* chore: clear unused files
* fix(tests): fix unit test
* refactor(auth): introduce plugin-based authentication architecture
Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).
Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
/ `get_request_context` dependencies remain unchanged. Routers import the same
symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.
Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>
* fix(tests): fix trusted mode test
* fix(tests): fix unit test
* fix(cli): remove unexisted transaction observer
* docs: update skills definition
* docs: update skills definition
* docs: update skills definition
* docs: update skills definition
* fix(skills): now we allow viking://agent/skills again, and optimize CLI for skills
* docs(skills): use -p instead of --parent in agent skills examples
Align the `ov skills add` examples in the context-types and viking-uri
docs with the short flag `-p` introduced for `ov skills list/find/show`,
so all four user-facing examples consistently demonstrate the short form
when targeting `viking://agent/skills`.
Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>
* fix(tests): error check for api key
* fix(tests): unit test wait until resource not busy
* fix(tests): unit test wait until resource not busy
* fix(sdk): args form in skills find
* fix(skills): pass target uri in request body
---------
Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
The 视频/音频 rows in docs/zh/concepts/06-extraction.md had the
parser names swapped — 视频 was mapped to AudioParser and 音频 to
VideoParser. The English doc (docs/en/concepts/06-extraction.md) is
correct, and the source of truth in openviking/parse/parsers/media/
confirms VideoParser handles .mp4/.avi/etc. and AudioParser handles
.mp3/.wav/etc.
Also expanded the extension lists to match constants.py exactly
instead of "等".
* docs(retrieval): note intent-analysis model is configurable via query_planner (#2224)
* docs(retrieval): note intent-analysis model is configurable via query_planner (#2224)
* docs(api): document observer.filesystem from #2045
* docs(api): document observer.filesystem from #2045
* docs(metrics): list filesystem component from #2045
* docs(metrics): list filesystem component from #2045
* feat(ovpack): add v2 manifest and conflict policy
Add a portable OVPack manifest for scalar metadata and make imports validate scope, derived files, and conflicts before writing.
* fix(ovpack): remove import vectorize option
Make OVPack imports always rebuild vectors in the target environment, keep legacy packages compatible, and reject unsupported manifest versions before writing.
* fix(ovpack): remove force import alias
Use on_conflict as the single OVPack import conflict policy and reject removed force inputs.
* fix(ovpack): regenerate runtime vector metadata
Keep type portable but stop exporting or applying created_at, updated_at, and active_count from OVPack manifests.
* fix(ovpack): validate manifest contents
* fix(ovpack): require manifests for imports
* fix(ovpack): close manifest validation gaps
* fix(ovpack): defer parent creation until validation passes
* fix(ovpack): remove export size guard
* fix(ovpack): support session and scope-root restores
* docs(ovpack): document full backup migration
* feat(ovpack): add backup restore workflow
* fix(ovpack): validate import scope compatibility
* feat: 提交1:路径变量系统
feat: Add path variable system with calendar variables
- Implement {calendar:today}, {calendar:ym}, etc.
- Integrate with all URI-handling API endpoints
- Add comprehensive unit tests
- Update documentation
提交2:Rust CLI重构
feat: Rust CLI refactor with progress bar support
- Split HttpClient into BaseClient and FileUploader
- Add dynamic timeout configuration
- Add progress bar for compression/upload
- Configure via --progress flag or config file
* feat: 提交1:路径变量系统
feat: Add path variable system with calendar variables
- Implement {calendar:today}, {calendar:ym}, etc.
- Integrate with all URI-handling API endpoints
- Add comprehensive unit tests
- Update documentation
提交2:Rust CLI重构
feat: Rust CLI refactor with progress bar support
- Split HttpClient into BaseClient and FileUploader
- Add dynamic timeout configuration
- Add progress bar for compression/upload
- Configure via --progress flag or config file
* feat: support --parent, and change default root path for image
* feat: support --parent, and change default root path for image
* docs: fix docs
* fix: review comments
---------
Co-authored-by: openviking <openviking@example.com>
## feat(cc-memory-plugin): implement persistent sessions, native MCP, and async write path
This update transitions the Claude Code memory plugin from a one-shot capture model to a persistent, per-session integration with OpenViking. It introduces native MCP support directly from the FastAPI server, significantly expands the tool surface, and optimizes performance via detached async write hooks.
### Core Engineering & Capabilities
* **Persistent Sessions:** Reworked lifecycle hooks (SessionStart, PreCompact, SessionEnd) to maintain stable session IDs across the entire Claude Code conversation.
* **Native MCP Endpoint:** Replaced the Node.js MCP subprocess with a native `/mcp` endpoint on the OpenViking server.
* Expands to 9 specialized tools: `search`, `read`, `list`, `store`, `add_resource`, `forget`, `grep`, `glob`, and `health`.
* Propagates identity headers (`X-OpenViking-Account`, `X-OpenViking-User`) through the MCP transport.
