Release v2.36.0
What's Changed
- refactor(oauth): wire one redaction owner into runtime execution by @chelojimenez in #3884
- refactor(oauth): converge entry points and retire legacy flows by @chelojimenez in #3885
- fix(auth): serve WorkOS client config at runtime, drop dead devMode knob by @chelojimenez in #3894
- test(oauth): add differential harness across protocol eras by @chelojimenez in #3886
- refactor(oauth): consolidate sequence diagram actions by @chelojimenez in #3887
- ops(axiom): version the alert monitors and add an idempotent apply script by @chelojimenez in #3898
- feat(sdk): add @mcpjam/sdk/oauth/node for SSRF-hardened OAuth networking by @chelojimenez in #3899
- feat(server): count socket-level failures so resets stop being invisible by @chelojimenez in #3900
- fix(evals): keep suite header actions visible with long names by @vigneshgopalandd-maker in #3896
- Remove stale "Compare from Eval Playground" docs by @mintlify[bot] in #3901
- fix(hosted): memoize client capabilities to stop a tools/list render loop by @chelojimenez in #3902
- ops(axiom): add error-class spike and novelty monitors, plus a replay harness by @chelojimenez in #3903
- fix(models): keep the model picker non-empty so Playground can't crash by @olartgabo in #3897
- fix(web): report the effective error origin, not the declared catalog value by @chelojimenez in #3928
- fix(oauth): drop the November special-case from protocol version labels by @nachocossio in #3927
- fix(environments): send projectId with update/archive/restore mutations (SUTB-10) by @devin-ai-integration[bot] in #3904
- fix(swarms): block a cloud launch whose servers are missing or local-only (SUTB-5) by @devin-ai-integration[bot] in #3905
- fix(swarms): label the two Describe persona sources as one required choice (SUTB-22) by @devin-ai-integration[bot] in #3906
- fix(swarms): one ghost trigger treatment for the Env/Client/Model/Score headers (SUTB-24) by @devin-ai-integration[bot] in #3907
- fix(swarms): clear a failed launch's error when Back returns to Describe (SUTB-1) by @devin-ai-integration[bot] in #3908
- SUTB-4: pin environment description as optional (does not reproduce) by @devin-ai-integration[bot] in #3909
- fix(evals): promote-to-eval lands on the created case on every surface (SUTB-16) by @devin-ai-integration[bot] in #3910
- fix(swarms): give the masked generation 5xx a correlation id (SUTB-14) by @devin-ai-integration[bot] in #3911
- fix(insights): keep the cluster layout when the colour mode flips by @devin-ai-integration[bot] in #3912
- fix(swarms): deep-link a live finding to its session and keep the running run reachable by @devin-ai-integration[bot] in #3913
- fix(chatboxes): the author's preview embed never renders a sign-in wall by @devin-ai-integration[bot] in #3914
- fix(swarms): stop the intensity preset from overwriting sessions the user already picked (SUTB-26) by @devin-ai-integration[bot] in #3915
- fix(user-testing): withhold the tester link while a scenario can't run, and mark required fields by @devin-ai-integration[bot] in #3916
- fix(user-testing): drop the double em dash from the scenarios empty state (SUTB-32) by @devin-ai-integration[bot] in #3917
- fix(swarms): keep an in-progress swarm through a remount, and say what the loading step is doing by @devin-ai-integration[bot] in #3918
- fix(ui): sandbox-image pickers use the app's Select, not a native select (SUTB-35) by @devin-ai-integration[bot] in #3919
- fix(user-testing): stop saying "chatbox" to users, mint tester links at /user-testing by @devin-ai-integration[bot] in #3920
- fix(chat): discard upstream error-page bodies and offer a retry (SUTB-31) by @devin-ai-integration[bot] in #3921
- Frame connect-time XAA failures for the surface that hit them (SUTB-27) by @devin-ai-integration[bot] in #3922
- test(swarms): pin a two-per-client-environment swarm launch with a GPT-4 judge (SUTB-15) by @devin-ai-integration[bot] in #3923
- fix(hosted): stop mangling the bearer-less 401 and wait out the token race by @devin-ai-integration[bot] in #3924
- chatbox: prompt for authorization only when the server requires it (SUTB-9) by @devin-ai-integration[bot] in #3925
- feat(insights): redesign Insights chrome and User Testing edit flow by @chelojimenez in #3931
- test(hosted): settle the OAuth gate before reporting a runtime 401 by @chelojimenez in #3939
- fix(guest-session): send 5xx through webError so the cause reaches Axiom by @chelojimenez in #3930
- fix(hosted): stop dropping a runtime 401 that beats the OAuth probe by @chelojimenez in #3940
- fix(logger): surface search matches hidden by the source filter (PUR-45) by @SebasKoria in #3938
- Docs: log panel filter banner and empty state by @mintlify[bot] in #3944
- feat(observability): identify the actor on every Sentry event by @chelojimenez in #3942
- fix(trace): stop trace timeline crashing on stale span message indices by @ignaciojimenezr in #3943
- fix(chat): cap live trace turn history to bound renderer memory growth by @ZeHuari in #3946
- fix(observability): stop filing Sentry issues for OS-killed utility p… by @ignaciojimenezr in #3945
- fix(errors): stop reporting upstream auth rejections as MCPJam 500s by @chelojimenez in #3948
- feat(server-connections): discovery preflight + inbound service-token guard by @chelojimenez in #3941
- fix(v1): map upstream auth rejections onto FORBIDDEN, not a 500 by @chelojimenez in #3953
- Update FORBIDDEN error code docs for upstream auth by @mintlify[bot] in #3954
- Stop reporting OAuth debugger advisories to Sentry by @ignaciojimenezr in #3955
- docs: replace Docker Hub pull with a build-from-source step by @olartgabo in #3775
Full Changelog: v2.35.1...v2.36.0