10 Commits
Author SHA1 Message Date
veenyi cf9d700d61 fix(fnos): 安装向导接管管理员密码,根治 Octop123 被弱密码黑名单拒绝导致 FPK 无法启动 (issue #502)
根因:应用密码策略(src/octop/infra/users/password.py)的常见弱密码黑名单包含 octop123,
而 FnOS FPK 把初始密码写死为 Octop123,首次启动 octop init 报 "password is too common"
直接退出("Octop process exited early"),全新安装的 native / docker FPK 均无法启动。

修复内容:
- 安装向导(wizard/install,native + docker)提供两种密码方式:
  ① 自己输入密码:install_init / install_callback 按应用侧策略预校验(≥8 位、
     含字母和数字、不在常见弱密码黑名单),无效密码在安装阶段直接拦截并中文提示;
  ② 自动生成随机密码(推荐):octop_generate_password 生成 16 位强密码。
- 随机/自定义密码双通道送达:
  ① 应用「设置」窗口(wizard/config)顶部直接显示当前账号与密码(安装/改密时
     由回调渲染占位符模板),用户免翻文件;
  ② 数据目录 octop-login.txt 回落备份,永久保留、随改密同步更新。
- 启动器与容器入口三重兜底:.env 无密码时自动生成;init 因密码策略被拒时
  自动改用随机密码重试一次,并回写 .env 保持一致 —— 存量坏 .env(Octop123)
  升级后首次启动即被救活,不再依赖用户手工清理。
- 应用「设置」窗口支持改密:保持不变 / 随机生成 / 自定义(config_init 前置校验),
  本地版走官方 CLI `octop user passwd` 离线改密(停服→改密→启服防写库冲突),
  Docker 版走 `docker exec octop octop user passwd`;凭据三处同步(.env /
  octop-login.txt / 设置窗口显示)。
- 官方 CLI 管理保障:安装回调注册 octop / octop-cli 到 PATH 并做 `octop version`
  冒烟验证(结果写入安装日志)。
- docker/docker-entrypoint.sh:未设置 OCTOP_DEFAULT_PASSWORD 时自动生成随机密码,
  指定密码被策略拒绝时自动回退随机;credential.txt 增加访问地址行。
- compose / .env.example / README / user-guide 移除 Octop123 默认值与宣传文案。

本地验证:19 个 shell 脚本 bash -n 全过;7 个向导 JSON 全部合法;密码生成 300/300
通过字符集/长度/首字母/末位数字断言;octop_validate_password 与官方
validate_password_policy 对拍 19/19 一致、黑名单 14 项逐字一致;渲染链端到端模拟
(生成→校验→回落保存→设置窗口渲染→JSON 复检)通过。
2026-09-12 08:15:24 +08:00
liukewia 01499517e7 docs: 更新默认管理员凭据说明 2026-09-03 10:22:05 +08:00
liukewia 903a958809 Update README files to reflect changes in initial admin credentials and password handling. The default password is no longer hardcoded; first-run credentials are now written to ~/octop-login.txt. Updated password policy to clarify requirements and options for setting a custom initial password using OCTOP_DEFAULT_PASSWORD. 2026-09-02 19:10:44 +08:00
jubaoliangandCursor b5d46ebfbf feat: enforce password policy and polish account/subagent UX
Require stronger passwords end-to-end (setup, Docker bootstrap, change-password), split password settings into a dedicated panel, and replace subagent file editing with a create/edit drawer.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 14:03:47 +08:00
jubaoliang ecad9ec3da feat: chat stream resume, shared terminal dock, and thread title repair (#157)
Keep dashboard chat turns attachable after reconnect, reuse one terminal
session store across Workbench and the chat dock, and migrate legacy
hard-cut thread titles to clipped titles with ellipsis.
2026-08-04 15:40:58 +08:00
leun c8373877f7 docs(mirrors): optimize default China mirror examples to Tencent Cloud
Update the "faster downloads" mirror examples in docker docs and
install scripts to use Tencent Cloud's PyPI/APT/NPM mirrors
(mirrors.cloud.tencent.com), so the documented defaults match what
scripts/install.sh and self_update.py already try first at runtime.

Affected: docker/Dockerfile, docker/docker_build.sh,
docker/README.md, docker/README_CN.md, scripts/README.md,
scripts/install.sh (--help).
2026-07-31 19:58:13 +08:00
薄生 dca16ccc21 Feat/postgresql dual backend (#60)
* feat: PostgreSQL dual-backend for control plane

Add SqlitePool|PostgresPool behind DatabasePool, parallel PG migrations,
setup wizard defer/bind, pg_dump backups with cross-engine refusal, and
memory defaulting to the control-plane DSN when using PostgreSQL.

* fix(chat): delete checkpoint data when a conversation thread is deleted

Deleting a thread only removed Octop's own metadata row; the actual
message history stayed in the agent's LangGraph checkpointer forever,
making "delete conversation" cosmetic. Also confirm before deleting a
session in the UI, since the action is now genuinely destructive.

Checkpoint deletion runs before the metadata row is removed: if it
fails outright (not just "nothing to delete"), the thread stays
visible/retryable instead of orphaning data with no remaining handle.

* fix(memory): stop suggesting pg_dump for portable export of postgres memory

The 501 hint told users to "use pg_dump on the memory schema instead".
That advice predates the shared-table layout: memory for ALL agents now
lives in one harness_memory schema isolated by a namespace column, so a
schema-level pg_dump would export every agent's memory, not just the
requester's — a cross-agent data exposure if followed on a multi-user
install.

Document the two migration models where the refusal is implemented:
sqlite memory is per-agent files moved via pack/adopt; postgres memory
is shared, and the supported way to use it from another host (e.g.
OpenClaw's harness-memory bridge with --backend postgres) is pointing
that host at the same DSN and namespace — shared, not migrated.

* fix(test): update test_slash_compact to renamed SqlitePool

The /compact test module still imported the pre-rename DBPool, which
broke collection (ImportError) on this branch after develop's compact
feature was merged in — DBPool was renamed to SqlitePool (the concrete
class) with DatabasePool now the Protocol.

DBPool -> SqlitePool at all three sites: the import, the _agent_manager
type hint, and the fixture's DBPool(path) instantiation. SqlitePool is
the byte-for-byte successor of DBPool and matches how every other test
constructs a pool; DatabasePool cannot be used at the instantiation
site (a Protocol is not instantiable).

pytest -m live now collects cleanly (31 selected, 0 errors);
test_slash_compact 3 tests pass.

* fix(test): make memory_backend db_path assertion separator-agnostic

test_explicit_sqlite_overrides_postgresql_control_plane compared the
resolved db_path against the literal "/tmp/ws/memory.sqlite", which the
code never produces on Windows: it builds the path with pathlib, so the
Windows CI job got "\tmp\ws\memory.sqlite" and the string equality failed.

Compare as Path objects so the assertion holds on every OS separator,
matching the .as_posix() discipline already used in test_config.py.
2026-07-24 14:45:53 +08:00
eb686c13e2 Release/0.9.10 (#21)
* feat: workspace file preview, browser workspace, and tooling updates

Consolidate the in-progress workspace changes:
- In-browser preview for PDF/Word/Excel documents (DocumentPreview)
- Harness /workspace/ path normalization for chat file downloads
- Browser workspace UI and remote browser panels
- Docker packaging and CI publish workflow updates
- Dependency bumps (pyproject/uv.lock, dashboard package deps)

* feat(chat): docked file preview, HTML preview, and history pull-refresh

Polish workspace/chat file viewing with dock modes and shared resize,
sandboxed HTML preview, overscroll history refresh for incomplete WS
replies, and a compact input when the chat panel is narrow.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor: delegate context usage to harness-agent 0.9.10

Bump orcakit-harness-agent and replace local token estimation with
HarnessAgent.aget_context_usage snapshots, keeping a stream-token
fallback for older wheels. Refresh the dashboard ring for the new
segment shape.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor: pass BackendWorkspace paths through without rewriting

Replace extract/normalize helpers with backend_workspace_path so absolute
and relative sources stay as-is. Unify workspace download/read/write on
_workspace_io_path and update dashboard media URL helpers to match.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(chat): unify browser and file panels into ChatDock

Replace separate FilePanel/ChatBrowserPanels/modal paths with a shared
ChatDock shell and useChatDockPanel state. Extract pointer-drag resize,
polish workspace file/media preview, and slim BrowserViewer for the
docked layout.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: release 0.9.10

* fix: CI warnings/failures for skillhub subprocess and Windows media preview

Kill and drain timed-out skillhub CLI children so asyncio transports close
on a live loop, and restore workspace-relative plus host-file fallbacks so
Windows drive-letter paths still resolve for media preview/import.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(test): use platform default backend for virtual_mode media import

Hard-coding root_dir='/' breaks Windows CI: virtual-mode uploads resolve
outside the process drive root. Match default_agent_backend_spec instead.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-19 10:01:05 +08:00
jubaoliangandjubaoliang 60eafec6af chore: release 0.9.8 (#15)
* fix: tolerate connector kind drift when resolving chat popup logos

getConnectorLogo now falls back to a normalized kind (lower-case,\nunderscore/hyphen unified) so connector instances created before the\ncatalog kind was finalized still resolve their logo in the chat picker\ninstead of showing a placeholder.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>

* chore: release 0.9.8

* fix: align dashboard tool labels with backend; bump harness-agent to 0.9.8

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-07-15 16:44:10 +08:00
jubaoliang 30b17554e3 Fix CI pipeline and make the test suite pass; rename project to Octop
CI:
- Drop Python 3.11 from the test matrix (package requires >=3.12); the
  3.11 jobs failed at `uv sync`. Linux and Windows now test Python 3.12.
- Rename tests/unit/infra/setup/tls/test_store.py -> test_tls_store.py to
  fix the pytest import collision (duplicate basename) that aborted
  collection on the 3.12 job.

Source bugs uncovered by the suite:
- Move ACTOR_SYSTEM to a runtime import in infra/cron/job.py (was wrongly
  placed under TYPE_CHECKING, causing NameError at runtime).
- Add missing users-table columns (login_failed_count, login_locked_until,
  preferences_json) in infra/db/migrate.py for legacy schema repair.
- Make auth.update_me honor explicit nulls via model_dump(exclude_unset=True).
- Relax skills hub endpoints to existence/ownership checks (require_agent_row)
  instead of requiring the agent to be running.
- Marshal WebSocket frames onto the owning event loop in chat/ws.py so the
  starlette TestClient portal does not deadlock.
- Include error details in the browser session 503 response.

Tests:
- Update tests to match current source APIs (harness async create/remove/
  rebuild, FakeHarnessAgent skill methods, workspace nested layout, JWT
  middleware, CLI surface, proactive config defaults, general-assistant
  template manifest).
- Migrate WebSocket tests to starlette TestClient(...).websocket_connect
  (httpx 0.28 removed AsyncClient.websocket_connect).
- Skip memory API tests when the optional harness_memory dependency is absent
  via pytest.importorskip.
- Remove the invalid diagnostic test tests/integration/test_diag_e2e.py
  (no assertions; inspected private internals only).

Also includes the pre-existing uncommitted orca -> Octop rename across docs,
README, LICENSE, Dockerfile and docker assets, as requested.
2026-07-10 00:40:24 +00:00