* **Async Write Path:** Introduced a detached worker pattern for `auto-capture`, `session-end`, and `subagent-stop` hooks. Claude Code no longer blocks on network round-trips to the OpenViking server.
* **Multi-Source Recall:** Enhanced `auto-recall` to search across memories, resources, and skills with URI-deduplication and score-based filtering.
### Configuration & Integration
* **Unified Auth:** Standardized on `Authorization: Bearer` tokens.
* **Config Resolution:** Established a clear priority chain: **Env Vars → ovcli.conf → ov.conf → Defaults**.
* Added comprehensive environment variable coverage for all tuning fields (e.g., `OPENVIKING_SCORE_THRESHOLD`, `OPENVIKING_COMMIT_TOKEN_THRESHOLD`).
* **One-Line Installer:** Added an interactive bash installer (`install.sh`) that handles dependencies, `ovcli.conf` setup, and marketplace registration, with support for both self-hosted and Volcengine Cloud options.
### Bug Fixes & Refinement
* **Self-Injection Prevention:** Implemented block-stripping logic in `auto-capture` to prevent the plugin from re-storing its own injected context blocks into the memory pool.
* **Session Bypass:** Fixed a bug where `session-start` and `subagent-start` ignored bypass patterns.
* **Subagent Isolation:** Implemented `SubagentStart/Stop` hooks with isolated session IDs and specialized agent headers for memory segregation.
* **Docs & Maintenance:** Bumped version to `0.2.2`; added comprehensive agent integration guides; fixed Vue interpolation and markdown fence issues in documentation.
* docs: fix code-doc inconsistencies in English documentation
- Fix default server host: docs claimed 0.0.0.0 but code defaults to 127.0.0.1
- Fix GLOBAL_SEARCH_TOPK: docs said 3 but code uses 10
- Fix VLM model name: docs had doubao-seed-2-0-code-preview-260215, code uses doubao-seed-2-0-pro-260215
- Fix metrics file reference: pointed to nonexistent .vscode/.workdir/metric/METRIC_res.md
- Fix build prerequisite: Go replaced by Rust/Cargo (no .go files remain in repo)
- Fix embedding provider list: README listed 7 providers, code supports 13
- Fix CLI command inconsistency: two ov commands in sessions doc should be openviking
- Add missing session archive endpoint to API overview table
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* docs: revert ov→openviking CLI rename in sessions doc
Both `ov` and `openviking` are registered entry points for the same
Rust CLI binary (pyproject.toml). The short `ov` alias is intentional
and valid — reverting the previous rename.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* docs: sync same fixes to Chinese docs, README_CN, and README_JA
Apply the same consistency fixes from the English docs to:
- docs/zh/ (Chinese documentation)
- README_CN.md (Chinese README)
- README_JA.md (Japanese README)
Changes mirror the English fixes: server host default, GLOBAL_SEARCH_TOPK,
VLM model name, build prerequisites (Go→Rust), embedding provider list,
metrics file reference, and missing session archive endpoint.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat(session): add account namespace policy and shared sessions
Unify namespace resolution across filesystem, indexing, and session storage.
Add account-shared session paths, role_id auth semantics, and an HTTP demo
script for the four namespace-policy combinations.
* space
* fix(pack): skip derived semantic files in ovpack transfer
Keep ovpack imports resilient to stale sidecars and rebuild semantics through the normal queue instead of restoring derived files verbatim.
* Revert "fix(pack): skip derived semantic files in ovpack transfer"
This reverts commit f4e4db8401.
* fix(namespace): default legacy accounts to agent-shared policy
Clarify that memory.agent_scope_mode is deprecated and document the supported agent memory migration paths.
* docs: fix docker deployment
* reorg: remove third_party/agfs
* feat(s3fs): add disable_batch_delete option for OSS compatibility
Port of PR #1333 from Go version to Rust:
- Add disable_batch_delete config option to S3Client
- When enabled, use sequential single-object deletes instead of DeleteObjects
- This is for S3-compatible services like Alibaba Cloud OSS that require
Content-MD5 for DeleteObjects but AWS SDK v2 does not send it by default
- Add documentation and config example for OSS
* fix(s3fs): pass disable_batch_delete config from Python to Rust
Add disable_batch_delete to the s3_plugin_config dict in _generate_plugin_config
so that the Python config can properly control the Rust S3FS plugin's behavior.
* reorg: remove third_party/agfs
* reorg: remove third_party/agfs
* change some docs
* change some docs
---------
Co-authored-by: openviking <openviking@example.com>
Update docs, tests, and example integrations to reflect accepted + task_id
session commits with task polling for completed results.
Also fix the local PR-Agent model provider prefix in .pr_agent.toml.
Use lock_expire as the single inactivity threshold for both lock files
and in-process handles, so long-running tasks are no longer released just
because the handle was created a long time ago. Make refresh/release and
handle lookup ownership-aware to avoid zombie handles and prevent stale
owners from deleting locks that have already been reclaimed.