fix(desktop): oauth popups open from the browser preview - #8435

Merged
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups
Aug 28, 2026
Merged

fix(desktop): oauth popups open from the browser preview#8435
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups

Conversation

@walid-baharwal

@walid-baharwalwalid-baharwal commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

What Changed

Two changes, both needed for an OAuth popup to work in the integrated browser preview.

apps/web/src/browser/HostedBrowserWebview.tsx sets allowpopups as an attribute on the <webview> element instead of from the ref callback. Electron reads that flag when the guest attaches, and the ref callback runs after the element is already in the DOM, so every preview guest attached with popups disabled.

apps/desktop/src/preview/Manager.ts reads the disposition the window-open handler already received. A new-window disposition with an http or https URL now opens a real window; everything else, target="_blank" links included, keeps loading in the preview tab as before. The popup is created with contextIsolation, sandbox, and nodeIntegration: false set explicitly, since a popup is not a webview attach and never passes the will-attach-webview hardening in DesktopWindow. It also gets a deny-only window-open handler of its own, so a page inside it cannot spawn native windows without limit. about:blank popups keep loading in the preview tab: Chromium copies the guest preferences for them and gives no way to override.

Why

A local app opened in the preview cannot finish an OAuth popup flow. Firebase signInWithPopup(auth, new GoogleAuthProvider()) reports auth/popup-blocked and no window appears, while the same app works in a normal Chrome or Firefox window.

Two separate causes stack up. window.open was denied and the URL was force-loaded into the same webContents, so window.open() returned null (the SDK reads that as a blocked popup) and the in-tab load destroyed the opener the popup needs to postMessage its credential back to. Underneath that, the guest attached with allowpopups false, so Electron blocked the call before the handler ran at all.

Instrumenting will-attach-webview in a running desktop build showed it directly:

[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":false} before
[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":true} after

Surfaces

Desktop only in behavior. The <webview> element lives in apps/web because the desktop app wraps the web client, but the tag only exists inside Electron and remote web previews never reach setWindowOpenHandler. No contract, provider, or docs change.

UI Changes

No layout, styling, or motion changed. The observable difference is whether a popup window exists, captured below in a dev build against a local page that calls window.open(url, name, "width=520,height=640"), the same shape signInWithPopup uses.

Before

window.open() returns null and no window opens.

Before: popup blocked

After

window.open() returns a window handle.

After: popup opens

The popup window itself, sized from the requested window features:

After: the popup window

Verification

Run in a dev desktop build (dev:desktop) with the preview open on a local page:

  • Scripted popup: window.open(...) returns a handle. Handler logged disposition: "new-window" and decided popup.
  • The popup reports window.opener present and typeof require === "undefined", so the opener survives and the hardening applied.
  • A nested window.open from inside the popup returns null.
  • A target="_blank" link logs disposition: "foreground-tab", decides navigate, and loads in the preview tab.
  • previewWindowOpenAction has focused unit tests next to isPreviewRefreshShortcut, the existing pure helper in the same file.

Checks run locally:

  • vp test run apps/desktop/src/preview/Manager.test.ts — 66 passed
  • tsgo --noEmit in apps/web and apps/desktop — clean
  • vp lint and vp fmt --check on the changed files — clean

The attach-timing half is not unit-testable in a meaningful way. A rendered-DOM assertion passes either way, because the ref callback does set the attribute, just too late for Electron to read it.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • Before/after evidence included

Fixes#6561

Written with Claude Opus 5 in Claude Code.


Note

Medium Risk
Changes preview navigation and spawns hardened native windows from third-party pages; security-sensitive but scoped to http/https scripted popups with explicit hardening and nested popup denial.

Overview
Fixes OAuth and other scripted window.open flows in the integrated browser preview by enabling popups at attach time and opening real windows when appropriate instead of navigating the preview tab.

HostedBrowserWebview sets allowpopups="true" on the <webview> element at render time (not in a ref callback), so Electron sees it before the guest attaches.

PreviewManager adds previewWindowOpenAction: scripted popups (new-window + http:/https:) are allowed as separate BrowserWindows with contextIsolation, sandbox, and no Node integration; target="_blank" and non-hardenable URLs (about:blank, file:, javascript:, etc.) still load in the preview tab. Child OAuth windows get a deny-all setWindowOpenHandler via did-create-window.

Unit tests cover the new helper’s popup vs navigate decisions.

Reviewed by Cursor Bugbot for commit 3f60be1. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix OAuth popups in desktop browser preview with hardened window.open handling

  • Adds previewWindowOpenAction in Manager.ts to classify window.open requests: http/https scripted popups return 'popup' and open as real BrowserWindows; target=_blank tabs and disallowed/invalid schemes (about, javascript, file, vscode) return 'navigate' and load in the existing preview tab.
  • New popup windows use hardened webPreferences (contextIsolation: true, nodeIntegration: false, sandbox: true) and deny further window.open calls from within them.
  • Fixes HostedBrowserWebview.tsx so the <webview> element reliably gets the allowpopups attribute at attach time.
  • Behavioral Change: setWindowOpenHandler now receives full details and uses details.url instead of bare url; non-http(s) URLs that previously may have opened as popups now navigate the current tab instead.

Macroscope summarized 3f60be1.

@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e56baf0c-bdec-4082-8fa9-d71789606066

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 27, 2026
Scripted `window.open` calls inside the integrated browser preview were denied
and loaded in the preview tab instead. Firebase `signInWithPopup` got a null
window handle back and reported `auth/popup-blocked`, and the in-tab load also
dropped the opener the popup needs to post the credential back to.
Popups with a `new-window` disposition and an http or https URL now get a real
window, with context isolation and the sandbox turned back on: a popup is not a
webview attach, so the `will-attach-webview` hardening never sees it and an
unoverridden child would inherit the picker preload's relaxed posture.
`about:blank` popups keep loading in the preview tab, since Chromium copies the
guest preferences for them and forbids overriding. Links with `target="_blank"`
are unchanged.
Fixespingdotgg#6561
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from e598878 to 8fa05aeCompareAugust 27, 2026 18:16
Comment threadapps/desktop/src/preview/Manager.ts
Comment threadapps/desktop/src/preview/Manager.ts
An allowed popup carried Electron's default window-open behavior, so a page
inside it could spawn native windows without limit. The popup now denies its
own window.open calls; no OAuth flow opens a second popup.
The popup preferences also drop nodeIntegrationInSubFrames, matching the three
keys every other hardened window in the app sets.
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from d2ce056 to 7c5b69aCompareAugust 27, 2026 18:31
Electron reads allowpopups when the guest attaches. The attribute was set from
the ref callback, which runs after the element is in the DOM, so every preview
guest attached with popups disabled and Electron blocked window.open before the
window-open handler ran.
Verified in a running desktop build: will-attach-webview reported
allowpopups: false before this change and true after.
@walid-baharwal
walid-baharwal marked this pull request as ready for review August 27, 2026 22:31

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding in the web scope: the new allowpopups JSX attribute is the right ownership fix, but its string value conflicts with React's element typing, so apps/web typecheck (tsgo --noEmit) breaks. Details inline.

Posted via Macroscope — UI Consistency

Comment threadapps/web/src/browser/HostedBrowserWebview.tsx Outdated

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

nodeIntegration: false,
sandbox: true,
},
} satisfies Electron.BrowserWindowConstructorOptions;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Popup may inherit picker preload

High Severity

POPUP_WINDOW_OPTIONS overrides isolation flags but never clears preload. Electron merges overrideBrowserWindowOptions with the guest's preferences, so the picker preload can still run in the OAuth window and observe keystrokes and clicks on a third-party login page.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I could not reproduce this one, so I am leaving the code as is. Details, in case I tested the wrong thing.

A popup opened from a webview guest does not inherit the guest's preload, with or without overrideBrowserWindowOptions. I checked with a standalone Electron 41.5.0 app that mirrors the preview setup: a <webview allowpopups> with a preload and contextIsolation=false, whose preload announces itself over IPC on load, then window.open(...) from inside the guest.

The preload reports from the guest and never from the popup:

RESULT preload-ran in: http://127.0.0.1:8899/popup-repro.html
RESULT popup created:

Same result with the override removed, and same with data: and http: popup URLs, so the override is not what is clearing it — the inheritance does not happen in the first place.

One thing worth flagging for anyone reading this later: webContents.getLastWebPreferences() does not report preload at all. It omits the key even for the guest, which definitely has one, so it cannot be used to check this.

If you have a case where the preload does reach the popup, I would like to see it — the exposure you describe would be real, since that preload listens for keydown and pointerdown.

@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR changes production preview behavior by enabling OAuth popup windows and altering Electron renderer security boundaries across the desktop and webview layers. An unresolved security concern about the preview preload potentially reaching third-party OAuth pages still requires validation.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

React types allowpopups as boolean, so the string literal failed apps/web's
tsgo --noEmit. Passing a real boolean typechecks but regresses the fix, since
react-dom drops boolean values for unrecognized attributes and sets nothing,
so the guest would attach with popups disabled again.
Verified after the change: the element carries allowpopups="true" and a
scripted window.open returns a window handle.
@MatthewFeroz

Copy link
Copy Markdown
Contributor

hoping this gets merged!

@MatthewFeroz

Copy link
Copy Markdown
Contributor

I double-checked the preload concern in Electron 41.5.0 and tested it myself. The preview’s preload script ran only inside the preview, not inside the popup. Electron’s code also confirms that preload scripts are not copied into new windows. This matches the author’s test, so I don’t think the Cursor warning is a real issue.

@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Status summary, since the Approvability verdict above predates the current head and reads as the most visible signal on this PR.

That verdict was posted at 8fa05ae and gives one reason: the preview picker preload may still execute in the popup and observe input. Two independent checks say it does not.

I tested it with a standalone Electron 41.5.0 app mirroring the preview setup — a <webview allowpopups> with a preload and contextIsolation=false, the preload announcing itself over IPC. It reports from the guest and never from the popup, with and without overrideBrowserWindowOptions, for both data: and http: popup URLs. @MatthewFeroz reproduced this independently and additionally checked Electron's source, which does not copy preload scripts into new windows.

Worth flagging for anyone testing this themselves: webContents.getLastWebPreferences() omits preload entirely, even for a webContents that has one, so it cannot be used to check this.

The popup is also created with contextIsolation: true, sandbox: true, nodeIntegration: false — verified at runtime as typeof require === "undefined" inside it — and denies its own window.open, so it cannot spawn further windows.

Current head is 8db8d83. All checks green, including Macroscope UI Consistency after the typing fix. Locally: 66 tests in Manager.test.ts pass, tsgo --noEmit clean for apps/web and apps/desktop, lint and format clean on the changed files.

No action needed from me unless something new turns up.

@MatthewFeroz

Copy link
Copy Markdown
Contributor

Just sent a video to the maintainers of this working. Small limitation in this is that passkeys don't function but I think that's out of scope for this PR. Great work!

@juliusmarminge
juliusmarminge merged commit 0e2905e into pingdotgg:mainAug 28, 2026
22 checks passed
@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Thanks for running it and recording the video — I could not produce one myself, so that fills the gap CONTRIBUTING asks for on interaction changes.

On passkeys: that is pre-existing and tracked separately in #5665 ("In app browser not triggering passkey fingerprint to sign in on mac", open since 2026-08-07), so it predates this branch. Nothing here touches WebAuthn — the change only decides whether window.open gets a real window and what preferences that window is created with. A passkey prompt failing inside the preview fails the same way on main today, with or without a popup involved.

So I agree it is out of scope, and I would rather not widen this PR to chase it.

