Uh oh!
There was an error while loading. Please reload this page.
fix(desktop): oauth popups open from the browser preview - #8435
Conversation
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Scripted `window.open` calls inside the integrated browser preview were denied and loaded in the preview tab instead. Firebase `signInWithPopup` got a null window handle back and reported `auth/popup-blocked`, and the in-tab load also dropped the opener the popup needs to post the credential back to. Popups with a `new-window` disposition and an http or https URL now get a real window, with context isolation and the sandbox turned back on: a popup is not a webview attach, so the `will-attach-webview` hardening never sees it and an unoverridden child would inherit the picker preload's relaxed posture. `about:blank` popups keep loading in the preview tab, since Chromium copies the guest preferences for them and forbids overriding. Links with `target="_blank"` are unchanged. Fixespingdotgg#6561
e598878 to
8fa05aeCompareUh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
An allowed popup carried Electron's default window-open behavior, so a page inside it could spawn native windows without limit. The popup now denies its own window.open calls; no OAuth flow opens a second popup. The popup preferences also drop nodeIntegrationInSubFrames, matching the three keys every other hardened window in the app sets.
d2ce056 to
7c5b69aCompareElectron reads allowpopups when the guest attaches. The attribute was set from the ref callback, which runs after the element is in the DOM, so every preview guest attached with popups disabled and Electron blocked window.open before the window-open handler ran. Verified in a running desktop build: will-attach-webview reported allowpopups: false before this change and true after.
There was a problem hiding this comment.
One finding in the web scope: the new allowpopups JSX attribute is the right ownership fix, but its string value conflicts with React's element typing, so apps/web typecheck (tsgo --noEmit) breaks. Details inline.
Posted via Macroscope — UI Consistency
Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 0604de5. Configure here.
| nodeIntegration: false, | ||
| sandbox: true, | ||
| }, | ||
| } satisfies Electron.BrowserWindowConstructorOptions; |
There was a problem hiding this comment.
Popup may inherit picker preload
High Severity
POPUP_WINDOW_OPTIONS overrides isolation flags but never clears preload. Electron merges overrideBrowserWindowOptions with the guest's preferences, so the picker preload can still run in the OAuth window and observe keystrokes and clicks on a third-party login page.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 0604de5. Configure here.
There was a problem hiding this comment.
I could not reproduce this one, so I am leaving the code as is. Details, in case I tested the wrong thing.
A popup opened from a webview guest does not inherit the guest's preload, with or without overrideBrowserWindowOptions. I checked with a standalone Electron 41.5.0 app that mirrors the preview setup: a <webview allowpopups> with a preload and contextIsolation=false, whose preload announces itself over IPC on load, then window.open(...) from inside the guest.
The preload reports from the guest and never from the popup:
RESULT preload-ran in: http://127.0.0.1:8899/popup-repro.html
RESULT popup created:
Same result with the override removed, and same with data: and http: popup URLs, so the override is not what is clearing it — the inheritance does not happen in the first place.
One thing worth flagging for anyone reading this later: webContents.getLastWebPreferences() does not report preload at all. It omits the key even for the guest, which definitely has one, so it cannot be used to check this.
If you have a case where the preload does reach the popup, I would like to see it — the exposure you describe would be real, since that preload listens for keydown and pointerdown.
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR changes production preview behavior by enabling OAuth popup windows and altering Electron renderer security boundaries across the desktop and webview layers. An unresolved security concern about the preview preload potentially reaching third-party OAuth pages still requires validation. Notes:
You can add or adjust custom eligibility rules. Learn more. |
React types allowpopups as boolean, so the string literal failed apps/web's tsgo --noEmit. Passing a real boolean typechecks but regresses the fix, since react-dom drops boolean values for unrecognized attributes and sets nothing, so the guest would attach with popups disabled again. Verified after the change: the element carries allowpopups="true" and a scripted window.open returns a window handle.
MatthewFeroz
commented
Aug 28, 2026
hoping this gets merged! |
MatthewFeroz
commented
Aug 28, 2026
I double-checked the preload concern in Electron 41.5.0 and tested it myself. The preview’s preload script ran only inside the preview, not inside the popup. Electron’s code also confirms that preload scripts are not copied into new windows. This matches the author’s test, so I don’t think the Cursor warning is a real issue. |
walid-baharwal
commented
Aug 28, 2026
Status summary, since the Approvability verdict above predates the current head and reads as the most visible signal on this PR. That verdict was posted at I tested it with a standalone Electron 41.5.0 app mirroring the preview setup — a Worth flagging for anyone testing this themselves: The popup is also created with Current head is No action needed from me unless something new turns up. |
MatthewFeroz
commented
Aug 28, 2026
Just sent a video to the maintainers of this working. Small limitation in this is that passkeys don't function but I think that's out of scope for this PR. Great work! |
Uh oh!
