Commit Graph
72 Commits
Author SHA1 Message Date
Asurada 8267365314 fix(web-studio): refresh context tree after external deletion (#4573) 2026-09-02 21:37:33 +08:00
Xinmin Zeng d0959da52d fix(studio): defer routes until auth mode resolves (#4430) 2026-09-02 12:04:02 +08:00
Zayn Jarvis 30ef75ce02 fix(web-studio): render L0/L1 sidecar metadata (#4519) 2026-08-31 18:00:03 +08:00
Zayn JarvisandClaude Opus 5 303e117238 feat(web-studio): search modes, panel collapse, and structured JSONL rendering (#4470)
* feat(web-studio): search modes, panel collapse, and structured JSONL rendering

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C65Cb79Dvr5zLD6ib1T9Ew

* fix(web-studio): keep the palette one width across search and dir browsing

`/` and `//` put the palette into directory browsing, which was still using
the narrow layout, so the dialog resized whenever the query switched between
searching and browsing. Only the empty idle prompt stays narrow now.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C65Cb79Dvr5zLD6ib1T9Ew

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-31 13:50:32 +08:00
yufeng 460f57c1a2 feat(web-studio): support trusted user switching (#4426)
* feat(web-studio): support trusted user switching

* fix(web-studio): support trusted switching without root key
2026-08-28 19:35:35 +08:00
Hao Zhe e7f2fe5190 fix(studio): prevent retrieval description label overlap (#4431) 2026-08-28 16:12:23 +08:00
Onefly 4738df667e fix(web-studio): make context tree keyboard-operable (#4301) 2026-08-27 10:19:17 +08:00
Axiomoth f926353e3e fix(i18n): 完善 Studio 简体中文界面文案 (#4297)
* fix(i18n): complete Simplified Chinese Studio copy

Signed-off-by: Axiomoth <alearner@splrad.com>

* fix(i18n): localize upload failure fallbacks

Signed-off-by: Axiomoth <alearner@splrad.com>

* fix(studio): preserve localized task errors

Signed-off-by: Axiomoth <alearner@splrad.com>

* fix(i18n): refine Studio labels and status output

Signed-off-by: Axiomoth <alearner@splrad.com>

* docs: refine Web Studio internationalization guide

Signed-off-by: Axiomoth <alearner@splrad.com>

* fix(studio): address localization review feedback

Signed-off-by: Axiomoth <alearner@splrad.com>

* fix(studio): translate retrieval labels

Signed-off-by: Axiomoth <alearner@splrad.com>

* fix(studio): address maintainer review feedback

Signed-off-by: Axiomoth <alearner@splrad.com>

* fix(web-studio): use theme-aware error colors

Signed-off-by: Axiomoth <alearner@splrad.com>

---------

Signed-off-by: Axiomoth <alearner@splrad.com>
2026-08-26 18:27:08 +08:00
yufeng 7b0dd5e29f fix(web-studio): support viking links in directory overviews (#4271)
* fix(web-studio): open viking links in directory overview

* fix(web-studio): preserve regular overview links
2026-08-24 19:53:22 +08:00
Axiomoth 6e944cc3e1 fix(studio): prevent token chart axis label clipping (#4105) 2026-08-22 09:37:44 +08:00
Axiomoth 69cad83737 fix(web-studio): avoid duplicate version prefix (#4203)
Signed-off-by: Axiomoth <alearner@splrad.com>
2026-08-22 08:50:58 +08:00
Hao Zhe a809a0aaef feat(studio): show error details in request logs (#4172)
* feat(studio): show error details in request logs

* fix(observability): harden audit error details
2026-08-21 11:57:08 +08:00
Hao Zhe 651f8fa2b5 fix(web-studio): respect task API limits (#4148)
* fix(web-studio): respect task API limits

* fix(web-studio): remove unsupported task time scope

* test(web-studio): pin task API limit
2026-08-20 19:35:05 +08:00
zgyandqin-ctx dc39985ad1 refactor: remove resource relation edges (#3956)
* refactor: remove resource relation edges

* fix: remove stale relation references

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-19 17:54:29 +08:00
Zayn JarvisandClaude Opus 5 7f65f3ea2d chore(web-studio): remove dead code and the unused pnpm lockfile (#4077)
* chore(web-studio): remove dead code (unreachable files and unused exports)

Static sweep of web-studio/src for code no module reaches from the
main.tsx / routeTree.gen.ts entry graph, plus exported symbols nothing
references anywhere (including their own file and tests).

Deleted files:
- src/router.tsx — superseded by the inline createRouter in main.tsx
- src/lib/sessions/generate-title.ts — never called
- src/lib/sessions/types/session.ts — re-export barrel nobody imports
- src/components/ui/{breadcrumb,combobox,context-menu,input-group,progress}.tsx
  — shadcn primitives never added to any screen; re-addable via `shadcn add`

Removed unused exports (and the imports/constants they were the last
consumer of):
- lib/admin-options.ts: sortedAccounts
- lib/sessions/types/chat.ts: ChatState
- lib/sessions/types/message.ts: getTextContent, getToolParts, getContextParts
- routes/home/-lib/format.ts: formatDateKey, formatTimestamp
- routes/playground/-lib/types.ts: VikingEntryHandler
- routes/playground/-lib/utils.ts: buildBreadcrumbs
- routes/resources/-hooks/viking-fm.ts: usePrefetchVikingFsList, useVikingFind
- routes/resources/-lib/normalize.ts: sameUri, normalizeUriForDisplay
- routes/resources/-lib/upload.ts: getExtensionFromName

No behaviour change. `vite build` succeeds, `tsc --noEmit` output is
byte-identical to main, and `vitest run` shows the same pre-existing
19 failed files / 56 failed tests as main.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore(web-studio): drop the unused pnpm lockfile

Nothing in the repo installs web-studio with pnpm: `make build-studio`
runs `npm ci && npm run build`, and both setup-node steps in
`.github/workflows/_build.yml` cache on `web-studio/package-lock.json`.
No workflow reads `pnpm-lock.yaml`.

The file had also drifted out of sync with package.json — 24 specifiers
missing — so `pnpm install --frozen-lockfile` failed outright, which only
ever hurt someone reaching for pnpm locally.

Also drops the `pnpm.onlyBuiltDependencies` field: pnpm 11 no longer
reads it and warns when it is present.

package-lock.json stays as the single source of truth.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 14:00:11 +08:00
skloxoandskloxo 8acd645998 feat(web-studio): extract task-pipeline.ts SSOT for unified drawer and table rendering (#3828)
* feat(web-studio): extract task-pipeline.ts SSOT for unified drawer rendering

* feat(web-studio): include task stats, process queue stats cards and full UI components

---------

Co-authored-by: skloxo <skloxo@users.noreply.github.com>
2026-08-18 12:48:00 +08:00
Zonas Zhou 65ca438694 fix(web-studio): render raw HTML in Markdown preview with sanitization (#4046)
- Add rehype-raw and rehype-sanitize so raw HTML in Markdown renders while stripping scripts and other dangerous tags
- Give table cells full borders, center content both axes, and pass through colSpan / rowSpan
- Add file-preview-html tests covering raw HTML rendering, table attribute passthrough, and script stripping
2026-08-18 12:09:23 +08:00
Oneflyandqin-ctx 0fc2a2cb46 fix(web-studio): normalize service worker scope (#3963)
* fix(web-studio): normalize service worker scope

* test(web-studio): remove service worker unit tests

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-13 14:26:20 +08:00
yufeng c54f724da2 feat(web-studio): improve resource import options (#3940)
* feat(web-studio): improve resource import options

* fix(web-studio): harden resource import flows

* fix(web-studio): harden resource import mode transitions

* docs(web-studio): remove resource import research notes

* fix(web-studio): address resource import review findings

* fix(web-studio): align resource import options with server

* fix(web-studio): expose unsupported TOS watch option

* refactor(web-studio): defer resource validation to server

* refactor(web-studio): centralize resource import requests

* fix(web-studio): 保留资源导入解析模式

* fix(web-studio): hide unfinished TOS import entry
2026-08-12 11:54:27 +08:00
yufeng cc5ba899d5 feat(web-studio): group skills by scope (#3931)
* feat(web-studio): 按作用域分组展示技能

* fix(web-studio): 完善技能详情交互
2026-08-11 18:09:57 +08:00
yufeng 668637f344 feat(web-studio): add account deletion workflow (#3912)
* feat(web-studio): add account deletion workflow

* fix(web-studio): address account deletion review
2026-08-10 16:00:45 +08:00
yufeng 42a7ff088a feat(web-studio): add scheduled resource sync management (#3909)
* feat(web-studio): add scheduled resource sync

* feat(web-studio): complete watch management workflow

* fix(web-studio): refine watch management workflow

* fix(web-studio): recover watch sync progress polling

* fix(web-studio): expose watch edit action
2026-08-10 14:56:10 +08:00
Ziyang Guo d94d133bef fix(studio): open Markdown links in resource preview (#3723) (#3726)
Route internal viking:// Markdown targets through the existing resource navigator instead of the attachment download endpoint. Preserve download fallback behavior for previews without a navigation callback and add a click regression test.

