From 1b7b562df3efa1a1fa742e1f9bf94596031cc611 Mon Sep 17 00:00:00 2001 From: fylorn <249551762+fylorn@users.noreply.github.com> Date: Sat, 3 Oct 2026 18:38:18 +0800 Subject: [PATCH] chore: 2026.10.1 Co-Authored-By: Claude Opus 5.5 --- package.json | 2 +- release-notes/2026.10.1.md | 34 ++++++++++++++++++++++++++++++++++ src-tauri/Cargo.lock | 2 +- src-tauri/Cargo.toml | 2 +- src-tauri/tauri.conf.json | 2 +- 5 files changed, 38 insertions(+), 4 deletions(-) create mode 100644 release-notes/2026.10.1.md diff --git a/package.json b/package.json index 082724e7..5cf1cdf0 100644 --- a/package.json +++ b/package.json @@ -2,7 +2,7 @@ "name": "thinkwatch-lite", "private": true, "description": "Desktop app for a local AI API gateway on macOS, Windows and Linux", - "version": "2026.10.0", + "version": "2026.10.1", "type": "module", "packageManager": "pnpm@11.13.0", "scripts": { diff --git a/release-notes/2026.10.1.md b/release-notes/2026.10.1.md new file mode 100644 index 00000000..af06ce72 --- /dev/null +++ b/release-notes/2026.10.1.md @@ -0,0 +1,34 @@ +**Upgrade notes:** +- The bundled core is now 0.59.0, which speaks control-plane protocol 35. A remote server has to run core 0.59.0 too: this version does not connect to 0.57.x, and 2026.10.0 and earlier do not connect to 0.59.0. +- **Request history is cleared** on the first start, as the request store is rebuilt. Configuration, keys and upstreams are kept. +- The Hidden characters and Output limit guards are removed (see *Three security guards*). If either was changed from its factory setting, set it back before updating: Hidden characters to Observe with both of its rules on, Output limit to Off with a limit of 100,000 characters. Otherwise core does not start and the app runs in safe mode until `hidden_text:` and `output_limit:`, with the lines indented under them, are deleted from the `security:` section of `config.yaml`. +- Two plugins come with the app and are added turned off. + +**Plugins:** +- The new Plugins page runs JavaScript plugins that change requests before they go to an upstream and answers before they reach the client. +- Plugins run in a sandbox inside core, with no access to files, the network or the environment. A plugin sees only the parts of a request it was granted, and never a real secret: recognized secrets are replaced with placeholders before it runs and put back afterwards. +- A plugin is one file that also holds its settings, its scope and what happens when it fails. Its editor has a Settings tab and a Code tab that are saved together, and adding a plugin opens the same editor. +- A plugin can be tried on a recent request, moved in the run order by dragging, and followed through its logs and statistics. The Traffic page marks requests a plugin changed, and a request's detail shows it before and after the plugins. +- Only a plugin that can change tool calls asks for confirmation in a system dialog: to be installed, turned on, have its code changed, or have a change to its file approved. +- The two included plugins are Answer in a chosen language and Convert WSL and Windows paths. + +**Session conversations:** +- A session has a new Conversation tab that replays it turn by turn: messages, folded thinking, tool calls with their results, and images. +- What cannot be shown is marked with the reason, such as a body past the retention period. + +**Three security guards:** +- Outbound redaction, tool-call inspection and the content filter now cover what the five guards did. Hidden characters are built-in content-filter rules, which delete the characters instead of refusing the request, and the output limit is gone. +- Content rules can refuse a request, delete what they match or only record it, and can match Unicode code points. +- Custom redaction rules can name their placeholder. Email addresses and Chinese mainland mobile numbers are new built-in redaction rules, off by default. +- Tool-call inspection has two new rules: a credential sent to a host other than its own provider, and a local file uploaded to a remote host. + +**Stored requests:** +- Request and answer bodies are stored with recognized secrets already replaced, whatever the redaction mode. +- Answers are kept up to 4 MiB (it was 256 KiB), and body storage defaults to 5 GiB (it was 2 GiB). Retention settings above 7 days, 90 days or 2 GiB now take effect; a fixed cleanup used to cut them back every hour. +- An error that an upstream answered, such as a 400, now counts as a failed request, with the upstream's message as the reason. + +**Fixes:** +- On Windows, the gateway no longer needs the Visual C++ Redistributable to start. +- A request holding many values that look like secrets no longer slows the gateway down. + +The [Plugins](https://thinkwat.ch/docs/lite/plugins) and [Features](https://thinkwat.ch/docs/lite/features) pages describe each of these in full. diff --git a/src-tauri/Cargo.lock b/src-tauri/Cargo.lock index 3f16c474..c61d36c8 100644 --- a/src-tauri/Cargo.lock +++ b/src-tauri/Cargo.lock @@ -4756,7 +4756,7 @@ dependencies = [ [[package]] name = "thinkwatch-lite" -version = "2026.10.0" +version = "2026.10.1" dependencies = [ "anyhow", "block2", diff --git a/src-tauri/Cargo.toml b/src-tauri/Cargo.toml index 7b30fce9..0d40570f 100644 --- a/src-tauri/Cargo.toml +++ b/src-tauri/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "thinkwatch-lite" -version = "2026.10.0" +version = "2026.10.1" edition = "2024" # **这个数决定依赖能升到哪一版。**edition 2024 的解析器只挑声明的 Rust # 版本编得动的依赖:写 1.85 的时候,`cargo update` 一直停在旧的 time 和 diff --git a/src-tauri/tauri.conf.json b/src-tauri/tauri.conf.json index 65e45606..fb165513 100644 --- a/src-tauri/tauri.conf.json +++ b/src-tauri/tauri.conf.json @@ -1,7 +1,7 @@ { "$schema": "https://schema.tauri.app/config/2", "productName": "ThinkWatch Lite", - "version": "2026.10.0", + "version": "2026.10.1", "identifier": "app.thinkwatch.lite", "build": { "beforeDevCommand": "pnpm dev",