[pull] main from Azure-Samples:main - #34
Conversation
Check Broken URLsWe have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue. Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.
|
Check Broken URLsWe have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue. Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.
|
3 similar comments
Check Broken URLsWe have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue. Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.
|
Check Broken URLsWe have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue. Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.
|
Check Broken URLsWe have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue. Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.
|
Check Broken PathsWe have automatically detected the following broken relative paths in your files. Check the file paths and associated broken paths inside them. For more details, check our Contributing Guide.
|
Check Broken URLsWe have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue. Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.
|
Check Broken PathsWe have automatically detected the following broken relative paths in your files. Check the file paths and associated broken paths inside them. For more details, check our Contributing Guide.
|
Check Broken URLsWe have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue. Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.
|
Check Broken URLsWe have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue. Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.
|
1 similar comment
Check Broken URLsWe have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue. Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.
|
…entation (#2653) * Initial plan * Add comprehensive Mermaid architecture diagrams and documentation Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com> * Move Architecture Overview link to list above HTTP Protocol Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com> * Address PR feedback: fix Mermaid syntax, update architecture docs Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com> * Fix formatting and Mermaid syntax issues per PR feedback Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com> * Update README.md * Update docs/README.md * Fix Mermaid parse error by removing parentheses from optional service labels Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com> * Fix Mermaid parse error by removing dashes from node labels Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com> --------- Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com> Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com> Co-authored-by: Pamela Fox <pamelafox@microsoft.com>
* Configure Azure Developer Pipeline * Private endpoints draft * Conditional for SPL * private endpoint for ACA * Add P2S VPN gateway and other improvements * Private endpoint almost working * Usving avm for the subnets * Connected app to vnet * Feedback from Matt * Move resources into modules * Bring back unneeded changes * Update prepdocs with ping and update docs * Fix VPN client link * Add App Service private endpoint for deployment * Revert unneeded bicep changes * Revert unneeded changes * Remove unneeded NSG rules * Address feedback from Copilot * Address feedback from Copilot * Address Copilot feedback * Update NSG, container registry * Update NSG, container registry * Address feedback * Bring back workload profile name
* Initial plan * Add Bicep description for infra/private-endpoints.bicep Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>
* GPT-5 evals * Add evals for GPT-5 * Upgrade openAI SDK * Change snapshots to reasoning_effort of minimal
…nt (#2672) * Add chat modes and prompts * Fix tasks to work with chat mode * Remove unrelated changes * Update docs about local dev * Add Windows command
* Use lowest reasoning effort appropriate for a model * Address comments from Copilot
* Improved custom mode and repo instructions * Update .github/copilot-instructions.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> * Update .github/copilot-instructions.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
…2669) Bumps the github-actions group with 1 update: [Azure/setup-azd](https://github.com/azure/setup-azd). Updates `Azure/setup-azd` from 2.1.0 to 2.2.0 - [Release notes](https://github.com/azure/setup-azd/releases) - [Changelog](https://github.com/Azure/setup-azd/blob/main/CHANGELOG.md) - [Commits](Azure/setup-azd@v2.1.0...v2.2.0) --- updated-dependencies: - dependency-name: Azure/setup-azd dependency-version: 2.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the github-actions group with 1 update: [actions/checkout](https://github.com/actions/checkout). Updates `actions/checkout` from 4 to 5 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v5) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Bump pypdf from 4.3.1 to 6.0.0 in /app/backend Bumps [pypdf](https://github.com/py-pdf/pypdf) from 4.3.1 to 6.0.0. - [Release notes](https://github.com/py-pdf/pypdf/releases) - [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md) - [Commits](py-pdf/pypdf@4.3.1...6.0.0) --- updated-dependencies: - dependency-name: pypdf dependency-version: 6.0.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> * Update snapshot for splitting --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Pamela Fox <pamela.fox@gmail.com>
