{"id":"pst_01M3K77VPKCPC32QG0G2TPPD5E","url":"https://openvibe.blog/@openvibe/patch-notes-security-regression-suites-for-the-four-classes-that-apply-to-the-wi","blog":{"id":"blg_01M362MF0EDJ7QHQTRD8A3Q981","handle":"openvibe","title":"The OpenVibe blog","url":"https://openvibe.blog/"},"title":"Patch notes: Security regression suites for the four classes that apply to the Wiki","summary":"What shipped on OpenVibe on 2026-09-28: 103 changes to OpenVibe.Live, OpenVibe.Host, OpenVibe.AI, OpenVibe.Media, OpenVibe.Network, OpenVibe.Chat and 18 more.","body_markdown":"What shipped on OpenVibe on 2026-09-28: 103 changes to OpenVibe.Live, OpenVibe.Host, OpenVibe.AI, OpenVibe.Media, OpenVibe.Network, OpenVibe.Chat and 18 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.\n\n## Highlights\n\n- **OpenVibe.Wiki:** Security regression suites for the four classes that apply to the Wiki (roadmap WS-R task 5). test/security-crawl.js lists every route of the booted app from Express's router stack (a route added later is crawled without anyone listing… ([`1e311db`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/1e311db2baadf622bcf949b7d72fe5aa8d6db969))\n- **OpenVibe.Blog:** Security regression suites for the four classes that apply to the Blog (roadmap WS-R task 5). test/security-crawl.js lists every route of the booted app from Express's router stack (a route added later is crawled without anyone listing… ([`21d5db3`](https://github.com/OpenVibers/OpenVibe.Blog/commit/21d5db386b7c595af448dd81690debdfd042c09b))\n- **OpenVibe.Host:** Per-actor limits on the dashboard's and the API's writes (roadmap WS-R task 4; openvibe-sdk 0.11.0 -> 0.12.0 openvibe-sdk/limits). server/http/actor-limits.js runs after the viewer is resolved and counts a signed-in person by subject, or a… ([`2b63389`](https://github.com/OpenVibers/OpenVibe.Host/commit/2b633899f41b559586e3d6c234925d498c7bf2cd))\n- **OpenVibe.Network:** README and STATUS.json are current (roadmap WS-U task 3): the README gains Purpose (the opening sentence), Owns, Does not own, Depends on, Capabilities (the 20 capabilities in the manifest, where other services' grants are seeded, and the… ([`5a50c12`](https://github.com/OpenVibers/OpenVibe.Network/commit/5a50c12a83f6501aacd663f15d3c06c718a4c83a))\n\n## OpenVibe.Live\n\n[openvibe.live](https://openvibe.live) · [repository](https://github.com/OpenVibers/OpenVibe.Live)\n\n- Arena personas, quotes and headlines and the auto-clip check send OpenVibe.AI data, not prompts (roadmap WS-O task 2; AI d271436). generatePersona sends the fighter's facts; generateQuotes sends the candidate lines; headlineFor sends the… ([`e7ebaf5`](https://github.com/OpenVibers/OpenVibe.Live/commit/e7ebaf536a7700522cc57027f10859761d96260c))\n- N-1 fixtures re-recorded from e7ebaf5, the release now in production (npm run n-1:record). ([`0a83434`](https://github.com/OpenVibers/OpenVibe.Live/commit/0a83434636061aacde03550295931c8bf47f275a))\n- The AI viewers send OpenVibe.AI their context, not prompts (roadmap WS-O task 2; AI 65b6a80 live.viewers.plan, reply, fold and clone templates). server/ai/viewers/ai-run.js runs a viewers template on the site's AI (admin switch and daily… ([`e3ad96d`](https://github.com/OpenVibers/OpenVibe.Live/commit/e3ad96df3d32b0e10771aa288d4aeff532d9b114))\n- N-1 fixtures re-recorded from e3ad96d, the release now in production (npm run n-1:record). ([`15da7e8`](https://github.com/OpenVibers/OpenVibe.Live/commit/15da7e83e95e73b0c90e2d25583b2a1b5bd6958c))\n- VOD and clip transcripts are made by OpenVibe.AI, not Live's own whisper (roadmap WS-O task 2; AI d46c217, be66fa4). A recording on Media is transcribed by live.media.transcribe one 5-minute window at a time, or whole when it is 200… ([`860c944`](https://github.com/OpenVibers/OpenVibe.Live/commit/860c944974d0e780860b66f45f03209783f2c84b))\n- N-1 fixtures re-recorded from 860c944, the release now in production (npm run n-1:record). ([`53f6ac6`](https://github.com/OpenVibers/OpenVibe.Live/commit/53f6ac65406b67896a5c91da1fa23b6da2abe71e))\n- Per-actor limits on Live's API writes (roadmap WS-R task 4; openvibe-sdk 0.11.0 -> 0.12.0 openvibe-sdk/limits). server/net/actor-limits.js counts writes by the person behind the token: their Network subject, or the person who made an hbt_… ([`85fc2fa`](https://github.com/OpenVibers/OpenVibe.Live/commit/85fc2faf857f1df419a6b2110117ecf5f8a0c48c))\n- N-1 fixtures re-recorded from 85fc2fa, the release now in production (npm run n-1:record). ([`b78d2ec`](https://github.com/OpenVibers/OpenVibe.Live/commit/b78d2ecf7a386e237b3e3966085b8dd282d6e393))\n- A private VOD or clip is transcribed and analysed too (roadmap