Commit graph

1075 commits

Author SHA1 Message Date
dongmucat
a3336fe13b test(search): publish label sync fixture versions
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 12:13:40 +08:00
dongmucat
ba7c242d69 test(namespace): align smoke with super admin visibility
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 12:04:33 +08:00
dongmucat
7fc0e2226c fix(namespace): refresh session roles for namespace visibility
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
cf744245c6 fix(search): filter rebuilds to published versions
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
082ab489a3 fix(search): refresh index after version yank
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
e066277065 fix(search): require published portal results
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
1d216e73f0 fix(frontend): expose namespace picker value
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
9149227206 fix(frontend): preserve namespace picker selectors
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
0cbe33436d fix(namespace): type nullable search terms
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
f8df616480 fix(namespace): scope review entry queries
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
78cbe05ebe fix(namespace): preserve bounded selection semantics
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
2bd358049b fix(frontend): bound namespace selection
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
8f6941e31e feat(frontend): add paged namespace picker
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
18c9370318 fix(frontend): bound namespace page queries
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
9de8a51d89 feat(namespace): filter paged namespace reads
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
a55264b130 fix(namespace): bound filtered namespace queries
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
2fa7a53e2b fix(namespace): preserve super admin skill reads
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
daba212271 fix(namespace): preserve my namespace compatibility
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
123d0d5f53 fix(namespace): page super admin visibility
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
669d341d51 fix(namespace): preserve review menu visibility
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
35e9ca588a fix(namespace): allow super admin namespace detail reads
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
1577384ffb fix(namespace): allow super admin namespace visibility
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
XiaoSeS
bafb9fe3b9
Merge pull request #608 from iflytek/fix/cli-namespace-errors
Some checks are pending
Deploy Docs / build (push) Waiting to run
Deploy Docs / Deploy (push) Blocked by required conditions
Security / Dependency Review (push) Waiting to run
Security / CodeQL (java-kotlin) (push) Waiting to run
Security / CodeQL (javascript-typescript) (push) Waiting to run
Security / CodeQL (python) (push) Waiting to run
fix(cli): normalize namespace coordinates and errors
2026-07-29 11:08:15 +08:00
XiaoSeS
13b3f2da92 chore(cli): integrate contributor merge update (#606)
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 10:37:03 +08:00
XiaoSeS
a9007a4e8c fix(cli): preserve download error contract (#606)
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 10:31:49 +08:00
dongmucat
c1835fc9e9 merge(main): resolve CLI error mapping conflicts (#606)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 10:24:23 +08:00
XiaoSeS
ad4a2dbc2f chore(cli): merge main into PR #608
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 10:19:03 +08:00
XiaoSeS
9f602f8184
Merge pull request #480 from yaffir/main
fix(auth): hide placeholder OAuth providers
2026-07-29 09:00:19 +08:00
XiaoSeS
7872e64177
Merge pull request #609 from iflytek/fix/auth-revoked-token-validation
test(auth): cover revoked CLI token lifecycles
2026-07-29 03:37:47 +08:00
XiaoSeS
19c3070291
Merge pull request #607 from gale-popai/fix/device-auth-redis-typing
fix(auth): read device-code state via ObjectMapper conversion, not cast
2026-07-29 03:37:25 +08:00
XiaoSeS
c5a2b18fd9
Merge pull request #592 from shychee/fix/label-search-sync-async
fix(search): rebuild search index asynchronously after label change
2026-07-28 23:35:11 +08:00
XiaoSeS
cfbcdd3296
Merge pull request #599 from iflytek/docs/star-watch-cta
docs(readme): add star/watch buttons and guidance to first screen
2026-07-28 22:48:49 +08:00
XiaoSeS
4ccd402880
Merge pull request #598 from iflytek/docs/harnessclaw-engine-integration
docs(integrations): add HarnessClaw Engine skill guide
2026-07-28 22:44:56 +08:00
XiaoSeS
155ab8f6d5 fix(auth): hide placeholder OAuth providers
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-28 22:16:45 +08:00
ylhu16
fab07cbc92 Merge remote-tracking branch 'origin/main' into review/pr480-20260728 2026-07-28 22:10:53 +08:00
XiaoSeS
e45b6f5398
Merge pull request #443 from myml/fix-protocol
fix(nginx): trust X-Forwarded-Proto only when configured
2026-07-28 20:15:43 +08:00
XiaoSeS
e4fb26d4ba fix(nginx): trust forwarded proto only when configured
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-28 20:03:50 +08:00
XiaoSeS
bbf9e4e714 Merge remote-tracking branch 'origin/main' into review/pr443-fix
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-28 20:03:50 +08:00
gale-popai
d977ea9dc4
fix(api): tell callers why a request was forbidden (#610)
* fix(api): tell callers why a request was forbidden

The scope filter already computes an exact reason ("Missing API token
scope: skill:delete", "API token cannot access endpoint: /x") and the
access-denied handler discarded it, returning a bare "Forbidden" for
every case: missing scope, endpoint closed to API tokens, and paths
that simply don't exist. Clients cannot tell those apart, so they
guess — the published CLI reports every 403 as "token may lack
required scope", which sent us debugging token scopes for an hour when
the real causes were a revoked token and a mistyped namespace path.

The reason now rides in the response via a new error.forbidden.detail
message (en + zh), and is logged alongside the exception type.

Signed-off-by: Gal Eyal <gal.e@popai.health>

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(api): safely expose API token denial reasons

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>

---------

Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-28 17:42:20 +08:00
dongmucat
d4d1f65705 fix(cli): scope local remove by namespace (#606)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
6e6cce0588 test(cli): cover all namespace request paths (#606)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
bd83d2d95f fix(cli): reject ambiguous namespace paths (#606)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
b702f0f9f6 test(cli): align namespace error contracts (#606)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
27efaa1b61 docs(cli): document namespace and error behavior (#606)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
3e66c80f94 fix(cli): preserve structured registry errors (#606)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
95da3cd5e8 fix(cli): normalize namespace coordinates (#606)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:31 +08:00
dongmucat
a94073004f docs(cli): define namespace error fix plan (#606)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:31 +08:00
1664940968@qq.com
1d679c526a
fix(auth): recover login page from stale lazy-loaded chunks after logout (#560)
* fix(auth): recover from stale login chunks after logout

* fix(auth): prevent repeated stale chunk reloads

Signed-off-by: ylhu16 <ylhu16@iflytek.com>

---------

Signed-off-by: ylhu16 <ylhu16@iflytek.com>
Co-authored-by: ylhu16 <ylhu16@iflytek.com>
2026-07-28 16:36:47 +08:00
Gal Eyal
8435ee1ab1 fix(auth): read device-code state via ObjectMapper conversion, not cast
The shared RedisTemplate uses GenericJackson2JsonRedisSerializer with
the application ObjectMapper, which embeds no type information, so
stored DeviceCodeData deserializes as a LinkedHashMap. The typed casts
in pollToken and authorizeDeviceCode then throw ClassCastException on
every call, making the whole device authorization flow unusable
(every poll returns 500).

Convert the raw value with ObjectMapper.convertValue instead of
casting; this reads both the current untyped map format and any typed
format, so no stored-data migration is needed. Adds bean setters to
DeviceCodeData for map conversion and regression tests that feed the
service exactly what Redis returns in production (untyped maps).

Fixes #604

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Gal Eyal <gal.e@popai.health>
2026-07-28 10:27:37 +03:00
dongmucat
5012b31af2 test(auth): cover CLI session fallback (#605)
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 15:22:11 +08:00