Skip to content

Changelog

2026-09-10 — Source review corrections (not a deployment)

  • The local v0.9.1/v0.9.2 changes below are unreleased source changes, not verified production releases. Public-launch acceptance remains incomplete.
  • Updated the public inventory to 40 paths / 50 operations, including Actions and runs. Full platform feature parity is not yet exposed through /v1.
  • Corrected rate-limit documentation: coverage is partial; application Redis does not configure SlowAPI automatically; headers and one error envelope are not universally guaranteed.
  • Documented missing OpenAPI security/response metadata and safe retry limits.
  • Corrected deletion guidance: nullable foreign keys still block referenced deletes; SET NULL is not safe for every routing relationship.
  • User App dependencies were upgraded to React19/Vite6/Vitest3; Admin remains React18/Vite5. Build/component tests do not prove full compatibility or GA.

Unreleased v0.9.2 — Security Hardening & DB Index Coverage

Added

  • Control Plane Rate Limits — Selected mutations in tenants, users, api-keys, upstream-accounts, and register gained explicit SlowAPI limits. Coverage is not universal, and cross-worker storage is not established by sharing a Python limiter instance.
  • Data Plane Rate Limits — projects.py mutations and file uploads now have rate limits (rate_limit / upload_rate_limit), closing a gap where project operations were unprotected.
  • Me API Rate Limits — A batch of 20 Me API mutation endpoints (connections, api-keys, invitations, conversations, uac-actions, test-lab, auth/logout) now have explicit rate limits. Previously relied only on cookie auth + CSRF + tenant gating.
  • Audit Log Coverage — transcription.completed and transcription.failed events added to the transcription service (was a gap). conversation.archived and conversation.deleted events added to Me API conversations (was a gap).
  • Database Index Coverage — Migration 0034 adds 8 indexes on FK columns used in WHERE/JOIN queries: tenants.plan_id, project_routing_bindings (3 composite), conversations (3 composite), audio_generation_jobs.user_id.

Changed

  • Registration now uses the common SlowAPI instance instead of its old dictionary. The reviewed instance uses in-process memory; production backend configuration and distributed enforcement require separate verification.
  • combine-as-imports = true added to ruff isort config to prevent aliased imports from being split into separate blocks.

Documentation

  • Updated Rate Limits reference with full endpoint-specific coverage across all three API planes (Data, Control, Me API).
  • Updated CURRENT-STATE.md with the verified protection matrix (rate-limit + audit coverage per endpoint).

Unreleased v0.9.1 — Session Stability & Image Contract

These changes are implemented in source, but the 2026-09-10 review found remaining refresh persistence/isolation and health-projection defects. They must not be described as a guarantee of uninterrupted provider sessions.

Added

  • Proactive Token Refresh — Access tokens are checked for JWT expiry before each request and refreshed via /api/auth/session when within the threshold. Capture-time expires_at storage so the monitor can act on captured sessions. Background refresh loop in lifespan.
  • Rate-Limit-Aware Circuit Breaker — 429 errors use a longer cooldown (5 minutes) vs generic failures (60 seconds). The breaker reason is stored so the connections endpoint can report why an account is unavailable.
  • Real Health Contract — /v1/connections now returns a real health field (healthy, unhealthy, rate_limited, cooldown, unknown) instead of null. The UI displays rate_limited and cooldown states with countdowns.
  • Image Generation Contract — IMAGE_GENERATION_UNAVAILABLE error code (HTTP 503, not retryable) for when ChatGPT returns text fallback instead of a structured image asset. Image failures are isolated from the circuit breaker — a healthy account stays available for text/chat.
  • Capabilities: Images Section — /v1/capabilities now includes a dedicated images section with state (unknown/unavailable), verified, error_code, retryable, and a note. chat.features.images is conditional on a connected account (was hardcoded true). providers.chatgpt.supports now includes "images".

Changed

  • NO_HEALTHY_SESSION is now retryable: false (was a defect causing integrators to retry dead sessions instead of surfacing re-auth).
  • chat_completions no longer crashes when the dependency returns a JSONResponse (no healthy session) — it short-circuits with the structured error.
  • Reactive expiry: 401/403 from upstream marks the account as expired so the connections page reflects reality and the router stops selecting it.
  • Failed streams no longer count as successful usage.

Documentation

  • Updated Errors reference with IMAGE_GENERATION_UNAVAILABLE and feature_unavailable_error type.
  • Updated Streaming guide with image generation failure handling.
  • Updated Connections reference with the real health contract.
  • Updated Capabilities reference with the images section and state field.
  • Corrected retryable list: NO_HEALTHY_SESSION removed (not retryable).

v0.9.0 — Public Developer Platform

Added

  • Streaming Error Contract — Provider/session errors during streaming are now emitted as structured response.failed lifecycle events with machine-readable error.code, error.retryable, and error.http_status. Error codes: ACCOUNT_REAUTH_REQUIRED, PROVIDER_RATE_LIMITED, PROVIDER_UNAVAILABLE, PROVIDER_TIMEOUT, INVALID_REQUEST.
  • Public OpenAPI — openapi-public.json endpoint serving only data plane routes (40 paths, 0 admin routes).
  • Public Swagger UI — /docs-public interactive API explorer.
  • llms.txt / llms-full.txt — Machine-readable agent documentation surfaces.

Changed

  • Streaming errors no longer appear as assistant content text — they are structured lifecycle events with finish_reason: "error".
  • Non-streaming errors return canonical HTTP status codes (401/403/429/502/504) instead of 200 with error text in content.

Documentation

  • Expanded Files & Attachments API reference with curl/Python/JavaScript examples
  • Added streaming error contract to Streaming guide
  • Added streaming error codes to Errors reference
  • Updated Handling Errors guide with canonical envelope and streaming examples

v0.4.6 — Initial Product Release

Added

  • Capability Discovery — Dynamic capability detection based on connected providers
  • User Chat — Full chat playground with streaming and conversation continuity
  • Conversations — Conversation persistence and continuity with upstream IDs
  • Projects — Project-native conversations with file context and memory policies
  • Attachments — File upload to chat messages with AI retrieval
  • Generated Assets — AI-generated files (images, data) with secure download
  • Speech Generation — Async TTS with Google Savio provider, voice selection, polling
  • Transcription — Audio-to-text with privacy-first processing (no transcript storage)
  • Usage Dashboard — Per-workspace usage tracking with summaries and records
  • Cross-Surface UX — Unified navigation across playground, library, and developer tools

Security

  • Cookie-authenticated BFF for User App with CSRF protection
  • Internal test-lab API keys never exposed to frontend
  • Cross-tenant asset access denied (404/403)
  • Tenant isolation enforced on all endpoints
  • Path traversal prevention on asset downloads

Architecture

  • Provider-neutral adapter pattern for all provider interactions
  • BFF pattern: User App → thin authenticated facade → canonical execution path
  • No provider logic duplication between Product API and User App API