Patch notes: Namespaces and grants

Imported. Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers.

What shipped on OpenVibe on 2026-09-26: 91 changes to OpenVibe.Host, OpenVibe.Media, OpenVibe.Network, OpenVibe.Codes, OpenVibe.Live, OpenVibe.Community and 17 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.

Highlights

  • OpenVibe.Media: Namespaces and grants (roadmap WS-G task 2): every namespace is a media_namespaces row (tenant, owner, policy, quota_bytes/quota_objects, used/reserved snapshot). A tenant's root is its app id, or app.<project_id> /… (09f3e0d)
  • OpenVibe.Media: Object explorer (roadmap WS-G task 12): openvibe.media/me shows a signed-in person the objects whose owner_subject is their Network subject, in every tenant, and /me/ops gives Network staff the operator views (15b8f93)
  • OpenVibe.Community: Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com"; any control character or backslash in next now goes home. test/open-redirect.test.js feeds it the known bypasses (1eff653)
  • OpenVibe.AI: Operator console (roadmap WS-O task 4): /console on ai.openvibe.network, server-rendered with no JavaScript, for OpenVibe.Network staff. Providers (secret reference names and whether they resolve, never a value; base URLs without query or… (86e1246)

OpenVibe.Host

openvibe.host · repository

  • Limits page source (roadmap WS-N task 7): GET /limits.json on the dashboard host lists the default project limits (projects per owner, sites, custom domains, deploys a day, storage, files and file size) for sandbox and production, read… (d1fc66d)
  • Browser check after the release-notification rollout: 23/23 sites pass (every CSP allows the Events realtime stream) (f619c3b)
  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (d8a5546)
  • ovhost archive (roadmap WS-S task 6, hazard H14): dead and backup database files encrypted with the backup key and copied to <prefix>-archive/<host>/<stamp>/ (outside the backup runs, so retention never prunes them), each upload checked by… (6e5e499)
  • Register: /internal/user-role removed (C-54, C-55; Network 60455b3, Live 3a99cdc, WS-B task 2). db-inventory: the 14 legacy databases archived off-host as 20260926-094703, a restore checked byte-identical (c940582)
  • Deploy proofs (roadmap WS-P task 3): the Live web-drain run, recorded. The first run found four 502s (the release socket unit had dropped its descriptor and Live bound 0.0.0.0:3000 itself); after the repair (Live ab8abff) 57/57 requests… (f62af29)
  • Host firewall proposal: the host firewall is off, so any 0.0.0.0 bind is public (how Live's :3000 was exposed 2026-09-25/26); the intended public listeners and a default-deny ufw allow list, left for the owner (SSH lock-out and WebRTC/TURN… (27f86d0)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (c42a6f0)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (326a91e)

OpenVibe.Media

openvibe.media · repository

  • Namespaces and grants (roadmap WS-G task 2): every namespace is a media_namespaces row (tenant, owner, policy, quota_bytes/quota_objects, used/reserved snapshot). A tenant's root is its app id, or app.<project_id> /… (09f3e0d)
  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (b353594)
  • Limits page source (roadmap WS-N task 7): GET /limits.json lists the developer limits enforced here (tenant storage per environment, child namespaces, single-part, multipart and part sizes, public playback size, how long an unfinished… (0fc4452)
  • Object explorer (roadmap WS-G task 12): openvibe.media/me shows a signed-in person the objects whose owner_subject is their Network subject, in every tenant, and /me/ops gives Network staff the operator views (15b8f93)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (a11fe37)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (f356d72)
  • Pages define the default theme's tokens (ADR-024, WS-E task 1): the network-down browser run found --accent undefined on Media with openvibe.network unreachable (Media's styles fell back, shared components did not); baseCss now carries… (2be314b)
  • The index page carries the default theme tokens too (ADR-024): browse.js writes its own <style>, which now starts with openvibe-shared's DEFAULT_VARS (exported from page-frame as DEFAULT_THEME_CSS) (25ee318)

OpenVibe.Network

openvibe.network · repository

  • Media namespaces and grants, Network's side (roadmap WS-G task 2): an app token's ns is [project_id, app.<project_id>.*], so the grant names the project's Media namespaces (app.<project_id> production, app.<project_id>.sandbox, and… (d057b43)
  • Pins: openvibe-contracts 0.56.0 -> 0.59.0 (media.object.list and media.object.delete now in the default sandbox allowance), openvibe-shared 1.17.1 -> 1.18.0 (update telemetry) (2472353)
  • Release health on /status (roadmap WS-P task 15): the ecosystem poll reads release_client_sessions and release_client_updates_total from the /metrics of services whose /release.json names a metrics_url (loopback), and /status and… (10404c4)
  • Retire the key-only role push to Live (roadmap WS-B task 2 step 5; register C-55, Live's route C-54): an admin role change no longer POSTs Live's /internal/user-role with the internal key (60455b3)
  • Tools' Media grants cover tools.* (roadmap WS-L task 5): a developer project's job results go to tools.app.<project_id>[.sandbox]; the default grant rows still as first seeded (['tools']) move to ['tools', 'tools.*'] at boot (416aed7)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (4a509b9)
  • Sandbox apps may manage their own Codes releases (roadmap WS-N task 5): codes.release.manage joins the default sandbox allowance and openvibe.codes the audiences that accept sandbox app tokens (Codes keeps sandbox releases marked as such)… (f9384c6)
  • OAuth client ai gets its redirect URI (roadmap WS-O task 4): https://ai.openvibe.network/auth/callback for OpenVibe.AI's operator console (merged into the existing client's list at boot, as for every contract client) (f5a71a2)

