### 亮点
- Lobster 可选插件工具,用于类型化工作流 + 审批门控。[文档](https://docs.clawd.bot/tools/lobster)
- 控制 UI 中的自定义助手身份 + 头像。[文档](https://docs.clawd.bot/cli/agents) [文档](https://docs.clawd.bot/web/control-ui)
- 缓存优化:缓存 TTL 清理 + 默认设置减少冷请求的令牌消耗。[文档](https://docs.clawd.bot/concepts/session-pruning)
- Exec 审批 + 提升的 ask/full 模式。[文档](https://docs.clawd.bot/tools/exec-approvals) [文档](https://docs.clawd.bot/tools/elevated)
- Signal 输入状态/已读回执 + MSTeams 附件。[文档](https://docs.clawd.bot/channels/signal) [文档](https://docs.clawd.bot/channels/msteams)
- `/models` 用户体验更新 + `clawdbot update wizard`。[文档](https://docs.clawd.bot/cli/models) [文档](https://docs.clawd.bot/cli/update)
### 变更
- 亮点:用于类型化工作流 + 审批门控的 Lobster 可选插件工具。[文档](https://docs.clawd.bot/tools/lobster) (#1152) 感谢 @vignesh07。
- 代理/UI:添加身份头像配置支持和控制 UI 头像渲染。(#1329, #1424) 感谢 @dlauer。[文档](https://docs.clawd.bot/gateway/configuration) [文档](https://docs.clawd.bot/cli/agents)
- 控制 UI:添加自定义助手身份支持和按会话身份显示。(#1420) 感谢 @robbyczgw-cla。[文档](https://docs.clawd.bot/web/control-ui)
- CLI:添加 `clawdbot update wizard`,包含交互式频道选择 + 重启提示,以及在变基前的预检检查。[文档](https://docs.clawd.bot/cli/update)
- 模型/命令:添加 `/models`,改进 `/model` 列表用户体验,并扩展 `clawdbot models` 分页。(#1398) 感谢 @vignesh07。[文档](https://docs.clawd.bot/cli/models)
- CLI:将网关服务命令移至 `clawdbot gateway` 下,将节点服务命令扁平化至 `clawdbot node` 下,并添加 `gateway probe` 用于可达性检查。[文档](https://docs.clawd.bot/cli/gateway) [文档](https://docs.clawd.bot/cli/node)
- Exec:添加提升的 ask/full 模式,收紧允许列表门控,并在写入时渲染审批表格。[文档](https://docs.clawd.bot/tools/elevated) [文档](https://docs.clawd.bot/tools/exec-approvals)
- Exec 审批:默认使用本地主机,添加网关/节点目标 + 目标详情,支持通配符代理允许列表,并收紧允许列表解析/安全二进制文件。[文档](https://docs.clawd.bot/cli/approvals) [文档](https://docs.clawd.bot/tools/exec-approvals)
- 心跳:允许显式会话密钥和活动时间。(#1256) 感谢 @zknicker。[文档](https://docs.clawd.bot/gateway/heartbeat)
- 会话:通过 `sessions.channelIdleMinutes` 添加按频道的空闲时长。(#1353) 感谢 @cash-echo-bot。
- 节点:以 exec 风格运行,在状态/描述中暴露 PATH,并为节点主机执行引导 PATH。[文档](https://docs.clawd.bot/cli/node)
- 缓存:添加 `cache.ttlPrune` 模式和针对缓存 TTL 行为的身份验证感知默认值。
- 队列:为自动回复添加按频道的防抖覆盖。[文档](https://docs.clawd.bot/concepts/queue)
- Discord:添加通配符频道配置支持。(#1334) 感谢 @pvoo。[文档](https://docs.clawd.bot/channels/discord)
- Signal:通过 signal-cli 添加输入状态指示器和私信已读回执。[文档](https://docs.clawd.bot/channels/signal)
- MSTeams:添加文件上传、自适应卡片和附件处理改进。(#1410) 感谢 @Evizero。[文档](https://docs.clawd.bot/channels/msteams)
- 入门:移除运行 setup-token 身份验证选项(改为粘贴 setup-token 或重用 CLI 凭据)。
- macOS:更新设置(权限中的位置访问、菜单中的连接模式,移除 CLI 安装 UI)。
- 诊断:添加用于调试的缓存跟踪配置。(#1370) 感谢 @parubets。
- 文档:Lobster 指南 + 组织 URL 更新,/model 允许列表故障排除,Gmail 消息搜索示例,gateway.mode 故障排除,提示注入指南,npm 前缀/node CLI 说明,控制 UI 开发 gatewayUrl 说明,tool_use 常见问题解答,展示视频,以及 sharp/node-gyp 解决方法。(#1427, #1220, #1405) 感谢 @vignesh07, @mbelinky。
### 重大变更
- **重大变更:** 控制 UI 现在默认拒绝没有设备身份的不安全 HTTP。使用 HTTPS(Tailscale Serve)或设置 `gateway.controlUi.allowInsecureAuth: true` 以允许仅令牌身份验证。[文档](https://docs.clawd.bot/web/control-ui#insecure-http)
- **重大变更:** 信封和系统事件时间戳现在默认为主机本地时间(原为 UTC),因此代理无需不断转换。
### 修复
- 流式传输/输入状态/媒体:在流式传输块之间保留回复标签,在运行开始时启动输入状态指示器,并接受带有空格/波浪号的 MEDIA 路径,同时优先使用消息工具提示进行图像回复。
- 代理/提供商:为 Claude 模型(Google Antigravity)丢弃未签名的思考块,并为严格提供商(Mistral/OpenRouter)强制执行字母数字工具调用 ID。(#1372) 感谢 @zerone0x。
- Exec 审批:将 main 视为默认代理,对齐节点/网关允许列表预检,验证解析后的路径,避免允许列表解析竞争,并避免空的可选参数。(#1417, #1414, #1425) 感谢 @czekaj。
- Exec/Windows:解析带有扩展名的 Windows exec 路径并处理安全二进制文件 exe 名称。
- 节点/macOS:在节点 exec 审批允许列表缺失时提示,持久化允许列表决策,并扁平化节点调用错误。(#1394) 感谢 @ngutman。
- 网关:防止多个网关共享相同的配置/状态(单例锁),保持自动绑定优先回环地址并显式绑定 tailnet,并改进 SSH 身份验证处理。(#1380)
- 控制 UI:移除聊天停止按钮,保持编辑器与底部边缘对齐,稳定会话预览,并在路由驱动的标签页更改时刷新调试面板。(#1373) 感谢 @yazinsai。
- UI/配置:为配置表单模块导出 `SECTION_META`。(#1418) 感谢 @MaudeBot。
- macOS:在流式回复期间保持聊天固定,包含 Textual 资源,尊重通配符 exec 审批,允许 SSH 代理身份验证,并默认分发构建为通用二进制文件。(#1279, #1362, #1384, #1396) 感谢 @ameno-, @JustYannicc。
- BlueBubbles:安全解析短消息 ID,在模板中暴露完整 ID,并强化短 ID 获取包装器。(#1369, #1387) 感谢 @tyler6204。
- 模型/配置:在线程/主题中继承会话模型覆盖,将 OpenCode Zen 模型映射到正确的 API,缩小 Anthropic OAuth 允许列表处理范围,种子允许列表回退,未设置允许列表时列出完整目录,并限制 `/model` 列表输出。(#1376, #1416)
- 内存:通过延迟向量探测防止 CLI 挂起,添加 sqlite-vec/嵌入超时,并使会话内存索引异步。
- Cron:将提醒上下文历史记录限制为 10 条消息,并遵守 `contextMessages`。(#1103) 感谢 @mkbehr。
- 缓存:恢复 1 小时缓存 TTL 选项并重置清理窗口。
- Zalo Personal:容忍来自 `zca` 的 ANSI/日志前缀 JSON 输出。(#1379) 感谢 @ptn1411。
- 浏览器:抑制托管配置文件的 Chrome 恢复提示。(#1419) 感谢 @jamesgroat。
- 基础设施:在包装中止信号时保留 fetch 辅助方法/预连接,并规范化 Telegram fetch 中止。
- 配置/诊断:避免无效配置的堆栈跟踪,记录配置路径,避免 WhatsApp 配置复活,并在 `gateway.mode` 未设置时警告。(#900)
- CLI:读取 Codex CLI account_id 用于工作区计费。(#1422) 感谢 @aj47。
- 日志/状态:将滚动日志文件名与本地时间对齐,并在 `clawdbot status` 中报告沙盒化运行时。(#1343)
- 嵌入式运行器:持久化注入的历史图像,以便附件不会在每次轮次重新加载。(#1374) 感谢 @Nicell。
- 节点/子代理:在工具失败日志中包含代理/节点/网关上下文,并确保子代理列表使用命令会话。
### Highlights
- Lobster optional plugin tool for typed workflows + approval gates. [docs](https://docs.clawd.bot/tools/lobster)
- Custom assistant identity + avatars in the Control UI. [docs](https://docs.clawd.bot/cli/agents) [docs](https://docs.clawd.bot/web/control-ui)
- Cache optimizations: cache-ttl pruning + defaults reduce token spend on cold requests. [docs](https://docs.clawd.bot/concepts/session-pruning)
- Exec approvals + elevated ask/full modes. [docs](https://docs.clawd.bot/tools/exec-approvals) [docs](https://docs.clawd.bot/tools/elevated)
- Signal typing/read receipts + MSTeams attachments. [docs](https://docs.clawd.bot/channels/signal) [docs](https://docs.clawd.bot/channels/msteams)
- `/models` UX refresh + `clawdbot update wizard`. [docs](https://docs.clawd.bot/cli/models) [docs](https://docs.clawd.bot/cli/update)