github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Aug 29, 2026
## What's Changed
* fix(grok): improve skills, plans, usage, and turn reliability by @t3dotgg in pingdotgg/t3code#8358
* fix(server): recover stale Codex approval callbacks by @luckyPipewrench in pingdotgg/t3code#5195
* test(server): remove duplicate missing worktree test by @t3-code[bot] in pingdotgg/t3code#8252
* fix(server): replay all un-applied events during projection bootstrap by @krutftw in pingdotgg/t3code#7538
* test: remove low-signal test files by @t3-code[bot] in pingdotgg/t3code#8397
* test: prune trivial error and layout tests by @t3-code[bot] in pingdotgg/t3code#8400
* Fix Android adaptive launcher icon by @colonelpanic8 in pingdotgg/t3code#4332
* feat(web): split provider settings into list and editor by @t3dotgg in pingdotgg/t3code#8380
* fix(codex): accept Codex 0.150 account plans by @gsimone in pingdotgg/t3code#8447
* fix(tooling): allow ignored-only staged changes by @juliusmarminge in pingdotgg/t3code#8468
* fix(mobile): keep iOS home header stable by @juliusmarminge in pingdotgg/t3code#8467
* fix(web): stop showing red x summaries for ordinary tool failures by @t3dotgg in pingdotgg/t3code#8395
* fix(mobile): refine Git action toast glass styling by @juliusmarminge in pingdotgg/t3code#8399
* fix(desktop): allow preview automation in agent-created threads by @t3dotgg in pingdotgg/t3code#8483
* test(web): remove redundant cache key test by @t3-code[bot] in pingdotgg/t3code#8484
* fix(release): move nightly schedule to minute 38 by @t3dotgg in pingdotgg/t3code#8509
* fix(web): stabilize the provider settings editor by @t3dotgg in pingdotgg/t3code#8472
* fix(web): open GitHub pull requests in browser when loading fails by @t3dotgg in pingdotgg/t3code#8507
* fix(codex): show sub-agent models by @t3dotgg in pingdotgg/t3code#8502
* feat(analytics): report connected client platforms by @t3dotgg in pingdotgg/t3code#8481
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB by @t3dotgg in pingdotgg/t3code#8235
* feat(web): toggle a thread's pin from the keyboard by @ipanasenko in pingdotgg/t3code#8440
* fix(web): add back button to project settings by @StiensWout in pingdotgg/t3code#8168
* refactor(mobile): compile semantic themes for Uniwind by @juliusmarminge in pingdotgg/t3code#7327
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times by @ikifar2012 in pingdotgg/t3code#5769
* fix(mobile): show OpenCode model sources in picker by @juliusmarminge in pingdotgg/t3code#8573
* fix(clients): honor project default models in new threads by @anirudhsama in pingdotgg/t3code#6011
* fix(mobile): show file actions on Android by @none23 in pingdotgg/t3code#8215
* fix(connect): explain DPoP connection failures by @extoci in pingdotgg/t3code#8351
* feat(web): make the sidebar project filter a searchable combobox by @SunkenInTime in pingdotgg/t3code#5931
* fix(server): a draft can retry its first send after a failed bootstrap by @shivamhwp in pingdotgg/t3code#8226
* fix(desktop): stop hidden previews draining battery by @Bil0000 in pingdotgg/t3code#8567
* fix(desktop): oauth popups open from the browser preview by @walid-baharwal in pingdotgg/t3code#8435
* fix(web): keep long task drawers usable on small screens by @shivamhwp in pingdotgg/t3code#8313
* fix(opencode): handle child approvals, stops, and model catalogs by @t3dotgg in pingdotgg/t3code#8480
* fix: make thread auto-settling opt-in by @shivamhwp in pingdotgg/t3code#8321
* fix(web): stop session activity timing test from blocking releases by @t3dotgg in pingdotgg/t3code#8585
* fix(mobile): show composer menus when starting a task by @juliusmarminge in pingdotgg/t3code#8587
* fix(web): show the configured stash shortcut by @UtkarshUsername in pingdotgg/t3code#8437
* feat(web): add toggleable confirmation before unpinning a thread by @UtkarshUsername in pingdotgg/t3code#7313
* fix: restore automatic thread settling defaults by @t3dotgg in pingdotgg/t3code#8596
* fix(mobile): restore composer glass and rounded shadows by @juliusmarminge in pingdotgg/t3code#8597
## New Contributors
* @luckyPipewrench made their first contribution in pingdotgg/t3code#5195
* @krutftw made their first contribution in pingdotgg/t3code#7538
* @colonelpanic8 made their first contribution in pingdotgg/t3code#4332
* @ikifar2012 made their first contribution in pingdotgg/t3code#5769
* @walid-baharwal made their first contribution in pingdotgg/t3code#8435
**Full Changelog**: pingdotgg/t3code@v0.0.35...v0.0.36
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.36
aaditagrawal added a commit to aaditagrawal/t3code that referenced this pull request Aug 29, 2026
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
bcotrim pushed a commit to bcotrim/mognet that referenced this pull request Aug 30, 2026
)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
(cherry picked from commit 0e2905e)
brentkelly added a commit to brentkelly/t3code-orchestrator that referenced this pull request Sep 2, 2026
* feat(analytics): threads and turns now know which client started them (pingdotgg#7774)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop marking mixed tool runs as failed (pingdotgg#7893)
* fix(web): command-click spaced folder links (pingdotgg#6439)
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(chat): stop pushing follow-up messages to the top (pingdotgg#7897)
* test(desktop): remove redundant release note assertion (pingdotgg#7873)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): handle wide ordered-list marker edge cases (pingdotgg#7856)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(ssh): restore user PATH for remote servers (pingdotgg#7213)
* fix(desktop): keep tailscale spawn defects from breaking advertised endpoints (pingdotgg#7116)
* fix(web): keep Codex service tier labels readable (pingdotgg#4503)
* fix: render workspace images in chat markdown (pingdotgg#6433)
* fix(clients): keep opening responses visible after turns settle (pingdotgg#7723)
* feat(web): add appearance contrast control (pingdotgg#7906)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop completed Codex threads from staying stuck on working (pingdotgg#7937)
* fix(mobile): preserve markdown image dimensions (pingdotgg#7940)
* fix(web): remove duplicate provider update progress (pingdotgg#7761)
* fix(server): fall back to the remote default branch instead of assuming main (pingdotgg#7078)
* fix(web): give sidebar project menu rows the same side padding as other menus (pingdotgg#7913)
* fix(clients): reconnect after credentials fail during remote server updates (pingdotgg#7953)
* feat(codex): submit thread feedback to OpenAI (pingdotgg#7949)
* fix(server): stop kills lingering Claude work (pingdotgg#5891)
* fix(ci): let Macroscope approve pull requests again (pingdotgg#7970)
* fix(clients): move settled pinned threads into the settled section (pingdotgg#7969)
* perf(ci): speed up release builds and Windows packaging (pingdotgg#7975)
* fix(web): stop tool calls from leaving a blank page in threads (pingdotgg#7971)
* fix(web): stop recovered tool failures from marking work logs red (pingdotgg#7999)
* fix(mobile): isolate markdown image requests (pingdotgg#7942)
* feat(web): redesign skills in `$` menu and in `/` menu (pingdotgg#8009)
* fix(web): restore right panel toggle clicks after closing on desktop (pingdotgg#8016)
* fix(web): keep server update banners flush with the composer (pingdotgg#8000)
* perf(web): reuse work log rows during streaming (pingdotgg#8006)
* fix(web): keep provider badge legible in dark themes (pingdotgg#7968)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): treat configured urls with uppercase schemes as secure (pingdotgg#8005)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(desktop): keep release notes visible while downloading (pingdotgg#6412)
* fix(web): show only providers with usage in usage views (pingdotgg#7563)
* fix(web): prevent expanded tool calls from hiding thread content (pingdotgg#8052)
* test(server): remove no-op live activity tests (pingdotgg#8056)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): clarify terminal sidebar grouping (pingdotgg#7967)
* fix(codex): show app access approval prompts (pingdotgg#8058)
* feat(web): upload image attachments before sending (pingdotgg#8048)
* fix(server): bound OpenCode skill discovery output (pingdotgg#7675)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(mobile): persist thread shelf collapse state (pingdotgg#5152)
* fix(mobile): restore Android tablet thread controls, clean up header (pingdotgg#5385)
* fix(mobile): land the first thread open above the composer on Android (pingdotgg#5585)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(server): check out submodules in a new worktree (pingdotgg#7674)
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
* fix(server): preserve merged PR badges after branch deletion (pingdotgg#6216)
* fix(server): return fresh live pull request reads (pingdotgg#6472)
* fix(web): compare client and server versions as semver, not strings (pingdotgg#7579)
* fix(web): stop follow-ups from leaving giant blank space (pingdotgg#8068)
* fix(marketing): stop automatic Vercel deployments on pull requests (pingdotgg#8070)
* chore: vouch repeat contributors (pingdotgg#8071)
* fix(server): keep the authoritative subagent model when snapshots race task_started (pingdotgg#7583)
* fix(server): honor auto-accept edits for the OpenCode provider (pingdotgg#7100)
* fix(server): run the CLI on Node versions without import.meta.main (pingdotgg#7141)
* fix(server): recover from provider interrupt failures (pingdotgg#7412)
* fix(server): recreate a thread's worktree before starting a turn (pingdotgg#7839)
* fix(server): thread delete no longer fails on already-removed worktrees (pingdotgg#8076)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop update notices showing through the composer (pingdotgg#8083)
* fix(web): detect outdated nightly servers (pingdotgg#8124)
* fix(web): align usage page skeleton layout (pingdotgg#8111)
* fix(web): make terminal links appear clickable only when clickable (pingdotgg#7488)
* fix(web): make Windows file links clickable in chat (pingdotgg#8081)
* fix(web): sort usage models by token count (pingdotgg#8108)
* fix: open agent file links in the file viewer (pingdotgg#8098)
* fix(server): stop routine events from rescanning thread history (pingdotgg#8150)
* fix(deps): stop pnpm installs from changing the lockfile (pingdotgg#8163)
* feat(web): settle and restore threads with a keyboard shortcut (pingdotgg#8089)
* perf(desktop): cut macOS signing calls by 81% (pingdotgg#8093)
* feat: link pull requests to threads (pingdotgg#8160)
* feat(web): safely attach HEIC photos as JPEG images (pingdotgg#8161)
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
* feat(mobile): track device models and OS versions (pingdotgg#8169)
* fix(grok): bound cumulative tool output updates (pingdotgg#7279)
* fix(web): delay thread shortcut hints by 200 ms (pingdotgg#8172)
* fix(server): stop probing Cursor until enabled (pingdotgg#8175)
* docs(release): verify remote updates with database migrations (pingdotgg#8177)
* fix(server): keep provider CLIs available in the macOS service (pingdotgg#8173)
* feat(claude): compact old threads before they burn through usage (pingdotgg#8144)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(client-runtime): retry queries after connection interruption (pingdotgg#8117)
* fix(server): keep previously used providers working after upgrades (pingdotgg#8176)
* feat(desktop): build macOS previews from a PR label (pingdotgg#8182)
* fix(web): thread jump hints no longer stick after a dictation paste (pingdotgg#8189)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): keep grouped project renames (pingdotgg#7831)
* feat(web): reveal chat file chips in the system file manager (pingdotgg#7140)
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(server): push no longer writes a feature branch's commits to its base branch (pingdotgg#8228)
* chore(deps): bump @clerk/electron to 0.0.37 (pingdotgg#8240)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(server): fetch legacy model classification from a hosted manifest (pingdotgg#8227)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* chore(release): prepare v0.0.34
* fix(desktop): let Clerk UI receive stable auth fixes (pingdotgg#8248)
* fix(app): un-settled threads return to the top of the list (pingdotgg#8231)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* perf(ci): cut about a minute from every release (pingdotgg#8250)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(ci): download macOS preview DMGs without signing in (pingdotgg#8243)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(codex): accept Codex 0.150 multi-agent events (pingdotgg#8346)
* chore(release): prepare v0.0.35
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
* Require human review for pull requests changing product defaults (pingdotgg#8603)
* fix(codex): avoid quadratic app-server input buffering (pingdotgg#8605)
