- show help instead of crashing on `omp setup` with no args
- show runtime-discovered MCP servers in `/mcp list`
- remove deprecated Anthropic model entries from models.json
- sort models by recency in model selector
- Extracted cross-platform URL and file path opening logic into a unified `openPath` utility function.
- Removed duplicate platform-specific browser opening code from five modules (stats-cli, debug, login-dialog, command-controller, mcp-command-controller) and replaced with calls to the centralized utility.
- Simplified error handling by delegating platform detection and command execution to the reusable utility function.
- Added abort signal support to MCP server connection and tool listing operations, enabling cancellation via Escape key during testing.
- Enhanced MCP connection timeout handling with improved abort signal integration in the withTimeout function to prevent race conditions.
- Improved MCP test command UI to display '(esc to cancel)' indicator and handle cancellation gracefully.
- Updated HTTP transport session termination to include timeout mechanism preventing indefinite hangs.
- Fixed MCP test command cleanup to prevent resource leaks when operations are cancelled or aborted.
- Removed unsafe OAuth endpoint extraction from error message text
- Fixed PKCE verifier storage with typed #codeVerifier field
- Fixed refresh token fallback using access token as refresh token
- Enforced restrictive file permissions (0o700/0o600) for MCP configs
- Fixed wizard buildConfig() to respect user-chosen env var and header names
- Fixed reauth endpoint discovery for non-OAuth servers
- Stored original config on connection, resolved config only for transport
- Added runtime type validation for enabled/timeout in config loaders
- Converted all TS private keywords to ES # private fields
- Wrapped uncaught throws in /mcp add with try/catch error handling
- Replaced new Promise with Promise.withResolvers() pattern
- Sanitized TUI output with replaceTabs/truncateToWidth
- Enforced http/https URL validation in add wizard
- Fixed greedy /mcp prefix match in input controller
- Corrected config filename references in MCP guide
- Added server name validation to updateMCPServer
- Fixed timeout timer leak in stdio transport
* + /mcp
- Reloads MCP manager in runtime state (no restart needed) and syncs with mcp.json.
- Handles OAuth discovery/auth flow automatically for auth-required servers.
- Validates server names and config shape before saving.
- Persists OAuth credentials in auth storage and links them to MCP config.
- Provides immediate connection checks and clear status messages.
- Supports enable/disable, reauth, and unauth flows that are easy to get wrong by hand.
* active agent tool registry runtime reload + token support for bearer auth http based transport
* +session rebind on succesful connection
* fix(coding-agent): address /mcp check failures
---------
Co-authored-by: can1357 <me@can.ac>