fix: ignore provider config flags in model picker - #2415
Michaelyklam wants to merge 1 commit into
Conversation
7ab7921 to
829ac52
Compare
829ac52 to
9f404c3
Compare
|
Maintainer pushed a small fix on top of your branch (force-pushed CI was red on The fix is just a comment-block reorganization: I moved the Your Local verification:
If CI on the new commit comes back green (in progress), this is ready for nesquena independent review. Thanks for the careful fix — the gating against |
nesquena
left a comment
There was a problem hiding this comment.
Review — end-to-end ✅ (clean APPROVE, no fix pushed)
What this ships
21-line fix in api/config.py to gate the provider-detection loop on either (a) a canonical id that's in _PROVIDER_MODELS / _PROVIDER_DISPLAY or (b) a dict-shaped provider config. Before the fix, the loop accepted EVERY key under providers: because the existing condition _canonical in _cfg_providers or _pid_key in _cfg_providers was always true while iterating _cfg_providers. Scalar siblings like providers.only_configured: true got canonicalized to only-configured and rendered as fake picker groups labeled Only-Configured. Closes #2399.
Surfaces touched: api/config.py (+21/-3), tests/test_issue2399_provider_config_flags.py (+79 new, 2 tests), CHANGELOG.md (+4). 3.11/3.12/3.13 CI green.
Traced against upstream hermes-agent
Pulled a fresh tarball. No cross-tool surface — _build_configured_model_badges lives in webui-only api/config.py. The CLI doesn't read these picker groups. No config.yaml shape change.
End-to-end trace
The buggy condition (pre-fix) at api/config.py:2972-2974 (before this PR):
for _pid_key in _cfg_providers:
_canonical = _canonicalise_provider_id(_pid_key)
...
if _canonical in _PROVIDER_MODELS or _canonical in _cfg_providers or _pid_key in _cfg_providers:
detected_providers.add(_canonical)Since we iterate _cfg_providers, the last clause _pid_key in _cfg_providers is always True. So the condition collapses to "always add canonical to detected_providers". Any scalar key under providers: becomes a fake provider group.
Verified canonical mapping of the failure-shape keys:
_canonicalise_provider_id("only_configured") = 'only-configured' (NOT in _PROVIDER_MODELS)
_canonicalise_provider_id("future_toggle") = 'future-toggle' (NOT in _PROVIDER_MODELS)
_canonicalise_provider_id("opencode_go") = 'opencode-go' (IS in _PROVIDER_MODELS)
_canonicalise_provider_id("nous") = 'nous' (IS in _PROVIDER_MODELS)
Pre-fix, all four would have been added. Only the last two should have been.
The new gate at api/config.py:2986-2993:
_is_known_provider = (
_canonical in _PROVIDER_MODELS or _canonical in _PROVIDER_DISPLAY
)
_is_provider_config = isinstance(_provider_cfg, dict)
if not (_is_known_provider or _is_provider_config):
continueOR semantics:
- Known provider id (canonical or alias) → admit, regardless of value shape.
- Dict-shaped value → admit, regardless of name (covers custom providers with
api_key/base_url/models). - Everything else (scalar value with unknown name) → skip.
Iteration shape change
for _pid_key in _cfg_providers → for _pid_key, _provider_cfg in _cfg_providers.items(). Adds value access needed for the isinstance(dict) check. Net-zero for known iteration semantics.
Other audit — things that are correct already
Branch matrix (verified)
_pid_key |
value | canonical | known? | dict? | added? |
|---|---|---|---|---|---|
openai |
{models: [...]} |
openai |
yes | yes | ✅ |
openai |
true |
openai |
yes | no | ✅ (known wins) |
opencode_go |
{api_key: ...} |
opencode-go |
yes | yes | ✅ |
nous |
true |
nous |
yes | no | ✅ |
only_configured |
true |
only-configured |
no | no | ❌ (skipped — the fix) |
future_toggle |
enabled |
future-toggle |
no | no | ❌ |
my-llm-server |
{base_url: ...} |
my-llm-server |
no | yes | ✅ (custom config) |
<unknown-flag> |
false |
<some> |
no | no | ❌ |
Security
- No SQL/shell/XSS. Provider id strings come from admin-controlled
config.yaml. Even with malicious config (admin self-injection), the output is rendered through the picker's text/title pipeline which escapes viat()/textContent elsewhere. No new attack surface introduced.
