Skip to content

LEGACY — v1.3.4 (old browser implementation)

Latest

Choose a tag to compare

@godhiraj-code godhiraj-code released this 11 Jan 11:02
· 32 commits to main since this release
c3b5e2b

Legacy v1.3.4 — use 5.x for the current platform

Get the current platform: v5.0.0-alpha.5 →

Important

This is the old browser-specific implementation. It is not the current general-purpose agent platform.
GitHub's Latest badge applies to full releases, so it still appears here while Starlight 5.x is in alpha.
For current platform development, download v5.0.0-alpha.5 using the link above.

Migration guide · Current website and demo

Historical v1.3.4 release notes

Added

  • Generic Semantic Perception: hub.js now implements generic class-name semantic extraction. It correctly identifies icon-only elements (like "Shopping Cart") even when they contain dynamic badges (e.g., "2"), eliminating the need for hardcoded selectors.
  • Reporting Integrity: intent_nli_test.js now strictly enforces minSteps verification. Partial execution (e.g., LLM stopping after one step) is now correctly flagged as a failure.
  • Self-Healing: Verified that the Hub learns selecting mappings on the fly (click:Shopping Cart -> a:has-text("2")) and persists them to starlight_memory.json, making subsequent runs instantaneous.

Added

  • JWT Authentication System (src/auth/jwt_handler.js)

    • Industry-standard JWT token generation and verification
    • HMAC-SHA256 signing with timing-safe comparison
    • Configurable token expiration (default: 3600s)
    • Token refresh capability for long-running sessions
    • Secure random secret generation
  • Input Validation Pipeline (src/validation/schema_validator.js)

    • Comprehensive JSON schema validation for all message types
    • Method-specific validation with strict patterns
    • Field type checking, length limits, and pattern matching
    • Prevention of malformed or malicious payloads
  • PII Protection System (src/utils/pii_redactor.js)

    • Automatic detection and redaction of sensitive data
    • Email addresses, phone numbers, credit cards, SSNs
    • JWT tokens and API keys
    • Recursive object sanitization
    • Compliance modes: alert, block, or redact
  • Encryption Layer (src/warp_sanitizer.js)

    • AES-256-GCM encryption for sensitive data
    • Secure key generation and management
    • Optional encryption for warp files
    • Key rotation support