* Group CSV rows into pages to avoid OOM in cloud ingestion CsvParser emitted one Page per row, so large CSV files created thousands of Page objects and could exhaust memory in the cloud ingestion text-processor function (#2878). Add an optional CSV_MAX_PAGE_CHARS azd env variable that, when greater than 0, groups consecutive rows into pages up to that many characters. Default behavior (one page per row) is unchanged. Plumbed through build_file_processors, prepdocs, both ingestion functions, and infra. Adds tests for grouping, splitting, oversized rows, and large-file regression. * Fix ruff UP012 in csv parser tests (drop redundant utf-8 encode arg) * Fix prepdocs parallel issue and add manage_indexer script * Address feedback about os.getenv * Remove trailing blank line in test_csvparser.py for black --------- Co-authored-by: Pamela Fox <pamelafox@microsoft.com>
…Promise, Chromium 150.0.0 changed scrollIntoView() to return a Promise. (#3134)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.12.0 to 2.13.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.12.0...2.13.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.13.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): upgrade msal to 1.37.0 and cryptography to 49.0.0 * docs(AGENTS): add manual test plan for msal / auth changes * docs(AGENTS): use generic REGION placeholder in msal test plan
….11.7 (#3140) * chore(deps): upgrade msgraph-sdk to 1.58.0 and microsoft-kiota-* to 1.11.7 * docs(AGENTS): add manual test plan for msgraph-sdk / kiota upgrades * docs(AGENTS): drop hardcoded env name from msgraph test plan
* Upgrade azure-search-documents to 12.1.0b1 Bump the SDK from 11.7.0b2 to 12.1.0b1 ahead of the MAF port. Real API changes handled: - QueryCaptionResult.additional_properties was removed; drop it from caption serialization and the test mock. - VectorizedQuery.k was renamed to k_nearest_neighbors. - SearchIndexKnowledgeSourceParameters (index-definition model) dropped include_reference_source_data; remove it from the test fixture. The query-time *Params models still accept it and are unchanged. - Update _generated imports to their public module paths. Behavior improvements reflected in updated snapshots: - Reference ids are now coerced to str, so first-citation [ref_id:0] correctly resolves to its source page instead of being left raw. - Agentic "thoughts" activity records now serialize as camelCase, matching the SDK model representation. Suppress ty call-non-callable false positives on SearchFieldDataType.Collection(). All 493 tests pass; ty, ruff, and black are clean. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Normalize agentic query_plan keys to snake_case after SDK upgrade azure-search-documents 12.1.0b1 regenerated its models from TypeSpec, so model .as_dict() now emits REST wire names (camelCase) instead of the snake_case Python attribute names emitted by 11.7.0b2. The query_plan in the agentic-retrieval ThoughtStep is built from response.activity[*].as_dict(), so its keys silently switched to camelCase (elapsedMs, knowledgeSourceName, searchIndexArguments, webArguments, inputTokens, outputTokens, ...). The frontend Execution Steps renderer (AgentPlan.tsx / agentPlanUtils.ts) reads snake_case, so without this the query plan would show "—" for elapsed time, fall back for source names, blank searches, and zeroed token graphs. Normalize the keys back to snake_case in the backend so the app's JSON contract stays snake_case and the frontend is untouched. Activity "type" discriminator values (searchIndex, web, ...) are values, not keys, so they are preserved. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Render query plan in camelCase on the frontend instead of normalizing in backend The azure-search-documents 12.1.0b1 upgrade regenerated the SDK models so KnowledgeAgentActivityRecord.as_dict() now emits REST wire names (camelCase). The earlier fix normalized those keys back to snake_case in the backend (camel_to_snake_keys helper) so the frontend query-plan renderer kept working. Switch to updating the frontend instead: the backend passes activity.as_dict() through verbatim, and the QueryPlanStep type + AgentPlan renderer read the SDK's native camelCase keys. This removes the backend translation layer and keeps the UI mirroring the SDK. Agent snapshots regenerated to camelCase accordingly. Note: retrieval_reasoning_effort in the request overrides (models.ts / Chat.tsx) is our own contract and stays snake_case; only the query_plan response fields change. TokenUsage object-literal keys are unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add e2e regression test for agentic query plan rendering Guards against the camelCase drift introduced by the azure-search-documents 12.x upgrade: activity.as_dict() switched from snake_case to camelCase, which the existing agentic e2e test did not catch because it only asserted section headers, not the actual Execution steps table content. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix query_source_authorization kwarg rename in azure-search-documents 12.1.0b1 The SDK renamed the retrieve()/search() keyword from x_ms_query_source_authorization to query_source_authorization. The knowledgebase retrieve() forwards unknown kwargs straight to the aiohttp transport, so the stale name raised TypeError: ClientSession._request() got an unexpected keyword argument 'x_ms_query_source_authorization' on the agentic retrieval path. Rename all four call sites and update the test mocks to mirror the SDK parameter name. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix agentic retrieval regression from azure-search-documents 12.1.0b1 The upgraded SDK defaults the knowledgebase retrieval client to api-version 2026-05-01-preview, whose retrieval execution currently 502s server-side on services that haven't rolled out that preview, and it also renamed the auth kwarg to query_source_authorization while gating it to 2026-05-01-preview+ via client-side validation. - Pin the knowledgebase client to 2025-11-01-preview (env-overridable via AZURE_SEARCH_KNOWLEDGEBASE_API_VERSION), the earliest version that supports the fields the app sends and retrieves successfully. - Only forward query_source_authorization when the client's api-version supports it and a token is present; the search index source retrieves fine without it. Both issues only surfaced via live agentic testing since the **kwargs mocks could not catch them. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add e2e test for agentic retrieval query plan rendering Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Default knowledgebase api-version to latest 2026-05-01-preview The earlier service-side 502 on 2026-05-01-preview was a transient outage per the search team, not a version problem. Default to the latest version (which supports every field the app sends, including query_source_authorization) and keep the env override for services still rolling out the preview. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Clarify knowledgebase api-version comment: 502 was East US 2 regional outage Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * test: drop never-executed auth kwarg read from early-return mocks The query_source_authorization rename put these lines in the diff, but both mocks return early (empty path / access control disabled) so the search closure never runs, leaving the renamed line uncovered. access_token stays None via its initializer, so the assertions are unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Remove knowledgebase api-version override, always use SDK default Reverts to main's behavior: pass no api_version to KnowledgeBaseRetrievalClient (SDK default is the latest 2026-05-01-preview) and forward query_source_authorization unconditionally. The override and version-gate were only added while debugging a 502 that turned out to be a regional outage, not a version problem. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Consolidate duplicate agentic query plan e2e tests Delete the weaker test_chat_agentic_query_plan and keep the stricter test, renamed to test_agentic_retrieval_query_plan for consistency with the other test_agentic_retrieval_* tests. Trim verbose backend-detail comments from the docstring and body. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…ut (#3144) * Handle Easy Auth redirect on /auth_setup fetch to fix CORS after logout Use redirect: "manual" so a 302 from Container Apps / App Service Easy Auth to login.microsoftonline.com does not surface as a CORS error on the initial fetch. When we see an opaqueredirect response, reload the page so the browser follows the redirect at the top level and the login flow can complete. Fixes #1780 * Address review: document why the never-resolving Promise is intentional
…#3093) * chore(deps): bump esbuild, @vitejs/plugin-react and vite Removes [esbuild](https://github.com/evanw/esbuild). It's no longer used after updating ancestor dependencies [esbuild](https://github.com/evanw/esbuild), [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). These dependencies need to be updated together. Removes `esbuild` Updates `@vitejs/plugin-react` from 4.7.0 to 6.0.2 - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.2/packages/plugin-react) Updates `vite` from 6.4.3 to 8.0.16 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite) --- updated-dependencies: - dependency-name: esbuild dependency-version: dependency-type: indirect - dependency-name: "@vitejs/plugin-react" dependency-version: 6.0.2 dependency-type: direct:development - dependency-name: vite dependency-version: 8.0.16 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com> * Drop Node 20 support: bump CI matrix and engines.node for vite 8 vite 8 requires Node >=22.12.0. Update the test matrix to [22, 24] (matches the current Cloud Shell Node 24), bump the azure-dev workflow to Node 22, and pin engines.node to >=22.12.0. Node 20 hit EOL in April 2026. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Pamela Fox <pamelafox@microsoft.com>
Bumps the github-actions group with 1 update: [DavidAnson/markdownlint-cli2-action](https://github.com/davidanson/markdownlint-cli2-action). Updates `DavidAnson/markdownlint-cli2-action` from 23 to 24 - [Release notes](https://github.com/davidanson/markdownlint-cli2-action/releases) - [Commits](DavidAnson/markdownlint-cli2-action@v23...v24) --- updated-dependencies: - dependency-name: DavidAnson/markdownlint-cli2-action dependency-version: '24' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the pallets group with 1 update: [click](https://github.com/pallets/click). Updates `click` from 8.4.1 to 8.4.2 - [Release notes](https://github.com/pallets/click/releases) - [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md) - [Commits](pallets/click@8.4.1...8.4.2) --- updated-dependencies: - dependency-name: click dependency-version: 8.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: pallets ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pymupdf](https://github.com/pymupdf/pymupdf) from 1.27.2.3 to 1.28.0. - [Release notes](https://github.com/pymupdf/pymupdf/releases) - [Changelog](https://github.com/pymupdf/PyMuPDF/blob/main/changes.txt) - [Commits](pymupdf/PyMuPDF@1.27.2.3...1.28.0) --- updated-dependencies: - dependency-name: pymupdf dependency-version: 1.28.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…3154) Bumps [prettier](https://github.com/prettier/prettier) from 3.8.1 to 3.9.4. - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.8.1...3.9.4) --- updated-dependencies: - dependency-name: prettier dependency-version: 3.9.4 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…end (#3156) Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.0.1 to 26.1.1. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.1.1 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [rollup-plugin-visualizer](https://github.com/btd/rollup-plugin-visualizer) from 5.12.0 to 7.0.1. - [Changelog](https://github.com/btd/rollup-plugin-visualizer/blob/master/CHANGELOG.md) - [Commits](btd/rollup-plugin-visualizer@v5.12.0...v7.0.1) --- updated-dependencies: - dependency-name: rollup-plugin-visualizer dependency-version: 7.0.1 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Replace the 9 `existing` resourceGroups resources with computed name
variables used via `scope: az.resourceGroup(<name>)`. Under Bicep
languageVersion 2.0 (symbolic-name codegen), a conditional `existing`
resourceGroups resource whose name equals the main resource group name
collides with the main resource group ("defined multiple times"), and the
sequencer self-dependency error also surfaces. Removing those resources
eliminates the collision so the template is valid whether Bicep compiles
it as 1.0 or 2.0, without changing deploy behavior.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…d popup redirect-bridge scaffolding (#3148) * Proxy /redirect to backend in vite dev config MSAL best-practice is that the popup redirect URI (/redirect) should be an empty page that does NOT load MSAL, so the parent window's popup client can scrape the auth code from the popup's URL and close it. The backend /redirect route returns an empty response for exactly this reason, but the vite dev server did not proxy /redirect, so in local dev the popup landed on vite's index.html fallback which re-initialized MSAL and prevented the parent from completing the login flow. Manifested with msal-browser 5.x, which is stricter about this pattern. * AGENTS.md: add local-dev popup login step to auth manual test plan The deployed site uses Easy Auth redirect flow; local dev uses MSAL popup. These are separate code paths and previous msal-browser upgrades silently broke the popup flow because vite wasn't proxying /redirect to the backend. Add an explicit step so future upgrades catch this before merging. * Fix MSAL popup login on msal-browser 5.x by running the redirect bridge msal-browser 5.x replaced the old "parent polls popup.location.href" popup handshake with a BroadcastChannel bridge: the popup redirect URI must run broadcastResponseToMainFrame() (from @azure/msal-browser/redirect-bridge) to post-message the auth response back to the opener and close itself. Our backend was serving /redirect as an empty page (correct for msal-browser 4.x but a no-op in 5.x), so the popup landed on /redirect#code=... and just sat there with no way to hand the code back to the parent. Supersedes the earlier vite.config.ts + AGENTS.md commits on this branch; the vite proxy addition was reverted here since the SPA fallback is what we actually want at /redirect. Changes: * app/backend/app.py: /redirect now serves index.html so the SPA loads there in both prod and local dev, giving the bridge script a chance to run. * app/frontend/src/index.tsx: before mounting the app, detect that this window was opened by MSAL as a popup and carries an auth response, then call broadcastResponseToMainFrame(). It broadcasts + closes the popup; the throw prevents the SPA from partially mounting in the popup and fighting with the parent frame's handshake. * app/frontend/vite.config.ts: revert the /redirect proxy entry — no longer needed now that /redirect serves index.html via the vite SPA fallback. * tests/test_app.py: /redirect now returns HTML (index.html) not an empty body — update assertion accordingly. * AGENTS.md: update the popup-fails hint under the auth manual test plan to point at index.tsx + the redirect-bridge. * Follow MSAL best practice: use a dedicated redirect.html popup page Per MSAL docs (msal-browser/docs/login-user.md#redirecturi-considerations), the popup redirect URI must be a minimal dedicated page containing ONLY the redirect-bridge script — no routing, no other application code — so it does not interfere with the BroadcastChannel handshake used since msal-browser 5.x. The previous approach in this branch loaded the full SPA at /redirect and did an early throw before mounting; that worked but violated MSAL guidance and forced the popup to download the entire ~1.9MB SPA bundle. Refactor to a proper dedicated entry point: * app/frontend/redirect.html: minimal HTML with <title>Signing in</title> and a single module script. * app/frontend/src/redirect.ts: only imports broadcastResponseToMainFrame from @azure/msal-browser/redirect-bridge and invokes it. * app/frontend/vite.config.ts: - Add redirect.html as a second rollup input entry. - Isolate @azure/msal-browser / @azure/msal-common into a dedicated 'msal' chunk so the redirect entry does not pull in React/Fluent UI/vendor. - Add a small dev middleware that aliases /redirect to /redirect.html so the popup redirect URI matches production without a trailing .html. * app/frontend/src/index.tsx: revert the popup-detection hack — no longer needed now that the popup loads redirect.html instead of index.html. * app/backend/app.py: /redirect now serves redirect.html (not index.html). * AGENTS.md: update the debugging hint to point at redirect.html + redirect.ts. Popup entry-point size dropped from the full ~1.9MB SPA bundle to just redirect.js (195 bytes) + msal.js (235KB gzip 59KB). * Keep LoginContext in sync with MSAL events (msal-react best practice) Per msal-react docs (hooks.md#usemsal-hook): > If your component relies on instance.getActiveAccount(), be aware that > getActiveAccount() may return null immediately after authentication > completes. This happens because the render triggered by > ACQUIRE_TOKEN_SUCCESS can run before setActiveAccount() has been called. > To handle this, subscribe to the ACTIVE_ACCOUNT_CHANGED event and retry > your logic when the active account becomes available. LayoutWrapper was only calling checkLoggedIn(instance) once on mount, and LoginButton relied on