Skip to content

fix: ignore provider config flags in model picker - #2415

Closed
Michaelyklam wants to merge 1 commit into
nesquena:masterfrom
Michaelyklam:fix/issue-2399-provider-config-flag
Closed

Michaelyklam wants to merge 1 commit into
nesquena:masterfrom
Michaelyklam:fix/issue-2399-provider-config-flag

Conversation

@Michaelyklam

Copy link
Copy Markdown
Contributor

Thinking Path

  • The model picker should only list real model providers.
  • providers.only_configured is a filtering flag, but the provider-detection loop treated every key under providers: as a candidate provider id.
  • Because the previous condition accepted the raw key itself, scalar flags could be canonicalized into provider ids such as only-configured and rendered as fake groups.
  • This PR narrows config-driven provider detection to known providers/aliases or dict-shaped provider configs, preserving custom provider config support while excluding scalar flags.

What Changed

  • Filtered the cfg["providers"] detection loop so scalar config flags no longer seed detected_providers.
  • Preserved canonical-to-raw key mapping for known providers and dict-valued provider/custom configs.
  • Added regression coverage for providers.only_configured: true and another unknown scalar sibling under providers:.
  • Added an Unreleased changelog note.

Why It Matters

  • Fixes a confusing fake Only-Configured provider group in the picker.
  • Keeps providers.only_configured as filtering behavior only, not a visible provider.
  • Avoids future scalar provider-level flags accidentally becoming picker groups.

Verification

  • env -u HERMES_CONFIG_PATH -u HERMES_WEBUI_HOST /home/michael/.hermes/hermes-agent/venv/bin/python -m pytest tests/test_issue2399_provider_config_flags.py tests/test_provider_mismatch.py -q — 65 passed
  • /home/michael/.hermes/hermes-agent/venv/bin/python -m py_compile api/config.py
  • git diff --check

Risks / Follow-ups

  • Low-risk backend picker-data change. Known provider ids/aliases and dict-shaped provider configs still seed groups; only scalar unknown provider siblings are ignored.

Closes #2399

Model Used

AI-assisted change with repository inspection, targeted editing, and shell-based test verification.

@Michaelyklam
Michaelyklam force-pushed the fix/issue-2399-provider-config-flag branch from 7ab7921 to 829ac52 Compare May 16, 2026 23:20
@nesquena-hermes
nesquena-hermes force-pushed the fix/issue-2399-provider-config-flag branch from 829ac52 to 9f404c3 Compare May 16, 2026 23:51
@nesquena-hermes

Copy link
Copy Markdown
Collaborator

Maintainer pushed a small fix on top of your branch (force-pushed 9f404c3c).

CI was red on test_issue604_all_providers_model_picker.py::test_cfg_providers_only_adds_known — that test does a windowed grep (1500 chars from the "Also detect providers explicitly listed" anchor) for _PROVIDER_MODELS to confirm the documentation describes the gating. Your new gating logic correctly references _PROVIDER_MODELS, but the in-line comment block pushed the reference 1731 chars from the anchor — 231 chars past the test's window.

The fix is just a comment-block reorganization: I moved the _PROVIDER_MODELS / _PROVIDER_DISPLAY gating description into the top anchor comment (where it's now part of the documented contract that the test asserts on), and shortened the in-loop comment to a back-reference. Distance from anchor to _PROVIDER_MODELS is now 325 chars — comfortably inside the window.

Your Author: Michael Lam is preserved on the commit — I amended only the comment text, not behavior or test files.

Local verification:

  • pytest tests/test_issue604_all_providers_model_picker.py tests/test_issue2399_provider_config_flags.py tests/test_provider_mismatch.py → 78 pass / 0 fail
  • Full suite pytest tests/5796 passed, 6 skipped, 3 xpassed, 8 subtests passed, 0 failed (112s)

If CI on the new commit comes back green (in progress), this is ready for nesquena independent review. Thanks for the careful fix — the gating against _PROVIDER_MODELS / _PROVIDER_DISPLAY / dict-shaped configs is exactly the right shape for #2399.