Backward compat
- Existing canonical-to-raw-key dedup (#2245) preserved at
api/config.py:2995. - Known providers with scalar config (e.g.
nous: true,openai: true) still picked up via the_is_known_providershort-circuit. No regression for users who used scalar shorthand.
Test coverage
test_providers_only_configured_flag_does_not_create_picker_grouppins the reported case + assertsopenaiis still present (positive control).test_unknown_scalar_provider_config_flags_are_ignoredpins the general shape (future_toggle: enabled→ not picked up).- Both reset
_available_models_cachebefore/after to avoid cross-test pollution.
Edge-case trace
| Scenario | Expected | Actual |
|---|---|---|
providers.only_configured: true + providers.openai: {...} |
openai shown, only-configured hidden | ✅ test |
providers.future_toggle: enabled + openai |
unknown scalar skipped | ✅ test |
Known provider with true scalar value |
shown (known wins) | ✅ harness trace |
| Custom provider with dict value | shown (dict wins) | ✅ harness trace |
Empty providers: map |
no detected providers | ✅ skipped iteration |
providers: null |
not a dict → outer guard skips | ✅ pre-existing |
| Cross-tool: CLI reads same config.yaml | unaffected (webui-only picker) | ✅ |
Tests
- PR-targeted: 2/2 pass.
- Full local suite (Python 3.14): 5675 passed, 0 failed.
- CI: 3.11/3.12/3.13 all green.
Minor observations (non-blocking)
- The pre-fix bug was effectively a no-op condition —
_pid_key in _cfg_providerswas always True. The condition appeared to validate something but did nothing. A linter that flags self-tautologies could have caught this earlier. _canonicalise_provider_idaccepts any string. It normalizes underscores to dashes and lowercases. Combined with the old "always add" path, this producedOnly-Configuredstyle display labels (via_canonical.title()somewhere downstream). The new gate is the right shape; the underlying canonicaliser is fine.- Could grow
_PROVIDER_DISPLAYallow-list. If future config schema adds new top-level scalar siblings (e.g.providers.retry_count: 3,providers.timeout_ms: 5000), they correctly skip. Good design — opt-in via dict shape rather than maintaining a per-flag denylist.
Recommendation
Approved. Surgical correction of an always-true condition. Gate semantics are clear (known canonical OR dict-shaped). Two regression tests pin both the reported failure case and the broader unknown-scalar shape. No backward compat concerns for users with scalar shorthand on known providers.
✅ Parked at approval — ready for the release agent's merge/tag pipeline.
|
Shipped via stage-373 / PR #2420 / v0.51.80 (Release BD). Attribution preserved in the squashed stage commit and the v0.51.80 CHANGELOG entry. Thank you! |
… 0.51.82) (#528) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/nesquena/hermes-webui](https://github.com/nesquena/hermes-webui) | patch | `0.51.75` → `0.51.82` | --- ### Release Notes <details> <summary>nesquena/hermes-webui (ghcr.io/nesquena/hermes-webui)</summary> ### [`v0.51.82`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05182--2026-05-17--Release-BF-stage-375--2-PR-batch--table-renderer-pipe-protection--Catppuccin-appearance-skin) [Compare Source](nesquena/hermes-webui@v0.51.81...v0.51.82) ##### Added - **PR [#​2432](nesquena/hermes-webui#2432 by [@​Michaelyklam](https://github.com/Michaelyklam) (closes [#​2426](nesquena/hermes-webui#2426)) — Add a Catppuccin skin to Appearance settings. The single opt-in skin maps light mode to Catppuccin Latte and dark mode to Catppuccin Mocha, using Mauve as the accent while preserving the existing theme/skin persistence and no-build-step architecture. ##### Fixed - **PR [#​2428](nesquena/hermes-webui#2428 by [@​bengdan](https://github.com/bengdan) — Protect pipes inside parens / brackets / braces from naive `split('|')` in the Markdown table renderer. Cells like `` `(a|b)` ``, `` `Union[int|float]` ``, `` `(a|b|c)` ``, and `` `Union[int|float|str]` `` now stay in a single column instead of mis-splitting. The fix uses an iterative `_protectPipes` loop so all pipes inside one bracket pair are caught, not just the first. Also adds a `$...$` guard so a KaTeX inline-math span straddling `|` column separators is left alone instead of being stashed as math. Stage-fix on the contributor branch (a) swapped the literal `}` glyphs in the regex character classes for `\x7d` hex escapes (semantically identical, but the JS source no longer carries bare close-brace glyphs that confused the brace-counting `extractFunc` in `tests/test_renderer_js_behaviour.py`); (b) dropped a stray apostrophe stop that would have mis-split `('a'|'b')`-style string-literal unions; (c) dropped angle brackets `<` / `>` from the protected-bracket set, after Opus advisor flagged that `| x < 5 | y > 10 |` would otherwise collapse into a single cell (comparison-operator usage dominates content-grouping usage in real LLM table output); and (d) added `tests/test_issue2428_table_pipe_protection.py` with 12 regression cases covering single-pipe, multi-pipe-in-brackets, apostrophes-with-pipes, the KaTeX-in-table guard, and the angle-bracket comparison-operator case. ### [`v0.51.81`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05181--2026-05-17--Release-BE-stage-374--6-PR-batch--cost-history-POSIX-lock--prompt-cache-tokens--Plugins-panel-i18n--pending-placeholder-chat--journal-replay-partial-recovery--default-off-RuntimeAdapter-Slice-2-seam) [Compare Source](nesquena/hermes-webui@v0.51.80...v0.51.81) ##### Added - **PR [#​2424](nesquena/hermes-webui#2424 by [@​Michaelyklam](https://github.com/Michaelyklam) (refs [#​1925](nesquena/hermes-webui#1925)) — Add the default-off `RuntimeAdapter` Slice 2 seam. `HERMES_WEBUI_RUNTIME_ADAPTER=legacy-journal` now routes chat start through a `LegacyJournalRuntimeAdapter` facade over the existing legacy streaming path, while the default remains `legacy-direct`. The new adapter interface/payload classes expose start/observe/status/cancel/approval/clarify methods and delegate controls to existing handlers without introducing a runner, sidecar, new process-local queues, cached agents, cancellation registries, or callback registries. - **PR [#​2421](nesquena/hermes-webui#2421 by [@​Michaelyklam](https://github.com/Michaelyklam) (fixes [#​2419](nesquena/hermes-webui#2419)) — Surface provider prompt-cache read/write tokens in WebUI usage displays. Cache-miss cost issues are now visible in the context tooltip and per-turn usage footer; counters carry through session persistence, SSE usage payloads, and live snapshots so deltas remain accurate across the active turn. - **PR [#​2425](nesquena/hermes-webui#2425 by [@​mccxj](https://github.com/mccxj) — Wire Settings → Plugins panel into the existing i18n system. Panel title, description, empty state, and per-plugin labels (hooks, enabled/disabled, load failures) now respect the user's language preference; 10 new keys ship in English with `TODO: translate` placeholders in 9 additional locales. ##### Fixed - **PR [#​2418](nesquena/hermes-webui#2418 by [@​Michaelyklam](https://github.com/Michaelyklam) (fixes [#​2402](nesquena/hermes-webui#2402)) — OpenRouter cost-history snapshot updates now take a provider-specific POSIX file lock around the read-modify-write cycle, preserving the existing process-local lock while preventing lost snapshot updates if WebUI is deployed with multiple worker processes sharing one Hermes home/state directory. - **PR [#​2431](nesquena/hermes-webui#2431 by [@​Michaelyklam](https://github.com/Michaelyklam) (fixes [#​2429](nesquena/hermes-webui#2429)) — Chat sends now render the assistant-side pending `Thinking…` placeholder immediately after the user turn is echoed, before `/api/chat/start` returns a stream id or the first SSE event arrives. The existing stale-stream guard remains in place for ordinary reasoning updates — only the explicit pre-stream placeholder path is allowed through. - **PR [#​2427](nesquena/hermes-webui#2427 by [@​franksong2702](https://github.com/franksong2702) (fixes [#​2423](nesquena/hermes-webui#2423)) — Recover already-journaled visible assistant text and tool cards when a WebUI process restart interrupts an in-flight browser-originated turn. The stale-stream repair path now materializes run-journal output before the explicit interrupted marker instead of collapsing the turn to "no agent output was recovered." ##### Documentation - **PR [#​2416](nesquena/hermes-webui#2416 by [@​Michaelyklam](https://github.com/Michaelyklam) (refs [#​1925](nesquena/hermes-webui#1925)) — Expand the runtime-adapter RFC with the concrete Slice 2 