2026-01-04 21:58:59 -05:00
{
"name" : "9router-app" ,
# v0.5.55 (2026-08-14)
## Features
- **Auth**: native SAML 2.0 SSO alongside OIDC — AuthnRequest generation, ACS
assertion handling, SP metadata export, admin config test, replay-protected
via a `saml_state` cookie matched against `InResponseTo`
- **Providers**: add Alibaba Token Plan (`token-plan.ap-southeast-1`) — the
fourth Alibaba key type, Singapore-only and OpenAI-compatible transport only
- **Providers**: add `glm-5.3` to GLM Coding and GLM (China)
- **Providers**: Kimchi accepts API keys as well as OAuth (dual auth), with a
working Test Connection for both modes
- **Antigravity**: add Gemini 3.7 Flash and its tiered high/medium/low variants
(also in the Gemini registry) with pricing and quota tracking
- **TTS**: add Fish Audio — model id travels in an HTTP `model` header, voice
is a `reference_id` (preset or cloned voice model)
- **OpenCode-Go**: route by request format via declared transports instead of
forcing every client into `/messages` — Codex/OpenAI clients no longer pay a
lossy Responses→OpenAI→Claude double translation. Per-model `supportedFormats`
guard; the bespoke executor is gone (its shared `_lastModel` cache could cross
auth headers between concurrent requests)
- **Usage**: dedup + cache Claude quota calls (120s TTL keyed by access token,
in-flight promise dedup, last-good read on soft failure) to stop multiple
tabs tripping 429; manual refresh (↻) sends `force=1` to bypass the cache
## Fixes
- **Docker**: ship `sql.js` in the image so the pure-JS DB fallback can start —
file tracing carried the package's JS without `dist/sql-wasm.wasm`, so a
container with no native driver aborted with ENOENT and never got a database
(#3248)
- **Usage**: read Gemini `usageMetadata` out of the antigravity `{ response }`
envelope — every non-streaming antigravity request logged `IN 0 | OUT 0`
(#3260)
- **Claude**: re-anchor passthrough cache breakpoints — the client's own
`cache_control` markers point at pre-normalization offsets, so the tail was
re-cached every request. Last system block and last tool pinned at 1h TTL,
last assistant turn at 5m, mid-conversation system messages folded into the
neighbouring user turn instead of hoisted into `body.system`
- **Combos**: detect images from Hermes and attachment payloads (`images[]`,
`experimental_attachments`, message-level `image_url`/`audio_url`, inline
`data:` URIs) so the Vision Adapter auto-switch fires for Hermes/Ollama/
Vercel AI SDK shapes
- **Kiro**: intercept chat via `x-amz-target` — Kiro IDE 1.0.228+ moved
`GenerateAssistantResponse` to `POST /` + header, bypassing MITM. Also emit
the now-mandatory initial-response frame and map the `auto` model slot
- **Kiro**: report real output tokens and stop discarding usable turns
- **Qoder**: detect billing blocks at stream start and return a synthetic 403
so combo/account fallback triggers instead of leaking the error into chat
- **Antigravity**: strip competitive system prompts (Zed IDE's Claude-agent
prompt) that Antigravity flags with a 429 Quota Exhausted
- **OpenCode**: send the official client fingerprint on free-tier requests so
the Console stops classifying traffic as unidentified and rate-limiting it;
session id resolves conversation-stable to preserve prompt caching
- **Responses**: don't close the message on an empty `tool_calls` array — some
providers attach one to every chunk, and the truthy check ended the message
on the first content token (#3234)
- **Translator**: preserve `prompt_cache_key` when converting chat to responses
- **Models**: expose snake_case token limits on `/v1/models`
- **Combos**: strip `stream_options` from the Fusion panel fan-out to avoid a
DeepSeek 400 (#3024); raise the dashboard model-test probe budget to 1024 and
soft-pass reasoning-only responses (#3010)
- **Headroom**: the toggle reflects the `headroomEnabled` setting even when the
proxy is down — it previously showed OFF while the engine kept calling
`/v1/compress`; proxy status stays visible via the status chip
- **Hermes**: add the `api_key` parameter to the model block in YAML config
- **Providers**: add llm7 to provider test support
## Docs
- **i18n**: add Spanish, French, and Brazilian Portuguese README translations
## Security
- **Real IP**: `x-9r-real-ip` and the Host fallback were trusted from
client-controlled headers whenever `custom-server.js` was not in the request
path (`npm run start`, `start:bun`), letting a remote caller pose as local to
skip API key auth and reach `LOCAL_ONLY_PATHS` (`/api/mcp/*`,
`/api/tunnel/enable`, `/api/auth/reset-password`). The server now stamps a
