Commit Graph
186 Commits
Author SHA1 Message Date
Qin Haojie 9d5646169b fix(observer): keep empty retrievals diagnostic-only (#3985)
Remove the cumulative retrieval error state and preserve zero-result metrics
without using retrieval yield to determine component health.
2026-08-13 21:46:31 +08:00
Qin Haojie ec18c1dcd8 fix(observer): treat empty retrievals as healthy (#3975)
Record actual search execution errors at the service boundary and use those
errors, rather than empty-result rates, to determine retrieval health.
2026-08-13 21:19:36 +08:00
Jiahui ZhouandTRAE CLI 482434ef6e feat(reindex): support tag updates (#3964)
* feat(reindex): support tag updates

Add replace and append tag modes to reindex vector rebuilds, preserve omission-aware behavior, and propagate options through background tasks and namespace rebuilds. Align Python, TypeScript, Go, and CLI interfaces with tests and documentation.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(reindex): lock file targets exactly

Use an exact path lock for existing file targets while retaining tree locks for directories and prune-orphans scopes. Add a regression test for single-file reindex.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(reindex): handle prune file targets

Use exact locks for existing file targets in prune-orphans mode while retaining tree scope for missing targets. Document the existing Go ReindexOptions wait semantics and add lock regression coverage.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
2026-08-13 13:41:12 +08:00
Jiajie - He/him/his 3577f77423 fix(compile): salvage partial output on timeout and iteration limits (#3948)
* fix(service): break startup circular imports with lazy exports

* fix(fs): avoid root semantic refresh when removing resource scope

* fix(compile): preserve existing wiki links

* fix(sdk): extend HTTP timeout for blocking batch writes

* fix(compile): salvage workspace output on runtime timeout

* feat(compile): support runtime timeout and salvage partial output

* fix: expand compile task and output limits

* revert file

* fix(compile): harden salvage and deadline handling

* update

* fix(compile): address salvage review feedback

* fix(compile): normalize escaped salvage links
2026-08-12 18:51:35 +08:00
zihengli cd55ec89a6 feat(assets): support fixed Git commits, explicit targets, and private repository auth (#3703)
* feat/openviking_assets_support_git_commit_id

* feat/openviking_assets_support_to

* feat/private_git_support_watch

* fix: doc_and_ut

* fix: doc_and_ut

* fix: adapt git token url
2026-08-11 14:07:21 +08:00
7f6085a2f9 feat(memory): support event tag filtering (#3850)
* feat(memory): support event tag filtering

Add session-level default event tags, commit-time overrides, durable queue propagation, and first-write vector index tagging. Include config update APIs and coverage for serialization, concurrency, extraction, and HTTP behavior.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(memory): expose event tags in SDKs and CLI

Add session default tag configuration, config updates, and commit-time event tag overrides across embedded Python, standalone Python, TypeScript, Go, and the Rust CLI. Preserve explicit empty-tag semantics and document each public interface.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(sdk): align legacy session tag APIs

Forward commit-time event tags through the legacy Python HTTP shims and align BaseClient session signatures without adding a new abstract-method requirement for existing subclasses.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(session): allow updating auto-commit policy

Extend PATCH session config to atomically update event tags and auto-commit settings. Merge policy objects by field, use explicit null to disable automatic commits, preserve omitted fields, and expose the contract across SDKs and CLI.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(session): align session config interfaces

Replace the generic session create config JSON flag with explicit event-tag and auto-commit options. Preserve omitted, object, and null auto-commit semantics across HTTP, embedded clients, SDKs, and CLI, reject ambiguous null policy fields, and handle nullable event configuration consistently.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* test(session): trim redundant event tag tests

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-10 11:58:02 +08:00
Ray Tien 9806d60443 fix(cli): keep Config test fixtures in sync (#3870) 2026-08-07 20:48:50 +08:00
Onefly 98e6e5d24f fix(cli): correct Rust CLI license metadata (#3729) 2026-08-07 17:15:31 +08:00
444cc87bf8 feat: OIDC and LDAP as new auth mode for OpenViking (#3708)
* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix: remove heima partner, clean up auth docs, add web-studio unsupported auth banner

- Remove heima from partner list in README (en/zh/ja)
- Remove unsupported env var references (OPENVIKING_AUTH_MODE, OPENVIKING_USERNAME,
  OPENVIKING_PASSWORD) from LDAP auth docs
- Remove temporary switch bash snippets from auth docs
- Fix ldap_password description
- Add web-studio unsupported-auth-mode banner for oidc/ldap servers

* fix: address OIDC/LDAP review comments on auth plugin design

Key changes driven by PR review:

- **Role mapping**: OIDC and LDAP external identities always resolve to
  USER role. Removed map_role() calls and group_membership-based role
  mapping. Admin access is gated by the root API key mechanism only.