There was an error while loading. Please reload this page.
walid-baharwal
commented
Aug 28, 2026
Thanks for running it and recording the video — I could not produce one myself, so that fills the gap CONTRIBUTING asks for on interaction changes. On passkeys: that is pre-existing and tracked separately in #5665 ("In app browser not triggering passkey fingerprint to sign in on mac", open since 2026-08-07), so it predates this branch. Nothing here touches WebAuthn — the change only decides whether So I agree it is out of scope, and I would rather not widen this PR to chase it. |
## What's Changed * fix(grok): improve skills, plans, usage, and turn reliability by @t3dotgg in pingdotgg/t3code#8358 * fix(server): recover stale Codex approval callbacks by @luckyPipewrench in pingdotgg/t3code#5195 * test(server): remove duplicate missing worktree test by @t3-code[bot] in pingdotgg/t3code#8252 * fix(server): replay all un-applied events during projection bootstrap by @krutftw in pingdotgg/t3code#7538 * test: remove low-signal test files by @t3-code[bot] in pingdotgg/t3code#8397 * test: prune trivial error and layout tests by @t3-code[bot] in pingdotgg/t3code#8400 * Fix Android adaptive launcher icon by @colonelpanic8 in pingdotgg/t3code#4332 * feat(web): split provider settings into list and editor by @t3dotgg in pingdotgg/t3code#8380 * fix(codex): accept Codex 0.150 account plans by @gsimone in pingdotgg/t3code#8447 * fix(tooling): allow ignored-only staged changes by @juliusmarminge in pingdotgg/t3code#8468 * fix(mobile): keep iOS home header stable by @juliusmarminge in pingdotgg/t3code#8467 * fix(web): stop showing red x summaries for ordinary tool failures by @t3dotgg in pingdotgg/t3code#8395 * fix(mobile): refine Git action toast glass styling by @juliusmarminge in pingdotgg/t3code#8399 * fix(desktop): allow preview automation in agent-created threads by @t3dotgg in pingdotgg/t3code#8483 * test(web): remove redundant cache key test by @t3-code[bot] in pingdotgg/t3code#8484 * fix(release): move nightly schedule to minute 38 by @t3dotgg in pingdotgg/t3code#8509 * fix(web): stabilize the provider settings editor by @t3dotgg in pingdotgg/t3code#8472 * fix(web): open GitHub pull requests in browser when loading fails by @t3dotgg in pingdotgg/t3code#8507 * fix(codex): show sub-agent models by @t3dotgg in pingdotgg/t3code#8502 * feat(analytics): report connected client platforms by @t3dotgg in pingdotgg/t3code#8481 * feat(server): accept PDF, ZIP, and other file uploads up to 50MB by @t3dotgg in pingdotgg/t3code#8235 * feat(web): toggle a thread's pin from the keyboard by @ipanasenko in pingdotgg/t3code#8440 * fix(web): add back button to project settings by @StiensWout in pingdotgg/t3code#8168 * refactor(mobile): compile semantic themes for Uniwind by @juliusmarminge in pingdotgg/t3code#7327 * fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times by @ikifar2012 in pingdotgg/t3code#5769 * fix(mobile): show OpenCode model sources in picker by @juliusmarminge in pingdotgg/t3code#8573 * fix(clients): honor project default models in new threads by @anirudhsama in pingdotgg/t3code#6011 * fix(mobile): show file actions on Android by @none23 in pingdotgg/t3code#8215 * fix(connect): explain DPoP connection failures by @extoci in pingdotgg/t3code#8351 * feat(web): make the sidebar project filter a searchable combobox by @SunkenInTime in pingdotgg/t3code#5931 * fix(server): a draft can retry its first send after a failed bootstrap by @shivamhwp in pingdotgg/t3code#8226 * fix(desktop): stop hidden previews draining battery by @Bil0000 in pingdotgg/t3code#8567 * fix(desktop): oauth popups open from the browser preview by @walid-baharwal in pingdotgg/t3code#8435 * fix(web): keep long task drawers usable on small screens by @shivamhwp in pingdotgg/t3code#8313 * fix(opencode): handle child approvals, stops, and model catalogs by @t3dotgg in pingdotgg/t3code#8480 * fix: make thread auto-settling opt-in by @shivamhwp in pingdotgg/t3code#8321 * fix(web): stop session activity timing test from blocking releases by @t3dotgg in pingdotgg/t3code#8585 * fix(mobile): show composer menus when starting a task by @juliusmarminge in pingdotgg/t3code#8587 * fix(web): show the configured stash shortcut by @UtkarshUsername in pingdotgg/t3code#8437 * feat(web): add toggleable confirmation before unpinning a thread by @UtkarshUsername in pingdotgg/t3code#7313 * fix: restore automatic thread settling defaults by @t3dotgg in pingdotgg/t3code#8596 * fix(mobile): restore composer glass and rounded shadows by @juliusmarminge in pingdotgg/t3code#8597 ## New Contributors * @luckyPipewrench made their first contribution in pingdotgg/t3code#5195 * @krutftw made their first contribution in pingdotgg/t3code#7538 * @colonelpanic8 made their first contribution in pingdotgg/t3code#4332 * @ikifar2012 made their first contribution in pingdotgg/t3code#5769 * @walid-baharwal made their first contribution in pingdotgg/t3code#8435 **Full Changelog**: pingdotgg/t3code@v0.0.35...v0.0.36 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.36
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358) Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com> Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com> Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com> Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com> Co-authored-by: Guilherme Barros <gbarros1095@gmail.com> Co-authored-by: PC <pc@localhost> Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com> * fix(server): recover stale Codex approval callbacks (pingdotgg#5195) * test(server): remove duplicate missing worktree test (pingdotgg#8252) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> * fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538) Co-authored-by: Theo Browne <me@t3.gg> * test: remove low-signal test files (pingdotgg#8397) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> * test: prune trivial error and layout tests (pingdotgg#8400) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> * Fix Android adaptive launcher icon (pingdotgg#4332) Co-authored-by: Yash Singh <saiansh2525@gmail.com> * feat(web): split provider settings into list and editor (pingdotgg#8380) * fix(codex): accept Codex 0.150 account plans (pingdotgg#8447) * fix(tooling): allow ignored-only staged changes (pingdotgg#8468) * fix(mobile): keep iOS home header stable (pingdotgg#8467) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(mobile): refine Git action toast glass styling (pingdotgg#8399) * fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483) * test(web): remove redundant cache key test (pingdotgg#8484) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> * fix(release): move nightly schedule to minute 38 Recent scheduled nightlies have been delayed or skipped. Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery. Authored by GPT-5.6 Sol with the Codex harness. * fix(web): stabilize the provider settings editor (pingdotgg#8472) * fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507) * fix(codex): show sub-agent models (pingdotgg#8502) * feat(analytics): report connected client platforms (pingdotgg#8481) * feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(web): toggle thread pin from the keyboard Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning. * fix(web): add back button to project settings (pingdotgg#8168) * refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327) Co-authored-by: codex <codex@users.noreply.github.com> * fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com> * fix(mobile): show OpenCode model sources in picker (pingdotgg#8573) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(clients): honor project default models in new threads (pingdotgg#6011) Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com> * fix(mobile): show file actions on Android (pingdotgg#8215) Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com> * fix(connect): explain DPoP connection failures (pingdotgg#8351) Co-authored-by: Julius Marminge <julius0216@outlook.com> * feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931) * fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(desktop): stop hidden previews draining battery (pingdotgg#8567) * fix(desktop): oauth popups open from the browser preview (pingdotgg#8435) Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(web): keep long task drawers usable on small screens (pingdotgg#8313) * fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480) * fix: make thread auto-settling opt-in (pingdotgg#8321) * fix(web): stop session activity timing test from blocking releases (pingdotgg#8585) * fix(mobile): show composer menus when starting a task (pingdotgg#8587) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(web): show the configured stash shortcut (pingdotgg#8437) Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com> * feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313) Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com> * fix: restore automatic thread settling defaults (pingdotgg#8596) * fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597) Co-authored-by: Julius Marminge <julius@mac.lan> * Remove Messages Glass Lab experiment (pingdotgg#8599) * chore(release): prepare v0.0.36 --------- Co-authored-by: Theo Browne <me@t3.gg> Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com> Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com> Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com> Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com> Co-authored-by: Guilherme Barros <gbarros1095@gmail.com> Co-authored-by: PC <pc@localhost> Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com> Co-authored-by: Josh <gitlucky@pipelab.org> Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Ivan Malison <IvanMalison@gmail.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: Julius Marminge <julius@mac.lan> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Illia Panasenko <hello@ipanasenko.me> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: codex <codex@users.noreply.github.com> Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com> Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com> Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live> Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com> Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com> Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com> Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com> Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com> Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
) Co-authored-by: Julius Marminge <julius0216@outlook.com> (cherry picked from commit 0e2905e)
* feat(analytics): threads and turns now know which client started them (pingdotgg#7774) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(web): stop marking mixed tool runs as failed (pingdotgg#7893) * fix(web): command-click spaced folder links (pingdotgg#6439) Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> * fix(chat): stop pushing follow-up messages to the top (pingdotgg#7897) * test(desktop): remove redundant release note assertion (pingdotgg#7873) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> * fix(web): handle wide ordered-list marker edge cases (pingdotgg#7856) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(ssh): restore user PATH for remote servers (pingdotgg#7213) * fix(desktop): keep tailscale spawn defects from breaking advertised endpoints (pingdotgg#7116) * fix(web): keep Codex service tier labels readable (pingdotgg#4503) * fix: render workspace images in chat markdown (pingdotgg#6433) * fix(clients): keep opening responses visible after turns settle (pingdotgg#7723) * feat(web): add appearance contrast control (pingdotgg#7906) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com> * fix(server): stop completed Codex threads from staying stuck on working (pingdotgg#7937) * fix(mobile): preserve markdown image dimensions (pingdotgg#7940) * fix(web): remove duplicate provider update progress (pingdotgg#7761) * fix(server): fall back to the remote default branch instead of assuming main (pingdotgg#7078) * fix(web): give sidebar project menu rows the same side padding as other menus (pingdotgg#7913) * fix(clients): reconnect after credentials fail during remote server updates (pingdotgg#7953) * feat(codex): submit thread feedback to OpenAI (pingdotgg#7949) * fix(server): stop kills lingering Claude work (pingdotgg#5891) * fix(ci): let Macroscope approve pull requests again (pingdotgg#7970) * fix(clients): move settled pinned threads into the settled section (pingdotgg#7969) * perf(ci): speed up release builds and Windows packaging (pingdotgg#7975) * fix(web): stop tool calls from leaving a blank page in threads (pingdotgg#7971) * fix(web): stop recovered