Patch notes: Staged tables move to Chat one table at a time
Imported. Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers.
What shipped on OpenVibe from 2026-09-25 to 2026-09-26: 82 changes to OpenVibe.Network, OpenVibe.Live, OpenVibe.Games, OpenVibe.Media, OpenVibe.Tools, OpenVibe.Billing and 12 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.
Highlights
- OpenVibe.Chat: Staged tables move to Chat one table at a time (WS-I task 2, register C-04; Live d6480da): table_authority now says who writes channel_moderators, channel_moderation_settings, emotes, user_tags, chat_ai_summaries and chat_timeline_events… (
e17dbbb) - OpenVibe.Live: Staged chat tables move to OpenVibe.Chat one table at a time (WS-I task 2, register C-04): server/chat/chat-tables.js reads who writes channel_moderators, channel_moderation_settings, emotes, user_tags, chat_ai_summaries and… (
d6480da)
OpenVibe.Network
- nginx (openvibe.network): /oauth/token gets its own limit (60/min, burst 30) instead of the sign-in limit (5/min) — a developer app's client-credentials tokens got 503s mid-flow (found by the daily developer path); limits answer 429; the… (
e5da5ac) - Status: the daily developer path's last run (passed or failed, each step) on /status and in /api/v1/status, from its result file — WS-N task 1 (
dc4cfb1) - Tools job proof (WS-L task 4): principal probe gets tools.job.create/read and events.event.read; /status and /api/v1/status show its last run (tools_job_proof) next to the developer path (
5716fd6) - Moderation audit log (WS-D task 1): records tools, games, wiki, blog, news, reviews, deals, coupons, trade and codes .moderation.action (common.moderation-action@1, Contracts 0.53.0), one row each with the service from the event's prefix… (
89f3eee) - Moderation audit: media.moderation.action too (Media's staff holds), in the consumer, the subscription topics and the admin filter; contracts 0.54.0 (
ce7596b) - Site settings as revisioned configuration (WS-C task 7): network.site_settings on openvibe-shared/config 1.14.0 journals every admin change (PUT /api/admin/settings, /email, /discord) as a revision with who and why, rows keep their type (a… (
cc405d5) - Size budgets for the home page (WS-T task 1): openvibe-shared/perf-budget 1.15.0 measures / as the server answers it (a fresh database, no browser) in npm test; budgets a little above the 2026-09-26 measurement (html 88 KB, js 6 files 228… (
71cf957) - Graceful stop (WS-P lifecycle): on SIGTERM Network stops taking connections, closes idle keep-alive ones and lets requests in flight finish (10 s at most) before exiting 0; it was the one service without a handler, so every restart cut… (
d1b7323) - Graceful stop, all of it (WS-P lifecycle follow-up): SIGTERM now also stops what used to run into the exit: the maintenance timers (notifications, email queue, retired-module sweep, session cleanup), the analytics prune, the ecosystem… (
631ed6f) - Loyalty (WS-K task 9): Live reads and writes its private live.loyalty summary (contracts 0.56.0; a grant row seeded under the older default gains it at boot); test/loyalty-policy.test.js: nobody holds the OpenCoins transfer grant (revoked… (
3900cd3) - Community themes with a review queue, import and export (WS-E task 2): a submitted or imported theme is pending and private to its author (usable by them at once, at most five waiting) until an admin approves it at /api/admin/themes (Theme… (
4f28b66) - Pages the browser check flagged (Host scripts/browser-check.js, WS-Q task 3): /login gets a canonical URL, a no-JS note (the form panels need JavaScript), named password toggles ("Show password"/"Hide password", was axe button-name… (
6665245) - npm test runs test/page-checks.test.js (the browser-check fixes: /login, the /updates filter chip, the home JSON-LD name) (
dae6ab2) - Operator parity checklist (WS-D task 5): an admin tab and GET /api/admin/operator-checklist list every operator job the old admin did (people, site, health/storage/media, queues, moderation/money/loyalty, releases/readiness) and where it… (
