2026-01-04 21:58:59 -05:00
{
"name" : "9router-app" ,
# v0.5.50 (2026-08-05)
## Features
- **Providers**: add TokenRouter (300+ models via OpenAI-compatible gateway) with
exact per-model pricing for 110 models and `reasoning_effort` thinking config
- **Providers**: add Self-hosted STT / TTS / Embedding — point 9Router at your own
OpenAI-compatible speech and embedding servers (whisper.cpp, faster-whisper,
Kokoro-FastAPI, llama-server, vLLM, Infinity). Unlike the named cloud providers
these read `baseUrl` per connection, so one provider can front several machines
- **Combos**: default-enable vision/audio capacity adapter (auto-routes to a
vision/audio-capable model when the target lacks that capability, falling back
to `oc/mimo-v2.5-free`), wired into chat handler routing
- **Endpoint**: auto-provision a "Default Key" for first-time users so `/v1`
works without a manual dashboard step
- **Codex**: support GPT-5.6 Max/Ultra reasoning-level overrides (cx/ routes only)
- **Qoder**: support PAT (Personal Access Token) connections end-to-end, alongside
OAuth device flow
- **CLI tools**: add OpenDesign (manalkaff/opendesign) support
- **Headroom**: report effective payload savings (tool schema/history bytes broken
out, byte-savings % reflects actual outbound reduction)
- **Ollama**: Cloud quota tracker (session + weekly) + proactive background OAuth
token refresh scheduler for all providers
## Fixes
- **Providers**: remove Qwen (OAuth flow stopped working reliably)
- **Passthrough**: detect codex-tui/Codex Desktop as native Codex client — they
were falling through to the translator and losing fields like `reasoning.summary`
- **OAuth**: scope antigravity header fixes to loadCodeAssist/onboardUser only
- **OAuth**: keep `open` external in the build so xAI/Grok token refresh works on
Windows
- **OAuth**: declare missing `searchParams` in register-session handler (was a
500 instead of JSON on error)
- **DB**: `ENABLE_REQUEST_LOGS` env var now overrides the UI setting correctly;
observability defaults to off (opt-in)
- **Translator**: preserve Codex Responses Lite tool use across chat-native
OpenAI-compatible providers
- **Translator**: don't drop image-only user messages in `prepareClaudeRequest`
- **Translator**: drop JSON Schema keywords Gemini rejects (`uniqueItems`,
`contains`, `multipleOf`, `unevaluatedProperties`, `unevaluatedItems`,
`contentSchema`)
- **Claude**: remove global header cache that leaked one client's identity
headers onto another client/account sharing the server; gate `anthropic-beta`
by model instead
- **Antigravity**: drop retired Gemini 3.0 quota tiers, show Gemini 3.6 Flash
usage bars
- **Cloudflare AI**: declare API key authentication (dashboard showed "No
connections" despite an active key)
- **GitHub Copilot**: hold monthly-exhausted accounts until UTC month reset
instead of only cooling down 120s
- **CodeBuddy**: dodge Tencent CN content filter, add usage tracking, normalize
codebuddy-intl messages
- **Usage**: stop losing cached prompt tokens in the forced-SSE→JSON path
- **Grok CLI**: display the public subscription tier from the OAuth token claim
- **Providers**: count apikey connections for Ollama free-tier card; free-tier/
apikey providers without `authModes` now default to apikey (were treated
oauth-only)
- **Build**: include static/public assets in standalone output (login page hung
on 404s when run via PM2)
- **Server**: support IntelliJ IDEA OpenAI-compatible clients over HTTP (h2c
upgrade handling)
- **Auth**: redirect already-logged-in sessions away from `/login`
- **CLI tools**: enable Apply button for dynamic OpenAI/Anthropic-compatible
provider connections
- **CLI**: include complete API artifacts in the CLI package
- **TTS**: a bare self-hosted model name is the MODEL, not the voice — `kokoro`
was parsed as a voice against a default model, 404ing or synthesising with the
wrong one
endpoint that drops packets never returns headers, so the request previously
hung indefinitely
2026-08-05 05:49:14 -04:00
"version" : "0.5.50" ,
2026-01-04 21:58:59 -05:00
"description" : "9Router web dashboard" ,
"private" : true ,
"scripts" : {
2026-07-10 02:08:02 -04:00
"dev" : "next dev --port 20127" ,
"dev:webpack" : "next dev --webpack --port 20127" ,
2026-05-14 22:30:31 -04:00
"build" : "next build --webpack" ,
2026-08-04 23:31:34 -04:00
"postbuild" : "node scripts/copy-standalone-assets.mjs" ,
"postbuild:bun" : "node scripts/copy-standalone-assets.mjs" ,
2026-08-14 05:32:40 -04:00
"start" : "node custom-server.js --port 20127" ,
2026-06-15 07:18:04 -04:00
"dev:bun" : "bun --bun next dev --webpack --port 20127" ,
2026-05-14 22:30:31 -04:00
"build:bun" : "bun --bun next build --webpack" ,
2026-08-14 05:32:40 -04:00
"start:bun" : "bun ./.next/standalone/custom-server.js" ,
2026-06-08 01:10:02 -04:00
"cli:pack" : "npm --prefix cli run pack:cli" ,
"cli:publish" : "npm --prefix cli run publish:cli"
2026-01-04 21:58:59 -05:00
} ,
"dependencies" : {
2026-05-13 22:54:52 -04:00
"@dnd-kit/core" : "^6.3.1" ,
"@dnd-kit/modifiers" : "^9.0.0" ,
"@dnd-kit/sortable" : "^10.0.0" ,
"@dnd-kit/utilities" : "^3.2.2" ,
2026-01-26 22:49:16 -05:00
"@monaco-editor/react" : "^4.7.0" ,
2026-06-18 03:58:00 -04:00
"@next/third-parties" : "^16.2.9" ,
feat(auth): add native SAML 2.0 SSO integration
Add SAML 2.0 as a second SSO protocol alongside OIDC under a unified
authMode/ssoType model. SP flows via @node-saml/node-saml: AuthnRequest
generation, ACS POST assertion handling, SP metadata export, and admin
config test endpoint. Replay-protected via saml_state cookie (httpOnly,
SameSite=Lax) matched against InResponseTo; wantAssertionsSigned enforced.
