summaryrefslogtreecommitdiff
path: root/source
AgeCommit message (Collapse)Author
2026-05-25Merge pull request #783 from songproducer/improve/late-page-qualityMichael Christen
fix: scale nodeStack capacity with query offset so late pages aren't …
2026-05-25Merge pull request #775 from songproducer/fix/xss-reflected-inputMichael Christen
fix: HTML-escape reflected user input and crawled document metadata to prevent XSS (#401, #630)
2026-05-23Merge pull request #777 from songproducer/fix/system-prompt-js-escapeMichael Christen
Fix JS syntax error when system prompt contains single quotes
2026-04-25fix: scale nodeStack capacity with query offset so late pages aren't evictedLeo Treasure
WeakPriorityBlockingQueue evicts lowest-scoring entries when full. With a fixed 150-slot nodeStack, page 2+ results compete against page 1 results and high-quality late-page candidates get evicted before ranking completes. Adding query.offset + query.itemsPerPage() to the initial capacity ensures enough slots exist for the requested page's candidates to survive. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-22Fix JS syntax error when system prompt contains single quotesLeo Treasure
2026-04-20fix: run blacklist import in background thread to avoid UI freeze (#625)Leo
The add operation iterated over all selected items, parsed them, and wrote to disk inline on the servlet thread. For large blacklists this blocked the whole request. Now: read all item strings from post before returning (thread safety), hand off the parse+write work to a daemon thread, and redirect immediately. Failures are logged via ConcurrentLog.warn instead of silently dropped. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-20fix: HTML-escape crawled document metadata in ViewFile parsed view to ↵Leo
prevent XSS (#630) dc_title, dc_creator, dc_subject, dc_description, dc_publisher, dc_format, and dc_identifier were all written with prop.put() and rendered unescaped in HTML <dd> elements. A malicious page title like <script>... would execute in the viewer's browser. Switch to prop.putHTML() for all dc_* metadata fields. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-20fix: HTML-escape prefermaskfilter in early-return path to prevent reflected ↵Leo
XSS (#401) In the early return path (no index / search not allowed), prefermaskfilter was reflected into value="#[prefermaskfilter]#" in yacysearch.html using prop.put(), allowing attribute-breaking XSS. The normal search path already used putHTML; apply the same to the early-return path. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-29Add thinking/tooling/vision/format model capability tests and suppress ↵Michael Peter Christen
thinking across LLM calls
2026-03-29better ranking for local hits with more contextMichael Peter Christen
2026-03-29Restore tool-enabled chat requests from persisted model capabilitiesMichael Peter Christen
2026-03-29Add configurable maximum length for RAG search documentsMichael Peter Christen
2026-03-28enhanced tooling/vision testing: persisting all testsMichael Peter Christen
2026-03-28Add search tool backed by shared RAG search document outputMichael Peter Christen
2026-03-28Respect persisted tooling capability for chat modelsMichael Peter Christen
2026-03-28if webfetch fails, it tells the LLM that this is not fatal and it should go onMichael Peter Christen
2026-03-28the mermaid generation tool now suggest to call the mermaid visualization toolMichael Peter Christen
2026-03-28hero page modification for YaCy ChatMichael Peter Christen
2026-03-28more modelsMichael Peter Christen
2026-03-28better tldr handlingMichael Peter Christen
2026-03-28Align RAG retrieval with web search and disable local post-rankingMichael Peter Christen
2026-03-28Fix yacychat P2P mode detection for global search visibilityMichael Peter Christen
2026-03-27Fix for 'n-' fragments that appeared after wrong parsing markdownMichael Peter Christen
2026-03-27Enhanced RAG Search:Michael Peter Christen
- using exactly the same search method as normal search - removed special search method
2026-03-26Strip markdown syntax from snippet text intended for browser displayMichael Peter Christen
2026-03-25modified ranking and query parser to allow more matches and better rankingMichael Peter Christen
2026-03-24renamed skills -> toolsMichael Peter Christen
2026-02-17Remove suspicious JavaScript code fragments from snippet lines.Michael Peter Christen
2026-02-17fixed parsing of x-data-elements in <div>Michael Peter Christen
2026-02-15fixed api-key handlingMichael Peter Christen
2026-02-10added vfs storage to yacychat so the current history does not depend on ↵Michael Peter Christen
localStorage any more
2026-02-10added virtual file system that stores users data in the users browserMichael Peter Christen
2026-02-09Renamed Table_API_p.html -> Automation_p.htmlMichael Peter Christen
2026-02-08added skill configuration: we present llm tools as "Skills" and makeMichael Peter Christen
them configurable in the YaCy GUI.
2026-02-08more safe configSaveMichael Peter Christen
2026-02-08added Mermaid rendering toolMichael Peter Christen
2026-02-08fix for NetworkPicture not giving away sync releaseMichael Peter Christen
2026-02-07added tool calling abilities to yacychat.html and added a tool handler to ↵Michael Peter Christen
RAGProxyServlet; also provided a large set of basic tools to handle calculations, date understanding, unit conversion, web fetch, number parsing, self reflection and more
2026-01-25Merge pull request #757 from pr0vieh/fix/745-persist-recrawl-jobMichael Christen
Persist recrawl job to restart on peer boot
2026-01-25Merge pull request #755 from Johnny1984/masterMichael Christen
HTML5 <meta charset="..."> support
2026-01-23Persist recrawl job to restart on peer bootpr0vieh
2026-01-22HTML5 <meta charset="...> supportJohnny1984
Fixes mojibake when crawling some websites.
2026-01-21Add DNS/network errors (-1) to permanent error status codespr0vieh
- DNS errors (NXDOMAIN, SERVFAIL, UnknownHostException) now treated as permanent failures - Updated default permanentStatus from '404,410' to '404,410,-1' - Added documentation explaining -1 status code represents DNS/network failures - Updated UI description in IndexFederated_p.html to reflect DNS error handling - Affects both transferURL and transferRWI DHT operations
2026-01-21Add configurable DHT error URL blocking with retry window and web UIpr0vieh
- Implement proactive DHT error URL rejection for both URL and RWI transfers - Add configurable opt-out via indexReceiveBlockErrors setting (default: true) - Introduce retry window for temporary errors (default: 30 days) - Permanent errors (404, 410) always blocked, configurable via permanentStatus - Add web UI controls in IndexFederated_p.html under Peer-to-Peer section - Bidirectional feedback: receivers reject and report error URLs to senders - Detailed logging shows blocked vs error-blocked counts separately - Uses load_date_dt field to calculate error age for retry decisions
2026-01-20feat: Add two-layer DHT error propagation to prevent broken URL redistributionpr0vieh
Problem: Failed URLs (404, DNS errors, timeouts) are continuously redistributed via DHT, causing infinite recrawl loops and network-wide index pollution. No mechanism exists in YaCy to communicate error status across peers. Solution - Layer 1 (Proactive Rejection): - Receiver checks local Solr index for httpstatus_i != 200 BEFORE accepting RWI entries - Rejects URL immediately if marked as failed previously - Adds rejected URL hash to errorURL response list - Prevents index pollution at ingestion time - Works even if sender doesn't support errorURL protocol (backward compatible) Solution - Layer 2 (Error Feedback): - Receiver reports rejected error URLs back to sender via errorURL response parameter - Sender receives errorURL list and marks those URLs locally as failed - Sender stops re-distributing these URLs to other peers - Network-wide error propagation prevents repeated distribution cycles Implementation Details: - transferURL.java: Implements proactive rejection + error reporting * Checks incoming URL against Solr error status before storing * Collects rejected URL hashes in errorURLs StringBuilder * Returns errorURL list to sender in response - Protocol.java: Processes error URL feedback from receiver * Extracts errorURL from response * Marks reported URLs locally via crawlQueues.errorURL.push() * Logs DHT error reports for monitoring Benefits: - Dramatically reduces network traffic of broken URLs - Prevents wasted crawl resources on unreachable targets - Maintains clean, usable index across distributed network - Defense-in-depth: two independent layers work together - Backward compatible: old peers ignore errorURL parameter Testing: - Log monitoring shows 'DHT: Received X rejected error URL reports from peer Y' - Proactive rejection shows 'blocked X URLs' in transfer logs - Error URLs automatically removed from circulation
2026-01-08fix for no search results within RAG local searchMichael Peter Christen
2026-01-08fixed bug in ai.production_models default value and replaced someMichael Peter Christen
outdated LLMs with new ones
2026-01-08replaced codex with regulaMichael Peter Christen
2026-01-06added global search to chatMichael Peter Christen
2026-01-03Fix: avoid 0-results by using remote metadata results when availableMichael Peter Christen
Use the remote metadata list directly (via addNodes) after storing/committing remote search results. This bypasses the flaky RWI→metadata lookup that can drop all results and yield a ZERO COUNT even when peers return references.