adapter-seam contract: minimal `RuntimeAdapter` methods, payload fields, `legacy-direct` / `legacy-journal` feature-flag rollback path, legacy-backend mapping, explicit non-goals, and adapter-seam acceptance tests. Keeps the next step scoped to a reversible protocol-translator boundary over the journaled legacy path, not a runner/sidecar or execution-ownership move. ### [`v0.51.80`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05180--2026-05-17--Release-BD-stage-373--2-PR-batch--provider-config-flag-filter--stale-compaction-greeting-heuristic) [Compare Source](nesquena/hermes-webui@v0.51.79...v0.51.80) ##### Fixed - **PR [#​2415](nesquena/hermes-webui#2415 by [@​Michaelyklam](https://github.com/Michaelyklam) (fixes [#​2399](nesquena/hermes-webui#2399)) — `providers.only_configured` and other scalar flags under the top-level `providers:` config mapping no longer appear as fake provider groups in the model picker. Provider detection now only seeds picker groups from known provider ids/aliases or dict-shaped provider configs, so filtering flags cannot render as `Only-Configured`. The gating contract is documented inline in `api/config.py` (within the existing `_PROVIDER_MODELS`/`_PROVIDER_DISPLAY` membership block) so the test\_issue604 source-scan stays satisfied. - **PR [#​2417](nesquena/hermes-webui#2417 by [@​nesquena-hermes](https://github.com/nesquena-hermes) (co-authored by [@​franksong2702](https://github.com/franksong2702), supersedes [#​2309](nesquena/hermes-webui#2309), closes [#​2308](nesquena/hermes-webui#2308)) — Compressed sessions with hidden "resume active task" context no longer treat a short fresh greeting (`hi`, `hello`, plus 6 CJK greetings) as implicit permission to continue an old agent task. Explicit continuation prompts (`continue`, `resume`, plus 4 CJK continuation phrases) still keep the compacted task context. The new helpers (`_normalize_fresh_chat_text`, `_is_casual_fresh_chat_message`, `_has_task_resume_compaction_marker`, `_context_messages_for_new_turn`) require BOTH the compaction phrase AND a task-resume keyword in the SAME message before treating it as a stale-task marker (precision-preserving guard). Length cap of 24 chars + workspace-prefix normalization + exact greeting-set match prevent false positives. CJK greetings/continuation terms are stored as Python `\u`-escape sequences so `api/streaming.py` passes the `test_title_sanitization::test_title_generation_source_has_no_cjk_literals` English-only-source invariant; runtime values are unchanged. Stage-372 Opus advisor pass caught two CJK codepoint typos (`嘖→嗨`, `哈喂→哈喽`) in the maintainer rebase and corrected them; new regression test `test_all_cjk_greetings_drop_stale_compaction_context` pins all 6 CJK greetings against future codepoint drift with `U+XXXX` failure messages. ### [`v0.51.79`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05179--2026-05-16--Release-BC-stage-372--5-PR-batch--text-mode-image-history-fix--Activity-group-compression-boundary--named-custom-provider-routing--quota-chip-Settings-toggle--RFC-docs) [Compare Source](nesquena/hermes-webui@v0.51.78...v0.51.79) ##### Added - **PR [#​2413](nesquena/hermes-webui#2413 (self-built follow-up to v0.51.78's [#​2082](nesquena/hermes-webui#2082), closes the quota-chip default-on regression) — New "Show provider quota chip in composer" checkbox in Settings → Preferences, default off. When disabled (the new default), the chip is hidden at all viewports and the `/api/provider/quota` fetch is skipped entirely. When enabled, the existing `@media (max-width:1399.98px)` gate from stage-371 still restricts the chip to wide desktops only. Per Nathan's directive 2026-05-16 immediately after stage-371 shipped — users get explicit agency over an ambient composer-chrome element. Wired through `api/config.py` `_SETTINGS_DEFAULTS`, `static/boot.js`, `static/panels.js` round-trip, `static/ui.js` short-circuit-when-disabled, `static/index.html` Settings field, and 11 locales in `static/i18n.js`. ##### Fixed - **PR [#​2406](nesquena/hermes-webui#2406 by [@​Michaelyklam](https://github.com/Michaelyklam) (fixes [#​2398](nesquena/hermes-webui#2398)) — The fallback synchronous `POST /api/chat` route now passes the active WebUI config into the conversation-history sanitizer, so text-mode