Skip to content
27 changes: 26 additions & 1 deletion BarWidget.qml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ Panel {
property var quotaData: ({accounts: []})
property var auth: ({})
property var preferences: ({})
property var updates: ({})
property var routingSettings: ({values: {}, capabilities: {}, strategies: []})
property var diagnostics: ({})
property var customProviders: []
Expand Down Expand Up @@ -91,7 +92,7 @@ Panel {
action.running = true
}
function clearConnectionState() {
preferences = ({})
preferences = ({}); updates = ({})
routingSettings = ({values: {}, capabilities: {}, strategies: []})
diagnostics = ({}); customProviders = []; clientKeys = []
providerWeightsSupported = false; showingDiagnostics = false
Expand Down Expand Up @@ -130,6 +131,7 @@ Panel {
}
}
if (result.preferences) preferences = result.preferences
if (result.updates) updates = result.updates
if (result.routing_settings) routingSettings = result.routing_settings
if (result.diagnostics) diagnostics = result.diagnostics
if (result.custom_providers) customProviders = result.custom_providers
Expand Down Expand Up @@ -958,6 +960,29 @@ Panel {
Hint { visible: !(root.snapshot.models || []).length; text: "No models reported by the enabled accounts." }
}
PanelSeparator { foreground: root.foreground }
Column {
visible: !root.remoteConnection
width: parent.width
spacing: Style.space(8)
Label { text: "Backend updates"; font.bold: true }
Hint { text: "Installed: " + (root.updates.installed_version || root.snapshot.version || "unknown") + " · Reviewed: " + (root.updates.reviewed_version || "check for updates") }
Hint { visible: !!root.updates.latest_version; text: "Latest upstream: " + (root.updates.latest_version || "") }
Hint { text: "Updating briefly restarts a running proxy. Your configuration and previous backend are kept for rollback." }
ActionButton { visible: !root.remoteConnection; text: "Check backend updates"; enabled: !root.busy; onClicked: root.perform(["check-updates"]) }
ActionButton {
visible: !root.remoteConnection && root.updates.update_supported === true && root.updates.update_available === true
text: "Install reviewed update"
enabled: !root.busy
onClicked: root.perform(["backend-update"])
}
ActionButton {
visible: !root.remoteConnection && root.updates.rollback_available === true
text: "Restore previous backend"
enabled: !root.busy
onClicked: root.perform(["backend-rollback"])
}
Hint { visible: !!root.updates.error; text: root.updates.error || "" }
}
Hint { visible: !!root.snapshot.model_error; text: root.snapshot.model_error || "" }
Hint { visible: root.remoteConnection && !root.snapshot.has_api_key; text: "Add a client API key above to list models." }
Label { text: root.remoteConnection ? "CLIProxyAPI · Remote" : "CLIProxyAPI " + (root.snapshot.version || "custom"); opacity: 0.35; font.pixelSize: Style.font.caption }
Expand Down
12 changes: 8 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ omarchy plugin add https://github.com/soojy/omaproxy --enable
```

1. Open **OmaProxy** from the robot icon in your bar.
2. Choose **Set up proxy**. The plugin downloads a pinned CLIProxyAPI release, verifies its SHA-256 against architecture-specific digests pinned in this plugin, and creates a user service.
2. Once a backend release has security approval, choose **Set up proxy**. The plugin verifies its pinned architecture-specific SHA-256 and creates a user service. Automatic setup is currently withheld; see the [security assessment](docs/backend-security.md).
3. Start the proxy, then select **Accounts → Add account** and finish the provider's browser sign-in.
4. Open **Limits** to see your remaining allowance.

Expand All @@ -76,7 +76,7 @@ Choose a model from **Settings → Show models**. Provider OAuth tokens stay wit
| xAI | ✓ | Not yet supported |
| OpenAI-compatible API endpoints | API-key form | Not yet supported |

¹ The installer pins **CLIProxyAPI v7.2.154**. Gemini, Qwen, and GitHub Copilot require a compatible backend; unsupported login options are hidden. Provider capabilities and quota endpoints can change.
¹ The installer pins a reviewed CLIProxyAPI release; see the [installer trust policy](docs/installer-security.md). Gemini, Qwen, and GitHub Copilot require a compatible backend; unsupported login options are hidden. Provider capabilities and quota endpoints can change.

Codex's `prolite` plan is displayed as **PRO · 5×** and `pro` as **PRO · 20×**. These labels describe plan tiers, not remaining tokens or temporary promotions. Monthly-only plans show their overall monthly allowance instead of an invented weekly window.

Expand All @@ -102,7 +102,7 @@ python3 ~/.config/omarchy/plugins/soojy.omaproxy/scripts/omaproxy.py setup \
--binary /absolute/path/to/cli-proxy-api-plus
```

OmaProxy creates its own configuration and credentials; it does not adopt another proxy's process or tokens. Use `--port 18317` on initial setup if 8317 is occupied. Re-running setup preserves existing settings; restart the proxy after replacing an active backend.
OmaProxy creates its own configuration and credentials; it does not adopt another proxy's process or tokens. Use `--port 18317` on initial setup if 8317 is occupied. Existing managed installations use the explicit backend update action. A user-selected `setup --binary` preserves configuration; restart the proxy after replacing an active custom backend.

## Privacy and local storage

Expand All @@ -125,7 +125,9 @@ rm -f ~/.config/systemd/user/omaproxy.service
systemctl --user daemon-reload
```

The backend version and archive digests are pinned in the plugin and are not silently updated by plugin updates. See the [installer trust policy](docs/installer-security.md) for the reviewed digests and download/extraction limits. Stored credentials remain in `~/.config/omaproxy/` after removal. XDG overrides are supported; adjust the paths if you use them.
Plugin updates leave the installed backend running. In **Settings → Backend updates**, check the actual installed version and latest upstream version or restore a permitted previous state. Automatic setup and upgrades are currently withheld because the pinned and latest checked official binaries have unresolved vulnerability advisories. See the [security assessment](docs/backend-security.md). An approved update will require `bwrap` and isolated configuration validation; a running proxy briefly restarts and a stopped proxy stays stopped.

See the [backend update and recovery guide](docs/backend-updates.md) and [installer trust policy](docs/installer-security.md). Stored credentials remain in `~/.config/omaproxy/` after removal. XDG overrides are supported; adjust the paths if you use them.

### Upgrading from 0.1.3 or earlier

Expand Down Expand Up @@ -164,6 +166,8 @@ Use the [isolated native preview](docs/native-preview.md) to exercise the panel

[Contributing](CONTRIBUTING.md) · [Architecture](docs/architecture.md) · [Report a bug](https://github.com/soojy/omaproxy/issues/new?template=bug_report.md)

Use the [isolated native preview](docs/native-preview.md) to exercise updater controls with fake accounts in the installed Omarchy QML components. It leaves your configured plugin and backend untouched.

## Credits

Inspired by [VibeProxy](https://github.com/automazeio/vibeproxy), powered by [CLIProxyAPI](https://github.com/router-for-me/CLIProxyAPI), and built on [Omarchy](https://omarchy.org) and [Quickshell](https://quickshell.org).
Expand Down
Loading
Loading