Edited and regenerated messages now pass the full policy gate
Edited and regenerated messages now run the same checks as a new message. Previously both paths called the model provider directly, so an edited or regenerated message — including one where a user added a card number or other sensitive data — could reach the model without the PII gate, plugins, firewall rules, rate limits, or budget checks running.
All of these now run on the exact turn the model is about to see, and a refused edit persists nothing.
SaaS tenants are already patched. Self-hosted customers should upgrade to v1.22.0.