Skip to content

Releases: yelixir-dev/commandcode-bridge

CommandCode Bridge 1.74.0.d

Choose a tag to compare

@yelixir-dev yelixir-dev released this 04 Oct 05:02

CommandCode Bridge 1.74.0.d lets you delete a credential from the dashboard without the bridge API key. The CommandCode CLI baseline remains 1.74.0; the 85-model catalog is unchanged.

What changed

  • Deleting a credential and pressing Save used to fail with 401 Unauthorized in any browser that had not stored the client key, and the Credentials tab gave no place to enter it.
  • The delete button on the Credentials tab now asks for confirmation and applies the deletion immediately. No Save, no restart, and no key are needed: the bridge stops using that key for new requests at once, and the deletion is written to the credentials file so it survives a restart.
  • Keys that came from COMMANDCODE_API_KEY(S) or the CLI auth file can be deleted too; the remaining keys are written to the credentials file.
  • The last credential cannot be deleted (add another key first). Unknown ids return 404.
  • Adding or replacing keys, other settings, and restarts still require the bridge API key.

Security notice

Anyone who can reach the bridge can now delete credentials (not add or replace them). A web page on another origin cannot trigger it, because a DELETE needs a CORS preflight that the bridge answers only for the same hostname; DNS rebinding against a loopback-only bridge is not covered. Keep the bridge on a trusted network. See docs/SECURITY.md.

Updating an installation

Install or rebuild this version using the deployment method already in use and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.74.0.d afterward. After that, delete keys directly from the Credentials tab.

The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.

Verification scope

npm run verify passed with 311 tests in 16 files, and GitHub CI passed on Node 20, 22, and 24. A headless browser against the built bridge, with no stored client key, deleted a credential after confirmation, kept it deleted across the dashboard refresh, routed live requests only to the remaining key without a restart, and refused the last key. Live upstream calls and Windows are not covered by those checks.

CommandCode Bridge 1.74.0.c

Choose a tag to compare

@yelixir-dev yelixir-dev released this 04 Oct 04:11

CommandCode Bridge 1.74.0.c fixes dashboard credential deletion and editing that did not take effect. The CommandCode CLI baseline remains 1.74.0; the 85-model catalog is unchanged.

What was wrong

  • The dashboard saves credentials to ~/.config/commandcode-bridge/credentials.json (or COMMANDCODE_CREDENTIALS_FILE, or $XDG_CONFIG_HOME/commandcode-bridge/credentials.json), but at startup the bridge read that file only when COMMANDCODE_CREDENTIALS_FILE was set to a non-empty value. install.sh and the env examples leave it empty, so on those installs deleted or added keys were saved and then ignored after restart; the key from COMMANDCODE_API_KEY(S) or the CLI auth file kept appearing.
  • After saving, the dashboard's 5-second refresh redrew the running (old) credential list until restart, so a deleted key looked like it came back.
  • The first save could drop an env-sourced key such as default from the file because its secret was not found.

Fixes

  • Startup now reads credentials from the same file the dashboard writes, whether or not COMMANDCODE_CREDENTIALS_FILE is set.
  • Until restart, the dashboard shows the saved configuration (still marked as needing a restart).
  • Saving keeps the secret of a credential that currently comes from the env or CLI auth.

Compatibility notice

  • Saved dashboard keys start being used. If you edited credentials in the dashboard on an install where COMMANDCODE_CREDENTIALS_FILE was empty, those saved keys were ignored until now. After updating and restarting, the bridge uses the keys listed in the credentials file instead of COMMANDCODE_API_KEY. Check the Credentials tab after the restart.
  • The last key cannot be removed from the dashboard if an env key exists. When the file lists no credentials, the bridge still falls back to COMMANDCODE_CREDENTIALS/COMMANDCODE_API_KEYS, COMMANDCODE_API_KEY, then the CLI auth file. To retire that key, remove it from the env file (or auth file) and restart.

Updating an installation

Install or rebuild this version using the deployment method already in use, preserve the existing credentials and dashboard configuration, and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.74.0.c afterward, then delete the unwanted credential, save, and restart once more.

The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.

Verification scope

npm run verify passed with 307 tests in 16 files, and GitHub CI passed on Node 20, 22, and 24. The built bridge, run with the installer's env layout, kept deletions and additions across the save, the next dashboard refresh, and a restart. Live upstream calls and Windows are not covered by those checks.

CommandCode Bridge 1.74.0.b

Choose a tag to compare

@yelixir-dev yelixir-dev released this 03 Oct 16:48

CommandCode Bridge 1.74.0.b releases PR #7 and PR #8, which change how a drained CommandCode key is handled. The CommandCode CLI baseline remains 1.74.0; the 85-model catalog is unchanged.

Compatibility notice: drained keys

CommandCode reports a key with no usable credit as HTTP 400 with an "insufficient credits" message, not 402. The bridge used to treat every 400 as a client error, so a drained key stayed in rotation and kept failing requests.