providers do not receive historical native `image_url` content parts when direct API callers use the legacy chat endpoint. This brings the sync route in line with the streaming chat path fixed for [#​2297](nesquena/hermes-webui#2297). - **PR [#​2408](nesquena/hermes-webui#2408 by [@​Michaelyklam](https://github.com/Michaelyklam) (fixes [#​2404](nesquena/hermes-webui#2404)) — Auto-compression cards now close the current live Activity burst before rendering, so post-compression tools start a fresh `Activity` row instead of joining the pre-compression tool group across a real timeline/context boundary. Adds a `closeCurrentLiveActivityGroup()` helper that clears the `data-live-activity-current` marker before `appendLiveCompressionCard()` inserts the compression card. Resolves the DEFER from stage-370 Opus advisor review of PR [#​2390](nesquena/hermes-webui#2390). - **PR [#​2411](nesquena/hermes-webui#2411 by [@​Michaelyklam](https://github.com/Michaelyklam) (fixes [#​2405](nesquena/hermes-webui#2405)) — Named `custom:*` providers no longer lose vendor-prefixed model selections when the static model picker has not hydrated that model yet. The frontend now treats named custom providers as routable aggregators for both mismatch-warning suppression and missing-dropdown fallback, and live-fetched models keep explicit `@custom:name:` provider context so selections persist instead of snapping back to the configured default. ##### Documentation - **PR [#​2407](nesquena/hermes-webui#2407 by [@​Michaelyklam](https://github.com/Michaelyklam) — Document the [#​1925](nesquena/hermes-webui#1925) runtime-adapter gate update: Slice 1 run-journal replay has now passed a 100-trial synthetic replay/restart validation pass on current `origin/master`, [#​2313](nesquena/hermes-webui#2313 selected-session chat SSE cap is shipped, and Slice 2 is ready for a reversible adapter-seam planning PR without moving execution ownership yet. ##### Test infrastructure - New regression test `tests/test_quota_chip_settings_toggle.py` (6 cases) pins the quota-chip toggle invariants: Settings field present with i18n labels, `show_quota_chip` default-`False` in `_SETTINGS_DEFAULTS` + `_SETTINGS_BOOL_KEYS`, render/refresh both short-circuit when disabled (no wasted API calls), boot initializes `window._showQuotaChip` from settings + default-false on settings-fetch failure, full panels.js round-trip, 11 locale strings present. ### [`v0.51.78`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05178--2026-05-16--Release-BB-stage-371--stuck-PR-sweep-salvage--RTL-chat--ambient-quota-chip-with-composer-clutter-gate) [Compare Source](nesquena/hermes-webui@v0.51.77...v0.51.78) ##### Added - **PR [#​2409](nesquena/hermes-webui#2409 (maintainer follow-up from 2026-05-16 stuck-PR sweep, co-authored by [@​malulian](https://github.com/malulian) and [@​ai-ag2026](https://github.com/ai-ag2026), closes [#​1721](nesquena/hermes-webui#1721) and [#​2082](nesquena/hermes-webui#2082)) — Two stalled contributor PRs absorbed into one self-built release after Telegram UX approval across mobile/laptop/desktop/wide viewports. - **Right-to-left chat layout (salvaged from [#​1721](nesquena/hermes-webui#1721) by [@​malulian](https://github.com/malulian))** — New Settings → Preferences toggle, default off, flips the chat-area direction for Arabic and Hebrew users. Honors [@​aronprins](https://github.com/aronprins)' design review on PR [#​1721](nesquena/hermes-webui#1721) (May 13 2026): drops the contributor's composer footer toggle button to keep composer real estate clean. Implementation includes a flash-prevention bootstrap `<script>` in `<head>` (applies `chat-content-rtl` class synchronously before any chat content paints), scoped CSS that only flips `.msg-row`, `.msg-body` tables, `.tool-call-group-summary`, and the composer `textarea#msg` — the sidebar, workspace panel, settings panel, and any other UI element stay left-to-right. Code blocks (`pre`, `code`, `kbd`, `samp`, `tt`, `.hljs`, `.code-block`) and tool-call group bodies force `direction:ltr; text-align:left; unicode-bidi:isolate` even under RTL, because Arabic and Hebrew developers still write English code, command lines, and JSON the same way English developers do (visually verified with embedded Python in an Arabic SSE