Commit Graph

253 Commits

Author SHA1 Message Date
can1357 3a92c920fd Merge PR #5182: fix(coding-agent): load web search fallbacks lazily (@wolfiesch) 2026-07-14 18:39:53 +02:00
Vu Anh Nguyen 570f8af57c fix(coding-agent): support GPT-5.6 Codex web search 2026-07-14 17:51:33 +07:00
can1357 d0f90f35ae refactor(coding-agent): removed unreliable web search providers
- Removed unreliable Bing and Yahoo HTML-scraping search providers.
- Deleted `src/web/search/providers/bing.ts` and `src/web/search/providers/yahoo.ts` implementation files.
- Updated `provider.ts`, `types.ts`, and `public.ts` to prune provider registration and configuration.
- Adjusted `web-search-public.test.ts` to exclude removed engines from test coverage.
2026-07-13 00:34:27 +02:00
can1357 dabe233c62 feat(coding-agent/web): improved perplexity results 2026-07-12 13:31:08 +02:00
Wolfgang Schoenberger 95add0187e fix(coding-agent): load web search fallbacks lazily 2026-07-11 15:26:37 -07:00
roboomp d7a71642c8 fix(coding-agent): guarded browser header generation
Lazy-initialized the header-generator dependency so compiled runtimes without its fs-loaded data_files fall back to the bundled Chrome header profile instead of failing extension imports.

Added a regression test that hides header-generator data_files in a fresh Bun subprocess and verifies fallback headers are returned.

Fixes #5178
2026-07-11 11:41:45 +00:00
can1357 ea632a518b feat(coding-agent): expanded search capabilities and scraping reliability
- Added six new search providers (Bing, Yahoo, Ecosia, Startpage, Mojeek, and Public) to expand coverage and parallel search capabilities.
- Implemented a unified `browserFetch` utility with headless-browser fallback and randomized Chrome profiles to improve scrape reliability.
- Integrated automated bot-defense mechanisms including CAPTCHA detection, ALTCHA proof-of-work, and homepage-token flows.
- Fixed hanging search CLI commands by ensuring proper closure of AuthStorage connections.
2026-07-11 07:33:22 +02:00
can1357 376084c19a feat(coding-agent/web): ensured proper cleanup of authentication storage
- Added a mandatory check to ensure authentication storage is successfully initialized before executing searches.
- Implemented a finally block to close the discovered authentication storage after the search execution completes.
2026-07-11 07:33:21 +02:00
can1357 4c167eaa6d feat(coding-agent): integrated google search with shared browser utilities
- Implemented a new Google search provider using headless browser scraping and HTML parsing.
- Integrated automated bot-challenge detection and error reporting for search operations.
- Consolidated navigation headers into a shared utility and updated existing DuckDuckGo provider to use it.
- Added comprehensive test suites for Google search parsing, deduplication, and browser operation diagnostics.
2026-07-11 07:33:19 +02:00
can1357 00076fd9b3 test(coding-agent): covered docs.rs gunzip cap via extracted seam
- Extracted gunzipRustdocJson() with overridable maxOutputLength so the cap contract is testable with real gzip payloads instead of the banned mock.module().
2026-07-05 13:31:22 +02:00
can1357 a7665077bc Merge PR #4278: fix(web): cap docs.rs gunzip decompressed size at 256 MB (@metaphorics) 2026-07-05 13:25:26 +02:00
can1357 7101527e60 fix(providers): skip borrowed xai env after oauth fallback 2026-07-05 13:03:06 +02:00
can1357 942ca7ce06 Merge PR #4539: fix(providers): prefer xAI OAuth for web search (@roboomp) 2026-07-05 13:03:06 +02:00
roboomp 4654125023 fix(providers): avoided borrowed xai env for oauth web search
Tightened xAI web_search's xai-oauth preference so lower-priority xai-oauth api_key or fallback credentials do not get shadowed by the shared XAI_API_KEY fallback.