  • A 400 "insufficient credits" response now cools the key down for the larger of COMMANDCODE_CREDENTIAL_COOLDOWN_MS and the billing refresh interval (5 minutes by default). Unlike 402, a billing refresh does not clear it early, because upstream pre-charges the estimated request cost and a positive balance can still be too small. This matches the CLI's own check.
  • The failing request moves to another key instead of failing. 403 responses now rotate on the Alpha path too, as they already did on the Provider path.
  • With a single key, a drained key returns 503 (NoAvailableCommandCodeCredentialError) for the cooldown window instead of repeating the upstream 400. After topping up, requests may stay refused for up to that window. The dashboard shows the key as "Cooling".
  • Other 400, 404 and 422 responses still fail immediately with no retry and no cooldown. 429/5xx keep retrying without a cooldown, as in 1.66.0.d.

Updating an installation

Install or rebuild this version using the deployment method already in use, preserve the existing credentials and dashboard configuration, and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.74.0.b afterward.

The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.

Verification scope

npm run verify passed with 303 tests in 16 files, and GitHub CI passed on Node 20, 22, and 24. The built bridge passed local HTTP QA with two keys against a mock upstream: an insufficient-credits 400 rotated the request to the other key, later requests skipped the drained key, and a plain 400 failed after one upstream call. Live upstream billing behavior and Windows are not covered by those checks.

Thanks to WhatAHappyPig for PR #7 and PR #8.

CommandCode Bridge 1.74.0.a

Choose a tag to compare

@yelixir-dev yelixir-dev released this 02 Oct 14:22

CommandCode Bridge 1.74.0.a aligns the bridge with CommandCode CLI 1.74.0 and is the first GitHub release since 1.53.0.c. It rolls up the untagged-until-now bridge versions 1.66.0.a through 1.66.0.d, which are now tagged individually. The static catalog has 85 models.

Compatibility notices

  • Dashboard replaced (1.66.0.b). /dashboard/ is now a static operations console served from dashboard/ (Overview, Credentials, Models, Settings, Info; Korean, English, and Chinese; light theme; ?demo). / and /dashboard redirect to /dashboard/. It uses the existing /health and /admin/* endpoints, so no API contract changed. The previous inline dashboard is kept under the tag legacy-dashboard-1.66.0.a.
  • Cooldown policy (1.66.0.d, PR #6). Only credential-scoped failures (401/402/403) disable or cool down a key. HTTP 429/5xx, empty bodies, stream error events, and network errors are retried within the request but no longer bench the key, so a single-key deployment no longer fails every request for 60 s after one at-capacity error. COMMANDCODE_CREDENTIAL_COOLDOWN_MS now only sets the minimum 402 cooldown. With several keys, a key-specific 429 no longer steers later requests away for 60 s.
  • Retired model (1.74.0.a). stealth/pixel-canary is removed because the CLI hides it after its stealth preview ended on 2026-09-30. Persisted entries and allowlist entries for it are dropped, and requests for it return 400 model_not_allowed.
  • Session affinity (1.66.0.c). Turns of one conversation (same system text and first user message) stay on the key that served it, and the bridge sends one stable threadId/x-session-id per conversation, as the CLI does. COMMANDCODE_SESSION_AFFINITY_TTL_MS=0 disables it. It has been verified against a mock upstream only.

Catalog changes

  • CLI 1.74.0 (1.74.0.a): adds opt-in deepseek/deepseek-v4.1-flash-fast, inclusionai/ling-3.1-flash:free, claude-sonnet-5-5, and gpt-6.1-sol; retires stealth/pixel-canary; reprices xai/grok-4.7 to $2/$6. Images are stripped for the new text-only inclusionai/ling-3.1-flash:free.
  • CLI 1.66.0 (1.66.0.a): adds 13 opt-in models (z-ai/glm-5.3-flashx, xiaomi/mimo-v2.6-pro, xiaomi/mimo-v2.6-pro-ultraspeed, xiaomi/mimo-v2.6-flash, Qwen/Qwen3.8-Omni-Flash, paid meituan/LongCat-2.0, stepfun/Step-5-Preview, stealth/space-bunny-alpha, stealth/pixel-canary, claude-opus-5-5, gpt-6-sol, gpt-6-luna, xai/grok-4.7), retires meituan/LongCat-2.0:free, and reprices deepseek/deepseek-v4-flash-vision-exp and stepfun/Step-3.5-Flash.
  • New models are disabled by default; the six established defaults are unchanged. Enable new models from the dashboard or COMMANDCODE_ALLOWED_MODELS.

Fixes and improvements

  • reasoning_effort: "off" is accepted and forwarded on the Alpha path. CLI 1.73.3 sends it for DeepSeek V4/V4.1 when thinking is disabled; the bridge used to reject it with 400.
  • The default COMMANDCODE_CLI_VERSION is 1.74.0. A wire audit of the 1.66.0 and 1.74.0 bundles found no other bridge-facing change; the new x-cli-surface header is sent only by cmd acp/cmd rpc, so the bridge does not send it.
  • Tests no longer read the host's real dashboard config or CLI auth files, so npm test and npm run verify pass on a host that also runs a deployment.

