Skip to content

2.3.1

Latest

Choose a tag to compare

@github-actions github-actions released this 26 Sep 10:49

Honest failures and tighter keys - PKM Assistant 2.3.1

In plain words. This release fixes ten things found by two audits of the plugin after 2.3.0.
Seven are about the chat telling you the truth when something goes wrong: a failed summary no
longer says "summarized", a file that is too big or of an unsupported type now shows a notice
instead of silently not attaching, a failed copy to the clipboard says so, the session save
window shows a human sentence instead of a raw error, and three small leaks are closed (the /
popup, the @ suggestions and the note opener no longer outlive a closed chat tab). Three are
about safety: an API key echoed back by a model provider in an error message is now redacted
before that text can reach any model or session file, a tool call whose agent was deleted
mid-turn is refused instead of silently running as the active agent, and the .gitignore
protection for your settings file compares whole lines, so an existing settings.json.example
entry no longer fools it. Nothing changes in how you use the plugin.

What changed, in detail:

  • Summaries. When the model fails to produce a summary, manual compression and the token
    viewer presets report the failure instead of success; the conversation is left as it was after
    the cheap trimming phase.
  • Attachments. Too many files, an image over 10 MB, a text file over 100 KB or an unsupported
    type each produce a notice with the reason. Processing continues with the remaining files.
  • Selection menu. A refused clipboard write shows an error notice. Copy still clears the
    selection immediately.
  • Session save. The analysis failure message is one of three sentences (interrupted, model did
    not respond in time, other error); the raw error stays in the log.
  • Chat lifecycle. Closing a tab or re-rendering the view closes the / trigger popup and its
    pending timer, destroys the previous @ autocomplete before creating a new one, and the note
    opener registry keeps only a reference to the app, not to the view.
  • API keys in error messages. Provider error bodies and stream error events (OpenAI-compatible,
    Anthropic, Gemini) are masked by pattern and redacted by the exact key used in the request,
    including URL-encoded and Bearer forms, before the text becomes a normalized error.
  • Agent identity for tools. A tool call that names an agent which no longer exists is refused
    with a clear permission error; a call with no agent at all is refused too. Approval windows are
    signed with the name of the agent whose permissions were checked.
  • .gitignore entries. The vault .gitignore is matched line by line and the entries are
    written one after another, with a warning for any entry that fails; a vault without
    .gitignore is left alone.