Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
421 commits
Select commit Hold shift + click to select a range
78bf391
feat: Add Superset plugin support and OIDC authentication integration
zhb-y-agent Apr 10, 2026
c040b8b
feat(plugins): Add plugin localization support and refactor Superset …
zhb-y-agent Apr 10, 2026
6d6e61b
feat(plugins): Add plugin localization support and refactor Superset …
zhb-y-agent Apr 10, 2026
935b548
docs(设计文档): 添加插件i18n自包含方案
zhb-y-agent Apr 10, 2026
9028faf
docs(i18n): Update translation guide to include plugin translation in…
zhb-y-agent Apr 10, 2026
eae255d
feat(auth): Add OAuth2 alias and update authentication documentation
zhb-y-agent Apr 10, 2026
eb4ebd5
docs(oidc): 补充OIDC/OAuth2 Provider对接的详细要求
zhb-y-agent Apr 10, 2026
f4d9e40
feat(plugin): Add password visibility toggle and description text for…
zhb-y-agent Apr 10, 2026
9b7c24c
feat(auth): Support manual OIDC/OAuth2 endpoint configuration and add…
zhb-y-agent Apr 10, 2026
98c83f7
feat(身份迁移): 实现匿名用户到认证用户的身份迁移功能
zhb-y-agent Apr 10, 2026
37017cc
feat(migration): Add anonymous workspace data migration functionality
zhb-y-agent Apr 10, 2026
b3bde64
fix(AuthButton): Improve logout logic to handle missing end_session_e…
zhb-y-agent Apr 10, 2026
72e2ae5
fix(identity migration): Prevent duplicate triggering of anonymous to…
zhb-y-agent Apr 10, 2026
82e916e
feat(authentication): Improve identity migration flow and local stora…
zhb-y-agent Apr 10, 2026
a122e77
feat(workspace): Improve robustness of anonymous workspace migration …
zhb-y-agent Apr 10, 2026
7b98382
feat(login): Add support for IdP-initiated SSO flow
zhb-y-agent Apr 10, 2026
de3559a
Merge pull request #289 from microsoft/feature/plugin-architecture
zhb-ai Apr 10, 2026
5142bc2
feat(auth): Add silent token refresh functionality and enhance securi…
zhb-y-agent Apr 11, 2026
c5f2ad4
fix(bug): Fix abnormal display status when canceling import
zhb-y-agent Apr 11, 2026
e2c9532
fix(IdentityMigrationDialog): Fix issue with preserving workspace dat…
zhb-y-agent Apr 11, 2026
28a526c
docs: 添加数据源插件开发指南文档
zhb-y-agent Apr 11, 2026
eac6515
eat(tables_routes): Add export table to CSV/TSV functionality
zhb-y-agent Apr 11, 2026
ec86904
feat(credential vault): Add credential vault feature to support remem…
zhb-y-agent Apr 11, 2026
67b31ff
Merge pull request #290 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
a4782b1
feat(security): 新增 ConfinedDir 路径安全原语及修复漏洞
zhb-y-agent Apr 11, 2026
0768156
feat(security): Add error message sanitization and unified error resp…
zhb-y-agent Apr 11, 2026
5374ef5
Merge pull request #291 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
ef48ebb
fix: Improve error handling logic to provide more user-friendly error…
zhb-y-agent Apr 11, 2026
3ee96c5
Merge pull request #292 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
4f65c4f
fix(security): Improve error message handling to enhance security
zhb-y-agent Apr 11, 2026
e9ae67f
Merge pull request #293 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
da60eeb
fix(security): Unify error message handling to prevent sensitive info…
zhb-y-agent Apr 11, 2026
c1f9378
Merge pull request #294 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
0cb48cc
feat(security): Add LLM error classification functionality and update…
zhb-y-agent Apr 11, 2026
4cb08c6
Merge pull request #295 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
20b9f40
docs: Add and update multiple documentation files and skills
zhb-y-agent Apr 11, 2026
28088e4
Merge pull request #296 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
d3a832b
data plugin ui plan
Chenglong-MS Apr 12, 2026
4dc82b6
Merge pull request #297 from microsoft/dev
zhb-ai Apr 12, 2026
e907c81
feat(auth): Improve OIDC/OAuth2 authentication flow and error handling
zhb-y-agent Apr 14, 2026
53dbe31
docs: Add configuration documentation and examples for Superset and D…
zhb-y-agent Apr 14, 2026
69166bd
Merge pull request #298 from microsoft/feature/plugin-architecture
zhb-ai Apr 14, 2026
2e10da7
halfway
Chenglong-MS Apr 14, 2026
86a6f6d
redesign data connector
Chenglong-MS Apr 15, 2026
a184067
updated data connector design
Chenglong-MS Apr 16, 2026
66ef7a0
cleanup
Chenglong-MS Apr 16, 2026
249f877
cleanup
Chenglong-MS Apr 16, 2026
0d31f4f
Merge remote-tracking branch 'origin/dev' into features/data-plugin-ui
Copilot Apr 16, 2026
4215765
Merge pull request #300 from microsoft/features/data-plugin-ui
Chenglong-MS Apr 16, 2026
87229d9
improvements
Chenglong-MS Apr 16, 2026
3023e7e
fix
Chenglong-MS Apr 16, 2026
f770ac1
add cosmosdb support
Chenglong-MS Apr 16, 2026
8ab7b03
Merge pull request #301 from microsoft/dev
zhb-ai Apr 16, 2026
01f0856
bug fix
Chenglong-MS Apr 16, 2026
fc80f38
haha
Chenglong-MS Apr 17, 2026
01b6d56
important agent redesign
Chenglong-MS Apr 17, 2026
bf1d79d
Merge branch 'dev' of https://github.com/IAMkecheng/data-formulator i…
IAMkecheng Apr 17, 2026
5ecbb5b
fix bugs and add test game dataset
IAMkecheng Apr 21, 2026
49169b7
new agent
Chenglong-MS Apr 22, 2026
f0a48a3
sidebar data load
Chenglong-MS Apr 22, 2026
ebc27e0
minor
Chenglong-MS Apr 22, 2026
b8793cc
fixes
Chenglong-MS Apr 22, 2026
50916b4
Update instantiate-spec.ts
IAMkecheng Apr 22, 2026
50323e5
Merge branch 'microsoft:dev' into dev
IAMkecheng Apr 22, 2026
460f496
Merge pull request #302 from IAMkecheng/dev
Chenglong-MS Apr 22, 2026
162cf9a
gallery fixes
Chenglong-MS Apr 22, 2026
3673fe9
gallery fix
Chenglong-MS Apr 22, 2026
22c9388
Merge pull request #305 from microsoft/dev
zhb-ai Apr 22, 2026
fadb7f0
Add SSO token support for auto-connection in DataConnector and Supers…
zhb-y-agent Apr 22, 2026
fe6da49
Enhance DataAgent action handling and retry logic
zhb-y-agent Apr 22, 2026
8f83094
Implement CSV streaming export functionality and enhance download UI
zhb-y-agent Apr 22, 2026
124ac0a
Enhance CSV export functionality with improved filename handling
zhb-y-agent Apr 22, 2026
d805588
docs(design-docs): 添加DataAgent工具调用过多问题的分析文档
zhb-y-agent Apr 22, 2026
4c5e4c7
Enhance internationalization support by implementing message_code pat…
zhb-y-agent Apr 22, 2026
f6bfbf0
Refactor workspace session management and enhance UI components
zhb-y-agent Apr 22, 2026
ed1aeec
Implement delete connector functionality in DataSourceSidebar
zhb-y-agent Apr 22, 2026
4d580a8
Enhance DataAgent and UI components with field display names support
zhb-y-agent Apr 22, 2026
de0d828
Enhance data table formatting and tooltip configuration
zhb-y-agent Apr 22, 2026
145ae4f
Refactor UUID generation for session IDs across components
zhb-ai Apr 23, 2026
6d42f05
Implement secure context check for OIDC authentication
zhb-ai Apr 23, 2026
e5fe11f
docs: 新增SSO门户一键登录和统一错误处理设计文档
zhb-y-agent Apr 23, 2026
9898136
docs(auth): 新增统一认证与凭证管理架构设计文档
zhb-y-agent Apr 23, 2026
530245d
docs: 新增统一错误处理机制和认证架构设计文档
zhb-y-agent Apr 23, 2026
a2da2f3
feat: Add Unified Error Handling System
zhb-y-agent Apr 23, 2026
7d1e9a6
feat: Implement automatic file upload conversion to parquet format an…
zhb-y-agent Apr 23, 2026
b4bc04b
refactor(data stream): Improve NDJSON data parsing and processing logic
zhb-y-agent Apr 23, 2026
483e7dd
fix: Improve error handling and logging
zhb-y-agent Apr 23, 2026
21146b6
docs(streaming-protocol): Add frontend-backend streaming communicatio…
zhb-y-agent Apr 23, 2026
5ef8425
Update data agent tool descriptions and enhance table context informa…
zhb-y-agent Apr 23, 2026
57c2188
feat(agent): Add execution code purpose description and optimize thin…
zhb-y-agent Apr 23, 2026
025175f
Merge pull request #306 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
17094ec
feat(logging): Implement log sanitization to protect sensitive data
zhb-ai Apr 24, 2026
a32b372
docs(error-handling): Update error handling skill documentation and a…
zhb-ai Apr 24, 2026
c2372b2
docs: change name
zhb-ai Apr 24, 2026
4a88355
refactor(error-handling): Enhance error handling in DataConnector and…
zhb-ai Apr 24, 2026
4d34059
add doc
zhb-ai Apr 24, 2026
29f0dc4
Merge pull request #307 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
ebc63bf
update doc
zhb-y-agent Apr 24, 2026
0a3bc67
Merge branch 'feature/plugin-architecture' of https://github.com/micr…
zhb-y-agent Apr 24, 2026
fc23f4b
docs: Update documentation and skill descriptions
zhb-y-agent Apr 24, 2026
ae00939
refactor(workspace): Change default workspace name from 'default' to …
zhb-y-agent Apr 24, 2026
1bcd07b
feat(security): Implement safety checks and deployment restrictions
zhb-y-agent Apr 24, 2026
a9bbcf7
docs: Update path security related documentation and test instructions
zhb-y-agent Apr 24, 2026
fad5065
docs: Add test-driven development workflow documentation
zhb-y-agent Apr 24, 2026
5fe5754
fix: Unify error handling protocol, all application errors return HTT…
zhb-y-agent Apr 24, 2026
0eb4149
fix(security): Enhance path security checks and modify workspace crea…
zhb-y-agent Apr 24, 2026
fa0c7ce
fix(security): Enhance security for error handling and path validation
zhb-y-agent Apr 24, 2026
100fe14
fix(tests): Update test cases to match latest implementation
zhb-y-agent Apr 24, 2026
cd9fe9d
Merge pull request #309 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
cb4578c
feat: Support backend OIDC authentication mode with TokenStore integr…
zhb-y-agent Apr 24, 2026
7204f2a
feat(data source sidebar): Add smart filters and table search functio…
zhb-y-agent Apr 24, 2026
0f26231
feat(data source): Enhance data preview and filtering functionality
zhb-y-agent Apr 24, 2026
a424860
Merge pull request #310 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
6b97b59
feat(data connector): Add column value query API to support smart fil…
zhb-y-agent Apr 24, 2026
5bd1f58
Merge pull request #311 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
b31656a
refactor(auth): Refactor OIDC authentication mode auto-detection logic
zhb-y-agent Apr 25, 2026
116bf06
feat(data preview): Add connector table preview component and integra…
zhb-y-agent Apr 25, 2026
5d3a976
docs: Add server migration guide documentation
zhb-y-agent Apr 25, 2026
b55cbd9
test(conftest): Add environment isolation fixtures to prevent test po…
zhb-y-agent Apr 25, 2026
6b7c341
feat(connection management): Add disconnect functionality
zhb-y-agent Apr 25, 2026
d18bc6d
fix: Ensure user identity information fields are string type
zhb-y-agent Apr 25, 2026
e16391f
refactor(i18n): Remove unused "disconnect" translation strings
zhb-y-agent Apr 25, 2026
88637e5
fix(i18n): Update connector preview text and layout
zhb-y-agent Apr 25, 2026
f9c77fc
feat(connector): implement lazy loading catalog and large directory p…
zhb-y-agent Apr 25, 2026
1fba24c
feat(connector): implement identity-isolated connector management mec…
zhb-y-agent Apr 25, 2026
087ef8e
docs: add implementation review checklist document
zhb-y-agent Apr 25, 2026
f6403c5
feat(connector): implement connector disconnect and SSO auto-reconnec…
zhb-y-agent Apr 25, 2026
d7b55a7
Merge pull request #312 from microsoft/feature/plugin-architecture
