Commit Graph
539 Commits
Author SHA1 Message Date
Evo f6bffda205 docs(mcp): add_resource to auto-binds root_uri when omitted with watch_interval (#2378) (#2393)
* docs(mcp): add_resource `to` auto-binds root_uri when omitted with watch_interval (#2378)

* docs(mcp): add_resource `to` auto-binds root_uri when omitted with watch_interval (#2378)
2026-06-03 12:00:44 +08:00
Evo 851848509d docs(config): correct documented vlm.max_concurrent default 100 -> 64 (#2376)
#2343 lowered the shipped default of vlm.max_concurrent (semantic-stage LLM
concurrency) from 100 to 64 in openviking_cli/utils/config/vlm_config.py, but
the config docs still documented it as 100.
2026-06-02 21:32:33 +08:00
yufeng 15f7d38fac docs: update agent integration docs (#2377)
* docs: fix Trae agent docs image links

* docs: split cli and agent cli access

* docs: normalize OpenCode agent name

* docs: normalize Hermes Agent name

* docs: polish agent access copy

* docs: keep CLI access label concise
2026-06-02 19:34:07 +08:00
MaojiaSheng 0b8f3f0894 fix(bot,ovcli): route explicit providers through VLM adapter and refresh config serialization/docs (#2379)
* fix: embedding images directly

* fix: skip default values in CLI config serialization, relax ovcli.conf validation

- Rust: add skip_serializing_if to Config/UploadConfig fields to avoid
  writing null/default values into ovcli.conf
- Python: change OVCLIConfig/OVCLIUploadConfig model_config from
  extra: "forbid" to extra: "ignore" for forward compatibility
- Simplify handle_extra_headers_aliases now that extra fields are ignored
- Add VLMProviderAdapter and integrate VLMFactory into _make_provider

* fix(bot): remove unused OpenAI provider and refresh config docs

Drop the unused OpenAI-compatible provider and its stale exports/tests now that explicit provider configs go through the VLM adapter path. Refresh the bot configuration docs with redacted remote OpenViking examples and clarify gateway/chat usage alongside Feishu configuration.

* revert: drop unrelated embedding changes from PR

Restore the embedder and queuefs files to match the upstream volcengine/OpenViking main branch so this PR only carries the bot provider cleanup and documentation updates.

* revert: align remaining embedding helpers with upstream

Restore the context, embedder base, embedding utils, and local index files to match volcengine/OpenViking main so the PR stays focused on bot-only changes.

* docs: sync cn
2026-06-02 14:02:17 +08:00
Qin Haojie b55df525bc feat(resources): bind watch tasks to imported root URI (#2378) 2026-06-02 14:01:52 +08:00
Dechao Sun c0abcb9a34 Improve vector storage backend persistence (#2367) 2026-06-01 22:14:55 +08:00
Evo 24bbb8b03b docs(api): document structured details on read() directory-URI error (#2349)
* docs(api): document structured details on read() directory-URI error

* docs(api): document structured details on read() directory-URI error (zh)
2026-06-01 20:30:24 +08:00
yufeng 1c9b273fc6 docs: fix Cursor agent docs image links (#2360) 2026-06-01 18:03:59 +08:00
ManAsWindandlinweiye bc5f97d6e1 feat(docs): The main site and the documentation site share cookie configurations (theme colors & Chinese/English switching). (#2353)
* feat: 主站和文档站共享cookie配置(主题色&中/英文切换)

* fix: preserve local main site link path

* fix: support configurable docs main site link

---------

Co-authored-by: linweiye <linweiye.voph@bytedance.com>
2026-06-01 16:05:16 +08:00
yufeng 5752ceb8fb docs: add general agent integration guides (#2354)
* docs: add general agent integration guides

* docs: remove ai generated notes from agent guides

* docs: add localized agent integration assets
2026-06-01 15:55:03 +08:00
Zayn Jarvis 1c4d663873 docs(zh): fix swapped Video/Audio parsers in extraction table (#2341)
The 视频/音频 rows in docs/zh/concepts/06-extraction.md had the
parser names swapped — 视频 was mapped to AudioParser and 音频 to
VideoParser. The English doc (docs/en/concepts/06-extraction.md) is
correct, and the source of truth in openviking/parse/parsers/media/
confirms VideoParser handles .mp4/.avi/etc. and AudioParser handles
.mp3/.wav/etc.

