mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-10-07 10:17:47 +08:00
98e91d33dcbc2609d901fe351839b74f2e2d84db
107
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
0b63e28e5a |
feat: MCP feature parity, the web app on the MCP core, and provider fixes (#951)
* fix(chat): close credential leaks and harden the chat route
- Vertex: a client-supplied base URL only works with the client's own Vertex key
- Accept only data: URLs for file parts in every message, so the server never downloads them
- Output budget retry accounts for the thinking budget Bedrock/Anthropic add, and reads
Volcengine, DashScope, SGLang and vLLM rejections; falls back to 16000 once
- x-max-output-tokens can only lower the budget on server credentials
- On server credentials only server models or AI_MODEL entries can be used
- Drop tool results together with the invalid tool calls they belong to
- Count quota tokens as input + output (cached tokens were counted twice)
- Private-URL check for custom base URLs, end Langfuse traces on error/abort/early return
- Fix repairToolCall ordering and placeholder, align edit_diagram prompt with operations
- Panel Bedrock keys are read from ADMIN_AWS_*; forward the access code to EdgeOne
- isMinimalDiagram only treats root cells as an empty canvas
* fix(api): require access codes and limit sizes on helper routes
- Shared checkAccessCode for validate-diagram, validate-model, parse-url, verify-access-code
- parse-url: 5 MB streamed body limit; validate-diagram: 5 MB image limit
- validate-model refuses redirects when private URLs are blocked
- Admin settings state shared across module instances via globalThis
- Server model ids: unique slugs (non-ASCII names encoded), duplicates rejected
- Panel Bedrock credentials stored as ADMIN_AWS_* so the DynamoDB client keeps its own
- Locale redirect keeps basePath and query; EdgeOne function drops open CORS and checks the access code
- Providers payload reports whether .env sets a default model
* fix(chat): keep saved diagrams and pages when restoring, editing and retrying
- Restored sessions no longer replay the last display_diagram over the saved diagram
- Failed or stopped edit_diagram restores the canvas
- Message snapshots keep the full multi-page document
- "Improve with suggestions" uses the normal send path (headers, xml, retry counters)
- Editing a message keeps its file/URL sections; cached example edits work
- New chat's first autosave no longer resets the UI
- Validation retries counted per user turn; validate-diagram sends the access code
- Cached examples only match the example files on an empty canvas
- Template sends keep attachments and wait for extraction
* fix(diagram): fix autosave staleness and XML repair corrupting valid diagrams
- Autosave guard reads refs, so edits after a theme or dark mode switch are kept
- Duplicate-id check and rename run per page; repair loop no longer quadratic
- autoFixXml no longer breaks style values, rich text " or single-line cells
- extractCompleteMxCells keeps the cell after a self-closing cell
- Better truncation detection; object/UserObject wrapped cells are editable
- Exports for thumbnail, PNG and save are routed by tag instead of a shared resolver
- History stores the full document; storage errors are reported, no auto-deletion of chats
- IndexedDB connection reopens after errors; focus refresh throttled
- Keep ?session= on locale redirect, map zh-Hant to zh-tw for draw.io
* fix(chat-input): stop template dialogs from sending and fix attachment races
- Template dialogs no longer submit the outer chat form
- Sending is blocked while files or URLs are still extracting
- File and URL extraction no longer drop or resurrect entries
- IME composition Enter no longer sends
- Tool call cards show the error text; keyboard handling on cards fixed
- Template import available when empty, edit dialog resets, saved templates refresh
- Only png/jpeg/gif/webp images accepted, SVG sent as text; PDF objects released
- parse-url request sends the access code
* fix(model-config): keep model selection valid and fix admin panel edge cases
- Fall back to the default server model when a saved one disappears
- Sync model config across tabs
- Validation uses the base path and sends the access code
- Model ids edited as drafts (no empty, duplicate or padded ids)
- Credential changes reset validation; stale validation results are dropped
- Admin: generateId over HTTP, env-locked group switches, discard and toggle fixes,
clearing a secret field keeps the saved key, first provider not auto-default when .env sets AI_MODEL
- Model selector items use unique values
* fix(electron): decrypt keys after ready and harden navigation and IPC
- Apply preset env after app ready, so Windows/Linux get decrypted keys
- Never re-encrypt ciphertext; restore env when switching or removing presets
- Block navigation away from the app, open external links in the browser, check IPC senders
- Keep inherited proxy settings, default NO_PROXY for localhost
- Serialize server start/restart, kill stuck processes, follow port changes
- Atomic config writes, keep corrupt files as backups, remember the server port
- Menu and settings window stay in sync; dev script gets the decrypted preset env
- Use app.isPackaged, parse inline .env comments, drop .env files from the bundle
* fix(mcp-server): fix XSS and crashes, make XML validation strict
- Validate and escape the mcp session id; only serve localhost Host/Origin
- Malformed URLs and session ids return errors instead of crashing the process
- Strict XML syntax check with saxes (linkedom never reports parse errors)
- autoFixXml no longer corrupts valid XML; attribute newlines serialized as entities
- Sessions stay alive while polled; browser pushes carry a base version (409 on conflict)
- Page tools respect the edit gate; UTF-8 bodies decoded correctly
- Export replies matched to requests and serialized; xml sync export handled
- UserObject/object cells addressable by id; history restored by stable id; logs off stdout
* fix(mcp-server): make edit_diagram all-or-nothing and fix preview sync races
- edit_diagram applies nothing when any operation fails, rejects invalid or
multi-cell new_xml, validates only the target page, and returns the
current page XML on every rejection (including stale edits)
- Fix get_diagram reading the old diagram right after an AI write: the
preview pushed its sync reply with a newer version than it was taken at
- Keep a user edit that loses the race with an AI write in history and
tell the user in the preview
- Autofix removes only exact foreign tags (a stray <mxGraph/> deleted
<mxGraphModel>), fixes tag case, drops orphan <mxPoint>s, and rejects
unknown element names in model XML
- Edit empty and compressed pages; PNG exports use the page on screen;
tag download exports; reload from the server after a page export
- Expand ~ in paths, tell the model when the browser sync timed out,
use registerPrompt, require SDK ^1.31.0
* feat(mcp-server): bring the web app's drawing knowledge to MCP
- Add a drawing guide adapted from the web system prompt (layout, edge
routing, styles, minimal style, editing rules), returned by
start_session, a new get_drawing_guide tool and the diagram-workflow prompt
- Add get_shape_library with the 30 icon libraries; the build copies
docs/shape-libraries into dist and CI checks the packed files
- Accept bare mxCell lists in create_new_diagram and add_page; the server
adds the wrapper and root cells
- Send server instructions, shorten create_new_diagram's description to
fit Claude Code's 2,048 character limit, and annotate every tool
- Fix dead links and the totals in docs/shape-libraries/README.md
* feat(mcp-server): add screenshot_diagram so the model can check its render
- New read-only screenshot_diagram tool returns the rendered page as a PNG
plus the web app's visual checklist (overlaps, edges crossing shapes,
readability, layout, rendering errors), replacing the web app's
separate vision model with the host model's own vision
- PNG exports use draw.io's width and pageId options: screenshots stay
under ~140,000 base64 characters and page exports no longer swap the
page on screen
- Fail fast with a clear message when the preview tab stopped polling
(browsers throttle background tabs)
- Mention the screenshot step in the drawing guide and instructions
* feat(mcp-server): auto-save each session's diagram to a .drawio file
- Save the latest diagram of every session 1 second after each change
(AI write, browser edit, history restore) to ~/.next-ai-drawio/<id>.drawio,
keep the newest 50, flush on shutdown; DRAWIO_DATA_DIR changes the folder
and "off" disables it, like the web app's IndexedDB sessions
- start_session names the file, so a resumed conversation can reopen the
diagram with load_diagram after the MCP process restarted
- Fix PNG/SVG exports randomly timing out: a previous export's 10 second
timer cleared the export in progress, and a late reply could be taken
for the current one; exports are now numbered
* refactor(mcp-server): move the preview page into src/preview
The 580-line page template in http-server.ts becomes index.html,
preview.css and preview.js, copied to dist/preview by the build and
filled at request time. The rendered page is unchanged apart from the
session id and draw.io origin now coming from a small config script.
Biome skips the folder because of the {{placeholders}}, as it never
linted the old template string either.
* feat(mcp-server): add theme menu, dark mode and editable SVG to the preview
- Pass themes=1 and dark=auto to the draw.io iframe, so the Extras menu
offers the Theme submenu and draw.io follows the system dark mode; the
header and dialogs follow it too through prefers-color-scheme
- Download dialog: new Editable SVG (.drawio.svg) format through draw.io's
xmlsvg export, default name diagram-YYYY-MM-DD, Enter saves and Escape
closes it and the history dialog
- export_diagram accepts format "drawio.svg" and detects the .drawio.svg
extension
- Use system fonts instead of Google Fonts, so the page works offline with
a self-hosted draw.io (DRAWIO_BASE_URL)
* docs(mcp-server): describe the new MCP features in all READMEs
- MCP server README: 13 tools, drawing rules and shape libraries,
screenshots, all-or-nothing edits, auto-save and how to continue a
diagram later, DRAWIO_DATA_DIR and DEBUG, offline use with a local
draw.io, and what to do when a background tab makes exports time out
- Fix two errors: History is a button at the top right of the preview
page, and exports are not limited to .drawio
- Claude Code plugin README: same tool list, formats and settings
- Root READMEs (English, Chinese, Japanese): short list of what the MCP
server can do
* fix(mcp-server): fix duplicate page exports and auto-save deleting user files
- Preview page: keep an MCP export open until the server has its result.
A poll answered before that still saw the request and started the same
export again, so a parallel page export could write the previous
page's image into its file
- Auto-save only removes its own mcp-*.drawio files, so a DRAWIO_DATA_DIR
that also holds the user's diagrams keeps them
- screenshot_diagram captures a page that has no id attribute by loading
just that page, like export_diagram
- An empty <Array as="points"/> no longer hides orphan mxPoints that
come after it
- POST /api/state refuses a push without xml, which used to wipe the
stored diagram
- Clear exportOptions when an export ends, reuse hasCells for the empty
diagram check, and reword two log lines
* fix: log Editable SVG saves, use local dates in file names, drop unused Electron dialogs
- /api/log-save accepted only drawio, png and svg, so saving as Editable
SVG (xmlsvg) got a 400 and was never recorded in Langfuse
- The default download name and the template export name used the UTC
date, which is the previous day on mornings in East Asia
- Remove the Electron openFile/saveFile IPC handlers, their preload
bindings and types; nothing in the app calls them
* refactor(mcp-server): make the diagram modules usable from the web app
The web app will reuse the MCP server's XML engine instead of its own
copy in lib/utils.ts, so these modules now run in the browser too.
- Relative imports end in .ts, rewritten to .js by tsc
(rewriteRelativeImportExtensions); Next.js resolves them directly
- Every module uses the global DOMParser/XMLSerializer: native in the
browser, linkedom in Node via installDomPolyfill. pages.ts parsed with
linkedom but serialized with the global serializer, which throws in
the browser
- The saxes syntax check moves to xml-syntax.ts, so the browser does not
pull in linkedom; it now also rejects undeclared prefixes such as
xlink:, as the browser does
- Page decompression uses pako and atob instead of node:zlib and Buffer
- hasCells moves to pages.ts, away from the file system code
- The duplicate cell id check counts UserObject/object ids
- wrapCellsInModel drops comments and text before the first cell, which
the web app accepts today
- validateAndFixXml takes { strict: false } for diagrams with user content
- Web tests run these modules with a browser DOM (jsdom)
- saxes becomes a direct dependency of the web app
* refactor(web): validate and repair diagram XML with the MCP server's engine
- Delete the web app's own copy of the XML checks and repairs from
lib/utils.ts (1,074 lines). loadDiagram now uses the MCP server's
validateAndFixXml without the strict checks, because the XML may hold
the user's own diagram
- display_diagram and append_diagram prepare the model's XML with the new
shared prepareNewDiagram, also used by the MCP create_new_diagram: wrap,
validate strictly and auto-fix while it is still a bare model (where
duplicate ids are renamed), then turn it into an mxfile
- The streaming preview of display_diagram no longer redraws the model's
raw cells after the tool handler loaded the checked diagram, and drops
a queued preview once the input is complete. That redraw lost
auto-fixes and UserObject/object wrappers, so a linked cell lost its
label; it also showed a second error toast
- The web repair regression tests now run against the MCP functions
- New e2e test checks the canvas content after display_diagram
- Fix the e2e upload tests, whose file input locator also matched the
template import input
* refactor(web): edit and wrap diagrams with the MCP server's code
- edit_diagram runs the MCP server's editDiagram: every new_xml is checked
first, one cell per operation, and after the edit only the target page
is checked, rejecting only errors this edit introduced. An unrelated
problem elsewhere in the document no longer blocks every edit. The
error lists each failed operation
- The streaming edit preview uses the MCP applyDiagramOperations
- Delete applyDiagramOperations (292 lines) and wrapWithMxFile from
lib/utils.ts, and the unused hand-copied scripts/test-diagram-operations.mjs
- One blank document (BLANK_MXFILE) for the web app and the MCP preview,
replacing four copies
- Saving a .drawio wraps a bare model with normalizeToMxfile
- The empty-diagram check uses hasCells, which also counts cells wrapped
in a UserObject/object
- DiagramOperation is the MCP type
- The wrapped-cell and empty-diagram tests now run against the MCP code
- New e2e test: edit_diagram changes the canvas, and a failing edit
leaves it as it was
* refactor(web): share prompt examples and the shape library with the MCP server
- The three XML examples (swimlanes, two edges, waypoints) that the web
system prompt, the display_diagram description and the MCP drawing
guide each had a copy of now live in packages/mcp-server/src/xml-examples.ts
- The shape library group list and reader come from the MCP
shape-library.ts; getShapeLibrary takes the folder, and the web route
passes docs/shape-libraries under the working directory as before.
Only the 30 known library names are read. Error texts differ slightly
- next.config.ts traces docs/shape-libraries/*.md for /api/chat, since
the read now happens in another module
- Every prompt is byte-for-byte unchanged: the web system prompt for five
model ids with and without minimal style, and the MCP drawing guide,
compared before and after; the library list and swimlane example match
the old tool description text exactly
* fix(providers): update the v6 SDK packages and fix Claude and Gemini settings
- Update ai to 6.0.300 and the @ai-sdk providers to their latest v6-line
versions. @ai-sdk/anthropic 3.0.47 did not know claude-opus-4-7/4-8
and capped their output at 32000 tokens; 3.0.127 allows 128000
- Drop the fine-grained-tool-streaming beta header for the Anthropic API:
the provider now streams tool input per tool (eager_input_streaming)
- Claude 4.7 and later reject a non-default temperature/top_p/top_k and
the extended thinking budget with a 400. A middleware retries once
without them, so TEMPERATURE and *_THINKING_BUDGET_TOKENS no longer
break those models
- Prompt caching also reaches Claude on the Anthropic API and OpenRouter;
before, only Bedrock got a cache marker
- GOOGLE_TOP_K and GOOGLE_TOP_P never reached Gemini: they were sent as
Google provider options, which drops them. They are call settings now.
GOOGLE_CANDIDATE_COUNT and GOOGLE_REASONING_EFFORT, which the provider
does not support, are removed
- Add @ai-sdk/openai-compatible as a direct dependency
* refactor: simpler streaming preview and small AI SDK cleanups
- useChat throttles streamed message updates (experimental_throttle,
150 ms), replacing the two hand-written 150 ms timers of the
display_diagram and edit_diagram previews (94 lines less). The preview
now only runs while the input streams; once it is complete the tool
handler takes over, so a queued preview can no longer redraw an edit
the handler rejected and rolled back. Measured on a streamed 60-cell
diagram: 41 redraws at least 97 ms apart, before 37 with gaps down to
48 ms
- The diagram check endpoint uses streamText with Output.object instead
of the deprecated streamObject, and returns its fixed result as a plain
text response; new route test
- Import createGateway/gateway from ai and drop the direct
@ai-sdk/gateway dependency
- The per-request message structure logs only print with
DEBUG_LLM_PAYLOAD=true
- Remove an empty onFinish callback
* refactor(chat): check the last tool part with the SDK's isToolUIPart
Drop the hand-written MessagePart and ChatMessage types that only served
this check.
* refactor(providers): one model factory for chat and the settings Test button
- getAIModel resolves credentials (client key, server env vars, the
existing SSRF rules) and createModel builds the model by SDK. The
provider-by-provider switch shrinks from 24 cases to the few that
differ (lib/ai-providers.ts 1531 -> 1106 lines)
- /api/validate-model calls getAIModel instead of its own 24-case switch
(503 -> 175 lines), which had drifted from the chat: it built Azure
with createOpenAI, Kimi and MiMo with createOpenAI instead of
createDeepSeek, and the official OpenAI endpoint with Chat Completions.
A passing test now means the chat works
- Plain OpenAI-compatible providers (SiliconFlow, SGLang, ModelScope,
GLM, Qwen, Qiniu, Novita, Atlas Cloud, EdgeOne, Doubao, MiniMax in
OpenAI mode, AIHubMix on a custom URL) use @ai-sdk/openai-compatible,
which reads reasoning_content, so their reasoning shows, and accepts
SGLang's stream as is (its 95-line stream rewrite is gone).
includeUsage keeps token usage for quotas. <think> tags in their text
become reasoning (extractReasoningMiddleware)
- SGLang without a base URL used OpenAI's endpoint; it now defaults to
http://127.0.0.1:8000/v1 like the Test button did
- Chat requests to a client base URL refuse redirects, as the Test
button already did (redirectGuardedFetch moves to lib/ssrf-protection)
- The Test button streams like the chat (the ModelScope special case is
gone), times out after 15 s, does not retry, asks the model to call a
ping tool and warns when it answers without one, and tests all models
at once. The time each test took shows on its check mark
- Unknown provider names are rejected with Object.hasOwn, and the error
texts list providers from PROVIDER_INFO instead of hand-kept lists
* feat(settings): link to each provider's key page and clean up base URLs
- A "Get API key" link next to the API Key field for the 19 providers
that have a key page (from env.example and the providers' docs). 17
answered 200 to curl; OpenAI's is behind a Cloudflare challenge and
DeepSeek's behind a regional block, both checked in Chrome
- Base URLs drop spaces, trailing slashes and a pasted endpoint path
(/chat/completions, /completions, /messages, /responses), which the
SDK would otherwise append a second time and get a 404. getAIModel does
this for the chat and the Test button; the field does it on blur and
shows the URL requests go to
* feat(errors): classify provider errors and show a hint the user can act on
- lib/llm-errors.ts sorts an error into about a dozen kinds (key
rejected, no access, unknown model, no credit, rate limited, context
too long, no image input, no tool calls, output cut off, provider down,
cannot connect, timeout): first texts that name the cause precisely,
then the HTTP status code, then general texts. It unwraps RetryError and
hides keys and Bearer tokens in the provider's message
- The chat route uses it for errors before the stream and, through
toUIMessageStreamResponse's onError, for errors in the stream. Errors
of the model's own tool call stay as they are: the same text goes back
to the model so it can fix the call
- The chat shows the hint in the user's language, then the provider's
message; a rejected key, missing access or unknown model adds an "Open
model settings" button. The Test button shows the same hints
- Fixes: our message "API key is required when using a custom base URL"
was replaced by "Authentication failed" because it contains "key"; a
provider's "Rate limit exceeded" opened this site's quota toast; an
error body like {"error": ...} was shown as raw JSON; the Test button
matched "401" in the message, where providers rarely put it
- Remove the string matching fallbacks in the chat panel
* refactor(settings): drop an unused index parameter
* feat(settings): fetch the model list from any provider and flag models that cannot draw
The "Fetch models" button asks the provider for its models (OpenAI-style
/models, Anthropic, Google, Ollama, OpenRouter, Vercel Gateway, AIHubMix)
and shows them in a searchable picker. This replaces the route that only
worked for AIHubMix.
A snapshot of models.dev (MIT) says which models support tool calls.
Models without them get a "no tool calls" badge in the picker and a hint
in the model list, since drawing needs tool calls. Refresh the snapshot
with scripts/update-model-catalog.mjs.
* fix(mcp-server): reject text between tags, which draw.io cannot open
draw.io reads any text inside a page as compressed page data, so a stray
text node makes the whole page fail with an atob error. gpt-5-mini sends
new cells with a literal "\n" between the tags; the edit card said
Complete while draw.io showed the error and kept the old diagram.
Validation now reports text between tags, and auto-fix turns a literal
\n, \t or \r between tags into whitespace. Other text goes back to the
model as an error. The compressed data directly under <diagram> is fine.