15e4d88)
OpenVibe.Live
- Rollback with newer writes (WS-P task 13): a database this release migrated and wrote to boots and works under the release of a week ago (checked out into a temporary worktree: initDb over the newer schema without errors, reads, writes)… (
8f2b4c3) - Expand/migrate/contract check (WS-P task 12): a new DROP TABLE, DROP COLUMN or rename of a real table in server/ fails the suite until test/fixtures/destructive-migrations.json lists it with its dated contract step; the five known table… (
26c69e0) - Clip cuts follow their Media job (WS-G task 3): a clip the server cuts answers with its clip.cut job id; the channel page and the broadcast dashboard follow it (public/js/ov-clip-jobs.js) and open the trim editor or say it failed, with a… (
73c8a39) - Site settings as revisioned configuration (WS-C task 7): live.site_settings on openvibe-shared/config 1.14.0 journals every admin change to site_settings as a revision with who and why (bulk and single PUT, DELETE), rows written around it… (
c7cb628) - Search facets and autocomplete (WS-O task 10): /search shows the first page's category and channel facets with counts and narrows to one (?category=&channel=, a new query starts without them); the box suggests titles as you type (GET… (
fe1fdf9) - Search suggestions: one per type and title (many VODs share a title), the best-ranked (
fbc7846) - Staged chat tables move to OpenVibe.Chat one table at a time (WS-I task 2, register C-04): server/chat/chat-tables.js reads who writes channel_moderators, channel_moderation_settings, emotes, user_tags, chat_ai_summaries and… (
d6480da) - Loyalty summary (WS-K task 9): Live writes its private live.loyalty user module on Network: channel points across channels and the top ten by points, the Arena Trash Level and XP (loyalty, never money; contracts 0.56.0). Viewers with… (
bf06877) - What the browser check found on Live (Host scripts/browser-check.js, WS-Q task 3): /chat and /search are server-rendered with their own title and canonical (/search?q=… names /search and stays noindex; its meta existed but the route was… (
934156b) - Found by the browser check on /vod/… and /clip/… (Host scripts/browser-check.js, WS-Q task 3): the VOD, clip and channel players' volume sliders are named ("Volume"; axe label, critical), and a guest's page no longer asks… (
fcfc0d5)
OpenVibe.Games
- Moderation audit (ADR-022, WS-D task 1): games.moderation.action from the outbox in the same transaction when staff revoke (mod.revoked, with the reason and the grants it ended), disable (mod.disabled) or put back a disabled (mod.enabled)… (
28c621d) - Readiness reports the players online (WS-P task 2): a non-required sessions check with detail.online, which OpenVibe.Host's protected probe reads before a restart disconnects them (
e11dd65) - Home keeps its navigation when openvibe.network is down (WS-P task 5): a plain nav (home, Scraplandia, the network sites) shows until the shared navbar mounts, and the theme loader is deferred so a slow openvibe.network never holds the… (
ef3b2cf) - Graceful stop (WS-P lifecycle follow-up): SIGTERM used to exit synchronously, cutting every WebSocket session and HTTP request in flight and never awaiting the outbox. Now, within 10 s (the unit allows 30): stop taking connections and… (
142d4ec) - dist-types: the shutdown test's declarations (tsc --build output, as for every other test) (
45fe3fa) - Legacy import: the 12 held users re-checked 2026-09-26 (still unreachable: no linked account, disabled password markers, SSO-only Live); the 200 rows stay a documented import-hold (WS-M task 8) (
1b70b69) - Client pages name an icon: public/favicon.svg, the network's app icon in the Games colours (openvibe-shared/app-icon favicon({ site: 'games' })), linked from index, play and editor. Without it the browser asked for /favicon.ico, which… (
0f29769)
OpenVibe.Media
- H15 repair (WS-G task 7): scripts/h15-repair.js tries every copy of each object with no good copy before anything is condemned: a B2/R2 copy marked corrupt only because its size differs from the size recorded at creation (no content hash)… (
