@karmaniverous/jeeves-server
    Preparing search index...

    Changelog

    All notable changes to this project will be documented in this file.

    • [271] fix(service): address review on insider scope enforcement (#271)

    Copilot review:

    • Propagate key scopes: verifyKey/resolveKeyAuth now return the matched key's (or issuing insider's) scopes and the middleware sets request.insiderScopes on key auth, so scoped machine insider keys get filtered archives and listings, and outsider directory shares hide entries outside the issuer's scopes.
    • Directory archive size limit counts only in-scope files (getDirSize takes an optional file filter), so denied content can neither block an export with 413 nor leak its size.
    • Split fileContent.ts (430 lines) into fileContent (GET), fileWrite (PUT) and fileRender (watcher proxy + Markdown pipeline).

    SOLID/DRY:

    • contentRoute.ts owns URL -> content path mapping; the middleware's string replace chain is gone. Key auth for /api/mermaid-export, /api/plantuml-export and /api/link-info is now verified against the content path, so share keys work there as documented (previously rejected).
    • scopeAccess.ts holds pure scope decisions; scopeGuard.ts the shared 403 response used by every route-level check.
    • archiveExport.ts owns directory archive export.
    • Middleware split into authenticateUtility / resolveUrlKey helpers.

    Tests: 494 -> 568 service tests. New route tests for archive export, file write, file content, file render, link info scope, share route, getDirSize, key scope propagation. Removed sharing tests that exercised an inline copy of the code; merged duplicate export format tests.

    Docs: scope enforcement in sharing/api-integration/exports guides, access decision flow diagram, plugin skill; fix scope examples that used /* (direct children only) where /** was meant; fix /api/path and /api/share body in the API reference.

    • [261] updated jeeves-core
    • Updated core
    • Release @karmaniverous/jeeves-server-openclaw v0.14.0
    • [261] chore(deps): pin @karmaniverous/jeeves 0.6.0-9
    • [261] updated core
    • [261] chore: release @karmaniverous/jeeves-server-openclaw v0.14.0-3
    • [261] chore(deps): pin @karmaniverous/jeeves 0.6.0-8
    • [261] updated core
    • [261] chore: release @karmaniverous/jeeves-server-openclaw v0.14.0-2
    • [261] fix(openclaw): accurate configRoot-unset startup warning (#266)
    • [261] chore(release): prettier-format openclaw.plugin.json after bump
    • [261] chore(deps): pin @karmaniverous/jeeves 0.6.0-7
    • [261] updated core
    • [261] [267] fix: tests and typecheck read core and CLI from source, not dist

    Service and openclaw vitest configs alias @karmaniverous/jeeves-server-core to packages/core/src, and their tsconfigs map it with paths, so typecheck and tests pass on a clean checkout with no dist/. The rollup builds override paths: {} and still build against the built core package. Service rootDir and outDir move to tsconfig.build.json (TS 6 rejects source outside rootDir).

    The config CLI test runs src/cli/index.ts through tsx instead of dist/src/cli/index.js.

    Source resolution exposes core's @deprecated mermaidCliPath, so the ignored field is no longer copied into RuntimeConfig.

    Closes #267

    • [261] fix: update root package-lock.json in release-it after:bump hook
    • [261] chore: release @karmaniverous/jeeves-server-openclaw v0.14.0-1
    • [261] feat(openclaw)!: standard OpenClaw plugin on jeeves core 0.6.0 with lazy configRoot

    Move the plugin (and jeeves-server-core) to @karmaniverous/jeeves@0.6.0-3, the static-content core (karmaniverous/jeeves#109).

    • Remove the ComponentWriter / TOOLS.md "## Server" section, the async status-menu cache (promptInjection) and the createPluginCli-based install/uninstall bin. jeeves install installs the plugin with openclaw plugins install and writes its config.
    • Resolve configRoot lazily (plugin config, then JEEVES_CONFIG_ROOT) when a tool runs. register() always succeeds, logs one warning when configRoot is unset, and defers core init() to first use. Tools invoked without it return a clear error naming both ways to set it. publicUrl is read per call.
    • Manifest: configRoot/pluginKey descriptions; configRoot has no default and is not required. SKILL.md gains name/description frontmatter (#260) and jeeves install instructions.
    • Tests: registration without config, tool error, plugin config / OpenClaw config entry / env var, late config, lazy publicUrl, no conversation hooks, manifest and skill frontmatter checks.

    BREAKING CHANGE: the jeeves-server-openclaw install|uninstall CLI is gone; install with jeeves install server (or openclaw plugins install). The plugin no longer writes TOOLS.md; use server_status and the skill.

