The LINE adapter passed text through as a single Plain component,
ignoring the mention payload (mentions[].index/length/isSelf) that the
Line Messaging API includes in the webhook. As a result:
- At(target=bot_account_id) never appeared in the message chain, so the
'at-bot' group respond rule silently dropped every @bot mention.
- The bot only replied when the message happened to match the prefix
rule (e.g. starting with 'ai').
Now LINEMessageConverter reads message.message.mention and builds the
chain per mention position:
- Bot mention (isSelf) -> At(target=bot_account_id) so AtBotRule matches
the same way as other adapters (dingtalk/lark etc.).
- Other mentions -> At(target=<line user id>, display=<mention text>).
At.__str__ already prepends '@', so the display text carries no
double '@' and the rendered text (prefix/regexp rules, quotes,
session context) is byte-identical to before.
- Missing/out-of-bounds mentions are skipped defensively.
target2yiri becomes an instance method (like wechatpad/aiocqhttp) so
the converters can hold bot_account_id; LINEAdapter passes it in from
its own config.
LINEEventConverter.target2yiri() built Friend.id/Group.id from
event.message.id, which is unique per message. Every incoming message
therefore mapped to a new session key, so LINE users and groups lost
conversation context on every turn.
Use event.source.user_id/group_id/room_id instead, matching the stable
identifiers other adapters (e.g. Telegram) use for session identity.
Falls back to the group/room id when user_id is absent, per LINE's
documented behavior for some group/room members.
* fix(wecombot): align media upload protocol
* fix(wecombot): deliver outbox media in reply and fix tool call recording
- Integrate _send_media into reply_message and reply_message_chunk so
sandbox outbox images/voices/files are uploaded and sent instead of
being silently dropped.
- Add missing import base64 that caused _send_media to fail with a
NameError swallowed by its except clause.
- Change yiri2target to return component dicts (text/image/voice/file)
so callers can distinguish text from media.
- Fix _get_message_for_tool_context using result.first()/row[0] which
returned a raw string instead of the ORM object, causing
"'str' object has no attribute 'pipeline_id'" in tool call recording.
Use result.scalars().first() per SQLAlchemy 2.0 convention.
* fix(pipeline): collect outbox attachments on final chunk with empty content
When the last streaming chunk has is_final=True but empty content
(e.g. the LLM sends all text in earlier chunks), the 'if result.content'
branch is skipped entirely, so _append_outbound_attachments never runs
and sandbox outbox images are silently dropped.
Add an elif branch for _is_final_assistant_message that creates an
empty MessageChain and still collects outbox attachments, so images
are delivered even when the final chunk carries no text.
* fix(box): bypass stdout truncation when reading outbox via exec
_read_outbox_via_exec used execute_tool which returns _serialize_result
where stdout is truncated to output_limit_chars (4000). A 7KB JPEG
encodes to ~9400 base64 chars, so the JSON payload was truncated and
json.loads failed silently, returning an empty list.
Call client.execute directly to get the raw BoxExecutionResult with
untruncated stdout, so base64 file data is preserved.
* fix(tests): adapt box and wrapper tests for client.execute and strict is_final check
- wrapper.py: restrict outbox collection on empty-content chunks to
actual MessageChunk instances with is_final=True, not generic Mock
objects that happen to have role='assistant'
- test_box_service.py: update _read_outbox_via_exec tests to mock
client.execute (returning BoxExecutionResult) instead of
execute_tool, matching the implementation change
* chore(wecombot): remove temporary upload log
* test(box): preserve direct outbox read and cleanup coverage
---------
Co-authored-by: fdc310 <2213070223@qq.com>
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com>
Telegram file.file_path is a full URL of the form
https://api.telegram.org/file/bot<TOKEN>/<path> that embeds the bot
token. Since #2362 this URL was copied into Image.url, so the token was
serialized into the message chain and thereby persisted to the
monitoring database, shown in the dashboard, and forwarded to every
installed plugin via event dispatch. Anyone with dashboard or plugin
access could recover the token and take full control of the bot.
Unlike the public CDN URLs used by the other adapters changed in #2362,
Telegram file URLs are only usable with the embedded token, so there is
no safe URL to expose. Store base64 only (as before #2362); the vision
path already relies solely on base64, so nothing downstream changes.
Add a regression test asserting the token never appears in the
converted Image or the serialized message chain.
Co-authored-by: Constantine1916 <Constantine1916@users.noreply.github.com>
Move the Lark SDK synchronous connection URL lookup off the main asyncio loop, serialize reconnects, and cover the incident with a non-blocking regression test.