* fix(chat): clearer provider errors and no empty bubble, found with real models
- An error object sent inside the stream (OpenRouter's { code, message })
showed as "[object Object]"; its message and status code are read now.
- A problem+json "detail" is added to the message: NVIDIA only said
"Gone" for a retired model. 410 counts as model not found.
- "Cannot connect to API" from the SDK gets the connection hint.
- Text that is only whitespace (Kimi K2.6 sends a space before a tool
call) no longer shows an empty bubble.
- allowSystemInMessages stops the warning on every request. Our system
messages carry cache points; a client's own system messages are already
dropped by the empty-content filter.
* feat(providers): suggest the Claude 5 and GPT 6 models, show GPT 6 reasoning
The suggested models stopped at Claude Opus 4.8 and GPT 5.5. They now
start with Claude Opus 5.5, Sonnet 5.5 and Fable 5.1, and gpt-6.1-sol,
gpt-6-sol, gpt-6-luna and gpt-6-astra (ids checked against the provider
lists). The Bedrock list is unchanged until its ids are checked.
The reasoning summary was only turned on for model ids containing o1,
o3, o4 or gpt-5, so GPT 6 models showed no thinking. It now matches the
o-series and gpt-5 or later by version, like the OpenAI SDK.
* fix(providers): keep thinking on the newest Claude models, fix the Bedrock ids
Measured on Bedrock: Claude Opus 4.7, 4.8 and every Claude 5 model reject
a thinking budget ("thinking.type.enabled") and a temperature, and all of
them accept adaptive thinking. The retry used to drop thinking, so with
a thinking budget set these models did not think at all. It now switches
to adaptive thinking with display "summarized"; without that setting the
models think but send no thinking text to show.
The suggested Bedrock ids had no region prefix, and the newer models only
answer through an inference profile id: "anthropic.claude-sonnet-5-5"
fails with "on-demand throughput isn't supported". Each suggested id was
called once; the Claude ones now start with "global.", Llama, Pixtral and
Nova 2 Lite with "us.". Nova Premier (end of life) and the ids without a
working profile are gone. The docs example had the same problem and a
wrong date.
* fix(chat): an edit after a broken edit call no longer fails, found with Opus 5.5
- Claude Opus 5.5 sent an edit with invalid JSON, then the same edit
again. The first call's streamed preview was never undone: its input
has no operations, and the undo sat behind that check. The second edit
then started from the preview, failed on a duplicate id, and the model
had to try a third time. The undo now runs first, and an edit that
starts in the same render uses the undone diagram.
- The SDK passes an invalid tool call's error as a string, which was
wrapped as a provider error. streamErrorText keeps it as the text the
model reads.
- Bedrock's "on-demand throughput isn't supported" gets the model id hint.
- The thinking header uses the page language ("Thought for 1 second" in
English), from the dictionary entries that were already there.
* chore(mcp-server): release the new features as 0.3.0
npm has 0.2.3. The earlier commits raised the version step by step to
0.6.0, but they ship together as one release.
* style: auto-format with Biome
* fix(chat): draw the built-in examples again and undo edit previews on errors
Found by the PR review:
- The built-in examples showed a finished card and an empty canvas. They
are answered in the browser, never reach the tool handler, and relied
on the final redraw that an earlier commit removed. The example branch
now loads its diagram itself.
- When the request failed while an edit was streaming (a provider error,
a lost connection), its preview stayed on the canvas. The error handler
now restores the diagram from before the preview.
- The model picker could not scroll with the wheel or touch: the settings
dialog blocks those events outside itself, and the picker is rendered
outside it. The popover is modal now.
- A fetch error and the open picker stayed when switching providers.
- Editing a model id kept the old test warning and response time, which
also hid the "may not be able to draw" hint for the new id.
* fix(mcp-server): keep both pages when get_diagram meets a page export, and more review fixes
Found by the PR review, each with a test that failed first:
- get_diagram during a page export returned the one-page projection on
screen as the whole document (6 of 6 times when timed so). The preview
page no longer answers a sync while a projection shows, and syncs after
reloading, so the poll that restores the real document exports it.
- Exports are numbered on the server too: a late result of an export that
timed out was saved as the next export's file.
- In Chrome, a new_xml with a syntax error counted the <parsererror>
element as a second cell, so the web app rejected edits that auto-fix
repairs ("must contain exactly one cell").
- hasCells missed single-quoted ids, so screenshot_diagram called such a
diagram empty and auto-save never created its file.
- A literal \n directly under a <diagram> that has a model passed
validation; only text-only pages are compressed data.
- A wrapped mxCell repeating its UserObject's id took the wrapper's place
in edits, so delete and update left an empty or nested wrapper.
- Bare cells with a shape or edge id of "0" or "1" are rejected with a
clear message instead of being renamed, which broke their edges.
- DRAWIO_DATA_DIR expands ~, which JSON configs pass on as it is.
* fix(server): count quota by the key actually used, and more review fixes
Found by the PR review, each with a test that failed first:
- Quota: any key header skipped it, even one the provider never reads
(x-aws-access-key-id with OpenAI), so a request ran on the server's
key without being counted. The check now runs after the model is
resolved and uses usesServerCredentials. On main already.
- usesServerCredentials read the raw base URL; "/" cleans up to none, so
an Ollama request ran on the server's key past the server-model check.
- SGLang's default 127.0.0.1:8000 only fills the settings form. Chat and
the model list used it as a real address, so the server called its own
machine even with private URLs blocked. Now a base URL is required.
- With a user's OpenAI key and no base URL, the SDK read the server's
OPENAI_BASE_URL. The official endpoint is now passed. On main already.
- The Test button refused nothing on the server's keys (Ollama Cloud),
and a 15 s timeout reported "connected, no tool call".
- The model list for Ollama without a base URL came from ollama.com while
chat went to the server's Ollama.
- Bedrock's "Too many tokens, please wait" counted as context too long.
- On the server's keys the provider's error text stays in the server log;
it can name the server's AWS account, role or internal hosts.
- Desktop app: the preset keys are the user's own (NEXT_AI_DRAWIO_DESKTOP),
so Max Output Tokens can be raised and keyless models in settings work
again. A launch that found the remembered port taken no longer replaces
it, which hid the user's chats and settings for good.
* ci: run auto-format with the Biome version in package.json again
package.json moved to Biome 2.5.7 but the auto-format job stayed on
2.4.13. The two format some files differently, so on this PR the bot
reformatted tests/unit/log-save-route.test.ts with 2.4.13 and the lint
job, on 2.5.7, then failed on it. The pin now matches package.json, as
its comment asks, and the file is back in 2.5.7's format.
* fix(chat): keep the canvas after an unrelated error, and more review fixes
Found by the second PR review:
- After a streamed edit, an older render of the stream stored the edit's
original diagram again, and the next failed request (no quota, a lost
connection) put that old diagram back on the canvas. The tool handler
now marks its call as handled, so the preview code leaves it alone.
- An edit applied before the UI showed an earlier broken edit's error was
erased when that error undid its preview, or was built on that preview.
The handler now starts from the diagram before all unhandled previews,
and reads the diagram state that updates at once.
- A failed or stopped display_diagram left its half drawn diagram on the
canvas. Its preview is undone now, like an edit's.
- "New chat" cleared a chat that could not be saved (storage full).
- The settings dialog showed a model list, a fetch error or a test result
on the provider that was opened after the request started, and marked a
model id changed during the test as tested.
- A tool call with broken JSON was shown as cut off by the output limit.
- History entries and session thumbnails could pair with a later diagram
when draw.io answered an export late.
- A server model saved before non-ASCII provider names got into the id
was reset to the default model.
* fix(mcp-server): count a one-page view only for that page, and more review fixes
Found by the second PR review:
- get_diagram with a page selector, or a rejected edit's error, counted
the whole document as seen, so an edit on another page could overwrite
the user's change there. A one-page view now counts for all pages only
if the others are unchanged; otherwise the reply says to get them.
- add_page accepted shapes with the root cell ids "0" and "1" and renamed
them, breaking their edges. The check also missed ids on UserObject
wrappers and ids written with spaces around the "=".
- Root cells written over two lines were kept as an extra layer, cells
with id = "a" did not count as cells, and CDATA text before a page's
model passed the check although draw.io cannot open the page.
- Auto-save cleanup deleted the user's own files that start with mcp-.
Only names in the session id format are removed now.
- Restoring a history entry dropped edits made in the browser since the
last entry. They are added to history first.
- A session whose state expired showed a blank page, and the next change
overwrote its auto-save file. The saved file is loaded instead.
- An edit on a page export's one-page projection, made before the real
document was back, replaced the whole document.
- A late sync reply could overwrite a newer edit: each sync export is
numbered, and the server ignores replies older than the current state.
- screenshot_diagram could return another session's image after
start_session ran during its retries.
* fix(server): use the keys the user sent, and more review fixes
Found by the second PR review:
- With AWS_BEARER_TOKEN_BEDROCK set on the server, a request with the
user's AWS keys ran on the server's token: the Bedrock SDK prefers it.
Checked with Bedrock: invalid user keys used to get an answer.
- An OpenAI key with the official URL filled in (the settings form does
that) went to the Responses API. Back to main's rule: a configured base
URL uses Chat Completions.
- A user's Ollama key went to the server's OLLAMA_BASE_URL, for chat and
for the model list. Like every other provider, it goes to the user's
base URL or Ollama Cloud.
- The server's keyless Ollama and EdgeOne were not counted in the quota.
- AI_MODEL models on the server's keys ran on any provider with a server
key, not only on AI_PROVIDER.
- A user's Azure key without a base URL used the server's resource name.
- The admin panel's Test button failed whenever access codes were set.
- DeepSeek's errors in the stream (plain text) were shown as they were,
without a hint and also on the server's keys. Bedrock's throttling in
the stream was not recognised as a rate limit.
- The EdgeOne function accepted text/plain; x=application/json, which
other sites can send without a CORS preflight.
- Desktop app: a launch that found the old port taken for a moment (the
previous version still quitting after an update) remembered the new
port for good. The new port is kept only when Windows reserves the old
one. A failed read of the presets file moved it aside as corrupt, and a
save could then replace the presets. Switching presets on the same port
now reloads the page. The dev launcher no longer misses a preset change
made before or during a restart.
* fix(chat): undo rejected or stopped previews, and more fixes from the third review
- A call the server runs (get_shape_library) still reaches the browser's
tool handler, and it dropped the stored diagram of an earlier broken
edit, whose preview then stayed. Only the tools that draw take it now.
- A display_diagram whose final XML fails the checks loads the diagram
from before its preview again, as a failed edit does.
- After Stop, a tool result that arrives later (a screenshot check still
running) no longer sends a new request; Stop also skips calls the tool
handler already took.
- New chat and opening another chat kept nothing of a diagram drawn
without messages when it could not be saved; now they stay on it.
- The settings dialog drops a model list or test result whose provider
credentials changed meanwhile, also in another tab.
- A saved provider this version does not know crashed the whole page on
load; it is skipped.
- The input emptied a moment after the message showed in the chat, so it
briefly appeared twice (seen as a flaky e2e test).
- The desktop app's preset switch on the same port refetches the server
models instead of reloading the page, which lost unsent attachments.
* fix(mcp-server): recover sessions in one place, and more fixes from the third review
- A session whose state expired was recovered from its auto-save file only
for the preview page; the tools built on their older copy and then
overwrote the file. They now recover it first (restoreSavedSession).
- A preview tab that missed the last AI write pushed its older diagram
over the recovered one after a restart. It now shows the recovered
diagram and keeps its own copy in History.
- An empty record of what the model has seen (after load_diagram or a
page tool on unseen changes) no longer lets one page of a multi-page
document count for all, and get_diagram counts a page only once found.
- History: a thumbnail goes only to the entry it shows, the cached image
never belongs to an older diagram, a re-serialized copy adds no entry,
and a cleared document with its own pages is kept before a restore.
- The root cell id check reads attributes one by one: rack-id="1" or id
text inside a label no longer counts.
- A compressed page counts as having cells; a saved file that could not
be read is never written over.
* fix(server): keep users' keys at their own endpoints, and more fixes from the third review
- Bedrock: a user's AWS keys no longer go to an endpoint the server sets
in AWS_ENDPOINT_URL_BEDROCK_RUNTIME / AWS_ENDPOINT_URL (read by the
upgraded SDK), and admin panel keys win over AWS_BEARER_TOKEN_BEDROCK,
as the Test button checks them. Checked with Bedrock.
- Ollama: a server key without a base URL (admin panel, OLLAMA_API_KEY)
goes to Ollama Cloud, as env.example says, instead of 127.0.0.1.
- Quota: EdgeOne counts whatever key header comes along, keyless Ollama at
a private address counts, and their provider texts stay in the log.
- An EdgeOne server model (admin panel, ai-models.json) works: the route
checked the raw provider header, which holds the name's slug.
- parse-url ends downloads it does not read (too large, PDF, errors).
- Desktop app: the port follows where the chats are (IndexedDB per
origin) instead of a remembered port, which could hide them for good;
a same-port restart tells the page to refetch the server models; a
failed preset switch no longer undoes a newer choice; a presets file
removed after a failed read can be saved again; .env values quoted from
start to end keep their inner quotes, as dotenv reads them.
* fix(security): check request sources, regions and endpoints
- Bedrock: a request's AWS region must be a region name. It becomes part
of the endpoint's host name, so a value such as
"us-east-1.attacker.example/" sent the server's bearer token or signed
request to another host.
- MCP preview server: only the preview page itself (Origin equal to the
Host) or a non-browser client may call it; a page on another localhost
port could replace the diagram with a plain text POST. History builds
its thumbnails element by element and shows only SVG data images, so a
stored value can no longer run script in the preview.
- chat, validate-model, validate-diagram, provider-models and parse-url
take JSON bodies only, so another website cannot make the user's own
server (the desktop app, a local install) run models with their keys;
the desktop app also refuses a foreign Host (DNS rebinding).
- The model list reads at most 2 MB, also through the Gateway SDK, and
answers only with its own error texts: the URL is the caller's and may
be an internal address.
- An admin panel provider with its own key and no URL no longer inherits
the global <P>_BASE_URL, which may be a proxy for another key; OpenAI
then gets the official endpoint, as its Test. Azure keeps the server's
resource.
* fix: what the third round broke, and the first batch's review
MCP preview after the server lost a session (it expired, or the MCP
process restarted):
- Every server state has an id, made when the state is created. The tab
notices a new id even when the version numbers happen to match, and
every push names the state it was based on, so one based on a lost state
is refused, also when it comes before the tab's first poll (the server
recovers the saved file first).
- The tab keeps the newest canvas XML, saved or not. When the server knows
nothing (no file) or exactly what the tab last saved, the canvas wins and
is saved, so edits made while the server was down are kept. Otherwise
the server's diagram (an AI write the tab missed, a cleared document
that was saved) is shown and the tab's copy goes to History.
- Late answers to an old state's push or poll are dropped; a failed push
says the server is unreachable; Download as .drawio saves the canvas.
Settings and server:
- Saved providers this version does not know stay in storage with their
keys, and sending no longer trips over them.
- The desktop "Ollama (Local)" preset with a key goes to local Ollama
again; a server model's Ollama URL variable is read; the admin panel
writes Ollama Cloud's URL for a key without one.
- Provider error texts show again in the desktop app and for EdgeOne.
- .env: a quoted value followed by a comment ending in a quote is read as
dotenv reads it; unquoted values are unchanged.
- Desktop app: the next launch opens the port where a chat was last
saved; a launch elsewhere that saves nothing does not move it, and a
page with no chats lets the next launch try the other port once.
- The Test button no longer stays busy after another tab changed the key.
- A completed append_diagram is no longer undone by an earlier failed
edit's preview; a file read once in vain is saved again once it is read
or gone.
From the first batch's review:
- The admin panel's Test of an entry without a URL now tests the server's
<P>_BASE_URL, where chat sends the entry's key; chat is unchanged (the
first fix rerouted working setups).
- The model list ends downloads that are too large, accepts answers
without a body, and keeps the "redirects are not allowed" explanation.
- A test covers the preview's History rendering.
* fix: older defects (batch C) and the second batch's review
Chats:
- New Chat right after an answer saves that chat once. Saves run one at
a time and read the chat on screen when their turn comes; a save
scheduled for a chat that is no longer on screen is dropped. A chat
whose id was still on its way to the URL no longer comes back after
New Chat (the next answer went into it).
- Crossing the 768 px breakpoint keeps the chat panel: a streaming answer,
unsaved messages and attachments stay. The panel gets the sizes of each
side, and a panel collapsed on desktop opens on mobile.
- The chat's export waits for its own reply: an edit's history export
still on its way no longer answers it with the older diagram, and two
file saves at once no longer swap results.
- A second edit in one answer is previewed on the first edit's result.
- Stop also ends a running screenshot check; a chat that cannot be saved
(storage full) can be left with "Continue without saving".
- Small diagrams with shapes count as diagrams; the tool card no longer
crashes on malformed operations.
Quota and providers:
- Requests that reach the server's own endpoints count toward the quota:
EdgeOne (always its own endpoint now), a private base URL whatever key
header is sent, keyless Ollama without a URL. With the quota on, a
redirect is followed only to a public address. The output cap applies
to these requests too.
- Stop records the tokens of the steps that finished; the screenshot check
counts its tokens without counting a request.
- EdgeOne configured only by AI_PROVIDER works, also in the admin Test,
which forwards the access code. Azure set up only in the admin panel
works in chat. The Test sends a Bedrock session token.
- The admin panel's Test of an entry without a URL uses the server's URL
as the server does (no private address check for it); the admin panel
no longer writes an Ollama URL.
MCP server:
- Write tools and start_session run one at a time, so two at once never
drop each other's change; a cancelled call waiting its turn is skipped.
get_diagram and export_diagram keep the session they started with.
- Export to .drawio first gets the user's latest edits from the browser.
- History thumbnails: one that arrives after the next AI write is
dropped; a sync reply keeps the image; a version that changed only page
settings is its own entry.
- A diagram over the 10 MB limit is saved without its image, or the user
is told to download it (the server now answers 413 instead of cutting
the connection).
- Labels holding text like id='1' or parent='1' are no longer read as
attributes (a layer or a parent was deleted). A broken bare
<mxGraphModel> file is refused.
- After a sync reply the tab no longer sends its autosave copy again.
Desktop and files:
- A newer switch of the same preset is not rolled back by an older one
that failed. .env values with escaped quotes are read whole.
- MCP saved files: a file that could not be read stays protected while a
folder without permission hides it, and is saved again once deleted.
- The desktop app reports "no chats" only when the count was read and no
model settings are stored.
* fix: what the batch C review found
- A redirect followed for a custom base URL (quota on) no longer carries
the user's key or cookies to another origin, as fetch itself does, and
a private address may redirect to another private one (already counted).
- The admin Test of an Ollama or Vertex AI entry without a URL goes where
chat sends that entry's key: the environment's own URL variable, for
Ollama else the local default. The Test of an Ollama Cloud key without
a URL went to the cloud while chat went to local Ollama.
- Chat saves: each save notes the chat on screen and the order of the
reads before reading its data. A save read before switching chats no
longer writes into the chat switched to, and a copy that waited for its
thumbnail no longer replaces a newer one.
- "Continue without saving" keeps its button when a later auto-save fails,
and goes away when a new message is sent.
- A screenshot check that was waiting for its image when the user pressed
Stop stays skipped after the next message.
- MCP History: draw.io's own copy of a diagram (after get_diagram) no
longer adds an entry without a picture; a change of background is still
its own version. The tab ignores an edit's answer that arrives after a
newer AI write loaded.
- Desktop: a deleted preset is not brought back by a failed switch, and a
request naming no preset does not stop a rollback. An origin keeping
an access code counts as having settings.
- .env: a quoted value ending in a backslash ("C:\dir\") is read as dotenv
reads it.
- The tool card no longer crashes on an id that does not turn into text;
an older Test's success timer no longer ends a newer Test's spinner.
- Tests that passed without their fix now check it.
* fix: what the whole-PR review and Copilot found
- A redirect followed for a custom base URL also drops the key headers of
providers that do not use Authorization (x-api-key, x-goog-api-key,
api-key) when it goes to another origin.
- A second Enter or click while a message is being prepared (attachments
read, diagram exported) no longer sends it twice.
- The admin Test on the deployment's own endpoints (EdgeOne, the server's
keyless Ollama, an address on the server's network) counts toward the
quota like a chat; the chat and the Test share one rule for it. The
Test of an Azure entry set up by AZURE_RESOURCE_NAME only goes where chat
goes.
- EdgeOne's function is called at the site root again, as on main: EdgeOne
serves edge functions there, outside Next's base path.
- MCP History: the state before a write is kept unless the browser saved
no change of the user's since the last server write (draw.io's sync copy
of it adds no entry), and the dedupe compares the exact text again, so a
change of page size or other settings only is its own version.
- MCP: an edit keeps untouched labels as draw.io shows them (a literal line
break in an attribute is a space); a new document of empty pages the
user named is auto-saved; load_diagram reads only regular files, so a
pipe cannot hold up the other write tools; the preview does not load
back its own push still on its way (an undo made meanwhile is saved).
- Two overlapping saves of a new chat no longer reload the canvas from the
older copy.
- At most three screenshot checks per user turn, passed or failed, as
documented.
- Desktop: the main window navigates only within the app (draw.io stays in
its frame); a presets file that is not JSON and cannot be moved aside is
not overwritten.
- A last self-closing cell with a raw "<" in a value is not taken for cut
off output.
- README: Material Design shapes load their icons from fonts.gstatic.com.
* fix(chat): stop saving and exporting an idle chat every second
Each auto-save takes a thumbnail, and draw.io's SVG gets a new random id
every time, so latestSvg changed and the diagram context rendered again.
getThumbnailSvg was a new function on every render, the auto-save depends
on it, so the next save was scheduled a second later: a chat with some
diagrams was saved and exported once a second for as long as it was open.
getThumbnailSvg (and the export helper it uses) now keep one identity;
they read refs only.
Found by hand in the production build; the new e2e test fails without the
fix on a production build (as CI runs it).
---------
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
|
||
|
|
155ef4f7ac |
fix: raise the output budget so reasoning models reach the tool call (#927)
* fix: raise the output budget so reasoning models reach the tool call A reasoning model spends the output budget in order: thinking first, then prose, then the tool call. With 16000 the thinking alone can consume all of it, so the turn ends with finishReason "length" before display_diagram is ever called. The canvas stays empty and nothing surfaces in the UI, because no tool call means no tool error, and the client never reads finishReason. Measured on openrouter deepseek/deepseek-v4-flash, the model from the report: - max_tokens=800 with reasoning on returns reasoning_tokens=800, empty content, finish_reason length. So reasoning is billed against this budget, not exempt. - refining an existing diagram (19k chars of XML in the input) produced 49142 chars of reasoning, zero tool calls, finishReason "length" at 16000 - the same request at 40000 finished and called edit_diagram with 12 operations 64000 cannot just be sent to every model: bedrock claude-3-haiku caps at 4096, nova-lite at 10000, and the openrouter deepseek-r1 endpoint counts input and output against one 64000 ceiling. All three name the real limit in the 400, so parse it and retry once. Verified: nova-lite logs "64000 rejected, retrying with 10000" and then completes its tool call. Also expose the budget in Settings. It is sent as a header rather than read from env only, so desktop users can raise it themselves without an env file. vercel.json goes back to the 300s it had before #238 traded it for $2-4/month. That is now Vercel's own default, and billing pauses while the function waits on the model, so the saving that motivated 120s no longer applies. edgeone.json is left alone: its 120 may be that platform's actual ceiling. * fix: only reinterpret an error as a budget rejection when it says so Review of the first commit found the retry could fire on errors that have nothing to do with the budget, which would replace a readable provider error with a truncated response: exactly the symptom this PR exists to remove. - Drop the generic "lower than N" pattern. For the Bedrock message it was dead code, since "model limit of N" matches first with the same number. Left live, it would read a number out of any message shaped like "must be lower than 2". - Skip errors whose status is not 400 or 422, so auth and rate-limit failures are never reinterpreted. - Require the parsed ceiling to be at least 1024. Below that a diagram cannot come out whole, so retrying would hide the error behind broken XML. - Validate MAX_OUTPUT_TOKENS from env the same way as the header, so a stray "-1" falls back instead of reaching the provider. Adds tests for the retry wrapper itself, which had none: it retries once with the named ceiling, leaves a 401 alone, does not retry when the ceiling is not smaller, propagates a second rejection, and preserves the other call options. Re-verified against the live APIs: bedrock nova-lite still logs "64000 rejected, retrying with 10000" and completes its tool call, and deepseek-v4-flash still finishes normally at 64000. |
||
|
|
96bca2b37b |
fix: always send maxOutputTokens; default 16000 (#915)
Unset does not mean the model's maximum — the provider fills in its own, and Bedrock's is 4096 (measured: converse with no inferenceConfig on us.anthropic.claude-opus-5 returns stopReason=max_tokens at exactly 4096). A 30-cell diagram is ~3000 tokens of XML, so anything larger arrived as truncated JSON and nothing reached the canvas. Small diagrams fitted, which made it look intermittent. |
||
|
|
80baf43827 |
fix: remove name-based image-input detection (#874) (#877)
supportsImageInput() guessed multimodal capability from the model id string. The heuristic misfired on newer models (e.g. kimi-k3.6, qwen36), either wrongly rejecting images for capable models or letting them through. The AI SDK does not emit a warning when an OpenAI-compatible endpoint silently drops an image, so the guess was the only signal — but an unreliable one. Drop the detection entirely and let the real provider error surface instead (already translated to a friendly message in chat-panel.tsx). Validation falls back to "valid" on any model error. - Remove supportsImageInput() and its pre-send check in chat route - Drop the vision-capability throw in getValidationModel() - Remove the corresponding unit tests |
||
|
|
6c6cf98019 |
fix: merge system messages for custom OpenAI-compatible endpoints (#774)
* fix: merge system messages for custom OpenAI endpoints (fixes #734) When using the OpenAI provider with a custom base URL (e.g., vLLM, LMStudio), the app sends two system messages to the API. Open-source model chat templates (Qwen, Llama, etc.) enforce that system messages must appear at the beginning and reject multiple system message blocks, causing the error: 'System message must be at the beginning.' Treat custom OpenAI endpoints (client-provided base URL or OPENAI_BASE_URL env var) the same as other known single-system providers by merging both system messages into one before sending. * fix: also detect custom OpenAI endpoint from serverModelConfig.baseUrlEnv --------- Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
e7453e86a6 |
feat: add custom system message setting for AI personalization (#728)
* feat: add custom system message setting for AI personalization Allow users to enter custom instructions via a textarea in Settings that get appended to the AI's system prompt. Includes server-side validation (type check + 5000 char limit), localStorage persistence, and i18n support for all 4 locales. * fix: add accessibility htmlFor/id pairing on custom system message textarea |
||
|
|
be4bc916fd |
feat: Add support for Chinese AI providers (GLM, Qwen, Kimi, MiniMax, Qiniu)
* feat: Add support for Chinese AI providers (GLM, Qwen, Kimi, MiniMax, Qiniu) - Add minimax, glm, qwen, qiniu, kimi to ProviderName type - Add provider configurations to PROVIDER_INFO with default base URLs - Add suggested models for MiniMax in SUGGESTED_MODELS - Add minimax/glm/qwen/qiniu/kimi cases to getAIModel using OpenAI-compatible SDK - Update ALLOWED_CLIENT_PROVIDERS and error messages - Add environment variable examples to env.example Fixes: MiniMax API compatibility issue (invalid chat setting 2013) * fix: Add missing providers to PROVIDER_ENV_VARS type * fix: Handle null case in PROVIDER_ENV_VARS for new providers * fix: Add minimax/glm/qwen/kimi/qiniu support to validate-model API - Add getDefaultBaseUrl helper function - Add validation cases for new providers in validate-model route * fix: Add new providers to buildProviderOptions switch case * fix: Merge multiple system messages into one for minimax/glm/qwen/kimi/qiniu MiniMax API doesn't support multiple system messages. This fix combines them into a single message for Chinese providers. * fix: Handle null provider in system message check * debug: Add logging for allMessages count * fix: Use effective provider (including env var fallback) for isSingleSystemProvider check * fix: apply biome formatting (line-wrapping) * docs: add Chinese AI providers documentation (MiniMax, GLM, Qwen, Kimi, Qiniu) - Add i18n translations for new providers in all language dictionaries - Add provider configuration documentation in en/cn/ja docs * fix: 改进 PR #722 的代码审查反馈 1. 删除重复的 getDefaultBaseUrl 函数,改用 model-config.ts 的 PROVIDER_INFO 2. validate-model 路由改用 AI SDK 的 createOpenAI + generateText 3. 修复 resolveBaseURL 回退逻辑,传入 PROVIDER_INFO 的 defaultBaseUrl 4. 删除无用的 .bak 备份文件 Co-authored-by: Shinyi <[email protected]> * fix: 修正中国 AI provider 端点配置 - qiniu: api.qiniucdn.com → api.qnaigc.com - qwen: dashscope.aliyun.com → dashscope.aliyuncs.com - 更新 env.example 文档链接 Co-authored-by: Shinyi <[email protected]> * feat: MiniMax 使用 Anthropic 兼容 API - MiniMax 改用 createAnthropic (而非 createOpenAI) - 支持 api.minimax.io/anthropic 和 api.minimaxi.com/anthropic - 合并多个 system 消息为单个 (MiniMax/GLM/Qwen/Kimi/Qiniu) - 更新默认模型为 MiniMax-M2.5 系列 - 支持 MINIMAX_BASE_URL 环境变量配置 Co-authored-by: Shinyi <[email protected]> * docs: 更新 MiniMax 文档 - 添加 Anthropic 兼容 API 说明 - 更新默认模型为 MiniMax-M2.5 - 添加国际版/中国大陆版配置示例 - 更新 env.example 注释 Co-authored-by: Shinyi <[email protected]> * fix: 完善 MiniMax 双端点支持及问题修复 - 支持 MiniMax Anthropic 兼容端点和 OpenAI 兼容端点自动切换 - 修正默认端点为 api.minimaxi.com (中国大陆可用) - 修复端点路径缺少 /v1 的问题 - 添加前端 MiniMax logo 映射 - 移除调试日志 - 修正 env.example 默认配置 * chore: clean backup artifacts and align biome formatting * fix: resolve effectiveProvider bug, deduplicate MiniMax URL logic, fix docs - Fix critical bug: effectiveProvider was empty during auto-detection, causing multi-system-message to be sent to MiniMax (which rejects it). Now uses resolved provider from getAIModel instead of re-deriving it. - Extract normalizeMiniMaxBaseURL() shared helper to eliminate duplication between ai-providers.ts and validate-model/route.ts - Add guard for undefined MiniMax baseURL to prevent hitting api.anthropic.com - Fix docs: mark China mainland URL as default (matches code behavior) - Restructure minimax/glm/qwen/kimi/qiniu validation to use shared pattern Co-Authored-By: Claude Opus 4.6 <[email protected]> * feat: document MiniMax dual API formats in docs and UI - Add hint below Base URL input when MiniMax is selected, explaining Anthropic-compatible (/anthropic) vs OpenAI-compatible (/v1) endpoints - Update all 3 ai-providers docs (en/cn/ja) to list all 4 endpoint options (China/International × Anthropic/OpenAI) - Add i18n translations for the hint in all 4 locales Co-Authored-By: Claude Opus 4.6 <[email protected]> * refactor: deduplicate PROVIDER_LOGO_MAP, remove unnecessary optional chaining - Extract PROVIDER_LOGO_MAP to lib/types/model-config.ts (was duplicated in model-config-dialog.tsx and model-selector.tsx) - Remove unnecessary ?. on PROVIDER_INFO.minimax (it's a full Record) --------- Co-authored-by: msga-oc <[email protected]> Co-authored-by: Shinyi <[email protected]> Co-authored-by: dayuan.jiang <[email protected]> Co-authored-by: Claude Opus 4.6 <[email protected]> |
||
|
|
41dc0b2b42 |
feat: add Material Design Icons shape library (#688)
* feat: add Material Design Icons shape library (#685) Add Google Material Design Icons as a new shape library using Google's CDN. Includes top 300 most popular icons by usage, and updates system prompts to guide the AI to call get_shape_library before using any icon library. * fix: align get_shape_library guidance for non-cloud icon libraries |
||
|
|
cd33e131ef |
feat: add API key load balancing for providers (#676)
Support multiple API keys per provider with random selection for load balancing. When AI_MODELS_CONFIG has multiple apiKeyEnv values for a provider, requests will randomly select one available key. - Update schema to accept apiKeyEnv as string or string array - Add random key selection in resolveApiKey() - Update validation to check at least one key exists - Add tests for array format support |
||
|
|
f8a0ebd149 | feat: add stop button to cancel AI generation | ||
|
|
b386dc45e6 |
fix(quota): bypass quota for users with Bedrock credentials (#621)
* fix(quota): bypass quota for users with Bedrock credentials The hasOwnApiKey check only looked for x-ai-api-key header, but Bedrock users provide AWS credentials via x-aws-access-key-id instead. This caused Bedrock users with their own credentials to still be subject to quota limits. * fix(quota): also bypass quota for Vertex AI users * style: auto-format with Biome --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> |
||
|
|
21567744ad |
fix(chat): repair inconsistent quote escaping in edit_diagram JSON
When the LLM generates edit_diagram tool calls, it sometimes produces inconsistent quote escaping in XML attributes within JSON strings. For example: y="-20\" instead of y=\"-20\" This causes JSON parsing to fail, and jsonrepair cannot fix this pattern. Added pre-processing regex to detect and fix cases where the opening quote is unescaped but the closing quote is escaped in attribute values. |
||
|
|
b23b9179a0 |
[Feature] Server-side multi-provider/model support (#583)
* [Feature] Server side multi-pvorider/model support * copilot suggesition implemented * feat: improve model selector UI and auto-select default server model - Replace emoji headers with Lucide icons (Monitor, User) - Fix transition-all to explicit properties per web guidelines - Use CSS padding instead of hardcoded space indentation - Add ModelSelectorSectionHeader component for section headers - Replace Star icon with "default" text label - Style Configure button with muted text color - Auto-select default server model when page loads - Support AI_MODELS_CONFIG env var for cloud deployments - Support custom apiKeyEnv/baseUrlEnv per provider config * docs: update server-side multi-model configuration documentation - Add AI_MODELS_CONFIG env var option for cloud deployments - Document apiKeyEnv and baseUrlEnv fields for custom env var names - Document default field for auto-selecting default model - Remove deprecated version field from examples - Add field reference table for clarity --------- Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
3b50c08258 | Update chat and validation API routes to handle API key | ||
|
|
c7a85d398f |
test: add Vitest and Playwright testing infrastructure (#512)
* test: add Vitest and Playwright testing infrastructure - Add Vitest for unit tests (39 tests) - cached-responses.test.ts - ai-providers.test.ts - chat-helpers.test.ts - utils.test.ts - Add Playwright for E2E tests (3 smoke tests) - Homepage load - Japanese locale - Settings dialog - Add CI workflow (.github/workflows/test.yml) - Add vitest.config.mts and playwright.config.ts - Update .gitignore for test artifacts * test: add more E2E tests for UI components - Chat panel tests (interactive elements, iframe) - Settings tests (dark mode, language, draw.io theme) - Save dialog tests (buttons exist) - History dialog tests - Model config tests - Keyboard interaction tests - Upload area tests Total: 15 E2E tests, all passing * test: fix E2E test issues from review Fixes based on Gemini and Codex review: - Remove brittle nth(1) selector in keyboard tests - Remove waitForTimeout(500) race condition - Remove if(isVisible) silent skip patterns - Add proper assertions instead of no-op checks - Remove expect(count >= 0) that always passes - Remove unused hasProviderUI variable All 14 E2E tests and 39 unit tests pass. * style: auto-format with Biome * fix: resolve lint errors for CI * test(e2e): add diagram generation tests with mocked AI responses - Add tests for generate, edit, and append diagram operations - Use SSE mocked responses matching AI SDK UI message stream format - Generate mxCell XML directly in tests for deterministic assertions - Tests verify tool card rendering and 'Complete' badge state * test: add comprehensive E2E tests for all major features - Error handling tests (API errors, rate limits, network timeout, truncated XML) - Multi-turn conversation tests (sequential requests, history preservation) - File upload tests (upload button, file preview, sending with message) - Theme switching tests (dark mode toggle, persistence, system preference) - Language switching tests (EN/JA/ZH, persistence, locale URLs) - Iframe interaction tests (draw.io loading, toolbar, diagram rendering) - Copy/paste tests (chat input, XML input, special characters) - History restore tests (new chat, persistence, browser navigation) * refactor: extract shared test helpers and improve error assertions - Create tests/e2e/lib/helpers.ts with shared SSE mock functions - Add proper error UI assertions to error-handling.spec.ts - Remove waitForTimeout calls in favor of real assertions - Update 6 test files to use shared helpers * docs: add testing section to CONTRIBUTING.md * fix: improve test infrastructure based on PR review - Fix double build in CI: remove redundant build from playwright webServer - Export chat helpers from shared module for proper unit testing - Replace waitForTimeout with explicit waits in E2E tests - Add data-testid attributes to settings and new chat buttons - Add list reporter for CI to show failures in logs - Add Playwright browser caching to speed up CI - Add vitest coverage configuration - Fix conditional test assertions to use test.skip() instead of silent pass - Remove unused variables flagged by linter * fix: improve E2E test assertions and remove silent skips - Replace silent test.skip() with explicit conditional skips - Add actual persistence assertion after page reload - Use data-testid selector for new chat button test * refactor: add shared fixtures and test.step() patterns - Add tests/e2e/lib/fixtures.ts with shared test helpers - Add tests/e2e/fixtures/diagrams.ts with XML test data - Add expectBeforeAndAfterReload() helper for persistence tests - Add test.step() for better test reporting in complex tests - Consolidate mock helpers into fixtures module - Reduce code duplication across 17 test files * fix: make persistence tests more reliable - Remove expectBeforeAndAfterReload from mocked API tests - Add explicit test.step() for before/after reload checks - Add retry config for flaky clipboard tests - Add sleep after reload for language persistence test * test: remove flaky XML paste test * docs: run both unit and e2e tests before PR * chore: add type check and unit test git hooks --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> |
||
|
|
03ac9a79de |
fix: detect models that don't support image input and return clear error (#474)
Some models (Kimi K2, DeepSeek, Qwen text models) don't support image/vision input. The AI SDK silently drops unsupported image parts, causing confusing responses where the model acts as if no image was uploaded. Added supportsImageInput() function to detect unsupported models by name, and return a 400 error with clear guidance when users try to upload images to these models. Closes #469 |
||
|
|
ca21a5bb27 |
feat: add EdgeOne Pages as AI provider (#456)
* feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * feat: edit diagram * feat: edit diagram * feat: edit diagram * feat: edit diagram * feat: edit diagram * feat: edit diagram * feat: edit diagram * feat: add edgeone provider * feat: add edgeone provider * feat: add edgeone provider * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: add cookie * fix: add cookie * fix: add cookie * fix: add cookie * fix: add cookie * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * fix: build error * feat: validate * feat: document link --------- Co-authored-by: zoejiezhou <[email protected]> |
||
|
|
2d62496f9f |
fix(edit_diagram): implement cascade delete for children and edges (#451)
* fix(edit_diagram): implement cascade delete for children and edges - Add automatic cascade deletion when deleting a cell - Recursively delete all child cells (parent attribute references) - Delete all edges referencing deleted cells (source/target) - Skip silently if cell already deleted (handles AI redundant ops) - Update prompts to inform AI about cascade behavior Fixes #450 * fix: add root cell protection and sync MCP server cascade delete - Add protection for root cells '0' and '1' to prevent full diagram wipe - Sync MCP server with main app's cascade delete logic - Both lib/utils.ts and packages/mcp-server now have identical delete behavior * chore(mcp): bump version to 0.1.9 * fix(cascade-delete): recursively collect edge children (labels) - Change from cellsToDelete.add(edgeId) to collectDescendants(edgeId) - Fixes orphaned edge labels causing draw.io to crash/clear canvas - Edge labels (parent=edgeId) are now deleted with their parent edge |
||
|
|
3047d19238 |
fix: rename edit_diagram type field to operation for better model compatibility (#402)
Fixes #374 - Models were confused by the `type` field name and sent `operation` instead. This change: - Renames DiagramOperation.type to DiagramOperation.operation across all files (MCP server, web app, hooks, components, system prompts) - Adds JSON examples in tool descriptions to show correct format - Updates all test data to use the new field name Affected files: - lib/utils.ts - app/api/chat/route.ts - hooks/use-diagram-tool-handlers.ts - components/chat-message-display.tsx - lib/system-prompts.ts - packages/mcp-server/src/diagram-operations.ts - packages/mcp-server/src/index.ts - scripts/test-diagram-operations.mjs MCP server version bumped to 0.1.6 |
||
|
|
ed069afdea |
fix: use full IP for userId to prevent quota collision (#400)
* fix: use full IP for userId to prevent quota collision - Remove .slice(0, 8) from base64 encoded IP - Each IP now has unique userId (no /16 collision) - Affects: quota tracking, Langfuse tracing * refactor: extract getUserIdFromRequest to shared utility - Create lib/user-id.ts with shared function - Fix misleading 'privacy' comment (base64 is not privacy) - Remove duplicate code from chat and log-feedback routes |
||
|
|
c6b0e5ac62 |
fix: use totalUsage with all token types for accurate quota tracking (#381)
The onFinish callback's 'usage' only contains the final step's tokens, which underreports usage for multi-step tool calls (like diagram generation). Changed to 'totalUsage' which provides cumulative counts across all steps. Include all 4 token types for accurate counting: 1. inputTokens - non-cached input tokens 2. outputTokens - generated output tokens 3. cachedInputTokens - tokens read from prompt cache 4. inputTokenDetails.cacheWriteTokens - tokens written to cache Tested locally: - Request 1 (cache write): 334 + 62 + 0 + 6671 = 7,067 tokens - Request 2 (cache read): 334 + 184 + 6551 + 120 = 7,189 tokens - DynamoDB total: 14,256 ✓ |
||
|
|
97ae9395cd |
feat: add server-side quota tracking with DynamoDB (#379)
- Add dynamo-quota-manager.ts for atomic quota checks using ConditionExpression - Enforce daily request limit, daily token limit, and TPM limit - Return 429 with quota details (type, used, limit) when exceeded - Quota is opt-in: only enabled when DYNAMODB_QUOTA_TABLE env var is set - Remove client-side quota enforcement (server is now source of truth) - Simplify use-quota-manager.tsx to only display toasts - Add @aws-sdk/client-dynamodb dependency |
||
|
|
5ec05eb100 |
refactor: simplify Langfuse integration with AI SDK 6 (#375)
- Remove manual token attribute setting (AI SDK 6 telemetry auto-reports) - Use totalTokens directly instead of inputTokens + outputTokens calculation - Fix sessionId bug in log-save/log-feedback (prevents wrong trace attachment) - Hash IP addresses for privacy instead of storing raw IPs - Fix isLangfuseEnabled() to check both keys for consistency |
||
|
|
a0fbc0ad33 |
fix: use last user message for Langfuse trace input (#371)
In multi-step tool flows, messages array contains assistant messages from previous steps. Using messages[messages.length - 1] would record the assistant's response as trace input instead of the user's question. |
||
|
|
5262b7bfb2 |
chore: upgrade AI SDK to v6.0.1 (#369)
- Upgrade ai package from ^5.0.89 to ^6.0.1 - Upgrade @ai-sdk/* provider packages to latest v3/v4 - Update convertToModelMessages call to async (new API) - Fix usage.cachedInputTokens to usage.inputTokenDetails?.cacheReadTokens |
||
|
|
85cb441e26 |
feat: multi-provider model configuration with UI/UX improvements (#355)
* feat: add multi-provider model configuration - Add model config dialog for managing multiple AI providers - Support for OpenAI, Anthropic, Google, Azure, Bedrock, OpenRouter, DeepSeek, SiliconFlow, Ollama, and AI Gateway - Add model selector dropdown in chat panel header - Add API key validation endpoint - Add custom model ID input with keyboard navigation - Fix hover highlight in Command component - Add suggested models for each provider including latest Claude 4.5 series - Store configuration locally in browser * feat: improve model config UI and move selector to chat input - Move model selector from header to chat input (left of send button) - Add per-model validation status (queued, running, valid, invalid) - Filter model selector to only show verified models - Add editable model IDs in config dialog - Add custom model input field alongside suggested models dropdown - Fix hover states on provider buttons and select triggers - Update OpenAI suggested models with GPT-5 series - Add alert-dialog component for delete confirmation * refactor: revert shadcn component changes, apply hover fix at usage site * feat: add AWS credentials support for Bedrock provider - Add AWS Access Key ID, Secret Access Key, Region fields for Bedrock - Show different credential fields based on provider type - Update validation API to handle Bedrock with AWS credentials - Add region selector with common AWS regions * fix: reset Test button after validation completes * fix: reset validation button to Test after success * fix: complete bedrock support and UI/UX improvements - Add bedrock to ALLOWED_CLIENT_PROVIDERS for client credentials - Pass AWS credentials through full chain (headers → API → provider) - Replace non-existent GPT-5 models with real ones (o1, o3-mini) - Add accessibility: aria-labels, focus-visible rings, inline errors - Add more AWS regions (Ohio, London, Paris, Mumbai, Seoul, São Paulo) - Fix setTimeout cleanup with useRef on component unmount - Fix TypeScript type consistency in getSelectedAIConfig fallback * chore: remove unused code - Remove unused setAccessCodeRequired state in chat-panel.tsx - Remove unused getSelectedModel export in model-config.ts * fix: UI/UX improvements for model configuration dialog - Add gradient header styling with icon badge - Change Configuration section icon from Key to Settings2 - Add duplicate model detection with warning banner and inline removal - Filter out already-added models from suggestions dropdown - Add type-to-confirm for deleting providers with 3+ models - Enhance delete confirmation dialog with warning icon - Improve model selector discoverability (show model name + chevron) - Add truncation for long model names with title tooltip - Remove AI provider settings from Settings dialog (now in Model Config) - Extract ValidationButton into reusable component * fix: prevent duplicate model IDs within same provider - Block adding model if ID already exists in provider - Block editing model ID to match existing model in provider * fix: improve duplicate model ID notifications - Add toast notification when trying to add duplicate model - Allow free typing when editing model ID, validate on blur - Show warning toast instead of blocking input * fix: improve duplicate model validation UX in config dialog - Add inline error display for duplicate model IDs - Show red border on input when error exists - Validate on blur with shake animation for edit errors - Prevent saving empty model names - Clear errors when user starts typing - Simplify error styling (small red text, no heavy chips) |
||
|
|
f087b54ee4 |
feat: add get_shape_library tool for AI icon discovery (#335)
* feat: add get_shape_library tool for AI icon discovery - Add server-side tool that returns shape library documentation - AI can fetch icon/shape names on-demand before generating diagrams - Includes path traversal protection and input sanitization - Library index embedded in tool description for discoverability - Supports 33 libraries: AWS, Azure, GCP, Kubernetes, Cisco, etc. * fix: improve get_shape_library error handling and imports - Move fs/path imports to top of file (avoid dynamic imports per call) - Distinguish file-not-found vs other errors in catch block - Include invalid input in validation error message - Log unexpected errors for debugging * docs: add get_shape_library to system prompt tool list - Add Tool4 (get_shape_library) to available tools section - Add usage guidance in 'Choose the right tool' section - Update AWS icons note to reference get_shape_library for icon discovery * fix: display get_shape_library tool output in chat UI * fix: correct state check for get_shape_library output display * fix: make get_shape_library output respect fold state * style: auto-format with Biome --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> |
||
|
|
cd76fa615e |
fix: edit_diagram streaming and JSON repair improvements (#271)
- Add shared editDiagramOriginalXmlRef between streaming preview and tool handler to avoid conflicts when applying operations (fixes "cell already exists" errors) - Add JSON repair preprocessing to fix LLM-generated malformed JSON like `:=` - Filter out tool calls with invalid/undefined inputs from interrupted streaming - Remove perf console logs |
||
|
|
f175276872 |
refactor: replace text-based edit_diagram with ID-based operations (#267)
* refactor: replace text-based edit_diagram with ID-based operations - Add applyDiagramOperations() function using DOMParser for ID lookup - New schema: operations array with type (update/add/delete), cell_id, new_xml - Update chat-panel.tsx handler for new operations format - Update OperationsDisplay component to show operation type and cell_id - Simplify system prompts with new ID-based examples - Add ID validation for add operations - Add warning for edges referencing deleted cells * fix: add ID validation to update operation and remove dead code - Add ID mismatch validation to update operation (consistency with add) - Remove orphaned replaceXMLParts function (~300 lines of dead code) - Update cell_id schema description for clarity - Add unit tests for applyDiagramOperations (11 tests) |
||
|
|
f743219c03 |
feat: add minimal style mode toggle for faster diagram generation (#260)
* feat: add minimal style mode toggle for faster diagram generation - Add Minimal/Styled toggle switch in chat input UI - When enabled, removes color/style instructions from system prompt - Faster generation with plain black/white diagrams - Improves XML auto-fix: handle foreign tags, extra closing tags, trailing garbage - Fix isMxCellXmlComplete to strip Anthropic function-calling wrappers - Add debug logging for truncation detection diagnosis * fix: prevent false XML parse errors during streaming - Escape unescaped & characters in convertToLegalXml() before DOMParser validation - Only log console.error for final output, not during streaming updates - Prevents Next.js dev mode error overlay from showing for expected streaming states |
||
|
|
0851b32b67 |
refactor: simplify LLM XML format to output bare mxCells only (#254)
* refactor: simplify LLM XML format to output bare mxCells only - Update wrapWithMxFile() to always add root cells (id=0, id=1) automatically - LLM now generates only mxCell elements starting from id=2 (no wrapper tags) - Update system prompts and tool descriptions with new format instructions - Update cached responses to remove root cells and wrapper tags - Update truncation detection to check for complete mxCell endings - Update documentation in xml_guide.md * fix: address PR review issues for XML format refactor - Fix critical bug: inconsistent truncation check using old </root> pattern - Fix stale error message referencing </root> tag - Add isMxCellXmlComplete() helper for consistent truncation detection - Improve regex patterns to handle any attribute order in root cells - Update wrapWithMxFile JSDoc to document root cell removal behavior * fix: handle non-self-closing root cells in wrapWithMxFile regex |
||
|
|
66bd0e5493 |
feat: add append_diagram tool and improve truncation handling (#252)
* feat: add append_diagram tool for truncation continuation When LLM output hits maxOutputTokens mid-generation, instead of failing with an error loop, the system now: 1. Detects truncation (missing </root> in XML) 2. Stores partial XML and tells LLM to use new append_diagram tool 3. LLM continues generating from where it stopped 4. Fragments are accumulated until XML is complete 5. Server limits to 5 steps via stepCountIs(5) Key changes: - Add append_diagram tool definition in route.ts - Add append_diagram handler in chat-panel.tsx - Track continuation mode separately from error mode - Continuation mode has unlimited retries (not counted against limit) - Error mode still limited to MAX_AUTO_RETRY_COUNT (1) - Update system prompts to document append_diagram tool * fix: show friendly message and yellow badge for truncated output - Add yellow 'Truncated' badge in UI instead of red 'Error' when XML is incomplete - Show friendly error message for toolUse.input is invalid errors - Built on top of append_diagram continuation feature * refactor: remove debug logs and simplify truncation state - Remove all debug console.log statements - Remove isContinuationModeRef, derive from partialXmlRef.current.length > 0 * docs: fix append_diagram instructions for consistency - Change 'Do NOT include' to 'Do NOT start with' (clearer intent) - Add <mxCell id="0"> to prohibited start patterns - Change 'closing tags </root></mxGraphModel>' to just '</root>' (wrapWithMxFile handles the rest) |
