635 Commits
Author SHA1 Message Date
jubaoliangjubaoliangCursorgithub-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>Dang Zitou
232030f46c chore: release 1.0.2b4 (#1226)
* docs: refresh README roadmap, anchors, and product sync (#1211)

Align EN/CN README with shipped features and current install/channel
docs; fix GitHub heading anchors and drop obsolete extras examples.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(dashboard): define missing --fn-bg-container theme variable (#1216)

Dark-theme surfaces that use var(--fn-bg-container, #fff) — most
visibly the knowledge-base Markdown preview body, toolbar and outline
panel — resolved to a white background while text stayed light, leaving
preview content invisible. Define the variable as #ffffff (light) and
#141414 (dark), and point the Admin/Users badge tints that borrowed the
name for a translucent fill at --fn-bg-tertiary so their look is
unchanged.

Fixes #1215

* feat(dashboard): let each account customize the sidebar (#1218)

Store group order, item placement, and hidden entries on the user so navigation can be rearranged without showing items the account cannot access.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* style(dashboard): apply Prettier to files that drifted from the formatter (#1222)

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* feat: store role-template id on users.role and harden mobile composer (#1220)

Collapse the dual user_role_id / role model so users.role and invites.role
hold the template public id, block deleting roles still in use, and keep
the chat composer visible under mobile browser visualViewport.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* docs: use product names for sibling project links in the README (#1225)

Link labels now match the product names while the repository URLs stay unchanged.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: release 1.0.2b4

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Dang Zitou <dengzitao888@163.com>
v1.0.2b4
2026-09-27 22:05:48 +08:00
c8217c1acf docs: refresh README roadmap, anchors, and product sync (#1212)
Align EN/CN README with shipped features and current install/channel
docs; fix GitHub heading anchors and drop obsolete extras examples.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 11:19:13 +08:00
jubaoliang 739c03feff Merge pull request #1188 from TencentCloud/release/1.0.2b3
chore: release 1.0.2b3
v1.0.2b3
2026-09-27 10:08:27 +08:00
jubaoliangandCursor a3851ea7e2 fix: check workspace root isdir only after a host-prefix guard
CodeQL flags is_dir on an admin-supplied path unless realpath is contained with startswith first. Keep the denylist, and stat the directory only inside that guard.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 02:02:25 +00:00
jubaoliangandCursor 349aec69ce fix: add trailing newline to PKCE test
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 01:23:17 +00:00
jubaoliangandCursor 6e10ba1673 fix: identify pypi.org by hostname and keep PKCE S256 out of tests
CodeQL treats a "pypi.org" substring as an incomplete URL check, and SHA-256 of the OAuth verifier as password hashing. Label only the parsed hostname, and verify S256 with the RFC 7636 vector.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 01:21:00 +00:00
jubaoliangandCursor b03978de36 chore: release 1.0.2b3
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 16:36:31 +00:00
9a13f53feb fix(chat): dedupe duplicate team live-across-tool-gap test (#1187)
origin/develop already carried two identical copies of the same case;
keep a single assertion.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 00:32:37 +08:00
9be32b03f9 feat(connectors): 企查查同时支持一键 OAuth 与 API Key (#1186)
公网 HTTP 等无法完成 OAuth 回调的环境隐藏一键授权,改为打开授权页取 Key 后粘贴;两种方式二选一,切换时替换另一模式凭证。

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 00:22:44 +08:00
6cf61fa458 fix(db): apply schema v18 via idempotent helper for old restores (#1183)
Raw 018 SQL alters user_invites even when the table is missing on pre-invite backups. Route v18 through _ensure_user_role_schema and bump watermark assertions to 18.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 23:53:19 +08:00
lihongyuan99 04ed76445f docs(fnos): name the fpk packages the release actually ships (#1145)
The 两种安装包 table listed octop-<ver>.fpk / octop-native-<ver>.fpk, which
no build stage emits: build-fpk.sh always appends the kind to the prefix,
CI sets FPK_NAME_PREFIX=Octop-fnos, and the v1.0.2b2 release carries
Octop-fnos-docker-1.0.2b2.fpk / Octop-fnos-native-1.0.2b2.fpk. The rest of
the file, including the manual-install step, already used those names.
2026-09-26 23:41:00 +08:00
95a669b825 fix(dashboard): add lock icons to account change-password fields (#1184)
Match the admin reset-password inputs by prefixing current/new password with Lock and confirm with LockOpen.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 23:33:41 +08:00
8082add666 fix(chat): show generic “calling tools” status instead of tool names (#1182)
Avoid leaking internal names like execute in the live process hint; always use the shared “正在调用工具” copy while a tool is running.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 23:33:29 +08:00
ac8c233180 feat(users): add role templates, invite snapshots, and profile avatars (#1180)
* feat(users): add role templates, invite snapshots, and profile avatars

Roles fill defaults for create, edit, and invite without rewriting existing users. Account type stays independent of the selected role.

