Patch notes: Chat parity script
Imported. Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers.
What shipped on OpenVibe on 2026-09-26: 118 changes to OpenVibe.Host, OpenVibe.Live, OpenVibe.Chat, OpenVibe.Blog, OpenVibe.Codes, OpenVibe.Community and 18 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.
Highlights
- OpenVibe.Chat: Chat parity script (roadmap WS-I task 6): scripts/parity.js runs the chat product end to end over the real protocol with two or three people connected and checks what each sees, one scenario per item: join (anonymous and signed in, the… (
91a36f2) - OpenVibe.Host: docs/release-notifications.md: before a site pins openvibe-shared 1.17.0, its CSP connect-src must allow https://events.openvibe.network (Live and Community do; Network, Wiki, Blog, Codes, Search, Reviews, VIP, Tips, Host, News, Deals and… (
d098cef)
OpenVibe.Host
- Developer path against production, daily (WS-N task 1): openvibe-devpath.timer runs OpenVibe.Examples' developer path as an unprivileged user with a dedicated test account from a root-only env file, writes step outcomes to… (
7f602fa) - Drills run an acceptance subset (WS-S task 2): drill.acceptance lists GETs the restored instance alone must answer with a status and top-level JSON keys — for services whose answers differ from production by nature or that have nothing… (
561d731) - Restore drill: sources with its acceptance subset (2026-09-25), passed (
da53761) - Restore drills: the sources row in the drill table (
8829dab) - openvibe-toolsjob.timer (WS-L task 4): the Tools job proof every six hours as principal probe; devpath-metrics.sh takes METRIC_PREFIX; alerts OpenVibeToolsJobProofFailed/Missed (
0cadec3) - Protected probes (WS-P task 2): kind sum adds up parts (unknown when any part is, never read as zero; each part validated, no sum in a sum); the example inventory probes Chat sockets (/ready connections), Games players online (readiness… (
cb0cb55) - Shared-host outage test (WS-P task 5): scripts/shared-host-outage.js loads every public site with openvibe.network blocked and checks content, navigation and theme; the recorded production run passes 18/18 after the Games navigation fix (
7256966) - Lifecycle declarations in ovhost validate (WS-P task 1): lib/lifecycle.js reads each service's lifecycle from the inventory entry (it replaces the manifest's on this host), validate --manifest <file>, or the manifest in the installed… (
70fc2ea) - Pins: openvibe-contracts 0.49.0 → 0.55.0 (the lifecycle block ovhost validate reads) (
e1bcba6) - validate: a git checkout reached through <dir>/current -> <dir>/releases/<id> is a deployed release (Live), so its detached HEAD is not a branch error; tracked changes still are (
2190761) - Browser check (WS-Q task 3; WS-T tasks 3-4): scripts/browser-check.js runs openvibe-shared/browser-harness against every public product (the registry's public origins whose home answers HTML; known routes + one sitemap URL per section… (
2286531) - browser-check: wait for Chrome to exit and its profile to be removed before the report is written (browser-harness close() now resolves once the profile is gone) (
3165a90) - Pins: openvibe-shared 1.13.0 -> 1.16.0 (browser-check finds the harness in the install) (
3dea84e) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
aad998d) - Browser check runs 2026-09-26 after the follow-up deploys: 21/23 sites, then 23/23 after the Live home shell stopped loading ov-mark twice and Tools moved to openvibe-shared 1.16.1 (
dd0dd12) - Release notifications (roadmap WS-P task 9): ovhost publishes host.deploy.activated to OpenVibe.Events (
62fad64) - docs/release-notifications.md: before a site pins openvibe-shared 1.17.0, its CSP connect-src must allow https://events.openvibe.network (Live and Community do; Network, Wiki, Blog, Codes, Search, Reviews, VIP, Tips, Host, News, Deals and… (
d098cef) - Release notifications publish host.release.published, not host.deploy.activated (WS-P task 9) (
100c279) - Pins: openvibe-contracts 0.55.0 -> 0.58.0 (host.release.published@1 is validated), openvibe-shared 1.16.1 -> 1.17.0 (
3ad54fd) - Pins: openvibe-shared 1.17.0 -> 1.17.1 (release notifications) (
5d53eef)
OpenVibe.Live
- Pins: openvibe-shared 1.14.0 -> 1.16.0 (
834d9d4) - A guest's session check answers 200, not 401 (browser check, WS-Q task 3): POST /api/auth/refresh without an ov_refresh cookie answers { access_token: null, user: null }. Every guest page view asks it (public/js/app.js tryRefreshToken… (
73588d9) - Clip page: a missing source VOD is absent, not a 404 (browser check on /clip/369, WS-Q task 3). GET /api/clips/:id says vod_visible: false when the clip's VOD is gone (Media 404) or hidden from this viewer, which is exactly when GET… (
448f212) - CSP: connect-src allows https://cloudflareinsights.com, where Cloudflare Web Analytics' beacon reports (its script, static.cloudflareinsights.com, was already allowed in script-src and, by mistake, in connect-src). The beacon sends on page… (
22d388a) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
2514d14) - The OV mark comes from openvibe-shared (/shared/ov-mark.js, 1.16.1: it stops animating when idle, hidden or off-screen) on the home, kiosk, tos, privacy and dmca pages; Live's older copy (public/js/ov-mark.js), which kept the shared one… (
953e4b9) - Home shell: no own <script> for /shared/ov-mark.js; the shared navbar loads it (the browser check counted it twice on every route); kiosk, tos, privacy and dmca have no navbar and keep theirs (
00c9457) - Chat parity follow-ups on Live (WS-I task 6): bans end at expires_at read as a UTC instant (datetime()), not text, so a timeout given as ISO no longer lasts until midnight UTC on Live's other surfaces; the floating chat widget applies the… (
