Commit Graph

575 Commits

Author SHA1 Message Date
Peter Steinberger cad34e612f feat(channels): add Matrix and LINE join introductions (#131128)
Introduce on admitted bot joins using the existing sealed no-tools turn and durable room dedupe. Matrix uses room metadata and readable history; LINE uses group names and explicitly unavailable history.

Mark Matrix bridge membership provenance without changing existing event delivery, invite handling, or auto-join. Exclude startup snapshots and already-joined profile updates, including startup connection recovery.

Simplify snapshot budget accounting while preserving prompt bytes, metadata order, and oldest-first message dropping. Add channel config, docs, and regression coverage.
2026-08-27 12:52:55 -07:00
Peter Steinberger 706a06eab6 refactor(channels): consolidate account logout cleanup (#130976)
* refactor(channels): consolidate account logout cleanup

* fix(channels): initialize local logout plugins
2026-08-27 09:18:11 -07:00
Peter Steinberger 395e5db41b chore(deps): refresh dependencies after seven-day cooldown (#130296)
* chore(deps): refresh cooled npm and plugin dependencies

* chore(deps): refresh cooled build and workflow tooling

* chore(deps): retain formatter compatibility

* chore(deps): retain lint compatibility
2026-08-26 16:13:18 -07:00
Peter Steinberger 4eea0d3e27 refactor(channels): remove redundant private runtime facades (#130186)
* refactor(channels): remove private runtime facades

* test(channels): refresh retired facade contract guards
2026-08-26 11:22:29 -07:00
Peter Steinberger 60e3d5f194 fix: prevent Feishu and Mattermost suite collection stalls (#130142)
* test(extensions): narrow ingress state import graph

* test(extensions): migrate ingress-only state imports

* test(extensions): sync xai ingress boundary alias

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-26 08:00:58 -07:00
Peter Steinberger 0a185b4c50 fix(line): preserve quick replies after rejected rich messages (#130076) 2026-08-26 05:20:02 -07:00
Peter Steinberger 820e7d0efa fix(line): preserve rich message source order (#129916)
* fix(line): preserve rich message source order

* fix(line): preserve final rich-reply action carrier
2026-08-26 01:34:14 -07:00
Peter Steinberger 9b77c06bbd fix(channels): honor trusted plugin activation contracts (#114492)
* fix(channels): validate activation through trusted channel owners

* refactor(channels): simplify credential contract detection

* test(channels): require complete Slack activation credentials

* test(channels): type trusted installed Slack owner fixture

* test(channels): preserve literal types in owner state fixtures
2026-08-25 22:55:17 -07:00
Peter Steinberger 4c4152e71d fix(channels): honor supported group history limits (#129710)
Co-authored-by: ayaangazali <ayaangazali.work@gmail.com>
2026-08-25 18:23:07 -07:00
Eden f3081bcb50 fix(line): preserve full Flex action labels up to LINE's limit (#128712)
* fix(line): preserve provider-native Flex action labels

Preserve LINE Flex action labels through destination-specific normalization while retaining template, quick-reply, callback, and URL safety limits.

Co-authored-by: 許元豪 <146086744+edenfunf@users.noreply.github.com>

* test(line): narrow Flex action-card component types

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-08-25 12:43:03 -07:00
Peter Steinberger 4dc7bb7411 chore(deps): refresh dependencies after seven-day cooldown (#129187)
* chore(deps): refresh dependencies after cooldown

* fix(gateway): emit append-only Responses content events

* chore(deps): retain unverified Sherpa runtime
2026-08-25 05:00:46 -07:00
xingzhou 736a03f9ad fix(line): prevent unbounded provider response buffering (#119099)
* fix(line): bound provider response bodies

* fix(line): preserve provider status on body errors

* test(line): keep response bounds coverage under lint budget

* test(line): cover bounded retry conflict responses

* chore(line): shrink assertion safety baseline
2026-08-25 01:13:58 -07:00
Peter Steinberger 234df15a6d chore: refresh dependencies after seven-day cooldown (#128414)
* build(deps): refresh dependencies after cooldown

Apply dependency, toolchain, action, image, and exact tool updates released by the inclusive 2026-08-16 seven-day cutoff. Adapt owner boundaries for the resulting CUA, logging, Teams, Markdown, native, and test-harness contract changes while retaining versions blocked by upstream compatibility constraints.

