The pcap route awaited homer with no timeout and no tie to the client
connection, then used stream.pipe(res). If the client gave up (nginx 499)
before homer answered, the homer response body was piped into a closed
response, pipe() detached without destroying it, and the unread body kept
its socket and buffers referenced by the global undici pool forever.
With homer slow, this leaked roughly one socket per abandoned request:
~1,300 open fds and +200 MB RSS per api-server worker within four hours.
- abort the homer auth and pcap fetches when the response closes or after 30s
- use stream.pipeline() so the homer stream is destroyed if the client leaves
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
- add inworld-tts-2 and inworld-tts-2-flash to the Inworld model list
- both return word timestamps; flash is the low-latency/low-cost variant
- model_id is passed through unchanged, so no other wiring is needed
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
The speechmatics branch of the /test route destructured only api_key out of the
decrypted credential, so testSpeechmaticsStt() passed realtimeUrl: undefined to
the sdk. ConnectionConfigFull only applies an override when the value is truthy,
so every credential was silently tested against wss://eu2.rt.speechmatics.com/v2
no matter which region was stored - a neu or wus key was judged by whatever eu2
happened to answer.
- pass speechmatics_stt_uri through from the route
- normalize it before handing it to the sdk. The field holds a bare hostname,
which the sdk cannot use as-is: it appends the language, yielding
"eu2.rt.speechmatics.com/en" and ERR_INVALID_URL. At call time the same value
goes to mod_speechmatics_transcribe as SPEECHMATICS_HOST, which always
connects over wss on port 443 with a path of /v2, so build exactly that url.
Anything else - a full ws url, a port - now fails the test with an actionable
message rather than passing against an endpoint only the test can reach, and a
credential that has lost the field fails too: the feature server omits
SPEECHMATICS_HOST when it is unset and the module refuses the session, so
defaulting to a hosted region here would show a green check on a dead
credential.
- record the speechmatics STT result with sttTestResult(), not ttsTestResult(),
which is what every other STT vendor in this file does; the tts column was
being stamped for an STT-only vendor
Adds coverage for the url building to the main test suite - it is the part of
this that can be exercised without an api key.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* initial changes for env var support
* WIP
* Update applications.js
* JSON stringify before encrypting
* use call_hook.url
* env vars working
GET /v1/AppEnv?url=[URL] to trigger options request to URL and return app-schema
POST /v1/Applications with {env_vars: [OBJECT} to create app with env vars
PUT /v1/Applications/[SID] with {env_vars: [OBJECT} to change env vars
GET returns env vars
POST and PUT will also trigger an OPTIONS request to the call_hook url to get schema and then validate the env_vars against it
* update appenv cannot finish request.
* wip
* wip
* wip
* wip
---------
Co-authored-by: Dave Horton <daveh@beachdognet.com>
Co-authored-by: Quan HL <quan.luuhoang8@gmail.com>
Co-authored-by: Hoan Luu Huu <110280845+xquanluu@users.noreply.github.com>
* https://github.com/jambonz/jambonz-api-server/issues/371
Implemented view_only permission feature
* calling prepare-permissions in create-test-db.js
* check if there is only 1 permission and if it is VIEW_ONLY then consider user as read-only user
* setting is_view_only flag for view user by userid