{"id":"pst_01M3J603CXB5V2ME40GX3ZWMB5","url":"https://openvibe.blog/@openvibe/patch-notes-private-and-unlisted-recordings-thumbnails-are-no-longer-listed-on-t","blog":{"id":"blg_01M362MF0EDJ7QHQTRD8A3Q981","handle":"openvibe","title":"The OpenVibe blog","url":"https://openvibe.blog/"},"title":"Patch notes: Private and unlisted recordings' thumbnails are no longer listed on th","summary":"What shipped on OpenVibe from 2026-09-26 to 2026-09-27: 34 changes to OpenVibe.Host, OpenVibe.Chat, OpenVibe.Community, OpenVibe.Events, OpenVibe.Live, OpenVibe.Media and 3 more.","body_markdown":"What shipped on OpenVibe from 2026-09-26 to 2026-09-27: 34 changes to OpenVibe.Host, OpenVibe.Chat, OpenVibe.Community, OpenVibe.Events, OpenVibe.Live, OpenVibe.Media and 3 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.\n\n## Highlights\n\n- **OpenVibe.Media:** Private and unlisted recordings' thumbnails are no longer listed on the media index (roadmap WS-R task 5; high): the Thumbnails tab of / and /browse listed every file in the thumbnails directory, so a frame of every private or unlisted VOD… ([`385416d`](https://github.com/OpenVibers/OpenVibe.Media/commit/385416df9e311a9ae07b38ddd7196ba0d597a0dd))\n- **OpenVibe.Chat:** Detaching a room says nothing to someone who may not (roadmap WS-R task 5: IDOR; low). A member who is not the room's manager got { removed: false } for an attachment that does not exist and 403 for one that does, so they could tell where… ([`9133c44`](https://github.com/OpenVibers/OpenVibe.Chat/commit/9133c4478dda08f8bb66f517144a8101b25da870))\n- **OpenVibe.Community:** IDOR suite (roadmap WS-R task 5: nobody acts on someone else's things by swapping ids). test/security-idor.test.js: alex owns a public, a private and a screenshot paste, paste comments, a thread with a reply, a typed comment, an uploaded… ([`7e22a51`](https://github.com/OpenVibers/OpenVibe.Community/commit/7e22a517153e9167ff6cd903d2efa0fbd84f3423))\n- **OpenVibe.Host:** browser-watch: a release is judged once its process has run 3 minutes (/release.json booted_at), and the confirming second run of a failure waits a minute first. On 2026-09-26 a check minutes after a Live restart failed on 4 console errors… ([`87bca98`](https://github.com/OpenVibers/OpenVibe.Host/commit/87bca98b1570394ec8013da34779ba0a53c74d38))\n- **OpenVibe.Network:** gitleaks allowlist for the SSRF suite's web-push test vector (roadmap WS-R task 5). test/security-ssrf.test.js subscribes with the public example subscription from the web-push documentation; its auth value matches the generic-api-key… ([`a7e07f7`](https://github.com/OpenVibers/OpenVibe.Network/commit/a7e07f73cf17d171126222dbfb16c8d59c773656))\n- **OpenVibe.Events:** Private-bypass suite, and an app token is never a realtime service viewer (roadmap WS-R task 5: private bypass; low). test/security-private.test.js publishes public, internal and per-person subject events and app events in two projects and… ([`2ad3f53`](https://github.com/OpenVibers/OpenVibe.Events/commit/2ad3f536b120ce0e7ef5f02a669dd246031ea614))\n- **OpenVibe.Live:** Security crawl for stream keys and secrets (roadmap WS-R task 5: stream-key exposure, internal-secret leak). test/security-crawl.js boots the real server/index.js as a restore-drill instance (reads only, no outbound connection) on a seeded… ([`1734f3e`](https://github.com/OpenVibers/OpenVibe.Live/commit/1734f3e9e3087fe1f17bc71001c1cf52acf88f33))\n\n## OpenVibe.Host\n\n[openvibe.host](https://openvibe.host) · [repository](https://github.com/OpenVibers/OpenVibe.Host)\n\n- Incident, maintenance and DNS controls (roadmap WS-N task 12; Contracts v0.66.0, pinned from 0.62.0). ovhost incident open|update|list and maintenance schedule|start|complete post to openvibe.network/status with Host's token… ([`59c31fe`](https://github.com/OpenVibers/OpenVibe.Host/commit/59c31fe7f3cbb1dfc98cc9e9dbd7edb3d84f994e))\n- browser-watch: a release is judged once its process has run 3 minutes (/release.json booted_at), and the confirming second run of a failure waits a minute first. On 2026-09-26 a check minutes after a Live restart failed on 4 console errors… ([`87bca98`](https://github.com/OpenVibers/OpenVibe.Host/commit/87bca98b1570394ec8013da34779ba0a53c74d38))\n- browser-watch