| fix(admin): keep onboarding precompute from flapping on PostHog blips The hourly run was scanning every macOS onboarding event and failing the task on 504/429, which pages on-call even though the dashboard still serves the last good cache. Co-authored-by: Cursor <cursoragent@cursor.com> | 11 小时前 |
| feat(admin): email new team members that they have dashboard access Adding someone on /dashboard/team granted access silently, so the person never learned they had it or which identity to sign in with. POST now sends them a short note with the admin.omi.me link and the exact Google address to use. The mail is best effort: a missing key, a provider rejection or an unreachable provider resolves to `emailSent: false` and a server log, and the dialog says "Added, but the invite email failed to send". The grant is never rolled back for a mail failure. Sends from admin@mail.omi.me, the domain Resend verifies and the backend already sends transactional mail from (omi.me apex is not verified). Runtime key comes from the new WEB_ADMIN_RESEND_API_KEY secret, copied from the backend's RESEND_API_KEY. Verification: - cd web/admin && npx vitest run app/api/omi/team-members lib/email -> 2 files, 19 tests passed - npx tsc --noEmit -p . -> clean - npx eslint <changed files> -> clean - python3 .github/scripts/check_public_build_contract.py -> passed | 8 天前 |
| feat(app): add guided voice introduction onboarding (#14514) * feat(app): add guided voice introduction onboarding * feat(app): instrument guided onboarding funnel | 18 天前 |
| Count mobile releases by first-seen PostHog builds | 9 天前 |
| feat(admin): let the workspace owner remove any admin, superadmins included adminData/{uid}.owner === true marks the owner. GET /api/omi/team-members now returns viewer.canRemove and an owner flag per member; DELETE removes a member (owner only, never yourself, 404 when already gone). Team page shows a Remove button with a confirm dialog for the owner. Verification: vitest 9/9 (web/admin/app/api/omi/team-members), tsc clean, eslint clean; real-path check on the development deploy follows in the PR. | 11 天前 |
| fix(backend): hide finished rule-discard noise across conversation reads (#20799) ## Coordinator follow-up The published lane is integrated by merging `origin/main` (no rebase, no force-push). The malformed-reason type guard and HTTP regression are included. Luna withdrew the default-detail P1: `include_discarded=true` stays the detail default so Show discarded still works; explicit false returns 404. ## Summary - Hide completed deterministic-rule discards even when sync retained live-target or shared metadata; preserve open sessions and explicit user keeps/photos. - Persist `discarded=true` with the rule decision in atomic intake and the sync reprocess shortcut, fenced against a changed content revision or fresh curation. - Project already-written completed rule discards as discarded in existing list/detail reads without a production write, Firestore index, client-copy change, or merge-gate relaxation. Show discarded remains recoverable. Failure-Class: new Line-Count-Exception: backend/database/conversations.py | 3657 -> 3715 | Keep the existing read projection and transactional discard owner together; the reusable metadata predicate lives in fragment_visibility.py. The list fill skips a capped number of legacy rule-discards so one stale row cannot empty a page, including a mixed page. Line-Count-Exception: backend/routers/conversations.py | 2266 -> 2275 | Enforce the existing discarded detail option independently of provenance without adding a route or response shape. An omitted detail read hides a completed rule-discard; an explicit include still shows it, and a stored discard stays visible. Line-Count-Exception: backend/utils/sync/pipeline.py | 3027 -> 3038 | The existing reprocess shortcut must commit the rule verdict before returning; policy remains in shared helpers. ## Test plan - [x] Synthetic incident metadata only; no production data, transcripts, Firestore, or api.omi.me access. - [x] Red proof via `BACKEND_UNIT_TEST_FILE_LIST=<absolute red-list.txt> PYTHON=backend/.venv/bin/python bash backend/test.sh`: `E AssertionError: assert 'incident' not in {'incident'}`; detail/read projection also returned false instead of true. - [x] Green through `backend/test.sh`: new read/persistence regressions and related sync/visibility/continuity/archive/budget/recovery suites. CPU-only `test_sync_capture_continuity.py` timing failures passed on the first allowed retry; guard unchanged. - [x] Preserve the existing deterministic-minimum title for kept empty-title rows. - [x] Hook/preflight and failure-class validation: `Failure-Class: new` accepted; 34 preflight checks, pyright (0 errors), selected backend unit files, and OpenAPI compatibility passed without bypasses. Exact line-count declarations above. - [x] Full CI requested with `ci:full`; four backend unit shards running at handoff. CI is not claimed green; coordinator owns merge/deploy. ## Reviewer risks - Read-time post-filtering keeps the indexed stored-flag query and its server limit/offset (desktop parity). If that window is full of a completed rule-discard, the page keeps reading after the last snapshot, capped at 64 skips, so the first page is not empty. A later offset still counts stored rows, so a refilled row can repeat at the next page boundary. The aggregate count still reflects the stored flag. - Stored decisions must match all of completed, rule/discard, and one of the four known reasons; unknown/model/Jev decisions stay unchanged. - Check explicit keep/photo protection and revision fencing, stale-decision clearing after substantive promotion, and unconditional deferral of an open live target. - No client rendered smoke or deployed incident confirmation was performed; verification is hermetic at the shared API read/persistence boundary. ## Known trunk reds (not fixed) - `test_shared_action_items.py::test_accept_shared_tasks_unavailable_claim_returns_503` - `test_app_client_ts_generator.py` - `test_desktop_tts_updates.py` rate-limit assertion ## GUARD CHANGED `test_sync_geolocation_enrichment.py` supplies the lifecycle dependency in its existing import-isolation fake. Existing policy tests are updated to require completed live/shared rule discards, while open-live and merge eligibility remain protected; no timing, hook, merge, or security guard is weakened. ## SCOPE ADDED None beyond the requested backend visibility fix and its required failure-class registration/regressions. ## SPEC DIVERGENCE The appended generic template prescribes `bun test` and denies the failure-class registry/pre-push hook. This Python checkout has all three: use `backend/test.sh`, `./scripts/failure-class`, and the live pre-push hook, as the task-specific brief requires. Known listed trunk reds are disclosed rather than repaired. Generated with [Devin](https://devin.ai) | 10 小时前 |
| fix: add admin auth to pages/api conversation-count route Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 6 个月前 |
| feat: add admin dashboard pages, API routes, and assets Adds all dashboard pages (apps, analytics, subscriptions, payouts, notifications, etc.), API proxy routes, and public assets. All API routes use lazy initialization for build-time safety. Fixes #6227 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 6 个月前 |
| feat: add admin dashboard pages, API routes, and assets Adds all dashboard pages (apps, analytics, subscriptions, payouts, notifications, etc.), API proxy routes, and public assets. All API routes use lazy initialization for build-time safety. Fixes #6227 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 6 个月前 |
| fix(admin): run the admin dashboard keyless on a narrow runtime identity (#17293) The admin dashboard built its Firebase Admin credential from a user-managed JSON key of firebase-adminsdk-4z2mm (a prod Owner) mounted from Secret Manager. That key is leaked and in use by an external actor; the dashboard was its only legitimate consumer. - admin.ts: use Application Default Credentials when no key pair is set; keep the cert path only when both FIREBASE_CLIENT_EMAIL and FIREBASE_PRIVATE_KEY are present (local non-prod), refuse half a pair, and log the credential mode with no secret material. - Deploy contract: stop mounting WEB_ADMIN_FIREBASE_* and remove the three bindings from the live service. - gcp_admin.yml: run prod as omi-admin-dashboard-runtime@ (datastore.user, firebaseauth.viewer, per-secret secretAccessor; no key). Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> | 13 天前 |
| chore(admin): document and verify local development | 2 个月前 |
| feat: add admin dashboard config and build files Migrates omi-admin Next.js app config into web/admin/. Includes package.json, Dockerfile, tsconfig, and tailwind config. Fixes #6227 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 6 个月前 |
| feat(admin): let the workspace owner remove any admin, superadmins included adminData/{uid}.owner === true marks the owner. GET /api/omi/team-members now returns viewer.canRemove and an owner flag per member; DELETE removes a member (owner only, never yourself, 404 when already gone). Team page shows a Remove button with a confirm dialog for the owner. Verification: vitest 9/9 (web/admin/app/api/omi/team-members), tsc clean, eslint clean; real-path check on the development deploy follows in the PR. | 11 天前 |
