@karmaniverous/jeeves-server
    Preparing search index...

    Changelog

    All notable changes to this project will be documented in this file.

    • [271] fix(service): enforce insider scopes for session-authenticated requests (#271)

    The API auth middleware accepted Google-session insiders on every content route without checking their scopes, so scoped insiders could read, export and overwrite files outside scope. /api/drives was unfiltered.

    • Enforce session insider scopes in the middleware for all content routes (path, file, raw, export, export-cache, mermaid/plantuml export, link-info). Navigation routes allow ancestors of in-scope paths; content routes require the path itself. Out-of-scope requests return 403, or fall back to a valid key on the URL.

    • Reject '..' path segments on content routes (400).

    • Filter /api/drives to navigable roots; refuse out-of-scope file metadata on /api/path and /api/link-info.

    • Defence in depth on PUT/POST /api/file and POST /api/share; filter archive export entries by scope.

    • Replace prefix-based directory visibility with segment-wise glob matching so wildcard scopes (e.g. jeeves-*/**) show their directories.

    Closes #271

    • [271] fix(service): address review on insider scope enforcement (#271)

    Copilot review:

    • Propagate key scopes: verifyKey/resolveKeyAuth now return the matched key's (or issuing insider's) scopes and the middleware sets request.insiderScopes on key auth, so scoped machine insider keys get filtered archives and listings, and outsider directory shares hide entries outside the issuer's scopes.
    • Directory archive size limit counts only in-scope files (getDirSize takes an optional file filter), so denied content can neither block an export with 413 nor leak its size.
    • Split fileContent.ts (430 lines) into fileContent (GET), fileWrite (PUT) and fileRender (watcher proxy + Markdown pipeline).

    SOLID/DRY:

    • contentRoute.ts owns URL -> content path mapping; the middleware's string replace chain is gone. Key auth for /api/mermaid-export, /api/plantuml-export and /api/link-info is now verified against the content path, so share keys work there as documented (previously rejected).
    • scopeAccess.ts holds pure scope decisions; scopeGuard.ts the shared 403 response used by every route-level check.
    • archiveExport.ts owns directory archive export.
    • Middleware split into authenticateUtility / resolveUrlKey helpers.

    Tests: 494 -> 568 service tests. New route tests for archive export, file write, file content, file render, link info scope, share route, getDirSize, key scope propagation. Removed sharing tests that exercised an inline copy of the code; merged duplicate export format tests.

    Docs: scope enforcement in sharing/api-integration/exports guides, access decision flow diagram, plugin skill; fix scope examples that used /* (direct children only) where /** was meant; fix /api/path and /api/share body in the API reference.

    • [261] updated jeeves-core
    • Updated core
    • Release @karmaniverous/jeeves-server v3.14.0
    • [261] chore(deps): pin @karmaniverous/jeeves 0.6.0-9
    • [261] updated core
    • [261] chore: release @karmaniverous/jeeves-server v3.14.0-2
    • [261] [267] fix: tests and typecheck read core and CLI from source, not dist

    Service and openclaw vitest configs alias @karmaniverous/jeeves-server-core to packages/core/src, and their tsconfigs map it with paths, so typecheck and tests pass on a clean checkout with no dist/. The rollup builds override paths: {} and still build against the built core package. Service rootDir and outDir move to tsconfig.build.json (TS 6 rejects source outside rootDir).

    The config CLI test runs src/cli/index.ts through tsx instead of dist/src/cli/index.js.

    Source resolution exposes core's @deprecated mermaidCliPath, so the ignored field is no longer copied into RuntimeConfig.

