Patch notes: 42 changes across 14 sites
Imported. Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers.
What shipped on OpenVibe on 2026-09-29: 42 changes to OpenVibe.Live, OpenVibe.Media, OpenVibe.Games, OpenVibe.Codes, OpenVibe.Network, OpenVibe.Chat and 8 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.
Highlights
- OpenVibe.Games: M1 identity: the WebSocket authenticates at the upgrade, the editor key is gone, and the contracts pin is current (ADR-0007 decisions 8 and 12). (
3ea36b3) - OpenVibe.Media: scripts/retire-r2.js and its test are removed: R2 stays as Media's fast tier (owner, 2026-09-29), so a tool that empties it has no place here. It ran once (its report is on the host); promotion is back on and the sweep refills R2. The… (
1535276) - OpenVibe.Games: Physics conformance suite and an in-memory mock world (ADR-0007 M1 step 1): packages/physics/src/conformance.test.ts runs every seam case against MockPhysicsWorld and the Havok adapter (bodies, sweeps, joints, sleep and settle thresholds… (
c24b7b1) - OpenVibe.Network: Plan T2 deletions in Network (each proven uncalled across the estate first): the one-time scripts hash-refresh-tokens, follows-backfill and creator-analytics-backfill; the built-in fallback tool catalog (before Tools has answered, the… (
f6fe857) - OpenVibe.Games: Movement state hash and determinism harness (ADR-0007 M1 step 2): stateHash.ts hashes the quantised PlayerMoveState (FNV-1a 32-bit over a documented big-endian stream; 1e-4 m, 1e-3 m/s) and measures divergence against the 1 mm / 1 cm/s… (
f328cfc)
OpenVibe.Live
- N-1 fixtures re-recorded from 1a28261, the release now in production (npm run n-1:record). (
ee2ad94) - Internal routes take service tokens (plan T2, X-Internal-Key retirement, step 1 of the sweep): /internal/user-avatar (live.avatar.write), /internal/url-registry/refresh (live.url_registry.refresh), /internal/analytics-summary… (
660833d) - N-1 fixtures re-recorded from 660833d, the release now in production (npm run n-1:record). (
f8880b1) - Live never sends X-Internal-Key again (plan T2, step 2 of the sweep): every call to Network's internal API goes with Live's client-credentials service token, including the avatar report and mark-read-by-type now that Network guards them… (
bea231e) - N-1 fixtures re-recorded from bea231e, the release now in production (npm run n-1:record). (
71829e5) - X-Internal-Key is gone from Live (plan T2, step 3 of the sweep): every internal route takes only a Network service token with the capability it performs (live.avatar.write, live.url_registry.refresh, live.analytics.read… (
66f590b) - N-1 fixtures re-recorded from 66f590b, the release now in production (npm run n-1:record). (
c56e9c4) - No floating promises left in Live (plan T0, the shared checker reports 0): the control socket awaits handleCommand so a rejection is caught and logged; the Kick and YouTube chat-relay connects stay fire-and-forget but log their rejections… (
6e7ed60)
OpenVibe.Media
- scripts/retire-r2.js and its test are removed: R2 stays as Media's fast tier (owner, 2026-09-29), so a tool that empties it has no place here. It ran once (its report is on the host); promotion is back on and the sweep refills R2. The… (
1535276) - docs/media-fabric.md: the accepted design for Media's storage and delivery (owner, 2026-09-29). Two fabrics (online: B2 canonical, R2 Standard hot, Bunny/CDN, the Media host's NVMe edge; archive/backup separately, deep archive never… (
12c6811) - Media Fabric F1a: every read goes through one placement router (docs/media-fabric.md). (
b2bdc44) - Media Fabric F1b, off until the edge host exists: the origin shield. For a public B2 copy Node answers with X-Accel-Redirect into nginx's /_media_shield/b2/ (a 10 MB slice cache with proxy_cache_lock, keyed by object path and slice, never… (
