Repository navigation
Releases: luetzey/who2be
Releases · luetzey/who2be
Release list
Who2Be v0.1.0
First public release. This section collects the entire development up to
the public switch as curated blocks.
Added
- Tag grouping for the playbook list and, for the first time, grouping on
the resource list (client-side, multi-tag membership with an "untagged"
group) - Policy presets in the agent editor ("Read only" / "Editor without
approval" / "Editor with approval"), derived from and applied to the
write-capability checkboxes; deviations show as "Custom" data-testid="branch-action-*"anchors on the shared status action bar
(submit/publish/reject/reactivate), used by the end-to-end journeys- Agent work area & knowledge base (ADR-0047/0048/0049): an unversioned
workspace per agent (private, plus shared areas via grants) with document
artifacts, file/URL ingest (20 MB limit, SSRF protection, content-addressed
blob store with MinIO/in-memory adapters), read-only SQL tables (SQLite per
area with engine-enforced query budgets), timeline merge, and its own
search index; plus an evidence-backed knowledge base (source-referenced
statements, tiersverified/derived/hypothesis, typed edges with
correlation discipline) — 23 new MCP tools (58 → 81), promotion from work
area into curated resources as an explicit step, and an automatic agent
access log with model snapshot for compliance - Table UI & exports: tables tab and table detail page in the web UI
(schema, conventions, row preview), table export as CSV/XLSX, note export
as Markdown/HTML plus print-to-PDF; export endpoints with row limit and
formula-injection guards - Semantic search & passage retrieval (ADR-0046): content chunking with
per-language full-text configs,search_contentreturns passages instead
of whole aggregates (REST + MCP), optional local embeddings with hybrid
RRF ranking andmodeparameter (auto|text|semantic|hybrid), semantic
agent memory retrieval, backfill CLIs - End-to-end test journeys: Playwright helpers (signup with
auto-confirm, session injection) and four journeys — persona lifecycle,
playbook→resource block-ref backlink, agent read-active, invitation
accept with email-mismatch guard - Language as a first-class concept (ADR-0045): one element = one
language (localeon the identity line of all five content types, with
badge and list filter; system prompt templates now with language choice),
workspace content language on creation, automatic output-language
instruction in the rendered agent system prompt, complete English rollout
package with locale-aware seeding and boot sync - Core AgentDB: versioned personae, playbooks (including composites),
resources with the BlockNote editor, agents, system prompt templates, and
external tools withtool-refplaceholders; status workflow
Draft → Review → Active → Archived with diff/restore - Multi-tenancy & RBAC: organizations → workspaces → entities, roles
admin > editor > viewer, magic-link invitations, MFA login step-up - MCP server: read/write/discovery tools, full-text search, feedback
flywheel (record_usage/submit_feedback), agent memory with an approval
gate, fine-grained agent write permissions including rate limits,
policy-filteredtools/list; stdio and HTTP transport with an OAuth 2.1
remote connector (Claude Code / Claude.ai) - Editions: on-prem (public-key-verified license key) and cloud
(Mollie billing packagewho2be-billing), build-isolated down to the web
bundle - Web UI: dashboard with status/attention band, workspace switcher,
backlinks, the "Warm Citrus" design language - Deployment: Hetzner stack (
deploy/hetzner/) with Compose, Caddy
(auto-HTTPS + security headers), backups, and a runbook - Quality/compliance: coverage ratchets for both stacks, OSS license
gates (fail-closed), security reviews phases 1+2 closed, FSL 1.1
licensing,THIRD-PARTY-LICENSES.md+ generator script
Changed
- Persona and playbook detail pages now use the shared status action bar
with a per-page label override — visible button and toast texts are
unchanged - MCP write-tool docstrings document the persona mode schema and the
canonical BlockNote body/pill format for playbooks and resources - Python minor/patch dependency updates (FastAPI 0.141.1, fastmcp 3.4.7,
pydantic-settings 2.15.0, redis 8.1.0, pypdf 6.16.1; dev tooling: pytest
9.1.1, mypy 2.3.1, ruff 0.16.3) - Public repository documents (README, CONTRIBUTING, SECURITY, CHANGELOG,
ROADMAP) are now in English, following the documentation standards'
audience rule; a versioned OpenAPI spec is checked in under
docs/reference/openapi.json(export script
scripts/export_openapi.py), anddocs/README.mdindexes the
documentation tree
Fixed
- End-to-end journeys run for real now: session upgrade to AAL2 via an
actual TOTP enrollment, promote-ready seed data, and corrected selectors;
the e2e CI job is a hard gate (was soft) describe_tablereturned 500 once a source convention had been set
(double JSON encoding via a duplicate row mapper); stored values are
unpacked by migration, and all three search paths now share one
full-text-config source- Work-area search anchors resolved to only the heading block instead of
the whole passage; index and read path now share the same passage
boundaries - Knowledge-base search missed inflected word forms (no stemming);
kb_node
is now indexed with the workspace's language config - MCP error messages dropped the API's machine-readable
reasoncodes;
all error statuses now carry(reason=…, actionable_by=…) - Tables created by agents were unlistable and undeletable over MCP; added
list_tables/delete_table, and name-conflict responses now include the
existing table's ID - Oversized table cells could be written but made every later read fail
(SQLITE_TOOBIG); writes are now rejected up front against the same
cell-size limit - Agent system prompts no longer advertise tools that the agent's policy
filters out oftools/list
Security
- All GitHub Actions in the CI/deploy workflows are pinned to full-length
commit SHAs (supply-chain hardening, satisfies the repository's actions
policy) - Phase-2 hardening of the agent work area: per-query time budgets and
result-size caps for agent SQL, an SQL function allowlist, a
forgery-proof access log (model config snapshotted at access time,
protected against cascade deletion), rate-limit checks before query
execution, and Markdown/CSV injection guards in server-rendered exports - XLSX/HTML export hardening: formula-injection guard on trimmed copies,
control-character validation, meta CSP andno-referrerin exported
HTML, and event-loop-safe rendering - npm audit cleanup in the web stack: transitive DoS/header-injection CVEs
intar,undici, andbrace-expansion(all dev tooling only, the
production bundle was not affected) closed via lockfile update react-router/react-router-dom7.17.0 → 7.18.1 (runtime dependency):
open redirect via backslash, RSC XSS, SSR hydration constructor
injection, and route-matching DoS (GHSA-wrjc-x8rr-h8h6,
GHSA-h8fp-f39c-q6mh, GHSA-337j-9hxr-rhxg, GHSA-chx6-hx7r-mcp5) closed via
lockfile update
Full changelog: CHANGELOG.md