main was pinned to hanzoai/ai v1.832.18, which is RETRACTED. That version seals the secret MASK as a provider key: the admin API returns "***" for a stored secret, so saving a provider form without touching the key field seals the literal "***" into KMS under the provider's own name — and because ai resolves KMS-first, the store then answers "***" for every read, outranking the env var that was serving the real key. The provider stops authenticating while its row still looks correct. v1.832.19 carries the guard. .19 also brings: secrets resolved from the EMBEDDED in-process KMS (this binary's own apps/kms) instead of over HTTP to the standalone deployment, which had never worked — 404 on the path it used, 401 on the correct one; /v1/provider-flags renamed to /v1/models/providers and derived from the served catalog, so the provider set and the model list cannot disagree; and a model family is now controlled from admin.hanzo.ai rather than only from deployment env. apps/referrals did not compile on main: payout.Deposit gained a required `ref` (commerce guards on it so a retried payout credits AT MOST ONCE) and this caller was not updated with it. A referral pays TWO wallets, so the referral id alone would name both and commerce would dedupe the second against the first — the referee's bonus would silently never land. bonusRef(id, side) makes each credit its own event while staying stable across retries. The published spec is regenerated: /v1/provider-flags is gone from openapi.yaml and plugin/ai/openapi.json (the .18 pin never regenerated it, so the drift gate was red), and the retired provider-flags product is dropped from the floor. Verified on Linux (macOS has no tmpfs for the pure-Go SQLCipher codec, so the store-backed suites cannot run there): apps/referrals, apps/ai, apps/kms and openapi all green. Co-authored-by: Hanzo Dev <dev@hanzo.ai>
230 KiB
230 KiB