{"id":"pst_01M3EQPWJ1Z466EC9BBD5ZBFMX","url":"https://openvibe.blog/@openvibe/patch-notes-namespaces-and-grants","blog":{"id":"blg_01M362MF0EDJ7QHQTRD8A3Q981","handle":"openvibe","title":"The OpenVibe blog","url":"https://openvibe.blog/"},"title":"Patch notes: Namespaces and grants","summary":"What shipped on OpenVibe on 2026-09-26: 91 changes to OpenVibe.Host, OpenVibe.Media, OpenVibe.Network, OpenVibe.Codes, OpenVibe.Live, OpenVibe.Community and 17 more.","body_markdown":"What shipped on OpenVibe on 2026-09-26: 91 changes to OpenVibe.Host, OpenVibe.Media, OpenVibe.Network, OpenVibe.Codes, OpenVibe.Live, OpenVibe.Community and 17 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.\n\n## Highlights\n\n- **OpenVibe.Media:** Namespaces and grants (roadmap WS-G task 2): every namespace is a media_namespaces row (tenant, owner, policy, quota_bytes/quota_objects, used/reserved snapshot). A tenant's root is its app id, or app.<project_id> /… ([`09f3e0d`](https://github.com/OpenVibers/OpenVibe.Media/commit/09f3e0daea1bd74e40218f0ca6f7ae63b4cfddc3))\n- **OpenVibe.Media:** Object explorer (roadmap WS-G task 12): openvibe.media/me shows a signed-in person the objects whose owner_subject is their Network subject, in every tenant, and /me/ops gives Network staff the operator views ([`15b8f93`](https://github.com/OpenVibers/OpenVibe.Media/commit/15b8f93ea7791e202c6f43ef2a4387324a6b29db))\n- **OpenVibe.Community:** Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\"; any control character or backslash in next now goes home. test/open-redirect.test.js feeds it the known bypasses ([`1eff653`](https://github.com/OpenVibers/OpenVibe.Community/commit/1eff6537c1aa8c4ad681bd4b4c0e0ea1edf8423f))\n- **OpenVibe.AI:** Operator console (roadmap WS-O task 4): /console on ai.openvibe.network, server-rendered with no JavaScript, for OpenVibe.Network staff. Providers (secret reference names and whether they resolve, never a value; base URLs without query or… ([`86e1246`](https://github.com/OpenVibers/OpenVibe.AI/commit/86e1246a750c94242b114de5cba2ee0e9fdd6057))\n\n## OpenVibe.Host\n\n[openvibe.host](https://openvibe.host) · [repository](https://github.com/OpenVibers/OpenVibe.Host)\n\n- Limits page source (roadmap WS-N task 7): GET /limits.json on the dashboard host lists the default project limits (projects per owner, sites, custom domains, deploys a day, storage, files and file size) for sandbox and production, read… ([`d1fc66d`](https://github.com/OpenVibers/OpenVibe.Host/commit/d1fc66db78c8e071157ac5c58e9d18d2f51308d1))\n- Browser check after the release-notification rollout: 23/23 sites pass (every CSP allows the Events realtime stream) ([`f619c3b`](https://github.com/OpenVibers/OpenVibe.Host/commit/f619c3b4fc2a0521c9c68964432227db85c2a51d))\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`d8a5546`](https://github.com/OpenVibers/OpenVibe.Host/commit/d8a55468bbfd9325034d8e96a7f1d6fe79edc4a3))\n- ovhost archive (roadmap WS-S task 6, hazard H14): dead and backup database files encrypted with the backup key and copied to <prefix>-archive/<host>/<stamp>/ (outside the backup runs, so retention never prunes them), each upload checked by… ([`6e5e499`](https://github.com/OpenVibers/OpenVibe.Host/commit/6e5e4999cde32dceb731af8cc193e189fe1899e2))\n- Register: /internal/user-role removed (C-54, C-55; Network 60455b3, Live 3a99cdc, WS-B task 2). db-inventory: the 14 legacy databases archived off-host as 20260926-094703, a restore checked byte-identical ([`c940582`](https://github.com/OpenVibers/OpenVibe.Host/commit/c9405829b83be769327a8574470a17e14614b1c7))\n- Deploy proofs (roadmap WS-P task 3): the Live web-drain run, recorded. The first run found four 502s (the release socket unit had dropped its descriptor and Live bound 0.0.0.0:3000 itself); after the repair (Live ab8abff) 57/57 requests… ([`f62af29`](https://github.com/OpenVibers/OpenVibe.Host/commit/f62af2934692950142bcbe539873857c2c258253))\n- Host firewall proposal: the host firewall is off, so any 0.0.0.0 bind is public (how Live's :3000 was exposed 2026-09-25/26); the intended public listeners and a default-deny ufw allow list, left for the owner (SSH lock-out and WebRTC/TURN… ([`27f86d0`](https://github.com/OpenVibers/OpenVibe.Host/commit/27f86d078b03f101a6f07cb76ac40c9f859b57e0))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`c42a6f0`](https://github.com/OpenVibers/OpenVibe.Host/commit/c42a6f0db170b40f51d536010afb574e53e94d64))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`326a91e`](https://github.com/OpenVibers/OpenVibe.Host/commit/326a91efeb8957c962358ff2572a35418b019d76))\n\n## OpenVibe.Media\n\n[openvibe.media](https://openvibe.media) · [repository](https://github.com/OpenVibers/OpenVibe.Media)\n\n- Namespaces and grants (roadmap WS-G task 2): every namespace is a media_namespaces row (tenant, owner, policy, quota_bytes/quota_objects, used/reserved snapshot). A tenant's root is its app id, or app.<project_id> /… ([`09f3e0d`](https://github.com/OpenVibers/OpenVibe.Media/commit/09f3e0daea1bd74e40218f0ca6f7ae63b4cfddc3))\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`b353594`](https://github.com/OpenVibers/OpenVibe.Media/commit/b3535947c30e817fc8ed5bb848cb6e156bb37073))\n- Limits page source (roadmap WS-N task 7): GET /limits.json lists the developer limits enforced here (tenant storage per environment, child namespaces, single-part, multipart and part sizes, public playback size, how long an unfinished… ([`0fc4452`](https://github.com/OpenVibers/OpenVibe.Media/commit/0fc4452e97947cbe61f514325600fc1e661a8ad9))\n- Object explorer (roadmap WS-G task 12): openvibe.media/me shows a signed-in person the objects whose owner_subject is their Network subject, in every tenant, and /me/ops gives Network staff the operator views ([`15b8f93`](https://github.com/OpenVibers/OpenVibe.Media/commit/15b8f93ea7791e202c6f43ef2a4387324a6b29db))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`a11fe37`](https://github.com/OpenVibers/OpenVibe.Media/commit/a11fe37975047cb0846bccec492ba5c43c91ff72))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`f356d72`](https://github.com/OpenVibers/OpenVibe.Media/commit/f356d7253b6ab4adba8395715f121b91130dc15e))\n- Pages define the default theme's tokens (ADR-024, WS-E task 1): the network-down browser run found --accent undefined on Media with openvibe.network unreachable (Media's styles fell back, shared components did not); baseCss now carries… ([`2be314b`](https://github.com/OpenVibers/OpenVibe.Media/commit/2be314bc29a76b1f97d555ba11718d3978036944))\n- The index page carries the default theme tokens too (ADR-024): browse.js writes its own <style>, which now starts with openvibe-shared's DEFAULT_VARS (exported from page-frame as DEFAULT_THEME_CSS) ([`25ee318`](https://github.com/OpenVibers/OpenVibe.Media/commit/25ee3187d53f8aec6d47a84c909dabb7f10ab159))\n\n## OpenVibe.Network\n\n[openvibe.network](https://openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Network)\n\n- Media namespaces and grants, Network's side (roadmap WS-G task 2): an app token's ns is [project_id, app.<project_id>.*], so the grant names the project's Media namespaces (app.<project_id> production, app.<project_id>.sandbox, and… ([`d057b43`](https://github.com/OpenVibers/OpenVibe.Network/commit/d057b43fde96f0f1d3b025d1e16db3e1816fcd1a))\n- Pins: openvibe-contracts 0.56.0 -> 0.59.0 (media.object.list and media.object.delete now in the default sandbox allowance), openvibe-shared 1.17.1 -> 1.18.0 (update telemetry) ([`2472353`](https://github.com/OpenVibers/OpenVibe.Network/commit/2472353fa90fbe7f41f13396ac87787faab67f36))\n- Release health on /status (roadmap WS-P task 15): the ecosystem poll reads release_client_sessions and release_client_updates_total from the /metrics of services whose /release.json names a metrics_url (loopback), and /status and… ([`10404c4`](https://github.com/OpenVibers/OpenVibe.Network/commit/10404c4f3ad7320529c682822c738724b9f01c2c))\n- Retire the key-only role push to Live (roadmap WS-B task 2 step 5; register C-55, Live's route C-54): an admin role change no longer POSTs Live's /internal/user-role with the internal key ([`60455b3`](https://github.com/OpenVibers/OpenVibe.Network/commit/60455b3490205d7b790306e55f78b374f9ce16c6))\n- Tools' Media grants cover tools.* (roadmap WS-L task 5): a developer project's job results go to tools.app.<project_id>[.sandbox]; the default grant rows still as first seeded (['tools']) move to ['tools', 'tools.*'] at boot ([`416aed7`](https://github.com/OpenVibers/OpenVibe.Network/commit/416aed7077a13aec287480fed556303a85b9e301))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`4a509b9`](https://github.com/OpenVibers/OpenVibe.Network/commit/4a509b98525b637e646c140d8e82540d3b11ef66))\n- Sandbox apps may manage their own Codes releases (roadmap WS-N task 5): codes.release.manage joins the default sandbox allowance and openvibe.codes the audiences that accept sandbox app tokens (Codes keeps sandbox releases marked as such)… ([`f9384c6`](https://github.com/OpenVibers/OpenVibe.Network/commit/f9384c6bab6b737f8d755d93dcd42beb7920e684))\n- OAuth client ai gets its redirect URI (roadmap WS-O task 4): https://ai.openvibe.network/auth/callback for OpenVibe.AI's operator console (merged into the existing client's list at boot, as for every contract client) ([`f5a71a2`](https://github.com/OpenVibers/OpenVibe.Network/commit/f5a71a23b954f67725aa373914030026f1f25fd0))\n\n## OpenVibe.Codes\n\n[openvibe.codes](https://openvibe.codes) · [repository](https://github.com/OpenVibers/OpenVibe.Codes)\n\n- Limits and tiers page (roadmap WS-N task 7): /docs/limits states the policy (sandbox and production, enforced at the capability by its owner, 429/413 problems with retry hints, trust tiers never change the grant check, overrides are per… ([`2985c64`](https://github.com/OpenVibers/OpenVibe.Codes/commit/2985c649e9ba8cb3ff67e2a14a5f2fb5205699f2))\n- Limits page: Host's section says it is read from Host's /limits.json instead of linking openvibe.host/limits.json, which the Sites placeholder answers 404 until Host Stage B serves openvibe.host ([`8afc669`](https://github.com/OpenVibers/OpenVibe.Codes/commit/8afc669a977b8ac5ef859e7330025425617f1b29))\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`3e11696`](https://github.com/OpenVibers/OpenVibe.Codes/commit/3e11696903bafd28f9e66f4ef1a055ee52b439f5))\n- Limits page: Media's /limits.json joins Host's and Events' (namespaces and quotas, WS-G task 2); an hours unit ([`bdd79c5`](https://github.com/OpenVibers/OpenVibe.Codes/commit/bdd79c5ec670898e966d80d4eea9401264c6d554))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`c090e28`](https://github.com/OpenVibers/OpenVibe.Codes/commit/c090e289e72325ec56ed14fa37a8b5836d0da760))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`341a18f`](https://github.com/OpenVibers/OpenVibe.Codes/commit/341a18f4b67d69a5eab360abde8684ff710d6d3e))\n\n## OpenVibe.Live\n\n[openvibe.live](https://openvibe.live) · [repository](https://github.com/OpenVibers/OpenVibe.Live)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`af82630`](https://github.com/OpenVibers/OpenVibe.Live/commit/af826304f4fd4f4c919014a4184dc8e82b1dd1ab))\n- Live users -> subject projection, the rest (roadmap WS-B task 2 steps 2, 4 prep and 5): Live no longer reads users.email or users.password_hash, POST /internal/user-role is retired, and the contract step is an operator script ([`3a99cdc`](https://github.com/OpenVibers/OpenVibe.Live/commit/3a99cdc30830a82cc3c855844cf7af8f0d0af922))\n- Pins: openvibe-shared 1.18.0 -> 1.19.0 (the update matrix: ov:content-dispose before a region is replaced) ([`53c9abd`](https://github.com/OpenVibers/OpenVibe.Live/commit/53c9abd7bdfbe59b54fef2d789cbc94bde348ed2))\n- Socket activation that stays in effect, on loopback: the release layout's socket unit still listened on 0.0.0.0:3000 with NonBlocking= in [Socket] (ignored by systemd); installing it on 2026-09-25 dropped the socket's descriptor, so the… ([`ab8abff`](https://github.com/OpenVibers/OpenVibe.Live/commit/ab8abff6dc118c46650372f82e8eab85e4f37f8b))\n- Pins: openvibe-shared 1.19.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`d1fcb69`](https://github.com/OpenVibers/OpenVibe.Live/commit/d1fcb6921dc06a54b33163db030170cad88daee1))\n- Open redirect fixed (roadmap WS-R task 5): Live's sign-in next let \"/<TAB>/evil.com\" and \"/\\evil.com\" through (browsers read both as \"//evil.com\") and trusted openvibe.<any tld>, which anyone can register. safeNext moves to… ([`c4e1761`](https://github.com/OpenVibers/OpenVibe.Live/commit/c4e1761752727c1cc88d49cd18a489ea0f0ee0ef))\n\n## OpenVibe.Community\n\n[openvibe.community](https://openvibe.community) · [repository](https://github.com/OpenVibers/OpenVibe.Community)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`6a855de`](https://github.com/OpenVibers/OpenVibe.Community/commit/6a855deeacbf3d324f08c69d04a16f8fe741669b))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`d511da5`](https://github.com/OpenVibers/OpenVibe.Community/commit/d511da544d71ebab9c70689b88701ece247d92ab))\n- Discord relay both ways, as an Events worker, with an external message map (roadmap WS-J tasks 5 and 6): replies follow new threads to Discord, edits PATCH and deletes (or gating a thread members-only) DELETE the Discord messages through… ([`f94d83a`](https://github.com/OpenVibers/OpenVibe.Community/commit/f94d83a2250a18f753597b948714cf982351acb0))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\"; any control character or backslash in next now goes home. test/open-redirect.test.js feeds it the known bypasses ([`1eff653`](https://github.com/OpenVibers/OpenVibe.Community/commit/1eff6537c1aa8c4ad681bd4b4c0e0ea1edf8423f))\n\n## OpenVibe.Reviews\n\n[openvibe.reviews](https://openvibe.reviews) · [repository](https://github.com/OpenVibers/OpenVibe.Reviews)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`01d7341`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/01d7341083ccd6ac7df406a7862c59a21b74e60b))\n- Static assets are immutable only when ?v= is the served file's hash (roadmap WS-P task 10): any ?v= used to be cached for a year, so after a deploy or a rollback an older page's URL could pin the wrong bytes; other ?v= values and plain… ([`217e003`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/217e0039b1f07e3ada0d99b1d6a46bfd0d981964))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`9b620b1`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/9b620b16926a58ef3acd5750f3f55e761338483c))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`4840286`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/4840286aa906ce6e94ea2a52fd51963b55751c7f))\n\n## OpenVibe.Wiki\n\n[openvibe.wiki](https://openvibe.wiki) · [repository](https://github.com/OpenVibers/OpenVibe.Wiki)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`1747009`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/1747009d57a30bb1771f24b83c8b72e493ebe8b5))\n- Static assets are immutable only when ?v= is the served file's hash (roadmap WS-P task 10): any ?v= used to be cached for a year, so after a deploy or a rollback an older page's URL could pin the wrong bytes; other ?v= values and plain… ([`255de21`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/255de2175427f664cb7247c12bb1f5fbdc9ecf2b))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`123bd4f`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/123bd4f459b8c241beb1adc71cccb2435b1e68b4))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`e0337a6`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/e0337a614995a8af2c65f620a6e0cf332791b04f))\n\n## OpenVibe.AI\n\n[ai.openvibe.network](https://ai.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.AI)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`1452cd7`](https://github.com/OpenVibers/OpenVibe.AI/commit/1452cd76e66fc097a893a99205bb012f8df4ae5d))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`baedda1`](https://github.com/OpenVibers/OpenVibe.AI/commit/baedda1fe9f8715f993e5cd7930723dc262b068f))\n- Operator console (roadmap WS-O task 4): /console on ai.openvibe.network, server-rendered with no JavaScript, for OpenVibe.Network staff. Providers (secret reference names and whether they resolve, never a value; base URLs without query or… ([`86e1246`](https://github.com/OpenVibers/OpenVibe.AI/commit/86e1246a750c94242b114de5cba2ee0e9fdd6057))\n\n## OpenVibe.Billing\n\n[billing.openvibe.network](https://billing.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Billing)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`876b010`](https://github.com/OpenVibers/OpenVibe.Billing/commit/876b01072d5dbd36e40faa6d10d4c017c3cd91a6))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`3d858ee`](https://github.com/OpenVibers/OpenVibe.Billing/commit/3d858ee36a21f0a558befc5c1f2c63eeb5e250a1))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`92edcae`](https://github.com/OpenVibers/OpenVibe.Billing/commit/92edcae7f4315ce81262624f7d78d359d9c24c20))\n\n## OpenVibe.Blog\n\n[openvibe.blog](https://openvibe.blog) · [repository](https://github.com/OpenVibers/OpenVibe.Blog)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`24705e9`](https://github.com/OpenVibers/OpenVibe.Blog/commit/24705e99a71f9de77b9ef899a9e6b14217dd7d9e))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`236bdba`](https://github.com/OpenVibers/OpenVibe.Blog/commit/236bdba972c70858b89c597f3542a5a560fe4b4c))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`047c956`](https://github.com/OpenVibers/OpenVibe.Blog/commit/047c9562ce8a2d6d871030b25e6f76fc16168e79))\n\n## OpenVibe.Chat\n\n[openvibe.chat](https://openvibe.chat) · [repository](https://github.com/OpenVibers/OpenVibe.Chat)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`252ac09`](https://github.com/OpenVibers/OpenVibe.Chat/commit/252ac09bb0d461d364e3c7c51a2865db5ec6225f))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`9b7da46`](https://github.com/OpenVibers/OpenVibe.Chat/commit/9b7da46576c8bc5d38fb9bb74b139273d81e4291))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`3cdd1dd`](https://github.com/OpenVibers/OpenVibe.Chat/commit/3cdd1ddb18ba4f4f986997304a2205a70e62b382))\n\n## OpenVibe.Coupons\n\n[openvibe.coupons](https://openvibe.coupons) · [repository](https://github.com/OpenVibers/OpenVibe.Coupons)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`0e2c7c6`](https://github.com/OpenVibers/OpenVibe.Coupons/commit/0e2c7c64