397 Commits
Author SHA1 Message Date
Dave HortonandClaude Opus 5.5 d657a0cb2d fix: ignore messaging_hook in application create/update (#567)
messaging_hook was removed along with smpp (#559), but POST and PUT
/Applications still pass the request body straight into the INSERT/UPDATE.
Clients that still send messaging_hook (even as null) get a 500:
"Unknown column 'messaging_hook' in 'field list'".

Drop the field from the request body so older clients keep working.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-08 12:19:24 -06:00
Dave HortonandClaude Opus 5.5 328087042f fix: release homer sockets when a pcap request is abandoned (#565)
The pcap route awaited homer with no timeout and no tie to the client
connection, then used stream.pipe(res). If the client gave up (nginx 499)
before homer answered, the homer response body was piped into a closed
response, pipe() detached without destroying it, and the unread body kept
its socket and buffers referenced by the global undici pool forever.

With homer slow, this leaked roughly one socket per abandoned request:
~1,300 open fds and +200 MB RSS per api-server worker within four hours.

- abort the homer auth and pcap fetches when the response closes or after 30s
- use stream.pipeline() so the homer stream is destroyed if the client leaves

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-07 17:04:33 -06:00
Hoan Luu HuuandClaude Opus 5 038388f052 feat(tts): add Inworld TTS 2 and TTS 2 Flash models (#564)
- add inworld-tts-2 and inworld-tts-2-flash to the Inworld model list
- both return word timestamps; flash is the low-latency/low-cost variant
- model_id is passed through unchanged, so no other wiring is needed

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-26 08:03:21 -04:00
Hoan Luu HuuandClaude Opus 5 baf80cb84c fix: speechmatics credential test ignored the configured region (#563)
The speechmatics branch of the /test route destructured only api_key out of the
decrypted credential, so testSpeechmaticsStt() passed realtimeUrl: undefined to
the sdk. ConnectionConfigFull only applies an override when the value is truthy,
so every credential was silently tested against wss://eu2.rt.speechmatics.com/v2
no matter which region was stored - a neu or wus key was judged by whatever eu2
happened to answer.

- pass speechmatics_stt_uri through from the route
- normalize it before handing it to the sdk. The field holds a bare hostname,
  which the sdk cannot use as-is: it appends the language, yielding
  "eu2.rt.speechmatics.com/en" and ERR_INVALID_URL. At call time the same value
  goes to mod_speechmatics_transcribe as SPEECHMATICS_HOST, which always
  connects over wss on port 443 with a path of /v2, so build exactly that url.
  Anything else - a full ws url, a port - now fails the test with an actionable
  message rather than passing against an endpoint only the test can reach, and a
  credential that has lost the field fails too: the feature server omits
  SPEECHMATICS_HOST when it is unset and the module refuses the session, so
  defaulting to a hosted region here would show a green check on a dead
  credential.
- record the speechmatics STT result with sttTestResult(), not ttsTestResult(),
  which is what every other STT vendor in this file does; the tts column was
  being stamped for an STT-only vendor

Adds coverage for the url building to the main test suite - it is the part of
this that can be exercised without an api key.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-14 11:06:28 -04:00
Sam Machin 53279a59c0 check account sid on client delete (#560) 2026-07-28 12:51:41 -04:00
Sam Machin 24621f79dd Remove smpp (#559)
* remove smpp

* update db-helpers
2026-07-28 10:32:42 -04:00
Dave HortonandClaude Opus 4.5 bff9314622 fix(security): add authorization checks to prevent cross-account access (CWE-639) (#558)
- Add precondition support to decorate.js retrieve function
- Fix google-custom-voices.js typo and add delete precondition
- Check ownership via speech_credential for google-custom-voices
- Add retrieve/delete preconditions to lcr-carrier-set-entries.js
- Add retrieve precondition to sip-gateways.js and smpp-gateways.js
- Add scope check to lcr-routes.js custom GET handler
- Add full authorization to tenants.js for all CRUD operations
- Add scoped query methods to tenant model

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-06-27 15:53:51 -04:00
Hoan Luu Huu 3bb33f24c2 fix microsoft SST endpoint id is failed on validating speech credential (#554) 2026-06-01 08:38:21 -04:00
Sam Machin e0a9035d38 prvent 0.0.0.0 & /0 gateways (#553) 2026-05-29 09:07:10 -04:00
Hoan Luu Huu dd755f8746 support houndify wss (#551) 2026-04-23 07:20:04 -04:00
Sam Machin fb54f562f7 Update recent-calls.js (#549) 2026-04-14 08:19:42 -04:00
Sam MachinandDave Horton 4c6ad12a7f fix query sp alerts & bump time-series (#547)
* fix query sp alerts & bump time-series

* add package-lock.json back

* fix: use shared parseAccountSid/parseServiceProviderSid from utils in alerts and recent-calls routes

* fix/update tests

* fix tests

---------

Co-authored-by: Dave Horton <daveh@beachdognet.com>
2026-03-30 10:25:45 -04:00
Hoan Luu Huu b95a593182 fixed houndify speech credential validation skiped if custom endpoint provided (#522) 2026-03-05 07:17:52 -05:00
rhondahollisandrhonda hollis c80928f569 add retell to predefined-carriers (#545)
Co-authored-by: rhonda hollis <rhonda@jambonz.org>
2026-02-24 12:50:49 -05:00
Hoan Luu Huu 99bfec5888 support inworld models (#543) 2026-02-12 07:46:07 -05:00
Dave Horton 9875686f92 Fix/carrier entry data (#542)
* protect against invalid carrier data entry

* sec fixes
2026-02-09 10:40:59 -05:00
Sam Machin f5fa3bdffb allow startrecording without siprec url for cloud (#530)
* allow startrecording without siprecm url for cloud

* update dependencies
2026-01-29 18:21:31 -05:00
Sam Machin bc26651cdb add new fieds for ICE and DTLS (#538) 2026-01-29 13:42:07 -05:00
Hoan Luu Huu 77dbe964aa fix soniox stt speech credential validation (#535) 2026-01-23 10:08:45 -05:00
Hoan Luu Huu 3609b8e828 support openai transcribe support auto language (#537) 2026-01-23 07:40:00 -05:00
Hoan Luu Huu 27addfa543 support google gemini tts (#534)
* support google gemini tts

* wip

* wip

* wip

* wip

* wip

* support speech utils
2026-01-22 08:24:05 -05:00
Dave Horton 6341132807 Feat/sql improvements (#536)
* add indexes

* update sql editor file

* upgrade schema

* optimize Applications.retrieveAll

* security fixes

* update gh workflows
2026-01-15 08:45:40 -05:00
Matt HertogsandClaude Sonnet 4.5 0bf68b6a9b Fix: Allow media_path updates from REST API (#533)
Added media_path to the list of allowed properties for call updates via REST API.
Includes validation to ensure media_path values are one of: no-media, partial-media, or full-media.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-01-09 15:52:23 -05:00
Sam Machin 69046ab5d2 Feat/admin numbers carriers (#532)
* add JAMBONES_ADMIN_CARRIER check to limit creating carriers and numbers

* fix logic
2026-01-07 08:01:44 -05:00
Dave Horton 3f1e756467 wip (#529) 2025-12-22 08:28:37 -05:00
Sam Machin 4201ebbe9c Fix/526 (#528)
* calidate webhook urls on update

* don't remove webhooks if not updated

* valid if object exists
2025-12-19 07:32:20 -05:00
Hoan Luu Huu dd79813229 cannot fetch voice_call_session (#525) 2025-12-17 07:27:01 -05:00
Hoan Luu Huu 1aa28e8ba0 fixed how to detect obscured key (#524)
* fixed how to detect obscured key

* wip

* wip
2025-12-12 08:56:55 -05:00
Hoan Luu Huu 15f2d92f71 subscription update-quantities validate min voice call sessions (#521)
* subscription update-quantities validate min voice call sessions

