Skip to content

Release: Staging to Production - v1.7.1 - #613

Merged
maxtechera merged 2 commits into
productionfrom
staging
Oct 20, 2025
Merged

Release: Staging to Production - v1.7.1#613
maxtechera merged 2 commits into
productionfrom
staging

Conversation

@maxtechera

Copy link
Copy Markdown
Collaborator

Summary

  • Refactor: Limited S3 storage to version management operations only
  • Release: Version 1.7.0 with new features

Changes Included

🔧 Infrastructure Improvements

  • S3 Storage Architecture Refinement (refactor: limit S3 storage to version management only #610)
    • Limited S3 usage to version management operations only
    • Removed S3 draft lookup from primary chatflow retrieval
    • Simplified database operations for better performance
    • Eliminated potential race conditions between S3 and database

📦 Release 1.7.0 Features (#611)

  • 🎥 Sora & Veo Video Generator Integration

    • Multi-provider support (OpenAI Sora and Google Veo)
    • Flexible aspect ratios and duration control
    • Reference image support with cropping
    • AI-powered prompt enhancement wizard
  • 🎨 Gamma Presentation Tool Integration

    • Full Gamma API integration for presentations
    • 100+ professional themes
    • Dynamic parameter configuration
  • ✨ Enhanced Credentials Modal Experience

    • Smart auto-selection of compatible credentials
    • Improved visual feedback and error handling
  • 🎨 Corporate Style & Branding Updates

    • Professional icon-based design system
    • Enhanced visual consistency

🐛 Bug Fixes

  • Fixed database rollback operation for proper flowData updates
  • ESLint compliance improvements
  • Fixed prototype pollution vulnerability

Test Plan

  • Verify chatflow loading works in editor
  • Verify chatflow predictions/executions work
  • Verify version history shows correctly
  • Verify rollback functionality works
  • Test video generation with both providers
  • Test Gamma integration
  • Test credentials auto-selection
  • Verify existing workflows still function

Deployment Notes

  • No new environment variables required
  • Backwards compatible with existing deployments
  • Optional API keys can be added for video generation features

🤖 Generated with Claude Code

bradtaylorsf and others added 2 commits October 20, 2025 17:06
# Release 1.7.0 - AI Video Creation & Enhanced User Experience

**Release Date:** October 17, 2025  
**Release Branch:** `release/1.7.0`

---

## 🎉 What's New

### 🎥 Sora & Veo Video Generator Integration

A completely new video generation feature has been added to TheAnswer,
enabling users to create AI-generated videos using OpenAI's Sora and
Google's Veo models.

**Key Features:**
- **Multi-Provider Support**: Choose between OpenAI Sora and Google Veo
models
- **Flexible Aspect Ratios**: Support for landscape, portrait, and
square formats
- **Video Duration Control**: Generate videos from 5 to 10+ seconds
- **Reference Image Support**: Upload and crop reference images to guide
video generation
- **Prompt Enhancement Wizard**: AI-powered prompt enhancement with
customizable parameters including:
  - Camera angles and movements
  - Visual style and mood
  - Scene details and subject characteristics
  - Lighting and tone preferences
- **Generation History**: Track and manage all your video generation
attempts
- **Job Polling**: Real-time status updates with automatic polling
- **Video Remix**: Iterate on existing generations with new prompts
- **Export & Save**: Download videos and save favorites to your library

**How to Use:**
1. Navigate to **Sidekick Studio > Video Creator** in the main
navigation
2. Enter your video prompt or use the Prompt Enhancer Wizard for better
results
3. Select your preferred provider (OpenAI or Google)
4. Configure generation parameters:
   - Aspect ratio (16:9, 9:16, or 1:1)
   - Video duration (5-10+ seconds)
   - Optional: Upload a reference image
   - Optional: Add negative prompts
5. Click "Generate Video" and monitor progress
6. Once complete, download or save to your library

**API Endpoints:**
- `POST /api/v1/video-generator/generate` - Start a new video generation
- `GET /api/v1/video-generator/job/:jobId` - Get job status
- `POST /api/v1/video-generator/save` - Save a video to library
- `GET /api/v1/video-generator/saved` - List saved videos
- `DELETE /api/v1/video-generator/saved/:id` - Delete saved video

**Billing Integration:**
Video generation usage is tracked and billed based on:
- Model provider (OpenAI/Google)
- Video duration
- Resolution/aspect ratio

---

### 🎨 Gamma Presentation Tool Integration

A new Gamma tool has been added, allowing AI agents to create beautiful
presentations directly from conversational prompts.