Also expanded the extension lists to match constants.py exactly
instead of "等".
2026-05-31 18:09:21 +08:00
Hao Zheandhaozhelee 7ae22460de feat(cli): Revamp OpenViking CLI (#2198)
* feat(ov-cli): improve CLI setup UX

* fix(ov-cli): harden config store updates

* fix(ov-cli): confirm identity for replaced root keys

* docs: move CLI setup guide to separate PR

* feat(cli): add localized terminal UX

* fix(cli): harden config store and shared UI helpers

---------

Co-authored-by: haozhelee <haozhelee@bytedance.com>
2026-05-29 20:01:17 +08:00
yufeng c6adb15c31 docs: add cursor agent guide and asset headers (#2310) 2026-05-29 19:45:16 +08:00
yufeng 18897e46d2 docs: add agent integration assets (#2306)
* docs: add agent integration assets

* ci: disable cache for agent assets
2026-05-29 16:33:06 +08:00
EurakaxunandEurekaxun 7b52d8fcd0 feat: add typed tool result stubs (#2248)
Co-authored-by: Eurekaxun <eurekaxun@163.com>
2026-05-28 23:53:08 +08:00
Lumos088 cb3e78cec0 Add files via upload (#2290) 2026-05-28 20:41:48 +08:00
Evo 677925e60d docs(mcp): grep pattern is a single string, not string-or-array (#2240) (#2270)
* docs(mcp): grep pattern is a single string, not string-or-array (#2240)

* docs(mcp): grep pattern is a single string, not string-or-array (#2240)
2026-05-28 18:13:26 +08:00
Evo bc3aebbbee docs(retrieval): note intent-analysis model is configurable via query_planner (#2224) (#2269)
* docs(retrieval): note intent-analysis model is configurable via query_planner (#2224)

* docs(retrieval): note intent-analysis model is configurable via query_planner (#2224)
2026-05-28 18:13:10 +08:00
Evo cfe3d8bb0a docs(api): document raw query param on /content/read (#2225) (#2278)
* docs(api): document `raw` query param on /content/read (#2225)

* docs(api): document `raw` query param on /content/read (#2225)
2026-05-28 18:12:36 +08:00
Evo cb4f6d27be docs(memory): document version field that now rejects v1 (#2264) (#2280)
* docs(memory): document version field that now rejects v1 (EN)

* docs(memory): document version field that now rejects v1 (ZH)
2026-05-28 18:11:58 +08:00
Evo 92f9612b38 docs(prompt-guide): document trajectories memory schema (#2282)
* docs(prompt-guide): document trajectories memory schema

* docs(prompt-guide): document trajectories memory schema (zh)
2026-05-28 18:11:27 +08:00
Qin Haojie 96df42f2a9 refactor(memory): remove legacy memory v1 (#2264) 2026-05-27 19:49:38 +08:00
agent 2b5fb5bd7a feat(search) Add lightweight query planner config for intent analysis (#2224)
* feat: query planer

* feat: add planer

* docs: clarify optional query planner config

* refactor: centralize query planner selection

* feat: file

* fix: format file
2026-05-27 16:30:28 +08:00
yufeng 45c4941ea4 fix docs about image links (#2241) 2026-05-26 16:05:56 +08:00
Evo 0eb3ae93a2 docs(prompt-guide): document embedding_template memory-schema field (#2234)
* docs(prompt-guide): document embedding_template memory-schema field (#2193)

* docs(prompt-guide): 文档化 embedding_template 记忆 schema 字段 (#2193)
2026-05-26 14:43:28 +08:00
AutoCoder 1d631cd38d Rename search tool to ov_search to avoid conflict with existing OpenClaw tool name (#2235) 2026-05-26 11:58:15 +08:00
zgy 8be3d4dae7 refactor: rename batch_add_messages to add_messages, add CLI add-messages command and update api docs (#2218)
* feat: add batch add_messages API for faster message ingestion

Previously, adding messages required one HTTP request per message,
making bulk operations (e.g. memory extraction, history migration)
very slow due to network round-trip overhead.