* subscription update-quantities validate min voice call sessions

* fixed review comment
2025-12-08 08:12:35 -05:00
Hoan Luu Huu 6ef40a648c allow boostAudioSignal from updateCall (#523) 2025-12-07 08:37:38 -05:00
Hoan Luu Huu 40754deb3e soundhound speech credential support audio endpoint (#520)
* soundhound speech credential support audio endpoint

* soundhound speech credential support audio endpoint

* wip

* wip
2025-11-28 21:47:40 -05:00
Sam Machin eb681f9ddf force account sip_realm to lowercase (#519) 2025-11-20 07:18:17 -05:00
Sam Machin 486428727a remove activation code from response (#513) 2025-11-12 13:13:09 -05:00
Hoan Luu Huu 0d66dc9c27 support sonic-3 (#507)
* support sonic-3

* update supported languages
2025-10-30 21:21:27 -04:00
Dave Horton e9d14e9e38 no need to update api_key use date more than once per minute (#506) 2025-10-28 17:18:22 -04:00
Hoan Luu Huu 42f4318a17 support gladia stt (#503)
* support gladia stt

* wip

* update verb specification
2025-10-20 04:47:17 -04:00
Hoan Luu Huu bcff9b35a6 support houndify stt (#498)
* support houndify stt

* wip

* test houdify stt credential

* wip

* wip

* update verb specification
2025-10-14 00:52:49 -04:00
Hoan Luu Huu 8267ddaffd support elevenlabs different endpoint (#502)
* support elevenlabs different endpoint

* wip

* wip

* wip
2025-10-09 08:20:11 -04:00
Hoan Luu Huu c3d12fafee support deeepgram influx (#501)
* support deeepgram influx

* update verb specification
2025-10-03 10:09:19 -04:00
Hoan Luu Huu 9421bb8aa1 fixed deepgram cannot fetch list of available voices for model (#500) 2025-09-27 10:13:06 -04:00
RJ Burnham a297d2038f Refactor S3MultipartUploadStream to optimize buffer handling and improve upload efficiency (#494)
- Replaced Buffer.concat with chunk accumulation to reduce time complexity during writes.
- Introduced bufferedBytes to track total size of accumulated chunks.
- Updated upload logic to handle parts more efficiently, minimizing memory overhead.
- Enhanced logging in upload function to include selected encoder format for better traceability.

(cherry picked from commit ce8bba2f18d807d4872b168e451e4501b1acb824)
2025-09-04 07:34:19 -04:00
Sam Machin 2e0ea56925 Fix API for Carriers & SIP Gateways (#492)
* allow account api keys to get/post sip gateways

* require sp sid when creating carriers

* allow account level api keys to query carriers

* lookup and set the service_provider_sid on account create carrier
2025-08-28 08:46:42 -04:00
Dave Horton 035458ad3c logging 2025-08-13 20:33:40 -04:00
Hoan Luu Huu fd9dc77a58 support resemble TTS (#488)
* support resemble TTS

* wip

* wip

* update speech utils version

* update resemble voice list
2025-08-13 08:18:08 -04:00
Hoan Luu Huu 2b66a121a0 fixed deepgram river does not return api_key (#486) 2025-07-30 08:29:57 -04:00
Hoan Luu Huu 3a6d10e725 support deepgram river (#481)
* support deepgram river

* update verb specification version
2025-07-29 13:51:36 -04:00
Sam Machin 9854666d4f add new /Callcount endpoint (#480)
* add new /Callcount endpoint

* update db-helpers

* update endpoint
2025-07-03 11:49:27 -04:00
Dave Horton 819319dbe5 logging 2025-07-01 18:25:54 -04:00
Hoan Luu Huu 0ba69e872b support assemblyai v3 (#475)
* support assemblyai v3

* update verb specification
2025-07-01 15:48:00 -04:00
Sam Machin 542ccfca79 check for whitespace in gateways and phone numbers (#477) 2025-07-01 07:16:27 -04:00