* fix(crypto): never overwrite Vault root key on transient read failures
Sweep finding B-01
* fix(crypto): clear cached ephemeral root key when Vault persist fails
The InvalidPath create branch cached the freshly generated root key in
self._root_key before encrypting/persisting it. If _encrypt_with_vault or
the KV write failed (transient transit/KV outage), get_root_key raised but
left the never-persisted key cached, so a retry returned it via the
`self._root_key is not None` fast path and encrypted data with a key that
vanishes on restart — the data-loss class this provider guards.
Wrap encrypt+persist in one try and null the cache before raising; add a
regression asserting the cache is cleared and the next call re-reads Vault.
Addresses the blocking review finding on #3423.
* fix(security): clean up code scanning and runtime findings
Harden path and logging boundaries, remove noisy cleanup issues,
and keep observability failures from breaking runtime flows.
* fix(security): close werewolf and feishu validation gaps
Block the remaining path traversal bypass in the werewolf demo,
and validate Feishu hosts on the main parse() entry point.
* fix: decrypt raises 'Ciphertext too short' on plaintext files shorter than 4 bytes
The decrypt() method checked ciphertext length before checking the magic
header. This caused plaintext files shorter than 4 bytes (including empty
files) to raise InvalidMagicError('Ciphertext too short') before the
'is this plaintext?' check could return them as-is.
Fix: swap the order — check if content starts with OVE1 magic first,
then only check length for actual encrypted content.
This fixes failures when append_file() reads an empty messages.jsonl
session file and tries to decrypt it.
* fix: add strict=True to zip() in summarizer (B905 lint)
---------
Co-authored-by: yc111233 <yc111233@gmail.com>
* lisence: change the main lisence from Apache-2.0 to AGPL-v3
* lisence: change the main lisence from Apache-2.0 to AGPL-v3
* lisence: change the main lisence from Apache-2.0 to AGPL-v3
---------
Co-authored-by: openviking <openviking@example.com>