Changes:
- Add POST /api/v1/sessions/{id}/messages/batch endpoint
- Add BatchAddMessageRequest model with max_length=500 limit
- Extract _resolve_message_parts() helper to deduplicate part resolution
- Add _defer_meta_save parameter to Session.add_message() for batch optimization
- Add batch_add_messages method to Python SDK clients (base/http/sync)
- Add batch_add_messages to Session wrapper class
- Update LangChain integration to use batch API
- Update Rust CLI add_memory to use batch API

* refactor: rename batch_add_messages to add_messages and add CLI add-messages command

- Rename batch_add_messages → add_messages across Python SDK, server router, and client
- Add 'ov session add-messages' CLI command with parse_messages() helper
- Update API docs (en/zh) to reflect new naming and CLI usage
- HTTP route path /messages/batch unchanged for backward compatibility

* fix: improve input validation and revert router function name

- parse_messages: return explicit errors for invalid JSON instead of silent fallback
- add_messages: validate spec keys to raise ValueError instead of KeyError
- Revert router endpoint function name to batch_add_messages

* revert: restore batch_add_messages naming across all Python layers and docs

* fix: keep Session.add_messages() as core method name, only SDK/Client/Router use batch_add_messages
2026-05-26 11:16:50 +08:00
t0saki 77a2ee88c3 docs: overhaul agent-integrations section (#2217)
* docs: overhaul agent-integrations section for clarity and beginner-friendliness

Restructure the agent-integrations documentation (EN + ZH) to be concise,
beginner-friendly, and consistently structured across all runtimes.

* docs(mcp-clients): clarify OAuth flow for Claude Desktop / Claude.ai

* docs(mcp-clients): add public access guide link for OAuth section

* docs: address review — clarify dev-mode auth, add missing import

* docs(mcp-guide): update verified platforms, fix OAuth section scope
2026-05-25 17:15:05 +08:00
Jiahui Zhou e9e6ce5e9a feat(server): add request-scoped http profiling (#2125) 2026-05-25 10:42:28 +08:00
t0saki 415eaa0692 docs: add AstrBot plugin to agent integrations (#2211) 2026-05-24 22:01:35 +08:00
Zayn Jarvis d578b03b0d docs: add v0.3.18 and v0.3.19 changelog (#2195) 2026-05-22 19:19:29 +08:00
Evo ab3cb26494 docs(oauth): point OAuth client OTP to sidebar OAuth setup entry from #2178 (#2192)
* docs(oauth): point OAuth client OTP to sidebar OAuth setup entry

* docs(oauth, zh): point OAuth client OTP to sidebar OAuth setup entry
2026-05-22 16:17:12 +08:00
Evo 01b9b3d583 docs(mcp): document code_outline / code_search / code_expand from #2146 (#2176)
* docs(mcp): add code_outline / code_search / code_expand rows for #2146

* docs(mcp): 中文同步 code_outline / code_search / code_expand for #2146
2026-05-22 11:18:28 +08:00
LinQiang391andCursor 87039cac4c docs(openclaw): align plugin docs with ClawHub standard install experience (#2150)
Use explicit clawhub: prefix across all install paths (README, INSTALL, INSTALL-ZH, INSTALL-AGENT, SKILL.md) since bare specs resolve to npm on current OpenClaw. Restructure ClawHub README with Quick Start first screen, How It Works, Tools table, Data Flow and Privacy section. Move engineering details into collapsible section. Demote ov-install to fallback. Fix ov-install params, OpenClaw min version, and parameter table. Allow images in ClawHub bundle.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-21 20:15:23 +08:00
Zayn Jarvis 4aeb25e5b9 docs: replace legacy console / port 8020 references with Web Studio (/studio) (#2175)
Follow-up to #2160 (console removal) and #2170 (OAuth UI moved to web-studio).
Six guides still showed the old `python -m openviking.console.bootstrap`
launch + `-p 8020:8020` docker run snippets, which now fail because the
console package is gone and the image no longer exposes 8020.

- docs/{en,zh}/getting-started/04-setup-for-agent.md: drop `-p 8020:8020`
  from docker run and the "ports: 1933:1933, 8020:8020" summary; note that
  Web Studio is served by the OV server at `/studio` so no extra port is
  needed.
- docs/{en,zh}/guides/03-deployment.md: drop 4× `-p 8020:8020` snippets,
  replace "OpenViking Console on port 8020" with the inline `/studio`
  mention, and update the "access this after startup" list to point at
  `http://localhost:1933/studio` (with 1934 documented as a legacy Caddy
  fallback consistent with the updated 12-public-access guide).
- docs/{en,zh}/guides/05-observability.md: rewrite the "Web Studio for
  web-based investigation" section. The standalone-bootstrap launch is
  gone; instead direct readers to `/studio` and its observability-relevant
  pages — Home (token/retrieval/context-commit trends, /api/v1/console/*
  BFF), Request Logs (audit), Resources, Retrieval, Sessions. Update the
  "choose an entry point" table accordingly.

docs/design/mcp-oauth2-1.md is intentionally untouched — it's a historical
design document. The README inside openviking/observability/usage_audit/
and 12-public-access.md were already updated in earlier PRs.
2026-05-21 20:00:41 +08:00
AutoCoder 9a37e75395 feat(mcp): add code_outline / code_search / code_expand tools (#2146) 2026-05-21 19:30:51 +08:00
t0saki da59289591 feat(oauth): move authorize UI into web-studio (#2160 follow-up) (#2170)
#2160 dropped the legacy `/console` standalone service but deliberately
left the OAuth authorize page's `/console` link and Quick-authorize panel
in place, calling out a follow-up to re-point them at web-studio. This
PR is that follow-up.

Backend
- `provider.authorize()` now defaults to redirecting to
  `/studio/oauth/consent` (same-origin SPA) instead of the server-rendered
  `/oauth/authorize/page`. New `FALLBACK_AUTHORIZE_PAGE` constant exposed
  for callers that need to opt into the legacy path.
- New public endpoint `GET /api/v1/auth/oauth/pending/{pending_id}` returns
  the minimum info the consent UI needs (client_name, redirect_host,
  scopes); deliberately does NOT expose display_code or full redirect_uri.
- `POST /api/v1/auth/oauth-verify` now accepts either `pending_id`
  (Studio consent path) or `code` (cross-device fallback).
- HTML `/oauth/authorize/page` template stripped of `/console` link, the
  `/console/api/v1/...` JS, and the Quick-authorize same-origin panel.
  It now serves as a pure cross-device fallback that points users at
  `/studio/oauth/verify` on another already-signed-in device.

Web Studio
- New `<IdentityPicker>` shared component: "current identity" or
  "use a different API key" — the temporary key is never persisted.
- New routes `/studio/oauth/consent` (same-device consent card) and
  `/studio/oauth/verify` (cross-device code entry).
- ConnectionDialog gains an "OAuth client OTP" section (same
  IdentityPicker), driving `POST /api/v1/auth/otp`.
- API key storage is unchanged: only sessionStorage. No new localStorage
  writes, no cross-tab channels — the consent UI runs inside Studio's own
  tab, so it reads the session-stored key directly.

Docs
- 11-oauth.md (zh/en): refreshed quickstart, How-it-works, Claude.ai
  walkthrough, curl example, and troubleshooting around the Studio
  consent / cross-device verify split.
- 12-public-access.md (zh/en): rewritten to lead with public HTTPS;
  the `:1934` Caddy block is now a one-paragraph compatibility note for
  deployments that already bookmarked it.
- mcp-oauth2-1.md: top-level "Studio migration" note explains the new
  default path; Phase 1 history retained.
- Caddyfile / docker-compose.yml comments reworded from "aggregated
  proxy" to "legacy fallback" to match the new docs.

Tests
- `tests/server/oauth/test_router.py` fixture pins to
  FALLBACK_AUTHORIZE_PAGE so existing end-to-end assertions keep working.
- 4 new tests cover the pending-info endpoint and pending_id verify path.
- 55 passed locally; ruff format+check, web-studio tsc/eslint/prettier
  all clean.

Security notes
- Consent UI requires explicit user click; client_name + redirect_host
  shown for phishing identification.
- Knowing a pending_id does not bypass Bearer auth.
- display_code is not returned by GET pending — the cross-device
  brute-force protection is preserved.
- `ctx.from_oauth` gate (router.py) untouched: OAuth bearer still
  cannot mint new OAuth state or OTPs.
2026-05-21 17:57:33 +08:00
Yuan Shenheng a27c18eee9 fix(examples): wait before quickstart preview (#2167) 2026-05-21 17:11:32 +08:00
Lumos088 dbb67f75d5 Add files via upload (#2162) 2026-05-21 16:45:55 +08:00
Zayn Jarvis d6a024efa5 feat(docker)!: drop legacy console (keep BFF + Caddy), ship web-studio in pip, fix favicons (#2160)
The OpenViking docker image still launched the legacy `openviking/console`
standalone service on port 8020. Now that web-studio is bundled into the OV
server itself at /studio (see #2156), that process is redundant and the
port is just a confusing artefact.

This change retires the old console (python package + 8020 + console-frontend
favicons) but **keeps the in-compose Caddy as a stable single-ingress on
port 1934**, just simplified to one upstream now that there's no 8020. The
server-side BFF at `openviking/server/routers/console.py` (under
`/api/v1/console/*`) is also kept — web-studio uses the same endpoints.

**The OAuth authorize page (`openviking/server/oauth/router.py`) is
deliberately untouched in this PR** — the console-link button and Quick
authorize same-origin panel will be re-pointed at web-studio in a focused
follow-up.

BREAKING CHANGES:
- Port 8020 is gone from the docker image and docker-compose.yml; Caddy at
  1934 now forwards everything to 1933 (web-studio lives at /studio there).
  Anything bookmarked at `http://host:8020/...` must migrate to
  `http://host:1933/studio/`.
- `python -m openviking.console.bootstrap` no longer exists; the python
  package `openviking.console` has been removed.

Pip packaging:
- web-studio dist is now shipped inside the wheel under
  `openviking/web_studio/dist/` (mirroring the old `openviking/console/static/`
  layout). The dockerfile copies `--from=web-studio-builder /web-studio/dist`
  into the source tree before `uv sync`, so the wheel produced by the
  default docker build always carries the SPA. Building the wheel without
  running `npm run build` first leaves the directory empty, which gracefully
  degrades /studio to a 404 without breaking server startup.
- Favicon assets (`favicon.ico` / `favicon-32.png` / `apple-touch-icon.png`,
  ~11 KB total) are duplicated into `openviking/server/static/` and shipped
  via package-data so `/favicon.*` and `/mcp/favicon.*` routes are always
  registered, regardless of whether the web-studio dist is bundled.
- `pyproject.toml` and `setup.py` `package-data` drop `console/static/**`
  and add `server/static/**` + `web_studio/dist/**`.
- New favicons (the 16/32/180 set in both `openviking/server/static/` and
  `web-studio/public/`) are downscaled from the canonical
  `web-studio/public/openviking-icon.png`, so the small-icon family matches
  the SPA's high-res rel="icon" target — the studio tab icon now stays
  consistent whether the browser uses the HTML link tag or falls back to
  auto-fetching `/favicon.ico`.

Server:
- `openviking/server/app.py` now reads `/studio` from
  `Path(__file__).parent.parent / 'web_studio' / 'dist'` by default;
  `OPENVIKING_WEB_STUDIO_DIR` still wins for dev mode pointing at a
  repo-local build. Favicon routes are unconditionally registered and
  load from `openviking/server/static/`.
- `openviking/observability/usage_audit/projection.py` drops the legacy
  `/console/*` skip prefix (the BFF prefix `/api/v1/console/*` remains).

Docker:
- `web-studio-builder` stage moved earlier (Stage 2) so its dist can flow
  into `py-builder` before `uv sync` runs.
- Runtime stage no longer separately copies the dist or sets
  `OPENVIKING_WEB_STUDIO_DIR`; the in-package path is the default.
- Entrypoint renamed `openviking-console-entrypoint.sh` -> `openviking-entrypoint.sh`
  and stripped of the `python -m openviking.console.bootstrap` launch.
- `EXPOSE 1933 8020` -> `EXPOSE 1933`.
- `docker-compose.yml` drops the openviking service's 8020 port mapping;
  the caddy service stays but no longer needs port 8020 exposed.
- `Caddyfile` simplified to a single `:1934 { reverse_proxy openviking:1933 }`
  — the legacy `/console/*` route to :8020 is gone.

