mirror of
https://github.com/danny-avila/LibreChat.git
synced 2026-06-30 11:24:09 +00:00
Some checks are pending
Docker Dev Branch Images Build / build (Dockerfile, lc-dev, node) (push) Waiting to run
Docker Dev Branch Images Build / build (Dockerfile.multi, lc-dev-api, api-build) (push) Waiting to run
GitNexus Index / index (push) Waiting to run
GitNexus Index / post-index (push) Blocked by required conditions
* 🪙 feat: Context-usage projection — data-provider + client wiring
Consumer side of the SDK-aligned context projection (agents
`projectAgentContextUsage`). Adds the `/api/endpoints/context-projection`
data-provider plumbing (endpoint, service, query key, `TContextProjectionRequest`)
and a `useContextProjectionQuery` gated to fire only when no fresh snapshot
covers the viewed branch.
Wires `useTokenUsage` precedence to: live snapshot → fresh persisted snapshot
(window matches the resolved one) → server projection → per-message estimate.
A model/window switch marks the baked snapshot stale (its `maxContextTokens`
no longer matches) and falls to the projection — closing the gauge's
window-switch (G1) and snapshot-less-branch (G2) gaps. Snapshot and projection
share the render-relevant fields, so they render uniformly.
Backend endpoint + agents version bump land in follow-up commits. Includes the
design spec (CONTEXT_PROJECTION_SPEC.md).
* 🪙 feat: Context-projection backend endpoint
POST /api/endpoints/context-projection → resolveContextProjection (packages/api):
reconstructs the viewed branch (parent-chain walk from messageId), resolves the
agent config (instructions/provider/model/maxContextTokens), reuses LibreChat's
stored per-message tokenCounts as the index map (no re-tokenizing), and calls
the agents SDK projectAgentContextUsage — no model call. Thin controller injects
db.getMessages/db.getAgent; route mirrors /token-config.
First cut targets message-windowing accuracy; tool-schema tokens are deferred to
a follow-up that reuses the full initializeAgent path.
* 🩹 fix: Codex review on context projection (G1 guard, IDOR, recount, summary)
- Guard `currentActive` against a stale window: a model/window switch on the
current branch left the live snapshot outranking the projection (G1 didn't
fire). Now defers to the projection unless streaming or the window matches.
- Scope branch lookups to the authenticated user (`getMessages` filter +
injected `userId`) — was loading any conversation by id (IDOR).
- Recount messages with no stored `tokenCount` via the tokenizer instead of
charging 0, so snapshot-less/imported histories don't under-report.
- Fall back (null) for already-summarized branches rather than projecting from
the full raw parent chain (the next call would send summary + tail); the
client's summary-baseline-aware estimate handles them until a follow-up
replays the summary boundary.
* 🩹 fix: Codex round 2 — drop agent load, summary marker, edit-invalidation
- Stop loading agent/model-spec config server-side (closes the agent-access
IDOR and the spec-prompt special-casing). Provider/model/window now come from
the client-resolved request (`limits.endpoint`/model — the agent's real
provider, not the `agents` endpoint, so the tokenizer is right). Agent/spec/
promptPrefix instructions are uniformly deferred to the full-fidelity follow-up.
- Detect summarized branches via the live path's `metadata.summaryUsedTokens`
marker (was the wrong `summaryTokenCount` field) and fall back to the
summary-aware estimate.
- Invalidate the projection query on in-place message edits via a branch
content `revision` in the cache key (the tail id is unchanged on edit).
Deferred (valid, not a regression): same-window endpoint/model switch keeps a
window-matched snapshot — needs endpoint/model persisted on the snapshot, which
lands with the fidelity follow-up. Smoke-tested: fits / prunes / summarized→null
/ no-window→null.
* 🛡️ fix: make context projection strictly additive (no-regression)
Revert the G1 window-match guard on the live/branch snapshot. When no explicit
maxContextTokens is set (the common default), the SDK's snapshot window is
reserve-derived (~0.9·(modelContext − maxOutputTokens)) while useTokenLimits
resolves the raw model context — so `snapshot.maxContextTokens === resolvedMax`
is false for the SAME model, and the guard would wrongly drop a valid
current-branch snapshot to projection/estimate post-stream (a regression in the
default case, per initialize.ts:1240-1243).
