Patch notes: 42 changes across 14 sites

Imported. Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers.

What shipped on OpenVibe on 2026-09-29: 42 changes to OpenVibe.Live, OpenVibe.Media, OpenVibe.Games, OpenVibe.Codes, OpenVibe.Network, OpenVibe.Chat and 8 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.

Highlights

  • OpenVibe.Games: M1 identity: the WebSocket authenticates at the upgrade, the editor key is gone, and the contracts pin is current (ADR-0007 decisions 8 and 12). (3ea36b3)
  • OpenVibe.Media: scripts/retire-r2.js and its test are removed: R2 stays as Media's fast tier (owner, 2026-09-29), so a tool that empties it has no place here. It ran once (its report is on the host); promotion is back on and the sweep refills R2. The… (1535276)
  • OpenVibe.Games: Physics conformance suite and an in-memory mock world (ADR-0007 M1 step 1): packages/physics/src/conformance.test.ts runs every seam case against MockPhysicsWorld and the Havok adapter (bodies, sweeps, joints, sleep and settle thresholds… (c24b7b1)
  • OpenVibe.Network: Plan T2 deletions in Network (each proven uncalled across the estate first): the one-time scripts hash-refresh-tokens, follows-backfill and creator-analytics-backfill; the built-in fallback tool catalog (before Tools has answered, the… (f6fe857)
  • OpenVibe.Games: Movement state hash and determinism harness (ADR-0007 M1 step 2): stateHash.ts hashes the quantised PlayerMoveState (FNV-1a 32-bit over a documented big-endian stream; 1e-4 m, 1e-3 m/s) and measures divergence against the 1 mm / 1 cm/s… (f328cfc)

OpenVibe.Live

openvibe.live · repository

  • N-1 fixtures re-recorded from 1a28261, the release now in production (npm run n-1:record). (ee2ad94)
  • Internal routes take service tokens (plan T2, X-Internal-Key retirement, step 1 of the sweep): /internal/user-avatar (live.avatar.write), /internal/url-registry/refresh (live.url_registry.refresh), /internal/analytics-summary… (660833d)
  • N-1 fixtures re-recorded from 660833d, the release now in production (npm run n-1:record). (f8880b1)
  • Live never sends X-Internal-Key again (plan T2, step 2 of the sweep): every call to Network's internal API goes with Live's client-credentials service token, including the avatar report and mark-read-by-type now that Network guards them… (bea231e)
  • N-1 fixtures re-recorded from bea231e, the release now in production (npm run n-1:record). (71829e5)
  • X-Internal-Key is gone from Live (plan T2, step 3 of the sweep): every internal route takes only a Network service token with the capability it performs (live.avatar.write, live.url_registry.refresh, live.analytics.read… (66f590b)
  • N-1 fixtures re-recorded from 66f590b, the release now in production (npm run n-1:record). (c56e9c4)
  • No floating promises left in Live (plan T0, the shared checker reports 0): the control socket awaits handleCommand so a rejection is caught and logged; the Kick and YouTube chat-relay connects stay fire-and-forget but log their rejections… (6e7ed60)

