Compare commits

..
5 Commits
Author SHA1 Message Date
bruno 23a3c147cd fix(editor): le bouton Sauvegarder ne reste plus bloque sur le spinner (BUG-054)
CI / lint (push) Successful in 1m45s
CI / security (push) Successful in 1m1s
CI / test (push) Successful in 2m55s
CI / build (push) Successful in 57s
CI / e2e (push) Successful in 10m48s
2026-09-17 08:00:13 -04:00
bruno f02174af57 fix(ai): mode agent utilise les outils natifs au lieu du bloc obsigate-action (BUG-053)
CI / lint (push) Successful in 1m33s
CI / security (push) Successful in 1m0s
CI / test (push) Successful in 2m57s
CI / build (push) Successful in 56s
CI / e2e (push) Successful in 10m48s
2026-09-17 07:30:31 -04:00
bruno e3434d19ea fix(ai): garantir une reponse finale quand la boucle d'agent epuise son budget (BUG-052)
CI / lint (push) Successful in 1m31s
CI / security (push) Successful in 1m2s
CI / test (push) Successful in 3m25s
CI / build (push) Successful in 56s
CI / e2e (push) Successful in 10m41s
2026-09-16 23:28:56 -04:00
bruno 62cff271d8 fix(ai): entetes navigateur pour le repli web_search (Bing/DDG, BUG-051)
CI / lint (push) Successful in 1m39s
CI / security (push) Successful in 1m0s
CI / test (push) Successful in 2m9s
CI / build (push) Successful in 56s
CI / e2e (push) Successful in 11m9s
2026-09-16 23:17:27 -04:00
bruno 56b46cde0e fix(ai): chaine de repli web_search (SearXNG -> DuckDuckGo -> Bing, BUG-051)
CI / lint (push) Successful in 1m32s
CI / security (push) Successful in 1m0s
CI / test (push) Successful in 3m8s
CI / build (push) Successful in 56s
CI / e2e (push) Successful in 10m44s
2026-09-16 23:13:44 -04:00
23 changed files with 701 additions and 97 deletions
+7
View File
@@ -67,3 +67,10 @@ DEEPSEEK_MODEL=deepseek-chat
# Google Gemini
# GEMINI_API_KEY=AIza...
# GEMINI_MODEL=gemini-2.0-flash
# ── Assistant IA — recherche web (outil web_search) ──
# Instance SearXNG auto-hébergée (aucune clé API requise)
# OBSIGATE_SEARXNG_URL=https://search.dracodev.net
# Chaîne de repli sans clé (DuckDuckGo puis Bing) si SearXNG ne remonte rien
# OBSIGATE_WEB_FALLBACK=1
# OBSIGATE_WEB_TIMEOUT=10
+80 -1
View File
@@ -6,7 +6,7 @@ Format basé sur [Keep a Changelog](https://keepachangelog.com/fr/1.1.0/),
et [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
> **En cours de développement** : les changements à venir sont listés dans la section
> [Unreleased](#unreleased). La dernière version livrée est **2.7.0**.
> [Unreleased](#unreleased). La dernière version livrée est **2.7.5**.
---
@@ -14,6 +14,85 @@ et [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
---
## [2.7.5] — 2026-09-17
### Corrigé
- **BUG-054 - Éditeur « Editer » : le bouton Sauvegarder restait bloqué sur le spinner de
chargement** : le bouton `#editor-save` est un nœud DOM partagé entre toutes les sessions
d'édition (y compris en mode en ligne). Une sauvegarde manuelle y remplaçait le crochet par un
spinner et le désactivait, mais cet état n'était jamais remis à zéro : après une sauvegarde
réussie (l'éditeur se ferme puis se rouvre), après une sauvegarde Forge, ou après un échec de
requête (le `catch` ne restaurait ni l'icône ni l'état), le spinner persistait jusqu'à un
rechargement complet de la page. Un helper `resetSaveButton()` restaure désormais le crochet
et réactive le bouton à l'ouverture (`openEditor`), à la fermeture (`closeEditor`) et en cas
d'échec (`saveFile`). Fichier : `frontend/js/utils.js`. Tests :
`tests/frontend/editor-inline.test.mjs` (+4).
---
## [2.7.4] — 2026-09-17
### Corrigé
- **BUG-053 - Assistant IA (mode agent) : le fichier demandé n'est pas créé** : le prompt
système du mode Général (et du dossier vide) enseignait encore le **protocole texte**
`obsigate-action`, si bien que le modèle décrivait l'action dans un bloc texte au lieu
d'appeler l'outil natif `create_file` — rien n'était donc créé (et le bloc, volumineux,
était tronqué avant sa fermeture). En mode agent, le prompt demande désormais d'appeler
directement les outils natifs (`create_file`, `create_directory`, …) et interdit les blocs
`obsigate-action` ; le chat classique conserve le protocole texte. La limite de sortie de
l'agent passe à 8 192 jetons pour laisser place au contenu complet d'un fichier.
Fichiers : `backend/bookslm.py`, `backend/bookslm_routes.py`. Tests : `tests/test_bookslm.py` (+3).
---
## [2.7.3] — 2026-09-16
### Corrigé
- **BUG-052 - Assistant IA : recherche web sans réponse finale (étapes et sources affichées, aucun texte)** :
quand le budget d'itérations (`DEFAULT_MAX_ITERATIONS = 10`) ou le quota d'appels d'outils
était épuisé pendant que le modèle enchaînait encore des recherches/lectures, la boucle
d'agent renvoyait un contenu vide → la conversation n'affichait que les étapes et les
sources. La boucle effectue désormais un **dernier appel sans outil** qui demande au modèle
de synthétiser les informations recueillies (`_finalize_answer`), avec un repli déterministe
listant les sources si cet appel échoue ou reste vide. Les appels d'outils non atteints du
lot en cours de quota reçoivent un résultat `deferred` pour garder la conversation valide.
Fichier : `backend/agent/loop.py`. Tests : `tests/test_agent_loop.py` (+2).
---
## [2.7.2] — 2026-09-16
### Corrigé
- **BUG-051 (complément) - Repli Bing : en-têtes de navigation navigateur** : un `User-Agent`
navigateur seul ne suffit pas — Bing renvoie des résultats factices (SERP sans rapport avec
la requête) aux appels dépourvus des en-têtes de navigation habituels. Les fournisseurs HTML
(DuckDuckGo, Bing) envoient désormais `Accept-Language`, `Sec-Fetch-*` et
`Upgrade-Insecure-Requests` (`BROWSER_HEADERS`). Vérifié en conteneur : recherche
« Canadien de Montréal 2026-2027 » → résultats NHL / RDS / Wikipédia pertinents
(`provider: bing`). Fichier : `backend/tools/web.py`.
---
## [2.7.1] — 2026-09-16
### Corrigé
- **BUG-051 - Assistant IA : « je ne peux pas accéder à internet » malgré la recherche web** :
lorsque l'instance SearXNG auto-hébergée ne remontait aucun résultat (moteurs amont
suspendus/CAPTCHA), `web_search` renvoyait une liste vide et le modèle concluait à une
absence d'accès réseau. L'outil essaie désormais une **chaîne de repli sans clé** —
SearXNG, puis DuckDuckGo (endpoint HTML sans JS), puis Bing (page de résultats HTML) —
et ne s'arrête qu'au premier fournisseur qui renvoie des résultats (`provider` dans le
résultat, `OBSIGATE_WEB_FALLBACK=0` pour désactiver les replis). Le message d'avertissement
final nomme les fournisseurs essayés. Fichier : `backend/tools/web.py`. Tests :
`tests/test_web_tools.py` (+4).
---
## [2.7.0] — 2026-09-16
### Ajouté
+3 -3
View File
@@ -4,7 +4,7 @@
**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.
[![Version](https://img.shields.io/badge/Version-2.7.0-blue.svg)]()
[![Version](https://img.shields.io/badge/Version-2.7.5-blue.svg)]()
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Docker](https://img.shields.io/badge/Docker-Ready-blue.svg)](https://www.docker.com/)
[![Python](https://img.shields.io/badge/Python-3.11+-green.svg)](https://www.python.org/)
@@ -916,8 +916,8 @@ Ce projet est sous licence **MIT** — voir le fichier [LICENSE](LICENSE) pour l
## 📝 Changelog
Consultez le [CHANGELOG.md](./CHANGELOG.md) pour l'historique complet de toutes les versions (v1.0.0 → v2.7.0).
Consultez le [CHANGELOG.md](./CHANGELOG.md) pour l'historique complet de toutes les versions (v1.0.0 → v2.7.5).
---
*Projet : ObsiGate | Version : 2.7.0 | Dernière mise à jour : Juin 2026*
*Projet : ObsiGate | Version : 2.7.5 | Dernière mise à jour : Juin 2026*
+3 -3
View File
@@ -2,7 +2,7 @@
**Ultra-light web gateway for your Obsidian vaults** — Access, browse, and search all your Obsidian notes from any device via a modern, responsive web interface.