8c19184) - Origin shield (F1b) review fixes, still inert until MEDIA_SHIELD is set. The edge is known from X-Media-Shield-Host, which only the edge server block sets and openvibe.media clears (req.hostname honoured a client's X-Forwarded-Host), and… (
29e6ada) - Origin shield: viewers keep the one public URL. A shield-eligible read (a public or unlisted B2 copy, never private, sandbox or a recording) that arrives on openvibe.media answers a 302 to the same path on the DNS-only edge host, where the… (
2ab62eb) - Origin shield on in production: edge.openvibe.media (DNS-only, DNS-01 certificate), the nginx shield, MEDIA_SHIELD=b2. The edge also hides B2's object headers (x-amz-version-id, x-bz-*). docs/media-fabric.md records the switch-on and the… (
a174534) - X-Internal-Key retirement, Media's step (plan T2): POST /internal/avatar-ingest takes Network's service token with media.avatar.ingest (server/service-guard.js, loopback only; a Bearer is judged on the token alone, the key still passes… (
8364eee)
OpenVibe.Games
- M1 identity: the WebSocket authenticates at the upgrade, the editor key is gone, and the contracts pin is current (ADR-0007 decisions 8 and 12). (
3ea36b3) - Physics conformance suite and an in-memory mock world (ADR-0007 M1 step 1): packages/physics/src/conformance.test.ts runs every seam case against MockPhysicsWorld and the Havok adapter (bodies, sweeps, joints, sleep and settle thresholds… (
c24b7b1) - Staff auth on openvibe-sdk v0.23.1's JWKS client (the last good keys through a Network outage, a rotation honoured on an unknown kid) and openvibe-contracts v0.78.0. Service and app principals are now checked by openvibe-contracts'… (
5d18446) - Movement state hash and determinism harness (ADR-0007 M1 step 2): stateHash.ts hashes the quantised PlayerMoveState (FNV-1a 32-bit over a documented big-endian stream; 1e-4 m, 1e-3 m/s) and measures divergence against the 1 mm / 1 cm/s… (
f328cfc) - The portal's JSON-LD comes from openvibe-shared/seo (plan T11): WebSite plus the game as the site's primary type, injected as the page is served instead of a hand-written block in index.html. The page is built once per file version… (
203057f)
OpenVibe.Codes
- Network tokens verify through openvibe-sdk/auth's JWKS client (v0.23.1) in place of Codes' own key fetcher: the last good keys through a Network outage, backoff, a rotation honoured at once. Sign-in sessions and playground app tokens use… (
57340a9) - Token rejections keep the reason about the token (wrong audience, expired, bad signature): the playground's developers need 'not for openvibe.media'. Only token.no_key, whose SDK text names the internal JWKS URL and the connect error… (
09212f6) - robots.txt, sitemap.xml and a new llms.txt come from openvibe-shared/seo (plan T11, server/http/discovery.js). The sitemap adds each public app and published release with its real publish date (one light query, releases.publicIndex); fixed… (
9c60e95) - Codes' outbox is openvibe-sdk/events createServiceOutbox (plan T1): the same event_outbox table, event-type allowlist and relay rules in one call, the hand-rolled wrapper gone. Pins openvibe-sdk v0.25.0, openvibe-contracts v0.79.0… (
3408517)
OpenVibe.Network
- X-Internal-Key retirement, Network's step (plan T2, register C-50–C-58), on openvibe-contracts v0.79.0 (via v0.78.0: the realtime manifest is gone, so the registry tests assert its absence). The 13 key-only internal routes nothing in the… (
79a4eea) - X-Internal-Key is gone from Network (plan T2, the last step of the sweep): every /internal route takes only a service token with the capability it performs (the router gate answers 401 token.missing without a Bearer and keeps the… (
3bff136) - Plan T2 deletions in Network (each proven uncalled across the estate first): the one-time scripts hash-refresh-tokens, follows-backfill and creator-analytics-backfill; the built-in fallback tool catalog (before Tools has answered, the… (