### Changes
- Highlight: Lobster optional plugin tool for typed workflows + approval gates. [docs](https://docs.clawd.bot/tools/lobster) (#1152) Thanks @vignesh07.
- Agents/UI: add identity avatar config support and Control UI avatar rendering. (#1329, #1424) Thanks @dlauer. [docs](https://docs.clawd.bot/gateway/configuration) [docs](https://docs.clawd.bot/cli/agents)
- Control UI: add custom assistant identity support and per-session identity display. (#1420) Thanks @robbyczgw-cla. [docs](https://docs.clawd.bot/web/control-ui)
- CLI: add `clawdbot update wizard` with interactive channel selection + restart prompts, plus preflight checks before rebasing. [docs](https://docs.clawd.bot/cli/update)
- Models/Commands: add `/models`, improve `/model` listing UX, and expand `clawdbot models` paging. (#1398) Thanks @vignesh07. [docs](https://docs.clawd.bot/cli/models)
- CLI: move gateway service commands under `clawdbot gateway`, flatten node service commands under `clawdbot node`, and add `gateway probe` for reachability. [docs](https://docs.clawd.bot/cli/gateway) [docs](https://docs.clawd.bot/cli/node)
- Exec: add elevated ask/full modes, tighten allowlist gating, and render approvals tables on write. [docs](https://docs.clawd.bot/tools/elevated) [docs](https://docs.clawd.bot/tools/exec-approvals)
- Exec approvals: default to local host, add gateway/node targeting + target details, support wildcard agent allowlists, and tighten allowlist parsing/safe bins. [docs](https://docs.clawd.bot/cli/approvals) [docs](https://docs.clawd.bot/tools/exec-approvals)
- Heartbeat: allow explicit session keys and active hours. (#1256) Thanks @zknicker. [docs](https://docs.clawd.bot/gateway/heartbeat)
- Sessions: add per-channel idle durations via `sessions.channelIdleMinutes`. (#1353) Thanks @cash-echo-bot.
- Nodes: run exec-style, expose PATH in status/describe, and bootstrap PATH for node-host execution. [docs](https://docs.clawd.bot/cli/node)
- Cache: add `cache.ttlPrune` mode and auth-aware defaults for cache TTL behavior.
- Queue: add per-channel debounce overrides for auto-reply. [docs](https://docs.clawd.bot/concepts/queue)
- Discord: add wildcard channel config support. (#1334) Thanks @pvoo. [docs](https://docs.clawd.bot/channels/discord)
- Signal: add typing indicators and DM read receipts via signal-cli. [docs](https://docs.clawd.bot/channels/signal)
- MSTeams: add file uploads, adaptive cards, and attachment handling improvements. (#1410) Thanks @Evizero. [docs](https://docs.clawd.bot/channels/msteams)
- Onboarding: remove the run setup-token auth option (paste setup-token or reuse CLI creds instead).