* fix(mobile): stabilize iOS header item transitions (pingdotgg#8607)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(mobile): upgrade to Expo SDK 57 (pingdotgg#8609)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(mobile): harden native header toolbar items (pingdotgg#8611)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): stop querying Claude context usage after turns (pingdotgg#8610)
* chore: vouch ryanrhughes (pingdotgg#8613)
* feat(web): attach PDFs, ZIPs, and other files to a turn (pingdotgg#8236)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): pass stashShortcutLabel in the mixed-attachments stash test
PRs pingdotgg#8437 and pingdotgg#8236 crossed: one made stashShortcutLabel a required
ComposerStashMenu prop, the other added a test case without it, so
main fails web typecheck.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat(web): keybinding settings as settings rows (pingdotgg#8532)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat: let an environment publish themes as a file (pingdotgg#8569)
Co-authored-by: Theo Browne <me@t3.gg>
* fix(web): clean up provider settings list and editor (pingdotgg#8504)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep project picker popup inside the sidebar (pingdotgg#8627)
* fix(mobile): prevent header overflow and back-button artifacts (pingdotgg#8624)
* fix(server): retry automatic thread title generation (pingdotgg#8087)
* fix(client-runtime): refresh edited pull request comments (pingdotgg#8094)
* fix(web): four composer spacing defects (pingdotgg#8090)
* perf(desktop): skip duplicate browser updates (pingdotgg#8018)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): render nested markdown images correctly (pingdotgg#8501)
* fix(web): unify activity logs and composer banners (pingdotgg#8693)
* fix(mobile): reduce dev-client reload and Metro startup cost (pingdotgg#8694)
Co-authored-by: Julius Marminge <julius@mac.lan>
* revert(web): restore previous composer banners (pingdotgg#8733)
* test(web): remove tests for unreachable helpers (pingdotgg#8738)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* feat(mobile): update tool summaries and chat transitions (pingdotgg#8793)
* feat(web): play video attachments in chat (pingdotgg#8688)
* fix(web,mobile): snooze menu no longer offers the same wake time twice (pingdotgg#8741)
* fix(grok): allow model changes in existing threads (pingdotgg#8392)
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
* feat(mobile): pick, share, and receive files in threads (pingdotgg#8237)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): reduce title bar scroll fade height (pingdotgg#8799)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(windows): strip quotes from repaired PATH (pingdotgg#8746)
* fix(web): open agent images in expanded preview (pingdotgg#8807)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(git): follow repository instructions in generated source control text (pingdotgg#8804)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop overpricing cached Claude tokens (pingdotgg#8806)
* fix(web): keep image preview above sidebar control (pingdotgg#8811)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): keep right panel synced with agent edits (pingdotgg#8803)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web,mobile): render Codex citations and artifact templates (pingdotgg#8584)
* chore: add Windows setup script to t3.json (pingdotgg#8814)
* fix(web): fold interim turn responses (pingdotgg#8828)
* fix(web): use circle alert for failed tool calls (pingdotgg#8840)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(mobile): add offline iPhone voice input (pingdotgg#8614)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent pull request metadata overlap (pingdotgg#8790)
* chore(release): prepare v0.0.37
* Add mobile composer attachment menu with video support (pingdotgg#8843)
* fix(mobile): map native menu icon colors explicitly
* fix(web): restore unified activity logs and composer banners (pingdotgg#8734)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
* fix(web): address composer banner review follow-ups (pingdotgg#8850)
* fix(web): widen sync banners and simplify the working timer (pingdotgg#8855)
* fix(preview): improve browser recording quality (pingdotgg#8839)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): mark pull request links as external (pingdotgg#8856)
* fix(mobile): replace Callstack glass with Expo glass (pingdotgg#8862)
* fix(server): skip IDE detection in Claude probes (pingdotgg#8634)
* chore(macroscope): review diagnostic overrides (pingdotgg#8917)
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* fix(contracts): accept CLI event origins (pingdotgg#8905)
* fix(web): hide invalid slash skill completions (pingdotgg#8904)
* fix(mobile): defer draft navigation until submission completes (pingdotgg#8914)
* chore: disable CodeRabbit review status (pingdotgg#8933)
* Delete app.json (pingdotgg#8934)
* fix(web): show scrollbar for wide markdown tables (pingdotgg#8868)
* fix(mobile): shimmer active tool rows (pingdotgg#8932)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(deps): bump Electron to 43.4.1 (pingdotgg#8626)
* fix(chat): smooth worktree setup status (pingdotgg#8922)
* feat(mobile): add video playback with native iOS controls (pingdotgg#8919)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent chat metadata overlap (pingdotgg#8851)
* fix(server): preserve usage cache outside walked roots (pingdotgg#8540)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(mobile): add native image and PDF previews (pingdotgg#8959)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): allow long thread IDs in HTTP routes (pingdotgg#8898)
* fix(shared): preserve Windows shell PATH priority (pingdotgg#8748)
* fix(web): make WSL settings searchable (pingdotgg#8881)
* feat(web): add expand/collapse all control to the files surface (pingdotgg#8889)
* Add auto_review configuration to coderabbit.yaml
* style: format CodeRabbit configuration
* feat(mobile): upload attachments while composing (pingdotgg#8978)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(chat): keep agent activity visible between actions (pingdotgg#8984)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): isolate remote web session cookies (pingdotgg#8085)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(pull-requests): link GitHub references in markdown (pingdotgg#8812)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* perf(server): reduce frequency of full tool call output being loaded into memory from db (pingdotgg#8988)
* feat(web): add pull request list filters (pingdotgg#8809)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(web): search individual settings by detail (pingdotgg#8831)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(client): render viewed images in work logs (pingdotgg#8936)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(client): use package import for markdown image helpers (pingdotgg#9010)
* test: remove static presentation snapshots (pingdotgg#9008)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* perf(server): bound snapshot activity payload memory (pingdotgg#9000)
* perf(server): cut idle CPU use and stop provider event leaks (pingdotgg#8187)
* perf(server): scan only appended transcript bytes for usage summaries (pingdotgg#9024)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): cut chatty tool-update frames by 90% (pingdotgg#8368)
* fix(server): settle threads server-side (pingdotgg#8600)
* fix(clients): dedupe skills in composer menus (pingdotgg#8043)
* fix(server): stop OpenCode child sessions (pingdotgg#9005)
* perf(web): defer pull request line stats until visible (pingdotgg#6471)
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): skip full-message reads while streaming (pingdotgg#9032)
* perf(client-runtime): halve server config bootstrap traffic (pingdotgg#8367)
Reuse one server config subscription for session bootstrap and live updates.
Preserve environment theme opt-in, replay, deletion, slow subscriber recovery, and config stream failure handling.
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
* fix(web): align un-settle banner action (pingdotgg#9033)
* fix(web): block type-to-focus behind open dialogs (pingdotgg#8139)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(shortcuts): copy active thread reference (pingdotgg#8994)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(mobile): keep thread scroll bounds current after animations (pingdotgg#9013)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): cache project favicon resolution (pingdotgg#9080)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(claude): add Claude Fable 5.1 model (pingdotgg#9078)
* fix(preview): restore recording and macOS rendering after Electron 43 (pingdotgg#9001)
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
* feat(desktop): add configurable quit shortcut confirmation (pingdotgg#9076)
* feat(web): open project settings from thread menus (pingdotgg#8925)
* fix(chat): reuse one row for live activity (pingdotgg#9062)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(models): discover Claude models from remote manifest (pingdotgg#9084)
* Revert "fix(chat): reuse one row for live activity" (pingdotgg#9096)
* fix(web): sync sidebar PR state from open panel (pingdotgg#9092)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): changing projects no longer creates a draft (pingdotgg#9097)
* fix(web): keep theme placeholder text dimmer than entered text (pingdotgg#9104)
* fix(web): keep the selected environment when changing projects (pingdotgg#9102)
* docs(plans): t3o-31 upstream sync to v0.0.38
* fix(board): clear the ten pre-existing typecheck errors before the upstream sync (t3o-31 P0)
Two test fakes failed with a bare Error in the Effect failure channel, a
closure-assigned let narrowed to never, and a single-override pill read
overriddenRows[0] under noUncheckedIndexedAccess. None changed behaviour;
they were masked because the recursive typecheck never reached apps/server.
* fix(sync): the three type errors and two test failures the v0.0.38 merge caused
- BoardModelRow reads planModeEnabled from client settings, as the composer does.
- findBranchPullRequest resolves the default branch for upstream's widened PR
cache key instead of passing null.
- The orphaned-session integration test mocks the supervisor reactor that the
startup seam yields (new inventory row).
- The projection resume test seeds board projector watermarks into
boards.projection_state, where t3o-26 reads them, and asserts over the union.
- searchSettings("work") now also matches upstream's worktree/network items.
* refactor(board): native title attributes become BoardHint tooltips
Upstream's new no-native-title-tooltip rule flags every intrinsic-element
title= in the board (61 sites). BoardHint wraps the styled Tooltip primitive
and renders its child as the trigger, so layout is unchanged; a nullish label
renders the child alone.
* docs(seams): record the v0.0.38 sync (t3o-31)
Merge-log row, the decisions taken (plans stay tracked, upstream's settlement
reactor accepted after audit, projector-enumeration policy, launcher protocol
note), an unmarked-edits debt table for the next sync, a marker census, the
three new upstream workflows to disable, and the runbook's per-package
verification notes.
* review(t3o-31): announce the board's status dots, and order the merge log
Round-1 nitpicks: a bare span's aria-label is not announced, so the working,
running and awaiting dots now carry role="img"; the v0.0.38 merge-log row
moves below the two 2026-08-09 rows so the table reads chronologically.
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: abcdmku <63693423+abcdmku@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: Rishet11 <154429365+Rishet11@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Naveed Iqbal <naveediqbal949@gmail.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: Tristan Knight <admin@snappeh.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Pavlo Trinko <paul.trinko95@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Rodrigo Brechard <rodrigobrechard@gmail.com>
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
Co-authored-by: spiky02plateau <155588579+spiky02plateau@users.noreply.github.com>
Co-authored-by: Carlos Jimenez <cjimenez@r21digital.com>
Co-authored-by: Mark Griffin <mrmg@deflexion.net>
Co-authored-by: MacKinley Smith <smithmackinley@gmail.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Mohtasham Murshid <154406804+MohtashamMurshid@users.noreply.github.com>
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
Co-authored-by: Vitaly Iegorov <vitalyiegorov@gmail.com>
Co-authored-by: Ahmed Besic <ahmed.besic2000@gmail.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: Matthew Feroz <136640686+MatthewFeroz@users.noreply.github.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: Will Sheldon <will@autimo.com>
Co-authored-by: mic <85814106+q1@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Integrated browser preview blocks OAuth popup authentication