WS-O task 2; Media 9aac60f signed playback URLs). The recording source for AI work is now a signed URL from Media (media-client signedMediaUrl, six hours), which works whatever… ([`695202d`](https://github.com/OpenVibers/OpenVibe.Live/commit/695202d8a9d91fbb74872e2f0dca837007b196ea))\n- N-1 fixtures re-recorded from 695202d, the release now in production (npm run n-1:record). ([`a7184ca`](https://github.com/OpenVibers/OpenVibe.Live/commit/a7184cadb0a4fda2d878a2c7bf680de5fe5a44b1))\n- README and STATUS.json are current (roadmap WS-U task 3; Contracts scripts/docs-currency.js passes). The README gains Purpose, Owns, Does not own, Depends on, Capabilities (what Live implements and the grants its principal holds)… ([`65b0dc8`](https://github.com/OpenVibers/OpenVibe.Live/commit/65b0dc80bbed87e1ff178c779c9b6a668d9cd7c7))\n- The pre-Media local path settings are gone (shim C-74): config.vod (VOD_PATH, CLIPS_PATH, COLD_STORAGE_PATH) and config.thumbnails (THUMBNAILS_PATH). VOD, clip and thumbnail files live in OpenVibe.Media, no code read these, and production… ([`b0cc2ef`](https://github.com/OpenVibers/OpenVibe.Live/commit/b0cc2ef4f8a57c9624b88af64a6aa4bd1e425279))\n- N-1 fixtures re-recorded from 65b0dc8, the release now in production (npm run n-1:record). ([`03f49b7`](https://github.com/OpenVibers/OpenVibe.Live/commit/03f49b7716b7cee1cce8a44e7155aeb96a67d004))\n- A follow Network took is notified by Network, not pushed from Live (roadmap WS-E task 3, D08; Network 8188c26). Both follow routes pushed a FOLLOW notification over Network's internal route for every follow. Network now sends one itself… ([`a70f562`](https://github.com/OpenVibers/OpenVibe.Live/commit/a70f562c269bd6fce143815dc0fa2a07b60559e5))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; Shared v1.25.0 openvibe-shared/test-runner). test/run.js is now the shared runner (same files, parallelism, 120 s timeout and [DB] filter) with the skip rule: a test… ([`278cd40`](https://github.com/OpenVibers/OpenVibe.Live/commit/278cd4047e57f4a4849b2adde497894a4f985445))\n\n## OpenVibe.Host\n\n[openvibe.host](https://openvibe.host) · [repository](https://github.com/OpenVibers/OpenVibe.Host)\n\n- ovhost absorbs the per-repository deploy scripts (roadmap WS-N task 11). A service entry's `strategy` picks the engine and the defaults the script it replaces encoded: git-checkout (the default, what ovhost did before), multi-app (Tools… ([`e4c7a58`](https://github.com/OpenVibers/OpenVibe.Host/commit/e4c7a58f37afacf393cbc3ff7cc993350b4ac348))\n- multi-app: a oneshot unit the unitsMatch glob catches is a job, not a service (found in the WS-N task 11 cutover, 2026-09-27). openvibe-tools*.service also matches openvibe-toolsjob.service, the job proof its timer runs (Type=oneshot… ([`08acfbd`](https://github.com/OpenVibers/OpenVibe.Host/commit/08acfbdf5754ccbeb1cd381c46df76208f689e4d))\n- pnpm-build: install with --config.confirmModulesPurge=false. When pnpm decides node_modules must be rebuilt (made under other settings, as production's Games checkout was), it asks first; under ovhost nothing answers, so it installed… ([`d8e8f7d`](https://github.com/OpenVibers/OpenVibe.Host/commit/d8e8f7ddeef1abdafb1491e961ab9d15da5365ae))\n- Release-lifecycle acceptance suite (D46, roadmap WS-P task 16): lib/acceptance.js holds the 14 D46 scenarios as 63 gates and scripts/release-acceptance.js runs them. ([`cfd3860`](https://github.com/OpenVibers/OpenVibe.Host/commit/cfd38602ed24319a493bfd41c4ceb8916a2062b3))\n- docs/release-acceptance.md: the release-lifecycle acceptance suite (D46, roadmap WS-P task 16) — how to run it, how a gate is judged, which gates measure each D46 quantity, the scenario table (gate, evidence, budget, where each number… ([`9e603ad`](https://github.com/OpenVibers/OpenVibe.Host/commit/9e603ade51b89659073b0cd1fc44b51fb05bc4a9))\n- Per-actor limits on the dashboard's and the API's writes (roadmap WS-R task 4; openvibe-sdk 0.11.0 -> 0.12.0 openvibe-sdk/limits). server/http/actor-limits.js runs after the viewer is resolved and counts a signed-in person by subject, or a… ([`2b63389`](https://github.com/OpenVibers/OpenVibe.Host/commit/2b633899f41b559586e3d6c234925d498c7bf2cd))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Capabilities (the three host.