chaining setLoggedIn off loginPopup().then() — which races the LOGIN_SUCCESS event handler that actually calls setActiveAccount. Fix: subscribe to LOGIN_SUCCESS, LOGOUT_SUCCESS, ACTIVE_ACCOUNT_CHANGED and ACQUIRE_TOKEN_SUCCESS events in LayoutWrapper and re-run checkLoggedIn on each. This way the loggedIn state (and downstream UI: LoginButton username, QuestionInput enabled state, etc.) stays authoritatively driven by MSAL instead of by promise-chain timing. * checkLoggedIn/getUsername: fall back to getAllAccounts() when no active account Root cause of the popup UI not updating after login (per browser log the events fire correctly and refresh runs, but checkLoggedIn returned false): * msal-browser fires ACQUIRE_TOKEN_SUCCESS before LOGIN_SUCCESS. * Our index.tsx handler only calls setActiveAccount() on LOGIN_SUCCESS. * checkLoggedIn / getUsername / getTokenClaims all use getActiveAccount(), which returns null between ACQUIRE_TOKEN_SUCCESS and setActiveAccount() running \u2014 so both refresh() calls in LayoutWrapper saw no account and setLoggedIn(false). msal-react's own useIsAuthenticated hook works around this by checking accounts.length > 0 (i.e. getAllAccounts()) instead of getActiveAccount(). Adopt the same pattern here: prefer active account, fall back to first cached account. The account is populated in getAllAccounts() as soon as MSAL processes the token response, so this no longer races setActiveAccount(). Also fix LoginButton's username useEffect: it was pinned to [] and never re-ran, so even if setLoggedIn eventually flipped to true, the button still rendered an empty username. Depend on [instance, loggedIn] so it refreshes on state change. * postLogoutRedirectUri should also be /redirect for popup logout logoutPopup lands the popup on postLogoutRedirectUri when Entra finishes signing the user out. That URL was previously "/" (the main app root), so after logout the popup rendered the full SPA instead of running the redirect-bridge and closing itself. Point postLogoutRedirectUri at /redirect too, so the bridge script broadcasts the logout response back to the opener and calls window.close(). The mainWindowRedirectUri: "/" already passed per-call in LoginButton.tsx takes care of navigating the parent window to "/" after logout completes. /redirect is already registered as an SPA redirect URI in scripts/auth_update.py, so no Entra app registration change is required. * Cache negative /.auth/me result so checkLoggedIn doesn't spam 404s Local dev (and any deploy without Easy Auth) has no /.auth/me endpoint, so getAppServicesToken() got a 404 on every call. checkLoggedIn / getUsername / getTokenClaims all fall back to getAppServicesToken(), and LayoutWrapper now calls checkLoggedIn on every MSAL event (LOGIN_SUCCESS, ACQUIRE_TOKEN_SUCCESS, ACTIVE_ACCOUNT_CHANGED, ...) — resulting in a storm of red 404s in the console after every login. Latch a globalThis.appServicesAuthUnavailable flag on the first 404 (Easy Auth availability is a deployment-time property, not something that flips at runtime) and short-circuit further getAppServicesToken() calls to Promise.resolve(null). * chore(deps): upgrade @azure/msal-browser to 5.17 and @azure/msal-react to 5.5 (#3139) * Fall back to first cached account in logout handler getActiveAccount() can be null between an MSAL token event and our setActiveAccount() handler (same msal-browser 5.x race that checkLoggedIn/getUsername already handle). Fall back to getAllAccounts()[0] so logoutPopup always fires, instead of accidentally routing to appServicesLogout() and navigating the top window to /.auth/logout. * Handle Easy Auth 302 to Entra on API fetches When the Container Apps / App Service Easy Auth session cookie is missing or expired, Easy Auth returns a 302 to login.microsoftonline.com for every request. The browser blocks the cross-origin redirect on a same-origin fetch (CORS: 'No Access-Control-Allow-Origin header'), so API calls like /chat/stream fail hard. Wrap fetch in fetchWithAuthRedirect() that uses redirect: 'manual' and reloads the page on opaqueredirect — the browser can follow the cross-origin 302 on a top-level navigation and Easy Auth will complete the sign-in flow. Same pattern that fetchAuthSetup() already uses for /auth_setup (issue #1780). * prettier: format redirect.html * Consolidate active-or-first-account fallback into a helper - Add getActiveOrFirstAccount(client) helper in authConfig.ts. - Use it in checkLoggedIn, getUsername, getTokenClaims, and LoginButton.handleLogoutPopup instead of repeating the getActiveAccount() ?? getAllAccounts()[0] pattern with duplicated explanatory comments. - Remove dead activeAccount local in TokenClaimsDisplay (declared but never read). * Expand redirectAlias comment to explain why we don't proxy to Quart * AGENTS.md: use <AUTH_ENV_NAME> placeholder instead of hardcoded env * Address Copilot review comments - test_redirect docstring: /redirect serves redirect.html (not index.html); update comment to match. - AGENTS.md step 7: rewrite the msal-browser 5.x explanation to describe the actual design (dedicated bridge page + vite middleware rewrite in dev, Quart route in prod) instead of the stale "empty page proxied to backend" wording. - authConfig.ts appServicesAuthUnavailable: only latch on HTTP 404 from /.auth/me. Other statuses (401 session-expired, 403, transient 5xx) can recover on the next call. - AnalysisPanel.tsx fetchCitation: activeCitation.indexOf('#') returns -1 (truthy) when '#' is absent, so the ternary was running the split branch and yielding undefined. Use String.prototype.includes for correctness.
* Upgrade default eval model from gpt-4.1 to gpt-5.4
The gpt-4.1 model is deprecated. Bump the default evaluation model
deployment to gpt-5.4 (version 2026-03-05) and update the docs.
Validated by provisioning the eval deployment in an azd env and
confirming it responds via the chat completions API.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Vendor evaltools with reasoning-model (gpt-5) support
The gpt-5.4 eval model upgrade broke evaluate.py because the upstream
ai-rag-chat-evaluator pinned azure-ai-evaluation==1.8.0, which sends
max_tokens (rejected by reasoning models) and lacks is_reasoning_model.
Vendor a lean subset of evaltools into evals/evaltools/ (eval runner,
metrics, service setup, markdown summary/diff CLI) so we can:
- construct the LLM-judged evaluators with is_reasoning_model=True, sending
max_completion_tokens instead of max_tokens
- require azure-ai-evaluation>=1.18.0
- read the unprefixed rating columns (groundedness/relevance) that newer
azure-ai-evaluation emits, while keeping gpt_* registry/summary keys for
baseline continuity
Drops the promptflow-based prompt metrics and Textual TUI reviewers.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Sort evaluate.py imports with evaltools as first-party
Vendoring evaltools into evals/ makes it a first-party import, so ruff's
isort groups it separately from third-party packages.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Trim unused service_setup functions from vendored evaltools
Remove get_openai_config_dict (only used by the dropped azure-ai-generative
generate flow) and get_search_client (unused), plus their now-unused
AzureKeyCredential and SearchClient imports.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Remove vendored evaltools LICENSE.md
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Consolidate citation metrics into vendored evaltools
Replace the inferior vendored has_citation/citation_match metrics with the
better file-extension-aware any_citation/citations_matched metrics (moved from
evals/evaluate.py into evaltools code_metrics.py). Removes the duplicate class
definitions and register_metric calls from evaluate.py so there is a single set.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Add unit tests for vendored evaltools + rename evaluate.py
- Rename evals/evaluate.py -> evals/run_evaluate.py to disambiguate from
the vendored evaltools library evaluate.py
- Add evals/tests/ with unit tests for send_question_to_target and the
vendored code + builtin metrics, adapted from ai-rag-chat-evaluator
- Scope main pytest run to tests/ via testpaths so it does not collect
evals/tests (which needs the evals requirements)
- Add .github/workflows/evals-test.yaml to run evals tests in CI
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Add gpt-5.4-judged baseline eval runs and refresh baseline summary
Run the full 50-question eval suite 4 times against pf-ragchat-public
using the new gpt-5.4 judge (replacing the deprecated gpt-4.1 judge) and
regenerate results_summaries/baseline.{md,json} from these runs.
New baseline vs old gpt-4.1-judged baseline: groundedness pass 0.985->0.99,
relevance pass 0.895->0.95, means and other metrics stable within CIs.
Old gpt54-low-top5-run* folders kept for historical reference.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Address PR review comments and add review utils tests
- Guard isclose stat comparison and fix ragged-row column count in review/utils
- Replace mutable default args and fix health-check deployment/model resolution in evaluate
- Make cli directory2 argument optional with proper type
- Use monkeypatch.setattr for requests.post in test_evaluate
- HTML-escape question/answer/truth/directory name in diff_markdown
- Add type annotations so ty check passes on evaltools
- Add unit tests for diff_directories, summarize_results, and diff_markdown escaping
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Add ty type-checking of vendored evaltools to evals CI
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Inline single-use config helpers in run_evaluate.py
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Address PR review comments on copied evaltools
- diff_markdown: use tuple form of isinstance for style consistency
- diff_markdown: skip questions not present in every run to avoid KeyError
- utils.diff_directories: raise ValueError when --changed has <2 dirs
- utils.summarize_results: sort stat columns for deterministic output
- summary_markdown: use len(headers) for separator row (clarity)
- code_metrics.citations_matched: guard num_citations==0 (avoid ZeroDivisionError)
- evaluate: drop dead OPENAI_GPT_MODEL fallback since run_evaluate.py always passes model
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Drop OpenAI.com pathway from evals service setup
run_evaluate.py is the sole caller and always supplies an Azure
openai_config, so the OpenAI.com (OPENAICOM_KEY / organization) branch
was dead code. Simplify get_openai_config / get_openai_client to
Azure-only and drop the now-unused OpenAIModelConfiguration type and
cast import.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Default eval jmespath to output_text; write relative testdata_path
- Change target_response_answer_jmespath default to output_text across
send_question_to_target, run_evaluation, and run_evaluate_from_config
to match the app's Responses-API shape
- Update send_question_to_target tests to the output_text response shape
- Write testdata_path in evaluate_parameters.json relative to results_dir
instead of an absolute path, and fix the 4 committed sample artifacts
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Address PR review: use AZURE_OPENAI_ENDPOINT, consolidate credential path, add request timeout
- run_evaluate.py: use AZURE_OPENAI_ENDPOINT env var directly
- service_setup.py: single credential path in get_openai_client; remove dead get_azd_credential helper and unused AzureDeveloperCliCredential import
- evaluate.py: add timeout to target requests.post; str() cast in truncate_for_log
- test_evaluate.py: accept **kwargs in requests.post mocks
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Harden eval schema checks, guard empty stats, and go keyless-only
- Treat missing answer/output_text as a schema violation in send_question_to_target
- Guard get_aggregate_stats_for_numeric_rating against empty input (no ZeroDivisionError)
- Standardize eval auth on keyless (drop unused AZURE_OPENAI_KEY path)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Escape metric cells in diff markdown; use Responses API for eval smoke test
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Fix evals CI ty check silently passing on evaltools
ty check evals/evaltools was a no-op: pyproject.toml's [tool.ty.src] include
list intentionally excludes evals/evaltools, so passing the directory path was
filtered out and ty found no files to check ('No python files found', always
green). Override src.include in the evals-test job so ty actually type-checks
the vendored package where eval-only deps are installed.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Fix eval review table misalignment and non-numeric diff arrows
- summarize_results(): drop metrics with no recognized stat (e.g. num_questions
which only carries a 'total' key). Previously such a metric added a header
column with no matching data cells, misaligning the table and truncating
columns via zip(*rows). The per-run question count is already shown by the
appended 'n' column.