Test: NODE_OPTIONS='--localstorage-file=/tmp/openviking-vitest-localstorage' pnpm test\nTest: pnpm build
2026-08-07 19:54:18 +08:00
444cc87bf8 feat: OIDC and LDAP as new auth mode for OpenViking (#3708)
* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix: remove heima partner, clean up auth docs, add web-studio unsupported auth banner

- Remove heima from partner list in README (en/zh/ja)
- Remove unsupported env var references (OPENVIKING_AUTH_MODE, OPENVIKING_USERNAME,
  OPENVIKING_PASSWORD) from LDAP auth docs
- Remove temporary switch bash snippets from auth docs
- Fix ldap_password description
- Add web-studio unsupported-auth-mode banner for oidc/ldap servers

* fix: address OIDC/LDAP review comments on auth plugin design

Key changes driven by PR review:

- **Role mapping**: OIDC and LDAP external identities always resolve to
  USER role. Removed map_role() calls and group_membership-based role
  mapping. Admin access is gated by the root API key mechanism only.

- **LDAP credential extraction**: Removed query-parameter-based username/
  password extraction (security concern — passwords in URLs can leak via
  shell history, proxy logs, and monitoring). Clients must use Basic Auth
  header or form data.

- **OIDC identifier sanitization**: Auth0 and other providers may include
  characters like "|" in the `sub` claim. These are now replaced with "_"
  to produce valid OpenViking user identifiers.

- **Dead code removal**: Removed _extract_groups, memberof_attribute,
  require_root_api_key_for_admin, _initialize_api_key_manager, and
  get_request_context_checks from both plugins since they are no longer
  needed.

- **Docs**: Removed query-parameter curl example, memberof_attribute and
  require_root_api_key_for_admin config references.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix(auth): bind lazy OIDC imports at module scope

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-06 12:36:37 +08:00
yufeng 2a2a674dee fix(web-studio): restore terminal history icon (#3735) 2026-08-04 19:09:41 +08:00
yufeng d59bdebb27 fix(web-studio): optimize large JSON previews (#3644) 2026-07-31 11:12:19 +08:00
Qin Haojie fd42b1ad92 feat(tasks): support task cancellation (#3577)
* feat(tasks): support task cancellation

* refactor(tasks): scope cancellation to current user

* feat(cli): support task cancellation

* refactor(tasks): make cancellation queue-aware

* refactor(tasks): simplify cancellation bookkeeping

* test: remove task cancellation coverage

* refactor(tasks): trim cancellation coordination

* fix(tasks): contain cancellation to owned work

* feat(tasks): persist resource source metadata

* fix(tasks): handle cancelled work consistently

* refactor(tasks): make completion queue-aware

* fix(tasks): persist terminal state before queue ack

* test(tasks): remove added lifecycle tests

* docs(tasks): document task cancellation
2026-07-30 20:34:27 +08:00
DuTao 6b416cd66d feat(bot): support image inputs in VikingBot Chat API (#3619)
* bot支持图片对话、去除Lite llm无效逻辑

* fix error

* clarify remote image URL validation
2026-07-30 14:00:48 +08:00
yufeng 291e9c580f feat(web-studio): enhance retrieval workflows and result inspection (#3576)
* feat(web-studio): add recall and advanced retrieval

* feat(web-studio): refine retrieval filters and result details

* fix(web-studio): harden retrieval interactions

* style(web-studio): refine dashboard panel sizing

* fix(web-studio): refine retrieval page behavior
2026-07-29 17:30:31 +08:00
yufeng c67222c3d4 fix(web-studio): standardize streamed event rendering (#3517)
* fix: render bot stream events consistently

* style: separate studio sidebar from content

* fix: standardize studio chat stream rendering

* fix: finalize chat on terminal response

* fix: complete reasoning fallback state

* fix: show agent session title

* style: consolidate playground panel controls

* fix: persist playground tree state

* style: improve session chat contrast

* fix: make session content width responsive

* feat: filter memory impact by type

* fix: widen memory impact drawer

* fix(web-studio): address streaming review feedback
2026-07-27 00:04:47 +09:00
yufeng feb51ffd05 fix(web-studio): preserve identity probe credential (#3509) 2026-07-24 22:14:45 +08:00
yufeng 0ac4b87b03 feat(web-studio): improve operational navigation and workflows (#3506)
* feat(web-studio): add operational navigation and views

* feat(web-studio): complete core management workflows

* feat(web-studio): show current user in header

* feat(web-studio): add task detail panel

* fix(web-studio): harden operational workflows

* fix(studio): widen navigation sidebar
2026-07-24 18:28:25 +08:00
DuTao 0ab85f450a feat(session): add turn-aware retention and reliable archive recovery (#3380)
* 优化OpenViking的 session compact逻辑,active message 改为turn,压缩 assistant,保留完整user。
详见RFC:https://github.com/volcengine/OpenViking/discussions/3330

* Vikingbot 使用 ov turn session

* fix pr comment

* 更新文档

* fix pr issue
2026-07-24 14:26:46 +08:00
yufeng feba7e78a2 feat(web-studio): add account switching and user management (#3500)
* feat(web-studio): add account switching and user management

* fix(web-studio): harden account identity switching
2026-07-24 14:03:43 +08:00
Jiahui Zhou 1c46d44fbc Fix/reindex preserve owners (#3096)
* fix: preserve reindex content owners

feat: allow trusted admin role assertion

feat: prune orphan vectors during reindex

fix: harden reindex memory body reads

feat: expose reindex prune options in clients

fix(cli): prefer workspace sdk for compat clients

fix: harden reindex prune orphans

* test: align reindex expectations after rebase
2026-07-14 20:38:30 +08:00
Zayn Jarvis cc0281ac70 fix(studio): sort limited listings by mtime (#3212)
* fix(studio): sort limited listings by mtime

* fix(client): forward ls ordering options
2026-07-13 16:17:02 +08:00
cd9add7a27 fix(feishu): surface permission errors clearly and keep users on page (#3032)
* fix(feishu): surface permission errors clearly and keep users on page

Map Feishu/Lark API failures to typed OpenViking errors with actionable hints, and keep Web Studio from treating HTTP 403 permission denials as session logout.

* fix(feishu): simplify API error mapping

* refactor(feishu): inline API error mapping

---------

Co-authored-by: wugj <wugj@g-bits.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-07-07 19:55:43 +08:00
Evo fe3bdf4139 fix: treat studio dev mode as root (#3020) 2026-07-06 11:25:12 +08:00
Yangfan Wu b0533b55a7 fix(web-studio): clarify usage audit access requirements (#2955) 2026-07-03 16:34:22 +08:00
Zayn Jarvis 8109ecc56b fix(web-studio): send identity headers in /health identity probe (#2983)
In trusted mode, /health identity resolution requires X-OpenViking-Account
and X-OpenViking-User headers alongside X-API-Key. Without them, the
trusted auth plugin raises InvalidArgumentError, the exception is swallowed
by the health handler, and the response omits role/account_id/user_id —
so the studio falls back to connectionRole='unknown' and gates the admin
UI behind 'Usage/Audit 未初始化'.

Sending the headers is always safe: in api_key mode the server strips
them from the request scope; in trusted mode they are required.

Closes #2977 for the web-studio side.
2026-07-03 16:09:44 +08:00
Zayn Jarvis 6f97624d8e feat(sessions): sort session list by filesystem modTime (#2972)
* fix(web-studio): lazy-create playground sessions to prevent orphans

The AgentPanel used to call POST /sessions on every page load (via a
useEffect gated on botHealth.isSuccess), creating empty UUID sessions
even when the user never sent a message. These orphan sessions cluttered
the session list.

Fix: generate a client-side UUID as the initial sessionId instead of an
empty string. The session is lazily created on the backend by the first
addMessage call (POST /sessions/{id}/messages uses auto_create=True).

- Remove startSession() and its auto-create useEffect
- Always have a sessionId (createRandomUuid fallback)
- Simplify useChat params (persistMessages always true, no preview fallback)
- Remove dead isCreating UI branch
- Call onSessionChange on mount so the URL stays in sync
- Error retry button now uses handleNewSession()

Closes: orphan empty sessions created on playground page load

* feat(sessions): sort session list by filesystem modTime

- Backend: add mod_time to session list API response (from viking_fs.ls stat)
- Frontend: useSessionListByRecency sorts by mod_time instead of N detail fetches
- Frontend: sidebar and playground history use recency-sorted list
- Frontend: sortTreeEntries sorts directories by modTime descending

Reduces session list load from 1+N requests to 1 request.
2026-07-03 11:05:35 +08:00
Zayn JarvisandClaude Opus 4.8 e1fdaf458a fix(web-studio): pin assumed account to admin key's own account (#2910)
When the Root API Key field holds an account-admin key (rather than a
root key), the studio kept using the previously selected / default
assumed account. An account-admin key is scoped to its own account, so
admin and data calls against any other account were rejected by the
server with "ADMIN can only manage account: <x>".

