lfnovo/open-notebook
53.3
Adequate · 20 September 2026
55.6k
lines of production code
TypeScript
with Python
1
measurement over time
What this system is
This system is an AI-powered knowledge management application that allows users to ingest, organize, and interact with diverse data sources through notebooks and chat interfaces. It features a robust backend for processing content via embeddings and transformations, alongside specialized capabilities for generating podcasts from source material. The platform supports a wide range of AI providers with secure credential management and offers a modern, responsive frontend for searching, analyzing, and synthesizing information.
How it got here
2024–2025 — Quiet Green redesign and architecture modernization
47 changes.
This period focused on a comprehensive visual overhaul to the 'Quiet Green' design system and a major backend restructuring, including the migration to a modular architecture, async database migrations, and credential-based API key management. The frontend was rebuilt using Next.js 16 and React 19, replacing legacy Streamlit components with a new dashboard, command palette, and robust state management. Concurrently, the application introduced significant new features such as background processing for embeddings and podcasts, a refined three-stage RAG 'Ask' graph, and enhanced source and notebook management interfaces.
2026 — AI infrastructure and security hardening
13 changes.
This period focused on centralizing AI provider management by replacing environment variables with a secure, database-backed credential system and model registry. Significant security improvements included hardening connection tests, preventing Jinja2 template injection, and securing audio file storage paths. The work also enhanced search capabilities, standardized mathematical formatting in prompts, and expanded frontend localization and testing infrastructure.
Features
Credential-based API key management replaces environment variables
The Settings page now uses a new credential system to manage provider configurations, replacing the previous environment-variable approach. Users can add, edit, and delete API keys via the new CredentialFormDialog, with provider-specific fields for Vertex (project, location, credentials path), Ollama (context length), and OpenAI-compatible providers (base URL hints). The interface includes a MigrationBanner to migrate existing environment-based configs to the database, and a DeleteCredentialDialog that allows migrating linked models to another credential before deletion. Provider sections display modality badges, connection status, and options to test credentials or discover models, while DefaultModelSelectors now support clearing optional model defaults and show fallback hints.
frontend/src/components/settings · high confidence
Dashboard layout with authentication guard and command palette
The dashboard area now includes a layout component that enforces authentication before rendering content, redirecting unauthenticated users to the login page while preserving the intended destination. It also integrates a global command palette for quick navigation and search, along with providers for modals and creation dialogs, and wraps the content in an error boundary. The main dashboard page itself now automatically redirects users to the notebooks section.
frontend/src/app/(dashboard) · high confidence
Expanded UI localization to 14 languages with automated parity testing
The frontend now supports 14 languages (English, German, Spanish, French, Italian, Japanese, Russian, Brazilian Portuguese, Turkish, Catalan, Polish, Bengali, and Simplified/Traditional Chinese). This change introduces the complete translation files for all supported locales, registers them in the central i18n configuration, and adds comprehensive test coverage to ensure key parity, correct interpolation placeholder usage, and no unused keys across all languages.
frontend/src/lib/locales · high confidence
Introduce open\_notebook.utils package with context building, chunking, and embedding utilities
This change introduces the new \open\_notebook.utils\ package, consolidating shared logic previously scattered across the codebase. It provides a \ContextBuilder\ for assembling chat context from sources, notes, and insights with token-aware truncation and priority management. The package includes \chunking.py\ for content-type-aware text splitting (HTML, Markdown, plain text) with configurable chunk sizes and overlap, and \embedding.py\ for unified embedding generation with automatic batching and mean pooling. Additional utilities cover field-level encryption for API keys, LLM error classification, proxy configuration to bypass internal database connections, runtime capability probes for optional engines like Docling and Crawl4AI, and text processing helpers for handling thinking tags and structured content formats.
_open\notebook/utils · high confidence
New API router structure and endpoints for Open Notebook
The \api/routers\ directory has been reorganized into a modular structure with dedicated files for distinct functional areas. This introduces a new \/auth/status\ endpoint to check authentication configuration, a \/capabilities\ endpoint to report the availability of opt-in extraction runtimes (Docling, Crawl4AI), and a \/config\ endpoint that provides version information, update status, and database health checks. Chat functionality is now handled by a dedicated \chat.py\ router that manages sessions and messages, supported by a shared \\_chat\_shared.py\ module for common logic. Additional routers provide endpoints for managing AI provider credentials (\credentials.py\), executing background commands (\commands.py\), handling content embedding (\embedding.py\), rebuilding embeddings (\embedding\_rebuild.py\), managing podcast episode profiles (\episode\_profiles.py\), and accessing source insights (\insights.py\).
