Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
232 commits
Select commit Hold shift + click to select a range
2d48bf4
Merge pull request #559 from ChronoAIProject/sync/post-release-v0.8.0
chronoai-shining May 14, 2026
f6c16f4
docs(skill): refresh ornn-agent-manual-cli to v1.2 against develop AP…
chronoai-shining May 14, 2026
522c22e
docs(readme): surface Ornn official website link (#572) (#573)
chronoai-shining May 18, 2026
cbd4342
chore(sdk): add discovery keywords + npm publish fields to TS SDK
chronoai-shining May 19, 2026
7149b81
chore(sdk): align Python SDK keywords with agent-API positioning
chronoai-shining May 19, 2026
ad22136
docs: changeset for #468
chronoai-shining May 19, 2026
8493a7d
docs(readme): add SDK quickstart section (#470)
chronoai-shining May 19, 2026
7523466
Merge pull request #589 from ChronoAIProject/chore/468-keywords-topics
chronoai-shining May 19, 2026
32ab049
docs(readme): add positioning / comparison table (#472)
chronoai-shining May 19, 2026
25ecc10
docs: add API_STABILITY.md commitment + deprecation policy (#474)
chronoai-shining May 19, 2026
d9a0faf
docs(readme,conventions): cross-link to API_STABILITY.md (#474)
chronoai-shining May 19, 2026
3c4f3cd
docs: changeset for #474
chronoai-shining May 19, 2026
58bb55b
Merge branch 'develop' into docs/470-sdk-quickstart
chronoai-shining May 19, 2026
1d6cab7
docs: create ERRORS.md + DEPRECATIONS.md (#576)
chronoai-shining May 19, 2026
a6dd03a
docs(conventions): point type + Link URLs at ERRORS/DEPRECATIONS.md (…
chronoai-shining May 19, 2026
9044325
docs: changeset for #576
chronoai-shining May 19, 2026
0767bf4
Merge pull request #590 from ChronoAIProject/docs/470-sdk-quickstart
chronoai-shining May 19, 2026
ffe357b
Merge branch 'develop' into docs/472-positioning-table
chronoai-shining May 19, 2026
cc77c2e
chore(api): delete dead skill repository remnant (#577)
chronoai-shining May 19, 2026
9b53961
Merge pull request #591 from ChronoAIProject/docs/472-positioning-table
chronoai-shining May 19, 2026
173e40a
Merge branch 'develop' into docs/474-api-stability
chronoai-shining May 19, 2026
55be1d3
Merge branch 'develop' into docs/576-errors-deprecations
chronoai-shining May 19, 2026
3effe5c
fix(api): fail-fast on bad env vars in quota migration script (#447)
chronoai-shining May 19, 2026
40e0639
test(api): unit-test parseNonNegativeInt edge cases (#447)
chronoai-shining May 19, 2026
3cb8e1e
docs: changeset for #447
chronoai-shining May 19, 2026
1660270
Merge pull request #593 from ChronoAIProject/docs/474-api-stability
chronoai-shining May 19, 2026
b366261
Merge branch 'develop' into docs/576-errors-deprecations
chronoai-shining May 19, 2026
5072b0f
Merge branch 'develop' into chore/577-delete-dead-repo
chronoai-shining May 19, 2026
c264ca1
feat(api): validateGitHubAppPrivateKey helper (#441)
chronoai-shining May 19, 2026
fd74d80
test(api): unit-test validateGitHubAppPrivateKey (#441)
chronoai-shining May 19, 2026
c12895c
feat(api): plug validateGitHubAppPrivateKey into POST /github/repo (#…
chronoai-shining May 19, 2026
ef508ce
docs: changeset for #441
chronoai-shining May 19, 2026
10b1ae3
Merge pull request #594 from ChronoAIProject/docs/576-errors-deprecat…
chronoai-shining May 19, 2026
d0f9d7a
Merge branch 'develop' into chore/577-delete-dead-repo
chronoai-shining May 19, 2026
b13c7d0
Merge branch 'develop' into chore/447-parseint-env
chronoai-shining May 19, 2026
7a1aa13
docs: add examples/ with three starter skills (#469)
chronoai-shining May 19, 2026
5278d83
docs(readme): link to examples/ from README + nav (#469)
chronoai-shining May 19, 2026
3785d6d
docs: changeset for #469
chronoai-shining May 19, 2026
991dad4
Merge pull request #595 from ChronoAIProject/chore/577-delete-dead-repo
chronoai-shining May 19, 2026
111f49d
Merge branch 'develop' into chore/447-parseint-env
chronoai-shining May 19, 2026
e710109
Merge branch 'develop' into chore/441-private-key-validation
chronoai-shining May 19, 2026
67533fd
fix(api): Zod-validate LLM re-ranker output (#444)
chronoai-shining May 19, 2026
96f3212
Merge pull request #596 from ChronoAIProject/chore/447-parseint-env
chronoai-shining May 19, 2026
9fa6bbd
Merge branch 'develop' into chore/441-private-key-validation
chronoai-shining May 19, 2026
9b88216
Merge branch 'develop' into docs/469-examples
chronoai-shining May 19, 2026
42957ad
fix(web): harden ZIP validator with size cap + zip-slip check (#443)
chronoai-shining May 19, 2026
0ff0832
Merge pull request #597 from ChronoAIProject/chore/441-private-key-va…
chronoai-shining May 19, 2026
a2c2831
Merge branch 'develop' into docs/469-examples
chronoai-shining May 19, 2026
ce539c3
Merge branch 'develop' into fix/444-rerank-zod
chronoai-shining May 19, 2026
c0b4716
fix(web): document or fix React keys on Array.map lists (#451)
chronoai-shining May 19, 2026
8eed0fb
Merge pull request #598 from ChronoAIProject/docs/469-examples
chronoai-shining May 19, 2026
1e77b2e
Merge branch 'develop' into fix/444-rerank-zod
chronoai-shining May 19, 2026
a43dc83
Merge branch 'develop' into fix/443-zip-validator
chronoai-shining May 19, 2026
86c955e
fix(web): silence auth/analytics/apiClient/activityApi logs in prod (…
chronoai-shining May 19, 2026
dd6fd08
Merge pull request #599 from ChronoAIProject/fix/444-rerank-zod
chronoai-shining May 19, 2026
60119c6
Merge branch 'develop' into fix/443-zip-validator
chronoai-shining May 19, 2026
a4f0d3d
Merge branch 'develop' into fix/451-react-keys
chronoai-shining May 19, 2026
8e696ac
fix(api): enforce visibility check on /skills/:idOrName/json (#567)
chronoai-shining May 19, 2026
d743f55
Merge pull request #601 from ChronoAIProject/fix/451-react-keys
chronoai-shining May 19, 2026
2a70a2b
Merge branch 'develop' into fix/443-zip-validator
chronoai-shining May 19, 2026
1606881
Merge branch 'develop' into fix/584-auth-console-logs
chronoai-shining May 19, 2026
