diff --git a/VERSION b/VERSION
index 3d9dcb1..35aa2f3 100644
--- a/VERSION
+++ b/VERSION
@@ -1 +1 @@
-0.25.3
+0.25.4
diff --git a/server/handlers/files.go b/server/handlers/files.go
index 9a09f76..c74ad3d 100644
--- a/server/handlers/files.go
+++ b/server/handlers/files.go
@@ -472,19 +472,21 @@ func (h *FileHandler) UploadToProject(c *gin.Context) {
userID := getUserID(c)
projectID := c.Param("id")
- // Verify project access (user owns or is team member)
- var exists bool
- err := database.DB.QueryRowContext(c.Request.Context(), database.Q(`
- SELECT EXISTS(
- SELECT 1 FROM projects
- WHERE id = $1 AND (owner_id = $2 OR team_id IN (
- SELECT team_id FROM team_members WHERE user_id = $2 AND is_active = true
- ))
- )
- `), projectID, userID).Scan(&exists)
- if err != nil || !exists {
- c.JSON(http.StatusForbidden, gin.H{"error": "project not found or access denied"})
- return
+ // Verify project access (user owns or is team member; admins bypass)
+ if c.GetString("role") != "admin" {
+ var exists bool
+ err := database.DB.QueryRowContext(c.Request.Context(), database.Q(`
+ SELECT EXISTS(
+ SELECT 1 FROM projects
+ WHERE id = $1 AND (owner_id = $2 OR team_id IN (
+ SELECT team_id FROM team_members WHERE user_id = $2 AND is_active = true
+ ))
+ )
+ `), projectID, userID).Scan(&exists)
+ if err != nil || !exists {
+ c.JSON(http.StatusForbidden, gin.H{"error": "project not found or access denied"})
+ return
+ }
}
file, header, err := c.Request.FormFile("file")
@@ -551,19 +553,21 @@ func (h *FileHandler) ListByProject(c *gin.Context) {
userID := getUserID(c)
projectID := c.Param("id")
- // Verify project access
- var exists bool
- err := database.DB.QueryRowContext(c.Request.Context(), database.Q(`
- SELECT EXISTS(
- SELECT 1 FROM projects
- WHERE id = $1 AND (owner_id = $2 OR team_id IN (
- SELECT team_id FROM team_members WHERE user_id = $2 AND is_active = true
- ))
- )
- `), projectID, userID).Scan(&exists)
- if err != nil || !exists {
- c.JSON(http.StatusForbidden, gin.H{"error": "project not found or access denied"})
- return
+ // Admins bypass project ownership/membership checks
+ if c.GetString("role") != "admin" {
+ var exists bool
+ err := database.DB.QueryRowContext(c.Request.Context(), database.Q(`
+ SELECT EXISTS(
+ SELECT 1 FROM projects
+ WHERE id = $1 AND (owner_id = $2 OR team_id IN (
+ SELECT team_id FROM team_members WHERE user_id = $2 AND is_active = true
+ ))
+ )
+ `), projectID, userID).Scan(&exists)
+ if err != nil || !exists {
+ c.JSON(http.StatusForbidden, gin.H{"error": "project not found or access denied"})
+ return
+ }
}
files, err := h.stores.Files.GetByProject(c.Request.Context(), projectID)
diff --git a/server/handlers/live_provider_test.go b/server/handlers/live_provider_test.go
index 6146f22..12e9820 100644
--- a/server/handlers/live_provider_test.go
+++ b/server/handlers/live_provider_test.go
@@ -4,7 +4,9 @@ import (
"context"
"fmt"
"net/http"
+ "net/http/httptest"
"os"
+ "strings"
"testing"
"time"
@@ -37,12 +39,22 @@ type liveProviderConfig struct {
// defaultEndpoints maps provider names to their default API endpoints.
var defaultEndpoints = map[string]string{
- "venice": "https://api.venice.ai/api/v1",
- "openai": "https://api.openai.com/v1",
- "anthropic": "https://api.anthropic.com/v1",
+ "venice": "https://api.venice.ai/api/v1",
+ "openai": "https://api.openai.com/v1",
+ "anthropic": "https://api.anthropic.com/v1",
+ "openrouter": "https://openrouter.ai/api/v1",
}
-// requireLiveProvider resolves provider config from env vars and skips if not configured.
+// providerKeyEnvs maps provider names to their API key env var names.
+var providerKeyEnvs = map[string]string{
+ "venice": "VENICE_API_KEY",
+ "openai": "OPENAI_API_KEY",
+ "anthropic": "ANTHROPIC_API_KEY",
+ "openrouter": "OPENROUTER_API_KEY",
+}
+
+// requireLiveProvider resolves the primary provider config from env vars.
+// Kept for backward compat — tests that only need one provider use this.
func requireLiveProvider(t *testing.T) liveProviderConfig {
t.Helper()
@@ -73,6 +85,191 @@ func requireLiveProvider(t *testing.T) liveProviderConfig {
return liveProviderConfig{Provider: provider, Key: key, Endpoint: endpoint}
}
+// requireLiveProviders resolves all configured providers for failover tests.
+// Reads LIVE_PROVIDERS (comma-separated, e.g. "venice,openai") and resolves
+// API keys from {PROVIDER}_API_KEY env vars. Falls back to requireLiveProvider
+// if LIVE_PROVIDERS is not set.
+func requireLiveProviders(t *testing.T) []liveProviderConfig {
+ t.Helper()
+
+ list := os.Getenv("LIVE_PROVIDERS")
+ if list == "" {
+ // Fallback: just the primary provider
+ return []liveProviderConfig{requireLiveProvider(t)}
+ }
+
+ var configs []liveProviderConfig
+ for _, name := range splitTrim(list, ",") {
+ keyEnv := providerKeyEnvs[name]
+ if keyEnv == "" {
+ keyEnv = strings.ToUpper(name) + "_API_KEY"
+ }
+ key := os.Getenv(keyEnv)
+ if key == "" {
+ t.Logf(" Skipping provider %s: %s not set", name, keyEnv)
+ continue
+ }
+ endpoint := os.Getenv(strings.ToUpper(name) + "_API_URL")
+ if endpoint == "" {
+ endpoint = defaultEndpoints[name]
+ }
+ if endpoint == "" {
+ t.Logf(" Skipping provider %s: no endpoint", name)
+ continue
+ }
+ configs = append(configs, liveProviderConfig{Provider: name, Key: key, Endpoint: endpoint})
+ }
+
+ if len(configs) == 0 {
+ t.Skip("no live providers configured — set LIVE_PROVIDERS + API keys")
+ }
+ t.Logf(" Live providers: %d configured", len(configs))
+ return configs
+}
+
+// splitTrim splits s by sep and trims whitespace from each element.
+func splitTrim(s, sep string) []string {
+ parts := strings.Split(s, sep)
+ var out []string
+ for _, p := range parts {
+ p = strings.TrimSpace(p)
+ if p != "" {
+ out = append(out, p)
+ }
+ }
+ return out
+}
+
+// providerModel holds a resolved (configID, modelID) pair from a provider.
+type providerModel struct {
+ ConfigID string
+ ModelID string
+ Provider string
+}
+
+// setupAllProviders creates configs and enables a model for each provider.
+// Tolerant: if a provider fails setup, it's skipped. Fails only if zero succeed.
+func setupAllProviders(t *testing.T, h *testHarness, adminToken string, providerList []liveProviderConfig) []providerModel {
+ t.Helper()
+ var models []providerModel
+ for _, pc := range providerList {
+ configID, modelID, err := trySetupProvider(h, adminToken, pc)
+ if err != nil {
+ t.Logf(" ⚠ %s setup failed: %v — skipping", pc.Provider, err)
+ continue
+ }
+ t.Logf(" Provider %s ready, model %s enabled", pc.Provider, modelID)
+ models = append(models, providerModel{ConfigID: configID, ModelID: modelID, Provider: pc.Provider})
+ }
+ if len(models) == 0 {
+ t.Fatal("no providers available after setup — all failed")
+ }
+ return models
+}
+
+// trySetupProvider is like setupProviderWithModel but returns error instead of t.Fatal.
+func trySetupProvider(h *testHarness, adminToken string, pc liveProviderConfig) (string, string, error) {
+ // Create provider
+ w := h.request("POST", "/api/v1/admin/configs", adminToken, map[string]interface{}{
+ "name": pc.Provider + " Test", "provider": pc.Provider,
+ "endpoint": pc.Endpoint, "api_key": pc.Key,
+ })
+ if w.Code != http.StatusCreated {
+ return "", "", fmt.Errorf("create config: %d: %s", w.Code, w.Body.String())
+ }
+ var cfg map[string]interface{}
+ decode(w, &cfg)
+ configID := cfg["id"].(string)
+
+ // Fetch models
+ w = h.request("POST", "/api/v1/admin/models/fetch", adminToken,
+ map[string]interface{}{"provider_config_id": configID})
+ if w.Code != http.StatusOK {
+ return "", "", fmt.Errorf("fetch models: %d: %s", w.Code, w.Body.String())
+ }
+
+ // Find and enable a non-reasoning model
+ w = h.request("GET", "/api/v1/admin/models", adminToken, nil)
+ var modelsResp map[string]interface{}
+ decode(w, &modelsResp)
+
+ var catalogID, modelID string
+ var fallbackCatalogID, fallbackModelID string
+
+ for _, raw := range modelsResp["models"].([]interface{}) {
+ m := raw.(map[string]interface{})
+ if m["visibility"].(string) != "disabled" {
+ continue
+ }
+ // Only pick models from this provider
+ if m["provider_config_id"] != nil && m["provider_config_id"].(string) != configID {
+ continue
+ }
+ mid := m["model_id"].(string)
+ cid := m["id"].(string)
+ if fallbackCatalogID == "" {
+ fallbackCatalogID = cid
+ fallbackModelID = mid
+ }
+ isReasoning := false
+ if caps, ok := m["capabilities"].(map[string]interface{}); ok {
+ if r, exists := caps["reasoning"]; exists && r == true {
+ isReasoning = true
+ }
+ }
+ if !isReasoning {
+ catalogID = cid
+ modelID = mid
+ break
+ }
+ }
+ if catalogID == "" {
+ catalogID = fallbackCatalogID
+ modelID = fallbackModelID
+ }
+ if catalogID == "" {
+ return "", "", fmt.Errorf("no disabled model found")
+ }
+
+ w = h.request("PUT", "/api/v1/admin/models/"+catalogID, adminToken,
+ map[string]interface{}{"visibility": "enabled"})
+ if w.Code != http.StatusOK {
+ return "", "", fmt.Errorf("enable model: %d: %s", w.Code, w.Body.String())
+ }
+ return configID, modelID, nil
+}
+
+// tryCompletion attempts a completion against each provider/model in order.
+// Returns the first successful response and the provider that worked.
+// Fails only if ALL providers fail.
+func tryCompletion(t *testing.T, h *testHarness, token, channelID string, models []providerModel, stream bool) (*httptest.ResponseRecorder, providerModel) {
+ t.Helper()
+ var lastW *httptest.ResponseRecorder
+ for _, pm := range models {
+ w := h.request("POST", "/api/v1/chat/completions", token, map[string]interface{}{
+ "channel_id": channelID,
+ "content": "Say ok",
+ "model": pm.ModelID,
+ "provider_config_id": pm.ConfigID,
+ "stream": &stream,
+ "max_tokens": 1200,
+ })
+ if w.Code == http.StatusOK {
+ t.Logf(" ✓ Completion via %s/%s (status %d)", pm.Provider, pm.ModelID, w.Code)
+ return w, pm
+ }
+ t.Logf(" ✗ %s/%s returned %d — trying next", pm.Provider, pm.ModelID, w.Code)
+ lastW = w
+ }
+ // All failed
+ body := ""
+ if lastW != nil {
+ body = lastW.Body.String()
+ }
+ t.Fatalf("all %d providers failed; last: %s", len(models), body)
+ return nil, providerModel{} // unreachable
+}
+
// setupProviderWithModel creates a provider config, fetches models, and enables
// the first available model. Returns (configID, enabledModelID).
func setupProviderWithModel(t *testing.T, h *testHarness, adminToken string, pc liveProviderConfig) (string, string) {
@@ -334,10 +531,10 @@ func TestLive_FetchModelsCapabilities(t *testing.T) {
// TestLive_ChatCompletion sends an actual non-streaming chat completion.
func TestLive_ChatCompletion(t *testing.T) {
h := setupHarness(t)
- pc := requireLiveProvider(t)
+ liveProvs := requireLiveProviders(t)
_, adminToken := h.createAdminUser("admin", "admin@test.com")
- configID, modelID := setupProviderWithModel(t, h, adminToken, pc)
+ models := setupAllProviders(t, h, adminToken, liveProvs)
w := h.request("POST", "/api/v1/channels", adminToken, map[string]interface{}{
"title": "Chat Test", "type": "direct",
@@ -349,18 +546,7 @@ func TestLive_ChatCompletion(t *testing.T) {
decode(w, &ch)
channelID := ch["id"].(string)
- stream := false
- w = h.request("POST", "/api/v1/chat/completions", adminToken, map[string]interface{}{
- "channel_id": channelID,
- "content": "Say ok",
- "model": modelID,
- "provider_config_id": configID,
- "stream": &stream,
- "max_tokens": 1200,
- })
- if w.Code != http.StatusOK {
- t.Fatalf("completion: want 200, got %d: %s", w.Code, w.Body.String())
- }
+ w, _ = tryCompletion(t, h, adminToken, channelID, models, false)
t.Logf(" ✓ Completion succeeded: %s", w.Body.String()[:min(200, w.Body.Len())])
}
@@ -368,10 +554,10 @@ func TestLive_ChatCompletion(t *testing.T) {
// creates a usage_log row with token counts.
