Commit Graph
44 Commits
Author SHA1 Message Date
dingbenandTRAE CLI 9097fef478 feat(server): refresh read-replica API key index via store watcher (#3857)
Read replicas load the API key store once at startup and never rewrite
it, so a user registered/rotated/removed on the writer stays invisible
(new key -> "Invalid API Key"; removed key -> still accepted).

Add an optional background watcher that polls the shared key store and
reloads the in-memory index only when it actually changes:

- APIKeyManager.reload(): strictly read-only refresh that rebuilds state
  and swaps it in atomically, never writing or migrating plaintext keys.
- compute_store_signature(): cheap (path, size, modTime) signature over
  accounts.json + every users.json so the watcher skips unchanged polls.
- ApiKeyAuthPlugin starts/stops the watcher behind api_key_watch_enabled
  (default off) with api_key_watch_interval_seconds; AuthPlugin.shutdown()
  is wired into app shutdown to cancel it cleanly.

Add coverage for reload convergence, read-only/no-migrate guarantees,
uninitialized-store tolerance, signature change detection, and watcher
reload/skip/shutdown behavior.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
2026-08-10 11:28:52 +08:00
jiakun-lu b8738e05f1 feat(server): make HTTP keep-alive idle timeout configurable (#3743) 2026-08-06 14:11:46 +08:00
444cc87bf8 feat: OIDC and LDAP as new auth mode for OpenViking (#3708)
* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix: remove heima partner, clean up auth docs, add web-studio unsupported auth banner

- Remove heima from partner list in README (en/zh/ja)
- Remove unsupported env var references (OPENVIKING_AUTH_MODE, OPENVIKING_USERNAME,
  OPENVIKING_PASSWORD) from LDAP auth docs
- Remove temporary switch bash snippets from auth docs
- Fix ldap_password description
- Add web-studio unsupported-auth-mode banner for oidc/ldap servers

* fix: address OIDC/LDAP review comments on auth plugin design

Key changes driven by PR review:

- **Role mapping**: OIDC and LDAP external identities always resolve to
  USER role. Removed map_role() calls and group_membership-based role
  mapping. Admin access is gated by the root API key mechanism only.

- **LDAP credential extraction**: Removed query-parameter-based username/
  password extraction (security concern — passwords in URLs can leak via
  shell history, proxy logs, and monitoring). Clients must use Basic Auth
  header or form data.

- **OIDC identifier sanitization**: Auth0 and other providers may include
  characters like "|" in the `sub` claim. These are now replaced with "_"
  to produce valid OpenViking user identifiers.

- **Dead code removal**: Removed _extract_groups, memberof_attribute,
  require_root_api_key_for_admin, _initialize_api_key_manager, and
  get_request_context_checks from both plugins since they are no longer
  needed.

- **Docs**: Removed query-parameter curl example, memberof_attribute and
  require_root_api_key_for_admin config references.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix(auth): bind lazy OIDC imports at module scope

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-06 12:36:37 +08:00
agent 1494dc3052 feat(agent-evolution): improve provenance, history, and account settings (#3695)
* feat(agent-evolution): record trajectory mapping in snapshot commits

* feat(agent-evolution): apply global switch immediately

* fix(snapshot): hide memory fields in visible history

* fix(agent-evolution): preserve batch snapshot provenance

* feat(agent-evolution): scope runtime settings by account

* fix(agent-evolution): serialize experience snapshot finalization
2026-08-03 20:52:46 +08:00
agent 0ec2bb0ec5 feat: live-reload Agent Evolution and add file usage sink (#3573)
* feat(agent-evolution): reload global switch at commit time

* feat(agent-evolution): expose configured account in status

* test(agent-evolution): cover account in status response

* fix(agent-evolution): align live config reload semantics

* fix(agent-evolution): tolerate non-object live config

* fix(usage-reporter): use snake case count fields

* feat(usage-reporter): add file log sink

* fix

* fix: address live reload and usage sink review findings

* fix(usage-reporter): complete file sink compatibility

* fix: make experience snapshot source unambiguous

* docs(usage-reporter): align count record implementation plan

* fix: address agent evolution review blockers

* fix(usage-reporter): preserve Windows rollover deadline

* fix(usage-reporter): encode file records as JSON envelopes

* fix(usage-reporter): use snake case unique id
2026-07-29 19:25:35 +08:00
Hao Zheandzhiheng.liu c61471ddc4 fix(deploy): harden bot and server deployment configuration (#3547)
* fix(bot): only require VKE credentials when the TOS storage path needs them

Sweep findings: C-14. Gate AK/SK validation on an actual TOS deployment and drop the unused cluster ID.

