Let users sign in with their directory (Active Directory / OpenLDAP)
credentials through the existing login form. Reuses sso_providers
(kind='ldap') and user_sso_identities, so no schema change is needed.
Authentication is search-then-bind: a service account resolves the user and
only the returned DN is bound with the submitted password, so user input is
never used as a bind identity. Roles come from a role template at first
provisioning only; changing a directory group later never re-templates an
existing account. Directory outages and wrong passwords stay distinguishable
(502 LDAP_UNAVAILABLE vs 401 AUTH_FAILED).
Hardening from review:
- An account holding its own password stops at the local check, so a local
secret is never forwarded to the directory nor counted against that
directory's own lockout policy.
- A lookup without a unique exact identifier match is refused instead of
being bound against the first hit.
- A failure during the user bind surfaces as LDAP_UNAVAILABLE rather than a
401 credential verdict.
- Binds are throttled before they reach the directory, keyed per identifier
and client address, with the address resolved from a trusted peer so a
spoofed X-Forwarded-For cannot reset the budget.
- Enabling a plain ldap:// URL without StartTLS is rejected; a disabled
certificate check is surfaced as a warning.
- auto_provision defaults to off, with an optional allowed_groups allow-list
and a group-search mode (member / uniqueMember / memberUid) for directories
that do not expose memberOf. Nested groups are not resolved.
- The identity key is configurable (entryUUID / objectGUID) and blank by
default; a connectivity probe reports which attribute the directory
exposes.
- Config changes are audited against the acting admin, and referrals are no
longer followed during binds.
Tests cover the above without a live directory (ldap3.Connection is the only
thing replaced); a live test exercises a real directory when configured.
Co-authored-by: jubaoliang <jubaoliang@gmail.com>
* feat(ollama): allow configuring local model download directory
Users who move Ollama models off the default path could list custom models
but Octop treated them as not downloaded. Persist an OLLAMA_MODELS directory,
scan manifests for downloaded names, and pass the path when starting serve.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(ollama): keep service running when saving models dir
Saving the download directory no longer sends enabled=false, so a running
Ollama daemon is not stopped. Disk-scanned models report size 0 so the UI
does not show the manifest file size as the model size.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
Plugin tools returning large octop_ui payloads (e.g. a bangumi season
with 1200+ episodes, ~228KB JSON) blew up the LLM context because the
same tool-result string served both the model and the UI.
Add OctopUiOffloadMiddleware at the innermost agent middleware layer:
when a ToolMessage content is a >=4000-char string carrying a non-empty
octop_ui renderer and data (and no file:// media refs), the payload is
moved in-place to ToolMessage.artifact and the model-visible content is
replaced by a compact result that keeps title/summary. Tool id,
tool_call_id, name and status are preserved.
Frontend restores rendering from artifact: ToolCallData.artifact,
closeToolCall extraction, history replay path, and resolvePluginUiData
prefers explicit data over data_ref. serialize.py surfaces artifact on
tool_result blocks; history recorder backfills artifact as fallback.
Spec: docs/octop-ui-payload-offload.md
Co-authored-by: jubaoliang <jubaoliang@gmail.com>
* refactor(agents): group thin modules into domain subpackages
Move plugin helpers, memory, settings stores, persona/MBTI, and avatar
bootstrap code under plugins/, memory/, settings/, persona/, and experts/
while keeping top-level import shims so existing call sites stay stable.
Co-authored-by: Cursor <cursoragent@cursor.com>
* refactor(agents): drop compatibility shims after subpackage move
Call sites already import the new package paths; remove the top-level
re-export stubs so the agents tree only shows real modules.
Co-authored-by: Cursor <cursoragent@cursor.com>
* refactor(agents): move thread helpers into threads/
Group artifact shaping, fork, and context breakdown under
agents/threads so top-level only keeps lifecycle/config adapters.
Co-authored-by: Cursor <cursoragent@cursor.com>
* refactor(agents): fold profile/runtime/tool catalog into settings/
Move the remaining config-surface helpers under settings/ and drop the
skill_package id-list aliases in favor of dump/parse_id_list.
Co-authored-by: Cursor <cursoragent@cursor.com>
* refactor(agents): group workspace_dir and execute_env under workspace/
Keep path resolution and harness execute-env injection together as one
workspace package; leave only manager and conversation_mode at top level.
Co-authored-by: Cursor <cursoragent@cursor.com>
* refactor(infra): fix history/SkillHub ownership and drop thin providers/
Move history_projection under history/, share SkillHub host/limits and
route expert skill downloads through skills.skillhub_market, and fold
Codex OAuth helpers into agents.providers to remove the tiny providers/
package.
Co-authored-by: Cursor <cursoragent@cursor.com>
* docs: sync AGENTS.md and guides with infra/agents layout
Reflect subpackages (settings/workspace/threads/persona, history/, skills/)
and drop stale runtime.py / mbti_profiles paths after the agents reorg.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Keep tool-approval bypass on the conversation (allow this tool / allow all)
without changing global security settings. Also let expert create carry
welcome quick prompts, and replace the login forgot-password tip with a
platform-specific CLI dialog.
Co-authored-by: Cursor <cursoragent@cursor.com>
* harness agent upgrade for cache polish
* format
* feat(memory): add coordinated memory slim commands and progress UI
* build(deps): require harness-memory 0.9.11
* fix(deps): restore harness-memory 0.9.11 floor after merge
* fix(agents): await async shutdown to drain SQLite workers
Use HarnessAgentManager.aclose() during shutdown so SQLite cleanup
finishes before the event loop closes, preventing background threads
from raising "Event loop is closed".
Add a real SQLite regression test and preserve the existing ordering
that waits for memory slimming to finish before closing agents.
Validation: make all — 3582 passed, 17 skipped.
* feat(auth): add optional login captcha (slider, turnstile/hcaptcha/recaptcha, tencent)
Password login can now be guarded by a captcha. Default slider stays
client-only; strong providers are verified server-side with the vendor
(Cloudflare Turnstile, hCaptcha, reCAPTCHA v2/v3, Tencent Cloud Captcha).
- infra/auth/captcha: env snapshot + settings blob resolution, provider
registry with per-vendor verify calls, siteverify with 10s timeout
- GET /api/auth/captcha (public widget config); POST /api/auth/login
accepts captcha_token; tencent token carries ticket:randstr and is
checked via GET with the client IP
- admin GET/PUT /api/settings/captcha behind the new captcha permission;
OCTOP_CAPTCHA_SECRET redacted in envs API; boot validation for strong
env providers
- dashboard: CaptchaField with slider/checkbox/invisible/popup modes,
login page wiring, advanced-settings captcha panel
- docs + i18n (en/zh) + unit/integration/frontend tests
* fix(captcha): verify Tencent tickets via DescribeCaptchaResult (TC3)
The legacy ssl.captcha.qq.com/ticket/verify endpoint rejects current
tickets with response=15 "decrypt fail" even for correct
CaptchaAppId/AppSecretKey pairs. Switch to the official ticket-check API:
- POST captcha.tencentcloudapi.com DescribeCaptchaResult (2019-07-22),
TC3-HMAC-SHA256 signed with CAM API keys; AppSecretKey stays in the body
- captcha settings gain cam_secret_id/cam_secret (encrypted at rest,
env fallback OCTOP_CAPTCHA_CAM_SECRET_ID/KEY); settings view exposes
cam_secret_id + has_cam_secret; dashboard shows the two fields for the
tencent provider only
- interpret maps CaptchaCode (1 OK; 7/8/9/15/16/21/100 fail) and
EvilLevel=100 (malicious) instead of the legacy response=="1"
- TC3 signer moved voice/tencent_sign.py -> utils/tencent_sign.py (shared)
- drop the redundant Host header from signed requests: httpx sets Host
from the URL (same value the signature covers), and an explicit Host
let host-routing system proxies intercept localhost mock calls
- secrets no longer appear in httpx URL logs (payload is in the body)
- move the Login Captcha settings tab next to HTTPS
* polish(dashboard): show reCAPTCHA v3 min score only when that provider is active
* fix(dashboard): captcha widgets follow the site locale, not the browser
- tencent popup: userLanguage from i18n.language (was navigator.language)
- turnstile: pass language render option
- hcaptcha/recaptcha/recaptcha-v3: hl script param from UI locale
- slider already renders site-provided labels
* feat(captcha): unlist reCAPTCHA v2 from the settings catalog
No verified deployment key for v2; keep the provider registered so
existing configs still verify, but stop offering it in the dropdown
(list_providers now filters on a per-provider listed flag).
* feat(cli): octop captcha reset — offline lockout escape hatch
Clears the stored captcha settings blob so login falls back to the
built-in slider when a misconfigured provider blocks all logins
(settings UI requires login, so it cannot fix itself). Boot-env
captcha is untouched; a running server needs a restart.
CHANGELOG: cover reset command, TC3 switch, widget language, v2 unlist.
* feat(cli): register octop captcha reset command and add changelog
Without the registry entry the command module from c5a7649d was
unreachable; CHANGELOG covers the login captcha feature, the TC3
ticket-check switch, widget locale, v2 unlisting, and captcha reset.
* fix(captcha): close pre-merge gaps + document the provider architecture
- envs API: redact OCTOP_CAPTCHA_CAM_SECRET_KEY like OCTOP_CAPTCHA_SECRET
(was exposed in plaintext by GET /api/envs)
- validate_boot: env-only tencent provider now requires the CAM keys,
failing fast at boot instead of at first login
- docs/configuration.md: document the two CAM env vars; note recaptcha
v2 is unlisted but resolvable
- providers.py: architecture docstring (four layers + settled design
decisions + adding-a-vendor recipe); rename _SuccessProvider to
_FormPostProvider; drop the register() cast, which exposed a real
structural bug: frozen-dataclass providers never satisfied the
Protocol's mutable metadata members — declare them read-only
properties so the structural check is real
- verify.py: docstring naming it the execution layer
Keep partial tokens and stream errors in thread history after a stop or
provider failure, and drive cron empty-state cards from manifest
task_examples. Backup skips stale workspace paths instead of creating them.
Co-authored-by: Cursor <cursoragent@cursor.com>
Admins can set storage-root and token quota when creating a user, and
cronjob_create now requires a display name with prompt-prefix fallback.
Co-authored-by: Cursor <cursoragent@cursor.com>
Replace the legacy shared/default Playwright session router with
per-user harness-browser profiles (`user-<id>`) so concurrent users no
longer share one Chrome session, cookie jar, or recording. The backend
now always derives the profile from the authenticated user (or the IM
thread's agent owner) instead of trusting client-supplied profile/session
ids, and a BrowserProfileMiddleware pins tool-selected profiles to the
same boundary. Also dedupes ThreadRegistry's session-refresh logic.
* feat(cron): add name field to cron jobs and update related interfaces
- Introduced a `name` field to the `OctopCronRow`, `OctopCronCreateBody`, and `OctopCronPatchBody` interfaces.
- Updated localization files to include validation messages for the new `name` field.
- Added a constant for maximum name length.
- Enhanced the UI to display the job name in the cron jobs table and detail views.
- Updated API documentation to reflect the new optional `name` parameter in cron job creation and updates.
- Implemented database schema changes to support the new `name` field in cron jobs.
This change improves the user experience by allowing users to assign descriptive names to their cron jobs, making them easier to identify.
* feat(cron): restrict cron job management to owners only
- Updated the cron job management logic to ensure that only the owner of a cron job can create, view, update, or delete it.
- Modified the API endpoints to return empty lists for non-owners attempting to access cron jobs.
- Enhanced the frontend logic to reflect these changes, ensuring a consistent user experience across the application.
- Updated related tests to verify that cron jobs are correctly scoped to their owners, preventing unauthorized access.
This change improves security and clarity in the management of cron jobs within shared agents.
* refactor(cron): improve code readability in cron management functions
- Reformatted the `_assert_cron_manage` function for better readability by adjusting the parameter layout.
- Simplified the invocation of the `create` function in the test case for clarity.