zhb-ai Apr 25, 2026
be970de
feat(connector): add catalog search functionality
zhb-y-agent Apr 25, 2026
9736eda
Merge pull request #313 from microsoft/feature/plugin-architecture
zhb-ai Apr 25, 2026
31a3a2b
docs: migrate design documents to dev-guides user docs and skills, up…
zhb-y-agent Apr 25, 2026
1cfdaa6
Merge pull request #314 from microsoft/feature/plugin-architecture
zhb-ai Apr 25, 2026
f4de05b
feat(i18n): add row limit warning messages
zhb-y-agent Apr 26, 2026
ababff3
feat(workspace): add lightweight metadata update and list change noti…
zhb-y-agent Apr 26, 2026
49d6fc2
fix(connection error handling): improve connection error message extr…
zhb-y-agent Apr 26, 2026
4b4f592
feat(agent): add reasoning log and knowledge system features
zhb-y-agent Apr 26, 2026
89359d2
feat(workspace): 添加对遗留工作区的自动修复支持
zhb-y-agent Apr 26, 2026
665b3ee
feat(data source): enhance table structure and column description met…
zhb-y-agent Apr 26, 2026
6c09a65
Merge pull request #315 from microsoft/feature/plugin-architecture
zhb-ai Apr 26, 2026
0d193cb
docs: update design documents and add user isolation defense-in-depth…
zhb-y-agent Apr 26, 2026
5e296e3
feat(DataAgent): add reasoning log recording functionality
zhb-y-agent Apr 26, 2026
90343dd
feat(knowledge): implement knowledge management backend functionality
zhb-y-agent Apr 26, 2026
02bdf0e
feat(knowledge system): implement knowledge base integration and expe…
zhb-y-agent Apr 27, 2026
3200934
fix: increase default formulateTimeoutSeconds from 60s to 180s
zhb-y-agent Apr 27, 2026
f9b7443
feat(i18n): add request timeout related error messages
zhb-y-agent Apr 27, 2026
021b480
chore: update .gitignore and remove .vscode/settings.json
zhb-ai Apr 27, 2026
8d30313
feat(logging): refactor ReasoningLogger and ExperienceDistillAgent fo…
zhb-ai Apr 27, 2026
ed5f36e
feat(datetime): establish unified datetime type system and enhance fr…
zhb-ai Apr 27, 2026
5f5ceb0
feat(knowledge): enhance knowledge rules management and introduce limits
zhb-ai Apr 27, 2026
d875252
feat: add date-time type system support
zhb-y-agent Apr 27, 2026
d1f1fdc
fix(experience save): only show save button on final leaf table and c…
zhb-y-agent Apr 27, 2026
a324c06
feat(data display): adjust number formatting based on semantic type
zhb-y-agent Apr 27, 2026
63245d4
feat(knowledge management): improve experience distillation and knowl…
zhb-y-agent Apr 27, 2026
5518355
docs: update multiple development guides and design documents
zhb-y-agent Apr 27, 2026
7091334
feat: add column description support and optimize catalog tree perfor…
zhb-y-agent Apr 27, 2026
4569dd0
feat(knowledge): add type-safe KnowledgeItemMeta class for frontend m…
zhb-y-agent Apr 27, 2026
1bc3294
feat(model support): add vision model support detection functionality
zhb-y-agent Apr 27, 2026
b1e6ad8
feat(recommended questions): add AI generation progress indicator and…
zhb-y-agent Apr 27, 2026
6165adc
docs(agent-knowledge): update design document for reasoning log conte…
zhb-y-agent Apr 27, 2026
1ccac0b
Merge pull request #316 from microsoft/feature/plugin-architecture
zhb-ai Apr 27, 2026
32cd9f4
docs(metadata): design-docs update
zhb-ai Apr 28, 2026
799e6a1
docs: add reference note for development guide 11
zhb-y-agent Apr 28, 2026
25a6bc7
docs: add incremental development rhythm rules document
zhb-y-agent Apr 28, 2026
efac99a
feat(catalog metadata): add catalog metadata synchronization and anno…
zhb-y-agent Apr 28, 2026
82d91b9
feat(catalog): add catalog sync status messages and internationalizat…
zhb-y-agent Apr 28, 2026
bab11ec
refactor(UI): optimize scrollbar styles and add resizable sidebar wid…
zhb-y-agent Apr 28, 2026
342c512
fix(MessageSnackbar): remove unused WarningIcon and use ErrorOutlineI…
zhb-y-agent Apr 28, 2026
dceb4de
feat(interaction strategy): add auto-selection and auto-focus strategies
zhb-y-agent Apr 28, 2026
915c31d
Merge pull request #317 from microsoft/feature/plugin-architecture
zhb-ai Apr 28, 2026
a8efcdb
feat(i18n): add new translations for common actions and enhance exist…
zhb-ai Apr 29, 2026
b5678e3
feat(reporting): enhance report export functionality with image and P…
zhb-ai Apr 29, 2026
2df2c6f
Merge pull request #318 from microsoft/feature/plugin-architecture
zhb-ai Apr 29, 2026
fcb3b3e
feat(clariifcation): implement structured clarification questions and…
zhb-ai Apr 29, 2026
28dd961
Merge pull request #319 from microsoft/feature/plugin-architecture
zhb-ai Apr 29, 2026
85b518b
feat(insight): unify chart insight error handling and timeout configu…
zhb-y-agent Apr 29, 2026
4455d3d
WIP: archive incomplete phase work
zhb-y-agent Apr 30, 2026
59d09e1
feat(error-handling): standardize API error responses and improve err…
zhb-ai Apr 30, 2026
a2efeca
feat(workspace): rename workspace summary endpoint and update naming …
zhb-ai Apr 30, 2026
1630543
feat(error-handling): enhance connector error classification and resp…
zhb-ai Apr 30, 2026
a0340cb
docs: conclude current phase work and update documentation
zhb-y-agent Apr 30, 2026
b92ae9d
feat(frontend state management): implement explicit loading state model
zhb-y-agent Apr 30, 2026
48df290
fix(dfSlice): remove frontend hardcoded timeout and update related do…
zhb-y-agent Apr 30, 2026
4b53bce
feat(i18n): add error messages for model loading failures
zhb-y-agent Apr 30, 2026
55ee4b3
feat(knowledge base): improve experience distillation user experience
zhb-y-agent Apr 30, 2026
59ff27a
feat(catalog tree): optimize virtualization rendering and catalog fet…
