Commit graph

249 commits

Author SHA1 Message Date
cbbf373b6a Restrict delivery HTTP to loopback and fix grant races.
Require trusted loopback requests for proactive send, accept hyphenated WhatsApp group JIDs, and serialize access-grant mutations to avoid lost concurrent updates.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-06 14:45:37 +08:00
356538ac18 Improve WhatsApp delivery suggestions and peer labels (ops.30).
Surface chat/access-list contacts as selectable targets with clearer nicknames, and keep conversation peers usable for ops schedulers.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-06 02:31:42 +08:00
385bc1edf5 Clarify that IM file delivery requires dsh_im_return_file (4.9.1-ops.22).
Strengthen tool and system-prompt copy so models do not treat a pasted workspace path as delivery.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 19:25:07 +08:00
a92080e490 Hide WhatsApp LID ids from session-header peer labels (4.9.1-ops.21).
Resolve nickname/phone via contact LID mapping and show only group title, pushName, and phone.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 19:14:38 +08:00
37742043a9 Show WhatsApp channel peer next to Agent Preset in session header (4.9.1-ops.20).
Plugins inject conversation.session.header.actions; resolve sessionId back to the bound chat and render nickname/phone or group title.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 19:10:07 +08:00
2718586fda Add per-DM and per-group Agent Preset overrides (4.9.1-ops.19).
Access grants can pin an agentPreset on direct members and groups; new sessions resolve override over the bot-global preset.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 18:53:43 +08:00
7993499273 Stop contact action buttons from invading the source column (4.9.1-ops.18).
The shared 72px actions width was crushing the contact table; give that column real space.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 18:20:06 +08:00
9baddba579 Keep contact grant actions on one horizontal row (4.9.1-ops.17).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 18:17:11 +08:00
e4cdb6f60a Show auto-collected contacts in a table (4.9.1-ops.16).
Align nickname, phone, source, and grant actions like the other access lists.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 18:14:13 +08:00
a10d900a7b Use table layout for access-grant people lists (4.9.1-ops.15).
Nickname, phone, permission, and actions sit in aligned columns with headers.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 18:08:59 +08:00
a59a09e0d2 Align access rows and theme native selects for dark mode (4.9.1-ops.14).
Use a shared three-column grid for admin/member rows, and inherit DSH color-scheme so channel/command dropdowns stay readable.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 18:04:25 +08:00
43f082d2e3 Replace IM channel rail with a top dropdown (4.9.1-ops.13).
Give the settings panel the full right-pane width instead of a left channel list.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 17:57:40 +08:00
ec96b4d6eb Compact access-grant member/admin rows for denser editing (4.9.1-ops.12).
Use flex-wrap rows so phone, command, and delete stay tight and soft-wrap only when the panel is too narrow.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 17:50:33 +08:00
87e44bd36e Hide fully authorized contacts from the quick-grant list (4.9.1-ops.11).
Recent contacts only show people who still need DM or group access actions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 17:44:17 +08:00
f96157da1e Sync WhatsApp group subjects into access UI (4.9.1-ops.10).
Refresh missing/forced group titles via groupMetadata and participating catalog so cards show real names instead of bare JIDs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 17:39:25 +08:00
a169b164a8 Show WA nicknames and auto-fill group subjects in access UI (4.9.1-ops.9).
Fetch groupMetadata.subject on @mentions for group cards; render contact pushName under phone rows so admins are not staring at bare numbers.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 17:29:43 +08:00
e8e58924ca Polish access-grant UI: no sticky typeahead overlay, flatter group cards (4.9.1-ops.8).
Suggestions only open while focused and hide exact matches; nested group admins/members drop extra frames; pending and actions show group names.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 17:20:53 +08:00
a4508a7caa Load WhatsApp accessGrant into bot settings (4.9.1-ops.7).
Settings button only forwarded accessPolicy, so the graded ACL page always opened empty; also refresh grant from connection.status on mount.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 17:12:24 +08:00
93672dfd91 Fix WhatsApp access settings showing empty grant state (4.9.1-ops.6).
Client normalizeBot dropped accessGrant/groupSessionScope, so pending, contacts, and group cards never appeared. Also record contacts only on DM/@, auto-create group buckets on @, and add one-click grant buttons.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 17:05:16 +08:00
a0c49707a1 Fix access-grant phone inputs losing focus after each keystroke.
Row keys included the phone value, so each character remounted the input; also sync draft from serialized grant content, not object identity.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 16:50:42 +08:00
9f97c44031 Add WhatsApp graded phone ACL (4.9.1-ops.4).
Replace allowlist-only gating with phone-scoped grants: global admins, DM members, per-group admins/members, pending approval via quote YES/NO or settings UI.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 16:45:21 +08:00
e5e1e6573a Strip WhatsApp @bot LID tokens from inbound group text.
Mention triggers leave opaque LID digits in the body; remove those only,
without injecting sender identity (use context enhancement when needed).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 16:04:55 +08:00
d9edca4d5f Fix WhatsApp group access when senders are opaque LIDs.
Resolve LID to phone aliases before allowlist and @mention checks so
group prompts are not silently dropped after a working direct chat.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 15:56:24 +08:00
7f1b9bd480 Add configurable group session scope (default user_in_chat).
Ops bots now isolate per-speaker Harness sessions in groups, with a
settings/RPC toggle to restore shared chat sessions when needed.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 15:39:28 +08:00
d10a941fc8 Fix client ModuleLoader id to dsh-im-ops after package rename.
GitHub installs still shipped the upstream @xmanrui/dsh-im client id, so the web shell loaded the bundle without registering the plugin.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-05 15:21:26 +08:00
xmanrui
965e839457 chore: release v4.9.1 2026-09-04 03:26:39 +08:00
xmanrui
6a6e3c96b8 fix: restore IM question and approval routing
Support current DSH Session.snapshotEvents while retaining the legacy session.events and apiProxy paths. Add regression coverage and record the nine-channel rollout and live verification for issue #70.
2026-09-04 03:24:35 +08:00
xmanrui
1b05fa8d32 fix: add actionable DingTalk connection diagnostics 2026-09-04 02:18:18 +08:00
xmanrui
3010535409 chore: release v4.9.0 2026-09-03 10:19:06 +08:00
xmanrui
149f435216 fix: trim redundant quoted message metadata 2026-09-03 03:11:14 +08:00
xmanrui
34f217cafc Merge pull request #122 and harden reply stall detection
Resolve the current main conflict, treat reply timeouts as inactivity windows, and confirm liveness through Harness instead of sticky interaction ownership.
2026-09-03 02:14:01 +08:00
xmanrui
2b6f4bdfb0 fix(feishu): preserve interaction card reply semantics 2026-09-03 01:12:51 +08:00
xmanrui
d4e1bd3cab Merge main into feat/feishu-interaction-cards
# Conflicts:
#	lib/index.js
2026-09-03 01:00:04 +08:00
xmanrui
3240632bef Merge main into agent/issue-88 and resolve workspace aliases 2026-09-03 00:47:38 +08:00
xmanrui
275dafbf19 chore: release v4.8.0 2026-09-02 23:48:02 +08:00
Chan
3562b9244e
feat(context-enhancement): 新增 chatId 与 threadId 来源字段 (#128)
Add chatId and threadId source fields across all nine IM channels, update UI/docs/tests, reconcile the latest main branch, and credit @Chan-0312 as a contributor.
2026-09-02 23:28:53 +08:00
xmanrui
88ef12ecc8 chore: release v4.7.0 2026-09-02 03:03:00 +08:00
xmanrui
37ec6abb06 feat: support limiting session list results 2026-09-02 03:01:44 +08:00
xmanrui
52deb872aa chore: release v4.6.0 2026-09-02 01:39:29 +08:00
xmanrui
9d2e9c800b fix(im): preserve cancellation during image fallback 2026-09-02 01:35:48 +08:00
xmanrui
c7679d86a1 Merge pull request #118 from GoldJohnKing/fix/non-vision-model-image-file-fallback 2026-09-02 01:33:28 +08:00
xmanrui
94e114b9b3 fix: preserve quoted message context across channels 2026-09-02 01:27:35 +08:00
C3H3-AI
b5378500ca fix(feishu): bind card decisions to the actor and reject stale cards
Address review feedback on the interaction cards:

