Patch notes: Namespaces and grants
Imported. Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers.
What shipped on OpenVibe on 2026-09-26: 91 changes to OpenVibe.Host, OpenVibe.Media, OpenVibe.Network, OpenVibe.Codes, OpenVibe.Live, OpenVibe.Community and 17 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.
Highlights
- OpenVibe.Media: Namespaces and grants (roadmap WS-G task 2): every namespace is a media_namespaces row (tenant, owner, policy, quota_bytes/quota_objects, used/reserved snapshot). A tenant's root is its app id, or app.<project_id> /… (
09f3e0d) - OpenVibe.Media: Object explorer (roadmap WS-G task 12): openvibe.media/me shows a signed-in person the objects whose owner_subject is their Network subject, in every tenant, and /me/ops gives Network staff the operator views (
15b8f93) - OpenVibe.Community: Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com"; any control character or backslash in next now goes home. test/open-redirect.test.js feeds it the known bypasses (
1eff653) - OpenVibe.AI: Operator console (roadmap WS-O task 4): /console on ai.openvibe.network, server-rendered with no JavaScript, for OpenVibe.Network staff. Providers (secret reference names and whether they resolve, never a value; base URLs without query or… (
86e1246)
OpenVibe.Host
- Limits page source (roadmap WS-N task 7): GET /limits.json on the dashboard host lists the default project limits (projects per owner, sites, custom domains, deploys a day, storage, files and file size) for sandbox and production, read… (
d1fc66d) - Browser check after the release-notification rollout: 23/23 sites pass (every CSP allows the Events realtime stream) (
f619c3b) - Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
d8a5546) - ovhost archive (roadmap WS-S task 6, hazard H14): dead and backup database files encrypted with the backup key and copied to <prefix>-archive/<host>/<stamp>/ (outside the backup runs, so retention never prunes them), each upload checked by… (
6e5e499) - Register: /internal/user-role removed (C-54, C-55; Network 60455b3, Live 3a99cdc, WS-B task 2). db-inventory: the 14 legacy databases archived off-host as 20260926-094703, a restore checked byte-identical (
c940582) - Deploy proofs (roadmap WS-P task 3): the Live web-drain run, recorded. The first run found four 502s (the release socket unit had dropped its descriptor and Live bound 0.0.0.0:3000 itself); after the repair (Live ab8abff) 57/57 requests… (
f62af29) - Host firewall proposal: the host firewall is off, so any 0.0.0.0 bind is public (how Live's :3000 was exposed 2026-09-25/26); the intended public listeners and a default-deny ufw allow list, left for the owner (SSH lock-out and WebRTC/TURN… (
27f86d0) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
c42a6f0) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
326a91e)
OpenVibe.Media
- Namespaces and grants (roadmap WS-G task 2): every namespace is a media_namespaces row (tenant, owner, policy, quota_bytes/quota_objects, used/reserved snapshot). A tenant's root is its app id, or app.<project_id> /… (
09f3e0d) - Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
b353594) - Limits page source (roadmap WS-N task 7): GET /limits.json lists the developer limits enforced here (tenant storage per environment, child namespaces, single-part, multipart and part sizes, public playback size, how long an unfinished… (
0fc4452) - Object explorer (roadmap WS-G task 12): openvibe.media/me shows a signed-in person the objects whose owner_subject is their Network subject, in every tenant, and /me/ops gives Network staff the operator views (
15b8f93) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
a11fe37) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
f356d72) - Pages define the default theme's tokens (ADR-024, WS-E task 1): the network-down browser run found --accent undefined on Media with openvibe.network unreachable (Media's styles fell back, shared components did not); baseCss now carries… (
2be314b) - The index page carries the default theme tokens too (ADR-024): browse.js writes its own <style>, which now starts with openvibe-shared's DEFAULT_VARS (exported from page-frame as DEFAULT_THEME_CSS) (
25ee318)
OpenVibe.Network
- Media namespaces and grants, Network's side (roadmap WS-G task 2): an app token's ns is [project_id, app.<project_id>.*], so the grant names the project's Media namespaces (app.<project_id> production, app.<project_id>.sandbox, and… (
d057b43) - Pins: openvibe-contracts 0.56.0 -> 0.59.0 (media.object.list and media.object.delete now in the default sandbox allowance), openvibe-shared 1.17.1 -> 1.18.0 (update telemetry) (
2472353) - Release health on /status (roadmap WS-P task 15): the ecosystem poll reads release_client_sessions and release_client_updates_total from the /metrics of services whose /release.json names a metrics_url (loopback), and /status and… (
10404c4) - Retire the key-only role push to Live (roadmap WS-B task 2 step 5; register C-55, Live's route C-54): an admin role change no longer POSTs Live's /internal/user-role with the internal key (
60455b3) - Tools' Media grants cover tools.* (roadmap WS-L task 5): a developer project's job results go to tools.app.<project_id>[.sandbox]; the default grant rows still as first seeded (['tools']) move to ['tools', 'tools.*'] at boot (
416aed7) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
4a509b9) - Sandbox apps may manage their own Codes releases (roadmap WS-N task 5): codes.release.manage joins the default sandbox allowance and openvibe.codes the audiences that accept sandbox app tokens (Codes keeps sandbox releases marked as such)… (
f9384c6) - OAuth client ai gets its redirect URI (roadmap WS-O task 4): https://ai.openvibe.network/auth/callback for OpenVibe.AI's operator console (merged into the existing client's list at boot, as for every contract client) (
f5a71a2)
OpenVibe.Codes
- Limits and tiers page (roadmap WS-N task 7): /docs/limits states the policy (sandbox and production, enforced at the capability by its owner, 429/413 problems with retry hints, trust tiers never change the grant check, overrides are per… (
2985c64) - Limits page: Host's section says it is read from Host's /limits.json instead of linking openvibe.host/limits.json, which the Sites placeholder answers 404 until Host Stage B serves openvibe.host (
8afc669) - Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
3e11696) - Limits page: Media's /limits.json joins Host's and Events' (namespaces and quotas, WS-G task 2); an hours unit (
bdd79c5) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
