What shipped across OpenVibe
Every change deployed to OpenVibe, newest first. Each line is a commit from the OpenVibers repositories, linked to the change itself. When enough have gathered, or a large feature lands, they are written up as Patch notes on openvibe.blog. JSON: /api/v1/changelog.
2026-09-29
6e7ed60LiveNo floating promises left in Live (plan T0, the shared checker reports 0): the control socket awaits handleCommand so a rejection is caught and logged; the Kick and YouTube chat-relay connects stay fire-and-forget but log their rejections…
c56e9c4LiveN-1 fixtures re-recorded from 66f590b, the release now in production (npm run n-1:record).
139ece3ToolsX-Internal-Key is gone from Tools (plan T2): GET /api/internal/analytics[/bots] on the gateway and the seven tool sites take only a Network service token with tools.analytics.read (401 token.missing without one), loopback only; the gateway…
3bff136NetworkX-Internal-Key is gone from Network (plan T2, the last step of the sweep): every /internal route takes only a service token with the capability it performs (the router gate answers 401 token.missing without a Bearer and keeps the…
8364eeeMediaX-Internal-Key retirement, Media's step (plan T2): POST /internal/avatar-ingest takes Network's service token with media.avatar.ingest (server/service-guard.js, loopback only; a Bearer is judged on the token alone, the key still passes…
a174534MediaOrigin shield on in production: edge.openvibe.media (DNS-only, DNS-01 certificate), the nginx shield, MEDIA_SHIELD=b2. The edge also hides B2's object headers (x-amz-version-id, x-bz-*). docs/media-fabric.md records the switch-on and the…
50e4dc1ChatPins current (plan T3 step 0): openvibe-sdk v0.23.1 (openvibe-sdk/db, ambient transactions, openvibe-sdk/testing, the JWKS client), openvibe-contracts v0.79.0, openvibe-shared v2.0.0 (none of its removed exports were used here), and the…
66f590bLiveX-Internal-Key is gone from Live (plan T2, step 3 of the sweep): every internal route takes only a Network service token with the capability it performs (live.avatar.write, live.url_registry.refresh, live.analytics.read…
71829e5LiveN-1 fixtures re-recorded from bea231e, the release now in production (npm run n-1:record).
55e4b84ToolsInternal analytics take Network service tokens (plan T2, X-Internal-Key retirement): GET /api/internal/analytics (and /bots) on the gateway and all seven tool sites accept a token holding tools.analytics.read (audience openvibe.tools…
5d18446GamesStaff auth on openvibe-sdk v0.23.1's JWKS client (the last good keys through a Network outage, a rotation honoured on an unknown kid) and openvibe-contracts v0.78.0. Service and app principals are now checked by openvibe-contracts'…
c24b7b1GamesPhysics conformance suite and an in-memory mock world (ADR-0007 M1 step 1): packages/physics/src/conformance.test.ts runs every seam case against MockPhysicsWorld and the Havok adapter (bodies, sweeps, joints, sleep and settle thresholds…
4bea21fSourcesNetwork tokens verify with keys from openvibe-sdk/auth's JWKS client (v0.23.1) in place of Sources' own key store: the last good keys through a Network outage, backoff, a rotation honoured on an unknown kid. Every service-token rule stays…
bea231eLiveLive never sends X-Internal-Key again (plan T2, step 2 of the sweep): every call to Network's internal API goes with Live's client-credentials service token, including the avatar report and mark-read-by-type now that Network guards them…
f8880b1LiveN-1 fixtures re-recorded from 660833d, the release now in production (npm run n-1:record).
79a4eeaNetworkX-Internal-Key retirement, Network's step (plan T2, register C-50–C-58), on openvibe-contracts v0.79.0 (via v0.78.0: the realtime manifest is gone, so the registry tests assert its absence). The 13 key-only internal routes nothing in the…
660833dLiveInternal routes take service tokens (plan T2, X-Internal-Key retirement, step 1 of the sweep): /internal/user-avatar (live.avatar.write), /internal/url-registry/refresh (live.url_registry.refresh), /internal/analytics-summary…
ee2ad94LiveN-1 fixtures re-recorded from 1a28261, the release now in production (npm run n-1:record).
2ab62ebMediaOrigin shield: viewers keep the one public URL. A shield-eligible read (a public or unlisted B2 copy, never private, sandbox or a recording) that arrives on openvibe.media answers a 302 to the same path on the DNS-only edge host, where the…
09212f6CodesToken rejections keep the reason about the token (wrong audience, expired, bad signature): the playground's developers need 'not for openvibe.media'. Only token.no_key, whose SDK text names the internal JWKS URL and the connect error…
57340a9CodesNetwork tokens verify through openvibe-sdk/auth's JWKS client (v0.23.1) in place of Codes' own key fetcher: the last good keys through a Network outage, backoff, a rotation honoured at once. Sign-in sessions and playground app tokens use…
29e6adaMediaOrigin shield (F1b) review fixes, still inert until MEDIA_SHIELD is set. The edge is known from X-Media-Shield-Host, which only the edge server block sets and openvibe.media clears (req.hostname honoured a client's X-Forwarded-Host), and…
8c19184MediaMedia Fabric F1b, off until the edge host exists: the origin shield. For a public B2 copy Node answers with X-Accel-Redirect into nginx's /_media_shield/b2/ (a 10 MB slice cache with proxy_cache_lock, keyed by object path and slice, never…
a3235a5SearchNetwork tokens verify with keys from openvibe-sdk/auth's JWKS client (v0.23.1) in place of the hand-written key store: fresh keys, the last good ones through a Network outage, backoff, and a rotation honoured on an unknown kid. Service…
dde5e8fAINetwork tokens verify with keys from openvibe-sdk/auth's JWKS client (v0.23.1): fresh keys, the last good ones through a Network outage, backoff, and a rotation honoured on an unknown kid, in place of the hand-written key store. Every…
12c6811Mediadocs/media-fabric.md: the accepted design for Media's storage and delivery (owner, 2026-09-29). Two fabrics (online: B2 canonical, R2 Standard hot, Bunny/CDN, the Media host's NVMe edge; archive/backup separately, deep archive never…
1535276Mediascripts/retire-r2.js and its test are removed: R2 stays as Media's fast tier (owner, 2026-09-29), so a tool that empties it has no place here. It ran once (its report is on the host); promotion is back on and the sweep refills R2. The…
d3f5e00SourcesA corrupt stored robots.txt row no longer throws: it reads as no rules and warns once per origin (plan T0). Test: test/robots-ssrf.test.js stores unparseable rules and checks the fetch goes on. Built on a free model, reviewed independently…
3ea36b3GamesM1 identity: the WebSocket authenticates at the upgrade, the editor key is gone, and the contracts pin is current (ADR-0007 decisions 8 and 12).