OpenVibe.Media

openvibe.media · repository

  • scripts/retire-r2.js and its test are removed: R2 stays as Media's fast tier (owner, 2026-09-29), so a tool that empties it has no place here. It ran once (its report is on the host); promotion is back on and the sweep refills R2. The… (1535276)
  • docs/media-fabric.md: the accepted design for Media's storage and delivery (owner, 2026-09-29). Two fabrics (online: B2 canonical, R2 Standard hot, Bunny/CDN, the Media host's NVMe edge; archive/backup separately, deep archive never… (12c6811)
  • Media Fabric F1a: every read goes through one placement router (docs/media-fabric.md). (b2bdc44)
  • Media Fabric F1b, off until the edge host exists: the origin shield. For a public B2 copy Node answers with X-Accel-Redirect into nginx's /_media_shield/b2/ (a 10 MB slice cache with proxy_cache_lock, keyed by object path and slice, never… (8c19184)
  • Origin shield (F1b) review fixes, still inert until MEDIA_SHIELD is set. The edge is known from X-Media-Shield-Host, which only the edge server block sets and openvibe.media clears (req.hostname honoured a client's X-Forwarded-Host), and… (29e6ada)
  • Origin shield: viewers keep the one public URL. A shield-eligible read (a public or unlisted B2 copy, never private, sandbox or a recording) that arrives on openvibe.media answers a 302 to the same path on the DNS-only edge host, where the… (2ab62eb)
  • Origin shield on in production: edge.openvibe.media (DNS-only, DNS-01 certificate), the nginx shield, MEDIA_SHIELD=b2. The edge also hides B2's object headers (x-amz-version-id, x-bz-*). docs/media-fabric.md records the switch-on and the… (a174534)
  • X-Internal-Key retirement, Media's step (plan T2): POST /internal/avatar-ingest takes Network's service token with media.avatar.ingest (server/service-guard.js, loopback only; a Bearer is judged on the token alone, the key still passes… (8364eee)

OpenVibe.Games

openvibe.games · repository

  • M1 identity: the WebSocket authenticates at the upgrade, the editor key is gone, and the contracts pin is current (ADR-0007 decisions 8 and 12). (3ea36b3)
  • Physics conformance suite and an in-memory mock world (ADR-0007 M1 step 1): packages/physics/src/conformance.test.ts runs every seam case against MockPhysicsWorld and the Havok adapter (bodies, sweeps, joints, sleep and settle thresholds… (c24b7b1)
  • Staff auth on openvibe-sdk v0.23.1's JWKS client (the last good keys through a Network outage, a rotation honoured on an unknown kid) and openvibe-contracts v0.78.0. Service and app principals are now checked by openvibe-contracts'… (5d18446)
  • Movement state hash and determinism harness (ADR-0007 M1 step 2): stateHash.ts hashes the quantised PlayerMoveState (FNV-1a 32-bit over a documented big-endian stream; 1e-4 m, 1e-3 m/s) and measures divergence against the 1 mm / 1 cm/s… (f328cfc)
  • The portal's JSON-LD comes from openvibe-shared/seo (plan T11): WebSite plus the game as the site's primary type, injected as the page is served instead of a hand-written block in index.html. The page is built once per file version… (203057f)

OpenVibe.Codes

openvibe.codes · repository

  • Network tokens verify through openvibe-sdk/auth's JWKS client (v0.23.1) in place of Codes' own key fetcher: the last good keys through a Network outage, backoff, a rotation honoured at once. Sign-in sessions and playground app tokens use… (57340a9)
  • Token rejections keep the reason about the token (wrong audience, expired, bad signature): the playground's developers need 'not for openvibe.media'. Only token.no_key, whose SDK text names the internal JWKS URL and the connect error… (09212f6)
  • robots.txt, sitemap.xml and a new llms.txt come from openvibe-shared/seo (plan T11, server/http/discovery.js). The sitemap adds each public app and published release with its real publish date (one light query, releases.publicIndex); fixed… (9c60e95)
  • Codes' outbox is openvibe-sdk/events createServiceOutbox (plan T1): the same event_outbox table, event-type allowlist and relay rules in one call, the hand-rolled wrapper gone. Pins openvibe-sdk v0.25.0, openvibe-contracts v0.79.0… (3408517)

OpenVibe.Network

openvibe.network · repository

  • X-Internal-Key retirement, Network's step (plan T2, register C-50–C-58), on openvibe-contracts v0.79.0 (via v0.78.0: the realtime manifest is gone, so the registry tests assert its absence). The 13 key-only internal routes nothing in the… (79a4eea)
  • X-Internal-Key is gone from Network (plan T2, the last step of the sweep): every /internal route takes only a service token with the capability it performs (the router gate answers 401 token.missing without a Bearer and keeps the… (3bff136)
  • Plan T2 deletions in Network (each proven uncalled across the estate first): the one-time scripts hash-refresh-tokens, follows-backfill and creator-analytics-backfill; the built-in fallback tool catalog (before Tools has answered, the… (f6fe857)
  • Grants for plan T3 and T4, on Contracts 0.80.0: Live reads a channel's moderation settings, moderators and emote count from Chat (chat.moderation.read); Chat uploads and deletes emote images in Media's chat namespace and runs the chat-AI… (b5d8707)