(cherry picked from commit 8790ba509f)

* fix(server): apply configured temp_upload.default_mode to uploads

Sweep findings: B-11, D-01. Apply the documented configured upload mode when requests omit it.

(cherry picked from commit a0dc2498e8)

* fix(bot): make one-click Docker deployment generate a working config and port mapping

Sweep findings: C-12. Generate the active ov.conf and keep gateway and Docker ports aligned.

(cherry picked from commit c22af83ab6)

* fix(server): make --bot work and propagate bot flags to workers

Sweep findings: B-09, B-15. Honor the public Bot alias and replay resolved Bot settings in worker processes.

(cherry picked from commit 32a898ca14)

* fix(docker): derive entrypoint/health port from configured server port

Sweep findings: F-06. Keep server startup and every container health check on the same effective port.

(cherry picked from commit 000795c7e3)

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-07-28 18:11:26 +08:00
agent 8391d3a758 feat: add global Agent Evolution switch and HTTP usage sink (#3223)
* feat: add per-user agent evolution settings

* simplify Agent Evolution user settings

* fix: preserve agent evolution client compatibility

* feat(snapshot): add path diff API

* feat(snapshot): expose path diff in clients and CLI

* fix(agent-evolution): gate case memory production

* fix(agent-evolution): preserve configuration compatibility

* feat(usage): add built-in HTTP sink

* fix(agent-evolution): address PR review findings

* fix(usage): isolate HTTP outbox by destination

* docs(usage): define CountRecord HTTP mapping

* docs(usage): plan CountRecord HTTP implementation

* feat(usage): emit CountRecord over HTTP

* docs(agent-evolution): design global switch

* docs(agent-evolution): plan global switch migration

* feat(agent-evolution): make production switch global

* fix(agent-evolution): preserve embedded defaults

* test(agent-evolution): cover failed archive policy replay

* docs(agent-evolution): clarify embedded compatibility

* docs(agent-evolution): expose global switch in example config

* refactor(agent-evolution): align global setting terminology

* fix(agent-evolution): preserve session skill extraction

* fix(usage-reporter): capitalize count record keys
2026-07-27 20:09:38 +08:00
agent ccc271ff27 feat: add extensible usage reporting (#3222)
* feat: add extensible usage reporting

* fix: harden usage reporter lifecycle

* fix: scope experience usage events correctly

* refactor: generalize usage event schema

* docs: design Codex experience memory tools

* docs: plan Codex experience memory tools

* feat: add Codex experience memory tools

* docs: remove temporary Codex implementation plans

* fix: capture Codex MCP tool parts

* fix: harden experience usage reporting

* fix: reload credentials for local MCP tools

* fix: preserve MCP tool-level errors

* fix: bound synchronous sink shutdown

* fix: enforce sink shutdown timeout

* fix: enforce experience tool contracts

* fix(usage-reporter): keep tool schemas and replay ids stable

* fix(usage-reporter): reject unidentifiable tool events
2026-07-16 15:33:27 +08:00
chenjw 1b4534effd docs: 本地 trace 文件路径改名 + 补充产生/上传 trace 排查文档 (#3263)
* docs: 本地 trace 文件路径改名 + 补充产生/上传 trace 排查文档

- 将默认本地 trace 路径从 ~/.openviking/data/traces/offline-traces.jsonl
  改为 ~/.openviking/logs/traces.jsonl,不再建 traces 子目录
- 新增 upload_offline_trace.py 脚本,支持上传 JSONL trace 到远端 OTLP
- 上传脚本上传成功后收集并打印 trace_id 列表
- 在中英文 observability guide 中新增「产生本地 Trace 并提交排查」一节,
  覆盖用户开启 local trace、复现问题、提交 JSONL 给管理员、管理员上传的完整流程
- 更新 test_server_config_loader.py 断言

* fix: return non-zero exit code when main file missing or no batches uploaded

Address review feedback: when --file points to a non-existent path, or
when uploaded_batches == 0 (empty file / all lines invalid), the script
now returns exit code 1 instead of silently returning 0.
2026-07-16 10:16:12 +08:00
Qin Haojie d7b96d7715 feat(server): add user add target defaults (#2888)
* feat: add user add target defaults

Allow deployments and per-user settings to provide default add targets while keeping explicit request targets authoritative.

* test: remove low-value CLI config parsing test

* refactor: unify user config option naming
2026-06-29 20:32:00 +08:00
Kevin HouandClaude Opus 4.8 83011af438 fix(server): map wildcard bind host to loopback for client URLs (#2856) (#2868)
server.host="0.0.0.0" is a bind/listen address, not a connectable
destination. It was used verbatim as the URL the web-studio bot dials
back into ov-server, producing http://0.0.0.0:1933 — so every bot tool
call failed to connect. Users had to work around it by switching host
to 127.0.0.1, which gives up binding on all interfaces.