cac9644GamesM1: gameServer.ts (≈2,700 lines, one class) is split into 20 systems under apps/server/src/game/systems/ (sessions, movement, replication, manipulation, combat, vehicles, inventory, interaction, economy, production, npcs, social…
5900501Gamesgitleaks: allow the made-up subject id usr_01JABCDEFGHJKMNPQRSTVWXYZ0 in flusher.test.ts (a test default, matched on path and value), which the generic-api-key rule flagged in 540f672.
540f672GamesM1 persistence: Games runs on PostgreSQL 18 + Valkey through openvibe-sdk (ADR-0007 decision 5). SQLite is gone (no data is restored; a new schema from scratch, no schema-version history).
cfaf83cGamesADR-0007: rewrite the moddable base (the base is the product, Scraplandia its first pack; Rapier; places and instances; PostgreSQL + Valkey with a write-behind flusher; declarative, QuickJS and Worker mods; phones a real target…
eb2d008GamesREADME and STATUS.json are current (roadmap WS-U task 3): the README gains Purpose (OpenVibe.Games: Scraplandia on openvibe.games), Owns, Does not own, Depends on, Capabilities (the four games.* capabilities in the manifest, and every…
bbb7765MediaTwo uploads/thumbnail paths no longer hang on a database error: a multipart part's completion read (getSession) sat outside its try, so a rejected read was an unhandled rejection and the PUT never answered; it now answers 500…
2e7d452Hosthost.example.json: Games is on PostgreSQL (its ADR-0007 M1, OpenVibe.Games 540f672): databases world = ov_games, the preflight loads pg and openvibe-sdk/db instead of better-sqlite3, no generated dist-types (Games no longer tracks build…
ea989e1Mediaretire-r2.js reads Media's start time in microseconds: systemctl's default whole seconds put a restart made in the same second as the gates before them, so --execute refused.
262aa44Mediaretire-r2.js --gates writes its settings revisions as Media itself (no actor): the config store takes a subject reference or none, and refused the bare string.
fec18a6Mediascripts/retire-r2.js retires the R2 cache tier (plan T4: B2 is canonical, R2 held 19 popular VODs as a cache). --gates closes promotion (storage_tier.r2Enabled, object_tier.active) and records when; --execute refuses until Media has…
1a28261LiveLive no longer carries the old game: OpenVibe.Games is being rewritten (its ADR-0007) and will never serve /game, /canvas or /api/game again, so the /game and /canvas redirects, the /api/game 410, the /ws/game and /ws/canvas upgrade…
3f8a615LiveN-1 fixtures re-recorded from 03f1593, the release now in production (npm run n-1:record).
1dd658eBillingA provider event that updates a payment intent or a subscription is marked processed only when the update committed: applyPlan called the async plan.apply without awaiting it (the PostgreSQL move made it async), so it ran after the event's…
5d062bfOpenReOpenRe's workers no longer drop async failures on the floor (Node ends a process on an unhandled rejection, which would drop every publisher on a worker): the coordinator's outbox prune catches its rejection; the restream worker awaits its…
1157859Hostovhost backs up and drills PostgreSQL services natively (every service but network, chat, tools, games and live is on PostgreSQL since 2026-09-28; the old inventory's SQLite paths no longer exist, so backups of those services had silently…
fe4ff08BillingThe SQLite era is gone (on PostgreSQL since 2026-09-28; no compatibility kept): the one-time migrate-to-postgres script, the *_DB_PATH settings (config, .env.example, systemd unit, test helpers), the unused better-sqlite3 dependency and…
67a10d7Billingscripts/reconcile.js: its comment names the ledger it reconciles (DATABASE_URL), not the SQLite path.
dbdcbeeMediaThe SQLite era is gone (on PostgreSQL since 2026-09-28; no compatibility kept): the one-time migrate-to-postgres script, the *_DB_PATH settings (config, .env.example, systemd unit, test helpers), the unused better-sqlite3 dependency and…
186baefWikiThe perf-budget test boots its server on its own PGlite directory (WIKI_PGLITE_DIR, a temp dir removed afterwards) with DATABASE_URL cleared: it used to fall back to the shared dev database data/pglite and migrate it. The exit wait is…
ae80018BlogThe perf-budget test boots its server on its own PGlite directory (BLOG_PGLITE_DIR, a temp dir removed afterwards) with DATABASE_URL cleared: it used to fall back to the shared dev database data/pglite and migrate it. It also asserts the…