Docs:
- en/zh quickstart updated to drop the 8020 mapping and explain that the
  API server now also serves `/studio`.
- Other guides (`12-public-access.md`, `11-oauth.md`, `05-observability.md`,
  `04-setup-for-agent.md`, `03-deployment.md`) are intentionally left for a
  focused follow-up PR alongside the OAuth quick-authorize reintroduction.

Tests:
- Deleted `tests/misc/test_console_{proxy,static_assets}.py` (covered the
  removed console package). `tests/observability/test_console_router.py`
  stays — it covers the BFF, which remains.
2026-05-21 16:41:29 +08:00
CuSO41108 4d406b76c8 docs: fix Chinese quickstart authentication links (#2152) 2026-05-21 14:14:02 +08:00
Evo 344bc71f92 docs(server): document public_base_url and upload_signed_ttl_seconds (#1847) (#2153)
* docs(server): document public_base_url and upload_signed_ttl_seconds (#1847)

* docs(server): document public_base_url and upload_signed_ttl_seconds (#1847) — ZH mirror
2026-05-21 14:13:06 +08:00
Evo 27ed1e1d81 docs(api): document Watch Management endpoints from #2110 (#2123)
* docs(api): document Watch Management endpoints from #2110

* docs(api): document Watch Management endpoints from #2110 (ZH)
2026-05-20 13:36:37 +08:00
Evo c11e19fdcd docs(mcp): document list_watches and cancel_watch in MCP integration table (#2110) (#2134)
* docs(mcp): document list_watches and cancel_watch in MCP integration table (#2110)

* docs(mcp): mirror Watch tools table update to zh guide (#2110)
2026-05-20 13:35:38 +08:00
t0saki 41a33ec16a feat(mcp): progressive single-entrypoint upload for local files (#1847)
* feat(mcp): progressive single-entrypoint upload for local files

Extends `add_resource` MCP tool to handle local-file paths via a server-orchestrated
two-step flow, eliminating the need for `ov` CLI in sandboxed agent environments
(Claude web, Manus) where local FS is unavailable and CLI install is blocked.

Behavior:
- Remote URL  → unchanged.
- Local path  → server mints a 6-char base62 token, returns prose Step 1 / Step 2
                instructions pointing at /api/v1/resources/temp_upload_signed.
                Agent uploads, then re-calls add_resource(temp_file_id=...).
- temp_file_id → resolved against per-tenant subdir, ingested via existing pipeline.

Token: in-memory dict, 10-min TTL, dict.pop doubles as replay protection.
Per-tenant temp-dir isolation ({root}/{aid}/{uid}/{tfid}); legacy CLI uploads
keep flat layout via dual-lookup in resolve_uploaded_temp_file_id.

Public base URL resolves env > config > listen-host fallback (12-factor: runtime
env trumps image-baked config; production deployments behind MCP proxy + nginx
must set OPENVIKING_PUBLIC_BASE_URL since the agent-facing URL is not derivable
from the server's request scope).

* feat(mcp): infer public base URL from request headers + emit fallback hint

Adds a third fallback layer between explicit operator config and listen-host
fallback: capture X-Forwarded-Host / X-Forwarded-Proto / Host headers in the
MCP identity middleware and use them when neither OPENVIKING_PUBLIC_BASE_URL
nor ServerConfig.public_base_url is set.

Resolution order is now: env > config > X-Forwarded-* > Host > listen-host.
The first two are explicit; the rest are inferred. When an inferred source is
used, the add_resource prose response appends a troubleshooting hint asking
the user to set OPENVIKING_PUBLIC_BASE_URL on the server if upload fails —
because inferred URLs can be wrong if the reverse-proxy chain doesn't forward
X-Forwarded headers, or if the server listens on 0.0.0.0.

Documents the variable in docker-compose.yml (commented-out env block) and
in the MCP integration guides (zh + en) — covers when it's required and the
full resolution chain.