/health already resolves the presented key and echoes back its identity
(role + account_id + user_id). Read account_id alongside role and, when
the key resolves as an admin key, pin the assumed account to the admin
key's own account so admin/data calls target the right tenant. Root keys
are not account-scoped, so their account selection is left untouched.

Also relabel the field "Root API Key" -> "Root or Admin API Key" (en + zh)
to reflect that an account-admin key is accepted there too.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-30 21:39:31 +08:00
Zayn JarvisandClaude Opus 4.8 c65a74569e feat(web-studio): redesign connection & identity settings (#2896)
Replace the connection setup with a clean three-field model plus a
dedicated User Management panel.

- Connection card is now exactly Server URL, Root API Key, User API Key.
  The Root key is the sole control-plane credential (unlocks User
  Management); the User key powers Playground / tenant data APIs and is
  set via "Use as User API Key". Removes the duplicated account/user
  dropdowns and the dual-purpose API-key field.
- Admin access is gated on the Root key only, never the User key.
- Stop normalizing the base URL on every keystroke (it collapsed
  "http://" back to "http:"); normalize at request time instead.
- Disable autocapitalize/autocorrect/spellcheck on URL/key/id inputs
  (the browser was capitalizing "http" -> "Http").
- Debounce field edits and key live behaviour off the committed
  connection, so typing no longer re-probes / refetches per keystroke.
- Guard the account-filter effect against a render loop and add
  keepPreviousData to the probe so adopting/rotating a key no longer
  blanks the panel.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-30 20:02:01 +08:00
yufeng 83cba39b9c perf: split web studio heavy chunks (#2886) 2026-06-29 16:10:03 +08:00
yufeng 65f80c46c8 feat: open studio metrics to users (#2882) 2026-06-29 15:08:36 +08:00
yufeng 91749e40c5 Fix web studio i18n literals (#2847) 2026-06-26 14:01:03 +08:00
Zayn Jarvis f6732b7dd5 fix: Web Studio playground mobile fullscreen actions (#2766)
* fix(web-studio): move playground actions into mobile drawer

* fix(web-studio): make mobile playground actions fullscreen

* docs: add web studio mobile screenshots
2026-06-23 11:03:41 +08:00
Zayn Jarvis 85069d0717 fix(studio): stabilize account selection (#2722)
* fix(studio): stabilize account selection

* fix(studio): use single selected api key state
2026-06-22 10:27:01 +08:00
yufeng 9be0124c36 fix(studio): improve terminal command guidance (#2552) 2026-06-10 20:56:34 +08:00
t0saki 8a3bfb68ff chore(oauth): remove dead push-OTP, repurpose footer to cross-device verify (#2538)
The push-OTP feature (mint an OTP in Studio to hand to an MCP client) was never
wired to a consumer: consume_otp had zero production callers and no endpoint or
grant ever redeemed an OTP. The 'full happy path' test actually exercised the
display_code flow, not OTP. So the sidebar footer's 'OAuth setup' entry minted a
code with nowhere to use it — dead, confusing UX.

Remove it end-to-end and repurpose the footer slot into an entry for the
cross-device verify page (enter the 6-char display_code), which previously had no
discoverable entry point in Studio.

Frontend:
- delete oauth-setup-dialog.tsx + /oauth/setup route (+ routeTree, i18n)
- extract CrossDeviceVerifyForm from verify.tsx; add CrossDeviceVerifyDialog
- footer 'OAuth verify' entry opens the verify dialog (desktop) / page (mobile)

Backend:
- drop issue_otp route + OTPRequest/OTPResponse, storage insert_otp/consume_otp,
  oauth_config.otp_ttl_seconds, and the OTP-specific tests
- keep otp.py generate_otp (cross-device display_code) + hash_secret, the shared
  _atomic_consume_code, and the oauth_codes.kind column
- convert the race/expiry/revoke/GC storage tests to auth-code rows

Docs: update 11-oauth, 06-mcp-integration, and the design doc to reflect removal.
2026-06-10 12:52:54 +08:00