Patch notes: 30 changes across 15 sites
Imported. Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers.
What shipped on OpenVibe on 2026-09-24: 30 changes to OpenVibe.Chat, OpenVibe.Network, OpenVibe.Games, OpenVibe.Live, OpenVibe.Billing, OpenVibe.Codes and 9 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.
Highlights
- OpenVibe.Chat: openvibe.chat, the site (WS-I task 8): global chat (server-rendered, live over /ws/chat), messages (inbox, conversations for participants only, start one by username) and settings (the chat.preferences record Live's chat reads), /updates… (
4937946)
OpenVibe.Chat
- ?token= on /ws/chat is deprecated (C-05): still honoured for the bots that use it, counted in /metrics chat_ws_url_token_uses{kind}; bots authenticate the upgrade with an Authorization header (tested) and browsers with their first join… (
01081ad) - Revocation propagation (WS-B task 4, Contracts 0.39.0): Chat subscribes to network.user.token_valid_after, keeps the latest cutoff per subject, refuses Network tokens issued before it (locally and on the Live fallback) and closes the… (
a2b12b5) - openvibe.chat, the site (WS-I task 8): global chat (server-rendered, live over /ws/chat), messages (inbox, conversations for participants only, start one by username) and settings (the chat.preferences record Live's chat reads), /updates… (
4937946) - deploy/nginx/openvibe.chat.conf: the reference vhost for openvibe.chat (everything to Chat on 4400, /ws/chat upgraded with long timeouts, sign-in/API/form posts rate-limited, /internal and /metrics 404, client address from the connection… (
e92a6ea) - Contracts 0.40.0 (the chat manifest names openvibe.chat) (
3c06399) - openvibe.chat: one navigation (the shared navbar carries Global chat, Messages and Settings; without JavaScript the Frame's noscript nav and a sign-in line) (
eedd3d3)
OpenVibe.Network
- Revocation propagation (WS-B task 4, Contracts 0.39.0): revokeTokens() moves token_valid_after, ends Network sessions and queues network.user.token_valid_after in the same transaction; password change and reset, bans, POST… (
8033d01) - Grant games events.subscription.manage on openvibe.events: Games subscribes to network.user.token_valid_after so a sign-out everywhere closes game sessions (
67f7013) - Username history (WS-B task 6): admins rename people (admin → Users → Rename, owner-protected, audited); every rename is kept in username_history, the old name stays reserved for 180 days (registration and renames refuse it for anyone… (
74d4610) - Names lookup: GET /api/v1/users/names/:name answers { current, network_id, renamed, previous_names } for a current or an old name (banned accounts and unknown names 404), so Live can redirect /@old and pick up a new name it has not seen… (
3aec618) - Contracts 0.40.0: openvibe.chat joins the first-party origins (the shared navbar on the new Chat site talks to Network) (
ee78598) - Registry flip: chat is live on openvibe.chat (exposure live/service); the Frame's site switcher opens it (its host now comes from the manifest's publicOrigin) (
cfb112b)
OpenVibe.Games
- Rank from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): owner from the is_owner claim, admin from staff.games.manage (map editor, noclip, mod administration), moderator from staff.moderation.chat, read from the token the… (
9cfbd11) - Legacy import re-checked 2026-09-24: the same 12 no-subject Live users (200 rows) are the standing import-hold; players.subject_id needs no backfill (ovn:1 moved, the rest are device guests and probes) (
bfebe5c) - Sign-out everywhere reaches Games (WS-B task 4, Contracts 0.39.0, SDK 0.9.1): POST /internal/events (GAMES_EVENTS_SECRET, signature v2, loopback only) applies network.user.token_valid_after into the SDK revocation store and closes the… (
5c002f2) - Guest conversion (WS-B task 8): the character a browser played as a guest moves into the account that signs in on it, into the first free slot, once (remembered by a hash of the guest token, never the token); it happens at the character… (
e307eaa)
OpenVibe.Live
- Chat sockets never carry the token in the URL (C-05): chat, the media player and the broadcast PiP send it in their first join message; a message typed while the chat socket reconnects stays in the box instead of being re-posted to global… (
ae589ac) - Revocation propagation (WS-B task 4, Contracts 0.39.0): POST /internal/network-events (signature v2, LIVE_EVENTS_SECRET else MEDIA_EVENTS_SECRET) records network.user.token_valid_after per subject, only ever forwards; verifyToken refuses a… (
a48c5a2) - Renamed channels (WS-B task 6): Live follows a Network rename (the signed token's username at sign-in, or GET /api/v1/users/names/:name for a /@name it does not know yet), keeps username_history, and the page fallback answers /@old with a… (
0aa56ad)
OpenVibe.Billing
billing.openvibe.network · repository
- Staff console access from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): a listed subject must also hold staff.money.cashouts (money is the owner's), not role admin; the session keeps the effective role and is re-checked… (
85fd198)
OpenVibe.Codes
- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0, docs regenerate from it): Codes staff are staff.site.configure (admin, as before) or CODES_STAFF_SUBJECTS (break-glass), not a role comparison.… (
57809ad)
OpenVibe.Community
openvibe.community · repository
- Revocation propagation (WS-B task 4, Contracts 0.39.0, SDK 0.9.1): Community subscribes to network.user.token_valid_after, applies it once through the inbox into openvibe-sdk createRevocationStore, and the viewer resolver treats a token… (
6b5f6e1)
OpenVibe.Coupons
- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): Coupons staff are staff.editorial.manage (admin, as before) or COUPONS_STAFF_SUBJECTS (the product's own, break-glass), not a role comparison.… (
74c4a1f)
OpenVibe.Deals
- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): moderators are staff.content.moderate (global_mod and up, as before) or DEALS_MODERATORS (the product's own role), not a role list. test/staff-map.test.js fails… (
c17c010)
OpenVibe.Host
- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): Host staff (quotas, takedowns, maintaining any project) are staff.site.configure (admin, as before), not a role list. test/staff-map.test.js fails on raw role… (
5a00513)
OpenVibe.News
- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): staff editors are staff.editorial.manage (admin, as before), not a role list; NEWS_EDITORS stays the product's own editor role. test/staff-map.test.js fails on… (
b592ef0)
OpenVibe.Reviews
- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): staff editors are staff.editorial.manage (admin; global_mods moderate but no longer edit entities), not a role list; REVIEWS_EDITORS stays the product's own… (
37b656f)
OpenVibe.Tools
- Guest conversion for the launcher (WS-B task 8): the first time an account asks for its recent tools from a browser, the tools that browser used as a guest (ov_recent_tools) join the account's tools.usage list, once per account and browser… (
bfa8c2e)
OpenVibe.Trade
- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): editors are staff.editorial.manage (admin, as before) or TRADE_EDITORS (the product's own role), not a role comparison. test/staff-map.test.js fails on raw role… (
d825075)
OpenVibe.VIP
- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): managing network plans and any creator's plans is staff.site.configure (admin, as before), decided once from the token in userPrincipal; VIP_STAFF_ROLES is gone.… (
964a10c)
Patch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.
Comments
Comments could not be loaded from OpenVibe.Community right now. Reload later.