Commit Graph

842 Commits

Author SHA1 Message Date
TyperBody 262980d612 fix(web): add missing common.next/previous pagination keys
The bot session monitor paging controls use `common.next` and
`common.previous`, but those keys never existed in any locale. They were
only rendered because of the hardcoded `defaultValue: 'Next'`/`'Previous'`.
Removing those fallbacks (previous commit) made i18next render the raw key
name, so the Playwright smoke tests could no longer find the "Next" button.

Add `common.previous` and `common.next` to all 8 locales (reusing each
language's existing `guidedTour.previous`/`next` wording) and re-align the
locale key order with the `en-US` reference.

Verified locally:
- scripts/check-i18n.mjs passes for all locales
- every t('...') key referenced by BotSessionMonitor.tsx now exists in en-US
- tests/e2e/bot-session-tool-timeline.spec.ts: 13/13 passed (including the
  two request-recovery cases that failed in CI)
- prettier / tsc / eslint clean
2026-09-25 18:07:11 +08:00
TyperBody f17b148b1a fix(web): align i18n locale keys and ordering with en-US
The bot session monitor referenced several translation keys that did not
exist in any locale file. Because i18next `fallbackLng` is `zh-Hans`, the
missing keys fell back to the hardcoded English `defaultValue`, leaking
untranslated strings (e.g. "0 sessions", "User ID or name", "Search") into
every non-English UI.

- Add the missing keys to all 8 locales with proper translations:
  `common.search`, `bots.sessionMonitor.{totalSessions,userSearch,startDate,endDate}`
  and `monitoring.toolCalls.{showDetails,hideDetails}`.
- Remove the hardcoded `defaultValue` fallbacks in `BotSessionMonitor.tsx`
  so translations are always driven by the locale files.
- Reorder nested keys in every locale file to match the `en-US.ts` reference
  order, keeping values untouched. This removes all structural drift between
  locale files (previously `guidedTour.*`, `plugins.*`, etc. were ordered
  differently).

Verified: `scripts/check-i18n.mjs` reports matching keys for all locales,
every key/value pair is preserved, Prettier passes, and `tsc --noEmit` is clean.
2026-09-25 17:05:02 +08:00
TyperBody 7543340f39 fix(web): stabilize invitation error assertions
The invitation error copy also renders as a transient sonner toast, so the
plain text locator resolved to two elements and tripped Playwright strict
mode while the toast was on screen.

Tag the inline error region with data-testid="invitation-error" and assert
against it, keeping the check deterministic under CI parallelism.
2026-09-25 15:19:34 +08:00
TyperBody 97c1addba7 Merge remote-tracking branch 'origin/master' into feat/totp-two-factor-auth
# Conflicts:
#	uv.lock
2026-09-25 14:31:03 +08:00
Type_rBody 5435b3bbfc Merge pull request #2575 from langbot-app/fix/assistant-i18n-locales
fix(web): add the assistant namespace to remaining locales
2026-09-25 14:20:03 +08:00
TyperBody 85da438d21 fix(web): add the assistant namespace to remaining locales
The workspace assistant added 39 keys under `assistant.*` to en-US,
zh-Hans and ja-JP, but es-ES, ru-RU, th-TH, vi-VN and zh-Hant were never
updated. The i18n key consistency check fails on all five, blocking the
release PR.

Add the full assistant namespace with translated copy so every locale
matches the en-US reference. No source changes; keys and placeholders
(`{{count}}`) mirror en-US exactly.
2026-09-25 14:07:50 +08:00
Type_rBody f09c8a8bed Merge pull request #2549 from langbot-app/experiment/in-process-assistant
feat(web): add an in-process workspace assistant
2026-09-25 13:56:30 +08:00
RockChinQ eb9261fae1 fix(migration): pin certified runner packages 2026-09-25 05:42:34 +00:00
TyperBody 03f50d1afc style(web): apply prettier formatting and drop an unused import
Run prettier over the assistant files and the new dock unit test so the
web lint job passes, and remove the unused ASSISTANT_BUTTON_SIZE import
flagged by code quality review.
2026-09-25 13:38:23 +08:00
TyperBody 6283d21311 fix(web): scroll assistant to newest turn and settle the rail on release
Opening the panel left the user at the oldest message because the scroll
effect did not depend on `open`. Add it and defer the scroll to the next
frame so the popover has laid out before the sentinel is measured.

A click or an aborted swipe never arms the long press, so no drop handler
ran and a hover-expanded button stayed expanded after the pointer left.
Track real pointer presence and re-sync the rail on release.
2026-09-25 13:32:29 +08:00
TyperBody e6e1958fc5 fix(web): let the docked assistant button collapse again
`shouldCollapseRail` was keyed on `!railExpanded`, mirroring the expand
helper instead of negating it. Once a hover revealed the button it could
never collapse back into the rail, so the collapse looked broken after the
first restore.