0df5662) - Chat parity gaps, Live's side (roadmap WS-I task 6): the subscriber read for sub-only chat, sub_only as a channel setting, the dashboard's slow mode actually saved, a dashboard delete reaching the whole channel room (
d4e849f) - Release notification after a deploy (roadmap WS-P task 9): deploy.sh runs
ovhost announce liveonce the release went live (5162b09) - Release notification: the event ovhost announce publishes is host.release.published (its own type in openvibe-contracts 0.58.0; host.deploy.activated stays tenant hosting's), in the deploy script's comment and the docs. Comments only (WS-P… (
cd67c66) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
f2b8508)
OpenVibe.Chat
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
15b266b) - A guest's session probe answers 200, not 401 (browser check, WS-Q task 3): GET /auth/me with no ov_token cookie and no Authorization header answers { user: null }, which the shared navbar reads as signed out. It asks on every page view… (
cf3807a) - Unknown pages answer an HTML 404 page to a browser (browser check, WS-Q task 3: openvibe.chat answered every unknown path with JSON). A GET or HEAD that asks for text/html, outside /api/, /internal/ and /ws/, gets the site's own page… (
f07cf8e) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
0fc8f2e) - Moderation found by the parity script (WS-I task 6): timeouts end on time, a ban holds from the moment the moderator is answered, the dashboard's range purge matches its range, and moderators are not slowed. (1) live-context.js read a… (
e26e063) - Cursor reads name what was deleted under the cursor (reconnect convergence, roadmap D22 and WS-I task 6): a reader that reconnects and reads ?after_id=<cursor> got only the newer rows, so a line deleted while it was away stayed on its… (
c832274) - Chat parity script (roadmap WS-I task 6): scripts/parity.js runs the chat product end to end over the real protocol with two or three people connected and checks what each sees, one scenario per item: join (anonymous and signed in, the… (
91a36f2) - Parity gaps closed (roadmap WS-I task 6): sub-only mode, blocks in public chat, slow mode as the saved setting, purges and deletes on every surface, /clear says what it does (
bcc53f4) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
df36e31)
OpenVibe.Blog
- Pins: openvibe-shared 1.15.0 -> 1.16.0 (
b512139) - The CSP allows Cloudflare Web Analytics (browser check, WS-Q task 3): script-src https://static.cloudflareinsights.com loads the beacon Cloudflare injects at the edge, connect-src https://cloudflareinsights.com is where it reports. The… (
8c6b686) - A guest's session probe answers 200, not 401 (browser check, WS-Q task 3): GET /auth/me with no session credential at all answers { user: null }, which the shared navbar reads as signed out. It asks on every page view, and the 401 logged a… (
897822f) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
be44292) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
86eb327)
OpenVibe.Codes
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
0d8ac03) - The CSP allows Cloudflare Web Analytics (browser check, WS-Q task 3): script-src https://static.cloudflareinsights.com loads the beacon Cloudflare injects at the edge, connect-src https://cloudflareinsights.com is where it reports. The… (
0cb7804) - A guest's session probe answers 200, not 401 (browser check, WS-Q task 3): GET /auth/me with no codes_at or codes_rt cookie (and no Authorization header) answers { user: null }, which the shared navbar reads as signed out. It asks on every… (
a2127a9) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
a89ab3b) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
900559b)
OpenVibe.Community
openvibe.community · repository
- Pins: openvibe-shared 1.15.0 -> 1.16.0 (
1bac6a9) - The CSP allows Cloudflare Web Analytics (browser check, WS-Q task 3): script-src https://static.cloudflareinsights.com loads the beacon Cloudflare injects at the edge, connect-src https://cloudflareinsights.com is where it reports. The… (
e2f7c1d) - A guest's session probe answers 200, not 401 (browser check, WS-Q task 3): GET /auth/me with no session credential at all answers { user: null }, which the shared navbar reads as signed out. It asks on every page view, and the 401 logged a… (
564c610) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
be15c21) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
9a468fb)
OpenVibe.Media
- Pins: openvibe-shared 1.15.0 -> 1.16.0 (
8c3c6fa) - Unknown paths answer Express's own 404 page under Media's CSP, which now allows Cloudflare Web Analytics (browser check, WS-Q task 3): server/not-found.js keeps default-src 'none' and adds script-src https://static.cloudflareinsights.com… (
b578bbb) - A guest's session probe answers 200, not 401 (browser check, WS-Q task 3): GET /auth/me with no session credential at all answers { user: null }, which the shared navbar reads as signed out. It asks on every page view, and the 401 logged a… (
7a0eaac) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
c110173) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
7d765ea)
OpenVibe.Wiki
- Pins: openvibe-shared 1.15.0 -> 1.16.0 (
679aba4) - The CSP allows Cloudflare Web Analytics (browser check, WS-Q task 3): script-src https://static.cloudflareinsights.com loads the beacon Cloudflare injects at the edge, connect-src https://cloudflareinsights.com is where it reports. The… (