Added regression coverage for the stored xai-oauth API-key plus shared XAI_API_KEY case, preserving explicit xai runtime credential routing.

Refs #4536
2026-07-04 17:40:35 +00:00
roboomp b59a4050d2 fix(providers): gated xai oauth preference on dedicated credential
Restricted the xai-oauth preference in web_search to dedicated credentials (hasNonEnvCredential("xai-oauth") or XAI_OAUTH_TOKEN) so an XAI_API_KEY-only environment no longer routes an explicit xai runtime/config credential through the xai-oauth resolver.

Added regression tests covering the shared-env case and the xai-only availability check.

Refs #4536
2026-07-04 17:30:37 +00:00
roboomp fd9bf38ebd fix(providers): preferred xai oauth for web search
Fixed xAI web_search credential resolution to try xai-oauth before xai API-key auth.

Added regression coverage for xai-oauth-only availability and precedence.

Fixes #4536
2026-07-04 17:22:51 +00:00
roboomp 1e6782af13 fix(providers): removed xai web search parameters
- Stopped adding Responses Agent Tools-incompatible search_parameters to xAI web_search requests.
- Kept limit and numSearchResults enforcement as a local cap over parsed sources and citations.
- Added regression coverage for limit, numSearchResults, recency, and local cap request shapes.

Fixes #4537
2026-07-04 17:19:29 +00:00
roboomp 289ea08a39 fix(providers): made gemini search model configurable
Added providers.webSearchGeminiModel and GEMINI_SEARCH_MODEL so Gemini web_search requests use a selected grounding model while keeping gemini-2.5-flash as the fallback.

Covered OAuth, Developer API, and missing modelVersion fallback paths in Gemini web search tests.

Fixes #4312
2026-07-02 12:44:55 +00:00
metaphorics 42543428cc fix(web): cap docs.rs gunzip decompressed size at 256 MB
docs-rs.ts:handleDocsRs downloads up to 50 MB of compressed rustdoc JSON (MAX_BYTES) and then decompresses it with gunzipSync without a size bound, so a zip bomb can expand 10:1+ and OOM/crash the process. Pass { maxOutputLength: 256 * 1024 * 1024 } to gunzipSync at line 402 to cap decompressed output; if the limit is exceeded it throws and falls through to the existing catch (signal check / return null), preserving the failure contract. Coding-agent typecheck (bun run check:types) and Biome check on the changed file pass; no dedicated test exists for this path.

Closes #4249
2026-07-02 17:30:22 +09:00
can1357 52003878b5 Merge PR #3865: fix(web-search): clarify DuckDuckGo bot detection failures (@roboomp) 2026-07-01 21:47:55 +02:00
can1357 09061ed801 feat(coding-agent/web): aligned duckduckgo search requests with native browser behavior
- Updated the default browser User-Agent string to emulate a modern version of Chrome.
- Added typical browser headers to the outgoing fetch request, including Sec-Ch-Ua, Sec-Fetch flags, and Referer.
- Added a blank "b" parameter to the form body to match native DuckDuckGo HTML search behavior.
2026-06-30 07:02:12 +02:00
roboomp cb547cf322 fix(web-search): clarified duckduckgo bot detection
Formatted fallback-chain provider errors through the shared formatter so Codex auth failures and DuckDuckGo bot-detection failures give actionable guidance.

Documented DuckDuckGo as a best-effort fallback for datacenter/shared-egress IPs and covered the provider guidance in regression tests.

Fixes #3863
2026-06-30 04:43:08 +00:00
can1357 6e166274cb fix(web-search,mcp): reused gemini oauth helper and formatted npx shim 2026-06-29 16:56:43 +02:00
can1357 6f8f76be43 Keep DuckDuckGo result cap unchanged 2026-06-29 16:45:47 +02:00
can1357 579b4f3f10 Merge PR #3800: fix(web-search): scrape DuckDuckGo HTML frontend instead of Instant Answer API (@roboomp) 2026-06-29 16:45:46 +02:00
can1357 6259792bd7 Merge PR #3811: fix(providers): support Gemini API key web search (@roboomp) 2026-06-29 16:45:46 +02:00
roboomp 530113eb71 fix(providers): supported gemini api key search
Enabled the Gemini web search provider to use standard Google developer API credentials when Cloud Code Assist OAuth is absent.