The projection now activates ONLY for snapshot-less branches (G2): the
precedence is live snapshot → persisted branch snapshot → projection → estimate,
where the first two are byte-for-byte the prior behavior and the projection just
slots ahead of the estimate. Window/model-switch (G1) detection needs the
snapshot to carry its model/window and defers to the fidelity follow-up.
* 🩹 fix: surface projections as estimates, not authoritative snapshots
A first-cut projection carries the SDK's windowing but omits instruction/tool
overhead, so rendering it as `isEstimate: false` showed a confident under-count
for snapshot-less branches. Mark projection-sourced views `isEstimate: true` +
`snapshotActive: false` (and drop the snapshot field) so they present as a
better estimate than sumBranch — improved used/window number, estimate framing,
no misleading granular breakdown with ~0 tools. Real snapshots stay
authoritative. (Codex round 3, projection.ts:139.)
* 🧹 chore: drop CONTEXT_PROJECTION_SPEC.md from the PR
* 🎨 style: fix import-sort order in projection.ts (CI sort-imports check)
* 🔧 chore: update @librechat/agents dependency to version 3.2.36 in package-lock.json and related package.json files
* chore: npm audit fix
* 🎨 style: fix import-sort order in data-service.ts (CI sort-imports check)
* 🩹 fix: drop dead calibrationRatio in projectionParams (tsc never error)
Inside the ternary, branchSnapshot is narrowed to null (the gate is
), so accessed a
property on (frontend typecheck failure). It was also dead — there is
never a snapshot to seed from in this branch — so just remove it.
* Revert "chore: npm audit fix"
This reverts commit 4cdb862d0c.
144 lines
4.5 KiB
JSON
144 lines
4.5 KiB
JSON
{
|
|
"name": "@librechat/backend",
|
|
"version": "v0.8.7-rc1",
|
|
"description": "",
|
|
"scripts": {
|
|
"start": "echo 'please run this from the root directory'",
|
|
"server-dev": "echo 'please run this from the root directory'",
|
|
"test": "cross-env NODE_ENV=test jest",
|
|
"b:test": "NODE_ENV=test bun jest",
|
|
"test:ci": "jest --ci --logHeapUsage",
|
|
"add-balance": "node ./add-balance.js",
|
|
"list-balances": "node ./list-balances.js",
|
|
"user-stats": "node ./user-stats.js",
|
|
"create-user": "node ./create-user.js",
|
|
"invite-user": "node ./invite-user.js",
|
|
"ban-user": "node ./ban-user.js",
|
|
"delete-user": "node ./delete-user.js"
|
|
},
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "git+https://github.com/danny-avila/LibreChat.git"
|
|
},
|
|
"keywords": [],
|
|
"author": "",
|
|
"license": "ISC",
|
|
"_moduleAliases": {
|
|
"~": "."
|
|
},
|
|
"imports": {
|
|
"~/*": "./*"
|
|
},
|
|
"bugs": {
|
|
"url": "https://github.com/danny-avila/LibreChat/issues"
|
|
},
|
|
"homepage": "https://librechat.ai",
|
|
"dependencies": {
|
|
"@anthropic-ai/vertex-sdk": "^0.16.0",
|
|
"@aws-sdk/client-bedrock-runtime": "^3.1013.0",
|
|
"@aws-sdk/client-cloudfront": "^3.1042.0",
|
|
"@aws-sdk/client-s3": "^3.980.0",
|
|
"@aws-sdk/cloudfront-signer": "^3.1036.0",
|
|
"@aws-sdk/credential-providers": "^3.1045.0",
|
|
"@aws-sdk/s3-request-presigner": "^3.758.0",
|
|
"@azure/identity": "^4.13.1",
|
|
