* feat: add live run-flow updates and diagnostics
* feat: update task status filter to include 'cancel_requested'
* feat: enhance run-flow diagnostics and task management with cancel-requested status handling
* fix: stabilize run flow live updates
* fix: align live run-flow review contracts
* fix: sanitize live run-flow events
* feat: support strategy selection in web analysis
* fix(review-feedback-1331): The worker receives the original skills list, while TaskInfo stores a
* fix(review-feedback-1331): 补充对应 Web/API 文档,或在 PR 中明确说明现有哪份文档已覆盖且本次无需更新的依据
The serve_spa handler at /{full_path:path} joined static_dir / full_path
without containment checks before serving the result via FileResponse.
Starlette's :path converter does not normalize `..` segments and uvicorn
does not collapse them either, so an unauthenticated request such as
GET /%2e%2e/%2e%2e/%2e%2e/etc/passwd (or with literal `..`) caused
pathlib's .is_file() and FileResponse to resolve outside the bundle
root and return arbitrary files readable by the server process — env
files, secrets under data/, source code, SSH keys, etc.
The repo already has _resolve_asset_path for this exact concern on the
/assets/{asset_path:path} route (rejects null bytes, leading `/` or `\`,
backslashes, drive letters, and any candidate that is not
is_relative_to the base directory after .resolve()). The fix reuses
that helper for serve_spa, so requests that escape static_dir now fall
through to index.html instead of leaking files.
Added a regression test that creates a temp static_dir, drops a sibling
secret.txt, and asserts that ../secret.txt, ../../secret.txt, and
foo/../../secret.txt all return the SPA index instead of the secret.
Vulnerability: Path traversal / arbitrary file read
Severity: high (unauthenticated; SPA fallback is not behind the auth
middleware, which only guards /api/v1/*)
Location: api/app.py:299-315 (pre-fix line numbers)
Impact: any file readable by the server process can be exfiltrated by an
attacker who can reach the HTTP port.
Co-authored-by: aeonframework <aeonframework@proton.me>
* fix: inject REPORT_LANGUAGE into workflow and add current_price to status API (#1013, #983)
* fix: preserve status API snapshot change pct fallbacks
* fix: keep status change pct scoped to intraday data
* fix: accept HK autocomplete codes on home analysis input
The home page stock input accepted plain A-share codes but rejected Hong Kong stocks selected from autocomplete. The root cause was that autocomplete submits the suggestion canonicalCode (for example 00700.HK), while the backend stock code utility only recognized .SH/.SZ/.SS suffixes. As a result, 00700.HK was treated as mixed alphanumeric noise and rejected with the generic validation error before analysis dispatch.
Extend shared stock code recognition and normalization to accept .HK suffixes alongside existing A-share suffixes. This keeps the existing manual input behavior for 00700 and makes the backend consistent with the canonicalCode format already used by the web stock index and autocomplete flow.
Add regression coverage on both sides of the boundary: backend contract tests now verify that trigger_analysis accepts 00700.HK from autocomplete and HK00700 from manual input, and frontend tests now verify that highlighted HK suggestions submit the canonical .HK code and are not rejected by local store validation.
* update CHANGELOG.md
* fix: align HK code validation with existing market rules
Follow up the home page HK autocomplete fix by tightening the shared stock code validator so exchange suffixes and prefixes no longer reuse the same generic 5-6 digit rule.
This change keeps SH/SZ/SS suffixes restricted to 6-digit mainland codes, treats HK suffixes and HK prefixes as 1-5 digit Hong Kong codes with zero-padding during normalization, and rejects invalid cross-market combinations such as 600519.HK, HK600519, and 00700.SH.
Add regression coverage for valid short HK forms like 1810.HK and HK700, plus negative tests for invalid suffix and prefix lengths, so the shared backend utility stays consistent with the existing web validation and data-provider normalization rules.