Key the predicate on `railExpanded` being true, restore the mirror
relationship with `shouldExpandRail`, and add regression coverage for the
expand -> leave -> collapse round trip. Also lengthen the rail strip.
2026-09-25 13:22:18 +08:00
TyperBody 88257fe0e2 Merge origin/master into experiment/in-process-assistant
Resolve conflicts in the workspace assistant integration:

- DynamicFormItemComponent: keep HEAD's compact model selector and
  `disabled` field support while adopting master's `sortModelsByCatalog`
  ordering and `MODEL_SELECT_TRIGGER_CLASS`.
- i18n (en-US, ja-JP, zh-Hans): keep both the `assistant` namespace from
  HEAD and master's `sidebarGuide` / `pipelineMigration` additions.

Add 0030_merge_assistant to join the assistant conversations branch with
the released chain so the migration graph converges on a single head.
Rename it from 0030_merge_assistant_conversations to stay within the 32
character revision limit enforced by test_migrations.

Also add assistant button docking (long-press drag, edge collapse to a
short blue rail, hover restore) with pure helpers in assistant-dock.ts
and unit coverage, plus auto-collapse for finished tool result cards.
2026-09-25 13:17:44 +08:00
TyperBody f316958619 Merge remote-tracking branch 'origin/master' into experiment/in-process-assistant 2026-09-25 12:46:34 +08:00
TyperBody 76398c8bc4 Merge origin/master into feat/totp-two-factor-auth
Resolve the revision-graph conflict introduced by the release line.

Conflicts
- tests/integration/persistence/test_rag_document_identity.py: master had
  independently introduced the same dynamic-head helper (`current_head`) plus
  a `DOCUMENT_IDENTITY_REVISION` constant, and it explicitly upgrades to that
  revision. Keep master's semantics (the explicit revision matters because
  upgrading to the head now also traverses the TOTP branch) while keeping the
  module-level alembic imports on this branch.

New migration
- 0030_merge_totp_into_release joins the TOTP branch's own merge revision
  (0026_merge_totp_and_rag_identity) with the release head
  (0029_merge_rag_identity). Both reached 0025_rag_document_identity without
  including each other, which left Alembic with two heads and made
  `upgrade head` fail with "Multiple head revisions are present".

Verification
- Single Alembic head confirmed (0030_merge_totp_into_release).
- tests/integration/persistence/test_rag_document_identity.py: 34 passed.
- Full fast integration suite: 356 passed, 84 skipped.
2026-09-24 02:27:37 +08:00
RockChinQ 9b589a8f08 merge: integrate 4.11 into master 2026-09-24 02:01:00 +08:00
TyperBody 0bf610037a fix(web): keep reset-password wire shape for the default method
resetPassword() unconditionally added `method` and an empty `totp_code` to
every request, which broke the Playwright smoke test that asserts the
recovery-key flow posts exactly {user, recovery_key, new_password}.

Send only the second-factor fields that apply to the selected method, so the
default recovery-key flow stays byte-compatible with existing callers while
the totp / recovery_code methods still carry their inputs.
2026-09-24 01:31:54 +08:00
TyperBody 28e8821365 fix(auth): repair TOTP CI failures
Address the migration and formatting failures reported on the TOTP branch.

Migrations
- Register totp_credentials and totp_recovery_codes in
  _ALEMBIC_TENANT_TABLES. On a legacy PostgreSQL install these two tables
  reference users.uuid, which only exists after 0009, so create_all() must
  not run ahead of Alembic the way it did for the other tenant tables.
  Without this the PostgreSQL migration test failed with
  "column uuid referenced in foreign key constraint does not exist".

Tests
- Resolve the Alembic head dynamically in the RAG document identity
  regression instead of pinning 0025_rag_document_identity. The TOTP and
  RAG branches now meet at a merge revision, so the pinned value was no
  longer the head. This matches the convention already used by
  test_migrations_postgres.

Formatting
- Apply ruff format to the new backend modules and prettier to the locale
  files and TOTP components, so the lint jobs pass.
2026-09-24 01:31:54 +08:00
TyperBody 8633567ce7 feat(auth): add TOTP two-factor authentication
Add a per-Account time-based one-time password (TOTP) second sign-in
factor, plus the owner/admin tooling needed to operate it.

