Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
Instruction file imported from mrcjshy/big-boss-oma-drip-check (.cursor/rules/php-security.mdc). Copyright stays with the author.
PHP Security
This file extends the common security rule with PHP specific content.
Database Safety
Use prepared statements (PDO, Doctrine, Eloquent query builder) for all dynamic queries.
Scope ORM mass-assignment carefully and whitelist writable fields.
Secrets and Dependencies
Load secrets from environment variables or a secret manager, never from committed config files.
Run composer audit in CI and review package trust before adding dependencies.
Auth and Session Safety
Use password_hash() / password_verify() for password storage.
Regenerate session identifiers after authentication and privilege changes.
Enforce CSRF protection on state-changing web requests.
Use it
Copy one of these into your project. Installing also returns the manifest and these snippets.
# after Install: the listing is in your workspace's routing pool - a plan picks it for its slot
curl -s -X POST https://api.opensmartroute.ai/api/v1/route -H 'Authorization: Bearer $OSR_API_KEY' -H 'Content-Type: application/json' -d '{"text": "...", "plan": true}'
Manifest
An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.