    Closes #267

    • [261] fix: update root package-lock.json in release-it after:bump hook
    • [261] chore(deps): pin @karmaniverous/jeeves 0.6.0-8
    • [261] updated core
    • [261] chore: release @karmaniverous/jeeves-server v3.14.0-1
    • [261] chore(deps): ncu -u --peer across all packages
    • [261] fix: adapt to puppeteer 25, archiver 8, markdown-it 15 and TypeScript 6 majors
    • [261] chore: resolve knip findings and audit advisories (lodash-es override)
    • [261] chore: apply prettier across the repo; ignore generated CHANGELOGs
    • [261] fix(build): clear vite native-config, chunk-size and rollup outputToFilesystem warnings
    • [261] chore: move every package to @karmaniverous/jeeves 0.6.0-4; allow install scripts by name
    • [261] chore(deps): pin @karmaniverous/jeeves 0.6.0-6
    • [261] fix(release): use --github.preRelease for release-it 21
    • [261] updated core
    • [261] fix(service): merge server_config_apply patches into the runtime config file (#265)
    • [261] chore(deps): pin @karmaniverous/jeeves 0.6.0-7
    • [261] updated core
    • [261] chore: release @karmaniverous/jeeves-server v3.14.0-0
    • SPA auth gate path prefix for share keys
    • Release @karmaniverous/jeeves-server v3.13.1
    • (#252) Self-validating signed token, delete magicLinkState
    • (#252) OTP generation, AES-256-GCM encryption, email template
    • (#252) Verification page, magicVerify route, sign-in redirect
    • (#253) Server-side auth gate in SPA fallback handler
    • (#241) Fix zero-byte ZIP export and add tar format for directories
    • Address copilot review - returnTo type guard, archive error logging, aria-labels, outsider docs
    • (#253) Remove client-side AuthGate, replace with AuthStatusProvider
    • Extract shared page shell (DRY pass - signInPage, verifyPage, pageShell)
    • Sync guides, skill, and API reference with #241 tar format, #252 OTP flow, #253 auth gate
    • Add magicToken + pageShell tests, replace trivial export/verifyPage tests
    • Dependency audit - update minor/patch deps (prettier, eslint, rollup, tailwindcss)
    • Release @karmaniverous/jeeves-server v3.13.0
    • Encode URL path segments in resolve-path API response
    • Release @karmaniverous/jeeves-server v3.12.2
    • [SERVER-312] fix: resolve-path route must use /api/ prefix to match middleware bypass and meta caller
    • Release @karmaniverous/jeeves-server v3.12.1
    • [SERVER-312] fix: prevent overlapping event queue batches, add eventQueue config (#245)
    • [SERVER-312] feat: expose resolve-path API endpoint, add publicUrl to server config (#247)
    • [SERVER-312] fix: make resolve-path endpoint unauthenticated (#247)
    • [SERVER-312] fix: remove publicUrl from plugin config, make eventQueueConcurrency configurable (#245, #247)
    • [SERVER-312] docs: update guides for eventQueue, eventQueueConcurrency, publicUrl, server_resolve_path (#244, #245, #246, #247)
    • [SERVER-312] refactor: extract resolveEventPaths helper, add skipAuth to ApiToolConfig (#245, #247)
    • [SERVER-312] test: replace trivial eventQueue tests, add resolve-path and config path resolution coverage (#244, #245, #247)
    • [SERVER-312] docs: sync skill, guides, and config reference with touched code (#244, #245, #246, #247)
    • [SERVER-312] fix: address Copilot review โ€” drainLoop error handling, resolve-path 404/400, absolute path validation, stale cursor recovery (#245, #247)
    • Updated core
    • Release @karmaniverous/jeeves-server v3.12.0
    • [README-404] fix: include guides/ in package files (fixes /readme 404)
    • Release @karmaniverous/jeeves-server v3.11.4
    • [ISSUE-239] feat: dynamic favicon from config

    Fixes #239. Also resolves lingering knip errors for unlisted and unused dependencies.

