Commit Graph
510 Commits
Author SHA1 Message Date
Erik Svilichandcan1357 d6f887d152 fix(coding-agent): close remaining extension-flag edge cases (GPT-5.5 review)
Three issues from an adversarial review, all rooted in the startup argv parse
running before extensions load:

1. Flag-looking string values (`--name --print`): the extension-aware reparse
   consumed the following token as the value, disagreeing with the startup
   parse that treated `--print` as the built-in flag — so the reparse could
   silently flip command shape. Extension string flags now consume a following
   token only in `--flag=value` form or when it is not flag-looking; pass a
   flag-looking value as `--flag=value`. Keeps both parses consistent.

2. `@file` string values (`--target @notes.md`): file args were processed from
   the startup parse, which misreads the value as a file and reads it into the
   prompt. processFileArguments now runs on the extension-aware parse
   (initialArgs.fileArgs); pipedInput stays early for mode detection.

3. Built-in collisions: an extension flag named like a built-in (e.g. `model`)
   was consumed by the built-in branch and never delivered to the runner.
   registerFlag now rejects names in BUILTIN_FLAG_NAMES with a clear error
   (isolated per-extension by loadExtension's try/catch).

Adds tests for all three plus the documented startup-parse misclassification.
2026-05-31 04:45:51 +02:00
Erik Svilichandcan1357 295c52a307 fix(coding-agent): drop unconsumed --flag=value values for non-consuming flags
Addresses review: a boolean flag in equals form still leaked its value. parseArgs
splices `--headless=true` into `--headless`, `true` so value-consuming flags can
pick the value up via `args[++i]`; a boolean flag sets itself without consuming
it, leaving `true` to fall through as a positional message — and since
applyExtensionFlags feeds this parse into buildInitialMessage, `omp
--headless=true "do the task"` sent `true` as the prompt.

Track the spliced value's index and, if no branch advanced past it (i.e. the
matched flag did not consume a value), drop it after the dispatch. Closes the
whole equals-form class — boolean extension flags and built-in non-consuming
flags (`--no-tools=true`, `--print=1`) alike — at the single parsing site.

Adds tests for boolean extension + built-in flags in equals form.
2026-05-31 04:45:51 +02:00
Erik Svilichandcan1357 b674e3a663 fix(coding-agent): unify extension-flag parsing through parseArgs
Addresses review: a string extension flag in equals form (--spawn-peer=reviewer)
was still leaking its value into the initial prompt. Root cause was a second,
hand-rolled argv parser in applyExtensionFlagValues that recognized only
`--flag` and `--flag value`, not `--flag=value`; it looked up the literal name
`spawn-peer=reviewer`, set nothing, and (because the reparse was gated on
"were values set") skipped the reparse entirely, so the extension-unaware
startup parse won — leaving `reviewer` as the first message. The extension
itself also never received the value.

Replace the duplicate parser with a single source of truth: extract
applyExtensionFlags() into cli/extension-flags.ts, which re-parses argv through
the same parseArgs() the startup pass uses (now seeded with the registered
flags) and pushes the resulting values onto the runner. parseArgs already
normalizes `--flag`, `--flag value`, and `--flag=value` identically, so no flag
form can be handled by one parser and missed by the other. The reparse is now
gated on registered-flag presence, not on values having been set.

Wires parseArgs's previously-unused `unknownFlags` output to the runner, and
removes the now-redundant parseArgs import from main.ts. Adds unit tests for
applyExtensionFlags across all flag forms (including equals form) plus the
no-runner / no-flags / no-args-passed gate cases.
2026-05-31 04:45:51 +02:00
Erik Svilichandcan1357 15f6f52e08 fix(coding-agent): make parseArgs non-mutating to fix double-splice on reparse
The `--option=value` handling splices the value into the argv to reuse the
`args[++i]` path, mutating the caller's array. The post-extension reparse in
runRootCommand then ran on that already-mutated argv, so

    omp --model=sonnet --spawn-peer reviewer "review"

re-spliced `sonnet` and leaked it into the initial prompt before "review".

parseArgs now copies its input and never mutates the caller's array, so
launch, acp, and the reparse are all safe. Drops the now-redundant
`[...rawArgs]` copy at the reparse site, and adds regression coverage for the
--option=value + extension-flag combo plus input non-mutation.
2026-05-31 04:45:51 +02:00
can1357 5f63165637 feat(setup-wizard): added interactive onboarding wizard on first launch
- Added setup wizard with provider login, glyph mode, and theme scenes shown once per setup version.
- Wired `omp setup` (no args) to trigger the wizard in a TTY; `--check`/`--json` still show help.
- Extracted `gradientEscape` and exported `PI_LOGO`/`ShineConfig` from welcome for shared use in splash/outro.
- Fixed race condition in `setSymbolPreset`/`setColorBlindMode` by tracking load request IDs.
2026-05-31 00:07:14 +02:00
can1357 d73393cf5c feat(cli): added shell completions for bash, zsh, and fish
- Added `omp completions ` command generating scripts from live command/flag metadata.
- Added hidden `omp __complete` helper for dynamic model and session candidates.
- Completions never drift from the CLI: flags, enums, and subcommands are derived from static descriptors.
2026-05-30 21:32:03 +02:00
can1357 f0b252449b feat(coding-agent): added tiny local model support for memory extraction and consolidation
- Added a new `providers.memoryModel` setting with tiny memory model options and `ONLINE_MEMORY_MODEL_KEY` default in settings.
- Updated Mnemosyne provider resolution so a configured local tiny model overrode remote completion and used new memory extraction and consolidation prompts.
- Expanded the tiny-model CLI registry to download and report all local tiny models (title plus memory) through a unified list.
2026-05-30 18:48:47 +02:00
can1357 a53acf1431 test(coding-agent): updated hashline preview tests to use snapshot-tagged headers
- Updated hashline streaming preview tests to generate snapshot-tagged section headers and use an in-memory snapshot store.
- Replaced untagged file markers in multi-section preview inputs with `formatHashlineHeader` values derived from recorded file contents.
- Changed the bash command error test to expect a returned `isError` result with exit code 1 instead of a rejected promise.
2026-05-30 17:51:11 +02:00
can1357 826c3b932d refactor(packages/coding-agent): reorganized tiny-title runtime stack
- Added tiny-title protocol contracts, including progress-state unions, message payloads, and transport interfaces.
- Added title text utilities to truncate long inputs, wrap `<user-message>` blocks, and normalize generated titles.
- Added tiny-title model registry and helpers with type-safe keys and runtime optional loading via optionalDependencies.
- Added client-side worker orchestration with spawn fallback, request queueing, progress/error routing, and smoke-test APIs.
- Added worker runtime for model resolution, prompt-based inference, lock-based install retries, and close-time cache clear.
2026-05-30 17:40:18 +02:00
Ogrodev 2e4f258050 fix(profiles): harden alias upsert, env precedence, and bootstrap flag handling
- profile-alias: refuse to rewrite a managed block whose start marker lacks a
  matching end marker instead of appending, which on the next install would
  splice from the stale start through the new end and delete intervening user
  shell config (data loss in dotfiles).
- dirs/cli: add resolveProfileEnv so OMP_PROFILE takes precedence and an
  explicitly-empty OMP_PROFILE selects the default profile instead of falling
  through to PI_PROFILE; share the rule across both env-read sites.
- dirs: reject uppercase profile names so profile identity/isolation is stable
  across case-sensitive and case-insensitive filesystems.
- profile-bootstrap: treat an unclassified bare long option as a possible
  extension string flag and forward its successor untouched (never as a global
  --profile/--alias), while exempting known value-less launch flags via
  VALUELESS_FLAGS so 'omp --print --profile work' still selects a profile.
- tests: cover all four contracts.
2026-05-30 11:05:30 -03:00
Ogrodev 458482613b fix(profile-bootstrap): extract profile flags beyond subcommand-shaped tokens
- Allow parsing global profile flags after an early launch token is chosen
- Only the first residual token can terminate subcommand dispatch scanning
- Keep `--profile` parsing active when later argv contains subcommand-like words
- Add coverage for launch argv that include command names before/after profile args
2026-05-30 10:17:35 -03:00
Ogrodev c41bb8c170 fix(profile-alias): align alias install handling for edge cases
- Reject /bin/sh as unsupported shell instead of mapping it to bash
- Make alias-shadow check for `omp` case-insensitive
- Preserve non-ENOENT read failures when loading shell config
- Treat missing shell config file as empty for fresh installs
- Add targeted tests for case-insensitive alias rejection, sh rejection, and read error behavior
2026-05-30 10:17:34 -03:00
Ogrodev 6c251ad5dd fix(coding-agent): validate profile before rendering alias script
- Use normalizeProfileName in installProfileAlias instead of raw trim/default checks
- Preserve error path for invalid/empty profile names before shell block rendering
- Keep behavior consistent with shared profile normalization logic
2026-05-30 09:39:26 -03:00
Ogrodev 3a50761153 fix(coding-agent): handle -- boundary and subcommands in CLI parsing
- Add POSIX `--` end-of-options handling in argument parser
- Stop consuming flags after `--` and pass remaining tokens as messages
- Stop global `--profile`/alias extraction at first registered subcommand
- Add focused tests for parseArgs and profile bootstrap boundary behavior
2026-05-30 09:08:15 -03:00
Ogrodev c800e1524a Merge remote-tracking branch 'upstream/main' into feat/profiles-and-alias
# Conflicts:
#	packages/coding-agent/src/cli.ts
2026-05-29 21:55:39 -03:00
bench-local f6ca76728b feat(ai): add Wafer Pass and Wafer Serverless providers
Wafer (https://wafer.ai) exposes a single OpenAI-compatible endpoint
(`https://pass.wafer.ai/v1`) for two SKUs whose entitlement differs
server-side, so we model them as two parallel providers — mirroring the
firepass/fireworks split so a user with both subscriptions can switch
without re-pasting:

- `wafer-pass` — flat-rate. `/v1/models` is filtered to entries whose
  `wafer.tier === "pass_included"`.
- `wafer-serverless` — pay-as-you-go superset of Pass.

Both issue `wfr_…` keys. `/login wafer-pass` and `/login wafer-serverless`
paste-and-validate via `/v1/models`. `WAFER_PASS_API_KEY` and
`WAFER_SERVERLESS_API_KEY` are wired through `getEnvApiKey`.

Bundled catalog:
- `wafer-pass`: GLM-5.1, Qwen3.5-397B-A17B.
- `wafer-serverless`: GLM-5.1, Qwen3.5-397B-A17B, Kimi-K2.6, Qwen3.6-35B-A3B.

Dynamic discovery via `/v1/models` overlays additional models at runtime
and folds the `wafer` envelope (tier, capabilities, cents/M pricing) into
the canonical `Model<"openai-completions">` shape. GLM-family entries
carry the zai-style thinking compat (`thinkingFormat: "zai"`,
`reasoningContentField: "reasoning_content"`) so reasoning tokens land in
the right field. Cents-per-million → dollars-per-million via /100.

Tests (`packages/ai/test/wafer.test.ts`, 5 cases): bundled catalog
contract for both providers and wire-id pass-through (case-sensitive,
no rewrite — `GLM-5.1` must round-trip verbatim or upstream 404s).
Optional `packages/ai/test/wafer.live.ts` exercises a real round-trip
against `pass.wafer.ai` when `WAFER_PASS_API_KEY` is set.
2026-05-27 20:45:33 -07:00
can1357 3d5f0d8868 refactor(coding-agent/cli): switched auth-broker serve to dedicated logger transport setter
- Updated the auth-broker CLI to import the transport setter from the logger module.
- Replaced the logger.setTransports call in runServe with the dedicated setTransports helper.
2026-05-28 00:51:35 +02:00
can1357 6491fff8f6 feat(ai): added strict auth-gateway mode with completion-probe checks
- Added strict `auth-gateway` check mode, propagated `--strict`, and updated strict output/exit rules.
- Added `checkCredentials` completion-probe support with timeout and provider-aware payload helpers.
- Changed OAuth credential checks to refresh first, preserve usage results, and skip completion on refresh failures.
- Added tests for completion-probe execution, OAuth refresh rejection, and `completion.reason`/sentinel behavior.
2026-05-28 00:35:15 +02:00
Ogrodev efac908118 fix(coding-agent): restore empty-string resume handling
Refactored the optional-value flag handling so per-flag quirks live in
shared metadata instead of the args.ts dispatch loop. Added
OPTIONAL_FLAGS in cli/flag-tables.ts with rejectEmpty and
rejectAtPrefix controls, then updated both parseArgs and the profile
bootstrap to consult the same source of truth.

This restores the pre-refactor behavior for `--resume`, `-r`, and
`--session`: an empty-string argv token is treated as “no value
provided”, leaving resume=true and the empty string to fall through as a
positional message on the next iteration. `--list-models` intentionally
keeps its existing empty-string behavior.

Added regressions for parseArgs(["--resume", ""]), parseArgs(["-r",
""]), parseArgs(["--session", ""]), the preserved
`--list-models` empty-string behavior, and the bootstrap path where an
empty-string resume value precedes `--profile`.
2026-05-27 10:09:15 -03:00
Ogrodev 09cb4fe6d7 fix(coding-agent): added --approval-mode to bootstrap STRING_VALUE_FLAGS
`--approval-mode` is a string-valued flag in args.ts (`args[++i]` with
no `-` prefix check), but profile-bootstrap.ts did not list it in
STRING_VALUE_FLAGS. As a result `omp --approval-mode --profile foo`
was rewritten to `argv: ["--approval-mode"]` and silently activated
profile `foo` instead of passing `--profile` through as the invalid
approval-mode value — the exact corruption the pre-parser exists to
prevent for string-valued flags.

Caught in code review of PR #1435 after upstream merge brought in
`--approval-mode`. `--auto-approve`/`--yolo` are boolean and require
no entry. Added a regression test that mirrors the existing
`--system-prompt` coverage so future upstream merges that add
string-valued flags can be caught the same way.
2026-05-27 08:14:43 -03:00
Ogrodev 680917f02a feat: added isolated profiles with --profile and --alias
Added named OMP profiles that isolate agent state (auth credentials,
sessions, settings, model cache, history, memories, blobs, plus
config root subdirs) under `~/.omp/profiles/<name>/agent/`. Activated
via `--profile <name>` or `OMP_PROFILE=<name>`; `default` maps back to
the regular `~/.omp/agent/` tree.

Added `--alias <command>` to generate a shell shortcut (e.g.
`omp-work`) that forwards `omp --profile <name>`. Detects the active
shell (bash, zsh, fish, PowerShell, pwsh), writes a wrapper into the
correct rc file, and preserves subcommands like `update`, `--version`,
and `--model` because the wrapper passes through argv unchanged.

The `--profile`/`--alias` bootstrap pre-parser lives in
`packages/coding-agent/src/cli/profile-bootstrap.ts` and runs before
any module that touches `getAgentDir()` (notably `@oh-my-pi/pi-utils/env`,
which eagerly loads `.env` from the agent directory at its own import
time). The pre-parser mirrors `parseArgs` value-consumption rules and
honors `--`, so commands like `omp --system-prompt --profile foo` pass
the literal `--profile` through as the prompt body instead of silently
activating profile `foo`.

XDG resolution for named profiles is keyed on the profile-specific
XDG path (`$XDG_*_HOME/omp/profiles/<name>`), never the base app root,
so a profile's location is decided once at first activation and stays
stable even after `omp config init-xdg` materializes the base later.
The default profile keeps its existing base-app-root check.

`setProfile(undefined)` (and `setProfile("default")`) restores the
pre-profile `PI_CODING_AGENT_DIR` snapshot taken at first activation
instead of unconditionally deleting it. `setAgentDir` refreshes the
snapshot since that call is the user explicitly redefining the
baseline.

Validation rejects profile names that match `.`/`..`, fail
`/^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$/`, or hit a Windows reserved
device name (`CON`, `PRN`, `AUX`, `NUL`, `COM0-9`, `LPT0-9`, including
dotted variants like `CON.txt`) — those would let `setProfile` accept
the input only for directory creation to fail later with confusing
errors on Windows.
2026-05-27 07:50:45 -03:00
can1357 e4a16451ec feat(coding-agent): added coding-agent approval types and mode options
- Added `ToolTier`, `ToolApproval`, and `ToolApprovalDecision` types and exported approval APIs.
- Updated approval-mode options from `auto|prompt|custom` to `always-ask|write|yolo` and defaulted mode to `yolo`.
- Changed approval resolution to apply per-tool decisions first, then mode-tier limits, with legacy-mode migration.
- Assigned read/write/exec `approval` and approval-detail prompts across built-in, custom, extension, and MCP tools.
2026-05-26 21:52:16 +02:00
can1357 1aa5e980ac feat(coding-agent): added approval-mode CLI override for session tool settings
- Added a new `approvalMode` argument to CLI parsing with validation for `auto`, `prompt`, and `custom` values.
- Registered `--approval-mode` on the launch command so it appears in generated help output.
- Applied the parsed approval mode as a runtime override on `Settings`, ensuring downstream `tools.approvalMode` reads reflect the CLI value.
2026-05-26 21:06:26 +02:00
oldschoolaandcan1357 4d26453a0b feat(coding-agent): restore per-tool approval policies with safer defaults
Re-introduces the per-tool approval system from luzidd's commit 39124f3 (which
is no longer reachable from main) and improves it before re-landing.

What's restored:
- ApprovalPolicy (allow/deny/prompt) plus DEFAULT_APPROVAL_POLICIES.
- ACTION_EXCEPTIONS registry (LSP read-only, bash critical patterns).
- getApprovalPolicy() six-level resolution order.
- ExtensionToolWrapper.execute() gate before extension handlers.
- --auto-approve / --yolo CLI flag and tools.approval.<tool> user config.
- docs/approval-mode.md user guide.

What's improved over the original:
- Replaced unchecked 'as any' casts with typed unknown narrowing helpers.
- Validate userConfig values: invalid strings, numbers, etc. fall through to
  the built-in default instead of being silently honoured (typo no longer
  locks a tool out or grants implicit approval).
- Expanded CRITICAL_BASH_PATTERNS: chmod -R /, chown -R /, bash <(curl ...),
  writes to /etc/passwd|shadow|sudoers, shutdown/reboot/halt/init 0,
  kill -9 1, nc -e / nc -c reverse shells. Pattern shapes require a
  command-position boundary so 'npm run reboot-tests' and 'echo "shutdown the
  queue"' don't false-positive.
- Added DEBUG_READONLY_ACTIONS exception so DAP inspection actions (threads,
  stack_trace, variables, scopes, read_memory, …) auto-allow while
  execution-side actions (launch, attach, continue, evaluate, write_memory,
  set_breakpoint, …) still prompt.
- formatApprovalPrompt: labels mcp__<server>__<tool> calls as MCP server
  tools, surfaces ssh host + command, recognises the modern § hashline header
  for edit, and truncates >240-char fields so a heredoc-sized body cannot
  blow out the confirmation dialog.
- Test suite grown from 40 to 57 cases — new coverage for invalid user
  config, the extended critical-bash patterns, benign-keyword negatives,
  debug exceptions, MCP/ssh prompt formatting, and command truncation.

Verification:
- bun test packages/coding-agent/test/tools/approval.test.ts -> 57 pass
- bun x biome check . -> clean
- bun run check:ts across all 9 workspaces -> clean
2026-05-26 20:53:33 +02:00
can1357 07d13ba15e refactor(auth-broker): migrated OAuth flow from pi-ai CLI to AuthStorage
- Migrated OAuth provider authentication from standalone `pi-ai` CLI to in-process `AuthStorage.login()` flow in coding-agent.
- Made provider argument optional for `login` and `logout` commands with interactive provider picker when omitted.
- Added `list` command to enumerate registered OAuth providers with optional `--json` output format.
- Removed `pi-ai` CLI binary and `bin` entry from @oh-my-pi/ai package; library API remains unchanged.
- Updated documentation and examples to reflect new `omp auth-broker` command interface and in-process OAuth flow.
2026-05-26 19:56:43 +02:00
roboomp b161d816b1 fix(coding-agent): converted cli pdf file arguments
Converted CLI document file arguments through the Markit path before adding them to the initial prompt, preventing PDF bytes from being sent directly to local vision models. Added a regression test for PDF file arguments.\n\nFixes #1401
2026-05-26 11:34:30 +00:00
can1357 2ad7124e25 feat(ai): added tri-state credential checks in auth-gateway check flow
- Added `checkCredentials()` with result types/options for per-credential tri-state health checks.
- Added `/v1/credentials/check` endpoint via `handleCredentialsCheck` returning `{ generatedAt, credentials }`.
- Added `omp auth-gateway check` flow with provider grouping, `--json` output, and exit status 1 on failures.
- Added command examples, changelog updates, and tests for expired OAuth refresh, null/missing config, and ordering edge cases.
2026-05-25 19:53:58 +02:00
ogormans-deptstack 537cc179f9 feat: add --hide-thinking CLI flag to suppress thinking blocks in TUI
Wire --hide-thinking launch flag that sets hideThinkingBlock before TUI
init. Display-only: does not disable model reasoning, just hides the
thinking output in the terminal.

- Add hideThinking to Args interface and parseArgs
- Add --hide-thinking flag definition in launch command
- Apply setting via settingsInstance.override in main

Closes #1313
2026-05-23 22:03:30 +01:00
can1357 1228c96959 feat(coding-agent): added worktree list/clear CLI with orphan pruning
- Added the new `omp worktree` (`wt`) command with `list|clear`, `all/dry-run/json` options, and CLI registration.
- Added `listWorktrees`/`clearWorktrees` flows that scan worktrees, classify orphaned entries, emit JSON, and call `worktree.prune`.
- Replaced legacy path encoding with `hashPath` via `getWorktreeDir`, updating task isolation, storage keys, and PR checkout paths.
- Added bounded PR worktree path retries before `git worktree add` and updated checkout-path tests for hashed names.
2026-05-22 12:47:13 +09:00
roboomp a6279e0730 fix(cli): restored binary update rollback
Rolled back binary updater replacements when post-install version verification fails instead of deleting the previous working binary first.

Added a release workflow gate that downloads the published macOS arm64 asset and verifies codesign plus --version before npm publishing.

Fixes #1240
2026-05-21 00:09:43 +00:00
can1357 cab5138c5d style(coding-agent/cli): simplified formatting of reinstall warning output
- Collapsed a multi-line reinstall-warning `console.log` statement into a single line.
- Preserved the existing warning message text and only simplified its formatting.
2026-05-17 12:13:53 +02:00
Can BölükandGitHub d62e7f4698 chore: update installation command in update-cli.ts 2026-05-17 11:23:02 +02:00
Bonobo 8a7f7d75c5 fix(coding-agent): correct install.sh fallback URL in omp update warning
The fallback reinstall hint printed when omp update can't verify the new
binary pointed at https://raw.githubusercontent.com/can1357/oh-my-pi/main/install.sh,
which returns 404. The installer actually lives at scripts/install.sh
(consistent with the README install instructions).
2026-05-17 05:54:08 +02:00
can1357 6db7d6af92 feat(ai): added auth-broker snapshot contract with generation checks
- Added generation-aware snapshot contracts with generation, serverNowMs, refresher, and rotatesInMs fields.
- Reworked /v1/snapshot serving and client fetching for If-None-Match long-poll with 304/200 status handling.
- Added status checks in remote-store and SDK/CLI snapshot paths, applying updates only when fetch returns 200.
- Added StreamOptions.onAuthError and stream one-shot 401 retry dispatch using refreshed credentials.
2026-05-17 04:54:30 +02:00
can1357 75f34d1815 feat(utils): added configurable logger transport switching for headless services
- Added a new `setTransports` logger API to swap console and file winston transports at runtime.
- Refactored logger transport creation to lazily build rotating file logs via a shared directory helper.
- Updated auth-broker serve startup/shutdown to use structured logger output and switch to console-only logs for its headless runtime.
2026-05-17 04:19:38 +02:00
can1357 0bb385f8ab feat(grievances): added consent gate & push
- Added `dev.autoqa.consent` setting and single-flight popup handler wired through `InteractiveMode`.
- Added `flushGrievances` to batch-POST unpushed rows to `dev.autoqaPush.endpoint` with cooldown and single-flight deduplication.
- Added `omp grievances push` subcommand with TTY progress bar for manual draining.
- Migrated shared DB logic to `openAutoQaDb` (with `pushed` column migration) exported from `report-tool-issue`.
2026-05-17 01:47:24 +02:00
can1357 484fca9c01 feat: added auth-gateway usage cache with single-flight 15s ttl fallback
- Added AbortSignal propagation and timeout-race handling for broker health, usage, refresh, and snapshot calls.
- Added single-flight usage-report caching with 15s TTL, per-caller abort races, and null-on-fail fallback.
- Expanded provider schemas and parse/build logic for cache metadata, headers, stop controls, and image/file content.
- Hardened auth flows by rejecting refresh sentinels and using timing-safe bearer-token comparisons.
2026-05-17 01:10:25 +02:00
can1357 df1c1a6ba8 feat(auth): added auth-gateway forward-proxy and broker usage/migrate endpoints
- Added `omp auth-gateway serve/token/status` — a forward-proxy injecting broker credentials for OpenAI Chat, Anthropic Messages, and OpenAI Responses wire formats.
- Added `GET /v1/usage` to auth-broker and auth-gateway; usage cache switched to 5-min per-credential TTL with jitter and last-good fallback on failure.
- Added `AuthStorage.setConfigApiKey/removeConfigApiKey/clearConfigApiKeys` so `models.yml` `apiKey` beats OAuth tokens without overriding `--api-key`.
- Added `omp auth-broker migrate --from-local` for idempotent upload of local SQLite/env credentials to the broker.
2026-05-16 23:25:10 +02:00
can1357 c3f5a60c22 feat(auth): added auth-broker for remote credential vault
- Added `AuthBrokerClient`, `RemoteAuthCredentialStore`, `AuthBrokerRefresher`, and `startAuthBroker` server in `packages/ai/src/auth-broker`.
- Renamed `AuthCredentialStore` class to `SqliteAuthCredentialStore`; extracted `AuthCredentialStore` as a persistence interface.
- Added `exportSnapshot`, `forceRefreshCredentialById`, `disableCredentialById`, and `upsertCredential` to `AuthStorage` for broker wire protocol.
- Added `omp auth-broker` CLI subcommand (serve, token, login, logout, import, status) and `discoverAuthStorage` broker-mode path keyed on `OMP_AUTH_BROKER_URL`.
2026-05-16 20:44:07 +02:00
can1357 f1f6516056 refactor: reorganized exports and removed obsolete helper branches
- Removed export leakage by demoting many helper and const symbols to module-local scope.
- Renamed underscore-prefixed internals and cache fields, then updated related references and `satisfies never` checks.
- Deleted obsolete logic branches and helpers, including harmony-stream interruption flow and unused benchmark runtime helpers.
- Updated Biome config and manifests by broadening lint coverage and removing an unused `@napi-rs/cli` dev dependency.
- Adjusted tests and utilities to use renamed test helpers and remove redundant private test-only helpers/locals.
2026-05-14 04:36:19 +02:00
Miroslav Drbalandcan1357 68627b0857 feat(coding-agent): add rpc-ui mode with tool UI context over RPC protocol
Adds a new `rpc-ui` mode that extends the existing headless RPC mode with
interactive tool support (ask tool, extension UI dialogs, etc.).

In plain `rpc` mode the session has `hasUI=false` and no UI context is
wired, so interactive tools are disabled. `rpc-ui` mode sets `hasUI=true`
and wires a single shared `RpcExtensionUIContext` instance into both the
tool context store and the extension runner. Both consumers share the same
`pendingExtensionRequests` map and output closure, so `extension_ui_response`
messages received on stdin are routed to the correct waiting promise
regardless of which code path (tool or extension) created the request.

Changes:
- `args.ts`: add `rpc-ui` to the `Mode` union and the parse guard
- `launch.ts`: expose `rpc-ui` in the OCLIF flag definition and help text
- `main.ts`: propagate `rpc-ui` through all RPC-mode guard conditions and
  pass `setToolUIContext` to `runRpcMode` when the mode is `rpc-ui`
- `rpc-mode.ts`: accept optional `setToolUIContext` callback; create one
  shared `RpcExtensionUIContext` instance and pass it to both the tool
  context store and the extension runner
2026-05-13 02:18:57 +02:00
can1357 b468bd5abd feat(stats): show input and output token totals 2026-05-12 16:40:43 +02:00
can1357 8d144e17ec feat(coding-agent/eval): added local python-runner subprocess execution
- Replaced Python execution with a local `python -u runner.py` subprocess and NDJSON stdin/stdout framing.
- Removed shared-gateway architecture, including coordinator lifecycle APIs, `useSharedGateway` wiring, and `jupyter` CLI/actions.
- Simplified setup checks to a plain Python 3 availability probe and removed automatic dependency-install fallbacks.
- Updated kernel cancellation and display processing to use status frames, SIGINT/SIGTERM escalation, and normalized output coercion.
- Added `python-runner` integration and display tests while deleting legacy websocket and kernel lifecycle test suites.
2026-05-12 09:09:24 +02:00
can1357 f56cbbf4c6 feat(stats): added frustration metrics to stats parser and charting
- Added new frustration and revised behavior metrics across stats types, parser mappings, and UI charts.
- Reworked session sync to fan out parsing across a capped worker pool with SyncOptions progress callbacks.
- Added worker-based parse messaging and throttled TTY progress rendering in the stats sync command.
- Updated behavior scoring to strip structured content, ignore noisy prompts, and fix profanity boundary regressions.
- Expanded user message schema and migrations, then repaired assistant model/provider links during sync backfill.
- Updated worker-import guidance in AGENTS.md and recorded sync-progress/metrics updates in package changelogs.
2026-05-12 07:55:23 +02:00
can1357 fdc3fe1196 refactor(coding-agent): removed configurable read timeout and standardized URL fetch timeout
- Removed the read CLI argument and tool schema field so read requests no longer accept custom timeouts.
- Updated URL read handling to stop forwarding timeout values and execute URL reads without a timeout parameter.
- Standardized URL read fetching to a fixed 30-second timeout and dropped timeout metadata from URL call rendering.
2026-05-07 05:39:22 +02:00
can1357 cc13fd3dce feat: added ScanDetail modes for fd, glob, and ast scans
- Added configurable `ScanDetail` modes across native fd/glob/ast flows and exposed `size` on `GlobMatch`/types.
- Added parallel grep processing with optional workers, buffered entry visits, and direct small-file reads.
- Changed `filesWithMatches` to stop at first match per file and report `totalMatches` as matching-file count.
- Fixed grep count/offset limits, timeout checks, and cancel handling by enforcing offsets in aggregate results.
- Updated PI_GREP_WORKERS and auto-absorb/read-summarize behavior/docs, including `read.summarize.prose` and pure-insert defaults.
- Added tests for filesWithMatches counts, cancel cases, and count-mode behavior, plus updated grep benchmark imports.
2026-05-06 17:00:45 +02:00
can1357 4087e69e70 feat(coding-agent): added read CLI command for inspecting tool output
- Registered a new `read` command in the CLI command registry so `omp read` can be invoked.
- Implemented `runReadCommand` to execute the read tool, wrap it with meta notices, and print text or image-result blocks.
- Added a `read` command class with required path input, optional timeout flag, and usage examples.
2026-05-04 04:27:47 +02:00
can1357 c65191911e feat(coding-agent/cli): added grievance clean action to the grievances command
- Added a `list`/`clean` positional action and examples to the grievances command, along with new `--id`, `--tool`, and `--all` flags for cleaning.
- Implemented `cleanGrievances` to delete grievances by id, tool, or all entries, enforce mutually exclusive selectors, and emit JSON counts when requested.
- Updated grievance DB access to use writable handles for clean operations and reset autoincrement sequence when removing all rows.
2026-05-03 07:39:52 +02:00
can1357 5d1ad6e80b fix(coding-agent): load extensions before --list-models
The --list-models handler in runRootCommand short-circuited to
listModels() right after Settings.init and modelRegistry.refresh,
exiting before extension loading ran in createAgentSession. As a
result, providers contributed via pi.registerProvider() (from -e
paths or settings.extensions) never appeared in the listing.

Extract a runListModelsCommand entry point in cli/list-models.ts
that loads extensions (CLI -e paths and settings.extensions) into
the supplied ModelRegistry, mirroring sdk.ts's handoff of pending
provider registrations, and then delegates to listModels. The load
is intentionally narrow: no agent loop, no MCP servers, no custom
tools.

Fixes #905
2026-05-02 07:48:30 +02:00
can1357 cf60e6df51 feat(coding-agent): implemented eval framework and replaced python tool
- Added a unified eval framework with parser grammar, backend interfaces, and JS/Python execution result types.
- Added eval tool docs and updated prompts for fenced cells, `eval.py`/`eval.js`, and fallback behavior.
- Replaced the built-in `python` tool with `eval` across registry, rendering, interactive modes, and tool settings.
- Migrated Python execution runtime from `src/ipy` to `src/eval/py`, renamed state fields, and removed legacy introspection.
- Refactored browser tooling from in-process VM helpers to worker-managed tab supervisors and protocol transport.
- Added eval parser fallback and JS tool-bridge tests, updated imports, and removed obsolete python-mode suites.
2026-04-30 18:08:37 +02:00