Co-authored-by: Cursor <cursoragent@cursor.com>

* style: format role and invite repositories for ruff

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: narrow invite role name before lookup

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:43:09 +08:00
0c57dbc80c test(chat): cover member live bit across tool gaps after host unlock (#1181)
Lock in that a team member stays in liveSpeakers through tool rounds even after the host done frees the composer.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:42:10 +08:00
0322d09ddd fix(chat): default-collapse thinking in team rooms only (#1179)
* fix(chat): default-collapse thinking in team rooms only

Keep solo chat expanded by default, and store team/solo preferences under separate localStorage keys so toggling one does not affect the other.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(chat): keep team member replies in one bubble and clear stale live state

Continue member answer text across completed tools in team rooms, and stop
snapshots/wrap-up from leaving finished speakers marked live in the footer.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:31:44 +08:00
jubaoliangandCursor 09d72e603b feat(dashboard): add remember-me checkbox on the login page
Default stays persistent (localStorage). Unchecking keeps the JWT in
sessionStorage for this tab only; SSO popups post the token back so the
opener can store it correctly.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:22:16 +08:00
Grapette.L f2d0baeb4e fix(config): bound OCTOP_PORT and --port to a bindable range (#1150)
* fix(config): 绑定端口越界时告警回落,--port 越界直接报错

OCTOP_PORT 只按 int() 解析、octop run --port 也只有 type=int,70000/-1
这类根本无法绑定的取值会盖掉 config.json 里本来可用的端口,进程死在
socket.bind 抛出的 OverflowError 里,报错既不含变量名也看不出端口来源;
--port 更是在启动之前就把该值写进 config.json,之后每次 octop run 都继续继承。

现按 resolve_bind 已经支持的「0 表示由系统随机分配端口」把取值收口到
0-65535:环境变量越界沿用「告警 + 不覆盖」的既有契约回落配置文件端口,
命令行 --port 越界交给 click.IntRange 在使用期错误里拦下、不落盘。

* docs: 补上绑定端口的取值范围说明

`octop run --port` 现在会渲染成 `INTEGER RANGE … [0<=x<=65535]`,环境变量表也顺手写明
`OCTOP_PORT` 接受 0–65535(0 = 由系统随机分配),与 `OCTOP_LOG_LEVEL` 那行「One of …」的写法一致。
2026-09-26 20:14:30 +08:00
HuiandClaude Opus 5.5 eb007ee434 fix(api): bound the audit-log limit before it reaches SQL LIMIT
GET /api/admin/audit-log forwarded an unvalidated `limit` into `LIMIT ?`,
the same gap #1018 closed for the thread list. SQLite reads a negative LIMIT
as "no limit", so ?limit=-1 returned the whole audit log in one response and
?limit=0 returned an empty page. Bound it with Query(ge=1, le=500), the
largest page the Settings -> Security audit panel offers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 19:57:35 +08:00
yc2bgr8 1711bd2e6a docs(cn): sync README_CN CLI reference with memory commands
README.md documents `octop memory list/slim` and the /memory slim
chat commands, but README_CN.md's CLI reference table predates them.
Add the three memory rows and the /memory slim paragraph in Chinese,
matching the English README.
2026-09-26 19:29:00 +08:00
jubaoliangandCursor 4c3bf76479 fix: team chat/IM UX, ACP sandbox, channel thinking, and related polish
Improve team streaming visibility (live speakers, generating footer, IM
dispatch/wrap-up), relax ACP tool enable under sandbox while locking
runners, strip channel think tags per show_thinking, and clarify provider
CLI usage in the assistant skill. Includes self-update/UpdateConfig WIP
from the same working tree.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 23:59:46 +08:00
HUANG Chengandjubaoliang bd73bb60aa fix(plugins): offload oversized octop_ui payloads to ToolMessage.artifact (#1032) (#1116)
Plugin tools returning large octop_ui payloads (e.g. a bangumi season
with 1200+ episodes, ~228KB JSON) blew up the LLM context because the
same tool-result string served both the model and the UI.