api/routers · high confidence
New Advanced settings page with system info and embedding rebuild tools
A new Advanced page has been added to the dashboard, featuring a SystemInfo component that displays the current application version, checks for available updates, and provides a link to the GitHub repository, alongside a RebuildEmbeddings component that allows users to configure and trigger the rebuilding of vector embeddings for sources, notes, and insights with real-time progress tracking.
frontend/src/app/(dashboard)/advanced · high confidence
New Docker Compose examples for local AI and speech processing
The examples directory now provides ready-to-use Docker Compose configurations for various deployment scenarios. Users can deploy a fully local AI stack with Ollama and Speaches for private, offline text-to-speech and speech-to-text processing, or use a simplified single-container setup for constrained environments. A new EasyPanel template is also included for one-click deployment on the EasyPanel platform. Additionally, the development configuration has been updated to bind the database port to localhost only for improved security and to align with the new multi-container structure.
examples · high confidence
New Podcasts dashboard page with Episodes and Templates tabs
A new Podcasts page has been added to the dashboard, providing a unified interface to manage podcast content. The page features two main views: an 'Episodes' tab for managing individual episodes and a 'Templates' tab for managing podcast templates. It includes logic to detect unconfigured episode or speaker profiles and displays a warning alert if setup is required. The page uses the application's standard shell and tab components, integrating with existing hooks for episode and speaker profiles.
frontend/src/app/(dashboard)/podcasts · high confidence
New Settings page with refresh capability
A new Settings page has been added to the dashboard, providing a user interface to manage application settings via the SettingsForm component. The page includes a refresh button that allows users to reload their current settings data.
frontend/src/app/(dashboard)/settings · high confidence
New Source Chat system prompt with math formatting and citation rules
A new system prompt for the Source Chat feature has been introduced to guide the AI assistant in analyzing specific source documents. The prompt instructs the model to leverage both source content and generated insights, enforce strict citation formats using document and insight IDs, and use specific LaTeX delimiters ($$...$$ for display, $...$ for inline) for mathematical expressions. It also includes instructions to handle unavailable source text gracefully and maintain focus on the provided document.
_prompts/source\chat · high confidence
New Sources management page with sorting and keyboard navigation
The Sources page has been implemented, allowing users to view, sort, and manage their data sources. Users can sort the source list by any column in ascending or descending order, navigate the list using keyboard arrows and Enter key, and add new sources via a dedicated dialog. The page features infinite scrolling for large datasets and includes an empty state with a 'New Source' button when no sources exist.
frontend/src/app/(dashboard)/sources · high confidence
New Transformations workspace with per-transformation model selection and Markdown playground
A new Transformations page has been added to the dashboard, allowing users to create, edit, and manage AI transformations. This feature introduces per-transformation custom model selection, letting users assign specific language models to individual transformations rather than using a global default. The workspace includes a dedicated playground for testing transformations with live input/output, featuring support for Markdown and LaTeX math rendering in the results. Users can also configure a default system prompt that applies to all transformations, and the interface provides a collapsible list view for managing multiple transformation definitions.
frontend/src/app/(dashboard)/transformations · high confidence
New UI component library and secure Markdown editor
The frontend now includes a comprehensive set of new UI primitives (Accordion, AlertDialog, Alert, Badge, Button, Card, Checkbox, Collapsible, Command, Dialog, DropdownMenu, FormSection, Input, Label) built on Radix UI and Tailwind CSS, providing a consistent design foundation. Additionally, a new MarkdownEditor component is introduced that supports live preview with KaTeX math rendering and syntax highlighting, while strictly sanitizing user input to prevent XSS attacks by stripping dangerous elements like iframes and scripts, yet preserving safe features like code-block copy buttons.
frontend/src/components/ui · high confidence
New background command infrastructure for embeddings, podcasts, and source processing
The application now offloads heavy operations—embedding notes/insights/sources, generating podcasts, and processing sources with transformations—to a dedicated background worker via the \surreal-commands\ library. This change introduces new command handlers (\embed\_note\_command\, \generate\_podcast\_command\, \process\_source\command\, etc.) that run asynchronously, preventing UI blocking during long-running tasks. Podcast generation now uses UUID-based directory names for safety and resolves speaker profiles by record ID. Source processing includes robust retry logic for transaction conflicts and ensures embedding jobs are submitted as fire-and-forget background tasks. The \\\init\\_.py\ also ensures internal database connections bypass HTTP proxies to avoid websocket tunneling issues.
