{"id":"pst_01M3B435QV9CETJGTVXYSQHEE6","url":"https://openvibe.blog/@openvibe/patch-notes-30-changes-across-15-sites","blog":{"id":"blg_01M362MF0EDJ7QHQTRD8A3Q981","handle":"openvibe","title":"The OpenVibe blog","url":"https://openvibe.blog/"},"title":"Patch notes: 30 changes across 15 sites","summary":"What shipped on OpenVibe on 2026-09-24: 30 changes to OpenVibe.Chat, OpenVibe.Network, OpenVibe.Games, OpenVibe.Live, OpenVibe.Billing, OpenVibe.Codes and 9 more.","body_markdown":"What shipped on OpenVibe on 2026-09-24: 30 changes to OpenVibe.Chat, OpenVibe.Network, OpenVibe.Games, OpenVibe.Live, OpenVibe.Billing, OpenVibe.Codes and 9 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.\n\n## Highlights\n\n- **OpenVibe.Chat:** openvibe.chat, the site (WS-I task 8): global chat (server-rendered, live over /ws/chat), messages (inbox, conversations for participants only, start one by username) and settings (the chat.preferences record Live's chat reads), /updates… ([`4937946`](https://github.com/OpenVibers/OpenVibe.Chat/commit/49379468a5a2707ef24b92707d7234dd5ba1d86f))\n\n## OpenVibe.Chat\n\n[openvibe.chat](https://openvibe.chat) · [repository](https://github.com/OpenVibers/OpenVibe.Chat)\n\n- ?token= on /ws/chat is deprecated (C-05): still honoured for the bots that use it, counted in /metrics chat_ws_url_token_uses{kind}; bots authenticate the upgrade with an Authorization header (tested) and browsers with their first join… ([`01081ad`](https://github.com/OpenVibers/OpenVibe.Chat/commit/01081ad94d89ddf3038f7c12ad235cc9eaaab849))\n- Revocation propagation (WS-B task 4, Contracts 0.39.0): Chat subscribes to network.user.token_valid_after, keeps the latest cutoff per subject, refuses Network tokens issued before it (locally and on the Live fallback) and closes the… ([`a2b12b5`](https://github.com/OpenVibers/OpenVibe.Chat/commit/a2b12b5070bb0b8f738f68e88031f5474ba31656))\n- openvibe.chat, the site (WS-I task 8): global chat (server-rendered, live over /ws/chat), messages (inbox, conversations for participants only, start one by username) and settings (the chat.preferences record Live's chat reads), /updates… ([`4937946`](https://github.com/OpenVibers/OpenVibe.Chat/commit/49379468a5a2707ef24b92707d7234dd5ba1d86f))\n- deploy/nginx/openvibe.chat.conf: the reference vhost for openvibe.chat (everything to Chat on 4400, /ws/chat upgraded with long timeouts, sign-in/API/form posts rate-limited, /internal and /metrics 404, client address from the connection… ([`e92a6ea`](https://github.com/OpenVibers/OpenVibe.Chat/commit/e92a6ead09f1b79f307eb8e8f92b34e156e97ba9))\n- Contracts 0.40.0 (the chat manifest names openvibe.chat) ([`3c06399`](https://github.com/OpenVibers/OpenVibe.Chat/commit/3c06399c8154dd8dd8e9e5a6ebdc5ea78a4db48a))\n- openvibe.chat: one navigation (the shared navbar carries Global chat, Messages and Settings; without JavaScript the Frame's noscript nav and a sign-in line) ([`eedd3d3`](https://github.com/OpenVibers/OpenVibe.Chat/commit/eedd3d3ccfa15fe0ec3b1f47432eb98d8f9fde63))\n\n## OpenVibe.Network\n\n[openvibe.network](https://openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Network)\n\n- Revocation propagation (WS-B task 4, Contracts 0.39.0): revokeTokens() moves token_valid_after, ends Network sessions and queues network.user.token_valid_after in the same transaction; password change and reset, bans, POST… ([`8033d01`](https://github.com/OpenVibers/OpenVibe.Network/commit/8033d0164267d382d6bfb4f1f3fc6c741e064ab2))\n- Grant games events.subscription.manage on openvibe.events: Games subscribes to network.user.token_valid_after so a sign-out everywhere closes game sessions ([`67f7013`](https://github.com/OpenVibers/OpenVibe.Network/commit/67f70139324d8f718950ac909aedb2593c9776e9))\n- Username history (WS-B task 6): admins rename people (admin → Users → Rename, owner-protected, audited); every rename is kept in username_history, the old name stays reserved for 180 days (registration and renames refuse it for anyone… ([`74d4610`](https://github.com/OpenVibers/OpenVibe.Network/commit/74d46102c4f6410b09dcb459a4f68d4b139de812))\n- Names lookup: GET /api/v1/users/names/:name answers { current, network_id, renamed, previous_names } for a current or an old name (banned accounts and unknown names 404), so Live can redirect /@old and pick up a new name it has not seen… ([`3aec618`](https://github.com/OpenVibers/OpenVibe.Network/commit/3aec618ada0f815b293fda053702f08e31ce74a0))\n- Contracts 0.40.0: openvibe.chat joins the first-party origins (the shared navbar on the new Chat site talks to Network) ([`ee78598`](https://github.com/OpenVibers/OpenVibe.Network/commit/ee78598dd059756ab8dfbd7087a37debe2713622))\n- Registry flip: chat is live on openvibe.chat (exposure live/service); the Frame's site switcher opens it (its host now comes from the manifest's publicOrigin) ([`cfb112b`](https://github.com/OpenVibers/OpenVibe.Network/commit/cfb112be129e464031c87775248c3d6414f3d27e))\n\n## OpenVibe.Games\n\n[openvibe.games](https://openvibe.games) · [repository](https://github.com/OpenVibers/OpenVibe.Games)\n\n- Rank from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): owner from the is_owner claim, admin from staff.games.manage (map editor, noclip, mod administration), moderator from staff.moderation.chat, read from the token the… ([`9cfbd11`](https://github.com/OpenVibers/OpenVibe.Games/commit/9cfbd11afd1bd69f8c457a79e059a16cd24b980e))\n- Legacy import re-checked 2026-09-24: the same 12 no-subject Live users (200 rows) are the standing import-hold; players.subject_id needs no backfill (ovn:1 moved, the rest are device guests and probes) ([`bfebe5c`](https://github.com/OpenVibers/OpenVibe.Games/commit/bfebe5c72323cf73f166ce09ca4f9a6a4e114cb2))\n- Sign-out everywhere reaches Games (WS-B task 4, Contracts 0.39.0, SDK 0.9.1): POST /internal/events (GAMES_EVENTS_SECRET, signature v2, loopback only) applies network.user.token_valid_after into the SDK revocation store and closes the… ([`5c002f2`](https://github.com/OpenVibers/OpenVibe.Games/commit/5c002f2c480bfe460800cbe2cbe29ae11670afd2))\n- Guest conversion (WS-B task 8): the character a browser played as a guest moves into the account that signs in on it, into the first free slot, once (remembered by a hash of the guest token, never the token); it happens at the character… ([`e307eaa`](https://github.com/OpenVibers/OpenVibe.Games/commit/e307eaa2d895d6698dfc683a944a8aad51b5eabd))\n\n## OpenVibe.Live\n\n[openvibe.live](https://openvibe.live) · [repository](https://github.com/OpenVibers/OpenVibe.Live)\n\n- Chat sockets never carry the token in the URL (C-05): chat, the media player and the broadcast PiP send it in their first join message; a message typed while the chat socket reconnects stays in the box instead of being re-posted to global… ([`ae589ac`](https://github.com/OpenVibers/OpenVibe.Live/commit/ae589aca17b7be1ee40cbb482cc6ff4653a90937))\n- Revocation propagation (WS-B task 4, Contracts 0.39.0): POST /internal/network-events (signature v2, LIVE_EVENTS_SECRET else MEDIA_EVENTS_SECRET) records network.user.token_valid_after per subject, only ever forwards; verifyToken refuses a… ([`a48c5a2`](https://github.com/OpenVibers/OpenVibe.Live/commit/a48c5a2af2c903e64838dfbbf6a0d112864c939a))\n- Renamed channels (WS-B task 6): Live follows a Network rename (the signed token's username at sign-in, or GET /api/v1/users/names/:name for a /@name it does not know yet), keeps username_history, and the page fallback answers /@old with a… ([`0aa56ad`](https://github.com/OpenVibers/OpenVibe.Live/commit/0aa56ad041bd46b676386c4eb6ae1843628c070c))\n\n## OpenVibe.Billing\n\n[billing.openvibe.network](https://billing.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Billing)\n\n- Staff console access from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): a listed subject must also hold staff.money.cashouts (money is the owner's), not role admin; the session keeps the effective role and is re-checked… ([`85fd198`](https://github.com/OpenVibers/OpenVibe.Billing/commit/85fd198ddbf6a7221b9f07409d6d1c113df003e1))\n\n## OpenVibe.Codes\n\n[openvibe.codes](https://openvibe.codes) · [repository](https://github.com/OpenVibers/OpenVibe.Codes)\n\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0, docs regenerate from it): Codes staff are staff.site.configure (admin, as before) or CODES_STAFF_SUBJECTS (break-glass), not a role comparison.… ([`57809ad`](https://github.com/OpenVibers/OpenVibe.Codes/commit/57809ad58828eb49c7b9d8607ca5044b623057e8))\n\n## OpenVibe.Community\n\n[openvibe.community](https://openvibe.community) · [repository](https://github.com/OpenVibers/OpenVibe.Community)\n\n- Revocation propagation (WS-B task 4, Contracts 0.39.0, SDK 0.9.1): Community subscribes to network.user.token_valid_after, applies it once through the inbox into openvibe-sdk createRevocationStore, and the viewer resolver treats a token… ([`6b5f6e1`](https://github.com/OpenVibers/OpenVibe.Community/commit/6b5f6e1b9810618ed411216798f65eec70dd11b6))\n\n## OpenVibe.Coupons\n\n[openvibe.coupons](https://openvibe.coupons) · [repository](https://github.com/OpenVibers/OpenVibe.Coupons)\n\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): Coupons staff are staff.editorial.manage (admin, as before) or COUPONS_STAFF_SUBJECTS (the product's own, break-glass), not a role comparison.