Added developer API request coverage for native Google Search grounding and preserved existing OAuth request serialization.

Fixes #3810
2026-06-29 13:51:42 +00:00
roboomp 75db042744 style: bun run fix 2026-06-29 09:49:49 +00:00
roboomp 755a61de07 fix(web-search): scrape DuckDuckGo HTML frontend instead of Instant Answer API
The DuckDuckGo provider hit api.duckduckgo.com (the Instant Answer API),
which only serves Wikipedia / Wolfram-Alpha-style topics — empty
AbstractText / Results / RelatedTopics for the vast majority of agent
queries. The orchestrator then rejected the empty response and surfaced
'DuckDuckGo returned no renderable search content', leaving users with
no working free fallback.

Switch the provider to POST html.duckduckgo.com/html/ (the no-JS HTML
frontend) with a browser User-Agent, parse the result blocks (unwrapping
//duckduckgo.com/l/?uddg=… redirect URLs), and map recency to the df
form field (d/w/m/y). When DuckDuckGo serves the bot-detection modal
(HTTP 200/202 with anomaly-modal body) we surface a clear
SearchProviderError so the orchestrator can fall through to the next
provider with cause attached.

Fixes #3799
2026-06-29 09:48:46 +00:00
roboomp ba6b64bf89 fix(search): honored explicit --provider auto override
Distinguished an absent provider (use configured preferred provider) from an explicit `--provider auto` (one-shot bypass that still respects exclusions) in executeSearch.

Fixes #3793
2026-06-29 09:08:37 +00:00
roboomp f228c56b28 fix(web-search): retried empty tavily recency results
Retry Tavily recency-filtered searches once without time_range when the filtered HTTP 200 response contains no renderable content.

Fixes #3633
2026-06-27 05:58:58 +00:00
roboomp c5555bec28 fix(providers): initialized zai mcp search session
Initialized the Z.AI Streamable HTTP MCP session before calling web_search_prime and preserved the returned session id on subsequent requests.

Added regression coverage for the authenticated MCP request sequence.

Fixes #3619
2026-06-27 02:20:39 +00:00
can1357 577d2a8eb8 style: biome format/organize-imports across integrated PRs 2026-06-27 02:06:38 +02:00
can1357 2d136ccf22 Fix web search provider result controls 2026-06-27 02:04:51 +02:00
zekdevs 4939bdd591 fix tinyfish results fetch 2026-06-26 10:57:17 -06:00
zekdevs 2023b45d2c add cap to xai sources 2026-06-26 10:11:31 -06:00
zekdevs 3106f76d11 cap xai response locally as upstream api has no limit support 2026-06-26 09:54:32 -06:00
zekdevs 1b530c6a2d move to new xai api and fix tinyfish review comment 2026-06-26 09:23:24 -06:00
zekdevs 64e4f00e3d add xai, ddg, firecrawl, and tinyfish as web_search providers 2026-06-26 08:41:20 -06:00
roboomp 921904b3de fix(web-search): cancelled queued exa waits
Raced queued Exa throttle waits against the caller abort signal so requests cancelled behind an earlier throttle wait reject immediately without breaking the serialized throttle chain.

Added regression coverage for cancelling a third Exa request queued behind another delayed request.

Fixes #3271
2026-06-22 17:59:17 +00:00
roboomp 022010ad97 fix(web-search): aborted exa throttle waits
Made Exa request pacing observe cancellation during the configured delay instead of waiting for the full delay before checking the signal.

Added regression coverage for a queued Exa request cancelled while throttled.

Fixes #3271
2026-06-22 17:54:15 +00:00
roboomp 9e32c19793 fix(web-search): paced exa search requests
Added configurable Exa search request pacing via exa.searchDelayMs so repeated web_search calls no longer burst directly into Exa rate limits.