    Closes #261 Closes #263 Closes #260

    • [261] chore(openclaw): update rollup, @rollup/plugin-commonjs and zod minors
    • [261] chore(deps): ncu -u --peer across all packages
    • [261] chore: resolve knip findings and audit advisories (lodash-es override)
    • [261] chore: apply prettier across the repo; ignore generated CHANGELOGs
    • [261] fix(openclaw): gate only tools that read configRoot
    • [261] feat(openclaw): pass lazy apiUrl to createPluginToolset; pin core 0.6.0-4
    • [261] test(openclaw): merge duplicate HTTP-tool configRoot tests
    • [261] chore(deps): pin @karmaniverous/jeeves 0.6.0-6
    • [261] fix(release): use --github.preRelease for release-it 21
    • [261] updated core
    • [261] chore: release @karmaniverous/jeeves-server-openclaw v0.14.0-0
    • Sync guides, skill, and API reference with #241 tar format, #252 OTP flow, #253 auth gate
    • Release @karmaniverous/jeeves-server-openclaw v0.13.0
    • [SERVER-312] fix: remove hardcoded j:/config fallback for configRoot (#244)
    • [SERVER-312] fix: replace hardcoded j/ drive prefix in tool examples (#246)
    • [SERVER-312] fix: require auth for server_resolve_path plugin tool (#247)
    • [SERVER-312] fix: make resolve-path endpoint unauthenticated (#247)
    • [SERVER-312] fix: remove publicUrl from plugin config, make eventQueueConcurrency configurable (#245, #247)
    • [SERVER-312] docs: update guides for eventQueue, eventQueueConcurrency, publicUrl, server_resolve_path (#244, #245, #246, #247)
    • [SERVER-312] refactor: extract resolveEventPaths helper, add skipAuth to ApiToolConfig (#245, #247)
    • [SERVER-312] docs: sync skill, guides, and config reference with touched code (#244, #245, #246, #247)
    • Updated core
    • Release @karmaniverous/jeeves-server-openclaw v0.12.0
    • Updated core
    • Release @karmaniverous/jeeves-server-openclaw v0.11.1
    • Updated core
    • Update guides, README, and skill for magic link auth and branding
    • Fix stale auth references in setup, SKILL, and api-integration guides
    • Release @karmaniverous/jeeves-server-openclaw v0.11.0
    • Updated core
    • Sync SKILL.md and api-integration guide with touched code
    • Release @karmaniverous/jeeves-server-openclaw v0.10.8
    • (openclaw) Externalize @karmaniverous/jeeves in rollup config (closes #224)
    • Updated deps
    • (openclaw) Use builtinModules and shared external array per review
    • Release @karmaniverous/jeeves-server-openclaw v0.10.7
    • Updated core
    • Update dependencies via ncu --peer
    • Release @karmaniverous/jeeves-server-openclaw v0.10.6
    • Pin jeeves-server-core dependency to ^0.1.2
    • Release @karmaniverous/jeeves-server-openclaw v0.10.5
    • Add contracts.tools to openclaw.plugin.json (#203)
    • Add npm publish safety net (.npmignore + gitignore *.local)
    • Switch from auto-changelog to git-cliff
    • Bump @karmaniverous/jeeves to ^0.5.10
    • Apply safe dependency updates
    • Release @karmaniverous/jeeves-server-openclaw v0.10.4
    • Updated jeeves-core
    • Release @karmaniverous/jeeves-server-openclaw v0.10.3
    • Create shared package, add missing plugin tools, DRY types (#194)
    • Address PR review โ€” URL encoding, rawUrl regression, lockfile sync
    • Rename shared package to @karmaniverous/jeeves-server-core
    • Sync all documentation with current implementation
    • Release @karmaniverous/jeeves-server-openclaw v0.10.2
    • Updated jeeves core
    • Release @karmaniverous/jeeves-server-openclaw v0.10.1
    • Markdown-it migration, block editing, OAuth2 flow (#162, #163)
    • Resolve all pre-existing eslint errors
    • Release @karmaniverous/jeeves-server-openclaw v0.10.0
    • Updated jeeves-core
    • Release @karmaniverous/jeeves-server-openclaw v0.9.1
    • [V3-7] feat: add publicUrl config for shareable URL rewriting (#145)

    When publicUrl is configured in the plugin, all URLs returned to tool callers are rewritten to use the public domain instead of the local bind address. When absent, URLs pass through unchanged (dev behavior).

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] feat: update TOOLS guidance to note automatic URL rewriting (#152)

    Remove the need for manual loopback URL rewriting instructions. Add a note that server tools automatically rewrite URLs when publicUrl is configured.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] chore: bump versions (service 3.7.0, openclaw 0.8.0)

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] refactor: SOLID/DRY pass across v3.7.0 changes

    • Remove eslint-disable comments in events.ts and fileContent.ts by using non-async plugin pattern (matching toggleCheckbox.ts convention)

    • Eliminate redundant handleText branches (rawOnly and non-rawOnly produced identical output)

    • Extract magic number 86400000 to named MS_PER_DAY constant

    • Optimize rewriteUrlsInData to pre-compute both origins instead of re-parsing URLs on every string match

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] test: improve coverage and remove trivial tests

    Add missing edge-case tests for events route (limit clamping, non-numeric input, negative values), serverTools URL rewriting (HTTPS with port, port-mismatch non-rewrite), and toggleCheckbox (content preservation, multi-checkbox targeting). No trivial tests found to remove.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] docs: sync documentation with v3.7.0 implementation

    Add publicUrl config to all doc surfaces (SKILL.md, openclaw-integration.md, README). Document checkbox toggling capability in TOOLS.md injection and SKILL.md. Add v3.7.0 and v0.8.0 CHANGELOG entries. Fix prettier formatting in toggleCheckbox test.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] fix: address Gemini review โ€” URL boundary, checkbox regex, Cheerio, race condition

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] fix: toggle-checkbox route wildcard position (CI fix)

    Move wildcard from middle of route path to end: POST /api/file//toggle-checkbox โ†’ POST /api/toggle-checkbox/. Fastify's find-my-way router requires wildcards to be the last character in the route.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • Release @karmaniverous/jeeves-server-openclaw v0.9.0
    • Release @karmaniverous/jeeves-server-openclaw v0.7.5
    • Unhoisted jeeves
    • Release @karmaniverous/jeeves-server-openclaw v0.7.4
    • Hoisted jeeves
    • Release @karmaniverous/jeeves-server-openclaw v0.7.3
    • [150] fix: consume core importMetaUrl for plugin install (#150)

    Fixes #150. Also closes #147.

    • Bump @karmaniverous/jeeves to ^0.5.4 in both packages
    • Replace distDir with importMetaUrl in plugin CLI
    • Remove unused node:path and node:url imports from cli.ts
    • Release @karmaniverous/jeeves-server-openclaw v0.7.2
    • Update @karmaniverous/jeeves to ^0.5.3 and bump minor/patch deps
    • Release @karmaniverous/jeeves-server-openclaw v0.7.1
    • [360] feat: Phase 1 โ€” core service adoption (getServiceUrl, getBindAddress, Node 22 fast-fail)

    • Bump @karmaniverous/jeeves to ^0.5.1 in both packages

    • Set engines.node to >=22 in all package.json files

    • Add runtime Node version fast-fail guard in CLI and start-server entry points

    • Replace bespoke watcherUrl, runnerUrl, metaUrl config properties with getServiceUrl() from core

    • Replace bespoke host config property with getBindAddress() from core

    • Fix hardcoded 127.0.0.1 in export route โ€” now uses resolved bind address

    • Add config migration: deprecated properties stripped with deprecation warnings

    • Update all call sites (runner proxy, search, fileContent, auth-status, status, export)

    • Update RuntimeConfig type and buildRuntimeConfig to remove deprecated fields

    • Wire init() in descriptor.run() and start-server.ts for core service resolution

    • Update all test files for new types and mock getServiceUrl/fetch

    Closes #135, #141, #142, #143, #145

    • [360] feat: Phase 2 โ€” core v0.5.1 wiring (cleanup escalation, getPackageVersion, substituteEnvVars TODO)

    • Wire gatewayUrl cleanup escalation in plugin via loadWorkspaceConfig()

    • Replace bespoke packageVersion.ts with core getPackageVersion(import.meta.url)

    • Add TODO comment to substituteEnvVars.ts (core does not export it yet)

    • Update onConfigApply signature to accept config argument (Task 7)

    • [360] docs: Phase 4 โ€” documentation updates for v3.6.0

    • Update SKILL.md: Node 22+, CSV rendering, directory counts, collapsible features, core service discovery

    • Update setup guide: remove deprecated config properties, add core service discovery guidance

    • Update README: Node 22+, add CSV and collapsible features to highlights

    • Review promptInjection.ts: no changes needed (status shape unchanged)

    • Release @karmaniverous/jeeves-server-openclaw v0.7.0
    • [53] chore: bump core to v0.4.6 (init before run) + fix knip issues
    • [53] chore: bump core to v0.4.6 (init before run) + fix knip issues
    • Release @karmaniverous/jeeves-server-openclaw v0.6.2
    • [51] feat: integrate descriptor.run from core v0.4.5
    • Release @karmaniverous/jeeves-server-openclaw v0.6.1
    • [35] fix: use static bind default, bump openclaw core dep, remove local stub
    • [35] fix: add missing dirs param to server_share plugin tool (#99, #87)