tool failures from marking work logs red (pingdotgg#7999) * fix(mobile): isolate markdown image requests (pingdotgg#7942) * feat(web): redesign skills in `$` menu and in `/` menu (pingdotgg#8009) * fix(web): restore right panel toggle clicks after closing on desktop (pingdotgg#8016) * fix(web): keep server update banners flush with the composer (pingdotgg#8000) * perf(web): reuse work log rows during streaming (pingdotgg#8006) * fix(web): keep provider badge legible in dark themes (pingdotgg#7968) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com> * fix(web): treat configured urls with uppercase schemes as secure (pingdotgg#8005) Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com> * fix(desktop): keep release notes visible while downloading (pingdotgg#6412) * fix(web): show only providers with usage in usage views (pingdotgg#7563) * fix(web): prevent expanded tool calls from hiding thread content (pingdotgg#8052) * test(server): remove no-op live activity tests (pingdotgg#8056) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> * fix(web): clarify terminal sidebar grouping (pingdotgg#7967) * fix(codex): show app access approval prompts (pingdotgg#8058) * feat(web): upload image attachments before sending (pingdotgg#8048) * fix(server): bound OpenCode skill discovery output (pingdotgg#7675) Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com> * fix(mobile): persist thread shelf collapse state (pingdotgg#5152) * fix(mobile): restore Android tablet thread controls, clean up header (pingdotgg#5385) * fix(mobile): land the first thread open above the composer on Android (pingdotgg#5585) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: codex <codex@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(server): check out submodules in a new worktree (pingdotgg#7674) Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr> * fix(server): preserve merged PR badges after branch deletion (pingdotgg#6216) * fix(server): return fresh live pull request reads (pingdotgg#6472) * fix(web): compare client and server versions as semver, not strings (pingdotgg#7579) * fix(web): stop follow-ups from leaving giant blank space (pingdotgg#8068) * fix(marketing): stop automatic Vercel deployments on pull requests (pingdotgg#8070) * chore: vouch repeat contributors (pingdotgg#8071) * fix(server): keep the authoritative subagent model when snapshots race task_started (pingdotgg#7583) * fix(server): honor auto-accept edits for the OpenCode provider (pingdotgg#7100) * fix(server): run the CLI on Node versions without import.meta.main (pingdotgg#7141) * fix(server): recover from provider interrupt failures (pingdotgg#7412) * fix(server): recreate a thread's worktree before starting a turn (pingdotgg#7839) * fix(server): thread delete no longer fails on already-removed worktrees (pingdotgg#8076) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(web): stop update notices showing through the composer (pingdotgg#8083) * fix(web): detect outdated nightly servers (pingdotgg#8124) * fix(web): align usage page skeleton layout (pingdotgg#8111) * fix(web): make terminal links appear clickable only when clickable (pingdotgg#7488) * fix(web): make Windows file links clickable in chat (pingdotgg#8081) * fix(web): sort usage models by token count (pingdotgg#8108) * fix: open agent file links in the file viewer (pingdotgg#8098) * fix(server): stop routine events from rescanning thread history (pingdotgg#8150) * fix(deps): stop pnpm installs from changing the lockfile (pingdotgg#8163) * feat(web): settle and restore threads with a keyboard shortcut (pingdotgg#8089) * perf(desktop): cut macOS signing calls by 81% (pingdotgg#8093) * feat: link pull requests to threads (pingdotgg#8160) * feat(web): safely attach HEIC photos as JPEG images (pingdotgg#8161) Co-authored-by: mweinbach <maxweinbach5@gmail.com> * feat(mobile): track device models and OS versions (pingdotgg#8169) * fix(grok): bound cumulative tool output updates (pingdotgg#7279) * fix(web): delay thread shortcut hints by 200 ms (pingdotgg#8172) * fix(server): stop probing Cursor until enabled (pingdotgg#8175) * docs(release): verify remote updates with database migrations (pingdotgg#8177) * fix(server): keep provider CLIs available in the macOS service (pingdotgg#8173) * feat(claude): compact old threads before they burn through usage (pingdotgg#8144) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(client-runtime): retry queries after connection interruption (pingdotgg#8117) * fix(server): keep previously used providers working after upgrades (pingdotgg#8176) * feat(desktop): build macOS previews from a PR label (pingdotgg#8182) * fix(web): thread jump hints no longer stick after a dictation paste (pingdotgg#8189) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(web): keep grouped project renames (pingdotgg#7831) * feat(web): reveal chat file chips in the system file manager (pingdotgg#7140) Co-authored-by: Dara Adedeji <daraaded@amazon.com> Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> * fix(server): push no longer writes a feature branch's commits to its base branch (pingdotgg#8228) * chore(deps): bump @clerk/electron to 0.0.37 (pingdotgg#8240) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(server): fetch legacy model classification from a hosted manifest (pingdotgg#8227) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * chore(release): prepare v0.0.34 * fix(desktop): let Clerk UI receive stable auth fixes (pingdotgg#8248) * fix(app): un-settled threads return to the top of the list (pingdotgg#8231) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * perf(ci): cut about a minute from every release (pingdotgg#8250) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(ci): download macOS preview DMGs without signing in (pingdotgg#8243) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(codex): accept Codex 0.150 multi-agent events (pingdotgg#8346) * chore(release): prepare v0.0.35 * fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358) Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com> Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com> Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com> Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com> Co-authored-by: Guilherme Barros <gbarros1095@gmail.com> Co-authored-by: PC <pc@localhost> Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com> * fix(server): recover