- Standardized CSS variable values for consistency.
- Enhanced layout styles for sidebar navigation and responsiveness.
- Refactored callout styles for better gradient definitions.
- Improved transition properties for smoother UI interactions.
- Added new icons for sidebar functionality and external links.
- Updated HTML structure in app-render for better sidebar management.
- Updated .gitignore to include .ant-colony directory.
- Modified README.md to reflect changes in gateway authentication settings.
- Added a new favicon.svg for improved branding.
- Refactored app.ts to implement theme management and sidebar navigation.
- Introduced sidebar-nav component for better navigation structure.
- Added controllers for overview, presence, and sessions management.
- Enhanced navigation library with new tab definitions and titles.
- Improved overview-view to display gateway health and stats dynamically.
- Updated styles.css for better theming and responsive design.
* feat: add Korean stop words and tokenization for memory search
* fix: address review comments on Korean query expansion
* fix: lint errors - curly brace and toSorted
* fix(memory): improve Korean stop words and deduplicate
* Memory: tighten Korean query expansion filtering
* Docs/Changelog: credit Korean memory query expansion
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
* feat: implement DM history backfill for BlueBubbles
- Add fetchBlueBubblesHistory function to fetch message history from API
- Modify processMessage to fetch history for both groups and DMs
- Use dmHistoryLimit for DMs and historyLimit for groups
- Add InboundHistory field to finalizeInboundContext call
Fixes#20296
* style: format with oxfmt
* address review: in-memory history cache, resolveAccount try/catch, include is_from_me
- Wrap resolveAccount in try/catch instead of unreachable guard (it throws)
- Include is_from_me messages with 'me' sender label for full conversation context
- Add in-memory rolling history map (chatHistories) matching other channel patterns
- API backfill only on first message per chat, not every incoming message
- Remove unused buildInboundHistoryFromEntries import
* chore: remove unused buildInboundHistoryFromEntries helper
Dead code flagged by Greptile — mapping is done inline in
monitor-processing.ts.
* BlueBubbles: harden DM history backfill state handling
* BlueBubbles: add bounded exponential backoff and history payload guards
* BlueBubbles: evict merged history keys
* Update extensions/bluebubbles/src/monitor-processing.ts
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
---------
Co-authored-by: Ryan Mac Mini <ryanmacmini@ryans-mac-mini.tailf78f8b.ts.net>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
Add integration test confirming that runMessageAction with a sandbox
root now accepts media paths under os.tmpdir() through the full
normalization pipeline (normalizeSandboxMediaList → resolveSandboxedMediaSource).
resolveSandboxedMediaSource() rejected all paths outside the sandbox
workspace root, including /tmp. This blocked sandboxed agents from
sending locally-generated temp files (e.g. images from Python scripts)
via messaging actions.
Add an os.tmpdir() prefix check before the strict sandbox containment
assertion, consistent with buildMediaLocalRoots() which already
includes os.tmpdir() in its default allowlist. Path traversal through
/tmp (e.g. /tmp/../etc/passwd) is prevented by path.resolve()
normalization before the prefix check.
Relates-to: #16382, #14174
applyMergePatch in merge-patch.ts iterates Object.entries(patch) without
filtering dangerous keys. When a caller passes a JSON-parsed object with
a "__proto__" key, the loop assigns result["__proto__"] = value, which
replaces the prototype of result and pollutes Object.prototype for the
entire process.
Add a BLOCKED_KEYS set ({"__proto__", "constructor", "prototype"}) and
skip those keys during iteration, matching the guard already present in
deepMerge (includes.ts) via isBlockedObjectKey.
Adds four tests covering __proto__, constructor, prototype, and nested
__proto__ injection.
Co-authored-by: Clawborn <tianrun.yang103@gmail.com>
* feat(channels): add Synology Chat native channel
Webhook-based integration with Synology NAS Chat (DSM 7+).
Supports outgoing webhooks, incoming messages, multi-account,
DM policies, rate limiting, and input sanitization.
- HMAC-based constant-time token validation
- Configurable SSL verification (allowInsecureSsl) for self-signed NAS certs
- 54 unit tests across 5 test suites
- Follows the same ChannelPlugin pattern as LINE/Discord/Telegram
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat(synology-chat): add pairing, warnings, messaging, agent hints
- Enable media capability (file_url already supported by client)
- Add pairing.notifyApproval to message approved users
- Add security.collectWarnings for missing token/URL, insecure SSL, open DM policy
- Add messaging.normalizeTarget and targetResolver for user ID resolution
- Add directory stubs (self, listPeers, listGroups)
- Add agentPrompt.messageToolHints with Synology Chat formatting guide
- 63 tests (up from 54), all passing
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* fix(gateway): allow localhost Control UI without device identity when allowInsecureAuth is set
* fix(gateway): pass isLocalClient to evaluateMissingDeviceIdentity
* test: add regression tests for localhost Control UI pairing
* fix(gateway): require pairing for legacy metadata upgrades
* test(gateway): fix legacy metadata e2e ws typing
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
- Introduced `command-palette`, `bottom-tabs`, and various overview components to improve user navigation and interaction.
- Implemented attention items and event log display for better monitoring of system status.
- Enhanced the overview layout with new cards for usage statistics, session details, and quick actions.
- Added functionality for handling keyboard shortcuts and improved event logging.
- Updated state management to support new dashboard features, including stream mode and log handling.
- Added `attention-center`, `bottom-tabs`, `command-palette`, `connection-badge`, `cron-summary-card`, `dashboard-header`, `event-log`, `log-tail`, `quick-actions`, and `quick-note-stream` components to improve user interaction and functionality.
- Enhanced the main content area with tab change handling and navigation events.
- Updated styles for various components, including improved padding, margins, and responsiveness.
- Introduced new icons and visual elements for better user experience across the dashboard.
- Adjusted padding, margins, and font sizes for better layout and readability.
- Introduced a new glow effect in the welcome section to enhance visual appeal.
- Updated badge and starter card styles for consistency and improved interaction.
- Enhanced responsiveness and dynamic color integration across various elements.
- Integrated dynamic agent color into the chat view, improving visual representation.
- Updated the agent avatar size for better visibility and aesthetics.
- Added a glow effect to the welcome section for enhanced user experience.
- Replaced the previous duty prompts with a new structure for quick-send starter cards, enhancing user interaction.
- Each starter card now includes a label, prompt, and icon for better clarity and engagement.
- Removed the outline expansion state as it is no longer needed with the new starter card implementation.
- Updated related methods to utilize the new starter card format, improving the overall chat experience.
- Added a new `resetSession` function to manage chat sessions effectively.
- Implemented a new button for starting a new chat, which resets the current session and clears chat history.
- Introduced a compact context button for improved user experience.
- Updated styles for chat components, including a new input divider for better layout.
- Enhanced CSS for various elements, improving responsiveness and visual consistency.
- Introduced new components for agent management, including `agent-panel`, `agent-dropdown-switcher`, and `agent-profile-provider`.
- Implemented `agent-avatar` for displaying agent profiles with color coding.
- Enhanced chat interface with `chat-bubble` for improved message display and interaction.
- Added new utility functions for managing agent profiles and sessions.
- Updated styles for better responsiveness and user experience across components.
- Introduced a new sessions list in the overview view, displaying active sessions with updated styles.
- Updated session summary type to include additional fields such as `kind`, `label`, and `displayName`.
- Modified the `loadSessions` function to accept new options for session retrieval.
- Improved responsiveness and layout of session rows with hover effects and better information display.
- Adjusted tick interval display format for improved readability.
- Added support for markdown rendering in chat messages using `@create-markdown/preview`.
- Implemented slash command functionality, allowing users to trigger commands with a '/' prefix.
- Enhanced chat input to handle file attachments and image pasting.
- Updated sidebar navigation to display the current agent version dynamically.
- Introduced new styles for chat components and improved responsiveness for mobile views.
- Added utility functions for managing agents and attachments in the chat context.
* includes: prompt overhead in compaction safeguard calculation.
Subtracts SUMMARIZATION_OVERHEAD_TOKENS from maxChunkTokens in both the main summarization path and the dropped-messages summarization path.
This ensures the chunk budget leaves room for the prompt overhead that generateSummary wraps around each chunk.
* adds: budget for overhead tokens to use an effectiveMax instead of maxTokens naïvely.
- Added `SUMMARIZATION_OVERHEAD_TOKENS = 4096` — a budget for the tokens that `generateSummary` adds on top of the serialized conversation (system prompt, `<conversation>` tags, summarization instructions, `<previous-summary>` block, and reasoning: "high" thinking budget).
- `chunkMessagesByMaxTokens` now divides `maxTokens` by `SAFETY_MARGIN` (1.2) before comparing against estimated token counts. Previously, the safety margin was only used in `computeAdaptiveChunkRatio` and `isOversizedForSummary` but not in the actual chunking loop — so chunks could be built that fit the estimated budget but exceeded the real budget once the API tokenized them properly.
- Introduced theme options for improved user experience in the dashboard.
- Refactored theme toggle to dynamically reorder buttons based on the active theme.
- Enhanced chat view with improved state management for messages and sessions.
- Added new icons for better visual representation in the chat interface.
- Updated styles for chat components to improve layout and responsiveness.
- Refactored connection status button classes for improved clarity and consistency.
- Adjusted styles for connection status buttons, including padding and height.
- Enhanced theme toggle button with responsive behavior for hover and focus states.
- Implemented transitions for button visibility and layout adjustments in collapsed state.
- Added a new connection status component with interactive features for displaying connection health.
- Introduced styles for connection status buttons, menus, and animations in styles.css.
- Updated OverviewView to conditionally render the connection section based on connection status.
- Improved user experience with click handling for connection actions and menu visibility.
- Removed direct gateway connection handling from app.ts.
- Introduced a new connection-status component to encapsulate connection health display.
- Updated app rendering logic to utilize the new component for improved modularity and readability.
- Introduced new CSS variables for liquid glass design, including blur, saturation, radius, and animation durations.
- Updated existing theme variables for 'docsTheme', 'landingTheme', and 'light' to align with the new design tokens.
- Enhanced sidebar and app shell styles for improved responsiveness and visual consistency.
- Added support for reduced motion preferences in animations.
- Updated .gitignore to include .ant-colony directory.
- Modified README.md to reflect changes in gateway authentication settings.
- Added a new favicon.svg for improved branding.
- Refactored app.ts to implement theme management and sidebar navigation.
- Introduced sidebar-nav component for better navigation structure.
- Added controllers for overview, presence, and sessions management.
- Enhanced navigation library with new tab definitions and titles.
- Improved overview-view to display gateway health and stats dynamically.
- Updated styles.css for better theming and responsive design.
- Added local pre-commit configuration file to .gitignore for better management.
- Removed the existing .pre-commit-config.yaml file as it is now managed locally.
- Updated AGENTS.md to reflect changes in pre-commit hook installation instructions.
- Enhanced CSS styles in dashboard-lit for improved theming and UI consistency, including new glassmorphism effects and responsive design adjustments.
- Introduced icon components for better visual representation in the OverviewView.
- Integrated a new Node.js script to check for sensitive content in changed files, including private IPs and gateway secrets.
- Updated CI workflow to include the setup of Node.js and the execution of the sensitive content check.
- Enhanced pre-commit hook to validate staged files against sensitive content rules.
- Added '@noble/ed25519' dependency for device identity signing.
- Implemented device identity generation and storage in the GatewayClient.
- Enhanced GatewayProvider to track reconnect failures and provide manual retry options.
- Updated OverviewView to display connection status and error messages related to device identity and secure context requirements.
- Improved README with security hardening instructions for the Control UI.
- Updated README with connection panel instructions for gateway URL and shared secret.
- Refactored GatewayProvider to manage gateway URL and shared secret more effectively.
- Added reconnect functionality to GatewayState for improved client management.
- Enhanced OverviewView and ChatView to support user input for gateway URL and shared secret, including error handling for password mismatches.
- Updated dependencies in `pnpm-lock.yaml` to reflect the new package structure.
- Cleaned up configuration and environment files related to the previous dashboard implementation.
- Added a new package `@openclaw/dashboard-next` for the Next.js dashboard.
- Implemented WebSocket client functionality in `@openclaw/dashboard-gateway-client`.
- Created UI components for chat and overview pages.
- Included configuration files and environment setup for local development.
- Updated `.gitignore` to exclude build artifacts for the new package.