- **LDAP credential extraction**: Removed query-parameter-based username/
  password extraction (security concern — passwords in URLs can leak via
  shell history, proxy logs, and monitoring). Clients must use Basic Auth
  header or form data.

- **OIDC identifier sanitization**: Auth0 and other providers may include
  characters like "|" in the `sub` claim. These are now replaced with "_"
  to produce valid OpenViking user identifiers.

- **Dead code removal**: Removed _extract_groups, memberof_attribute,
  require_root_api_key_for_admin, _initialize_api_key_manager, and
  get_request_context_checks from both plugins since they are no longer
  needed.

- **Docs**: Removed query-parameter curl example, memberof_attribute and
  require_root_api_key_for_admin config references.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix(auth): bind lazy OIDC imports at module scope

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-06 12:36:37 +08:00
Jiahui Zhou 6f43a4040c feat: support processing mode for content write (#3615) 2026-08-05 21:42:33 +08:00
Kchen 8d1d52fe5d 资源导入:支持解析后不拆分文档 (#3645) 2026-08-05 11:34:10 +08:00
Hao Zheandzhiheng.liu c4d2b27c64 fix(ov): harden CLI configuration and command behavior (#3552)
* docs: fix stale commands, paths, and provider claims

Sweep findings: D-03, D-04, D-05, D-06, D-07, D-08, D-09. Align setup and API examples with current configuration and CLI behavior.

(cherry picked from commit 2b21ee513b)

* fix(review): correct crypto output flag

Addresses blocking review finding on #3401.

(cherry picked from commit 85bb502709)

* docs(ov): finish stale CLI path cleanup

Complete the #3401 salvage by updating the API-writing templates and the remaining encryption guide examples to the Rust CLI surface.

* fix(ov): make local content operations race-safe

Salvage the safe-I/O portions of OpenViking#3414: reject unsupported local watch requests before upload, atomically create download targets, and write snapshot output before reporting JSON success. Add focused regression coverage.

* fix(ov): validate timeout and node-limit inputs

Salvage and complete OpenViking#3414 by validating every timeout and node-limit surface consistently while preserving config commands as a repair path for invalid persisted values.

* fix(ov): allow explicit help before language setup

Salvage OpenViking#3416 with a narrower contract: only clap-recognized -h/--help requests bypass first-run language selection. Bare command groups, legacy -help, and option values keep the existing gate.

* docs(ov): align session and snapshot command examples

Salvage OpenViking#3419 by correcting positional session and snapshot examples, documenting the canonical observer filesystem command, and keeping fs as a compatible alias.

* fix(ov): honor configured output defaults safely

Salvage and complete OpenViking#3424 with CLI-over-config precedence, runtime validation for normal commands, and a table fallback that leaves config repair commands usable. Also clarify the Python-client versus Rust-CLI upload-mode controls.

* fix(ov): preserve zero node-limit semantics

* ci: skip embedding-dependent resource test without secrets

* fix(cli): validate compile timeout consistently

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-07-31 21:45:53 +08:00
zihengli 36d419aaa6 fix:openviking assets import external connector switch (#3634)
* fix:openviking assets import external connector switch

* fix(tests): update quick-start fake embedder compatibility

* fix:openviking assets import external connector switch

* fix:openviking assets import external connector switch
2026-07-31 13:55:41 +08:00
Qin Haojie fd42b1ad92 feat(tasks): support task cancellation (#3577)
* feat(tasks): support task cancellation

* refactor(tasks): scope cancellation to current user

* feat(cli): support task cancellation

* refactor(tasks): make cancellation queue-aware

* refactor(tasks): simplify cancellation bookkeeping

* test: remove task cancellation coverage

* refactor(tasks): trim cancellation coordination

* fix(tasks): contain cancellation to owned work

* feat(tasks): persist resource source metadata

* fix(tasks): handle cancelled work consistently

* refactor(tasks): make completion queue-aware

* fix(tasks): persist terminal state before queue ack

* test(tasks): remove added lifecycle tests

* docs(tasks): document task cancellation
2026-07-30 20:34:27 +08:00
zihengli 47bbf7a66a feat(cli): add Openviking asset manifest mode to add-resource (#3358)
* feat: implement server-resolved OpenViking Assets manifests

Add the openviking-assets/1 declaration flow with server-owned configuration parsing and native Rust CLI execution.