* fix(ui): align markdown renderer env typing

* fix(deps): align postcss and mistral peer contracts

* fix(deps): repair refreshed dependency contracts

* fix(deps): retain tslog startup budget

* fix(ci): verify Android tools with SHA-256

* fix(ci): fence Android SDK cache version
2026-08-24 03:01:54 -07:00
Peter Steinberger 04d174584d perf(line): skip empty inbound media projection (#127827)
Co-authored-by: Amp <amp@ampcode.com>
2026-08-22 02:42:05 -07:00
Eden 14b59a06f5 fix(line): deliver a location LINE cannot render instead of dropping it (#126298)
* fix(line): deliver a location LINE cannot render instead of dropping it

A location whose title or address is blank makes LINE reject the whole
request, so every delivery path filtered it out before sending. The reply
then arrived without the pin, and nothing told the user or the operator that
a part of the message had been removed: the coordinates the sender supplied
were discarded silently.

The location builder now answers with the values the sender wrote — the
non-blank label plus the coordinates — as a text message, so an unrenderable
pin degrades into something the chat can show instead of disappearing. Both
delivery paths inherit that from the single builder, and the three call sites
that used to skip a null result no longer have a branch to take.

Live validation against the Messaging API confirms the shape: the authored
location is rejected with "May not be empty" on messages[0].address, the same
rejection kills an entire batch that also carries valid text, and both
degraded forms validate cleanly.

* fix(line): bound the location fallback to LINE's text limit

Nothing caps the location labels at the schema, so a long title with a blank
address produced one raw text message past LINE's 5,000-character limit — the
provider rejected it and the location was lost exactly as silently as before.

The pin path already caps each label at 100 characters. Name that limit and
apply it in the fallback too, so both forms carry the same bound instead of
one of them re-deriving the provider's rules.

* test(line): merge the duplicate send.js imports
2026-08-20 00:29:51 +08:00
Peter Steinberger d8ebe85c24 refactor(line): replace nine-marker prompt DSL with typed rich messages (#124755)
* refactor(line): replace nine-marker prompt DSL with typed rich messages

Delete the LINE plugin's double-bracket marker language (quick_replies,
location, confirm, buttons, media_player, event, agenda, device,
appletv_remote) and its parser. Portable interactions now flow through the
existing presentation-block seam (renderPresentation, matching Discord and
Feishu); LINE-specific cards ride closed channelData.line schemas mapped to
the existing Flex renderers. Prompt section shrinks to four capability
lines and explicitly de-fangs marker text. Removes the stale
assertion-safety baseline entry for the deleted parser.

Production LOC net -69, tests net -433. Suite: 510/510 green.

* fix(line): declare rich message schema dependency

* fix(line): satisfy rich message type checks

* docs(line): mark card fragments as partial
2026-08-16 12:45:39 -07:00
Eden 12138d2cee fix(line): retry lost pushes without duplicating an accepted send (#124464)
A LINE push made exactly one attempt, so a transient provider or transport
failure dropped the reply even though retrying was safe to do. Retrying alone
would have duplicated a send LINE already accepted, so every push now carries an
X-Line-Retry-Key and reuses it across attempts: LINE answers a replayed key with
409 and the accepted request's sent messages, which resolves to the original
delivery instead of a second message.

Retries follow LINE's documented policy - server errors and transport failures
only, never 2xx, 409 or any 4xx - and run through the shared channel API retry
runner in strict mode. Replies stay single-attempt because LINE offers no retry
key for them.
2026-08-16 15:21:20 -04:00
Peter Steinberger 568b920b21 feat(lint): enforce import ordering and deduplication (#124730)
* refactor(imports): dedupe and hoist imports

* feat(lint): enforce import/no-duplicates and import/first
2026-08-16 11:44:52 -07:00
Peter Steinberger 63401b730b fix: keep doctor security conditions as single findings (#124666)
* fix(doctor): record security finding severity