[![Version](https://img.shields.io/badge/Version-2.7.0-blue.svg)]()
[![Version](https://img.shields.io/badge/Version-2.7.5-blue.svg)]()
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)
[![Docker](https://img.shields.io/badge/Docker-Ready-blue.svg)](https://www.docker.com/)
[![Python](https://img.shields.io/badge/Python-3.11+-green.svg)](https://www.python.org/)
@@ -1085,8 +1085,8 @@ This project is licensed under the **MIT License** - see the [LICENSE](LICENSE)
## 📝 Changelog
See [CHANGELOG.md](./CHANGELOG.md) for the complete version history (v1.0.0 → v2.7.0).
See [CHANGELOG.md](./CHANGELOG.md) for the complete version history (v1.0.0 → v2.7.5).
---
*Project: ObsiGate | Version: 2.7.0 | Last updated: May 2026*
*Project: ObsiGate | Version: 2.7.5 | Last updated: May 2026*
+1 -1
View File
@@ -1 +1 @@
2.7.0
2.7.5
+85 -17
View File
@@ -40,6 +40,15 @@ MAX_TOOL_RESULT_CHARS = 100_000
# Quota: maximum tool calls executed per agent run (``BOOKSLM_MAX_TOOL_CALLS``).
DEFAULT_MAX_TOOL_CALLS = int(os.environ.get("BOOKSLM_MAX_TOOL_CALLS", "25"))
# Sent as a last user turn when the loop stopped before the model produced an
# answer (iteration/quota budget exhausted while it was still calling tools).
_FINALIZE_INSTRUCTION = (
"N'appelle plus aucun outil. Réponds maintenant directement à l'utilisateur, "
"en français, à partir des informations déjà recueillies ci-dessus. "
"Structure la réponse en Markdown, cite les liens sources utiles, et si les "
"informations sont insuffisantes, dis-le explicitement."
)
# Stopping reasons
STOP_DONE = "done"
STOP_MAX_ITERATIONS = "max_iterations"
@@ -109,8 +118,8 @@ def _assistant_tool_message(content: str | None, tool_calls: list[Any]) -> dict[
}
def _deferred_tool_message(call: Any) -> dict[str, Any]:
"""Answer a tool call that was not reached because the run paused.
def _deferred_tool_message(call: Any, reason: str | None = None) -> dict[str, Any]:
"""Answer a tool call that was not reached because the run stopped early.
A single LLM response may carry several tool calls. When one of them is
mutating and pauses the run for confirmation, the assistant message already
@@ -125,7 +134,7 @@ def _deferred_tool_message(call: Any) -> dict[str, Any]:
"name": call.name,
"content": json.dumps({
"status": "deferred",
"reason": (
"reason": reason or (
"Not executed: the run paused to confirm an earlier tool call. "
"Re-issue this call if it is still needed."
),
@@ -133,6 +142,69 @@ def _deferred_tool_message(call: Any) -> dict[str, Any]:
}
def _fallback_summary(executed: list[ToolCallRecord]) -> str:
"""Deterministic non-empty answer built from the gathered tool results.
Used only if the final synthesis call fails or returns nothing, so a turn
never ends on an empty message (BUG-052).
"""
lines: list[str] = []
for record in executed:
data = record.result
if not isinstance(data, dict):
continue
for item in (data.get("results") or [])[:5]:
if not isinstance(item, dict):
continue
title = item.get("title") or item.get("url") or ""
url = item.get("url") or ""
lines.append(f"- [{title}]({url})" if url else f"- {title}")
if data.get("url") and data.get("text"):
title = data.get("title") or data["url"]
lines.append(f"- [{title}]({data['url']})")
if not lines:
return "Je n'ai pas pu produire de réponse à partir des résultats obtenus."
unique = list(dict.fromkeys(lines))
return "Voici les sources pertinentes trouvées :\n" + "\n".join(unique)
async def _finalize_answer(
llm: Callable[..., Any],
convo: list[dict[str, Any]],
executed: list[ToolCallRecord],
steps: list[dict[str, Any]],
iterations: int,
stopped: str,
) -> AgentResult:
"""Guarantee a textual answer when the loop stopped before producing one.
Web research often exhausts the iteration budget while the model is still
calling tools; returning ``content=""`` left the conversation with steps and
sources but no answer. One final tool-less call asks the model to synthesize
the gathered results, and a deterministic source list is used as a last
resort (BUG-052).
"""
content = ""
if executed:
try:
response = await llm(
[*convo, {"role": "user", "content": _FINALIZE_INSTRUCTION}], []
)
content = (response.content or "").strip()
except Exception as e:
logger.warning(f"Agent final synthesis failed: {e}")
if not content:
content = _fallback_summary(executed)
return AgentResult(
content=content,
messages=convo,
tool_calls=executed,
steps=steps,
iterations=iterations,
stopped=stopped,
)
def _execute_confirmed(
ctx: ToolContext,
confirm_pending: dict[str, Any],
@@ -275,13 +347,14 @@ async def run_agent(
for index, call in enumerate(response.tool_calls):
if quota is not None and len(executed) >= quota:
logger.warning(f"Agent reached the tool-call quota ({quota})")
return AgentResult(
content=response.content or "",
messages=convo,
tool_calls=executed,
steps=steps,
iterations=iteration,
stopped=STOP_QUOTA_EXCEEDED,
# Keep the conversation valid for the synthesis call: the
# assistant message announced every tool call of the batch.
for skipped in response.tool_calls[index:]:
convo.append(_deferred_tool_message(
skipped, "Not executed: the tool-call quota was reached."
))
return await _finalize_answer(
llm, convo, executed, steps, iteration, STOP_QUOTA_EXCEEDED
)
try:
result = call_tool(call.name, ctx, call.arguments)
@@ -327,11 +400,6 @@ async def run_agent(
})
logger.warning(f"Agent reached max iterations ({max_iterations})")
return AgentResult(
content="",
messages=convo,
tool_calls=executed,
steps=steps,
iterations=max_iterations,
stopped=STOP_MAX_ITERATIONS,
return await _finalize_answer(
llm, convo, executed, steps, max_iterations, STOP_MAX_ITERATIONS
)
+32 -2
View File
@@ -486,12 +486,17 @@ def build_system_prompt(context: dict[str, Any], scope: str = "directory", vault
return prompt
GENERAL_SYSTEM_PROMPT = """Tu es l'assistant intégré d'ObsiGate, une application web auto-hébergée pour consulter, rechercher et éditer des vaults Obsidian (Markdown).
GENERAL_SYSTEM_HEADER = """Tu es l'assistant intégré d'ObsiGate, une application web auto-hébergée pour consulter, rechercher et éditer des vaults Obsidian (Markdown).
Tes deux rôles :
1. **Aider sur l'application** : expliquer la navigation, la recherche (full-text, filtres `tag:`, `created:`, `path:`), l'éditeur (CodeMirror, autosave, raccourcis), les onglets et le split view, les sauvegardes et la restauration, le partage public, l'export (HTML/Markdown/ePub/PDF), Mermaid, Excalidraw, les plugins, les thèmes, le mode hors-ligne, le MFA, etc.
2. **Proposer des actions concrètes** : créer un fichier ou un dossier dans un vault.
"""
# Text action protocol — used by the classic (non-agent) chat endpoint, where
# the model has no native tool calling; the frontend turns each block into a
# clickable “Apply” card.
GENERAL_ACTION_TEXT_PROTOCOL = """
Quand l'utilisateur demande explicitement de créer un fichier, inclus un bloc de ce type dans ta réponse (un bloc par fichier, et rien d'autre à l'intérieur du bloc) :
```obsigate-action
@@ -513,6 +518,25 @@ Règles :
- Réponds dans la langue de l'utilisateur, de façon concise et structurée (Markdown).
"""
# Agent mode: the model has native tools, so it must call them (function
# calling) instead of emitting the text `obsigate-action` blocks — otherwise
# the requested file is never created (BUG-053).
GENERAL_ACTION_TOOL_PROTOCOL = """
Tu disposes d'outils natifs (function calling) pour lire, chercher et modifier les vaults : `create_file`, `create_directory`, `append_to_file`, `edit_file`, `read_file`, `search_fulltext`, etc.
Quand l'utilisateur demande explicitement de créer un fichier, **appelle directement l'outil `create_file`** avec `{"vault": "<nom du vault>", "path": "<chemin/relatif.md>", "content": "<contenu markdown>"}`. Pour créer un dossier, appelle `create_directory`.
Règles :
- N'écris **jamais** de bloc ```obsigate-action``` : en mode agent, toutes les actions passent par les outils natifs.
- Écris le contenu **complet** demandé dans l'argument `content` (ne le tronque pas, pas de « … » ni de ligne omise).
- Pour créer un fichier dans un nouveau dossier, un seul appel `create_file` avec le chemin complet suffit (les dossiers parents sont créés automatiquement).
- N'invente jamais un nom de vault : utilise l'un des vaults disponibles listés ci-dessous.
- Réponds dans la langue de l'utilisateur, de façon concise et structurée (Markdown).
"""
# Backwards-compatible alias (classic chat prompt).
GENERAL_SYSTEM_PROMPT = GENERAL_SYSTEM_HEADER + GENERAL_ACTION_TEXT_PROTOCOL
def _format_app_context(app_context: dict[str, Any] | None, recent_files: list[dict[str, Any]] | None) -> str:
"""Render the live application state for the General assistant prompt.
@@ -588,14 +612,20 @@ def build_general_system_prompt(
vaults: list[str] | None = None,
app_context: dict[str, Any] | None = None,
recent_files: list[dict[str, Any]] | None = None,
agent: bool = False,
) -> str:
"""System prompt for the General assistant (app help + actions).
``app_context`` carries the live UI state (open documents, current
directory, active search) and ``recent_files`` the last modified files, so
the assistant knows what the user is doing rather than answering blind.
``agent`` selects the action protocol: the classic chat endpoint (no native
tools) uses the text ``obsigate-action`` blocks, while the tool-calling
agent endpoint must invoke the native tools instead (BUG-053).
"""
prompt = GENERAL_SYSTEM_PROMPT
protocol = GENERAL_ACTION_TOOL_PROTOCOL if agent else GENERAL_ACTION_TEXT_PROTOCOL
prompt = GENERAL_SYSTEM_HEADER + protocol
if vaults:
prompt += "\nVaults disponibles : " + ", ".join(sorted(vaults)) + "\n"
else:
+17 -3
View File
@@ -193,10 +193,12 @@ def _recent_files_for_prompt(current_user, limit: int = 10) -> list[dict[str, An
return []
def _resolve_system_prompt(req, current_user) -> str:
def _resolve_system_prompt(req, current_user, agent: bool = False) -> str:
"""Resolve the vault access and build the assistant system prompt.
Shared by the classic chat endpoint and the tool-calling agent endpoint.
``agent=True`` selects the native-tool action protocol (no text
``obsigate-action`` blocks) for the General/empty-directory prompts.
"""
mode = _normalize_mode(req.mode)
vault_path: Path | None = None
@@ -222,6 +224,7 @@ def _resolve_system_prompt(req, current_user) -> str:
list(index.keys()),
app_context=_submitted_app_context(req),
recent_files=_recent_files_for_prompt(current_user),
agent=agent,
)
elif effective_mode == "documents":
prompt = build_system_prompt(context, scope="documents", vault_name=req.vault)
@@ -233,6 +236,7 @@ def _resolve_system_prompt(req, current_user) -> str:
list(index.keys()),
app_context=_submitted_app_context(req),
recent_files=_recent_files_for_prompt(current_user),
agent=agent,
)
prompt += (
f"\n## Dossier vide\nLe dossier « {req.directory or '/'} » "
@@ -243,6 +247,14 @@ def _resolve_system_prompt(req, current_user) -> str:
else:
prompt = build_system_prompt(context, scope="directory", vault_name=req.vault)
if agent and effective_mode != "general" and context["file_count"] > 0:
prompt += (
"\n## Mode agent\n"
"Utilise les outils natifs (function calling) pour agir sur les fichiers "
"(`create_file`, `create_directory`, `append_to_file`, `edit_file`, …). "
"N'écris jamais de bloc ```obsigate-action```."
)
skill_id = getattr(req, "skill", None)
if skill_id:
skill_prompt = get_skill_prompt(skill_id, current_user)
@@ -499,7 +511,7 @@ async def api_bookslm_agent(
``confirm`` / ``confirm_messages``.
"""
_validate_vision_support(req)
system_prompt = _resolve_system_prompt(req, current_user)
system_prompt = _resolve_system_prompt(req, current_user, agent=True)
vault_path = _resolve_optional_vault_path(req, current_user)
messages: list[dict] = [{"role": "system", "content": system_prompt}]
@@ -519,7 +531,9 @@ async def api_bookslm_agent(
provider=req.provider,
model=req.model,
temperature=0.3,
max_tokens=4096,
# Tool-call arguments can carry a whole file body (e.g. a generated
# table): leave more room than the plain-chat default.
max_tokens=8192,
)
async def generate_sse():
+243 -54
View File
@@ -2,27 +2,35 @@
Phase 1 of the documented web-toolset roadmap:
* ``web_search`` — query the self-hosted SearXNG instance (no API key).
* ``web_search`` — query the self-hosted SearXNG instance (no API key) and,
when it returns nothing, fall back to keyless HTML providers (DuckDuckGo,
then Bing) so a dead meta-search instance never leaves the assistant
answering « je n'ai pas accès à internet ».
* ``fetch_url`` — retrieve a public web page and return readable text.
Both are READ-risk tools (no confirmation), rate-limited through the shared
All are READ-risk tools (no confirmation), rate-limited through the shared
registry, SSRF-guarded (scheme + private-address rejection), and size-capped.
Configuration (environment):
* ``OBSIGATE_SEARXNG_URL`` — defaults to https://search.dracodev.net
* ``OBSIGATE_WEB_TIMEOUT`` — seconds, default 10
* ``OBSIGATE_WEB_FALLBACK`` — ``0``/``false`` disables the keyless HTML
fallbacks (SearXNG only), default enabled
"""
from __future__ import annotations
import base64
import binascii
import html as html_lib
import ipaddress
import logging
import os
import re
import socket
from collections.abc import Callable
from typing import Any
from urllib.parse import urlparse
from urllib.parse import parse_qs, urlparse
import httpx
@@ -34,7 +42,30 @@ logger = logging.getLogger("obsigate.tools.web")
SEARXNG_URL = os.environ.get("OBSIGATE_SEARXNG_URL", "https://search.dracodev.net")
WEB_TIMEOUT = float(os.environ.get("OBSIGATE_WEB_TIMEOUT", "10"))
WEB_FALLBACK_ENABLED = os.environ.get("OBSIGATE_WEB_FALLBACK", "1").strip().lower() not in {
"0",
"false",
"no",
"off",
}
USER_AGENT = "ObsiGateAssistant/1.0 (+self-hosted vault AI)"
# Search engines reject non-browser agents on their public HTML endpoints.
BROWSER_UA = (
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 "
"(KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
)
# A minimal UA is not enough: Bing serves decoy SERPs (unrelated results) to
# requests missing the usual browser navigation headers.
BROWSER_HEADERS = {
"User-Agent": BROWSER_UA,
"Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8",
"Accept-Language": "fr-CA,fr;q=0.9,en-US;q=0.8,en;q=0.7",
"Sec-Fetch-Dest": "document",
"Sec-Fetch-Mode": "navigate",
"Sec-Fetch-Site": "none",
"Sec-Fetch-User": "?1",
"Upgrade-Insecure-Requests": "1",
}
MAX_FETCH_BYTES = 1_500_000
MAX_TEXT_CHARS = 20_000
@@ -46,6 +77,18 @@ _BLOCK_SPLIT_RE = re.compile(
r"</?(?:p|div|br|li|h[1-6]|tr|table|ul|ol|section|article|header|footer)\b[^>]*>",
re.IGNORECASE,
)
_DDG_RESULT_RE = re.compile(
r'<a[^>]*class="result__a"[^>]*href="([^"]+)"[^>]*>(.*?)</a>', re.IGNORECASE | re.DOTALL
)
_DDG_SNIPPET_RE = re.compile(
r'<a[^>]*class="result__snippet"[^>]*>(.*?)</a>', re.IGNORECASE | re.DOTALL
)
_BING_RESULT_RE = re.compile(
r'<h2[^>]*>\s*<a[^>]*href="([^"]+)"[^>]*>(.*?)</a>', re.IGNORECASE | re.DOTALL
)
_BING_SNIPPET_RE = re.compile(
r'<p class="b_lineclamp[^"]*">(.*?)</p>', re.IGNORECASE | re.DOTALL
)
class SSRFError(ToolError):
@@ -99,6 +142,160 @@ def _html_to_text(raw: str) -> str:
return text.strip()
def _response_text(resp: httpx.Response) -> str:
"""Decode a response body without relying on ``resp.text`` (easier to mock)."""
return resp.content.decode(resp.encoding or "utf-8", errors="replace")
def _clean_fragment(fragment: str) -> str:
return html_lib.unescape(_TAG_RE.sub("", fragment)).strip()
def _result(
title: str, url: str, snippet: str, published: Any = None, score: Any = None
) -> dict[str, Any]:
return {
"title": (title or "")[:300],
"url": url or "",
"snippet": (snippet or "")[:600],
"published": published,
"score": score,
}
def _search_searxng(
query: str, params: WebSearchInput
) -> tuple[list[dict[str, Any]], list[str]]:
"""Query the self-hosted SearXNG instance (JSON API)."""
