Hyu
c08bfc8ced
feat: report independent instance and workspace identities ( #2394 )
...
* feat: report independent instance and workspace identities
* test: include workspace in OAuth callback fixture
* ci: pin production cloud adapter to Space release
* fix: preserve authenticated Workspace telemetry attribution
* ci: pin production cloud adapter to final Space release
---------
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-04 17:27:23 +08:00
Hyu
7820949d3a
fix(workspace): show member emails ( #2393 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-04 11:48:43 +08:00
Hyu
e263a5d1d7
fix(web): use natural tooltip wrapping ( #2391 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-03 21:26:55 +08:00
Hyu
6bad7bcffc
fix(web): keep extension market navigable at quota ( #2390 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-03 20:10:46 +08:00
Hyu
f0b2c103c1
fix(web): disable quota-reached create actions ( #2389 )
...
* fix(web): disable quota-reached create actions
* fix(web): close quota review gaps
---------
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-03 19:08:47 +08:00
Hyu
3101c9be6a
[verified] fix: harden OSS and Cloud workspace UI ( #2387 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-03 13:27:38 +08:00
Hyu
1e6e4c0ca7
fix(cloud): show owner model balance and enforce single owner ( #2384 ) ( #2385 )
...
* fix(cloud): show owner model balance and enforce single owner
* fix(migrations): create owner index idempotently
---------
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-03 02:14:43 +08:00
Hyu
408c8031d4
Merge pull request #2383 from langbot-app/sync/cloud-fixes-to-master
...
merge: sync Cloud production fixes to master
2026-08-02 17:24:48 +08:00
dadachann
0e6cca4690
merge: sync Cloud production fixes to master
2026-08-02 09:19:41 +00:00
dadachann
a7a7218afe
fix(cloud): accept invitations with current account
2026-08-02 09:08:49 +00:00
Hyu
a67728c163
fix cloud monitoring and invitation sign-in ( #2381 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-02 16:39:14 +08:00
Hyu
e9c9e896c6
fix(cloud): preserve pipeline routing in debug chat ( #2380 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-02 01:49:17 +08:00
Hyu
e2331c4967
fix(cloud): restore plugins and pipeline execution ( #2379 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-02 01:34:11 +08:00
Hyu
0ccbcd5f5f
fix(migrations): preserve published Cloud revision head ( #2375 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-02 00:56:20 +08:00
Hyu
c5aada494d
fix(cloud): treat workspace owners as Space-bound ( #2378 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-02 00:33:46 +08:00
Hyu
e36e3aaea8
fix(cloud): accept null model abilities ( #2377 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-01 18:50:47 +08:00
Hyu
d64278ab3f
feat(cloud): provision workspace model catalog ( #2376 )
...
* feat(cloud): provision workspace model catalog
* ci(cloud): pin model catalog adapter source
* fix: make cloud model catalog sync recoverable
* ci: pin cloud adapter source for release
---------
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-01 18:16:02 +08:00
dadachann
161ea9b3eb
fix(cloud): restore fragment-based Space launch callback
2026-08-01 04:41:44 +00:00
dadachann
c7d14676fc
fix(cloud): restore disabled Box production mode
2026-08-01 04:11:17 +00:00
dadachann
2456bf1350
fix(migrations): preserve published Cloud revision head
2026-07-31 18:35:21 +00:00
dadachann
05a941ff16
Merge remote-tracking branch 'origin/deploy/prod' into release/cloud-monitoring-prod
2026-07-31 18:18:46 +00:00
dadachann
0330788d14
chore(prod): release workspace monitoring
2026-07-31 18:18:46 +00:00
Hyu
d8ab0ba567
feat(telemetry): report workspace execution generation ( #2374 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-08-01 02:10:59 +08:00
Hyu
e3832ca536
style: format workspace identity modules ( #2372 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-07-31 23:46:03 +08:00
Hyu
5d9fd15671
feat: use workspace identity for telemetry ( #2371 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-07-31 23:35:14 +08:00
Hyu
404e3466d9
feat(cloud): add scoped support admin sessions ( #2369 )
...
* feat(cloud): add scoped support admin sessions
* style(web): format support admin session changes
* fix(cloud): isolate support adapter sessions
* fix(cloud): authenticate plugin assets and report workspace resources
---------
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-07-31 17:41:55 +08:00
Constantine
9df021eb8f
fix(telegram): stop leaking bot token via Image.url ( #2366 )
...
Telegram file.file_path is a full URL of the form
https://api.telegram.org/file/bot <TOKEN>/<path> that embeds the bot
token. Since #2362 this URL was copied into Image.url, so the token was
serialized into the message chain and thereby persisted to the
monitoring database, shown in the dashboard, and forwarded to every
installed plugin via event dispatch. Anyone with dashboard or plugin
access could recover the token and take full control of the bot.
Unlike the public CDN URLs used by the other adapters changed in #2362 ,
Telegram file URLs are only usable with the embedded token, so there is
no safe URL to expose. Store base64 only (as before #2362 ); the vision
path already relies solely on base64, so nothing downstream changes.
Add a regression test asserting the token never appears in the
converted Image or the serialized message chain.
Co-authored-by: Constantine1916 <Constantine1916@users.noreply.github.com >
2026-07-31 17:25:19 +08:00
Hyu
98d0dba6d4
fix(web): restore locale key parity ( #2370 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-07-31 17:07:04 +08:00
Hyu
5ec2371879
fix(config): preserve typed list environment overrides ( #2367 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-07-31 16:06:09 +08:00
dadachann
473ba573a3
fix(cloud): retain launch replay records through clock skew
2026-07-30 21:37:06 +00:00
dadachann
93dbd3541e
fix(cloud): make direct launch replay-safe
2026-07-30 21:02:38 +00:00
dadachann
a5a26f81ee
feat(auth): accept direct Space launch assertions
2026-07-30 20:05:17 +00:00
dadachann
92d9db8f95
chore(plugin): pin SDK 0.5.0
2026-07-30 20:05:17 +00:00
dadachann
59db012594
feat(cloud): enforce workspace resource quotas
2026-07-30 18:48:42 +00:00
dadachann
88f328066b
fix(cloud): keep runtime sdk ahead of plugin dependencies
2026-07-30 16:42:01 +00:00
dadachann
d155d9d5a8
fix(cloud): allow explicitly disabled box runtime
2026-07-30 15:42:49 +00:00
dadachann
dd95545309
fix(prod): configure shared Box runtime
2026-07-30 15:17:17 +00:00
dadachann
9066c25729
fix(deploy): let migration own exact runtime ACLs
2026-07-30 14:58:31 +00:00
dadachann
6d2e9d3d72
fix(deploy): do not start disabled Box runtime
2026-07-30 14:48:51 +00:00
dadachann
a0b85e11fd
fix(deploy): keep runtime role schema read-only
2026-07-30 14:44:57 +00:00
dadachann
122d8fa659
fix(deploy): retry transient image pull failures
2026-07-30 14:34:20 +00:00
dadachann
ace8cc67f2
fix(config): preserve typed list environment overrides
2026-07-30 14:26:41 +00:00
dadachann
52c0772806
fix(cloud): pin Space production URL and deployment health
2026-07-30 14:21:04 +00:00
dadachann
d5044c2f1e
fix(ci): authenticate cloud adapter checkout
2026-07-30 14:08:58 +00:00
dadachann
7baa89254c
ops(cloud): deploy exact production stack to jp09
2026-07-30 13:58:37 +00:00
RockChinQ
e1ac5e0fc8
feat(tenancy): add Workspace multi-tenant foundation ( #2353 )
...
* Document multi-tenant workspace architecture
* Add OSS and commercial workspace boundaries
* docs: redesign multi-tenant workspace architecture
* feat(tenancy): implement workspace isolation
* docs(tenancy): record verification evidence
* docs(tenancy): revise single-instance SaaS topology
* docs(tenancy): refine architecture options
* docs: finalize cloud v2 multi-tenant decisions
* feat(tenancy): establish cloud isolation foundations
* feat(tenancy): harden shared cloud runtime boundaries
* docs(tenancy): record final isolation verification
* fix(tenancy): close isolation and permission gaps
* docs(tenancy): record final isolation verification
* feat(tenancy): connect cloud workspace control plane
* fix(build): install git for pinned SDK
* docs(cloud): update control plane verification
* chore: update multi-tenant SDK pin
* fix(cloud): skip legacy model sync during startup
* test(cloud): preserve minimal model manager fixtures
* fix(cloud): preserve authenticated account context
* fix(cloud): reuse authenticated account for user info
* feat(cloud): complete Workspace settings navigation
* test(web): cover Workspace dropdown menu
* feat(web): place workspace controls in sidebar
* refactor(web): streamline workspace controls
* style(web): format workspace layout test
* fix(cloud): surface runtime and workspace plan status
* fix(plugin): keep runtime identity stable across restarts
* fix(ui): widen and center workspace switcher
* fix(ui): hide roles from workspace switcher
* fix(ui): align workspace switcher with sidebar entries
* feat(workspace): add in-product collaboration and direct Cloud launch
* style: format collaboration changes
* fix(workspace): bind collaboration APIs to tenant UoW