OpenVibe.Chat

openvibe.chat · repository

  • Pins current (plan T3 step 0): openvibe-sdk v0.23.1 (openvibe-sdk/db, ambient transactions, openvibe-sdk/testing, the JWKS client), openvibe-contracts v0.79.0, openvibe-shared v2.0.0 (none of its removed exports were used here), and the… (50e4dc1)
  • robots.txt, llms.txt and sitemap.xml come from openvibe-shared/seo (plan T11, server/web/discovery.js): public data only, lastmod from the data itself (the newest public message, each room's last activity), never today; every previous… (2091ec6)

OpenVibe.Search

search.openvibe.network · repository

  • Network tokens verify with keys from openvibe-sdk/auth's JWKS client (v0.23.1) in place of the hand-written key store: fresh keys, the last good ones through a Network outage, backoff, and a rotation honoured on an unknown kid. Service… (a3235a5)
  • Crawl files through openvibe-shared/seo (plan T11): /llms.txt (what Search is, its public pages and machine-readable endpoints), /robots.txt from the shared builder with every existing rule kept, /sitemap.xml whose lastmods come from the… (fb2eed3)

OpenVibe.Sources

sources.openvibe.network · repository

  • A corrupt stored robots.txt row no longer throws: it reads as no rules and warns once per origin (plan T0). Test: test/robots-ssrf.test.js stores unparseable rules and checks the fetch goes on. Built on a free model, reviewed independently… (d3f5e00)
  • Network tokens verify with keys from openvibe-sdk/auth's JWKS client (v0.23.1) in place of Sources' own key store: the last good keys through a Network outage, backoff, a rotation honoured on an unknown kid. Every service-token rule stays… (4bea21f)

OpenVibe.Tools

openvibe.tools · repository

  • Internal analytics take Network service tokens (plan T2, X-Internal-Key retirement): GET /api/internal/analytics (and /bots) on the gateway and all seven tool sites accept a token holding tools.analytics.read (audience openvibe.tools… (55e4b84)
  • X-Internal-Key is gone from Tools (plan T2): GET /api/internal/analytics[/bots] on the gateway and the seven tool sites take only a Network service token with tools.analytics.read (401 token.missing without one), loopback only; the gateway… (139ece3)

OpenVibe.AI

ai.openvibe.network · repository

  • Network tokens verify with keys from openvibe-sdk/auth's JWKS client (v0.23.1): fresh keys, the last good ones through a Network outage, backoff, and a rotation honoured on an unknown kid, in place of the hand-written key store. Every… (dde5e8f)

OpenVibe.Blog

openvibe.blog · repository

  • Blog on the service kit (plan T1): sign-in is openvibe-sdk/sso createSsoClient (state + PKCE S256, server-side exchange, next limited to this site and the Network), service tokens are checked by openvibe-sdk/auth verifyServiceToken (the… (f3fac6a)

OpenVibe.Coupons

openvibe.coupons · repository

  • Coupons on the service kit (plan T1): sign-in is openvibe-sdk/sso createSsoClient (state + PKCE S256, server-side exchange, next limited to this site and the Network) and server/auth/sso.js with the openvibe-shared/auth-client import is… (d4d51e1)

OpenVibe.Deals

openvibe.deals · repository

  • Deals on the service kit (plan T1): sign-in is openvibe-sdk/sso createSsoClient (state + PKCE S256, server-side exchange, next limited to this site and the Network), service tokens are checked by openvibe-sdk/auth verifyServiceToken (the… (8d78e7e)

OpenVibe.Tips

openvibe.tips · repository

  • Tips' outbox is openvibe-sdk/events createServiceOutbox (plan T1): tips_event_outbox, the service as actor, internal visibility and important priority on every envelope as before; callers use emitIn(t, envelope) inside the change's… (592a420)

Patch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.

Comments

Comments could not be loaded from OpenVibe.Community right now. Reload later.