1. Bind card decisions to the initiating actor. The card-action operator
   (operatorOpenId) is now passed into the approval and question handlers:
   - submitByApprovalId receives { actor } so another allowed group member
     cannot approve/reject someone else's approval;
   - the answer branch requires pending.actor === operator.

2. Include the question index in the answer button action and validate it
   against the current pending question, so a stale card from an earlier
   question in a multi-question interaction cannot be applied to the next one.

3. When both the card send and the plain-text fallback fail, the error is no
   longer swallowed: it propagates so the interaction is not marked as
   presented and the existing retry/reconnect behaviour can run.

Adds regression tests for all three cases.
2026-09-02 00:18:50 +08:00
C3H3-AI
0b42ea9889 feat(feishu): interactive approval and question cards with buttons
Render Harness approval and single-choice question interactions as
interactive Feishu cards with approve/reject and answer buttons,
matching the already-available interactionCards behaviour. Cards are now
the default; set DSH_IM_INTERACTION_CARDS=0 (or interactionCards=false)
to keep the plain-text reply flow.

- bridge.mjs: approve:/reject:/answer: card actions, interactionCards
  option, gated approval render hook, interactive question presentation,
  and operationArguments/printableText helpers; refactor the inline
  question answer into #submitQuestionAnswer so both text replies and
  card buttons share one path.
- feishu-cards.mjs: approvalCard (approve/reject) and questionCard
  (option buttons) templates.
- feishu-runtime.mjs: default interactionCards from env (on).
- harness-approval.mjs: optional channel render hook + submitByApprovalId.
- i18n-en: add the new card t() keys.
- Tests: pin the plain-text reply flow in state-machine suites that
  drive it, and add dedicated card tests for the default approve/reject,
  answer buttons, and the text fallback. Full suite shows no new
  failures versus upstream.
2026-09-02 00:18:37 +08:00
C3H3-AI
955c2217fd fix(feishu): renew the reply wait window while the turn is active
A long-running Harness task was falsely reported as MODEL_REPLY_TIMEOUT
after the fixed 10-minute deadline even though the backend was still
working. Replace the hard wall-clock deadline with an activity-based
stall window: the wait renews whenever the turn produces new events, the
control ownership is active, or (mid-turn with no new events) Harness
still reports the session as running. Only a genuine stall with no
progress for the whole timeoutMs window fails fast.

This is the shared harness-client layer, exercised end-to-end by the
Feishu channel (which already exposes HARNESS_REPLY_TIMEOUT_MS); other
channels inherit the same fix.

Adds two regression tests: a long-running turn with periodic activity
completes instead of timing out, and a genuinely stalled turn still
fails with harness-reply-timeout.
2026-09-02 00:17:18 +08:00
GoldJohnKing
994df6e1e3 Merge upstream v4.5.0 (xmanrui/main) into fix/non-vision-model-image-file-fallback
- CHANGELOG: keep the image-fallback entry under Unreleased alongside the new 4.5.0 section
- harness-client: upstream renameSession coexists with the image-rejection fallback retry path
- lib/index.js rebuilt from merged sources
2026-09-01 23:18:12 +08:00
xmanrui
c2be2389b0 chore: release v4.5.0 2026-09-01 22:39:47 +08:00
xmanrui
d044f1b0aa fix: preserve session titles without context enhancement 2026-09-01 22:30:35 +08:00
GoldJohnKing
36d10dc499 chore: rebuild lib for non-vision image fallback 2026-09-01 21:29:43 +08:00
evanfang0054
c7cb678bd2 chore: rebuild lib for feishu issue-86 card rotation 2026-09-01 17:53:44 +08:00