    • [ISSUE-239] fix: restore accidentally deleted types in types.ts
    • [ISSUE-239] fix: use correct versions for updated dependencies
    • Lintfix
    • Release @karmaniverous/jeeves-server v3.11.3
    • Unified code block toolbar with word-wrap toggle and copy button
    • Update README, user guide, and spec for unified code block toolbar
    • Release @karmaniverous/jeeves-server v3.11.2
    • SPA sign-in, public content routes, magic link, URL encoding, dark mode
    • Address Copilot review โ€” XSS, open redirect, async I/O, React anti-patterns
    • Resolve lint warnings โ€” tsdoc escaping, restore eslint-disable, setState anti-pattern
    • Updated core
    • Replace all FastifyPluginAsync eslint-disables with FastifyPluginCallback
    • Release @karmaniverous/jeeves-server v3.11.1
    • Expand config schema for magic link auth and instance branding
    • Surface branding in /status, redact emailAuth in /config
    • Add branding context and wire into App and Header
    • Add mailer service for magic link auth (nodemailer + handlebars)
    • Magic link backend routes + token state + transport init
    • Redesign sign-in page with email magic link form and branding support
    • Address Copilot PR review comments on magic-link-branding
    • Resolve lint errors (prettier, deprecated z.email, unnecessary optionals, async mocks)
    • Only show auth buttons for fully configured modes (getEffectiveAuthModes)
    • Updated core
    • SOLID/DRY pass - generic TTL map, DEFAULT_BRANDING, setSessionCookie, renderErrorPage, export DEFAULT_TEMPLATE
    • Update guides, README, and skill for magic link auth and branding
    • Fix stale auth references in setup, SKILL, and api-integration guides
    • Add ttlStateMap, errorPage tests; improve email tests with mock transport
    • Release @karmaniverous/jeeves-server v3.11.0
    • Address Copilot review and CI smoke test failures
    • [211] fix: show edit button on rendered tab for insiders (#211)
    • [213] feat: add logging.level and logging.file config support (#213)
    • [214] feat: auth-gated SPA fallback with branded sign-in page (#214)
    • Updated core
    • DRY deep-share param extraction, remove redundant nullish coalescing
    • Sync README, guides, and core exports with touched code
    • Sync SKILL.md and api-integration guide with touched code
    • Add tests for extractDeepParams and sanitizeReturnTo, consolidate signInPage tests
    • Add zod direct dependency, remove stale package-directory
    • Release @karmaniverous/jeeves-server v3.10.15
    • Updated deps
    • Release @karmaniverous/jeeves-server v3.10.14
    • Add content/ to service package files field
    • Background-cache service health checks in /status (#177)
    • Scope refresh timer and add error handling per review
    • Release @karmaniverous/jeeves-server v3.10.13
    • [220] fix: thread auth key through Puppeteer export for raw image resolution (#220)
    • [220] fix: restrict auth key interception to local origin
    • Merge remote-tracking branch 'origin/bugfix/220-raw-image-export-auth' into chore/ncu-update-and-hoist-144
    • Updated core
    • Use substituteEnvVars from @karmaniverous/jeeves core (#144)
    • Update dependencies via ncu --peer
    • Release @karmaniverous/jeeves-server v3.10.12
    • Strip fragment from href before resolving deep share link target path
    • Use strict undefined check for empty fragment preservation
    • Release @karmaniverous/jeeves-server v3.10.11
    • Pin jeeves-server-core dependency to ^0.1.2
    • Release @karmaniverous/jeeves-server v3.10.10
    • Export config Zod schema via core package (#204)
    • Resolve lint errors in export ordering and stale disable directive
    • Remove unused zod dependency from service package
    • Bump @karmaniverous/jeeves to ^0.5.10
    • Apply safe dependency updates
    • Fix knip configuration hints
    • Update all deps and migrate core/service to rollup+ts builds
    • Merge main into branch, resolve package.json conflicts
    • Release @karmaniverous/jeeves-server v3.10.9
    • Include scripts/ in service package files for postinstall
    • Merge remote-tracking branch 'origin/main' into chore/git-cliff-changelogs

    Conflicts:

    packages/service/package.json

    • Release @karmaniverous/jeeves-server v3.10.8
    • Edit-cell line offset โ€” resolve td/th to table, not tr
    • Add npm publish safety net (.npmignore + gitignore *.local)
    • Add files whitelists and npm-pack-check CI workflow
    • Switch from auto-changelog to git-cliff
    • Release @karmaniverous/jeeves-server v3.10.7
    • Updated jeeves-core
    • Release @karmaniverous/jeeves-server v3.10.6
    • Mobile checkbox interaction โ€” use removeAttribute + event delegation
    • Resolve lint errors in MarkdownView scroll preservation
    • Use scroll listener for scroll preservation per review
    • Move enableCheckboxes to useLayoutEffect per review
    • Release @karmaniverous/jeeves-server v3.10.5
    • Create shared package, add missing plugin tools, DRY types (#194)
    • Resolve pre-existing knip failures
    • Upgrade client eslint to v10, fix lint errors from stricter rules
    • Rename shared package to @karmaniverous/jeeves-server-core
    • Sync all documentation with current implementation
    • Release @karmaniverous/jeeves-server v3.10.4
    • Add copy button to table cell hover controls (#188)
    • Add /api prefix to OAuth API routes (#190)
    • Guard navigator.clipboard before writeText calls
    • Resolve state.json from state root instead of package directory (#185)
    • Use path.dirname/basename for state dir resolution
    • Remove state.json and dead keyRotatedAt code (#192)
    • Updated jeeves core
    • Release @karmaniverous/jeeves-server v3.10.3
    • Store insider seeds in config.json instead of state.json (#185)
    • Release @karmaniverous/jeeves-server v3.10.2
    • Authenticate embedded images for all outsider shares (#183)
    • Release @karmaniverous/jeeves-server v3.10.1
    • /go/:slug shortlink redirects (#180)
    • Resolve serverRoot via package.json discovery (#178)
    • Release @karmaniverous/jeeves-server v3.10.0
    • Markdown-it migration, block editing, OAuth2 flow (#162, #163)
    • Cell edit popup textarea
    • Block type label in edit popup
    • Client-side undo/redo stack
    • Resolve remaining React lint errors
    • Resolve all pre-existing eslint errors
    • Address Gemini review โ€” undo correctness, reactivity, DRY, cleanup
    • Preserve source mapping on diagrams and HTML blocks for block editing (#167)
    • Constrain edit popup height to prevent overflow (#168)
    • Address Gemini review โ€” remove redundant variable, handle indented HTML blocks (#168)
    • Resolve built client dir when running under tsx (#170)
    • Address Gemini review โ€” env vars, path-based detection, cross-platform docs (#170)
    • Exclude dist/src from source-mode detection to fix CI smoke tests (#170)
    • Add line wrapping and contained positioning to popup CodeEditor (#172)
    • Unify cell/block editor, pure flex height chain, SOLID/DRY cleanup (#172)
    • Ctrl+Enter save keybinding โ€” use Prec.highest to override basicSetup (#175)
    • Move undo/redo to header, preserve scroll on save (#174, #176)
    • Move undo/redo to document toolbar next to width buttons (#174)
    • Release @karmaniverous/jeeves-server v3.9.0
    • Updated jeeves-core
    • Release @karmaniverous/jeeves-server v3.8.5
    • Make clear-cache visible to outsiders in download menu
    • Move DownloadDropdown outside isInsider gate in DirectoryRow
    • [V3-7] fix: prettier formatting in toggleCheckbox route

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • Lintfix
    • Release @karmaniverous/jeeves-server v3.8.4
    • [V3-7] fix: checkbox click handler โ€” use native capture-phase delegation via ref callback, fix mtime stale-write flow
    • [V3-7] refactor: simplify checkbox toggle to fire-and-forget (no mtime, no conflict)

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • Fix
    • Release @karmaniverous/jeeves-server v3.8.3
    • [V3-7] fix: use descendant selector for checkbox indexing (li > input -> li input)
    • Release @karmaniverous/jeeves-server v3.8.2
    • [V3-7] fix: checkbox toggle click handling for dangerouslySetInnerHTML

    With dangerouslySetInnerHTML, the browser toggles native checkboxes before the React click handler fires. Read input.checked directly (already the desired new state) instead of inverting it. Replace preventDefault with stopPropagation to allow the visual toggle while preventing parent navigation.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • Release @karmaniverous/jeeves-server v3.8.1
    • [V3-7] fix: correct /events route path to /api/events (#156)

    The events route was registered as '/events' instead of '/api/events', causing 404 responses. Fixed the path and added tests.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] feat: add checkbox indexing and mtime to markdown pipeline (#154)