* feat(web): consolidate dashboard, chat, and backtest UI improvements
- polish dashboard follow-up pages and shared UI states across home, chat, and backtest flows
- consolidate chat and backtest page layout, styling, and interaction improvements into a single web UI update
- improve follow-up context handling in chat and add broader regression coverage for dashboard and chat components
- refine text color and opacity usage across shared components for more consistent readability
- restore home page mobile scrolling after the broader UI refactor changed page overflow behavior
- update related tests and changelog entries to reflect the finalized web interaction and styling changes
* feat(ui): optimize light theme shadows, navigation, alerts, and chat bubble styles
- Soften light mode box-shadows globally, replacing hardcoded grays with dynamic CSS variables for a cleaner, non-muddy depth effect.
- Unify SidebarNav active item style: remove inset shadow, apply primary background, and use bold font for better visibility.
- Fix ApiErrorAlert and InlineAlert contrast in light mode: use deep red text for high legibility, and robust dark/light theme CSS variables.
- Fix ThemeToggle menu z-index (z-40) in Shell to prevent overlap by main content pages (e.g., Settings, Backtest).
- Refactor ChatPage avatars and message bubbles to use dedicated dual-theme CSS classes (.chat-avatar-*, .chat-bubble-*).
- Add distinct borders to User/AI chat avatars with lowered opacity in dark mode to prevent visual glare.
- Add subtle borders to AI message bubbles in light mode to enhance separation, preserving semi-transparent borders in dark mode.
* fix(web): restore picker flows and align chat/report interactions
- restore intelligent import file picker behavior and add regression coverage
- align report markdown E2E expectations with the current UI
- improve markdown plain-text extraction used by report export flows
- fix chat session history deletion accessibility by separating row selection and delete actions into independent native buttons
- add chat history regression tests for keyboard-accessible deletion behavior
- deduplicate shared action button variant styles without changing the public Button variant API
- keep user-facing web interactions consistent after recent UI updates
* fix(web): resolve dashboard build issue and speed resolver benchmarks
- remove duplicate notify fields from useHomeDashboardState to fix the dsa-web TypeScript build
- keep the theme toggle button disabled in the current UI state
- cache local name-to-code indexes and fast-return on ambiguous local stock names
- split resolver performance coverage into fast-path and typo-fallback benchmarks with warm-up steps and smaller iteration budgets
* update README.md
* feat(autocomplete): rebuild web autocomplete mvp
* feat(autocomplete): add error boundary and runtime fallback
Add error boundary and runtime error handling to improve autocomplete stability:
- Add StockAutocompleteBoundary class component to catch render errors
- Add FallbackInput component for graceful degradation
- Add runtimeFallback state and error handling in useAutocomplete hook
- Wrap search logic with try-catch to prevent crashes
- Add comprehensive tests for error scenarios
This ensures the autocomplete degrades to a plain input when:
- Index loading fails (existing behavior)
- Runtime search throws (new)
- Component tree throws during render (new)
* feat(autocomplete): add input validation and optimize name resolution
- Add early rejection for obviously invalid mixed alphanumeric input
- Skip expensive AkShare/fuzzy fallback for non-CJK free text
- Enhance frontend validation with isObviouslyInvalidStockQuery
- Increase minimum query length from 1 to 2 characters
- Add comprehensive test coverage for validation logic
- Update E2E test placeholder text to reflect new capabilities
These changes address code review feedback about:
- Preventing abuse from invalid input patterns
- Improving performance by avoiding unnecessary network calls
- Ensuring consistent validation between frontend and backend
* fix(autocomplete): harden input validation and runtime guards
* update doc
* style(autocomplete): adjust suggestion item hover effect
- Reduce hover background opacity from 35% to 25% for lighter visual effect
- Brighten hover color in dark theme from #257280 to #2dcae6
* fix(autocomplete): do not auto-highlight first suggestion to preserve raw input on Enter
* test(home): align report fixture with report language metadata
* fix: unify task queue stock dedupe key
* feat: add configurable report language
* Fix review follow-ups for history and fallback localization
* fix: prefer .env report language at startup
* fix: address report language review feedback
* fix: address latest report language review feedback
* Improve analysis API async contracts and startup helpers
* Fix rebased analysis API contract regressions
* fix: align frontend report type union with full responses