These changes enhance the maintainability of the code and improve the overall structure of the cron management logic.
Expired tokens that cannot be refreshed now prompt the dashboard to re-authorize. Cache OAuth discovery for an hour, and localize callback and start-error copy.
* feat(media): add generation model management and feedback
* chore: document media generation and restore quality gates
* test(browser): support missing getuid on Windows
---------
Co-authored-by: leoxyang <leoxyang@tencent.com>
* refactor: replace hardcoded media type mappings with INBOUND_EXTENSION_MEDIA_TYPES
- Removed the _EXTENSION_MEDIA_TYPES dictionary from uploads.py and replaced it with INBOUND_EXTENSION_MEDIA_TYPES imported from inbound_store.py.
- Updated the _resolve_media_type and validate_inbound_media_type functions to utilize the new mapping for determining media types based on file extensions.
- Added unit tests to ensure that unknown MIME types correctly fall back to their respective extensions and that unsupported types raise appropriate errors.
* fix(api): improve error handling for upload requests
- Refactored error rejection in requestUpload to provide clearer error messages, including response text when available.
- Updated error handling in WorkspaceDrawer and useChatAttachments to utilize a new utility function for consistent API error messaging.
* feat: add error handling for unsupported and oversized attachments
- Introduced new error codes for unsupported file types and oversized attachments in the API.
- Updated localization files for English and Chinese to include messages for these new error codes.
- Enhanced the inbound media validation logic to raise appropriate errors when attachments exceed size limits or are of unsupported types.
- Added unit tests to verify the new error handling for attachment validation.
* feat: expand allowed inbound media types and improve validation logic
- Added a comprehensive list of allowed inbound media types and their corresponding file extensions to enhance file type validation.
- Introduced new test cases to ensure that various file extensions and MIME types are correctly validated, including support for additional programming and document formats.
- Updated the existing validation logic to accommodate new media types and ensure proper fallback mechanisms for unknown MIME types.
- Add server-wide plugin enable/disable (PATCH /plugins/{id}) and a
reload endpoint to pick up CLI installs without a full restart.
- Serve read-only plugin UI assets with traversal checks.
- Persist per-agent plugin tool enable flags and hot-sync the harness
denylist so disables take effect on the next turn (no full reload).
- Add a tool catalog and plugin market UI plus a tool settings API.
- Ship demo plugins: ui-card, server-status, bilibili-anime.
- Update i18n bundles and API docs.
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: CodeBuddy <noreply@codebuddy.ai>
* feat: minimal layout, user email, KB text docs, and remote desktop hub
Add classic/minimal chrome with a unified chat records host, optional user
email (invite/login), in-app markdown/txt knowledge editing, and a combined
remote desktop/phone control surface—plus host path and mobile setup hardening.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(host_dirs): don't jail host-root browse to home drive on Windows
The restrict_to_home=False case allows any absolute host path (no home
jail). On POSIX everything sits under '/'; on Windows the denylist is
empty and windows_neutralize_host_root rewrites root_dir '/' at runtime,
so a drive-relative '/' must stay allowed. The new _path_within_base
containment incorrectly rejected root_dir '/' on Windows when the checkout
drive differed from the home drive, breaking from-expert/local_shell agent
creation.
Also mark test_install_published_expert_accepts_create_options posix_only:
it relies on local_shell workspace file writes unsupported on Windows.
---------
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Register routers/repos/migrations, OpenAPI tags, i18n/error codes, sidebar routes, and docs for the new platform capabilities.
Co-authored-by: Cursor <cursoragent@cursor.com>
Keep dashboard chat turns attachable after reconnect, reuse one terminal
session store across Workbench and the chat dock, and migrate legacy
hard-cut thread titles to clipped titles with ellipsis.
Restore syncs providers and reloads agents in-process; rename cron_timezone to
default_timezone with GET /api/settings/timezone; reload only impacted agents
after provider changes; align dashboard timestamps to the server timezone.
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Expose /api/filesystem for lazy directory listing and write probes, wire
RootDirSelect into expert/agent forms, and validate non-/ paths before save.
Co-authored-by: Cursor <cursoragent@cursor.com>