dongmucat
b630f871a1
test(security): make access denied locale deterministic
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 12:18:01 +08:00
dongmucat
a3336fe13b
test(search): publish label sync fixture versions
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 12:13:40 +08:00
dongmucat
ba7c242d69
test(namespace): align smoke with super admin visibility
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 12:04:33 +08:00
dongmucat
7fc0e2226c
fix(namespace): refresh session roles for namespace visibility
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
cf744245c6
fix(search): filter rebuilds to published versions
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
082ab489a3
fix(search): refresh index after version yank
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
e066277065
fix(search): require published portal results
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
1d216e73f0
fix(frontend): expose namespace picker value
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
9149227206
fix(frontend): preserve namespace picker selectors
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
0cbe33436d
fix(namespace): type nullable search terms
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
f8df616480
fix(namespace): scope review entry queries
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
78cbe05ebe
fix(namespace): preserve bounded selection semantics
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
2bd358049b
fix(frontend): bound namespace selection
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
8f6941e31e
feat(frontend): add paged namespace picker
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
18c9370318
fix(frontend): bound namespace page queries
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
9de8a51d89
feat(namespace): filter paged namespace reads
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:08 +08:00
dongmucat
a55264b130
fix(namespace): bound filtered namespace queries
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
2fa7a53e2b
fix(namespace): preserve super admin skill reads
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
daba212271
fix(namespace): preserve my namespace compatibility
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
123d0d5f53
fix(namespace): page super admin visibility
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
669d341d51
fix(namespace): preserve review menu visibility
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
35e9ca588a
fix(namespace): allow super admin namespace detail reads
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
dongmucat
1577384ffb
fix(namespace): allow super admin namespace visibility
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 11:53:07 +08:00
XiaoSeS
bafb9fe3b9
Merge pull request #608 from iflytek/fix/cli-namespace-errors
...
Deploy Docs / build (push) Waiting to run
Deploy Docs / Deploy (push) Blocked by required conditions
Security / Dependency Review (push) Waiting to run
Security / CodeQL (java-kotlin) (push) Waiting to run
Security / CodeQL (javascript-typescript) (push) Waiting to run
Security / CodeQL (python) (push) Waiting to run
fix(cli): normalize namespace coordinates and errors
2026-07-29 11:08:15 +08:00
XiaoSeS
13b3f2da92
chore(cli): integrate contributor merge update ( #606 )
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 10:37:03 +08:00
XiaoSeS
a9007a4e8c
fix(cli): preserve download error contract ( #606 )
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 10:31:49 +08:00
dongmucat
c1835fc9e9
merge(main): resolve CLI error mapping conflicts ( #606 )
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-29 10:24:23 +08:00
XiaoSeS
ad4a2dbc2f
chore(cli): merge main into PR #608
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 10:19:03 +08:00
XiaoSeS
9f602f8184
Merge pull request #480 from yaffir/main
...
fix(auth): hide placeholder OAuth providers
2026-07-29 09:00:19 +08:00
XiaoSeS
7872e64177
Merge pull request #609 from iflytek/fix/auth-revoked-token-validation
...
test(auth): cover revoked CLI token lifecycles
2026-07-29 03:37:47 +08:00
XiaoSeS
19c3070291
Merge pull request #607 from gale-popai/fix/device-auth-redis-typing
...
fix(auth): read device-code state via ObjectMapper conversion, not cast
2026-07-29 03:37:25 +08:00
XiaoSeS
c5a2b18fd9
Merge pull request #592 from shychee/fix/label-search-sync-async
...
fix(search): rebuild search index asynchronously after label change
2026-07-28 23:35:11 +08:00
XiaoSeS
cfbcdd3296
Merge pull request #599 from iflytek/docs/star-watch-cta
...
docs(readme): add star/watch buttons and guidance to first screen
2026-07-28 22:48:49 +08:00
XiaoSeS
4ccd402880
Merge pull request #598 from iflytek/docs/harnessclaw-engine-integration
...
