +00:00
Kai (Tam Nhu) Tran 9dd9bf2978 feat(websearch): add agy provider and deprecate gemini cli fallback (#1607)
Google retired the gemini CLI on 2026-06-18, so the gemini websearch fallback no longer
works. Add agy (Antigravity) as the primary CLI websearch provider end to end: runtime spawn
in websearch-transformer.cjs (agy --dangerously-skip-permissions --print-timeout Ns -p),
detection (agy.ts), config schema and defaults, hook env, status, dashboard persistence, and docs.

The legacy gemini provider stays present but is marked deprecated for enterprise users who
retain access. Image analysis already supported the agy provider (no change). The CLIProxy
gemini quota fetcher (Gemini API OAuth, not the cli binary) is untouched.

Validation: typecheck, lint, and the websearch + config + web-server unit suites pass.
2026-06-27 10:01:25 -04:00
github-actions[bot] 608ff97e35 chore(release): 8.6.1-dev.5 2026-06-26 19:45:20 +00:00
Thibault Jaigu a167f94e1b feat: add Requesty as an OpenAI-compatible provider (#1604)
Add a Requesty provider preset to the provider preset catalog, mirroring the existing OpenRouter preset (base https://router.requesty.ai/v1, default model openai/gpt-4o-mini, OpenAI-compatible).
2026-06-26 15:41:24 -04:00
Thieu Nguyen ba0e768fbf fix(codex): normalize CLIProxy responses routes (#1605)
Normalize Codex Responses base URLs so CCS-backed Codex launches use /backend-api/codex on the original CLIProxy backend. Share the Codex Responses route builder with ccsxp provider repair, and repair stale native Codex provider auth blocks when env_key token injection is used.
2026-06-26 15:41:15 -04:00
juwain 3847443da3 fix(cliproxy): keep proxy-chain base URL authoritative over --settings env
Claude Code applies the --settings `env` block over the process
environment, so the persisted ANTHROPIC_BASE_URL (CLIProxy-direct)
overrode the ephemeral proxy-chain URL CCS injects via env. Claude then
bypassed the tool-sanitization / codex-reasoning proxies, surfacing as
`400 {"detail":"System messages are not allowed"}` for Codex.

Write a runtime settings overlay (in os.tmpdir(), matching
createOpenAICompatLaunchSettings) whose routing env keys reflect the
resolved launch environment, and pass it to `--settings`. The overlay is
cleaned up on Claude exit; subcommands keep the persisted path untouched.

Reuse the canonical routing/model env key lists from shell-executor
instead of duplicating them.
2026-06-26 17:11:12 +03:00
github-actions[bot] 36ea9064e7 chore(release): 8.6.1-dev.4 2026-06-24 22:48:58 +00:00
Kai (Tam Nhu) Tran d7933c6243 feat(bar): swipeable profile carousel and condensed alerts (#1603)
Closes #1602
2026-06-24 18:44:53 -04:00
github-actions[bot] 0d20a102bd chore(release): 8.6.1-dev.3 2026-06-24 22:19:45 +00:00
Kai (Tam Nhu) Tran 62274dabfa fix(bar): align subscription carousel and collapse stale blank space (#1600)
Closes #1599
2026-06-24 18:15:43 -04:00
github-actions[bot] 7c635a1714 chore(release): 8.6.1-dev.2 2026-06-24 21:09:56 +00:00