Provider Hub v0.6.8
Security and correctness fixes
- Search evidence now has explicit channels: real search citation text and successfully fetched page content. URL/title/fetch-failure status alone can never validate a field.
- Official search citations remain usable when the official page returns 403, while blocked/non-public sources are discarded.
- Added end-to-end hard deadline across DNS resolution and HTTPS source retrieval.
- Client disconnect now aborts upstream generation; relay observes writable backpressure and marks cancelled requests failed.
- Provider Hub generates and stores its own request UUID; caller-controlled X-Request-ID is never persisted.
- SSE parsing joins legal multiline data events before JSON parsing.
Existing v0.6.7 capabilities
- One-click model specification completion with field-level evidence.
- Token, cache, reasoning, latency, rate-limit and cost logs.
- Provider-reported usage/cost preferred; local estimation is explicitly labeled.
Verification
- 92/92 automated tests passed.
- Includes blocked-fetch, 403 citation, private DNS, stalled DNS, malformed search, caller-ID redaction, multiline SSE, downstream cancellation, Token/fee and one-click completion tests.
- Package dry-run, syntax, diff and secret scans passed.
SHA-256: F795049940681C21DD737AD3A0AA2A11A198CA56DE8EC865345059735EC23B26