3c52c78
Merge branch 'develop' into fix/567-json-endpoint-visibility
chronoai-shining May 19, 2026
924b88d
fix(web): render Mermaid SVG inside a sandboxed iframe (#440)
chronoai-shining May 19, 2026
d2a6dd8
Merge pull request #602 from ChronoAIProject/fix/584-auth-console-logs
chronoai-shining May 19, 2026
ac41f2f
test(web): drop unused fileFromZip helper from zipValidator tests (#443)
chronoai-shining May 19, 2026
8444213
refactor(web): route apiDelete through fetchWithRetry (#578)
chronoai-shining May 19, 2026
a58cc50
Merge branch 'develop' into fix/443-zip-validator
chronoai-shining May 19, 2026
b5daeb1
Merge branch 'develop' into fix/567-json-endpoint-visibility
chronoai-shining May 19, 2026
26339de
Merge branch 'develop' into fix/440-mermaid-iframe
chronoai-shining May 19, 2026
5e86671
Merge pull request #605 from ChronoAIProject/fix/578-apidelete-dedup
chronoai-shining May 19, 2026
5c015c3
Merge branch 'develop' into fix/443-zip-validator
chronoai-shining May 19, 2026
95cbeea
Merge branch 'develop' into fix/567-json-endpoint-visibility
chronoai-shining May 19, 2026
bd22d27
Merge branch 'develop' into fix/440-mermaid-iframe
chronoai-shining May 19, 2026
201b260
Merge pull request #600 from ChronoAIProject/fix/443-zip-validator
chronoai-shining May 19, 2026
e11918f
Merge branch 'develop' into fix/567-json-endpoint-visibility
chronoai-shining May 19, 2026
e50db21
Merge branch 'develop' into fix/440-mermaid-iframe
chronoai-shining May 19, 2026
8e7e2fb
Merge pull request #603 from ChronoAIProject/fix/567-json-endpoint-vi…
chronoai-shining May 19, 2026
3f54e15
Merge branch 'develop' into fix/440-mermaid-iframe
chronoai-shining May 19, 2026
0f1c9c3
Merge pull request #604 from ChronoAIProject/fix/440-mermaid-iframe
chronoai-shining May 19, 2026
0197d3e
fix(api): Zod-parse playground LLM stream events (#449)
chronoai-shining May 19, 2026
2ba513e
Merge pull request #606 from ChronoAIProject/fix/449-chat-events-zod
chronoai-shining May 19, 2026
4bb2587
fix(web): replace hardcoded hex colors on landing pages with tokens (…
chronoai-shining May 19, 2026
b684b1a
fix(api): cap admin skill-search query time + index hot fields (#446)
chronoai-shining May 19, 2026
4003080
feat(api): surface SRI integrity hash on /versions response (#461)
chronoai-shining May 19, 2026
51c958e
docs: publish SDK_PUBLISHING.md + pre-publish install notes (#473)
chronoai-shining May 19, 2026
f19ba5f
Merge pull request #609 from ChronoAIProject/fix/452-landing-tokens
chronoai-shining May 19, 2026
6076c43
Merge branch 'develop' into fix/446-admin-search
chronoai-shining May 19, 2026
f79c16c
Merge branch 'develop' into feat/461-integrity-hash
chronoai-shining May 19, 2026
0ae3663
Merge branch 'develop' into docs/473-sdk-publish
chronoai-shining May 19, 2026
c7c62ae
refactor(api): introduce skillId helper, drop `as any` on _id queries…
chronoai-shining May 19, 2026
2bfe889
Merge pull request #610 from ChronoAIProject/fix/446-admin-search
chronoai-shining May 19, 2026
fb4086b
Merge branch 'develop' into feat/461-integrity-hash
chronoai-shining May 19, 2026
f200c74
Merge branch 'develop' into docs/473-sdk-publish
chronoai-shining May 19, 2026
f213212
Merge branch 'develop' into fix/448-toobjectid
chronoai-shining May 19, 2026
8c22821
ci(python-sdk): add pip-audit + bound transitive deps (#445)
chronoai-shining May 19, 2026
8bdcc3f
Merge pull request #611 from ChronoAIProject/feat/461-integrity-hash
chronoai-shining May 19, 2026
4ef23d8
Merge branch 'develop' into docs/473-sdk-publish
chronoai-shining May 19, 2026
d180759
Merge branch 'develop' into fix/448-toobjectid
chronoai-shining May 19, 2026
c0cbf58
Merge branch 'develop' into ci/445-python-sdk-lockfile
chronoai-shining May 19, 2026
296eabf
Merge pull request #612 from ChronoAIProject/docs/473-sdk-publish
chronoai-shining May 19, 2026
cd54c70
Merge branch 'develop' into fix/448-toobjectid
chronoai-shining May 19, 2026
4d84db6
Merge branch 'develop' into ci/445-python-sdk-lockfile
chronoai-shining May 19, 2026
e30af9f
feat(api): return 201 + Location on resource-creating POSTs (#458)
chronoai-shining May 19, 2026
08880e6
Merge pull request #613 from ChronoAIProject/fix/448-toobjectid
chronoai-shining May 19, 2026
39b0ba7
Merge branch 'develop' into ci/445-python-sdk-lockfile
chronoai-shining May 19, 2026
d32f2a8
Merge branch 'develop' into feat/458-post-created
chronoai-shining May 19, 2026
521ebc8
ci(python-sdk): fix pip-audit invocation (#445)
chronoai-shining May 19, 2026
343b213
ci(python-sdk): skip editable in pip-audit (ornn-sdk not on PyPI yet)
chronoai-shining May 19, 2026
c6d284e
ci(python-sdk): install deps directly for pip-audit (skip editable or…
chronoai-shining May 19, 2026
c8ffdff
fix(python-sdk): bump pytest to >=9.0.3 (CVE-2025-71176)
chronoai-shining May 19, 2026
9f6deb1
Merge pull request #614 from ChronoAIProject/ci/445-python-sdk-lockfile
chronoai-shining May 19, 2026
0585929
Merge branch 'develop' into feat/458-post-created
chronoai-shining May 19, 2026
b0d77d4
ci(python-sdk): add ruff + mypy gates, clean up flagged code (#583)
chronoai-shining May 19, 2026
d67d3da
fix(web): render not-found state on Playground when skill is 404 (#563)
chronoai-shining May 19, 2026
447355b
Merge pull request #615 from ChronoAIProject/ci/583-ruff-mypy
chronoai-shining May 19, 2026
9855ca4
Merge branch 'develop' into feat/458-post-created
chronoai-shining May 19, 2026
11e31c8
Merge branch 'develop' into fix/563-playground-private-skill-v2
chronoai-shining May 19, 2026
8d6e54b
ci: integrate Codecov + add coverage badge (#471)
chronoai-shining May 19, 2026
e5a9ca3
Merge pull request #616 from ChronoAIProject/ci/471-codecov
chronoai-shining May 19, 2026
37e5f43
Merge branch 'develop' into feat/458-post-created
chronoai-shining May 19, 2026
0aa265d
Merge branch 'develop' into fix/563-playground-private-skill-v2