* capabilities and the grants Host uses: events.event.publish, network.operator.alert, network.status.incident), Deploy (the ovhost CLI… ([`5d35e9d`](https://github.com/OpenVibers/OpenVibe.Host/commit/5d35e9dac82c2192c4a170ac6d2af5c8b72f3aca))\n- docs/deploy-strategies.md: the strategies have been in production since the 2026-09-27 cutover, and every service deploys and rolls back with ovhost. The state said 'Not on the host yet' and the checklist 'Nothing here has been run'; the… ([`6d2aaaa`](https://github.com/OpenVibers/OpenVibe.Host/commit/6d2aaaa630e29d2bfd261a7f75cbbbaa2b8c1d46))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, even one that had skipped part of its work. It is now the shared… ([`ee84fbc`](https://github.com/OpenVibers/OpenVibe.Host/commit/ee84fbc2e1ab97a7a28a75b89a7991c54af43a34))\n\n## OpenVibe.AI\n\n[ai.openvibe.network](https://ai.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.AI)\n\n- Arena personas, quotes and headlines and the auto-clip check are versioned templates (roadmap WS-O task 2). live.arena.persona, live.arena.quotes, live.arena.headline and live.clips.confirm move from passthrough to structured workflows… ([`d271436`](https://github.com/OpenVibers/OpenVibe.AI/commit/d27143693c979c52d11b9bc70b08bfdf3cc5216c))\n- The AI viewers are versioned templates (roadmap WS-O task 2). live.viewers.plan, live.viewers.reply and live.viewers.fold move from passthrough to structured workflows (version 2), and live.viewers.clone is new. The director's rules, its… ([`65b6a80`](https://github.com/OpenVibers/OpenVibe.AI/commit/65b6a804e4c5c7bc336d43cac13211004257671b))\n- Namespaces are the token's ns claim, nothing else: the fallback for service tokens without ns (AI_NS_FALLBACK) and the open-rule lever (AI_NS_REQUIRED=false) are retired (shims C-22 and C-23, roadmap WS-O task 2). Every caller's token… ([`5b73bb9`](https://github.com/OpenVibers/OpenVibe.AI/commit/5b73bb92159f55f692c340a9e6f5a011bc260e46))\n- live.media.transcribe runs one window of a recording where it lies (roadmap WS-O task 2, so Live's VOD and clip transcripts can move here). The transcribe step streams through the loopback reader, now shared with media.analyze (one per… ([`d46c217`](https://github.com/OpenVibers/OpenVibe.AI/commit/d46c21713890c7c5d2f09f98daf8885bf6ab84f9))\n- Recordings are loudness-normalised before speech-to-text, as Live's VOD transcripts were (loudnorm I=-16 before whisper), so a quiet streamer is still heard. It applies to every batch window (transcripts and media.analyze), not live… ([`be66fa4`](https://github.com/OpenVibers/OpenVibe.AI/commit/be66fa4d46c83696294d1a91787d6aa5ab2ccba2))\n- Offloaded recordings are readable: a redirect from Media to its object storage is followed (roadmap WS-O task 2). Most VODs live in B2 (676) or R2 (19), and Media answers /v/:id with a 302 to a presigned URL there. The fetcher refused… ([`549bed0`](https://github.com/OpenVibers/OpenVibe.AI/commit/549bed09452233c6b21d529ab905a7bd8fbad4da))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Purpose (the opening paragraph), Owns, Does not own, Depends on, Capabilities (all seven ai.* capabilities, including ai.credential.manage and… ([`6c8b833`](https://github.com/OpenVibers/OpenVibe.AI/commit/6c8b8338be936cbd3a6f50dee3f790807f145a0e))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so media-analysis without ffmpeg, which runs only its parser… ([`f6fdbc9`](https://github.com/OpenVibers/OpenVibe.AI/commit/f6fdbc9cbc3c87d684046940e49dd5ddffd5c79b))\n\n## OpenVibe.Media\n\n[openvibe.media](https://openvibe.media) · [repository](https://github.com/OpenVibers/OpenVibe.Media)\n\n- Signed playback URLs for a VOD or clip, so a reader with no key can read a private recording its owning app asked for: OpenVibe.AI transcribing it (roadmap WS-O task 2). GET /api/v1/:app/vods/:id/signed-url and /clips/:id/signed-url (the… ([`9aac60f`](https://github.com/OpenVibers/OpenVibe.Media/commit/9aac60f0b6ac96e82adfca07b94f988afb5759e6))\n- /limits.json lists the per-actor rate limits as rate_limits (roadmap WS-R task 4): every named limit the routes declared (object upload, parts, complete, delete, jobs, files, me), with its numbers per caller per minute and hour and 429… ([`6248363`](https://github.com/OpenVibers/OpenVibe.Media/commit/62483631db9b9c120662abf2b21d4cff0a2bdc80))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Purpose (the opening overview), Owns, Does not own, Depends on, Capabilities (the nine media.