… ([`74c4a1f`](https://github.com/OpenVibers/OpenVibe.Coupons/commit/74c4a1fd28dc040f562f58045e904320a579afc9))\n\n## OpenVibe.Deals\n\n[openvibe.deals](https://openvibe.deals) · [repository](https://github.com/OpenVibers/OpenVibe.Deals)\n\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): moderators are staff.content.moderate (global_mod and up, as before) or DEALS_MODERATORS (the product's own role), not a role list. test/staff-map.test.js fails… ([`c17c010`](https://github.com/OpenVibers/OpenVibe.Deals/commit/c17c0100c977ac8ced6952ff89a00531f07d086b))\n\n## OpenVibe.Host\n\n[openvibe.host](https://openvibe.host) · [repository](https://github.com/OpenVibers/OpenVibe.Host)\n\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): Host staff (quotas, takedowns, maintaining any project) are staff.site.configure (admin, as before), not a role list. test/staff-map.test.js fails on raw role… ([`5a00513`](https://github.com/OpenVibers/OpenVibe.Host/commit/5a0051349cd1c444af79b8adde2186fbcd235be1))\n\n## OpenVibe.News\n\n[openvibe.news](https://openvibe.news) · [repository](https://github.com/OpenVibers/OpenVibe.News)\n\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): staff editors are staff.editorial.manage (admin, as before), not a role list; NEWS_EDITORS stays the product's own editor role. test/staff-map.test.js fails on… ([`b592ef0`](https://github.com/OpenVibers/OpenVibe.News/commit/b592ef0d086a82b4b222c0b3598adbbf757a0b9f))\n\n## OpenVibe.Reviews\n\n[openvibe.reviews](https://openvibe.reviews) · [repository](https://github.com/OpenVibers/OpenVibe.Reviews)\n\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): staff editors are staff.editorial.manage (admin; global_mods moderate but no longer edit entities), not a role list; REVIEWS_EDITORS stays the product's own… ([`37b656f`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/37b656fb63b102331c92ead641ade0fc71bb6f37))\n\n## OpenVibe.Tools\n\n[openvibe.tools](https://openvibe.tools) · [repository](https://github.com/OpenVibers/OpenVibe.Tools)\n\n- Guest conversion for the launcher (WS-B task 8): the first time an account asks for its recent tools from a browser, the tools that browser used as a guest (ov_recent_tools) join the account's tools.usage list, once per account and browser… ([`bfa8c2e`](https://github.com/OpenVibers/OpenVibe.Tools/commit/bfa8c2e1c9b1461b5821e1816e6e19f15bc9ab17))\n\n## OpenVibe.Trade\n\n[openvibe.trade](https://openvibe.trade) · [repository](https://github.com/OpenVibers/OpenVibe.Trade)\n\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): editors are staff.editorial.manage (admin, as before) or TRADE_EDITORS (the product's own role), not a role comparison. test/staff-map.test.js fails on raw role… ([`d825075`](https://github.com/OpenVibers/OpenVibe.Trade/commit/d8250750c7afc4b2ec8af2c9c2d48e4ea43a0d14))\n\n## OpenVibe.VIP\n\n[openvibe.vip](https://openvibe.vip) · [repository](https://github.com/OpenVibers/OpenVibe.VIP)\n\n- Staff powers from the contracts staff map (WS-D, ADR-022; Contracts 0.38.0): managing network plans and any creator's plans is staff.site.configure (admin, as before), decided once from the token in userPrincipal; VIP_STAFF_ROLES is gone.… ([`964a10c`](https://github.com/OpenVibers/OpenVibe.VIP/commit/964a10c45578c804a96886d8b259d9251a6e6141))\n\n---\n\nPatch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.","revision":1,"state":"published","visibility":"public","published_at":"2026-09-25T01:50:17.854Z","revised_at":"2026-09-25T01:50:17.852Z","author":{"subject":"usr_01KKT9AC60KM7CRTB3WN1Z8P56","name":"goosely","username":"goosely"},"authorship":{"mode":"imported","workflow":null,"reviewed":false,"disclosure":{"mode":"imported","short":"Imported","long":"Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers."}},"tags":["patch-notes","chat","network","games","live","billing","codes","community","coupons","deals","host"],"categories":[],"series":{"title":"Patch notes","url":"https://openvibe.blog/@openvibe/series/patch-notes","position":null},"media":[],"citations":[],"indexability":{"indexable":true,"robots":"index, follow","reasons":[]}}