keeps what failed: per route, the axe rule ids with up to 3 targets, the first console errors, overflow offenders and bad statuses (at most 20, clipped), in the site's state file for the operator (never in metrics); the CLI… ([`18d8822`](https://github.com/OpenVibers/OpenVibe.Host/commit/18d8822eb5780e0d170ae71ad9c6e4b6cdc0e602))\n- docs/operator-alerts.md: the browser check's settle window, retry delay and failure details. ([`8a981f5`](https://github.com/OpenVibers/OpenVibe.Host/commit/8a981f55b8d2196bbdb6d8ff712767122c2b562d))\n- SSRF regression test for tenant-named hosts (roadmap WS-R task 5). A custom domain is the one host a tenant names, and it is proven by a DNS TXT record through the configured resolver, never by a request to it: test/security-ssrf.test.js… ([`94e1616`](https://github.com/OpenVibers/OpenVibe.Host/commit/94e16164956de8beeb93c1a94212f7d36241247d))\n\n## OpenVibe.Chat\n\n[openvibe.chat](https://openvibe.chat) · [repository](https://github.com/OpenVibers/OpenVibe.Chat)\n\n- N-1: fixtures re-recorded from 6181238 with Live's chat surfaces at 13525eb, the releases in production. The Live-file filter now matches the checkout's own directory name (the harness labels files with it). From a checkout not named… ([`ac1708a`](https://github.com/OpenVibers/OpenVibe.Chat/commit/ac1708a668f7a5d4f017c2d5d41205fe22d458c1))\n- Secrets and private rooms, by crawl (roadmap WS-R task 5: internal-secret leak, private room bypass). test/security-crawl.js lists every route of the booted app from Express's router stack (a route added later is crawled without anyone… ([`655135d`](https://github.com/OpenVibers/OpenVibe.Chat/commit/655135db628eaab3c4aee4ef93f5a5daf9284d9c))\n- Detaching a room says nothing to someone who may not (roadmap WS-R task 5: IDOR; low). A member who is not the room's manager got { removed: false } for an attachment that does not exist and 403 for one that does, so they could tell where… ([`9133c44`](https://github.com/OpenVibers/OpenVibe.Chat/commit/9133c4478dda08f8bb66f517144a8101b25da870))\n- The soundboard's audio download cannot be steered inward (roadmap WS-R task 5: SSRF; low). The audio URL comes from 101soundboards' API answer; its check allowed only 101soundboards.com but judged one DNS answer with its own list, which… ([`d4704b2`](https://github.com/OpenVibers/OpenVibe.Chat/commit/d4704b221d5ef3291fb0a6cc1a6126057c9f35f3))\n\n## OpenVibe.Community\n\n[openvibe.community](https://openvibe.community) · [repository](https://github.com/OpenVibers/OpenVibe.Community)\n\n- Security crawl for internal secrets (roadmap WS-R task 5: internal-secret leak). test/security-secrets.test.js boots the app with every secret Community reads set to an obviously fake sentinel (sentinel-not-a-secret-<name>)… ([`cf50b27`](https://github.com/OpenVibers/OpenVibe.Community/commit/cf50b27e5c00369ff0792130fef0485de2576027))\n- Private things stay private on every read path (roadmap WS-R task 5: private bypass), with four fixes the new test found. test/security-private.test.js seeds private text and screenshot pastes (and a comment on one), an unlisted paste… ([`249d0ed`](https://github.com/OpenVibers/OpenVibe.Community/commit/249d0eda7bcbff414f1875096593598ba929d7ed))\n- IDOR suite (roadmap WS-R task 5: nobody acts on someone else's things by swapping ids). test/security-idor.test.js: alex owns a public, a private and a screenshot paste, paste comments, a thread with a reply, a typed comment, an uploaded… ([`7e22a51`](https://github.com/OpenVibers/OpenVibe.Community/commit/7e22a517153e9167ff6cd903d2efa0fbd84f3423))\n- SSRF (roadmap WS-R task 5): Community fetches no URL a user chooses, and a test keeps it so; the live-mode paste proxy no longer lets a visitor's path leave Live's paste API. Every outbound call goes to a base URL from the owner's… ([`69f5feb`](https://github.com/OpenVibers/OpenVibe.Community/commit/69f5feb384e4366923462e10f7b0671bdd0cd9c8))\n\n## OpenVibe.Events\n\n[events.openvibe.network](https://events.