18 Commits
Author SHA1 Message Date
badgerbees 3ed1d5f9d8 fix(feishu): harden API client with defensive HTTP status checks (#407)
- Check resp.StatusCode range (2xx) before JSON decoding
- Provide clear actionable errors with HTTP status codes for 5xx failures
- Prevent cryptic JSON parse errors from HTML error pages
2026-08-05 23:02:41 +07:00
badgerbees 544b6c6532 Providers: strip Gemma 4 reasoning leak (#933) 2026-04-17 19:58:51 +07:00
badgerbeesandViet Tran f5917b0e46 fix(backup): harden tenant restore preview and lookup handling (#920)
* fix(backup): harden tenant restore preview and lookup handling

* test(pg): fix hook test migration path

* test(ci): stabilize race coverage tests

* fix(hooks): scope GetByID and allow loopback tests

* fix(backup): harden tenant restore replace/new contracts + race-safe SSRF flag

- Replace mode no longer deletes the tenants row (FK safe vs excluded
  diagnostic tables: traces, activity_logs, usage_snapshots, spans,
  embedding_cache, pairing_requests, paired_devices,
  channel_pending_messages, cron_run_logs). Metadata is preserved in place.
- shouldRestoreTable now excludes tenants for both new and replace modes.
- CLI: add validateTenantRestoreFlags guardrail. mode=new requires
  --new-tenant-slug and rejects --tenant/--tenant-id; upsert/replace warn
  on stray --new-tenant-slug; invalid --mode values rejected. TAB in help
  text fixed; flag descriptions clarified.
- HTTP: resolveRestoreTarget rejects tenant_id for mode=new regardless
  of tenant_slug (matches CLI contract). New i18n key
  MsgRestoreNewModeRejectsTenantID (en/vi/zh).
- security/ssrf: allowLoopbackForTest switched to atomic.Bool so
  concurrent reads from outbound dialers are race-safe.
- Polish: vi backup.json key order matches en/zh; TenantRestoreOptions.Mode
  doc comment documents upsert/replace/new semantics including clone
  behavior for new.
- Tests: unit coverage for validator (12 cases), HTTP guardrails
  (3 cases), shouldRestoreTable replace branch. Integration test
  tests/integration/tenant_restore_replace_test.go regression-guards
  the FK fix using activity_logs seed + DeleteTenantDataForTest helper.

---------

Co-authored-by: Viet Tran <viettranx@gmail.com>
2026-04-16 15:49:50 +07:00
badgerbeesandViet Tran 770af6b1c0 Vault: handle empty delete responses (#913)
Co-authored-by: Viet Tran <viettranx@gmail.com>
2026-04-15 17:11:32 +07:00
badgerbeesandviettranx 6608e3dafe fix(telegram): preserve Telegram topic routing for delayed notifications (#850)
* Fix delayed Telegram topic routing

* refactor: export TaskLocalKeyMetadata and fix formatting

- Export TaskLocalKeyMetadata from tools package for reuse
- Remove duplicate taskLocalKeyMetadata from tasks package
- Fix gofmt indentation issue in notifyLeaders
- Add trailing newline to team_tool_helpers_test.go

---------

Co-authored-by: viettranx <viettranx@gmail.com>
2026-04-12 17:05:57 +07:00
badgerbees 7fa2d201fb fix(agent): strip internal routing tags from outbound delivery (#416)
- Introduced StripMessageDirectives in the agent loop to remove internal
  [[name:value]] routing tags from user-facing content while preserving
  them in session store for model context
- Narrowed regex from wildcard `(?s)\[\[.*?\]\]` to structured
  `\[\[\w+(?::[^\]\n]+)?\]\]` to avoid false positives on legitimate content
- Preserved [[tts...]] tags for TTS AutoTagged pipeline compatibility
- Added 15 unit tests covering strip, preserve, and edge cases
- Fixed step numbering in agent loop (steps 5-9)
2026-03-24 10:24:10 +07:00
badgerbees 7200ecb7fe feat(providers): add native Azure OpenAI and Foundry header support (#319) 2026-03-21 07:33:18 +07:00
badgerbeesandviettranx 551b6670d5 fix(tools): resolve Windows build errors and harden filesystem security (#318)
* fix(tools): resolve Windows build errors and harden filesystem security

* fix(tools): remove stale Windows skip in hardlink test

Now that checkHardlink uses GetFileInformationByHandle on Windows,
the test should run on all platforms.