Add OctopUiOffloadMiddleware at the innermost agent middleware layer:
when a ToolMessage content is a >=4000-char string carrying a non-empty
octop_ui renderer and data (and no file:// media refs), the payload is
moved in-place to ToolMessage.artifact and the model-visible content is
replaced by a compact result that keeps title/summary. Tool id,
tool_call_id, name and status are preserved.

Frontend restores rendering from artifact: ToolCallData.artifact,
closeToolCall extraction, history replay path, and resolvePluginUiData
prefers explicit data over data_ref. serialize.py surfaces artifact on
tool_result blocks; history recorder backfills artifact as fallback.

Spec: docs/octop-ui-payload-offload.md

Co-authored-by: jubaoliang <jubaoliang@gmail.com>
2026-09-25 23:06:19 +08:00
347dee56f4 refactor(infra): group agents modules and clarify package ownership (#1164)
* refactor(agents): group thin modules into domain subpackages

Move plugin helpers, memory, settings stores, persona/MBTI, and avatar
bootstrap code under plugins/, memory/, settings/, persona/, and experts/
while keeping top-level import shims so existing call sites stay stable.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(agents): drop compatibility shims after subpackage move

Call sites already import the new package paths; remove the top-level
re-export stubs so the agents tree only shows real modules.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(agents): move thread helpers into threads/

Group artifact shaping, fork, and context breakdown under
agents/threads so top-level only keeps lifecycle/config adapters.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(agents): fold profile/runtime/tool catalog into settings/

Move the remaining config-surface helpers under settings/ and drop the
skill_package id-list aliases in favor of dump/parse_id_list.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(agents): group workspace_dir and execute_env under workspace/

Keep path resolution and harness execute-env injection together as one
workspace package; leave only manager and conversation_mode at top level.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(infra): fix history/SkillHub ownership and drop thin providers/

Move history_projection under history/, share SkillHub host/limits and
route expert skill downloads through skills.skillhub_market, and fold
Codex OAuth helpers into agents.providers to remove the tiny providers/
package.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs: sync AGENTS.md and guides with infra/agents layout

Reflect subpackages (settings/workspace/threads/persona, history/, skills/)
and drop stale runtime.py / mbti_profiles paths after the agents reorg.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 22:32:41 +08:00
DuhuandDuHu 7617133b31 feat(connectors): 恢复企查查一键 OAuth,保留 internal HTTP 工具加载 (#1106)
* QMCP-2014 feat(connectors): restore QCC OAuth with internal HTTP transport

* QMCP-2014 docs(connectors): record QCC OAuth end-to-end acceptance

---------

Co-authored-by: DuHu <duhu@greatld.com>
2026-09-25 21:51:33 +08:00
jubaoliangandCursor 1d2b2558fb feat(chat): team artifacts, fan-in tool trail, and host wrap-up context
Persist member file refs and tool history on team walls, open docks by producer agent, and inject truncated member answers into host follow-up so wrap-up can follow their advice.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 14:48:45 +08:00
2209cdc90f chore(deps): switch runtime packages to octop-* 1.0.0 (#1136)
Replace orcakit-harness-agent / harness-* with octop-harness, octop-gateway, octop-memory, and octop-browser, and align docs, UI copy, and generated paths.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 06:44:24 +08:00
jubaoliangandCursor 5e34c8a001 fix: connectors empty layout and restore prior control-plane behaviors
Apply the remaining working-tree changes: connectors empty-state layout,
plus the knowledge, HITL, captcha, workspace, user-cache, and SSRF
adjustments with matching tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 22:40:47 +08:00
jubaoliangandCursor 44023b192f docs: point README at TencentCloud octop-harness repos
The harness-* libraries are now published as octop-harness, octop-gateway,
octop-memory, and octop-browser.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 18:23:52 +08:00
689216e4b6 feat: admin user batch policies, token UX, default FS root, and media push hardening (#1114)
* feat: admin user batch policies, token UX, default FS root, and media push hardening

Add admin user batch enable/disable/delete and resource policies (token quota,
max experts), improve token inputs with K/M presets, default unrestricted
local backends to host filesystem root, and tighten gateway tool-media push
with clearer path-outside-root stream errors.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(workspace): treat Windows drive roots as host-root sentinels

Default FS-root backends use C:/ on Windows; treating that as a scoped
jail put workspaces under the drive root and broke bootstrap/invite tests.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 17:22:49 +08:00
4e09aeb956 fix(knowledge): map per-base document cap to KNOWLEDGE_DOC_LIMIT (#1013)
`_map_knowledge_error` matched the literal "at most 100" to classify the
document-cap error, but `KnowledgeRepo.create_document` interpolates the
per-base `max_documents`, which has been user-configurable since 90b8ca25.
Any cap other than the default 100 therefore fell through to the base-cap
branch (the repo message also contains "knowledge bases") and the user was
told they had created too many knowledge bases.

