Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
68 commits
Select commit Hold shift + click to select a range
dc85985
🗄️ fix: Fall Back to In-Memory Storage When Web Storage Is Denied (#1…
berry-13 Sep 28, 2026
ae71af6
🥤 fix: Keep Pending Code Steers Within the Composer (#16446)
lia-by-librechat[bot] Sep 28, 2026
a9b4916
🧻 fix: Clear Stale Draft Text After Sending (#16444)
lia-by-librechat[bot] Sep 28, 2026
fcb8871
📃 style: Match File Activity Icons To File Rows (#16445)
lia-by-librechat[bot] Sep 28, 2026
76dbb93
🧤 docs: Define Safe Backend Error Contracts in AGENTS.md (#16443)
lia-by-librechat[bot] Sep 28, 2026
50ce289
🎚️ fix: Apply librechat.yaml Rate Limits to Route Limiters (#16432)
berry-13 Sep 28, 2026
71398ae
🔒 fix: Guard 2FA Deep-Link Redirects Against Blocked Session Storage …
berry-13 Sep 28, 2026
ffa54e0
⛴️ chore: Bring Canary Up to Date With Dev
lia-librechat Sep 28, 2026
e20558b
⛴️ fix: Keep MCP App and Speech Limits in One E2E Config
lia-librechat Sep 28, 2026
d8b9371
⛴️ test: Check Code Steers in the Canary Thread
lia-librechat Sep 28, 2026
40bb16e
🎼 feat: Add Claude Sonnet 5.5 Support (#16460)
danny-avila Sep 28, 2026
f624ad0
🔁 fix: Retry Code API Rate Limits That Reject Before a Workspace Call…
danny-avila Sep 28, 2026
5de01de
🔲 fix: Anchor Quote Popup to Visible Selection (#16458)
lia-by-librechat[bot] Sep 28, 2026
1ff532a
📶 fix: Ride Out Transient Worker Status Failures Within the Worker's …
danny-avila Sep 28, 2026
d263da5
🧾 fix: Validate Principal Config Overrides Against configSchema (#16433)
berry-13 Sep 28, 2026
33ee88e
⏩ refactor: Clarify Steering Timing and First-Response Fallback (#16465)
lia-by-librechat[bot] Sep 28, 2026
46f81b6
fix: Enforce Tool Approval Policy on Headless Agent Runs (#16467)
lia-by-librechat[bot] Sep 28, 2026
7e786ba
🥧 refactor: Show Failed Call Fractions and Preview Age (#16468)
lia-by-librechat[bot] Sep 29, 2026
42568a0
🔀 fix: Resolve SplitText Direction From Its Own Text Under RTL (#16454)
shukiv Sep 29, 2026
03b89f8
🔩 fix: Raise Vulnerable Dependency Floors (#16474)
lia-by-librechat[bot] Sep 29, 2026
63363a7
⏱️ fix: Fit Workspace Command Timeouts Inside the Configured Request …
danny-avila Sep 29, 2026
a7662d2
🕘 feat: Distinguish Tool Preparation From Tool Call Time (#16455)
lia-by-librechat[bot] Sep 29, 2026
867fd5e
🛤️ feat: Route Linked Worktree Requests into Per-Worktree Lanes (#16477)
danny-avila Sep 29, 2026
d7e7064
🧧 fix: Redeem Admin OAuth Codes Only Once (#16513)
lia-by-librechat[bot] Sep 29, 2026
5682f77
🫸 fix: Keep Historical Artifacts Closed During Regeneration (#16511)
lia-by-librechat[bot] Sep 29, 2026
f995ba1
🪸 fix: Restore File Search on Later Agent Turns (#16516)
lia-by-librechat[bot] Sep 29, 2026
4d33d8c
↪️ fix: Block Unsafe MCP OAuth Redirects and Private IPs (#16514)
lia-by-librechat[bot] Sep 29, 2026
3e19b18
🎯 feat: Tolerant Workspace Edits with Host-Rendered Conflict Diagnost…
danny-avila Sep 29, 2026
ad28144
🎨 fix: Color Pressed MCP Tool Option Toggles With Their Series Role (…
berry-13 Sep 29, 2026
e9d1d33
🧬 feat: Resolve GPT Point Releases to Their Family and Add GPT-6.1 So…
danny-avila Sep 29, 2026
ea7ac99
🛶 fix: Keep Trigger Bans Off Shared Loopback IPs (#16535)
lia-by-librechat[bot] Sep 30, 2026
f4f3677
🦫 fix: Bound Error Text Before URL Redaction (#16532)
lia-by-librechat[bot] Sep 30, 2026
981e73d
👫 fix: Keep Firecrawl and SearXNG Credentials Paired (#16538)
lia-by-librechat[bot] Sep 30, 2026
5f4d96c
🧘 fix: Keep Prose Mounted While Activity Labels Update (#16531)
lia-by-librechat[bot] Sep 30, 2026
7fe6eab
⛴️ chore: Include Latest Canary Features in Sync
lia-librechat Sep 30, 2026
8f64336
⛴️ chore: Merge Latest Dev Fixes into Canary Sync
lia-librechat Sep 30, 2026
b881b83
⛴️ style: Match Theme Class Ordering in Canary Sync
lia-librechat Sep 30, 2026
5bd84bb
⛴️ fix: Align Canary Timing Types and CI Formatting
lia-librechat Sep 30, 2026
2aea0d6
🏝️ feat: Scope YAML Custom Endpoints by Tenant (#16537)
danny-avila Sep 30, 2026
207ee8b
⛴️ chore: Include Tenant-Scoped Endpoints in Canary Sync
lia-librechat Sep 30, 2026
14f7b28
🦮 fix: Bind Per-User MCP API Keys to Their Destinations (#16536)
lia-by-librechat[bot] Sep 30, 2026
7f3f82f
⛴️ chore: Include MCP Credential Binding in Canary Sync
lia-librechat Sep 30, 2026
e4f10b6
⛴️ test: Make Passkey Ordering Fixtures Deterministic
lia-librechat Sep 30, 2026
f03ecb7
🚿 fix: Strip Code Approval Modes From Imported Chats (#16542)
lia-by-librechat[bot] Sep 30, 2026
210086a
🟰 fix: Normalize File Edits Before Approval (#16543)
lia-by-librechat[bot] Sep 30, 2026
6a1d30c
🚀 v0.8.8 (#15735)
danny-avila Sep 30, 2026
0a85ff5
✂️ fix: Keep Parts After a Summary in the Summary-Bounded History Rea…
berry-13 Sep 30, 2026
12efd62
🗳️ fix: Defer Thread Approval Card to the Open Composer Review (#16437)
berry-13 Sep 30, 2026
5748708
📦 chore: bump agents SDK to v4.0.0 (#16558)
danny-avila Sep 30, 2026
601e07e
📦 chore: npm audit fix (#16559)
danny-avila Sep 30, 2026
cd63070
🪮 perf: Match Tolerant Edit Lines Without Rebuilding Windows (#16562)
lia-by-librechat[bot] Sep 30, 2026
99255e3
⏹️ fix: Cancel MCP OAuth From the Tool Dialog (#16561)
lia-by-librechat[bot] Sep 30, 2026
d33c72e
🛂 fix: Rate Limit Authenticated 2FA Management (#16565)
danny-avila Sep 30, 2026
89e1567
🔐 fix: Keep the MCP OAuth Prompt Open While a Stale Status Says Conne…
danny-avila Sep 30, 2026
b341f93
🏎️ perf: Re-render Only the Tail Rows When a Message Is Sent (#16572)
danny-avila Sep 30, 2026
e9e5b36
⛴️ chore: Include Latest Canary Themes and Command Output
lia-librechat Sep 30, 2026
ff3f0f8
⛴️ chore: Refresh Canary Sync With Latest Dev Fixes
lia-librechat Sep 30, 2026
47b3b9b
⛴️ style: Match Canary Theme Class Ordering
lia-librechat Sep 30, 2026
fd510aa
⛴️ test: Keep Executor and Timing Callback Adapters Aligned
lia-librechat Sep 30, 2026
44e364d
🆙 chore: Bump Packages and Helm for v0.8.8 (#16573)
lia-by-librechat[bot] Sep 30, 2026
c60dac3
🏰 ci: Gate Main Promotions on Approved Dev Commits (#16570)
lia-by-librechat[bot] Sep 30, 2026
6bd6577
⛴️ chore: Include Canary Retention and Control Themes
lia-librechat Oct 1, 2026
84a53a4
⛴️ chore: Include Latest Dev Release and Promotion Gates
lia-librechat Oct 1, 2026
67e4609
⛴️ fix: Reset Agent Search and Wait for Completed Diagram Exports
lia-librechat Oct 1, 2026
ada91c1
📦 chore: npm audit fix + bump agents SDK to v4.0.1 (#16581)
danny-avila Oct 1, 2026
9f1256e
⏸️ fix: Pause LibreOffice Previews (#16583)
lia-by-librechat[bot] Oct 1, 2026
e8f3be0
🎁 chore: Bump Packages and Helm After Security Fixes (#16582)
lia-by-librechat[bot] Oct 1, 2026
f66ad88
⛴️ chore: Sync Latest Dev Security and Package Updates
lia-librechat Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -595,7 +595,7 @@ GOOGLE_KEY=user_provided
#============#