url = SEARXNG_URL.rstrip("/") + "/search"
resp = httpx.get(
url,
params={
"q": query,
"format": "json",
"categories": params.category or "general",
"pageno": max(1, params.page),
**({"language": params.language} if params.language else {}),
"safesearch": "1",
},
headers={"User-Agent": USER_AGENT},
timeout=WEB_TIMEOUT,
follow_redirects=False,
)
resp.raise_for_status()
data = resp.json()
results = [
_result(
item.get("title") or "",
item.get("url") or "",
item.get("content") or "",
item.get("publishedDate"),
item.get("score"),
)
for item in (data.get("results") or [])[: params.max_results]
]
unresponsive = [
name for entry in (data.get("unresponsive_engines") or [])
for name in ([entry[0]] if isinstance(entry, (list, tuple)) and entry else [entry])
if isinstance(name, str)
]
return results, unresponsive
def _unwrap_duckduckgo_url(href: str) -> str:
"""DuckDuckGo HTML wraps hits in ``/l/?uddg=<urlencoded target>``."""
href = html_lib.unescape(href)
if href.startswith("//"):
href = "https:" + href
if "uddg=" in href:
values = parse_qs(urlparse(href).query).get("uddg")
if values:
return values[0]
return href
def _search_duckduckgo(
query: str, params: WebSearchInput
) -> tuple[list[dict[str, Any]], list[str]]:
"""Keyless fallback: scrape the DuckDuckGo no-JS HTML endpoint."""
resp = httpx.get(
"https://html.duckduckgo.com/html/",
params={"q": query, **({"kl": params.language} if params.language else {})},
headers=BROWSER_HEADERS,
timeout=WEB_TIMEOUT,
follow_redirects=False,
)
resp.raise_for_status()
body = _response_text(resp)
snippets = [_clean_fragment(m.group(1)) for m in _DDG_SNIPPET_RE.finditer(body)]
results: list[dict[str, Any]] = []
for index, match in enumerate(_DDG_RESULT_RE.finditer(body)):
results.append(
_result(
_clean_fragment(match.group(2)),
_unwrap_duckduckgo_url(match.group(1)),
snippets[index] if index < len(snippets) else "",
)
)
if len(results) >= params.max_results:
break
return results, []
def _unwrap_bing_url(href: str) -> str:
"""Bing wraps hits in ``/ck/a?...&u=a1<base64url target>``."""
href = html_lib.unescape(href)
match = re.search(r"[?&]u=a1([A-Za-z0-9_\-]+)", href)
if not match:
return href
token = match.group(1).replace("-", "+").replace("_", "/")
token += "=" * (-len(token) % 4)
try:
return base64.b64decode(token).decode("utf-8", errors="replace")
except (ValueError, binascii.Error):
return href
def _search_bing(
query: str, params: WebSearchInput
) -> tuple[list[dict[str, Any]], list[str]]:
"""Last-resort keyless fallback: scrape Bing's result page."""
resp = httpx.get(
"https://www.bing.com/search",
params={"q": query, **({"setlang": params.language} if params.language else {})},
headers=BROWSER_HEADERS,
timeout=WEB_TIMEOUT,
follow_redirects=False,
)
resp.raise_for_status()
body = _response_text(resp)
snippets = [_clean_fragment(m.group(1)) for m in _BING_SNIPPET_RE.finditer(body)]
results: list[dict[str, Any]] = []
for index, match in enumerate(_BING_RESULT_RE.finditer(body)):
results.append(
_result(
_clean_fragment(match.group(2)),
_unwrap_bing_url(match.group(1)),
snippets[index] if index < len(snippets) else "",
)
)
if len(results) >= params.max_results:
break
return results, []
_Provider = Callable[[str, WebSearchInput], "tuple[list[dict[str, Any]], list[str]]"]
def _provider_chain() -> list[tuple[str, _Provider]]:
"""Ordered providers: self-hosted meta-search first, then keyless fallbacks."""
chain: list[tuple[str, _Provider]] = [("searxng", _search_searxng)]
if WEB_FALLBACK_ENABLED:
chain.append(("duckduckgo", _search_duckduckgo))
chain.append(("bing", _search_bing))
return chain
@tool(
name="web_search",
description=(
@@ -111,67 +308,59 @@ def _html_to_text(raw: str) -> str:
scopes=(ToolScope.IN_APP,),
)
def web_search(ctx, params: WebSearchInput) -> dict[str, Any]:
"""Query the self-hosted SearXNG instance and return trimmed results."""
"""Try each configured provider and return the first non-empty result set."""
query = params.query.strip()
if not query:
raise ToolError("Requête vide", code="invalid_arguments")
url = SEARXNG_URL.rstrip("/") + "/search"
try:
resp = httpx.get(
url,
params={
"q": query,
"format": "json",
"categories": params.category or "general",
"pageno": max(1, params.page),
**({"language": params.language} if params.language else {}),
"safesearch": "1",
},
headers={"User-Agent": USER_AGENT},
timeout=WEB_TIMEOUT,
follow_redirects=False,
)
resp.raise_for_status()
data = resp.json()
except httpx.HTTPError as e:
logger.warning("web_search failed: %s", e)
attempts: list[str] = []
unresponsive: list[str] = []
reachable = False
last_error: Exception | None = None
for name, provider in _provider_chain():
attempts.append(name)
try:
results, engines = provider(query, params)
except (httpx.HTTPError, ValueError, AttributeError) as e:
logger.warning("web_search provider %s failed: %s", name, e)
last_error = e
continue
reachable = True
if engines:
unresponsive = engines
if results:
payload: dict[str, Any] = {
"query": query,
"provider": name,
"results": results,
"count": len(results),
}
if unresponsive:
payload["unresponsive_engines"] = unresponsive[:8]
return payload
if not reachable:
raise ToolError(
"Le moteur de recherche web est momentanément indisponible.",
code="web_search_unavailable",
) from e
results: list[dict[str, Any]] = []
for item in (data.get("results") or [])[: params.max_results]:
results.append(
{
"title": (item.get("title") or "")[:300],
"url": item.get("url") or "",
"snippet": (item.get("content") or "")[:600],
"published": item.get("publishedDate"),
"score": item.get("score"),
}
)
unresponsive = [
name for entry in (data.get("unresponsive_engines") or [])
for name in ([entry[0]] if isinstance(entry, (list, tuple)) and entry else [entry])
if isinstance(name, str)
]
payload: dict[str, Any] = {
) from last_error
# Every provider answered but returned nothing: tell the model explicitly
# so it stops retrying the same query until its tool quota burns out.
payload = {
"query": query,
"engine": "searxng",
"results": results,
"count": len(results),
"provider": attempts[-1],
"results": [],
"count": 0,
"warning": (
"Aucun résultat : les fournisseurs de recherche web sont "
f"indisponibles ({', '.join(attempts)}). "
"Ne relance pas la même recherche — dis-le à l'utilisateur."
),
}
if unresponsive:
payload["unresponsive_engines"] = unresponsive[:8]
if not results:
# An instance whose upstream engines are all blocked (CAPTCHA / rate
# limit) answers 200 with an empty list. Without an explicit hint the
# model retries the same search until it burns its tool quota.
payload["warning"] = (
"Aucun résultat : les moteurs de recherche de l'instance SearXNG sont "
f"indisponibles ({', '.join(unresponsive[:5]) or 'inconnus'}). "
"Ne relance pas la même recherche — dis-le à l'utilisateur."
)
return payload
+1 -1
View File
@@ -2626,7 +2626,7 @@ dependencies = [
[[package]]
name = "obsigate-desktop"
version = "2.7.0"
version = "2.7.5"
dependencies = [
"chrono",
"env_logger",
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "obsigate-desktop"
version = "2.7.0"
version = "2.7.5"
description = "ObsiGate Desktop — Porte d'entrée native pour vos vaults Obsidian"
authors = ["Bruno Charest"]
edition = "2021"
+1 -1
View File
@@ -1,7 +1,7 @@
{
"$schema": "https://raw.githubusercontent.com/nicedoc/obsigate/main/desktop/tauri.conf.schema.json",
"productName": "ObsiGate",
"version": "2.7.0",
"version": "2.7.5",
"identifier": "com.obsigate.desktop",
"build": {
"frontendDist": "../frontend",
+10 -1
View File
@@ -14,7 +14,7 @@
- **Projet** : ObsiGate — Porte d'entrée web pour vaults Obsidian
- **Stack** : Python 3.11+ (backend FastAPI) · JavaScript/Vanilla (frontend) · Tauri/Rust (desktop)
- **Dernière mise à jour** : 2026-09-16
- **Dernière mise à jour** : 2026-09-17
---
@@ -160,6 +160,10 @@ Avant de corriger quoi que ce soit, un agent IA doit :
| *BUG-048* | [🟡 IMPORTANT] Assistant IA : les entrées « Contextes » et « Skills » du menu « + » n'ouvraient pas leur menu (`@` / `/`) | 🟢 corrigé | P2 | 📱 frontend | IA | `frontend/js/bookslm.js` | Menu « + » de l'assistant → cliquer « Contextes » ou « Skills » | `e.stopPropagation()` sur les entrées du panneau `.bookslm-ext-menu` (le clic remontait au gestionnaire du panneau qui annulait le rendu asynchrone) | Journal 2026-09-16. Tests : `tests/frontend/ai.test.mjs` (+3) |
| *BUG-049* | [🔵 MINEUR] Assistant IA : icône du bouton « + » invisible (largeur SVG nulle) | 🟢 corrigé | P3 | 📱 frontend | IA | `frontend/style.css` | Ouvrir l'assistant et observer le bouton « + » | Sélecteur porté à `.bookslm-input-area button.bookslm-btn-plus` (la règle générique `padding: 8px 16px` sur un bouton 32 px annulait la largeur de contenu) | Vérifié navigateur : SVG 0 px → 18 px. Journal 2026-09-16 |
| *BUG-050* | [🟡 IMPORTANT] Assistant IA : échec de la création d'un sous-dossier contenant un fichier (appels d'outils parallèles + confirmation) | 🟢 corrigé | P1 | ⚙️ backend + 🤖 ia | IA | `backend/agent/loop.py`, `backend/services/mutations.py`, `backend/tools/service.py`, `backend/bookslm.py` | Mode Agent : « crée le dossier X et un fichier Y dedans » puis Appliquer | `backend/agent/loop.py` : résultats « deferred » (`_deferred_tool_message`) pour les `tool_calls` non atteints lors d'une pause de confirmation ; `backend/services/mutations.py` : `create_directory(..., exist_ok=True)` ; `backend/tools/service.py` + `backend/bookslm.py` : consignes `create_file` (parents auto-créés, chemin imbriqué unique) | Cause : le message assistant listait plusieurs `tool_calls` mais la pause n'ajoutait le résultat que du seul appel confirmé → conversation invalide (tool_call_id sans réponse) au resume. Tests : `tests/test_agent_loop.py` (+1), `tests/test_tools_mutations.py` (+1), `tests/test_api_main.py` (+1) |
| *BUG-051* | [🟡 IMPORTANT] Assistant IA : la recherche web répond toujours « je ne peux pas accéder à internet » (mode agent ou non) | 🟢 corrigé | P1 | ⚙️ backend + 🤖 ia | IA | `backend/tools/web.py`, `tests/test_web_tools.py` | Assistant : « fais une recherche sur l'horaire du Canadien de Montréal 2026-2027 » | `backend/tools/web.py` : chaîne de repli sans clé — SearXNG puis DuckDuckGo (HTML sans JS) puis Bing (HTML), premier fournisseur non vide retenu (`provider`), replis désactivables via `OBSIGATE_WEB_FALLBACK=0` | Cause : l'instance SearXNG par défaut (`search.dracodev.net`) remonte 0 résultat (moteurs amont suspendus/CAPTCHA) → le modèle en déduisait une absence d'accès réseau. Tests : `tests/test_web_tools.py` (+4) |
| *BUG-052* | [🟡 IMPORTANT] Assistant IA : recherche web sans réponse finale (10 étapes + sources affichées, aucun texte dans la conversation) | 🟢 corrigé | P1 | ⚙️ backend + 🤖 ia | IA | `backend/agent/loop.py`, `tests/test_agent_loop.py` | Assistant (mode agent) : recherche web qui enchaîne 10 étapes puis n'affiche aucune réponse | `backend/agent/loop.py` : `_finalize_answer` — dernier appel LLM sans outil (instruction de synthèse) quand le budget d'itérations/quota est épuisé, repli déterministe `_fallback_summary` (liste des sources), résultats `deferred` pour les appels non atteints du lot en quota | Cause : `content=""` renvoyé sur `STOP_MAX_ITERATIONS`/`STOP_QUOTA_EXCEEDED` alors que le modèle appelait encore des outils. Tests : `tests/test_agent_loop.py` (+2) |
| *BUG-053* | [🟡 IMPORTANT] Assistant IA (mode agent) : le fichier demandé n'est pas créé — le modèle émet un bloc texte `obsigate-action` au lieu d'appeler l'outil `create_file` | 🟢 corrigé | P1 | ⚙️ backend + 🤖 ia | IA | `backend/bookslm.py`, `backend/bookslm_routes.py`, `tests/test_bookslm.py` | Mode agent, contexte Général (ou dossier vide) : « créer le fichier TestVault/sport/… avec le tableau des 84 matchs » → réponse avec un bloc ```obsigate-action``` tronqué, aucun fichier | `backend/bookslm.py` : protocole d'action scindé — `GENERAL_ACTION_TOOL_PROTOCOL` (outils natifs, interdiction des blocs `obsigate-action`) utilisé quand `agent=True`, protocole texte conservé pour le chat classique ; `backend/bookslm_routes.py` : `_resolve_system_prompt(..., agent=True)` depuis l'endpoint agent + règle « Mode agent » pour les prompts dossier/documents, `max_tokens` agent 4096 → 8192 (contenu de fichier complet) | Cause : le prompt Général enseignait encore le protocole texte alors que l'agent dispose du function calling. Tests : `tests/test_bookslm.py` (+3) |
| *BUG-054* | [🟡 IMPORTANT] Éditeur « Editer » : le bouton Sauvegarder reste bloqué sur le spinner de chargement (retour au crochet uniquement après un refresh complet) | 🟢 corrigé | P1 | 📱 frontend | IA | `frontend/js/utils.js` | Ouvrir un fichier → Editer → cliquer Sauvegarder (ou Ctrl+S) ; rouvrir l'éditeur : le bouton reste un spinner désactivé | Nouveau helper `resetSaveButton()` (crochet `&#10003;` + `disabled=false` + styles en ligne nettoyés) appelé à l'ouverture (`openEditor`), à la fermeture (`closeEditor`) et en cas d'échec (`saveFile`). Tests : `tests/frontend/editor-inline.test.mjs` (+4) | Le nœud `#editor-save` est partagé entre sessions : l'état « spinner + désactivé » posé par une sauvegarde manuelle n'était jamais remis à zéro (succès → fermeture puis réouverture, Forge, ou échec réseau dans le `catch`). Seul un rechargement de `index.html` restaurait le crochet |
| | | | | | | | | | | |
### TODOs techniques (améliorations / nouvelles tâches)
@@ -210,6 +214,11 @@ Avant de corriger quoi que ce soit, un agent IA doit :
| 2026-09-16 | BUG-048, #98 | Correction + feature | `frontend/js/bookslm.js`, `frontend/js/config.js`, `frontend/js/sidebar.js`, `frontend/style.css`, `frontend/locales/{fr,en}.json`, `.gitea/workflows/ci.yml`, `tests/frontend/ai.test.mjs`, `tests/frontend/ai-sidebar.test.mjs` (nouveau), `docs/features/ai-assistant-history.md`, `docs/ROADMAP.md`, `CHANGELOG.md` | **BUG-048** : les entrées « Contextes » et « Skills » du menu « + » ouvraient bien leur menu (`@` / `/`), mais le clic remontait au gestionnaire du panneau qui annulait le rendu asynchrone → menu jamais affiché ; correction par `e.stopPropagation()` sur les entrées du panneau `.bookslm-ext-menu`. **#98** : la barre de filtrage de la sidebar agit désormais sur l'onglet « Historique IA » — `filterAIHistory()` (config.js) filtre par titre, aperçu, répertoire, contexte ou libellé de mode, insensible casse/accents (`_aiNorm`), cache sessions `_aiSessionsCache`, message « aucune correspondance » (`bookslm.history_no_match`) dans la liste et placeholder dédié (`sidebar.filter_ai`) ; `initSidebarFilter` (sidebar.js) route saisie/touche casse/bouton « × » vers `filterAIHistory` quand l'onglet IA est actif ; chaque entrée du panneau « + » porte l'icône Lucide `plus`. Vérifié : tests frontend IA 87/87 (+3), nouvelle suite `ai-sidebar` 6/6, unit 9/9, 9 suites JSDOM vertes, validate-imports 38 modules, pytest / ruff / mypy inchangés (aucune modification backend). | 🟢 corrigé (en attente vérif utilisateur) — CI Gitea verte (lint, test, security, build, e2e) pour v2.5.0 (run #1511) |