@nesquena nesquena left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review — end-to-end ✅ (clean APPROVE, no fix pushed)

What this ships

21-line fix in api/config.py to gate the provider-detection loop on either (a) a canonical id that's in _PROVIDER_MODELS / _PROVIDER_DISPLAY or (b) a dict-shaped provider config. Before the fix, the loop accepted EVERY key under providers: because the existing condition _canonical in _cfg_providers or _pid_key in _cfg_providers was always true while iterating _cfg_providers. Scalar siblings like providers.only_configured: true got canonicalized to only-configured and rendered as fake picker groups labeled Only-Configured. Closes #2399.

Surfaces touched: api/config.py (+21/-3), tests/test_issue2399_provider_config_flags.py (+79 new, 2 tests), CHANGELOG.md (+4). 3.11/3.12/3.13 CI green.

Traced against upstream hermes-agent

Pulled a fresh tarball. No cross-tool surface_build_configured_model_badges lives in webui-only api/config.py. The CLI doesn't read these picker groups. No config.yaml shape change.

End-to-end trace

The buggy condition (pre-fix) at api/config.py:2972-2974 (before this PR):

for _pid_key in _cfg_providers:
    _canonical = _canonicalise_provider_id(_pid_key)
    ...
    if _canonical in _PROVIDER_MODELS or _canonical in _cfg_providers or _pid_key in _cfg_providers:
        detected_providers.add(_canonical)

Since we iterate _cfg_providers, the last clause _pid_key in _cfg_providers is always True. So the condition collapses to "always add canonical to detected_providers". Any scalar key under providers: becomes a fake provider group.

Verified canonical mapping of the failure-shape keys:

_canonicalise_provider_id("only_configured") = 'only-configured'   (NOT in _PROVIDER_MODELS)
_canonicalise_provider_id("future_toggle")   = 'future-toggle'     (NOT in _PROVIDER_MODELS)
_canonicalise_provider_id("opencode_go")     = 'opencode-go'       (IS  in _PROVIDER_MODELS)
_canonicalise_provider_id("nous")            = 'nous'              (IS  in _PROVIDER_MODELS)

Pre-fix, all four would have been added. Only the last two should have been.

The new gate at api/config.py:2986-2993:

_is_known_provider = (
    _canonical in _PROVIDER_MODELS or _canonical in _PROVIDER_DISPLAY
)
_is_provider_config = isinstance(_provider_cfg, dict)
if not (_is_known_provider or _is_provider_config):
    continue

OR semantics:

  • Known provider id (canonical or alias) → admit, regardless of value shape.
  • Dict-shaped value → admit, regardless of name (covers custom providers with api_key/base_url/models).
  • Everything else (scalar value with unknown name) → skip.

Iteration shape change

for _pid_key in _cfg_providersfor _pid_key, _provider_cfg in _cfg_providers.items(). Adds value access needed for the isinstance(dict) check. Net-zero for known iteration semantics.

Other audit — things that are correct already

Branch matrix (verified)

_pid_key value canonical known? dict? added?
openai {models: [...]} openai yes yes
openai true openai yes no ✅ (known wins)
opencode_go {api_key: ...} opencode-go yes yes
nous true nous yes no
only_configured true only-configured no no ❌ (skipped — the fix)
future_toggle enabled future-toggle no no
my-llm-server {base_url: ...} my-llm-server no yes ✅ (custom config)
<unknown-flag> false <some> no no

Security

  • No SQL/shell/XSS. Provider id strings come from admin-controlled config.yaml. Even with malicious config (admin self-injection), the output is rendered through the picker's text/title pipeline which escapes via t()/textContent elsewhere. No new attack surface introduced.

Backward compat

  • Existing canonical-to-raw-key dedup (#2245) preserved at api/config.py:2995.
  • Known providers with scalar config (e.g. nous: true, openai: true) still picked up via the _is_known_provider short-circuit. No regression for users who used scalar shorthand.

Test coverage

  • test_providers_only_configured_flag_does_not_create_picker_group pins the reported case + asserts openai is still present (positive control).
  • test_unknown_scalar_provider_config_flags_are_ignored pins the general shape (future_toggle: enabled → not picked up).
  • Both reset _available_models_cache before/after to avoid cross-test pollution.

