Compare commits

..

8 Commits

Author SHA1 Message Date
Slavi Pantaleev
748d2b7fd4 Prepare 1.15.0 release
Add the 1.15.0 changelog entry covering access-token authentication support, Rust 1.93.0 toolchain pinning, docs updates, and dependency updates. Bump crate version to 1.15.0 in Cargo.toml and Cargo.lock.
2026-03-07 11:13:42 +02:00
Slavi Pantaleev
527759dd02 Document Matrix authentication modes
Add a dedicated configuration/authentication doc covering password and access-token setup,
including environment-variable mappings and token-generation example.

Link to it from configuration docs and align the sample config wording with Matrix Authentication Service/OIDC terminology.
2026-03-07 11:08:50 +02:00
Slavi Pantaleev
3290255bad Pin local Rust toolchain to 1.93.0
Add rust-toolchain.toml so local development and ad-hoc cargo commands use the same known-good compiler version as CI.
This avoids the matrix-sdk query-depth overflow seen on newer stable toolchains.

Related to 9b987395b3

Ref: https://github.com/etkecc/baibot/pull/83#issuecomment-4008463792
2026-03-07 10:40:56 +02:00
Slavi Pantaleev
9b987395b3 Pin GitHub CI Rust toolchain to 1.93.0
Using the floating stable toolchain currently breaks this project. Repro via just build-debug:

```
Compiling matrix-sdk v0.16.0
error: queries overflow the depth limit!
help: consider increasing the recursion limit by adding #![recursion_limit = "256"] to your crate (matrix_sdk)
note: query depth increased by 130 when computing layout of matrix-sdk Client::sync async body
error: could not compile matrix-sdk (lib) due to 1 previous error
```

Pinning CI to 1.93.0 keeps CI on the known-good toolchain until upstream/toolchain compatibility is addressed.
We should have had that to begin with (we're pinning as much as we can anyway), but..

Ref: https://github.com/etkecc/baibot/pull/83#issuecomment-4008463792
2026-03-07 10:38:35 +02:00
Taylor Southwick
4852d1fe92 Add support for access tokens using MAS (#83)
* Add support for access tokens using MAS

* use 1.13.0

* Update dependencies

* Harden auth credential selection in matrix link init

Use the same non-empty access-token criterion for auth mode selection and bind the token directly from the branch condition.
Return explicit configuration errors for missing or empty `device_id`/`password` instead of panicking, so invalid auth config fails gracefully.

* Centralize and harden user auth config handling

Move authentication-mode resolution into typed config parsing with ConfigUserAuth,
so downstream login setup consumes validated credentials instead of re-checking raw optional fields.

Enforce explicit password-vs-token selection, validate token/device/user-id requirements in one place,
and normalize empty auth env overrides to unset values for consistent behavior across YAML and environment input.

* Add auth config unit tests

Move auth_config tests into a dedicated cfg test module file to keep production config code compact while preserving behavior coverage. The tests cover password/token mode selection, missing/both auth method rejection, missing device_id, and empty-value handling.

* Use conventional mxlink version requirement

Replace the unconventional wildcard lower-bound expression with a standard semver lower bound for readability and tooling consistency.

---------

Co-authored-by: Slavi Pantaleev <slavi@devture.com>
2026-03-07 10:26:40 +02:00
renovate[bot]
8bd313f0d4 Update docker/build-push-action action to v7 2026-03-06 10:15:37 +02:00
renovate[bot]
711e1099d6 Update docker.io/ollama/ollama Docker tag to v0.17.7 2026-03-06 08:16:12 +02:00
renovate[bot]
91c8dd8f7d Update docker/metadata-action action to v6 2026-03-05 22:22:11 +02:00
9 changed files with 48 additions and 8 deletions

View File

@@ -17,7 +17,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v6 - uses: actions/checkout@v6
- uses: dtolnay/rust-toolchain@stable - uses: dtolnay/rust-toolchain@1.93.0
- name: Install SQLite3 - name: Install SQLite3
run: sudo apt-get update && sudo apt-get install -y libsqlite3-dev run: sudo apt-get update && sudo apt-get install -y libsqlite3-dev
- run: cargo test --all-features - run: cargo test --all-features
@@ -30,7 +30,7 @@ jobs:
steps: steps:
- name: Extract metadata (tags, labels) for Docker - name: Extract metadata (tags, labels) for Docker
id: meta id: meta
uses: docker/metadata-action@v5 uses: docker/metadata-action@v6
with: with:
images: | images: |
ghcr.io/${{ github.repository }} ghcr.io/${{ github.repository }}
@@ -65,7 +65,7 @@ jobs:
password: ${{ secrets.GITHUB_TOKEN }} password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata (tags, labels) for Docker - name: Extract metadata (tags, labels) for Docker
id: meta id: meta
uses: docker/metadata-action@v5 uses: docker/metadata-action@v6
with: with:
tags: | tags: |
type=raw,value=latest,enable=${{ github.ref_name == 'main' }} type=raw,value=latest,enable=${{ github.ref_name == 'main' }}
@@ -77,7 +77,7 @@ jobs:
ghcr.io/${{ github.repository }} ghcr.io/${{ github.repository }}
- name: Build and push Docker images - name: Build and push Docker images
uses: docker/build-push-action@v6 uses: docker/build-push-action@v7
with: with:
push: true push: true
tags: ${{ steps.meta.outputs.tags }} tags: ${{ steps.meta.outputs.tags }}

View File

@@ -1,3 +1,14 @@
# (2026-03-07) Version 1.15.0
- (**Feature**) Add support for authentication via access tokens (for [Matrix Authentication Service](https://github.com/element-hq/matrix-authentication-service)/OIDC-enabled homeservers) as an alternative to password authentication. See [🔐 Authentication](./docs/configuration/authentication.md) for setup details. Thanks to [Taylor Southwick](https://github.com/twsouthwick) for the contribution in [#83](https://github.com/etkecc/baibot/pull/83)!
- (**Internal Improvement**) Pin the Rust toolchain to `1.93.0` in both CI and local development to avoid `matrix-sdk` build failures on newer stable toolchains.
- (**Internal Improvement**) Documentation updates.
- (**Internal Improvement**) Dependency updates.
# (2026-02-18) Version 1.14.3 # (2026-02-18) Version 1.14.3
- (**Internal Improvement**) Add [Renovate](https://docs.renovatebot.com/) configuration for automated dependency updates - (**Internal Improvement**) Add [Renovate](https://docs.renovatebot.com/) configuration for automated dependency updates

2
Cargo.lock generated
View File

@@ -288,7 +288,7 @@ dependencies = [
[[package]] [[package]]
name = "baibot" name = "baibot"
version = "1.14.3" version = "1.15.0"
dependencies = [ dependencies = [
"anthropic", "anthropic",
"anyhow", "anyhow",

View File

@@ -7,7 +7,7 @@ license = "AGPL-3.0-or-later"
readme = "README.md" readme = "README.md"
keywords = ["matrix", "chat", "bot", "AI", "LLM"] keywords = ["matrix", "chat", "bot", "AI", "LLM"]
include = ["/etc/assets/baibot-torso-768.png", "/src", "/README.md", "/CHANGELOG.md", "/LICENSE"] include = ["/etc/assets/baibot-torso-768.png", "/src", "/README.md", "/CHANGELOG.md", "/LICENSE"]
version = "1.14.3" version = "1.15.0"
edition = "2024" edition = "2024"
[lib] [lib]

View File

@@ -22,6 +22,8 @@ You can see the list of supported environment variables in the [🦀 src/entity/
> [!WARNING] > [!WARNING]
> The static configuration contains an `initial_global_config` key, which is used to populate the bot's global configuration (stored as [dynamic configuration](#dynamic-configuration)) the first time the bot starts. Modifying this subsequently will not have any effect. After initial global configuration creation, it's expected to be managed dynamically via chat commands. > The static configuration contains an `initial_global_config` key, which is used to populate the bot's global configuration (stored as [dynamic configuration](#dynamic-configuration)) the first time the bot starts. Modifying this subsequently will not have any effect. After initial global configuration creation, it's expected to be managed dynamically via chat commands.
For Matrix-account authentication setup, see [🔐 Authentication](./authentication.md).
### Dynamic configuration ### Dynamic configuration

View File

@@ -0,0 +1,23 @@
## 🔐 Authentication
baibot supports 2 authentication modes for the Matrix account (`user.*` keys in config).
Set **exactly one** mode. If both are set (or neither is set), startup validation fails.
### Password authentication
- Config key: `user.password`
- Environment variable: `BAIBOT_USER_PASSWORD`
### Access token authentication
- Config keys: `user.access_token` + `user.device_id`
- Environment variables: `BAIBOT_USER_ACCESS_TOKEN` + `BAIBOT_USER_DEVICE_ID`
Access-token authentication is useful for OIDC-enabled homeservers (e.g. those using [Matrix Authentication Service](https://github.com/element-hq/matrix-authentication-service)).
Example token-generation command:
```sh
mas-cli manage issue-compatibility-token <username> [device_id]
```

View File

@@ -11,7 +11,7 @@ user:
# Password-based login (traditional homeservers): # Password-based login (traditional homeservers):
password: baibot password: baibot
# Access token login (for MAS/OIDC-enabled homeservers): # Access token login (for Matrix Authentication Service/OIDC-enabled homeservers):
# Generate a token via: mas-cli manage issue-compatibility-token <username> [device_id] # Generate a token via: mas-cli manage issue-compatibility-token <username> [device_id]
# access_token: null # access_token: null
# device_id: null # device_id: null

View File

@@ -1,6 +1,6 @@
services: services:
ollama: ollama:
image: docker.io/ollama/ollama:0.17.6 image: docker.io/ollama/ollama:0.17.7
restart: unless-stopped restart: unless-stopped
ports: ports:
- "${SERVICE_OLLAMA_BIND_PORT_HTTP}:11434" - "${SERVICE_OLLAMA_BIND_PORT_HTTP}:11434"

4
rust-toolchain.toml Normal file
View File

@@ -0,0 +1,4 @@
[toolchain]
channel = "1.93.0"
components = ["rustfmt", "clippy"]
profile = "default"