- Resolve one flat Manifest against one Catalog through an authenticated server endpoint with strict schema and Git semantic validation.
- Reject recursive includes and unsafe clone URLs; return a resolved plan without submitting resources or running server-side batches.
- Keep local credential aliases, manifest state, dry-run, failure isolation, and per-asset create/sync orchestration in the CLI.
- Generate normalized stable asset identities on the server and remove the CLI direct SHA-1 dependency.
- Update flat examples and add server resolver/API plus Rust CLI coverage.

* feat: implement server-resolved OpenViking Assets manifests

* feat: implement server-resolved OpenViking Assets manifests

* fix(pathlock): tolerate missing lock token after recursive delete

* feat: implement server-resolved OpenViking Assets manifests

* feat: implement server-resolved OpenViking Assets manifests
2026-07-30 15:29:07 +08:00
zihengli e9c4cc97c3 refactor: extract Connector delegation and expose declarative add_type (#3591)
* refactor: delegate add_resource imports to external Connector

* refactor: delegate add_resource imports to external Connector

* refactor: extract Connector delegation and expose declarative add_type

* fix: merge main to refactor/connector_delegator

* fix: merge main to refactor/connector_delegator
2026-07-29 18:09:25 +08:00
Jiahui Zhou 34b5a88971 Feat/add resource tags (#3560)
* feat: allow tags during resource import

* feat: support uploaded resource watches with tags

* feat: add resource tag flags to CLI

* fix: reject uploaded resource watches with tags

* docs: untrack add resource tags design draft

* fix: write add_resource tags during ingest

* docs: move add_resource tags docs into resources api

* fix: tighten add_resource tag ingestion semantics

* fix: address add_resource tag review feedback

* fix: merge resource tags at vector upsert

* refactor: carry add_resource tags with ingest options
2026-07-29 15:43:06 +08:00
fujiajie666 c91b0d36f2 feat: implement Skill-driven knowledge compilation for ov compile (#3567)
* feat(compile): implement skill-driven ov compile

Require a Skill and run compile tasks through VikingBot AgentLoop with structured wiki bundle rendering and durable task state.

Add OpenViking batch-write and bot proxy APIs, Python SDK and Rust CLI support, shared link and memory helpers, tests, and a One-Page demo.

* fix(compile): refine defaults, links, and failure handling

* fix(compile): normalize skill tools and degrade gracefully

* feat(compile): support skill-defined artifact outputs

* feat(compile): improve artifact reliability and wiki navigation

* feat(compile): support generating and updating skill packages

* fix(compile): validate OKF frontmatter and catalog page types

* feat(compile): rank target catalog and validate updates lazily

* feat(compile): tag generated wiki files for search

* fix(compile): preserve generated skill artifacts in submissions

* fix(compile): enforce fixed toolset and workspace artifact submissions

* fix(skills): preserve nested metadata in skill frontmatter

* fix(compile): normalize wiki paths and citation line breaks

* docs(examples): remove outdated compile demos

* docs(api): document compile and batch-write endpoints

* fix(content): allow arbitrary resource files in batch writes

* fix(compile): harden task lifecycle, auth, and execution

* fix(compile): disable direct exec by default

* fix(compile): allow file-only tasks when exec is disabled

* fix(compile): prevent task lock leaks
2026-07-28 20:33:25 +08:00
Jiahui Zhou 5d1ba45be4 Feat/add resource processing mode (#3566)
* feat: add resource processing mode

