| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
chore: clarify comments and remove obsolete code examples across backend and web - Remove redundant comments across Go sources and Svelte components. - Clarify documentation for provider authentication, streaming, and model discovery. - Explain cache behavior, configuration precedence, and locale fallback rules. - Document security safeguards, implementation limitations, and existing test boundaries. - Remove obsolete commented code without changing runtime behavior. - Refresh documentation references and clarify tool dependency requirements. | 4 天前 | |
fix: secure storage paths and authenticate REST and Ollama servers - Reject unsafe cross-platform storage names and traversal attempts. - Confine symlink targets within configured filesystem storage directories. - Require API keys for every non-loopback server binding. - Authenticate Ollama routes and securely forward configured credentials. - Validate chat pattern, context, and session names early. - Sanitize client errors to hide internal filesystem details. - Default REST server binding to loopback port 8080. - Add regression coverage for traversal, symlinks, and authentication. | 1 个月前 |