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Events)\n\n- Security crawl for secrets (roadmap WS-R task 5: internal-secret leak). Events holds one kind of secret, each subscription's signing secret, and reads none from its environment (test/security-secrets.test.js asserts that: a new… ([`7efb758`](https://github.com/OpenVibers/OpenVibe.Events/commit/7efb7580e64a6b779701e195fb0ec6c8bef8b727))\n- Private-bypass suite, and an app token is never a realtime service viewer (roadmap WS-R task 5: private bypass; low). test/security-private.test.js publishes public, internal and per-person subject events and app events in two projects and… ([`2ad3f53`](https://github.com/OpenVibers/OpenVibe.Events/commit/2ad3f536b120ce0e7ef5f02a669dd246031ea614))\n- IDOR suite, and an app's subscriptions are scoped to its project and environment (roadmap WS-R task 5: IDOR; low). test/security-idor.test.js swaps ids between two apps, two projects, two environments and two services: reading, rotating… ([`04a2857`](https://github.com/OpenVibers/OpenVibe.Events/commit/04a2857dbf19c3ac806f8e7c1863fa645d19c11f))\n- SSRF suite for app endpoints and a ratchet over outbound calls (roadmap WS-R task 5: SSRF). test/security-ssrf.test.js tries every internal spelling where an app subscription is made and again where each delivery is made, through the real… ([`0fcd17a`](https://github.com/OpenVibers/OpenVibe.Events/commit/0fcd17a24506d76a6d750fb39297e12835420330))\n\n## OpenVibe.Live\n\n[openvibe.live](https://openvibe.live) · [repository](https://github.com/OpenVibers/OpenVibe.Live)\n\n- Security crawl for stream keys and secrets (roadmap WS-R task 5: stream-key exposure, internal-secret leak). test/security-crawl.js boots the real server/index.js as a restore-drill instance (reads only, no outbound connection) on a seeded… ([`1734f3e`](https://github.com/OpenVibers/OpenVibe.Live/commit/1734f3e9e3087fe1f17bc71001c1cf52acf88f33))\n- A streamer's own AI endpoint goes out through the egress guard (roadmap WS-R task 5: SSRF). The AI viewers' \"bring your own\" base URL is typed by the streamer, but llm.js POSTed to it with a plain fetch: any signed-in user could point POST… ([`aeb3e68`](https://github.com/OpenVibers/OpenVibe.Live/commit/aeb3e688da46658f4a654fedfabfc514e5e0bcca))\n- IDOR and DM privacy suites (roadmap WS-R task 5: IDOR on objects, private room bypass). test/security-idor.test.js tries every write route that takes an object id with another streamer's id: VODs and clips through Live's Media proxy (edit… ([`8539e3f`](https://github.com/OpenVibers/OpenVibe.Live/commit/8539e3fb253d235363de6edf66049fb8acd33839))\n- The soundboard's audio download cannot be steered inward (roadmap WS-R task 5: SSRF; low; the same fix as OpenVibe.Chat's copy). The 101soundboards audio URL comes from that API's answer; its check allowed only 101soundboards.com but… ([`2e6f546`](https://github.com/OpenVibers/OpenVibe.Live/commit/2e6f546444ef378a6e2126702960623635ac97a2))\n\n## OpenVibe.Media\n\n[openvibe.media](https://openvibe.media) · [repository](https://github.com/OpenVibers/OpenVibe.Media)\n\n- Internal secrets never leave Media, by test (roadmap WS-R task 5): test/security-secrets.test.js boots the real server/index.js in-process with an obviously fake sentinel for every secret it reads (internal key, signing and view-hash… ([`db4c60c`](https://github.com/OpenVibers/OpenVibe.Media/commit/db4c60cf09db804164e4dab6da5f1b8c7713f3be))\n- Private and unlisted recordings' thumbnails are no longer listed on the media index (roadmap WS-R task 5; high): the Thumbnails tab of / and /browse listed every file in the thumbnails directory, so a frame of every private or unlisted VOD… ([`385416d`](https://github.com/OpenVibers/OpenVibe.Media/commit/385416df9e311a9ae07b38ddd7196ba0d597a0dd))\n- A call acting for one user no longer writes another user's media (roadmap WS-R task 5; medium): with the app key and X-OV-User-Id, which is meant to carry that user's permissions, user B could update (visibility included), delete… ([`62160a8`](https://github.com/OpenVibers/OpenVibe.Media/commit/62160a8b4a2442f30fac7bfd52e03b2348f796eb))\n- The avatar fetch uses openvibe-shared/egress's address rule (roadmap WS-R task 5; low): its own copy had drifted and took the IPv6 forms that wrap an internal IPv4 address (v4-compatible ::127.0.0.1, 6to4 2002:7f00:1::, Teredo), site-local… ([`1157a54`](https://github.com/OpenVibers/OpenVibe.Media/commit/1157a5459a908ba5601a6321761e2954bdf94ff5))\n\n## OpenVibe.Network\n\n[openvibe.network](https://openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Network)\n\n- Security