per-process `x-9r-peer-token` on every request it sanitizes and only trusts
`x-9r-real-ip` behind it — falling back to Host in development and failing
closed in production (GHSA-pjm4-8fpg-f9p6). Also fixes IPv6 loopback
detection (`::1`, `::ffff:127.0.0.1`) and routes `npm run start` /
`start:bun` through `custom-server.js`
- **Search**: `resolveBaseUrl()` rejects client-supplied non-public baseUrls
(SSRF guard on `/v1/search`)
- **Login**: fresh-install remote login with the default password returns 403
without issuing a JWT
- **Usage**: `/api/usage/request-details` redacts request/response payloads
2026-08-14 06:08:02 -04:00
"version" : "0.5.55" ,
2026-01-04 21:58:59 -05:00
"description" : "9Router web dashboard" ,
"private" : true ,
"scripts" : {
2026-07-10 02:08:02 -04:00
"dev" : "next dev --port 20127" ,
"dev:webpack" : "next dev --webpack --port 20127" ,
2026-05-14 22:30:31 -04:00
"build" : "next build --webpack" ,
2026-08-04 23:31:34 -04:00
"postbuild" : "node scripts/copy-standalone-assets.mjs" ,
"postbuild:bun" : "node scripts/copy-standalone-assets.mjs" ,
2026-08-14 05:32:40 -04:00
"start" : "node custom-server.js --port 20127" ,
2026-06-15 07:18:04 -04:00
"dev:bun" : "bun --bun next dev --webpack --port 20127" ,
2026-05-14 22:30:31 -04:00
"build:bun" : "bun --bun next build --webpack" ,
2026-08-14 05:32:40 -04:00
"start:bun" : "bun ./.next/standalone/custom-server.js" ,
2026-06-08 01:10:02 -04:00
"cli:pack" : "npm --prefix cli run pack:cli" ,
"cli:publish" : "npm --prefix cli run publish:cli"
2026-01-04 21:58:59 -05:00
} ,
"dependencies" : {
2026-05-13 22:54:52 -04:00
"@dnd-kit/core" : "^6.3.1" ,
"@dnd-kit/modifiers" : "^9.0.0" ,
"@dnd-kit/sortable" : "^10.0.0" ,
"@dnd-kit/utilities" : "^3.2.2" ,
2026-01-26 22:49:16 -05:00
"@monaco-editor/react" : "^4.7.0" ,
2026-06-18 03:58:00 -04:00
"@next/third-parties" : "^16.2.9" ,
feat(auth): add native SAML 2.0 SSO integration
Add SAML 2.0 as a second SSO protocol alongside OIDC under a unified
authMode/ssoType model. SP flows via @node-saml/node-saml: AuthnRequest
generation, ACS POST assertion handling, SP metadata export, and admin
config test endpoint. Replay-protected via saml_state cookie (httpOnly,
SameSite=Lax) matched against InResponseTo; wantAssertionsSigned enforced.
- src/lib/auth/saml.js: SAML instance builder, X.509 cert formatter, claim pickers
- 4 routes under src/app/api/auth/saml/: start, acs, metadata, test
- settingsRepo: ssoType + saml* defaults; login/status routes dispatch by type
- profile page: SSO protocol switcher, IdP metadata XML + cert uploaders
- login page: dynamic SAML sign-in button; Header: SAML user badge
2026-08-13 06:53:17 -04:00
"@node-saml/node-saml" : "^5.1.0" ,
2026-02-21 02:36:06 -05:00
"@xyflow/react" : "^12.10.1" ,
2026-01-09 05:29:11 -05:00
"bcryptjs" : "^3.0.3" ,
2026-08-13 00:50:00 -04:00
"chalk" : "^5.6.2" ,
2026-03-11 06:00:49 -04:00
"confbox" : "^0.2.4" ,
2026-01-05 03:55:56 -05:00
"express" : "^5.2.1" ,
"http-proxy-middleware" : "^3.0.5" ,
2026-01-09 05:29:11 -05:00
"jose" : "^6.1.3" ,
2026-04-17 00:33:36 -04:00
"marked" : "^18.0.1" ,
2026-05-10 10:54:54 -04:00
"material-symbols" : "^0.44.6" ,
2026-01-26 22:49:16 -05:00
"monaco-editor" : "^0.55.1" ,
2026-02-01 21:17:15 -05:00
"next" : "^16.1.6" ,
2026-03-06 04:41:02 -05:00
"node-forge" : "^1.3.3" ,
2026-01-04 21:58:59 -05:00
"node-machine-id" : "^1.1.12" ,
2026-02-01 21:17:15 -05:00
"open" : "^11.0.0" ,
"ora" : "^9.1.0" ,
2026-08-13 00:50:00 -04:00
"prop-types" : "^15.8.1" ,
2026-02-01 21:17:15 -05:00
"react" : "19.2.4" ,
"react-dom" : "19.2.4" ,
2026-03-11 07:04:38 -04:00
"react-is" : "^16.13.1" ,
2026-02-21 02:36:06 -05:00
"recharts" : "^3.7.0" ,
2026-02-08 04:28:13 -05:00
"selfsigned" : "^5.5.0" ,
2026-02-01 21:17:15 -05:00
"socks-proxy-agent" : "^8.0.5" ,
2026-03-19 04:32:29 -04:00
"sql.js" : "^1.14.1" ,
2026-02-01 21:17:15 -05:00
"undici" : "^7.19.2" ,
2026-01-04 21:58:59 -05:00
"uuid" : "^13.0.0" ,
2026-02-01 21:17:15 -05:00
"zustand" : "^5.0.10"
2026-01-04 21:58:59 -05:00
} ,
2026-03-18 09:25:48 -04:00
"optionalDependencies" : {
"better-sqlite3" : "^12.6.2"
} ,
2026-05-09 06:48:20 -04:00
"comment_better_sqlite3" : "kept in optionalDependencies so npm install doesn't fail on systems without build tools — sql.js is used as fallback at runtime" ,
2026-01-04 21:58:59 -05:00
"devDependencies" : {
"@tailwindcss/postcss" : "^4.1.18" ,
"eslint" : "^9" ,
2026-02-01 21:17:15 -05:00
"eslint-config-next" : "16.1.6" ,
2026-02-24 23:40:50 -05:00
"postcss" : "^8.5.6" ,
2026-01-04 21:58:59 -05:00
"tailwindcss" : "^4"
}
2026-02-26 21:17:49 -05:00
}