Edge-case trace

Scenario Expected Actual
providers.only_configured: true + providers.openai: {...} openai shown, only-configured hidden ✅ test
providers.future_toggle: enabled + openai unknown scalar skipped ✅ test
Known provider with true scalar value shown (known wins) ✅ harness trace
Custom provider with dict value shown (dict wins) ✅ harness trace
Empty providers: map no detected providers ✅ skipped iteration
providers: null not a dict → outer guard skips ✅ pre-existing
Cross-tool: CLI reads same config.yaml unaffected (webui-only picker)

Tests

  • PR-targeted: 2/2 pass.
  • Full local suite (Python 3.14): 5675 passed, 0 failed.
  • CI: 3.11/3.12/3.13 all green.

Minor observations (non-blocking)

  1. The pre-fix bug was effectively a no-op condition_pid_key in _cfg_providers was always True. The condition appeared to validate something but did nothing. A linter that flags self-tautologies could have caught this earlier.
  2. _canonicalise_provider_id accepts any string. It normalizes underscores to dashes and lowercases. Combined with the old "always add" path, this produced Only-Configured style display labels (via _canonical.title() somewhere downstream). The new gate is the right shape; the underlying canonicaliser is fine.
  3. Could grow _PROVIDER_DISPLAY allow-list. If future config schema adds new top-level scalar siblings (e.g. providers.retry_count: 3, providers.timeout_ms: 5000), they correctly skip. Good design — opt-in via dict shape rather than maintaining a per-flag denylist.

Recommendation

Approved. Surgical correction of an always-true condition. Gate semantics are clear (known canonical OR dict-shaped). Two regression tests pin both the reported failure case and the broader unknown-scalar shape. No backward compat concerns for users with scalar shorthand on known providers.

✅ Parked at approval — ready for the release agent's merge/tag pipeline.

@nesquena-hermes

Copy link
Copy Markdown
Collaborator

Shipped via stage-373 / PR #2420 / v0.51.80 (Release BD). Attribution preserved in the squashed stage commit and the v0.51.80 CHANGELOG entry. Thank you!

eleboucher pushed a commit to eleboucher/homelab that referenced this pull request May 17, 2026
… 0.51.82) (#528)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/nesquena/hermes-webui](https://github.com/nesquena/hermes-webui) | patch | `0.51.75` → `0.51.82` |

---

### Release Notes

<details>
<summary>nesquena/hermes-webui (ghcr.io/nesquena/hermes-webui)</summary>

### [`v0.51.82`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05182--2026-05-17--Release-BF-stage-375--2-PR-batch--table-renderer-pipe-protection--Catppuccin-appearance-skin)

[Compare Source](nesquena/hermes-webui@v0.51.81...v0.51.82)

##### Added

- **PR [#&#8203;2432](nesquena/hermes-webui#2432 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (closes [#&#8203;2426](nesquena/hermes-webui#2426)) — Add a Catppuccin skin to Appearance settings. The single opt-in skin maps light mode to Catppuccin Latte and dark mode to Catppuccin Mocha, using Mauve as the accent while preserving the existing theme/skin persistence and no-build-step architecture.

##### Fixed

- **PR [#&#8203;2428](nesquena/hermes-webui#2428 by [@&#8203;bengdan](https://github.com/bengdan) — Protect pipes inside parens / brackets / braces from naive `split('|')` in the Markdown table renderer. Cells like `` `(a|b)` ``, `` `Union[int|float]` ``, `` `(a|b|c)` ``, and `` `Union[int|float|str]` `` now stay in a single column instead of mis-splitting. The fix uses an iterative `_protectPipes` loop so all pipes inside one bracket pair are caught, not just the first. Also adds a `$...$` guard so a KaTeX inline-math span straddling `|` column separators is left alone instead of being stashed as math. Stage-fix on the contributor branch (a) swapped the literal `}` glyphs in the regex character classes for `\x7d` hex escapes (semantically identical, but the JS source no longer carries bare close-brace glyphs that confused the brace-counting `extractFunc` in `tests/test_renderer_js_behaviour.py`); (b) dropped a stray apostrophe stop that would have mis-split `('a'|'b')`-style string-literal unions; (c) dropped angle brackets `<` / `>` from the protected-bracket set, after Opus advisor flagged that `| x < 5 | y > 10 |` would otherwise collapse into a single cell (comparison-operator usage dominates content-grouping usage in real LLM table output); and (d) added `tests/test_issue2428_table_pipe_protection.py` with 12 regression cases covering single-pipe, multi-pipe-in-brackets, apostrophes-with-pipes, the KaTeX-in-table guard, and the angle-bracket comparison-operator case.