    Assign sequential data-checkbox-index to each GFM task-list checkbox in rendered HTML. Include file mtime in markdown API responses so the client can send it with toggle-checkbox requests for stale-write protection.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] feat: add POST /api/file/*/toggle-checkbox endpoint (#154)

    Insider-only endpoint to flip a single GFM task-list checkbox in a markdown source file. Uses mtime-based stale-write protection (409 on conflict). Includes tests for happy path, stale-write, outsider rejection, and out-of-range index.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] feat: wire MarkdownView checkbox toggling (#154)

    Enable interactive checkboxes for insiders in rendered markdown. POST toggle-checkbox on click with data-checkbox-index, checked state, and mtime. Update mtime on success, re-fetch on 409 conflict. Disable checkboxes and show loading state during flight.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] chore: bump versions (service 3.7.0, openclaw 0.8.0)

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] style: fix prettier formatting in markdown tests

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] refactor: SOLID/DRY pass across v3.7.0 changes

    • Remove eslint-disable comments in events.ts and fileContent.ts by using non-async plugin pattern (matching toggleCheckbox.ts convention)

    • Eliminate redundant handleText branches (rawOnly and non-rawOnly produced identical output)

    • Extract magic number 86400000 to named MS_PER_DAY constant

    • Optimize rewriteUrlsInData to pre-compute both origins instead of re-parsing URLs on every string match

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] test: improve coverage and remove trivial tests

    Add missing edge-case tests for events route (limit clamping, non-numeric input, negative values), serverTools URL rewriting (HTTPS with port, port-mismatch non-rewrite), and toggleCheckbox (content preservation, multi-checkbox targeting). No trivial tests found to remove.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] docs: sync documentation with v3.7.0 implementation

    Add publicUrl config to all doc surfaces (SKILL.md, openclaw-integration.md, README). Document checkbox toggling capability in TOOLS.md injection and SKILL.md. Add v3.7.0 and v0.8.0 CHANGELOG entries. Fix prettier formatting in toggleCheckbox test.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] fix: address Gemini review โ€” URL boundary, checkbox regex, Cheerio, race condition

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [V3-7] fix: toggle-checkbox route wildcard position (CI fix)

    Move wildcard from middle of route path to end: POST /api/file//toggle-checkbox โ†’ POST /api/toggle-checkbox/. Fastify's find-my-way router requires wildcards to be the last character in the route.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • Release @karmaniverous/jeeves-server v3.8.0
    • Release @karmaniverous/jeeves-server v3.6.5
    • Unhoisted jeeves
    • Release @karmaniverous/jeeves-server v3.6.4
    • Hoisted jeeves
    • Release @karmaniverous/jeeves-server v3.6.3
    • [150] fix: consume core importMetaUrl for plugin install (#150)

    Fixes #150. Also closes #147.

    • Bump @karmaniverous/jeeves to ^0.5.4 in both packages
    • Replace distDir with importMetaUrl in plugin CLI
    • Remove unused node:path and node:url imports from cli.ts
    • Release @karmaniverous/jeeves-server v3.6.2
    • Update @karmaniverous/jeeves to ^0.5.3 and bump minor/patch deps
    • Update @types/node to ^25.5.2
    • Update @karmaniverous/jsonmap ^0.3.1 โ†’ ^2.1.1
    • Release @karmaniverous/jeeves-server v3.6.1
    • [360] feat: Phase 1 โ€” core service adoption (getServiceUrl, getBindAddress, Node 22 fast-fail)

    • Bump @karmaniverous/jeeves to ^0.5.1 in both packages

    • Set engines.node to >=22 in all package.json files

    • Add runtime Node version fast-fail guard in CLI and start-server entry points

    • Replace bespoke watcherUrl, runnerUrl, metaUrl config properties with getServiceUrl() from core

    • Replace bespoke host config property with getBindAddress() from core

    • Fix hardcoded 127.0.0.1 in export route โ€” now uses resolved bind address

    • Add config migration: deprecated properties stripped with deprecation warnings

    • Update all call sites (runner proxy, search, fileContent, auth-status, status, export)

    • Update RuntimeConfig type and buildRuntimeConfig to remove deprecated fields

    • Wire init() in descriptor.run() and start-server.ts for core service resolution

    • Update all test files for new types and mock getServiceUrl/fetch

    Closes #135, #141, #142, #143, #145

    • [360] feat: Phase 2 โ€” core v0.5.1 wiring (cleanup escalation, getPackageVersion, substituteEnvVars TODO)

    • Wire gatewayUrl cleanup escalation in plugin via loadWorkspaceConfig()

    • Replace bespoke packageVersion.ts with core getPackageVersion(import.meta.url)

    • Add TODO comment to substituteEnvVars.ts (core does not export it yet)

    • Update onConfigApply signature to accept config argument (Task 7)

    • [360] feat: Phase 3 โ€” UX improvements (CSV tables, directory item counts, collapsible frontmatter, collapsible TOC)

    • Add CSV rendered table view with RFC 4180 parser and HTML table rendering

    • Add Rendered/Raw tab support for .csv files in FileContentView

    • Add .csv-table styles matching prose typography

    • Add directory item counts (nonrecursive) in Size column for directory rows

    • Add collapsible large frontmatter (>10 lines collapsed by default with toggle)

    • Add collapsible TOC sections with chevron toggles and auto-expand on scroll

    • Add TocSection component with buildTocTree() and findAncestorSlugs() utilities

    • Add 12 unit tests for CSV parsing (quoted fields, escaped quotes, empty fields, etc.)

    Closes #48, #49, #115, #116

    • [360] docs: Phase 4 โ€” documentation updates for v3.6.0

    • Update SKILL.md: Node 22+, CSV rendering, directory counts, collapsible features, core service discovery

    • Update setup guide: remove deprecated config properties, add core service discovery guidance

    • Update README: Node 22+, add CSV and collapsible features to highlights

    • Review promptInjection.ts: no changes needed (status shape unchanged)

    • [360] chore: Phase 5 โ€” quality gates clean (knip fixes, remove package-directory dep)

    • Remove unused package-directory dependency (replaced by core getPackageVersion)

    • Add start-server.ts as knip entry point

    • All quality gates pass: lint, typecheck, knip, build, test (165 tests)

    • [360] chore: remove TASK.md build artifact, DRY up Node version check and fix minor issues

    • [360] test: add missing test coverage for v3.6.0 features

    • Deprecated config property migration (loadConfig.test.ts)

    • Collapsible frontmatter threshold logic (markdown.test.ts)

    • Export URL 0.0.0.0 โ†’ 127.0.0.1 fallback (export.test.ts)

    • Directory itemCount mapping (directory.test.ts)

    • CSV table css-table class + large CSV (csv.test.ts)

    • Runner proxy URL resolution (runner.test.ts)

    • Search watcher URL resolution (search.test.ts)

    • [360] refactor: address code review โ€” async directory reads, CSV row normalization, extract mapDirectoryEntry

    • [360] docs: fix Node version in deployment guide (20 โ†’ 22)

    • [360] refactor: split TocSection.tsx โ€” move utilities to tocUtils.ts (fixes react-refresh lint)

    • Release @karmaniverous/jeeves-server v3.6.0
    • [53] chore: bump core to v0.4.6 (init before run) + fix knip issues
    • [53] chore: bump core to v0.4.6 (init before run) + fix knip issues
    • Release @karmaniverous/jeeves-server v3.5.2
    • [51] feat: integrate descriptor.run from core v0.4.5
    • Release @karmaniverous/jeeves-server v3.5.1
    • Align config validate test assertion with core SDK output
    • [35] chore: bump @karmaniverous/jeeves to ^0.4.3, remove cosmiconfig dep

    Bump the core jeeves dependency in packages/service from ^0.3.0 to ^0.4.3 and remove the cosmiconfig dependency (no longer needed after config loading is switched to direct JSON reads in the next commit).

