Honest failures and tighter keys - PKM Assistant 2.3.1
In plain words. This release fixes ten things found by two audits of the plugin after 2.3.0.
Seven are about the chat telling you the truth when something goes wrong: a failed summary no
longer says "summarized", a file that is too big or of an unsupported type now shows a notice
instead of silently not attaching, a failed copy to the clipboard says so, the session save
window shows a human sentence instead of a raw error, and three small leaks are closed (the /
popup, the @ suggestions and the note opener no longer outlive a closed chat tab). Three are
about safety: an API key echoed back by a model provider in an error message is now redacted
before that text can reach any model or session file, a tool call whose agent was deleted
mid-turn is refused instead of silently running as the active agent, and the .gitignore
protection for your settings file compares whole lines, so an existing settings.json.example
entry no longer fools it. Nothing changes in how you use the plugin.
What changed, in detail:
- Summaries. When the model fails to produce a summary, manual compression and the token
viewer presets report the failure instead of success; the conversation is left as it was after
the cheap trimming phase. - Attachments. Too many files, an image over 10 MB, a text file over 100 KB or an unsupported
type each produce a notice with the reason. Processing continues with the remaining files. - Selection menu. A refused clipboard write shows an error notice. Copy still clears the
selection immediately. - Session save. The analysis failure message is one of three sentences (interrupted, model did
not respond in time, other error); the raw error stays in the log. - Chat lifecycle. Closing a tab or re-rendering the view closes the
/trigger popup and its
pending timer, destroys the previous@autocomplete before creating a new one, and the note
opener registry keeps only a reference to the app, not to the view. - API keys in error messages. Provider error bodies and stream error events (OpenAI-compatible,
Anthropic, Gemini) are masked by pattern and redacted by the exact key used in the request,
including URL-encoded andBearerforms, before the text becomes a normalized error. - Agent identity for tools. A tool call that names an agent which no longer exists is refused
with a clear permission error; a call with no agent at all is refused too. Approval windows are
signed with the name of the agent whose permissions were checked. .gitignoreentries. The vault.gitignoreis matched line by line and the entries are
written one after another, with a warning for any entry that fails; a vault without
.gitignoreis left alone.