### [`v0.51.81`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05181--2026-05-17--Release-BE-stage-374--6-PR-batch--cost-history-POSIX-lock--prompt-cache-tokens--Plugins-panel-i18n--pending-placeholder-chat--journal-replay-partial-recovery--default-off-RuntimeAdapter-Slice-2-seam)

[Compare Source](nesquena/hermes-webui@v0.51.80...v0.51.81)

##### Added

- **PR [#&#8203;2424](nesquena/hermes-webui#2424 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (refs [#&#8203;1925](nesquena/hermes-webui#1925)) — Add the default-off `RuntimeAdapter` Slice 2 seam. `HERMES_WEBUI_RUNTIME_ADAPTER=legacy-journal` now routes chat start through a `LegacyJournalRuntimeAdapter` facade over the existing legacy streaming path, while the default remains `legacy-direct`. The new adapter interface/payload classes expose start/observe/status/cancel/approval/clarify methods and delegate controls to existing handlers without introducing a runner, sidecar, new process-local queues, cached agents, cancellation registries, or callback registries.
- **PR [#&#8203;2421](nesquena/hermes-webui#2421 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (fixes [#&#8203;2419](nesquena/hermes-webui#2419)) — Surface provider prompt-cache read/write tokens in WebUI usage displays. Cache-miss cost issues are now visible in the context tooltip and per-turn usage footer; counters carry through session persistence, SSE usage payloads, and live snapshots so deltas remain accurate across the active turn.
- **PR [#&#8203;2425](nesquena/hermes-webui#2425 by [@&#8203;mccxj](https://github.com/mccxj) — Wire Settings → Plugins panel into the existing i18n system. Panel title, description, empty state, and per-plugin labels (hooks, enabled/disabled, load failures) now respect the user's language preference; 10 new keys ship in English with `TODO: translate` placeholders in 9 additional locales.

##### Fixed

- **PR [#&#8203;2418](nesquena/hermes-webui#2418 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (fixes [#&#8203;2402](nesquena/hermes-webui#2402)) — OpenRouter cost-history snapshot updates now take a provider-specific POSIX file lock around the read-modify-write cycle, preserving the existing process-local lock while preventing lost snapshot updates if WebUI is deployed with multiple worker processes sharing one Hermes home/state directory.
- **PR [#&#8203;2431](nesquena/hermes-webui#2431 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (fixes [#&#8203;2429](nesquena/hermes-webui#2429)) — Chat sends now render the assistant-side pending `Thinking…` placeholder immediately after the user turn is echoed, before `/api/chat/start` returns a stream id or the first SSE event arrives. The existing stale-stream guard remains in place for ordinary reasoning updates — only the explicit pre-stream placeholder path is allowed through.
- **PR [#&#8203;2427](nesquena/hermes-webui#2427 by [@&#8203;franksong2702](https://github.com/franksong2702) (fixes [#&#8203;2423](nesquena/hermes-webui#2423)) — Recover already-journaled visible assistant text and tool cards when a WebUI process restart interrupts an in-flight browser-originated turn. The stale-stream repair path now materializes run-journal output before the explicit interrupted marker instead of collapsing the turn to "no agent output was recovered."