cbe1413) - Waveform and preview-sprite variants as jobs (WS-G task 13): object.waveform (PNG, showwavespic) and object.sprite (JPEG sheet from one fast seek per frame, layout in its metadata) make private asset objects recorded as the source's… (
f9c89e1) - Clip cut on media_jobs (WS-G task 3): a new clip's cut and every re-cut run as the job clip.cut (lane clips, 2 at a time, runs while recording): POST /clips and /:id/recut answer 202 with job_id for the UI to follow and reattach to… (
1337cc1) - Storage-tier policy as revisioned configuration (WS-C task 7): media.storage_tier on openvibe-shared/config 1.14.0: revision 1 imported from media_settings, PUT /tiers/settings is one validated revision (types, 1-100 percentages, interval… (
41b548e) - Moderation audit (WS-D task 1): placing or releasing a staff hold (moderation, dmca, admin, evidence) announces media.moderation.action (common.moderation-action@1) in the same transaction, the staff subject as actor when named; a… (
c90ea88) - Size budgets for the home page (WS-T task 1): openvibe-shared/perf-budget (shared 1.15.0) measures / as the server answers it on a fresh database, no browser, in npm test; budgets a little above the 2026-09-26 measurement (
37accc9) - Job fencing (WS-P lifecycle follow-up): succeed() and fail() matched status = 'running' only, with no owner token, so a worker that had lost its job (lease run out, recovery requeued it, another claim took it) could still overwrite it… (
a348ea7)
OpenVibe.Tools
- Network diagnostics family acceptance (WS-L task 6): every net tool, taken from the registry, has a tools.tool@1 entry on its own host (input and route, or a stated reason when unavailable), help content (title, description, intro… (
195e8ce) - Favourites for everyone (WS-L task 1): without an account a browser keeps its starred tools in the ov_tool_favs cookie on the tools zone (24, newest first) and they join the account's favourites once at sign-in; stars on search results as… (
db18e70) - Size budgets for the home page (WS-T task 1): openvibe-shared/perf-budget (gateway on shared 1.15.0) measures the gateway's / as it runs, no browser, in npm test; budgets a little above the 2026-09-26 measurement (html 135 KB / 19 KB… (
78b8f8f) - Graceful stop for every Tools process (WS-P lifecycle follow-up): apps/_shared/graceful.js on SIGTERM/SIGINT stops timers, pollers and the job worker first, then stops taking connections, closes idle keep-alive ones, answers requests in… (
93f0f6c) - /developers: long commands scroll inside their code blocks instead of widening the page (858 px wide at 768 px, found by the browser check, Host scripts/browser-check.js, WS-Q task 3), and each block is focusable with a visible focus ring… (
2140ef5) - Family pages' "Open …" button (.cta) is --on-accent-strong on --accent-strong (openvibe-shared 1.13.0 tokens, 4.5:1 in every theme) instead of white on --accent (3.67:1, axe color-contrast serious on /network-tools, /developer-tools… (
f0307c0) - Tool pages: the "Primary" address tag on the highlighted row is --text-primary instead of --text-muted, which read 3.16:1 on the accent glow (axe color-contrast serious on /tool/yaml and every tool page; found by the browser check, WS-Q… (
858845c)
OpenVibe.Billing
billing.openvibe.network · repository
- Public billing policy at /policy (WS-K task 10): what a viewer pays per Vibe at each tier, what a creator receives and what OpenVibe keeps, tips credited in full, subscription price, split and site-route fee, cashout minimum, hold and… (
72cf2d2) - Console test: robots.txt allows the public /policy and nothing else (
8ca3039) - Policy: the terms link goes to openvibe.network/terms (the /legal/terms path does not exist) (
2bc0cd0) - .env.example: names with a working default are commented (optional), so ovhost validate's from-example check requires only what the service cannot run without (