    The server_share tool was missing the dirs parameter that the POST /api/share endpoint accepts. Added dirs to tool parameters and buildRequest body.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] refactor: migrate openclaw plugin to core v0.4.4 SDK

    Remove hand-rolled serviceCommands/pluginRemove in favor of core's createServiceManager and createPluginCli. Rewrite cli.ts to delegate to createPluginCli factory. Update index.ts to construct a full JeevesComponentDescriptor for createComponentWriter.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] fix: resolve lint errors from core v0.4.4 migration
    • [35] refactor: adopt createPluginToolset, health-nested status, event endpoint (#87, #112, #118, #128)
    • [35] refactor: remove Connected Services from TOOLS.md writer (closes #128)
    • [35] docs: sync documentation with SDK adoption changes
    • [35] docs: add title front matter to all guides
    • Release @karmaniverous/jeeves-server-openclaw v0.6.0
    • Release @karmaniverous/jeeves-server-openclaw v0.5.1
    • [117] feat: bump core to v0.3.0 and consolidate status endpoint (#117)
    • [117] refactor(openclaw): use resolveOptionalPluginSetting for getPluginKey (#112)
    • Release @karmaniverous/jeeves-server-openclaw v0.5.0
    • [113] feat: add host bind and metaUrl config options
    • Release @karmaniverous/jeeves-server-openclaw v0.4.1
    • Core v0.2.0 SDK adoption (#111) (#111)
    • Release @karmaniverous/jeeves-server-openclaw v0.4.0
    • (openclaw) Adopt jeeves core component writer
    • Add tagPrefix to auto-changelog config for monorepo tags
    • (openclaw) Derive plugin version from package.json at runtime
    • (openclaw) Address Gemini review โ€” error handling and writer cleanup
    • (openclaw) Bundle @karmaniverous/jeeves into plugin dist
    • (openclaw) Use createAsyncContentCache from jeeves v0.1.1
    • (openclaw) Resolve SOLID/DRY violations
    • Full documentation pass with PlantUML diagrams
    • Fix diagram image paths in guides
    • (openclaw) Cover service commands
    • (openclaw) Expand coverage for openclawPaths, pluginRemove, serviceCommands
    • (openclaw) Update deps, clean knip config
    • (openclaw) Update @karmaniverous/jeeves to 0.1.3
    • (openclaw) Use resolveWorkspacePath from jeeves 0.1.4
    • (openclaw) Update @karmaniverous/jeeves to 0.1.5
    • (openclaw) Update jeeves to 0.1.6, add servicePackage/pluginPackage
    • Release @karmaniverous/jeeves-server-openclaw v0.3.1
    • Release @karmaniverous/jeeves-server-openclaw v0.3.0
    • Document scope override precedence in OpenClaw skill
    • Release @karmaniverous/jeeves-server-openclaw v0.2.1
    • Search facets, metadata chips, and click-to-filter
    • Server_share sends POST with JSON body instead of GET (#87)
    • Server_browse and server_export route mismatches
    • Document ?events=N query param on /api/status
    • Release @karmaniverous/jeeves-server-openclaw v0.2.0
    • Updated docs
    • Refresh README and guides for v3 CLI + config
    • Add changelogs as children of package guide indexes
    • Add guide index content and fix typedoc trailing comma
    • Release @karmaniverous/jeeves-server-openclaw v0.1.1
    • Release @karmaniverous/jeeves-server-openclaw v0.1.0
    • Plugin auth chain, status endpoint improvements (#83) (#83)
    • Remove unnecessary auth from /api/status calls (endpoint is public)
    • Add pattern to StatusResponse events type
    • Lintfix
    • Add knip configs, remove dead exports, clean all code quality checks
    • Release @karmaniverous/jeeves-server-openclaw v0.1.0-1
    • Implement OpenClaw plugin (Phase 3, Steps 11-15)
    • Address Gemini code review feedback across PRs #65-#76
    • Address all gap analysis findings
    • Resolve TS2352 warnings in openclaw test mocks
    • Incorporate main (PR #77 gap-analysis)
    • Zero version
    • Monorepo scaffolding (Phase 1, Step 1)
    • Add tsdoc.json to both package roots
    • Add tsdoc.json to both package roots
    • Eliminate all lint warnings
    • SOLID/DRY pass #3 + plugin test coverage
    • Make both packages releasable
    • Release @karmaniverous/jeeves-server-openclaw v0.1.0-0