* refactor(security): keep audit severity internal

* fix(security): preserve channel finding severity
2026-08-16 10:24:40 -07:00
Peter Steinberger ea77e21646 perf(test): remove ingress capacity waits (#124630) 2026-08-16 07:15:33 -07:00
Peter Steinberger 51964c1eee fix(line): bound inbound media response bodies (#124606) 2026-08-16 06:52:56 -07:00
Peter Steinberger c0824d284e test(extensions): remove type-only probe contracts (#124190) 2026-08-15 08:02:07 -07:00
Peter Steinberger f0d277277b test(perf): assert live duplicate tombstones (#124012) 2026-08-14 21:45:48 -07:00
Peter Steinberger 81e0cf0d1d test: replace ingress waits with stop barriers (#123990) 2026-08-14 20:59:52 -07:00
Josh Avant 97a53a9b35 feat: audit admitted channel participant identity (#122863)
* feat: audit admitted channel participant identity

* fix: preserve Telegram identity through thread recovery

* fix: signal held gateway process groups

* fix: keep audit evidence passive in collect routing

* fix: validate copied channel participant evidence

* fix: bind channel participant evidence to host ingress

* fix: honor Telegram proof credential roles

* fix: restart held Telegram proof through gateway

* fix: repair channel identity CI regressions

* test(matrix): bind thread routing owner

* fix: preserve direct DM SDK compatibility

* fix: bind channel provenance at host runtime

* test(feishu): provide channel context builder

* fix: defer record-bound channel runtime resolution

* fix: keep channel admission evidence core-private

* fix(audit): bind channel admission to plugin lifecycle

* fix(audit): bind ingress provenance to final context

* refactor(audit): split admission scope keys

* test(queue): cover combined metadata carriers

* refactor(audit): keep lifecycle helpers private

* fix(queue): preserve combined turn authority

* test(channels): provide ingress context builders

* test(channels): align integrated CI fixtures

* test(clickclack): resolve model-loop ingress

* docs: preserve channel participant evidence invariant
2026-08-14 08:57:01 -05:00
Peter Steinberger 40af3646d7 test(extensions): remove shared helper replays (#122773) 2026-08-12 12:19:38 -07:00
Peter Steinberger 99d662473c fix(channels): fail-fast headless channel setup with plugin-declared env contracts (#122530)
* fix(channels): validate headless channel setup

* docs(channels): document headless provisioning

* fix(channels): repair setup metadata typing

* chore(channels): regenerate official channel catalog for env metadata

* fix(slack): keep mode-conditional env contract plugin-owned

Static --use-env declaration keeps only the unconditional SLACK_BOT_TOKEN;
socket-vs-HTTP conditional requirements (app token, signing secret) stay in
Slack's own setup validation so HTTP mode no longer demands an irrelevant
SLACK_APP_TOKEN.

* chore(sdk): regenerate api baselines and catalog after rebase

* fix(slack): align manifest env declaration with runtime contract

* chore(sdk): regenerate api baselines after rebase

* chore(sdk): regenerate api baselines after rebase

* chore(sdk): regenerate api baselines after rebase
2026-08-12 17:12:15 +00:00
Masato Hoshino 504badbfb1 fix(line): treat a non-positive mediaMaxMb as unset (#121184)
`channels.line.mediaMaxMb` has no range constraint, so a configured `0` or
negative value loads cleanly and then survives the `??` chain in `createLineBot`
into `mediaMaxBytes`. Every non-empty inbound media download is then measured
against a 0-byte budget it cannot satisfy: `saveMediaStream` throws
`Media exceeds 0MB limit`, the LINE handler degrades the attachment to
`[line attachment unavailable]`, and the only trace is a verbose log line that
never names the setting.

Treat a non-positive value as unset at every link of the chain, so it falls back
to the same 10 MB default an unset field already means, and a non-positive
caller override no longer discards a valid account config value. Matrix
(#120466) and Zalo (#120988) resolved the identical contract the same way; LINE
was the last bundled channel resolving this field by hand without the guard.

Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
2026-08-10 22:30:10 -05:00
Peter Steinberger b6b937d6ac chore(types): give test helpers nameable exported types (#121783) 2026-08-10 18:17:50 -07:00
Peter Steinberger da4a656cdb improve: doctor migration checks no longer load every bundled plugin runtime (#120678)
* perf(plugins): declare doctor contract surfaces

* perf(doctor): slim migration import closures

* perf(plugins): narrow doctor declaration record surface and wire owner-test lane

Registry records carry only the doctorContract declaration instead of the whole
parsed manifest, and check:changed now selects the src/plugins-owned declaration
honesty and closure-guard tests for extension module/manifest changes so
cross-lane drift cannot pass PR classification.

* fix(doctor): keep control-plane dist imports require-safe

Keep doctor and channel control-plane chunks off exec-class dependencies, and enforce native require(esm) loading during postbuild.

* chore(plugin-sdk): regenerate API baseline

* chore(plugin-sdk): sync export ordering

* fix(plugins): satisfy doctor contract CI boundaries

* perf(doctor): make qqbot doctor closure dependency-light

qqbot was the last plugin above 5s in doctor state-migration enumeration
(~8s under tsx/jiti). The cost was not the state-key builder (already a
leaf): its doctor closure value-imported the runtime-doctor SDK barrel,
whose plugin-state-store/state-db re-exports pull kysely (~330 modules),
plus security-runtime for one fileExists (~200 modules), all resolved
per-module by jiti during enumeration.

Split the migration-define helpers and light re-exports into a new
private-local plugin-sdk/runtime-doctor-migrations subpath; runtime-doctor
re-exports it so its public surface is byte-identical (API baseline hash
unchanged). qqbot's doctor-contract and state-migrations now import only
the light subpath, swapping fileExists for the equivalent async
legacyStateFileExists already in the closure.

qqbot enumeration: ~8.0s/531 modules -> ~0.25s/18 modules.

* chore(plugin-sdk): drop private-local subpath from API baseline

runtime-doctor-migrations is private-local-only; the baseline tracks public
modules, and the earlier line was generated before the classification.

* fix(plugins): register runtime-doctor-migrations boundary paths

The private-local subpath list feeds the extension package boundary map;
the shared paths config and xai's derived overrides must carry the same
entry or the boundary contract test fails.
2026-08-08 13:29:18 -07:00
Peter Steinberger 48639663b0 chore(release): prepare 2026.8.1 (#120375) 2026-08-07 18:44:12 -07:00
Peter Steinberger 60a8ec821c refactor(plugins): reuse canonical error coercion (#119451) 2026-08-04 21:05:45 -07:00
Peter Steinberger f9d9d1225a refactor(channels): own the lifecycle status contract in SDK patch factories (#118795)
* refactor(sdk): add channel lifecycle patch factories

* refactor(channels): adopt lifecycle patches in a-m

* refactor(channels): adopt lifecycle patches in n-z

* refactor(runtime): lifecycle-own ambient registries

* test(slack): assert lifecycle factory fields

* fix(sdk): preserve lifecycle patch extras types

* test(zalouser): widen lifecycle status sink

* test(irc): avoid shadowed status patch

* fix(zalo): reuse account-agnostic media route

* fix(gateway): accept explicit channel ready recovery

* test(qa): assert terminal Slack block fact

* test(qa): restore Slack blocked lifecycle scenario

* test(gateway): lock explicit lifecycle recovery contract
2026-08-03 12:39:48 -07:00
Vincent Koc 21a767639f fix(plugins): unify HTTP route conflict handling (#118203)
* fix(plugins): unify HTTP route conflict handling

* fix(plugins): preserve source-less route replacement

* test(line): type webhook route source
2026-08-04 02:15:00 +08:00
clawsweeper[bot] e402606c71 fix(line): clear default access token when removing account (#118055)
* fix(line): clear default access token when removing account

* fix(line): clear default access token when removing account

---------

Co-authored-by: clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>
2026-08-03 05:20:38 -07:00
Peter Steinberger 4c66ed5615 feat(channels): lifecycle wave 2 — fifteen more channels publish recorded lifecycle (#118298)
* feat(channels): publish lifecycle from existing status sinks

