Releases: rtc-agent/web-components
Release list
v0.3.1-rc.1
Changes
- refactor(admin-ui): rename permission points from
user:*toadmin_user:* - fix(component): parse userId from RTC JWT
user_idclaim instead of external auth provider - feat(admin-ui): permission-aware Function Groups filtering for RTC Agent
- test: fix Token Exchange tests and GlobalRtcAgent mocks
Co-Authored-By: Claude Code noreply@anthropic.com
Full Changelog: v0.3.1-rc.0...v0.3.1-rc.1
v0.3.1-rc.0
Changes
Features
- Token auto-refresh: Implement automatic token refresh mechanism with request queue to handle concurrent 401 errors gracefully
- Unified error handling: Response interceptor now unwraps the unified
{ success, data }response format - Auto-retry: Requests are automatically retried after successful token refresh
- RTC Agent config: Add theme (system mode) and bubble position (bottom-right) configuration
Bug Fixes
- rtc-agent-setup: Gracefully handle missing dist files in monorepo CI environments
- Test fixes: Correct import case sensitivity issues for Linux CI environment
- Error messages: Update error message format to use Chinese (请求失败)
Testing
- Fix app.test.tsx imports and update tests to match new error handling implementation
- Remove broken integration test that was testing middleware logic incorrectly
Related
- Depends on: rtc-agent/server v0.3.1-rc.0
v0.3.0-rc.4
✨ New Features
OAuth2 PKCE Support
Implement RFC 7636 PKCE (Proof Key for Code Exchange) flow for enhanced OAuth2 security:
- Add
generatePKCEParamsfunction andPKCEParamsinterface - Update
OAuth2Client.getAuthorizationUrlto accept PKCE parameters - Update
OAuth2Client.exchangeTokento passcode_verifier - Integrate PKCE flow in login component with storage/cleanup
- Export PKCE types and functions for external use
Files changed:
packages/client/src/oauth2-client.ts(+71/-2)packages/component/src/components/login/rtc-login-dialog.ts(+29/-12)packages/client/src/index.ts(+4/-4)packages/component/src/config/auth.ts(+1)
🚀 Performance Improvements
Batch Fetch Optimization
Increase BATCH_SIZE from 10 to 500 in client:
- Reduce RPC call count for better performance with large datasets
- Particularly impactful when fetching messages, sessions, and other paginated resources
Files changed:
packages/client/src/client.ts(+1/-1)
📦 Package Updates
@rtc-agent/client: PKCE support + batch optimization@rtc-agent/component: Login dialog PKCE integration
Co-Authored-By: Claude Code noreply@anthropic.com
v0.3.0-rc.3
⚠️ Breaking Changes
URL Naming Convention Unification
All URL-related configuration fields now use uppercase 'URL' for consistency:
workerUrl→workerURLscenariosUrl→scenariosURLserverUrl→serverURL(OAuth2Client, S3Client, PersistenceConfig, AUTH_CONFIG)
This affects:
createRtcAgent()factory function configurationRtcAgentcomponent propertiesOAuth2ClientOptions,S3ClientOptions,PersistenceConfig- All documentation and examples
🐛 Bug Fixes
Security
- Prevent duplicate OAuth token exchange with reentry guard
- Improve OAuth2 error message security (avoid leaking sensitive details)
- Improve type accuracy, security, and debuggability in FunctionRegistry
Race Conditions & Concurrency
- Fix TOCTOU race in softDeleteSession (wrap check+write in transaction)
- Fix OffsetManager cache rollback on DB failure
- Fix logo setter async race condition (generation counter)
- Fix ResourceScope listener mismatch and OffsetManager rollback gap
- Fix throttle race condition in event binding controller
- Fix lifecycle race conditions and resource leaks in component
- Fix error isolation and dead code in event pipeline
Type Safety
- Correct virtualFSGrep return type to match GrepResult
- Fix UUID schema mismatch (count>1 returns array but schema described string)
- Fix markdown generator oneOf union type rendering
- Eliminate 'any' type assertions in entity-repository
- Unwrap CustomEvent detail in factory DOM callbacks
Other Fixes
- Remove debug markers and fix redundant gap fill check
- Fix memory leaks and improve command extensibility
- Initialize theme in component lifecycle
- Standardize localStorage key naming
🔧 Refactoring
- Unify URL naming convention across all packages (client, persistence, component)
- Remove verbose debug logs across controllers and utilities
- Consolidate register methods in FunctionRegistry
- Simplify auth to AuthProvider-only mode (remove OAuth2 internal flow)
- Translate Chinese comments to English
- Standardize SVG icon formats
- Migrate console.* to scoped logger
📚 Documentation
- Update all documentation for serverURL naming convention
- Add @deprecated to UI-layer Session/Message types
- Fix logger docs and deduplicate scopes
- Improve security documentation
🧪 Testing
- 1002 tests passing
- All pre-commit and pre-push checks passing
📦 Protocol Updates
- Regenerate models from OpenAPI spec
- MessageListRequest.cursor: number → string
- Remove 'reserved' notes from FileAttachment and UserMessageContent.files
v0.3.0-rc.2
Fix
- Fixed worker filename regex to match Vite-generated hashes with underscores (e.g.
shared-worker-Bw4_Rekb.js) - Updated
rtc-agent-setup.jsregex from/[A-Za-z0-9]+/to/[\w-]+/to match underscores and hyphens
Breaking Changes (since 0.2.x)
onUIUpdatecallback parameter changed fromUIUpdateEventtoUIUpdatePayload(includes{ event, seq })UIUpdateListenersignature changed to(event, seq)publish()is now async (fire-and-forget pattern recommended)
See commit history for full details.
v0.3.0-rc.1
What's Changed
Features
- input-area: Enable attach file button with file picker by @leichujun in #8df4b44
- Added hidden file input element for file selection
- Implemented
_handleAttachClickto trigger file picker dialog - Implemented
_handleFileSelectto handle file upload after selection - Supports multiple file selection with
accept="image/*,text/*"filter - Previously disabled attach button is now fully functional
New Contributors
- @leichujun made their first contribution in this release
Full Changelog: v0.3.0-rc.0...v0.3.0-rc.1
v0.3.0-rc.0
🚀 新功能
文件上传重试机制
- 实现手动重试失败的文件上传(替代网络恢复时的自动同步)
- 在内存中保存 File 对象,支持无需重新选择文件的重试
- 在 RtcInputArea 中添加公共
retryUpload()方法 - 上传完成前检查 syncStatus,确保文件已同步到 S3
- 即使文件上传失败也允许表单提交(仅阻止正在上传的文件)
文件预览增强
- 添加
rtc-file-preview-modal组件,支持图片和文本文件预览 - 实现文件粘贴上传功能,支持即时预览
- 自包含的缩略图加载,通过 FileStorageContext 管理
离线优先文件存储
- 新增离线优先的 S3 文件存储系统
- 支持文件在离线状态下缓存,网络恢复后同步
🎨 UI 改进
文件预览缩略图
- 使用 SVG alert 图标替代 emoji 错误图标
- 使用 SVG retry 图标替代文本重试按钮
- 悬停时显示重试按钮覆盖层,提供更清晰的视觉反馈
🔧 重构
文件预览架构
- 重构文件缩略图为自包含加载模式,通过 FileStorageContext 管理
- 禁用网络在线事件自动同步,改为用户手动重试
📦 其他变更
- 新增 alert-16.svg 图标用于错误状态
- 在 RtcChatLayout 中添加
_handleFileRetry处理器,连接重试事件
🐛 修复
- 修复文件上传状态检查,确保只在同步完成后标记为已加载
- 修复 TypeScript 类型检查,移除未使用的 setupNetworkListener 方法
完整变更日志: v0.2.9-rc.1...v0.3.0-rc.0
v0.2.9-rc.1
What's Changed
Features
- feat(component/input-area): add badge to scenario button showing selected count
- feat(component/input-area): disable unimplemented attach and voice buttons
Full changelog since v0.2.9-rc.0:
- Scenario button now displays a badge with the count of selected scenarios
- Attach and voice buttons are disabled until their features are implemented
v0.2.9-rc.0
What's Changed
Features
- feat(persistence): add IndexedDB persistent queue for UI updates
- Persist UI update events to IndexedDB before dispatch, enabling reconnecting tabs to catch up on missed events after page refreshes or weak-network reconnections
- Auto-increment
seqfield for cursor-based tracking and gap detection - Worker exposes
getCatchUpEvents(fromSeq)for main thread catch-up withhasGapflag onUIUpdatecallback now includesseqfor precise progress tracking- New
onStateGapcallback signals when full state refresh is needed
Breaking Changes
UIUpdateListenersignature changed to(event, seq)publish()is now async (fire-and-forget pattern recommended)
Tests
- Comprehensive gap detection tests for
getCatchUpEvents - Persistent UI update queue E2E tests
- Worker bridge tests
v0.2.8-rc.4
Fix
auth: attempt token refresh on page load in AuthProvider mode
When the page is refreshed after the access token expires (e.g. user leaves the page idle for a long time), the component called provider.isLoggedIn() which returned false synchronously, and immediately showed the login page without ever calling provider.refreshToken().
Root cause: setAuthProvider() treated isLoggedIn() === false as a final state, never attempting async refresh.
Fix: When isLoggedIn() returns false, setAuthProvider() now calls provider.refreshToken() asynchronously. If refresh succeeds → user stays logged in; if it fails → login page is shown.
Includes a guard to skip state updates if the auth provider was cleared (logout/destroy) during the async refresh.