4a5cddf) - /policy: a canonical link (config.baseUrl + /policy) and the network's app icon inline (openvibe-shared/app-icon), so the browser no longer asks the API for /favicon.ico and logs its 404 on every visit; both found by the browser check… (
f7ff3cd) - nginx vhost: the public policy (/policy, /policy.json, /robots.txt) is served without the host-wide X-Robots-Tag noindex, as robots.txt and the app intend (the browser check found production's /policy noindex); that location repeats… (
5fa5546)
OpenVibe.Codes
- API explorer (WS-C task 6): /docs/api lists every service's OpenAPI 3.1 document from openvibe-contracts 0.51.0; /docs/api/:service shows each route with its method, capabilities, visibility, parameters, request and response schemas… (
eba81c5) - Docs: the update system (WS-A task 4) at /docs/updates: the network changelog feed and its shape (with a live sample), the data-ov-shipped markup, openvibe-shared/frame shipped()/updatesBody()/shippedScript() and openvibe-sdk/frame… (
fbe0ebe) - Moderation audit (ADR-022, WS-D task 1): codes.moderation.action from the outbox in the same transaction: release.revoked when Codes staff revoke a release their project role would not let them manage (also a staff project deletion)… (
28dbf08) - Docs: /docs/billing renders the billing policy from OpenVibe.Billing's /policy.json (WS-K task 10): currencies, purchase tiers with the creator value and what OpenVibe keeps, tips, the subscription split and fee, cashout minimum and hold… (
e86ba95) - .env.example: names with a working default are commented (optional), so ovhost validate's from-example check requires only what the service cannot run without (
237d9ff) - nginx: /auth/me, the session probe the shared navbar asks on every page view, gets its own location on the API zone (burst 30) instead of the sign-in zone (10 a minute, burst 10), and both answer 429 when limited instead of nginx's default… (
f1ddee9)
OpenVibe.Blog
- Moderation audit (ADR-022, WS-D task 1): blog.moderation.action from the outbox in the same transaction when staff unpublish (post.unpublished) or delete (post.deleted) a post only their staff powers allow, with the author as… (
ee4a607) - Size budgets for the home page (WS-T task 1): openvibe-shared/perf-budget (shared 1.15.0) measures / as the server answers it on a fresh database, no browser, in npm test; budgets a little above the 2026-09-26 measurement (
30a2b69) - .env.example: names with a working default are commented (optional), so ovhost validate's from-example check requires only what the service cannot run without (
d48688d) - Buttons and .button links are --on-accent-strong on --accent-strong (openvibe-shared 1.13.0 tokens, 4.5:1 in every theme) instead of white on --accent (3.67:1, axe color-contrast serious on the 404 page's "The OpenVibe blog" link; found by… (
b5b49d3) - nginx: /auth/me, the session probe the shared navbar asks on every page view, gets its own location on the API zone (burst 30) instead of the sign-in zone (10 a minute, burst 10), and both answer 429 when limited instead of nginx's default… (
6555217)
OpenVibe.Chat
- Staged tables move to Chat one table at a time (WS-I task 2, register C-04; Live d6480da): table_authority now says who writes channel_moderators, channel_moderation_settings, emotes, user_tags, chat_ai_summaries and chat_timeline_events… (
e17dbbb) - Online now (WS-F task 2, ADR-005 amendment 1): GET /api/chat/online?users=a,b answers online or offline for up to 50 usernames from Chat's open connections (global chat, rooms, DMs); nothing stored, no Events topic; someone hidden by… (
0b68fb6) - Chat rooms on the realtime plane (WS-I task 9, contracts 0.57.0): a message in a public room is announced as chat.room.message.created (visibility public) in the transaction that stores it; deleting one, or turning the room private… (
593513b) - nginx: /auth/me, the session probe the shared navbar asks on every page view, gets its own location on the API zone (burst 30) instead of the sign-in zone (10 a minute, burst 10), and both answer 429 when limited instead of nginx's default… (