* fix: keep semantic artifacts in vectors-only add resource

* test: support processing mode in api test client

* docs: document add resource processing mode

* fix: align processing mode after resource ingestion refactor

* feat: expose processing mode in TypeScript SDK

* fix: preserve add resource compatibility
2026-07-28 20:09:06 +08:00
agent 27debfe7a8 feat(snapshot): add path diff API, SDK, and CLI (#3451)
* feat(snapshot): add path diff API

* feat(snapshot): expose path diff in clients and CLI

* fix(snapshot): pin path diff to resolved commits

* fix(snapshot): bound path diff resource usage

* fix(snapshot): bound diff blob reads

* fix(snapshot): harden path diff API

* fix(snapshot): bound path diff resource usage

* fix(build): sync native binding dependencies
2026-07-23 17:45:36 +08:00
Zayn Jarvis 997e750ccc fix(ov): redact gateway secrets in config show and create root key with 0600 (#3411)
* fix(ov): redact gateway secrets in config show and create root key with 0600

Sweep findings: E-02, E-03. Prevent credential disclosure in output and at key creation.

* test(ov): drop trivial init-key permission test

The 0600 fix is a one-line OpenOptions::mode; a dedicated tokio+tempfile
test module for a single mode assertion is not worth its weight. The
redaction test in store.rs (a real multi-case security behavior) stays.
2026-07-23 10:47:28 +08:00
Qin Haojie fd098cfd65 fix(cli): preserve structured API errors (#3379)
* fix(error): preserve structured errors in cli

* fix(cli): preserve status for non-json errors
2026-07-22 18:06:48 +08:00
Jiahui Zhou 4295dfdef0 docs(cli): update ov cli readme (#3388) 2026-07-22 00:01:59 +10:00
Jiahui Zhou 5390bd5e54 fix: require all retrieval tags in search (#3097) 2026-07-21 11:54:01 +08:00
ef4d97ebe3 feat(snapshot): support path-filtered commit history (#3271)
* feat(snapshot): support path-filtered commit history

* refactor(snapshot): reuse SDK git log implementation

* fix(snapshot): harden path-filtered log resource limits

* chore: remove stale SDK lock entry

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-07-16 19:53:40 +08:00
Jiahui Zhou 1c46d44fbc Fix/reindex preserve owners (#3096)
* fix: preserve reindex content owners

feat: allow trusted admin role assertion

feat: prune orphan vectors during reindex

fix: harden reindex memory body reads

feat: expose reindex prune options in clients

fix(cli): prefer workspace sdk for compat clients

fix: harden reindex prune orphans

* test: align reindex expectations after rebase
2026-07-14 20:38:30 +08:00
DuTao cbfb387dc7 feat(bot): add unified VikingBot gateway routing and OpenViking auth (#3119)
* bot opt config\api check

* 优化vikingbot的启动链路

* 美化颜色

* docs: add VikingBot gateway routing diagram

* fix(bot): harden gateway auth and proxy routing
2026-07-10 17:45:41 +08:00
zgy 6ab724bc67 fix(cli): avoid misreporting upstream model auth errors (#3116) 2026-07-10 16:05:37 +08:00
Qin Haojie 3003ed61d7 feat(retrieval): support image search (#3093)
Add multimodal image vectorization and image query support across the server, SDKs, and CLI.
2026-07-09 16:42:53 +08:00
zgy 07113f81e0 fix(cli): don't misreport remote fetch auth failures as API key errors (#3074)
When the server crawls a URL that returns 401/403, it wraps the failure
in a 5xx envelope. The CLI matched on auth-flavored message text alone
and rendered "OpenViking rejected the API key", wrongly pointing users
at their local config.

Gate the API-key error report on status: 5xx responses are never treated
as a client auth failure even when the message mentions authentication or
forbidden. Also split the 401 vs 403 fetch messages so 403 reads as an
access-denied / anti-bot block rather than a credential problem.
2026-07-08 14:50:59 +08:00
Qin Haojie 44180e39ff fix(cli): preserve mixed warning output fields (#3062)
Keep warning arrays from taking over table rendering when an API result also contains scalar fields like status, root_uri, and task_id.
2026-07-07 17:09:27 +08:00
baojun-zhang 6a33ebb7ca Optimize glob walkdir (#3013)
* feat(storage): optimize glob func

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* fix(localfs): offload blocking fs operations to spawn_blocking