zhb-y-agent Apr 30, 2026
e0690ae
fix: fix data catalog tree building and frontend table annotation fet…
zhb-y-agent Apr 30, 2026
53f8859
feat(sandbox): implement cross-call namespace persistent SandboxSession
zhb-y-agent Apr 30, 2026
9393d53
Merge pull request #322 from microsoft/feature/plugin-architecture
zhb-ai Apr 30, 2026
283fd39
fix(security): prevent directory traversal and XSS attacks
zhb-y-agent Apr 30, 2026
7fd637a
refactor: remove type annotations for legacy Python compatibility
zhb-y-agent Apr 30, 2026
464abd5
Merge pull request #323 from microsoft/feature/plugin-architecture
zhb-ai Apr 30, 2026
b18e3cf
fix(security): enhance error handling and sensitive information filte…
zhb-y-agent May 1, 2026
2d4b220
feat(error handling): add error message sanitization and streaming wa…
zhb-y-agent May 1, 2026
6ecdda4
feat(auth): enhance SSO integration security and test coverage
zhb-y-agent May 1, 2026
e9710be
feat(测试): 添加统一docker-compose测试服务和PowerShell管理脚本
zhb-y-agent May 1, 2026
4251221
Merge pull request #324 from microsoft/feature/plugin-architecture
zhb-ai May 1, 2026
aa6ae38
fix(security): enhance log desensitization functionality to support s…
zhb-y-agent May 1, 2026
92ab564
Merge pull request #325 from microsoft/feature/plugin-architecture
zhb-ai May 1, 2026
c52c5da
feat(reasoning_log): add automatic log rotation by date functionality
zhb-y-agent May 1, 2026
fe596c6
docs(knowledge system): add 15.3 knowledge injection and search plann…
zhb-y-agent May 1, 2026
0d34057
feat(元数据同步): 增强目录元数据同步与展示功能
zhb-y-agent May 2, 2026
563e5e7
feat(agents): enhance metadata display with verbose_name and expressi…
zhb-y-agent May 2, 2026
9dcc45b
Merge pull request #326 from microsoft/feature/plugin-architecture
zhb-ai May 2, 2026
58567c8
feat(data loader): add sorting functionality to Superset data loader
zhb-y-agent May 2, 2026
048970f
docs(design-docs): add data loader sorting consistency and identifier…
zhb-y-agent May 2, 2026
1fbe1b2
Merge pull request #327 from microsoft/feature/plugin-architecture
zhb-ai May 2, 2026
37a8661
feat(knowledge system): merge skills and experiences directories into…
zhb-y-agent May 3, 2026
b9d1e64
refactor(knowledge): merge skills and experiences directories into ex…
zhb-y-agent May 3, 2026
2244e46
feat(knowledge distillation): add timeout parameter support for exper…
zhb-y-agent May 3, 2026
93d0369
refactor(knowledge): unify rule injection logic and improve search al…
zhb-y-agent May 3, 2026
e88d282
docs: update document content and structure
zhb-y-agent May 3, 2026
bd04e74
feat(i18n): add Agent log related translations and feature support
zhb-y-agent May 3, 2026
6a9740e
Merge pull request #328 from microsoft/feature/plugin-architecture
zhb-ai May 3, 2026
76330e6
feat(data loading): add AI data assistant functionality and multi-tab…
zhb-y-agent May 4, 2026
db3e4f0
Merge pull request #329 from microsoft/feature/plugin-architecture
zhb-ai May 4, 2026
b948eb3
feat(table): implement pagination and sorting functionality
zhb-y-agent May 5, 2026
6dc04b8
feat: unify data loading row limit and remove frontend row selector
zhb-y-agent May 5, 2026
3a56fae
docs: unify data loading row limit documentation
zhb-y-agent May 5, 2026
45db677
Merge pull request #330 from microsoft/feature/plugin-architecture
zhb-ai May 5, 2026
8be51ae
refactor(data loading): remove rowLimit related code
zhb-y-agent May 5, 2026
7aeef6a
Merge pull request #331 from microsoft/feature/plugin-architecture
zhb-ai May 5, 2026
ea94d8d
update experienes
Chenglong-MS May 6, 2026
79d6707
updates
Chenglong-MS May 7, 2026
1de1328
minor
Chenglong-MS May 7, 2026
d23e85c
refactor(data loading): enhance column metadata handling in SupersetL…
zhb-y-agent May 7, 2026
6c15da2
docs: update SSO OAuth configuration guide and example files
zhb-y-agent May 8, 2026
6d8185a
feat(data loading): update to use Chart Data API for data retrieval
zhb-y-agent May 8, 2026
c3b44e7
clarify+explain
Chenglong-MS May 8, 2026
99c4650
fix some issues with long thread break
Chenglong-MS May 9, 2026
f0975a5
feat(error handling): enhance error message extraction for RTK serial…
zhb-y-agent May 9, 2026
6534fa1
Merge branch 'dev' into feature/plugin-architecture
zhb-ai May 9, 2026
0557b4c
Merge pull request #334 from microsoft/feature/plugin-architecture
zhb-ai May 9, 2026
2e367fc
feat(data loading): add support for temporal column conversion in Sup…
zhb-y-agent May 9, 2026
31b469e
language
Chenglong-MS May 9, 2026
529b545
clarification module update
Chenglong-MS May 9, 2026
2a68c16
update layout algorithm
Chenglong-MS May 9, 2026
5b4aeda
minor
Chenglong-MS May 10, 2026
ca7c5e7
feat(superset): enhance list_tables to include full column metadata v…
zhb-y-agent May 10, 2026
f53b971
fix
Chenglong-MS May 10, 2026
3fa2390
issues: SSO登录态不一致及退出未清空状态问题
zhb-y-agent May 10, 2026
cd2afd4
fixes
Chenglong-MS May 10, 2026
573e6b6
more flexible editing
Chenglong-MS May 11, 2026
45387ea
styling hint
Chenglong-MS May 11, 2026
139b7eb
restyle agent update
Chenglong-MS May 11, 2026
b767bac
ISSUE : refactor agent styling for improved consistency
zhb-y-agent May 11, 2026
b5a71d0
fix ollama issue
Chenglong-MS May 11, 2026
42f0251
some polishment
Chenglong-MS May 11, 2026
9cc1d96
message
Chenglong-MS May 12, 2026
7b436ef
hide issues from main
Chenglong-MS May 12, 2026
3d1a783
remove old design docs
Chenglong-MS May 12, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
fix(security): enhance error handling and sensitive information filte…
…ring