- macOS: refresh Settings (location access in Permissions, connection mode in menu, remove CLI install UI).
- Diagnostics: add cache trace config for debugging. (#1370) Thanks @parubets.
- Docs: Lobster guides + org URL updates, /model allowlist troubleshooting, Gmail message search examples, gateway.mode troubleshooting, prompt injection guidance, npm prefix/node CLI notes, control UI dev gatewayUrl note, tool_use FAQ, showcase video, and sharp/node-gyp workaround. (#1427, #1220, #1405) Thanks @vignesh07, @mbelinky.
### Breaking
- **BREAKING:** Control UI now rejects insecure HTTP without device identity by default. Use HTTPS (Tailscale Serve) or set `gateway.controlUi.allowInsecureAuth: true` to allow token-only auth. [docs](https://docs.clawd.bot/web/control-ui#insecure-http)
- **BREAKING:** Envelope and system event timestamps now default to host-local time (was UTC) so agents don’t have to constantly convert.
### Fixes
- Streaming/Typing/Media: keep reply tags across streamed chunks, start typing indicators at run start, and accept MEDIA paths with spaces/tilde while preferring the message tool hint for image replies.
- Agents/Providers: drop unsigned thinking blocks for Claude models (Google Antigravity) and enforce alphanumeric tool call ids for strict providers (Mistral/OpenRouter). (#1372) Thanks @zerone0x.
- Exec approvals: treat main as the default agent, align node/gateway allowlist prechecks, validate resolved paths, avoid allowlist resolve races, and avoid null optional params. (#1417, #1414, #1425) Thanks @czekaj.
- Exec/Windows: resolve Windows exec paths with extensions and handle safe-bin exe names.
- Nodes/macOS: prompt on allowlist miss for node exec approvals, persist allowlist decisions, and flatten node invoke errors. (#1394) Thanks @ngutman.
- Gateway: prevent multiple gateways from sharing the same config/state (singleton lock), keep auto bind loopback-first with explicit tailnet binding, and improve SSH auth handling. (#1380)
- Control UI: remove the chat stop button, keep the composer aligned to the bottom edge, stabilize session previews, and refresh the debug panel on route-driven tab changes. (#1373) Thanks @yazinsai.
- UI/config: export `SECTION_META` for config form modules. (#1418) Thanks @MaudeBot.
- macOS: keep chat pinned during streaming replies, include Textual resources, respect wildcard exec approvals, allow SSH agent auth, and default distribution builds to universal binaries. (#1279, #1362, #1384, #1396) Thanks @ameno-, @JustYannicc.
- BlueBubbles: resolve short message IDs safely, expose full IDs in templates, and harden short-id fetch wrappers. (#1369, #1387) Thanks @tyler6204.
- Models/Configure: inherit session model overrides in threads/topics, map OpenCode Zen models to the correct APIs, narrow Anthropic OAuth allowlist handling, seed allowlist fallbacks, list the full catalog when no allowlist is set, and limit `/model` list output. (#1376, #1416)
- Memory: prevent CLI hangs by deferring vector probes, add sqlite-vec/embedding timeouts, and make session memory indexing async.
- Cron: cap reminder context history to 10 messages and honor `contextMessages`. (#1103) Thanks @mkbehr.
- Cache: restore the 1h cache TTL option and reset the pruning window.
- Zalo Personal: tolerate ANSI/log-prefixed JSON output from `zca`. (#1379) Thanks @ptn1411.
- Browser: suppress Chrome restore prompts for managed profiles. (#1419) Thanks @jamesgroat.
- Infra: preserve fetch helper methods/preconnect when wrapping abort signals and normalize Telegram fetch aborts.
- Config/Doctor: avoid stack traces for invalid configs, log the config path, avoid WhatsApp config resurrection, and warn when `gateway.mode` is unset. (#900)
- CLI: read Codex CLI account_id for workspace billing. (#1422) Thanks @aj47.
- Logs/Status: align rolling log filenames with local time and report sandboxed runtime in `clawdbot status`. (#1343)
- Embedded runner: persist injected history images so attachments aren’t reloaded each turn. (#1374) Thanks @Nicell.
- Nodes/Subagents: include agent/node/gateway context in tool failure logs and ensure subagent list uses the command session.