* feat(glob): cap glob api default node_limit at 256

* feat(sdk): add node_limit options for glob in python and go SDKs
2026-07-06 21:39:16 +08:00
MaojiaSheng 3c419ed09a chore: replace doubao 2.0 pro with doubao 2.0 lite as recomended VLM model (#2984) 2026-07-03 16:09:20 +08:00
17631bd353 feat: support ignoring certain files in the multi-version management function, similar to the git ignore feature (#2930)
* docs: add ovgitignore design spec

Co-Authored-By: Claude <noreply@anthropic.com>

* docs: add ovgitignore implementation plan

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(git): add ovgitignore matcher

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(git): apply ovgitignore during commits

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(pyagfs): expose ovgitignore commit results

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(vikingfs): manage account ovgitignore

Co-Authored-By: Claude <noreply@anthropic.com>

* docs(git): document ovgitignore semantics

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(git): enable ovgitignore restore assertion and document python api

Co-Authored-By: Claude <noreply@anthropic.com>

* fix: fix gitignore

* fix: fix gitignore

* feat: 新增 git ignore 相关的接口

* fix: 修复 cli 命令渲染

* doc: 删除执行计划文档

* doc: 删除执行计划文档

* feat: 在 http client 中新增 git ignore 相关接口

* fix: 修改文档中关于 .ovgitignore 被版本化的内容

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-07-02 11:45:38 +08:00
Qin Haojie 8186cfbdeb feat(auth): support seeded API key generation (#2932)
* feat(auth): support seeded API key generation

Allow admin key issuance flows to accept an optional seed so clients can derive predictable user API keys when needed, while preserving random generation by default.

* fix(go-sdk): preserve explicit empty seed payloads

Use pointer seed options so callers can distinguish omitted seeds from explicit empty seeds, matching the Admin API behavior.
2026-07-02 10:47:18 +08:00
Qin Haojie 6223537a00 feat(fs): 新增 attrs 元信息接口 (#2906)
* feat(fs): add attrs metadata endpoint

* feat(fs): move set tags under attrs API
2026-07-01 11:57:04 +08:00
Qin Haojie d7b96d7715 feat(server): add user add target defaults (#2888)
* feat: add user add target defaults

Allow deployments and per-user settings to provide default add targets while keeping explicit request targets authoritative.

* test: remove low-value CLI config parsing test

* refactor: unify user config option naming
2026-06-29 20:32:00 +08:00
t0saki 2846bb6e76 feat(resources): ingest whole sites via sitemap / RSS / Atom (#2858)!
Add WebFeedAccessor (priority 60) that turns a single sitemap /
sitemapindex / RSS / Atom URL into ONE resource tree: it mirrors every
listed page into a temp directory and reuses the existing DirectoryParser
pipeline (the same "fetch-many -> dir -> tree" contract as GitAccessor).
A watch on the feed URL keeps the whole site refreshed (new pages added,
removed pages dropped on each rebuild).

- New openviking/parse/accessors/web_feed_accessor.py: WebFeedAccessor +
  sitemap/feed extractors (nested sitemapindex recursion with depth cap,
  RSS 2.0 / Atom via feedparser), bounded concurrent polite mirroring,
  robots.txt, same-host / include / exclude / max_pages limits.
- args={"site": true} forces whole-site ingestion from a bare domain or
  page by auto-discovering the sitemap/RSS (robots.txt, HTML
  <link rel=alternate>, conventional paths); {"site": false} opts a
  feed-looking URL back out to HTTPAccessor.
- Thread accessor-selection kwargs through can_handle; the registry
  tolerates accessors whose can_handle lacks **kwargs (back-compatible).
- Single-page adds get a non-blocking "this site exposes a sitemap/RSS"
  suggestion appended to the MCP add_resource response, gated to the
  site root only; never auto-crawls.
- New WebFeedConfig (parsers.webfeed): max_pages, concurrency, politeness
  delay, same_host_only, respect_robots, max_depth, suggest_feed.
- Dependencies: feedparser (robust RSS/Atom), defusedxml (XXE-safe XML).
- Docs: zh/en resources API, MCP/CLI/SDK help, ov.conf.example.
- Tests: 52 unit tests (fake httpx, no network).
2026-06-26 21:13:03 +08:00
Zayn Jarvis fb39c57442 document reindex modes (#2845) 2026-06-26 16:35:11 +08:00
Qin Haojie f9c1a60658 fix: narrow legacy agent id compatibility (#2839)
Treat agent_id as an actor peer alias in new clients while keeping X-OpenViking-Agent handling only on server ingress for old clients.
2026-06-26 14:37:57 +08:00
0102a48c2a fix(skills): now we allow viking://agent/skills again, and optimize CLI for skills (#2813)
* chore: clear unused files

* fix(tests): fix unit test

* refactor(auth): introduce plugin-based authentication architecture

Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).

Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
  plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
  / `get_request_context` dependencies remain unchanged. Routers import the same
  symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
  not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): fix trusted mode test

* fix(tests): fix unit test

* fix(cli): remove unexisted transaction observer

* docs: update skills definition

* docs: update skills definition

* docs: update skills definition

* docs: update skills definition

* fix(skills): now we allow viking://agent/skills again, and optimize CLI for skills

* docs(skills): use -p instead of --parent in agent skills examples

Align the `ov skills add` examples in the context-types and viking-uri
docs with the short flag `-p` introduced for `ov skills list/find/show`,
so all four user-facing examples consistently demonstrate the short form
when targeting `viking://agent/skills`.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): error check for api key

* fix(tests): unit test wait until resource not busy

* fix(tests): unit test wait until resource not busy

* fix(sdk): args form in skills find

* fix(skills): pass target uri in request body

---------

Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-06-25 14:36:06 +08:00
Haoyu Zhangandzhanghaoyu.la aa53e7aede feat: 实现 commit、restore、show 文件系统多版本管理功能 (#2756)
* feat: 实现 commit、restore、show 文件系统多版本管理功能

fix: 修复commit时删除文件

fix: commit 的 fast path 1 添加 Racy-clean 机制

fix: 将 sdk 中的 git 命令改为 snapshot 命令,同步修改单测

fix: 多版本管理的文件存储目录改为 .ovgit

feat: snapshot cli 渲染

fix: 修复 restore 时将删除的文件回滚时,目录不存在的问题

feat: restore 命令的 project_dir 参数改为可选,不传时默认全目录回滚

feat: 更新文档

fix: 删除暂未使用的配置参数

feat: 新增示例脚本

fix: 修复示例代码

fix: 修复 restore 返回的 task id 任务完成状态

feat: 在 restore 修改文件系统时加锁

fix: fix openviking_sdk

* feat: 将git多版本管理功能改为默认打开,并复用agfs的配置参数作为默认值

* fix: restore 命令改为先完成 ref 一致性协议再写回 VFS;object store 并发改为使用唯一 temp path

* fix: 在 git 配置检验层去除未实现的cas_mode = "redis_lock"模式

* fix: 在 Rust GitService 边界统一校验 account

* fix: 当前commit不支持通过 path 传入目录,增加报错信息

* fix: 将git文件默认存储路径统一为 .ovgit

* fix: restore 时写入 VFS 失败时返回详细的报错,并继续触发 reindex

* fix: 校验 commit、restore、show 的路径

* feat: 实现 commit 时指定目录

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
2026-06-25 11:28:04 +08:00
Zayn Jarvis c0fa12f9ef docs: clarify local cli binary smoke (#2792) 2026-06-24 14:02:13 +08:00
t0saki 2af4d748d8 fix(cli): omit null/empty request fields so older instances accept them (#2799)
The CLI unconditionally attaches optional fields to the find/search/add_resource
request bodies — `args` as an empty `{}` and `tags`/`context_type` as `null` —
even when the user never set them. OpenViking kernels use
`model_config = ConfigDict(extra="forbid")` on these routes, so any instance that
predates a field rejects the whole request with
`body.<field>: Extra inputs are not permitted`. This breaks whenever the CLI is
newer than the target instance (and, symmetrically, when a field is later
renamed/removed): e.g. `ov add-resource` fails on `body.args` against a pre-#2549
instance, and `ov find` fails on `body.tags` against a strict pre-#2706 instance.