func TestLive_UsageLogging(t *testing.T) {
h := setupHarness(t)
- pc := requireLiveProvider(t)
+ liveProvs := requireLiveProviders(t)
_, adminToken := h.createAdminUser("admin", "admin@test.com")
- configID, modelID := setupProviderWithModel(t, h, adminToken, pc)
+ models := setupAllProviders(t, h, adminToken, liveProvs)
w := h.request("POST", "/api/v1/channels", adminToken, map[string]interface{}{
"title": "Usage Test", "type": "direct",
@@ -382,23 +568,12 @@ func TestLive_UsageLogging(t *testing.T) {
var ch map[string]interface{}
decode(w, &ch)
- stream := false
- w = h.request("POST", "/api/v1/chat/completions", adminToken, map[string]interface{}{
- "channel_id": ch["id"].(string),
- "content": "Say ok",
- "model": modelID,
- "provider_config_id": configID,
- "stream": &stream,
- "max_tokens": 1200,
- })
- if w.Code != http.StatusOK {
- t.Fatalf("completion: %d: %s", w.Code, w.Body.String())
- }
+ _, used := tryCompletion(t, h, adminToken, ch["id"].(string), models, false)
var rowCount, promptTokens, completionTokens int
err := database.TestDB.QueryRow(
"SELECT COUNT(*), COALESCE(SUM(prompt_tokens), 0), COALESCE(SUM(completion_tokens), 0) FROM usage_log WHERE provider_config_id = "+database.PH(1),
- configID).Scan(&rowCount, &promptTokens, &completionTokens)
+ used.ConfigID).Scan(&rowCount, &promptTokens, &completionTokens)
if err != nil {
t.Fatalf("query usage_log: %v", err)
}
@@ -408,16 +583,16 @@ func TestLive_UsageLogging(t *testing.T) {
if promptTokens == 0 {
t.Fatal("completion should report prompt tokens")
}
- t.Logf(" ✓ Usage: %d row(s), prompt=%d completion=%d", rowCount, promptTokens, completionTokens)
+ t.Logf(" ✓ Usage: %d row(s), prompt=%d completion=%d (via %s)", rowCount, promptTokens, completionTokens, used.Provider)
}
// TestLive_StreamingUsageLogging verifies streaming completions log usage.
func TestLive_StreamingUsageLogging(t *testing.T) {
h := setupHarness(t)
- pc := requireLiveProvider(t)
+ liveProvs := requireLiveProviders(t)
_, adminToken := h.createAdminUser("admin", "admin@test.com")
- configID, modelID := setupProviderWithModel(t, h, adminToken, pc)
+ models := setupAllProviders(t, h, adminToken, liveProvs)
w := h.request("POST", "/api/v1/channels", adminToken, map[string]interface{}{
"title": "Stream Usage Test", "type": "direct",
@@ -428,23 +603,12 @@ func TestLive_StreamingUsageLogging(t *testing.T) {
var ch map[string]interface{}
decode(w, &ch)
- stream := true
- w = h.request("POST", "/api/v1/chat/completions", adminToken, map[string]interface{}{
- "channel_id": ch["id"].(string),
- "content": "Say ok",
- "model": modelID,
- "provider_config_id": configID,
- "stream": &stream,
- "max_tokens": 1200,
- })
- if w.Code != http.StatusOK {
- t.Fatalf("streaming completion: %d: %s", w.Code, w.Body.String())
- }
+ _, used := tryCompletion(t, h, adminToken, ch["id"].(string), models, true)
var rowCount, promptTokens, completionTokens int
err := database.TestDB.QueryRow(
"SELECT COUNT(*), COALESCE(SUM(prompt_tokens), 0), COALESCE(SUM(completion_tokens), 0) FROM usage_log WHERE provider_config_id = "+database.PH(1),
- configID).Scan(&rowCount, &promptTokens, &completionTokens)
+ used.ConfigID).Scan(&rowCount, &promptTokens, &completionTokens)
if err != nil {
t.Fatalf("query usage_log: %v", err)
}
@@ -454,7 +618,7 @@ func TestLive_StreamingUsageLogging(t *testing.T) {
if promptTokens == 0 {
t.Fatal("streaming completion should report prompt tokens")
}
- t.Logf(" ✓ Streaming usage: %d row(s), prompt=%d completion=%d", rowCount, promptTokens, completionTokens)
+ t.Logf(" ✓ Streaming usage: %d row(s), prompt=%d completion=%d (via %s)", rowCount, promptTokens, completionTokens, used.Provider)
}
// TestLive_PricingFromCatalog verifies model sync populates pricing.
diff --git a/server/handlers/projects.go b/server/handlers/projects.go
index 551a8a5..f690fd7 100644
--- a/server/handlers/projects.go
+++ b/server/handlers/projects.go
@@ -449,16 +449,20 @@ func (h *ProjectHandler) loadAndAuthorize(c *gin.Context) (*models.Project, bool
}
userID := getUserID(c)
- teamIDs, _ := h.stores.Teams.GetUserTeamIDs(c.Request.Context(), userID)
- ok, err := h.stores.Projects.UserCanAccess(c.Request.Context(), userID, projectID, teamIDs)
- if err != nil {
- c.JSON(http.StatusInternalServerError, gin.H{"error": "access check failed"})
- return nil, false
- }
- if !ok {
- c.JSON(http.StatusNotFound, gin.H{"error": "project not found"})
- return nil, false
+ // Admins can access all projects
+ if c.GetString("role") != "admin" {
+ teamIDs, _ := h.stores.Teams.GetUserTeamIDs(c.Request.Context(), userID)
+
+ ok, err := h.stores.Projects.UserCanAccess(c.Request.Context(), userID, projectID, teamIDs)
+ if err != nil {
+ c.JSON(http.StatusInternalServerError, gin.H{"error": "access check failed"})
+ return nil, false
+ }
+ if !ok {
+ c.JSON(http.StatusNotFound, gin.H{"error": "project not found"})
+ return nil, false
+ }
}
project, err := h.stores.Projects.GetByID(c.Request.Context(), projectID)
diff --git a/server/handlers/settings.go b/server/handlers/settings.go
index 2ab63ea..e9450d3 100644
--- a/server/handlers/settings.go
+++ b/server/handlers/settings.go
@@ -171,8 +171,11 @@ func (h *SettingsHandler) GetSettings(c *gin.Context) {
userID := getUserID(c)
var settingsRaw string
+ // Handle three states: SQL NULL, JSON null, or valid JSON object.
+ // NULLIF(settings, 'null') converts JSON null to SQL NULL,
+ // then COALESCE handles both SQL NULL cases.
err := database.DB.QueryRow(
- database.Q(`SELECT settings::text FROM users WHERE id = $1`), userID,
+ database.Q(`SELECT COALESCE(NULLIF(settings::text, 'null'), '{}') FROM users WHERE id = $1`), userID,
).Scan(&settingsRaw)
if err != nil {
c.JSON(http.StatusInternalServerError, gin.H{"error": "failed to load settings"})
@@ -202,12 +205,25 @@ func (h *SettingsHandler) UpdateSettings(c *gin.Context) {
return
}
- // JSONB merge — existing keys preserved, incoming keys overwrite
+ // JSONB merge — existing keys preserved, incoming keys overwrite.