* capabilities and the grants Media uses at Network, Live and Events)… ([`14cac06`](https://github.com/OpenVibers/OpenVibe.Media/commit/14cac06886649848c332cfa564aa6b3594ea09bc))\n- Media's readiness has no fake green (roadmap WS-Q task 7, Shared v1.24.0). events_outbox answered ok with { enabled: false } while the relay was off, and an unconfigured remote tier (b2, r2) had no check at all, so nothing showed it was… ([`51283d3`](https://github.com/OpenVibers/OpenVibe.Media/commit/51283d3211216cb66edb4baf96005915ea989e33))\n- H15 repair: resize, and the legacy row follows (roadmap WS-G task 7, found by the no-fake-green readiness sweep). Media's readiness is degraded again by 3 objects with no good copy: VODs 939, 1277 and 1309, the same three the 2026-09-25… ([`8b2e542`](https://github.com/OpenVibers/OpenVibe.Media/commit/8b2e5429a480597c788672d4c77e7ed2921116ee))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; Shared v1.25.0 openvibe-shared/test-runner). The test script was a shell loop that stopped at the first failure and counted nothing, so a test that printed \"⚠️ ffmpeg… ([`47b21bd`](https://github.com/OpenVibers/OpenVibe.Media/commit/47b21bde0b4863344fafbb90109922fbf8757687))\n\n## OpenVibe.Network\n\n[openvibe.network](https://openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Network)\n\n- Per-actor limits on the account API's writes (roadmap WS-R task 4; openvibe-sdk 0.11.0 -> 0.12.0 openvibe-sdk/limits). server/auth/actor-limits.js counts writes by the person whose session token makes them (their subject). ([`ddd87b6`](https://github.com/OpenVibers/OpenVibe.Network/commit/ddd87b6844fad1f0f878ed574ce0e2c990e5e695))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Purpose (the opening sentence), Owns, Does not own, Depends on, Capabilities (the 20 capabilities in the manifest, where other services' grants are seeded, and the… ([`5a50c12`](https://github.com/OpenVibers/OpenVibe.Network/commit/5a50c12a83f6501aacd663f15d3c06c718a4c83a))\n- Roadmap baseline regenerated 2026-09-28 (roadmap WS-Q task 6): 639 tables, 2453 routes, 112 call sites, 378 discrepancies, from fresh production, GitHub and origin/main scans. 6/7 exit criteria pass; EC7 waits for the host owner's hazard… ([`c022f86`](https://github.com/OpenVibers/OpenVibe.Network/commit/c022f86236f3e8251c924fae6c98494658b795a4))\n- Roadmap baseline reads the release layout, and ranks docs-only deploy drift low. collect-prod.sh took every /opt/openvibe.<svc> checkout's HEAD, so Live, which runs from current -> releases/<time>-<sha> (a git worktree of repo/) since… ([`0b1dbdf`](https://github.com/OpenVibers/OpenVibe.Network/commit/0b1dbdff3ad33cbcf7db79ba0251ae4e8747c27e))\n- Network notifies a new follow itself (roadmap WS-E task 3, D08: Live's pushes that have a domain event move off Live; ADR-020, ADR-030). Since follows moved to Network (FOLLOWS_AUTHORITY=network, 2026-09-26), a follow made on… ([`8188c26`](https://github.com/OpenVibers/OpenVibe.Network/commit/8188c26f3c885e6eae4488f69cf2a3dbb6fb2605))\n- No fake green in Network's readiness and in the registry's status (roadmap WS-Q task 7; Shared v1.24.0). Production's /api/ready reported the Discord bot check \"ok\" with the detail \"not configured\"; it now returns skip('not configured')… ([`ac71bb4`](https://github.com/OpenVibers/OpenVibe.Network/commit/ac71bb4d82b09a1fe384119a22d92bd3eb98abbf))\n\n## OpenVibe.Chat\n\n[openvibe.chat](https://openvibe.chat) · [repository](https://github.com/OpenVibers/OpenVibe.Chat)\n\n- N-1 fixtures re-recorded from a2d100d, the Chat release now in production, with Live's widget at 06cf38b (npm run n-1:record). ([`ccc5349`](https://github.com/OpenVibers/OpenVibe.Chat/commit/ccc5349918933eb10fe76d2dfe8ce81b7e124af3))\n- Per-actor rate limits on Chat's REST API (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/net/actor-limits.js is one limiter for the app. It counts a person as user:usr_… (user:<id> before their subject is known) whether they… ([`27cb1cb`](https://github.com/OpenVibers/OpenVibe.Chat/commit/27cb1cba83228b75a4c175e625e7c78915b79748))\n- Signed-out reads keep only the per-address limit (900 a minute). On Live's busiest streams many viewers share one carrier or campus address, and a per-actor budget of 120 a minute for all of them would refuse real people. Signed-in reads… ([`3aab730`](https://github.com/OpenVibers/OpenVibe.Chat/commit/3aab730c5105594523ed58ab0643c6eedc6b5214))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Security (SECURITY.md, auth, private data, network exposure, egress, secrets by name) and Deploy (sudo ovhost deploy chat, unit, port, env file, /ready, both nginx… ([`d87c8d3`](https://github.com/OpenVibers/OpenVibe.Chat/commit/d87c8d3c906ad52ef8bf123ce60373fdefcf09e6))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so message-deleted without an OpenVibe.Events checkout next to… ([`4c517a5`](https://github.com/OpenVibers/OpenVibe.Chat/commit/4c517a59ead3c9e71139b6d4954de8306a4d83ba))\n\n## OpenVibe.Codes\n\n[openvibe.codes](https://openvibe.codes) · [repository](https://github.com/OpenVibers/OpenVibe.Codes)\n\n- Security regression suites for the four classes that apply to Codes (roadmap WS-R task 