docs(integrations): add HarnessClaw Engine skill guide
2026-07-28 22:44:56 +08:00
XiaoSeS
155ab8f6d5
fix(auth): hide placeholder OAuth providers
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-28 22:16:45 +08:00
ylhu16
fab07cbc92
Merge remote-tracking branch 'origin/main' into review/pr480-20260728
2026-07-28 22:10:53 +08:00
XiaoSeS
e45b6f5398
Merge pull request #443 from myml/fix-protocol
...
fix(nginx): trust X-Forwarded-Proto only when configured
2026-07-28 20:15:43 +08:00
XiaoSeS
e4fb26d4ba
fix(nginx): trust forwarded proto only when configured
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-28 20:03:50 +08:00
XiaoSeS
bbf9e4e714
Merge remote-tracking branch 'origin/main' into review/pr443-fix
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-28 20:03:50 +08:00
gale-popai
d977ea9dc4
fix(api): tell callers why a request was forbidden ( #610 )
...
* fix(api): tell callers why a request was forbidden
The scope filter already computes an exact reason ("Missing API token
scope: skill:delete", "API token cannot access endpoint: /x") and the
access-denied handler discarded it, returning a bare "Forbidden" for
every case: missing scope, endpoint closed to API tokens, and paths
that simply don't exist. Clients cannot tell those apart, so they
guess — the published CLI reports every 403 as "token may lack
required scope", which sent us debugging token scopes for an hour when
the real causes were a revoked token and a mistyped namespace path.
The reason now rides in the response via a new error.forbidden.detail
message (en + zh), and is logged alongside the exception type.
Signed-off-by: Gal Eyal <gal.e@popai.health>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(api): safely expose API token denial reasons
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
---------
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-28 17:42:20 +08:00
dongmucat
d4d1f65705
fix(cli): scope local remove by namespace ( #606 )
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
6e6cce0588
test(cli): cover all namespace request paths ( #606 )
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
bd83d2d95f
fix(cli): reject ambiguous namespace paths ( #606 )
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
b702f0f9f6
test(cli): align namespace error contracts ( #606 )
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
27efaa1b61
docs(cli): document namespace and error behavior ( #606 )
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
3e66c80f94
fix(cli): preserve structured registry errors ( #606 )
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:32 +08:00
dongmucat
95da3cd5e8
fix(cli): normalize namespace coordinates ( #606 )
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:31 +08:00
dongmucat
a94073004f
docs(cli): define namespace error fix plan ( #606 )
...
Signed-off-by: dongmucat <1127093059@qq.com>
2026-07-28 16:58:31 +08:00
1664940968@qq.com
1d679c526a
fix(auth): recover login page from stale lazy-loaded chunks after logout ( #560 )
...
* fix(auth): recover from stale login chunks after logout
* fix(auth): prevent repeated stale chunk reloads
Signed-off-by: ylhu16 <ylhu16@iflytek.com>
---------
Signed-off-by: ylhu16 <ylhu16@iflytek.com>
Co-authored-by: ylhu16 <ylhu16@iflytek.com>
2026-07-28 16:36:47 +08:00
Gal Eyal
8435ee1ab1
fix(auth): read device-code state via ObjectMapper conversion, not cast
...
The shared RedisTemplate uses GenericJackson2JsonRedisSerializer with
the application ObjectMapper, which embeds no type information, so
stored DeviceCodeData deserializes as a LinkedHashMap. The typed casts
in pollToken and authorizeDeviceCode then throw ClassCastException on
every call, making the whole device authorization flow unusable
(every poll returns 500).
Convert the raw value with ObjectMapper.convertValue instead of
casting; this reads both the current untyped map format and any typed
format, so no stored-data migration is needed. Adds bean setters to
DeviceCodeData for map conversion and regression tests that feed the
service exactly what Redis returns in production (untyped maps).
Fixes #604
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Gal Eyal <gal.e@popai.health>
2026-07-28 10:27:37 +03:00