Backend
- TotpService: enrolment, constant-time verification with a +/- one step
  drift window, single-use recovery codes and disablement.
  * shared secret is only ever persisted as a Fernet token whose key is
    derived (HKDF-SHA256) from the instance JWT secret and gated by a
    key_version epoch;
  * recovery codes are only ever persisted as salted
    PBKDF2-HMAC-SHA256 digests (600k iterations) and are single-use;
  * the consumed counter advances monotonically so a captured code cannot
    be replayed inside the same time window.
- New persistence entities and alembic migrations for credentials and
  recovery codes.
- Login second-factor challenge, bound to the Account that passed the
  password step.
- Owner/admin oversight endpoints to inspect and re-bind the second
  factor of any Account.

Frontend
- Account settings panel for enrolling, managing, re-binding and
  disabling the second factor.
- Login second-factor step and the matching client methods.
- Strings for all eight locales.

The shared secret never crosses the API boundary: enrolment returns a
server-rendered QR code (as a data: URL) and the plaintext secret is
discarded as soon as the image is produced.
2026-09-24 01:31:54 +08:00
RockChinQ fd940a3a06 Merge pull request #2559 from Rapeter/codex/fix-storage-analysis-menu-icon
fix(web): add storage analysis menu icon
2026-09-23 18:17:21 +08:00
RockChinQ a8d291e581 fix(plugins): retain Host progress fallback after master merge 2026-09-21 17:04:57 +00:00
RockChinQ 5d9684731e merge(4.11): integrate master marketplace updates preserving Runner lifecycle 2026-09-21 16:58:35 +00:00
Zhong 74a0aa3563 fix(web): add storage analysis menu icon 2026-09-21 21:00:55 +08:00
RockChinQ 44ee0e8d71 test(web): align bot form assertion with responsive grid layout 2026-09-21 11:35:19 +00:00
TyperBody 163dac48b0 fix(plugins): correct install progress bounds, skill identity, and stage accuracy
Addresses review feedback on the marketplace installed-state change.

- Progress: byte-derived progress no longer has time-based drift layered on
  top, and fallback drift is clamped to the current stage range, so the bar
  cannot exceed the download band. 90/100 bytes at 40s elapsed used to report
  61% against a declared 5-45% band; it now reports 41%. Drift is measured
  from when the stage was entered rather than from task start.
- Skills: a marketplace skill is no longer reported installed from a bare
  skill name. The backend names skills from their own SKILL.md and records no
  publisher, so alice/review and bob/review install identically; matching the
  bare name marked every publisher's skill as installed. Skill cards now
  resolve to not-installed until the installed skill carries a publisher.
- Stages: "installing plugin dependencies" and "launching plugin" described
  work this task context cannot observe (installation persistence ran under
  the former; the runtime installs dependencies and starts the plugin inside
  apply_plugin_installation under the latter). They become "persisting the
  installation" and "installing or starting plugin", and the frontend maps
  that combined step to the dependency stage rather than the launch stage.
- Removed the per-dependency progress fields: the backend never populated
  them, so the UI could never have displayed them.

The stage mapping and progress maths move to install-progress.ts, and the
installed-state matching to a React-free marketplace-installed.ts, so both
are covered by executable tests (+9).

