diff --git a/.changeset/require-owned-conversations.md b/.changeset/require-owned-conversations.md deleted file mode 100644 index c98d1e0f..00000000 --- a/.changeset/require-owned-conversations.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -'@smooai/smooth-operator': minor ---- - -SMOODEV-3412: `AppState::with_require_owned_conversations(true)` — let an org-authenticated host make ownerless conversations unreachable. - -`may_read_conversation` treats a conversation with no `user` participant as open to every principal. That is deliberate and load-bearing for anonymous/widget flows (th-909995): those principals own nothing, and the conversations they create are exactly the ownerless ones, so denying them locked callers out of their own sessions. - -An **org-authenticated** pot is the opposite case. Every caller is a real user, and the ownerless conversations in its org are the ones machines made — phone calls, SMS, widget chats. In SmooAI's `copilot-ws` that meant the operator's history picker listed **customer conversations**, and could resume them: a stored pointer bound a new session to a customer's phone call on every drawer open. - -The new flag makes ownerless unlistable, unresumable and unreadable. **Off by default**, so no existing host changes behaviour. - -It is checked before the scope match, so it covers `UserScope::Denied` too: an emailless principal owns nothing and must reach nothing. The flag therefore **fails closed** — enabling it with a verifier whose principals carry no `email` claim breaks the picker rather than leaking through it. Ship the claim first. diff --git a/dotnet/server/aspnetcore/SmooAI.SmoothOperator.Server.AspNetCore.csproj b/dotnet/server/aspnetcore/SmooAI.SmoothOperator.Server.AspNetCore.csproj index f3d6a49e..99d99c05 100644 --- a/dotnet/server/aspnetcore/SmooAI.SmoothOperator.Server.AspNetCore.csproj +++ b/dotnet/server/aspnetcore/SmooAI.SmoothOperator.Server.AspNetCore.csproj @@ -15,7 +15,7 @@ attribute. (Keep the element-form version out of comments: the sync regex replaces the first element-form match in the file.) --> SmooAI.SmoothOperator.Server.AspNetCore - 1.61.0 + 1.62.0 SmooAI ai;agent;llm;chat;smooth-operator;server;aspnetcore;websocket;smooai MIT diff --git a/dotnet/server/postgres/src/SmooAI.SmoothOperator.Server.Postgres.csproj b/dotnet/server/postgres/src/SmooAI.SmoothOperator.Server.Postgres.csproj index 3ca76493..c0f92afc 100644 --- a/dotnet/server/postgres/src/SmooAI.SmoothOperator.Server.Postgres.csproj +++ b/dotnet/server/postgres/src/SmooAI.SmoothOperator.Server.Postgres.csproj @@ -15,7 +15,7 @@ attribute. (Keep the element-form version out of comments: the sync regex replaces the first element-form match in the file.) --> SmooAI.SmoothOperator.Server.Postgres - 1.61.0 + 1.62.0 SmooAI ai;agent;llm;chat;smooth-operator;server;postgres;pgvector;smooai MIT diff --git a/dotnet/server/src/SmooAI.SmoothOperator.Server.csproj b/dotnet/server/src/SmooAI.SmoothOperator.Server.csproj index 030b9206..99706ff3 100644 --- a/dotnet/server/src/SmooAI.SmoothOperator.Server.csproj +++ b/dotnet/server/src/SmooAI.SmoothOperator.Server.csproj @@ -14,7 +14,7 @@ scripts/sync-versions.mjs (do NOT confuse with the SmooAI.SmoothOperator.Core PackageReference version below, which tracks the separately-published engine). --> SmooAI.SmoothOperator.Server - 1.61.0 + 1.62.0 SmooAI ai;agent;llm;chat;smooth-operator;server;websocket;smooai MIT diff --git a/examples/web-chat/CHANGELOG.md b/examples/web-chat/CHANGELOG.md index c7173af6..89e99951 100644 --- a/examples/web-chat/CHANGELOG.md +++ b/examples/web-chat/CHANGELOG.md @@ -1,5 +1,12 @@ # @smooai/smooth-operator-web-chat-example +## 0.0.127 + +### Patch Changes + +- Updated dependencies [714b7bb] + - @smooai/smooth-operator@1.62.0 + ## 0.0.126 ### Patch Changes diff --git a/examples/web-chat/package.json b/examples/web-chat/package.json index e67a5b03..b5afdb7c 100644 --- a/examples/web-chat/package.json +++ b/examples/web-chat/package.json @@ -1,6 +1,6 @@ { "name": "@smooai/smooth-operator-web-chat-example", - "version": "0.0.126", + "version": "0.0.127", "private": true, "description": "A smooth-web-like Vite + React chat client that drives a running smooth-operator server over its WebSocket protocol — token streaming, inline tool-call/result blocks, a conversation sidebar, and oldest-first history, all on top of the published @smooai/smooth-operator SDK.", "type": "module", diff --git a/go/version.go b/go/version.go index a496bdeb..fbef3fe5 100644 --- a/go/version.go +++ b/go/version.go @@ -5,4 +5,4 @@ package e2e // language artifacts. The real Go "publish" is a git tag (go/v); this // constant is the anchor that scripts/sync-versions.mjs keeps in sync with the // canonical npm version on every changeset release. -const Version = "1.61.0" +const Version = "1.62.0" diff --git a/python/pyproject.toml b/python/pyproject.toml index 63485f02..1c663cbb 100644 --- a/python/pyproject.toml +++ b/python/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "smooai-smooth-operator" -version = "1.61.0" +version = "1.62.0" description = "Python protocol types and native async WebSocket client for the smooth-operator protocol. Generated from the language-neutral JSON Schemas in spec/." readme = "README.md" license = { text = "MIT" } diff --git a/python/server/pyproject.toml b/python/server/pyproject.toml index 5c277ba0..37fe8c69 100644 --- a/python/server/pyproject.toml +++ b/python/server/pyproject.toml @@ -1,6 +1,6 @@ [project] name = "smooai-smooth-operator-server" -version = "1.61.0" +version = "1.62.0" description = "Native async WebSocket server for the smooth-operator protocol — parity with the Rust and C# reference servers, consuming the in-process smooai-smooth-operator-core engine." readme = "README.md" license = { text = "MIT" } diff --git a/rust/Cargo.lock b/rust/Cargo.lock index e4ff415d..dc6cec92 100644 --- a/rust/Cargo.lock +++ b/rust/Cargo.lock @@ -4118,7 +4118,7 @@ checksum = "8ed6a63f02c8539c91a8685a86f4099661ba3da017932f6ebbea6de3f0fa7c90" [[package]] name = "smooai-smooth-operator" -version = "1.61.0" +version = "1.62.0" dependencies = [ "anyhow", "async-trait", @@ -4152,7 +4152,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-backplane-nats" -version = "1.61.0" +version = "1.62.0" dependencies = [ "anyhow", "async-nats", @@ -4168,7 +4168,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-backplane-redis" -version = "1.61.0" +version = "1.62.0" dependencies = [ "anyhow", "async-trait", @@ -4184,7 +4184,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-dynamodb" -version = "1.61.0" +version = "1.62.0" dependencies = [ "anyhow", "async-trait", @@ -4205,7 +4205,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-memory" -version = "1.61.0" +version = "1.62.0" dependencies = [ "anyhow", "async-trait", @@ -4218,7 +4218,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-adapter-postgres" -version = "1.61.0" +version = "1.62.0" dependencies = [ "anyhow", "async-trait", @@ -4313,7 +4313,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-ingestion" -version = "1.61.0" +version = "1.62.0" dependencies = [ "anyhow", "async-trait", @@ -4361,7 +4361,7 @@ dependencies = [ [[package]] name = "smooai-smooth-operator-server" -version = "1.61.0" +version = "1.62.0" dependencies = [ "anyhow", "async-trait", diff --git a/rust/Cargo.toml b/rust/Cargo.toml index 506209d0..36047fcc 100644 --- a/rust/Cargo.toml +++ b/rust/Cargo.toml @@ -40,7 +40,7 @@ smooai-smooth-operator-core = "1.10.0" # Intra-workspace dep on the reference lib carries its version so the adapters / # ingestion / server that depend on it are publishable (path = local dev, # version = the crates.io requirement). -smooth-operator = { package = "smooai-smooth-operator", path = "smooth-operator", version = "1.61.0" } +smooth-operator = { package = "smooai-smooth-operator", path = "smooth-operator", version = "1.62.0" } async-trait = "0.1" anyhow = "1" diff --git a/rust/adapters/backplane-nats/Cargo.toml b/rust/adapters/backplane-nats/Cargo.toml index 0ad34ddc..156654a6 100644 --- a/rust/adapters/backplane-nats/Cargo.toml +++ b/rust/adapters/backplane-nats/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-backplane-nats" -version = "1.61.0" +version = "1.62.0" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/rust/adapters/backplane-redis/Cargo.toml b/rust/adapters/backplane-redis/Cargo.toml index f4992a30..1d684ddb 100644 --- a/rust/adapters/backplane-redis/Cargo.toml +++ b/rust/adapters/backplane-redis/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-backplane-redis" -version = "1.61.0" +version = "1.62.0" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/rust/adapters/dynamodb/Cargo.toml b/rust/adapters/dynamodb/Cargo.toml index 1fa57257..3ac6b86f 100644 --- a/rust/adapters/dynamodb/Cargo.toml +++ b/rust/adapters/dynamodb/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-dynamodb" -version = "1.61.0" +version = "1.62.0" edition.workspace = true license.workspace = true repository.workspace = true @@ -19,7 +19,7 @@ s3-vectors = ["dep:aws-sdk-s3vectors", "dep:aws-smithy-types"] smooth-operator = { workspace = true } smooai-smooth-operator-core = { workspace = true } # IndexingStore / IndexingRun for the persistent admin indexing-runs store. -smooai-smooth-operator-ingestion = { path = "../../ingestion", version = "1.61.0" } +smooai-smooth-operator-ingestion = { path = "../../ingestion", version = "1.62.0" } async-trait = { workspace = true } anyhow = { workspace = true } chrono = { workspace = true } diff --git a/rust/adapters/in-memory/Cargo.toml b/rust/adapters/in-memory/Cargo.toml index c71465c7..b607695f 100644 --- a/rust/adapters/in-memory/Cargo.toml +++ b/rust/adapters/in-memory/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-memory" -version = "1.61.0" +version = "1.62.0" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/rust/adapters/postgres/Cargo.toml b/rust/adapters/postgres/Cargo.toml index deb0c341..3db2b0c2 100644 --- a/rust/adapters/postgres/Cargo.toml +++ b/rust/adapters/postgres/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-adapter-postgres" -version = "1.61.0" +version = "1.62.0" edition.workspace = true license.workspace = true repository.workspace = true @@ -15,7 +15,7 @@ smooth-operator = { workspace = true } # `postgres` feature pulls in PostgresCheckpointStore (sync r2d2 path). smooai-smooth-operator-core = { workspace = true, features = ["postgres"] } # IndexingStore / IndexingRun for the persistent admin indexing-runs store. -smooai-smooth-operator-ingestion = { path = "../../ingestion", version = "1.61.0" } +smooai-smooth-operator-ingestion = { path = "../../ingestion", version = "1.62.0" } async-trait = { workspace = true } anyhow = { workspace = true } chrono = { workspace = true } diff --git a/rust/ingestion/Cargo.toml b/rust/ingestion/Cargo.toml index 44c6571a..980e3f0c 100644 --- a/rust/ingestion/Cargo.toml +++ b/rust/ingestion/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-ingestion" -version = "1.61.0" +version = "1.62.0" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/rust/smooth-operator-server/Cargo.toml b/rust/smooth-operator-server/Cargo.toml index 4b912400..ffd114f3 100644 --- a/rust/smooth-operator-server/Cargo.toml +++ b/rust/smooth-operator-server/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator-server" -version = "1.61.0" +version = "1.62.0" edition.workspace = true license.workspace = true repository.workspace = true @@ -35,22 +35,22 @@ smooth-operator = { workspace = true } smooai-smooth-operator-core = { workspace = true } # In-memory storage + backplane — ALWAYS included. The local-flavor default and # the lean (`--no-default-features`) build run entirely on these. -smooai-smooth-operator-adapter-memory = { path = "../adapters/in-memory", version = "1.61.0" } +smooai-smooth-operator-adapter-memory = { path = "../adapters/in-memory", version = "1.62.0" } # Persistent storage + admin-store backends, selected at runtime to match the # configured storage backend (Postgres / DynamoDB; default in-memory). Optional: # gated behind the `postgres` / `dynamodb` features so a lean local/embed build # can exclude tokio-postgres / the AWS SDK. The `postgres` crate also provides the # gateway-backed embedder/reranker, so the `postgres` feature additionally enables # the semantic-retrieval path in `embedder.rs` / `reranker.rs`. -smooai-smooth-operator-adapter-postgres = { path = "../adapters/postgres", version = "1.61.0", optional = true } -smooai-smooth-operator-adapter-dynamodb = { path = "../adapters/dynamodb", version = "1.61.0", optional = true } +smooai-smooth-operator-adapter-postgres = { path = "../adapters/postgres", version = "1.62.0", optional = true } +smooai-smooth-operator-adapter-dynamodb = { path = "../adapters/dynamodb", version = "1.62.0", optional = true } # Distributed Backplane backends for horizontal scale-out, selected at runtime # via SMOOTH_AGENT_BACKPLANE (default in-memory / single-process). Optional: gated # behind the `redis` / `nats` features so a lean build excludes their drivers. -smooai-smooth-operator-adapter-backplane-redis = { path = "../adapters/backplane-redis", version = "1.61.0", optional = true } -smooai-smooth-operator-adapter-backplane-nats = { path = "../adapters/backplane-nats", version = "1.61.0", optional = true } +smooai-smooth-operator-adapter-backplane-redis = { path = "../adapters/backplane-redis", version = "1.62.0", optional = true } +smooai-smooth-operator-adapter-backplane-nats = { path = "../adapters/backplane-nats", version = "1.62.0", optional = true } # Admin API surfaces indexing-run status via the ingestion crate's IndexingStore. -smooai-smooth-operator-ingestion = { path = "../ingestion", version = "1.61.0" } +smooai-smooth-operator-ingestion = { path = "../ingestion", version = "1.62.0" } async-trait = { workspace = true } anyhow = { workspace = true } diff --git a/rust/smooth-operator/Cargo.toml b/rust/smooth-operator/Cargo.toml index 0f26cf3b..79711ee3 100644 --- a/rust/smooth-operator/Cargo.toml +++ b/rust/smooth-operator/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "smooai-smooth-operator" -version = "1.61.0" +version = "1.62.0" edition.workspace = true license.workspace = true repository.workspace = true diff --git a/typescript/CHANGELOG.md b/typescript/CHANGELOG.md index 3be09265..65a990d6 100644 --- a/typescript/CHANGELOG.md +++ b/typescript/CHANGELOG.md @@ -1,5 +1,19 @@ # @smooai/smooth-operator +## 1.62.0 + +### Minor Changes + +- 714b7bb: SMOODEV-3412: `AppState::with_require_owned_conversations(true)` — let an org-authenticated host make ownerless conversations unreachable. + + `may_read_conversation` treats a conversation with no `user` participant as open to every principal. That is deliberate and load-bearing for anonymous/widget flows (th-909995): those principals own nothing, and the conversations they create are exactly the ownerless ones, so denying them locked callers out of their own sessions. + + An **org-authenticated** pot is the opposite case. Every caller is a real user, and the ownerless conversations in its org are the ones machines made — phone calls, SMS, widget chats. In SmooAI's `copilot-ws` that meant the operator's history picker listed **customer conversations**, and could resume them: a stored pointer bound a new session to a customer's phone call on every drawer open. + + The new flag makes ownerless unlistable, unresumable and unreadable. **Off by default**, so no existing host changes behaviour. + + It is checked before the scope match, so it covers `UserScope::Denied` too: an emailless principal owns nothing and must reach nothing. The flag therefore **fails closed** — enabling it with a verifier whose principals carry no `email` claim breaks the picker rather than leaking through it. Ship the claim first. + ## 1.61.0 ### Minor Changes diff --git a/typescript/package.json b/typescript/package.json index f6520544..14a302bf 100644 --- a/typescript/package.json +++ b/typescript/package.json @@ -1,6 +1,6 @@ { "name": "@smooai/smooth-operator", - "version": "1.61.0", + "version": "1.62.0", "description": "TypeScript SDK for the smooth-operator WebSocket protocol: the native client (`.`), React bindings (`./react`), and the embeddable web-component chat widget (`./widget`). Generated from the language-neutral JSON Schemas in spec/.", "license": "MIT", "type": "module",