---------

Co-authored-by: viettranx <viettranx@gmail.com>
2026-03-21 07:29:48 +07:00
badgerbees adb81d1069 feat(channels): enforce MediaMaxBytes for outbound media uploads in Telegram and Discord (#317) 2026-03-21 07:14:58 +07:00
badgerbees 874923d44b fix(telegram): suppress duplicate messages on high-latency streaming connections (#286)
fix(telegram): suppress duplicate messages on high-latency streaming connections
2026-03-20 18:21:46 +07:00
badgerbeesandviettranx 55bc752773 fix(agent): handle duplicate tool call IDs in OpenAI-compatible transcripts (#283)
* fix(agent): handle duplicate tool call IDs with occurrence-aware sanitization

* refactor(agent): simplify duplicate tool call ID handling

Replace complex occurrence-aware queue system with simpler approach:
- uniquifyToolCallIDs: append runID+iteration+index to all IDs at
  response time, guaranteeing cross-turn uniqueness via UUID
- sanitizeHistory: simple seen-set dedup for legacy sessions with
  pre-existing duplicate IDs, no queue/counter logic needed
- Restore full problem description in sanitizeHistory docstring
- Add unit tests for both dedup paths and edge cases

---------

Co-authored-by: viettranx <viettranx@gmail.com>
2026-03-20 06:32:38 +07:00
badgerbees 9100f981d7 fix(providers): robust Gemini thought_signature detection and history mapping
Improves supportsThoughtSignature with providerType and model normalization.
Strengthens collapseToolCallsWithoutSig with TrimSpace and camelCase support
to handle 'Thinking=OFF' whitespace signatures and proxy key translations.
2026-03-20 00:14:33 +07:00
badgerbees bc16af3797 fix(agent): handle duplicate tool call IDs in OpenAI-compatible transcripts
Simplified approach to fix duplicate tool_call_ids that cause HTTP 400 on OpenAI-compatible APIs (OpenRouter, vLLM, DeepSeek).

- uniquifyToolCallIDs: appends runID+iteration+index to all IDs at response time, guaranteeing cross-turn uniqueness via UUID
- sanitizeHistory: simple seen-set dedup for legacy sessions with pre-existing duplicate IDs
- Anthropic guard: skips ID rewriting when RawAssistantContent is present
- Unit tests for both paths + edge cases

Closes #283
2026-03-20 00:10:52 +07:00
badgerbeesandviettranx 3f9401257c feat(telegram): networking isolation and sticky IPv4 fallback (#278)
* fix(telegram): isolated transport, sticky fallback, and overall timeouts

* fix(telegram): improve networking isolation for high-concurrency

- Tune MaxIdleConnsPerHost to 64 (default 2 starves concurrent sends)
- Fix data race in enableIPv4Only using sync.Once
- Add force_ipv4 config option for explicit IPv4-only mode
- Narrow auto-detect heuristic to "unreachable" only (avoid false-positive on timeouts)
- Use bot username instead of token prefix in logs
- Extract applyIPv4Dialer helper for reuse between config and runtime paths

---------

Co-authored-by: viettranx <viettranx@gmail.com>
2026-03-19 20:45:49 +07:00
badgerbeesandviettranx d46061405f fix(telegram): enforce transport policy and SSRF guard for media downloads
* fix(telegram): thread transport policy into media downloads with SSRF guard

* fix(telegram): trust configured APIServer during media downloads

* fix(telegram): use proper download timeout and clone DefaultTransport

- Clone http.DefaultTransport when proxy is configured to preserve
  connection pool, TLS handshake timeout, and keep-alive defaults
- Use dedicated 5-minute context timeout for media downloads instead
  of the shared 30s client timeout, preventing large file timeouts
  (local Bot API supports up to 200 MB)

---------

Co-authored-by: viettranx <viettranx@gmail.com>
2026-03-17 18:21:45 +07:00
badgerbeesandviettranx 1c4dce0ccf feat(telegram): implement robust message splitting and dynamic HTML retry logic (#236)
* feat(telegram): implement robust message splitting and dynamic HTML retry logic

* fix(telegram): fix sendHTML error chain regression and add split depth limit

- Re-check err.Error() in thread-not-found handler instead of stale errStr,
  restoring the original chained fallback behavior
- Add maxSplitDepth (5) to prevent unbounded recursion when Telegram
  repeatedly rejects split chunks
- Rename misleading test case to reflect actual monolithic fallback behavior

---------

Co-authored-by: viettranx <viettranx@gmail.com>
2026-03-17 13:01:20 +07:00
badgerbees 365f41f81c fix: pass custom name to DashScopeProvider for correct registry lookup (#228) 2026-03-16 22:54:10 +07:00
badgerbees 5c0612a07f fix(providers): prevent Gemini thought_signature from leaking to other providers and breaking validation (#230)
* fix: prevent gemini thought_signature from leaking to other providers

* test: refine gemini model detection for robust provider multiplexing
2026-03-16 22:53:21 +07:00