[pull] main from LibreChat-AI:main - #280
Merged
Merged
Conversation
* 🥤 fix: Keep Pending Code Steers Within the Composer * 🧪 test: Keep Pending Code Steer Preview Controls Visible * 🧪 test: Prove Pending Code Starts Inside the Composer --------- Co-authored-by: Lia <lia@librechat.ai>
Co-authored-by: Lia <lia@librechat.ai>
Co-authored-by: Lia <lia@librechat.ai>
Co-authored-by: Lia <lia@librechat.ai>
Route modules build their rate limiters while they load, and both server entries required them before startup checks copied rateLimits from librechat.yaml into the environment. The conversationsImport, tts, stt and route-scoped fileUploads budgets therefore ignored the yaml unless the matching environment variable was also set. Require the routes only after performStartupChecks in index.js and experimental.js.
…16439) * 🔒 fix: Guard 2FA Deep-Link Redirects Against Blocked Session Storage The post-login redirect store was the one session-storage consumer in the client that reached for it bare-handed: a context where storage access throws crashed the login screen's persist effect and the post-challenge boot instead of dropping the destination. Route every access through throwing-safe helpers so a blocked store costs the deep link, never the sign-in, and pin the ordinary 2FA challenge's deep-link survival and consumption with mock-harness scenarios plus blocked-storage unit tests. The challenge screen's code inputs also gain accessible names. * ♿ fix: Name the 2FA Verify Button by Its Visible Text The challenge submit button carried aria-label 'Continue' over the visible text 'Verify', so its accessible name did not contain the visible label (WCAG 2.5.3). The visible text names the button on its own; the label is dropped. * 🧪 test: Keep the 2FA Mock Harness From Re-Declaring Destinations The shell's authenticated queries 401 against the real backend under the stand-in bearer, and the auth-recovery login bounce carries the current URL as redirect_to, re-persisting the deep link mid-test. Answer those queries empty and leave /api/config real. * 🧪 test: Answer the Shell's Empty Shapes in the 2FA Deep-Link Harness The composer and its selectors iterate their query results, so the stand-in session's shell queries need per-endpoint empty payloads rather than a blank object; the destination's marker rides the query string so no conversation has to exist for the landing to hold; and the second sign-in declares its own destination, which is the deterministic form of consumption-across-sign-ins. * 🧪 test: Assert the 2FA Shell Across Viewports The account button hides in the mobile drawer and the drawer never satisfies a pointer click's stability check, so the shell assertion polls for whichever marker the viewport shows and the session ends through an in-page logout request, which the route mocks can actually see. * 🧪 test: Locate the Login Password Field by Label * 🧪 test: Let the CI Storage Polyfill Replace the Blocked Store The CI-mode build ships a storage polyfill that answers a broken sessionStorage by installing its own in-memory shim with defineProperty, which crashed against a non-configurable blocker and took the app boot with it. The blocker stays configurable: the shim is per-document, so the challenge's document swap still empties it and the landing contract is the same either way.
Sonnet 5.5 (`claude-sonnet-5-5`) rejects `thinking.type: disabled` and takes `between_tools` as its lowest thinking setting, binds thinking blocks to the conversation prefix, caps effort at `high` while thinking is off, rejects sampling parameters, supports the `updates` thinking display, and ships with 128k output / 1M context at Sonnet 5 pricing. Family gates in data-provider now use "5.5 or later" semantics so Opus 5.6+, Sonnet 5.6+ and the Mythos-class line (Fable) inherit the newest contract instead of falling back to the Opus 5 / Sonnet 5 paths.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )