Commit Graph

3449 Commits

Author SHA1 Message Date
can1357 8fe602173b chore: bump version to 13.9.14 2026-03-10 04:24:07 +01:00
can1357 fc9cd327f7 refactor: less tools for explore, less enthusiastic exploring 2026-03-10 04:23:54 +01:00
can1357 d30d55119c chore: bump version to 13.9.13 2026-03-10 04:10:50 +01:00
can1357 d139e30e1d test(coding-agent): updated interactive mode status test to use buildSessionContext
- Imported buildSessionContext from session-manager module.
- Replaced inline session context object with buildSessionContext factory call in test assertion.
2026-03-10 04:10:36 +01:00
can1357 e27afce0b2 feat: system prompt changes + better AST-grep guidance 2026-03-10 04:08:08 +01:00
can1357 0015dff67a fix(coding-agent/config): changed inspect_image.enabled default from true to false
- Updated the default value for the inspect_image.enabled setting to false to align with expected behavior.
2026-03-10 02:54:09 +01:00
maximhar b24a4fe600 Fix provider-scoped Responses history replay (#338) 2026-03-10 02:54:01 +01:00
maximhar 6394a87da2 feat(coding-agent): add inspect_image tool and image guidance flow (#295)
* feat(coding-agent): add inspect_image tool with dedicated renderer

Closes #280

* test(coding-agent): adapt block-images read test for inspect_image default

* fix(coding-agent): satisfy resolver test formatting

* test(coding-agent): stabilize inspect image tool tests

* test(coding-agent): normalize inspect image stubs
2026-03-10 02:49:32 +01:00
Miroslav Drbal [ApoC] ef33f7b4c8 fix(coding-agent): show compaction summary after manual /compact (#318)
The manual /compact command path in executeCompaction() called
rebuildChatFromMessages() but never added the compactionSummary
message to the chat. The auto-compaction path in event-controller
explicitly adds it, but the manual path was missing this step.

Capture the CompactionResult returned by session.compact() and
render the summary via addMessageToChat(), matching the behavior
of the auto-compaction flow.

Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
2026-03-10 02:48:52 +01:00
can1357 b73b9ba64d revert(coding-agent/config): restored hardcoded model policies application in registry
- Reapplied #applyHardcodedModelPolicies method to enforce gpt-5.4 context window policy across all model loading paths.
- Updated model registry to apply hardcoded policies after both initial load and dynamic discovery.
- Adjusted test expectations to reflect the restored policy enforcement behavior.
2026-03-10 02:46:42 +01:00
can1357 206839254d fix(coding-agent): clear stale optimistic user state on rebuild 2026-03-10 02:43:09 +01:00
ravshansbox c4715a918a Fix delayed display of submitted user messages (#312) 2026-03-10 02:42:46 +01:00
can1357 707622deba refactor(providers): restructured service tier validation into reusable type guard
- Extracted service tier validation into dedicated `isSpecialServiceTier()` type guard function.
- Replaced inline undefined checks with centralized validation across four provider modules.
- Consolidated service tier logic to improve maintainability and reduce duplication.
2026-03-10 02:40:13 +01:00
Sascha Buehrle b892e7a3d8 fix: gracefully disable thinking for non-reasoning models (fixes #350) (#351)
When a user switches to a model that doesn't support thinking (e.g.,
Gemini 1.5 Flash) while a thinking level is still set from a previous
model, the app crashes with an uncaught exception from
requireSupportedEffort().

Add model.reasoning guards in mapOptionsForApi() for all provider paths
(Anthropic, Google, Google Gemini CLI, Google Vertex, OpenAI) so that
thinking is gracefully disabled instead of throwing. The Bedrock path
already had this guard.
2026-03-10 02:39:55 +01:00
can1357 6eb5b3fc59 chore: bump version to 13.9.12 2026-03-09 16:15:02 +01:00
can1357 f728fcb2c3 fix(tests): type safety in signature persistence 2026-03-09 16:14:49 +01:00
can1357 68ae4b7bee feat(coding-agent): added Tavily web search provider with OAuth auth
- Added Tavily web search provider with API key authentication and credential discovery from environment or database.
- Integrated Tavily as highest-priority search provider in fallback chain with structured response mapping and error handling.
- Added Tavily OAuth login flow in CLI and auth-storage with manual API key input and validation.
- Added comprehensive test suite for Tavily provider covering registration, response mapping, error handling, and credential validation.

Fixes #313
2026-03-09 16:11:38 +01:00
can1357 46be698745 feat(coding-agent): removed Kagi summarizer integration from fetch tool
- Removed Kagi Universal Summarizer integration from fetch tool and YouTube scraper.
- Removed `fetch.useKagiSummarizer` configuration setting from settings schema.
- Simplified renderHtmlToText() and renderUrl() functions by removing Kagi summarization fallback logic.
- Fixed indentation inconsistencies in test files from tabs to spaces.
2026-03-09 15:56:04 +01:00
can1357 2ec4401bcd fix: isolate auto-compaction abort state
Fixes #275
2026-03-09 15:54:24 +01:00
can1357 d74cd0de5c fix handoff system prompt reset 2026-03-09 15:52:34 +01:00
can1357 adce19b3ae fix exa fallback availability review 2026-03-09 15:45:33 +01:00
Eric Pfister 92faa65b54 fix: web search falls through to Exa when Anthropic api_key is stored in DB (#322)
findAnthropicAuth() only checked OAuth credentials in agent.db, missing
api_key type credentials entirely. Users authenticated via stored API key
(not env var, not OAuth) got null from isAvailable(), causing the provider
chain to skip Anthropic.

Added tier 4 (api_key in agent.db) between OAuth check and env var
fallback. Refactored store lifecycle so tiers 3-4 share one instance.

Also fixed ExaProvider.isAvailable() which unconditionally returned true,
ignoring exa.enabled/exa.enableSearch settings and never checking for
credentials. It now respects both settings and requires an actual API key.
2026-03-09 15:45:19 +01:00
Miroslav Drbal [ApoC] 24c3cf232b fix(session): bypass user-prompt pipeline in handoff (#331)
* fix(session): bypass user-prompt pipeline in handoff

handoff() was calling #promptWithMessage, which gates on an API key
check before reaching this.agent.prompt(). That gate is appropriate for
user-facing prompts but has no place in an internal document-generation
call: it blocked the test spy on agent.prompt and required callers to
carry real credentials just to run the handoff path.

Fix: call #promptAgentWithIdleRetry directly (preserving the
busy-wait behaviour and #promptInFlightCount tracking) and skip the
user-prompt pipeline (API key validation, bash/python flushes, file
mention expansion, plan messages, extension events) entirely. handoff
creates a fresh session immediately after, so none of that setup
applies.

Tests now reach agent.prompt with no stub on modelRegistry.getApiKey.

* fix(patch): HASHLINE_PREFIX_RE strips comment lines with word: pattern

The regex used [0-9a-zA-Z]{1,16} for the hash ID segment, which matched
common comment patterns like '# Note:', '# TODO:', '# FIXME:'. When a
single-line replacement contained such a comment, nonEmpty===1 and
hashPrefixCount===1, triggering stripping and eating the comment prefix.

Actual hashline IDs are always exactly 2 chars from ZPMQVRWSNKTXJBYH.
Constrain the regex to that exact alphabet so no English word can match.

Also update tests that used fake IDs (AB, CD, EF) not in the real alphabet.

* Revert "fix(patch): HASHLINE_PREFIX_RE strips comment lines with word: pattern"

This reverts commit 112ad083de956d4ed8b78a7e6e9af2c061befbd5.

---------

Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
2026-03-09 15:44:21 +01:00
can1357 7136808b9a fix(ai): added idle timeout watchdog to OpenAI-family streaming transports
- Added idle-iterator utility to enforce maximum gaps between stream events, preventing indefinite hangs when providers stop sending mid-response. Applied watchdog to OpenAI completions, responses, Azure OpenAI responses, and Codex SSE streams with configurable timeout via PI_OPENAI_STREAM_IDLE_TIMEOUT_MS.
- Added separate first-event timeout for Codex websocket connections to quickly fall back to SSE when a prewarmed socket connects but never starts the response stream. Codex websocket now validates auth headers match before reusing connections.
- Fixed OAuth token refresh and usage lookups to respect request timeouts instead of waiting indefinitely during credential selection or rotation.
2026-03-09 15:40:39 +01:00
can1357 2d732bb033 fix(coding-agent): resolved symlinked paths before passing to brush
- Resolved symlinked paths before passing to brush shell to keep `pwd` output aligned with canonical Git worktree paths.
- Added `resolveShellCwd` helper that safely resolves symlinks and falls back to original path on error.
- Added test case verifying symlinked directories are canonicalized before execution.
2026-03-09 15:39:05 +01:00
can1357 aa18e3f26d feat: add hash prompt actions
Fixes #283
2026-03-09 15:38:39 +01:00
can1357 111d5f9cc6 test: add thinking signature regressions 2026-03-09 15:38:39 +01:00
can1357 99127dc95d test(model-registry): cover gpt-5.4 context metadata 2026-03-09 15:38:39 +01:00
HvC 50a9f872de fix(tui): fixed windows numpad input (#339)
* fix(tui): fixed windows numpad input

* numlock handles in kitty CSI p2

* fix(tui): preserved modified numlock keypad nav

* fix(tui): restored autocomplete keystroke triggers

---------

Co-authored-by: Brit <lol@no.com>
2026-03-09 15:14:28 +01:00
ravshansbox d17c7ce709 fix(ai): restored email-first identity matching for codex and anthropic (#344) 2026-03-09 15:08:58 +01:00
RzNmKX d861a3d52a fix(ai): Bedrock thinking signature and tool_choice errors (#333)
* fix: strip invalid thinking signatures from aborted/errored messages

When a stream is interrupted mid-response, thinking blocks may have
empty or partial cryptographic signatures. These get persisted to
session history and sent on the next API call, causing:
'Invalid signature in thinking block'

transformMessages() now detects aborted/errored assistant messages and
clears thinkingSignature fields so they are treated as unsigned thinking
(converted to text by the serializer).

Also protect truncateForPersistence from corrupting signatures — clear
them entirely instead of truncating, since a partial signature is always
invalid.

* fix: disable thinking when tool_choice forces tool use on Bedrock

Bedrock rejects requests that combine extended thinking with forced
tool_choice (any or specific tool). The Anthropic provider already had
a guard (disableThinkingIfToolChoiceForced) but the Bedrock provider
was missing the equivalent check.

Also fix thinking block serialization: when a thinking block has no
valid signature (e.g., from an aborted stream), convert it to plain
text instead of sending it as reasoningContent without a signature.
The API requires the signature field on all reasoning blocks for models
that support it.

Add thinking block diagnostics to error messages for signature/thinking
related failures to aid debugging.
2026-03-09 15:02:19 +01:00
Miroslav Drbal [ApoC] 27d951ea37 fix(patch): HASHLINE_PREFIX_RE incorrectly strips comment lines matching '# Word:' pattern (#334)
* fix(patch): HASHLINE_PREFIX_RE strips comment lines with word: pattern

The regex used [0-9a-zA-Z]{1,16} for the hash ID segment, which matched
common comment patterns like '# Note:', '# TODO:', '# FIXME:'. When a
single-line replacement contained such a comment, nonEmpty===1 and
hashPrefixCount===1, triggering stripping and eating the comment prefix.

Actual hashline IDs are always exactly 2 chars from ZPMQVRWSNKTXJBYH.
Constrain the regex to that exact alphabet so no English word can match.

Also update tests that used fake IDs (AB, CD, EF) not in the real alphabet.

* test(patch): add regression tests for comment line prefix stripping bug

Three new tests in hashlineParseContent describe block:
- hashlineParseText preserves '# Word:' comment lines (unit)
- full pipeline: replacing '# Note:' comment line preserves prefix
- full pipeline: replacing '# TODO:' comment line preserves prefix

These would have caught the HASHLINE_PREFIX_RE bug where [0-9a-zA-Z]{1,16}
matched comment words, causing stripNewLinePrefixes to eat the '# Note:'
prefix when a single comment line was the sole replacement entry.

---------

Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
2026-03-09 14:59:52 +01:00
Miroslav Drbal [ApoC] e6d5a58ed1 fix(model-registry): remove hardcoded gpt-5.4 context window override (#335)
#applyHardcodedModelPolicies forced contextWindow=1_000_000 on any model
with id 'gpt-5.4' regardless of provider. This was wrong in every case:

- github-copilot/gpt-5.4: inflated from bundled 400K (and overwrote the
  ~274K that Copilot's live /models discovery returns via capabilities.limits)
- openai/gpt-5.4: deflated from bundled 1_050_000 to 1_000_000
- openai-codex, opencode, opencode-zen: same downgrade from 1_050_000

The method was called twice — after static load and after runtime discovery —
so it reliably clobbered the correct provider-specific value both times.

No documented rationale exists for the override. The bundled models.json
values are already correct. Remove the method and its two call sites.

fixes #332

Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
2026-03-09 14:59:06 +01:00
ravshansbox 731e46aa8e fix: preserved stale PR indicator during refresh (#346) 2026-03-09 14:57:15 +01:00
can1357 2b3d85392d chore: configured bun runtime settings in bunfig.toml
- Disabled telemetry collection by default.
- Added run configuration to use bun runtime.
- Maintained existing install and loader settings.
2026-03-09 00:17:52 +01:00
can1357 bd23578f55 chore: bump version to 13.9.11 2026-03-08 16:36:37 +01:00
can1357 1598210369 test: seed anthropic auth in handoff handoff tests 2026-03-08 16:36:16 +01:00
can1357 0462d9b88c chore(deps): removed redundant tsconfig.build.json files across packages
- Deleted tsconfig.build.json and tsconfig.check.json files that only extended the base tsconfig.json without adding configuration.
- Updated check:ts script to remove the unused packages/stats/tsconfig.client.json reference.
2026-03-08 16:31:57 +01:00
can1357 710cd638d6 chore: bump version to 13.9.10 2026-03-08 16:24:59 +01:00
can1357 6635129b7c test(coding-agent): updated 8 mock functions to accept unused parameters
- Updated 8 test mock functions to accept unused parameters for API compatibility.
2026-03-08 16:24:44 +01:00
can1357 486e585f39 refactor(coding-agent): migrated fetch mocks to hookFetch utility with resource cleanup
- Replaced vi.spyOn fetch mocking pattern with hookFetch utility across 5 test files.
- Migrated fetch mocks to use resource management with 'using' keyword for automatic cleanup.
- Removed @ts-expect-error comments related to fetch.preconnect type issues.
- Updated ts-hook-fetch rule documentation with expanded patterns and clearer lifecycle guidance.
2026-03-08 16:22:18 +01:00
can1357 9d4ddef7b6 fix(ai): corrected credential matching to compare by type and identity key
- Fixed API key credential matching to compare by type and identity key instead of object identity.
- Fixed credential deduplication to preserve existing credentials when replacement key matches.
- Fixed auth schema version preservation by conditionally writing schema version only on initial setup.
- Added test coverage for API key reuse, email deduplication, and schema version preservation.
2026-03-08 16:21:09 +01:00
can1357 005401e82a refactor: extracted fetch mocking into reusable hookFetch utility
- Extracted fetch mocking logic into reusable `hookFetch()` utility function with middleware-style handler pattern.
- Replaced manual `globalThis.fetch` assignment and restoration across 10 test files with `hookFetch()` calls using `using` statement for automatic cleanup.
- Implemented Disposable pattern with Symbol.dispose for fetch hook resource management, eliminating try-finally blocks.
- Exported `hookFetch` from utils public API to enable consistent fetch mocking across packages.
2026-03-08 16:16:54 +01:00
can1357 e1d8ed2c10 feat(ai): added identity key deduplication to auth credentials storage
- Added `identity_key` column to auth credentials storage for improved credential deduplication.
- Added schema versioning system to auth credentials database for safer migrations.
- Changed credential deduplication logic to use single identity key instead of multiple identifiers for better performance.
- Fixed credential deduplication to correctly handle OAuth accounts with matching emails but different account IDs.
- Implemented automatic backfilling of identity keys during database schema migrations.
- Added 5 test cases for schema migration and identity key backfilling scenarios.
2026-03-08 16:11:18 +01:00
can1357 59ae4ff707 test(coding-agent): updated mock fetch to filter endpoints and ignore concurrent discovery
- Updated mock fetch handler to filter test endpoints and ignore concurrent provider discovery requests.
2026-03-08 15:59:06 +01:00
can1357 57c89cf503 refactor(auth-storage): restructured credential matching to use accountId
- Extracted OAuth identifier logic into public functions extractOAuthCredentialIdentifiers and extractOAuthTokenIdentifiers.
- Replaced single credentialIdentity string with multi-identifier resolveCredentialIdentifiers returning string[] for flexible matching.
- Changed credential deduplication from email-based to accountId-based matching in replaceAuthCredentialsForProvider.
- Updated auth-storage tests to verify accountId-prioritized deduplication behavior across soft-disable and hard-delete scenarios.
- Added documentation comments in coding-agent modules explaining partial JSON preservation for streaming tool previews.
- Documented streaming tool preview requirements and render paths in AGENTS.md.
2026-03-08 15:58:52 +01:00
can1357 19feec9592 feat(bash): added env parameter to bash tool for safe variable passing
- Added `env` parameter to bash tool for safe environment variable passing without shell re-parsing.
- Added support for rendering partial environment variable assignments in command preview during streaming.
- Updated bash tool prompt to recommend `env` parameter for multiline, quote-heavy, and untrusted values.
- Refactored tool execution component to conditionally merge partial JSON arguments during streaming.
- Added helper functions for environment variable normalization, escaping, and formatting.
2026-03-08 15:53:33 +01:00
can1357 15547f73c6 chore: bump version to 13.9.8 2026-03-08 08:16:18 +01:00
can1357 628e68e6ae fix(ai): corrected WebSocket fallback to safely replay buffered output over SSE
- Fixed WebSocket stream fallback logic to safely replay buffered output over SSE when WebSocket fails after partial content has been streamed.
- Added tracking flag to prevent unsafe replays of tool calls and terminal events during fallback transitions.
- Enhanced error recovery to reset output state when replaying buffered content over SSE connection.
2026-03-08 07:51:19 +01:00
can1357 85621f37bf feat(coding-agent/web): added docs.rs scraper with rustdoc JSON parsing and caching
- Added docs.rs scraper for extracting Rust crate documentation from rustdoc JSON, supporting modules, functions, structs, traits, enums, and other Rust items with intelligent caching.
- Implemented rustdoc JSON parsing with type rendering for complex Rust types including generics, lifetimes, trait bounds, and qualified paths.
- Added caching layer for rustdoc JSON with date-based versioning for 'latest' releases to reduce repeated fetches.
2026-03-08 07:50:16 +01:00