5). test/security-crawl.js lists every route of the booted app from Express's router stack (a route added later is crawled without anyone listing it)… ([`644ce53`](https://github.com/OpenVibers/OpenVibe.Codes/commit/644ce53da63457554168f741855e6b40b0102619))\n- Per-actor rate limits at Codes' capability boundaries (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/http/actor-limits.js makes one limiter per app. It covers /api/v1, the signed-in portal (/projects), release actions, the… ([`d78de70`](https://github.com/OpenVibers/OpenVibe.Codes/commit/d78de7052c08dc38c6e2c400a0b63a1b00793f1f))\n- README and STATUS.json are current (roadmap WS-U task 3): the grants section opens with the two capabilities Codes implements and every grant it uses elsewhere (its principal, the person's token, the app's token, Network export tokens)… ([`7d6f65a`](https://github.com/OpenVibers/OpenVibe.Codes/commit/7d6f65ac198d95f70ac840c24d03d1407affb7a9))\n- The webhook tester checks signature v2 only (compatibility shim C-61). OpenVibe.Events stopped sending the v1 header (X-OpenVibe-Signature, an HMAC of the body alone that verifies forever) on 2026-09-28 (shim C-60) and every consumer… ([`64d8feb`](https://github.com/OpenVibers/OpenVibe.Codes/commit/64d8feb1ac841c01f93e197b6a20eb07a09ef428))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`1246445`](https://github.com/OpenVibers/OpenVibe.Codes/commit/1246445c4abaddcacf4d04adf172d601700833e3))\n\n## OpenVibe.Blog\n\n[openvibe.blog](https://openvibe.blog) · [repository](https://github.com/OpenVibers/OpenVibe.Blog)\n\n- Security regression suites for the four classes that apply to the Blog (roadmap WS-R task 5). test/security-crawl.js lists every route of the booted app from Express's router stack (a route added later is crawled without anyone listing… ([`21d5db3`](https://github.com/OpenVibers/OpenVibe.Blog/commit/21d5db386b7c595af448dd81690debdfd042c09b))\n- Per-actor rate limits on Blog's /api/v1, the editor and comment posts (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/http/actor-limits.js makes one limiter per app and counts requests once req.viewer is resolved. A person… ([`21d537c`](https://github.com/OpenVibers/OpenVibe.Blog/commit/21d537c6e6b90712512916e4d7377d581ee2f646))\n- README and STATUS.json are current (roadmap WS-U task 3): Capabilities is now a level-2 section and lists the grants Blog uses elsewhere, including network.integration.github.read (changelog) and ai.run.create/ai.run.read (AI drafts)… ([`8a7f8eb`](https://github.com/OpenVibers/OpenVibe.Blog/commit/8a7f8ebe862b0e1c0bb119ee96c42f38fc0e5321))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`9f339e3`](https://github.com/OpenVibers/OpenVibe.Blog/commit/9f339e3c27abfa4445a7d52cc6c1153c4a88b5ec))\n\n## OpenVibe.Events\n\n[events.openvibe.network](https://events.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Events)\n\n- /limits.json lists the per-actor rate limits as rate_limits (roadmap WS-R task 4), so Codes' limits page shows what is enforced: every named limit the routes declared, with its numbers per caller per minute and hour and what a caller gets… ([`1c26536`](https://github.com/OpenVibers/OpenVibe.Events/commit/1c26536e94c46be26355bb4e1d48ced0cf99ff21))\n- Deliveries carry only the v2 signature (shim C-60 retired). The v1 header, X-OpenVibe-Signature, was an HMAC of the body with no timestamp and so replayable, and it is no longer sent. Checked on 2026-09-28: every consumer in production… ([`f55f7eb`](https://github.com/OpenVibers/OpenVibe.Events/commit/f55f7eb601be58220089c197f7dd2178b46d8d15))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Capabilities (the seven implemented capabilities; Events calls no service with a grant; events.usage.recorded), Security (SECURITY.md, auth, private data, egress… ([`19919ec`](https://github.com/OpenVibers/OpenVibe.Events/commit/19919ece79707eed051c3f18ab37b7fdb6d939a6))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`7c575cd`](https://github.com/OpenVibers/OpenVibe.Events/commit/7c575cd8ba545dfb7c4c53667dac7a71f77ac309))\n\n## OpenVibe.News\n\n[openvibe.news](https://openvibe.news) · [repository](https://github.com/OpenVibers/OpenVibe.News)\n\n- Per-actor rate limits on News' /api/v1, the editor desk and the comment form (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/http/actor-limits.js makes one limiter per app and counts requests once req.viewer is resolved and a… ([`8ab47a6`](https://github.com/OpenVibers/OpenVibe.News/commit/8ab47a6a78168e1b25ac07c01aeb3a0bb743bbb9))\n- README and STATUS.json are current (roadmap WS-U task 3): Capabilities is now a level-2 section and lists the grants News uses at Sources, Events, Network, Community and AI; Deploy says production deploys with sudo ovhost deploy news… ([`97dae43`](https://github.com/OpenVibers/OpenVibe.News/commit/97dae43a2d41c5528bbb4c93ff2ea7ea456203dd))\n- News's readiness has no fake green (roadmap WS-Q task 7, Shared v1.24.0). sources_pull answered ok ({ pull: 'off' }) when the pull was switched off and had never run, which verified nothing. It now reports skipped with the reason… ([`2b8bcd1`](https://github.com/OpenVibers/OpenVibe.News/commit/2b8bcd15a08a2bc3d49bfd74b2353d51b8d59277))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`cb6d79e`](https://github.com/OpenVibers/OpenVibe.News/commit/cb6d79e2a6d9c7c07ca76eb7bdb14d41c81b7278))\n\n## OpenRe.Stream\n\n[openre.stream](https://openre.stream) · [repository](https://github.com/OpenVibers/OpenRe.Stream)\n\n- Per-actor limits on the ingest API's writes (roadmap WS-R task 4; openvibe-sdk 0.11.0 -> 0.12.0 openvibe-sdk/limits). server/api/actor-limits.js counts a signed-in person's writes by subject: OPENRE_LIMITS_MINUTE / _HOUR (120 and 3000)… ([`cf423e3`](https://github.com/OpenVibers/OpenRe.Stream/commit/cf423e377878eb60e449205a670130e6febb6b07))\n- README and STATUS.json are current (roadmap WS-U task 3): a Capabilities section lists the seven openre.* capabilities and what OpenRe calls at Events, Live (live.lineage.resolve, also added to the grants list) and Media; Security notes… ([`c77ec2a`](https://github.com/OpenVibers/OpenRe.Stream/commit/c77ec2a9a1e350fb4ae1c646ec74693fae4f2fa3))\n- OpenRe's /api/ready is in the openvibe-shared/ready shape (roadmap WS-Q task 7, Shared v1.24.0). It answered { status, checks: { db: true, key: true }, … }, an ad-hoc body Network's registry could only read by HTTP status, so the status… ([`0afc069`](https://github.com/OpenVibers/OpenRe.Stream/commit/0afc0690bc45c7abce22c2df599b456e2b025c1d))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so rtmp-e2e without ffmpeg, which checks nothing and exits 0… ([`d9f4240`](https://github.com/OpenVibers/OpenRe.Stream/commit/d9f42407f66648c547c32989ecf862b0bc949b63))\n\n## OpenVibe.Wiki\n\n[openvibe.wiki](https://openvibe.wiki) · [repository](https://github.com/OpenVibers/OpenVibe.Wiki)\n\n- Security regression suites for the four classes that apply to the Wiki (roadmap WS-R task 5). test/security-crawl.js lists every route of the booted app from Express's router stack (a route added later is crawled without anyone listing… ([`1e311db`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/1e311db2baadf622bcf949b7d72fe5aa8d6db969))\n- Per-actor rate limits on Wiki's /api/v1 and its editing forms (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/http/actor-limits.js makes one limiter per app and counts requests once req.actor is resolved. A person counts as… ([`32a26ef`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/32a26ef43c5f4ac2c02c813f0ba68fda5f8cd5cf))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Capabilities (the eight implemented capabilities and the grants Wiki uses at Events, Community, Sources, Media and VIP), Security (SECURITY.md, the threat review… ([`3302540`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/3302540e8b5fdf3c07db9fce688be2f4ab8b847b))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`a81573f`](https://github.com/OpenVibers/OpenVibe.Wiki/commit/a81573f9ad37722a4d4ffc5bce36565d7d8e5096))\n\n## OpenVibe.Billing\n\n[billing.openvibe.network](https://billing.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Billing)\n\n- Per-person rate limits on Billing's money-creating routes (roadmap WS-R task 4; openvibe-sdk v0.12.0 is now a dependency). Every /api/v1 caller is a first-party service (Live, Tips, VIP) acting for many people, so… ([`80f97aa`](https://github.com/OpenVibers/OpenVibe.Billing/commit/80f97aabbecb0fcb81842480166533ff0452c8a5))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Owns, Does not own, Depends on, Capabilities (the eight billing.* capabilities, their callers, and the grants Billing uses at Events and Network), Acceptance (what… ([`f24684b`](https://github.com/OpenVibers/OpenVibe.Billing/commit/f24684bb84ec1670bd08670891e6742fa433a548))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`1f9df56`](https://github.com/OpenVibers/OpenVibe.Billing/commit/1f9df5681486992d3fa8f076ff11f22aea5f0b25))\n\n## OpenVibe.Coupons\n\n[openvibe.coupons](https://openvibe.coupons) · [repository](https://github.com/OpenVibers/OpenVibe.Coupons)\n\n- Per-actor rate limits on Coupons' /api/v1 and its page forms (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/http/actor-limits.js makes one limiter per app and counts requests once req.viewer is resolved. A person counts as… ([`64835d2`](https://github.com/OpenVibers/OpenVibe.Coupons/commit/64835d2a1c926e89116a35218d7a2d081f38b67a))\n- README and STATUS.json are current (roadmap WS-U task 3): Deploy now says production deploys with sudo ovhost deploy coupons (unit, port, env file, rollback) and keeps the first-install steps; Security points to SECURITY.md; Capabilities… ([`b91cd79`](https://github.com/OpenVibers/OpenVibe.Coupons/commit/b91cd795e8ee4a3e49317a6e3cb000fa92da9325))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`168262d`](https://github.com/OpenVibers/OpenVibe.Coupons/commit/168262d1baa81ab1973863d66d52ab213711ef81))\n\n## OpenVibe.Deals\n\n[openvibe.deals](https://openvibe.deals) · [repository](https://github.com/OpenVibers/OpenVibe.Deals)\n\n- Per-actor rate limits on Deals' /api/v1 and its page forms (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/http/actor-limits.js makes one limiter per app and counts requests once req.viewer is resolved. A person counts as… ([`fa0582d`](https://github.com/OpenVibers/OpenVibe.Deals/commit/fa0582d267ef61e7b141299008d6239dd34f49ce))\n- README and STATUS.json are current (roadmap WS-U task 3): a Capabilities section lists the twelve capabilities Deals implements and the grants it uses at Network, Events, Sources and Community; Deploy says production deploys with sudo… ([`533450f`](https://github.com/OpenVibers/OpenVibe.Deals/commit/533450f9cc4a358ba50f353f06826ec3611b4ddc))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`0bf25e2`](https://github.com/OpenVibers/OpenVibe.Deals/commit/0bf25e2e5a50e0dca1887d3545be2c95c3cd2749))\n\n## OpenVibe.Reviews\n\n[openvibe.reviews](https://openvibe.reviews) · [repository](https://github.com/OpenVibers/OpenVibe.Reviews)\n\n- Per-actor rate limits on Reviews' /api/v1 and its forms (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/http/actor-limits.js makes one limiter per app and counts requests once req.actor is resolved and a route's capability guard… ([`1cff36b`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/1cff36b8b9d385c4effb323f0506ede106b18d22))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Capabilities (the eight implemented capabilities and the grants Reviews uses at Sources, Events and Community), Security (SECURITY.md, the threat review, auth… ([`c87b344`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/c87b34440b0d50bc2cdf6c136775002ed9080c1e))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`8416fcb`](https://github.com/OpenVibers/OpenVibe.Reviews/commit/8416fcb1f0f2b1969a1261fe4ee5bf6aa3600cd2))\n\n## OpenVibe.Sources\n\n[sources.openvibe.network](https://sources.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Sources)\n\n- Per-actor rate limits on Sources' /api/v1 (roadmap WS-R task 4; openvibe-sdk v0.12.0 is now a dependency). server/api/actor-limits.js counts each request by the principal that passed the route's capability guard (req.principal.sub… ([`351383e`](https://github.com/OpenVibers/OpenVibe.Sources/commit/351383e8111395668a16f66b11d659549c6483fb))\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Capabilities (the three implemented capabilities and the events.event.publish grant Sources uses at Events), Security (service-token auth, the SSRF-guarded fetcher… ([`1670853`](https://github.com/OpenVibers/OpenVibe.Sources/commit/167085388a637eed3f0d47b3c6eabb8c9d00814d))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`6e1185e`](https://github.com/OpenVibers/OpenVibe.Sources/commit/6e1185e5c315ff3f5676b86dd3dfe6761ef82e32))\n\n## OpenVibe.Trade\n\n[openvibe.trade](https://openvibe.trade) · [repository](https://github.com/OpenVibers/OpenVibe.Trade)\n\n- Per-actor rate limits on Trade's /api/v1 and its watchlist, alert and editor forms (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/http/actor-limits.js makes one limiter per app and counts requests once req.viewer is resolved… ([`4658447`](https://github.com/OpenVibers/OpenVibe.Trade/commit/4658447782c7d259e59d8c1060fd05c60cf66574))\n- README and STATUS.json are current (roadmap WS-U task 3): a Capabilities section lists the twelve capabilities Trade implements and the grants it uses at Events and Sources; Deploy says production deploys with sudo ovhost deploy trade… ([`273bce7`](https://github.com/OpenVibers/OpenVibe.Trade/commit/273bce7b1b8771037bc2a660fa8784dc1aa049a7))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`d515e46`](https://github.com/OpenVibers/OpenVibe.Trade/commit/d515e46f7f32a6265a8e7feab49e97b9811094ed))\n\n## OpenVibe.Community\n\n[openvibe.community](https://openvibe.community) · [repository](https://github.com/OpenVibers/OpenVibe.Community)\n\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Purpose (the opening overview), Owns, Does not own, Depends on, Acceptance (what the test files prove), and Security (SECURITY.md, auth, private data, egress… ([`2da3501`](https://github.com/OpenVibers/OpenVibe.Community/commit/2da3501e28457fa4978c0bc4a1b3bfc9188b77b9))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`581d805`](https://github.com/OpenVibers/OpenVibe.Community/commit/581d80535f4bd1081afeb7a564392d4e1e5eb000))\n\n## OpenVibe.Games\n\n[openvibe.games](https://openvibe.games) · [repository](https://github.com/OpenVibers/OpenVibe.Games)\n\n- Prettier on the files the mod-principal and budget work touched (networkGrants, registry, runtime, routes' tests, revocationEvents, modLifecycleProof): formatting only, no change in behaviour. ([`b6a825d`](https://github.com/OpenVibers/OpenVibe.Games/commit/b6a825d81e3e17dade277f90d2b8a0a323681667))\n- Per-actor limits on Games' HTTP writes (roadmap WS-R task 4; openvibe-sdk 0.11.0 -> 0.12.0 openvibe-sdk/limits). apps/server/src/net/actorLimits.ts counts the capability boundaries after the caller is authorised and before the body is… ([`51d8688`](https://github.com/OpenVibers/OpenVibe.Games/commit/51d86883a1dc1fb4098866fd2426516e09e05335))\n\n## OpenVibe.Search\n\n[search.openvibe.network](https://search.openvibe.network) · [repository](https://github.com/OpenVibers/OpenVibe.Search)\n\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Security (auth, private data, loopback-only routes, egress, secrets by name) and Deploy (sudo ovhost deploy search, unit, port, env file, data path, rollback)… ([`e8511d8`](https://github.com/OpenVibers/OpenVibe.Search/commit/e8511d849720534a9ffcd54b052663111e5b1e6f))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`04f9fd4`](https://github.com/OpenVibers/OpenVibe.Search/commit/04f9fd45c3c10b401704da2994700c14290b5051))\n\n## OpenVibe.Tips\n\n[openvibe.tips](https://openvibe.tips) · [repository](https://github.com/OpenVibers/OpenVibe.Tips)\n\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Capabilities (the 18 tips.* capabilities and the grants Tips uses at Billing, Events, Network and Live) and Deploy (sudo ovhost deploy tips, unit, port, env file… ([`13986b5`](https://github.com/OpenVibers/OpenVibe.Tips/commit/13986b59e697d12a328a4f12e993295445ca40be))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`3cc8c83`](https://github.com/OpenVibers/OpenVibe.Tips/commit/3cc8c8354183008026e38a99db9ef96014663467))\n\n## OpenVibe.VIP\n\n[openvibe.vip](https://openvibe.vip) · [repository](https://github.com/OpenVibers/OpenVibe.VIP)\n\n- README and STATUS.json are current (roadmap WS-U task 3): the README gains Capabilities (the 14 vip.* capabilities and the grants VIP uses at Billing, Events and Network) and Deploy (sudo ovhost deploy vip, unit, port, env file, state… ([`95b3e19`](https://github.com/OpenVibers/OpenVibe.VIP/commit/95b3e196daa152c2e7f8e940a1f02b7fe32706ba))\n- npm test no longer counts a skipped test as passed (roadmap WS-Q task 7; openvibe-shared/test-runner, Shared v1.25.0). test/run.js counted every file that exited 0 as passed, so a file that printed that it skipped its work and checked… ([`63f46fa`](https://github.com/OpenVibers/OpenVibe.VIP/commit/63f46fa5a5ff7ccda8acb0a63ff0f64db5f7805b))\n\n## OpenVibe.Tools\n\n[openvibe.tools](https://openvibe.tools) · [repository](https://github.com/OpenVibers/OpenVibe.Tools)\n\n- Per-actor rate limits in every Tools app (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits; openvibe-tools-shared 1.2.0), only where the guard has no per-caller limit of its own. apps/_shared/actor-limits.js makes one limiter per app from… ([`e55469f`](https://github.com/OpenVibers/OpenVibe.Tools/commit/e55469f2bf9ede55f08b5fb58951a00d375595b9))\n\n---\n\nPatch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.","revision":1,"state":"published","visibility":"public","published_at":"2026-09-28T05:19:12.602Z","revised_at":"2026-09-28T05:19:12.597Z","author":{"subject":"usr_01KKT9AC60KM7CRTB3WN1Z8P56","name":"goosely","username":"goosely"},"authorship":{"mode":"imported","workflow":null,"reviewed":false,"disclosure":{"mode":"imported","short":"Imported","long":"Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers."}},"tags":["patch-notes","live","host","ai","media","network","chat","codes","blog","events","news"],"categories":[],"series":{"title":"Patch notes","url":"https://openvibe.blog/@openvibe/series/patch-notes","position":null},"media":[],"citations":[],"indexability":{"indexable":true,"robots":"index, follow","reasons":[]}}