stale Codex approval callbacks (pingdotgg#5195) * test(server): remove duplicate missing worktree test (pingdotgg#8252) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> * fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538) Co-authored-by: Theo Browne <me@t3.gg> * test: remove low-signal test files (pingdotgg#8397) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> * test: prune trivial error and layout tests (pingdotgg#8400) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> * Fix Android adaptive launcher icon (pingdotgg#4332) Co-authored-by: Yash Singh <saiansh2525@gmail.com> * feat(web): split provider settings into list and editor (pingdotgg#8380) * fix(codex): accept Codex 0.150 account plans (pingdotgg#8447) * fix(tooling): allow ignored-only staged changes (pingdotgg#8468) * fix(mobile): keep iOS home header stable (pingdotgg#8467) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(mobile): refine Git action toast glass styling (pingdotgg#8399) * fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483) * test(web): remove redundant cache key test (pingdotgg#8484) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> * fix(release): move nightly schedule to minute 38 Recent scheduled nightlies have been delayed or skipped. Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery. Authored by GPT-5.6 Sol with the Codex harness. * fix(web): stabilize the provider settings editor (pingdotgg#8472) * fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507) * fix(codex): show sub-agent models (pingdotgg#8502) * feat(analytics): report connected client platforms (pingdotgg#8481) * feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(web): toggle thread pin from the keyboard Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning. * fix(web): add back button to project settings (pingdotgg#8168) * refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327) Co-authored-by: codex <codex@users.noreply.github.com> * fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769) Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com> * fix(mobile): show OpenCode model sources in picker (pingdotgg#8573) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(clients): honor project default models in new threads (pingdotgg#6011) Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com> * fix(mobile): show file actions on Android (pingdotgg#8215) Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com> * fix(connect): explain DPoP connection failures (pingdotgg#8351) Co-authored-by: Julius Marminge <julius0216@outlook.com> * feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931) * fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(desktop): stop hidden previews draining battery (pingdotgg#8567) * fix(desktop): oauth popups open from the browser preview (pingdotgg#8435) Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(web): keep long task drawers usable on small screens (pingdotgg#8313) * fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480) * fix: make thread auto-settling opt-in (pingdotgg#8321) * fix(web): stop session activity timing test from blocking releases (pingdotgg#8585) * fix(mobile): show composer menus when starting a task (pingdotgg#8587) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(web): show the configured stash shortcut (pingdotgg#8437) Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com> * feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313) Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com> * fix: restore automatic thread settling defaults (pingdotgg#8596) * fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597) Co-authored-by: Julius Marminge <julius@mac.lan> * Remove Messages Glass Lab experiment (pingdotgg#8599) * chore(release): prepare v0.0.36 * Require human review for pull requests changing product defaults (pingdotgg#8603) * fix(codex): avoid quadratic app-server input buffering (pingdotgg#8605) * fix(mobile): stabilize iOS header item transitions (pingdotgg#8607) Co-authored-by: Julius Marminge <julius@mac.lan> * chore(mobile): upgrade to Expo SDK 57 (pingdotgg#8609) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(mobile): harden native header toolbar items (pingdotgg#8611) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(server): stop querying Claude context usage after turns (pingdotgg#8610) * chore: vouch ryanrhughes (pingdotgg#8613) * feat(web): attach PDFs, ZIPs, and other files to a turn (pingdotgg#8236) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(web): pass stashShortcutLabel in the mixed-attachments stash test PRs pingdotgg#8437 and pingdotgg#8236 crossed: one made stashShortcutLabel a required ComposerStashMenu prop, the other added a test case without it, so main fails web typecheck. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(web): keybinding settings as settings rows (pingdotgg#8532) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> * feat: let an environment publish themes as a file (pingdotgg#8569) Co-authored-by: Theo Browne <me@t3.gg> * fix(web): clean up provider settings list and editor (pingdotgg#8504) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(web): keep project picker popup inside the sidebar (pingdotgg#8627) * fix(mobile): prevent header overflow and back-button artifacts (pingdotgg#8624) * fix(server): retry automatic thread title generation (pingdotgg#8087) * fix(client-runtime): refresh edited pull request comments (pingdotgg#8094) * fix(web): four composer spacing defects (pingdotgg#8090) * perf(desktop): skip duplicate browser updates (pingdotgg#8018) Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(web): render nested markdown images correctly (pingdotgg#8501) * fix(web): unify activity logs and composer banners (pingdotgg#8693) * fix(mobile): reduce dev-client reload and Metro startup cost (pingdotgg#8694) Co-authored-by: Julius Marminge <julius@mac.lan> * revert(web): restore previous composer banners (pingdotgg#8733) * test(web): remove tests for unreachable helpers (pingdotgg#8738) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> * feat(mobile): update tool summaries and chat transitions (pingdotgg#8793) * feat(web): play video attachments in chat (pingdotgg#8688) * fix(web,mobile): snooze menu no longer offers the same wake time twice (pingdotgg#8741) * fix(grok): allow model changes in existing threads (pingdotgg#8392) Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com> * feat(mobile): pick, share, and receive files in threads (pingdotgg#8237) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(web): reduce title bar scroll fade height (pingdotgg#8799) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(windows): strip quotes from repaired PATH (pingdotgg#8746) * fix(web): open agent images in expanded preview (pingdotgg#8807) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(git): follow repository instructions in generated source control text (pingdotgg#8804) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(server): stop overpricing cached Claude tokens (pingdotgg#8806) * fix(web): keep image preview above sidebar control (pingdotgg#8811) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): keep right panel synced with agent edits (pingdotgg#8803) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web,mobile): render Codex citations and artifact templates (pingdotgg#8584) * chore: add Windows setup script to t3.json (pingdotgg#8814) * fix(web): fold interim turn responses (pingdotgg#8828) * fix(web): use circle alert for failed tool calls (pingdotgg#8840) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * feat(mobile): add offline iPhone voice input (pingdotgg#8614) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(web): prevent pull request metadata overlap (pingdotgg#8790) * chore(release): prepare v0.0.37 * Add mobile composer attachment menu with video support (pingdotgg#8843) * fix(mobile): map native menu icon colors explicitly * fix(web): restore unified activity logs and composer banners (pingdotgg#8734) Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: Julius Marminge <jmarminge@gmail.com> * fix(web): address composer banner review follow-ups (pingdotgg#8850) * fix(web): widen sync banners and simplify the working timer (pingdotgg#8855) * fix(preview): improve browser recording quality (pingdotgg#8839) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): mark pull request links as external (pingdotgg#8856) * fix(mobile): replace Callstack glass with Expo glass (pingdotgg#8862) * fix(server): skip IDE detection in Claude probes (pingdotgg#8634) * chore(macroscope): review diagnostic overrides (pingdotgg#8917) Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> * fix(contracts): accept CLI event origins (pingdotgg#8905) * fix(web): hide invalid slash skill completions (pingdotgg#8904) * fix(mobile): defer draft navigation until submission completes (pingdotgg#8914) * chore: disable CodeRabbit review status (pingdotgg#8933) * Delete app.json (pingdotgg#8934) * fix(web): show scrollbar for wide markdown tables (pingdotgg#8868) * fix(mobile): shimmer active tool rows (pingdotgg#8932) Co-authored-by: Julius Marminge <julius@mac.lan> * chore(deps): bump Electron to 43.4.1 (pingdotgg#8626) * fix(chat): smooth worktree setup status (pingdotgg#8922) * feat(mobile): add video playback with native iOS controls (pingdotgg#8919) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(web): prevent chat metadata overlap (pingdotgg#8851) * fix(server): preserve usage cache outside walked roots (pingdotgg#8540) Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com> * feat(mobile): add native image and PDF previews (pingdotgg#8959) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(server): allow long thread IDs in HTTP routes (pingdotgg#8898) * fix(shared): preserve Windows shell PATH priority (pingdotgg#8748) * fix(web): make WSL settings searchable (pingdotgg#8881) * feat(web): add expand/collapse all control to the files surface (pingdotgg#8889) * Add auto_review configuration to coderabbit.yaml * style: format CodeRabbit configuration * feat(mobile): upload attachments while composing (pingdotgg#8978) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(chat): keep agent activity visible between actions (pingdotgg#8984) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(server): isolate remote web session cookies (pingdotgg#8085) Co-authored-by: Julius Marminge <julius0216@outlook.com> * feat(pull-requests): link GitHub references in markdown (pingdotgg#8812) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * perf(server): reduce frequency of full tool call output being loaded into memory from db (pingdotgg#8988) * feat(web): add pull request list filters (pingdotgg#8809) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * feat(web): search individual settings by detail (pingdotgg#8831) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * feat(client): render viewed images in work logs (pingdotgg#8936) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(client): use package import for markdown image helpers (pingdotgg#9010) * test: remove static presentation snapshots (pingdotgg#9008) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> * perf(server): bound snapshot activity payload memory (pingdotgg#9000) * perf(server): cut idle CPU use and stop provider event leaks (pingdotgg#8187) * perf(server): scan only appended transcript bytes for usage summaries (pingdotgg#9024) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Theo Browne <me@t3.gg> * perf(server): cut chatty tool-update frames by 90% (pingdotgg#8368) * fix(server): settle threads server-side (pingdotgg#8600) * fix(clients): dedupe skills in composer menus (pingdotgg#8043) * fix(server): stop OpenCode child sessions (pingdotgg#9005) * perf(web): defer pull request line stats until visible (pingdotgg#6471) Co-authored-by: Theo Browne <me@t3.gg> * perf(server): skip full-message reads while streaming (pingdotgg#9032) * perf(client-runtime): halve server config bootstrap traffic (pingdotgg#8367) Reuse one server config subscription for session bootstrap and live updates. Preserve environment theme opt-in, replay, deletion, slow subscriber recovery, and config stream failure handling. Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com> * fix(web): align un-settle banner action (pingdotgg#9033) * fix(web): block type-to-focus behind open dialogs (pingdotgg#8139) Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com> * feat(shortcuts): copy active thread reference (pingdotgg#8994) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(mobile): keep thread scroll bounds current after animations (pingdotgg#9013) Co-authored-by: Julius Marminge <julius@mac.lan> * fix(server): cache project favicon resolution (pingdotgg#9080) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(claude): add Claude Fable 5.1 model (pingdotgg#9078) * fix(preview): restore recording and macOS rendering after Electron 43 (pingdotgg#9001) Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com> * feat(desktop): add configurable quit shortcut confirmation (pingdotgg#9076) * feat(web): open project settings from thread menus (pingdotgg#8925) * fix(chat): reuse one row for live activity (pingdotgg#9062) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * feat(models): discover Claude models from remote manifest (pingdotgg#9084) * Revert "fix(chat): reuse one row for live activity" (pingdotgg#9096) * fix(web): sync sidebar PR state from open panel (pingdotgg#9092) Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com> * fix(web): changing projects no longer creates a draft (pingdotgg#9097) * fix(web): keep theme placeholder text dimmer than entered text (pingdotgg#9104) * fix(web): keep the selected environment when changing projects (pingdotgg#9102) * docs(plans): t3o-31 upstream sync to v0.0.38 * fix(board): clear the ten pre-existing typecheck errors before the upstream sync (t3o-31 P0) Two test fakes failed with a bare Error in the Effect failure channel, a closure-assigned let narrowed to never, and a single-override pill read overriddenRows[0] under noUncheckedIndexedAccess. None changed behaviour; they were masked because the recursive typecheck never reached apps/server. * fix(sync): the three type errors and two test failures the v0.0.38 merge caused - BoardModelRow reads planModeEnabled from client settings, as the composer does. - findBranchPullRequest resolves the default branch for upstream's widened PR cache key instead of passing null. - The orphaned-session integration test mocks the supervisor reactor that the startup seam yields (new inventory row). - The projection resume test seeds board projector watermarks into boards.projection_state, where t3o-26 reads them, and asserts over the union. - searchSettings("work") now also matches upstream's worktree/network items. * refactor(board): native title attributes become BoardHint tooltips Upstream's new no-native-title-tooltip rule flags every intrinsic-element title= in the board (61 sites). BoardHint wraps the styled Tooltip primitive and renders its child as the trigger, so layout is unchanged; a nullish label renders the child alone. * docs(seams): record the v0.0.38 sync (t3o-31) Merge-log row, the decisions taken (plans stay tracked, upstream's settlement reactor accepted after audit, projector-enumeration policy, launcher protocol note), an unmarked-edits debt table for the next sync, a marker census, the three new upstream workflows to disable, and the runbook's per-package verification notes. * review(t3o-31): announce the board's status dots, and order the merge log Round-1 nitpicks: a bare span's aria-label is not announced, so the working, running and awaiting dots now carry role="img"; the v0.0.38 merge-log row moves below the two 2026-08-09 rows so the table reads chronologically. --------- Co-authored-by: Theo Browne <me@t3.gg> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com> Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com> Co-authored-by: abcdmku <63693423+abcdmku@users.noreply.github.com> Co-authored-by: Guilherme Barros <gbarros1095@gmail.com> Co-authored-by: Rishet11 <154429365+Rishet11@users.noreply.github.com> Co-authored-by: Alex <me@pixp.cc> Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com> Co-authored-by: Naveed Iqbal <naveediqbal949@gmail.com> Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com> Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com> Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com> Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com> Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com> Co-authored-by: Simone <lucenz@proton.me> Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com> Co-authored-by: Tristan Knight <admin@snappeh.com> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Pavlo Trinko <paul.trinko95@gmail.com> Co-authored-by: codex <codex@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: Rodrigo Brechard <rodrigobrechard@gmail.com> Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr> Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com> Co-authored-by: spiky02plateau <155588579+spiky02plateau@users.noreply.github.com> Co-authored-by: Carlos Jimenez <cjimenez@r21digital.com> Co-authored-by: Mark Griffin <mrmg@deflexion.net> Co-authored-by: MacKinley Smith <smithmackinley@gmail.com> Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com> Co-authored-by: mweinbach <maxweinbach5@gmail.com> Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com> Co-authored-by: Mohtasham Murshid <154406804+MohtashamMurshid@users.noreply.github.com> Co-authored-by: Dara Adedeji <daraaded@amazon.com> Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com> Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com> Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com> Co-authored-by: PC <pc@localhost> Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com> Co-authored-by: Josh <gitlucky@pipelab.org> Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Ivan Malison <IvanMalison@gmail.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com> Co-authored-by: Julius Marminge <julius@mac.lan> Co-authored-by: Illia Panasenko <hello@ipanasenko.me> Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com> Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live> Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com> Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com> Co-authored-by: Ryan Hughes <ryan@heyoodle.com> Co-authored-by: Vitaly Iegorov <vitalyiegorov@gmail.com> Co-authored-by: Ahmed Besic <ahmed.besic2000@gmail.com> Co-authored-by: maria <maria@kuuro.net> Co-authored-by: Matthew Feroz <136640686+MatthewFeroz@users.noreply.github.com> Co-authored-by: Julius Marminge <jmarminge@gmail.com> Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com> Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com> Co-authored-by: Will Sheldon <will@autimo.com> Co-authored-by: mic <85814106+q1@users.noreply.github.com> Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>


What Changed
Two changes, both needed for an OAuth popup to work in the integrated browser preview.
apps/web/src/browser/HostedBrowserWebview.tsxsetsallowpopupsas an attribute on the<webview>element instead of from the ref callback. Electron reads that flag when the guest attaches, and the ref callback runs after the element is already in the DOM, so every preview guest attached with popups disabled.apps/desktop/src/preview/Manager.tsreads thedispositionthe window-open handler already received. Anew-windowdisposition with an http or https URL now opens a real window; everything else,target="_blank"links included, keeps loading in the preview tab as before. The popup is created withcontextIsolation,sandbox, andnodeIntegration: falseset explicitly, since a popup is not a webview attach and never passes thewill-attach-webviewhardening inDesktopWindow. It also gets a deny-only window-open handler of its own, so a page inside it cannot spawn native windows without limit.about:blankpopups keep loading in the preview tab: Chromium copies the guest preferences for them and gives no way to override.Why
A local app opened in the preview cannot finish an OAuth popup flow. Firebase
signInWithPopup(auth, new GoogleAuthProvider())reportsauth/popup-blockedand no window appears, while the same app works in a normal Chrome or Firefox window.Two separate causes stack up.
window.openwas denied and the URL was force-loaded into the same webContents, sowindow.open()returnednull(the SDK reads that as a blocked popup) and the in-tab load destroyed the opener the popup needs topostMessageits credential back to. Underneath that, the guest attached withallowpopupsfalse, so Electron blocked the call before the handler ran at all.Instrumenting
will-attach-webviewin a running desktop build showed it directly:Surfaces
Desktop only in behavior. The
<webview>element lives inapps/webbecause the desktop app wraps the web client, but the tag only exists inside Electron and remote web previews never reachsetWindowOpenHandler. No contract, provider, or docs change.UI Changes
No layout, styling, or motion changed. The observable difference is whether a popup window exists, captured below in a dev build against a local page that calls
window.open(url, name, "width=520,height=640"), the same shapesignInWithPopupuses.Before
window.open()returns null and no window opens.After
window.open()returns a window handle.The popup window itself, sized from the requested window features:
Verification
Run in a dev desktop build (
dev:desktop) with the preview open on a local page:window.open(...)returns a handle. Handler loggeddisposition: "new-window"and decidedpopup.window.openerpresent andtypeof require === "undefined", so the opener survives and the hardening applied.window.openfrom inside the popup returnsnull.target="_blank"link logsdisposition: "foreground-tab", decidesnavigate, and loads in the preview tab.previewWindowOpenActionhas focused unit tests next toisPreviewRefreshShortcut, the existing pure helper in the same file.Checks run locally:
vp test run apps/desktop/src/preview/Manager.test.ts— 66 passedtsgo --noEmitinapps/webandapps/desktop— cleanvp lintandvp fmt --checkon the changed files — cleanThe attach-timing half is not unit-testable in a meaningful way. A rendered-DOM assertion passes either way, because the ref callback does set the attribute, just too late for Electron to read it.
Checklist
Fixes#6561
Written with Claude Opus 5 in Claude Code.
Note
Medium Risk
Changes preview navigation and spawns hardened native windows from third-party pages; security-sensitive but scoped to http/https scripted popups with explicit hardening and nested popup denial.
Overview
Fixes OAuth and other scripted
window.openflows in the integrated browser preview by enabling popups at attach time and opening real windows when appropriate instead of navigating the preview tab.HostedBrowserWebviewsetsallowpopups="true"on the<webview>element at render time (not in a ref callback), so Electron sees it before the guest attaches.PreviewManageraddspreviewWindowOpenAction: scripted popups (new-window+http:/https:) are allowed as separateBrowserWindows withcontextIsolation,sandbox, and no Node integration;target="_blank"and non-hardenable URLs (about:blank,file:,javascript:, etc.) still load in the preview tab. Child OAuth windows get a deny-allsetWindowOpenHandlerviadid-create-window.Unit tests cover the new helper’s popup vs navigate decisions.
Reviewed by Cursor Bugbot for commit 3f60be1. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Fix OAuth popups in desktop browser preview with hardened
window.openhandlingpreviewWindowOpenActionin Manager.ts to classifywindow.openrequests: http/https scripted popups return'popup'and open as realBrowserWindows;target=_blanktabs and disallowed/invalid schemes (about, javascript, file, vscode) return'navigate'and load in the existing preview tab.webPreferences(contextIsolation: true,nodeIntegration: false,sandbox: true) and deny furtherwindow.opencalls from within them.<webview>element reliably gets theallowpopupsattribute at attach time.setWindowOpenHandlernow receives fulldetailsand usesdetails.urlinstead of bareurl; non-http(s) URLs that previously may have opened as popups now navigate the current tab instead.Macroscope summarized 3f60be1.