**Features:**
- **Full Gamma API Integration**: Create presentations, documents, and
webpages
- **Comprehensive Configuration Options**:
  - Text mode (outline, bullets, paragraph, freestyle)
  - Theme selection (100+ professional themes)
  - Card count and splitting preferences
  - Text tone, audience, and language customization
  - Image generation with style preferences
  - Card dimensions (standard, vertical, horizontal)
  - Sharing and access controls
- **Poll Until Complete**: Automatic polling for generation completion
- **Configurable Options**: Allow agents to dynamically adjust
parameters
- **Export Formats**: Export as PDF, PPT, or Markdown

**How to Use:**
1. Add the **Gamma** tool to your chatflow or agent
2. Configure your Gamma API credentials in the Credentials panel
3. Set default preferences for:
   - Theme name
   - Number of cards
   - Text tone and audience
   - Image model and style
4. Enable "Ask User" options to let the AI determine these dynamically
5. Use in prompts like: "Create a 10-slide presentation about climate
change with a professional tone"

**Credential Setup:**
1. Go to Credentials panel
2. Add new credential → Select "Gamma API"
3. Enter your Gamma API key from [gamma.app/api](https://gamma.app/api)

---

### ✨ Enhanced Credentials Modal Experience

Significant improvements to the credentials management interface for a
smoother user experience.

**Improvements:**
- **Smart Auto-Selection**: Automatically selects existing compatible
credentials when available
- **Better Visual Feedback**: Enhanced icons and status indicators for
Assistant and Sidekick cards
- **User Preference Memory**: Remembers your preference to auto-select
credentials
- **Improved Modal Flow**: Better organization and clearer credential
selection process
- **Enhanced Error Handling**: More informative error messages when
credentials are missing or invalid

**How to Use:**
1. When setting up a new flow or tool requiring credentials:
   - If you have compatible credentials, they'll be auto-selected
   - You can still choose different credentials from the dropdown
2. The system will remember your preference for future setups
3. Visual indicators show which credentials are currently in use
4. Missing credentials are now more clearly highlighted with actionable
prompts

---

### 🎨 Corporate Style & Branding Updates

Major visual refresh across documentation and landing pages with a more
professional, icon-based design system.

**Changes:**
- Replaced emoji-based UI elements with professional Lucide React icons
- Updated all landing pages (Agents, Apps, Chat, Browser Sidekick, etc.)
- Enhanced visual consistency across documentation
- Improved readability and accessibility
- Modernized component styling throughout

**Affected Pages:**
- Home page
- Agents page
- Apps page
- Browser Sidekick
- Chat interface
- Creator portal
- JLINC Partnership
- Getting Started
- Webinar pages

---

## 🐛 Bug Fixes

### Critical Fixes

#### S3 Storage Architecture Refinement
**Impact:** Medium - Improves reliability and simplifies codebase

**What Was Fixed:**
- Limited S3 storage usage to version management operations only
- Removed S3 draft lookup from primary chatflow retrieval
- Eliminated race conditions between S3 and database
- Simplified `getChatflowById` signature by removing `useDraft`
parameter

**Technical Details:**
- S3 is now exclusively used for:
  - Version listing
  - Version retrieval
  - Version rollback operations
- All active chatflow operations now use database as single source of
truth
- Removed `useDraft` parameter from API endpoints
- Updated controller calls to consistently use database

**Why This Matters:**
Previously, the system would check both S3 and database for draft
states, creating potential inconsistencies. This change ensures:
- More predictable behavior
- Better performance (fewer S3 calls)
- Reduced complexity
- Clearer separation of concerns

**Files Changed:**
- `packages/server/src/controllers/chatflows/index.ts`
- `packages/server/src/services/chatflows/index.ts`

---

#### Database Rollback Operation Fix
**Impact:** High - Prevents data loss during version rollback

**What Was Fixed:**
- Fixed flowData not updating in database during rollback operations
- Ensured rollback operations properly sync between S3 versions and
database

**Technical Details:**
- Added database update step during version rollback
- Ensures `flowData` field is properly updated when rolling back to
previous version
- Maintains consistency between version storage and active chatflow
state

**Why This Matters:**
Previously, rolling back to a previous version would update references
but not the actual flow data, causing confusion and potential data loss.

