m4
|
aae8d0a379
|
feat: workspace file references, read-file-images middleware, image model enabled flag
In-progress work committed to unblock the config import/export plan:
- prompts: FILE_REFERENCES section for workspace-relative file citation
- backends: resolve quoted virtual absolute paths onto the sandbox workspace
- middleware: read_file_images middleware; message_budget extensions
- image_gen/model_registry: image model 'enabled' flag refactor
- memory/launch, gateway/background_runs, tools/image follow-ons
- scripts: dev_backend.sh, release.sh
- tests for the above
|
2026-08-12 19:43:35 +08:00 |
|
m4
|
dbb6b7abde
|
feat(model-registry): add delegation-JWT auth and config/snapshot HTTP API
- BFF service token (constant-time, plaintext or SHA-256 hash) plus
X-Evo-Actor delegation JWT verification (ES256/RS256, iss/aud, <=60s
lifetime, required claims, thread binding) with atomic jti anti-replay
- Config API: GET/PUT /api/model-registry, credential rotation endpoint,
GET /api/models selector; PUT runs the section 9.2 save-time checks
inside the registry write transaction after credential writes
- Snapshot API: create/bind/delete routes delegating to SnapshotService
with thread/deployment binding checks and 9.5 unified error payloads
- Platform security config loader (config.yaml fields), OpenAPI export
(scripts/export_model_registry_schema.py -> model_registry/openapi.json)
- Mount new routes in langgraph_dev/http.py; retire the legacy
GET /api/models and POST /api/runtime-snapshots handlers
- Declare PyJWT>=2.8 (previously transitive); extend the 9.5 error code
table with the HTTP-layer codes (400/401/403/422/500)
|
2026-07-21 09:28:55 +08:00 |
|