chronoai-shining May 19, 2026
c12e7bb
Merge pull request #618 from ChronoAIProject/feat/458-post-created
chronoai-shining May 19, 2026
7fffa31
Merge branch 'develop' into fix/563-playground-private-skill-v2
chronoai-shining May 19, 2026
59269fe
Merge pull request #619 from ChronoAIProject/fix/563-playground-priva…
chronoai-shining May 19, 2026
72ae5d3
feat!: lowercase_snake_case error codes (#585)
chronoai-shining May 19, 2026
a195ec6
Merge pull request #621 from ChronoAIProject/feat/585-lowercase-error…
chronoai-shining May 19, 2026
096a103
feat!: URL + header conventions per CONVENTIONS.md (#586)
chronoai-shining May 19, 2026
7f3d858
Merge pull request #622 from ChronoAIProject/feat/586-url-conventions
chronoai-shining May 19, 2026
d39ac3a
feat!: drop legacy ownerId + dead auth-chain exports (#581)
chronoai-shining May 19, 2026
0da1801
Merge pull request #623 from ChronoAIProject/feat/581-drop-ownerid
chronoai-shining May 19, 2026
cfedcec
feat!: RFC 7807 application/problem+json error envelope (#456)
chronoai-shining May 19, 2026
87383fc
Merge pull request #625 from ChronoAIProject/feat/456-rfc7807-envelope
chronoai-shining May 19, 2026
c3a1e57
feat(api): publish JSON Schema for SKILL.md frontmatter (#464)
chronoai-shining May 19, 2026
d3b7fb9
docs(conventions): describe skill manifest JSON Schema endpoint (#464)
chronoai-shining May 19, 2026
e27639d
feat(api): add Idempotency-Key middleware module (#459)
chronoai-shining May 19, 2026
f4bbdb1
feat(api): wire Idempotency-Key middleware into the request chain (#459)
chronoai-shining May 19, 2026
377f849
feat(api): dist-tag schema + service layer (#463)
chronoai-shining May 19, 2026
1177265
feat(api): 3 dist-tag routes wired on /skills (#463)
chronoai-shining May 19, 2026
f5c092b
Merge pull request #626 from ChronoAIProject/feat/464-frontmatter-jso…
chronoai-shining May 19, 2026
8c4755a
fix(api): drop unused `c` arg in idempotency test handler (#459)
chronoai-shining May 19, 2026
97b7df6
Merge branch 'develop' into feat/463-dist-tags
chronoai-shining May 19, 2026
7956816
Merge pull request #628 from ChronoAIProject/feat/463-dist-tags
chronoai-shining May 19, 2026
d524692
Merge branch 'develop' into feat/459-idempotency-key
chronoai-shining May 19, 2026
6237622
Merge pull request #627 from ChronoAIProject/feat/459-idempotency-key
chronoai-shining May 19, 2026
ce7aeab
feat(api): harden AgentSeal subprocess — path validation + unref on k…
chronoai-shining May 20, 2026
0bccacf
feat(api): add AGENTSEAL_ENABLED config + thread through bootstrap (#…
chronoai-shining May 20, 2026
d843e0b
chore(api): tighten 31 bare catch {} blocks (#579)
chronoai-shining May 20, 2026
632ff6c
feat(api): backend zip-bomb caps mirroring #443 client guards (#633)
chronoai-shining May 20, 2026
d039964
fix(api): sweep c.req.json() bypass pattern (#438)
chronoai-shining May 20, 2026
999cea2
chore: enable noImplicitOverride across ornn-api/web/sdk (#450 part 1)
chronoai-shining May 20, 2026
a455714
Merge pull request #634 from ChronoAIProject/feat/442-agentseal-path-…
chronoai-shining May 20, 2026
4436e0e
Merge branch 'develop' into chore/579-bare-catch-sweep
chronoai-shining May 20, 2026
83aa8ca
Merge pull request #635 from ChronoAIProject/chore/579-bare-catch-sweep
chronoai-shining May 20, 2026
792dcc3
Merge branch 'develop' into feat/633-zip-bomb-backend-caps
chronoai-shining May 20, 2026
3ebf56b
Merge pull request #636 from ChronoAIProject/feat/633-zip-bomb-backen…
chronoai-shining May 20, 2026
d181fc6
Merge branch 'develop' into fix/438-validate-body-sweep
chronoai-shining May 20, 2026
eeff22f
Merge pull request #637 from ChronoAIProject/fix/438-validate-body-sweep
chronoai-shining May 20, 2026
e775017
Merge branch 'develop' into chore/450-stricter-ts-flags
chronoai-shining May 20, 2026
9789209
Merge pull request #638 from ChronoAIProject/chore/450-stricter-ts-flags
chronoai-shining May 20, 2026
018f9b9
test(api): OpenAPI spec contract tests (#462)
chronoai-shining May 20, 2026
679973a
Merge pull request #642 from ChronoAIProject/ci/462-openapi-contract-…
chronoai-shining May 20, 2026
7179349
feat: docker-compose for one-command local dev (#466)
chronoai-shining May 20, 2026
b1dd75f
Merge pull request #643 from ChronoAIProject/feat/466-docker-compose
chronoai-shining May 20, 2026
d7985f0
chore(api): consolidate 61 standalone pino loggers behind createLogge…
chronoai-shining May 20, 2026
9149673
Merge pull request #644 from ChronoAIProject/chore/575-logger-consoli…
chronoai-shining May 20, 2026
17cd5d2
feat: cursor pagination + SDK searchAll iterator (#457 + #465)
chronoai-shining May 20, 2026
d93a1b2
Merge pull request #645 from ChronoAIProject/feat/457-465-cursor-pagi…
chronoai-shining May 20, 2026
16fabb2
feat(api): sliding-window rate limit + RFC 9239 headers (#439 + #460)
chronoai-shining May 20, 2026
7de8c5e
Merge pull request #646 from ChronoAIProject/feat/439-460-rate-limiting
chronoai-shining May 20, 2026
3d50e90
test(api): backfill repository unit tests for 6 domains + platform se…
chronoai-shining May 20, 2026
e5f60a5
refactor(api): decompose bootstrap.ts into per-domain wiring modules …
chronoai-shining May 20, 2026
a3476ac
refactor(web): decompose SkillDetailPage into 9 colocated components …
chronoai-shining May 20, 2026
3eeb787
chore: enable stricter TS flags across all 3 packages (#450) (#658)
chronoai-shining May 21, 2026
5b63dbd
refactor(web): decompose DocsPage into 5 colocated components (#453) …
chronoai-shining May 21, 2026
e97dfdd
refactor(web): decompose PlaygroundPage into 6 colocated components (…
chronoai-shining May 21, 2026
9a54497
chore(api): enable exactOptionalPropertyTypes on ornn-api (#657 part …
chronoai-shining May 21, 2026
9374483
chore(web): enable exactOptionalPropertyTypes on ornn-web (#657 part …
chronoai-shining May 21, 2026
6752f42
refactor(web): extract useSkillDetail() hook from SkillDetailPage (#4…
chronoai-shining May 21, 2026
f036395
refactor(web): extract usePlaygroundSession() hook from PlaygroundPag…
chronoai-shining May 21, 2026
b737c1b
chore(infra): direct ornn-api ingress for anonymous browse (#661) (#666)
chronoai-shining May 21, 2026
227bf88
revert(infra): remove direct ornn-api ingress from #661 (#667)
chronoai-shining May 21, 2026
da38626
fix(web): TagInput duplicate handling — clear input + show error (#65…
chronoai-shining May 21, 2026
c00a4c8
fix(api): admin user search matches display name + email (#587) (#669)
chronoai-shining May 21, 2026
e5e4f0c
fix: chat composer length cap + visible counter (#654) (#670)
chronoai-shining May 21, 2026
e6df2fc
fix(web): validate guided supporting-file uploads (#655) (#671)
chronoai-shining May 21, 2026
4a34183
fix(api): frontmatter validation errors are actionable (#649) (#672)
chronoai-shining May 21, 2026
38c875b
fix: install-card prompt pins to viewed skill version (#639) (#673)
chronoai-shining May 21, 2026
1cbe0ea
fix(web): real popover for BroadcastsPage recipients tooltip (#507) (…
chronoai-shining May 21, 2026
7aa1710
fix(web): Free/ZIP upload restores real pre-submit state on reject (#…
chronoai-shining May 21, 2026
dccbdb3
fix(web): drop dead X-User-* headers from createSkill + logActivity (…
chronoai-shining May 21, 2026
2033791
fix(web): three quota refresh races on Playground + Skill Gen (#629 +…
chronoai-shining May 21, 2026
cadc31e
chore(api): delete dead backfill-skill-author-display-names script (#…
chronoai-shining May 21, 2026
8c499ac
fix(api): LLM provider save preserves models + Playground default pin…
chronoai-shining May 21, 2026
f737be3
fix(api): GitHub import `skipValidation` bypasses frontmatter Zod too…
chronoai-shining May 21, 2026
fc84e40
fix(web): dedup concurrent NyxID token-refresh requests (#631) (#678)
chronoai-shining May 21, 2026
6fad5ca
docs(readme): add Ornn hero brand image above status pills (#684) (#685)
chronoai-shining May 21, 2026
837933a
fix(web): Registry page localises end-to-end in ZH mode (#682) (#687)
chronoai-shining May 21, 2026
8a766be
fix(web): Guided env-var input enforces 30-item cap inline (#683) (#686)
chronoai-shining May 21, 2026
a3f7bbe
docs(readme): trim badge row to CI + release + license (#688) (#689)
chronoai-shining May 21, 2026
5857a93
docs(assets): store hero SVG suite for future README use (#690) (#691)
chronoai-shining May 21, 2026
35f864d
docs(readme): swap hero to <picture> with dark variant (#692) (#693)
chronoai-shining May 21, 2026
b647bc2
docs(readme): rework header — drop logo, dark-only clickable hero, ba…
chronoai-shining May 22, 2026
5cfce09
docs(readme): remove premature SDK quickstart section (#701)
chronoai-shining May 22, 2026
a5fce28
docs: changeset for #701
chronoai-shining May 22, 2026
6b60f7e
Merge pull request #702 from ChronoAIProject/claude/kind-lamport-3b418c
chronoai-shining May 22, 2026
9c43b54
docs(readme): restructure to tight 5-section layout (#703)
chronoai-shining May 22, 2026
10f45c7
docs: changeset for #703
chronoai-shining May 22, 2026
c405f6c
Merge pull request #704 from ChronoAIProject/claude/readme-restructure
chronoai-shining May 22, 2026
fab2198
docs(readme): restyle How-it-works mermaid with Editorial Forge palet…
chronoai-shining May 22, 2026
89ef0f0
docs: changeset for #705
chronoai-shining May 22, 2026
da64d7f
Merge pull request #706 from ChronoAIProject/claude/readme-mermaid-re…
chronoai-shining May 22, 2026
1c6acc2
docs(readme): polish How-it-works mermaid — bracketed titles, edge-la…
chronoai-shining May 22, 2026
2248a51
docs: changeset for #707
chronoai-shining May 22, 2026
703097f
Merge pull request #708 from ChronoAIProject/claude/readme-mermaid-po…
chronoai-shining May 22, 2026
c500e83
fix(web): mirror actionable invalid_type messages on frontend Zod sch…
chronoai-shining May 22, 2026
caaa74f
fix(web): EditSkillPage hands skill.guid to write mutations (#565) (#…
chronoai-shining May 22, 2026
dd6abe5
fix(api): route LLM requests on provider apiFormat (#574) (#733)
chronoai-shining May 28, 2026
228edb9
fix(api): reuse chrono-sandbox session across tool rounds (#531) (#734)
chronoai-shining May 28, 2026
74b8f93
fix(api): drop deactivated NyxID services from system-services facet …
chronoai-shining May 28, 2026
efd0f32
fix(web): P1 i18n cluster — 6 admin/creation surfaces follow active l…
chronoai-shining May 28, 2026
1cb7a4f
fix(web): drop credentials:'include' from login activity POST (#709) …
chronoai-shining May 28, 2026
8d29da8
fix(web): refresh all-versions list + z-bump toast above modals (#699…
chronoai-shining May 28, 2026
8f05f5d
fix(web): include path + rephrase required-gates in section form erro…
chronoai-shining May 28, 2026
08120dc
fix(web): preserve backend error.message envelope on non-2xx (#694) (…
chronoai-shining May 28, 2026
41f1195
fix(api): keep user env values out of LLM prompt + override at sandbo…
chronoai-shining May 28, 2026
8f85c8f
fix(web): P2 cluster — mirror route, mode-card alignment, search plac…
chronoai-shining May 28, 2026
44f0010
fix(api): friendly sandbox error in playground transcript (#530) (#746)
chronoai-shining May 28, 2026
89cbc29
fix(web): poll bell notifications list on same 30s as count (#728) (#…
chronoai-shining May 28, 2026
acad1a9
fix(web): surface failed audit rerun on Skill Detail (#718) (#743)
chronoai-shining May 28, 2026
fb7c06b
fix(web): notifications scroll + semantic-empty validation (#723 #726…
chronoai-shining May 28, 2026
3bfc7a0
fix: stale share-target metadata — search filter + flagged chips (#72…
chronoai-shining May 28, 2026
27fa8e3
docs: prep release v0.9.0 (#754)
chronoai-shining May 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
5 changes: 5 additions & 0 deletions .changeset/admin-search-cap-446.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"ornn-api": patch
---

Add `maxTimeMS` + ensure indexes on admin skill search (#446). `GET /admin/skills?q=…` ran an escaped `$regex` against `name` and `description` with no time cap and no documented indexes — a crafted partial-match query on a large collection could pin a Mongo node's CPU indefinitely. Adds a 5 s `maxTimeMS` to both `countDocuments` + `find`, and a new `SkillRepository.ensureIndexes()` (wired into bootstrap) that creates `name` (unique), `description`, `createdBy + createdOn`, `createdOn`, and `isPrivate + createdOn` indexes — partial-regex still can't use a btree, but the secondary filters (`createdBy=…`, `isPrivate=…`) and the `createdOn` sort now hit indexes instead of a full collection scan.
19 changes: 19 additions & 0 deletions .changeset/admin-settings-zod-actionable-698.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
"ornn-web": patch
---

`useSectionForm` validation errors now include the offending field path and rephrase length-1 string failures as "is required" instead of the raw `Too small: expected string to have >=1 characters` (#698).

The shared admin-settings form hook joined `i.message` only when surfacing Zod validation issues. The Mirror section (and every other section that uses `.min(1)` as a required-field gate) ended up emitting a single SectionShell alert that read like:

> Too small: expected string to have >=1 characters; Too small: expected string to have >=1 characters; Too small: expected string to have >=1 characters; ...

— with no indication of which fields needed filling.

Fix: prefix each issue with `path.join(".")`, and for the specific `code: "too_small"` + `type: "string"` + `minimum: 1` triple swap the message to `is required`. Renders as:

> owner: is required; repo: is required; branch: is required; appId: is required; installationId: is required; appPrivateKey: is required

— actionable from the alert alone, no schema-by-schema rewrite needed.

Per-section schemas can still ship their own friendlier messages (`.min(1, "Owner is required")`) — those flow through `i.message` unchanged.
13 changes: 13 additions & 0 deletions .changeset/admin-user-search-display-name-587.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
"ornn-api": patch
---

Admin Users search now matches display name as well as email (#587).

The search input's placeholder said "email or display name" but the Mongo filter only matched `email` with an anchored-prefix regex. Display names + display-name substrings were silently ignored, so admins typing `Haylee01` or `Proxy` got empty result lists even though those users existed.

Fix is additive — the email behaviour is preserved (still an anchored, case-insensitive prefix match), and a case-insensitive **substring** match on `displayName` is OR'd in alongside it. Display names don't have a meaningful prefix (the issue's reproducer was `Proxy` matching `Ornn Local Proxy`), so substring is the right shape.

Both the unbounded `findAllInRole` (the admin dashboard's paginated-in-memory path) and the paginated `listUsers` (the page-then-fetch path) use the same `buildUserSearchFilter` helper so they stay in sync.

Regex metacharacters in the query are escaped, same as before — pinned with a new test so the escape stays in place.
11 changes: 11 additions & 0 deletions .changeset/agentseal-path-validation-442.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
"ornn-api": patch
---

Harden the AgentSeal subprocess (#442). Two defensive changes, both small.

**Boot-time path validation.** `AgentSealScanner`'s constructor now refuses `python` / `script` config values that aren't absolute paths to existing regular files. Closes a lateral-movement gap: if scanner config ever sourced from a less-trusted place (admin-editable UI, env that picks up `PATH`), `spawn("python", ...)` would silently resolve against `$PATH` and let an attacker swap in any binary they could plant on the search path. Validation only fires when `enabled: true`, so dev/test envs that don't have agentseal installed can boot fine. New `AGENTSEAL_ENABLED=false` env flag toggles the whole scanner (default `true`).

**Unref child after kill.** When the subprocess hits the timeout and we send SIGTERM / SIGKILL, we now also call `child.unref()` so the killed process can no longer keep the API event loop alive during shutdown. Previously, a scanner mid-flight when the API received SIGTERM could delay graceful shutdown by up to `timeoutMs + 1s`.

Tests: 6 new assertions on the path validator (relative rejected, missing rejected, directory rejected, disabled skips validation, happy path constructs, helper unit-tested). Existing subprocess tests adjusted to use a real on-disk dummy script.
4 changes: 4 additions & 0 deletions .changeset/api-stability-doc-474.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
---

Publishes `docs/API_STABILITY.md` (#474) — the public stability commitment for `/api/v1/*`. Codifies the alpha caveat, the post-v1 semver policy, three stability tiers (`stable` / `beta` / `experimental` declared via OpenAPI `x-stability`), and the deprecation policy (RFC 8594 headers, two-minor-release lead time, signal channels, breaking-change checklist). Linked from README docs section; `CONVENTIONS.md §7` cross-links here.
5 changes: 5 additions & 0 deletions .changeset/apidelete-dedup-578.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"ornn-web": patch
---

Route `apiDelete` through `fetchWithRetry` (#578) so the proactive-refresh / 401-retry / redirect-to-login logic lives in one place instead of being copy-pasted between `GET/POST/PATCH/PUT` and DELETE. Behaviour-equivalent: DELETE still proactively refreshes, retries once on 401, redirects to `/login` if refresh fails, and surfaces non-2xx responses as `ApiClientError`. Only observable difference is the default error code on bodyless failures is now `UNKNOWN_ERROR` instead of `DELETE_FAILED` — that string was a dead default, no caller checks it.
11 changes: 11 additions & 0 deletions .changeset/audit-rerun-silent-fail-718.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
"ornn-web": patch
---

Skill Detail now surfaces a "latest rerun failed" indicator next to the score so a failed audit rerun is no longer invisible (#718).

Background: `auditSummaryByVersion` returns the latest *completed* audit per version. When a rerun ends in `failed`, the summary still points at the previous successful record, and Skill Detail renders that stale score — visually identical to "current passing audit". Admins only discovered the failure by opening Audit History.

Fix: `useSkillDetail` already loads `versionAuditHistory` (newest-first across all statuses) to compute `versionAuditRunning`. Compute one more derived flag from it — `versionAuditLatestFailed = history[0].status === "failed" && newer than the displayed completed audit` — and thread it through to `AuditVerdictPill` as the new `latestRerunFailed` prop. The pill keeps the old completed score (so admins can still see the last-good number) and renders a danger-toned banner directly below: "Latest rerun failed — score above is from the prior audit. Check audit history for details." (`skillDetail.auditLatestFailed`).

No backend change. The shape `getAudit` returns is unchanged — the gap was that the *latest-of-any-status* signal was already in hand and just wasn't propagated.
9 changes: 9 additions & 0 deletions .changeset/bare-catch-sweep-579.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
"ornn-api": patch
---

Audit + tighten the 31 bare `catch {}` blocks across `ornn-api/src` (#579).

Critical-path catches that swallowed errors silently now capture the error and emit `logger.debug({ err }, '…')` — analytics dispatch, NyxID org lookups, audit-bundle reads, audit-JSON parse, package-parse on source-refresh, optional JSON-array form fields, generation-context binary skips, LLM output parse, GitHub URL parse. Caller behavior is unchanged (still returns null / falls back to defaults), but a misconfigured or broken upstream is now observable in logs instead of hidden behind an empty result set.

The catches that already logged, already rethrew as `AppError`, or where the return value IS the signal (validation result, violation list, parse-failure fallback) are left alone. Each one that stays silent on purpose now carries a one-line comment explaining why, so a future reader doesn't re-flag it.
25 changes: 25 additions & 0 deletions .changeset/bootstrap-decompose-580.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
---
"ornn-api": patch
---

Decompose `bootstrap.ts` per-domain (#580).

Lifts 10 leaf domains' wiring out of the 1089-line `bootstrap.ts` monolith into per-domain `bootstrap.ts` modules. Each one exports a `wire{Domain}({ db, logger, ...deps })` function that bundles repo construction + `ensureIndexes()` fire-and-forget catch + any one-shot boot migration + service construction + routes construction into a single call. The orchestrator stays in charge of *ordering* and shared client construction; the per-domain *detail* moves out.

Domains extracted:

- announcements
- analytics
- quota (consumed by playground / skill-gen / admin)
- redemption-codes (admin + me route surfaces, shared service for atomic pivot consistency)
- broadcasts (2-step: shared repo first, then service + routes)
- notifications (consumes shared broadcasts repo for the merged feed)
- platform settings (legacy single-doc surface)
- admin (dashboard + users + quota admin)
- skill search
- skill generation
- playground

What's still inlined: skills CRUD, skill audit, GitHub mirror, settings export/import, and `createAdminRoutes` (skill / generation / agentseal admin). These have heavier cross-cutting dependency lists (scheduler lifecycle, audit fan-out, analytics emitter closures) — extracting them cleanly needs a follow-up.

bootstrap.ts: **1089 → 970 lines** (-11%, -119 lines net). No behavioral change — boot order is preserved, all 798 tests still pass.
5 changes: 5 additions & 0 deletions .changeset/chat-events-zod-449.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"ornn-api": patch
---

Type-check playground LLM stream events with a Zod discriminated union (#449). `chatService` previously read `event.type`, `event.delta`, `event.item` via `as any` — a runtime no-op that let upstream field renames silently propagate `undefined` through the SSE stream to clients. Three permissive schemas (`response.output_text.delta`, `response.content_part.delta`, `response.output_item.done`) now gate every event; unknown shapes are dropped with a debug log so the upstream API can add fields freely without breaking us.
26 changes: 26 additions & 0 deletions .changeset/chat-input-length-cap-654.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
"ornn-web": patch
"ornn-api": patch
---

Chat composer length cap + counter (#654).

The Playground + AI-generation chat composer accepted prompts of any length — the live reproducer was 24 000 chars typed, send button still enabled, no warning. Backend caps existed only for message *count* (100), never message *content*.

Front-end (`ChatInput.tsx`):

- `maxLength={32_000}` on the textarea — browser-side hard cap on typing / paste.
- Live `<used> / <max>` counter appears once the input crosses 24 000 chars (75 %); stays hidden below that so the composer isn't chromed for normal use.
- Counter flips danger-tone + send button disables when content is over the cap (defensive — `maxLength` should make this unreachable, but covers IME / non-browser-paste edge cases).
- Imperative `setValue` (used by suggestion-prompt clicks) truncates past the cap so curated copy can't bypass the limit silently.

Back-end:

- `playgroundMessageSchema.content` adds `.max(MAX_CHAT_MESSAGE_CHARS)` — rejects with `400 content_too_long` (RFC 7807 envelope).
- `skills/generation` JSON path validates prompt length AND each multi-turn message's content length symmetrically — rejects with `400 prompt_too_long` or `400 content_too_long`.

The 32 000-char ceiling is `~8k tokens` at 4 chars/token. Generous for interactive prompts without enabling whole-novel pastes; the three constants are deliberately duplicated across `ChatInput.tsx`, `playground/routes.ts`, and `skills/generation/routes.ts` with cross-referencing comments so a change in one stays in step with the others.

Pinned with `ChatInput.test.tsx` (7 assertions covering `maxLength` attribute, counter visibility, send-enable / disable, imperative truncate, empty disabled).

Closes #654.
4 changes: 4 additions & 0 deletions .changeset/codecov-471.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
---

Codecov integration + coverage badge (#471). CI now runs `bun test --coverage` (per-workspace lcov) and `pytest --cov` (sdk/python coverage.xml) and uploads both via `codecov/codecov-action@v4` — separate `bun` / `python` flags so a regression in one language is obvious. New `codecov.yml` commits to a realistic 70% project / 80% patch target and excludes the four god-files awaiting decomposition (SkillDetailPage, DocsPage, PlaygroundPage, bootstrap.ts) so the headline number reflects code that's reasonably testable today. README gains the Codecov badge.
19 changes: 19 additions & 0 deletions .changeset/concurrent-token-refresh-dedup-631.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
"ornn-web": patch
---

Deduplicate concurrent NyxID token-refresh requests (#631).

`authStore.refreshToken()` could fire 2–4 times within the same millisecond — `apiClient.fetchWithRetry`'s proactive `ensureFreshToken()`, its reactive 401-retry path, the scheduled `startTokenRefresh` `setTimeout`, and the `visibilitychange` handler all converge near the expiry boundary. Each fired its own `POST /oauth/token` with `grant_type=refresh_token`.

NyxID rotates the refresh token on every successful exchange. The second concurrent caller therefore lost the rotation race and got:

```json
{"error":"invalid_request","error_description":"Conflict: Refresh token was concurrently rotated, please retry"}
```

…which the SPA's `refreshToken` `catch` interpreted as a hard failure: it nulled the access + refresh tokens and surfaced an unexpected logout. Users observed it as "I came back to the tab and got logged out".

Fix funnels every caller through a single `_refreshInFlight: Promise<void> | null` slot on the store. The first caller stores the promise; subsequent callers `await` the same one. The slot is cleared in `finally` so a later (truly new) refresh starts fresh.

Slot is excluded from `partialize` — Promises aren't serialisable and the dedup window only matters within a tab's lifetime.
13 changes: 13 additions & 0 deletions .changeset/cors-cleanup-528.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
"ornn-web": patch
---

Remove dead `X-User-*` headers from skill-create + activity log (#528).

`createSkill` (POST /api/v1/skills — used by Free / Guided / AI-generated save) and `logActivity` (POST /api/v1/activity/login|logout) still attached `X-User-Email` / `X-User-Display-Name` headers, leftover from a pre-NyxID-proxy auth model where the backend read identity off these headers. The backend hasn't read them in months (identity comes from the proxy-forwarded JWT), and the `apiClient.createHeaders` cleanup that struck the same code from the shared client missed these two raw-`fetch` callers.

Sending them caused the browser's CORS preflight to ask permission for `X-User-Email` and `X-User-Display-Name`. The backend CORS allowlist is `["Content-Type", "Authorization"]` (`bootstrap.ts:744`), so the preflight response didn't include those headers — the browser then blocked the actual `POST` with a CORS error. End user sees: "Save Skill" never completes, DevTools shows preflight `204` then a `CORS error` on the real request.

