Commit Graph

279 Commits

Author SHA1 Message Date
can1357 af2e2bf05c Merge PR #7121: fix(search): paginate DuckDuckGo HTML results (@roboomp) 2026-07-31 19:14:47 +02:00
smoldrago 6c367fd0bc fix(web-search): surface xai-oauth support in Grok search provider label 2026-07-31 13:20:03 +02:00
roboomp a07d782058 fix(search): paginated duckduckgo results
Followed DuckDuckGo's returned continuation form until the requested result limit is satisfied, preserving deduplication across pages and the existing search deadline.

Added regression coverage for continuation field submission and 20-result collection.

Fixes #7116
2026-07-30 22:09:44 +00:00
can1357 55ac64679e Merge PR #6652: feat(ai): add Exa API key login (@will-bogusz) 2026-07-30 01:26:50 +02:00
roboomp e5ea31b22c fix(coding-agent): require web_search_call in codex search
GPT-5.6 Responses-Lite models receive tool_choice "auto" (the forced
hosted choice is invalid under the lite shape, #5771/#5772), so the model
may answer without invoking the hosted web_search tool. The codex search
parser accepted any non-empty answer, returning a stale completion with
zero sources as a successful search.

callCodexSearch now tracks response.web_search_call.* events (and
web_search_call output items) and throws CodexNoWebSearchError when none
occurred. The candidate chain treats that error as retryable, advancing
default lite models to a non-lite model that forces web_search, and
surfaces a clear failure when the model was explicitly configured.

Fixes #6988

(cherry picked from commit a276cd0b3df1d0d041faf0a63fabcbb884e36a91)
2026-07-29 23:08:54 +02:00
usr_bin_roygbiv f32dd6eff4 Fix wrapped Markdown list and output block layout 2026-07-28 07:06:31 +00:00
Will 7e00fa5a76 docs: clarify Exa authentication options 2026-07-25 19:14:48 -04:00
Will 19d7d14a94 feat(ai): add Exa API key login 2026-07-25 19:08:02 -04:00
can1357 5acdefc7b3 feat(coding-agent/web): introduced structured web-search query parsing module
- Implemented a structured web-search query parsing module supporting directives, tokenization, date parsing, and syntax serialization.
- Updated search providers to map query directives and date bounds to native provider parameters and filters.
- Added lenient result constraint post-filtering and configuration settings for enhanced engine routing.
- Added comprehensive unit and integration tests covering query parsing, constraint filtering, and provider-specific request mapping.
2026-07-24 16:05:14 +02:00
can1357 5b3275c7ae feat(coding-agent): introduced ordered provider priority lists for search and images
- Replaced single-provider preferences with ordered priority lists for web search and image generation.
- Added a `MultiSelectSubmenu` component supporting toggle and reordering interactions in settings.
- Implemented migration logic to convert legacy single-provider preferences into ordered priority lists.
- Updated setup wizard scenes, image generation fallback logic, and search provider chains to use priority lists.
2026-07-23 20:44:50 +02:00
can1357 878b8fd556 Merge PR #6029: feat(omp): configure web search provider order (@riverpilot)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/selector-controller.ts
2026-07-23 20:18:08 +02:00
can1357 344714aea7 Merge PR #4890: feat(coding-agent): use Grok 4.5 for xAI web search (@metaphorics)
# Conflicts:
#	packages/coding-agent/src/web/search/providers/xai.ts
2026-07-23 20:16:05 +02:00
CoderTCY d115ac66c1 Fix by review 2026-07-23 10:23:06 +08:00
CoderTCY 1071984385 Fixes 2026-07-23 09:54:35 +08:00
CoderTCY 3ada287cb0 feat(firecrawl): support keyless mode when no API key is configured
When FIRECRAWL_API_KEY is not set, fall back to Firecrawl keyless mode
(omit Authorization header). Auto-chain still requires a credential via
isAvailable; explicit webSearch: firecrawl works keyless via
isExplicitlyAvailable returning true.

Closes https://github.com/can1357/oh-my-pi/issues/4332
2026-07-23 09:54:35 +08:00
Alexander Kirilin 735be36df6 feat(omp): configure web search provider order 2026-07-18 20:12:26 -04:00
roboomp 2d27bfdd66 fix(search): allowed command-backed codex keys
- Exposed command-backed provider-key detection from ModelRegistry.
- Allowed configured Codex command keys to outrank stored OAuth while preserving the custom-endpoint OAuth guard.
- Added resolver-precedence regression coverage.

Fixes #6001
2026-07-18 15:34:03 +00:00
roboomp feac38298f fix(search): guarded codex origin from resolver storage
- Validated the openai-codex credential origin against the registry storage that supplies the bearer, closing the OAuth-leak path when authStorage and modelRegistry diverge.
- Added a regression test covering the mismatched storage case.

Fixes #6001
2026-07-18 15:26:37 +00:00
roboomp 9c2682cea2 fix(search): honored configured codex transport
- Routed Codex web search through configured Responses base URLs, API keys, and headers while preserving the official OAuth backend.
- Refused OAuth leakage to custom endpoints and stopped explicitly selected providers from silently falling back.
- Added transport, safety, and fail-closed regression coverage.

Fixes #6001
2026-07-18 15:21:09 +00:00
roboomp acff852022 fix(web-search): scoped kimi search to kimi code credentials
The Kimi web-search adapter posts to the Kimi Code endpoint
(api.kimi.com/coding/v1/search) but resolved and advertised Moonshot
Open Platform credentials (moonshot provider, MOONSHOT_API_KEY,
api.moonshot.ai). Those are a different credential system, so a valid
Open Platform key was rejected with 401 and the preferred provider
silently fell back to another engine.

resolveKey() and isAvailable() now use kimi-code credentials only
(explicit MOONSHOT_SEARCH_API_KEY / KIMI_SEARCH_API_KEY overrides or a
stored kimi-code login), and the missing-credential error and provider
metadata name the Kimi Code requirement.

Fixes #5762
2026-07-16 22:39:01 +00:00
can1357 6356873927 fix(web-search): reuse supplied registry auth 2026-07-16 03:31:58 +02:00
roboomp 91b67c7b0f fix(web-search): honored configured xai transport
- Routed native xAI Responses search through configured provider base URLs and headers.
- Kept endpoint credentials coupled and rejected official OAuth tokens for custom endpoints.
- Added proxy routing and credential-leak regression coverage.

Fixes #5599
2026-07-15 17:44:30 +00:00
can1357 88ab942d9f Merge PR #5478: fix(web-search): stop Perplexity OAuth token leaking to the API-key endpoint (@roboomp) 2026-07-14 22:58:48 +02:00
roboomp c97449c51d fix(web-search): stop perplexity oauth token leaking to api-key endpoint
The consumer ask endpoint (/rest/sse/perplexity_ask) intermittently closes
its socket before responding. getApiConfigs emitted the OAuth session JWT
(returned by getApiKey while OAuth is the active origin) as a direct
api.perplexity.ai api-key config, so a transient transport failure on the
ask endpoint fell through and sent the session token as a Bearer to the
direct API, whose 401 masked the real error.

- Suppress the direct api-key config when getCredentialOrigin reports the
  active perplexity credential as oauth.
- Give the OAuth ask request one transport-only retry; HTTP responses
  (including 401/429) are final and never retried.
- Add regression coverage for both legs.

Fixes #5315
2026-07-14 18:28:43 +00:00
can1357 3a92c920fd Merge PR #5182: fix(coding-agent): load web search fallbacks lazily (@wolfiesch) 2026-07-14 18:39:53 +02:00
Vu Anh Nguyen 570f8af57c fix(coding-agent): support GPT-5.6 Codex web search 2026-07-14 17:51:33 +07:00
can1357 d0f90f35ae refactor(coding-agent): removed unreliable web search providers
- Removed unreliable Bing and Yahoo HTML-scraping search providers.
- Deleted `src/web/search/providers/bing.ts` and `src/web/search/providers/yahoo.ts` implementation files.
- Updated `provider.ts`, `types.ts`, and `public.ts` to prune provider registration and configuration.
- Adjusted `web-search-public.test.ts` to exclude removed engines from test coverage.
2026-07-13 00:34:27 +02:00
can1357 dabe233c62 feat(coding-agent/web): improved perplexity results 2026-07-12 13:31:08 +02:00
Wolfgang Schoenberger 95add0187e fix(coding-agent): load web search fallbacks lazily 2026-07-11 15:26:37 -07:00
roboomp d7a71642c8 fix(coding-agent): guarded browser header generation
Lazy-initialized the header-generator dependency so compiled runtimes without its fs-loaded data_files fall back to the bundled Chrome header profile instead of failing extension imports.

Added a regression test that hides header-generator data_files in a fresh Bun subprocess and verifies fallback headers are returned.

Fixes #5178
2026-07-11 11:41:45 +00:00
can1357 ea632a518b feat(coding-agent): expanded search capabilities and scraping reliability
- Added six new search providers (Bing, Yahoo, Ecosia, Startpage, Mojeek, and Public) to expand coverage and parallel search capabilities.
- Implemented a unified `browserFetch` utility with headless-browser fallback and randomized Chrome profiles to improve scrape reliability.
- Integrated automated bot-defense mechanisms including CAPTCHA detection, ALTCHA proof-of-work, and homepage-token flows.
- Fixed hanging search CLI commands by ensuring proper closure of AuthStorage connections.
2026-07-11 07:33:22 +02:00
can1357 376084c19a feat(coding-agent/web): ensured proper cleanup of authentication storage
- Added a mandatory check to ensure authentication storage is successfully initialized before executing searches.
- Implemented a finally block to close the discovered authentication storage after the search execution completes.
2026-07-11 07:33:21 +02:00
can1357 4c167eaa6d feat(coding-agent): integrated google search with shared browser utilities
- Implemented a new Google search provider using headless browser scraping and HTML parsing.
- Integrated automated bot-challenge detection and error reporting for search operations.
- Consolidated navigation headers into a shared utility and updated existing DuckDuckGo provider to use it.
- Added comprehensive test suites for Google search parsing, deduplication, and browser operation diagnostics.
2026-07-11 07:33:19 +02:00
robomp-bot ea5503bc53 fix(coding-agent): pin xAI web search to low reasoning effort
Address PR #4890 review: grok-4.5 defaults reasoning.effort to high, but xAI documents low as the tier for latency-sensitive tool calling. buildRequestBody now sets reasoning.effort=low so web search avoids paying for high-reasoning tokens and is less likely to hit the 60s hard timeout. Update the request-body regression tests to defend the new shape.
2026-07-09 15:46:53 +09:00
robomp-bot 998b6be655 feat(coding-agent): use Grok 4.5 for xAI web search
Switch xAI web-search requests to the flagship Grok 4.5 model and cover the request body contract.
2026-07-09 14:26:49 +09:00
can1357 00076fd9b3 test(coding-agent): covered docs.rs gunzip cap via extracted seam
- Extracted gunzipRustdocJson() with overridable maxOutputLength so the cap contract is testable with real gzip payloads instead of the banned mock.module().
2026-07-05 13:31:22 +02:00
can1357 a7665077bc Merge PR #4278: fix(web): cap docs.rs gunzip decompressed size at 256 MB (@metaphorics) 2026-07-05 13:25:26 +02:00
can1357 7101527e60 fix(providers): skip borrowed xai env after oauth fallback 2026-07-05 13:03:06 +02:00
can1357 942ca7ce06 Merge PR #4539: fix(providers): prefer xAI OAuth for web search (@roboomp) 2026-07-05 13:03:06 +02:00
roboomp 4654125023 fix(providers): avoided borrowed xai env for oauth web search
Tightened xAI web_search's xai-oauth preference so lower-priority xai-oauth api_key or fallback credentials do not get shadowed by the shared XAI_API_KEY fallback.