Verified: ruff, tsc --noEmit, prettier --check, eslint (0 errors), 98/98 unit
tests.
2026-09-21 00:40:23 +08:00
RockChinQ 503fec4d6e feat(web): unify guided tours and complete translations 2026-09-19 22:14:29 +08:00
fdc310 e7ad051cf6 Merge remote-tracking branch 'origin/dev/4.11.x' into dev/4.11.x
# Conflicts:
#	uv.lock
#	web/src/i18n/locales/en-US.ts
#	web/src/i18n/locales/ja-JP.ts
#	web/src/i18n/locales/zh-Hans.ts
#	web/src/i18n/locales/zh-Hant.ts
2026-09-19 11:00:45 +08:00
fdc310 cc8a0ec847 feat: simplify resource setup and detail guides 2026-09-19 02:39:35 +08:00
RockChinQ 804c089d20 fix(wizard): show default AI preparation progress in button 2026-09-19 00:05:49 +08:00
RockChinQ 79cac0c6a3 fix(reasoning): apply explicit per-call levels without runner config caching 2026-09-19 00:05:49 +08:00
RockChinQ da4b0d6ca2 fix(wizard): prepare default Local Agent and refine Runner setup 2026-09-18 19:27:56 +08:00
fdc310 960e322c79 feat(web): add contextual setup guides 2026-09-18 19:08:30 +08:00
RockChinQ bece2aa554 fix(wizard): restore message pipeline setup and page bot preview 2026-09-18 16:01:55 +08:00
RockChinQ 60606e1997 fix(migration): improve runner migration and plugin installation feedback 2026-09-18 13:10:32 +08:00
RockChinQ a6ac25cf84 feat(agent): add task-oriented run logs and execution details 2026-09-18 00:59:17 +08:00
RockChinQ b264d46d77 feat: delegate sandbox policy to runners and simplify pipeline migration 2026-09-17 23:05:27 +08:00
fdc310 c4e14516ed feat(web): add sidebar onboarding guide 2026-09-17 05:05:01 +08:00
RockChinQ 8c119bc4b6 feat: add verified manual pipeline migration for plugin runners 2026-09-16 18:13:11 +00:00
TyperBody f998e475e3 fix 2026-09-16 22:58:10 +08:00
huanghuoguoguo 38471d5df1 style(assistant): compact model picker in header 2026-09-16 22:37:02 +08:00
huanghuoguoguo 0be53c6ef4 feat(assistant): improve chat feedback and model selection 2026-09-16 22:37:02 +08:00
huanghuoguoguo 48140fbfd4 fix(assistant): align resource tools with application services 2026-09-16 22:37:02 +08:00
huanghuoguoguo e82d71029e feat(assistant): prototype in-process workspace assistant 2026-09-16 22:37:02 +08:00
RockChinQ 273b1ea3cf Merge master into dev/4.11.x and preserve plugin runner architecture
Reconcile migration branches without rewriting published revisions; retain additive Codex, monitoring, provider and platform fixes. Keep dynamic runner schemas and Host ownership, restore compatibility regressions, and preserve safe model-test error handling.
2026-09-16 08:13:07 +00:00
TyperBody 4535a21cb5 feat(plugins): show installed state in marketplace and search installed extensions
Marketplace cards now reflect whether an extension is already installed in
the current workspace, and the installed-extension list gains a search box.

Backend (stream install progress):
- _read_httpx_response_limited gains an optional task_context: it publishes
  download_total from Content-Length before the first chunk and updates
  download_current / download_speed per chunk. The marketplace download path
  previously had no progress reporting; it now matches the GitHub path.
- _marketplace_get forwards task_context to that helper.
- install_plugin resets the per-install counters so re-installing the same
  plugin cannot inherit stale metadata, and reports human-readable stages:
  preparing -> downloading -> inspecting -> storing -> installing
  dependencies -> launching -> waiting for plugin to become ready.

Frontend (installed state):
- New marketplace-installed helper normalises the sidebar identities
  (plugin: author/name, mcp: author__name, skill: bare name) into one
  type:author/name index and resolves a card's installed state from it.
  useMarketplaceInstalledIndex memoises on the sidebar lists, so a finished
  install (which refreshes the sidebar) re-evaluates the cards automatically.
- PluginMarketCardVO carries installed / hasUpdate. An installed extension
  turns its download affordance into a hollow green ring with a green check
  in place, instead of adding a separate badge; the count slot switches to
  the installed label. Cards with an available update use amber.
- PluginMarketComponent derives the annotated list and shares the index with
  RecommendationLists.

Frontend (install task UI):
- mapActionToStage matches the new connector stage strings. The pre-download
  stages are checked before the generic "install" match, because
  "preparing plugin install" also contains "install".
- Stage progress ranges are non-overlapping; overall progress interpolates on
  real byte counts while downloading and drifts monotonically elsewhere,
  capped at 99%.
- The progress dialog and task queue expose the launching stage.

Frontend (installed list search):
- The installed list had no search at all. A query box in the page header
  filters by label / name / author / description, case-insensitively, applied
  before grouping so grouped and flat views both honour it.
- Search misses and an empty list now show distinct empty states, with a
  clear action on a search miss.
- AsyncTask entity gains the optional created_at field.

i18n: new marketplace / install / search strings across all 8 locales.

Verified: ruff format + check, tsc --noEmit, prettier --check, eslint
(0 errors), and 89/89 frontend unit tests.
2026-09-16 02:03:57 +08:00
dadachann f8123ead0a feat(telemetry): add isolated beta quality diagnostics and release identity 2026-09-15 09:35:01 +00:00
Hyu 91d6de8858 fix(bots): add icon to processor compatibility warning 2026-09-15 15:11:30 +08:00
Hyu 11f73ddf12 fix(bots): highlight unsupported processor events and show overlap 2026-09-15 15:05:34 +08:00
Hyu 8b7621cb29 fix(i18n): refine processor compatibility warning 2026-09-15 14:58:41 +08:00
Hyu b71d18f697 test(bots): wait for save notices before reusing subscriptions 2026-09-15 14:58:08 +08:00
Hyu 1c17c4a0db fix(bots): warn about incomplete processor event support 2026-09-15 14:56:43 +08:00