##### Documentation

- **PR [#&#8203;2416](nesquena/hermes-webui#2416 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (refs [#&#8203;1925](nesquena/hermes-webui#1925)) — Expand the runtime-adapter RFC with the concrete Slice 2 adapter-seam contract: minimal `RuntimeAdapter` methods, payload fields, `legacy-direct` / `legacy-journal` feature-flag rollback path, legacy-backend mapping, explicit non-goals, and adapter-seam acceptance tests. Keeps the next step scoped to a reversible protocol-translator boundary over the journaled legacy path, not a runner/sidecar or execution-ownership move.

### [`v0.51.80`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05180--2026-05-17--Release-BD-stage-373--2-PR-batch--provider-config-flag-filter--stale-compaction-greeting-heuristic)

[Compare Source](nesquena/hermes-webui@v0.51.79...v0.51.80)

##### Fixed

- **PR [#&#8203;2415](nesquena/hermes-webui#2415 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (fixes [#&#8203;2399](nesquena/hermes-webui#2399)) — `providers.only_configured` and other scalar flags under the top-level `providers:` config mapping no longer appear as fake provider groups in the model picker. Provider detection now only seeds picker groups from known provider ids/aliases or dict-shaped provider configs, so filtering flags cannot render as `Only-Configured`. The gating contract is documented inline in `api/config.py` (within the existing `_PROVIDER_MODELS`/`_PROVIDER_DISPLAY` membership block) so the test\_issue604 source-scan stays satisfied.
- **PR [#&#8203;2417](nesquena/hermes-webui#2417 by [@&#8203;nesquena-hermes](https://github.com/nesquena-hermes) (co-authored by [@&#8203;franksong2702](https://github.com/franksong2702), supersedes [#&#8203;2309](nesquena/hermes-webui#2309), closes [#&#8203;2308](nesquena/hermes-webui#2308)) — Compressed sessions with hidden "resume active task" context no longer treat a short fresh greeting (`hi`, `hello`, plus 6 CJK greetings) as implicit permission to continue an old agent task. Explicit continuation prompts (`continue`, `resume`, plus 4 CJK continuation phrases) still keep the compacted task context. The new helpers (`_normalize_fresh_chat_text`, `_is_casual_fresh_chat_message`, `_has_task_resume_compaction_marker`, `_context_messages_for_new_turn`) require BOTH the compaction phrase AND a task-resume keyword in the SAME message before treating it as a stale-task marker (precision-preserving guard). Length cap of 24 chars + workspace-prefix normalization + exact greeting-set match prevent false positives. CJK greetings/continuation terms are stored as Python `\u`-escape sequences so `api/streaming.py` passes the `test_title_sanitization::test_title_generation_source_has_no_cjk_literals` English-only-source invariant; runtime values are unchanged. Stage-372 Opus advisor pass caught two CJK codepoint typos (`嘖→嗨`, `哈喂→哈喽`) in the maintainer rebase and corrected them; new regression test `test_all_cjk_greetings_drop_stale_compaction_context` pins all 6 CJK greetings against future codepoint drift with `U+XXXX` failure messages.

### [`v0.51.79`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05179--2026-05-16--Release-BC-stage-372--5-PR-batch--text-mode-image-history-fix--Activity-group-compression-boundary--named-custom-provider-routing--quota-chip-Settings-toggle--RFC-docs)

[Compare Source](nesquena/hermes-webui@v0.51.78...v0.51.79)

##### Added

- **PR [#&#8203;2413](nesquena/hermes-webui#2413 (self-built follow-up to v0.51.78's [#&#8203;2082](nesquena/hermes-webui#2082), closes the quota-chip default-on regression) — New "Show provider quota chip in composer" checkbox in Settings → Preferences, default off. When disabled (the new default), the chip is hidden at all viewports and the `/api/provider/quota` fetch is skipped entirely. When enabled, the existing `@media (max-width:1399.98px)` gate from stage-371 still restricts the chip to wide desktops only. Per Nathan's directive 2026-05-16 immediately after stage-371 shipped — users get explicit agency over an ambient composer-chrome element. Wired through `api/config.py` `_SETTINGS_DEFAULTS`, `static/boot.js`, `static/panels.js` round-trip, `static/ui.js` short-circuit-when-disabled, `static/index.html` Settings field, and 11 locales in `static/i18n.js`.