46bac64) - A guest's session probe answers 200, not 401 (browser check, WS-Q task 3): GET /auth/me with no session credential at all answers { user: null }, which the shared navbar reads as signed out. It asks on every page view, and the 401 logged a… (
9409f51) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
40c54a0) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
7cd86c5)
OpenVibe.AI
ai.openvibe.network · repository
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
3fc0b18) - nginx: the commented template for exposing /api/ sets the client-IP headers from $remote_addr (X-Real-IP, X-Forwarded-For, CF-Connecting-IP), like every active location, instead of $proxy_add_x_forwarded_for, which passes a client-sent… (
f7be9bd) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
779a031) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
ce1f414)
OpenVibe.Events
events.openvibe.network · repository
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
39eba17) - nginx: the commented template for exposing /api/ sets the client-IP headers from $remote_addr (X-Real-IP, X-Forwarded-For, CF-Connecting-IP), like every active location, instead of $proxy_add_x_forwarded_for, which passes a client-sent… (
e6dd3c1) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
dfa5e12) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
5f1eafb)
OpenVibe.Network
- Pins: openvibe-shared 1.15.0 -> 1.16.0 (
d5805c9) - The CSP allows Cloudflare Web Analytics (browser check, WS-Q task 3): script-src https://static.cloudflareinsights.com loads the beacon Cloudflare injects at the edge, connect-src https://cloudflareinsights.com is where it reports. The… (
b764d94) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
5084cfe) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
2b3998c)
OpenVibe.Search
search.openvibe.network · repository
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
e90cb82) - The CSP allows Cloudflare Web Analytics (browser check, WS-Q task 3): script-src https://static.cloudflareinsights.com loads the beacon Cloudflare injects at the edge, connect-src https://cloudflareinsights.com is where it reports. The… (
f69ca74) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
91d2068) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
f58f819)
OpenVibe.Sources
sources.openvibe.network · repository
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
375cf8f) - The public landing page's CSP allows Cloudflare Web Analytics (browser check, WS-Q task 3): script-src https://static.cloudflareinsights.com loads the beacon Cloudflare injects at the edge, connect-src https://cloudflareinsights.com is… (
3abc2de) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
44c69cc) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
32c8c98)
OpenVibe.Tools
- Pins: openvibe-shared -> 1.16.1 in all eight apps (was 1.13.0, gateway 1.15.0): the /updates filter chip contrast fix and the OV mark that stops animating when idle (
ea03851) - Release notification after a deploy (roadmap WS-P task 9): deploy.sh runs
ovhost announce toolsonce the gateway is healthy (782ed60) - Release notification: the event ovhost announce publishes is host.release.published (its own type in openvibe-contracts 0.58.0; host.deploy.activated stays tenant hosting's), in the deploy script's comment and the README. Comments only… (
c25ba2b) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
4238494)
OpenVibe.Billing
billing.openvibe.network · repository
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
04c0ae8) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
8494483) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
5c1d552)
OpenVibe.Coupons
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
f366b24) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
899873c) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
1931942)
OpenVibe.Deals
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
ff39f56) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
16823d5) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
73221d8)
OpenVibe.News
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
9460c86) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
48a339d) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
9202f90)
OpenRe.Stream
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
8f4b3cb) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
8686bec) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
e1b2799)
OpenVibe.Reviews
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
ad96e46) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
cbf43f5) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
6a57a20)
OpenVibe.Tips
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
403b0af) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
7df65f4) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
4c8d635)
OpenVibe.Trade
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
c82abfa) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
f798f44) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
6d81aa8)
OpenVibe.VIP
- Pins: openvibe-shared 1.13.0 -> 1.16.0 (
194153f) - Pins: openvibe-shared 1.16.0 -> 1.16.1 (the OV mark stops animating when idle, hidden or off-screen) (
3695c03) - Pins: openvibe-shared 1.16.1 -> 1.17.1 (release notifications) (
f2a386e)
OpenVibe.Games
- The server's 404 page names the client's icon (<link rel="icon" type="image/svg+xml" href="/favicon.svg">, as the client pages do since 0f29769). Without it the browser asked for /favicon.ico, a second 404 and a console error on every… (
74d039d)
Patch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.
Comments
Comments could not be loaded from OpenVibe.Community right now. Reload later.