    Note: openclaw dep bump deferred to S4/S5 as it requires API migration.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] feat: replace cosmiconfig with direct JSON config loading

    Replace cosmiconfig-based config loading with direct JSON file reads. Add config path migration logic that automatically moves old-style jeeves-server.config.json to new jeeves-server/config.json convention. Make loadConfig/initConfig/resetConfig synchronous since all I/O is now sync fs operations.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] feat: use getBindAddress from core, replace localhost with 127.0.0.1

    Import SERVER_PORT and getBindAddress from @karmaniverous/jeeves for schema defaults instead of hardcoded values. Replace 'localhost' with '127.0.0.1' in URL constructions (export route, path redirect) to avoid DNS resolution ambiguity.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] fix: use static bind default, bump openclaw core dep, remove local stub
    • [35] fix: decode HTML entities in TOC heading text (#102)

    The TOC sidebar displayed raw HTML entities like " and ' because heading text was only stripped of HTML tags, not decoded. Now uses cheerio to properly extract text content with entity decoding.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] fix: show user-friendly search error messages (#98)

    Parse watcher error responses and display contextual messages instead of raw JSON error strings in the search modal.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] fix: encode browse path segments in API calls, add SPA catch-all (#50, #127)

    Client API functions now properly encode each path segment with encodeURIComponent, fixing issues with dotfile directories and paths containing special characters. Also added a setNotFoundHandler SPA fallback to catch edge cases where wildcard routes miss certain paths (e.g. dot-prefixed segments on Linux).

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] refactor: replace hand-rolled package.json walk with packageDirectorySync (#96)

    Replaced the manual directory walk in packageVersion.ts with packageDirectorySync from the package-directory npm package. Added package-directory as a direct dependency of the service package.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] feat: define JeevesComponentDescriptor for server component

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] refactor: migrate GET /status to createStatusHandler factory

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] feat: add GET /api/events endpoint for event log queries

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] feat: add POST /config/apply endpoint using createConfigApplyHandler

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] refactor: migrate openclaw plugin to core v0.4.4 SDK

    Remove hand-rolled serviceCommands/pluginRemove in favor of core's createServiceManager and createPluginCli. Rewrite cli.ts to delegate to createPluginCli factory. Update index.ts to construct a full JeevesComponentDescriptor for createComponentWriter.

    Co-Authored-By: Claude Opus 4.6 noreply@anthropic.com

    • [35] fix: resolve lint errors from core v0.4.4 migration
    • [35] chore: update deps (peer-safe)
    • [35] refactor: replace hand-rolled CLI with createServiceCli(descriptor) (#106)
    • [35] refactor: SOLID/DRY cleanup
    • [35] test: add tests for diagramExport and sharing helpers
    • [35] docs: sync documentation with SDK adoption changes
    • [35] fix: resolve startCommand path absolutely for CI compatibility
    • [35] docs: add title front matter to all guides
    • Release @karmaniverous/jeeves-server v3.5.0
    • Release @karmaniverous/jeeves-server v3.4.2
    • [120] fix: runner proxy routes call /status instead of /stats and /health (#120)
    • [120] fix: runner proxy routes call /status instead of /stats and /health (#120)
    • Release @karmaniverous/jeeves-server v3.4.1
    • [117] feat: bump core to v0.3.0 and consolidate status endpoint (#117)
    • Release @karmaniverous/jeeves-server v3.4.0
    • [113] feat: add host bind and metaUrl config options
    • Release @karmaniverous/jeeves-server v3.3.1
    • Core v0.2.0 SDK adoption (#111) (#111)
    • Release @karmaniverous/jeeves-server v3.3.0
    • Release @karmaniverous/jeeves-server v3.2.1
    • Add tagPrefix to auto-changelog config for monorepo tags
    • Full documentation pass with PlantUML diagrams
    • Fix diagram image paths in guides
    • Release @karmaniverous/jeeves-server v3.2.0
    • Explicit scope overrides take precedence over named scopes
    • Release @karmaniverous/jeeves-server v3.1.3
    • Parse inline tokens in heading renderer (code spans, bold, italic)
    • Release @karmaniverous/jeeves-server v3.1.2
    • Rendered tab persists when switching to Raw on watcher-rendered files
    • Rendered tab persists when switching to Raw on watcher-rendered files
    • Prevent full data reload on tab switch (only reload on path change)
    • Revert "fix: Rendered tab persists when switching to Raw on watcher-rendered files"

    This reverts commit 572cec8bc999df7e834fa66ff948747f2d35be32.