Add map_bind_host_to_loopback() and use it when deriving the
client-facing server URL, so wildcard binds resolve to loopback while
real hosts pass through unchanged:
  - "0.0.0.0", "", "*"  -> 127.0.0.1
  - "::", "::0", "[::]"  -> [::1]
  - bare IPv6 literals (e.g. "::1") stay bracketed for URL syntax

Applied in get_server_url_from_server_data (covers the bot proxy, the
bot config loader, and doctor) and the mcp_endpoint public-base-URL
"listen" fallback. server.host="0.0.0.0" now works for the bot without
the 127.0.0.1 workaround.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-29 15:35:26 +08:00
87329714dd feat(grep): integrate VikingDB bm25 keyword search for grep engine (#2144)
* feat(grep): integrate VikingDB bm25 keyword search for grep engine

* fix(grep): address CI review feedback: max-size eviction to _count_cache, use Literal, Split regex alternation into individual keywords for bm25 (max 10)

* fix(schema): use dynamic __version__ for schema_version and handle dev suffixes in version comparison

* fix(schema): upsert data to vikingdb lack of content

* chore: add benchmark for retrieval

* fix(grep): vikingdb return 200 and no results means no matching content, not necessary to fallback to local fs

* fix(benchmark): sub uri args; add report

* refactor: code format by ruff

* optimize: move grep config (engine and switch_to_remote_threshold) to ov.conf

* optimize: auto adapt remote_return_limit by agg API; rm unnecessary params in keywords search

* fix: adjust benchmark scripts

* fix(grep): store full content for BM25; use PathScope depth; reduce redundant API calls

* refactor: new benchmark

* fix: step1 add resource by real code data

* feat(benchmark): split grep benchmark into effectiveness/performance suites with async reindex

* optimize (benchmark): adjust keywords and ground truth for testing

* fix: truncate 64KB for content field

* optimize: effectiveness add resource plainly

* optimize: change param use of SearchByKeywords from "keywords" to "query"

* optimize(benchmark): refactor effectiveness scripts

* optimize: ensure raw data for content field

* optimize: fulltext analyzer's stop-words only use symbols

* fix: adapt to new ov cli for benchmark

* optimize: reuse file content to avoid re-read AGFS file

* optimize: tune grep vikingdb defaults and refresh bm25 benchmark scripts

* optimize: benchmark client timeout

* update README

* fix: rm unused param

* fix: default values in docs

* optimize: increase truncate byte size to 1MB for content field for VikingDB

* fix(logger): harden queued stream logging (#2786)

* fix(logger): replace StreamHandler with QueueHandler+QueueListener to prevent thread deadlock

When log.output='stdout' (default) and the server is managed by systemd,
concurrent log writes can deadlock because logging.StreamHandler holds a
thread lock across stream.flush() which blocks on systemd-piped file I/O.

During session.commit() phase 2, multiple async coroutines (memory
extraction, summarization) concurrently call logger.info()/warning()
with large payloads. The first thread's flush() blocks on the pipe,
while all subsequent threads block on handler.acquire() forever.
This permanently silences the server log and prevents _write_done_file()
from executing, leaving phase 2 hanging without .done.

Fix: use QueueHandler + QueueListener from stdlib logging.handlers
(Python 3.2+). QueueHandler.emit() does queue.put(record) with no lock
or I/O, returning immediately. QueueListener has a dedicated single
thread as the sole consumer touching the real StreamHandler, making
lock contention impossible.

Changes in _create_log_handler(): stdout/stderr branches now create
a shared QueueListener with unbounded queue, returning QueueHandler
instances to callers. _build_standard_handler() delegates formatter
and filter setup to the real handler in the listener thread.

Closes: #2752

* fix(logger): harden queued stream logging

---------

Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>

---------

Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>
2026-06-24 18:46:02 +08:00
DuTao 027e21bb7e feat(bot): Simplify the bot auth check, support ov's trusted auth_mode. (#2769)
* 增加bot的配置校验。优化bot的逻辑

* 去除 mode的逻辑依赖

* 调整dev的提示文案

* fix:
1. trusted localhost允许 without root key;
2. 调整文档废弃root_api_key;

* 现在 proxy 生成 openviking_connection 时会带上当前 OpenViking server 的 server_url,VikingBot 收到 request-scoped connection 后会优先使用这个 URL,不会再 fallback 到静态 bot.ov_server.server_url 去请求另一台 server。

* fix ipv6

* fix trusted模式chat指令使用root_api_key
2026-06-23 11:59:35 +08:00
MaojiaShengandclaude-sonnet-4-6 ab656e240d refactor(auth): introduce plugin-based authentication architecture (#2709)
* chore: clear unused files

* fix(tests): fix unit test

* refactor(auth): introduce plugin-based authentication architecture

Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).

Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
  plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
  / `get_request_context` dependencies remain unchanged. Routers import the same
  symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
  not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): fix trusted mode test

* fix(tests): fix unit test

---------

Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
2026-06-18 20:05:17 +08:00
Zayn Jarvis 6b3d261b61 docs: remove stale agent header references (#2462) 2026-06-05 17:27:07 +08:00
Jiahui Zhou e9e6ce5e9a feat(server): add request-scoped http profiling (#2125) 2026-05-25 10:42:28 +08:00
HaotianChen616 f39b030926 feat: externalize oversized session tool results (#2058)
Squashed commits:

- 28e175c8 feat: externalize oversized session tool results
- 73d6461d feat: coalesce OpenClaw tool results by turn
- 3bf4a0c2 fix: apply tool result config and filtered listing
- a5bc0582 [bugfix] extractNewTurnMessages会错误过滤掉没有text block的assistant toolCall,用[toolCall: toolName]占位符确保消息传入
- 1d76827b style: format tool result compression changes
- 495b5623 fix: preserve textless toolUse turns
- 399f2dc3 feat: expose tool result access tools
- 43b48dd7 fix: honor min preview chars for source reads
- 6eaaf54f fix: split aggregated tool result messages
- f8ad98c3 fix: hydrate tool outputs for extraction
- f9031458 fix: improve tool descriptions for tool result access tools
- ae3bcd33 fix: hydrate source-read tool outputs
- 8976f8ce test: add tool result compression bench cases
2026-05-21 14:36:10 +08:00
t0saki 41a33ec16a feat(mcp): progressive single-entrypoint upload for local files (#1847)
* feat(mcp): progressive single-entrypoint upload for local files

Extends `add_resource` MCP tool to handle local-file paths via a server-orchestrated
two-step flow, eliminating the need for `ov` CLI in sandboxed agent environments
(Claude web, Manus) where local FS is unavailable and CLI install is blocked.

Behavior:
- Remote URL  → unchanged.
- Local path  → server mints a 6-char base62 token, returns prose Step 1 / Step 2
                instructions pointing at /api/v1/resources/temp_upload_signed.
                Agent uploads, then re-calls add_resource(temp_file_id=...).
- temp_file_id → resolved against per-tenant subdir, ingested via existing pipeline.

Token: in-memory dict, 10-min TTL, dict.pop doubles as replay protection.
Per-tenant temp-dir isolation ({root}/{aid}/{uid}/{tfid}); legacy CLI uploads
keep flat layout via dual-lookup in resolve_uploaded_temp_file_id.

Public base URL resolves env > config > listen-host fallback (12-factor: runtime
env trumps image-baked config; production deployments behind MCP proxy + nginx
must set OPENVIKING_PUBLIC_BASE_URL since the agent-facing URL is not derivable
from the server's request scope).

* feat(mcp): infer public base URL from request headers + emit fallback hint

Adds a third fallback layer between explicit operator config and listen-host
fallback: capture X-Forwarded-Host / X-Forwarded-Proto / Host headers in the
MCP identity middleware and use them when neither OPENVIKING_PUBLIC_BASE_URL
nor ServerConfig.public_base_url is set.

Resolution order is now: env > config > X-Forwarded-* > Host > listen-host.
The first two are explicit; the rest are inferred. When an inferred source is
used, the add_resource prose response appends a troubleshooting hint asking
the user to set OPENVIKING_PUBLIC_BASE_URL on the server if upload fails —
because inferred URLs can be wrong if the reverse-proxy chain doesn't forward
X-Forwarded headers, or if the server listens on 0.0.0.0.

Documents the variable in docker-compose.yml (commented-out env block) and
in the MCP integration guides (zh + en) — covers when it's required and the
full resolution chain.

* fix(mcp): address Copilot review on PR #1847

- Relax temp_file_id regex from `[a-zA-Z0-9]+` extension to any non-separator
  chars, and dedupe to a single TEMP_FILE_ID_RE in local_input_guard. The old
  pattern rejected `Path("report.my-file").suffix == ".my-file"` and similar
  legitimate filenames, breaking the progressive upload flow.
- Hoist `_resolve_temp_or_path` import to module level in mcp_endpoint
  (verified no circular import).
- Add `_is_safe_namespace_component` defense-in-depth at the signed-upload
  route so a future code path that mints tokens from less-trusted input
  still cannot escape the per-tenant directory.
- Broaden partial-file cleanup to any exception via try/finally + flag,
  not just HTTPException — prevents OSError/IO failures from leaving
  half-written files behind.
- Scope `_cleanup_temp_files` to the tenant subdir at the signed-upload
  route to bound the rglob scan; the legacy `/temp_upload` route still
  cleans the root level.
- Add round-trip test for unusual filename extensions (.my-file, .bak~, .中文).

