Skip to content

v0.6.52 — masked-key proofing for example cards + drop NEW badges

Choose a tag to compare

@vibecoder11200 vibecoder11200 released this 28 Sep 02:29
· 17 commits to master since this release

v0.6.52 (2026-09-28)

Fork-polish release on top of the v0.5.91 sync: drops upstream's NEW badges and fixes the masked-API-key bug that broke every dashboard Example/Test "Run" button (surfaced by the new System One card).

Removed

  • NEW badges from upstream v0.5.91: sidebar Media Providers expander tag, per-kind (System One) tag, and the 9Remote tag — this fork doesn't ship promo badges.

Fixed — masked API keys never reach a credential slot (S7 follow-up)

  • All five dashboard example/test cards (Generic — image/video/music/imageToText/System One, TTS, STT, Embedding, Combo detail) prefilled their API-Key field from /api/keys, which since S7 returns the MASKED display value (sk-{id}-••••{last4}). The Run button built Authorization: Bearer sk-…••••… and the browser threw Failed to read the 'headers' property from 'RequestInit': String contains non ISO-8859-1 code point before any request was sent — every media-provider example page was affected, not just System One.
    • The prefill is gone; the key field is now a RAW-key input (empty = local mode, no Authorization header — works with Require-API-Key off, exactly like the server-side model ping's documented behavior). With Require-API-Key on, paste the raw key shown once at creation.
    • A guard rejects pasted masked values (•) with a clear message instead of the cryptic fetch crash.
  • Audited every other API-key flow that arrived with v0.5.91: the provider-page Test button and System One probe go through the server-side ping (x-9r-cli-token, S7-safe); Codex profiles take keys from ApiKeySelect (already S7-filtered); the new aggregator providers use per-connection credentials — all safe.