- diff_markdown.main(): only compute the up/down arrow when both the compared
value and the baseline value are numeric. A metric numeric in the baseline run
could be a non-numeric placeholder (e.g. the string 'Failed') in a later run,
which raised TypeError on value > first_value and broke 'evaltools diff'.
Also compare against the already-rounded first_value instead of re-reading raw.
- Add tests for both cases.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Address PR review: preserve traceback, surface HTTP errors, validate highlight run, fix docs examples
- send_question_to_target(): use bare 'raise' instead of 'raise e' to preserve
the original traceback when raise_error=True, and call r.raise_for_status()
after the POST so 4xx/5xx responses surface as HTTP errors with status codes
rather than being misreported as JSON/schema problems.
- summary_markdown.main(): validate the --highlight run name and raise a helpful
ValueError listing available runs instead of a bare 'x is not in list'.
- docs/evaluation.md: replace the non-existent results/baseline/ example paths
with clear RUNHERE/FIRSTRUNHERE/SECONDRUNHERE placeholders.
- Add tests for the HTTP-error paths and summary_markdown highlight behavior.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Fix latency aggregation and attribution
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Use tenant credential for eval judges
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Migrate to Azure AI Foundry account + project Deploy the Azure AI account as an Azure AI Foundry account (kind: 'AIServices' with allowProjectManagement) and create a Foundry project inside it, replacing the classic kind: 'OpenAI' account. Models are still deployed on the account, so the backend endpoint (*.openai.azure.com) and all AZURE_OPENAI_* env vars are unchanged. - Add infra/core/ai/ai-foundry-project.bicep: project resource + project-scoped RBAC (Azure AI Project Manager for the deploying user, Azure AI User for the backend identity) + name/endpoint outputs. - Bump the account AVM module to 0.15.0 for allowProjectManagement support. - Gate Foundry behavior on self-created accounts only: bring-your-own accounts (AZURE_OPENAI_SERVICE set) keep their existing kind and get no project, so classic Azure OpenAI accounts keep working unchanged. - Refactor private-endpoints.bicep to support multiple DNS zones per endpoint; the Foundry PE resolves services.ai.azure.com in addition to openai.azure.com and cognitiveservices.azure.com. - Add FOUNDRY_PROJECT_NAME / FOUNDRY_PROJECT_ENDPOINT outputs and wire foundryProjectName through main.parameters.json and both CI pipelines. - Document BYO behavior in docs/deploy_existing.md. Resolves #3084 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Ignore compiled Bicep output (infra/main.json) `az bicep build` emits infra/main.json / infra/main.test.json next to the templates; these are build artifacts and should never be committed. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fully skip Azure OpenAI provisioning for bring-your-own accounts Previously the openAi AVM module still ran for bring-your-own (BYO) existing accounts, upserting the account and pushing model deployments, which made the conditional logic hard to follow. Now the module only runs on a fresh Foundry deploy (deployFoundryAccount). For BYO we skip the account, model deployments, Foundry project, and private endpoint entirely, only keeping the RG-scoped role assignments the app's managed identity needs. - Gate openAi module and its private endpoint on deployFoundryAccount - Simplify the module (always AIServices + allowProjectManagement) and the private-endpoint DNS zone list (always the three Foundry zones) - Add openAiServiceNameResolved / openAiEndpointResolved helper vars so env vars + outputs work across fresh / BYO-existing / custom paths; BYO endpoint is string-built to match the backend's derivation - Document that BYO users must pre-create model deployments and manage their own private networking Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs: explain why ai-foundry-project.bicep isn't an AVM module Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix BYO gating: deploy Foundry account on openAiHost intent, not openAiServiceName AZURE_OPENAI_SERVICE is also a bicep output azd persists after every deploy, so gating deployFoundryAccount on empty(openAiServiceName) wrongly skipped the account on redeploys. Gate on isAzureOpenAiHost && deployAzureOpenAi (matching upstream); azure_custom remains the don't-touch BYO path. Reuse openAiServiceName for the account name/subdomain idempotently. Fix docs note accordingly. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix(infra): keep Foundry template in classic ARM mode to avoid RG collision Pin the openAi AVM account module to 0.14.0 (was 0.15.0) and drop the user-defined type in ai-foundry-project.bicep. Both 0.15.0 and UDTs force the compiled template into symbolic-name mode (languageVersion 2.0), where the many same-named `existing` resourceGroups references collide during ARM validation ("resourceGroup ... is defined multiple times"), breaking real azd provision. 0.14.0 is the newest account version that supports allowProjectManagement while compiling to classic mode. Validated with a live `azd provision`: the AIServices account flips to a Foundry account (allowProjectManagement=true) and the Foundry project is created, with FOUNDRY_PROJECT_NAME / FOUNDRY_PROJECT_ENDPOINT populated. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix safety-eval callback for Responses API response shape The non-streaming /chat response now returns the assistant answer in 'output_text' (Responses API migration), not 'message'. Update the adversarial simulator callback to build the assistant turn from output_text so ContentSafetyEvaluator receives the app's reply. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix VPN gateway SKU to AZ variant (VpnGw2AZ) Azure no longer allows non-availability-zone VPN gateway SKUs and rejects them with NonAzSkusNotAllowedForVPNGateway. Switch the P2S VPN gateway (AZURE_USE_VPN_GATEWAY=true path) from VpnGw2 to VpnGw2AZ. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs: correct reuse-existing NOTE — in-place Foundry upgrade The reuse-by-name flow (OPENAI_HOST=azure + AZURE_OPENAI_SERVICE) runs the same AVM account module (kind: AIServices + allowProjectManagement) against the existing account and creates a Foundry project. A classic kind: 'OpenAI' account is therefore upgraded in place (Microsoft's documented non-destructive upgrade) and can host a project. The prior NOTE was misleading. Clarify that only the azure_custom bring-your-own path leaves an account untouched. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs(infra): tighten deployFoundryAccount comment Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs(infra): drop redundant Foundry account comments Remove the languageVersion 2.0 / #3146 rationale (already documented where the plain-string RG vars are defined) and the duplicate module-level header, keeping the inline comment on the kind/allowProjectManagement params. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs(infra): move Foundry account comment above the module Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * refactor(infra): rename openAi module to foundry for clarity Rename the Cognitive Services account module symbol and deployment name from openAi to foundry to make it clear it provisions a Microsoft Foundry (AIServices) account. Params/vars/outputs that map to azd env vars (openAiHost, openAiServiceName, AZURE_OPENAI_*) are unchanged. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * refactor(infra): rename foundry module to foundryAccount Pairs with the foundryProject module (account vs. project inside it). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs(infra): link private DNS zone reference for Foundry account Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs(infra): fix private DNS zone reference link Point to private-endpoint-dns (the page that actually lists the Foundry Tools account zones), not private-endpoint-dns-integration. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs(infra): tighten DNS zone comment Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Fix azd target environment loading Replace the duplicated local environment loaders with dotenv-azd so azd resolves AZURE_ENV_NAME consistently in hooks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Use consistent azd environment override behavior Honor LOADING_MODE_FOR_AZD_ENV_VARS at every dotenv-azd call site so backend, scripts, and evals share one policy. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Test azd loading modes in script entry points Verify both override modes and ensure the ADLS and Cosmos migration entry points continue into their orchestration paths. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Upgrade agentic knowledge base model Default new agentic knowledge base deployments to gpt-5-mini version 2025-08-07 while preserving all existing model, version, deployment, SKU, and capacity overrides. Update the agentic retrieval deployment guide to match. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2 * Use GPT-5.4 for agentic knowledge base Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2 * Apply suggestion from @pamelafox * Apply suggestion from @pamelafox * Fix knowledge base environment variable names Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2 * Evaluate GPT-5.4 agentic retrieval Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2 * Compare agentic knowledge base models Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2 * Restore default evaluation mode Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2
* Default agentic retrieval to minimal Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2 * test: add capacity-matched retrieval evals Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2 * docs: add eval throttling guidance Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2 * docs: clarify evaluation capacity setup Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2 --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix creation of knowledgebase in cloud ingestion * small fix after running py -m black * leave cloudingestionstrategy unchanged. * leave cloudingestionstrategy unchanged, remove empty line.
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.2.0 to 12.3.0. - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@12.2.0...12.3.0) --- updated-dependencies: - dependency-name: pillow dependency-version: 12.3.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…3176) Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.11 to 3.4.12. - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.11...3.4.12) --- updated-dependencies: - dependency-name: dompurify dependency-version: 3.4.12 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pypdf](https://github.com/py-pdf/pypdf) from 6.13.3 to 6.14.2. - [Release notes](https://github.com/py-pdf/pypdf/releases) - [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md) - [Commits](py-pdf/pypdf@6.13.3...6.14.2) --- updated-dependencies: - dependency-name: pypdf dependency-version: 6.14.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.1)
Can you help keep this open source service alive? 💖 Please sponsor : )