v2026.3.11
发布于 2026-03-12 · 翻译于
🎯 一句话总结:此版本重点增强安全性,优化 iOS/macOS 交互体验,升级记忆系统多模态能力并新增多家模型支持。
📋 更新要点(中文翻译)
1修复网关 WebSocket 劫持漏洞,增强浏览器连接安全性。
2iOS 主页新增欢迎屏与固定工具栏,优化小屏设备适配体验。
3macOS 聊天界面新增模型选择器,支持持久化思考级别设置。
4Ollama 新增一级安装向导,支持本地与云加本地混合模式。
5新增 OpenCode Go 提供商,共享密钥配置简化设置流程。
6记忆系统支持 Gemini 多模态索引,可检索图片与音频内容。
7Discord 支持自定义自动归档线程时长,不再强制默认一小时。
8OpenRouter 内置 Hunter 与 Healer Alpha 模型供免费试用。
9macOS 优化远程网关认证检测,明确共享令牌与配对设备验证。
10记忆搜索升级 Gemini 嵌入模型,支持配置维度与自动重建索引。
▶查看英文原文(Release Notes)
### Security
- Gateway/WebSocket: enforce browser origin validation for all browser-originated connections regardless of whether proxy headers are present, closing a cross-site WebSocket hijacking path in `trusted-proxy` mode that could grant untrusted origins `operator.admin` access. (GHSA-5wcw-8jjv-m286)
### Changes
- OpenRouter/models: add temporary Hunter Alpha and Healer Alpha entries to the built-in catalog so OpenRouter users can try the new free stealth models during their roughly one-week availability window. (#43642) Thanks @ping-Toven.
- iOS/Home canvas: add a bundled welcome screen with a live agent overview that refreshes on connect, reconnect, and foreground return, and move the compact connection pill off the top-left canvas overlay. (#42456) Thanks @ngutman.
- iOS/Home canvas: replace floating controls with a docked toolbar, make the bundled home scaffold adapt to smaller phones, and open chat in the resolved main session instead of a synthetic `ios` session. (#42456) Thanks @ngutman.
- macOS/chat UI: add a chat model picker, persist explicit thinking-level selections across relaunch, and harden provider-aware session model sync for the shared chat composer. (#42314) Thanks @ImLukeF.
- Onboarding/Ollama: add first-class Ollama setup with Local or Cloud + Local modes, browser-based cloud sign-in, curated model suggestions, and cloud-model handling that skips unnecessary local pulls. (#41529) Thanks @BruceMacD.
- OpenCode/onboarding: add new OpenCode Go provider, treat Zen and Go as one OpenCode setup in the wizard/docs while keeping the runtime providers split, store one shared OpenCode key for both profiles, and stop overriding the built-in `opencode-go` catalog routing. (#42313) Thanks @ImLukeF and @vincentkoc.
- Memory: add opt-in multimodal image and audio indexing for `memorySearch.extraPaths` with Gemini `gemini-embedding-2-preview`, strict fallback gating, and scope-based reindexing. (#43460) Thanks @gumadeiras.
- Memory/Gemini: add `gemini