Skip to content

[pull] main from LibreChat-AI:main - #280

Merged
pull[bot] merged 8 commits into
innFactory:mainfrom
LibreChat-AI:main
Sep 28, 2026
Merged

pull[bot] merged 8 commits into
innFactory:mainfrom
LibreChat-AI:main

Conversation

@pull

@pull pull Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

berry-13 and others added 8 commits September 28, 2026 12:28
* 🥤 fix: Keep Pending Code Steers Within the Composer

* 🧪 test: Keep Pending Code Steer Preview Controls Visible

* 🧪 test: Prove Pending Code Starts Inside the Composer

---------

Co-authored-by: Lia <lia@librechat.ai>
Co-authored-by: Lia <lia@librechat.ai>
Route modules build their rate limiters while they load, and both server
entries required them before startup checks copied rateLimits from
librechat.yaml into the environment. The conversationsImport, tts, stt
and route-scoped fileUploads budgets therefore ignored the yaml unless
the matching environment variable was also set. Require the routes only
after performStartupChecks in index.js and experimental.js.
…16439)

* 🔒 fix: Guard 2FA Deep-Link Redirects Against Blocked Session Storage

The post-login redirect store was the one session-storage consumer in the
client that reached for it bare-handed: a context where storage access
throws crashed the login screen's persist effect and the post-challenge
boot instead of dropping the destination. Route every access through
throwing-safe helpers so a blocked store costs the deep link, never the
sign-in, and pin the ordinary 2FA challenge's deep-link survival and
consumption with mock-harness scenarios plus blocked-storage unit tests.
The challenge screen's code inputs also gain accessible names.

* ♿ fix: Name the 2FA Verify Button by Its Visible Text

The challenge submit button carried aria-label 'Continue' over the visible
text 'Verify', so its accessible name did not contain the visible label
(WCAG 2.5.3). The visible text names the button on its own; the label is
dropped.

* 🧪 test: Keep the 2FA Mock Harness From Re-Declaring Destinations

The shell's authenticated queries 401 against the real backend under the
stand-in bearer, and the auth-recovery login bounce carries the current URL
as redirect_to, re-persisting the deep link mid-test. Answer those queries
empty and leave /api/config real.

* 🧪 test: Answer the Shell's Empty Shapes in the 2FA Deep-Link Harness

The composer and its selectors iterate their query results, so the stand-in
session's shell queries need per-endpoint empty payloads rather than a
blank object; the destination's marker rides the query string so no
conversation has to exist for the landing to hold; and the second sign-in
declares its own destination, which is the deterministic form of
consumption-across-sign-ins.

* 🧪 test: Assert the 2FA Shell Across Viewports

The account button hides in the mobile drawer and the drawer never
satisfies a pointer click's stability check, so the shell assertion polls
for whichever marker the viewport shows and the session ends through an
in-page logout request, which the route mocks can actually see.

* 🧪 test: Locate the Login Password Field by Label

* 🧪 test: Let the CI Storage Polyfill Replace the Blocked Store

The CI-mode build ships a storage polyfill that answers a broken
sessionStorage by installing its own in-memory shim with
defineProperty, which crashed against a non-configurable blocker and
took the app boot with it. The blocker stays configurable: the shim is
per-document, so the challenge's document swap still empties it and the
landing contract is the same either way.
Sonnet 5.5 (`claude-sonnet-5-5`) rejects `thinking.type: disabled` and takes
`between_tools` as its lowest thinking setting, binds thinking blocks to the
conversation prefix, caps effort at `high` while thinking is off, rejects
sampling parameters, supports the `updates` thinking display, and ships with
128k output / 1M context at Sonnet 5 pricing.

Family gates in data-provider now use "5.5 or later" semantics so Opus 5.6+,
Sonnet 5.6+ and the Mythos-class line (Fable) inherit the newest contract
instead of falling back to the Opus 5 / Sonnet 5 paths.
@pull pull Bot locked and limited conversation to collaborators Sep 28, 2026
@pull pull Bot added the ⤵️ pull label Sep 28, 2026
@pull
pull Bot merged commit 40bb16e into innFactory:main Sep 28, 2026
1 check passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants