v0.4.3
·
7 commits
to release/0.4
since this release
Features
- Studio Operations: Added
list_studios,list_studio_hardware/_base_images/_sdk_versions, and four plaintext-variable operations, exposed viams-hub studio list,studio variable,studio hardware|base-images|sdk-versions, andms-hub list --repo-type studio. - MCP Operations: Added
HubApi.list_operational_mcp_servers()andms-hub mcp list --hosted, unblocking the umbrella SDK's MCPApi delegation. - Studio Visibility: Introduced
protectedvisibility (app public, code hidden). - RepoInfo Runtime Fields: RepoInfo now carries Studio runtime fields (
sdk_type,sdk_version,base_image,hardware,mcp_support,runtime). - Token Permission Tiers: Added
TokenScopeannotations; read-scoped tokens can log in with a warning that writes need a higher tier; rejected writes name the required tier. decode_mcp_list_response: Added a function to decode MCP list responses (PR #67).
Fixes
- Agent Permission Handling: Surface explicit 403
OperationNotAllowederrors when agent repository listing requires read permission; prevent legacy agent list permission envelopes from rendering as empty repository results. - MCP Pagination: Backfill requested pagination metadata when the service omits
page_numberandpage_size; reject invalid page numbers before issuing network requests. - Agent-IDP Unicode Errors: Replace raw Unicode encoding failures with
E3021InvalidParametererrors. - Compat Layer Token Leak: The compat layer forwarded
token/endpointinto request bodies, serialising the caller's API token into PATCH bodies; all Studio shims now split control kwargs from business fields. - Studio Logs TypeError:
HubApi().get_studio_logs(..., token=...)raised TypeError and could never succeed; per-calltoken=was silently ignored on every Studio shim. - Cover Image Drop:
cover_imagewas renamed tocoverImageand dropped by the server; Studio cover images never applied. - Error Code Mapping: 403 now separates insufficient permission from exhausted quota (new
QuotaExceededError, not retryable); 409 maps toAlreadyExistsError; OpenAPI string error codes are now recognised. - Public Studio Token Demand:
get_studiodemanded a token for spaces the spec says are public. - Studio Logs Pagination Footer:
studio logsread atotalfield the response never had, so its pagination footer never printed.
Enhancements
- Agent-IDP Signing Validation: Validate canonical Agent-IDP signing components for ASCII-only values and reserved delimiters.
- MCP List Output: Simplify MCP list output by omitting unsupported status data.
- Regression Coverage: Expanded coverage for scoped tokens, legacy permission envelopes, MCP pagination, and Agent-IDP signing validation.
- MCP Discovery Verb: MCP discovery sends PUT first (the only verb the spec defines) and remembers which verb a deployment serves, so the loser is tried at most once.
- Studio Owner Listing: Listing a Studio owner asks for every status; the endpoint keeps filtering to running spaces even with an owner set, so "list my spaces" returned nothing.
Documentation
- README Updates: New Studio/MCP command surface, a Token permission levels section, and the SDK method reference.
Testing
- Spec Vendoring: Vendored the spec under
tests/data/and check it againstOPERATION_REGISTRY. - Test Coverage: 723 unit tests (881 in mock mode) and 28 integration tests against the live service.
- Release History Reconstruction: Added v0.3.0 and v0.3.1 entries, condensed v0.4.0 bullets, and folded older releases into an "Older releases" block.
What's Changed
- [Fix] Fix Agent Permission Handling and MCP Pagination by @wangxingjun778 in #65
- [Fix] Fix Agent Permission Handling and MCP Pagination by @wangxingjun778 in #66
- add decode_mcp_list_response by @wangxingjun778 in #67
Full Changelog: v0.4.2...v0.4.3