Skip to content

v0.4.3

Choose a tag to compare

@wangxingjun778 wangxingjun778 released this 15 Sep 12:08
· 7 commits to release/0.4 since this release

Features

  • Studio Operations: Added list_studios, list_studio_hardware / _base_images / _sdk_versions, and four plaintext-variable operations, exposed via ms-hub studio list, studio variable, studio hardware|base-images|sdk-versions, and ms-hub list --repo-type studio.
  • MCP Operations: Added HubApi.list_operational_mcp_servers() and ms-hub mcp list --hosted, unblocking the umbrella SDK's MCPApi delegation.
  • Studio Visibility: Introduced protected visibility (app public, code hidden).
  • RepoInfo Runtime Fields: RepoInfo now carries Studio runtime fields (sdk_type, sdk_version, base_image, hardware, mcp_support, runtime).
  • Token Permission Tiers: Added TokenScope annotations; read-scoped tokens can log in with a warning that writes need a higher tier; rejected writes name the required tier.
  • decode_mcp_list_response: Added a function to decode MCP list responses (PR #67).

Fixes

  • Agent Permission Handling: Surface explicit 403 OperationNotAllowed errors when agent repository listing requires read permission; prevent legacy agent list permission envelopes from rendering as empty repository results.
  • MCP Pagination: Backfill requested pagination metadata when the service omits page_number and page_size; reject invalid page numbers before issuing network requests.
  • Agent-IDP Unicode Errors: Replace raw Unicode encoding failures with E3021 InvalidParameter errors.
  • Compat Layer Token Leak: The compat layer forwarded token / endpoint into request bodies, serialising the caller's API token into PATCH bodies; all Studio shims now split control kwargs from business fields.
  • Studio Logs TypeError: HubApi().get_studio_logs(..., token=...) raised TypeError and could never succeed; per-call token= was silently ignored on every Studio shim.
  • Cover Image Drop: cover_image was renamed to coverImage and dropped by the server; Studio cover images never applied.
  • Error Code Mapping: 403 now separates insufficient permission from exhausted quota (new QuotaExceededError, not retryable); 409 maps to AlreadyExistsError; OpenAPI string error codes are now recognised.
  • Public Studio Token Demand: get_studio demanded a token for spaces the spec says are public.
  • Studio Logs Pagination Footer: studio logs read a total field the response never had, so its pagination footer never printed.

Enhancements

  • Agent-IDP Signing Validation: Validate canonical Agent-IDP signing components for ASCII-only values and reserved delimiters.
  • MCP List Output: Simplify MCP list output by omitting unsupported status data.
  • Regression Coverage: Expanded coverage for scoped tokens, legacy permission envelopes, MCP pagination, and Agent-IDP signing validation.
  • MCP Discovery Verb: MCP discovery sends PUT first (the only verb the spec defines) and remembers which verb a deployment serves, so the loser is tried at most once.
  • Studio Owner Listing: Listing a Studio owner asks for every status; the endpoint keeps filtering to running spaces even with an owner set, so "list my spaces" returned nothing.

Documentation

  • README Updates: New Studio/MCP command surface, a Token permission levels section, and the SDK method reference.

Testing

  • Spec Vendoring: Vendored the spec under tests/data/ and check it against OPERATION_REGISTRY.
  • Test Coverage: 723 unit tests (881 in mock mode) and 28 integration tests against the live service.
  • Release History Reconstruction: Added v0.3.0 and v0.3.1 entries, condensed v0.4.0 bullets, and folded older releases into an "Older releases" block.

What's Changed

Full Changelog: v0.4.2...v0.4.3