Commit Graph
2219 Commits
Author SHA1 Message Date
YOMXXXandGitHub 733fcfe7ca fix(security): allow Windows read commands (#2399) 2026-05-22 17:02:22 +05:30
Andrew BarnesandGitHub f9d94817dd fix: explain reset-data Windows file locks (#2395) 2026-05-22 17:01:15 +05:30
1b29d6b67c docs(cef): add Windows startup triage notes (#2393)
Co-authored-by: Cyrus Gray <144336577+graycyrus@users.noreply.github.com>
2026-05-22 16:57:05 +05:30
5bdc9c2ee5 docs(installer): print Linux AppImage fallback hint (#2392)
Co-authored-by: Aqil Aziz <aqilaziz@users.noreply.github.com>
2026-05-22 16:54:32 +05:30
Aqil AzizandGitHub ddbd0fcbe5 docs(linux): add AppImage failure notes (#2391) 2026-05-22 16:54:02 +05:30
Aqil AzizandGitHub e6f08c6319 docs(e2e): add desktop deep-link smoke (#2389) 2026-05-22 16:43:21 +05:30
Aqil AzizandGitHub c14a196967 docs(auth): add sign-in troubleshooting runbook (#2386) 2026-05-22 16:41:19 +05:30
Aqil AzizandGitHub 72fb7a8d5e docs(cef): document Linux shell fallback (#2387) 2026-05-22 16:40:32 +05:30
70ef42750b docs(local-ai): document local chat routing (#2383)
Co-authored-by: Aqil Aziz <aqilaziz@users.noreply.github.com>
2026-05-22 16:36:51 +05:30
Aqil AzizandGitHub 203367cb45 fix(auth): refresh RPC cache before deep-link session store (#2384) 2026-05-22 16:30:38 +05:30
Aqil AzizandGitHub e3948a3479 ci(release): reject AppImage with bad sharun lib path (#2385) 2026-05-22 16:24:47 +05:30
Aqil AzizandGitHub 6b3a7924bb fix(tools): preserve Windows process env (#2382) 2026-05-22 16:21:38 +05:30
CodeGhost21andGitHub 61dd544e2f fix(channels/discord): convert upstream 401/403 to domain-scoped error so card click can't sign user out (#2285) (#2376) 2026-05-22 16:14:36 +05:30
b2f053f5e1 composio: instagram oauth fails with http 429 in composio integration (#1952) (#2259)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-22 16:01:12 +05:30
Srinivas VaddiandGitHub 607a6a1db5 Add tool registry policy diagnostics (#2336) 2026-05-22 15:59:35 +05:30
oxoxDevandGitHub b08aa3ea8d fix(tauri): retry main-window lookup on Windows after SW_SHOW (#3A) (#2341) 2026-05-22 15:59:05 +05:30
002dc8d76d fix(subagent): dedup tool specs before sending to provider (#2485)
Co-authored-by: sanil-23 <sanil@alphahuman.xyz>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-22 15:29:03 +05:30
github-actions[bot] 0ad723595e chore(staging): v0.54.7 2026-05-22 08:55:46 +00:00
oxoxDevandGitHub 62727e1dc7 fix(core/socketio): accept http://tauri.localhost origin (#2331 follow-up) (#2482) 2026-05-22 14:09:40 +05:30
Srinivas VaddiandGitHub 80b92076d3 Add generated tool wrapper abstraction (#2333) 2026-05-22 14:05:24 +05:30
9d0cce77ce feat(embeddings): rate-limit cloud embedding requests to the backend's hard 60/min cap (#2461)
Co-authored-by: sanil-23 <sanil@alphahuman.xyz>
Co-authored-by: Claude <noreply@anthropic.com>
2026-05-22 13:58:06 +05:30
github-actions[bot] 7fe3dd06ba chore(staging): v0.54.6 2026-05-21 20:17:36 +00:00
OffByOneandGitHub c9ab4b9c12 Add German locale support (#2378) 2026-05-22 00:18:16 +05:30
CodeGhost21andGitHub b3e0021aae fix(channels): distinguish rate-limit sources in chat error classifier (#2364) (#2371) 2026-05-22 00:17:07 +05:30
a20f75bc4b fix(memory): accept time_window_days alias in query_global (#2350)
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Cyrus Gray <144336577+graycyrus@users.noreply.github.com>
2026-05-22 00:12:15 +05:30
github-actions[bot] f02543b80a chore(staging): v0.54.5 2026-05-21 18:41:18 +00:00
Mega MindandGitHub 2a935d35b1 test(e2e): add E2E coverage for 15 Composio connector flows (#2351) 2026-05-22 00:08:11 +05:30
Mega MindandGitHub c6c9abbe18 refactor(tls): move tls.rs → tls/mod.rs per module-layout rule (#2460) 2026-05-22 00:08:01 +05:30
Srinivas VaddiandGitHub 0257a6cf79 Add approval audit history read path (#2335) 2026-05-21 23:52:52 +05:30
Srinivas VaddiandGitHub 190397c4cb Thread tool call context through policy (#2334) 2026-05-21 23:47:45 +05:30
oxoxDevandGitHub b1bbc53fce feat: tighten runtime policy + transport guards (#2331) 2026-05-21 23:39:05 +05:30
Mega MindandGitHub beba562df2 fix(windows): make pnpm dev:app:win work behind TLS-inspecting proxies (#2449) 2026-05-21 23:29:01 +05:30
YellowSnnowmannandGitHub 7aa1bf1f88 fix(agent): handle config rejection in streaming_chat path (#2346) 2026-05-21 23:24:07 +05:30
d7b27b94fc fix(memory): run memory_tree on TRUNCATE journal instead of WAL (#2455)
Co-authored-by: sanil-23 <sanil@alphahuman.xyz>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-21 23:16:51 +05:30
JAYcodrGitHubagent:skill-master <skill-master@openclaw>
013381e880 fix(i18n): complete zh-CN translations for workspace, mascot, MCP Ser… (#2440)
Co-authored-by: agent:skill-master <skill-master@openclaw>
2026-05-21 23:02:54 +05:30
oxoxDevandGitHub e031d85ed2 feat(agents): route prediction-market intents via new markets_agent specialist (#2427) (#2430) 2026-05-21 22:58:00 +05:30
YellowSnnowmannandGitHub f51f140234 fix(prompt-injection): rebalance detector + classify rejections as expected (#2429) 2026-05-21 22:57:55 +05:30
YellowSnnowmannandGitHub 208a64483b fix(auth-profiles): tolerate legacy kind values on load (#2439) 2026-05-21 22:57:49 +05:30
oxoxDevandGitHub dcec5858e0 fix(tauri): pre-flight every xdg-utils binary before register_all (#5V) (#2416) 2026-05-21 22:57:44 +05:30
Aqil AzizandGitHub ec9708ac6f fix(composio): surface Gmail scope errors as permissions (#2414) 2026-05-21 17:23:44 +05:30
6137b67811 fix(memory_tree,sync_status,scripts): IMMEDIATE-tx ingest, reembed skip-persistence, sidecar-based sync-status accounting, Windows dev-script PATH (#2349)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: sanil-23 <sanil@alphahuman.xyz>
2026-05-21 16:31:25 +05:30
JinHyuk SungandGitHub 7675c01c5c fix(billing): hide budget-complete prompt for free zero-budget plans (#2300) 2026-05-21 16:19:29 +05:30
Steven EnamakelandGitHub bf6f25e64c Update Product Hunt badges in README (#2425) 2026-05-21 01:27:25 -07:00
Steven EnamakelandGitHub d1f8305e20 Update README.md (#2424) 2026-05-21 01:21:00 -07:00
Steven EnamakelandGitHub c204a53de2 feat(mcp-clients): MCP client subsystem with Smithery registry + UI (#2409) 2026-05-20 23:05:14 -07:00
AryanandGitHub 6281aeaf42 docs(linux): add arch linux setup and build instructions (#2343) 2026-05-20 19:31:16 -07:00
48c4da4e2a fix(cron): classify agent job errors into actionable user messages (#2279) (#2340)
Co-authored-by: sanil-23 <sanil@alphahuman.xyz>
Co-authored-by: Claude <noreply@anthropic.com>
2026-05-20 19:30:59 -07:00
3e2ba6648d fix(notifications): render <openhuman-link> tags in notification bodies (#2279) (#2339)
Co-authored-by: sanil-23 <sanil@alphahuman.xyz> 
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-20 19:30:41 -07:00
c81fe3dbcc fix(auth): narrow SessionExpired to confirmed OpenHuman backend 401s
## Summary

- Narrows `is_session_expired_error` in `src/core/jsonrpc.rs` so `DomainEvent::SessionExpired` only fires for **confirmed OpenHuman session expiry**, not for downstream provider 401s.
- Adds `is_downstream_provider_auth_error` helper for diagnostic logging only (no session side-effects).
- Adds `'provider_auth'` error kind to `CoreRpcErrorKind` in `coreRpcClient.ts`; tightens `classifyRpcError` with the same HTTP-method-prefix logic.
- Fixes Discord card-click logout (issue #2285) as a direct consequence.

## Root Cause

`is_session_expired_error` used a loose `"401 + unauthorized"` string match. Discord bot-token failures arrive as `"Discord API error: Discord list guilds failed (401): Unauthorized"` — which contains both "401" and "unauthorized" — causing the full user session to be cleared on every Discord card interaction.

## Fix

OpenHuman backend errors (from `authed_json` in `src/api/rest.rs`) always use the format `"{HTTP_METHOD} /path failed (401 Unauthorized): {body}"`. Provider errors start with the provider name. The fix keeps the `"401 + unauthorized"` branch only when the message starts with an HTTP method verb, which matches backend paths while excluding Discord, OpenAI, Anthropic, Composio, etc.

## Test plan

- [x] `src/core/jsonrpc_tests.rs` — 10 `is_session_expired_error` tests covering: HTTP-method-prefix matches, Discord exclusion, BYO-key exclusion, Composio exclusion, explicit markers still match
- [x] `app/src/services/__tests__/coreRpcClient.test.ts` — 3 new `test.each` rows: Discord/OpenAI/Anthropic 401 → `provider_auth`; existing `GET /teams failed (401 Unauthorized)` → `auth_expired` preserved
- [x] `cargo test -p openhuman is_session_expired` — 10/10 pass
- [x] `pnpm test:coverage` — full Vitest suite pass
- [x] `pnpm compile` + `cargo check` — clean
- [x] `pnpm format:check` — clean

## Submission Checklist

- [x] Tests added or updated (happy path + at least one failure / edge case)
- [x] Diff coverage ≥ 80% — all new/changed lines in `jsonrpc.rs` and `coreRpcClient.ts` covered by unit tests
- [x] No new external network dependencies introduced
- [x] N/A: Coverage matrix — no new production feature rows
- [x] N/A: Manual smoke checklist — no release surfaces touched

## Related

Closes #2286
Related: #2285 (Discord card-click logout — fixed as a consequence of this change)

---

## AI Authored PR Metadata (required for Codex/Linear PRs)

### Linear Issue
- Key: N/A
- URL: N/A

### Commit & Branch
- Branch: `fix/session-expired-cascade-2286`
- Commit SHA: a0da2423

### Validation Run
- [x] `pnpm --filter openhuman-app compile`
- [x] `pnpm --filter openhuman-app format:check`
- [x] `pnpm --filter openhuman-app lint`
- [x] `cargo check --manifest-path Cargo.toml`
- [x] `pnpm test:coverage` (Vitest full suite)
- [x] `cargo test -p openhuman is_session_expired` (10/10 pass)

### Validation Blocked
- `command:` N/A
- `error:` N/A
- `impact:` N/A

### Behavior Changes
- Intended behavior change: provider-auth 401s (Discord, OpenAI BYO-key, Composio direct-mode) no longer clear the user session
- User-visible effect: clicking the Discord channel card no longer logs the user out; BYO-key misconfiguration no longer forces re-auth

### Parity Contract
- Legacy behavior preserved: OpenHuman backend 401s (`GET /teams failed (401 Unauthorized)`) still trigger session expiry
- Guard/fallback/dispatch parity checks: `api_error` in `inference/provider/ops.rs` still publishes SessionExpired directly for backend auth failures (independent of this fix)

### Duplicate / Superseded PR Handling
- Duplicate PR(s): none
- Canonical PR: this PR

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **Bug Fixes**
  * Improved error classification to distinguish user session expiry from external provider authentication failures, reducing mistaken session terminations and improving recovery and logging behavior.

* **Tests**
  * Expanded and tightened test coverage to ensure confirmed session-expiry signals are detected while external API 401/unauthorized responses do not trigger session-expiry handling.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/tinyhumansai/openhuman/pull/2356?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: M3gA-Mind <megamind@mahadao.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-20 19:29:46 -07:00
369a39288c test(e2e): wipe memory tree during test reset
## Summary

- Extends `openhuman.test_reset` so E2E resets also wipe Memory Tree state via the existing `memory_tree_wipe_all` path.
- Adds reset summary fields for memory-tree rows, content directories, and Composio sync-state rows so Appium logs show exactly what was cleared.
- Adds a focused async unit test covering memory-tree content directory cleanup through the new reset helper.

## Problem

- #1862 tracks that `openhuman.test_reset` only cleared auth/onboarding/cron state, while Memory Tree data could survive between specs in a shared Appium session.
- That means memory-oriented specs can pass or fail based on chunks, wiki content, or sync cursors left by an earlier spec.

## Solution

- Calls `read_rpc::wipe_all_rpc(&config)` from `test_support::rpc::reset` after cron cleanup and before config/auth clearing.
- Surfaces `memory_tree_rows_deleted`, `memory_tree_dirs_removed`, and `memory_tree_sync_state_cleared` in `ResetSummary`, `reset_json`, and the controller schema.
- Keeps this as a scoped #1862 slice; other domains listed in the issue can land as separate hook PRs.

## Submission Checklist

- [x] Tests added or updated (happy path + at least one failure / edge case) per [Testing Strategy](../gitbooks/developing/testing-strategy.md#failure-path-requirement) — focused unit test covers Memory Tree content-dir cleanup; existing `wipe_all_rpc` owns table/sync-state failure behavior.
- [x] **Diff coverage >= 80%** — new Rust test covers the new helper path; CI coverage gate is authoritative.
- [x] Coverage matrix updated — N/A: E2E test-support reset plumbing, no product feature row added/removed.
- [x] All affected feature IDs from the matrix are listed in the PR description under `## Related` — N/A: no feature matrix row.
- [x] No new external network dependencies introduced (mock backend used per [Testing Strategy](../gitbooks/developing/testing-strategy.md#mock-policy))
- [x] Manual smoke checklist updated if this touches release-cut surfaces ([`docs/RELEASE-MANUAL-SMOKE.md`](../docs/RELEASE-MANUAL-SMOKE.md)) — N/A: test-support RPC only.
- [x] Linked issue closed via `Closes #NNN` in the `## Related` section — N/A: scoped slice; references #1862 without closing the umbrella.

## Impact

- E2E specs that call `resetApp(...)` now start without prior Memory Tree chunks, summary/wiki files, or sync cursors.
- User runtime behavior is unchanged unless the E2E-only `openhuman.test_reset` controller is compiled/enabled.

## Related

- Refs #1862
- Follow-up PR(s)/TODOs: add hook coverage for remaining #1862 domains: channels, skills, webview_accounts, threads, notifications, webhooks, cost, referral, composio.

---

## AI Authored PR Metadata (required for Codex/Linear PRs)

### Linear Issue
- Key: N/A
- URL: N/A

### Commit & Branch
- Branch: `codex/1862-test-reset-memory-tree`
- Commit SHA: `48630b40f69400d6a3c5e055e80c25486e3bba6d`

### Validation Run
- [x] `pnpm --filter openhuman-app format:check` — N/A: no frontend files changed.
- [x] `pnpm typecheck` — N/A: no TypeScript files changed.
- [x] Focused tests: attempted `cargo test -p openhuman test_support::rpc::tests::wipe_memory_tree_removes_content_dirs_and_reports_summary --lib`.
- [x] Rust fmt/check (if changed): `cargo fmt --all --check`; `git diff --check`.
- [x] Tauri fmt/check (if changed): N/A: no Tauri shell files changed.

### Validation Blocked
- `command:` `cargo test -p openhuman test_support::rpc::tests::wipe_memory_tree_removes_content_dirs_and_reports_summary --lib`
- `error:` local Windows build fails before tests in `whisper-rs-sys` because `clang.dll` / `libclang.dll` is missing and `LIBCLANG_PATH` is unset.
- `impact:` focused test did not execute locally; CI Linux/Windows runners with libclang are expected to compile and run it.

### Behavior Changes
- Intended behavior change: E2E-only test reset now wipes Memory Tree state in addition to cron/auth/onboarding state.
- User-visible effect: none in normal builds; E2E logs show memory-tree wipe counts.

### Parity Contract
- Legacy behavior preserved: cron cleanup, auth clearing, onboarding reset, and active-user removal still run and still short-circuit on failure.
- Guard/fallback/dispatch parity checks: Memory Tree wipe reuses the existing user-facing `wipe_all_rpc` implementation instead of adding a second deletion path.

### Duplicate / Superseded PR Handling
- Duplicate PR(s): N/A
- Canonical PR: this PR
- Resolution (closed/superseded/updated): N/A


<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **New Features**
  * Reset now clears memory-tree persistent data during fresh-install resets and reports rows deleted, directories removed, and sync-state entries cleared.

* **Documentation**
  * Updated reset operation schema and outputs to include memory-tree cleanup fields.

* **Tests**
  * Added a unit test verifying memory-tree wipe removes content directories and reports summary metrics.

* **Bug Fixes**
  * Increased core startup readiness timeout to reduce startup failures.

<!-- review_stack_entry_start -->

[![Review Change Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/tinyhumansai/openhuman/pull/2308?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: aqilaziz <gonzes7@gmail.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-20 17:07:59 -07:00