## infiniflow/ragflow — v0.26.2…v0.26.3

_140 commits._

### Features
- **feat(go): implement chatbots/<dialog_id>/info and searchbots/detail (#15420)** (7d422ba)
- **add web and build start steps (#16572)** (3e7e5f4)
- **Feat: add DOCX parser (#16521)** (c8cf0c9)
- **feat(agent): report accurate aggregated token usage and propagate session/user + input/output to Langfuse for agent runs (#16420)** (742188c)
- **feat(frontend): add AuthenticatedImg component for authorized image requests (#16525)** (81cfcdf)
- **feat(agent): add BGPT structured literature evidence search tool (#16050)** (9bf5760)
- **Feat: SoMark (#16482)** (400476f)
- **[Go] Add API /api/v1/chat/recommendation and consolidate with /api/v1/searchbots/related_questions (#16500)** (8f24b30)
- **feat(mcp): add ragflow_list_datasets and ragflow_list_chats tools (#15384)** (f60245f)
- **Add CAJAL scientific paper agent template (#14641)** (06b07bb)
- **Add spacy based ner and relationship extractor for both python and Go version with equivalent outputs (#16456)** (5af361e)
- **feat(go-api): Migrate Box web OAuth connector APIs to Go (#16480)** (3633d08)
- **[Go] Add /api/v1/searchbots/mindmap and /api/v1/chat/mindmap (#16443)** (3bb976b)
- **Go CLI: add admin_command  response table funtion (#16454)** (5276baf)
- **Go CLI: add show users plan summary (#16463)** (6370fce)
- **Revert "feat(go-api): Add Go chat session message delete and feedback APIs" (#16465)** (1087a25)
- **feat(go-api): Add Go chat session message delete and feedback APIs (#16442)** (a553886)
- **feat: handle partial upload success in document batch upload (#16438)** (a339e8a)
- **Go CLI: Add create and drop commands (#16430)** (d4ef3d2)
- **feat(agent): add module-level debug logging for canvas execution flow (#16200)** (78db4e9)
- **Feat: add duplicate action to agent list (#14769) (#14856)** (dc07b6c)
- **feat(agent): add Pipeline chunker component for pre-chunking workflows (#14773) (#15068)** (f57f3b4)
- **feat(go-agent): Ported retrieval node, added Keenable web search tool (#16396)** (f58fae5)

### Fixes
- **Fix the sandbox exec image cannot show and download (#16577)** (93f6d64)
- **fix workflow file type Identify (#16576)** (4a81b9c)
- **Fix: display model_id in memory_list (#16567)** (bc54903)
- **Fix: send agent log date filters as local wall-clock strings (#16575)** (9a6d30b)
- **Fix chat thinking & Figure issue in GO (#16558)** (24118ac)
- **fix(go): chunk stats after chunk deletion (#16553)** (42aba36)
- **fix(go): Add tenant filter to file queries (#16526)** (dfd95c9)
- **Fix Go: fix minio port issue (#16552)** (11dfea4)
- **Fix: PDF page count detection for compressed PDFs (#16487)** (fc91165)
- **Fix graphrag generate error - AttributeError: 'RedisDB' object has no attribute 'mget' (#16573)** (f7e39a0)
- **Fix: disable agent tests (#16562)** (6ea9580)
- **Fix: correct download_deps.py path in error messages and add native libs doc (#16557)** (7ae18a4)
- **Fix: hide model settings button and related functionality (#16563)** (16b8c79)
- **Fix: pass mcp to useExportMcp for correct JSON export filename (#16564)** (2ef7818)
- **Fix: enhance reference handling in SessionChat component (#16571)** (c44d56f)
- **fix(go): shared chatbot session id length (#16559)** (d31640a)
- **fix: unable to load pic in chunk result (#16485)** (9c8d8c7)
- **fix: unable to build go backend (#16542)** (3a5bc13)
- **fix: add search keywords and filter for datasets-search (#16550)** (92e8eb5)
- **[Python] 1, Fix to allow single login, 2, update password to force re-login (#16556)** (4130091)
- **fix(go): clear task cancel signals and chunk counters on rerunWithDelete (#16544)** (cbb2494)
- **fix(go): prevent moving folders into themselves (#16522)** (fa1b52c)
- **Go: fix lint (#16533)** (0b9ab12)
- **fix(go): agent settings update clearing DSL (#16495)** (d0d0339)
- **fix(go): agent explore thumbnail loading for multiple doc_ids (#16514)** (a67026f)
- **fix(go): accept disabled chunk filter in list chunks handler (#16532)** (cb8012e)
- **fix: JSONMap scan in dataset index chunking config (#16489)** (b482516)
- **fix: get duplicate datasetID when get-Chat (#16498)** (d6b1c59)
- **fix: unadble to add metadata for file in kb (#16523)** (ee45c97)
- **Fix: close MCP sessions after canvas execution to prevent connection leaks (#13295)** (27c9a09)
- **fix: improve Normal role badge visibility with proper styling (#16528)** (3195d6f)
- **[Go] Fix to allow duplicate key for provider (#16543)** (7abc694)
- **fix(go): document count in kb (#16490)** (9b83d0f)
- **Fix: use .a to replace .so for pdfium/pdf_oxide/office_oxide (#16496)** (42a0faa)
- **perf: batch-embed entity/edge names in set_graph() to fix stall on large graphs (#16205) (#16472)** (b0e6007)
- **fix: return call failed when LLM not available (#16518)** (4a72c97)
- **fix: normalize Q&A parser ID key to lowercase 'qa' (#16530)** (fb03765)
- **Go CLI: fix list provider models (#16493)** (f4f9e44)
- **fix: unable to open filter in agent page(no agent tags...) (#16531)** (9eacbb4)
- **Fix GetProjectRoot in GO (#16520)** (5ba25a5)
- **fix(harness): truncate text on rune boundary to keep UTF-8 valid (#16511)** (97a4c64)
- **fix(api): fall back to factory max_tokens for tenant models (#16364)** (d770217)
- **fix(qa): preserve final CSV pair row number (#16433)** (b8e960e)
- **fix(deepdoc): parse bodyless HTML fragments (#16423)** (b42414b)
- **fix(agent): filter TuShare news with upstream keyword input (#16361)** (508f622)
- **fix(web): sanitize agent rerun modal HTML against stored XSS (#16516)** (572f1ea)
- **Fix: ollama provider (#16519)** (b6fa5ce)
- **fix(agent/tools): GoogleScholar empty json output and ignored top_n (#16419)** (828c578)
- **Fix g++ 11 incompatibility issue (#16512)** (6648fe4)
- **fix: handle non-serializable objects in agent canvas SSE and state se… (#14210)** (38f8f8a)
- **fix(agent): prevent empty LLM user message after prompt fitting (#16413)** (e23f63b)
- **fix(common/time_utils): correct None/empty timestamp fallback and ISO 8601 parsing (#16483)** (45fc7fe)
- **Fix: CI (#16504)** (b53b693)
- **Fix harness streaming emit (#16486)** (63bdf5c)
- **fix(agent): add canvas_type filter and field to list_agents API (#15754)** (3c946a7)
- **Fix: UI cannot start up (#16497)** (d2ecd57)
- **fix: remove dup-prefix in bot_routes (#16492)** (b3af9fc)
- **fix(agent): return session_id when chat completion produces no events (#15169) (#15228)** (09dc4c8)
- **fix(agent): inject uploaded attachments into LLM context (#15215) (#15220)** (dc8b6d7)
- **fix: adjust width of messageItemSectionLeft to fit-content (#16488)** (9542e6d)
- **Fix: allow any host for url for development (#16459)** (2018eec)
- **Go CLI: fix api commands (#16457)** (7c1edca)
- **[Go] Fix beta auth for /documents/images/:image_id and /documents/:id/preview and /thumbnails (#16453)** (48b7702)
- **fix(py): chat message reference deletion index (#16436)** (a10a2d8)
- **fix: new chat cannot be edit (#16434)** (445a13e)
- **fix: unable to upload avatar for search (#16437)** (43f75fd)
- **fix: auth middleware double responses on early rejection (#16444)** (c5e10a1)
- **[Go] Fix searchbot retrieval_test accept kb_id as array, fix model recognize (#16452)** (c0f6429)
- **[Go] Fix searchbot BETA auth (#16450)** (ec5cd6b)
- **fix: user-setting modal fixes and DOMPurify cleanup (#16449)** (ca17808)
- **Fix: failed to get embedding model by embd_id: model config not found BAAI/bge-m3@...@SILICONFLOW (#16445)** (9b726a5)
- **fix(rag/nlp): handle non-numbered DOCX heading styles (#16219)** (ebd4f4e)
- **Fix PR template (#16439)** (d56c17b)
- **fix: update variable completeness check to allow None parameter (#16389)** (b6dbb2f)
- **Fix: clean up iteration child nodes and edges on delete (#13889) (#14033)** (9f6f0c5)
- **fix(agent): enforce document access on POST /api/v1/agents/rerun (#15145)** (8fb692f)
- **Fix: UserFillUp interactive forms not working in agent explore mode (#14589)** (f0f10b6)
- **fix(api): gate sandbox artifact download on agent session ownership (#16169)** (212429b)
- **fix(agent): add SSRF guard to Invoke HTTP component (#15426)** (660970b)
- **fix: require explicit anonymous webhook access (#14890)** (6079ded)
- **fix(agent): enforce tenant ownership on agentbots completions/inputs (#15457)** (43a9d53)
- **fix(agent): authenticate "Thinking" button in shared/embedded chat via beta token (#14985) (#15238)** (7ecc090)
- **fix(agent): bind session_id to path agent_id on GET/DELETE agent sessions (#15374)** (7b81f63)
- **fix(agent): Switch no longer matches an empty condition (all([]) is True) (#15644)** (608fc5d)
- **fix: guard SSRF in ExeSQL agent tool DB host (#15609)** (e256d91)
- **fix(agent): restore be_output and test DeepL error return (#16363)** (6a4de82)
- **fix(agent): add HTTP timeout to external API tools (#15436)** (14174b2)
- **fix(codeql): close remaining 44 CodeQL alerts post-merge (#16408)** (0c39521)
- **fix(security): address 93 CodeQL code-scanning alerts across 61 files (#16407)** (195bfff)

### Backend
- **Port agent PRs to GO - 2 (#16565)** (dcbd0d2)
- **workflow steps separated to go or python (#16561)** (404ef4c)
- **Stabilize timeout tests with semantic assertions (#16537)** (ba552f6)
- **feat(go-api) sessions message update  (#16517)** (0de69e5)
- **Feat/oss parser no post (#16464)** (5bc4753)
- **Port agent PRs to GO (#16529)** (133b1e1)
- **Implement chat completions in go (#16491)** (7862f69)
- **revert: roll back tests.yml CI changes from PR #16391 (#16505)** (8e1dc4f)
- **Port 14 upstream agent security / correctness fixes to Go canvas (#16455)** (4c54cef)
- **Go CLI: merge function (#16458)** (bd56a14)
- **Feature big query connector (#15871)** (5fc254e)
- **feat[Go]: implement searches/<search_id>/completions POST (#16440)** (1c0cdd8)
- **Go CLI: refactor commands (#16447)** (3202ec6)
- **Guard /datasets/{dataset_id}/chunks cannot parse ingestion pipeline, use /documents/ingest instead (#16395)** (6e82e27)
- **Feat/agent thinking switch (#15446)** (0d7ad0e)
- **Harden closed-advisory fixes (#16409)** (faef22c)
- **feat[Go]: port agent attachment download, chatbot + agentbot completion/info endpoints from Python (#16405)** (dfe2dc3)
- **feat[Go]: port agent webhook trigger, agent file upload/download, component input-form + debug endpoints from Python (#16403)** (477f2fc)

### Docs
- **Docs: Update version references to v0.26.3 in READMEs and docs (#16574)** (32c5cb1)
- **Docs: Added v0.26.3 release notes. (#16566)** (ce8941d)
- **Docs: Added an FAQ (#16466)** (c117513)
- **Docs: Updated release date and cli installation commands (#16435)** (6d6e32a)

### Chore
- **refactor: use WaitGroup.Go to simplify code (#16539)** (17e3e34)
- **refactor: replace context.WithCancel with t.Context (#16509)** (fcf2ca8)
- **build(deps): bump crawl4ai from 0.8.9 to 0.9.0 (#16470)** (540acb4)
- **Refactor: oss parser go refactor (#16391)** (98323e7)
- **refactor: enhance UI components and improve layout (#15984)** (61ac1c1)
- **build(codeql): exclude office_oxide CGO files so Go analysis completes (#16410)** (ee165c5)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/infiniflow/ragflow?utm_source=github-action)._