f178849d14e24a4d9f7531a60a0d78a4))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`ae8beca`](https://github.com/OpenVibers/OpenVibe.Coupons/commit/ae8becaad341c41cab1063c4df8429d10fe1d340))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`39a20ed`](https://github.com/OpenVibers/OpenVibe.Coupons/commit/39a20ed7a576522bb37b7876ef6f0f2ac94d87bd))\n\n## OpenVibe.Deals\n\n[openvibe.deals](https://openvibe.deals) · [repository](https://github.com/OpenVibers/OpenVibe.Deals)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`6b30998`](https://github.com/OpenVibers/OpenVibe.Deals/commit/6b309981c71035f667020b3c6a61b9851ef1260c))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`b266be3`](https://github.com/OpenVibers/OpenVibe.Deals/commit/b266be36ef4d41e509909d3298647d7afc8b87ac))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`b5867df`](https://github.com/OpenVibers/OpenVibe.Deals/commit/b5867df38bdc903b5c9614f485a2c957ce2c7e33))\n\n## OpenVibe.Events\n\n[events.openvibe.network](https://events.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Events)\n\n- Limits page source (roadmap WS-N task 7): GET /limits.json lists the developer limits enforced here per project and environment (publish rate, bytes kept, retention, webhook subscriptions, payload and batch size, realtime topics), read… ([`5889c2c`](https://github.com/OpenVibers/OpenVibe.Events/commit/5889c2c50f0de966769edb5e4fa0c2361443f12b))\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`390f1cd`](https://github.com/OpenVibers/OpenVibe.Events/commit/390f1cdc80e3b5eb23cbd9e83600bdf7f9b9990e))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`a38de79`](https://github.com/OpenVibers/OpenVibe.Events/commit/a38de7968f16ffdf37f41b52162e20b4fc90fdff))\n\n## OpenVibe.News\n\n[openvibe.news](https://openvibe.news) · [repository](https://github.com/OpenVibers/OpenVibe.News)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`57c5ab3`](https://github.com/OpenVibers/OpenVibe.News/commit/57c5ab39666a107926acea70b3ca973413061b6a))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`90fbbad`](https://github.com/OpenVibers/OpenVibe.News/commit/90fbbad0c937f78b7d3ab971fb36cb8ce6795520))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`36b91d3`](https://github.com/OpenVibers/OpenVibe.News/commit/36b91d3d1316141955d087368238e2f2874d61d4))\n\n## OpenVibe.Tips\n\n[openvibe.tips](https://openvibe.tips) · [repository](https://github.com/OpenVibers/OpenVibe.Tips)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`d328728`](https://github.com/OpenVibers/OpenVibe.Tips/commit/d3287287585d2fb641fdd92609c7a615bc54b607))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`3c9237f`](https://github.com/OpenVibers/OpenVibe.Tips/commit/3c9237f007a68f3a907681a003d17433fcaf30f6))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`7c0d2f8`](https://github.com/OpenVibers/OpenVibe.Tips/commit/7c0d2f88ca0bba90c6d7d5981a2adaae93044e32))\n\n## OpenVibe.Tools\n\n[openvibe.tools](https://openvibe.tools) · [repository](https://github.com/OpenVibers/OpenVibe.Tools)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`7487547`](https://github.com/OpenVibers/OpenVibe.Tools/commit/74875471ab91a3a2237eac19eee3dcf80f94d323))\n- Sandbox and developer-app results to Media under the project's namespace (roadmap WS-L task 5): a job submitted by a developer app remembers its project (tool_jobs.project_id), and its result files go to Media under tools.app.