| chore(docker): remove trailing whitespace | 2 个月前 |
| fix(admin): run the admin dashboard keyless on a narrow runtime identity (#17293) The admin dashboard built its Firebase Admin credential from a user-managed JSON key of firebase-adminsdk-4z2mm (a prod Owner) mounted from Secret Manager. That key is leaked and in use by an external actor; the dashboard was its only legitimate consumer. - admin.ts: use Application Default Credentials when no key pair is set; keep the cert path only when both FIREBASE_CLIENT_EMAIL and FIREBASE_PRIVATE_KEY are present (local non-prod), refuse half a pair, and log the credential mode with no secret material. - Deploy contract: stop mounting WEB_ADMIN_FIREBASE_* and remove the three bindings from the live service. - gcp_admin.yml: run prod as omi-admin-dashboard-runtime@ (datastore.user, firebaseauth.viewer, per-secret secretAccessor; no key). Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> | 13 天前 |
| feat: add admin dashboard config and build files Migrates omi-admin Next.js app config into web/admin/. Includes package.json, Dockerfile, tsconfig, and tailwind config. Fixes #6227 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 6 个月前 |
| feat(admin): /dashboard embeds self-hosted Grafana; legacy grid at /dashboard/classic | 1 个月前 |
| chore(web,plugins): drop dead deps/components; require iq_rating env credentials web: 24 of 49 unused shadcn wrappers in admin (+21 deps, lockfile-consistent, transitives preserved where live code needs them); react-window et al from web/app; eventsource-parser et al from personas; paidamount.tsx + its ADMIN_KEY env; Dockerfile.datadog; .backup hook file; web/frontend README rewritten to match reality (Next ~16, h.omi.me share host, no compose/staging). plugins: _mem0/ (100% commented out; keep-rule in LEGACY_MONOLITH.md now scoped to the actually-mounted _multion), apps-js/ + advanced/ husks, README rewritten to the current SDK + omi-*-app tree, dated superseded note on the plugin refactor audit. Security: iq_rating no longer carries hardcoded OMI_APP_ID/OMI_APP_SECRET defaults (public since 2025-12-16) - it now fails fast at import unless both come from the environment. DEPLOY COORDINATION: set both (secret ROTATED) on the Cloud Run plugins service before the next manual deploy; gcp_plugins.yml is workflow_dispatch-only so nothing breaks until then. Verification: rg zero-refs for every deleted file; all edited JSON parses; all 36 README-mentioned paths exist; py_compile on edited plugin modules; repo-wide sk_ default sweep clean. | 1 个月前 |
| chore(web,plugins): drop dead deps/components; require iq_rating env credentials web: 24 of 49 unused shadcn wrappers in admin (+21 deps, lockfile-consistent, transitives preserved where live code needs them); react-window et al from web/app; eventsource-parser et al from personas; paidamount.tsx + its ADMIN_KEY env; Dockerfile.datadog; .backup hook file; web/frontend README rewritten to match reality (Next ~16, h.omi.me share host, no compose/staging). plugins: _mem0/ (100% commented out; keep-rule in LEGACY_MONOLITH.md now scoped to the actually-mounted _multion), apps-js/ + advanced/ husks, README rewritten to the current SDK + omi-*-app tree, dated superseded note on the plugin refactor audit. Security: iq_rating no longer carries hardcoded OMI_APP_ID/OMI_APP_SECRET defaults (public since 2025-12-16) - it now fails fast at import unless both come from the environment. DEPLOY COORDINATION: set both (secret ROTATED) on the Cloud Run plugins service before the next manual deploy; gcp_plugins.yml is workflow_dispatch-only so nothing breaks until then. Verification: rg zero-refs for every deleted file; all edited JSON parses; all 36 README-mentioned paths exist; py_compile on edited plugin modules; repo-wide sk_ default sweep clean. | 1 个月前 |
| feat: add admin dashboard config and build files Migrates omi-admin Next.js app config into web/admin/. Includes package.json, Dockerfile, tsconfig, and tailwind config. Fixes #6227 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 6 个月前 |
| feat: add admin dashboard config and build files Migrates omi-admin Next.js app config into web/admin/. Includes package.json, Dockerfile, tsconfig, and tailwind config. Fixes #6227 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 6 个月前 |
| chore(admin): document and verify local development | 2 个月前 |
| test(web-admin): add unit tests for useAuthToken hooks 8 tests covering: token resolution, error handling, no-user state, authenticatedFetcher headers/errors, fetchWithAuth auth headers, caller header preservation, FormData Content-Type skip. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 5 个月前 |