Skip to content

v0.2.0

Latest

Choose a tag to compare

@kleinmatic kleinmatic released this 04 Sep 22:00
· 1 commit to main since this release

Config validation, a security fix, and a documentation pass. Upgrade if you are on 0.1.x.

Fixed

Authentication could be bypassed with a blank API key. Present in 0.1.0 and 0.1.1. Inline api_keys were read from YAML without stripping or dropping empty entries. A blank entry matched the empty token of a request carrying no Authorization header, so the bridge answered it. api_keys: ["${MY_KEY}"] with the variable unset renders exactly that shape. Blank entries are now dropped when the config loads, and an empty token can never match a key. Only affects configs using inline api_keys; the api_keys_env path always filtered correctly.

docker build -t a2a-bridge . failed in 0.1.1. The version is derived from the git tag, and the image does not copy .git, so the build raised LookupError. Building now works, and --build-arg VERSION=0.2.0 stamps a real version into the image.

Added

Config mistakes now produce messages that name the file, the agent and what to write instead, rather than a Python traceback about dataclass constructor arguments:

agents.yml: agent 'publisher': unknown option: card_urls.
Valid: artifact_join, caller, card_url, conversation_id_header, endpoint_url, id, ...

Also caught now: typos in top-level options (api_key_env: used to load a bridge with no keys, in silence), duplicate agent ids, malformed caller blocks, and YAML that is the wrong shape. The bridge warns at startup when no API keys are configured and it is open to anyone who can reach it.

Documentation

A correction worth reading if you rely on the session fallback. The docs said that without conversation_id_header the bridge hashes the first user message, and that sessions break only when someone edits it. It hashes the newest message, which is different on every turn, so the fallback starts a new session every turn. Set conversation_id_header.

The README, both example configs and the LibreChat guide were rewritten in plainer language. Every configuration option is now documented, which the previous release claimed but did not do.

pip install a2a-bridge==0.2.0