---

### Code Quality Improvements

#### ESLint Compliance
**Impact:** Low - Code quality and maintainability

**What Was Fixed:**
- Fixed linting errors across multiple files
- Improved code consistency
- Updated ESLint configuration for better coverage
- Resolved React hook dependencies warnings
- Fixed prototype pollution vulnerability (Code Scanning Alert #202)

**Files Changed:**
- Multiple files across `packages/docs`, `packages-answers/ui`, and
`packages/components`
- Added `.eslintignore` patterns for better control
- Updated workflow configurations

---

## 🔧 Technical Improvements

### Dependency Updates
- Added `replicate` package for AI model integrations
- Updated various package versions for security and compatibility
- Added new video generation dependencies

### API Architecture
- New video generator service layer with LangFuse tracking
- Enhanced error handling in video generation pipeline
- Improved billing event tracking for video usage

### Database Schema
- No schema changes in this release (backwards compatible)

---

## ⚠️ Breaking Changes

### S3 Storage API Changes (Minor)

**Affected API:**
- `getChatflowById(id, useDraft)` → `getChatflowById(id)`

**Migration Guide:**
If you were using the `useDraft` parameter in custom integrations:

**Before:**
```javascript
const chatflow = await getChatflowById(chatflowId, true)  // Get draft from S3
```

**After:**
```javascript
const chatflow = await getChatflowById(chatflowId)  // Always uses database
```

**Impact Assessment:**
- **Internal API only** - Does not affect external integrations
- Most users won't need to make any changes
- If you have custom server modifications that call this function,
update your calls

---

## 📦 Installation & Upgrade

### For New Installations:
```bash
git clone <repository>
cd theanswer
git checkout release/1.7.0
pnpm install
pnpm build
```

### For Existing Installations:
```bash
git fetch origin
git checkout release/1.7.0
pnpm install  # Install new dependencies
pnpm build    # Rebuild all packages
```

### Environment Variables:
No new environment variables are required for this release.

**Optional for Video Generation:**
- `OPENAI_API_KEY` - For Sora video generation
- `GOOGLE_API_KEY` - For Veo video generation

**Optional for Gamma Integration:**
- Users must provide their own Gamma API keys via the credentials panel

---

## 🧪 Testing Recommendations

After upgrading, please test:

1. **Video Generation**:
   - Try generating a video with OpenAI Sora
   - Try generating a video with Google Veo
   - Test the prompt enhancement wizard
   - Verify video save/download functionality

2. **Gamma Integration**:
   - Add Gamma credentials
   - Create a presentation via AI agent
   - Test different theme and format options

3. **Credentials Flow**:
   - Set up a new chatflow with tools requiring credentials
   - Verify auto-selection works
   - Check that existing credentials remain functional

4. **Chatflow Operations**:
   - Load existing chatflows
   - Save changes to chatflows
   - Test version rollback functionality
   - Verify drafts save correctly

5. **General Stability**:
   - Run existing agents and workflows
   - Check that all integrations still work
   - Verify billing events are tracked correctly

---

## 📊 Statistics

- **Total Commits:** 20
- **Files Changed:** 85+
- **Lines Added:** ~5,000+
- **Lines Removed:** ~500+
- **New Features:** 3 major features
- **Bug Fixes:** 3 critical fixes
- **Contributors:** 3

---

## 🙏 Credits

Special thanks to our contributors:
- **Brad Taylor** - Video generation architecture & Gamma Integration
- **Max Techera**  - S3 storage refactoring
- **Diego Costa** - Credentials UX improvements
- **Answer Team** - Testing and code review

---

## 📚 Documentation Updates

New documentation has been added for:
- Video Creator user guide
- Gamma tool integration guide
- Credentials management best practices
- API reference updates

Visit our [documentation](https://docs.answeragent.ai) for detailed
guides.

---

## 🐛 Known Issues

None reported at release time.

If you encounter any issues, please report them on our [GitHub
Issues](https://github.com/the-answerai/theanswer/issues) page.