||
|
|
987dc9f026 |
fix: add configurable MAX_OUTPUT_TOKENS to prevent truncation (#251)
- Add MAX_OUTPUT_TOKENS env var (fixes output truncation with Bedrock) - Remove redundant fixToolCallInputs function - Remove jsonrepair dependency - Consolidate duplicate lastMessage/userInputText variables |
||
|
|
e321ba7959 |
chore: optimize Vercel costs by removing analytics and configuring functions (#238)
- Create vercel.json with optimized function settings: - Chat API: 512MB memory, 120s timeout - Other APIs: 256MB memory, 10s timeout - Remove @vercel/analytics package and imports - Reduce chat route maxDuration from 300s to 120s Expected savings: $2-4/month, keeping costs under $20 included credit |
||
|
|
97cc0a07dc |
fix: disable history XML replacement by default (#217)
Some models (e.g. minimax) copy placeholder text instead of generating fresh XML, causing tool call validation failures and infinite loops. Added ENABLE_HISTORY_XML_REPLACE env var (default: false) to control this behavior. |
||
|
|
a047a6ff97 |
feat: Display AI reasoning/thinking blocks in chat interface (#152)
* feat: Add reasoning/thinking blocks display in chat interface * feat: add multi-provider options support and replace custom reasoning UI with AI Elements * resolve conflicting reasoning configs and correct provider-specific reasoning parameters * try to solve conflict * fix: simplify reasoning display and remove unnecessary dependencies - Remove Streamdown dependency (~5MB) - reasoning is plain text only - Fix Bedrock providerOptions merging for Claude reasoning configs - Remove unsupported DeepSeek reasoning configuration - Clean up unused environment variables (REASONING_BUDGET_TOKENS, REASONING_EFFORT, DEEPSEEK_REASONING_*) - Remove dead commented code from route.ts Reasoning blocks contain plain thinking text and don't need markdown/diagram/code rendering. * feat: comprehensive reasoning support improvements Major improvements: - Auto-enable reasoning display for all supported models - Fix provider-specific reasoning configurations - Remove unnecessary Streamdown dependency (~5MB) - Clean up debug logging Provider changes: - OpenAI: Auto-enable reasoningSummary for o1/o3/gpt-5 models - Google: Auto-enable includeThoughts for Gemini 2.5/3 models - Bedrock: Restrict reasoningConfig to only Claude/Nova (fixes MiniMax error) - Ollama: Add thinking support for qwen3-like models Other improvements: - Remove ENABLE_REASONING toggle (always enabled) - Fix Bedrock providerOptions merging for Claude - Simplify reasoning component (plain text rendering) - Clean up unused environment variables * fix: critical bugs and documentation gaps in reasoning support Critical fixes: - Fix Bedrock shallow merge bug (deep merge preserves anthropicBeta + reasoningConfig) - Add parseInt validation with parseIntSafe helper (prevents NaN errors) - Validate all numeric env vars with min/max ranges Documentation improvements: - Add BEDROCK_REASONING_BUDGET_TOKENS and BEDROCK_REASONING_EFFORT to env.example - Add OLLAMA_ENABLE_THINKING to env.example - Update JSDoc with accurate env var list and ranges Code cleanup: - Remove debug console.log statements from route.ts - Refactor duplicate providerOptions assignments --------- Co-authored-by: Dayuan Jiang <[email protected]> Co-authored-by: Dayuan Jiang <[email protected]> |
||
|
|
d2ba133eaf |
feat: add PDF and text file upload support (#205)
- Add client-side PDF text extraction using unpdf library - Support text files (.txt, .md, .json, .csv, .py, .js, .ts, etc.) - Add file preview with character count for PDF/text files - Add 150k character limit for extracted content - Highlight Paper to Diagram example with NEW badge - Fix React hydration error by adding explicit IDs to ResizablePanelGroup - Remove code duplication by centralizing file utilities in pdf-utils.ts |
||
|
|
43e5993f47 |
fix: improve LLM diagram context awareness and image preview (#202)
- Add replaceHistoricalToolInputs to replace XML in tool calls with placeholders - Send both previousXml and current xml so LLM can understand user's manual edits - Update system message to mark current XML as authoritative source of truth - Fix React StrictMode issue with blob URL cleanup in FilePreviewList - Add unoptimized prop to Image components for blob URLs |
||
|
|
97ab82e027 |
feat: add bring-your-own-API-key support (#186)
- Add AI provider settings to config panel (provider, model, API key, base URL) - Support 7 providers: OpenAI, Anthropic, Google, Azure, OpenRouter, DeepSeek, SiliconFlow - Client API keys stored in localStorage, never stored on server - Client settings override server env vars when provided - Skip server credential validation when client provides API key - Bypass usage limits (request/token/TPM) when using own API key - Add /api/config endpoint for fetching usage limits - Add privacy notices to settings dialog, about pages, and quota toast - Add clear settings button to reset saved API keys - Update README files (EN/CN/JA) with BYOK documentation Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
967d63c57e |
feat: support minimax model (#185)
* feat: support minimax model with XML wrapping fix - Add wrapWithMxFile utility to properly wrap XML for draw.io - Fix 'Not a diagram file' error when model generates raw <root> XML - Add supportsPromptCaching check for conditional caching - Only enable Bedrock prompt caching for Claude models * docs: update model mention to minimax-m2 across About pages and READMEs - Update tooltip in chat-panel.tsx to mention minimax-m2 model change - Update English, Chinese, and Japanese About pages with model change info - Update English, Chinese, and Japanese READMEs with demo site model note --------- Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
95c5a75ca3 |
feat: Show detailed error messages instead of generic 'Internal server error' (#144) (#154)
* feat: Show detailed error messages instead of generic 'Internal server error' (#144) * refactor: simplify error handling logic per feedback * refactor: imported AI SDK error handler * fix: remove unused import and expand sensitive data filter - Remove unused NoSuchModelError import - Add 'secret', 'password', 'credential' to sensitive data filter --------- Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
622829b903 |
feat: add daily token limit with actual usage tracking (#171)
* feat: add daily token limit with actual usage tracking - Add DAILY_TOKEN_LIMIT env var for configurable daily token limit - Track actual tokens from Bedrock API response metadata (not estimates) - Server sends inputTokens + cachedInputTokens + outputTokens via messageMetadata - Client increments token count in onFinish callback with actual usage - Add NaN guards to prevent corrupted localStorage values - Add token limit toast notification with quota display - Remove client-side token estimation (was blocking legitimate requests) - Switch to js-tiktoken for client compatibility (pure JS, no WASM) * feat: add TPM (tokens per minute) rate limiting - Add 50k tokens/min client-side rate limit - Track tokens per minute with automatic minute rollover - Check TPM limit after daily limits pass - Show toast when rate limit reached - NaN guards for localStorage values * feat: make TPM limit configurable via TPM_LIMIT env var * chore: restore cache debug logs * fix: prevent race condition in TPM tracking checkTPMLimit was resetting TPM count to 0 when checking, which overwrote the count saved by incrementTPMCount. Now checkTPMLimit only reads and incrementTPMCount handles all writes. * chore: improve TPM limit error message clarity |
||
|
|
ecea8a6005 | fix: use static maxDuration value for Next.js 16 compatibility (#160) | ||
|
|
ee9267d54c |
chore: make maxDuration configurable via env variable (#157)
Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
8c431ee6ed |
fix: preserve message parts order in chat display (#151)
- Fix bug where text after tool calls was merged with initial text - Group consecutive text/file parts into bubbles while keeping tools in order - Parts now display as: plan -> tool_result -> additional text - Remove debug logs from fixToolCallInputs function Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
86420a42c6 |
fix: implement client-side caching for example diagrams (#150)
- Add client-side cache check in onFormSubmit to bypass API calls for example prompts - Use findCachedResponse to match input against cached examples - Directly set messages with cached tool response when example matches - Hide regenerate button for cached example responses (toolCallId starts with 'cached-') - Prevents unnecessary API calls when using example buttons Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
0baf21fadb |
fix: validate XML before displaying diagram to catch duplicate IDs (#147)
- Add validation to loadDiagram in diagram-context, returns error or null - display_diagram and edit_diagram tools now check validation result - Return error to AI agent with state: output-error so it can retry - Skip validation for trusted sources (localStorage, history, internal templates) - Add debug logging for tool call inputs to diagnose Bedrock API issues |
||
|
|
8b578a456e |
fix: Remove hardcoded temperature parameter to support models that don't support it (#133)
* Fix: remove hardcoded temperature parameter to support reasoning models * feat: make temperature configurable via AI_TEMPERATURE env var - Instead of removing temperature entirely, make it optional via env var - Set AI_TEMPERATURE=0 for deterministic output (recommended for diagrams) - Leave unset for models that don't support temperature (e.g., GPT-5.1 reasoning) * docs: add AI_TEMPERATURE env var documentation - Update env.example with AI_TEMPERATURE option - Update README.md configuration section - Add Temperature Setting section in ai-providers.md * docs: add TEMPERATURE env var documentation - Update env.example with TEMPERATURE option - Update README.md, README_CN.md, README_JA.md configuration sections - Add Temperature Setting section in ai-providers.md - Update route.ts to use TEMPERATURE env var --------- Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
3894abd9ed |
feat: add tool call JSON repair and Bedrock compatibility (#127)
- Add fixToolCallInputs() to fix Bedrock API requirement (JSON object, not string) - Add experimental_repairToolCall for malformed JSON from model - Add stepCountIs(5) limit to prevent infinite loops - Update edit_diagram tool description with JSON escaping warning Co-authored-by: dayuan.jiang <[email protected]> |
||
|
|
cbb92bd636 | fix: set maxDuration to 60 for Vercel hobby plan (#122) |