* docs(mcp): reflect server-minted temp_file_id in progressive-upload flow

Post-rebase onto TempUploadStore, the agent no longer learns the temp_file_id
from the MCP prose — the server mints it at upload time and returns it in the
JSON response body. Update both en + zh docs accordingly. Also note that the
signed endpoint shares the same persistence layer as /temp_upload, so
local/shared modes (and multi-worker via shared) apply uniformly.

* fix(mcp): address Copilot review on rebased PR #1847

- Drop `upload_signed_max_bytes` config field. The signed endpoint now relies on
  TempUploadStore's streaming `temp_upload.shared_max_size_bytes` check (single
  source of truth, fires even when Content-Length is missing/chunked). Map
  oversize from InvalidArgumentError back to 413.
- Normalize `X-Forwarded-Host` / `X-Forwarded-Proto` to the first comma-separated
  value in `_resolve_public_base_url`, matching the OAuth issuer resolver. Fixes
  malformed upload URLs under multi-hop proxy chains.
- Complete the `public_base_url` field comment to reflect all five fallback layers
  in the resolver, not just env > field > listen.
- Add `watch_interval` / `to` parameters to the MCP tool tables in both en + zh
  integration guides — they were merged in from main's Watch Management API
  during the rebase but the table wasn't updated.
2026-05-19 12:32:45 +08:00
yepper 9ebfd59342 feat(metrics): add vikingbot feedback observability (#2037)
* feat(metrics): add vikingbot feedback observability

* fix(bot): align feedback observability contracts

* fix(metrics): decouple feedback collector bootstrap
2026-05-15 17:30:24 +08:00
Kchenandchenpengfei cd72f9182e feat(observability): dump HTTP query, request body, and response body to trace spans (#2052)
Add an opt-in middleware that attaches the request and response bodies
(truncated, content-type filtered) onto the active OpenTelemetry root span,
and surface the URL query string as `url.query`. Off by default — bodies
may contain secrets and high-cardinality content; enable via
`server.observability.dump_body.enabled` and bound payload size with
`max_bytes`.

The dump middleware is registered before the HTTP observability middleware
so it nests inside the trace span (Starlette executes later-registered
middleware first). Streaming, multipart, and binary content types are
skipped, and any capture failure is swallowed so the request path is never
affected.

Co-authored-by: chenpengfei <chenpengfei@bytedance.com>
2026-05-14 21:18:43 +08:00
Qin Haojie 9d36b2fd83 feat(console): 增加 Usage/Audit Dashboard BFF (#2016)
* feat(console): add usage audit dashboard BFF

* feat(console): add usage audit retention config

* docs(console): remove local usage audit design doc
2026-05-14 18:19:42 +08:00
Jiahui Zhou 4f28f086bd feat(server): add shared temp upload mode (#1899)
fix(server): move shared temp uploads to upload namespace

refactor(server): flatten shared upload namespace

refactor(server): simplify shared upload semantics

fix(server): restrict upload scope and add python shared upload mode
2026-05-08 11:12:57 +08:00
baojun-zhang d7fdb489ce feat(observability): support header param while OTLP export (#1805)
* feat(observability): support header param while OTLP export

* feat(observability): support header param while OTLP export
2026-04-29 20:14:31 +08:00
baojun-zhang 64682ae189 feat(encryption): make apikey hash encryption as single switch (#1736)
* feat(encryption): make apikey hash encryption as single switch

* feat(encryption): add break change note
2026-04-27 19:23:23 +08:00
baojun-zhangandMaojiaSheng 17d2c5603e feat(observability): unify observability context && support otel && etc. (#1666)
* feat(observability): unify OTLP metrics export, log/trace context, and telemetry bridging
- - Add OTLP metrics http/grpc exporter that pushes MetricRegistry snapshots
- - Decouple telemetry response payload from telemetry collection; always finish() and bridge summary to metrics
- - Unify observability config under server.observability (metrics/traces/logs siblings); update ov.conf.example and docs (zh/en)
- - Improve log/trace correlation via structured context injection
- - Add/adjust tests for exporter lifecycle, config loader, metrics/telemetry runtime
- BREAKING CHANGE: remove legacy telemetry.* config path; use server.observability.*

* feat(observability): import Status/StatusCode for LogToSpanEventFilter

* feat(observability): fix check issue

* feat(observability): format code

---------

Co-authored-by: MaojiaSheng <shengmaojia@bytedance.com>
2026-04-24 21:32:25 +08:00
yeshion23333 31c33d7ce9 fix(bot):Fix bot api-channel auth check (#1640)
* 1. 修复bot api鉴权;
2. 修复--with-bot log 路径