crawl for secrets (roadmap WS-R task 5: internal-secret leak). test/security-secrets.test.js boots the real server with a throwaway RS256 and VAPID pair and a fake low-entropy sentinel in every secret it reads from the… ([`655e8ad`](https://github.com/OpenVibers/OpenVibe.Network/commit/655e8ad5d8c0f4591c797f5ac8b30413dc375267))\n- Private-bypass and IDOR suites (roadmap WS-R task 5). test/security-private.test.js crawls every GET route Express knows after boot as anonymous, another user, a developer app and a service principal, and no answer may carry alice's… ([`fd866c0`](https://github.com/OpenVibers/OpenVibe.Network/commit/fd866c049906153e91dd4ac33dfa6b3c524d5855))\n- Web push endpoints cannot be steered inward (roadmap WS-R task 5: SSRF; low). A push subscription's endpoint is a URL the browser hands over, so anyone signed in chose where Network POSTs: web-push sent to it as stored, 127.0.0.1… ([`80caea9`](https://github.com/OpenVibers/OpenVibe.Network/commit/80caea96b6bcaddb76f331905931232af0cf72ac))\n- gitleaks allowlist for the SSRF suite's web-push test vector (roadmap WS-R task 5). test/security-ssrf.test.js subscribes with the public example subscription from the web-push documentation; its auth value matches the generic-api-key… ([`a7e07f7`](https://github.com/OpenVibers/OpenVibe.Network/commit/a7e07f73cf17d171126222dbfb16c8d59c773656))\n\n## OpenVibe.Tools\n\n[openvibe.tools](https://openvibe.tools) · [repository](https://github.com/OpenVibers/OpenVibe.Tools)\n\n- The paste proxy reaches only Community's paste API, and yt-dlp only YouTube links (roadmap WS-R task 5: SSRF; low). The gateway forwarded /api/pastes/* to `${communityUrl}/api/pastes${req.url}` with the visitor's token… ([`3680e83`](https://github.com/OpenVibers/OpenVibe.Tools/commit/3680e838ebe342e23a3efee5b4b1e146f94f7732))\n- Secrets never reach a visitor of the gateway or the maps satellite, by test (roadmap WS-R task 5: internal-secret leak). apps/_shared/test/no-network.js is a preload for a started satellite: every connection or lookup that is not loopback… ([`427b354`](https://github.com/OpenVibers/OpenVibe.Tools/commit/427b354b0ae1cbc6f37e2cdcef0a5c934e57ca5b))\n- maps: no RIDB API key in the code. RIDB_API_KEY comes from the environment only (set in production's /etc/openvibe/tools.env on 2026-09-27, before this deploy); without it RIDB is skipped with one warning. The two keys that were defaults… ([`b635f97`](https://github.com/OpenVibers/OpenVibe.Tools/commit/b635f975acdb17ae3745ad7d333b4a0bc4a5a871))\n\n## OpenVibe.Sources\n\n[sources.openvibe.network](https://sources.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Sources)\n\n- The fetch guard's address rule cannot drift from the platform's (roadmap WS-R task 5: SSRF; low). Sources keeps its own address list, and it had drifted from openvibe-shared/egress (the rule Live, Events, Chat and Tools use)… ([`8a7b7ea`](https://github.com/OpenVibers/OpenVibe.Sources/commit/8a7b7ea53f69b8735379d0bb4f105bfe25d13940))\n- A failed fetch's event no longer carries the endpoint's credential (roadmap WS-R task 5: internal-secret leak; low). sources.fetch.failed named the endpoint as registered, so a feed whose URL carries a provider key (?api_key=…) sent that… ([`ad53d2f`](https://github.com/OpenVibers/OpenVibe.Sources/commit/ad53d2fbfaef771537caef4911c0ff8c3e4bc4da))\n\n---\n\nPatch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.","revision":1,"state":"published","visibility":"public","published_at":"2026-09-27T19:38:15.327Z","revised_at":"2026-09-27T19:38:15.326Z","author":{"subject":"usr_01KKT9AC60KM7CRTB3WN1Z8P56","name":"goosely","username":"goosely"},"authorship":{"mode":"imported","workflow":null,"reviewed":false,"disclosure":{"mode":"imported","short":"Imported","long":"Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers."}},"tags":["patch-notes","host","chat","community","events","live","media","network","tools","sources"],"categories":[],"series":{"title":"Patch notes","url":"https://openvibe.blog/@openvibe/series/patch-notes","position":null},"media":[],"citations":[],"indexability":{"indexable":true,"robots":"index, follow","reasons":[]}}