1. 18 Jun, 2026 2 commits
    • feat(openapi): refine API key auth proxy and app isolation (#7126) · e24fef92
      * feat(openapi): allow app-level API Key display and restrict scope
      
      - Expose raw API Key in app-level listing to support key replication
      - Restrict app-level API Key usage to chat completion endpoints only
      - Add COPY_API_KEY audit event for tracking key access
      - Implement API Key request path validation for security enforcement
      
      * feat(openapi): support API key auth proxy for team members
      
      - Add `authProxy` configuration to team-level API keys.
      - Implement `ChatCompletionAuthProxy` schema for optional identity
        delegation in chat completion requests.
      - Add `resolveChatCompletionEffectiveTmbId` to handle proxy logic,
        ensuring members exist within the key's team.
      - Update `authChatCompletionHeaderRequest` to integrate identity
        proxying while maintaining strict security boundaries for chat access.
      - Add internationalization support for the new feature in settings.
      
      * feat(openapi): distinguish global and app API keys
      
      - Update documentation to clarify the distinction between Global and App
        API keys.
      - Enforce `authProxy` permissions: only allow team owners to enable
        `authProxy` on Global API Keys.
      - Restrict `authProxy` usage to Global API Keys; App API Keys do not
        support this feature.
      - Migrate API key management UI to `MyModalV2`.
      - Add test coverage for API key update permissions.
      
      * fix(openapi): update new API key tip copy
      
      * fix(openapi): copy API key without modal
      
      * fix(openapi): address API key review comments
      
      * fix(openapi): ensure API key copy audit completes
      Finley Ge committed
    • feat(app): filter unavailable tools in system tool selector (#7138) · 741ad4e2
      - Add `status` field to system tool schemas and definitions.
      - Implement `isSelectableToolStatus` to restrict tools displayed in the
        creation/selection list to those with 'Normal' status.
      - Update `getSystemToolTemplates` API to filter root tools and toolset
        children based on their status.
      - Add unit tests to verify tool filtering logic.
      Finley Ge committed
  2. 17 Jun, 2026 3 commits
    • refactor: align system tool JSON schema codec (#7116) · ffa1037a
      * refactor(core): optimize system tool input/output schema management
      
      - Use `JSONSchema` instead of `InputConfig` for system tool I/O
        definitions
      - Centralize JSON Schema to Node I/O conversion utilities
      - Cleanup redundant type definitions and schema properties across
        packages
      
      * refactor(app): optimize SecretInputModal UI and logic
      
      - Migrate to updated MyModal component and refactor layout
      - Update input styling and placeholder logic
      - Add missing input controller for 'input' type fields
      
      * refactor(global): improve workflow JSON schema mapping and tool catalog
      
      - Update `getJsonSchemaPropertyFromValueType` to handle complex types
        like `arrayObject` and `chatHistory` properly instead of falling back
        to default types.
      - Refactor `getEnumValuesFromNodeInput` to correctly collect enum values
        from different input configurations.
      - Update `useToolCatalog` to use `nodeInputs2JsonSchema` for consistent
        schema generation across tools and nodes.
      - Add comprehensive test cases to verify JSON schema conversion for
        various value types and enum sources.
      
      * perf: get tool client code
      
      * chore: avoid schema loading for tool display metadata
      
      * perf: tool throw error
      
      ---------
      
      Co-authored-by: archer <545436317@qq.com>
      Finley Ge committed
    • Fix/http nodes (#7111) · cc59ee8b
      * feat: add httpFullError output handling and localization support
      
      * refactor: remove ensureHttp468Outputs, rely on template output merge
      
      * perf: http code
      
      * doc
      
      * fix: test
      
      ---------
      
      Co-authored-by: archer <545436317@qq.com>
      siigure committed
  3. 16 Jun, 2026 13 commits
    • Fix chat (#7131) · da3d14bc
      * fix: interactive
      
      * fix: test
      Archer committed
    • fix: slider title (#7130) · a6fc27f6
      Archer committed
    • fix(sandbox): resolve inotify infinite loops & proxy loopback connection (#7129) · eb27fafe
      * Update repository.ts
      
      * refactor(fastgpt): update default fastgpt-ide-agent image to ghcr.io
      DigHuang committed
    • fix: action (#7128) · a1674a5f
      * fix: action
      
      * perf: modal
      
      * fix: openapi
      Archer committed
    • refactor(app): optimize tool selector UI/UX (#7127) · 4f30121d
      Refactor tool selector and modal layout to improve responsiveness and
      consistency. Update grid structures, adjust padding and sizing, and
      streamline component interaction flows.
      Finley Ge committed
    • feat: chat title generate (#7120) · 2a715bcc
      * perf: chat title generation
      
      * fix: ts
      
      * test: align sandbox proxy secret validation error
      
      * perf: zero point
      Archer committed
    • fix: 数据集更新接口不支持 API Key 鉴权 (#7006) (#7123) · ff03d538
      问题 (#7006):
      
      通过 API Key 调用知识库更新接口(api/core/dataset/update)返回 403
      unAuthorization。API Key 可正常使用 list/create/delete,唯独 update 报错。
      
      根因:
      
      update.ts 中 authDataset/authUserPer 调用缺少 authApiKey: true。
      parseHeaderCert() 默认 authApiKey=false,API Key 鉴权分支不会被执行,
      请求走到末尾被拒绝。
      
      对比其他端点:
      - create.ts — authDataset({ authApiKey: true, ... }) ✓
      - collection/create.ts — authDataset({ authApiKey: true, ... }) ✓
      - collection/list.ts — authDataset({ authApiKey: true, ... }) ✓
      - update.ts — authDataset 和 authUserPer 均缺少 authApiKey ✗
      
      改动:
      
      update.ts 四处调用各添加 authApiKey: true:
      1. authDataset 主入口 Read 权限检查 (L88)
      2. authDataset 移动目标文件夹 Manage 权限检查 (L109)
      3. authDataset 移动源文件夹 Manage 权限检查 (L122)
      4. authUserPer 移动至/从根目录的团队创建权限检查 (L132)
      
      测试:
      
      新增 projects/app/test/api/core/dataset/update.test.ts:
      - token 认证更新数据集
      - API Key 认证更新数据集
      
      Fixes #7006
      
      Signed-off-by: DadaVinqi <DadaVinqi@users.noreply.github.com>
      Co-authored-by: DadaVinqi <DadaVinqi@users.noreply.github.com>
      DadaVinqi committed
    • feat(sandbox): migrate to standalone Rust proxy and implement stateless WSS… · 0b86c361
      feat(sandbox): migrate to standalone Rust proxy and implement stateless WSS gateway with dynamic file sync (#7034)
      
      * feat(sandbox): implement stateless WSS gateway, Rust agent-proxy service, and interactive terminal
      
      - Implement stateless WSS gateway for agent-sandbox connection.
      - Migrate WSS proxy to a standalone Rust service.
      - Integrate interactive PTY terminal and clean up obsolete APIs.
      - Add unit & integration tests for Rust proxy & agent with CI workflow.
      - Unify proxy secrets under AGENT_SANDBOX_PROXY_SECRET.
      - Implement fine-grained session ticket permissions & enhance proxy log security.
      
      * refactor(sandbox): upgrade agent & proxy to Rust 2024, optimize file operations, and support connection limiting
      
      - Implement dynamic file change sync with debounce and robust connection limiting.
      - Upgrade Rust dependencies, split ide agent modules and enhance file access security.
      - Optimize Docker build targets, configure default Sealos image, and implement native file operations.
      - Support dynamic gateway hostnames, add proxy ping keepalive, and refine terminal resize checks.
      - Upgrade to Rust 2024, secure workspace operations, and refine adapter helpers.
      
