- New tool nexus_vision: describe an image via a vision chat model
(default google/gemini-3.1-flash-lite) and record result in journal.
- NordRouter /media/upload now detects MIME from file extension so
data: URLs use the correct type (fixes HTTP 415 for images/audio/video).
- HttpClient supports FormData bodies (undici) for future multipart use.
STT does not produce a local media file, so journal.filePath should be
null. Otherwise admin gallery tries to serve the source file from outside
the media dir and gets a broken link.
KeyResolver now wraps getApiKey in try/catch and falls back to env instead of
crashing startup. ProvidersStore.getApiKey returns undefined when the cipher is
disabled rather than throwing. Server starts cleanly with env-only, and uses the
encrypted DB key when the master key is present.
Fastify + single-page frontend on shared @nexusai/core. Reads the same SQLite
journal and media dir. Features: usage stats (by provider/capability/day),
content gallery (image/audio/video with local file serving + path-traversal
guard), provider CRUD with encrypted keys (masked in UI), enable/disable,
set-default, and real key validation via zero-cost /media/models call.
Adds Journal.getById and NordRouterMediaProvider.checkKey to core.
AES-256-GCM encryption (KeyCipher) with master key from NEXUS_MASTER_KEY,
never persisted. ProvidersStore in SQLite: CRUD, enable/disable, default,
encrypted api keys, masked views for UI. KeyResolver applies env>DB precedence
and supports multiple providers. context.ts registers providers dynamically
from resolved config; backward compatible with env-only setups.
Monorepo-lite with shared @nexusai/core and @nexusai/mcp-server (stdio).
Provider-agnostic tools with explicit provider selection; NordRouter adapter
(media generate/poll/download, estimate, upload, models) and search via
perplexity/sonar. Local STT via faster-whisper uv sidecar. SQLite journal of
every generation for usage stats and future admin. 10 MCP tools.