* feat(channels): thread lifecycle through provider monitors

* fix(mattermost): keep lifecycle status helper private

* fix(matrix): preserve terminal lifecycle during startup cleanup

* fix(matrix): reject invalid tokens during startup

* test(mattermost): drop unused vi import
2026-08-02 17:30:56 -07:00
clawsweeper[bot] 492b8841c8 fix(line): skip invalid location messages before delivery (#118064)
Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
2026-08-02 12:17:24 -05:00
Peter Steinberger bd86a69d1c fix(line): preserve semantic indentation in fenced code (#117996)
Co-authored-by: Peter Steinberger <steipete@macos.shared>
2026-08-02 06:59:28 -07:00
wangyan2026 70394e190c [AI] fix(line): downgrade row-overflow tables to ordered bullet text (#117481)
Add tableRowCap() pre-check before Flex conversion so row-overflow
tables route through formatOversizedTableAsBullets() + segments instead
of being silently truncated by the renderer's slice(0,10/12).

- tableHasInlineMarkup() reuses renderTableCell's canonical hasMarkup
- processLineMessage checks row count before convertTableToFlexBubble
- convertTableToFlexBubble shares tableHasInlineMarkup for layout decision
- Delivery-boundary tests in auto-reply-delivery.test.ts
- Runtime artifact tests with LINE SDK provider-facing proof

Co-authored-by: Peter Steinberger <steipete@macos.shared>
2026-08-02 00:11:23 -07:00
Peter Steinberger e98fdeefdf refactor(errors): consolidate message formatting (#117818) 2026-08-01 22:05:49 -07:00
Peter Steinberger eda7cab081 refactor(line): remove dead card helpers (#117729) 2026-08-01 18:48:40 -07:00
Peter Steinberger 568ea29d2e refactor(plugins): inherit shared package boundary settings (#117474) 2026-08-01 09:11:09 -07:00
Peter Steinberger a88f3ffc96 fix(line): preserve ordered oversized table delivery (#117335)
* fix(line): preserve ordered delivery of oversized markdown tables

* fix(line): type ordered delivery at provider and test boundaries

* fix(line): narrow ordered provider messages to flex or text

---------

Co-authored-by: Peter Steinberger <steipete@macos.shared>
2026-08-01 03:44:30 -07:00
Peter Steinberger 8b7fad18ec fix(line): centralize card and template message alt text (#117280)
* fix(line): unify card and template alternative text limits

* test(line): use synchronous provider request listener

---------

Co-authored-by: Peter Steinberger <steipete@macos.shared>
2026-08-01 01:17:34 -07:00
Ayaan Gazali 11069c3df5 fix(channels): config validation rejects documented channels.<id>.configWrites on 13 channels (#117206) 2026-08-01 15:33:16 +08:00
Peter Steinberger 0a146d5a18 fix(line): centralize Flex alternative-text bounds (#117217)
Co-authored-by: Peter Steinberger <steipete@macos.shared>
2026-07-31 23:23:52 -07:00
Peter Steinberger 45f274f757 fix(line): avoid replaying ambiguous auto replies (#117126)
Co-authored-by: Peter Steinberger <steipete@macos.shared>
2026-07-31 17:32:53 -07:00
Peter Steinberger 9e4381eb1c refactor(channels): unify bundled channel setup contracts (#117106)
* refactor(channels): canonicalize bundled setup contracts

* test(matrix): use scoped environment fixtures
2026-07-31 16:57:29 -07:00
Peter Steinberger a39f0b7ea3 fix(channels): preserve accepted LINE and Mattermost delivery (#117024)
* fix(channels): preserve accepted delivery identities

* fix(channels): satisfy accepted-delivery owner boundaries

---------

Co-authored-by: Peter Steinberger <steipete@macos.shared>
2026-07-31 14:28:55 -07:00
Peter Steinberger 50771abc6a fix(line): preserve provider delivery receipts and completed sends (#116879)
* fix(line): preserve provider message ids in receipts

* fix(line): unify legacy text delivery receipts

---------

Co-authored-by: Peter Steinberger <steipete@macos.shared>
2026-07-31 07:52:16 -07:00