Commit Graph

1455 Commits

Author SHA1 Message Date
Yichen Jiang
9f996be8e3 fix(web-config): close the wire boundary, the redacted-replace data loss, and three P2s
Five findings from the #939 review, each reproduced before being fixed.

**Configuration reads are as privileged as writes.** `settings.describe`
returns every exposed namespace's configuration and `credentials.describe`
reports whether an arbitrary environment-variable name is configured and from
where — reconnaissance no anonymous caller should have. Both join
PRIVILEGED_METHODS, so the whole configuration plane is loopback-only until
real authentication exists; `trustedHosts` was never authentication. The model
catalog stays reachable: it carries no endpoints or key state, and a LAN
client's model picker legitimately needs it. Asserted over a real HTTP server,
because the Host header a browser actually sends is what decides this.

**The proxy serves only namespaces a registered model provider addresses.**
The settings seam is general — any plugin may register one — but the Web
configuration plane is the model-provider surface. Without the gate, every
future `settings.register()` would silently become remotely readable and
writable configuration. An unregistered namespace and an unexposed one answer
identically, so no caller can enumerate the registry one probe at a time.

**Path-addressed writes replace the redacted-document rebuild.** The editor
reads the REDACTED descriptor, so rebuilding a section from it and replacing
wholesale deleted every literal secret the wire never returned — reproduced as
`{baseURL, reasoning}` in, stored `apiKey` gone out. `settings.mutate` applies
set/unset ops to the section as it stands at the front of the seam's write
queue, and the client names only fields it can see, so an unseen secret is
untouched by construction rather than by care.

P2s in the same pass: `llm/adapters-updated` now contains async listener
rejections (an uncontained one escaped as unhandledRejection, contradicting
the documented "observer failures are contained"); llm-deepseek's retry-policy
swap uses the atomic `registration.replace` instead of dispose-then-register,
which published `[]` then `["deepseek-official"]` so an observer saw the
provider disappear and come back; and a transport rejection no longer strands
the page in `loading` or a card in `busy`, with removal failures surfaced on
the page banner instead of swallowed.
2026-07-30 18:30:15 +08:00
Hypatia May
7cafb71ad7 Merge remote-tracking branch 'origin/master' into codex/status-bar-token-metrics 2026-07-30 18:29:08 +08:00
Hypatia May
7a6d64981c round 3: disambiguate standalone compaction sections 2026-07-30 18:28:06 +08:00
kingwl
1f5d09c2d7 Merge origin/master into codex/figma-context-injection-row
# Conflicts:
#	packages/client/ui-conversation/README.i18n.yaml
2026-07-30 18:27:49 +08:00
ZiyaZhang
98c6380f07 Merge remote-tracking branch 'upstream/master' into fix/session-waiting-approval 2026-07-30 03:25:49 -07:00
kingwl
cdd1074805 Merge remote-tracking branch 'origin/master' into codex/queue-collapse
# Conflicts:
#	packages/client/ui-conversation/README.i18n.yaml
2026-07-30 18:21:07 +08:00
Hypatia May
d0e387dfdc Merge remote-tracking branch 'origin/master' into codex/status-bar-token-metrics
# Conflicts:
#	packages/client/ui-conversation/README.i18n.yaml
2026-07-30 18:19:35 +08:00
Chinesezjc
7a60a236bc feat(web): render read tool output as a line-numbered code card
Consume the card:'read' result view (path, numbered lines, totalLines, lang)
the read backend PR added. ReadBlock (ui-primitives) draws a per-line gutter
with each line's own file number, shiki highlighting via a new highlightLines
returning per-line token arrays, a 显示 X / Y 行 window note, a height cap
matching TerminalBlock, and a copy control. read-card-model is the single
resultView derivation; a keyed ReadRow registers under read with the card
resident under its path-link summary. The generic fallback and the details
panel are read-aware. Fixture gains a windowed read turn for the built-boot
snapshot.
2026-07-30 18:15:38 +08:00
Hypatia May
4de4d693a2 round 2: address manual compaction review findings 2026-07-30 18:15:12 +08:00
Chinesezjc
2928c65ccd feat(web): fold the search truncation total into the summary line
Replace the separate '已截断 · 共 N' pill with '显示 X / 共 N 处匹配 · K 个文件'
(and '显示 X / 共 N 个路径' for glob), mirroring the read card's '显示 X / Y 行',
so the retained count and the pre-cap total read as one clause instead of two
numbers that appear to disagree.
2026-07-30 18:09:03 +08:00
_Kerman
f296fd3075 Merge remote-tracking branch 'github/master' into xtr/trajectory-timeline-click-focus
# Conflicts:
#	apps/web/tests/details-session-lifecycle.e2e.ts
#	packages/client/ui-layout/README.i18n.yaml
2026-07-30 18:08:22 +08:00
creatixchu
f4111a3701 fix(ui): drop the caption from the /permission error text too
Review round: the no-caption rule the Agent Note states applied only to the
success texts, leaving `permission · unknown permission preset "bogus" (…)`.
The error text now reads `unknown preset "bogus" (…)` and its exact wording
is pinned; the fixture mirror drops `JSON.stringify` for the host's own
quoting so the two cannot drift on a quoted argument.