c090e28) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
341a18f)
OpenVibe.Live
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
af82630) - Live users -> subject projection, the rest (roadmap WS-B task 2 steps 2, 4 prep and 5): Live no longer reads users.email or users.password_hash, POST /internal/user-role is retired, and the contract step is an operator script (
3a99cdc) - Pins: openvibe-shared 1.18.0 -> 1.19.0 (the update matrix: ov:content-dispose before a region is replaced) (
53c9abd) - Socket activation that stays in effect, on loopback: the release layout's socket unit still listened on 0.0.0.0:3000 with NonBlocking= in [Socket] (ignored by systemd); installing it on 2026-09-25 dropped the socket's descriptor, so the… (
ab8abff) - Pins: openvibe-shared 1.19.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
d1fcb69) - Open redirect fixed (roadmap WS-R task 5): Live's sign-in next let "/<TAB>/evil.com" and "/\evil.com" through (browsers read both as "//evil.com") and trusted openvibe.<any tld>, which anyone can register. safeNext moves to… (
c4e1761)
OpenVibe.Community
openvibe.community · repository
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
6a855de) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
d511da5) - Discord relay both ways, as an Events worker, with an external message map (roadmap WS-J tasks 5 and 6): replies follow new threads to Discord, edits PATCH and deletes (or gating a thread members-only) DELETE the Discord messages through… (
f94d83a) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com"; any control character or backslash in next now goes home. test/open-redirect.test.js feeds it the known bypasses (
1eff653)
OpenVibe.Reviews
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
01d7341) - Static assets are immutable only when ?v= is the served file's hash (roadmap WS-P task 10): any ?v= used to be cached for a year, so after a deploy or a rollback an older page's URL could pin the wrong bytes; other ?v= values and plain… (
217e003) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
9b620b1) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
4840286)
OpenVibe.Wiki
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
1747009) - Static assets are immutable only when ?v= is the served file's hash (roadmap WS-P task 10): any ?v= used to be cached for a year, so after a deploy or a rollback an older page's URL could pin the wrong bytes; other ?v= values and plain… (
255de21) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
123bd4f) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
e0337a6)
OpenVibe.AI
ai.openvibe.network · repository
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
1452cd7) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
baedda1) - Operator console (roadmap WS-O task 4): /console on ai.openvibe.network, server-rendered with no JavaScript, for OpenVibe.Network staff. Providers (secret reference names and whether they resolve, never a value; base URLs without query or… (
86e1246)
OpenVibe.Billing
billing.openvibe.network · repository
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
876b010) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
3d858ee) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
92edcae)
OpenVibe.Blog
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
24705e9) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
236bdba) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
047c956)
OpenVibe.Chat
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
252ac09) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
9b7da46) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
3cdd1dd)
OpenVibe.Coupons
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
0e2c7c6) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
ae8beca) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
39a20ed)
OpenVibe.Deals
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
6b30998) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
b266be3) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
b5867df)
OpenVibe.Events
events.openvibe.network · repository
- Limits page source (roadmap WS-N task 7): GET /limits.json lists the developer limits enforced here per project and environment (publish rate, bytes kept, retention, webhook subscriptions, payload and batch size, realtime topics), read… (
5889c2c) - Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
390f1cd) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
a38de79)
OpenVibe.News
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
57c5ab3) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
90fbbad) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
36b91d3)
OpenVibe.Tips
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
d328728) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
3c9237f) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
7c0d2f8)
OpenVibe.Tools
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
7487547) - Sandbox and developer-app results to Media under the project's namespace (roadmap WS-L task 5): a job submitted by a developer app remembers its project (tool_jobs.project_id), and its result files go to Media under tools.app.<project_id>… (
04a5876) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
1907390)
OpenVibe.Trade
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
101445e) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
e8fee67) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
e427ca0)
OpenVibe.VIP
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
3f0380c) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
7bd0676) - Open redirect fixed (roadmap WS-R task 5): the sign-in next let "/<TAB>/evil.com" through, which browsers read as "//evil.com" (they drop tab and newline characters and read a backslash as "/"); any control character or backslash in next… (
2629597)
OpenRe.Stream
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
0c16746) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
9cf13a8)
OpenVibe.Search
search.openvibe.network · repository
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
74755cb) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
18e7c29)
OpenVibe.Sources
sources.openvibe.network · repository
- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) (
bb8e68f) - Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) (
d423030)
Patch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.
Comments
Comments could not be loaded from OpenVibe.Community right now. Reload later.