10 Commits

Author SHA1 Message Date
roboomp cc688c6b5c fix(catalog): restored headers omitted from model cache
Recorded which cached model ids had headers omitted and which header sets cannot be reconstructed from current static inputs.

Fresh/offline cache reads now restore exact static headers before returning models. Dynamic-only or dynamically-augmented header models bypass fresh-cache reuse and refetch online; offline and failure fallbacks omit them instead of returning unusable models without required transport headers.

Bumped the cache schema to v10 and added static, dynamic, offline, and raw-persistence regressions.

Fixes #5780
2026-07-17 03:27:12 +00:00
roboomp 3ab9ef29c1 fix(catalog): omitted all headers from model cache
Replaced the incomplete credential-header denylist with a default-deny cache boundary: no model header values are persisted because custom providers may use arbitrary authentication header names.

Bumped the cache schema to v9 and enabled SQLite secure_delete so older header-bearing rows are invalidated without leaving credential bytes in free pages. Added coverage for X-Goog-Api-Key, X-Access-Token, arbitrary headers, and physical scrubbing of pre-v9 cache rows.

Fixes #5780
2026-07-17 03:12:28 +00:00
roboomp c654abc980 fix(auth): scoped post-login model refresh and stripped cache credentials
Native /login and /logout (plus setup-wizard sign-in and RPC login)
refreshed model discovery with the default all-provider
online-if-uncached strategy, which reused a fresh authoritative cache row
and never re-ran fetchDynamicModels with the just-persisted credential,
so newly authenticated models stayed unavailable in-session and stale
endpoint data survived a relogin. Each auth-completion path now awaits a
provider-scoped refreshProvider(providerId, "online").

Also fixed writeModelCache serializing credential-bearing request headers
(Authorization, X-Api-Key, api-key, cookie, proxy-authorization) into the
plaintext models.db; they are now stripped before persistence and
re-derived on load from AuthStorage / provider config.

Fixes #5780
2026-07-17 03:03:25 +00:00
can1357 105a68654e test(ai): updated model cache migration test assertions for legacy invalidation
- Updated the migration test to assert that legacy cached models are invalidated rather than preserved.
- Verified that subsequent model discovery writes fresh models correctly after invalidation.
2026-07-01 20:03:04 +02:00
can1357 56fbfdea96 fix(pr-3347): use worktree-local cleanup helper in ai tests 2026-06-27 02:04:51 +02:00
oldschoola e17f692af7 test(ai): migrate 24 test files from fs.rm to removeWithRetries
Batch-migrated all packages/ai/test/ files that used fs.rm/fs.rmSync
directly to use removeWithRetries/removeSyncWithRetries from
@oh-my-pi/pi-utils. This fixes EBUSY failures on Windows where SQLite
database files are still locked by the process when afterEach cleanup
hooks run.

Files migrated (24 total):
- 5 auth-broker test files (auth-broker-*.test.ts)
- 11 auth-storage test files (auth-storage-*.test.ts)
- 4 non-auth test files (aws-credentials, issue-1417, issue-957, model-cache)
- 3 remaining test files (remote-auth-store, request-debug, stream)
- 2 sync migration files (anthropic-alignment, image-limits)

Total: 28 fs.rm/fs.rmSync calls replaced with retry-enabled versions.
The retry logic: 40 retries, 25ms delay, EBUSY/EPERM/ENOTEMPTY on Windows.
2026-06-23 12:43:23 -07:00
can1357 ae415199dc feat: added build-time compatibility in ModelSpec/buildModel pipeline
- Centralized catalog and registry handling on `ModelSpec` and `buildModel`, resolving compatibility at model build time.
- Removed runtime compatibility detectors and switched provider request flows to direct `model.compat` reads.
- Added compat fields (`supportsReasoningParams`, `alwaysSendMaxTokens`, `strictResponsesPairing`, `whenThinking`).
- Persisted explicit compatibility overrides through `compatConfig` in discovery and cache merge paths.
2026-06-10 06:20:51 +02:00
can1357 1b9d9d0851 refactor(catalog)!: split model catalog from pi-ai
Move bundled models, model cache/manager, thinking metadata, effort helpers,
provider descriptors/discovery, wire constants, and model identity utilities
into the new @oh-my-pi/pi-catalog package.

Update pi-ai to keep provider runtime/auth concerns, move catalog provider
metadata into CATALOG_PROVIDERS, and migrate coding-agent, agent, stats, docs,
and tests to import catalog values from pi-catalog.

Split coding-agent model registry helpers into discovery, roles, and models
config modules while preserving registry orchestration.

BREAKING CHANGE: @oh-my-pi/pi-ai no longer exports catalog subpaths such as
/models, /model-cache, /model-manager, /model-thinking, /effort,
/provider-models*, discovery helpers, and provider wire constants; use the
matching @oh-my-pi/pi-catalog subpaths instead.
2026-06-10 04:06:57 +02:00
can1357 9d457f73d9 test: migrated test imports to package subpath exports
- Replaced relative `../src` imports with `@oh-my-pi/pi-ai` and `@oh-my-pi/pi-agent-core` subpaths.
2026-06-08 19:03:55 +02:00
roboomp 15a09be4e7 fix(ai): migrated model cache schema v2 rows
Added a model-cache migration that backfills the schema v3 static_fingerprint column and preserves v2 cached provider discovery rows. Added regression coverage for reading legacy cache data and overwriting it on the next discovery write.\n\nFixes #1219
2026-05-20 07:34:25 +00:00