      * feat(skill): redesign skill detail page with split layout and refine sandbox editor styling
      
      * refactor(sandbox): optimize edit-debug hot-reload and skip S3 pull on cold-start
      
      - Refine edit-debug sandbox hot-reload and auto resume logic.
      - Skip S3 pull on cold-start when volume exists and fix OpenSandbox getInfo.
      
      * feat(sandbox): implement cold archive and restore, unify file limits, and relax proxy secret
      
      * style(skill): adjust chatbox and input layout padding for skill detail page
      
      * feat(sandbox): add archive migration API and restore   support for empty or archived workspaces
      
      refactor(sandbox): enhance workspace archiving/restore, zip safety, and websocket stability
      
      * feat(sandbox): migrate archived records across providers, adjust probe timeout and command limits
      
      * feat(skill): add preview empty state, disable sending before sandbox ready, and unify error handling
      
      * refactor(skill): simplify export, fix import encoding, and use default LLM
      
      * feat(sandbox): ensure zip availability and track archiving failures
      
      * feat(sandbox): refactor workspace fs watcher with debouncer, improve terminal styling, and add archive progress tracking
      
      - rust ide agent: Integrate notify-debouncer-full to debounce workspace file system events and broadcast batches with sequential numbers to handle lagged events.
      - frontend/sandbox: Remove client-side debounce in favor of backend debouncing, refine workspace file tree refreshing, and adjust terminal background and horizontal padding.
      - archive: Introduce onProgress callback for resource archiving and utilize it in initSandboxArchive API to log real-time progress and errors.
      
      * docs(skill): comprehensive user guides for agent skills
      
      * refactor(sandbox): improve TS safety, simplify markdown frontmatter, and support sandboxToolMap info
      DigHuang committed
    • fix: update pro modal titles in multiple languages for consistency (#7107) · 7bf0b268
      * fix: update pro modal titles in multiple languages for consistency
      
      * feat: add commercial dataset type handling and pro modal integration
      
      * perf: pro modal ui
      
      ---------
      
      Co-authored-by: archer <545436317@qq.com>
      siigure committed
  4. 15 Jun, 2026 4 commits
    • perf: node store (#7112) · 9f383002
      * perf: node store
      
      * revert
      
      * fix: loop
      
      * doc
      
      * feat: source
      
      * perf: store chat
      
      * perf: optimize chat node response preview reads
      
      * perf: speed up persisted node response tree compose
      
      * doc
      
      * perf: depth
      
      * perf: chat anination
      Archer committed
    • folder-depth-limit (#7103) · 4fa14557
      * feat: implement folder depth management and error handling
      
      - Added new error codes for folder depth limits in CommonErrEnum.
      - Introduced folder depth validation logic in the parent folder management.
      - Implemented API for fetching subtree maximum folder depth.
      - Enhanced folder creation and movement operations to respect maximum folder depth constraints.
      - Updated UI components to handle folder depth checks and display appropriate error messages.
      - Localized new error messages in English and Chinese.
      
      * refactor: simplify folder depth limit to backend validation
      
      Remove frontend drag pre-check and subtreeDepth API; rename env to
      MAX_FOLDER_DEPTH with strict IntSchema validation; keep create-folder
      button hiding only.
      
      * perf: limit tip
      
      * chore: remove unrelated folder depth changes
      
      ---------
      
      Co-authored-by: archer <545436317@qq.com>
      siigure committed
    • Chat UI improvement (#7118) · 7d5b6a5c
      * feat: add chat scroll to bottom button
      
      * fix: refine chat history pagination and scrollbar
      
      * refactor: remove chat scroll button delay
      
      * fix: align chat action buttons
      
      * fix: stop chat auto scroll after user scrolls up
      
      * fix: truncate long chat placeholder app name
      
      * fix: refresh chat history silently after title update
      
      * fix: stabilize chat input placeholder text type
      Xianquan committed
  5. 13 Jun, 2026 2 commits
  6. 12 Jun, 2026 6 commits
  7. 11 Jun, 2026 6 commits
  8. 10 Jun, 2026 4 commits