commands · high confidence
New common UI components and language switching support
The frontend now includes a suite of reusable UI components in the common directory, including a Command Palette for quick navigation and search, a Language Toggle for switching between supported locales, a Theme Toggle for light/dark/system themes, and a Model Selector for choosing AI models. Additional shared components such as ConfirmDialog, ConnectionGuard, ContentUnavailable, ContextIndicator, ContextToggle, EmptyState, ErrorBoundary, InlineEdit, and LoadingSpinner have been added to standardize user interactions and error handling across the application.
frontend/src/components/common · high confidence
New frontend hooks for authentication, credentials, and model management
The \frontend/src/lib/hooks\ directory now includes a comprehensive set of React hooks to manage application state and API interactions. This adds \useAuth\ for handling login, logout, and session hydration, \useCredentials\ for managing API keys and provider configurations, and \useModels\ for listing, creating, and testing AI models. It also introduces \useCapabilities\ to detect available extraction runtimes, \useCreateDialogs\ to centralize dialog state, and \useModalManager\ to control modals via URL parameters. Additionally, hooks for notebooks, notes, podcasts, search, and settings have been added to streamline data fetching and mutations across the application.
frontend/src/lib/hooks · high confidence
New notebook creation dialog and collapsible column component
Users can now create new notebooks via a dedicated dialog that validates input using Zod and integrates with the existing translation system for localized labels. Additionally, a new collapsible column component has been introduced to manage sidebar visibility, featuring specific styling adjustments to ensure correct text orientation for CJK characters when collapsed.
frontend/src/components/notebooks · high confidence
New notebooks dashboard with list/tile view toggle and recent items
The notebooks page now features a dedicated dashboard layout that includes a 'Recently Viewed' section at the top, followed by active and archived notebook lists. Users can switch between tile and list display modes using the new view toggle buttons, search across notebooks, and create new notebooks directly from the page. The interface also supports filtering active and archived items by name and provides a refresh button to update the list.
frontend/src/app/(dashboard)/notebooks · high confidence
New operational scripts for documentation, link validation, and container startup
This change introduces several new utility scripts to the \scripts/\ directory. \export\_docs.py\ consolidates markdown documentation files from subdirectories into single files with a generated Table of Contents, facilitating use with platforms that have file upload limits. \check\_md\_links.py\ validates relative links within tracked markdown files to detect broken references. \docker-entrypoint.sh\ adds opt-in support for heavy extraction runtimes (Docling and Crawl4AI) at container startup, installing them conditionally based on environment variables while ensuring graceful degradation if installation fails. Finally, \wait-for-api.sh\ ensures the frontend waits for the API to be healthy before starting, preventing initial connection errors.
scripts · high confidence
New podcast generation prompts with solo-speaker support
Added \prompts/podcast/outline.jinja\ and \prompts/podcast/transcript.jinja\ to drive podcast creation. The outline prompt generates a structured JSON outline from a briefing and context, and the transcript prompt produces segment-level dialogue. The transcript prompt now supports a solo-speaker mode: when only one speaker is provided, it enforces that speaker for all dialogue and prevents inventing additional speakers, while multi-speaker conversations continue to distribute lines based on personality and expertise.
prompts/podcast · high confidence
New podcast profile management forms
Added EpisodeProfileFormDialog and SpeakerProfileFormDialog components to the frontend, enabling users to create and edit podcast episode and speaker profiles. These forms validate inputs using Zod schemas, support localization via i18next, and integrate with backend hooks for profile creation and updates, including handling of speaker configurations and LLM model selections.
frontend/src/components/podcasts/forms · high confidence
New release-candidate verification tooling for local testing
Added executable scripts and configuration files in the release-test directory to support local verification of release candidates. The rc-stack.sh script allows users to spin up a complete stack (app, SurrealDB, and an Nginx reverse proxy) using a specific image tag, optionally importing a data dump or enabling heavy runtimes like Docling and Crawl4AI. The release-image-test.sh script provides automated gates for fresh-install and upgrade scenarios, ensuring database migrations and worker processes function correctly on the published image. These tools also include container-level probes to verify environment variable handling (such as worker concurrency and proxy settings) within the shipped Docker image.
scripts/release-test · high confidence
New search components for model selection, notebook scoping, and result streaming
The search interface now includes an Advanced Models dialog that lets users independently select language models for strategy, answer, and final answer generation. A NotebookScopeSelector allows users to restrict search and ask operations to specific notebooks, with a clear action to reset the scope. The StreamingResponse component has been updated to display collapsible sections for the AI's reasoning strategy and individual intermediate answers, while the final answer renders with clickable reference links that open detail modals. A SaveToNotebooksDialog enables users to save the question and answer pair into selected notebooks.
frontend/src/components/search · high confidence
New source creation workflow with batch processing and HTML paste support
The source creation interface has been rebuilt into a multi-step wizard (SourceTypeStep, NotebooksStep, ProcessingStep) that allows users to add sources via URL, file upload, or text entry. This update introduces batch processing capabilities, enabling users to submit multiple URLs or files at once (up to 50), with validation and error reporting for invalid entries. Additionally, the text input now detects and preserves HTML content from the clipboard, and users can optionally select existing notebooks and apply transformations during the creation process.
frontend/src/components/sources/steps · high confidence
New source detail page with integrated chat
A new page component has been added at the source detail route, presenting a split-view layout that displays the source information alongside a dedicated chat panel. This interface allows users to view source details and interact with a chat session simultaneously, supporting features like session management, model selection, and message streaming within the same view.
frontend/src/app/(dashboard)/sources/\[id\] · high confidence
New source management and chat components
The sources directory now includes a comprehensive set of new components for managing and interacting with sources. Users can add new sources via a multi-step wizard (AddSourceDialog) supporting links, file uploads, and text, with options to link them to notebooks and apply transformations. Existing sources can be linked to notebooks through a dedicated dialog (AddExistingSourceDialog) that deduplicates search results by parent ID. Source cards (SourceCard) display status and actions like retry or refresh. A new ChatPanel component enables conversational interaction with sources, featuring session management, model selection, and message actions like saving to notes or copying. Notebook associations can be managed directly from the source view.
frontend/src/components/sources · high confidence
New utility modules for date localization, error handling, and source/note context management
This change introduces several new utility modules in the frontend library. The \date-locale.ts\ module adds support for mapping language codes (including Japanese, Turkish, German, Spanish, Catalan, Russian, Bengali, Brazilian Portuguese, and Polish) to date-fns locales for proper date formatting. The \error-handler.ts\ module provides utilities to map backend API error messages to i18n keys, improving error clarity for users. The \source-context.ts\ and its tests implement logic for bulk including or excluding sources and notes from chat context, allowing users to manage which data is included in LLM queries. Finally, \source-references.tsx\ adds functionality to parse and render clickable citations for sources, notes, and insights within chat text.
frontend/src/lib/utils · high confidence
Notebook page introduces bulk source/note context controls and mobile tabbed navigation
The notebook detail page now supports bulk-include/excluding all sources and notes from the chat context, with the selected default action persisting for newly loaded items via pagination. On mobile devices, the layout switches to a tabbed interface (Sources, Notes, Chat) to avoid double-mounting components, while desktop retains the multi-column view. The page also handles notebook ID decoding and displays a not-found state when the notebook is missing.
frontend/src/app/(dashboard)/notebooks/\[id\] · high confidence
Notebooks UI components and tests added
This change introduces the core UI components for the Notebooks feature, including the NotebookCard and NotebookRow for list views, the NotebookHeader for inline editing and archive/delete actions, and the NotebookDeleteDialog which now supports a preview step and options to keep or delete exclusive sources. It adds the NotesColumn for managing notes with bulk context inclusion/exclusion and the NoteEditorDialog with support for fullscreen mode and handling of missing or error states. The ChatColumn component is added to display the chat interface with context statistics, and a RecentlyViewed section is introduced to show quick links to recent notebooks and sources. Comprehensive unit tests are added for ChatColumn, NoteEditorDialog, and NotesColumn to verify loading states, error handling, and user interactions.
frontend/src/app/(dashboard)/notebooks/components · high confidence
Quiet Green design foundation and dev-only styleguide
The application now uses the 'Quiet Green' design system, introducing a new color palette (fern, sage, gold, teal, etc.), specific typography (Instrument Sans, Bricolage Grotesque, Spline Sans Mono), and UI primitives (cards, buttons, inputs) defined in the new \globals.css\. A new \/dev/design\ page has been added as a living styleguide to visualize these tokens and components; this page is internal-only and returns a 404 in production builds.
frontend/src/app · high confidence
Settings form with Docling runtime gating and new enrichment toggles
The Settings page now includes a new SettingsForm component that manages content processing options, including the addition of Docling formula and vision enrichment toggles. The form dynamically gates Docling and Crawl4AI engine options based on backend capability probes: if the runtimes are unavailable, the relevant controls are disabled and helpful hints are shown; if the probe fails, it fails closed to prevent advertising unverified engines; and during loading, it optimistically assumes availability to avoid UI flicker. The form also handles resetting from saved settings and submitting updates via the useUpdateSettings hook.
frontend/src/app/(dashboard)/settings/components · high confidence
Removals
Removal of legacy Streamlit UI components
The \stream\_app\ module has removed several core UI files (\chat.py\, \note.py\, \source.py\, \consts.py\, and \utils.py\) that previously provided the chat interface, note management dialogs, source ingestion panels, and session state utilities. This deletion eliminates the direct Streamlit-based frontend capabilities for chatting, editing notes, and processing sources within this specific application area.
_stream\app · high confidence
Removed legacy Notebooks and Search pages
The legacy Streamlit-based Notebooks and Search pages have been removed from the application. This deletes the previous UI for managing notebooks (creating, editing, deleting) and performing text/vector searches, which are being replaced by the new architecture.
pages · high confidence
Security
Fix: Prevent Jinja2 template injection in generic prompt pattern
A new generic Jinja2 template file has been added to the prompts/pattern directory to safely render user-provided prompts. This change addresses a security vulnerability where user-controlled input was previously compiled as Jinja2 template source, potentially allowing template injection attacks. The new template ensures that user input is treated as literal text rather than executable template code, while still supporting optional format instructions.
prompts/pattern · high confidence
Secure runtime API URL configuration with strict header validation
The frontend now exposes a runtime configuration endpoint that determines the API base URL by validating the incoming Host and X-Forwarded-Proto headers against strict regular expressions. This change prevents header-injection attacks where a malicious proxy could redirect browser API traffic (including auth tokens) to an attacker-controlled host. The endpoint prioritizes the explicit API\_URL environment variable, falls back to auto-detection from validated headers, and safely defaults to localhost if the headers are malformed or missing.
frontend/src/app/config · high confidence
Architecture
Backend architecture refactoring and new error handling
The open\_notebook backend has been reorganized: the monolithic domain, repository, and utility modules have been removed in favor of a modular structure (domain module, database migrations, and specific service files), and a new configuration file standardizes data, upload, podcast, and tiktoken cache folders. Additionally, new exception types (UnsupportedTypeException, ContextLengthExceededError, NoTranscriptFound) have been added to improve error specificity, and developer documentation (AGENTS.md) has been introduced to guide backend changes.
_open\notebook · high confidence
Behavioural changes
API service layer reorganization and security hardening
The API codebase has been restructured into a dedicated \api/\ directory, introducing a service-layer pattern for credentials and podcast operations to separate business logic from routing. Security is strengthened by enforcing constant-time password comparison, rejecting oversized request bodies before authentication, and ensuring CORS headers are correctly applied to error responses. The startup process is now resilient to a not-yet-ready database, and environment variable loading is centralized at the application entry point.
api · high confidence
Ask and chat now support reasoning models and scoped search
The Ask feature now uses a three-stage graph (strategy, per-search answers, final synthesis) with an increased output budget of 8192 tokens to prevent truncation in token-dense languages and to allow reasoning models to think before answering. The Ask graph now supports notebook scoping so searches run only against sources linked to selected notebooks, and it fails fast when the strategy model returns no search terms. Chat and source chat also clean thinking tags from model responses and use a unified model-provisioning path. Source extraction was migrated to content-core 2.x with fallback to 'auto' when a configured engine's runtime is missing, and YouTube transcript selection now honors a broader default language list. The old ask\_content and content\_process graphs were removed, and the chat graph no longer uses the ask\_the\_document tool.
_open\notebook/graphs · high confidence
Async database migration system and SurrealQL injection protections
The database layer now uses an async migration runner (open\_notebook/database/async\_migrate.py) that executes 25 SurrealQL migration files, with a synchronous wrapper (migrate.py) for backward compatibility. Additionally, repository functions (repository.py) now validate table and relationship identifiers to prevent SurrealQL injection in RELATE, UPSERT, and UPDATE operations, and ensure the internal SurrealDB WebSocket connection bypasses HTTP proxies.
_open\notebook/database · high confidence
Centralized AI provider management with credential-based key storage and secure connection testing
The AI infrastructure module has been restructured to use a single provider registry as the source of truth, replacing scattered configuration dicts. API keys are now managed via database-backed credentials with environment variable fallback, and connection tests have been hardened to prevent filesystem information leakage (specifically for Vertex credentials) and to pin DNS resolution at request time to mitigate rebinding attacks. Model discovery and provisioning now rely on this unified registry, ensuring that provider metadata, test models, and environment mappings are consistent across the backend.
_open\notebook/ai · high confidence
Database schema and search logic updates
This update introduces a series of database migrations that enhance search performance and flexibility, introduce credential-based API key management, and refine podcast profile configurations. Search functions now support notebook-scoping and resolve insight hits to parent sources, while new indexes improve source listing speed. A dedicated credential table replaces the previous provider configuration singleton, allowing for more granular API key and model settings. Podcast profiles now use model registry references instead of legacy provider/model strings, and audio file paths are stored relative to the podcast folder. Additionally, the system now tracks recently viewed notebooks and sources, exposes Docling enrichment toggles, and allows per-transformation model selection.
_open\notebook/database/migrations · high confidence
Frontend restructured with Next.js 16, larger upload limits, and renamed Models settings
The frontend has been restructured around a new Next.js 16 configuration that increases the proxy body size limit to 100MB to support larger file uploads and simplifies reverse proxy routing via rewrites to the FastAPI backend. The legacy 'API Keys' settings page has been renamed to 'Models' (with a permanent redirect from /settings/api-keys), and the dev server now supports custom allowed origins via the NEXT\_ALLOWED\_DEV\_ORIGINS environment variable. The project also includes a new standalone server startup script defaulting to port 8502, updated linting and testing configurations, and comprehensive documentation for frontend development rules.
frontend · high confidence
Improved API URL resolution and credential update reliability
The frontend now uses a centralized configuration module that prioritizes runtime API settings from the server over environment variables, resolving connectivity issues for reverse proxy users. Additionally, credential updates are fixed to correctly clear fields by sending explicit null values instead of undefined, ensuring that emptying a field in the UI actually removes it on the backend.
frontend/src/lib · high confidence
Introduces new Zustand-based state management stores for authentication, navigation, theming, and UI layout
The application now uses dedicated Zustand stores to manage core frontend state, replacing previous implementations. The new auth-store handles login, logout, and session validation with specific error handling for network issues and server connectivity. A theme-store enables users to switch between light, dark, and system themes, persisting the choice to localStorage and applying it to the document root. Navigation and layout preferences are now managed by separate stores: navigation-store tracks return paths with a 1-hour staleness check, notebook-columns-store persists the collapsed state of sources and notes panels, notebook-view-store saves the list/tile view preference, and sidebar-store manages the sidebar's collapsed state. All stores use persistence middleware to retain user preferences across sessions.
frontend/src/lib/stores · high confidence
Introduction of comprehensive TypeScript type definitions for frontend-backend contracts
The frontend now includes a complete set of TypeScript interfaces in \frontend/src/lib/types\ that strictly define the data structures exchanged with the backend API. This covers core domain models (Notebooks, Notes, Sources), configuration and connection states, authentication, and the model registry. It also introduces specific types for new and enhanced features: podcast episode profiles and speaker configurations (referencing profiles by ID), search and 'Ask' requests scoped to specific notebooks, source chat sessions with context indicators, and per-transformation model selection. These definitions ensure type safety across the application and align the frontend with the current Python API schema.
frontend/src/lib/types · high confidence
New application shell and sidebar layout with credential migration guidance
The frontend layout has been restructured with a new AppShell component that wraps the main content area, and a comprehensive AppSidebar featuring collapsible navigation, platform-aware keyboard shortcuts, and updated menu items (including the renamed 'Models' page). A new SetupBanner component now appears at the top of the main content, alerting users if encryption is not configured or if they need to migrate provider credentials from environment variables to the new credential-based system.
frontend/src/components/layout · high confidence
New frontend API client layer with configurable timeouts and standardized query keys
The frontend now uses a centralized API client (\frontend/src/lib/api/client.ts\) that automatically attaches authentication tokens, resolves the base URL dynamically, and handles 401 redirects. A key behavioral change is the default request timeout, which is now set to 10 minutes (600,000ms) to accommodate slow LLM operations, and can be overridden via the \NEXT\_PUBLIC\_API\_TIMEOUT\_MS\ environment variable. This client powers a new set of typed API modules (e.g., \chatApi\, \credentialsApi\, \sourcesApi\) and a standardized React Query configuration (\query-client.ts\) that defines consistent query keys and retry logic for the application.