* fix(mcp): address Copilot review on PR #1847

- Relax temp_file_id regex from `[a-zA-Z0-9]+` extension to any non-separator
  chars, and dedupe to a single TEMP_FILE_ID_RE in local_input_guard. The old
  pattern rejected `Path("report.my-file").suffix == ".my-file"` and similar
  legitimate filenames, breaking the progressive upload flow.
- Hoist `_resolve_temp_or_path` import to module level in mcp_endpoint
  (verified no circular import).
- Add `_is_safe_namespace_component` defense-in-depth at the signed-upload
  route so a future code path that mints tokens from less-trusted input
  still cannot escape the per-tenant directory.
- Broaden partial-file cleanup to any exception via try/finally + flag,
  not just HTTPException — prevents OSError/IO failures from leaving
  half-written files behind.
- Scope `_cleanup_temp_files` to the tenant subdir at the signed-upload
  route to bound the rglob scan; the legacy `/temp_upload` route still
  cleans the root level.
- Add round-trip test for unusual filename extensions (.my-file, .bak~, .中文).

* docs(mcp): reflect server-minted temp_file_id in progressive-upload flow

Post-rebase onto TempUploadStore, the agent no longer learns the temp_file_id
from the MCP prose — the server mints it at upload time and returns it in the
JSON response body. Update both en + zh docs accordingly. Also note that the
signed endpoint shares the same persistence layer as /temp_upload, so
local/shared modes (and multi-worker via shared) apply uniformly.

* fix(mcp): address Copilot review on rebased PR #1847

- Drop `upload_signed_max_bytes` config field. The signed endpoint now relies on
  TempUploadStore's streaming `temp_upload.shared_max_size_bytes` check (single
  source of truth, fires even when Content-Length is missing/chunked). Map
  oversize from InvalidArgumentError back to 413.
- Normalize `X-Forwarded-Host` / `X-Forwarded-Proto` to the first comma-separated
  value in `_resolve_public_base_url`, matching the OAuth issuer resolver. Fixes
  malformed upload URLs under multi-hop proxy chains.
- Complete the `public_base_url` field comment to reflect all five fallback layers
  in the resolver, not just env > field > listen.
- Add `watch_interval` / `to` parameters to the MCP tool tables in both en + zh
  integration guides — they were merged in from main's Watch Management API
  during the rebase but the table wasn't updated.
2026-05-19 12:32:45 +08:00
Qin Haojie 9846bbca5d fix(vlm): honor LiteLLM native routes (#2111) 2026-05-18 17:11:01 +08:00
Qin Haojie 578148a855 docs: clarify resource API field names (#2107) 2026-05-18 14:57:43 +08:00
Simon Shiandqin-ctx 72b407ffa8 feat(embedder): expose encoding_format for OpenAI/Azure providers (#2092)
* feat(embedder): expose encoding_format for OpenAI/Azure providers

The OpenAI Python SDK 2.x defaults to encoding_format="base64" so the
client can decode embeddings into native float arrays locally. Some
self-hosted or vendor-fronted OpenAI-compatible gateways cannot
deserialize base64 embedding payloads coming back from upstream models
and silently hang for tens of seconds before returning HTTP 500 (e.g.
gateways that wrap providers like Qwen, GLM, Doubao, etc. behind a
strongly-typed Java SDK).

Add an optional `encoding_format` field on EmbeddingModelConfig that
gets forwarded to OpenAIDenseEmbedder. The field is unset by default,
so existing deployments keep the SDK's default behavior. Users hitting
the base64 incompatibility can set:

    "embedding": {
      "dense": {
        "provider": "openai",
        "encoding_format": "float",
        ...
      }
    }

Wiring is intentionally limited to provider="openai" and
provider="azure" — the only two factory branches that route to
OpenAIDenseEmbedder for an actual upstream HTTP gateway. Other
providers either don't expose this knob (volcengine/vikingdb/jina/...)
or run against local stacks where the issue cannot occur (ollama).

* test(embedder): improve encoding_format validation error handling

- Add ValidationError import from pydantic for explicit exception handling
- Update test_rejects_unknown_value to assert ValidationError instead of generic Exception
- Improve test specificity by catching the exact validation error type raised by pydantic models

* docs(embedder): complete encoding_format configuration guide

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-05-18 14:13:03 +08:00
Evo b1c3936ae5 docs(en/metrics): add per-channel one-turn resolution PromQL example from #2037 (#2082) 2026-05-18 14:08:23 +08:00
Evo 2146f85b99 docs(deployment): document embedding + ollama probes on /ready from #1910 (#2086)
* docs(deployment): document embedding + ollama probes in /ready response (EN)

* docs(deployment): document embedding + ollama probes in /ready response (ZH)
2026-05-18 14:07:15 +08:00