OPENAI_API_KEY=user_provided
# OPENAI_MODELS=gpt-6-astra,gpt-6-sol,gpt-6-luna,gpt-5.6,gpt-5.6-terra,gpt-5.6-luna,gpt-5.5,gpt-5.5-pro,chat-latest,gpt-5.4,gpt-5.4-pro,gpt-5.4-mini,gpt-5.4-nano,gpt-5.3-codex,gpt-5.2,gpt-5,gpt-5-codex,gpt-5-mini,gpt-5-nano,o3-pro,o3,o4-mini,gpt-4.1,gpt-4.1-mini,gpt-4.1-nano,o3-mini,o1-pro,o1,gpt-4o,gpt-4o-mini
# OPENAI_MODELS=gpt-6-astra,gpt-6.1-sol,gpt-6-sol,gpt-6-luna,gpt-5.6,gpt-5.6-terra,gpt-5.6-luna,gpt-5.5,gpt-5.5-pro,chat-latest,gpt-5.4,gpt-5.4-pro,gpt-5.4-mini,gpt-5.4-nano,gpt-5.3-codex,gpt-5.2,gpt-5,gpt-5-codex,gpt-5-mini,gpt-5-nano,o3-pro,o3,o4-mini,gpt-4.1,gpt-4.1-mini,gpt-4.1-nano,o3-mini,o1-pro,o1,gpt-4o,gpt-4o-mini

DEBUG_OPENAI=false

Expand Down
5 changes: 5 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Enable required code-owner reviews in dev/main branch rules to enforce this.
/.github/CODEOWNERS @danny-avila
/.github/workflows/ @danny-avila
/.github/scripts/ @danny-avila
/.github/MAIN_PROMOTION.md @danny-avila
138 changes: 138 additions & 0 deletions .github/MAIN_PROMOTION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,138 @@
# Manually Approved Main Promotion

`main` is a release pointer into `dev` history. The **Promote Dev to Main** workflow
moves that pointer to one approved, fully tested `dev` commit. It creates no merge,
rebase, squash, or new commit and never force-pushes. It is not an automated merge bot.

## Trust boundary

```text
maintainer dispatches workflow on main with two exact SHAs
-> different environment reviewer approves
-> read-only validation of platform protections, actors, refs and full CI
-> short-lived App token for this repository, Contents: write only
-> repeat all validation, fetch into a bare object store, non-forced push
-> verify the new main SHA and revoke the App token
```

The privileged job runs inline code from the workflow revision on `main`, not a
script from the candidate branch. It does not check out application source, restore
caches, download PR artifacts, install packages, or execute repository-local actions.
The sole action used there is `actions/create-github-app-token`, pinned to a full
upstream commit SHA. The separate policy-test job has read-only permissions, no App
credential, no protected environment, and does not persist checkout credentials.

Inputs travel through environment variables and must be complete lowercase SHA-1
commit IDs before they are used as API or Git arguments. Repository identity, GitHub
hosts, dispatch event, workflow path and `main` ref are fixed. Both the original actor
and any rerun actor must have GitHub's `admin` or `maintain` role. API failures,
incomplete responses, missing CI runs, duplicate/missing jobs and unexpected states
refuse promotion. There is no bypass or "ignore failures" input.

The CI gate accepts only the latest full `push` or `workflow_dispatch` run on `dev`
for the exact input SHA, from the repository's existing backend and frontend workflow
IDs and paths. All build, typecheck, test-shard and circular-dependency jobs must be
present and successful. Only the PR-only **Codegraph select** job may be skipped.
An older successful run cannot conceal a newer failed or pending full run. PR checks
and checks from a different commit do not qualify. This gate does not imply that
Lighthouse, Playwright or integration lanes that only run on PRs tested the resulting
post-merge SHA; maintainers still assess those PR results and release readiness.

The candidate must be the current `dev` tip, and the reviewed baseline must still be
the current `main` tip. `main` must be an ancestor of the candidate. Ref and CI
validation is repeated after approval and immediately before the push. Concurrency
serializes promotion runs without cancelling a job mid-push. Git's non-forced server
update rejects a concurrent change that cannot fast-forward to the candidate. The
cross-ref check is not an atomic lock on `dev`: if it advances after the final read,
`main` still receives only the pinned, previously approved SHA, never the new tip.

## Required repository setup (administrator)

This PR adds code, **not** platform protection settings or credentials. Do not place
the promotion key in repository-wide or organization-wide secrets. Keep it exclusively
in the protected environment below. A missing environment can be auto-created by
GitHub without protection; the inline gate refuses that state before minting a token.

1. Protect **both `dev` and `main`** with rulesets/branch protection:
- Disallow force pushes and deletions. Require code-owner reviews for workflow,
script and CODEOWNERS changes, with stale approvals dismissed and approval of
the most recent reviewable push by someone other than its author.
- Restrict updates to `main` to release maintainers and the dedicated promotion
App. A fast-forward App update is not a PR merge: if a PR-only rule prevents
it, decide the narrowly scoped release-App exception explicitly. Never give
the App unrestricted bypass of force-push, deletion or other safety rules.
- `.github/CODEOWNERS` requests Danny's review of the release control plane;
it enforces nothing until the platform requires code-owner review. Add another
trusted code owner before Danny-authored control-plane changes can satisfy
mandatory code-owner review; the author cannot approve their own PR.
2. Create an environment named **`main-promotion`**:
- Configure trusted **Required reviewers** and enable **Prevent self-review**.
Use enough trusted reviewers that someone other than the initiator can approve.
- Disable **Allow administrators to bypass configured protection rules**.
- Select **Selected branches and tags**. Add exactly one rule: type **Branch**,
name **`main`**. No tag rule, wildcard, `dev`, or other branch.
3. Create a **dedicated GitHub App**, installed only on `LibreChat-AI/LibreChat`, with
repository **Contents: read and write** (and GitHub's required metadata access).
Do not reuse a PAT or a broad existing App. Do not grant Workflows, Actions,
Administration, Secrets or organization permissions.
4. In that environment only, store:
- Variable **`MAIN_PROMOTION_APP_ID`**: the dedicated App's ID.
- Secret **`MAIN_PROMOTION_APP_PRIVATE_KEY`**: its private key.
The workflow requests a repository-scoped token with only Contents: write. The
pinned token action attempts revocation in its post-job step, including failures.
An interrupted runner may not execute cleanup; the installation token's short
lifetime bounds that residual risk. Do not disable token revocation.
5. Merge this implementation into **`dev`** after review. Bootstrap it onto `main`
once with a separately approved, ordinary exact-SHA fast-forward; `workflow_dispatch`
cannot run a new workflow until its definition reaches the default branch.
Never bypass failed checks or protections as part of bootstrap. Changes to any
`.github/workflows/`, `.github/scripts/` or `.github/CODEOWNERS` file are deliberately
excluded from automated promotion, including this workflow's own updates. Those
use the separately reviewed manual path, so the App needs no Workflows permission.

A repository administrator and the trusted `main` workflow are the root of trust.
This is not a defense against a malicious repository administrator or a compromised
reviewer who knowingly authorizes a malicious release. Nor does it harden the other
existing publish workflows: an App push to `main` intentionally triggers the existing
main-push automation, with its own permissions and dependencies. Review that downstream
publishing surface separately before relying on the release process end to end.

## Promote a normal tested dev commit

1. Run `git ls-remote --heads origin main dev` in your own upstream clone. Review the
candidate and both **full** CI runs at the exact `dev` SHA.
2. If path filters omitted a full run for that SHA, run the existing **Backend Unit
Tests** and **Frontend Unit Tests** workflows manually on `dev`, then wait for
success. Their new `workflow_dispatch` trigger uses full suites, not PR selection.
3. Dispatch **Promote Dev to Main** using branch **`main`**. Supply the full `dev` SHA
as `dev_sha` and the full current `main` SHA as `expected_main_sha`. Example:

```sh
gh workflow run promote-main.yml --repo LibreChat-AI/LibreChat --ref main \
-f dev_sha=<approved-current-dev-sha> \
-f expected_main_sha=<reviewed-current-main-sha>
```

4. A different configured reviewer examines the input SHAs and approves the
`main-promotion` environment deployment. The job still revalidates everything.
5. Read the run summary and confirm `git ls-remote --heads origin main`. Monitor
downstream main-push publishing workflows separately. If refs or CI changed,
review a fresh dispatch. If the final read failed after a push, inspect the live
`main` tip before retrying: the push may have succeeded. Do not force-push.

Rollback of code is a new reviewed revert on `dev`, followed by another approved
fast-forward. Never move `main` backwards. Promotion adds no merge commit, but any
merge commits already present in `dev` are preserved as part of its history.

## Local validation

```sh
python3 -I .github/scripts/test_main_promotion.py
```

Tests extract and execute the workflow's actual inline policy against controlled
API responses and exercise real local bare Git repositories. They never use live
GitHub credentials or update a remote repository. Run the policy-test workflow and
YAML/action lint before delivery. A production promotion cannot be verified until
administrator setup and bootstrap are complete; do not report it as deployed merely
because local tests pass.
Loading
Loading