OpenVibe.Codes

openvibe.codes · repository

  • Limits and tiers page (roadmap WS-N task 7): /docs/limits states the policy (sandbox and production, enforced at the capability by its owner, 429/413 problems with retry hints, trust tiers never change the grant check, overrides are per… (2985c64)
  • Limits page: Host's section says it is read from Host's /limits.json instead of linking openvibe.host/limits.json, which the Sites placeholder answers 404 until Host Stage B serves openvibe.host (8afc669)
  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (3e11696)
  • Limits page: Media's /limits.json joins Host's and Events' (namespaces and quotas, WS-G task 2); an hours unit (bdd79c5)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (c090e28)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (341a18f)

OpenVibe.Live

openvibe.live · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (af82630)
  • Live users -> subject projection, the rest (roadmap WS-B task 2 steps 2, 4 prep and 5): Live no longer reads users.email or users.password_hash, POST /internal/user-role is retired, and the contract step is an operator script (3a99cdc)
  • Pins: openvibe-shared 1.18.0 -> 1.19.0 (the update matrix: ov:content-dispose before a region is replaced) (53c9abd)
  • Socket activation that stays in effect, on loopback: the release layout's socket unit still listened on 0.0.0.0:3000 with NonBlocking= in [Socket] (ignored by systemd); installing it on 2026-09-25 dropped the socket's descriptor, so the… (ab8abff)
  • Pins: openvibe-shared 1.19.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (d1fcb69)
  • Open redirect fixed (roadmap WS-R task 5): Live's sign-in next let "/<TAB>/evil.com" and "/\evil.com" through (browsers read both as "//evil.com") and trusted openvibe.<any tld>, which anyone can register. safeNext moves to… (c4e1761)

OpenVibe.Community

openvibe.community · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (6a855de)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (d511da5)
  • Discord relay both ways, as an Events worker, with an external message map (roadmap WS-J tasks 5 and 6): replies follow new threads to Discord, edits PATCH and deletes (or gating a thread members-only) DELETE the Discord messages through… (f94d83a)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com"; any control character or backslash in next now goes home. test/open-redirect.test.js feeds it the known bypasses (1eff653)

OpenVibe.Reviews

openvibe.reviews · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (01d7341)
  • Static assets are immutable only when ?v= is the served file's hash (roadmap WS-P task 10): any ?v= used to be cached for a year, so after a deploy or a rollback an older page's URL could pin the wrong bytes; other ?v= values and plain… (217e003)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (9b620b1)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (4840286)

OpenVibe.Wiki

openvibe.wiki · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (1747009)
  • Static assets are immutable only when ?v= is the served file's hash (roadmap WS-P task 10): any ?v= used to be cached for a year, so after a deploy or a rollback an older page's URL could pin the wrong bytes; other ?v= values and plain… (255de21)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (123bd4f)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (e0337a6)

OpenVibe.AI

ai.openvibe.network · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (1452cd7)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (baedda1)
  • Operator console (roadmap WS-O task 4): /console on ai.openvibe.network, server-rendered with no JavaScript, for OpenVibe.Network staff. Providers (secret reference names and whether they resolve, never a value; base URLs without query or… (86e1246)

OpenVibe.Billing

billing.openvibe.network · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (876b010)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (3d858ee)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (92edcae)

OpenVibe.Blog

openvibe.blog · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (24705e9)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (236bdba)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (047c956)

OpenVibe.Chat

openvibe.chat · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (252ac09)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (9b7da46)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (3cdd1dd)

OpenVibe.Coupons

openvibe.coupons · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (0e2c7c6)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (ae8beca)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (39a20ed)

OpenVibe.Deals

openvibe.deals · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (6b30998)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (b266be3)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (b5867df)

OpenVibe.Events

events.openvibe.network · repository

  • Limits page source (roadmap WS-N task 7): GET /limits.json lists the developer limits enforced here per project and environment (publish rate, bytes kept, retention, webhook subscriptions, payload and batch size, realtime topics), read… (5889c2c)
  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (390f1cd)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (a38de79)

OpenVibe.News

openvibe.news · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (57c5ab3)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (90fbbad)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (36b91d3)

OpenVibe.Tips

openvibe.tips · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (d328728)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (3c9237f)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (7c0d2f8)

OpenVibe.Tools

openvibe.tools · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (7487547)
  • Sandbox and developer-app results to Media under the project's namespace (roadmap WS-L task 5): a job submitted by a developer app remembers its project (tool_jobs.project_id), and its result files go to Media under tools.app.<project_id>… (04a5876)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (1907390)

OpenVibe.Trade

openvibe.trade · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (101445e)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (e8fee67)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (e427ca0)

OpenVibe.VIP

openvibe.vip · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (3f0380c)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (7bd0676)
  • Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (2629597)

OpenRe.Stream

openre.stream · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (0c16746)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (9cf13a8)

OpenVibe.Search

search.openvibe.network · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (74755cb)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (18e7c29)

OpenVibe.Sources

sources.openvibe.network · repository

  • Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (bb8e68f)
  • Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (d423030)

Patch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.

Comments

Comments could not be loaded from OpenVibe.Community right now. Reload later.