Vaadin 25.3 Adds Auditable AI Forms and a Coding-Agent Dev Loop
Summary
Vaadin 25.3 is a major feature release centered on visibility into AI actions, production behavior, and coding-agent changes. Its AI form filler now marks every AI-changed field and can show reported confidence, source excerpts, and document locations; users can review or revert individual values. Source tracking is disabled by default because it consumes additional output tokens, and the AI form features require a commercial subscription. RequestInterceptor can inspect, modify, or reject prompts and attachments before orchestration, while ResponseMetadata exposes finish reasons and token usage, and ToolException lets tools return controlled failure messages to the model. Built-in providers also add per-turn tool-call limits and optional background execution. The free `vaadin-ai-core-flow` module contains the interceptor, metadata, and provider API, while commercial controllers and field markers move to `vaadin-ai-extensions-flow`; the integration remains experimental and requires a feature flag. Vaadin also adds a preview dev-loop daemon and CLI for coding agents. Its `apply` command chooses between browser updates, hot swapping, and restarts, reports compile errors with file and line information, and preserves the last working application when an edit fails, although annotation processors and some signature changes remain limitations. Observability Kit 5 replaces the Java-agent deployment model with Micrometer and requires Java 21 and Vaadin 25.3, but changes meter names and dashboard behavior. Flow's browser engine has also moved from GWT-compiled Java to TypeScript across 107 modules, without changing the Java API; add-ons using the old GWT client API must be rewritten. The release includes new UI components, validation and accessibility APIs, server-sent-event push as an experiment, TypeScript 7 checks, and deprecations affecting NativeTable and three kits before Vaadin 26.