d461fd4) - nginx: every Chat location that sets its own proxy_set_header (Connection "" for upstream keepalive) repeats Host and the client address: /auth/me, /auth/, /api/ and / had lost the server-level ones, so REST requests reached Chat as… (
b2d329a)
OpenVibe.Community
openvibe.community · repository
- Size budgets for the home page (WS-T task 1): openvibe-shared/perf-budget (shared 1.15.0) measures / as the server answers it on a fresh database, no browser, in npm test; budgets a little above the 2026-09-26 measurement (
5bf0400) - Graceful stop (WS-P lifecycle follow-up): SIGTERM used to close only the HTTP server (which waited on 65 s keep-alive connections until the 5 s fallback) while the events outbox, the Discord relay, the Pulse subscription retries and the… (
fc7aaf6) - Breadcrumb links are underlined: in the muted crumb line they were told apart by colour alone (axe link-in-text-block, serious, on /pulse, /s and every paste and thread page; found by the browser check, Host scripts/browser-check.js, WS-Q… (
4072708) - nginx: /auth/me, the session probe the shared navbar asks on every page view, gets its own location on the API zone (burst 30) instead of the sign-in zone (10 a minute, burst 10), and both answer 429 when limited instead of nginx's default… (
eb68e9e)
OpenVibe.AI
ai.openvibe.network · repository
- Graceful stop stops the ai.run.* relay (WS-P lifecycle follow-up): close() (SIGTERM) now, after runs.drain() has queued the last run events, stops the events outbox and awaits its send in progress (events.stop(); unsent rows stay for the… (
dc75e16) - Citations or explicit gaps on every run (WS-O task 3): each run records grounding { cited, gaps }: the source ordinals its output cites, and the gaps it names; an output that cites nothing and names no gap gets one written for it (no… (
5451f85)
OpenVibe.Deals
- Moderation audit (ADR-022, WS-D task 1): deals.moderation.action from the outbox in the same transaction when a moderator edits, expires, disables, enables, reviews, merges or unmerges someone else's offer (offer.*, the submitter as… (
98999bf) - .env.example: names with a working default are commented (optional), so ovhost validate's from-example check requires only what the service cannot run without (
68537be)
OpenVibe.Wiki
- Size budgets for the home page (WS-T task 1): openvibe-shared/perf-budget (shared 1.15.0) measures / as the server answers it on a fresh database, no browser, in npm test; budgets a little above the 2026-09-26 measurement (
b793836) - nginx: /auth/me, the session probe the shared navbar asks on every page view, gets its own location on the API zone (burst 30) instead of the sign-in zone (10 a minute, burst 10), and both answer 429 when limited instead of nginx's default… (
a8362b9)
OpenVibe.Coupons
- Moderation audit (ADR-022, WS-D task 1): coupons.moderation.action from the outbox in the same transaction when staff or a staff-capable service disables, expires, re-enables (coupon.disabled|expired|enabled, the note as reason) or… (
f86f660)
OpenVibe.News
- .env.example: names with a working default are commented (optional), so ovhost validate's from-example check requires only what the service cannot run without (
8103b67)
OpenVibe.Search
search.openvibe.network · repository
- The front page and /updates carry a canonical URL on the configured origin (config.baseUrl, passed to pageRouter); result pages stay noindex without one. The browser check (Host scripts/browser-check.js, WS-Q task 3) found the indexable… (
99f1e76)
OpenVibe.Tips
- .env.example: names with a working default are commented (optional), so ovhost validate's from-example check requires only what the service cannot run without (
1cfee92)
OpenVibe.VIP
- .env.example: names with a working default are commented (optional), so ovhost validate's from-example check requires only what the service cannot run without (
ad49965)
Patch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.
Comments
Comments could not be loaded from OpenVibe.Community right now. Reload later.