- src/lib/auth/saml.js: SAML instance builder, X.509 cert formatter, claim pickers
- 4 routes under src/app/api/auth/saml/: start, acs, metadata, test
- settingsRepo: ssoType + saml* defaults; login/status routes dispatch by type
- profile page: SSO protocol switcher, IdP metadata XML + cert uploaders
- login page: dynamic SAML sign-in button; Header: SAML user badge
2026-08-13 06:53:17 -04:00
"@node-saml/node-saml" : "^5.1.0" ,
2026-02-21 02:36:06 -05:00
"@xyflow/react" : "^12.10.1" ,
2026-01-09 05:29:11 -05:00
"bcryptjs" : "^3.0.3" ,
2026-08-13 00:50:00 -04:00
"chalk" : "^5.6.2" ,
2026-03-11 06:00:49 -04:00
"confbox" : "^0.2.4" ,
2026-01-05 03:55:56 -05:00
"express" : "^5.2.1" ,
"http-proxy-middleware" : "^3.0.5" ,
2026-01-09 05:29:11 -05:00
"jose" : "^6.1.3" ,
2026-04-17 00:33:36 -04:00
"marked" : "^18.0.1" ,
2026-05-10 10:54:54 -04:00
"material-symbols" : "^0.44.6" ,
2026-01-26 22:49:16 -05:00
"monaco-editor" : "^0.55.1" ,
2026-02-01 21:17:15 -05:00
"next" : "^16.1.6" ,
2026-03-06 04:41:02 -05:00
"node-forge" : "^1.3.3" ,
2026-01-04 21:58:59 -05:00
"node-machine-id" : "^1.1.12" ,
2026-02-01 21:17:15 -05:00
"open" : "^11.0.0" ,
"ora" : "^9.1.0" ,
2026-08-13 00:50:00 -04:00
"prop-types" : "^15.8.1" ,
2026-02-01 21:17:15 -05:00
"react" : "19.2.4" ,
"react-dom" : "19.2.4" ,
2026-03-11 07:04:38 -04:00
"react-is" : "^16.13.1" ,
2026-02-21 02:36:06 -05:00
"recharts" : "^3.7.0" ,
2026-02-08 04:28:13 -05:00
"selfsigned" : "^5.5.0" ,
2026-02-01 21:17:15 -05:00
"socks-proxy-agent" : "^8.0.5" ,
2026-03-19 04:32:29 -04:00
"sql.js" : "^1.14.1" ,
2026-02-01 21:17:15 -05:00
"undici" : "^7.19.2" ,
2026-01-04 21:58:59 -05:00
"uuid" : "^13.0.0" ,
2026-02-01 21:17:15 -05:00
"zustand" : "^5.0.10"
2026-01-04 21:58:59 -05:00
} ,
2026-03-18 09:25:48 -04:00
"optionalDependencies" : {
"better-sqlite3" : "^12.6.2"
} ,
2026-05-09 06:48:20 -04:00
"comment_better_sqlite3" : "kept in optionalDependencies so npm install doesn't fail on systems without build tools — sql.js is used as fallback at runtime" ,
2026-01-04 21:58:59 -05:00
"devDependencies" : {
"@tailwindcss/postcss" : "^4.1.18" ,
"eslint" : "^9" ,
2026-02-01 21:17:15 -05:00
"eslint-config-next" : "16.1.6" ,
2026-02-24 23:40:50 -05:00
"postcss" : "^8.5.6" ,
2026-01-04 21:58:59 -05:00
"tailwindcss" : "^4"
}
2026-02-26 21:17:49 -05:00
}