"@azure/search-documents": "^12.0.0",
|
|
"@azure/storage-blob": "^12.30.0",
|
|
"@google/genai": "^2.8.0",
|
|
"@keyv/redis": "^4.3.3",
|
|
"@librechat/agents": "^3.2.36",
|
|
"@librechat/api": "*",
|
|
"@librechat/data-schemas": "*",
|
|
"@microsoft/microsoft-graph-client": "^3.0.7",
|
|
"@modelcontextprotocol/sdk": "^1.29.0",
|
|
"@node-saml/passport-saml": "^5.1.0",
|
|
"@opentelemetry/api": "^1.9.0",
|
|
"@opentelemetry/instrumentation-express": "^0.56.0",
|
|
"@opentelemetry/instrumentation-http": "^0.207.0",
|
|
"@opentelemetry/instrumentation-ioredis": "^0.55.0",
|
|
"@opentelemetry/instrumentation-mongodb": "^0.60.0",
|
|
"@opentelemetry/instrumentation-mongoose": "^0.54.0",
|
|
"@opentelemetry/instrumentation-undici": "^0.18.0",
|
|
"@opentelemetry/resources": "^2.6.1",
|
|
"@opentelemetry/sdk-node": "^0.218.0",
|
|
"@opentelemetry/semantic-conventions": "^1.39.0",
|
|
"@smithy/node-http-handler": "^4.4.5",
|
|
"ai-tokenizer": "^1.0.6",
|
|
"axios": "^1.16.0",
|
|
"bcryptjs": "^2.4.3",
|
|
"compression": "^1.8.1",
|
|
"connect-redis": "^8.1.0",
|
|
"cookie": "^0.7.2",
|
|
"cookie-parser": "^1.4.7",
|
|
"cors": "^2.8.5",
|
|
"dedent": "^1.5.3",
|
|
"dotenv": "^16.0.3",
|
|
"eventsource": "^3.0.2",
|
|
"express": "^5.2.1",
|
|
"express-mongo-sanitize": "^2.2.0",
|
|
"express-rate-limit": "^8.5.1",
|
|
"express-session": "^1.18.2",
|
|
"express-static-gzip": "^2.2.0",
|
|
"file-type": "^21.3.2",
|
|
"firebase": "^11.0.2",
|
|
"form-data": "^4.0.4",
|
|
"get-stream": "^6.0.1",
|
|
"handlebars": "^4.7.9",
|
|
"https-proxy-agent": "^7.0.6",
|
|
"ioredis": "^5.3.2",
|
|
"js-yaml": "^4.1.1",
|
|
"jsonwebtoken": "^9.0.0",
|
|
"jszip": "^3.10.1",
|
|
"jwks-rsa": "^3.2.0",
|
|
"keyv": "^5.3.2",
|
|
"keyv-file": "^5.1.2",
|
|
"klona": "^2.0.6",
|
|
"librechat-data-provider": "*",
|
|
"lodash": "^4.17.23",
|
|
"mammoth": "^1.11.0",
|
|
"mathjs": "^15.2.0",
|
|
"meilisearch": "^0.38.0",
|
|
"memorystore": "^1.6.7",
|
|
"mime": "^3.0.0",
|
|
"module-alias": "^2.2.3",
|
|
"mongodb": "^6.14.2",
|
|
"mongoose": "^8.23.1",
|
|
"multer": "^2.1.1",
|
|
"nanoid": "^3.3.7",
|
|
"node-fetch": "^2.7.0",
|
|
"nodemailer": "^8.0.5",
|
|
"ollama": "^0.5.0",
|
|
"openai": "5.8.2",
|
|
"openid-client": "^6.5.0",
|
|
"passport": "^0.6.0",
|
|
"passport-apple": "^2.0.2",
|
|
"passport-discord": "^0.1.4",
|
|
"passport-facebook": "^3.0.0",
|
|
"passport-github2": "^0.1.12",
|
|
"passport-google-oauth20": "^2.0.0",
|
|
"passport-jwt": "^4.0.1",
|
|
"passport-ldapauth": "^3.0.1",
|
|
"passport-local": "^1.0.0",
|
|
"pdfjs-dist": "^5.4.624",
|
|
"prom-client": "^15.1.3",
|
|
"rate-limit-redis": "^4.2.0",
|
|
"sanitize-html": "^2.13.0",
|
|
"sharp": "^0.33.5",
|
|
"traverse": "^0.6.7",
|
|
"ua-parser-js": "^1.0.36",
|
|
"undici": "^7.24.1",
|
|
"winston": "^3.11.0",
|
|
"winston-daily-rotate-file": "^5.0.0",
|
|
"xlsx": "https://cdn.sheetjs.com/xlsx-0.20.3/xlsx-0.20.3.tgz",
|
|
"yauzl": "^3.2.1",
|
|
"zod": "^3.22.4"
|
|
},
|
|
"devDependencies": {
|
|
"@babel/preset-env": "^7.29.5",
|
|
"@types/sanitize-html": "^2.13.0",
|
|
"jest": "^30.2.0",
|
|
"mongodb-memory-server": "^11.0.1",
|
|
"nodemon": "^3.0.3",
|
|
"supertest": "^7.1.0"
|
|
}
|
|
}
|