<project_id>… ([`04a5876`](https://github.com/OpenVibers/OpenVibe.Tools/commit/04a5876022854203c56a498ef5394b46bf256205))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`1907390`](https://github.com/OpenVibers/OpenVibe.Tools/commit/190739043ff4c4c867c25f6e2fff6f7816727d61))\n\n## OpenVibe.Trade\n\n[openvibe.trade](https://openvibe.trade) · [repository](https://github.com/OpenVibers/OpenVibe.Trade)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`101445e`](https://github.com/OpenVibers/OpenVibe.Trade/commit/101445ef538de460656692bc421db7250b35a3be))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`e8fee67`](https://github.com/OpenVibers/OpenVibe.Trade/commit/e8fee67a5de0e6d4610f83b05aea648e6315d0e8))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`e427ca0`](https://github.com/OpenVibers/OpenVibe.Trade/commit/e427ca0b8e6f314ee3d7bb996a0e7a00852f23fc))\n\n## OpenVibe.VIP\n\n[openvibe.vip](https://openvibe.vip) · [repository](https://github.com/OpenVibers/OpenVibe.VIP)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`3f0380c`](https://github.com/OpenVibers/OpenVibe.VIP/commit/3f0380c81d27612e7f4fca8197b4393544cf925f))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`7bd0676`](https://github.com/OpenVibers/OpenVibe.VIP/commit/7bd067614464cb7128254b5910d18747ca5a1c69))\n- Open redirect fixed (roadmap WS-R task 5): the sign-in next let \"/<TAB>/evil.com\" through, which browsers read as \"//evil.com\" (they drop tab and newline characters and read a backslash as \"/\"); any control character or backslash in next… ([`2629597`](https://github.com/OpenVibers/OpenVibe.VIP/commit/2629597be331644e10a8601837bb26bd60cc213b))\n\n## OpenRe.Stream\n\n[openre.stream](https://openre.stream) · [repository](https://github.com/OpenVibers/OpenRe.Stream)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`0c16746`](https://github.com/OpenVibers/OpenRe.Stream/commit/0c16746dd6e3c93daa4e8826f4fa35f3590e9440))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`9cf13a8`](https://github.com/OpenVibers/OpenRe.Stream/commit/9cf13a8b61b517cd3f69c491104b4ca7a24ac253))\n\n## OpenVibe.Search\n\n[search.openvibe.network](https://search.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Search)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`74755cb`](https://github.com/OpenVibers/OpenVibe.Search/commit/74755cb0f291094ead9d02afde2cbc01571e66fb))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`18e7c29`](https://github.com/OpenVibers/OpenVibe.Search/commit/18e7c295275a4205832cf07eb3f31aad3dfcdf90))\n\n## OpenVibe.Sources\n\n[sources.openvibe.network](https://sources.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Sources)\n\n- Pins: openvibe-shared 1.17.1 -> 1.18.0 (update telemetry: prompted count, sessions by generation) ([`bb8e68f`](https://github.com/OpenVibers/OpenVibe.Sources/commit/bb8e68f37823b7318ae281159623b5003507525d))\n- Pins: openvibe-shared 1.18.0 -> 1.20.0 (the update matrix and release manifest 1.2.0: client generations, the shell) ([`d423030`](https://github.com/OpenVibers/OpenVibe.Sources/commit/d4230300cf0651209185c439d868096f83f8222f))\n\n---\n\nPatch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.","revision":1,"state":"published","visibility":"public","published_at":"2026-09-26T11:30:50.055Z","revised_at":"2026-09-26T11:30:50.051Z","author":{"subject":"usr_01KKT9AC60KM7CRTB3WN1Z8P56","name":"goosely","username":"goosely"},"authorship":{"mode":"imported","workflow":null,"reviewed":false,"disclosure":{"mode":"imported","short":"Imported","long":"Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers."}},"tags":["patch-notes","host","media","network","codes","live","community","reviews","wiki","ai","billing"],"categories":[],"series":{"title":"Patch notes","url":"https://openvibe.blog/@openvibe/series/patch-notes","position":null},"media":[],"citations":[],"indexability":{"indexable":true,"robots":"index, follow","reasons":[]}}