merge: pull mhiqrambg/9router-mibp-version into master

Merge the MIBP fork (v1.0.14, synced to decolua v0.5.81) into our master
(0.5.86) at merge-base a8c9d380. Keep HEAD's infra policy (untracked
lockfile, mirror-configurable Dockerfile, decolua GHCR/DockerHub, README)
while absorbing the fork's engine features:

- feat(providers): freebuff provider + executor + OAuth + usage tracking
- feat(providers): cline free-tier models, Freebuff catalog sync
- feat(proxy-pools): pool egress geo probe, proxy-pool fitness + retry
- fix(usage): hide noAuth providers (devin-cli, mimo-free) from usage list
- test(harness): DATA_DIR isolation so tests never write the real DB
- fix(codebuddy-intl): probe token in connection test, OAuth by identity
- chore(guards): durable markers so fixes aren't silently dropped

Resolutions:
- registry/index.js regenerated deterministically (122 providers, alpha
  order). trae/windsurf/devin-cli stay hidden per HEAD security posture
  (no tool-calling / local-agent shell access) — not re-enabled.
- nonStreamingHandler: drop the generic unconditional unwrapDataEnvelope
  call; envelope unwrap stays scoped to clineEnvelope-quirk providers
  (unwrapClineEnvelope), fixing a latent mibp bug where non-opted-in
  providers ({success,data} bodies) were stripped.
- Drop fork-local Docker lockfile policy (package-lock.json, AGENTS.md,
  .npmrc verify scripts): this repo keeps package-lock untracked (nix
  build deploy). .npmrc (audit=false/fund=false) kept.
- Keep gitbook-pages workflow enabled (ours); mibp disabled it.
- Restore 13 upstream tests mibp deleted (they cover features we keep).

Verified: 2841 tests, 2687 pass, fail set byte-identical to HEAD (zero
new regressions); providers/alias/oauth baselines regenerated to merged
code and all green.
This commit is contained in:
asepharyana
2026-09-23 11:44:58 +07:00
96 changed files with 7709 additions and 1787 deletions
+24 -11
View File
@@ -1,6 +1,10 @@
import pkg from "../../package.json" with { type: "json" };
const APP_VERSION = pkg.version || "0.0.0";
// Cline CLI identity (mirrors apps/cli + sdk/packages/llms request-headers.ts
// in cline/cline). Upstream gates the cline-free/* model aliases to Cline
// product surfaces + recent client versions — requests sent as
// X-CLIENT-TYPE 9router are 403'd with "only available via Cline product
// surfaces". Verified live 2026-09-11: cline-cli/3.0.61 passes the gate.
const CLINE_CLIENT_TYPE = "cline-cli";
const CLINE_CLIENT_VERSION = "3.0.61";
export function getClineAccessToken(token) {
if (typeof token !== "string") return "";
@@ -21,17 +25,26 @@ export function getClineAuthorizationHeader(token) {
return accessToken ? `Bearer ${accessToken}` : "";
}
export function buildClineHeaders(token, extraHeaders = {}) {
const authorization = getClineAuthorizationHeader(token);
export function buildClineHeaders(token, extraHeaders = {}, opts = {}) {
// API keys ride plain Bearer; OAuth access tokens must carry the WorkOS
// `workos:` prefix so the backend routes verification to WorkOS
// (cline/cline: "Prefixed with 'workos:'..."). Verified live 2026-09-11:
// plain sk_* works, workos:sk_* → 401.
const trimmed = typeof token === "string" ? token.trim() : "";
const authorization = !trimmed
? ""
: opts.isApiKey
? `Bearer ${trimmed}`
: getClineAuthorizationHeader(trimmed);
const headers = {
"HTTP-Referer": "https://cline.bot",
"X-Title": "Cline",
"User-Agent": `9Router/${APP_VERSION}`,
"X-PLATFORM": process.platform || "unknown",
"X-PLATFORM-VERSION": process.version || "unknown",
"X-CLIENT-TYPE": "9router",
"X-CLIENT-VERSION": APP_VERSION,
"X-CORE-VERSION": APP_VERSION,
"User-Agent": `Cline/${CLINE_CLIENT_VERSION}`,
"X-PLATFORM": "cli",
"X-PLATFORM-VERSION": CLINE_CLIENT_VERSION,
"X-CLIENT-TYPE": CLINE_CLIENT_TYPE,
"X-CLIENT-VERSION": CLINE_CLIENT_VERSION,
"X-CORE-VERSION": CLINE_CLIENT_VERSION,
"X-IS-MULTIROOT": "false",
...extraHeaders,
};