Net change: both callers now send only `Content-Type` + `Authorization` (matching the rest of the SDK), the preflight allow-headers list is fully satisfied, and the real request goes through.

This is the definitive fix for the `POST /skills` case. The `PUT /skills/:id` case tracked in #565 doesn't send `X-User-*` itself, but the parallel login-time `logActivity` failure here was producing a CORS-error toast that could be misattributed to the in-flight PUT — worth re-verifying #565 after this lands.
32 changes: 32 additions & 0 deletions .changeset/cursor-pagination-457-465.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
---
"ornn-api": minor
"@chronoai/ornn-sdk": minor
---

Cursor pagination on `/skill-search` per CONVENTIONS.md §4.3 + SDK auto-pagination iterator (#457 + #465).

**API (`/api/v1/skill-search`)**

- Accepts `?cursor=<opaque-base64>` (alongside the existing `?page=N`). When both are sent, `cursor` wins.
- Accepts `?limit=N` as an alias for the existing `?pageSize=N`.
- Response now carries a `meta` envelope: `{ data: { items, total, page, pageSize, totalPages, meta: { limit, hasMore, nextCursor? } }, error }`. The legacy fields stay until they're sunset — clients can migrate at their own pace.
- A malformed cursor returns `400 invalid_cursor` (RFC 7807 problem+json) instead of silently falling back to page 1.
- Cursor payload is server-internal (`{ page: number }` today, `lastSort` keyset in a future PR) — clients MUST treat it as opaque.

**SDK (`@chronoai/ornn-sdk`)**

- `client.search()` now accepts `cursor` + `limit` params (additive).
- New `client.searchAll({ q })` returns an `AsyncIterableIterator<SkillSummary>`. Threads `meta.nextCursor` automatically; terminates on `hasMore === false` or no more cursor. 10k-page safety cap.

```ts
for await (const skill of client.searchAll({ q: "pdf" })) {
console.log(skill.name);
}
```

**Out of scope (follow-up)**

- Real lastSort keyset cursor under the hood — current cursor encodes `{ page }` so the wire contract conforms to §4.3 while the underlying query stays offset-based. Switching the payload is invisible to clients.
- Cursor support on other list endpoints (categories, tags, users) — those keep their existing offset shape for now.
- Python SDK `search_all()` — follow-up.
- `Sunset:` header on the legacy `page`/`pageSize` shape — once cursor adoption is high enough.
5 changes: 5 additions & 0 deletions .changeset/delete-dead-skill-repo-577.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"ornn-api": patch
---

Delete dead `domains/skills/crud/repositories/` subdirectory (#577) — a 218-line `SkillRepository` impl + interface + test that no route, service, or test outside the directory itself imported. The live skill repository (915 lines) lives at `domains/skills/crud/repository.ts` and is unaffected.
29 changes: 29 additions & 0 deletions .changeset/dist-tags-463.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
---
"ornn-api": minor
---

Add dist-tags for skill versions (#463). Lets callers pin to a stable channel without enumerating versions or hard-coding numbers, matching the shape npm / yarn / pnpm exposes.

**New surface**

```http
GET /api/v1/skills/{idOrName}/dist-tags → { tags: { latest, stable, ... } }
PUT /api/v1/skills/{id}/dist-tags/{tag} Body: { version }
DELETE /api/v1/skills/{id}/dist-tags/{tag}
GET /api/v1/skills/{idOrName}?version=@stable → resolves via dist-tag
```

`SkillDetailResponse` now carries a `distTags` field on every read.

**Semantics**

- `latest` is **auto-managed**. Every successful publish sets `distTags.latest = newVersion`. `PUT` / `DELETE` against `latest` return 400 `dist_tag_immutable`.
- Custom tags (`stable`, `beta`, `rc-1`, ...) are owner-managed. Tag names match `/^[a-z][a-z0-9-]{0,49}$/` — npm rules, leading letter required so tags don't look like version numbers.
- Setting a tag for a non-existent version returns 404 `skill_version_not_found`.
- `?version=@latest` falls back to `skill.latestVersion` on legacy skills predating this PR so the resolution path stays compatible.

**Out of scope**

- TS / Python SDK helper methods around dist-tags — the endpoints work directly via the raw client. SDK convenience wrappers ride in a follow-up so this PR stays scoped.
- OpenAPI spec entries for the new paths — `/api/v1/openapi.json` is already incomplete for `/skills/:id/*` write paths; the bigger contract-test pass in #462 will pick all of them up at once.
- schemastore-style schema for the dist-tag write body (not visible in any IDE flow today).
14 changes: 14 additions & 0 deletions .changeset/docker-compose-466.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
"ornn-api": patch
"ornn-web": patch
---

Ship a `docker-compose.yml` for one-command local dev (#466). Brings up MongoDB, MinIO, `ornn-api`, and `ornn-web` in a single `docker compose up`. README's new "Run Ornn locally (5 minutes)" section and `CONTRIBUTING.md`'s rewritten "Getting set up" tier the prerequisites by what each contributor actually needs:

- **Unit tests / lint / typecheck:** just Bun + Docker.
- **Running the services:** `docker compose up`.
- **Full integration with NyxID / chrono-storage / chrono-sandbox / opensandbox:** the existing K8s manifests under `deployment/`.

NyxID stays out of compose deliberately — mocking the OAuth + JWT-signing path is non-trivial and would either ship a fake or pin to a real staging. Public endpoints (`/livez`, `/api/v1/skill-format/rules`, `/api/v1/skill-manifest-schema.json`, OpenAPI spec) work without auth, which is enough for most contributor flows. Auth-required endpoints need `NYXID_BASE_URL` pointed at your own NyxID instance — same model the existing `deployment/.env.ornn` uses.

Includes a sample `.env.compose.sample` with the only knob a contributor typically overrides (`ENCRYPTION_KEY`).
Loading
Loading