Skip to content

Port upstream 0.64.0: LLM Proxy base URL setting, private-network HTTP, tolerant quota_groups - #704

Closed
Finesssee wants to merge 3 commits into
port/upstream-0.64.0from
port/micro-0.64.0-llmproxy-parity
Closed

Finesssee wants to merge 3 commits into
port/upstream-0.64.0from
port/micro-0.64.0-llmproxy-parity

Conversation

@Finesssee

Copy link
Copy Markdown
Collaborator

Found by the 0.60.4-0.69.0 port gap audit (gap G7, release bullet 0.64.0 #29).

Summary

LLM Proxy now behaves like upstream 0.64.0 for its endpoint handling:

  • The base URL is a stored setting (Providers tab, LLM Proxy, "Base URL"), with LLM_PROXY_BASE_URL as the fallback. The API key path is unchanged (LLM_PROXY_API_KEY bearer, keyring, or Preferences).
  • Endpoint policy is "https or private-network http": plain HTTP is accepted for loopback, RFC1918, unique-local, link-local and .local hosts. Public hosts still need HTTPS, and user info is rejected.
  • The quota URL keeps any ?query / #fragment at the end: the configured base is split at the first ? or #, trailing slashes are trimmed, /v1 is appended only when the percent-decoded path does not already end in /v1, then /quota-stats and the suffix.
  • Malformed quota_groups (string, number, null, array of non-objects, group with a non-numeric remaining_percent) is treated as absent for that provider without discarding its requests, tokens or cost. Arrays and objects (values) are both accepted.

Upstream reference

  • Release bullet: "Improved: LLM Proxy via plugin, preserving self-hosted origins, aggregate usage, provider summaries".
  • Tag-pinned at v0.64.0 (read-only GET): Sources/CodexBarCore/Resources/Plugins/llmproxy.ts (endpoint policy, suffix split, tolerant quota_groups), Sources/CodexBarCore/Providers/LLMProxy/LLMProxySettingsReader.swift (private-network HTTP validation, error text), Sources/CodexBar/Providers/LLMProxy/LLMProxyProviderImplementation.swift (API key + Base URL settings fields).
  • I did not look up the upstream PR number, so none is cited.

Ported / Deferred

Ported: base URL setting with env fallback, private-network HTTP policy (new validated_https_or_private_http_url next to validated_https_url, which keeps its HTTPS-only behavior), suffix-preserving /v1/quota-stats URL, tolerant quota_groups, Settings field with en-US strings, settings-side validation (provider_workspace.rs) so a bad URL is rejected at save time.

Left out:

  • Other locales fall back to en-US for the four new LlmProxy* keys (same fallback path other recent keys use).
  • Upstream's plugin returns no primary window when no quota group reports a percentage; Win-CodexBar keeps its existing 0% primary. That is unrelated to this gap and was not changed.
  • Upstream availability gating on "key and base URL both configured" is not ported; Win-CodexBar's provider enablement is unchanged.
  • Numeric strictness of the upstream plugin (for example rejecting a non-integer total_requests) is not ported; existing serde decoding is kept.

Validation

All with cargo +1.98.0 through the E-core wrappers, slot-8 target dir.

  • cargo fmt --all: clean
  • cargo clippy --workspace --all-targets -- -D warnings: pass
  • cargo test -p codexbar --lib -- llmproxy provider_workspace locale validated: 34 passed
  • cargo test -p codexbar (full): 2167 passed, 0 failed, 1 ignored
  • cargo test -p codexbar-desktop-tauri: 461 passed, 1 failed, the known bootstrap_payload_exposes_every_provider_variant (fixed by Isolate bootstrap payload test from real settings #684, ignored per brief)
  • pnpm --dir apps/desktop-tauri exec vitest run: 67 files, 402 tests passed
  • pnpm --dir apps/desktop-tauri run build: pass
  • pnpm --dir apps/desktop-tauri run lint: only pre-existing unused-variable warnings in untouched files

New tests cover URL suffix//v1 rules (including percent-encoded v1, query and fragment), the https-or-private-http policy (accept and reject lists), settings-over-env precedence, malformed/array/object quota_groups, and save-time validation.

Affected areas

  • Providers (rust/src/providers/llmproxy, shared URL validator in providers/mod.rs)
  • Settings (workspace-value validation, Providers tab field)
  • Frontend (Providers tab credentials section, i18n keys)
  • Tray / float bar / CLI

UI proof

Pending: coordinator will capture CUA proof on a fresh build (LLM Proxy "Base URL" field in the Providers tab).

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Validated 2026-10-01 at c49c894 (port content) + 90e07b4 (lint companion):

  • cargo fmt --all — pass.
  • cargo test --manifest-path rust/Cargo.toml — full workspace suite pass, 0 failed / 1 ignored, before and after the lint companion; covers the new quota-stats summary parsing tests, tolerant quota_groups (map or array), elapsed-reset filtering, zero-spend retention, USD formatting, malformed-payload rejection, and the private-HTTP host allowlist/reject additions (printer.local.:8000, [fe80::1], .local without label, localhost.:8000, [::ffff:10.0.0.1], [2001:db8::1], percent-encoded .local bypass).
  • cargo clippy --manifest-path rust/Cargo.toml --all-targets -- -D warnings — pass. The new format_usd cast carries the repo's allow(..., reason) convention; companion commit 90e07b4 additionally fixes three pre-existing lint sites (alibabatokenplan manual_range_contains, kiro + openai nonminimal_bool) that clippy 1.96 flags identically on origin/main — no behavior change.
  • Pushed edbf2def..90e07b4e as a fast-forward; ls-remote head matches local 90e07b4e.
  • Per maintainer guidance for backend parity items, no browser-use UI proof is included for this validation pass; informational-window rendering behavior is exercised by the unit tests above.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

UI proof (browser-use)

Combined build of integrate/v0.70.0-ports at ddd85594 (all 40 port PRs and the follow-ups). Debug desktop build in proof mode, isolated config/data dirs, driven by browser-use over the WebView2 DevTools protocol with DOM events only (no mouse or keyboard input, no focus changes). All data is synthetic: local mock servers for L1, a seeded usage snapshot plus synthetic local logs for L2.

Scenario Check Result
L1 tray (mock servers) #704 LLM Proxy (saved base URL with ?tenant query, private-network http on 127.0.0.1): Quota 60%, 2,060 requests, 61,600 tokens, 5 / 7 active keys, provider rows PASS
L1 tray (mock servers) #704 LLM Proxy bridge: cost 'Approx. spend' $15.75 carried (the tray hides cost sections by design) PASS
L1 settings #704 LLM Proxy settings: Base URL field shows the saved private-network URL with query kept PASS
L1 settings #704 LLM Proxy settings: public plain-HTTP base URL is rejected on Save, saved value unchanged PASS
L1 mock request logs #704 LLM Proxy mock: /proxy/v1/quota-stats?tenant=proof (query kept after the inserted path), bearer PASS

Every surface also passed the privacy check (no email-like text, account e-mail nodes or profile paths in the DOM) and theme auto rendered dark on the tray flyout, float bar and settings windows.

Validation at ddd85594: cargo fmt --all --check, cargo clippy --workspace --all-targets -- -D warnings, cargo test -p codexbar (3567 passed, 0 failed) and cargo test -p codexbar-desktop-tauri (606 passed, 0 failed). Screenshots were captured for each scenario and kept with the local proof kit.

@Finesssee

Copy link
Copy Markdown
Collaborator Author

Shipped in v0.70.0: this PR's head is included in main via #735 (merge commit 9d0a37a). Closing as integrated.

@Finesssee Finesssee closed this Oct 3, 2026
junglesub-bot Bot pushed a commit to junglesub/Win-CodexBar that referenced this pull request Oct 4, 2026
…g, private-network HTTP, tolerant quota_groups (the clippy companion 90e07b4 is already on release as 546a398; renames the nesszer#704 endpoint-policy host check so it does not collide with the shared is_private_network_host)
junglesub-bot Bot pushed a commit to junglesub/Win-CodexBar that referenced this pull request Oct 4, 2026
… merged next to Hyper/GitKraken/Bifrost/Aixy and the nesszer#704 LLM Proxy keys; Crof stays retired; llmman dashboard routed through provider_dashboard_url)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant