Zhichang Yu
4c54cefd29
Port 14 upstream agent security / correctness fixes to Go canvas (#16455)
Mirrors 14 merged upstream PRs into the Go agent port.
PRs ported:
- #15609 ExeSQL SSRF guard + DNS pin
- #15436 HTTP timeout on external API tools
- #16363 be_output restore + DeepL error path
- #15644 switch no longer matches empty condition
- #15374 session_id bind to path agent_id (DAO idor guard)
- #16169 sandbox artifact ownership gate
- #15457 tenant ownership on agentbots
- #15145 rerun agent document access check
- #15446 thinking switch (component portion; provider policy lives in
internal/llm)
- #15426 Invoke URL/proxy SSRF + DNS pin + no-redirects
- #15238 agentbot thinking-logs beta endpoint
- #14589 UserFillUp SSE event propagation
- #14890 anonymous webhook opt-in
- #15068 PipelineChunker new component (text/file_ref/parser_id
dispatch; file-format extraction is a follow-up)
40 files, +2355 / -58 lines. 33 new tests, all targeted package suites
pass (1721 + 4 skipped); 1 pre-existing flaky test unrelated.
2026-06-30 16:28:48 +08:00
..
2026-06-12 22:58:28 +08:00
2026-06-12 22:58:28 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 09:45:16 +08:00
2026-06-30 16:28:48 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 09:45:16 +08:00
2026-06-30 16:28:48 +08:00
2026-06-30 16:28:48 +08:00
2026-06-30 16:28:48 +08:00
2026-06-29 09:45:16 +08:00
2026-06-30 16:28:48 +08:00
2026-06-24 16:50:40 +08:00
2026-06-29 09:45:16 +08:00
2026-06-30 16:28:48 +08:00
2026-06-30 16:28:48 +08:00
2026-06-30 16:28:48 +08:00
2026-06-22 18:16:15 +08:00
2026-06-22 18:16:15 +08:00
2026-06-24 17:34:01 +08:00
2026-06-29 21:37:11 +08:00
2026-06-26 19:22:57 +08:00
2026-06-26 19:23:45 +08:00
2026-06-25 14:15:29 +08:00
2026-06-25 14:15:29 +08:00
2026-06-03 20:08:55 +08:00
2026-06-03 20:08:55 +08:00
2026-06-24 14:42:10 +08:00
2026-06-24 17:05:58 +08:00
2026-06-24 17:05:58 +08:00
2026-06-25 13:32:22 +08:00
2026-06-25 13:32:22 +08:00
2026-06-29 09:45:16 +08:00
2026-06-10 11:07:45 +08:00
2026-06-30 16:28:48 +08:00
2026-06-30 16:28:48 +08:00
2026-06-12 16:09:10 +08:00
2026-06-12 16:09:10 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 09:45:16 +08:00
2026-06-12 16:09:10 +08:00
2026-06-12 16:09:10 +08:00
2026-06-25 19:25:55 +08:00
2026-06-25 19:25:55 +08:00
2026-06-03 17:35:36 +08:00
2026-06-18 11:09:22 +08:00
2026-06-29 09:45:16 +08:00
2026-06-10 21:27:35 +08:00
2026-06-26 19:21:52 +08:00
2026-06-26 15:36:01 +08:00
2026-06-29 09:45:16 +08:00
2026-06-18 18:07:27 +08:00
2026-06-18 18:07:27 +08:00
2026-06-08 11:53:19 +08:00
2026-06-08 11:53:19 +08:00
2026-06-18 17:56:51 +08:00
2026-06-29 17:03:26 +08:00
2026-06-29 20:07:12 +08:00
2026-06-22 18:17:37 +08:00
2026-06-29 09:45:16 +08:00
2026-06-29 17:17:20 +08:00
2026-06-12 18:18:55 +08:00
2026-05-29 19:32:21 +08:00
2026-06-12 20:49:34 +08:00
2026-06-12 20:49:34 +08:00
2026-06-26 13:51:56 +08:00
2026-06-29 09:45:16 +08:00
2026-06-15 14:44:16 +08:00