conversation). Localized in 11 locales (en, it, ja, ru, es, de, zh-CN, zh-TW, pt, ko, fr). - **Ambient provider quota chip (overridden from [#​2082](nesquena/hermes-webui#2082) by [@​ai-ag2026](https://github.com/ai-ag2026))** — New green pill chip in the composer footer that surfaces the active provider's remaining quota (OpenRouter credit balance shaped as `$X.YZ`, or account-limit-shaped providers as `N%`), with click-through to Settings → Providers. Fetches `/api/provider/quota` on boot and on tab visibility return. Hidden below 1400px viewport via `@media (max-width:1400px) { display:none !important }` because the composer footer at 1280px laptop and 1440px standard desktop was already tight and the chip squeezed adjacent chips (model picker truncated from `Claude Sonnet 4 7` to `Claude Sonnet 4`, workspace dropdown lost text). Mobile users find quota through the dedicated mobile-config drawer; laptop users follow the chip's click-target into Settings → Providers anyway. The chip's value proposition (ambient quota visibility) is preserved on wide displays where there's genuine composer room without trading off existing chip readability. ##### Test infrastructure - New regression test `tests/test_pr1721_rtl_salvage.py` (8 cases) pins the RTL salvage invariants: Settings field + i18n keys present, no composer footer button (negative assertion encoding [@​aronprins](https://github.com/aronprins)' design objection), bootstrap script runs synchronously in `<head>` before paint, CSS scoped to chat only (negative tests against `.sidebar`, `.settings-panel`, `.workspace-panel`, `html`, `body` rules), code blocks force LTR under RTL, tool-call bodies force LTR under RTL, panels.js load/save round-trip, `rtl` in `api/config.py` DEFAULTS and writable-key allow-list, 11 locale strings present. ### [`v0.51.77`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05177--2026-05-16--Release-BA-stage-370--1-PR-follow-up--live-Activity-grouping-boundary-fix) [Compare Source](nesquena/hermes-webui@v0.51.76...v0.51.77) ##### Fixed - **PR [#​2390](nesquena/hermes-webui#2390 by [@​franksong2702](https://github.com/franksong2702) (refs [#​2376](nesquena/hermes-webui#2376), [#​2344](nesquena/hermes-webui#2344), [#​2347](nesquena/hermes-webui#2347), [#​2377](nesquena/hermes-webui#2377)) — Live progress Activity grouping no longer degrades consecutive tool calls into repeated `Activity: 1 tool` rows. The frontend was using one reset helper for two different jobs — resetting where the next assistant text segment should render, and closing the current live Activity group — but those are not the same operation. Tool starts now only reset the next-text-segment anchor; the live Activity group closes only when the model emits a visible `interim_assistant` progress update (the actual timeline boundary). The flow stays: ```text Thinking card visible progress note Activity: N related tools visible progress note Activity: N related tools final answer ``` Adds a WebUI-only ephemeral progress contract in `api/streaming.py` that asks multi-step tool-heavy turns to emit concise visible progress notes in the user's language, while explicitly forbidding exposure of hidden reasoning, chain-of-thought, scratchpads, secrets, raw logs, or long tool output. Any selected personality prompt is preserved. New regressions cover the progress-contract reach-through, the interim-assistant split boundary, and the consecutive-tools-in-one-Activity-row invariant. ### [`v0.51.76`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05176--2026-05-16--Release-AZ-stage-369--4-PR-safe-lane-batch--live-timeline-preservation--OpenRouter-cost-history--chat-stream-cap--credential-pool-cache) [Compare Source](nesquena/hermes-webui@v0.51.75...v0.51.76) ##### Added - **PR [#​2195](nesquena/hermes-webui#2195 by [@​Michaelyklam](https://github.com/Michaelyklam) (refs [#​692](nesquena/hermes-webui#692)) — OpenRouter cost history backend. New `GET /api/providers/openrouter/cost_history` endpoint backed by daily snapshots from OpenRouter's `/auth/key` cumulative spend. Process-local lock around the snapshot read-modify-write critical section so concurrent dashboard refreshes or multiple tabs cannot overwrite newer reads with stale ones. Delta computation handles cumulative-counter resets (key rotation, OpenRouter-side reset) by starting a fresh series and using the current value as that day's delta rather than emitting negative spend. Backend-only slice; the 7-day daily cost chart UI is a separate follow-up. ##### Fixed - **PR [#​2347](nesquena/hermes-webui#2347 by [@​franksong2702](https://github.com/franksong2702) (fixes [#​2344](nesquena/hermes-webui#2344)) — Preserve live agent timeline across session switches. Previously, switching away from an active stream and returning rebuilt the turn from the persisted `INFLIGHT` tail, which is enough to reconnect the stream but is not a full-fidelity DOM timeline — Thinking/tool grouping flattened, interim assistant text moved away from its surrounding context, auto-compression cards could project twice. The restore path now snapshots the live assistant turn DOM during the active stream and, on return, loads the persisted transcript first then merges the live snapshot back in so the on-screen scene is preserved as the user left it. Stamping `row.dataset.sessionId` at turn creation prevents the new live-turn sites from re-triggering the lossy rebuild path. - **PR [#​2393](nesquena/hermes-webui#2393 by [@​Michaelyklam](https://github.com/Michaelyklam) (refs [#​2313](nesquena/hermes-webui#2313)) — Cap live chat stream transports to the selected conversation. Previously, keeping many sessions open accumulated one long-lived `/api/chat/stream` EventSource per session. New `closeOtherLiveStreams(activeSid)` helper in `static/messages.js`; `attachLiveStream()` now reuses an existing same-session transport first, closes other sessions' chat SSE transports, then opens or replaces the selected session's stream. Background sessions still reattach normally when the user selects them — only the SSE transport is pruned, not the server-side stream ownership. New regression test pins the ordering (reuse first, prune background streams next, replace active transport last). - **PR [#​2396](nesquena/hermes-webui#2396 by [@​starship-s](https://github.com/starship-s) — Preserve session agents for credential pools. The per-session `AIAgent` cache signature previously mixed stable agent identity with the volatile resolved API key, so credential-pool providers (where each request can resolve a different runtime token even when provider/model config is unchanged) missed the cache every turn and rebuilt the agent — losing warmed cross-turn state such as memory-provider prefetch results for providers like Hindsight. New credential-aware cache-signature helper uses a stable sentinel for credential-pool routes while preserving hashed API-key identity for non-pool routes; reused cached agents refresh runtime credentials in place; `AIAgent._primary_runtime` stays aligned after refresh so fallback/transport recovery cannot resurrect an old token; agents still in fallback-active state rebuild rather than mutate to avoid mixed primary/fallback runtime state. Static non-pool API keys still participate in the cache signature so explicit credential changes continue to invalidate. </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEwMS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19--> Reviewed-on: https://git.erwanleboucher.dev/eleboucher/homelab/pulls/528
…del picker by @Michaelyklam (fixes nesquena#2399)
…del picker by @Michaelyklam (fixes nesquena#2399)
Thinking Path
providers.only_configuredis a filtering flag, but the provider-detection loop treated every key underproviders:as a candidate provider id.only-configuredand rendered as fake groups.What Changed
cfg["providers"]detection loop so scalar config flags no longer seeddetected_providers.providers.only_configured: trueand another unknown scalar sibling underproviders:.Why It Matters
Only-Configuredprovider group in the picker.providers.only_configuredas filtering behavior only, not a visible provider.Verification
env -u HERMES_CONFIG_PATH -u HERMES_WEBUI_HOST /home/michael/.hermes/hermes-agent/venv/bin/python -m pytest tests/test_issue2399_provider_config_flags.py tests/test_provider_mismatch.py -q— 65 passed/home/michael/.hermes/hermes-agent/venv/bin/python -m py_compile api/config.pygit diff --checkRisks / Follow-ups
Closes #2399
Model Used
AI-assisted change with repository inspection, targeted editing, and shell-based test verification.