---

## 🔜 Coming Soon

Features planned for upcoming releases:
- Additional video model integrations
- Batch video generation
- Video editing capabilities
- Enhanced presentation customization
- More AI tool integrations

---

## 📞 Support

For questions or issues:
- **Documentation:** https://docs.answeragent.ai
- **Discord:** https://discord.gg/X54ywt8pzj
- **GitHub Issues:** https://github.com/the-answerai/theanswer/issues
- **Email:** support@answeragent.ai

---

**Full Changelog:**
[`staging...release/1.7.0`](staging...release/1.7.0)

---------

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Co-authored-by: Cameron Taylor <50385537+ct3685@users.noreply.github.com>
Co-authored-by: Jaime Morales <jaime@lastrev.com>
Co-authored-by: Diego Costa <diecoscai@gmail.com>
Co-authored-by: Max Techera <maxi.techerag@gmail.com>
## Summary
- Removed S3 draft lookup from `getChatflowById` - now always returns
database version
- Removed S3 lookup from `getChatflowForPrediction` - predictions use
database directly
- Removed `useDraft` parameter from `getChatflowById` signature
- Updated controller calls to remove unnecessary parameters
- S3 storage now exclusively used for version operations (list, get
specific version, rollback)

## Changes
**Before:** S3 was used for both normal chatflow operations and version
management
**After:** S3 only used for version history/rollback features

### Modified Files
- `packages/server/src/services/chatflows/index.ts`
  - Simplified `getChatflowById` to only use database
  - Simplified `getChatflowForPrediction` to only use database
- `packages/server/src/controllers/chatflows/index.ts`
  - Updated `getChatflowById` and `updateChatflow` calls

## Test Plan
- [ ] Verify chatflow loading works in editor
- [ ] Verify chatflow predictions/executions work
- [ ] Verify version history still shows correctly
- [ ] Verify rollback functionality still works
- [ ] Verify chatflow updates increment version and save to S3
if (!current[keys[i]]) current[keys[i]] = {}
current = current[keys[i]]
}
current[keys[keys.length - 1]] = value

Check warning

Code scanning / CodeQL

Prototype-polluting function Medium

The property chain
here
is recursively assigned to
current
without guarding against prototype pollution.

Copilot Autofix

AI 10 months ago

To securely fix the prototype pollution risk, we should improve the check in updateField so that every property key on the assignment path is blocked if it matches any of the known prototype-polluting keys (__proto__, prototype, constructor). This must occur not just for the full path, but for each segment/key during object traversal and assignment. Additionally, before assigning to each nested object, we should ensure we do not traverse or create properties with these dangerous names, and that every value we dive into for deep assignment is a non-array object (not affected by prototype chains).

Specifically, in updateField in packages-answers/ui/src/VideoCreator/PromptEnhancerWizard.tsx:

  • Strengthen the for-loop (lines 233–236) to skip or block property creation if keys[i] is a dangerous property.
  • Do the same for the final assigned key (keys[keys.length - 1]).
  • Optionally, use a helper function (e.g., isSafeKey(key: string): boolean) for readability.

No new imports are needed, and all edits are within the shown code snippet.


Suggested changeset 1
packages-answers/ui/src/VideoCreator/PromptEnhancerWizard.tsx

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/packages-answers/ui/src/VideoCreator/PromptEnhancerWizard.tsx b/packages-answers/ui/src/VideoCreator/PromptEnhancerWizard.tsx
--- a/packages-answers/ui/src/VideoCreator/PromptEnhancerWizard.tsx
+++ b/packages-answers/ui/src/VideoCreator/PromptEnhancerWizard.tsx
@@ -221,20 +221,38 @@
 
