What's Changed
- fix: make the license provider more HA by @thedadams in #7292
- chore: update vulnerable dependencies by @calvinmclean in #7261
- fix: don't hold a DB transaction across auth provider HTTP calls by @ibuildthecloud in #7228
- chore: update vulnerable UI dependencies by @calvinmclean in #7304
- docs: update example k8s values file by @cloudnautique in #7306
- feat: tool-call enforcement backend for MDM configurations by @g-linville in #7282
- chore: remove Bifrost LLM dispatch by @calvinmclean in #7233
- chore: use CODEOWNERS for dependency reviews by @calvinmclean in #7316
- fix: intialize composite clients upfront by @thedadams in #7315
- feat: add Community Edition enrollment API and UI by @thedadams in #7303
- fix: highlight missing Kubernetes secret bindings by @calvinmclean in #7246
- enhance: admin devices & mcp filters getting started guide by @ivyjeong13 in #7319
- feat(tunnels): add managed MCP WebSocket tunneling by @thedadams in #7311
- fix: always set peer config in helm chart by @thedadams in #7327
- chore: update "getting started" obot sentry guide steps & text by @ivyjeong13 in #7326
- fix: send spec-ful issuer by @thedadams in #7328
- chore: add logging for oauth errors by @thedadams in #7329
- enhance: update My Api Keys -> Agent Auth Scope by @ivyjeong13 in #7323
- fix: remove undesired fields from the tunnels table by @thedadams in #7338
- feat: add support for user limits by @thedadams in #7322
- fix: resolve provider model IDs with slashes by @calvinmclean in #7307
- fix: ui changes for agent auto scope details & text updates by @ivyjeong13 in #7344
- fix(license): validate community email domains by @thedadams in #7342
- fix: prefer tunnel display name to id in errors by @thedadams in #7337
- chore(ui): update MCP tunnels by @thedadams in #7340
- fix: disallow removing in-use allowed URLs for tunnels by @thedadams in #7339
- fix(ui): offer community license from resolve dialog by @thedadams in #7345
- enhance: return user limit and user count in version API by @thedadams in #7349
- fix(ui): show disconnected MCP tunnel status by @thedadams in #7343
- feat: add ui for enforcement and backend tweaks by @g-linville in #7332
- chore: change Community Edition to Obot Community by @thedadams in #7351
- fix: use sensitive input for local auth login by @ivyjeong13 in #7346
- chore: change to forbidden status for too many users by @thedadams in #7360
- fix: disable interaction w/ "getting started" guides & add steps in obot-sentry guide by @ivyjeong13 in #7359
- fix: community edition license ui updates by @ivyjeong13 in #7352
- fix: reject resource URLs without an MCP ID by @thedadams in #7361
- docs: add enforcement by @g-linville in #7362
- fix(ui): avoid duplicate tunnel disconnected status by @thedadams in #7365
- fix: stamp MDM download zip entries with a modification time by @njhale in #7363
- chore: update docs w/ reskin api keys -> agent auth scopes by @ivyjeong13 in #7364
- enhance(devices): add limits similar to users by @thedadams in #7368
- fix: update licensing page & add community logo by @ivyjeong13 in #7370
- fix: strip trailing newline when copying code snippets by @njhale in #7372
- Route OAuth debugger requests through MCP tunnels by @thedadams in #7355
- fix(oauth): sanitize error redirect descriptions by @thedadams in #7369
- fix: ensure backend APIs are not authorized by UI by @thedadams in #7375
- chore: general ui cleanup by @ivyjeong13 in #7358
- docs/architecture diagram image by @cjellick in #7408
- docs: mention Cursor settings for enforcement by @g-linville in #7373
- fix: ensure caches are started before start the server by @thedadams in #7411
- fix: limit models & model access policy to llm/llm-mini by @ivyjeong13 in #7341
- fix: use creatable capabilities constant in agent auth scope details view by @ivyjeong13 in #7416
- fix(docs): disable Codex web search for Azure and Bedrock by @calvinmclean in #7418
- chore: bump obot-sentry default version to v0.1.4 by @njhale in #7421
Full Changelog: v0.24.1...v0.25.0-rc1