Updating an installation

Install or rebuild this version using the deployment method already in use, preserve the existing credentials and dashboard configuration, and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.74.0.a afterward. Docker images must be rebuilt to pick up dashboard/, which is now part of the runtime image.

The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.

Verification scope

npm run verify passed with 293 tests in 16 files, and GitHub CI passed on Node 20, 22, and 24. The built bridge passed local HTTP QA against a mock upstream (/health, /v1/models, request validation, reasoning_effort: "off", retired-model refusal). Live upstream inference, real multi-account session affinity, and Windows are not covered by those checks.

Thanks to WhatAHappyPig for PR #6.

CommandCode Bridge 1.53.0.c

Choose a tag to compare

@yelixir-dev yelixir-dev released this 16 Sep 14:19

CommandCode Bridge 1.53.0.c incorporates PR #3 and the text-only image policy from issue #5. The CommandCode CLI baseline remains 1.53.0; the 70-model catalog is unchanged.

Compatibility notice: reasoning output

With INCLUDE_REASONING=true, reasoning is no longer appended to content:

  • Streaming clients receive delta.reasoning_content.
  • Non-streaming clients receive message.reasoning_content.

Clients that display reasoning must read the separate field. Assistant history containing reasoning_content is forwarded as native reasoning parts on the Alpha path. With reasoning disabled, Provider responses strip that field.

Fixes and improvements

  • Provider non-streaming visibility and retry checks now agree: exposed reasoning-only responses return without an unnecessary retry, while hidden reasoning does not turn an empty length response into blank success.
  • Alpha sends base64 image data URIs as native image parts with the CLI's mimeType field. Remote URLs remain text placeholders; the bridge does not download them.
  • Both Alpha and Provider apply the CLI 1.53.0 text-only model list, including aliases. Images are removed for those models and replaced with numbered/omission text markers without mutating the original conversation.
  • Vision-capable models retain image input. Unknown/custom models follow the CLI's image-capable fallback; that fallback is not a guarantee that a particular upstream model supports vision.

Thanks to the PR #3 contributor for the image and reasoning implementation. The original contributor commits are preserved.

Updating an installation

Install or rebuild this version using the deployment method already in use, preserve the existing credentials and dashboard configuration, and restart the managed service. Publishing this release does not update running servers automatically. Verify that /health reports 1.53.0.c afterward.

For Docker deployments still using files older than 1.53.0.b, take the updated Compose file and recreate the container. The dashboard restart button needs both COMMANDCODE_BRIDGE_RESTART_MODE=exit and an external restart policy.

The attached npm archive contains built runtime files and requires the dependencies declared in package.json; it is not a standalone executable or a complete Docker build context. Use the source archive for a Docker build.

Verification scope

The merged implementation passed 265 tests across 17 files, local HTTP QA, independent review, and GitHub CI on Node 20, 22, and 24. Release validation checks the versioned build and npm package separately. Windows and live upstream inference are not covered by those local checks.

CommandCode Bridge 1.53.0.b

Choose a tag to compare

@yelixir-dev yelixir-dev released this 15 Sep 14:39

Bridge-only bugfix release against an unchanged CommandCode CLI 1.53.0. No catalog, model, or configuration default changed other than the bridge version string.

Fixed

Dashboard restart under Docker (#4) — two cascading bugs made saved model changes impossible to apply in a container.

  • The restart request lost its Authorization header after a save and returned 401. auth() skipped fullBridgeKey() whenever a pending client key was set, while the server reported the configured key as [REDACTED] and localStorage was written only after a successful restart. The pending key now participates in authentication directly.
  • POST /admin/restart answered {"ok":true} while doing nothing on an unsupervised process. It now returns restart_requested: false with a restart_mode and a reason, keeps the configuration marked dirty, and the dashboard tells the operator to restart the service instead of polling for a restart that cannot happen.

Upstream request shape — top_p and stop are no longer forwarded to CommandCode. The CLI wire body carries only model, messages, tools, system, max_tokens, stream, and optional temperature and reasoning_effort, so forwarding those two fields made bridge traffic distinguishable from CLI traffic. Clients may still send them; they are dropped before the upstream request.

Action required for Docker users

The dashboard restart button needs a supervised process. systemd is detected automatically; every other supervisor, including Docker with a restart policy, requires COMMANDCODE_BRIDGE_RESTART_MODE=exit.

Both shipped Compose files now set it, so pull the updated docker-compose.yml (or release/docker-compose.yml) and recreate the container:

git pull
docker compose up -d --build

Running the new code with an old Compose file leaves the restart button reporting that the deployment cannot restart itself. That message is accurate; restart the container by hand, or adopt the updated Compose file.

Verification

npm run verify passes end to end: typecheck, eslint, Prettier, 233 tests in 15 files, and build.