     const updateField = (path: string, value: any) => {
         const blockedKeys = ['__proto__', 'prototype', 'constructor']
+        function isSafeKey(key: string) {
+            return !blockedKeys.includes(key)
+        }
         setEnhancedData((prev) => {
             const newData = { ...prev }
             const keys = path.split('.')
-            // Prevent prototype pollution: block dangerous keys
-            if (keys.some((k) => blockedKeys.includes(k))) {
-                console.warn('Blocked prototype-polluting path:', path)
-                return newData
+            // Prevent prototype pollution: block dangerous keys at every step
+            for (let k of keys) {
+                if (!isSafeKey(k)) {
+                    console.warn('Blocked prototype-polluting key in path:', path)
+                    return newData
+                }
             }
             let current: any = newData
             for (let i = 0; i < keys.length - 1; i++) {
-                if (!current[keys[i]]) current[keys[i]] = {}
-                current = current[keys[i]]
+                const thisKey = keys[i]
+                if (!isSafeKey(thisKey)) {
+                    console.warn('Blocked prototype-polluting key in path segment:', thisKey)
+                    return newData
+                }
+                // Only create a new object if current[thisKey] is not an object already
+                if (!current[thisKey] || typeof current[thisKey] !== 'object' || Array.isArray(current[thisKey])) {
+                    current[thisKey] = {}
+                }
+                current = current[thisKey]
             }
-            current[keys[keys.length - 1]] = value
+            const lastKey = keys[keys.length - 1]
+            if (!isSafeKey(lastKey)) {
+                console.warn('Blocked prototype-polluting key at assignment:', lastKey)
+                return newData
+            }
+            current[lastKey] = value
             return newData
         })
     }
EOF
@@ -221,20 +221,38 @@

const updateField = (path: string, value: any) => {
const blockedKeys = ['__proto__', 'prototype', 'constructor']
function isSafeKey(key: string) {
return !blockedKeys.includes(key)
}
setEnhancedData((prev) => {
const newData = { ...prev }
const keys = path.split('.')
// Prevent prototype pollution: block dangerous keys
if (keys.some((k) => blockedKeys.includes(k))) {
console.warn('Blocked prototype-polluting path:', path)
return newData
// Prevent prototype pollution: block dangerous keys at every step
for (let k of keys) {
if (!isSafeKey(k)) {
console.warn('Blocked prototype-polluting key in path:', path)
return newData
}
}
let current: any = newData
for (let i = 0; i < keys.length - 1; i++) {
if (!current[keys[i]]) current[keys[i]] = {}
current = current[keys[i]]
const thisKey = keys[i]
if (!isSafeKey(thisKey)) {
console.warn('Blocked prototype-polluting key in path segment:', thisKey)
return newData
}
// Only create a new object if current[thisKey] is not an object already
if (!current[thisKey] || typeof current[thisKey] !== 'object' || Array.isArray(current[thisKey])) {
current[thisKey] = {}
}
current = current[thisKey]
}
current[keys[keys.length - 1]] = value
const lastKey = keys[keys.length - 1]
if (!isSafeKey(lastKey)) {
console.warn('Blocked prototype-polluting key at assignment:', lastKey)
return newData
}
current[lastKey] = value
return newData
})
}
Copilot is powered by AI and may make mistakes. Always verify output.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +1119 to +1127
// Update database with the rolled-back flowData and increment version
const newVersion = (chatflow.currentVersion || 1) + 1
chatflow.flowData = versionContent.flowData
chatflow.currentVersion = newVersion

const dbResponse = await chatFlowRepository.save(chatflow)

// Save to S3 as new version (this creates a new version with the rollback content)
await chatflowStorageService.rollbackToVersion(chatflowId, version, user)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge S3 rollback version numbers diverge from database

After the refactor, the database is now the source of truth and rollbackChatflowToVersion writes the rolled-back flow into the DB and increments currentVersion ((lines 1119‑1124). Immediately afterwards it calls chatflowStorageService.rollbackToVersion, but that helper still derives the new version number from the archived record’s currentVersion instead of the value just persisted in the DB (chatflow-storage/index.ts lines 306‑318). If you roll back from version 10 to 5, the DB ends up at version 11 while the object saved to S3 is tagged as version 6, overwriting/duplicating older versions. Because version history is now read from S3 while executions read from the DB, the two stores get out of sync and the UI can no longer display or roll back to the most recent DB version. Consider passing the DB’s incremented version into the storage helper or letting the helper return the new version so both sources stay consistent.

Useful? React with 👍 / 👎.

@maxtechera
maxtechera merged commit 3a4f9fd into production Oct 20, 2025
5 of 7 checks passed
@maxtechera
maxtechera temporarily deployed to staging - aai-unified2-flowise-moonstruck October 20, 2025 20:34 — with Render Inactive
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants