Commit Graph
7466 Commits
Author SHA1 Message Date
jiwangyihao ec00294462 fix(ai): 仅为 paste-code provider 合成默认手动粘贴码提示
机器人指出之前的 CLI 侧 gating 是无效的:runLocalLogin 对非 paste-code provider
省略 onManualCodeInput,但 AuthStorage.login 仍以 ctrl.onManualCodeInput ??
manualCodeInput 注入默认值,因此 loopback OAuth provider 的 OAuthCallbackFlow
仍会让 readline 粘贴提示与 HTTP 回调竞争;回调先到时该提示悬挂,终端进入
脏/阻塞状态。

在唯一汇聚点 AuthStorage.login 做权威 gating:

- 仅当 provider 属于 PASTE_CODE_LOGIN_PROVIDERS 时才合成默认 manualCodeInput;
  loopback provider 不再获得手动码竞争。
- 调用方显式传入的 onManualCodeInput 对任意 provider 仍被透传(逃生舱)。
- 该修复覆盖所有调用方,不止 auth-broker CLI。
- CLI 侧的 usesManualInput gating 保留为纵深防御,并更新注释指明 storage 层
  才是权威闸门,纠正机器人指出的“只在此处省略”误导性表述。

新增针对 storage 契约的回归测试(auth-storage-manual-code-gate.test.ts):
loopback provider 不被注入默认提示;显式提示对 loopback 仍透传;paste-code
provider(gitlab-duo-agent)在调用方省略时被合成默认提示并经 onPrompt 路由。
2026-06-26 16:13:25 +08:00
jiwangyihao af32c22ffe fix(agent): /move 后按会话实时 cwd 重新作用域 Duo 发现
机器人指出 agent.ts 的 #cwd 在构造时固定,/move 更新 SessionManager 与
进程 cwd 后不会重建 Agent,导致 GitLab Duo Agent 的 namespace/project 发现
持续读取旧仓库的 git remote。

按既有 resolver 模式(getReasoning/getServiceTier)修复:

- Agent 新增可选 cwdResolver;构造时存入 #cwdResolver。
- AgentLoopConfig 新增 getCwd 每调用解析器,config 同时携带静态 cwd 与
  getCwd。
- agent-loop 在 streamFunction 调用点计算 effectiveCwd = getCwd?.() ?? cwd,
  每次 LLM 调用读取一次,因此运行中途的 /move 也能被工作区级 provider 发现
  感知。
- sdk.ts 主 Agent 传入 cwdResolver: () => sessionManager.getCwd(),该值在
  /move 时由 SessionManager.#cwd 更新。

新增针对可观测契约的回归测试(mock streamFn 记录 options.cwd):resolver
覆盖静态 cwd、resolver 返回 undefined 时回退静态 cwd、以及运行中途变更可被
逐次调用读取(模拟 /move)。
2026-06-26 16:13:24 +08:00
jiwangyihao 4fdf2f83a5 fix(ai): 处理 rebase 后 Codex 新增的三项审阅意见
- catalog CHANGELOG 删除 rebase 重放进已发布 [16.1.4] 段落的重复 Claude 4.6 条目,使该段落与上游 main 完全一致(已发布段不可变)
- Duo Agent finally 清理在最终 idle timeout(重试已耗尽)时也发送 stop PATCH,避免代理/LB 持续断连场景下服务端工作流残留
- auth-broker login 仅对 pasteCodeFlow provider 传入 onManualCodeInput,普通 loopback provider 不再让 readline 提示与 HTTP 回调竞争导致终端残留
2026-06-26 16:13:23 +08:00
jiwangyihao d6194030e5 feat(agent): thread cwd through to local tool execution 2026-06-26 16:13:20 +08:00
can1357 ff759ed850 chore: bump version to 16.1.22 2026-06-26 09:19:53 +02:00
can1357 0007489195 chore: update changelogs 2026-06-26 09:19:23 +02:00
can1357 c474c6cde4 Merge remote-tracking branch 'origin/farm/6727da85/mcp-oauth-plane-resource-strip' 2026-06-26 09:19:10 +02:00
roboomp fcee2cb783 style: bun run fix 2026-06-26 07:09:36 +00:00
roboomp ff6e1b6e17 fix(mcp/oauth): skip discovery metadata with mismatched issuer
`discoverOAuthEndpoints` probes `/.well-known/oauth-authorization-server` at
the origin root before path-prefixed candidates and returns on the first hit.
Plane hosts a root issuer (`https://mcp.plane.so/`) at origin root and a
separate path-scoped issuer (`https://mcp.plane.so/http`) at the path-prefixed
well-known. The `/http/mcp` endpoint advertises only the path-scoped issuer
through protected-resource metadata, so discovery should follow that issuer's
metadata — instead it accepted the wrong origin-root document and routed the
grant to `https://mcp.plane.so/authorize`, which rejects every request with
`server_error=An unexpected error occurred` before the consent screen.

RFC 8414 §3.3 requires the metadata's `issuer` to equal the URL the client
used to construct the metadata URL. Validate it in the discovery loop: when
the queried well-known is the official authorization-server or OpenID Connect
document, skip metadata whose `issuer` doesn't match (after trailing-slash
normalization). Documents without an `issuer` field keep the existing
permissive behavior so legacy/nonstandard servers continue to work.

Verified live against `https://mcp.plane.so/http/authorize` with the same
client/PKCE: pre-fix `302 -> /callback?error=server_error`, post-fix
`302 -> /http/consent?txn_id=…`. Adds an `oauth-discovery.test.ts`
regression suite covering Plane's wrong-issuer origin-root document plus
trailing-slash and no-issuer paths.

Fixes #3537
2026-06-26 07:09:24 +00:00
roboomp f6005e0d67 fix(mcp): hid stdio windows subprocess consoles
Set windowsHide for every Windows stdio MCP spawn path so direct .exe servers no longer open a visible cmd.exe window.

Added a regression test covering direct Windows executable MCP server launch options.

Fixes #3535
2026-06-26 06:58:19 +00:00
can1357 018a9638c0 chore: bump version to 16.1.21 2026-06-26 07:39:22 +02:00
can1357 963dd0eb69 test: align MCP OAuth refresh assertions with options-object signature
refreshMCPOAuthToken now takes a trailing { authorizationUrl, stripSameOriginResource } options object (issue #3502 follow-up). Update the two stale per-profile binding assertions to expect it, and assert the fallback resource is not persisted (resource: undefined) since it is re-derived from config.url on each refresh.
2026-06-26 07:39:02 +02:00
can1357 2879143f6e test(coding-agent/extensibility): resolved symlinks in legacy module tests
- Updated module path validation to use real paths to prevent test failures in environments where node_modules might be symlinked.
2026-06-26 07:29:36 +02:00
can1357 dfa9dc28df feat(coding-agent/tools): updated todo task display and status messaging
- Clarify the auto-advancement logic for the in-progress pointer in the documentation and output.
- Add an overall completion count summary to the task list view.
- Update the list format to use standard checkbox indicators and explicit tags for task statuses.
2026-06-26 06:55:01 +02:00
can1357 301d145301 Merge remote-tracking branch 'origin/farm/c42beb4b/fix-duplicate-todo-panels' 2026-06-26 05:15:39 +02:00
roboomp ce41a47b99 fix(tui): preserved live todo snapshot across mid-turn rebuild
Mid-turn renderSessionContext (settings overlay close, focus attach during streaming) now hands the rebuilt todo snapshot back to the EventController via the new inheritDisplaceableTodo method instead of sealing it. Idle rebuilds keep the historic seal path.

Added a regression test that asserts the trailing todo snapshot is published to the controller and stays displaceable while session.isStreaming is true.

Fixes #3516
2026-06-26 02:50:30 +00:00
can1357 170b293d0e chore: update changelogs 2026-06-26 04:39:50 +02:00
can1357 f4339d1c43 Merge remote-tracking branch 'origin/farm/c42beb4b/fix-duplicate-todo-panels' 2026-06-26 04:39:33 +02:00
can1357 bfc07971cd Merge remote-tracking branch 'origin/farm/3d061a17/stop-stale-advisor-loop' 2026-06-26 04:39:21 +02:00
can1357 52b049457e Merge remote-tracking branch 'origin/farm/06e0487b/legacy-extension-validation-load-path' 2026-06-26 04:38:46 +02:00
can1357 cf2f25de1e Merge remote-tracking branch 'origin/farm/e69418eb/macos-image-paste-keybind' 2026-06-26 04:38:42 +02:00
can1357 716c0d1bba Merge remote-tracking branch 'origin/farm/7fe9d14c/autolearn-capture-terminal-stop' 2026-06-26 04:38:34 +02:00
can1357 54afbd10a8 Merge remote-tracking branch 'origin/farm/420d6ddb/mcp-oauth-skip-resource-when-same-origin' 2026-06-26 04:38:29 +02:00
roboomp bd6710bd02 fix(tui): deferred todo displacement to successful result
Dropped eager todo snapshot displacement from tool_execution_start, streaming message_update, and the rebuild assistant-iteration step. Displacement now runs only when the next todo's successful result lands, so a failed follow-up leaves the last-good todo panel on screen.

Added regression coverage for the failed follow-up case and updated the streamed-second-todo test to drive displacement from the success result.

Fixes #3516
2026-06-26 02:21:37 +00:00
roboomp ba3a6079be fix(tui): collapsed multi-todo rebuild snapshots
Resolved any tracked todo snapshot before storing a fresh one in the rebuild paths so an assistant message replaying multiple todo tool calls collapses to the final snapshot.

Added a renderSessionContext regression test for two todo tool calls in one rebuilt assistant message.

Fixes #3516
2026-06-26 02:17:12 +00:00
roboomp 58373fdee9 fix(tui): handled streamed todo replacement
Resolved existing todo components before tool execution so streamed tool-call previews can still displace stale todo snapshots.

Added regression coverage for pre-created todo calls replacing a prior todo panel after intervening tool output.

Fixes #3516
2026-06-26 02:12:43 +00:00
roboomp a2230b3dd0 fix(tui): collapsed repeated todo snapshots
Kept successful todo result blocks live until a later todo update replaces them or the turn ends.

Added regression coverage for same-turn todo snapshot replacement after intervening tool output.

Fixes #3516
2026-06-26 02:04:19 +00:00
roboomp f62ee17080 fix(advisor): forwarded severity escalations past dedupe
Tracked the highest delivered severity per note so a nit can later land as a concern or blocker without being silently dropped.

De-escalation back to nit/concern stays treated as a duplicate so the model cannot flap severities to bypass dedupe.

Fixes #3511
2026-06-26 00:34:04 +00:00
roboomp cce5133bfa fix(advisor): reset advisory dedupe state
Cleared delivered-note memory when the advisor session state resets across conversation boundaries.

Added coverage that repeated advice is allowed again after the dedupe state resets.

Fixes #3511
2026-06-26 00:31:51 +00:00
roboomp 6d58901cc3 fix(advisor): suppressed repeated advisories
Deduplicated advisor notes inside the advise tool so a model cannot enqueue the same advisory repeatedly in one session.

Added focused regression coverage for duplicate advisory suppression.

Fixes #3511
2026-06-26 00:26:01 +00:00
roboomp 006470a111 fix(plugins): resolved string export deps
Handled package root export sugar when legacy extension bare dependency resolution falls back from Bun.resolveSync in compiled binaries.

Fixes #3508
2026-06-26 00:13:30 +00:00
roboomp b7706f1a44 fix(plugins): loaded legacy extensions safely
Restored the pi-ai OAuth device-code helper expected by legacy provider packages and rewrote extension-owned bare dependencies to file URLs during validation so compiled binaries do not rely on Bun's runtime bare resolver.

Excluded worker entry modules from the compiled legacy bundled registry so validation does not import worker-only code on the main thread.

Fixes #3508
2026-06-26 00:06:25 +00:00
roboomp 257b515353 fix(coding-agent): attach every image in a multi-file Finder selection
Reviewer caught: the macOS file-URL loop returned after the first
image-shaped path, silently dropping the rest of a multi-image
selection. The bracketed-paste handler in `CustomEditor.handleInput`
already iterates every extracted image path; the keybind path now does
the same. Mixed selections (one .pdf + two images) still attach all
images and skip the non-images.

Tests cover (a) multi-image selection (3 attached), (b) mixed selection
with the file-URL fallback owning the outcome (text fallback MUST NOT
run when at least one file URL was an image).

Refs #3506
2026-06-25 23:35:31 +00:00
roboomp 8bb6fd76ba fix(coding-agent): recover image paths with unescaped spaces in keybind fallback
Reviewer caught: `extractImagePathFromText` reused the bracketed-paste
splitter, which treats unescaped spaces as separators. macOS screenshot
filenames default to names like
`/Users/me/Desktop/Screenshot 2026-06-25 at 1.23.45 PM.png` — the
splitter shredded those into 5 segments, the second segment failed the
explicit-path check, and the helper returned undefined, so the keybind
fallback pasted the path verbatim instead of attaching the image.

Add a whole-text-as-path stage gated on a new ABSOLUTE_PATH_PREFIX_REGEX
(matches `/`, `~/`, `file://`, `\\`, or a drive letter), used
only when the splitter found nothing (otherwise multi-path text like
`/tmp/a.png /tmp/b.png` would be mis-joined). Prose containing a
path-shaped fragment ("see /tmp/x.png") fails both passes and still
pastes as text.

Tests cover (a) macOS screenshot names with spaces, (b) ~/Pictures and
Windows paths with spaces, (c) anchored prose fragments not hijacking
the fallback, and (d) end-to-end real-file integration via
handleImagePaste.

Refs #3506
2026-06-25 23:30:12 +00:00
roboomp a1f5b8cbcb style: bun run fix 2026-06-25 23:25:13 +00:00
roboomp b3f99dc634 fix(coding-agent): reach macOS public.file-url pasteboard via osascript
Reviewer caught (correctly) that the #3506 text fallback relied on
`clipboard.readText()`, which on Darwin shells out to `pbpaste(1)` —
pbpaste only surfaces plain text / RTF / EPS, so a Finder Cmd+C
pasteboard (`public.file-url` only, no plain text, no raw image bytes)
made readText() return empty and the new path-detection never ran.

Add a Darwin-only `readMacFileUrlsFromClipboard` helper that pipes a
small AppleScript through `osascript -` to coerce the pasteboard via
`«class furl»` and emit POSIX paths one per line. Wire it into
`InputController.handleImagePaste` between the readImage and readText
calls; the first image-shaped path routes through
`handleImagePathPaste`, non-image file URLs (e.g. a copied .pdf) fall
through to the existing text fallback. The clipboard interface field is
optional so existing test fixtures keep working without changes.

Tests: covers (a) Darwin file-URL pasteboard with empty pbpaste,
(b) non-image file URLs falling through to text, (c) the helper itself
on darwin/non-darwin and when osascript fails.

Refs #3506
2026-06-25 23:25:00 +00:00
roboomp 509eed817c fix(coding-agent): decode file:// URLs in pasted image paths
When the macOS pasteboard's text representation forwards a
`file:///Users/.../img.png` URL (Ghostty/iTerm2/etc. forwarding the
`public.file-url` representation after a Finder copy), the smart
bracketed-paste / keybind fallback recognized it as a path but
`loadImageInput` then tried to read a literal `file://` path and
failed. `normalizePastedPath` now decodes `file://` URLs via
`node:url.fileURLToPath` before the explicit-path check, mirroring
Codex's `normalize_pasted_path` in
`codex-rs/tui/src/clipboard_paste.rs`. Both the bracketed-paste path
and the new `extractImagePathFromText` keybind path benefit.

Refs #3506
2026-06-25 23:17:53 +00:00
roboomp e1dc21e0b5 fix(coding-agent): attach image on clipboard image-file paste
When the clipboard exposes only a file URL for an image (e.g. Finder
`Cmd+C` on a `.png`, certain screenshot tools), arboard's
`get_image()` returns `ContentNotAvailable`. `handleImagePaste` then
fell through to the #1628 smart-paste text fallback and pasted the path
verbatim, while the terminal-mediated paste round-tripped through
bracketed-paste's `extractBracketedImagePastePaths` and attached the
image — producing the asymmetric "for image I need control+v which is
very odd" symptom on macOS.

Refactor `custom-editor.ts` to share the bracketed-paste path-detection
logic via a new `extractImagePathFromText` export, then route the text
fallback through `handleImagePathPaste` whenever the clipboard text is
exactly one explicit image file path. Both keybind- and terminal-mediated
paste now agree.

Fixes #3506
2026-06-25 23:06:39 +00:00
roboomp 132531ee47 fix(mcp/oauth): preserve advertised origin resource indicators
Review on PR #3503 caught the last provenance edge case: some servers can
explicitly advertise an origin-only resource equal to the authorization-server
origin. That value is still authoritative provider metadata and must be sent;
only OMP-synthesized fallback resources should be stripped.

- `filterResourceIndicator` now strips same-origin values only when `stripSameOriginResource` is set. Provider-advertised `oauth.resource` and authorization-URL `?resource=` values preserve both origin-only and path-scoped forms.
- Updated grant tests to preserve advertised origin resources, trailing-slash origin resources, and URL-embedded origin resources while still stripping fallback origin/path resources for Plane.
- Updated refresh tests to preserve advertised origin resources and strip only fallback origin/path resources.
- Updated changelog wording to describe fallback-only stripping.

Fixes #3502
2026-06-25 22:04:49 +00:00
roboomp 3c3a552d49 fix(mcp/oauth): preserve authorization-url embedded path resources
Review on PR #3503 caught one remaining provenance hole: a provider can embed a
path-scoped same-host `resource` directly in the authorization URL while
`oauth.resource` remains undefined. The controller marks its separate
`config.url` resource as fallback, but the URL-embedded parameter is still
provider-authored and must not inherit the fallback same-origin stripping
policy.

- `generateAuthUrl` now filters an existing `?resource=` from the authorization URL with the path-preserving default, regardless of `stripSameOriginResource` on the caller-supplied fallback resource.
- Added a regression that simulates `authorize?resource=https://gateway.example.com/svc/mcp` plus fallback `resource=https://gateway.example.com`; the authorize URL, `flow.resource`, and token request all preserve `/svc/mcp`.
- Updated the changelog to explicitly mention authorization-URL-embedded path resources.

Fixes #3502
2026-06-25 21:55:59 +00:00
roboomp 80c0beb84a fix(mcp/oauth): preserve advertised path-scoped resource indicators
Review on PR #3503 caught that the broad same-origin filter broke valid
protected-resource discovery shapes such as
`https://gateway.example.com/my-service/mcp`: same host as the authorization
server, but a distinct MCP service identified by path. Those advertised
resources must be preserved for audience selection.

- Replaced the unconditional same-origin filter with a provenance-aware policy: exact auth-server-origin resources are always stripped, path-scoped same-origin resources are preserved by default, and only OMP-synthesized fallback resources opt into same-origin path stripping.
- Added `stripSameOriginResource` to `MCPOAuthConfig` and `RefreshMCPOAuthTokenOptions`; quick-add/reauth set it only when the resource came from `config.url` / `runtimeBaseConfig.url` fallback rather than `oauth.resource` or an existing auth resource.
- Refresh uses the same flag when `MCPManager.prepareConfig` falls back to `config.url`, and no longer persists fallback resources into the credential as if they were provider-advertised material.
- Updated RFC 8707 tests to cover both sides: gateway path resource preserved, Plane-style fallback `/http/mcp` stripped, refresh path mirrors the same distinction.

Fixes #3502
2026-06-25 21:48:14 +00:00
roboomp aff0cf95a2 fix(autolearn): make auto-continue capture turn terminal
With `autolearn.autoContinue` on, the controller fires a synthetic
turn whose only user-role payload is `autolearn-nudge.md`. The old
prompt opened with "Before you finish:" and gave no terminal
contract, so after the `learn`/`manage_skill` call the agent read
its own unanswered prior question (e.g. "Want me to commit and
push?") as accepted and continued — pushing commits, running tools,
etc. — without the user ever answering.

Split the nudge into two prompts and pick at fire time:

- passive (rides the user's real next message) keeps additive
  framing — "answer the user normally; the capture is in addition
  to, not a replacement for, the work the user just asked for".
- auto-continue (`autolearn-nudge-autocontinue.md`) is explicitly
  terminal — "not a user reply; do not treat this as approval or
  acceptance of any pending action; capture, then stop; do not run
  other tools, resume prior work, or answer your own pending
  questions; wait for the user's next prompt".

Attribution stays `user` so llama.cpp keeps reusing the warm
prefix (#3456). Regression tests pin the load-bearing terminal
language in both branches.

Fixes #3504
2026-06-25 21:44:45 +00:00
roboomp f7fa80e00e fix(mcp/oauth): strip same-origin path resource indicators too
Plane also rejects `resource=https://mcp.plane.so/http/mcp`, not only the bare
origin forms. That means the MCP OAuth resource filter must treat any resource
URL on the authorization-server origin as redundant for these MCP servers, not
just exact origin/origin-slash values.

- Broadened the filter to compare `new URL(resource).origin` with the persisted authorization-server origin.
- Updated grant and refresh RFC 8707 tests: same-origin path resources such as `/http/mcp` are now stripped from authorize, token exchange, and refresh; cross-origin resources remain preserved.
- Updated docs/changelog wording from exact self-referential origin to same-origin resource indicators.

Verified live against `https://mcp.plane.so/authorize`: patched `MCPOAuthFlow` with `resource=https://mcp.plane.so/http/mcp` generates no `resource` parameter and Plane redirects to `/consent?txn_id=…`.

Fixes #3502
2026-06-25 21:36:32 +00:00
roboomp 11c10640f2 fix(mcp/oauth): persist authorization-server origin so refresh filters against it
Review on PR #3503 flagged that the prior fix anchored the initial-grant filter
on `authorizationUrl` but the refresh filter on `tokenUrl`. RFC 8414 lets the
authorize and token endpoints sit on different origins, so when they do, a
`config.url` fallback equal to the auth-server origin survives the refresh
filter — the credential works until expiry, then refresh resurrects the same
self-referential `resource` the authorize/token exchange intentionally
omitted.

- `MCPStoredOAuthCredential.authorizationUrl?: string` — new field, the issuer the grant was minted against.
- `MCPOAuthFlow.authorizationUrl` getter exposes the value so the persistence site can write it (symmetric with `flow.resource`).
- `refreshMCPOAuthToken` accepts `{ authorizationUrl }` via the trailing options object; filters self-referential indicators against the supplied URL, falling back to `tokenUrl`'s origin for legacy credentials. New `RefreshMCPOAuthTokenOptions` interface keeps the positional resource form working.
- `mcp-command-controller.ts` persists `flow.authorizationUrl` on credential write; `manager.ts` extracts it from the embedded credential material (legacy `MCPAuthConfig` rows lack it and continue through the `tokenUrl` fallback) and threads it to `refreshMCPOAuthToken`.
- Tests: 3 new cross-origin refresh cases — stripped when resource equals auth-server origin with cross-origin token endpoint; preserved when resource points at a third origin; legacy `tokenUrl`-anchored fallback still works without `authorizationUrl`. Plus a `flow.authorizationUrl` getter test. Updated `mcp-manager-oauth-refresh.test.ts` to account for the new opts arg.

Fixes #3502
2026-06-25 21:04:58 +00:00
roboomp dbff881fba fix(mcp/oauth): apply self-referential resource filter on refresh too
When the initial grant strips a self-referential resource (per the previous
commit), the credential is stored with `resource: undefined`. On the next
refresh, `MCPManager.prepareConfig` (`packages/coding-agent/src/mcp/manager.ts:1232-1233`)
falls back from `material?.resource` to `config.url` and pipes it into
`refreshMCPOAuthToken` — re-introducing the same self-referential value that
broke the initial authorize against strict servers like Plane. RFC 8707 §2.2
also requires the token-request indicator to match the authorize indicator,
so dropping in one mandates dropping in the other.

- Hoisted `filterSelfReferentialResource(resource, serverUrl)` to module scope so the class-method form and the free `refreshMCPOAuthToken` share the rule. `MCPOAuthFlow.#filterResourceIndicator` is now a thin delegate.
- `refreshMCPOAuthToken` now passes the resource through the same filter, using `tokenUrl` as the origin yardstick (RFC 8414 puts authorize and token endpoints on the same issuer, and MCP discovery follows that contract).
- Added 3-test `RFC 8707 resource indicator (refresh)` suite covering: resource equals token-server origin (stripped), origin with trailing slash (stripped), and a path-bearing resource (preserved).

Fixes #3502
2026-06-25 20:54:16 +00:00
roboomp 093243bff5 fix(mcp/oauth): drop self-referential resource indicator from authorize/token requests
Some MCP authorization servers reject `resource=<auth-server-origin>` with
`server_error&error_description=An+unexpected+error+occurred` before the
consent screen is shown. Plane (`https://mcp.plane.so`) is the live example:
`resource=https://mcp.plane.so` or `https://mcp.plane.so/` errors; the same
authorize request with no resource (or a path-bearing resource like
`https://mcp.plane.so/sse`) succeeds.

Per RFC 8707 §2 the resource indicator distinguishes *other* resource servers
from the authorization server, so a self-referential value is never required.
`MCPOAuthFlow` now strips a resource that equals the authorization-server
origin (with or without trailing slash) in three places:

- the constructor, when resolving the configured resource;
- `generateAuthUrl()`, including the URL-override path that re-reads `?resource=` from the authorize URL;
- `exchangeToken()`, which reads `this.#resource` (RFC 8707 §2.2 requires the token request indicator to match the authorize request, so dropping in one mandates the other).

Verified live against `https://mcp.plane.so/authorize`: pre-fix the generated
URL produces `302 → /callback?error=server_error&…`; post-fix it produces
`302 → /consent?txn_id=…`.

Fixes #3502
2026-06-25 20:48:30 +00:00
can1357 0fc6d136c3 chore: bump version to 16.1.20 2026-06-25 22:45:00 +02:00
can1357 7690dfe7fb chore: update changelogs 2026-06-25 22:44:19 +02:00
can1357 5a50b047d5 Merge PR #3428: Fix active goal compaction after yield stop (@cexll) 2026-06-25 22:39:28 +02:00
can1357 938489f3fd feat(coding-agent): added configurable service tier settings for subagents and advisor
- Introduced `serviceTierSubagent` and `serviceTierAdvisor` settings to allow independent service tier control for subagents and the advisor model.
- Enabled `"inherit"` mode for these settings, allowing subagents and the advisor to track the main session's live effective service tier, including dynamic toggles like `/fast`.
- Added a resolution layer to ensure service tier propagation from parent sessions to spawned task agents and evaluators.
2026-06-25 22:35:15 +02:00