mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-10-08 02:37:46 +08:00
Chats: - New Chat right after an answer saves that chat once. Saves run one at a time and read the chat on screen when their turn comes; a save scheduled for a chat that is no longer on screen is dropped. A chat whose id was still on its way to the URL no longer comes back after New Chat (the next answer went into it). - Crossing the 768 px breakpoint keeps the chat panel: a streaming answer, unsaved messages and attachments stay. The panel gets the sizes of each side, and a panel collapsed on desktop opens on mobile. - The chat's export waits for its own reply: an edit's history export still on its way no longer answers it with the older diagram, and two file saves at once no longer swap results. - A second edit in one answer is previewed on the first edit's result. - Stop also ends a running screenshot check; a chat that cannot be saved (storage full) can be left with "Continue without saving". - Small diagrams with shapes count as diagrams; the tool card no longer crashes on malformed operations. Quota and providers: - Requests that reach the server's own endpoints count toward the quota: EdgeOne (always its own endpoint now), a private base URL whatever key header is sent, keyless Ollama without a URL. With the quota on, a redirect is followed only to a public address. The output cap applies to these requests too. - Stop records the tokens of the steps that finished; the screenshot check counts its tokens without counting a request. - EdgeOne configured only by AI_PROVIDER works, also in the admin Test, which forwards the access code. Azure set up only in the admin panel works in chat. The Test sends a Bedrock session token. - The admin panel's Test of an entry without a URL uses the server's URL as the server does (no private address check for it); the admin panel no longer writes an Ollama URL. MCP server: - Write tools and start_session run one at a time, so two at once never drop each other's change; a cancelled call waiting its turn is skipped. get_diagram and export_diagram keep the session they started with. - Export to .drawio first gets the user's latest edits from the browser. - History thumbnails: one that arrives after the next AI write is dropped; a sync reply keeps the image; a version that changed only page settings is its own entry. - A diagram over the 10 MB limit is saved without its image, or the user is told to download it (the server now answers 413 instead of cutting the connection). - Labels holding text like id='1' or parent='1' are no longer read as attributes (a layer or a parent was deleted). A broken bare <mxGraphModel> file is refused. - After a sync reply the tab no longer sends its autosave copy again. Desktop and files: - A newer switch of the same preset is not rolled back by an older one that failed. .env values with escaped quotes are read whole. - MCP saved files: a file that could not be read stays protected while a folder without permission hides it, and is saved again once deleted. - The desktop app reports "no chats" only when the count was read and no model settings are stored.
85 lines
3.5 KiB
TypeScript
85 lines
3.5 KiB
TypeScript
import { POST as validateModel } from "@/app/api/validate-model/route"
|
|
import { checkAdminAuth } from "@/lib/admin/auth"
|
|
import {
|
|
AdminProviderSchema,
|
|
loadAdminProviders,
|
|
mergeSecrets,
|
|
} from "@/lib/admin/providers"
|
|
import { globalBaseUrl } from "@/lib/ai-providers"
|
|
|
|
export const runtime = "nodejs"
|
|
export const dynamic = "force-dynamic"
|
|
|
|
// Test a model with the client's CURRENT provider state (which may be
|
|
// unsaved). Secret fields arrive either as plaintext (newly typed) or as
|
|
// masked {isSet} markers, which are resolved against settings.json — so
|
|
// testing works both before and after saving.
|
|
export async function POST(req: Request) {
|
|
const authError = checkAdminAuth(req)
|
|
if (authError) return authError
|
|
|
|
let body: { provider?: unknown; modelId?: string }
|
|
try {
|
|
body = await req.json()
|
|
} catch {
|
|
return Response.json({ error: "Invalid JSON body" }, { status: 400 })
|
|
}
|
|
|
|
const parsed = AdminProviderSchema.safeParse(body.provider)
|
|
if (!parsed.success || !body.modelId) {
|
|
return Response.json(
|
|
{ valid: false, error: "Invalid provider or model" },
|
|
{ status: 400 },
|
|
)
|
|
}
|
|
|
|
// SECURITY: a stored secret is only resolved from an {isSet} marker if
|
|
// the endpoint it would be sent to (provider + baseUrl) still matches
|
|
// the stored entry. Otherwise a tampered baseUrl could exfiltrate the
|
|
// stored key to an arbitrary host. Mismatches must re-supply plaintext.
|
|
const stored = loadAdminProviders().find((p) => p.id === parsed.data.id)
|
|
const sameEndpoint =
|
|
stored &&
|
|
stored.provider === parsed.data.provider &&
|
|
(stored.baseUrl ?? "") === (parsed.data.baseUrl ?? "") &&
|
|
(stored.awsRegion ?? "") === (parsed.data.awsRegion ?? "")
|
|
const [resolved] = mergeSecrets(
|
|
[parsed.data],
|
|
sameEndpoint && stored ? [stored] : [],
|
|
)
|
|
|
|
const serverUrl = globalBaseUrl(resolved.provider)
|
|
return validateModel(
|
|
new Request(new URL("/api/validate-model", req.url), {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-Type": "application/json",
|
|
// Checked again there, in place of an access code
|
|
"x-admin-password": req.headers.get("x-admin-password") || "",
|
|
// The EdgeOne function checks the access code and Pages
|
|
// cookies, and its URL is built from the page's origin
|
|
"x-access-code": req.headers.get("x-access-code") || "",
|
|
cookie: req.headers.get("cookie") || "",
|
|
...(req.headers.get("origin") && {
|
|
origin: req.headers.get("origin") as string,
|
|
}),
|
|
},
|
|
body: JSON.stringify({
|
|
provider: resolved.provider,
|
|
apiKey: resolved.apiKey,
|
|
// Without a URL of its own, chat sends the entry's key to
|
|
// the server's <P>_BASE_URL: test that endpoint, not
|
|
// another one. It is the server's own, which chat uses
|
|
// without the checks for a URL a user typed.
|
|
baseUrl: resolved.baseUrl || serverUrl,
|
|
...(!resolved.baseUrl && serverUrl && { serverBaseUrl: true }),
|
|
modelId: body.modelId,
|
|
awsAccessKeyId: resolved.awsAccessKeyId,
|
|
awsSecretAccessKey: resolved.awsSecretAccessKey,
|
|
awsRegion: resolved.awsRegion,
|
|
vertexApiKey: resolved.vertexApiKey,
|
|
}),
|
|
}),
|
|
)
|
|
}
|