Skip to content
This repository was archived by the owner on Feb 23, 2026. It is now read-only.

v4.5.9

Choose a tag to compare

@github-actions github-actions released this 30 Jan 21:14
· 166 commits to main since this release

v4.5.9 — Release Notes (since v4.5.6)

Production hardening for multi-account auth: safer storage, better repair flows, and more usable UI.

Highlights

  • Self-healing accounts storage: detects corrupt JSON, quarantines it, and recovers safely.
  • Legacy account repair: prompts to repair missing identity during login; can auto-repair once on first send if needed.
  • Race-safe storage: migration + read/merge/write now runs under a single lock strategy (antigravity-style).
  • Better TUI UX: wrap-safe toast/status formatting (paths/tokens truncated, messages clamped).
  • Account control: enable/disable accounts via openai-accounts-toggle.
  • CI publish fixed: npm Trusted Publishing (OIDC) for tag releases.

User-Facing Changes

Account Repair + Quarantine

  • Login now checks the accounts file for:
    • corrupt JSON files (quarantines and replaces with a valid empty store), and
    • legacy entries missing identity fields (offers repair before continuing).
  • If a request starts with no eligible accounts, the plugin can auto-repair once (then retry the next eligible account if available).

Wrap-Safe Messaging (TUI)

  • Added message formatting to keep toasts/status readable:
    • long tokens/paths truncated,
    • status messages clamped to avoid UI overflow,
    • short, actionable toast copy.

Account Management

  • New tool: openai-accounts-toggle (1-based index) to enable/disable accounts without editing JSON.

Reliability & Data Safety

Storage Locking

  • Storage locks now ensure the file exists before locking to reduce edge-case breakage.
  • Legacy migration and all read/merge/write paths operate under the same lock discipline to reduce cross-process race conditions.

Quarantine + Atomic Write Hardening

  • Quarantine files (containing refresh tokens) now:
    • attempt 0600 permissions (best-effort),
    • are pruned to prevent unbounded buildup.
  • Atomic write paths clean up .tmp files on failures.

Disabled Account Safety

  • Disabled accounts (enabled: false) are excluded from refresh/hydration and proactive refresh (no token mutation).

OAuth / Manual Paste Flow

  • Manual OAuth paste now prefers the full redirect URL and validates OAuth state when present (warns when missing).

Docs

  • Updated docs/multi-account.md and docs/troubleshooting.md with repair/quarantine behavior, retention notes, and account toggle usage.

Full Changelog: v4.5.8...v4.5.9