frontend/src/lib/api · high confidence
New structured RAG query process with improved citation and math formatting
The Ask feature now uses a new three-stage prompt strategy (entry, query\_process, final\_answer) to improve research accuracy. The system first formulates a search strategy, then generates answers for specific terms, and finally synthesizes a response. This update enforces stricter citation rules, requiring exact document IDs (including type prefixes like 'note:' or 'source:') to be used in brackets, and introduces specific formatting instructions for math (using $$ for display and $ for inline) to ensure proper rendering.
prompts/ask · high confidence
New system prompt for chat assistant with math and citation guidance
A new system prompt file (prompts/chat/system.jinja) has been introduced to define the behavior of the chat assistant. This prompt instructs the model to act as a cognitive study assistant, specifically directing it to use $$...$$ for display math and $...$ for inline math to ensure proper rendering. It also enforces strict citation rules, requiring the assistant to reference documents using their exact IDs (including type prefixes like 'note:' or 'source:') found in the provided context, and prohibits making up document IDs.
prompts/chat · high confidence
Podcast generation and management UI overhaul
The podcast workspace has been rebuilt with a new content selection interface that allows users to choose specific notebooks, sources, and notes for generation, including granular source modes (insights vs. full content) and real-time token/character counting. Episode cards now display resolved model details (provider and model name) for both new and legacy episodes, with graceful fallbacks for unresolvable references. Profile management panels for episodes and speakers have been introduced, enabling users to create, edit, duplicate, and delete profiles, with clear indicators for required model setup and voice model configuration. The generation dialog has been refactored to handle content selection and context building more robustly, addressing previous token-count race conditions.
frontend/src/components/podcasts · high confidence
Podcast generation now uses model registry IDs and secure relative audio paths
Podcast episode and speaker profiles now reference AI models (for outlines, transcripts, and TTS) by their database record ID instead of legacy provider/model strings, allowing the system to resolve credentials and configurations (including Anthropic-compatible settings and max\_tokens) from the central model registry. Additionally, audio file storage has been secured: paths are now stored relative to the podcasts folder, with validation logic that rejects absolute paths or directory traversal attempts, ensuring that generated audio files are safely contained within the designated output directory.
_open\notebook/podcasts · high confidence
Quiet Green design foundation and screen-by-screen reskin
The application receives a comprehensive visual overhaul called the "Quiet Green" design system. This update replaces the previous color palette and typography with a new semantic token system (fern green primary actions, teal for AI/system voice, clay for warnings) and switches fonts to Bricolage Grotesque, Instrument Sans, and Spline Sans Mono. The reskin is applied across the app shell, notebook workspace, sources table, dialogs, and settings pages, resulting in a flatter, more unified interface with improved theme tracking (including for the markdown editor) and better handling of UI elements like list markers and long model names. This is a purely visual change with no new features or behavioral modifications.
(repo-wide) · high confidence
Refactored domain models and introduced credential-based API key management
The domain layer has been restructured to support a new credential-based system for managing AI provider configurations. The legacy singleton \ProviderConfig\ is replaced by individual \Credential\ records that store encrypted API keys and provider-specific settings (such as base URLs, endpoints, and Vertex AI project details) in a flexible \config\ object, allowing new options like Ollama's \num\_ctx\ to be added without database migrations. This change also introduces a new \ContentSettings\ model to expose user-facing toggles for content processing, including Docling OCR, formula extraction, vision enrichment, and YouTube language preferences. Additionally, the \Notebook\ model now supports cascade deletion of associated chat sessions and provides a detailed delete preview, while the base \ObjectModel\ enforces stricter validation to prevent SurrealQL injection in order-by clauses.
_open\notebook/domain · high confidence
Removal of legacy prompt templates
The application has removed four existing Jinja2 prompt templates: ask\_content.jinja, chat.jinja, spr.jinja, and summarize.jinja. These files previously defined the system instructions and context structures for content querying, conversational chat with tool usage, Sparse Priming Representation generation, and incremental summarization. Their deletion indicates a shift in how the model interactions are configured, likely moving towards a new prompt management strategy or different underlying logic.
prompts · high confidence
Search page handles URL parameters and opens matched records directly
The search page now supports navigation via URL parameters (e.g., from the command palette), automatically triggering a search or ask based on the 'q' and 'mode' query strings. Additionally, when a user clicks on a search result, the system now opens the specific matched record (such as an insight) rather than its parent source, providing more precise access to the relevant content.
frontend/src/app/(dashboard)/search · high confidence
Standardized math formatting in transformation prompts
The transformation prompt template now explicitly instructs models to use $$...$$ for display math and $...$ for inline math, ensuring formulas render correctly in the UI. This change also clarifies that fenced LaTeX code blocks should only be used when the user explicitly requests the source code, preventing unnecessary code blocks in standard mathematical explanations.
prompts/transformation · high confidence
Fixes
Enable end-to-end SSE streaming via Next.js API proxy
Added a new internal SSE proxy utility (\_sse-proxy.ts) and two Next.js API route handlers (search/ask and chat messages) that forward requests to the upstream backend while preserving the Server-Sent Events stream. This ensures that real-time streaming responses are correctly passed through the Next.js frontend layer without buffering or interruption, improving the responsiveness of search and chat interactions.
frontend/src/app/api · high confidence
Test coverage
Added test environment setup and mocks; Added test suite for source insight failures, Anthropic-compatible provider wiring, and Ask graph behavior.
Dependencies
Migrate build system from Poetry to uv and upgrade frontend to Next.js 16
The project has switched its Python dependency management from Poetry to uv, replacing the \poetry.lock\ file with a \pyproject.toml\ that uses setuptools for building and uv for dependency resolution. This migration includes upgrading the backend Python dependencies to their latest major versions (e.g., LangChain 1.x, LangGraph 1.x) and enforcing a stricter Python version range (3.11–3.12). On the frontend, the \package.json\ and \package-lock.json\ have been updated to use Next.js 16.3.4 and React 19.2.3, alongside other dependency bumps like Axios 1.18.1. Additionally, a security override forces Pillow \>= 12.2.0 to address known vulnerabilities in older versions.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 53.
Lenses
- Code Health 70
- Architecture 53
- Maturity 72
- Readiness 58
- Security 79
- Accessibility 46
Changes since last survey
- 300 commits — 188 feature/other, 112 fixes
By area
- (root) — 114 commits
- frontend/src — 69 commits
- frontend/package-lock.json — 18 commits
- api/routers — 16 commits
- (repo) — 12 commits
- open_notebook/ai — 12 commits
- .github/workflows — 6 commits
- open_notebook/domain — 6 commits
- docs/0-START-HERE — 5 commits
- open_notebook/database — 5 commits
- api/credentials_service.py — 4 commits
- docs/5-CONFIGURATION — 4 commits
- api/CLAUDE.md — 3 commits
- commands/embedding_commands.py — 3 commits
- docs/7-DEVELOPMENT — 3 commits
- .claude/skills — 2 commits
- api/auth.py — 2 commits
- docs/1-INSTALLATION — 2 commits
- open_notebook/utils — 2 commits
- scripts/release-test — 2 commits
Notable commits
- fix: Fix SSE stream parsing in source chat: buffer partial lines and stream-decode (#1289)
- fix: Merge pull request #734 from vincentrou/fix-docs-quick-start-local
- fix: chore(frontend): typed locales, drop unused deps, fix AGENTS.md drift (#1061)
- fix: chore(lint): re-enable F401/F841/E722 and fix fallout (#1062)
- fix: chore: remove dead auth helper and fix stale default-password docs (#1026)
- fix: fix(api): let typed domain exceptions reach the global handlers (#1078)
- fix: fix(api): normalize openai_compatible provider name in models endpoint (#801)
- fix: fix(api): return 404 instead of 500 for missing resources in CRUD endpoints (#862) (#924)
- fix: fix(api): use configured base_url for OpenAI model discovery (#784)
- fix: fix(ask): raise output budget to 8192 and fail on empty strategy (#1323)
- fix: fix(auth): accept UTF-8 passwords (#1344)
- fix: fix(commands): register legacy embedding aliases (#876)
- fix: fix(credentials): emit vertex_project/vertex_location for Vertex (#1177)
- fix: fix(credentials): persist Ollama num_ctx via a flexible config object (#903)
- fix: fix(docker): force frontend bind address in supervisord so injected HOSTNAME can't break it (#1059)
- fix: fix(docker): make wait-for-api.sh POSIX and enforce LF line endings (#586) (#598)
- fix: fix(docker): retry npm ci to survive transient registry ECONNRESETs (#840)
- fix: fix(embedding): drop degenerate tiny chunks before embedding (#764) (#768)
- fix: fix(frontend): Ask spinner never stops under React Strict Mode (#1235)
- fix: fix(frontend): follow app theme in markdown editor (#1294)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
lfnovo/open-notebook was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 3127f14ea9dbb519f0e4ddc64a0742ca644ba6ef — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.