mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-10-06 01:37:48 +08:00
MCP preview after the server lost a session (it expired, or the MCP process restarted): - Every server state has an id, made when the state is created. The tab notices a new id even when the version numbers happen to match, and every push names the state it was based on, so one based on a lost state is refused, also when it comes before the tab's first poll (the server recovers the saved file first). - The tab keeps the newest canvas XML, saved or not. When the server knows nothing (no file) or exactly what the tab last saved, the canvas wins and is saved, so edits made while the server was down are kept. Otherwise the server's diagram (an AI write the tab missed, a cleared document that was saved) is shown and the tab's copy goes to History. - Late answers to an old state's push or poll are dropped; a failed push says the server is unreachable; Download as .drawio saves the canvas. Settings and server: - Saved providers this version does not know stay in storage with their keys, and sending no longer trips over them. - The desktop "Ollama (Local)" preset with a key goes to local Ollama again; a server model's Ollama URL variable is read; the admin panel writes Ollama Cloud's URL for a key without one. - Provider error texts show again in the desktop app and for EdgeOne. - .env: a quoted value followed by a comment ending in a quote is read as dotenv reads it; unquoted values are unchanged. - Desktop app: the next launch opens the port where a chat was last saved; a launch elsewhere that saves nothing does not move it, and a page with no chats lets the next launch try the other port once. - The Test button no longer stays busy after another tab changed the key. - A completed append_diagram is no longer undone by an earlier failed edit's preview; a file read once in vain is saved again once it is read or gone. From the first batch's review: - The admin panel's Test of an entry without a URL now tests the server's <P>_BASE_URL, where chat sends the entry's key; chat is unchanged (the first fix rerouted working setups). - The model list ends downloads that are too large, accepts answers without a body, and keeps the "redirects are not allowed" explanation. - A test covers the preview's History rendering.
75 lines
2.9 KiB
TypeScript
75 lines
2.9 KiB
TypeScript
import { POST as validateModel } from "@/app/api/validate-model/route"
|
|
import { checkAdminAuth } from "@/lib/admin/auth"
|
|
import {
|
|
AdminProviderSchema,
|
|
loadAdminProviders,
|
|
mergeSecrets,
|
|
} from "@/lib/admin/providers"
|
|
import { globalBaseUrl } from "@/lib/ai-providers"
|
|
|
|
export const runtime = "nodejs"
|
|
export const dynamic = "force-dynamic"
|
|
|
|
// Test a model with the client's CURRENT provider state (which may be
|
|
// unsaved). Secret fields arrive either as plaintext (newly typed) or as
|
|
// masked {isSet} markers, which are resolved against settings.json — so
|
|
// testing works both before and after saving.
|
|
export async function POST(req: Request) {
|
|
const authError = checkAdminAuth(req)
|
|
if (authError) return authError
|
|
|
|
let body: { provider?: unknown; modelId?: string }
|
|
try {
|
|
body = await req.json()
|
|
} catch {
|
|
return Response.json({ error: "Invalid JSON body" }, { status: 400 })
|
|
}
|
|
|
|
const parsed = AdminProviderSchema.safeParse(body.provider)
|
|
if (!parsed.success || !body.modelId) {
|
|
return Response.json(
|
|
{ valid: false, error: "Invalid provider or model" },
|
|
{ status: 400 },
|
|
)
|
|
}
|
|
|
|
// SECURITY: a stored secret is only resolved from an {isSet} marker if
|
|
// the endpoint it would be sent to (provider + baseUrl) still matches
|
|
// the stored entry. Otherwise a tampered baseUrl could exfiltrate the
|
|
// stored key to an arbitrary host. Mismatches must re-supply plaintext.
|
|
const stored = loadAdminProviders().find((p) => p.id === parsed.data.id)
|
|
const sameEndpoint =
|
|
stored &&
|
|
stored.provider === parsed.data.provider &&
|
|
(stored.baseUrl ?? "") === (parsed.data.baseUrl ?? "") &&
|
|
(stored.awsRegion ?? "") === (parsed.data.awsRegion ?? "")
|
|
const [resolved] = mergeSecrets(
|
|
[parsed.data],
|
|
sameEndpoint && stored ? [stored] : [],
|
|
)
|
|
|
|
return validateModel(
|
|
new Request(new URL("/api/validate-model", req.url), {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-Type": "application/json",
|
|
// Checked again there, in place of an access code
|
|
"x-admin-password": req.headers.get("x-admin-password") || "",
|
|
},
|
|
body: JSON.stringify({
|
|
provider: resolved.provider,
|
|
apiKey: resolved.apiKey,
|
|
// Without a URL of its own, chat sends the entry's key to
|
|
// the server's <P>_BASE_URL: test that endpoint, not
|
|
// another one
|
|
baseUrl: resolved.baseUrl || globalBaseUrl(resolved.provider),
|
|
modelId: body.modelId,
|
|
awsAccessKeyId: resolved.awsAccessKeyId,
|
|
awsSecretAccessKey: resolved.awsSecretAccessKey,
|
|
awsRegion: resolved.awsRegion,
|
|
vertexApiKey: resolved.vertexApiKey,
|
|
}),
|
|
}),
|
|
)
|
|
}
|