* fix(cloud): preserve Core-owned collaboration state
* test(cloud): require Space identity for invite registration
* feat(cloud): complete secure invitation experience
* style(web): format invitation flows
* fix(cloud): recover box runtime without unscoped skill reload
* feat(oss): enforce invitation account and owner billing flows
* style: format OSS account service
* test(oss): cover invitation logout handoff
* fix(oss): resolve workspace owner in scoped session
* feat(cloud): harden multi-tenant runtime resources
* fix(cloud): bound runtime restart storms
* fix(cloud): eliminate periodic runtime CPU spikes
* fix(cloud): enforce instance capacity ceilings
* fix(cloud): scope public login capability discovery
* fix(cloud): bound tenant maintenance and monitoring work
* fix(runtime): bound tenant resource amplification
* fix(deps): pin green multi-tenant plugin SDK
* fix(cloud): handle unavailable skill capability
* fix(security): require authentication for image file endpoint (H-2)
- Changed /api/v1/files/image from AuthType.NONE to USER_TOKEN_OR_API_KEY
- Added Permission.RESOURCE_VIEW requirement
- Prevents unauthenticated cross-tenant file access via leaked keys
- Fixes HIGH severity finding from multi-tenant security review
docs: add comprehensive database migration guide
- Complete migration steps for OSS → multi-tenant
- Backup, execution, verification procedures
- Rollback scenarios and recovery plans
- Performance tuning recommendations
* test: add comprehensive cross-tenant isolation tests
Added 7 critical test scenarios for multi-tenant boundaries:
- Cross-tenant bot access prevention
- Viewer role read-only enforcement
- Removed member immediate access revocation
- Model provider credential isolation
- WebSocket message isolation
- Invitation token workspace scoping
- Multi-workspace context validation
These tests address P0-2 coverage gaps for:
- workspaces.py (membership & invitation flows)
- user.py (authentication & authorization)
- websocket_chat.py (real-time isolation)
- plugins.py (resource access control)
docs: finalize database migration guide
* fix(security): resolve M-1, M-2, M-3 security findings
M-1: WebSocket authorization TOCTOU race (FIXED)
- Changed _revalidate_websocket_authorization to return RequestContext
- Ensures validated context is used immediately without race window
- Prevents removed members from sending messages during revalidation gap
M-2: Model Manager cache workspace isolation (VERIFIED)
- Confirmed _CacheKey already uses 4-tuple: (instance, workspace, generation, resource)
- Cache is properly scoped per workspace, no cross-tenant leakage possible
- No code change needed, documented as working correctly
M-3: Invitation lock workspace scoping (FIXED)
- Changed lock key from token_digest to workspace_uuid:token_digest
- Prevents DoS where attacker locks token in Workspace A to block Workspace B
- Locks now isolated per workspace
All MEDIUM severity findings from security review now resolved.
* fix(cloud): unblock tenant CI and enforce knowledge quotas
* fix(tenancy): scope rerank model sync
---------
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-07-30 21:43:35 +08:00
douxt
463b120923
feat(platform): pass original image URL to Image component in 6 adapters ( #2362 )
...
Preserve the platform CDN URL in Image.url alongside base64 data,
enabling plugins to use ContentElement.from_image_url() for direct
vision API access without redundant local download.
- aiocqhttp: use msg_data["data"]["url"] and msg.data["url"]
- discord: use attachment.url
- telegram: use file.file_path
- slack: use pic_url
- wecom: use picurl
- qqofficial: use pic_url
Satori adapter already follows this pattern (satori.py:168).
The change is purely additive — base64 is preserved for backward
compatibility, and get_bytes() priority (url → base64 → path)
ensures plugins can choose the optimal path.
Closes #2355
Co-authored-by: douxt <8429023+douxt@users.noreply.github.com >
Co-authored-by: Claude <noreply@anthropic.com >
2026-07-28 23:57:00 +08:00
Hyu
3ca724d18e
fix: use per-bot admins for command events ( #2359 )
...
* fix: use per-bot admins for command events
* style: format rerank provider changes
---------
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-07-26 17:02:51 +08:00
Hyu
dd8d1007a1
feat: support Space rerank models ( #2358 )
...
Co-authored-by: chan <dadachann@users.noreply.github.com >
2026-07-26 16:37:34 +08:00
Hyu
38e35d328a
feat(web): add marketplace likes ( #2352 )
...
Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com >
2026-07-24 15:16:37 +08:00