- Add safe path check function to prevent open redirects
- Improve error message handling, filter sensitive information and stack traces
- Implement unified secure error responses in Docker sandbox and agents
- Add test cases to verify security filtering functionality
  • Loading branch information
zhb-y-agent committed May 1, 2026
commit b18e3cfb2775096308faa7edb94ac017125381c9
18 changes: 15 additions & 3 deletions docs-cn/config-examples/superset/oauth_config.py
Original file line number Diff line number Diff line change
Expand Up @@ -250,12 +250,24 @@ def _validate_origin(cls, raw):
origin = cls._normalise_origin(raw)
return origin if origin in cls._allowed_origins() else ""

@staticmethod
def _safe_next_path(raw_path):
"""只允许站内相对路径进入 login next 参数。"""
next_path = (raw_path or "/").rstrip("?").replace("\\", "/")
parsed = urlparse(next_path)
if (
not next_path.startswith("/")
or next_path.startswith("//")
or parsed.scheme
or parsed.netloc
):
return "/"
return next_path

@expose("/", methods=["GET"])
def df_sso_bridge(self):
if not self._is_real_logged_in_user():
next_url = request.full_path.rstrip("?")
if not next_url.startswith("/"):
next_url = "/"
next_url = self._safe_next_path(request.full_path)
return redirect(f"/login/?next={quote(next_url)}")
Comment thread Fixed
Comment thread Fixed

df_origin = self._validate_origin(request.args.get("df_origin"))
Expand Down
36 changes: 25 additions & 11 deletions py-src/data_formulator/agents/agent_data_rec.py
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@

from data_formulator.agents.agent_utils import extract_json_objects, extract_code_from_gpt_response, generate_data_summary, supplement_missing_block, ensure_output_variable_in_code
from data_formulator.agents.agent_diagnostics import AgentDiagnostics
from data_formulator.security.sanitize import sanitize_error_message

import traceback
import pandas as pd

import logging
Expand Down Expand Up @@ -254,8 +254,10 @@ def process_gpt_response(self, input_tables, messages, response, t_llm=None):
t_exec_total = 0.0

if isinstance(response, Exception):
result = {'status': 'other error', 'content': str(response.body),
'diagnostics': self._diag.for_error(messages, error=str(response.body))}
raw_error = str(getattr(response, "body", response))
safe_error = sanitize_error_message(raw_error)
result = {'status': 'other error', 'content': safe_error,
'diagnostics': self._diag.for_error(messages, error=safe_error)}
return [result]

candidates = []
Expand Down Expand Up @@ -337,9 +339,18 @@ def process_gpt_response(self, input_tables, messages, response, t_llm=None):
)
t_exec_total += time.time() - t_exec_start

if execution_result['status'] != 'ok':
diagnostics = execution_result.get("diagnostics", {})
raw_exec_error = diagnostics.get(
"safe_detail",
execution_result.get('content', execution_result.get('error_message', 'Unknown error')),
)
safe_exec_error = sanitize_error_message(raw_exec_error)
else:
safe_exec_error = None
_diag_exec = {
"status": execution_result['status'],
"error_message": execution_result.get('content') if execution_result['status'] != 'ok' else None,
"error_message": safe_exec_error,
"available_dataframes": execution_result.get('df_names', []),
}

Expand Down Expand Up @@ -368,19 +379,22 @@ def process_gpt_response(self, input_tables, messages, response, t_llm=None):
},
}
else:
error_message = execution_result.get('content', execution_result.get('error_message', 'Unknown error'))
result = {
'status': 'error',
'code': code,
'content': error_message
'content': safe_exec_error or 'Unknown error'
}

except Exception as e:
logger.warning('Error occurred during code execution:')
error_message = traceback.format_exc()
logger.warning(error_message)
result = {'status': 'other error', 'code': code, 'content': f"Unexpected error: {error_message}", 'content_code': 'agent.unexpectedError'}
_diag_exec = {"status": "exception", "error_message": str(e)}
logger.exception('Error occurred during code execution')
safe_error = sanitize_error_message(f"{type(e).__name__}: {e}")
result = {
'status': 'other error',
'code': code,
'content': "Unexpected error during code execution.",
'content_code': 'agent.unexpectedError'
}
_diag_exec = {"status": "exception", "error_message": safe_error}
else:
result = {'status': 'error', 'code': "", 'content': "No code block found in the response. The model is unable to generate code to complete the task.", 'content_code': 'agent.noCodeBlock'}

