Serendipity
|
2d0e8c4997
|
chore: ruff lint 修复 + 第一优先级全部完成
|
2026-07-11 19:50:35 +08:00 |
|
Serendipity
|
1d58a55a73
|
feat: Searcher 集成 HybridRetriever + SearchConfig 配置
|
2026-07-11 19:43:49 +08:00 |
|
Serendipity
|
2e95f68864
|
fix: list_collections 异常向上传播而非静默吞掉
|
2026-07-10 15:28:03 +08:00 |
|
Serendipity
|
b97cff8857
|
fix: chunk 配置通过 DocumentIngestor 传递,不再被硬编码覆盖
- DocumentIngestor 新增 chunk_config 参数,类型 ChunkConfig
- ingest_file 使用 self.chunk_config.max_size/overlap 代替硬编码 1000/100
- deps.py get_ingestor 传入 config.chunk 配置对象
Co-Authored-By: Claude <noreply@anthropic.com>
|
2026-07-10 15:23:14 +08:00 |
|
Serendipity
|
405303e82c
|
fix: 修复 44 个代码审查问题 (CRITICAL/HIGH/MEDIUM/LOW)
Batch 1 — CRITICAL (1):
- 提取 is_safe_path() 到 src/core/security.py 公共模块
- CLI 和 ingest_obsidian.py 统一添加路径遍历防护
Batch 2 — HIGH (13) + 架构重构:
- CLI 复用 deps.py AppState, 消除 30 行重复代码
- AppState/get_state 添加线程安全锁
- serve 命令传递 --config 到 uvicorn (H1)
- OpenAIEmbedder 懒创建+复用 HTTP 客户端 (H2)
- DashscopeEmbedder import 移到模块顶部 (H3)
- 路径检查改用 os.path.commonpath (H4)
- embedder.embed() 返回值长度检查 (H5)
- 健康检查不泄露内部错误详情 (H7)
- /api/v1/collections 添加 API Key 认证 (H8)
- API Key 使用 hmac.compare_digest 恒定时间比较 (H9)
- 添加 CORS 中间件 (H10)
- ServerConfig 支持 SSL 配置 (H11)
- HF_ENDPOINT 修改添加详细注释 (H12)
Batch 3 — MEDIUM (20) + Splitter Protocol:
- 定义 Splitter(Protocol) 接口, DocumentIngestor 接受可选 splitter
- DashScope 响应添加结构验证 (M2)
- ingest_obsidian.py 支持 CLI 参数和 OBSIDIAN_DIRS 环境变量 (M6)
- scripts/serve.py 添加废弃警告 (M7)
- content 限制 500KB, collection 正则限制字符集 (M12-M14)
- 默认监听地址 127.0.0.1 (M16)
- 添加安全响应头中间件 (M17)
- verify_api_key 认证失败记录日志 (M19)
Batch 4 — LOW (10):
- CLI emoji 清理为纯文本标记 (L5)
- logging.basicConfig 移到 FastAPI lifespan (L1)
- VectorDB 添加 write_guard() 上下文管理器 (L3)
- IngestRequest file_path/content 互斥校验 (L10)
- ingest_obsidian.py 注释修正 (L6)
测试: 46 → 70 (+24)
- tests/test_security.py: 11 个路径安全测试
- tests/test_deps.py: 11 个依赖注入测试
Co-Authored-By: Claude <noreply@anthropic.com>
|
2026-07-06 16:56:38 +08:00 |
|
Serendipity
|
832201186d
|
fix: 修复 11 个代码架构审计问题
H1: AppConfig 自定义 __init__ 改用 from_dict() 类方法
H2: list_collections_with_stats 改为从 ChromaDB 直接查询
H3: RateLimiter 过期 key 自动清理, 防止内存泄漏
M1: delete_by_source 区分 ValueError 与真实异常, 记日志
M2: VectorDB 新增 list_collections() 封装方法
M3: _remove_by_source 异常记日志, 不再静默吞掉
M4: CLI 集合回退支持 MD_VECTOR_DB_COLLECTION 环境变量
L1: DEFAULT_CONFIG_PATH 自动从项目根目录解析
L2: ingest 命令内重复 import 移至模块顶部
L3: 新增死循环回归测试 + 密集分隔符分块测试
L4: 统一 logger 名称为 md-vector-db
删除旧版审计文档
测试: 48 passed
|
2026-07-06 13:16:26 +08:00 |
|
Serendipity
|
0aee167085
|
feat: multi-collection support — each project uses its own isolated collection
|
2026-07-05 02:07:02 +08:00 |
|
Serendipity
|
4114a168b4
|
refactor: FastAPI Depends injection replacing globals, real health check, logging config
|
2026-07-05 01:46:59 +08:00 |
|