##### Fixed

- **PR [#&#8203;2406](nesquena/hermes-webui#2406 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (fixes [#&#8203;2398](nesquena/hermes-webui#2398)) — The fallback synchronous `POST /api/chat` route now passes the active WebUI config into the conversation-history sanitizer, so text-mode providers do not receive historical native `image_url` content parts when direct API callers use the legacy chat endpoint. This brings the sync route in line with the streaming chat path fixed for [#&#8203;2297](nesquena/hermes-webui#2297).
- **PR [#&#8203;2408](nesquena/hermes-webui#2408 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (fixes [#&#8203;2404](nesquena/hermes-webui#2404)) — Auto-compression cards now close the current live Activity burst before rendering, so post-compression tools start a fresh `Activity` row instead of joining the pre-compression tool group across a real timeline/context boundary. Adds a `closeCurrentLiveActivityGroup()` helper that clears the `data-live-activity-current` marker before `appendLiveCompressionCard()` inserts the compression card. Resolves the DEFER from stage-370 Opus advisor review of PR [#&#8203;2390](nesquena/hermes-webui#2390).
- **PR [#&#8203;2411](nesquena/hermes-webui#2411 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (fixes [#&#8203;2405](nesquena/hermes-webui#2405)) — Named `custom:*` providers no longer lose vendor-prefixed model selections when the static model picker has not hydrated that model yet. The frontend now treats named custom providers as routable aggregators for both mismatch-warning suppression and missing-dropdown fallback, and live-fetched models keep explicit `@custom:name:` provider context so selections persist instead of snapping back to the configured default.

##### Documentation

- **PR [#&#8203;2407](nesquena/hermes-webui#2407 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) — Document the [#&#8203;1925](nesquena/hermes-webui#1925) runtime-adapter gate update: Slice 1 run-journal replay has now passed a 100-trial synthetic replay/restart validation pass on current `origin/master`, [#&#8203;2313](nesquena/hermes-webui#2313 selected-session chat SSE cap is shipped, and Slice 2 is ready for a reversible adapter-seam planning PR without moving execution ownership yet.

##### Test infrastructure

- New regression test `tests/test_quota_chip_settings_toggle.py` (6 cases) pins the quota-chip toggle invariants: Settings field present with i18n labels, `show_quota_chip` default-`False` in `_SETTINGS_DEFAULTS` + `_SETTINGS_BOOL_KEYS`, render/refresh both short-circuit when disabled (no wasted API calls), boot initializes `window._showQuotaChip` from settings + default-false on settings-fetch failure, full panels.js round-trip, 11 locale strings present.

### [`v0.51.78`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05178--2026-05-16--Release-BB-stage-371--stuck-PR-sweep-salvage--RTL-chat--ambient-quota-chip-with-composer-clutter-gate)

[Compare Source](nesquena/hermes-webui@v0.51.77...v0.51.78)

##### Added

- **PR [#&#8203;2409](nesquena/hermes-webui#2409 (maintainer follow-up from 2026-05-16 stuck-PR sweep, co-authored by [@&#8203;malulian](https://github.com/malulian) and [@&#8203;ai-ag2026](https://github.com/ai-ag2026), closes [#&#8203;1721](nesquena/hermes-webui#1721) and [#&#8203;2082](nesquena/hermes-webui#2082)) — Two stalled contributor PRs absorbed into one self-built release after Telegram UX approval across mobile/laptop/desktop/wide viewports.
  - **Right-to-left chat layout (salvaged from [#&#8203;1721](nesquena/hermes-webui#1721) by [@&#8203;malulian](https://github.com/malulian))** — New Settings → Preferences toggle, default off, flips the chat-area direction for Arabic and Hebrew users. Honors [@&#8203;aronprins](https://github.com/aronprins)' design review on PR [#&#8203;1721](nesquena/hermes-webui#1721) (May 13 2026): drops the contributor's composer footer toggle button to keep composer real estate clean. Implementation includes a flash-prevention bootstrap `<script>` in `<head>` (applies `chat-content-rtl` class synchronously before any chat content paints), scoped CSS that only flips `.msg-row`, `.msg-body` tables, `.tool-call-group-summary`, and the composer `textarea#msg` — the sidebar, workspace panel, settings panel, and any other UI element stay left-to-right. Code blocks (`pre`, `code`, `kbd`, `samp`, `tt`, `.hljs`, `.code-block`) and tool-call group bodies force `direction:ltr; text-align:left; unicode-bidi:isolate` even under RTL, because Arabic and Hebrew developers still write English code, command lines, and JSON the same way English developers do (visually verified with embedded Python in an Arabic SSE conversation). Localized in 11 locales (en, it, ja, ru, es, de, zh-CN, zh-TW, pt, ko, fr).
  - **Ambient provider quota chip (overridden from [#&#8203;2082](nesquena/hermes-webui#2082) by [@&#8203;ai-ag2026](https://github.com/ai-ag2026))** — New green pill chip in the composer footer that surfaces the active provider's remaining quota (OpenRouter credit balance shaped as `$X.YZ`, or account-limit-shaped providers as `N%`), with click-through to Settings → Providers. Fetches `/api/provider/quota` on boot and on tab visibility return. Hidden below 1400px viewport via `@media (max-width:1400px) { display:none !important }` because the composer footer at 1280px laptop and 1440px standard desktop was already tight and the chip squeezed adjacent chips (model picker truncated from `Claude Sonnet 4 7` to `Claude Sonnet 4`, workspace dropdown lost text). Mobile users find quota through the dedicated mobile-config drawer; laptop users follow the chip's click-target into Settings → Providers anyway. The chip's value proposition (ambient quota visibility) is preserved on wide displays where there's genuine composer room without trading off existing chip readability.

##### Test infrastructure

- New regression test `tests/test_pr1721_rtl_salvage.py` (8 cases) pins the RTL salvage invariants: Settings field + i18n keys present, no composer footer button (negative assertion encoding [@&#8203;aronprins](https://github.com/aronprins)' design objection), bootstrap script runs synchronously in `<head>` before paint, CSS scoped to chat only (negative tests against `.sidebar`, `.settings-panel`, `.workspace-panel`, `html`, `body` rules), code blocks force LTR under RTL, tool-call bodies force LTR under RTL, panels.js load/save round-trip, `rtl` in `api/config.py` DEFAULTS and writable-key allow-list, 11 locale strings present.

### [`v0.51.77`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05177--2026-05-16--Release-BA-stage-370--1-PR-follow-up--live-Activity-grouping-boundary-fix)

[Compare Source](nesquena/hermes-webui@v0.51.76...v0.51.77)

##### Fixed

- **PR [#&#8203;2390](nesquena/hermes-webui#2390 by [@&#8203;franksong2702](https://github.com/franksong2702) (refs [#&#8203;2376](nesquena/hermes-webui#2376), [#&#8203;2344](nesquena/hermes-webui#2344), [#&#8203;2347](nesquena/hermes-webui#2347), [#&#8203;2377](nesquena/hermes-webui#2377)) — Live progress Activity grouping no longer degrades consecutive tool calls into repeated `Activity: 1 tool` rows. The frontend was using one reset helper for two different jobs — resetting where the next assistant text segment should render, and closing the current live Activity group — but those are not the same operation. Tool starts now only reset the next-text-segment anchor; the live Activity group closes only when the model emits a visible `interim_assistant` progress update (the actual timeline boundary). The flow stays:

  ```text
  Thinking card
  visible progress note
  Activity: N related tools
  visible progress note
  Activity: N related tools
  final answer
  ```

  Adds a WebUI-only ephemeral progress contract in `api/streaming.py` that asks multi-step tool-heavy turns to emit concise visible progress notes in the user's language, while explicitly forbidding exposure of hidden reasoning, chain-of-thought, scratchpads, secrets, raw logs, or long tool output. Any selected personality prompt is preserved. New regressions cover the progress-contract reach-through, the interim-assistant split boundary, and the consecutive-tools-in-one-Activity-row invariant.

### [`v0.51.76`](https://github.com/nesquena/hermes-webui/blob/HEAD/CHANGELOG.md#v05176--2026-05-16--Release-AZ-stage-369--4-PR-safe-lane-batch--live-timeline-preservation--OpenRouter-cost-history--chat-stream-cap--credential-pool-cache)

[Compare Source](nesquena/hermes-webui@v0.51.75...v0.51.76)

##### Added

- **PR [#&#8203;2195](nesquena/hermes-webui#2195 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (refs [#&#8203;692](nesquena/hermes-webui#692)) — OpenRouter cost history backend. New `GET /api/providers/openrouter/cost_history` endpoint backed by daily snapshots from OpenRouter's `/auth/key` cumulative spend. Process-local lock around the snapshot read-modify-write critical section so concurrent dashboard refreshes or multiple tabs cannot overwrite newer reads with stale ones. Delta computation handles cumulative-counter resets (key rotation, OpenRouter-side reset) by starting a fresh series and using the current value as that day's delta rather than emitting negative spend. Backend-only slice; the 7-day daily cost chart UI is a separate follow-up.

##### Fixed

- **PR [#&#8203;2347](nesquena/hermes-webui#2347 by [@&#8203;franksong2702](https://github.com/franksong2702) (fixes [#&#8203;2344](nesquena/hermes-webui#2344)) — Preserve live agent timeline across session switches. Previously, switching away from an active stream and returning rebuilt the turn from the persisted `INFLIGHT` tail, which is enough to reconnect the stream but is not a full-fidelity DOM timeline — Thinking/tool grouping flattened, interim assistant text moved away from its surrounding context, auto-compression cards could project twice. The restore path now snapshots the live assistant turn DOM during the active stream and, on return, loads the persisted transcript first then merges the live snapshot back in so the on-screen scene is preserved as the user left it. Stamping `row.dataset.sessionId` at turn creation prevents the new live-turn sites from re-triggering the lossy rebuild path.

- **PR [#&#8203;2393](nesquena/hermes-webui#2393 by [@&#8203;Michaelyklam](https://github.com/Michaelyklam) (refs [#&#8203;2313](nesquena/hermes-webui#2313)) — Cap live chat stream transports to the selected conversation. Previously, keeping many sessions open accumulated one long-lived `/api/chat/stream` EventSource per session. New `closeOtherLiveStreams(activeSid)` helper in `static/messages.js`; `attachLiveStream()` now reuses an existing same-session transport first, closes other sessions' chat SSE transports, then opens or replaces the selected session's stream. Background sessions still reattach normally when the user selects them — only the SSE transport is pruned, not the server-side stream ownership. New regression test pins the ordering (reuse first, prune background streams next, replace active transport last).

- **PR [#&#8203;2396](nesquena/hermes-webui#2396 by [@&#8203;starship-s](https://github.com/starship-s) — Preserve session agents for credential pools. The per-session `AIAgent` cache signature previously mixed stable agent identity with the volatile resolved API key, so credential-pool providers (where each request can resolve a different runtime token even when provider/model config is unchanged) missed the cache every turn and rebuilt the agent — losing warmed cross-turn state such as memory-provider prefetch results for providers like Hindsight. New credential-aware cache-signature helper uses a stable sentinel for credential-pool routes while preserving hashed API-key identity for non-pool routes; reused cached agents refresh runtime credentials in place; `AIAgent._primary_runtime` stays aligned after refresh so fallback/transport recovery cannot resurrect an old token; agents still in fallback-active state rebuild rather than mutate to avoid mixed primary/fallback runtime state. Static non-pool API keys still participate in the cache signature so explicit credential changes continue to invalidate.

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEwMS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->

Reviewed-on: https://git.erwanleboucher.dev/eleboucher/homelab/pulls/528
SysAdminDoc pushed a commit to SysAdminDoc/hermes-webui that referenced this pull request Jun 26, 2026
bernyforce pushed a commit to bernyforce/hermes-webui that referenced this pull request Jul 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: providers.only_configured appears as a provider in the model picker

3 participants