f6fe857) - Grants for plan T3 and T4, on Contracts 0.80.0: Live reads a channel's moderation settings, moderators and emote count from Chat (chat.moderation.read); Chat uploads and deletes emote images in Media's chat namespace and runs the chat-AI… (
b5d8707)
OpenVibe.Chat
- Pins current (plan T3 step 0): openvibe-sdk v0.23.1 (openvibe-sdk/db, ambient transactions, openvibe-sdk/testing, the JWKS client), openvibe-contracts v0.79.0, openvibe-shared v2.0.0 (none of its removed exports were used here), and the… (
50e4dc1) - robots.txt, llms.txt and sitemap.xml come from openvibe-shared/seo (plan T11, server/web/discovery.js): public data only, lastmod from the data itself (the newest public message, each room's last activity), never today; every previous… (
2091ec6)
OpenVibe.Search
search.openvibe.network · repository
- Network tokens verify with keys from openvibe-sdk/auth's JWKS client (v0.23.1) in place of the hand-written key store: fresh keys, the last good ones through a Network outage, backoff, and a rotation honoured on an unknown kid. Service… (
a3235a5) - Crawl files through openvibe-shared/seo (plan T11): /llms.txt (what Search is, its public pages and machine-readable endpoints), /robots.txt from the shared builder with every existing rule kept, /sitemap.xml whose lastmods come from the… (
fb2eed3)
OpenVibe.Sources
sources.openvibe.network · repository
- A corrupt stored robots.txt row no longer throws: it reads as no rules and warns once per origin (plan T0). Test: test/robots-ssrf.test.js stores unparseable rules and checks the fetch goes on. Built on a free model, reviewed independently… (
d3f5e00) - Network tokens verify with keys from openvibe-sdk/auth's JWKS client (v0.23.1) in place of Sources' own key store: the last good keys through a Network outage, backoff, a rotation honoured on an unknown kid. Every service-token rule stays… (
4bea21f)
OpenVibe.Tools
- Internal analytics take Network service tokens (plan T2, X-Internal-Key retirement): GET /api/internal/analytics (and /bots) on the gateway and all seven tool sites accept a token holding tools.analytics.read (audience openvibe.tools… (
55e4b84) - X-Internal-Key is gone from Tools (plan T2): GET /api/internal/analytics[/bots] on the gateway and the seven tool sites take only a Network service token with tools.analytics.read (401 token.missing without one), loopback only; the gateway… (
139ece3)
OpenVibe.AI
ai.openvibe.network · repository
- Network tokens verify with keys from openvibe-sdk/auth's JWKS client (v0.23.1): fresh keys, the last good ones through a Network outage, backoff, and a rotation honoured on an unknown kid, in place of the hand-written key store. Every… (
dde5e8f)
OpenVibe.Blog
- Blog on the service kit (plan T1): sign-in is openvibe-sdk/sso createSsoClient (state + PKCE S256, server-side exchange, next limited to this site and the Network), service tokens are checked by openvibe-sdk/auth verifyServiceToken (the… (
f3fac6a)
OpenVibe.Coupons
- Coupons on the service kit (plan T1): sign-in is openvibe-sdk/sso createSsoClient (state + PKCE S256, server-side exchange, next limited to this site and the Network) and server/auth/sso.js with the openvibe-shared/auth-client import is… (
d4d51e1)
OpenVibe.Deals
- Deals on the service kit (plan T1): sign-in is openvibe-sdk/sso createSsoClient (state + PKCE S256, server-side exchange, next limited to this site and the Network), service tokens are checked by openvibe-sdk/auth verifyServiceToken (the… (
8d78e7e)
OpenVibe.Tips
- Tips' outbox is openvibe-sdk/events createServiceOutbox (plan T1): tips_event_outbox, the service as actor, internal visibility and important priority on every envelope as before; callers use emitIn(t, envelope) inside the change's… (
592a420)
Patch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.
Comments
Comments could not be loaded from OpenVibe.Community right now. Reload later.