Added regression coverage for the stored xai-oauth API-key plus shared XAI_API_KEY case, preserving explicit xai runtime credential routing.

Refs #4536
2026-07-04 17:40:35 +00:00
roboomp b59a4050d2 fix(providers): gated xai oauth preference on dedicated credential
Restricted the xai-oauth preference in web_search to dedicated credentials (hasNonEnvCredential("xai-oauth") or XAI_OAUTH_TOKEN) so an XAI_API_KEY-only environment no longer routes an explicit xai runtime/config credential through the xai-oauth resolver.

Added regression tests covering the shared-env case and the xai-only availability check.

Refs #4536
2026-07-04 17:30:37 +00:00
roboomp fd9bf38ebd fix(providers): preferred xai oauth for web search
Fixed xAI web_search credential resolution to try xai-oauth before xai API-key auth.

Added regression coverage for xai-oauth-only availability and precedence.

Fixes #4536
2026-07-04 17:22:51 +00:00
roboomp 1e6782af13 fix(providers): removed xai web search parameters
- Stopped adding Responses Agent Tools-incompatible search_parameters to xAI web_search requests.
- Kept limit and numSearchResults enforcement as a local cap over parsed sources and citations.
- Added regression coverage for limit, numSearchResults, recency, and local cap request shapes.

Fixes #4537
2026-07-04 17:19:29 +00:00
roboomp 289ea08a39 fix(providers): made gemini search model configurable
Added providers.webSearchGeminiModel and GEMINI_SEARCH_MODEL so Gemini web_search requests use a selected grounding model while keeping gemini-2.5-flash as the fallback.

Covered OAuth, Developer API, and missing modelVersion fallback paths in Gemini web search tests.

Fixes #4312
2026-07-02 12:44:55 +00:00
metaphorics 42543428cc fix(web): cap docs.rs gunzip decompressed size at 256 MB
docs-rs.ts:handleDocsRs downloads up to 50 MB of compressed rustdoc JSON (MAX_BYTES) and then decompresses it with gunzipSync without a size bound, so a zip bomb can expand 10:1+ and OOM/crash the process. Pass { maxOutputLength: 256 * 1024 * 1024 } to gunzipSync at line 402 to cap decompressed output; if the limit is exceeded it throws and falls through to the existing catch (signal check / return null), preserving the failure contract. Coding-agent typecheck (bun run check:types) and Biome check on the changed file pass; no dedicated test exists for this path.

Closes #4249
2026-07-02 17:30:22 +09:00
can1357 52003878b5 Merge PR #3865: fix(web-search): clarify DuckDuckGo bot detection failures (@roboomp) 2026-07-01 21:47:55 +02:00
can1357 09061ed801 feat(coding-agent/web): aligned duckduckgo search requests with native browser behavior
- Updated the default browser User-Agent string to emulate a modern version of Chrome.
- Added typical browser headers to the outgoing fetch request, including Sec-Ch-Ua, Sec-Fetch flags, and Referer.
- Added a blank "b" parameter to the form body to match native DuckDuckGo HTML search behavior.
2026-06-30 07:02:12 +02:00
roboomp cb547cf322 fix(web-search): clarified duckduckgo bot detection
Formatted fallback-chain provider errors through the shared formatter so Codex auth failures and DuckDuckGo bot-detection failures give actionable guidance.

Documented DuckDuckGo as a best-effort fallback for datacenter/shared-egress IPs and covered the provider guidance in regression tests.

Fixes #3863
2026-06-30 04:43:08 +00:00
can1357 6e166274cb fix(web-search,mcp): reused gemini oauth helper and formatted npx shim 2026-06-29 16:56:43 +02:00
can1357 6f8f76be43 Keep DuckDuckGo result cap unchanged 2026-06-29 16:45:47 +02:00