Highlights
- Xiaomi MiMo Desktop: handshake region + cookie threading — three defects fixed that made every
mimo-x-*-previewcall fail. Reason-blind error:getServiceCookiealready distinguished "no-pass-token" from "sso-failed" but the executor collapsed both into a misleading "sign in to MiMo Desktop" message — newgetMimoAccountSession()returns{cookie, reason}with reason-specific guidance. Region mismatch: the SSO handshake could succeed on the CN cluster while the chat request still went to the SGP host, so a valid CN-minted cookie got a 401 — the handshake now returns the winning region andbuildUrlusescredentials.__mimoAccountRegion. Wrong cookie names: Xiaomi issues SID-scoped identity cookies (mimopc_ph/mimopc_slh), not the region-derived names the old needed-list expected — emission now usesserviceToken+userId+cUserId+ anymimo*cookie.userId/cUserIdfrom Desktop auto-detect now reach the saved connection, and[MimoSSO]per-step diagnostics were added. The handshake now completes and Xiaomi authenticates the session; a remaining 403membership_requiredis an account-entitlement issue, not a code defect. - Antigravity: projectId provisioning + diagnosable gateway 403s — every stored antigravity connection shipped
projectId=""(DB-verified), so the executor sent a locally fabricated id as the request project field. Two provisioning holes:projectId.jsskippedonboardUserfor any endpoint containingdaily-(the canary host antigravity actually uses), and the dashboard OAuth connect path only firedonboardUserwhen a projectId was already present — never rescuing an empty one — and never persisted the issued id. Now: the sameloadCodeAssist→onboardUserfallback as gemini-cli, the connect path tries both production and canary hosts,onboardUseris always attempted (bounded, awaited) even whenloadCodeAssistreturns no project, and any issued id is adopted and persisted. The executor's newparseErrorturns an empty-body 403 into a diagnosable message (host + project sent + gateway headers) and warns whenever a fabricated projectId is used. Note: bare 403s also occur on healthy connections, so the missing id is a real defect but not a proven deterministic cause of every failure — intermittent body-less 403s remain consistent with Google-side gateway rejection on the canary host.
Install / upgrade: npm install -g @rsalmn/extremerouter · Docker: rsalmn/extremerouter:0.9.1 · Single executables attached below (Windows / Linux / macOS).