+ // Must handle three column states:
+ // 1. SQL NULL (never saved)
+ // 2. JSON literal null (corrupted by earlier bug)
+ // 3. JSON array (corrupted by repeated appends to null)
+ // 4. Valid JSON object (normal)
+ // NULLIF converts JSON null → SQL NULL, then COALESCE → '{}',
+ // and we enforce jsonb_typeof = 'object' to catch array corruption.
var mergeQuery string
if database.IsSQLite() {
- mergeQuery = `UPDATE users SET settings = json_patch(settings, ?), updated_at = datetime('now') WHERE id = ?`
+ mergeQuery = `UPDATE users SET settings = json_patch(
+ CASE WHEN settings IS NULL OR settings = 'null' OR json_type(settings) != 'object'
+ THEN '{}' ELSE settings END,
+ ?), updated_at = datetime('now') WHERE id = ?`
} else {
- mergeQuery = `UPDATE users SET settings = settings || $1::jsonb, updated_at = NOW() WHERE id = $2`
+ mergeQuery = `UPDATE users SET settings = (
+ CASE WHEN settings IS NULL OR settings = 'null'::jsonb OR jsonb_typeof(settings) != 'object'
+ THEN '{}'::jsonb ELSE settings END
+ ) || $1::jsonb, updated_at = NOW() WHERE id = $2`
}
_, err = database.DB.Exec(mergeQuery, string(patch), userID)
if err != nil {
diff --git a/server/pages/loaders.go b/server/pages/loaders.go
index 1174eac..e57ede3 100644
--- a/server/pages/loaders.go
+++ b/server/pages/loaders.go
@@ -430,22 +430,14 @@ func (e *Engine) settingsLoader(c *gin.Context, s store.Stores) (any, error) {
data := &SettingsPageData{Section: section}
- // Read feature gates from admin config
- if s.GlobalConfig != nil {
+ // Read feature gates from policies (where admin settings saves them).
+ // Keys: allow_user_byok, allow_user_personas
+ if s.Policies != nil {
ctx := context.Background()
-
- // BYOK: check if user providers are enabled
- if raw, err := s.GlobalConfig.Get(ctx, "user_providers"); err == nil && raw != nil {
- if v, ok := raw["enabled"].(bool); ok {
- data.BYOKEnabled = v
- }
- }
-
- // User Personas: check if user-created personas are enabled
- if raw, err := s.GlobalConfig.Get(ctx, "user_personas"); err == nil && raw != nil {
- if v, ok := raw["enabled"].(bool); ok {
- data.UserPersonasEnabled = v
- }
+ policies, err := s.Policies.GetAll(ctx)
+ if err == nil {
+ data.BYOKEnabled = policies["allow_user_byok"] == "true"
+ data.UserPersonasEnabled = policies["allow_user_personas"] == "true"
}
}
diff --git a/server/pages/templates/base.html b/server/pages/templates/base.html
index e39d0af..3e7d2e5 100644
--- a/server/pages/templates/base.html
+++ b/server/pages/templates/base.html
@@ -26,12 +26,10 @@
@@ -58,6 +56,7 @@
{{end}}
+
{{if eq .Surface "chat"}}{{template "surface-chat" .}}
{{else if eq .Surface "admin"}}{{template "surface-admin" .}}
{{else if eq .Surface "editor"}}{{template "surface-editor" .}}
@@ -65,6 +64,7 @@
{{else if eq .Surface "settings"}}{{template "surface-settings" .}}
{{else}}
Unknown surface: {{.Surface}}
{{end}}
+
{{if .Banner.Visible}}
diff --git a/server/pages/templates/surfaces/admin.html b/server/pages/templates/surfaces/admin.html
index b4be5f7..ed519aa 100644
--- a/server/pages/templates/surfaces/admin.html
+++ b/server/pages/templates/surfaces/admin.html
@@ -9,7 +9,7 @@
{{/* Top Bar */}}
- {{/* Left Nav */}}
-
- {{/* People sections */}}
- {{if eq $section "users"}}
Users
- {{else}}
Users{{end}}
- {{if eq $section "teams"}}
Teams
- {{else}}
Teams{{end}}
- {{if eq $section "groups"}}
Groups
- {{else}}
Groups{{end}}
-
+ {{/* Left Nav — populated by admin-scaffold.js from ADMIN_SECTIONS */}}
+
{{/* Content Area */}}
@@ -218,6 +210,7 @@
+
diff --git a/server/store/postgres/helpers.go b/server/store/postgres/helpers.go
index a19c65d..d133b0a 100644
--- a/server/store/postgres/helpers.go
+++ b/server/store/postgres/helpers.go
@@ -46,7 +46,6 @@ func (b *UpdateBuilder) Set(col string, val interface{}) *UpdateBuilder {
// SetNull adds a col = NULL pair to the UPDATE.
func (b *UpdateBuilder) SetNull(col string) *UpdateBuilder {
- b.argIdx++
b.sets = append(b.sets, fmt.Sprintf("%s = NULL", col))
return b
}
diff --git a/src/css/modals.css b/src/css/modals.css
index 799144b..29cae7a 100644
--- a/src/css/modals.css
+++ b/src/css/modals.css
@@ -293,6 +293,7 @@
transition: opacity var(--transition);
}
.team-admin-back:hover { opacity: 1; }
+.team-admin-content { flex: 1; flex-direction: column; min-width: 0; }
.team-tab-content { padding: 0; }
/* Health + Routing admin (v0.22.3) */
diff --git a/src/js/admin-handlers.js b/src/js/admin-handlers.js
index 5beb992..ff922b1 100644
--- a/src/js/admin-handlers.js
+++ b/src/js/admin-handlers.js
@@ -469,11 +469,9 @@ async function saveGrant(resourceType, resourceId) {
// ── Admin Listeners (extracted from initListeners) ──
function _initAdminListeners() {
- // Admin panel navigation (elements may not exist for non-admin users)
- document.getElementById('adminBackBtn')?.addEventListener('click', UI.closeAdmin);
- document.querySelectorAll('.admin-cat').forEach(btn => {
- btn.addEventListener('click', () => UI.switchAdminCategory(btn.dataset.cat));
- });
+ // Back button and category tab navigation are handled by the inline
+ // script in admin.html (sessionStorage return URL + location.replace).
+ // Only wire up section-specific action handlers here.
document.getElementById('adminSaveSettings')?.addEventListener('click', handleSaveAdminSettings);
// Admin — users
diff --git a/src/js/admin-scaffold.js b/src/js/admin-scaffold.js
index 63006c0..8fa0b47 100644
--- a/src/js/admin-scaffold.js
+++ b/src/js/admin-scaffold.js
@@ -181,7 +181,13 @@
'
Loading...
' +
'
' +
'
' +
- '
' +
+ '
' +
+ '
' +
+ '
' +
+ '
' +
+ '
' +
+ '
' +
+ '
' +
'
';
SCAFFOLDING.storage = '';
diff --git a/src/js/api.js b/src/js/api.js
index 09a178d..7a1d577 100644
--- a/src/js/api.js
+++ b/src/js/api.js
@@ -334,6 +334,7 @@ const API = {
listWorkspaces() { return this._get('/api/v1/workspaces'); },
createWorkspace(data) { return this._post('/api/v1/workspaces', data); },
updateWorkspace(id, patch) { return this._patch(`/api/v1/workspaces/${id}`, patch); },
+ deleteWorkspace(id) { return this._delete(`/api/v1/workspaces/${id}`); },
listGitCredentials() { return this._get('/api/v1/git-credentials'); },
// ── Messages ─────────────────────────────
diff --git a/src/js/notes.js b/src/js/notes.js
index 80eb981..cf52971 100644
--- a/src/js/notes.js
+++ b/src/js/notes.js
@@ -634,7 +634,7 @@ function _showSaveToNoteModal(opts) {
modal.id = 'saveToNoteModal';
modal.className = 'modal-overlay active';
modal.innerHTML = `
-
+
Save to Note
diff --git a/src/js/panels.js b/src/js/panels.js
index 0585ad3..2f0b0ed 100644
--- a/src/js/panels.js
+++ b/src/js/panels.js
@@ -318,11 +318,11 @@ function _initWorkspaceResize() {
// the open-transition is still animating.
secondary.style.transition = 'none';
void secondary.offsetWidth;
- // #surface has transform:scale(z) from applyAppearance.
- // getBoundingClientRect returns post-transform visual px.
- // Divide by scale to recover CSS px for style.width.
- const surface = document.getElementById('surface');
- const m = surface?.style.transform?.match(/scale\(([^)]+)\)/);
+ // #surfaceInner has transform:scale(z) from applyAppearance.
+ // getBoundingClientRect on descendants returns post-transform
+ // visual px. Divide by scale to recover CSS px for style.width.
+ const inner = document.getElementById('surfaceInner');
+ const m = inner?.style.transform?.match(/scale\(([^)]+)\)/);
const scale = m ? parseFloat(m[1]) : 1;
const startW = secondary.getBoundingClientRect().width / scale;
secondary.style.width = startW + 'px';
diff --git a/src/js/projects-ui.js b/src/js/projects-ui.js
index c407fa8..e74cf56 100644
--- a/src/js/projects-ui.js
+++ b/src/js/projects-ui.js
@@ -1035,9 +1035,13 @@ async function showWorkspacePicker(chatId) {
for (const opt of options) {
const row = document.createElement('div');
row.className = 'editor-qo-row' + (opt.value === currentWsId ? ' active' : '');
- row.style.fontWeight = opt.value === currentWsId ? '600' : '';
- row.textContent = opt.label;
- row.addEventListener('click', async () => {
+ row.style.cssText = 'display:flex;align-items:center;gap:8px;' + (opt.value === currentWsId ? 'font-weight:600;' : '');
+
+ const label = document.createElement('span');
+ label.style.flex = '1';
+ label.style.cursor = 'pointer';
+ label.textContent = opt.label;
+ label.addEventListener('click', async () => {
overlay.remove();
if (opt.value === '__new__') {
const name = prompt('Workspace name:');
@@ -1064,6 +1068,46 @@ async function showWorkspacePicker(chatId) {
}
}
});
+ row.appendChild(label);
+
+ // Action buttons for real workspaces (not "None" or "Create new")
+ if (opt.value && opt.value !== '__new__') {
+ const renameBtn = document.createElement('button');
+ renameBtn.className = 'icon-btn';
+ renameBtn.title = 'Rename';
+ renameBtn.textContent = '✏';
+ renameBtn.style.cssText = 'font-size:12px;padding:2px 4px;flex-shrink:0;';
+ renameBtn.addEventListener('click', async (e) => {
+ e.stopPropagation();
+ const newName = prompt('Rename workspace:', opt.label);
+ if (!newName || !newName.trim() || newName.trim() === opt.label) return;
+ try {
+ await API.updateWorkspace(opt.value, { name: newName.trim() });
+ UI.toast('Workspace renamed');
+ overlay.remove();
+ showWorkspacePicker(chatId); // reopen with updated names
+ } catch (err) { UI.toast('Rename failed: ' + err.message, 'error'); }
+ });
+ row.appendChild(renameBtn);
+
+ const delBtn = document.createElement('button');
+ delBtn.className = 'icon-btn icon-btn-danger';
+ delBtn.title = 'Delete workspace';
+ delBtn.textContent = '🗑';
+ delBtn.style.cssText = 'font-size:12px;padding:2px 4px;flex-shrink:0;';
+ delBtn.addEventListener('click', async (e) => {
+ e.stopPropagation();
+ if (!await showConfirm(`Delete workspace "${opt.label}"?\n\nAll files in this workspace will be permanently deleted.`)) return;
+ try {
+ await API.deleteWorkspace(opt.value);
+ UI.toast('Workspace deleted');
+ overlay.remove();
+ showWorkspacePicker(chatId);
+ } catch (err) { UI.toast('Delete failed: ' + err.message, 'error'); }
+ });
+ row.appendChild(delBtn);
+ }
+
list.appendChild(row);
}
diff --git a/src/js/settings-handlers.js b/src/js/settings-handlers.js
index 0d210de..1a358b4 100644
--- a/src/js/settings-handlers.js
+++ b/src/js/settings-handlers.js
@@ -141,7 +141,7 @@ function _initUserProviderPrimitives() {
formEl.style.display = 'none';
_userProvForm.setCreateMode();
_userProvList.refresh();
- fetchModels();
+ if (typeof fetchModels === 'function') fetchModels();
} catch (e) { UI.toast(e.message, 'error'); }
},
onCancel: () => {
@@ -167,7 +167,7 @@ function _initUserProviderPrimitives() {
await API.deleteConfig(prov.id);
UI.toast('Provider removed', 'success');
_userProvList.refresh();
- fetchModels();
+ if (typeof fetchModels === 'function') fetchModels();
} catch (e) { UI.toast(e.message, 'error'); }
},
onRefresh: async (prov) => {
@@ -176,7 +176,7 @@ function _initUserProviderPrimitives() {
const result = await API.fetchProviderModels(prov.id);
const total = result.total || 0;
UI.toast(`${prov.name}: ${total} model${total !== 1 ? 's' : ''} synced`, 'success');
- fetchModels();
+ if (typeof fetchModels === 'function') fetchModels();
} catch (e) { UI.toast(`Failed to fetch models: ${e.message}`, 'error'); }
},
});
@@ -291,24 +291,23 @@ function _initUserRolePrimitive() {
},
fetchModels: async () => {
// Refresh App.models to ensure personal provider models are current.
- // Without this, newly added providers may not appear in the dropdown.
- await fetchModels();
- return App.models || [];
+ if (typeof fetchModels === 'function') await fetchModels();
+ return (typeof App !== 'undefined' && App.models) || [];
},
fetchRoles: async () => {
- const settings = await API.getSettings();
+ const settings = await API.getSettings() || {};
return settings.model_roles || {};
},
onSave: async (roleId, config) => {
if (!config.primary) throw new Error('Select both a provider and model');
- const settings = await API.getSettings();
+ const settings = await API.getSettings() || {};
const roles = settings.model_roles || {};
roles[roleId] = config;
await API.updateSettings({ model_roles: roles });
UI.toast(`${roleId} role override saved`, 'success');
},
onClear: async (roleId) => {
- const settings = await API.getSettings();
+ const settings = await API.getSettings() || {};
const roles = settings.model_roles || {};
delete roles[roleId];
await API.updateSettings({ model_roles: Object.keys(roles).length > 0 ? roles : null });
@@ -463,77 +462,46 @@ function _renderCmdResults(query) {
}
// ── Settings Listeners (extracted from initListeners) ──
+// Settings surface elements (settingsModel, providerShowAddBtn, etc.) only
+// exist on the /settings/ surface. Team admin elements (settingsTeamAddMemberBtn,
+// etc.) exist on the chat surface. Both are wired here — settings-surface
+// features under a guard, team admin features unconditionally via ?.
function _initSettingsListeners() {
- // Settings modal elements only exist on the settings surface.
- // On chat surface, openSettings() navigates to /settings/ instead.
- const settingsModel = document.getElementById('settingsModel');
- if (!settingsModel) return;
-
- document.getElementById('settingsCloseBtn')?.addEventListener('click', UI.closeSettings);
- document.getElementById('settingsSaveBtn')?.addEventListener('click', handleSaveSettings);
- document.querySelectorAll('.settings-tab').forEach(tab => {
- tab.addEventListener('click', () => UI.switchSettingsTab(tab.dataset.stab));
- });
- settingsModel.addEventListener('change', function() {
- const model = App.findModel(this.value);
- const caps = model?.capabilities || {};
- const hint = document.getElementById('settingsMaxHint');
- if (hint) {
- hint.textContent = caps.max_output_tokens > 0
- ? `(model max: ${(caps.max_output_tokens / 1000).toFixed(0)}K)`
- : '';
- }
- });
- document.getElementById('profileChangePwBtn').addEventListener('click', () => {
- document.getElementById('profileChangePwForm').style.display = '';
- });
- document.getElementById('profileSavePwBtn').addEventListener('click', handleChangePassword);
-
- // Avatar upload
- document.getElementById('avatarUploadBtn').addEventListener('click', () => {
- document.getElementById('avatarFileInput').click();
- });
- document.getElementById('avatarFileInput').addEventListener('change', async function() {
- const file = this.files[0];
- if (!file) return;
- const reader = new FileReader();
- reader.onload = async () => {
- try {
- const data = await API.uploadAvatar(reader.result);
- if (data.avatar) {
- API.user.avatar = data.avatar;
- API.saveTokens();
- updateAvatarPreview(data.avatar);
- UI.updateUser();
- UI.toast('Avatar updated');
+ // ── Settings surface features (only exist on /settings/) ──
+ // Use data-surface to detect we're on the settings surface (not chat).
+ // Individual features guard on their own elements since each section
+ // only renders its own DOM.
+ const isSettingsSurface = document.body.dataset.surface === 'settings';
+ if (isSettingsSurface) {
+ // General section: model change hint
+ const settingsModel = document.getElementById('settingsModel');
+ if (settingsModel) {
+ settingsModel.addEventListener('change', function() {
+ const model = App.findModel(this.value);
+ const caps = model?.capabilities || {};
+ const hint = document.getElementById('settingsMaxHint');
+ if (hint) {
+ hint.textContent = caps.max_output_tokens > 0
+ ? `(model max: ${(caps.max_output_tokens / 1000).toFixed(0)}K)`
+ : '';
}
- } catch (e) { UI.toast(e.message || 'Upload failed', 'error'); }
- };
- reader.readAsDataURL(file);
- this.value = '';
- });
- document.getElementById('avatarRemoveBtn').addEventListener('click', async () => {
- try {
- await API.deleteAvatar();
- API.user.avatar = null;
- API.saveTokens();
- updateAvatarPreview(null);
- UI.updateUser();
- UI.toast('Avatar removed');
- } catch (e) { UI.toast(e.message || 'Remove failed', 'error'); }
- });
+ });
+ }
- // User BYOK provider primitives
- _initUserProviderPrimitives();
- _initUserRolePrimitive();
- document.getElementById('providerShowAddBtn').addEventListener('click', () => {
- const formEl = document.getElementById('providerAddForm');
- if (_userProvForm) _userProvForm.setCreateMode();
- formEl.style.display = '';
- });
+ // Providers section: BYOK form + list primitives
+ _initUserProviderPrimitives();
+ document.getElementById('providerShowAddBtn')?.addEventListener('click', () => {
+ const formEl = document.getElementById('providerAddForm');
+ if (_userProvForm) _userProvForm.setCreateMode();
+ if (formEl) formEl.style.display = '';
+ });
- // Settings — Team management (team admin self-service)
+ // Models section: role primitives
+ _initUserRolePrimitive();
+ }
+
+ // ── Team management (team admin self-service, on chat surface) ──
document.getElementById('settingsTeamAddMemberBtn')?.addEventListener('click', async () => {
document.getElementById('settingsTeamAddMember').style.display = '';
const sel = document.getElementById('settingsTeamMemberUser');
@@ -578,7 +546,7 @@ function _initSettingsListeners() {
_teamPersonaForm.clearForm();
UI.toast('Team persona created');
await UI.loadTeamManagePersonas(teamId);
- await fetchModels();
+ if (typeof fetchModels === 'function') await fetchModels();
} catch (e) { UI.toast(e.message, 'error'); }
},
onCancel: () => { container.style.display = 'none'; _teamPersonaForm.clearForm(); }
@@ -627,7 +595,7 @@ function _initSettingsListeners() {
_userPersonaForm.clearForm();
UI.toast('Persona created');
await UI.loadUserPersonas();
- await fetchModels();
+ if (typeof fetchModels === 'function') await fetchModels();
} catch (e) { UI.toast(e.message, 'error'); }
},
onCancel: () => { container.style.display = 'none'; _userPersonaForm.clearForm(); }
@@ -644,28 +612,6 @@ function _initSettingsListeners() {
});
}
});
-
- // Admin — banner controls
- document.getElementById('adminBannerEnabled')?.addEventListener('change', (e) => {
- document.getElementById('bannerConfigFields').style.display = e.target.checked ? '' : 'none';
- });
- ['adminBannerText', 'adminBannerBg', 'adminBannerFg'].forEach(id => {
- document.getElementById(id)?.addEventListener('input', UI.updateBannerPreview);
- });
- document.getElementById('adminBannerBg')?.addEventListener('input', (e) => { document.getElementById('adminBannerBgHex').value = e.target.value; });
- document.getElementById('adminBannerFg')?.addEventListener('input', (e) => { document.getElementById('adminBannerFgHex').value = e.target.value; });
- document.getElementById('adminBannerBgHex')?.addEventListener('input', (e) => { if (/^#[0-9a-f]{6}$/i.test(e.target.value)) { document.getElementById('adminBannerBg').value = e.target.value; UI.updateBannerPreview(); }});
- document.getElementById('adminBannerFgHex')?.addEventListener('input', (e) => { if (/^#[0-9a-f]{6}$/i.test(e.target.value)) { document.getElementById('adminBannerFg').value = e.target.value; UI.updateBannerPreview(); }});
-
- // Admin — auto-compaction controls
- document.getElementById('adminCompactionEnabled')?.addEventListener('change', (e) => {
- document.getElementById('compactionConfigFields').style.display = e.target.checked ? '' : 'none';
- });
-
- // Admin — search provider controls
- document.getElementById('adminSearchProvider')?.addEventListener('change', (e) => {
- document.getElementById('searxngConfigFields').style.display = e.target.value === 'searxng' ? '' : 'none';
- });
}
// Admin settings toggle wiring — safe to call from admin surface scaffold
@@ -704,4 +650,187 @@ function _initAdminSettingsToggles() {
document.getElementById('usageRefreshBtn')?.addEventListener('click', () => UI.loadAdminUsage());
document.getElementById('usagePeriod')?.addEventListener('change', () => UI.loadAdminUsage());
document.getElementById('usageGroupBy')?.addEventListener('change', () => UI.loadAdminUsage());
+
+ // Admin — settings export/import
+ document.getElementById('adminExportSettings')?.addEventListener('click', _exportAdminSettings);
+ const importBtn = document.getElementById('adminImportSettings');
+ const importFile = document.getElementById('adminImportFile');
+ if (importBtn && importFile) {
+ importBtn.addEventListener('click', () => importFile.click());
+ importFile.addEventListener('change', () => {
+ if (importFile.files[0]) _importAdminSettings(importFile.files[0]);
+ importFile.value = ''; // reset so same file can be re-selected
+ });
+ }
+}
+
+// ── Admin Settings Export ────────────────────
+async function _exportAdminSettings() {
+ try {
+ const data = await API.adminGetSettings();
+ const envelope = {
+ _type: 'switchboard_admin_settings',
+ _version: 1,
+ _exported_at: new Date().toISOString(),
+ _switchboard_version: window.__VERSION__ || 'unknown',
+ settings: data.settings || {},
+ policies: data.policies || {},
+ };
+
+ const blob = new Blob([JSON.stringify(envelope, null, 2)], { type: 'application/json' });
+ const url = URL.createObjectURL(blob);
+ const a = document.createElement('a');
+ a.href = url;
+ const ts = new Date().toISOString().replace(/[:.]/g, '-').slice(0, 19);
+ a.download = `switchboard-admin-${ts}.json`;
+ a.click();
+ URL.revokeObjectURL(url);
+
+ // Count sensitive keys so admin is aware
+ const sensitiveKeys = ['search_config', 'notifications'];
+ const hasSensitive = sensitiveKeys.some(k => data.settings?.[k]);
+ UI.toast(
+ 'Settings exported' + (hasSensitive ? ' (includes API keys/credentials)' : ''),
+ hasSensitive ? 'warning' : 'success'
+ );
+ } catch (e) {
+ UI.toast('Export failed: ' + e.message, 'error');
+ }
+}
+
+// ── Admin Settings Import ────────────────────
+async function _importAdminSettings(file) {
+ try {
+ const text = await file.text();
+ let envelope;
+ try {
+ envelope = JSON.parse(text);
+ } catch (_) {
+ UI.toast('Invalid JSON file', 'error');
+ return;
+ }
+
+ if (envelope._type !== 'switchboard_admin_settings') {
+ UI.toast('Not a Switchboard settings export', 'error');
+ return;
+ }
+
+ const settingsCount = Object.keys(envelope.settings || {}).length;
+ const policiesCount = Object.keys(envelope.policies || {}).length;
+ const totalKeys = settingsCount + policiesCount;
+
+ if (totalKeys === 0) {
+ UI.toast('Settings file is empty', 'warning');
+ return;
+ }
+
+ const meta = envelope._exported_at
+ ? `Exported ${new Date(envelope._exported_at).toLocaleString()}`
+ : 'Unknown export date';
+ const ver = envelope._switchboard_version
+ ? ` from v${envelope._switchboard_version}`
+ : '';
+
+ const confirmed = await showConfirm(
+ `Import ${totalKeys} settings?\n\n` +
+ `${settingsCount} config keys, ${policiesCount} policies\n` +
+ `${meta}${ver}\n\n` +
+ `This will overwrite current admin settings.`
+ );
+ if (!confirmed) return;
+
+ let applied = 0;
+ let errors = 0;
+
+ // Apply policies (string values)
+ for (const [key, val] of Object.entries(envelope.policies || {})) {
+ try {
+ await API.adminUpdateSetting(key, { value: val });
+ applied++;
+ } catch (e) {
+ console.warn(`[import] policy "${key}" failed:`, e.message);
+ errors++;
+ }
+ }
+
+ // Apply settings (JSON values)
+ for (const [key, val] of Object.entries(envelope.settings || {})) {
+ try {
+ await API.adminUpdateSetting(key, { value: val });
+ applied++;
+ } catch (e) {
+ console.warn(`[import] setting "${key}" failed:`, e.message);
+ errors++;
+ }
+ }
+
+ if (errors === 0) {
+ UI.toast(`Imported ${applied} settings`, 'success');
+ } else {
+ UI.toast(`Imported ${applied} settings, ${errors} failed (check console)`, 'warning');
+ }
+
+ // Reload the settings form to reflect imported values
+ if (typeof UI !== 'undefined' && UI.loadAdminSettings) {
+ await UI.loadAdminSettings();
+ }
+ } catch (e) {
+ UI.toast('Import failed: ' + e.message, 'error');
+ }
+}
+
+// ── User-Facing Model/Persona Functions ──────
+// These are called from onclick handlers rendered by loadUserModels() and
+// loadUserPersonas(). Defined here so they're available on the settings
+// surface (admin-handlers.js which also defines them is only loaded on
+// chat and admin surfaces).
