Rocky
4c9e5feec0
Make session refresh retries idempotent
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Preserve the successor session for legitimate refresh retries so transient failures no longer revoke the user's session family.
2026-08-25 13:13:41 +08:00
Rocky
36a926f12f
Improve dynamic hint availability and streaming
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Expand curated hot topics while keeping slow current-information responses alive through reverse proxies and client idle timeouts.
2026-08-24 11:14:09 +08:00
Rocky
e522788867
Refine dynamic hint feed curation
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Remove redundant cloud fallbacks and focus each locale on a compact, safer set of timely topics with diversified English RSS coverage.
2026-08-23 20:20:53 +08:00
Rocky
51c37e6206
fix(gateway): restore safe search fallback
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Fall back to guarded Chat Completions answers when DeepSeek web search fails so grounded current-information hints do not surface generic provider errors.
2026-08-23 14:32:43 +08:00
Rocky
03eac71905
Harden current-information search failures
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Preserve required-search semantics for live hints and expose stable gateway error codes without leaking provider details.
2026-08-22 22:43:16 +08:00
Rocky
4f5b6eafbd
Merge remote-tracking branch 'origin/dependabot/github_actions/gradle/actions-6'
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
2026-08-22 17:56:54 +08:00
Rocky
f95d09f303
Merge remote-tracking branch 'origin/dependabot/github_actions/actions/setup-java-5'
2026-08-22 17:56:54 +08:00
Rocky
b4064126fe
Merge remote-tracking branch 'origin/dependabot/github_actions/actions/checkout-7'
2026-08-22 17:56:54 +08:00
Rocky
544e0d7356
Add TOTP-gated provider API key reveal
...
Allow super administrators to inspect effective provider credentials only after audited, rate-limited step-up verification.
2026-08-22 17:56:35 +08:00
Rocky
636a8541bc
Fix provider configuration response rendering
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Align the admin page with the array response defined by the production API and OpenAPI contract so successful status loads cannot trip the route error boundary.
2026-08-22 17:21:20 +08:00
Rocky
10ba4f0a0c
Fix production migration privilege compatibility
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Rescope OOBE claims with permitted ALTER operations and make deployment smoke validation require every migration through V28.
2026-08-22 16:44:24 +08:00
Rocky
9fb947aa7d
Add runtime provider controls and searchable AI routing
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Manage provider keys at runtime, route current-information questions through server-side search with safe fallback, and scope OOBE usage claims to grants.
2026-08-22 16:33:17 +08:00
Rocky
f8fa93dc48
Fix production health build identification
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Mount the versioned health route instead of the legacy shadowing handler so deployments can verify the exact running image.
2026-08-21 23:15:59 +08:00
Rocky
0d236f57fb
Add anonymous OOBE gateway grants
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Provide App Attest-bound, one-time onboarding AI access without creating accounts, with durable replay protection and production deployment safeguards.
2026-08-21 22:55:46 +08:00
Rocky
edd0d9feca
Correct product analytics cohorts and reporting
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
2026-08-21 17:50:35 +08:00
Rocky
b25f5ae6e9
Clarify Hint pack save behavior
...
Keep manual editing while making save the only user action and applying changes immediately without a separate publish workflow.
2026-08-21 15:37:13 +08:00
Rocky
454ba8ddc5
Migrate AI Hint feed generation
...
Bring dynamic hint generation into the account service while preserving the legacy key.osglab.com deployment for existing clients.
2026-08-21 15:17:15 +08:00
Rocky
d0abe27623
Add managed content and keyboard usage insights
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Introduce versioned official content workflows and privacy-safe keyboard analytics, while preventing repeat DeviceCheck sign-ins from incorrectly restricting eligible accounts.
2026-08-21 13:34:03 +08:00
Rocky
b5212dcdc2
Enhance ledger operations and referral lifecycle
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Add traceable ledger filtering and permanent referral codes so operators can investigate credit activity without weakening immutable accounting guarantees.
2026-08-20 22:14:22 +08:00
Rocky
74c3fcd45f
Add admin dashboard filtering and sorting
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Provide stable server-side list queries and focused chart controls so operators can inspect large datasets without misleading partial-page ordering.
2026-08-20 18:05:49 +08:00
Rocky
034a3e8745
Add complimentary OOBE polish and configurable admin mTLS
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Allow one server-audited onboarding polish request without credits and make the certificate gate temporarily reversible while preserving application authentication.
2026-08-20 17:05:35 +08:00
Rocky
0b4acb5978
Visualize admin analytics dashboards
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Turn operational, product, and referral metrics into accessible charts so trends, funnels, retention, and channel quality are faster to interpret.
2026-08-20 16:02:21 +08:00
Rocky
4b465e0e5e
Add privacy-safe product analytics
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Establish an idempotent analytics pipeline and internal decision dashboard while keeping event metadata allowlisted and account deletion enforceable.
2026-08-20 15:20:01 +08:00
Rocky
231c5040a5
Add StoreKit history and modernize admin console
...
CI / verify (push) Has been cancelled
CI / publish (push) Has been cancelled
Expose ledger-backed cross-device purchase history while shipping the tested React admin redesign in the same reproducible deployment revision.
2026-08-19 22:13:13 +08:00
Rocky
11ec34dacb
Enforce deterministic gateway task policies
...
Make the server authoritative for thinking, model, search, tools, retry, and output budgets while preserving legacy client behavior.
2026-08-19 20:55:05 +08:00
Rocky
3edc86a9a0
Show product usage types in credit ledger
...
Persist hotword request origin so every reservation lifecycle entry can be classified without mutating the immutable ledger.
2026-08-19 19:47:12 +08:00
Rocky
e1fd35b1ff
Fix managed ASR settlement and empty polish recovery
...
Accept the final sequence format returned by Volcengine without weakening ordering checks, and retry one safe buffered DeepSeek empty response under the same credit reservation.
2026-08-19 19:16:05 +08:00
Rocky
2194e69bb8
Accept bounded StoreKit signing clock skew
...
Allow legitimate App Store transaction timestamps to differ within the existing verification tolerance while preserving rejection beyond that boundary.
2026-08-19 18:26:54 +08:00
Rocky
75c046d91d
Show latest credit ledger in admin
...
Expose a paginated global ledger timeline and load it automatically so operators can see recent credit activity without first locating a user.
2026-08-19 18:05:54 +08:00
Rocky
58445dd880
Show complete user credit data in admin
...
Load users by registration order, expose consumed and current credits, and accept short internal IDs so support can reliably locate accounts.
2026-08-19 17:54:27 +08:00
Rocky
c592f426be
Enable StoreKit credit purchases in production
...
Keep runtime grant verification aligned with all database migrations so release builds fail before missing table privileges reach deployment.
2026-08-19 15:57:45 +08:00
Rocky
1737106560
checkpoint before checking out feature/account-managed-gateway
2026-08-19 15:53:08 +08:00
Rocky
25cfbfa4e6
Polish admin layout and navigation rhythm
...
Prevent Web Awesome controls from overflowing while giving dashboard sections and navigation states consistent visual spacing.
2026-08-18 09:22:17 +08:00
Rocky
971b7e26c6
Modernize admin UI and harden provider contracts
...
Adopt Web Awesome for consistent accessible controls while aligning production ASR, App Attest, and runtime dependency safeguards.
2026-08-17 21:07:18 +08:00
dependabot[bot]
babc80044d
Bump actions/setup-java from 4 to 5
...
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 4 to 5.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](https://github.com/actions/setup-java/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-17 07:23:55 +00:00
dependabot[bot]
0dff35a0f7
Bump actions/checkout from 4 to 7
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v7 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-17 07:23:55 +00:00
Rocky
dcd77b86ca
Make admin verification directly executable
...
Preserve the deployment verification script as an executable operational check so certificate-boundary acceptance is repeatable.
2026-08-17 15:21:05 +08:00
Rocky
405a2cfc0f
Harden admin deployment and local acceptance
...
Enforce mTLS and least-privilege runtime boundaries while adding repeatable MySQL 8.4 and Docker smoke checks that require no production secrets.
2026-08-17 15:20:46 +08:00
Rocky
1a9c518f96
Add secure administrator operations console
...
Provide TOTP-authenticated, role-controlled user and credit workflows with paginated audit data and SQL-backed statistics so operations can manage growth safely.
2026-08-17 15:20:34 +08:00
Rocky
676bfd2451
Fix production referral service wiring
...
Bind the referral route interface to its service and extend the module regression test to cover every route-facing operations boundary.
2026-08-16 21:14:50 +08:00
Rocky
c415c53a1c
Fix production credit service wiring
...
Register the credits service through its route-facing interface and verify the application module resolves the binding without touching MySQL.
2026-08-16 19:39:06 +08:00
Rocky
a17d058748
Fix container build workspace ownership
...
Allow the non-root Gradle builder to create project-local caches during reproducible image builds.
2026-08-16 15:07:51 +08:00
Rocky
3824d0f6c3
Fix MySQL gateway migration ordering
...
Split replacement-key recreation so MySQL drops the old constraint before validating its reused name.
2026-08-16 15:00:10 +08:00
Rocky
41e2145334
Publish verified Docker images to GHCR
...
Make deployments pull immutable CI-built images while keeping test failures diagnosable before any package is published.
2026-08-16 14:56:36 +08:00
dependabot[bot]
e6ce70117b
Bump gradle/actions from 4 to 6
...
Bumps [gradle/actions](https://github.com/gradle/actions ) from 4 to 6.
- [Release notes](https://github.com/gradle/actions/releases )
- [Commits](https://github.com/gradle/actions/compare/v4...v6 )
---
updated-dependencies:
- dependency-name: gradle/actions
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-16 06:48:12 +00:00
Rocky
0af35d44f4
Establish secure account and managed AI backend
...
Provide the production foundation for Apple identity, immutable credits, referrals, integrity checks, managed providers, and hardened Docker deployment.
2026-08-16 14:46:23 +08:00