Repository navigation
Add native routing, diagnostics, client keys and quota alerts - #6
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 48 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (22)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
soojy
left a comment
There was a problem hiding this comment.
Reviewed native routing, provider management, diagnostics, downstream keys, alerts, and QML. Credentials stay in private storage and request bodies/stdin; public diagnostics use bounded allowlists and HMAC labels. Key revocation checks the exact value and protects the configured primary key. Added a guard blocking local management mutations while an interrupted backend transaction requires recovery. Independently ran 145 tests with zero skips against each backend, then 159 tests with zero skips after integrating the protocol suite. Hosted CI passes both backend lanes, and the native fake-account preview passes. No new source-code security merge blocker identified. This PR does not change the backend pin; the existing/proposed backend dependency advisory findings remain tracked by the changes requested on #5.
OmaProxy's panel exposes only basic routing and provider creation, and has no request diagnostics or separate client keys. This adds capability-aware controls within the existing three tabs:
All local routing/provider/client mutations share a lock. JSON responses are capped at 2 MiB. Closing conceals account details and discards credential forms; queued page refresh handles opening before backend status arrives. The healthy icon uses Omarchy's accent color.
Adds isolated native preview tooling using the installed Omarchy components and a fake bridge. No live settings, accounts, service or notification commands are used by the preview.
Validation: 144 Python tests passed without skips against both CLIProxyAPI v7.2.154 and v8.0.13; JavaScript checks, plugin validation, QML parsing and diff checks passed. Native preview exercises routing, provider edits, diagnostics, named-key creation/copy/revocation and alert error receipts. Pointer hit testing, real OAuth/provider inference and actual desktop notification delivery remain unverified.
Related: #3. Complements backend updater #5 and client protocol coverage #4. No backend upgrade or live plugin restart is performed by this PR.
Integration: these PRs overlap in
BarWidget.qml,scripts/omaproxy.pyandREADME.md. A resolved combined verification branch, SHA0df387d42e0672d6b20efe6cc2e2e4a8a4224908, preserves both feature sets. Its full suite passed 176 tests with zero skips on each backend, including the real update sandbox and actual Codex client. JavaScript, manifest, QML, Python, actionlint and diff gates passed. An independent review found no concrete merge blocker. This is an integration reference for merging the separate PRs; hosted CI remains unverified.The merged native preview passed as well: ten inspected cards and fifteen commands covering updater and native controls together, cold Settings loading before navigation and concealed reopening. Pointer hit testing remains outside that lane.