Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions .agents/docs/gateway-extensions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
# Gateway extensions

The `@cordisx/plugin-cli-proxy-api/extensions/v1` entrypoint is the generic
CordisX contract for extending the managed CLIProxyAPI gateway. It is not a
provider-specific integration and must not contain private tenant, domain,
header, or product policy.

## Topology

- CordisX runs one Host-owned CLIProxyAPI managed process.
- The gateway package supplies one native `cordisx-gateway-bridge` plugin.
- Consumer plugins register adapters and connections through the
`cliProxyGatewayExtensions` context service.
- A registration change creates one generation-fenced materialization and
managed-service restart transaction. Disposing the consumer binding revokes
only that producer generation.
- The bridge publishes models as `connectionId/modelId` and routes them to its
own static executor. It never starts a proxy process per connection.

## Public contract

An adapter declares bounded session extraction and request transforms. Session
sources are an HTTP header or a body JSON Pointer. Transforms may clear headers
and set headers or body values with `{{session}}`, `{{connectionId}}`, and
`{{sourceModelId}}` substitutions.

A connection references an existing Host-managed source, a stable
`connectionId`, one adapter revision, an endpoint path, an authorization mode,
and model mappings. The Host materializer resolves the source origin and
authorization into the private process configuration. Endpoint and credential
values are neither registration fields nor renderer-visible state.

`connectionId` is the identity shared with Host profile synchronization. Host
`providerBindings` explicitly bind an existing managed connection to a target
profile and do not duplicate credentials. This package uses that identity
semantics but does not import Host-private synchronization contracts or create
a second persistent connection database.

## Fail-closed behavior

Required adapters are removed from model publication when missing, disabled,
or revision-mismatched. The native bridge remains loaded even when its active
plan is empty so known protected model IDs remain owned by its router and fail
inside the executor before an upstream request. They must not fall through to
another provider with the same model ID.

The native executor removes caller authorization, host, content-length, and
adapter-declared untrusted headers before applying connection authorization.
Missing required sessions and missing credentials fail before `host.http.do`
or `host.http.do_stream`.

## Verification boundary

`npm run test:native` builds the current-platform C-shared bridge and loads it
through the real CLIProxyAPI plugin host from `CLIPROXY_SOURCE` (default
`/private/tmp/cliproxy-src`). Its synthetic loopback tests cover two connections
with the same source model and different credentials, header and body session
sources, leakage checks, streaming, cancellation, required-adapter failures,
and disabled-plan fallback protection.

The checked-in runtime artifact is Darwin arm64. `scripts/build-native.mjs`
can build Darwin, Linux, or Windows on arm64 or x64 when run on that target, but
release artifacts must declare only binaries actually included in
`runtime-manifest.json`. This test is native ABI evidence, not a real provider,
native CordisX App, credential migration, or cross-platform acceptance test.
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,4 @@ dist/
node_modules/

.cache/sdk/
.cache/native-gateway-bridge/
3 changes: 3 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,9 @@ for the interaction contract and older-Host capability boundary.

Dependency setup: [notification migration](./.agents/docs/notifications.md).

Gateway extension architecture and verification:
[gateway extensions](./.agents/docs/gateway-extensions.md).

## Development and release

- Requires Node.js 22 or newer. Install dependencies with `npm ci`.
Expand Down
8 changes: 6 additions & 2 deletions THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,11 @@
# Third-party notices

This repository does not currently vendor third-party source or assets.
The native gateway bridge statically links `gopkg.in/yaml.v3` version 3.0.1.
Files ported from libyaml are licensed under the MIT License, copyright
2006-2011 Kirill Simonov. Remaining files are licensed under the Apache License
2.0, copyright 2011-2019 Canonical Ltd. The upstream license and notice are at
<https://github.com/go-yaml/yaml/tree/v3.0.1>.

Development dependencies retain their own licenses and notices. The future
runtime package must update this file if it begins to redistribute any
runtime package must update this file if it redistributes additional
third-party code or media.
7 changes: 7 additions & 0 deletions config/cli-proxy-api.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,10 @@ remote-management:
disable-auto-update-panel: true
codex-api-key: []
openai-compatibility: []
plugins:
enabled: true
dir: runtime/cli-proxy-plugins
configs:
cordisx-gateway-bridge:
enabled: true
active: false
2 changes: 1 addition & 1 deletion cordisx-package.json
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,6 @@
"runtimeManifest": {
"path": "./runtime-manifest.json",
"schema": "https://raw.githubusercontent.com/cordisx/cordisx-protocol/main/schemas/plugin-manifest.v14.schema.json",
"digest": "sha256:a66facc4315bf2b63941e94551ee982c32c034188bfbceb92135c779f0332dbf"
"digest": "sha256:485bcb6d6d89e2d41065f563b0ecba1d556693149374505ecc69f25d8cfb39f7"
}
}
5 changes: 5 additions & 0 deletions native/gateway-bridge/go.mod
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
module github.com/cordisx/plugin-cli-proxy-api/native/gateway-bridge

go 1.22

require gopkg.in/yaml.v3 v3.0.1
4 changes: 4 additions & 0 deletions native/gateway-bridge/go.sum
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM=
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
Loading
Loading