Covered the provider contract with a focused Exa test and recorded the back-to-back request repro.

Fixes #3271
2026-06-22 17:47:28 +00:00
roboomp 5258c5d6e3 fix(coding-agent): stop perplexity auto-chain from hijacking openrouter auth
PerplexityProvider.isAvailable() accepted authStorage.hasAuth("openrouter")
as a valid credential, so any user with an OpenRouter key configured (for
LLM access) had every webSearch: auto request silently routed through
OpenRouter's perplexity/sonar-pro endpoint. Since Perplexity sits first in
SEARCH_PROVIDER_ORDER, downstream providers like Gemini were never reached
and users saw unexpected charges on their OpenRouter billing.

Auto-chain admission now requires a direct Perplexity credential
(PERPLEXITY_COOKIES, Perplexity OAuth, or PERPLEXITY_API_KEY).
isExplicitlyAvailable still returns true, so users who want the
OpenRouter-backed perplexity/sonar-pro path can opt in by setting
webSearch: perplexity explicitly — the existing OpenRouter fallback in
getApiConfigs handles that case unchanged.

Fixes #3251
2026-06-22 10:42:37 +00:00
can1357 92bae8ab91 refactor(coding-agent): consolidated parallel API logic
- Centralized Parallel API utilities and parsing logic into a single module.
- Exported constants and helper functions from `parallel.ts` to replace duplicated definitions in the search provider.
- Updated the search provider to leverage the unified `parseParallelSearchPayload` function with metadata parsing toggled off.
2026-06-22 07:20:35 +02:00
can1357 8351536641 refactor(coding-agent): consolidated and prioritize perplexity authentication
- Moved authentication logic to `perplexity-auth.ts` to share logic between search providers and CLI commands.
- Updated authentication priority to prefer browser cookies over OAuth tokens during search operations.
- Modified the `token` CLI command to display active OAuth tokens when both an OAuth token and an API key are configured.
- Added comprehensive unit tests in `perplexity.test.ts` to verify authentication priority and precedence.
2026-06-19 17:44:59 +02:00
can1357 256587bbbe ux(coding-agent): standardized elision indicators in scraper output
- Replaced inconsistent list truncation messages with a standardized `[...N items elided...]` format across all scrapers.
- Updated documentation reference to use consistent variable naming convention.
2026-06-19 04:51:39 +02:00
can1357 1df1349b99 ux: standardized elision markers
- Updated various truncation and overflow messages across `pi-shell` and `coding-agent` to use the consistent `[...N units elided...]` format.
- Improved clarity of elided output by explicitly stating the count and type of omitted information.
2026-06-19 04:42:06 +02:00
can1357 38d1d3a2f5 feat(coding-agent): vendor relevant parts of markit 2026-06-18 19:11:22 +02:00
can1357 291b3c74c2 feat: enhanced model reasoning, schema normalization, and loop guarding
- Integrated comprehensive loop guard support for DeepSeek and assistant prose patterns, including configurable stream checks.
- Implemented Moonshot Flavored JSON Schema (MFJS) normalization for improved tool compatibility and enum type inference.
- Added support for Ollama reasoning effort backfilling and Grok-specific service tier cost tracking across providers.
- Expanded model catalog with new entries and unified compatibility logic for improved OpenRouter API integration.
2026-06-18 04:51:43 +02:00
can1357 92855e3daa refactor(coding-agent/web): derived search provider order and labels from common options
- Derived the `SEARCH_PROVIDER_ORDER`, `SEARCH_PROVIDER_PREFERENCES`, and `SEARCH_PROVIDER_LABELS` metadata dynamically from a single `SEARCH_PROVIDER_OPTIONS` source of truth.
- Reprioritized the default search provider sequence, shifting higher-order choices like Perplexity, Gemini, and Anthropic ahead of Tavily and Brave.
- Updated documentation to reflect the new search provider evaluation order.
2026-06-18 00:59:55 +02:00