Classify both caps by the stable wording of their own messages instead of
a magic number, and drive the mapping from the real repo in a regression
test so the wording coupling cannot silently rot again.

Co-authored-by: sxh <sunxianhong@ncti-gba.cn>
Co-authored-by: sxh313 <sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:11:19 +08:00
02b807fd9e fix(knowledge): keep the suffix that keys a renamed document (#1108)
files.document_path() keys the stored bytes on {doc_id}{suffix}, so a rename
that drops or swaps the extension moves the row off its own file: the
original-file route 404s, delete_document() unlinks the wrong key with
missing_ok=True and leaks the bytes, and re-saving an md/txt document
writes a second file. rename_document() now restores the document suffix
the way create_text_document() already normalises it; folders and names that
already carry the right extension are untouched.

Closes #1107

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:11:04 +08:00
af2c742801 fix(api): bound the thread-list limit before it reaches SQL LIMIT (#1018)
GET /api/agents/{agent_id}/threads forwarded an unvalidated `limit` into
`LIMIT ?`. SQLite reads a negative LIMIT as "no limit", so ?limit=-1 returned the
caller's whole thread collection and ?limit=0 returned an empty page; the same
statement reaches psycopg unchanged, where a negative LIMIT is an error. Bound it
with Query(ge=1, le=HISTORY_MAX_LIMIT), the ceiling this module already uses for
message pages.

Co-authored-by: sxh <sunxianhong@ncti-gba.cn>
Co-authored-by: sxh313 <sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:10:42 +08:00
lihongyuan99andjubaoliang aeb486c722 fix(security): keep IPv6 brackets and path params when rebuilding pinned URLs (#1092)
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:10:19 +08:00
0559b0cf5d fix(agents): HITL 会话跳过策略不再按进程缓存 (#1090)
threads.hitl_policy 是策略的唯一事实来源:每次判定都回查该行。
octop run --workers N(或 CLI 与服务并发)共用一个库时,进程内缓存会让
另一个进程撤销的跳过继续自动放行工具调用,也会让新授予的跳过不生效;
写库失败时缓存里还会留下一个从未落库的豁免策略。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:09:58 +08:00
309db11140 fix(users): 角色与禁用状态改为读库,多 worker 下撤权不再滞后 (#1102) (#1103)
UserManager.get_by_id 与 authenticate 从进程内镜像回答,而 deps.py 的
resolve_user_from_token 每个认证请求都要经过 get_by_id。octop run
--workers N,或 CLI 离线写同一 SQLite 时,另一个进程的 set_role /
disable / remove 不会更新这份镜像:被降级的管理员、被禁用甚至已删除的
用户在其它 worker 上仍按旧身份通过鉴权。

现在两个读取点回到 users 行——行不存在或 disabled 时返回 None,并顺手
清掉镜像里的过期条目;authenticate 用它本来就已经取到的行构造 User。
disable / remove 一直会弹出本地镜像,所以单进程语义不变,登录响应的
role 也不再来自这份进程私有副本。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:09:37 +08:00
62218f6914 fix(backup): 导入工作区 zip 时跳过 Octop 自有的 _builtin_skills 条目 (#1104) (#1105)
POST /workspace/archive 直接把归档条目写进工作区,唯一的规则
_safe_zip_name 只防目录穿越,不防保留前缀,所以一个 zip 可以在
_builtin_skills/ 和 .octop/_builtin_skills/ 下落盘。该前缀是 Octop
自有目录:delete/move 走 _assert_workspace_mutable 会拒绝它,
sync_octop_builtin_skills 也只清理 RETIRED_BUILTIN_SKILLS,于是植入的
技能既按 kind="builtin" 被加载,又无法通过 API 删除。

现在在解包处过滤该前缀,并沿用已有 warnings 字段报告跳过的条数,
imported 不再把保留路径算成成功导入。导出本来就会打包该前缀,但
无需在恢复时还原:每次 agent 启动都会从包内重新写入自有文件。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:09:19 +08:00
de0f7a89a4 fix(workspace): PUT /file 与 POST /upload 补上 _builtin_skills 写保护 (#1100) (#1101)
同一文件里 mkdir / delete / move / PUT /doc 都用 _assert_workspace_mutable
拦下 Octop 内置技能根 _builtin_skills,只有这两个写接口漏了:owner 可以往
_builtin_skills/<name>/SKILL.md 写内容,_resolve_skill 之后会把它当作
kind="builtin" 的技能列出来,而 delete/move 与 skills 的删除接口对 builtin
一律拒绝,重启同步也只清 RETIRED_BUILTIN_SKILLS 白名单,所以写进去就删不掉。