Expand Down
33 changes: 24 additions & 9 deletions py-src/data_formulator/agents/agent_data_transform.py
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@

from data_formulator.agents.agent_utils import extract_json_objects, extract_code_from_gpt_response, supplement_missing_block, ensure_output_variable_in_code
from data_formulator.agents.agent_diagnostics import AgentDiagnostics
from data_formulator.security.sanitize import sanitize_error_message
from data_formulator.agents.agent_data_rec import (
SHARED_ENVIRONMENT,
SHARED_SEMANTIC_TYPE_REFERENCE,
Expand Down Expand Up @@ -156,8 +157,10 @@ def process_gpt_response(self, response, messages, t_llm=None):
t_exec_total = 0.0

if isinstance(response, Exception):
result = {'status': 'other error', 'content': str(response.body),
'diagnostics': self._diag.for_error(messages, error=str(response.body))}
raw_error = str(getattr(response, "body", response))
safe_error = sanitize_error_message(raw_error)
result = {'status': 'other error', 'content': safe_error,
'diagnostics': self._diag.for_error(messages, error=safe_error)}
return [result]

candidates = []
Expand Down Expand Up @@ -237,9 +240,18 @@ def process_gpt_response(self, response, messages, t_llm=None):
)
t_exec_total += time.time() - t_exec_start

if execution_result['status'] != 'ok':
diagnostics = execution_result.get("diagnostics", {})
raw_exec_error = diagnostics.get(
"safe_detail",
execution_result.get('content', execution_result.get('error_message', 'Unknown error')),
)
safe_exec_error = sanitize_error_message(raw_exec_error)
else:
safe_exec_error = None
_diag_exec = {
"status": execution_result['status'],
"error_message": execution_result.get('content') if execution_result['status'] != 'ok' else None,
"error_message": safe_exec_error,
"available_dataframes": execution_result.get('df_names', []),
}

Expand Down Expand Up @@ -271,15 +283,18 @@ def process_gpt_response(self, response, messages, t_llm=None):
result = {
'status': 'error',
'code': code,
'content': execution_result['content']
'content': safe_exec_error or 'Unknown error'
}

except Exception as e:
logger.warning('Error occurred during code execution:')
logger.warning(f"Error type: {type(e).__name__}, message: {str(e)}")
error_message = f"An error occurred during code execution. Error type: {type(e).__name__}, message: {str(e)}"
result = {'status': 'error', 'code': code, 'content': error_message}
_diag_exec = {"status": "exception", "error_message": str(e)}
logger.exception('Error occurred during code execution')
safe_error = sanitize_error_message(f"{type(e).__name__}: {e}")
result = {
'status': 'error',
'code': code,
'content': "An error occurred during code execution."
}
_diag_exec = {"status": "exception", "error_message": safe_error}

else:
result = {'status': 'error', 'code': "", 'content': "No code block found in the response. The model is unable to generate code to complete the task.", 'content_code': 'agent.noCodeBlock'}
Expand Down
38 changes: 26 additions & 12 deletions py-src/data_formulator/sandbox/docker_sandbox.py
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@
import pandas as pd

from data_formulator.datalake.parquet_utils import safe_data_filename
from data_formulator.security.sanitize import sanitize_error_message
from .base import Sandbox

logger = logging.getLogger(__name__)
Expand All @@ -35,6 +36,15 @@
DEFAULT_TIMEOUT = int(os.environ.get("DOCKER_SANDBOX_TIMEOUT", "120"))


def _safe_error_response(content, detail=None):
response = {"status": "error", "content": content}
if detail:
safe_detail = sanitize_error_message(detail)
if safe_detail:
response["diagnostics"] = {"safe_detail": safe_detail}
return response


class DockerSandbox(Sandbox):
"""Execute Python code inside a Docker container.

Expand Down Expand Up @@ -179,22 +189,25 @@ def run_python_code(
),
}
except Exception as exc:
logger.exception("Failed to start Docker container")
self._cleanup(tmpdir)
return {
"status": "error",
"content": f"Failed to start Docker container: {exc}",
}
return _safe_error_response(
"Failed to start Docker container.",
f"{type(exc).__name__}: {exc}",
)

stdout = proc.stdout or ""
stderr = proc.stderr or ""

if proc.returncode != 0 or "__DOCKER_SANDBOX_OK__" not in stdout:
self._cleanup(tmpdir)
err_detail = stderr.strip() or stdout.strip() or "Unknown error"
return {
"status": "error",
"content": f"Docker sandbox execution failed:\n{err_detail}",
}
logger.error("Docker sandbox execution failed: %s", err_detail)
safe_detail = sanitize_error_message(err_detail)
return _safe_error_response(
safe_detail or "Docker sandbox execution failed.",
safe_detail,
)