- Add `compact_request_body()` and apply it in find/search/add_resource: drop
  null-valued keys and an empty `args` object before sending. Scoped to these
  read/create routes only, where a missing optional field and an explicit null
  are equivalent — not applied globally, since null may mean "clear" on a future
  update/PATCH route. This mirrors the existing `create_parent` backward-compat
  convention.
- When a field is explicitly set but unsupported, translate the raw pydantic
  `Extra inputs are not permitted` error into a version-mismatch hint and suggest
  `ov health`, instead of surfacing the opaque API error.

Tests: unit tests for `compact_request_body` and `extra_forbidden_field`.
2026-06-24 12:54:10 +08:00
Xiaobin Huang 6d6660b162 chore(cli): show detailed validation error messages, extract zh-CN to store (#2762)
validation_error_copy() took _error: &Error but completely ignored
it, always returning the same generic message regardless of the actual
failure. Users saw 'Validation failed. Check the server URL and API
key if required.' for every kind of error — network unreachable,
unhealthy server, rejected API key, or HTTP errors.

Now inspects the error to provide actionable messages:
- Network errors → 'Cannot reach the server. Check the URL.'
- Unhealthy server → 'Server reported unhealthy status.'
- Auth rejected (401/403) → 'API key was rejected.'
- HTTP errors → 'Server returned HTTP {status}.'
- Config errors → passes through the original message
- Other → original generic fallback

Both English (validation_error_copy) and Chinese
(validation_error_copy_zh) paths updated.
2026-06-24 11:15:04 +08:00
MaojiaShengandclaude-sonnet-4-6 1cc72d1dc8 fix(cli): remove unexisted transaction observer (#2764)
* chore: clear unused files

* fix(tests): fix unit test

* refactor(auth): introduce plugin-based authentication architecture

Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).

Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
  plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
  / `get_request_context` dependencies remain unchanged. Routers import the same
  symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
  not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): fix trusted mode test

* fix(tests): fix unit test

* fix(cli): remove unexisted transaction observer

---------

Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
2026-06-23 15:23:14 +08:00
Zayn Jarvis f869731485 Support gzip responses in Rust CLI (#2783) 2026-06-23 12:12:47 +08:00
DuTao 027e21bb7e feat(bot): Simplify the bot auth check, support ov's trusted auth_mode. (#2769)
* 增加bot的配置校验。优化bot的逻辑

* 去除 mode的逻辑依赖

* 调整dev的提示文案

* fix:
1. trusted localhost允许 without root key;
2. 调整文档废弃root_api_key;

* 现在 proxy 生成 openviking_connection 时会带上当前 OpenViking server 的 server_url,VikingBot 收到 request-scoped connection 后会优先使用这个 URL,不会再 fallback 到静态 bot.ov_server.server_url 去请求另一台 server。

* fix ipv6

* fix trusted模式chat指令使用root_api_key
2026-06-23 11:59:35 +08:00
Xiaobin Huang 44b3895e8b fix(cli): filter non-Press key events to prevent double-registration (#2737)
* fix(cli): filter non-Press key events to prevent double-registration in interactive prompts

On Windows with ENABLE_VIRTUAL_TERMINAL_INPUT enabled (crossterm 0.28.1),
the console can generate both Press and Release key events for a single
physical key press. The TUI runner (tui/mod.rs) already filters for
KeyEventKind::Press, but the config wizard, config switch selector,
and skill multi-select did not, causing double-processing of every
key press.

Add key.kind == KeyEventKind::Press guard to all three interactive
event-reading loops:
- config_wizard/wizard.rs: prompt_select and prompt_text
- handlers.rs: config switch prompt_select
- commands/skills.rs: skill multi-select prompt

Also add explicit Event::Key(_) => {} arms to discard non-Press
key events cleanly.

* perf(cli): render only on state change, not on every event loop iteration

Previously ui.render() was called at the top of every event loop
iteration, causing a full clear-and-redraw for every ignored event
(Release, Resize, and other non-Press events). On Windows with
ENABLE_VIRTUAL_TERMINAL_INPUT enabled, crossterm can emit multiple
events per physical key press, leading to excessive flickering.

Restructure all three interactive event loops to:
- Render once initially before the loop
- Re-render only when selection/state actually changes (Up/Down/Space)
- Re-render on terminal resize
- Skip render entirely for Release, unhandled Press, and other events
2026-06-20 12:57:32 +08:00
Zayn Jarvis 0418a4537c fix config wizard user management flow (#2721) 2026-06-19 13:33:22 +08:00