The Note now states the line it draws: the rule bans a caption for the
command's own value, not the vocabulary, so `/plan`'s `Plan mode off.` and
`/goal`'s `Goal cleared.` conform as written — recorded with the broader
name-ban as a rejected alternative. The web row assertions are scoped to the
row so unrelated page text reading `permission` cannot satisfy them.
2026-07-30 18:07:35 +08:00
_Kerman
daed49ad54 perf(ui-trajectory): reuse finalized stream projections 2026-07-30 18:05:49 +08:00
Tianyi Cui
53ff5c6ef2 Merge branch 'master' into feature/shared-cli-config-foundation 2026-07-30 18:02:07 +08:00
Yichen Jiang
3ba4d40e6a fix(user-interaction): address review feedback 2026-07-30 17:59:37 +08:00
_Kerman
7ec01dad08 fix(ui-trajectory): bound expensive record previews 2026-07-30 17:55:06 +08:00
creatixchu
c0679f42b5 fix(web): cap the approval takeover at the composer's text height
The approval panel replaces the InputBar while a sandbox escalation waits,
and its justification and command are unbounded model text. With no height
cap, a long command grew the card until the refuse/allow row went under the
fold: at 900x700 the action row's bottom landed at y=749, so the user could
read the request and not answer it.

Justification and command now scroll in one region capped at the same height
as the composer's draft area, with the amber strip and the action row outside
it. The cap is one value with two consumers — declared as
--dsh-composer-text-max-height on ConversationRoot's .composerSeat, the
composer chain's only shared ancestor — so the seat cannot cap its two states
differently. The card rebinds the l2 scrollbar pair like every other scrolling
surface on an elevated background.

Covered by a new web e2e scenario that drives the real composition (read-only
session, denied write, the model's escalation retry, answer clicked through
the panel) and measures the live panel at two viewport heights against the
composer's own cap, read off the textarea rather than hardcoded.
2026-07-30 17:50:04 +08:00
_Kerman
c000bf3be8 fix(ui): hide sidebar resize pill 2026-07-30 17:43:45 +08:00
Chinesezjc
f6802ee019 feat(web): render web_search/web_fetch output as a web card
Consume the card:'web' result view (structured sources + answer for search, the
URL and HTTP status for fetch) the web backend PR added. WebBlock
(ui-primitives) draws both kinds via the kind discriminant: a citation list of
safe external links (the MarkdownText protocol allowlist, title-or-hostname
label), a truncation indicator, a height cap matching TerminalBlock; a fetch
summary for the other kind. web-card-model is the single resultView derivation;
a keyed WebRow registers under web_search and web_fetch with the card resident
under its summary. The generic fallback and the details panel are web-aware.
Fixture gains web_search and web_fetch turns for the built-boot snapshot.
2026-07-30 17:43:13 +08:00
Chinesezjc
71adea8ba4 feat(web): render grep/glob search output as a search card
Consume the card:'search' result view (matches grouped by file for grep, a
path list for glob) the search backend PR added. SearchBlock (ui-primitives)
draws both kinds via the kind discriminant with a per-file collapse, a
truncation pill, a height cap matching TerminalBlock, and a copy control;
search-card-model is the single resultView derivation; a keyed SearchRow
registers under grep and glob with the card resident under its summary. The
generic fallback and the details panel are search-aware. Fixture gains grep and
glob turns for the built-boot snapshot.
2026-07-30 17:42:59 +08:00
_Kerman
287289ddbc feat(ui): highlight trajectory errors 2026-07-30 17:42:02 +08:00
ZiyaZhang
51711a3772 docs(ui-sidebar): defer session status ownership 2026-07-30 02:41:32 -07:00
ZiyaZhang
285cd60744 docs(ui-workspace): align approval status contracts 2026-07-30 02:40:31 -07:00
Yichen Jiang
31a498b1db test(web): follow inline custom answer input 2026-07-30 17:39:28 +08:00
ZiyaZhang
9eee7cb462 Merge remote-tracking branch 'upstream/master' into fix/session-waiting-approval 2026-07-30 02:36:30 -07:00
Tianyi Cui
66e182b516 Merge branch 'master' into feature/shared-cli-config-foundation 2026-07-30 17:35:47 +08:00
kingwl
3d6cacc59b Merge remote-tracking branch 'origin/master' into codex/composer-dock-stacking
# Conflicts:
#	packages/client/ui-conversation/README.i18n.yaml
2026-07-30 17:35:22 +08:00
kingwl
0f0564b3d0 Merge origin/master into codex/figma-context-injection-row 2026-07-30 17:35:04 +08:00
Yichen Jiang
c86b7c2c3a Merge remote-tracking branch 'origin/master' into worktree/fix-multi-select-custom-answer
# Conflicts:
#	packages/client/ui-question/README.i18n.yaml
#	packages/client/ui-question/src/client/QuestionComposer.tsx
#	packages/host/apiproxy/README.i18n.yaml
#	packages/ui/tui/README.i18n.yaml
2026-07-30 17:34:48 +08:00
creatixchu
0f8cde3e02 Merge remote-tracking branch 'origin/master' into worktree/command-row-copy 2026-07-30 17:34:38 +08:00
kingwl
f5228e7c71 Merge origin/master into codex/figma-context-injection-row
# Conflicts:
#	packages/client/ui-conversation/README.i18n.yaml
#	packages/client/ui-conversation/src/client/chat/ToolRow.module.css
#	packages/client/ui-conversation/src/client/chat/ToolRow.tsx
2026-07-30 17:34:14 +08:00
creatixchu
d9cb19f276 feat(ui): drop the slash and the argument echo from the command row
The web command row renders `title · summary` from one logged command
lifecycle pair, and the two halves were written without knowing about each
other: the title was the dispatched line rebuilt from `command/run` and the
summary was `command/done`'s verbatim text, so every Access-chip pick read
`/permission workspace-write · Permission preset: workspace-write.` — the
command name twice and its argument twice.

The title is now the bare command name (no `/`, no arguments — the summary
already says what the command did), and a command handler's settlement text
never repeats the command's own name, so `/permission` returns `preset
workspace-write`. The row reads `permission · preset workspace-write`, and
the TUI notice still names the preset that now applies. The log is
unchanged: `command/run` keeps its structured name/args split for a richer
registered row.
2026-07-30 17:34:03 +08:00
Hypatia May
16378e4ba7 Merge remote-tracking branch 'origin/fix/human-transcript-projection' into fix/web-transcript-projection
# Conflicts:
#	packages/client/ui-conversation/README.i18n.yaml
2026-07-30 17:33:55 +08:00
_Kerman
d1dc303bc6 Merge remote-tracking branch 'origin/master' into xtr/react-loop-simplification
# Conflicts:
#	docs/cordis-catalog/services.md
#	docs/core-data-structures/session.i18n.yaml
#	docs/persistence-catalog.md
#	packages/cordis/tool-cordis/src/api-catalog.ts
2026-07-30 17:30:10 +08:00
Hypatia May
cc7c1f44de Merge remote-tracking branch 'origin/master' into codex/status-bar-token-metrics 2026-07-30 17:29:50 +08:00
_Kerman
3c4a185e35 fix(ui): balance trajectory context icon 2026-07-30 17:28:04 +08:00
_Kerman
5a0d26a0e4 test: migrate consumers to inbox and owned-run APIs 2026-07-30 17:28:03 +08:00
kingwl
abf498b8dc fix(web): align composer context stack 2026-07-30 17:26:44 +08:00
Hypatia May
fd0fa8806f Merge remote-tracking branch 'origin/master' into codex/status-bar-token-metrics
# Conflicts:
#	packages/client/ui-conversation/README.i18n.yaml
2026-07-30 17:22:42 +08:00
Hypatia May
6d58953f30 fix(token-meter): close projected usage review gaps 2026-07-30 17:22:15 +08:00
_Kerman
80e55ecaf8 fix(ui): enlarge trajectory context icon 2026-07-30 17:21:28 +08:00
ZiyaZhang
472ba33cd9 refactor(ui-workspace): reuse status dot vocabulary 2026-07-30 02:17:14 -07:00
imccyu
4cd5745b94 Merge branch 'master' into codex/details-default-closed 2026-07-30 17:14:51 +08:00
ZiyaZhang
c153b51281 Merge remote-tracking branch 'upstream/master' into fix/session-waiting-approval 2026-07-30 02:13:11 -07:00
_Kerman
0bc495c465 Merge remote-tracking branch 'github/master' into xtr/trajectory-timeline-click-focus 2026-07-30 17:12:30 +08:00
_Kerman
411bbdf2aa feat(ui): compact trajectory role labels 2026-07-30 17:11:07 +08:00
Hypatia May
da41677049 fix(web): address transcript review follow-ups 2026-07-30 17:10:45 +08:00
Tianyi Cui
abd7d57358 Merge branch 'master' into feature/shared-cli-config-foundation 2026-07-30 17:08:42 +08:00
ZiyaZhang
61803f1a46 fix(ui-workspace): expose session status accessibly 2026-07-30 02:07:36 -07:00
_Kerman
997932ffd6 feat(ui): refine trajectory timeline interaction 2026-07-30 17:00:58 +08:00