Weekly platform digest covering releases from iblai/iblai-prod-images (1.278.0 – 1.296.0) and iblai/iblai-web-frontend (47 releases total), published between 2026-10-02 and 2026-10-09.
| Service | Image / Pin | Version Span |
|---|---|---|
| dm | iblai-dm-pro | 4.412.0-ai → 4.421.0-ai |
| os | iblai-os-spa | 0.158.3 → 0.163.1 |
| lms | iblai-lms-spa | 0.88.0 → 0.91.0 |
| edx | iblai-edx-pro | sumac.2.63.2 → sumac.2.65.0 |
| cli | ibl-cli | 7.24.0 → 7.28.0 |
| auth | iblai-auth-spa | 2.6.0 → 2.7.0 |
| agent-ai | @iblai/agent-ai | 2.11.1 → 2.11.2 |
| web-containers | @iblai/web-containers | 1.35.1 → 1.38.1 |
| data-layer | @iblai/data-layer | 1.27.0 → 1.29.2 |
| mcp | @iblai/mcp | 1.25.0 → 1.28.1 |
| iblai-js | @iblai/iblai-js | 2.29.1 → 2.33.3 |
iblai-dm-pro (4.412.0-ai → 4.421.0-ai)
Per-mentor configuration flags (4.413.0). Four new nullable flags on the Mentor model, all off by default, settable on the mentor creation and settings endpoints:
show_last_conversation— client reopens the user's last conversation instead of starting fresh.enable_document_filter— gates whether a chat-timedocument_filterpayload is honored for retrieval. Off by default: user-submitted filters are ignored unless an admin enables it.disable_privacy_mode— turns off end-user chat-privacy controls for the mentor: hides the privacy button, the API returns 403 on attempts to make a session private. Also clamps the global per-user privacy setting so a locked mentor always records at least anonymized history.enable_in_chat_llm_change— students may pick a different LLM for their current session via a websocketllm_provider/llm_namepair; the backend validates against the tenant's credentials, stores the choice on the session (Session.llm_user_selected), and uses it for subsequent turns. Reverts to the mentor LLM on a new chat.- RBAC: members get read-only access to all four; write returns 403.
- Deploy:
ibl dm migrate(migration0389_per_mentor_config_flags) and re-runpython manage.py seed_rbac_data.
Agent welcome-screen settings (4.415.0). Three new Mentor fields:
guided_prompts_count(1–10, default 5) — drives the session guided-prompts endpoint; omitting?countfalls back to this value.welcome_heading_style(agent_name|personal_greeting, defaultagent_name).starter_promptsgains valuesall(show both guided and suggested) andnone(skip generation entirely — no LLM call).- A new admin-only preview endpoint
GET …/mentors/<mentor>/guided-prompts/preview/generates cold-start prompts honoring these settings, gated by theIbl.Mentor/Settings/write action. - Chat privacy toggle is now two-way: recording can be re-enabled by the session owner or a tenant admin, resuming history on the same session.
- RBAC: members get read on the two new fields; write returns 403.
- Deploy:
ibl dm migrate(migration0390_mentor_welcome_screen_settings) and re-runpython manage.py seed_rbac_data.
CRM module (4.416.0). Search, overview, deal board, favorites, saved views, history, and organization activities added to the platform's built-in CRM.
RBAC endpoint rate limiting (4.417.0). Per-user, per-platform throttling on /api/core/rbac/ (including agent-* aliases): RBAC_READ_THROTTLE_RATE (default 600/min; GET/HEAD/OPTIONS and permissions/check/ POST) and RBAC_WRITE_THROTTLE_RATE (default 120/min; all other methods). Server-to-server callers are exempt; ENABLE_THROTTLE=false disables it globally. Over the limit returns 429 with Retry-After. No migration; env vars are optional.
Smarter course-info sync (4.418.0). Course-info syncs triggered by edX publishes are now grouped per course — one sync per burst, 60 s after the first publish. A sync waits until edX serves the structure matching the latest publish before saving. Uses the edX completion plugin's GET /api/ibl/completion/course_version/<course_id> when available; gracefully falls back without it, so DM and edX can be deployed in either order. New optional CATALOG_APP_COURSE_SYNC_* settings (window, retry delays, version-check switch).
- Migration:
dl_catalog_app.0023_courseinfo_sync_fields— four nullable columns, safe for rolling deploys, must run before the new code starts.
Mentor provisioning & file handling (4.419.0).
- Mentor creation now provisions
MentorandMentorSettingsin a single transaction across all creation paths (public endpoint, template/wizard, seeded/default mentors, workflows, assessments, diagnostics, edX adaptive stubs, chat tool). - Run
python manage.py backfill_mentor_settingsafter deploy to repair any existing mentors missing settings (--dry-runavailable). - File/image uploads without a typed prompt now proceed — retrieval is skipped for a blank query, and the turn runs on the file alone.
- Uploaded documents stay available throughout the chat session regardless of conversation length.
- A mid-conversation model swap correctly handles reasoning blocks from the prior model.
- With
ENABLE_READ_REPLICA=true, Langfuse and ClickHouse routers now claim their databases before the read-replica catch-all, so evaluation endpoints work correctly. - Deploy: no schema migration. Run
python manage.py backfill_mentor_settingsafter deploy.
Data reports rate limiting (4.421.0). Three new per-user, per-platform budgets: DATA_REPORTS_READ_THROTTLE_RATE (default 120/min), DATA_REPORTS_GENERATE_THROTTLE_RATE (default 10/min; covers on-demand generation, learner chat-history reports and exports), DATA_REPORTS_DOWNLOAD_THROTTLE_RATE (default 30/min; report files, session exports, Heygen/Veo videos). Server-to-server callers are exempt. No migration; env vars are optional.
iblai-os-spa (0.158.3 → 0.163.1)
Product tour (0.161.0). Interactive guided-tour tooltips with state saved to user public metadata, giving first-time users a walkthrough of the OS interface.
SDK component migration (0.158.4–0.159.0). The agent datasets tab, API tab, and tools tab now render from shared SDK components (AgentApiTab, AgentToolsTab) with pagination. Mentor embed settings now persist the "Context Aware" and "Open By Default" toggles correctly, and "Create Embed" no longer overwrites Advanced CSS.
Code mode on Codex and Claude Code (0.162.0). Code mode runs on Codex and Claude Code over ACP with the SDK LLM model picker. Codex model listing uses codex debug models. DNS-over-HTTPS lookups are supported and custom domains surface in code mode. New IBL_VIBE_SKILLS_TAG and data-dir lock features.
Desktop app v0.95.24 (0.162.3). The Tauri desktop app now routes Microsoft/Azure AD and Microsoft Graph SSO sign-in through the in-app OAuth popup.
Incognito mode (0.163.0). Privacy/incognito mode added to the OS chat interface.
Accessibility menu (via SDK). Draggable floating accessibility menu button with persistent settings.
Per-model LLM availability (via SDK). Unavailable models are disabled in the agent LLM picker, evaluation picker, and sandbox picker.
Agent shared memory (0.163.1 via SDK). Agents can use shared memory across sessions.
Chrome extension v1.1.2 (0.158.6). Tenant-switch auth refresh in the browser extension.
iblai-lms-spa (0.88.0 → 0.91.0)
Product tour (0.90.0). Interactive guided-tour tooltips for the LMS interface.
Course content outline & tabs revamp (0.91.0). Redesigned course content outline and tab navigation.
Gradebook & instructor dashboard rebuild (0.91.0). Native re-implementation of the gradebook and instructor dashboard views, replacing MFE iframes.
iblai-edx-pro (sumac.2.63.2 → sumac.2.65.0)
Microsoft Graph SSO backend (sumac.2.64.0). A single Microsoft app registration now signs in both personal Microsoft accounts and work/school accounts from any Entra ID tenant. The new backend (microsoft-graph slug by default) is separate from the existing azuread-oauth2 v1.0 backend. Email resolves from Graph mail with a deliverable UPN fallback; the social UID is the immutable Graph id. Opt-in via ENABLE_MICROSOFT_GRAPH_SSO_BACKEND in CLI config. Requires ibl-third-party-auth ≥ 2.7.0.
- Deploy: build and roll out a new edX image, restart LMS and workers. Enable the Microsoft provider row in Django admin after deploy.
Course structure version check (sumac.2.65.0). New read-only endpoint GET /api/ibl/completion/course_version/<course_id> (staff and superusers) reports the course's latest published structure version versus the cached block structure version. Callers like the Manager's course sync can verify the cache reflects the latest publish before fetching.
Faster course_data (sumac.2.65.0). GET /api/ibl/completion/course_data/<course_id> now loads all blocks and content in one pass — about 2–2.7× faster on production courses.
- Deploy: build and roll out a new edX image, restart LMS.
ibl-cli (7.24.0 → 7.28.0)
Microsoft Graph SSO settings (7.25.0). ENABLE_MICROSOFT_GRAPH_SSO_BACKEND (default false) and MICROSOFT_GRAPH_SSO_NAME (default microsoft-graph).
Same-origin SPA API (7.26.0). IBL_REVERSE_PROXY.ENABLE_SPA_SAME_ORIGIN_API (default false) serves the unified backend API routes under /backend on each SPA's primary domain (/backend/dm, /backend/asgi including websockets, /backend/lms, /backend/studio), eliminating CORS preflight requests. Requires ENABLE_UNIFIED_API_GATEWAY. To switch an SPA: set its IBL_SPA.<SPA>.API_BASE_URL to https://<spa-domain>/backend. Not served on CUSTOM_TENANT_DOMAINS vhosts.
- Deploy:
ibl config set IBL_REVERSE_PROXY.ENABLE_SPA_SAME_ORIGIN_API=true, thenibl render && ibl global-proxy reload.
ibl sandbox (7.27.0). Full lifecycle management for the iblai-sandbox code-execution platform (KVM microVMs). Commands: check, up, launch, update, down, start, stop, restart, logs, status, scale --workers, firewall, hosts list|add|drain|enable|disable|remove, migrate, createsuperuser, issue-token. Presets: sandbox-only (all components on one server) and sandbox-host (scale-out KVM node). Service toggles under IBL_SANDBOX.* (control plane, worker, beat, host runtime, Postgres, Redis, dashboard). check validates Docker, /dev/kvm, database, Redis, and nftables. up applies guest-egress firewall, stages the guest image, runs migrations, and loads the image pinned by digest. status checks health and capacity endpoints and exits non-zero when unhealthy. Scaling via GLOBAL_MAX_SESSIONS, HOST_MAX_SESSIONS, admission memory/CPU thresholds. Built-in egress firewall with configurable connection rates.
OS API base URL (7.28.0). IBL_SPA.OS.API_BASE_URL (default https://api.<BASE_DOMAIN>) rendered as NEXT_PUBLIC_API_BASE_URL in .env.os. Set to https://<os-domain>/backend for same-origin API.
iblai-auth-spa (2.6.0 → 2.7.0)
Free-plan checkout on sign-up (2.7.0). The Sign Up flow now creates an organization through the free-plan checkout, streamlining onboarding.
CRM copy and layout (2.7.0). Updated CRM-facing copy; the slide panel has been removed in favor of direct navigation.
Custom-domains API (2.6.1). Custom-domains requests now use the correct trailing slash.
@iblai/agent-ai (2.11.1 → 2.11.2)
Multi-tenant token handling (2.11.1). Tokens are re-minted when the cached iblData belongs to a different tenant, and consolidated-token proxy calls no longer send cookies — preventing cross-tenant state leakage.
Embed path fix (2.11.2). The embed iframe path no longer doubles the leading slash.
@iblai/web-containers (1.35.1 → 1.38.1)
Per-model LLM availability (1.35.1). Each model's availability is now evaluated individually; unavailable models are disabled in the agent LLM picker, sandbox picker, and evaluation picker.
Accessibility menu (1.36.0). A draggable floating accessibility button with a useDraggablePosition hook. Settings storage is guarded against SecurityError in restrictive iframe contexts.
Incognito mode (1.37.0–1.38.0). Privacy/incognito mode for chat with two-way messaging — users can toggle recording off and back on within a session.
Agent shared memory (1.38.1). Agents can read and write shared memory across sessions.
@iblai/data-layer (1.27.0 → 1.29.2)
Pinned messages filtering (1.27.0). getPinnedMessages now accepts mentor and search parameters and uses a session-free GET.
Custom-domains fix (1.29.1). Custom-domains requests include the trailing slash.
Agent shared memory (1.29.2). Data hooks for reading and writing agent shared memory.
@iblai/mcp (1.25.0 → 1.28.1)
Accessibility components (1.25.0–1.26.0). Documented accessibility components, the drag hook, and the useDraggablePosition API for MCP server consumers.
Pinned-messages hook (1.25.0). Documented mentor and search parameters on the pinned-messages hook.
Rolls up the underlying web-containers and data-layer changes.
@iblai/iblai-js (2.29.1 → 2.33.3)
Umbrella SDK package. Rolls up all agent-ai, web-containers, data-layer, mcp, and auth changes listed above.