校验放在取 workspace 之前(与其余写接口一致),upload 校验的是最终真正使用的
target,并且先于读取请求体。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:09:01 +08:00
5bb827f37b fix(auth): OCTOP_CAPTCHA_V3_MIN_SCORE 只接受 [0, 1] 内的有限值 (#1087) (#1088)
nan / -inf / 负数会被 float() 成功解析并原样透传给 recaptcha-v3 的判定式
`float(score) < min_score`,而该式对 NaN 恒为 False,等于静默关闭分数门槛;
inf / >1 则反向锁死所有登录。现在沿用同一解析点已有的"值不可用即回落
0.5"规则,只放行 [0, 1] 内的有限值。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 15:08:22 +08:00
lihongyuan99 dfd7fd0c9f fix(plugins): keep wiki_summary requests under *.wikipedia.org (#1027)
wiki_summary interpolates its `lang` argument straight into the URL host
(`https://{lang}.wikipedia.org/...`), and the tool schema the harness
builds from the signature gives the model an unconstrained `str`. A value
like "evil.com#" makes httpx resolve host=evil.com, and "localhost:8443/"
reaches a loopback port -- the response's `extract` is then echoed back
into the chat, so it is also a read-back channel.

Validate `lang` as a bare subdomain label and return the usual error card
otherwise; real codes (zh, en, zh-classical, simple, nb) are unaffected.
2026-09-24 15:04:12 +08:00
github-actions[bot] 02a6e28d23 Merge pull request #1079 from TencentCloud/chore/sync-develop-after-1.0.2b2
chore: sync main into develop after 1.0.2b2
2026-09-23 15:27:21 +00:00
jubaoliang c04aacc604 Merge pull request #1076 from TencentCloud/release/1.0.2b2
chore: release 1.0.2b2
v1.0.2b2
2026-09-23 23:14:35 +08:00
jubaoliangandCursor cf99ab89df chore: sync uv.lock for 1.0.2b2
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 15:09:50 +00:00
jubaoliangandCursor f6acc87e62 chore: release 1.0.2b2
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 15:06:20 +00:00
jubaoliangandCursor 6ede49b2f5 fix(experts): drop redundant add buttons from the edit drawer
Managing skills and subagents already covers install and copy, so the extra add actions only duplicated that entry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 23:02:04 +08:00
jubaoliangandCursor 494a921cfc fix(fnos): parse prerelease versions for FPK builds
Digits-only sed left VER as the whole pyproject line for 1.0.2b1, so
native upload and GHCR wait both failed and no .fpk was attached.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 22:48:41 +08:00
694a8cea8d feat(teams): 主持人先改写再派工,成员回复同步到 IM 通道 (#1064)
用户原话不再原样转给成员;通道原先只看得到主持人短答,成员收口后补推带说话人的完整消息。

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 22:48:26 +08:00
4ea7963b2d fix(acp): 沙箱环境下禁用向外委托 Runner (#1061)
* fix(acp): block outbound runners under directory sandbox

Host-spawned acp_runner would bypass a scoped root_dir jail; gate the
per-agent tool in API/runtime and gray the ACP UI while inbound octop acp stays available.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(acp): allow workspace-scoped local roots for outbound runners

Windows rewrites host `/` to the agent workspace; treating that as a
directory sandbox made ACP enable/round-trip fail on win32 CI.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 22:48:13 +08:00
jubaoliangandCursor 963cb14007 fix(chat): show the real team name on the welcome heading
Team rooms used a hardcoded "#管理团队" / "#Manage team" string instead of
the agent name already passed into WelcomeScreen.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 17:50:34 +08:00
jubaoliangandCursor df7f7d187c feat(connectors): 企查查改为 API Key,并用 internal 模式加载工具
公网 HTTP 无法完成 OAuth 回调;对话若按 gateway 注入会得到空工具表。改为粘贴 Key,harness 走内部 HTTP 聚合五个 MCP。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 17:50:19 +08:00
6f7815bb71 feat(connectors): 新增企查查 OAuth 连接器,一次授权接入五类 MCP 服务 (#1033)
* QMCP-2014 feat(connectors): add QCC MCP OAuth connector

* QMCP-2014 feat(connectors): share QCC OAuth across five MCP servers

---------

Co-authored-by: DuHu <duhu@greatld.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 15:45:02 +08:00