Harden launch security and support all OpenCode Go models - #32
Conversation
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
Completed the adversarial end-to-end smoke test against PR #32 head Runtime evidence
No provider quota or real provider credentials were used. All upstream traffic was captured by local recording services; all ten planned runtime assertions passed. |
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
Tested PR #32 head
The managed proxy setup, loopback health, and exact |
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
Merged locally into main as c7374ef (4 commits + merge) and pushed. Tests: 916 passed, ruff clean. Closing as content is now in main. |
Summary
Prepares the proxy for a public launch as an independent, single-user adapter with strict credential, routing, and process-ownership boundaries.
route(model)resolves explicitopencode-go/<id>, Zen, and native ownership before dispatch; malformed, unknown, and uncertified Go IDs fail closed127.0.0.1:8787, with release-pinned sources and truthful adapter identity502, including failures before a streaming response is committed/modelsdiscovery is filtered through the certified protocol map and merged with the offline seed using collision-safe explicit Go slugsValidation:
uv sync; 916 pytest tests passed with 2 skipped and 12 subtests; Ruff passed; Python source/wheel build passed; Swift build passed; 6 Swift tests passed;git diff --checkpassed.Summary by cubic
Hardens launch security and model routing so the proxy fails closed instead of allowing unauthenticated remote clients or silently swapping unknown models, and routes every documented OpenCode Go model by protocol family.
OPENCODE_GO_PROXY_ALLOW_REMOTE=1andOPENCODE_GO_PROXY_CALLER_TOKEN(at least 32 characters), and remote clients must send the token inX-OpenCode-Go-Proxy-Token.Host: localhostheader no longer admits a remote client.400before routing; previously unknown IDs silently becamedeepseek-v4-flash./modelsendpoint and catalog entries are namespacedopencode-go/<model>.Written for commit 79cb542. Summary will update on new commits.
Link to Devin session: https://app.devin.ai/sessions/d1b9b744fad04ef69de26d2c4ca6261d
Open in Devin Desktop: https://app.devin.ai/desktop/session/d1b9b744fad04ef69de26d2c4ca6261d?variant=devin
Requested by: @kartikkabadi