* 1. 修复bot api鉴权;
2. 修复--with-bot log 路径

* 修复channel 鉴权

* 移除url的引用
2026-04-22 20:40:28 +08:00
MaojiaSheng b13410546b fix: auth and system cmds (#1545) 2026-04-17 20:04:30 +08:00
baojun-zhang 629fc241e4 feat(metric): add token-full-cycle metric (#1488)
* feat(metric): add token full-cycle metric && support token dashboard && optimize metric guide && deprecated 'server.telemetry.prometheus.enabled' configuration && change metric config to observability.metric

* feat(metric): add token full-cycle metric && support token dashboard && optimize metric guide && deprecated 'server.telemetry.prometheus.enabled' configuration && change metric config to observability.metric

* feat(metric): add debug log

* feat(metric): format code

* feat(metric): format code
2026-04-16 18:22:40 +08:00
baojun-zhang b441622ee6 feat(metric): add metric system (#1357)
* feat(metric): add metric system

* feat(metric): add metric system

* feat(metric): add metric system

* fix(metric): do not cancel refresh tasks on deadline; trust only authenticated account id; avoid per-scrape rerank clients

* doc(metric): add metric guide doc

* doc(metric): add metric guide doc

* doc(metric): add metric guide doc

* doc(metric): add metric guide doc

* feat(metric): fix bug & change account dimension switch to default true
2026-04-14 20:55:02 +08:00
Ryanba fd3ca3658f fix(config): point missing-config help messages to openviking.ai docs (#1370) 2026-04-11 20:52:25 +08:00
Jiahui Zhou 1a3bd31199 feat(auth): Restrict trusted mode without API key to localhost (#1279) 2026-04-07 18:11:39 +08:00
MaojiaShengandopenviking ce998873f9 lisence: change the main lisence to AGPL-3.0 (#1085)
* lisence: change the main lisence from Apache-2.0 to AGPL-v3

* lisence: change the main lisence from Apache-2.0 to AGPL-v3

* lisence: change the main lisence from Apache-2.0 to AGPL-v3

---------

Co-authored-by: openviking <openviking@example.com>
2026-03-30 14:37:42 +08:00
Qin HaojieandClaude Opus 4.6 7d9075af16 fix(config): validate config files consistently (#904)
Reject unknown ov.conf and ovcli.conf fields with friendly suggestions,
and fail fast during server startup instead of silently ignoring typos.

Co-Authored-By: Claude Opus 4.6
2026-03-24 11:31:57 +08:00
Jiahui Zhou 7398c660db feat(server): add trusted auth mode for tenant headers (#868) 2026-03-23 10:39:23 +08:00
08d9949072 feat(telemetry): add Prometheus metrics exporter via observer pattern (#806)
* feat(telemetry): add Prometheus metrics exporter via observer pattern

Adds PrometheusObserver implementing BaseObserver with thread-safe
counters and histograms for retrieval, embedding, VLM, and cache
metrics. Exposes /metrics endpoint in Prometheus text exposition
format. Opt-in via server.telemetry.prometheus.enabled config.

No new dependencies - generates Prometheus text format manually.

* style: use dict.fromkeys per ruff C420

* fix(telemetry): wire PrometheusObserver into data collection and address review feedback

- Hook observer into RetrievalStatsCollector and other data paths
- Register metrics router statically in create_app()
- Remove unrelated with_bot/bot_api_url config changes

* fix(telemetry): measure VLM call duration at call sites

Time each VLM API call using time.perf_counter() and pass the
measured duration through to update_token_usage(), which records
it in the Prometheus histogram.

Previously duration_seconds always defaulted to 0.0 because no
backend passed actual timing data. Now all three backends (OpenAI,
VolcEngine, LiteLLM) measure wall-clock time around the API call
in get_completion, get_completion_async, get_vision_completion,
and get_vision_completion_async.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
2026-03-21 14:20:38 +08:00
baojun-zhang 8cdecd9163 feat: Add multi-tenant file encryption capability (#828)
* feat: Add multi-tenant file encryption capability

* feat: move cli command `ov crypto` to `ov system crypto` && ruff format && add encryption config example

* feat: reformat code

* feat: adjust crypto.rs to support diff platform

* feat: reformat code
2026-03-21 13:35:46 +08:00
r266-techandr266-tech 5b9b533924 feat(server): add configurable worker count to prevent single-worker blocking (#470)
Add --workers CLI flag and server.workers config option to allow running
uvicorn with multiple worker processes. This prevents a single slow or
blocking request from stalling the entire HTTP server, including
lightweight endpoints like /health.

When workers > 1, the server uses uvicorn's factory mode with an import
string so each worker process can independently initialize the
application.

Configuration:
  - CLI: openviking-server --workers 4
  - ov.conf: { "server": { "workers": 4 } }
  - Default: 1 (preserves existing behavior)

Closes #464

Co-authored-by: r266-tech <r266-tech@users.noreply.github.com>
2026-03-08 01:04:48 +08:00
MaojiaSheng 96efba54fa feat: define a system path for future deployment (#423) 2026-03-05 12:30:20 +08:00
1b175344e8 Feature/vikingbot_opt: OpenAPI interface standardization;Feishu multi-user experience; observability enhancements; configuration system modernization. (#419)
* feat: add ov chat command and refactor channel architecture

- Add ChatChannel for interactive chat with User:/Bot: labels and thinking display
- Add SingleTurnChannel for one-off -m mode with minimal output
- Add StdioChannel for JSON-based IPC with Rust TUI
- Rename 'vikingbot agent' to 'vikingbot chat'
- Add Python 'ov chat' command that proxies to vikingbot chat
- Add Rust 'ov chat' command that proxies to vikingbot chat
- Refactor ChannelManager to support both config and direct channel addition
- Update event types for better thinking/tool_call/tool_result display
- Default session key: cli__chat__default

* feishu channel opt

* feishu channel opt

* fix: IM channels only process RESPONSE messages

- Update feishu, dingtalk, discord, email, qq, slack, telegram, whatsapp
- Add filter in send() to skip thinking/tool_call/tool_result messages
- Only process is_normal_message (RESPONSE type)

* feat(tracing): add abstract trace decorator for session-aware observability

- Add vikingbot/utils/tracing.py with backend-agnostic @trace decorator
- Use ContextVar for session_id propagation through nested calls
- Implement lazy binding to Langfuse via propagate_attributes
- Update AgentLoop._process_message() to use @trace decorator
- Simplify langfuse initialization logging in commands.py
- Add session_id parameter to litellm_provider.chat()
- Clean up redundant code in utils/helpers.py

The trace decorator abstracts observability concerns, allowing future
switching between Langfuse, OpenTelemetry, or other backends without
modifying business logic.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

* feat: add tracing base on langfuse

* 1. feishu channel opt
2. support multi users

* 1. feishu channel opt
2. support multi users

* 1. feishu channel opt
2. support multi users

* fix(langfuse): use module-level propagate_attributes from SDK v3

The propagate_attributes function is a module-level export in Langfuse
Python SDK v3, not a method of the Langfuse client instance.

- Import propagate_attributes from langfuse module
- Remove misleading warning when propagate_kwargs is empty
- Reduce log noise by changing info logs to debug

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor: unify workspace_id naming and improve tracing integration

Standardize terminology and clean up tracing/Langfuse integration:

- Rename sandbox_key to workspace_id across agent, memory, and tools
- Delete deprecated langfuse_decorator.py (superseded by tracing.py)
- Fix Langfuse v3 SDK propagate_attributes usage (module-level function)
- Improve session_id extraction with better signature inspection
- Reduce log noise in Langfuse attribute propagation

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* 1. feishu channel opt
2. support multi users

* feat(tracing): add user_id extraction support for Langfuse

Add extract_user_id parameter to @trace decorator to enable user
tracking in Langfuse. This allows grouping traces by user in the UI.

- Add extract_user_id parameter to @trace decorator
- Extract user_id from InboundMessage.sender_id
- Pass user_id to Langfuse propagate_attributes
- Update loop.py to use new lambda style for session_id extraction

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix http server

* fix http server

* fix http server

* fix(langfuse): change propagate_attributes log level to info

* feat(tracing): add @observe decorator to create Langfuse traces

* fix(tracing): apply @observe at decoration time, not runtime

* fix http server

* fix(tracing): add detailed diagnostics for Langfuse client status

* fix(langfuse): add diagnostic logging for client initialization

* fix(langfuse): add diagnostic logging for config check

* 飞书chat

* opt http client

* docs(readme): add Langfuse observability configuration guide

* opt http client

* opt http client

* opt http client

* opt http client

* opt http client

* fix(langfuse): fix token reporting to use usage_details format

- Change usage to usage_details for Langfuse v3 SDK compatibility
- Add support for cache_read_input_tokens (OpenAI/Anthropic prompt caching)
- Add logger import and debug logging for token reporting

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* opt http client

* eval command

* eval command

* eval command

* md

* cleanup(tests): remove obsolete test suite and related docs

Remove the entire legacy test suite including:
- Unit tests (test_agent, test_bus, test_channels, test_config)
- Integration tests (test_agent_e2e)
- Test fixtures, utilities, and OpenSpec config
- Test runner tools (tester/)

These tests were outdated and no longer maintained. Future testing
should use a modern testing framework.

* docs(readme): update configuration paths and chat examples

- Update default config path to ~/.openviking/ov.conf
- Add interactive chat mode examples (--no-markdown, --logs flags)
- Remove VKE deployment guide section
- Update Docker volume mount paths

* docs(agent): add comprehensive docstrings to core classes

Add detailed Google-style docstrings to:
- AgentLoop.__init__() - parameters and examples
- AgentLoop._publish_thinking_event() - event publishing
- ToolContext - all attributes documented
- Tool base class - complete usage example

Improves code maintainability and IDE support.

* feat(server): add bot API proxy support and CLI integration

Server changes:
- Add --with-bot flag to enable Bot API proxy
- Register bot_router at /bot/v1 prefix
- Add bot_api_url configuration option
- Initialize bot proxy in bootstrap process

CLI changes:
- Update ov chat endpoint to /bot/v1/chat
- Fix UTF-8 input handling
- Add endpoint configuration via env var

* feat(core): improve agent tools, tracing and session management

- Enhance tool registry with better error handling
- Update OpenAPI channel configuration
- Improve session manager with better state handling
- Enhance Langfuse tracing integration with diagnostic logging

* feat(cli): add agent tools and improve CLI commands

- Enhance CLI commands with new agent tool integration
- Move plugin analysis doc to docs directory
- Add RFC for OpenViking CLI ov-chat command
- Add server restart script

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: DuTao <dutao.1786@bytedance.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: fujiajie.1030 <fujiajie.1030@bytedance.com>
2026-03-04 20:48:11 +08:00
Qin HaojieandClaude Opus 4.6 9e69113ad0 fix(server): 未配置 root_api_key 时仅允许 localhost 绑定 (#310)
当 root_api_key 未配置时 resolve_identity() 将所有请求解析为 ROOT,
结合默认绑定 0.0.0.0 会导致任何网络请求均可执行管理员操作。

- 将默认 host 从 0.0.0.0 改为 127.0.0.1
- 添加 validate_server_config() 启动校验:无 key + 非 localhost 时拒绝启动
- 将 dev mode 日志从 info 升级为 warning
- 更新中英文认证文档的开发模式段落

Closes #302

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-26 17:58:24 +08:00
Qin Haojie b92f2c0fc7 feat: 多租户 Phase 1 - API 层多租户能力 (#260)
* doc: update design

* feat: multi_tenant

* feat: multi_tenant

* feat: multi tenant

* feat: multi tenant

* fix: tests

* fix: rust cli
2026-02-24 13:40:44 +08:00
MaojiaSheng db7319f4a2 refactor: to accelerate cli launch speed, refactor openviking_cli dir (#150)
* fix: remove await asyncio and call agfs directly

* feat: mv cli out of openviking

* refactor: mv cli out of openviking

* refactor: mv cli out of openviking
2026-02-12 22:12:50 +08:00
qin-ctx 6d55bf4aa1 feat: 新增 Bash CLI 基础框架与完整命令实现 (T3 + T5) (#132)
* feat: 新增 Typer CLI 并统一配置加载机制

引入基于 Typer 的完整 CLI 模块 (openviking/cli),支持 resources、
sessions、search、filesystem、content、relations、pack、debug、
observer、system 等子命令。

新增统一配置加载器 (config_loader),采用三级解析链(显式路径 →
环境变量 → ~/.openviking/),同时服务于 server (ov.conf) 和
CLI (ovcli.conf)。

精简 AsyncOpenViking / SyncOpenViking 客户端,移除 service 模式
(vectordb_url / agfs_url) 和环境变量回退逻辑,仅保留 embedded
和 HTTP 两种模式。

同步更新中英文文档、示例和测试。

* fix: remove user  when create session

* fix: tests

* fix: tests
2026-02-11 15:53:10 +08:00
qin-ctx 3165ffa0da feat: add HTTP Server and Python HTTP Client (T2 & T4) (#109)
* feat: add Server/Client architecture with HTTP API and restructure documentation

  - Implement FastAPI-based HTTP server (openviking/server/) with REST API
  - Add client abstraction layer (LocalClient, HTTPClient, BaseClient)
  - Add CLI entry point (python -m openviking serve)
  - Fix bugs: session.session_id, link/unlink param names, hmac.compare_digest
  - Restructure docs: remove numbered prefixes, add guides/, rewrite API reference
    with both Python SDK and HTTP API (curl) examples (en/zh)
  - Add quickstart-server, deployment, authentication, monitoring guides
  - Update examples and design docs to reflect implementation

* 提供单测 和 文档

* Merge branch 'main' into feature/server_client

* feat: add server/client examples and server tests

* fix: cross-references

* fix : tests
2026-02-09 21:12:15 +08:00