Reproduce the MiMo Desktop login surface server-side so headless/Docker deployments can link a Xiaomi account without the Desktop client. The account session (passToken) is captured during the proxied login and stored per connection. - Five account clusters (cn/sgp/ams/ru/in): per-region mimo-server host and SSO sid, unknown region falls back to sgp - mimo-v2.6-pro/flash/pro-ultraspeed dual-route models: account-service route when desktop credentials exist, cloud API (sk- key) otherwise; drops obsolete mimo-x-*-preview ids - Desktop ServiceTokenManager 2-phase handshake (single serviceLogin with target sid, raw 64-bit nonce preserved), per-region session cache - reasoning_effort bridged to output_config.effort; i18n runtime now observes characterData mutations so React text rewrites get translated - Security hardening on the login proxy: session travels only in the httpOnly cookie (never in the URL), proxy branch requires dashboard auth, authorization/proxy-authorization never forwarded upstream, and upstream Set-Cookie is not replayed onto the app origin
95 lines
3.5 KiB
JavaScript
95 lines
3.5 KiB
JavaScript
import { CLAUDE_API_HEADERS } from "../shared.js";
|
|
|
|
// Dual auth (same pattern as kimi):
|
|
// - API key (sk-...) → cloud API on api.xiaomimimo.com
|
|
// - Desktop account/OAuth → same cloud host, plus the dual-route v2.6 models
|
|
// served by the account-service route (mimo-server-<cluster>.xiaomimimo.com),
|
|
// authorized by a Xiaomi account session cookie, not the key.
|
|
// Endpoint is picked per model in the executor, same as opencode-go's /responses split.
|
|
export default {
|
|
id: "xiaomi-mimo",
|
|
priority: 290,
|
|
alias: "xiaomi-mimo",
|
|
aliases: [
|
|
"mimo",
|
|
"mimo-desktop",
|
|
"xmd",
|
|
],
|
|
uiAlias: "mimo",
|
|
display: {
|
|
name: "Xiaomi MiMo",
|
|
icon: "smart_toy",
|
|
color: "#FF6900",
|
|
textIcon: "XM",
|
|
website: "https://xiaomimimo.com",
|
|
notice: {
|
|
apiKeyUrl: "https://platform.xiaomimimo.com/console/api-keys",
|
|
signupUrl: "https://mimo.xiaomimimo.com/desktop/invite/",
|
|
},
|
|
},
|
|
category: "oauth",
|
|
authModes: ["oauth", "apikey"],
|
|
hasOAuth: true,
|
|
// Keys are cluster-specific. MiMo Desktop declares five regions
|
|
// (CN/SGP/AMS/RU/IN) — host + sid follow mimo-server-<code> / mimo<code>.
|
|
regions: [
|
|
{ id: "cn", label: "China (中国大陆)" },
|
|
{ id: "sgp", label: "Singapore (新加坡)" },
|
|
{ id: "ams", label: "Europe · Amsterdam (欧洲)" },
|
|
{ id: "ru", label: "Russia (俄罗斯)" },
|
|
{ id: "in", label: "India (印度)" },
|
|
],
|
|
defaultRegion: "sgp",
|
|
serviceKinds: ["llm", "tts"],
|
|
transport: {
|
|
baseUrl: "https://api.xiaomimimo.com/v1/chat/completions",
|
|
validateUrl: "https://api.xiaomimimo.com/v1/models",
|
|
},
|
|
// Multi-endpoint: pick the transport matching client sourceFormat to skip translation.
|
|
transports: [
|
|
{
|
|
format: "openai",
|
|
baseUrl: "https://api.xiaomimimo.com/v1/chat/completions",
|
|
auth: { combined: true, header: "Authorization", scheme: "bearer" },
|
|
},
|
|
{
|
|
format: "claude",
|
|
baseUrl: "https://api.xiaomimimo.com/anthropic/v1/messages",
|
|
headers: { ...CLAUDE_API_HEADERS },
|
|
auth: { combined: true, header: "x-api-key", scheme: "raw" },
|
|
},
|
|
],
|
|
models: [
|
|
// Cloud API & Desktop dual-route models (prefers the desktop account quota when available)
|
|
{ id: "mimo-v2.6-pro", name: "MiMo V2.6 Pro", upstreamModelId: "xiaomi/mimo-v2.6-pro", supportedFormats: ["openai"] },
|
|
{ id: "mimo-v2.6-flash", name: "MiMo V2.6 Flash", upstreamModelId: "xiaomi/mimo-v2.6-flash", supportedFormats: ["openai"] },
|
|
{ id: "mimo-v2.6-pro-ultraspeed", name: "MiMo V2.6 Pro UltraSpeed", upstreamModelId: "xiaomi/mimo-v2.6-pro-ultraspeed", supportedFormats: ["openai"] },
|
|
// Cloud API models (api.xiaomimimo.com/v1)
|
|
{ id: "mimo-v2.5-pro", name: "MiMo V2.5 Pro" },
|
|
{ id: "mimo-v2.5", name: "MiMo V2.5" },
|
|
{ id: "mimo-v2-omni", name: "MiMo V2 Omni" },
|
|
{ id: "mimo-v2-flash", name: "MiMo V2 Flash" },
|
|
{ id: "mimo-v2.5-tts", name: "MiMo V2.5 TTS", kind: "tts" },
|
|
],
|
|
ttsConfig: {
|
|
baseUrl: "https://api.xiaomimimo.com/v1/chat/completions",
|
|
authType: "apikey",
|
|
authHeader: "bearer",
|
|
format: "xiaomi-mimo-tts",
|
|
},
|
|
features: {
|
|
usage: true,
|
|
usageApikey: true,
|
|
},
|
|
// Custom OAuth — non-standard ECDH encrypted-callback flow.
|
|
// Handled by the Xiaomi MiMo OAuth service, not the generic PKCE pipeline.
|
|
oauth: {
|
|
custom: true,
|
|
authorizeUrl: "https://platform.xiaomimimo.com/authorize",
|
|
// The callback carries ?u=<ECDH-encrypted payload> instead of ?code=.
|
|
// Decryption yields { uid, sk, url }.
|
|
callbackParam: "u",
|
|
kn: "mimocode",
|
|
},
|
|
};
|