# ---- read back output ---------------------------------------------
# Defensive: ensure the filename stays inside output_dir even if
Expand Down Expand Up @@ -226,11 +239,12 @@ def run_python_code(
try:
output_df = pd.read_parquet(parquet_out)
except Exception as exc:
logger.exception("Failed to read output parquet")
self._cleanup(tmpdir)
return {
"status": "error",
"content": f"Failed to read output parquet: {exc}",
}
return _safe_error_response(
"Failed to read output parquet.",
f"{type(exc).__name__}: {exc}",
)

self._cleanup(tmpdir)
return {"status": "ok", "content": output_df}
Expand Down
26 changes: 23 additions & 3 deletions py-src/data_formulator/security/sanitize.py
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,26 @@
_GENERIC_502 = "Upstream service unavailable"
_GENERIC_4XX = "Bad request"


def _extract_traceback_summary(message: str) -> str:
"""Return the final exception line from a Python traceback when possible."""
if "Traceback (most recent call last):" not in message:
return message

for line in reversed(message.splitlines()):
stripped = line.strip()
if not stripped:
continue
if stripped.startswith("Traceback (most recent call last):"):
continue
if stripped.startswith("File "):
continue
if stripped.startswith("^"):
continue
if re.match(r"^[\w.]+(?:Error|Exception|Warning|Interrupt|Exit)\b", stripped):
return stripped
return ""

_HTTP_CLIENT_MESSAGES: dict[int, str] = {
400: "Bad request",
401: "Authentication required",
Expand Down Expand Up @@ -151,11 +171,11 @@ def sanitize_error_message(error_message: str) -> str:
summary is returned to the browser.
"""
# Cap input length first to prevent ReDoS on crafted payloads.
message = html.escape(error_message[:2000])
message = html.escape(_extract_traceback_summary(error_message[:2000]))

# Remove API keys / tokens
# Remove credentials and tokens from key=value-style messages.
message = re.sub(
r'(api[-_]?key|api[-_]?token)[=:]\s*[^\s&]+',
r'(api[-_]?key|api[-_]?token|access[-_]?token|refresh[-_]?token|token|password|passwd|pwd|secret|client[-_]?secret|connection[-_]?string)[=:]\s*[^\s&]+',
r'\1=<redacted>', message, flags=re.IGNORECASE,
)

Expand Down
66 changes: 66 additions & 0 deletions tests/backend/routes/test_agent_diagnostics_wiring.py
Original file line number Diff line number Diff line change
Expand Up @@ -122,6 +122,39 @@ def test_exception_response_has_error_diagnostics(self) -> None:
assert diag["agent"] == "DataRecAgent"
assert diag["error"] == "rate limit"

@patch("data_formulator.agents.agent_data_rec.supplement_missing_block")
@patch("data_formulator.sandbox.create_sandbox")
def test_execution_exception_diagnostics_are_sanitized(self, mock_sandbox_factory, mock_supplement) -> None:
mock_supplement.return_value = (
{"chart_type": "Bar Chart", "output_variable": "result_df"},
["result_df = pd.DataFrame({'x':[1]})"],
None,
0.0,
)
import pandas as pd
mock_sandbox = MagicMock()
mock_sandbox.run_python_code.return_value = {
"status": "ok",
"content": pd.DataFrame({"x": [1]}),
}
mock_sandbox_factory.return_value = mock_sandbox

agent = self._make_agent()
agent.workspace.write_parquet.side_effect = RuntimeError(
r"boom C:\Users\dev\secret.txt token=secret-token"
)
response = _make_llm_response(LLM_CONTENT_WITH_JSON_AND_CODE)
messages = [{"role": "system", "content": "sys"}, {"role": "user", "content": "q"}]

candidate = agent.process_gpt_response([], messages, response)[0]

assert candidate["content"] == "Unexpected error during code execution."
exec_error = candidate["diagnostics"]["execution"]["error_message"]
assert "RuntimeError" in exec_error
assert "Traceback" not in exec_error
assert r"C:\Users\dev" not in exec_error
assert "secret-token" not in exec_error


# ---------------------------------------------------------------------------
# DataTransformationAgent
Expand Down Expand Up @@ -182,6 +215,39 @@ def test_exception_response_has_error_diagnostics(self) -> None:
assert diag["agent"] == "DataTransformationAgent"
assert diag["error"] == "server error"

@patch("data_formulator.agents.agent_data_transform.supplement_missing_block")
@patch("data_formulator.sandbox.create_sandbox")
def test_execution_exception_diagnostics_are_sanitized(self, mock_sandbox_factory, mock_supplement) -> None:
mock_supplement.return_value = (
{"chart_type": "Bar Chart", "output_variable": "result_df"},
["result_df = pd.DataFrame({'x':[1]})"],
None,
0.0,
)
import pandas as pd
mock_sandbox = MagicMock()
mock_sandbox.run_python_code.return_value = {
"status": "ok",
"content": pd.DataFrame({"x": [1]}),
}
mock_sandbox_factory.return_value = mock_sandbox

agent = self._make_agent()
agent.workspace.write_parquet.side_effect = RuntimeError(
r"boom /tmp/workspace/secret.txt token=secret-token"
)
response = _make_llm_response(LLM_CONTENT_WITH_JSON_AND_CODE)
messages = [{"role": "system", "content": "sys"}, {"role": "user", "content": "q"}]

candidate = agent.process_gpt_response(response, messages)[0]

assert candidate["content"] == "An error occurred during code execution."
exec_error = candidate["diagnostics"]["execution"]["error_message"]
assert "RuntimeError" in exec_error
assert "Traceback" not in exec_error
assert "/tmp/workspace" not in exec_error
assert "secret-token" not in exec_error


# ---------------------------------------------------------------------------
# DataLoadAgent
Expand Down
Loading