Repository navigation
Releases: Harsh23Kashyap/customchat
Release list
CustomChat 0.1.17
Configuration is grouped by task, with a searchable feature directory. Workspace tools are in the directory rather than a top button grid. Status rows and live preview remain. Provider switches clear stale endpoint overrides; ZIP and YAML import/export guidance is clearer.
Validated: 498 source tests; installed-wheel suite 496 passed, 2 optional skips; browser checks for navigation, provider switches and Nerd import/export.
CustomChat 0.1.16
0.1.16 adds resizable settings columns and the private keys-only NewsNerd starter.
Workspace layout
- Drag either divider to resize navigation, settings, and the preview or prompt/code editor. Widths stay in this browser. Arrow keys adjust; Home or double-click resets. Minimum widths keep each column usable.
- Hide/show chat preview reclaims the space and remembers the choice. Prompt/code editors remain available.
- Styled scrollbars match the workspace and chat. Compact/mobile layouts retain their existing flow without resize handles.
Private custom source keys
- Sources and APIs now has private credential controls for native HTTP sources with declared header-to-environment mappings. Save/remove works without restarting or contacting the source; the field clears after saving and only presence is reported.
- Saved keys are bound to the source ID, environment label, and configured URL. Destination changes require a new saved key. Keys stay out of YAML, exports, prompts and status responses.
- Credential-bearing sources require HTTPS, reject redirects and fail before a request when a key is missing. Imported Python connector permissions are unchanged: bounded mode is NOT a security sandbox and does not receive API keys.
- HTTP article mapping handles a single author string and reports rejected or malformed responses instead of treating them as empty news.
NewsNerd starter
Attached newsnerd-ready-keys.zip contains the active native NewsAPI connector, gpt-4o-mini provider configuration, all nine filled prompt texts, two filled inert code-helper reference drafts, wording, light/dark colors, retrieval, memory and budgets. No real keys, private saved looks, test-question history or chats are included.
- Start CustomChat 0.1.16:
uvx --from customchat-app==0.1.16 customchat-app start - Configuration > Load and share Nerds: choose the attached ZIP, review, Load and run, then Edit NewsNerd Ready configuration.
- Model and key: save your OpenAI key. Sources and APIs > Custom source credentials: save your NewsAPI key.
- Open the imported app's Chat and ask short keywords such as
AI regulation.
This is configured for local development/testing, not production. NewsAPI Developer has a 24-hour delay and quota. Hosted OpenAI calls cost money when you ask questions. App question/model-call limits are not a dollar billing meter. Live news/model services were not called in verification; no correctness or live-key-validity claim is made. The preview conversation is a visual sample, not a generated news response.
Sources: https://newsapi.org/docs/authentication ; https://newsapi.org/docs/endpoints/everything ; https://newsapi.org/pricing ; https://developers.openai.com/api/docs/models/gpt-4o-mini
Verification
- Source suite: 498 tests, 498 passed, no skips.
- Fresh installed wheel: 498 tests, 496 passed, 2 optional-dependency skips.
- Wheel/sdist metadata checks and isolated install/demo/alias/conflict acceptance passed.
- Source and installed-wheel browser checks passed: both dividers, persistence, keyboard, preview hide/show, mobile flow, ZIP import, private source-key save/remove, prompt/code hydration, and no JavaScript errors. Desktop, mobile, preview-hidden, prompt/code, and key-control screenshots inspected.
- Only fake source/provider responses were used; no paid service calls.
v0.1.15 - Configuration acceptance fixes and offline emoji
0.1.15 publishes the accepted configuration work to both GitHub and PyPI. 0.1.14 was published on GitHub only; its PyPI publish was cancelled, so PyPI stayed on 0.1.13. This release supersedes 0.1.14 everywhere.
Configuration page
- Selected prompt and code-helper editors open in a right-side pane on desktop and inline on mobile, with compact helper descriptions.
- Source and additional fields save to the app file with revision checks. Reload shows the saved values, pending restart is labeled, and export is blocked until restart so a ZIP cannot contain stale settings.
- Stale concurrent edits are rejected instead of overwriting newer saves.
- Optional fields show a single "(not filled)" marker that tracks typing, clearing, image upload, save and reload.
- Provider fallback has normal typed controls (enable, provider, model, base URL, environment variable name, temperature, timeout) with validation. Structured and empty values hydrate and persist, and invalid blocks are rejected without overwriting the saved file.
- Numeric fields reject empty input instead of silently saving 0, and multiline text is preserved exactly.
- Articles-style JSON is rejected with a routing hint to Code helpers > Search connector > Match a real response instead of being imported or executed.
- Appearance Save is labeled to its scope, reset stays in the menu, and mobile layouts no longer clip the prompt placeholder or generation actions.
Emoji
- 80 bundled static images (Google Noto Color Emoji, SIL OFL 1.1) render the supported picker and demo emoji without network fonts. Custom emoji still use native fonts.
Verification
- 486 tests, 484 pass, 2 optional skips, on the source tree and on a fresh installed wheel.
- Independent retest of the exact change composition passed: helper panes, offline emoji, blank-field markers, JSON routing, source save and restart-guarded export, fallback controls, numeric and multiline boundaries.
The attached NewsNerd demo workspace ZIP is unchanged from 0.1.14 (SHA-256 b6a9b3cf484d100bd329655b9c1f14fbea335d3941d0a25910c85474ea151a60).
0.1.14 - prompt pane, persistent guide and theme fixes
Full saved prompts in the desktop preview pane; prompt switches match workspace state; preset navigation keeps scroll; first-display guide persistence across ports with manual replay; floating Save and a red Reset menu; active nav and welcome illustration follow the palette.
newsnerd-filled-demo-0.1.14.zip is an importable workspace, not the program source ZIP. All settings sections contain safe sample values, nine distinct prompts, optional stages on, inert helper drafts, budget, theme, local fictional evidence and an example.invalid API placeholder. No credentials. Not live news: Demo does not execute optional model stages. A few optional fields remain empty to demonstrate not-filled labels.
476 tests: 474 passed, 2 optional skips on exact remote source and built wheel; 17 hydration scenarios plus prompt/navigation, guide, real ZIP import, floating actions, theme and mobile checks. Tests use Demo/fakes, not all live services or arbitrary custom programs. Public PyPI verification follows publication.
v0.1.13 - Hydrated normal configuration controls
Changes
- Removed the raw All app fields dump. Normal Configuration controls show the workspace's current values.
- Source toggles recognize configured source types with custom IDs. Named APIs retain their settings in typed source controls.
- Current matching presets are selected; changed looks say Custom. Saved-state selection matches current model settings.
- App-file theme and branding seed values when no saved theme override exists.
- Existing code helpers and saved-key presence show in the usual controls. Empty optional values and missing keys explicitly say not filled. No secret values are returned.
- Extra nested fields use typed controls in their normal sections. Saving source/additional fields requires restart; edits never execute code or contact a service.
Verification
- Exact GitHub source and rebuilt wheel each passed 473 tests: 471 passed, 2 optional skips.
- 17 focused browser hydration scenarios: manual workspace, all theme controls, light/dark colors, presets, custom look, saved states, model/retrieval/budget, named APIs, extra fields, missing/saved keys, helper and prompt fields, restart persistence, custom-field saving, ZIP imported state and mobile.
- Regression browser tests: all nine offline prompt generators, both code routes, YAML/ZIP import, cited Demo answer, stop/remove, traversal rejection and continuous scrolling at 1366/980/760/390 pixels.
Model-dependent tests use Demo/fakes, not a live model. Missing values are not invented; unused services are not enabled automatically. Extra stored fields do not create new runtime capabilities. Imported bundles exclude keys. Python connectors use a bounded process, NOT a security sandbox. A finite test matrix does not cover every possible custom program or API.
v0.1.12 - Current workspace configuration and wider bundle review
Changes
- Bundle review uses the full content width without an unrelated live preview, with readable desktop columns and a stacked mobile layout.
- Configuration shows the current workspace's actual title, wording, colors, fonts, prompts and app-file fields, whether created manually or imported.
- App-file edits use revision checks and an explicit restart notice. Model Apply persists to the app file.
- Code helpers reopen saved drafts or existing connector source as inert text. Saving a draft never activates or runs it.
- Imported workspaces have an explicit configuration link and remain separate from the original app.
- Saved keys remain private and available only within their workspace. Portable exports exclude keys.
Verified before release
- Exact GitHub source and rebuilt wheel: 461 tests each, 459 passed and 2 optional skips.
- Browser tests: manually created workspace edit/restart/reopen; ZIP and YAML import/run; imported configuration; cited Demo answer; stop/remove; all 9 offline prompt generators and both code routes.
- Navigation, scrolling and review layout tested at 1366, 980, 760 and 390 pixels; actual screenshots inspected.
- Missing/invalid token access denied for the new configuration and helper-draft endpoints.
Model-dependent checks use Demo/test doubles, not a live model. All app-file edits require restarting the workspace to apply all fields. Python connectors run in a bounded subprocess, not a security sandbox.
v0.1.11 - Continuous settings and Nerd ZIP fixes
Configuration now scrolls through all sections without hiding neighbors or trapping upward scrolling. Prompt and code editors stay inline.
Nerd imports skip benign repository metadata while rejecting private files by name. Empty local sources and YAML-only imports create document folders and show setup warnings. Source archives are explained separately from Nerd exports.
Load and share Nerds has a redesigned drop zone and a dedicated export card.
Verified: 454 automated tests run, 452 passed, 2 optional-dependency skips. Real browser checks at 1366, 980, 760 and 390px: all-section navigation, wheel scrolling up, stable document height, ZIP export/import. All nine offline prompt generator stages, both code routes, genuine ZIP review, explicit code consent, child start/cited answer/stop/remove passed.
Tests use offline Demo and fixtures, not live model-quality or remote-service claims.
0.1.10 - Simpler setup and configuration layout fixes
Configuration fixes
- Short, stacked setup summaries replace drifting label/value rows. Full check details and limits remain in an expandable section.
- Workspace tabs use a consistent responsive grid.
- Open your chat and other action links center their labels, remove underlines and grow instead of clipping wrapped text.
- The prompt/code editor stays inside its grid track, with a single mobile surface instead of nested rounded borders.
Verification
-446 tests run locally:444 passed,2 optional-dependency skips. Existing ResourceWarnings remain.
- Setup, details disclosure, Changes/Deploy action links and code editor checked at390,760,980 and1440px, including actual screenshot inspection. No horizontal overflow or JavaScript errors observed.
- Rebuilt wheel/sdist checked; installed wheel ran all9 generator stages and both code routes, plus genuine ZIP review/consent/start/cited-answer/stop/remove flow on desktop and phone.
- No provider, prompt, live-model or data behavior change. Offline Demo is not a real language model; existing security and semantic limits still apply.
0.1.9 - Tested prompt boundaries and adversarial fixtures
Hardening
- Application-owned trust boundary appended to all nine runtime stages, including customized prompts. Generated drafts get the boundary from the app, not model output.
- Structured JSON for generator/code reference data; exact stage output checks, invalid-summary rejection and enabled checker failure shown as non-approval.
- Synchronous question API now applies enabled question/relevance checks like the streamed flow.
- Static code review tightens exact imports/signatures, reflection, secret printing, environment mutation and import-time execution patterns. No generated code auto-executes.
Test matrix
- 442 source tests pass locally, rebuilt wheel/sdist metadata/install checks pass.
- 13 synthetic attack families across nine prompt constructions (117), 26 code input/policy constructions, runtime/history/failure fixtures, nine AST escape examples, eight malformed-label/citation cases and four benign controls.
- Genuine ZIP drop/review/consent/start/cited answer/stop/remove flow and all nine generator UI stages checked on installed wheel, desktop/phone, reduced motion, no auto-save.
- ChatGPT provided a separate simulated attack second opinion. It did not run the actual backend. Optional second followup returned a site error after one retry. No live-model attack-success rate is claimed.
Residual risks
No finite test matrix covers every attack. Prompt defenses and JSON serialization are not immunity. Models can still obey poisoned content or launder false claims; citation syntax does not prove support. Optional support checks are model-dependent and off by default. Streaming may show text before final checks, so there is no confidentiality guarantee. Static Python checks do not isolate capabilities or enforce all network endpoints. Bounded mode is NOT a security sandbox; host files/network remain accessible. Human review stays required.
0.1.8 - Static review before loading a Nerd
- Dropped bundles now show a local static review before load: declared purpose/configuration, file/function counts, Python imports and detected network/environment/file/process/dynamic-call patterns.
- Scan evidence includes file/line references. Full code review and explicit consent remain before running Python.
- No bundle code is imported or executed, no model is called, no destination is contacted and no environment value is read during review.
- Honest limits: detected names can be unrelated functions. Aliases, dynamic calls, dependencies and runtime behavior can evade this scan. No detected pattern does not mean absent or safe. This is not a safety verdict; bounded mode is NOT a security sandbox, and host files/network remain accessible.
- 431 source tests passed locally. Rebuilt wheel/sdist pass metadata checks and installation. Genuine ZIP drag/drop/review/consent/start/cited answer/stop/remove flow checked on desktop and phone, including reduced motion and current-app preservation. Static review pixels inspected on both screen sizes.