✨ Enhancements
- Cookie-based authentication with CSRF protection
Sign-in and sign-out flows now use secure, HttpOnly authentication cookies alongside a CSRF cookie for browser-based sessions.
- Added an API auth token endpoint that returns the current JWT when available via cookie or header
- Enterprise sign-up and SSO flows now complete via cookie-based authentication, with success redirects that no longer include the token in the URL
- Mutating requests now enforce double-submit CSRF validation and return
403on mismatch or missing tokens
🐛 Bug Fixes
- Filter sub-session user prompts from agentic coding SSE output Internal sub-session user prompt events are no longer persisted or streamed to the primary coding session’s SSE output, while sub-session assistant tool-call events continue to be forwarded so task execution signals remain visible. Primary-session user messages render as before. The default reasoning variant now falls back to low when no explicit setting is provided.
-
Null-safe secret handling for agentic coding apps
Improved secret creation for agentic coding apps to gracefully handle cases where app settings are missing or empty.
- Added a null check for secrets so no secret is created when the app configuration is unavailable
- Prevents unnecessary errors when there are no secrets to create
- Reliable logout cookie cleanup Logout now reliably clears all authentication-related cookies.
-
Persist reasoning and patch data in agentic coding prompts
Prompt persistence and event streaming now correctly capture reasoning, patch, and tool data across prompt lifecycles.
- Added patch-type prompt support and richer structured metadata, including message/part tracking and started/ended timestamps
- Event streaming now persists assistant updates per part, improving partial vs. completed handling for tool and patch data
- Agentic coding prompts API now returns results in chronological order (oldest first)