Skip to content

Add native routing, diagnostics, client keys and quota alerts - #6

Merged
soojy merged 3 commits into
soojy:mainfrom
Marlos001:feat/native-controls-20261003
Oct 5, 2026
Merged

soojy merged 3 commits into
soojy:mainfrom
Marlos001:feat/native-controls-20261003

Conversation

@Marlos001

@Marlos001 Marlos001 commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

OmaProxy's panel exposes only basic routing and provider creation, and has no request diagnostics or separate client keys. This adds capability-aware controls within the existing three tabs:

  • Weighted routing, retry limits, and v8 session-affinity/cooldown settings, with narrow management writes and readback. Unsupported v7 affinity settings remain read only.
  • Custom API-provider edit/remove/model-discovery actions, explicit credential weights and model aliases. Blank keys preserve credentials; URL-only edits preserve current backend models. Remote providers require an effective credential, including edits from a keyless localhost endpoint.
  • Bounded diagnostics with distinct account/upstream-key populations and anonymous receipt metadata. Automatic refresh never consumes the usage queue. Manual capture explains its consuming behavior and reports invalid/omitted receipts.
  • Named downstream client keys with a private HMAC-only registry, clipboard copy, exact-value revocation, recovery and primary-key protection. Receipt attribution requires an actual downstream key field.
  • Desktop quota alerts, off by default, with bounded polling, fresh-data checks, deduplication and sanitized errors.

All local routing/provider/client mutations share a lock. JSON responses are capped at 2 MiB. Closing conceals account details and discards credential forms; queued page refresh handles opening before backend status arrives. The healthy icon uses Omarchy's accent color.

Adds isolated native preview tooling using the installed Omarchy components and a fake bridge. No live settings, accounts, service or notification commands are used by the preview.

Validation: 144 Python tests passed without skips against both CLIProxyAPI v7.2.154 and v8.0.13; JavaScript checks, plugin validation, QML parsing and diff checks passed. Native preview exercises routing, provider edits, diagnostics, named-key creation/copy/revocation and alert error receipts. Pointer hit testing, real OAuth/provider inference and actual desktop notification delivery remain unverified.

Related: #3. Complements backend updater #5 and client protocol coverage #4. No backend upgrade or live plugin restart is performed by this PR.

Integration: these PRs overlap in BarWidget.qml, scripts/omaproxy.py and README.md. A resolved combined verification branch, SHA 0df387d42e0672d6b20efe6cc2e2e4a8a4224908, preserves both feature sets. Its full suite passed 176 tests with zero skips on each backend, including the real update sandbox and actual Codex client. JavaScript, manifest, QML, Python, actionlint and diff gates passed. An independent review found no concrete merge blocker. This is an integration reference for merging the separate PRs; hosted CI remains unverified.

The merged native preview passed as well: ten inspected cards and fifteen commands covering updater and native controls together, cold Settings loading before navigation and concealed reopening. Pointer hit testing remains outside that lane.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 48 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: fc1fc77e-713d-4d38-80ff-698366d50f3a
📥 Commits

Reviewing files that changed from the base of the PR and between f8ae0dc and c679503.

📒 Files selected for processing (22)
  • BarWidget.qml
  • README.md
  • docs/client-keys.md
  • docs/diagnostics.md
  • docs/native-preview.md
  • docs/quota-alerts.md
  • docs/routing.md
  • scripts/client_keys.py
  • scripts/diagnostics.py
  • scripts/omaproxy.py
  • scripts/preview-plugin.py
  • scripts/providers.py
  • scripts/quota_alerts.py
  • scripts/routing.py
  • tests/fixtures/preview_bridge.py
  • tests/test_client_keys.py
  • tests/test_controls_bridge.py
  • tests/test_diagnostics.py
  • tests/test_providers.py
  • tests/test_quota_alerts.py
  • tests/test_request_bounds.py
  • tests/test_routing.py
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@soojy soojy left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed native routing, provider management, diagnostics, downstream keys, alerts, and QML. Credentials stay in private storage and request bodies/stdin; public diagnostics use bounded allowlists and HMAC labels. Key revocation checks the exact value and protects the configured primary key. Added a guard blocking local management mutations while an interrupted backend transaction requires recovery. Independently ran 145 tests with zero skips against each backend, then 159 tests with zero skips after integrating the protocol suite. Hosted CI passes both backend lanes, and the native fake-account preview passes. No new source-code security merge blocker identified. This PR does not change the backend pin; the existing/proposed backend dependency advisory findings remain tracked by the changes requested on #5.

@soojy
soojy merged commit 569a1f7 into soojy:main Oct 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants