Commit Graph
1524 Commits
Author SHA1 Message Date
Neal Shah 4f84decdec fix tool call blank content (#2458) 2026-02-10 14:14:27 -08:00
Neal Shah e55829623f Revert "allow empty message (#2455)" (#2457)
This reverts commit 7880ade5d7.
2026-02-10 14:01:31 -08:00
Daniel Salazar 5e8ce3a021 fix: decrease large error log from wrong model (#2456)
* [PUT-471] feat: estimate and bill input for gemini imgaes :dev:

* fix: decrease large error log from wrong model
2026-02-10 13:36:35 -08:00
Neal Shah 7880ade5d7 allow empty message (#2455) 2026-02-10 12:53:56 -08:00
Daniel SalazarandProgrammerIn-wonderland 91afa2c356 [PUT-471] feat: estimate and bill input for gemini imgaes :dev: (#2453)
* [PUT-471] feat: estimate and bill input for gemini imgaes :dev:

* [PUT-472] add input/output costs to openai image models too

* npm version bump

* remove second url log

* fix gemini pro image

---------

Co-authored-by: ProgrammerIn-wonderland <3838shah@gmail.com>
2026-02-10 12:52:33 -08:00
Neal Shah 4fb84bc117 add configurable backend (#2452)
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
2026-02-09 21:47:12 -08:00
KernelDeimos e5750d8eb7 fix: add explicit handling for access token in ACL
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
For reasons still unknown, there are circumstances where the permission
scanner denies permission to access tokens that should have been granted
permission. This change de-abstracts/flattens the logic for checking
access tokens so that it is easier to understand and maintain. The newly
implemented code does not suffer from the same issue.
2026-02-09 18:26:03 -05:00
Reynaldi Chernando e2ccaadf2f Fix gemini 3 pro image model name (#2450) 2026-02-09 12:24:40 -08:00
Daniel Salazar f9805dfffb fix: decrease log usage (#2449) 2026-02-08 22:26:23 -08:00
Daniel Salazar 380e72cad2 fix: axiosRequest log dumping b64 urls (#2448) 2026-02-08 21:47:04 -08:00
Daniel Salazar 7d84d7a46b fix: dev center emails (#2447) 2026-02-08 18:37:32 -08:00
Nariman Jelveh 74c23f609e Set email confirmation default to false
Change default behavior for email confirmation by initializing email_confirmation_required to 0 (not required) instead of 1. Remove the duplicate declaration and clarify the comment; existing logic still overrides this default (sets to 0 for matching pseudo_user/uuid_user and to 1 when event.requires_email_confirmation). Minor whitespace cleanup.
2026-02-08 12:02:23 -08:00
Daniel Salazar de7e831eff fix: gemini via openrouter models (#2438)
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
* fix: gemini

* feat: let logservice log to console

* fix: log

* feat: dev-center emails
2026-02-08 01:42:31 -08:00
Nariman Jelveh cfc56877e2 Store email confirmation flag on signup 2026-02-07 19:15:59 -08:00
Nariman Jelveh 873da5ae61 Honor event.requires_email_confirmation flag 2026-02-07 19:00:19 -08:00
Neal Shah ce96fb54ae Update error message for email confirmation (#2442) 2026-02-07 18:51:49 -08:00
Neal Shah 8e3d285671 merge users (#2441) 2026-02-07 18:44:31 -08:00
Neal Shah 262e31a6a6 Ns/service guard (#2440)
* add enforcer mechanism

* update better-sqlite3
2026-02-07 17:24:09 -08:00
Nariman Jelveh 48e37251df Return JSON errors for signup and handle in GUI 2026-02-07 16:41:59 -08:00
Neal Shah 03827e4197 Increase opus 4.6 max tokens (#2439)
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
2026-02-07 13:05:07 -08:00
KernelDeimos 020a64dbbd fix: ensure cache invalidation when verifying OTP
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
It is possible this broke after redis caching was employed because it
broke the expectation that assignments to attributes on cached objects
would remain for future accesses on said objects. This has not been
confirmed as the cause.
2026-02-06 23:42:47 -05:00
Neal Shah ac8456f8d3 Restrict apps from using /puterai/openai/v1 (#2435) 2026-02-06 18:43:18 -08:00
Neal Shah 28cedec9de chat_completions tool call fixes (#2434)
* chat_completions tool call fixes

* update chat completions test
2026-02-06 15:10:27 -08:00
Daniel Salazar fbb2080a66 fix: don't use ai aggregators if we have the model ourselves (#2424)
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
* cleanup: eslint changes

* fix: don't use ai aggregators if we have the model ourselves
2026-02-05 16:30:45 -08:00
Daniel Salazar 5fdfae6087 fix: usage limited error handling (#2423) 2026-02-05 15:15:27 -08:00
Neal Shah 15bd2ec5ac opus 4.6 fix billing (#2422) 2026-02-05 10:21:09 -08:00
Neal Shah e3db664690 Ns/opus 4.6 (#2420)
* add opus 4.6

* remove log from webserver service
2026-02-05 10:08:52 -08:00
Neal Shah f8f134412f web-cdn-test (#2414)
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
* web-cdn-test

* fix tests
2026-02-04 16:29:27 -08:00
Daniel Salazar e9d0bdf19b feat: add alerting for usage abuse (#2413)
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
2026-02-04 13:08:18 -08:00
KernelDeimos b8bdc16a03 fix: move readdir-subdomains to ESM
This also causes the filename to have the extension `.mjs` instead of
`.js`, as well as an await added in FilesystemAPIService. Luckily
lifecycle events are async so this didn't cause any problems.

I add this change somewhat reluctantly because this _should_ be a
non-functional change. Technically adding the `await` in
FilesystemAPIService makes it possible (albiet incredibly unlikely) for
some subtle bug or change in behavior to be introduced.
2026-02-04 14:13:43 -05:00
KernelDeimos 13fc737ca0 clean: remove debug logs added to /readdir-subdomains 2026-02-04 14:13:43 -05:00
KernelDeimos 0a694154b1 dev: add /readdir-subdomains endpoint
This endpoint can be called to get subdomain information after
performing a readdir without fetching subdomains.

This was AI-assisted with modifications and bug fixes as necessary.
2026-02-04 14:13:43 -05:00
KernelDeimos d94e3f45ac dev: add readdirSubdomains 2026-02-04 14:13:43 -05:00
KernelDeimos a4088023a3 dev: add parameter to exclude fetching subdomains
This parameter will allow readdir requests to not include subdomain
fetching, which will allow for the later effort of fetching subdomains
for directory listings in the gui with a separate request.
2026-02-04 14:13:43 -05:00
Daniel Salazar eead0fdfa9 fix: redis cache for user (#2409)
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
2026-02-03 17:47:43 -08:00
KernelDeimos 5433dde6d7 dev(extensions): [+] dev-socket
This extensions brings back the dev-socket functionality, which is
really important when testing things like broadcast, alarms, events, etc
; it saves a lot of time if you can invoke a command directly to the
backend.

This is an optional extension that will not be included in production
deployments. This is for development purposes only.
2026-02-03 19:39:07 -05:00
KernelDeimos de7fbced6b log: add debug logs for BroadcastService
These will be more important now that we're changing the transport for
broadcast messages between instances from websockets to webhooks.
2026-02-03 19:39:07 -05:00
KernelDeimos 3a7314d119 dev(backend): add send support for webhook broadcast
This still needs to be tested. I was going to test this using the `test`
command registered by BroadcastService that exists for this purpose but
`dev.sock` doesn't seem to be working anymore.

Why wasn't `dev.sock` working? Well... we deleted all the code that
makes it work. Why did we delete it? That question isn't a setup for my
next statement; I genuinely do not know. The whole point of dev.sock was
so we could remove the dev console but still maintain support for this
commandline interface that's absolutely needed for testing things that
aren't accesible directly from Puter's GUI.
2026-02-03 19:39:07 -05:00
KernelDeimos a40ec79d66 dev(tools): script to manually test broadcast webhooks
This tool makes it possible to manually test webhook support in
BroadcastService without running multiple Puter instances. This helps to
verify the functionality without setting up multiple Puter peers
locally.
2026-02-03 19:39:07 -05:00
KernelDeimos 47432853c4 dev(backend): add broadcast webhook endpoint
This commit adds the "receive" side of webhook support for
BroadcastService, which will eventually make broadcasting stateless and
not requiring of persistent connections.

Some specific considerations taken into account include:
- incremental nonce to prevent replay attacks
- request timestamp to prevent nonce-reuse after restarting
- HMAC signature to ensure authorized peer

Known limitations:
- if instances run indefinitely, eventually the nonce value would wrap
  around to zero and broadcasts would stop working. It is assumed that
  9 quintillion requests in the lifetime of an instance is reasonably
  impossible.
2026-02-03 19:39:07 -05:00
Daniel Salazar e938d5183a fix: limit open router expensive models for now (#2407)
* fix: limit open router expensive models for now

* fix: import extension
2026-02-03 14:43:15 -08:00
Neal Shah 665aee735b dav.puter.com CORS headers (#2406)
* webdav cors stuff

* if OPTIONS request just let it through
2026-02-03 14:13:42 -08:00
KernelDeimos cbde123aa1 fix(backend): undo part of 35461a0
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
It turns out this part of `35461a0` was not necessary to fix this issue,
and the code is still more correct if it falls true when the token's
authorizor has a permission granted.
2026-02-03 15:46:30 -05:00
KernelDeimos 8cd0a7f76b dev(backend): clear cache when revoking tokens 2026-02-03 15:46:30 -05:00
KernelDeimos 3ffe8eaf30 dev(backend): add revoke_access_token endpoint 2026-02-03 15:46:30 -05:00
Daniel Salazar 0234e34b46 Reapply: reverted redis migration changes (#2403) 2026-02-03 11:25:28 -08:00
Daniel Salazar baceb05b48 Revert "feat: replace serializible caches with redis instead of kvjs 🚀 (#2381)"
This reverts commit 7a47047c0d.
2026-02-03 12:43:00 -05:00
Daniel Salazar a4b90083e0 Revert "fix: missing redis changes (#2401)"
This reverts commit 07a389798d.
2026-02-03 12:43:00 -05:00
Daniel Salazar 07a389798d fix: missing redis changes (#2401)
Docker Image CI / build-and-push-image (push) Has been cancelled
Maintain Release Merge PR / update-release-pr (push) Has been cancelled
release-please / release-please (push) Has been cancelled
test / test-backend (24.x) (push) Has been cancelled
test / API tests (node env, api-test) (24.x) (push) Has been cancelled
test / puterjs (node env, vitest) (24.x) (push) Has been cancelled
2026-02-03 02:55:44 -08:00
Daniel Salazar 7a47047c0d feat: replace serializible caches with redis instead of kvjs 🚀 (#2381)
* wip: redis move

* fix: redis in extensions

* fix: bad isEMpty assignment

* fix: bad redis client config

* wip

* fix: redis keys cache

* fix: redis batch delete

* fix: change bulk cache times to allow for more instaces

* fix: broken tests
2026-02-03 02:18:31 -08:00