| 2026-09-16 | BUG-049, #99, #100 | Correction + feature | `frontend/style.css`, `frontend/js/config.js`, `frontend/js/viewer.js`, `frontend/js/sidebar.js`, `frontend/js/bookslm.js`, `frontend/locales/{fr,en}.json`, `.gitea/workflows/ci.yml`, `tests/frontend/ai.test.mjs`, `tests/frontend/sidebar-filters.test.mjs` (nouveau), `docs/features/sidebar-filters.md` (nouvelle), `docs/features/ai-assistant-history.md`, `docs/ROADMAP.md`, `CHANGELOG.md` | **BUG-049** : icône du bouton « + » de l'assistant invisible — la règle générique `.bookslm-input-area button` (spécificité supérieure) imposait `padding: 8px 16px` sur un bouton `width: 32px` ⇒ largeur de contenu nulle ⇒ SVG `width: 0px` ; sélecteur porté à `.bookslm-input-area button.bookslm-btn-plus` (+ `:hover`), vérifié en navigateur (Playwright : SVG 0 px → 18 px). **#99** : la barre de filtrage de la sidebar agit désormais sur les vues **Récents** (`filterRecentFiles`, titre/chemin/vault/aperçu/tags) et **Sauvegardes** (`filterSavedSearches`, cumulable avec les pills type), insensible casse/accents (`_sidebarNorm`/`_savedNorm`), message d'absence de résultat (`sidebar.no_results`) et placeholders dédiés (`sidebar.filter_recent`, `sidebar.filter_saved`) ; `initSidebarFilter` refactoré en `routeFilter`/`routeClear` couvrant les 5 onglets. **#100** : « Deep Research » ajoute une **pastille** `.bookslm-chip-deep-research` (au lieu d'injecter la directive dans le composeur), active le mode Agent et injecte la directive au moment de l'envoi. Vérifié : tests frontend IA 88/88 (+1), `sidebar-filters` 8/8 (nouveau), `ai-sidebar` 6/6, unit 9/9, 9 suites JSDOM vertes, validate-imports 38 modules, vérification navigateur du bouton « + » ; backend inchangé (pytest / ruff / mypy valides). | 🟢 corrigé (en attente vérif utilisateur) |
| 2026-09-16 | BUG-050 | Correction | `backend/agent/loop.py`, `backend/services/mutations.py`, `backend/tools/service.py`, `backend/bookslm.py`, `tests/test_agent_loop.py`, `tests/test_tools_mutations.py`, `tests/test_api_main.py`, `docs/features/ai-tools-mcp.md`, `CHANGELOG.md` | **BUG-050** : création d'un sous-dossier contenant un fichier en mode Agent. (1) La boucle d'agent renvoyait la conversation sans réponse pour les `tool_calls` non atteints lorsqu'un appel mutateur déclenchait une confirmation → le provider rejetait le tour de reprise (« tool_call_id » orphelin) ; les appels restants reçoivent désormais un résultat `deferred` explicite (`_deferred_tool_message`) que le modèle réémet après confirmation. (2) `create_directory` est idempotent côté outil IA (`exist_ok=True`, succès si le dossier existe), le REST restant strict (409). (3) Consignes renforcées : `create_file` crée les dossiers parents, un seul appel avec chemin imbriqué suffit (`backend/bookslm.py`, descriptions d'outils). Vérifié : pytest 1091 passed / 6 skipped, ruff 0 (backend), mypy 0 (71 fichiers), tests frontend validate-imports 38 modules + unit 9/9. | 🟢 corrigé (en attente vérif utilisateur) |
| 2026-09-16 | BUG-051 | Correction | `backend/tools/web.py`, `tests/test_web_tools.py`, `docs/features/ai-tools-roadmap.md`, `docs/features/ai-assistant-conversation-ux.md`, `docs/ROADMAP.md`, `CHANGELOG.md` | **BUG-051** : `web_search` ne dépend plus d'une seule instance SearXNG. Nouvelle chaîne de fournisseurs (`_provider_chain`) : SearXNG (auto-hébergé, JSON) → DuckDuckGo (`html.duckduckgo.com/html/`, extraction `result__a`/`result__snippet`, décodage du lien `uddg=`) → Bing (`www.bing.com/search`, extraction `h2 > a` + `p.b_lineclamp*`, décodage de la redirection `u=a1<base64url>`), UA navigateur, premier fournisseur non vide retenu et exposé (`provider`). Le champ `warning` final liste les fournisseurs essayés ; replis désactivables via `OBSIGATE_WEB_FALLBACK=0` ; erreur `web_search_unavailable` uniquement si tous les fournisseurs sont injoignables. Vérifié : pytest 1082 passed / 6 skipped (14 erreurs MCP préexistantes, sans lien), ruff 0 (backend), mypy 0 (`backend/tools/web.py`), `tests/test_web_tools.py` 13/13, recherche live Bing (horaire Canadiens) sur l'hôte. | 🟢 corrigé (en attente vérif utilisateur) |
| 2026-09-16 | BUG-051 (complément) | Correction | `backend/tools/web.py`, `CHANGELOG.md` | **BUG-051** suite : un `User-Agent` navigateur seul ne suffit pas — Bing renvoie une SERP factice (résultats sans rapport, ex. « highest paying jobs » / « Sam Reid ») aux requêtes sans en-têtes de navigation. Ajout de `BROWSER_HEADERS` (`Accept-Language`, `Sec-Fetch-*`, `Upgrade-Insecure-Requests`) pour DuckDuckGo et Bing. Vérifié **en conteneur** (`obsigate-test`, v2.7.1) : `web_search('Canadien de Montreal horaire matchs 2026 2027')` → `provider: bing`, 5 résultats pertinents (nhl.com/fr/canadiens, rds.ca, fr.wikipedia.org). | 🟢 corrigé (en attente vérif utilisateur) |
| 2026-09-16 | BUG-052 | Correction | `backend/agent/loop.py`, `tests/test_agent_loop.py`, `CHANGELOG.md` | **BUG-052** : la boucle d'agent ne rendait plus jamais de réponse vide. `_finalize_answer` : à l'épuisement du budget d'itérations (`STOP_MAX_ITERATIONS`) ou du quota d'appels (`STOP_QUOTA_EXCEEDED`), un dernier appel LLM **sans outil** reçoit une instruction de synthèse (« N'appelle plus aucun outil. Réponds maintenant… ») et son texte devient la réponse ; si l'appel échoue ou reste vide, `_fallback_summary` compose une liste déterministe des sources (`web_search`/`fetch_url`) pour ne jamais renvoyer un tour vide. Les `tool_calls` non atteints lors d'un arrêt sur quota reçoivent un résultat `deferred` (conversation valide pour la synthèse). Vérifié : `tests/test_agent_loop.py` 16/16 (+2 : synthèse finale, repli sources), suite complète 1084 passed / 6 skipped (14 erreurs MCP préexistantes), ruff 0 (backend), mypy 0 (`backend/agent/loop.py`). | 🟢 corrigé (en attente vérif utilisateur) |
| 2026-09-16 | BUG-053 | Correction | `backend/bookslm.py`, `backend/bookslm_routes.py`, `tests/test_bookslm.py`, `CHANGELOG.md` | **BUG-053** : en mode agent, le prompt Général (et dossier vide) enseignait le protocole texte `obsigate-action` ; le modèle décrivait donc l'action au lieu d'appeler l'outil natif `create_file` (bloc volumineux de surcroît tronqué avant fermeture → aucun fichier créé). Le prompt est scindé : `GENERAL_ACTION_TOOL_PROTOCOL` (appel direct des outils natifs, interdiction explicite des blocs `obsigate-action`) pour `build_general_system_prompt(agent=True)`, le protocole texte restant utilisé par le chat classique ; `_resolve_system_prompt` propage `agent` et ajoute une règle « Mode agent » aux prompts dossier/documents ; `max_tokens` de l'agent porté à 8192 pour un contenu de fichier complet. Vérifié : `tests/test_bookslm.py` 68/68 (+3 : prompt agent sans protocole texte, prompt classique inchangé, prompt système de l'endpoint agent), suite complète 1087 passed / 6 skipped (14 erreurs MCP préexistantes), ruff 0 (backend), mypy 0 (`backend/bookslm.py`, `backend/bookslm_routes.py`). | 🟢 corrigé (en attente vérif utilisateur) |
| 2026-09-17 | BUG-054 | Correction | `frontend/js/utils.js`, `tests/frontend/editor-inline.test.mjs`, `CHANGELOG.md`, `docs/ISSUES_TODOLIST.md` | **BUG-054** : le bouton `#editor-save` (nœud partagé entre toutes les sessions d'édition) restait bloqué sur le spinner de chargement et désactivé — une sauvegarde manuelle (clic ou Ctrl+S) remplaçait le crochet par le loader et ne le restaurait jamais : succès (l'éditeur se ferme, la réouverture réaffichait le spinner), sauvegarde Forge, ou échec réseau (le `catch` ne restaurait ni l'icône ni l'état). Nouveau helper `resetSaveButton()` (crochet `&#10003;`, `disabled=false`, styles en ligne nettoyés) appelé à l'ouverture (`openEditor`), à la fermeture (`closeEditor`) et en cas d'échec (`saveFile`). Vérifié : `tests/frontend/editor-inline.test.mjs` 29/29 (+4), validate-imports 38 modules / 0 erreur. | 🟢 corrigé (en attente vérif utilisateur) |
---
+3 -2
View File
@@ -1,6 +1,6 @@
# ObsiGate — Roadmap
> **Version :** 2.7.0 | **Dernière mise à jour :** 2026-09-16
> **Version :** 2.7.5 | **Dernière mise à jour :** 2026-09-17
> **Ce fichier ne contient que le travail à venir** (🔵 En cours + ⚪ Backlog) et un index compact
> vers les fonctionnalités livrées.
> - **Méthode de livraison à appliquer pour toute tâche : [DELIVERY_WORKFLOW.md](./DELIVERY_WORKFLOW.md)**
@@ -87,7 +87,8 @@
[features/ai-tools-roadmap.md](./features/ai-tools-roadmap.md) (frameworks évalués,
bibliothèques par catégorie, transverse retry/cache/secrets/async).
- **Sous-tâches :**
- [ ] `web_search` : chaîne de repli sans clé (DuckDuckGo) + fournisseurs optionnels (Tavily, Brave, SerpAPI, Exa)
- [x] `web_search` : chaîne de repli sans clé (SearXNG → DuckDuckGo → Bing, `OBSIGATE_WEB_FALLBACK`) — BUG-051
- [ ] `web_search` : fournisseurs optionnels à clé (Tavily, Brave, SerpAPI, Exa)
- [ ] `fetch_url` : pages dynamiques via Playwright (worker isolé) ; crawl multi-pages Scrapy en tâche de fond
- [ ] Sources connectées : Gitea/GitHub (priorité haute) puis Google Drive / OneDrive (OAuth2 `authlib`)
- [ ] Production de documents : conversion, tableurs, PDF/Word (outils WRITE + confirmation)
@@ -133,6 +133,11 @@
ne remonte aucun résultat (moteurs amont suspendus/CAPTCHA) : `warning` +
`unresponsive_engines` dans le résultat — sans ce signal, l'assistant relançait la
même recherche jusqu'au quota d'outils.
- [x] **G8.** **Chaîne de repli web (BUG-051)** : `web_search` interroge successivement
SearXNG, puis DuckDuckGo (HTML sans JS) puis Bing (HTML), et retient le premier
fournisseur non vide (`provider`) ; les replis se désactivent via
`OBSIGATE_WEB_FALLBACK=0`. Évite que l'assistant conclue « pas d'accès à internet »
quand l'instance SearXNG est bloquée par ses moteurs amont.
### Outils restants — documentés pour le futur (hors #91)
La catégorie Notion « étapes » peut s'étendre ; chaque futur outil devra être un
+1 -1
View File
@@ -17,7 +17,7 @@
## B. Function calling in-app (3-4 jours) — ✅ livré (2026-09-11)
- [x] **B1.** Abstraction tool-calling provider-agnostique : `backend/ai_chat.py` (`chat_completion`, `ToolCall`, `LLMResponse`) — OpenAI-compat (`tools`/`tool_choice`, parsing `tool_calls`) + Gemini (`functionDeclarations`/`functionCall`)
- [x] **B2.** Agent loop `backend/agent/loop.py` : boucle tool→résultat→tool, limite d'itérations (10), truncation des résultats ; endpoint opt-in `POST /api/ai/bookslm/agent` (events SSE `tool`/`message`/`confirmation`)
- [x] **B3.** Fallback : retry sans `tools` si le provider rejette les tools (400/404/422) → chat simple ; protocole texte `obsigate-action` conservé côté frontend
- [x] **B3.** Fallback : retry sans `tools` si le provider rejette les tools (400/404/422) → chat simple ; protocole texte `obsigate-action` conservé côté frontend **pour le chat classique uniquement** (BUG-053 : en mode agent, le prompt impose les outils natifs et interdit les blocs `obsigate-action`)
- [x] **B4.** SSE réellement streaming — `ai_chat.stream_completion` (`_openai_stream` + `_gemini_stream`) alimente `/api/ai/bookslm/chat` token par token ; le middleware GZip laisse passer les endpoints SSE BooksLM.
- [x] **B5.** Confirmations UI : toggle « mode agent » (front → `/agent`), événements `tool`/`confirmation`, carte Apply + aperçu diff (LCS) pour les mutations, reprise `confirm`/`confirm_messages` côté backend. *S'active dès que la phase D enregistre des outils `write`.*
- [x] **B6.** Outils de navigation in-app : `open_file`, `reveal_in_tree` (événement `obsigate:open-file`) — livré via les liens cliquables de l'assistant (#80, [ai-assistant-ux.md](./ai-assistant-ux.md))
+10 -2
View File
@@ -37,8 +37,11 @@ réécriture de la boucle n'est nécessaire.
## 3. Phase 2 — catégories à implémenter
### 3.1 Recherche web étendue (`web_search`)
- **Fallback sans clé** : aujourd'hui SearXNG auto-hébergé (`OBSIGATE_SEARXNG_URL`).
Prévoir une chaîne de repli si l'instance est indisponible (DuckDuckGo HTML).
- **Fallback sans clé — ✅ livré (BUG-051)** : chaîne de fournisseurs dans
`backend/tools/web.py` — SearXNG auto-hébergé (`OBSIGATE_SEARXNG_URL`) puis, si
aucun résultat, DuckDuckGo (`html.duckduckgo.com/html/`) puis Bing
(`www.bing.com/search`). Le premier fournisseur non vide est retenu et exposé
(`provider`) ; replis désactivables via `OBSIGATE_WEB_FALLBACK=0`.
- **Fournisseurs optionnels** (clé dans Infisical, jamais en dur) : Tavily
(résultats orientés agents), Brave Search API, SerpAPI (Google), Exa.
Interface unifiée type `anysearch` pour un sélecteur de fournisseur unique.
@@ -77,6 +80,11 @@ audit) et **jamais** avec un token en dur :
- Livré : la note intermédiaire du modèle devient une étape visible.
- Extension possible : exposer les itérations de la boucle (`iterations`) comme
étapes de planification quand un outil de plan est ajouté.
- **Garantie de réponse finale — ✅ livré (BUG-052)** : à l'épuisement du budget
d'itérations ou du quota d'appels d'outils, `_finalize_answer` déclenche un
dernier appel LLM **sans outil** (instruction de synthèse) ; un repli
déterministe liste les sources si cet appel échoue. Une recherche web ne peut
plus se terminer sur une conversation sans texte.
## 4. Transverse — à faire avec la phase 2
+25
View File
@@ -365,6 +365,9 @@ function escapeHtml(str) {
async function openEditor(vaultName, filePath) {
state.editorVault = vaultName;
state.editorPath = filePath;
// A previous session may have left the shared save button in its spinner
// state (manual save, Forge, failed request). BUG-054.
resetSaveButton();
const modal = document.getElementById("editor-modal");
const titleInput = document.getElementById("editor-title-input");
@@ -582,6 +585,7 @@ function closeEditor() {
const modal = document.getElementById("editor-modal");
if (!modal) return;
modal.classList.remove("active");
resetSaveButton();
stopCollab();
if (state.editorView) {
state.editorView.destroy();
@@ -683,6 +687,26 @@ async function reloadExternalWrite(vault, path) {
}
}
/**
* Restore the save button to its idle state (checkmark, enabled).
*
* The button (`#editor-save`) is a single shared DOM node reused across every
* edition session, including inline mode where it travels with the editor
* container. A manual save swaps its content for a spinner and disables it; if
* that state is not cleared on success/failure, the spinner leaks into the next
* session and only a full page reload (which re-parses index.html) brings the
* checkmark back. BUG-054.
*/
function resetSaveButton() {
const saveBtn = document.getElementById("editor-save");
if (!saveBtn) return;
saveBtn.disabled = false;
saveBtn.innerHTML = '&#10003;';
saveBtn.style.background = '';
saveBtn.style.color = '';
saveBtn.style.borderColor = '';
}
async function saveFile(silent = false) {
// If Forge is open, delegate save to the iframe
var forgeFrame = document.getElementById("forge-iframe");
@@ -750,6 +774,7 @@ async function saveFile(silent = false) {
}
} catch (err) {
console.error("Save error:", err);
resetSaveButton();
if (saveDot) { saveDot.className = 'editor-save-dot err'; }
if (saveLabel) saveLabel.textContent = 'Erreur';
// If offline, queue the save for later sync
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "obsigate",
"version": "2.7.0",
"version": "2.7.5",
"description": "**Porte d'entrée web ultra-léger pour vos vaults Obsidian** — Accédez, naviguez et recherchez dans toutes vos notes Obsidian depuis n'importe quel appareil via une interface web moderne et responsive.",
"main": "patch.js",
"directories": {
+25
View File
@@ -356,6 +356,31 @@ test("style.css: #editor-body scrolls through the CodeMirror scroller only", ()
"global .cm-scroller min-height override reintroduces the double scrollbar");
});
// ── BUG-054: the shared save button must not stay stuck on the spinner ──
test("utils.js resetSaveButton restores the checkmark and re-enables the button", () => {
const fn = utilsSrc.match(/function resetSaveButton\(\) \{([\s\S]*?)\n\}/);
assert.ok(fn, "resetSaveButton not found");
assert.match(fn[1], /saveBtn\.disabled = false;/);
assert.match(fn[1], /saveBtn\.innerHTML = '&#10003;'/);
assert.match(fn[1], /saveBtn\.style\.background = '';/);
});
test("utils.js openEditor resets the save button before each session", () => {
const fn = utilsSrc.match(/async function openEditor\(vaultName, filePath\) \{([\s\S]*?)\n\}/);
assert.ok(fn, "openEditor not found");
assert.match(fn[1], /resetSaveButton\(\);/);
});
test("utils.js closeEditor resets the save button on success/cancel/delete", () => {
const fn = utilsSrc.match(/function closeEditor\(\) \{([\s\S]*?)\n\}/);
assert.ok(fn, "closeEditor not found");
assert.match(fn[1], /resetSaveButton\(\);/);
});
test("utils.js saveFile restores the save button when the request fails", () => {
assert.match(utilsSrc, /console\.error\("Save error:", err\);\s*\n\s*resetSaveButton\(\);/);
});
console.log(`\n${testCount - failCount}/${testCount} tests passed`);
if (failCount > 0) {
console.error(`${failCount} test(s) failed`);
+34
View File
@@ -182,6 +182,40 @@ class TestConfirmationAndLimits:
assert result.iterations == 2
assert len(result.tool_calls) == 2
@pytest.mark.asyncio
async def test_max_iterations_synthesizes_final_answer(self, monkeypatch):
"""BUG-052: exhausting the budget must still produce an answer."""
