mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-10-03 16:27:47 +08:00
Compare commits
base: i/next-ai-draw-io:feat-admin-settings-panel
i/next-ai-draw-io:main
i/next-ai-draw-io:renovate/major-major-dependencies
i/next-ai-draw-io:renovate/core-framework-packages
i/next-ai-draw-io:renovate/npm-electron-vulnerability
i/next-ai-draw-io:renovate/npm-next-vulnerability
i/next-ai-draw-io:renovate/major-core-framework-packages
i/next-ai-draw-io:renovate/electron-packages
i/next-ai-draw-io:renovate/biome
i/next-ai-draw-io:fix/output-token-budget
i/next-ai-draw-io:feat/declarative-diagram-engine
i/next-ai-draw-io:fix/default-max-output-tokens
i/next-ai-draw-io:ci/biome-exclude-public
i/next-ai-draw-io:codex/fix-model-selector-overflow
i/next-ai-draw-io:feat/mcp-load-diagram
i/next-ai-draw-io:ci/publish-mcp-npm
i/next-ai-draw-io:fix/ssrf-parse-url-dns
i/next-ai-draw-io:fix/remove-image-input-detection
i/next-ai-draw-io:fix/ai-model-comma-multi
i/next-ai-draw-io:ci/pin-biome
i/next-ai-draw-io:feat-admin-settings-panel
i/next-ai-draw-io:refresh-suggested-models
i/next-ai-draw-io:fix/bedrock-tool-streaming-zod
i/next-ai-draw-io:fix/parse-url-ssrf
i/next-ai-draw-io:chore/bump-version-0.4.16
i/next-ai-draw-io:chore/remove-dead-close-prevention-code
i/next-ai-draw-io:fix/electron-iframe-beforeunload
i/next-ai-draw-io:fix/biome-schema-version
i/next-ai-draw-io:dependabot/npm_and_yarn/npm_and_yarn-344d30ea66
i/next-ai-draw-io:chore/bump-version-0.4.15
i/next-ai-draw-io:fix/mcp-create-diagram-tool-description
i/next-ai-draw-io:fix/chat-lobby-panel-visibility
i/next-ai-draw-io:fix/streaming-perf-prism-scroll
i/next-ai-draw-io:chore/update-bundled-drawio-version
i/next-ai-draw-io:fix/mcp-server-body-size-limit
i/next-ai-draw-io:chore/remove-mcp-preview-labels
i/next-ai-draw-io:fix/mcp-server-bind-localhost
i/next-ai-draw-io:feat/auto-update
i/next-ai-draw-io:fix/zoom-reset-and-indexeddb-conflict
i/next-ai-draw-io:fix/mcp-server-cors-security
i/next-ai-draw-io:fix/electron-startup-port-issues
i/next-ai-draw-io:feat/material-design-icons
i/next-ai-draw-io:fix/kimi-k2.5-image-support
i/next-ai-draw-io:pr-657-updated
i/next-ai-draw-io:fix/idb-closing-retry
i/next-ai-draw-io:feat/add-zh-hant-locale
i/next-ai-draw-io:fix/idb-closing-retry-clean
i/next-ai-draw-io:fix/electron-beforeunload-v2
i/next-ai-draw-io:fix/electron-close-beforeunload
i/next-ai-draw-io:fix/upgrade-wrangler-cve-2026-0933
i/next-ai-draw-io:features/validate-diagram-with-vlm
i/next-ai-draw-io:pr-586
i/next-ai-draw-io:fix/edit-diagram-json-quote-escaping
i/next-ai-draw-io:fix/autosave-sync-user-modifications
i/next-ai-draw-io:copilot/sub-pr-579
i/next-ai-draw-io:fix/user-apikey-baseurl-isolation
i/next-ai-draw-io:chore/add-opencode-to-gitignore
i/next-ai-draw-io:chore/reduce-renovate-noise
i/next-ai-draw-io:feature/url-content-extraction
i/next-ai-draw-io:fix/doubao-multimodal-provider
i/next-ai-draw-io:test/add-testing-infrastructure
i/next-ai-draw-io:fix/save-toast-after-download
i/next-ai-draw-io:fix/docker-compose-yaml-syntax
i/next-ai-draw-io:fix/flash-of-default-content-on-refresh
i/next-ai-draw-io:fix/image-not-supported-error-detection
i/next-ai-draw-io:fix-aichat
i/next-ai-draw-io:fix/deepseek-image-error-message
i/next-ai-draw-io:docs/i18n-structure
i/next-ai-draw-io:chore/cleanup-header-about-link
i/next-ai-draw-io:fix/404-error
i/next-ai-draw-io:fix/cascade-delete-edit-diagram
i/next-ai-draw-io:chore/cleanup-root-folder
i/next-ai-draw-io:fix/move-utility-buttons-to-settings
i/next-ai-draw-io:fix/auto-format-fork-prs
i/next-ai-draw-io:remove-electron-settings
i/next-ai-draw-io:refactor/extract-diagram-tool-handlers
i/next-ai-draw-io:fix/quota-token-counting
i/next-ai-draw-io:fix/continuation-retry-limit
i/next-ai-draw-io:chore/upgrade-ai-sdk-v6
i/next-ai-draw-io:fix/openai-reasoning-not-showing
i/next-ai-draw-io:debug/langfuse-instrumentation-log
i/next-ai-draw-io:fix/langfuse-standalone-instrumentation
i/next-ai-draw-io:feat/multi-provider-model-config
i/next-ai-draw-io:fix/electron-workflow-permissions
i/next-ai-draw-io:feat/mcp-history
i/next-ai-draw-io:feat/mcp-xml-validation
i/next-ai-draw-io:chore/add-auto-format-workflow
i/next-ai-draw-io:revert-293-fix/drawio-save-button
i/next-ai-draw-io:fix/drawio-save-button
i/next-ai-draw-io:feature/mcp-server
i/next-ai-draw-io:fix/truncation-error-handling
i/next-ai-draw-io:fix/shorten-toast-duration
i/next-ai-draw-io:fix/xml-auto-fix-99-percent
i/next-ai-draw-io:fix/limit-auto-retry-count
i/next-ai-draw-io:refactor/dry-eliminate-code-duplication
i/next-ai-draw-io:cloudflare-worker-wip
i/next-ai-draw-io:chore/add-tone-style-guidelines
i/next-ai-draw-io:fix/bug-fixes
i/next-ai-draw-io:fix/hydration-and-prompts
i/next-ai-draw-io:feat/enhance-system-prompt
i/next-ai-draw-io:fix/restore-status-notice
i/next-ai-draw-io:fix/prevent-back-gesture-navigation
i/next-ai-draw-io:feat/message-edit-regenerate
i/next-ai-draw-io:feat/message-edit-regenerate-and-langfuse-feedback
i/next-ai-draw-io:feat/langfuse-integration
i/next-ai-draw-io:feat/improve-cache-and-edit-tracking
i/next-ai-draw-io:feat/add-deepseek-provider
i/next-ai-draw-io:fix/empty-content-array-filter
i/next-ai-draw-io:feat/tool-streaming
i/next-ai-draw-io:test/replicate-pr21-copy-button
i/next-ai-draw-io:feature/claude-code-actions
i/next-ai-draw-io:feature/improve-pr-review-workflow
i/next-ai-draw-io:docs/update-examples
i/next-ai-draw-io:fix/resize
i/next-ai-draw-io:chore/fix-readme
i/next-ai-draw-io:chore/modify_readme
i/next-ai-draw-io:v0.4.16
i/next-ai-draw-io:v0.4.15
i/next-ai-draw-io:v0.4.14
i/next-ai-draw-io:v0.4.13
i/next-ai-draw-io:v0.4.12
i/next-ai-draw-io:v0.4.11
i/next-ai-draw-io:v0.4.10
i/next-ai-draw-io:v0.4.9
i/next-ai-draw-io:v0.4.8
i/next-ai-draw-io:v0.4.7
i/next-ai-draw-io:v0.4.6
i/next-ai-draw-io:v0.4.5
i/next-ai-draw-io:v0.4.4
i/next-ai-draw-io:v0.4.3
i/next-ai-draw-io:v0.4.1
i/next-ai-draw-io:v0.4.0
i/next-ai-draw-io:v0.3.0
i/next-ai-draw-io:v0.2.0
..
compare: i/next-ai-draw-io:ci/pin-biome
i/next-ai-draw-io:renovate/major-major-dependencies
i/next-ai-draw-io:renovate/core-framework-packages
i/next-ai-draw-io:renovate/npm-electron-vulnerability
i/next-ai-draw-io:renovate/npm-next-vulnerability
i/next-ai-draw-io:main
i/next-ai-draw-io:renovate/major-core-framework-packages
i/next-ai-draw-io:renovate/electron-packages
i/next-ai-draw-io:renovate/biome
i/next-ai-draw-io:fix/output-token-budget
i/next-ai-draw-io:feat/declarative-diagram-engine
i/next-ai-draw-io:fix/default-max-output-tokens
i/next-ai-draw-io:ci/biome-exclude-public
i/next-ai-draw-io:codex/fix-model-selector-overflow
i/next-ai-draw-io:feat/mcp-load-diagram
i/next-ai-draw-io:ci/publish-mcp-npm
i/next-ai-draw-io:fix/ssrf-parse-url-dns
i/next-ai-draw-io:fix/remove-image-input-detection
i/next-ai-draw-io:fix/ai-model-comma-multi
i/next-ai-draw-io:ci/pin-biome
i/next-ai-draw-io:feat-admin-settings-panel
i/next-ai-draw-io:refresh-suggested-models
i/next-ai-draw-io:fix/bedrock-tool-streaming-zod
i/next-ai-draw-io:fix/parse-url-ssrf
i/next-ai-draw-io:chore/bump-version-0.4.16
i/next-ai-draw-io:chore/remove-dead-close-prevention-code
i/next-ai-draw-io:fix/electron-iframe-beforeunload
i/next-ai-draw-io:fix/biome-schema-version
i/next-ai-draw-io:dependabot/npm_and_yarn/npm_and_yarn-344d30ea66
i/next-ai-draw-io:chore/bump-version-0.4.15
i/next-ai-draw-io:fix/mcp-create-diagram-tool-description
i/next-ai-draw-io:fix/chat-lobby-panel-visibility
i/next-ai-draw-io:fix/streaming-perf-prism-scroll
i/next-ai-draw-io:chore/update-bundled-drawio-version
i/next-ai-draw-io:fix/mcp-server-body-size-limit
i/next-ai-draw-io:chore/remove-mcp-preview-labels
i/next-ai-draw-io:fix/mcp-server-bind-localhost
i/next-ai-draw-io:feat/auto-update
i/next-ai-draw-io:fix/zoom-reset-and-indexeddb-conflict
i/next-ai-draw-io:fix/mcp-server-cors-security
i/next-ai-draw-io:fix/electron-startup-port-issues
i/next-ai-draw-io:feat/material-design-icons
i/next-ai-draw-io:fix/kimi-k2.5-image-support
i/next-ai-draw-io:pr-657-updated
i/next-ai-draw-io:fix/idb-closing-retry
i/next-ai-draw-io:feat/add-zh-hant-locale
i/next-ai-draw-io:fix/idb-closing-retry-clean
i/next-ai-draw-io:fix/electron-beforeunload-v2
i/next-ai-draw-io:fix/electron-close-beforeunload
i/next-ai-draw-io:fix/upgrade-wrangler-cve-2026-0933
i/next-ai-draw-io:features/validate-diagram-with-vlm
i/next-ai-draw-io:pr-586
i/next-ai-draw-io:fix/edit-diagram-json-quote-escaping
i/next-ai-draw-io:fix/autosave-sync-user-modifications
i/next-ai-draw-io:copilot/sub-pr-579
i/next-ai-draw-io:fix/user-apikey-baseurl-isolation
i/next-ai-draw-io:chore/add-opencode-to-gitignore
i/next-ai-draw-io:chore/reduce-renovate-noise
i/next-ai-draw-io:feature/url-content-extraction
i/next-ai-draw-io:fix/doubao-multimodal-provider
i/next-ai-draw-io:test/add-testing-infrastructure
i/next-ai-draw-io:fix/save-toast-after-download
i/next-ai-draw-io:fix/docker-compose-yaml-syntax
i/next-ai-draw-io:fix/flash-of-default-content-on-refresh
i/next-ai-draw-io:fix/image-not-supported-error-detection
i/next-ai-draw-io:fix-aichat
i/next-ai-draw-io:fix/deepseek-image-error-message
i/next-ai-draw-io:docs/i18n-structure
i/next-ai-draw-io:chore/cleanup-header-about-link
i/next-ai-draw-io:fix/404-error
i/next-ai-draw-io:fix/cascade-delete-edit-diagram
i/next-ai-draw-io:chore/cleanup-root-folder
i/next-ai-draw-io:fix/move-utility-buttons-to-settings
i/next-ai-draw-io:fix/auto-format-fork-prs
i/next-ai-draw-io:remove-electron-settings
i/next-ai-draw-io:refactor/extract-diagram-tool-handlers
i/next-ai-draw-io:fix/quota-token-counting
i/next-ai-draw-io:fix/continuation-retry-limit
i/next-ai-draw-io:chore/upgrade-ai-sdk-v6
i/next-ai-draw-io:fix/openai-reasoning-not-showing
i/next-ai-draw-io:debug/langfuse-instrumentation-log
i/next-ai-draw-io:fix/langfuse-standalone-instrumentation
i/next-ai-draw-io:feat/multi-provider-model-config
i/next-ai-draw-io:fix/electron-workflow-permissions
i/next-ai-draw-io:feat/mcp-history
i/next-ai-draw-io:feat/mcp-xml-validation
i/next-ai-draw-io:chore/add-auto-format-workflow
i/next-ai-draw-io:revert-293-fix/drawio-save-button
i/next-ai-draw-io:fix/drawio-save-button
i/next-ai-draw-io:feature/mcp-server
i/next-ai-draw-io:fix/truncation-error-handling
i/next-ai-draw-io:fix/shorten-toast-duration
i/next-ai-draw-io:fix/xml-auto-fix-99-percent
i/next-ai-draw-io:fix/limit-auto-retry-count
i/next-ai-draw-io:refactor/dry-eliminate-code-duplication
i/next-ai-draw-io:cloudflare-worker-wip
i/next-ai-draw-io:chore/add-tone-style-guidelines
i/next-ai-draw-io:fix/bug-fixes
i/next-ai-draw-io:fix/hydration-and-prompts
i/next-ai-draw-io:feat/enhance-system-prompt
i/next-ai-draw-io:fix/restore-status-notice
i/next-ai-draw-io:fix/prevent-back-gesture-navigation
i/next-ai-draw-io:feat/message-edit-regenerate
i/next-ai-draw-io:feat/message-edit-regenerate-and-langfuse-feedback
i/next-ai-draw-io:feat/langfuse-integration
i/next-ai-draw-io:feat/improve-cache-and-edit-tracking
i/next-ai-draw-io:feat/add-deepseek-provider
i/next-ai-draw-io:fix/empty-content-array-filter
i/next-ai-draw-io:feat/tool-streaming
i/next-ai-draw-io:test/replicate-pr21-copy-button
i/next-ai-draw-io:feature/claude-code-actions
i/next-ai-draw-io:feature/improve-pr-review-workflow
i/next-ai-draw-io:docs/update-examples
i/next-ai-draw-io:fix/resize
i/next-ai-draw-io:chore/fix-readme
i/next-ai-draw-io:chore/modify_readme
i/next-ai-draw-io:v0.4.16
i/next-ai-draw-io:v0.4.15
i/next-ai-draw-io:v0.4.14
i/next-ai-draw-io:v0.4.13
i/next-ai-draw-io:v0.4.12
i/next-ai-draw-io:v0.4.11
i/next-ai-draw-io:v0.4.10
i/next-ai-draw-io:v0.4.9
i/next-ai-draw-io:v0.4.8
i/next-ai-draw-io:v0.4.7
i/next-ai-draw-io:v0.4.6
i/next-ai-draw-io:v0.4.5
i/next-ai-draw-io:v0.4.4
i/next-ai-draw-io:v0.4.3
i/next-ai-draw-io:v0.4.1
i/next-ai-draw-io:v0.4.0
i/next-ai-draw-io:v0.3.0
i/next-ai-draw-io:v0.2.0
2
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
c00d8bbc18 |
ci: pin Biome to 2.4.13 in auto-format workflow
CI used npx @biomejs/biome@latest, which drifted to 2.5.0 and failed the format job (deprecated config fields + stricter parsing of existing files like public/resnet50.svg) on unrelated PRs. Pin to the version already in package.json so CI matches local and pre-commit runs. |
||
|
|
449e4c4e26 |
feat: add file-based admin settings panel at /admin (#866)
* feat: add file-based admin settings panel at /admin
Settings saved in the panel are written to data/settings.json and
overlaid onto process.env, taking precedence over environment
variables and applying immediately without restart. Enable by setting
ADMIN_PASSWORD; on serverless platforms without persistent disk the
panel degrades to read-only.
* polish: admin panel UI improvements
- Provider logos in credential rows (shared ProviderLogo component,
extracted from model-config-dialog)
- Scroll-spy active state in the sidebar nav
- Green success state in the save bar that clears after a few seconds
- Wider content column (max-w-6xl) for less wasted space on desktop
* polish: admin panel section toggles and reorder
- Move Quota & Rate Limits to the end of the settings page
- Add enable switches to Observability and Quota sections; default off
with fields grayed out, auto-on when any field is already configured
* polish: make section enable switch more visible
Wrap the switch in a labeled pill ('Enabled'/'Disabled') with border
and background so the off state is clearly visible.
* refactor: derive admin registry from PROVIDER_INFO, simplify page state
- Provider options, labels, and base-URL placeholders now come from
PROVIDER_INFO instead of hand-copied lists (fixes SiliconFlow .com/.cn
placeholder drift; panel names now match the model-config dialog)
- Replace free-text subgroup strings + SUBGROUP_PROVIDERS reverse map
with a typed provider field on SettingDef
- Precompute SETTINGS_BY_GROUP and PROVIDER_SUBGROUPS at module level
- Merge justSaved into saveMessage, drop unused mainRef, hoist
fetchSettings out of the component, dedupe savedText logic
- Serialize from SETTINGS_REGISTRY directly; json validators in a map
instead of a hardcoded key check
- Make allowPrivateUrls a function so ALLOW_PRIVATE_URLS edits in the
admin panel apply without restart
* feat: graphical model management in admin panel
Replace the provider credential fields and raw AI_MODELS_CONFIG JSON
textarea with a Models section mirroring the in-app model settings UI:
provider instance list with logos, credential fields per provider type,
model add/remove with suggestions, per-model connectivity test, and a
default-provider star.
On save the server derives everything the runtime needs into
settings.json: credential env vars (with _2 suffixes for multiple
instances of one provider), AI_MODELS_CONFIG, and AI_PROVIDER/AI_MODEL
for the default. Secrets round-trip as masked markers and are never
sent back to the browser. The general settings registry now only
covers non-provider settings (generation, access, features,
observability, quota).
* fix: allow testing unsaved providers in admin panel
The test button previously looked up credentials by providerId in the
saved settings, so testing a newly added (unsaved) provider failed with
'Unknown provider or model'. The test endpoint now accepts the client's
current provider state; newly typed secrets are used as-is and masked
markers are resolved against the stored values, so testing works both
before and after saving.
* fix: merge env AI_MODELS_CONFIG with admin panel providers
Previously, saving in the admin panel wrote a complete AI_MODELS_CONFIG
into settings.json, which (by overlay precedence) replaced any config
from .env or ai-models.json — admins lost their env-configured models.
The panel no longer writes AI_MODELS_CONFIG. Instead its providers are
merged with the env baseline at read time in loadRawServerModelsConfig,
and panel credentials go to ADMIN_-prefixed env vars wired up via
apiKeyEnv/baseUrlEnv so they never shadow standard vars. Env-based
providers now appear read-only in the panel, name clashes are rejected,
and a panel default overrides the env default. data/ is now gitignored.
* fix: block global-credential providers already managed via env
Bedrock, Vertex AI, and Ollama credentials live in fixed env vars with
no apiKeyEnv redirection, so a panel instance of one of these would
silently override the credentials that env-configured models rely on.
The API now rejects saving such a provider when the env config already
uses that type, and the Add Provider dropdown disables it with a
'managed via env' note.
* fix: address admin panel review findings
- Security: test-model no longer resolves a stored secret when the
request's baseUrl/provider differs from the stored entry, closing a
path where a tampered baseUrl could exfiltrate a saved key
- Save failures are now visible: the save bar shows the error in red
(was masked by the persistent 'Unsaved changes' text), and per-field
validation errors from the settings API are surfaced under each field
- The Observability/Quota enable switch is now real: toggling off stages
deletion of the group's saved values, and the toggle no longer snaps
back to Enabled after saving
- Env provider's default star is hidden when a panel provider is the
active default (no more double star)
- Clearing a credential field reverts to the stored value instead of
silently deleting it; an explicit X button removes a stored secret
- Form inputs are disabled during an in-flight save
* refactor(admin): split 1549-line admin page into focused modules
Extract admin-shared.ts (types + fetch helper), setting-field.tsx
(registry-driven fields), and models-section.tsx (provider/model
manager) from page.tsx. Pure mechanical move, no behavior change.
* feat(admin): share credential fields with user dialog and localize panel
Extract ProviderCredentialsFields (display name + per-provider
credential inputs) used by both the user ModelConfigDialog and the
admin Models panel; secret input passed via renderSecret (plaintext
vs masked), test button via footer slot. Add full i18n for the admin
panel across en/zh/ja/zh-Hant, reusing modelConfig.* for shared parts.
* fix(admin): address Copilot review findings
- Reflect built-in defaults for boolean settings (ALLOW_PRIVATE_URLS
defaults on) and allow clearing a saved boolean back to default,
so the SSRF toggle matches actual runtime behavior.
- Harden JSON loading: filter settings values to strings only, and
schema-validate stored ADMIN_PROVIDERS entries, dropping malformed
ones instead of letting them reach runtime code.
- Set beforeunload returnValue so the unsaved-changes prompt shows in
all browsers; reject non-finite numbers in settings validation.
- Fix README/CN/JA docs that claimed the panel auto-generates
AI_MODELS_CONFIG (providers are merged at read time, not written).
- Add unit tests for corrupted-file value filtering and provider
schema validation.
* docs: move admin panel details to dedicated docs/{en,cn,ja}/admin-panel.md
The READMEs now carry a short blurb + link, matching the existing
per-topic docs (docker.md, ai-providers.md, ...). Removes the ~22-line
inline section and the duplicated data/settings.json mentions.
* fix(admin): address follow-up Copilot findings on the prior fixes
- loadAdminProviders now validates against a stored-shape schema where
secrets are plain strings, so a hand-edited ADMIN_PROVIDERS holding an
{isSet} marker is dropped instead of later crashing maskSecret().
- loadSettings guards against array values (typeof [] === 'object'),
which would otherwise overlay numeric keys onto process.env.
- Admin SecretInput uses the bare id so the shared component's
<Label htmlFor> stays associated (only one ProviderDetail mounts).
- Add tests: marker-secret rejection, array-values guard, bedrock
multi-secret round-trip.
|
1 changed files with 3 additions and 1 deletions
@@ -23,7 +23,9 @@ jobs:
|
||||
node-version: '24'
|
||||
|
||||
- name: Run Biome format
|
||||
run: npx @biomejs/biome@latest check --write --no-errors-on-unmatched .
|
||||
# Pin to the version in package.json so CI matches local/pre-commit
|
||||
# (npx @latest drifts — e.g. 2.5.0 broke this job on unrelated PRs).
|
||||
run: npx @biomejs/[email protected] check --write --no-errors-on-unmatched .
|
||||
|
||||
- name: Check for changes
|
||||
id: changes
|
||||
|
||||
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.