    • Release @karmaniverous/jeeves-server v3.1.1
    • Extend /api/status with ?events=N for recent event log (#89)
    • Render text/number facets as text inputs, chips for select/multiselect
    • Schema-driven facet rendering by uiHint
    • Two-step facet selection + garbage value filtering
    • Garbage value diagnostics for inference rule debugging
    • Metadata chips on search results with click-to-filter
    • Search facets, metadata chips, and click-to-filter
    • Cap schema-driven facet chips to fields with โ‰ค30 values
    • Use type=number input for number facets
    • Increase facets timeout to 15s, add error logging
    • Restore eager facet loading on modal open
    • Text/number facets skip value cleaning, cast values to String
    • Restore light mode text-foreground on Add Filter menu labels
    • Make +N more chip overflow a clickable link that expands the result
    • Close SearchableSelect dropdown on outside click (capture phase)
    • Remove hardcoded filters, fix lazy facet loading
    • Document ?events=N query param on /api/status
    • Lazy-load facets only when 'Add filter' is clicked
    • Release @karmaniverous/jeeves-server v3.1.0
    • Updated docs
    • Refresh README and guides for v3 CLI + config
    • Add typedoc config and dependencies
    • Add changelogs as children of package guide indexes
    • Add guide index content and fix typedoc trailing comma
    • Release @karmaniverous/jeeves-server v3.0.1
    • Release @karmaniverous/jeeves-server v3.0.0
    • Named access scopes (#84) (#84)
    • Make resetConfig reload runtime config
    • Plugin auth chain, status endpoint improvements (#83) (#83)
    • Normalize path for watcher render (Windows backslash + uppercase drive)
    • Resolve remaining lint errors (type annotations, unused params, unnecessary conditionals)
    • Lintfix
    • Add knip configs, remove dead exports, clean all code quality checks
    • Release @karmaniverous/jeeves-server v3.0.0-1
    • Migrate config from jiti/TS to cosmiconfig/JSON
    • Add CLI commands (start, config validate/show, service)
    • Add GET /api/status endpoint
    • Internalize diagram dependencies (mermaid/plantuml)
    • Add GET /api/link-info endpoint
    • Add scroll anchoring for async diagram renders
    • Add GET /api/search/facets proxy endpoint
    • Schema-driven search facet filters (Step 10)
    • Document rendering pipeline (Phase 4, Steps 16-18)
    • Set rootDir and update start script path for monorepo layout
    • Adjust rootDir depth for monorepo dist/src/config path
    • Adjust relative paths for monorepo dist/src/ layout
    • Cosmiconfig searchPlaces, SOLID/DRY pass, test coverage
    • Resolve package.json path portably for version
    • Remove unused parameter in linkInfo test
    • Add missing return-await in facets handler
    • Address Gemini code review feedback across PRs #65-#76
    • Address all gap analysis findings
    • Force white background in panzoom fullscreen (dark mode)
    • Resolve all client ESLint errors and warnings
    • Resolve knip unused files, dependencies, and exports
    • CI failures and SvgViewer panzoom re-init bug
    • CI rimraf resolution and remove redundant client steps
    • Incorporate main (PR #77 gap-analysis)
    • Publishconfig public access
    • Monorepo scaffolding (Phase 1, Step 1)
    • Extract buildRuntimeConfig to resolve.ts (DRY)
    • Extract shared renderMarkdownContent pipeline
    • Add resolve.ts unit tests (21 tests)
    • SOLID/DRY/test coverage pass
    • Migrate default port to 1934
    • Add tsdoc.json to both package roots
    • Add tsdoc.json to both package roots
    • Make both packages releasable
    • Add client as workspace member, align puppeteer versions
    • Release @karmaniverous/jeeves-server v3.0.0-0