_register(monkeypatch, "_echo", lambda ctx, params: {"value": 1})
llm = ScriptedLLM([
LLMResponse(tool_calls=[ToolCall(id="1", name="_echo", arguments={})]),
LLMResponse(tool_calls=[ToolCall(id="2", name="_echo", arguments={})]),
LLMResponse(content="synthèse finale"),
])
result = await run_agent(
[{"role": "user", "content": "loop"}], ctx=_ctx(), llm=llm, max_iterations=2
)
assert result.stopped == STOP_MAX_ITERATIONS
assert result.content == "synthèse finale"
# The last call is tool-less and carries the synthesis instruction.
assert llm.calls[-1]["tools"] == []
assert "N'appelle plus aucun outil" in llm.calls[-1]["messages"][-1]["content"]
@pytest.mark.asyncio
async def test_max_iterations_falls_back_to_sources(self, monkeypatch):
"""An empty/failed synthesis still returns the gathered sources."""
_register(monkeypatch, "_search", lambda ctx, params: {
"results": [{"title": "T", "url": "https://ex.dev/a"}]
})
llm = ScriptedLLM([
LLMResponse(tool_calls=[ToolCall(id="1", name="_search", arguments={})]),
LLMResponse(content=""),
])
result = await run_agent(
[{"role": "user", "content": "loop"}], ctx=_ctx(), llm=llm, max_iterations=1
)
assert result.stopped == STOP_MAX_ITERATIONS
assert "https://ex.dev/a" in result.content
# ═══════════════════════════════════════════════════════════════════
# Permissions (index-backed)
+41
View File
@@ -729,6 +729,23 @@ class TestGeneralPrompt:
prompt = build_general_system_prompt(["Alpha"])
assert "Contexte applicatif actuel" not in prompt
def test_general_prompt_agent_uses_native_tools(self):
"""BUG-053: the agent must call tools, not emit `obsigate-action` blocks."""
from backend.bookslm import build_general_system_prompt
prompt = build_general_system_prompt(["Alpha"], agent=True)
assert "create_file" in prompt
# The text-protocol example block must not be taught in agent mode.
assert '"action": "create_file"' not in prompt
assert "inclus un bloc de ce type" not in prompt
def test_general_prompt_classic_keeps_text_protocol(self):
"""The classic chat endpoint still uses the text action protocol."""
from backend.bookslm import build_general_system_prompt
prompt = build_general_system_prompt(["Alpha"])
assert '"action": "create_file"' in prompt
def test_documents_prompt_scope(self):
from backend.bookslm import build_system_prompt
@@ -899,6 +916,30 @@ class TestBooksLMAgentEndpoint:
)
assert resp.status_code == 401
def test_agent_prompt_uses_native_tools_not_text_protocol(self, bookslm_client, monkeypatch):
"""BUG-053: the agent system prompt must not teach the text protocol."""
import backend.bookslm_routes as routes
from backend.ai_chat import LLMResponse
captured = {}
async def fake_chat_completion(messages, **kwargs):
captured["system"] = messages[0]["content"]
return LLMResponse(content="ok")
monkeypatch.setattr(routes, "chat_completion", fake_chat_completion)
monkeypatch.setattr(routes, "_resolve_provider_name", lambda requested: "deepseek")
token, _ = _login_bookslm(bookslm_client)
resp = bookslm_client.post(
"/api/ai/bookslm/agent",
json={"directory": "", "message": "cree un fichier", "mode": "general"},
headers={"Authorization": f"Bearer {token}"},
)
assert resp.status_code == 200
assert "create_file" in captured["system"]
assert '"action": "create_file"' not in captured["system"]
def test_agent_tool_call_flow(self, bookslm_client, monkeypatch):
import backend.bookslm_routes as routes
from backend.ai_chat import LLMResponse, ToolCall
+72 -3
View File
@@ -33,6 +33,40 @@ def _ctx() -> ToolContext:
return ToolContext(user={"username": "tester", "vaults": []}, mode=ToolMode.IN_APP)
def _html_get(routes: dict[str, str], searxng: Any = None):
"""Dispatch httpx.get by URL marker: searxng JSON, HTML providers, else error."""
def fake_get(url, params=None, **kw):
url = str(url)
if "search.dracodev.net" in url:
if searxng is not None:
return searxng
raise web.httpx.ConnectError("searxng down")
for marker, body in routes.items():
if marker in url:
return FakeResponse(content=body.encode("utf-8"), url=url)
raise web.httpx.ConnectError(f"no route: {url}")
return fake_get
DDG_HTML = (
'<div class="result">'
'<a rel="nofollow" class="result__a" '
'href="//duckduckgo.com/l/?uddg=https%3A%2F%2Fexample.com%2Fpage&amp;rut=1">'
"Example <b>Page</b></a>"
'<a class="result__snippet" href="#">A useful snippet</a>'
"</div>"
)
BING_HTML = (
'<h2 class=""><a target="_blank" '
'href="https://www.bing.com/ck/a?u=a1aHR0cHM6Ly9leGFtcGxlLmNvbS9iaW5n&amp;ntb=1">'
"Bing <strong>Result</strong></a></h2>"
'<p class="b_lineclamp2">Bing snippet here</p>'
)
class TestRegistration:
def test_tools_registered_read_only_in_app(self):
for name in ("web_search", "fetch_url"):
@@ -58,7 +92,7 @@ class TestWebSearch:
monkeypatch.setattr(web.httpx, "get", fake_get)
out = web.web_search(_ctx(), web.WebSearchInput(query="pizza", max_results=3))
assert out["engine"] == "searxng"
assert out["provider"] == "searxng"
assert out["count"] == 3
assert len(out["results"][0]["snippet"]) <= 600
assert captured["params"]["q"] == "pizza"
@@ -70,11 +104,11 @@ class TestWebSearch:
def test_empty_result_set_warns_about_blocked_engines(self, monkeypatch):
"""An all-blocked instance answers 200 with no results: the model must
be told instead of retrying the same search until the quota burns."""
monkeypatch.setattr(web.httpx, "get", lambda *a, **kw: FakeResponse(json_data={
monkeypatch.setattr(web.httpx, "get", _html_get({}, searxng=FakeResponse(json_data={
"results": [],
"number_of_results": 0,
"unresponsive_engines": [["duckduckgo", "CAPTCHA"], ["google", "access denied"]],
}))
})))
out = web.web_search(_ctx(), web.WebSearchInput(query="meteo montreal"))
assert out["count"] == 0
assert out["unresponsive_engines"] == ["duckduckgo", "google"]
@@ -100,6 +134,41 @@ class TestWebSearch:
web.web_search(_ctx(), web.WebSearchInput(query="x"))
assert ei.value.code == "web_search_unavailable"
def test_falls_back_to_duckduckgo_when_searxng_empty(self, monkeypatch):
monkeypatch.setattr(web.httpx, "get", _html_get(
{"html.duckduckgo.com": DDG_HTML},
searxng=FakeResponse(json_data={"results": []}),
))
out = web.web_search(_ctx(), web.WebSearchInput(query="python release"))
assert out["provider"] == "duckduckgo"
assert out["count"] == 1
assert out["results"][0]["title"] == "Example Page"
assert out["results"][0]["url"] == "https://example.com/page"
assert out["results"][0]["snippet"] == "A useful snippet"
def test_falls_back_to_bing_when_searxng_unreachable(self, monkeypatch):
monkeypatch.setattr(web.httpx, "get", _html_get(
{"bing.com": BING_HTML},
searxng=None,
))
out = web.web_search(_ctx(), web.WebSearchInput(query="python release"))
assert out["provider"] == "bing"
assert out["count"] == 1
assert out["results"][0]["title"] == "Bing Result"
assert out["results"][0]["url"] == "https://example.com/bing"
assert out["results"][0]["snippet"] == "Bing snippet here"
def test_fallback_can_be_disabled(self, monkeypatch):
monkeypatch.setattr(web, "WEB_FALLBACK_ENABLED", False)
monkeypatch.setattr(web.httpx, "get", _html_get(
{"html.duckduckgo.com": DDG_HTML, "bing.com": BING_HTML},
searxng=FakeResponse(json_data={"results": []}),
))
out = web.web_search(_ctx(), web.WebSearchInput(query="python release"))
assert out["count"] == 0
assert out["provider"] == "searxng"
assert "warning" in out
class TestFetchUrl:
def test_html_converted_to_text(self, monkeypatch):