+
+if (typeof toggleUserModelVisibility === 'undefined') {
+ window.toggleUserModelVisibility = async function(modelId, providerConfigId, currentlyHidden) {
+ const compositeKey = (providerConfigId || '') + ':' + modelId;
+ try {
+ await API.setModelPreference(modelId, providerConfigId || null, !currentlyHidden);
+ if (currentlyHidden) App.hiddenModels.delete(compositeKey);
+ else App.hiddenModels.add(compositeKey);
+ await UI.loadUserModels();
+ if (typeof fetchModels === 'function') await fetchModels();
+ } catch (e) { UI.toast(e.message, 'error'); }
+ };
+}
+
+if (typeof bulkSetUserModelVisibility === 'undefined') {
+ window.bulkSetUserModelVisibility = async function(show) {
+ const models = (App.models || []).filter(m => !m.isPersona);
+ if (!models.length) return;
+ const shouldHide = !show;
+ const toUpdate = models
+ .filter(m => {
+ const compositeKey = (m.configId || '') + ':' + (m.baseModelId || m.id);
+ return App.hiddenModels.has(compositeKey) !== shouldHide;
+ })
+ .map(m => ({ model_id: m.baseModelId || m.id, provider_config_id: m.configId || '' }));
+ if (!toUpdate.length) { UI.toast(show ? 'All already visible' : 'All already hidden'); return; }
+ try {
+ await API.bulkSetModelPreferences(toUpdate, shouldHide);
+ toUpdate.forEach(e => {
+ const key = (e.provider_config_id || '') + ':' + e.model_id;
+ shouldHide ? App.hiddenModels.add(key) : App.hiddenModels.delete(key);
+ });
+ await UI.loadUserModels();
+ if (typeof fetchModels === 'function') await fetchModels();
+ UI.toast(`${toUpdate.length} model${toUpdate.length !== 1 ? 's' : ''} ${show ? 'shown' : 'hidden'}`);
+ } catch (e) { UI.toast(e.message, 'error'); }
+ };
+}
+
+if (typeof deleteUserPersona === 'undefined') {
+ window.deleteUserPersona = async function(id, name) {
+ if (!await showConfirm(`Delete persona "${name}"?`)) return;
+ try {
+ await API.deleteUserPersona(id);
+ UI.toast('Persona deleted');
+ await UI.loadUserPersonas();
+ if (typeof fetchModels === 'function') await fetchModels();
+ } catch (e) { UI.toast(e.message, 'error'); }
+ };
}
diff --git a/src/js/ui-admin.js b/src/js/ui-admin.js
index b74fabc..3ed8653 100644
--- a/src/js/ui-admin.js
+++ b/src/js/ui-admin.js
@@ -72,13 +72,15 @@ Object.assign(UI, {
closeAdmin() {
const base = window.__BASE__ || '';
- window.location.href = base + '/';
+ const returnURL = sessionStorage.getItem('sb_admin_return');
+ sessionStorage.removeItem('sb_admin_return');
+ window.location.href = returnURL || (base + '/');
},
// ── Navigate to specific section ──────────
openAdminSection(section) {
const base = window.__BASE__ || '';
- window.location.href = base + '/admin/' + (section || 'users');
+ location.replace(base + '/admin/' + (section || 'users'));
},
// ── Category switch ───────────────────────
diff --git a/src/js/ui-core.js b/src/js/ui-core.js
index 7c7ef20..988d7a6 100644
--- a/src/js/ui-core.js
+++ b/src/js/ui-core.js
@@ -1481,30 +1481,24 @@ const UI = {
// which only loaded on chat/settings — editor surface was skipped.
applyAppearance(scale, msgFont) {
- // Use transform:scale() on #surface — the prototype's proven approach.
- // Transform operates on the visual layer without affecting layout flow
- // of siblings (banners stay unscaled). Inverse dimensions provide the
- // right layout space so the scaled visual output fills the viewport:
- // At 80%: width=125%, height=125% of surface → scale(0.8) → visual 100%
- // At 150%: width=66.7%, height=66.7% of surface → scale(1.5) → visual 100%
- const surface = document.getElementById('surface');
- if (surface) {
+ // Scale #surfaceInner — the generic wrapper injected by base.html
+ // around every surface template. No surface-specific selectors.
+ // #surface stays as flex child, banners are siblings — untouched.
+ const inner = document.getElementById('surfaceInner');
+ if (inner) {
if (scale === 100) {
- surface.style.transform = '';
- surface.style.transformOrigin = '';
- surface.style.width = '';
- surface.style.height = '';
+ inner.style.transform = '';
+ inner.style.width = '';
+ inner.style.height = '';
} else {
const z = scale / 100;
- surface.style.transform = `scale(${z})`;
- surface.style.transformOrigin = 'top left';
- surface.style.width = (10000 / scale) + '%';
- surface.style.height = `calc(var(--surface-h) * ${10000 / scale} / 100)`;
+ inner.style.transform = `scale(${z})`;
+ inner.style.width = (100 / z) + '%';
+ inner.style.height = (100 / z) + '%';
}
}
document.documentElement.style.setProperty('--msg-font', msgFont + 'px');
localStorage.setItem('cs-appearance', JSON.stringify({ scale, msgFont }));
- // Recheck tab overflow after layout settles
requestAnimationFrame(() => {
document.querySelectorAll('.modal-overlay.active .modal-tabs').forEach(t => {
if (typeof checkTabsOverflow === 'function') checkTabsOverflow(t);
@@ -1513,7 +1507,7 @@ const UI = {
},
restoreAppearance() {
- // Clear any stale zoom from previous scaling approaches
+ // Clear stale zoom/transform from any previous scaling approaches
document.body.style.zoom = '';
document.documentElement.style.zoom = '';
try {
@@ -1523,7 +1517,6 @@ const UI = {
if (scale !== 100 || msgFont !== 14) {
UI.applyAppearance(scale, msgFont);
} else {
- // Still set the CSS variable for default
document.documentElement.style.setProperty('--msg-font', msgFont + 'px');
}
} catch (_) { /* corrupt localStorage — ignore */ }
diff --git a/src/js/ui-settings.js b/src/js/ui-settings.js
index 176d86d..19686dc 100644
--- a/src/js/ui-settings.js
+++ b/src/js/ui-settings.js
@@ -362,7 +362,7 @@ Object.assign(UI, {
titleEl.textContent = teamName;
}
document.getElementById('teamAdminPicker').style.display = 'none';
- document.getElementById('teamAdminContent').style.display = '';
+ document.getElementById('teamAdminContent').style.display = 'flex';
// Reset forms (null-safe — not all form containers may exist)
['settingsTeamAddMember', 'settingsTeamAddPersona', 'settingsTeamProviderForm'].forEach(id => {
@@ -607,13 +607,18 @@ Object.assign(UI, {
async loadUserRoles() {
const el = document.getElementById('userRolesConfig');
const notice = document.getElementById('userRolesDisabled');
- const tabBtn = document.getElementById('settingsRolesTabBtn');
if (!el) return;
// Only show if BYOK is enabled
const byokAllowed = App.policies?.allow_user_byok === 'true';
- if (tabBtn) tabBtn.style.display = byokAllowed ? '' : 'none';
- if (!byokAllowed) return;
+ if (!byokAllowed) {
+ el.style.display = 'none';
+ if (notice) {
+ notice.innerHTML = '
BYOK (Bring Your Own Key) must be enabled by your admin before you can configure model role overrides.
';
+ notice.style.display = '';
+ }
+ return;
+ }
// Check if user has personal providers
try {
@@ -623,7 +628,10 @@ Object.assign(UI, {
if (personalProviders.length === 0) {
el.style.display = 'none';
- if (notice) notice.style.display = '';
+ if (notice) {
+ notice.innerHTML = '
Add a personal provider in My Providers first to configure model role overrides.
';
+ notice.style.display = '';
+ }
return;
}
el.style.display = '';
@@ -789,7 +797,21 @@ Object.assign(UI, {
el.innerHTML = '
No models available
';
return;
}
- el.innerHTML = models.map(m => {
+
+ const hiddenCount = models.filter(m => {
+ const cfgId = m.config_id || m.provider_config_id || '';
+ return App.hiddenModels.has((cfgId || '') + ':' + (m.model_id || m.id));
+ }).length;
+ const visibleCount = models.length - hiddenCount;
+
+ let html = `
+
${visibleCount} visible, ${hiddenCount} hidden of ${models.length} total
+
+
+
+
`;
+
+ html += models.map(m => {
const mid = m.model_id || m.id;
const cfgId = m.config_id || m.provider_config_id || '';
const compositeKey = (cfgId || '') + ':' + mid;
@@ -808,6 +830,7 @@ Object.assign(UI, {
`;
}).join('');
+ el.innerHTML = html;
} catch (e) { el.innerHTML = `
${esc(e.message)}
`; }
},