3 participants

@walid-baharwal@MatthewFeroz@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(desktop): oauth popups open from the browser preview - #8435

Merged
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups
Aug 28, 2026
Merged

fix(desktop): oauth popups open from the browser preview#8435
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups

Conversation

@walid-baharwal

@walid-baharwalwalid-baharwal commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

What Changed

Two changes, both needed for an OAuth popup to work in the integrated browser preview.

apps/web/src/browser/HostedBrowserWebview.tsx sets allowpopups as an attribute on the <webview> element instead of from the ref callback. Electron reads that flag when the guest attaches, and the ref callback runs after the element is already in the DOM, so every preview guest attached with popups disabled.

apps/desktop/src/preview/Manager.ts reads the disposition the window-open handler already received. A new-window disposition with an http or https URL now opens a real window; everything else, target="_blank" links included, keeps loading in the preview tab as before. The popup is created with contextIsolation, sandbox, and nodeIntegration: false set explicitly, since a popup is not a webview attach and never passes the will-attach-webview hardening in DesktopWindow. It also gets a deny-only window-open handler of its own, so a page inside it cannot spawn native windows without limit. about:blank popups keep loading in the preview tab: Chromium copies the guest preferences for them and gives no way to override.

Why

A local app opened in the preview cannot finish an OAuth popup flow. Firebase signInWithPopup(auth, new GoogleAuthProvider()) reports auth/popup-blocked and no window appears, while the same app works in a normal Chrome or Firefox window.

Two separate causes stack up. window.open was denied and the URL was force-loaded into the same webContents, so window.open() returned null (the SDK reads that as a blocked popup) and the in-tab load destroyed the opener the popup needs to postMessage its credential back to. Underneath that, the guest attached with allowpopups false, so Electron blocked the call before the handler ran at all.

Instrumenting will-attach-webview in a running desktop build showed it directly:

[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":false} before
[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":true} after

Surfaces

Desktop only in behavior. The <webview> element lives in apps/web because the desktop app wraps the web client, but the tag only exists inside Electron and remote web previews never reach setWindowOpenHandler. No contract, provider, or docs change.

UI Changes

No layout, styling, or motion changed. The observable difference is whether a popup window exists, captured below in a dev build against a local page that calls window.open(url, name, "width=520,height=640"), the same shape signInWithPopup uses.

Before

window.open() returns null and no window opens.

Before: popup blocked

After

window.open() returns a window handle.

After: popup opens

The popup window itself, sized from the requested window features:

After: the popup window

Verification

Run in a dev desktop build (dev:desktop) with the preview open on a local page:

  • Scripted popup: window.open(...) returns a handle. Handler logged disposition: "new-window" and decided popup.
  • The popup reports window.opener present and typeof require === "undefined", so the opener survives and the hardening applied.
  • A nested window.open from inside the popup returns null.
  • A target="_blank" link logs disposition: "foreground-tab", decides navigate, and loads in the preview tab.
  • previewWindowOpenAction has focused unit tests next to isPreviewRefreshShortcut, the existing pure helper in the same file.

Checks run locally:

  • vp test run apps/desktop/src/preview/Manager.test.ts — 66 passed
  • tsgo --noEmit in apps/web and apps/desktop — clean
  • vp lint and vp fmt --check on the changed files — clean

The attach-timing half is not unit-testable in a meaningful way. A rendered-DOM assertion passes either way, because the ref callback does set the attribute, just too late for Electron to read it.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • Before/after evidence included

Fixes#6561

Written with Claude Opus 5 in Claude Code.


Note

Medium Risk
Changes preview navigation and spawns hardened native windows from third-party pages; security-sensitive but scoped to http/https scripted popups with explicit hardening and nested popup denial.

Overview
Fixes OAuth and other scripted window.open flows in the integrated browser preview by enabling popups at attach time and opening real windows when appropriate instead of navigating the preview tab.

HostedBrowserWebview sets allowpopups="true" on the <webview> element at render time (not in a ref callback), so Electron sees it before the guest attaches.

PreviewManager adds previewWindowOpenAction: scripted popups (new-window + http:/https:) are allowed as separate BrowserWindows with contextIsolation, sandbox, and no Node integration; target="_blank" and non-hardenable URLs (about:blank, file:, javascript:, etc.) still load in the preview tab. Child OAuth windows get a deny-all setWindowOpenHandler via did-create-window.

Unit tests cover the new helper’s popup vs navigate decisions.

Reviewed by Cursor Bugbot for commit 3f60be1. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix OAuth popups in desktop browser preview with hardened window.open handling

  • Adds previewWindowOpenAction in Manager.ts to classify window.open requests: http/https scripted popups return 'popup' and open as real BrowserWindows; target=_blank tabs and disallowed/invalid schemes (about, javascript, file, vscode) return 'navigate' and load in the existing preview tab.
  • New popup windows use hardened webPreferences (contextIsolation: true, nodeIntegration: false, sandbox: true) and deny further window.open calls from within them.
  • Fixes HostedBrowserWebview.tsx so the <webview> element reliably gets the allowpopups attribute at attach time.
  • Behavioral Change: setWindowOpenHandler now receives full details and uses details.url instead of bare url; non-http(s) URLs that previously may have opened as popups now navigate the current tab instead.

Macroscope summarized 3f60be1.

@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e56baf0c-bdec-4082-8fa9-d71789606066

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 27, 2026
Scripted `window.open` calls inside the integrated browser preview were denied
and loaded in the preview tab instead. Firebase `signInWithPopup` got a null
window handle back and reported `auth/popup-blocked`, and the in-tab load also
dropped the opener the popup needs to post the credential back to.
Popups with a `new-window` disposition and an http or https URL now get a real
window, with context isolation and the sandbox turned back on: a popup is not a
webview attach, so the `will-attach-webview` hardening never sees it and an
unoverridden child would inherit the picker preload's relaxed posture.
`about:blank` popups keep loading in the preview tab, since Chromium copies the
guest preferences for them and forbids overriding. Links with `target="_blank"`
are unchanged.
Fixespingdotgg#6561
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from e598878 to 8fa05aeCompareAugust 27, 2026 18:16
Comment threadapps/desktop/src/preview/Manager.ts
Comment threadapps/desktop/src/preview/Manager.ts
An allowed popup carried Electron's default window-open behavior, so a page
inside it could spawn native windows without limit. The popup now denies its
own window.open calls; no OAuth flow opens a second popup.
The popup preferences also drop nodeIntegrationInSubFrames, matching the three
keys every other hardened window in the app sets.
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from d2ce056 to 7c5b69aCompareAugust 27, 2026 18:31
Electron reads allowpopups when the guest attaches. The attribute was set from
the ref callback, which runs after the element is in the DOM, so every preview
guest attached with popups disabled and Electron blocked window.open before the
window-open handler ran.
Verified in a running desktop build: will-attach-webview reported
allowpopups: false before this change and true after.
@walid-baharwal
walid-baharwal marked this pull request as ready for review August 27, 2026 22:31

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding in the web scope: the new allowpopups JSX attribute is the right ownership fix, but its string value conflicts with React's element typing, so apps/web typecheck (tsgo --noEmit) breaks. Details inline.

Posted via Macroscope — UI Consistency

Comment threadapps/web/src/browser/HostedBrowserWebview.tsx Outdated

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

nodeIntegration: false,
sandbox: true,
},
} satisfies Electron.BrowserWindowConstructorOptions;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Popup may inherit picker preload

High Severity

POPUP_WINDOW_OPTIONS overrides isolation flags but never clears preload. Electron merges overrideBrowserWindowOptions with the guest's preferences, so the picker preload can still run in the OAuth window and observe keystrokes and clicks on a third-party login page.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I could not reproduce this one, so I am leaving the code as is. Details, in case I tested the wrong thing.

A popup opened from a webview guest does not inherit the guest's preload, with or without overrideBrowserWindowOptions. I checked with a standalone Electron 41.5.0 app that mirrors the preview setup: a <webview allowpopups> with a preload and contextIsolation=false, whose preload announces itself over IPC on load, then window.open(...) from inside the guest.

The preload reports from the guest and never from the popup:

RESULT preload-ran in: http://127.0.0.1:8899/popup-repro.html
RESULT popup created:

Same result with the override removed, and same with data: and http: popup URLs, so the override is not what is clearing it — the inheritance does not happen in the first place.

One thing worth flagging for anyone reading this later: webContents.getLastWebPreferences() does not report preload at all. It omits the key even for the guest, which definitely has one, so it cannot be used to check this.

If you have a case where the preload does reach the popup, I would like to see it — the exposure you describe would be real, since that preload listens for keydown and pointerdown.

@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR changes production preview behavior by enabling OAuth popup windows and altering Electron renderer security boundaries across the desktop and webview layers. An unresolved security concern about the preview preload potentially reaching third-party OAuth pages still requires validation.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

React types allowpopups as boolean, so the string literal failed apps/web's
tsgo --noEmit. Passing a real boolean typechecks but regresses the fix, since
react-dom drops boolean values for unrecognized attributes and sets nothing,
so the guest would attach with popups disabled again.
Verified after the change: the element carries allowpopups="true" and a
scripted window.open returns a window handle.
@MatthewFeroz

Copy link
Copy Markdown
Contributor

hoping this gets merged!

@MatthewFeroz

Copy link
Copy Markdown
Contributor

I double-checked the preload concern in Electron 41.5.0 and tested it myself. The preview’s preload script ran only inside the preview, not inside the popup. Electron’s code also confirms that preload scripts are not copied into new windows. This matches the author’s test, so I don’t think the Cursor warning is a real issue.

@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Status summary, since the Approvability verdict above predates the current head and reads as the most visible signal on this PR.

That verdict was posted at 8fa05ae and gives one reason: the preview picker preload may still execute in the popup and observe input. Two independent checks say it does not.

I tested it with a standalone Electron 41.5.0 app mirroring the preview setup — a <webview allowpopups> with a preload and contextIsolation=false, the preload announcing itself over IPC. It reports from the guest and never from the popup, with and without overrideBrowserWindowOptions, for both data: and http: popup URLs. @MatthewFeroz reproduced this independently and additionally checked Electron's source, which does not copy preload scripts into new windows.

Worth flagging for anyone testing this themselves: webContents.getLastWebPreferences() omits preload entirely, even for a webContents that has one, so it cannot be used to check this.

The popup is also created with contextIsolation: true, sandbox: true, nodeIntegration: false — verified at runtime as typeof require === "undefined" inside it — and denies its own window.open, so it cannot spawn further windows.

Current head is 8db8d83. All checks green, including Macroscope UI Consistency after the typing fix. Locally: 66 tests in Manager.test.ts pass, tsgo --noEmit clean for apps/web and apps/desktop, lint and format clean on the changed files.

No action needed from me unless something new turns up.

@MatthewFeroz

Copy link
Copy Markdown
Contributor

Just sent a video to the maintainers of this working. Small limitation in this is that passkeys don't function but I think that's out of scope for this PR. Great work!

@juliusmarminge
juliusmarminge merged commit 0e2905e into pingdotgg:mainAug 28, 2026
22 checks passed
@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Thanks for running it and recording the video — I could not produce one myself, so that fills the gap CONTRIBUTING asks for on interaction changes.

On passkeys: that is pre-existing and tracked separately in #5665 ("In app browser not triggering passkey fingerprint to sign in on mac", open since 2026-08-07), so it predates this branch. Nothing here touches WebAuthn — the change only decides whether window.open gets a real window and what preferences that window is created with. A passkey prompt failing inside the preview fails the same way on main today, with or without a popup involved.

So I agree it is out of scope, and I would rather not widen this PR to chase it.

github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Aug 29, 2026
## What's Changed
* fix(grok): improve skills, plans, usage, and turn reliability by @t3dotgg in pingdotgg/t3code#8358
* fix(server): recover stale Codex approval callbacks by @luckyPipewrench in pingdotgg/t3code#5195
* test(server): remove duplicate missing worktree test by @t3-code[bot] in pingdotgg/t3code#8252
* fix(server): replay all un-applied events during projection bootstrap by @krutftw in pingdotgg/t3code#7538
* test: remove low-signal test files by @t3-code[bot] in pingdotgg/t3code#8397
* test: prune trivial error and layout tests by @t3-code[bot] in pingdotgg/t3code#8400
* Fix Android adaptive launcher icon by @colonelpanic8 in pingdotgg/t3code#4332
* feat(web): split provider settings into list and editor by @t3dotgg in pingdotgg/t3code#8380
* fix(codex): accept Codex 0.150 account plans by @gsimone in pingdotgg/t3code#8447
* fix(tooling): allow ignored-only staged changes by @juliusmarminge in pingdotgg/t3code#8468
* fix(mobile): keep iOS home header stable by @juliusmarminge in pingdotgg/t3code#8467
* fix(web): stop showing red x summaries for ordinary tool failures by @t3dotgg in pingdotgg/t3code#8395
* fix(mobile): refine Git action toast glass styling by @juliusmarminge in pingdotgg/t3code#8399
* fix(desktop): allow preview automation in agent-created threads by @t3dotgg in pingdotgg/t3code#8483
* test(web): remove redundant cache key test by @t3-code[bot] in pingdotgg/t3code#8484
* fix(release): move nightly schedule to minute 38 by @t3dotgg in pingdotgg/t3code#8509
* fix(web): stabilize the provider settings editor by @t3dotgg in pingdotgg/t3code#8472
* fix(web): open GitHub pull requests in browser when loading fails by @t3dotgg in pingdotgg/t3code#8507
* fix(codex): show sub-agent models by @t3dotgg in pingdotgg/t3code#8502
* feat(analytics): report connected client platforms by @t3dotgg in pingdotgg/t3code#8481
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB by @t3dotgg in pingdotgg/t3code#8235
* feat(web): toggle a thread's pin from the keyboard by @ipanasenko in pingdotgg/t3code#8440
* fix(web): add back button to project settings by @StiensWout in pingdotgg/t3code#8168
* refactor(mobile): compile semantic themes for Uniwind by @juliusmarminge in pingdotgg/t3code#7327
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times by @ikifar2012 in pingdotgg/t3code#5769
* fix(mobile): show OpenCode model sources in picker by @juliusmarminge in pingdotgg/t3code#8573
* fix(clients): honor project default models in new threads by @anirudhsama in pingdotgg/t3code#6011
* fix(mobile): show file actions on Android by @none23 in pingdotgg/t3code#8215
* fix(connect): explain DPoP connection failures by @extoci in pingdotgg/t3code#8351
* feat(web): make the sidebar project filter a searchable combobox by @SunkenInTime in pingdotgg/t3code#5931
* fix(server): a draft can retry its first send after a failed bootstrap by @shivamhwp in pingdotgg/t3code#8226
* fix(desktop): stop hidden previews draining battery by @Bil0000 in pingdotgg/t3code#8567
* fix(desktop): oauth popups open from the browser preview by @walid-baharwal in pingdotgg/t3code#8435
* fix(web): keep long task drawers usable on small screens by @shivamhwp in pingdotgg/t3code#8313
* fix(opencode): handle child approvals, stops, and model catalogs by @t3dotgg in pingdotgg/t3code#8480
* fix: make thread auto-settling opt-in by @shivamhwp in pingdotgg/t3code#8321
* fix(web): stop session activity timing test from blocking releases by @t3dotgg in pingdotgg/t3code#8585
* fix(mobile): show composer menus when starting a task by @juliusmarminge in pingdotgg/t3code#8587
* fix(web): show the configured stash shortcut by @UtkarshUsername in pingdotgg/t3code#8437
* feat(web): add toggleable confirmation before unpinning a thread by @UtkarshUsername in pingdotgg/t3code#7313
* fix: restore automatic thread settling defaults by @t3dotgg in pingdotgg/t3code#8596
* fix(mobile): restore composer glass and rounded shadows by @juliusmarminge in pingdotgg/t3code#8597
## New Contributors
* @luckyPipewrench made their first contribution in pingdotgg/t3code#5195
* @krutftw made their first contribution in pingdotgg/t3code#7538
* @colonelpanic8 made their first contribution in pingdotgg/t3code#4332
* @ikifar2012 made their first contribution in pingdotgg/t3code#5769
* @walid-baharwal made their first contribution in pingdotgg/t3code#8435
**Full Changelog**: pingdotgg/t3code@v0.0.35...v0.0.36
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.36
aaditagrawal added a commit to aaditagrawal/t3code that referenced this pull request Aug 29, 2026
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
bcotrim pushed a commit to bcotrim/mognet that referenced this pull request Aug 30, 2026
)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
(cherry picked from commit 0e2905e)
brentkelly added a commit to brentkelly/t3code-orchestrator that referenced this pull request Sep 2, 2026
* feat(analytics): threads and turns now know which client started them (pingdotgg#7774)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop marking mixed tool runs as failed (pingdotgg#7893)
* fix(web): command-click spaced folder links (pingdotgg#6439)
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(chat): stop pushing follow-up messages to the top (pingdotgg#7897)
* test(desktop): remove redundant release note assertion (pingdotgg#7873)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): handle wide ordered-list marker edge cases (pingdotgg#7856)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(ssh): restore user PATH for remote servers (pingdotgg#7213)
* fix(desktop): keep tailscale spawn defects from breaking advertised endpoints (pingdotgg#7116)
* fix(web): keep Codex service tier labels readable (pingdotgg#4503)
* fix: render workspace images in chat markdown (pingdotgg#6433)
* fix(clients): keep opening responses visible after turns settle (pingdotgg#7723)
* feat(web): add appearance contrast control (pingdotgg#7906)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop completed Codex threads from staying stuck on working (pingdotgg#7937)
* fix(mobile): preserve markdown image dimensions (pingdotgg#7940)
* fix(web): remove duplicate provider update progress (pingdotgg#7761)
* fix(server): fall back to the remote default branch instead of assuming main (pingdotgg#7078)
* fix(web): give sidebar project menu rows the same side padding as other menus (pingdotgg#7913)
* fix(clients): reconnect after credentials fail during remote server updates (pingdotgg#7953)
* feat(codex): submit thread feedback to OpenAI (pingdotgg#7949)
* fix(server): stop kills lingering Claude work (pingdotgg#5891)
* fix(ci): let Macroscope approve pull requests again (pingdotgg#7970)
* fix(clients): move settled pinned threads into the settled section (pingdotgg#7969)
* perf(ci): speed up release builds and Windows packaging (pingdotgg#7975)
* fix(web): stop tool calls from leaving a blank page in threads (pingdotgg#7971)
* fix(web): stop recovered tool failures from marking work logs red (pingdotgg#7999)
* fix(mobile): isolate markdown image requests (pingdotgg#7942)
* feat(web): redesign skills in `$` menu and in `/` menu (pingdotgg#8009)
* fix(web): restore right panel toggle clicks after closing on desktop (pingdotgg#8016)
* fix(web): keep server update banners flush with the composer (pingdotgg#8000)
* perf(web): reuse work log rows during streaming (pingdotgg#8006)
* fix(web): keep provider badge legible in dark themes (pingdotgg#7968)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): treat configured urls with uppercase schemes as secure (pingdotgg#8005)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(desktop): keep release notes visible while downloading (pingdotgg#6412)
* fix(web): show only providers with usage in usage views (pingdotgg#7563)
* fix(web): prevent expanded tool calls from hiding thread content (pingdotgg#8052)
* test(server): remove no-op live activity tests (pingdotgg#8056)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): clarify terminal sidebar grouping (pingdotgg#7967)
* fix(codex): show app access approval prompts (pingdotgg#8058)
* feat(web): upload image attachments before sending (pingdotgg#8048)
* fix(server): bound OpenCode skill discovery output (pingdotgg#7675)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(mobile): persist thread shelf collapse state (pingdotgg#5152)
* fix(mobile): restore Android tablet thread controls, clean up header (pingdotgg#5385)
* fix(mobile): land the first thread open above the composer on Android (pingdotgg#5585)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(server): check out submodules in a new worktree (pingdotgg#7674)
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
* fix(server): preserve merged PR badges after branch deletion (pingdotgg#6216)
* fix(server): return fresh live pull request reads (pingdotgg#6472)
* fix(web): compare client and server versions as semver, not strings (pingdotgg#7579)
* fix(web): stop follow-ups from leaving giant blank space (pingdotgg#8068)
* fix(marketing): stop automatic Vercel deployments on pull requests (pingdotgg#8070)
* chore: vouch repeat contributors (pingdotgg#8071)
* fix(server): keep the authoritative subagent model when snapshots race task_started (pingdotgg#7583)
* fix(server): honor auto-accept edits for the OpenCode provider (pingdotgg#7100)
* fix(server): run the CLI on Node versions without import.meta.main (pingdotgg#7141)
* fix(server): recover from provider interrupt failures (pingdotgg#7412)
* fix(server): recreate a thread's worktree before starting a turn (pingdotgg#7839)
* fix(server): thread delete no longer fails on already-removed worktrees (pingdotgg#8076)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop update notices showing through the composer (pingdotgg#8083)
* fix(web): detect outdated nightly servers (pingdotgg#8124)
* fix(web): align usage page skeleton layout (pingdotgg#8111)
* fix(web): make terminal links appear clickable only when clickable (pingdotgg#7488)
* fix(web): make Windows file links clickable in chat (pingdotgg#8081)
* fix(web): sort usage models by token count (pingdotgg#8108)
* fix: open agent file links in the file viewer (pingdotgg#8098)
* fix(server): stop routine events from rescanning thread history (pingdotgg#8150)
* fix(deps): stop pnpm installs from changing the lockfile (pingdotgg#8163)
* feat(web): settle and restore threads with a keyboard shortcut (pingdotgg#8089)
* perf(desktop): cut macOS signing calls by 81% (pingdotgg#8093)
* feat: link pull requests to threads (pingdotgg#8160)
* feat(web): safely attach HEIC photos as JPEG images (pingdotgg#8161)
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
* feat(mobile): track device models and OS versions (pingdotgg#8169)
* fix(grok): bound cumulative tool output updates (pingdotgg#7279)
* fix(web): delay thread shortcut hints by 200 ms (pingdotgg#8172)
* fix(server): stop probing Cursor until enabled (pingdotgg#8175)
* docs(release): verify remote updates with database migrations (pingdotgg#8177)
* fix(server): keep provider CLIs available in the macOS service (pingdotgg#8173)
* feat(claude): compact old threads before they burn through usage (pingdotgg#8144)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(client-runtime): retry queries after connection interruption (pingdotgg#8117)
* fix(server): keep previously used providers working after upgrades (pingdotgg#8176)
* feat(desktop): build macOS previews from a PR label (pingdotgg#8182)
* fix(web): thread jump hints no longer stick after a dictation paste (pingdotgg#8189)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): keep grouped project renames (pingdotgg#7831)
* feat(web): reveal chat file chips in the system file manager (pingdotgg#7140)
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(server): push no longer writes a feature branch's commits to its base branch (pingdotgg#8228)
* chore(deps): bump @clerk/electron to 0.0.37 (pingdotgg#8240)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(server): fetch legacy model classification from a hosted manifest (pingdotgg#8227)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* chore(release): prepare v0.0.34
* fix(desktop): let Clerk UI receive stable auth fixes (pingdotgg#8248)
* fix(app): un-settled threads return to the top of the list (pingdotgg#8231)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* perf(ci): cut about a minute from every release (pingdotgg#8250)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(ci): download macOS preview DMGs without signing in (pingdotgg#8243)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(codex): accept Codex 0.150 multi-agent events (pingdotgg#8346)
* chore(release): prepare v0.0.35
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
* Require human review for pull requests changing product defaults (pingdotgg#8603)
* fix(codex): avoid quadratic app-server input buffering (pingdotgg#8605)
* fix(mobile): stabilize iOS header item transitions (pingdotgg#8607)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(mobile): upgrade to Expo SDK 57 (pingdotgg#8609)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(mobile): harden native header toolbar items (pingdotgg#8611)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): stop querying Claude context usage after turns (pingdotgg#8610)
* chore: vouch ryanrhughes (pingdotgg#8613)
* feat(web): attach PDFs, ZIPs, and other files to a turn (pingdotgg#8236)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): pass stashShortcutLabel in the mixed-attachments stash test
PRs pingdotgg#8437 and pingdotgg#8236 crossed: one made stashShortcutLabel a required
ComposerStashMenu prop, the other added a test case without it, so
main fails web typecheck.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat(web): keybinding settings as settings rows (pingdotgg#8532)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat: let an environment publish themes as a file (pingdotgg#8569)
Co-authored-by: Theo Browne <me@t3.gg>
* fix(web): clean up provider settings list and editor (pingdotgg#8504)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep project picker popup inside the sidebar (pingdotgg#8627)
* fix(mobile): prevent header overflow and back-button artifacts (pingdotgg#8624)
* fix(server): retry automatic thread title generation (pingdotgg#8087)
* fix(client-runtime): refresh edited pull request comments (pingdotgg#8094)
* fix(web): four composer spacing defects (pingdotgg#8090)
* perf(desktop): skip duplicate browser updates (pingdotgg#8018)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): render nested markdown images correctly (pingdotgg#8501)
* fix(web): unify activity logs and composer banners (pingdotgg#8693)
* fix(mobile): reduce dev-client reload and Metro startup cost (pingdotgg#8694)
Co-authored-by: Julius Marminge <julius@mac.lan>
* revert(web): restore previous composer banners (pingdotgg#8733)
* test(web): remove tests for unreachable helpers (pingdotgg#8738)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* feat(mobile): update tool summaries and chat transitions (pingdotgg#8793)
* feat(web): play video attachments in chat (pingdotgg#8688)
* fix(web,mobile): snooze menu no longer offers the same wake time twice (pingdotgg#8741)
* fix(grok): allow model changes in existing threads (pingdotgg#8392)
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
* feat(mobile): pick, share, and receive files in threads (pingdotgg#8237)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): reduce title bar scroll fade height (pingdotgg#8799)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(windows): strip quotes from repaired PATH (pingdotgg#8746)
* fix(web): open agent images in expanded preview (pingdotgg#8807)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(git): follow repository instructions in generated source control text (pingdotgg#8804)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop overpricing cached Claude tokens (pingdotgg#8806)
* fix(web): keep image preview above sidebar control (pingdotgg#8811)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): keep right panel synced with agent edits (pingdotgg#8803)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web,mobile): render Codex citations and artifact templates (pingdotgg#8584)
* chore: add Windows setup script to t3.json (pingdotgg#8814)
* fix(web): fold interim turn responses (pingdotgg#8828)
* fix(web): use circle alert for failed tool calls (pingdotgg#8840)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(mobile): add offline iPhone voice input (pingdotgg#8614)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent pull request metadata overlap (pingdotgg#8790)
* chore(release): prepare v0.0.37
* Add mobile composer attachment menu with video support (pingdotgg#8843)
* fix(mobile): map native menu icon colors explicitly
* fix(web): restore unified activity logs and composer banners (pingdotgg#8734)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
* fix(web): address composer banner review follow-ups (pingdotgg#8850)
* fix(web): widen sync banners and simplify the working timer (pingdotgg#8855)
* fix(preview): improve browser recording quality (pingdotgg#8839)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): mark pull request links as external (pingdotgg#8856)
* fix(mobile): replace Callstack glass with Expo glass (pingdotgg#8862)
* fix(server): skip IDE detection in Claude probes (pingdotgg#8634)
* chore(macroscope): review diagnostic overrides (pingdotgg#8917)
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* fix(contracts): accept CLI event origins (pingdotgg#8905)
* fix(web): hide invalid slash skill completions (pingdotgg#8904)
* fix(mobile): defer draft navigation until submission completes (pingdotgg#8914)
* chore: disable CodeRabbit review status (pingdotgg#8933)
* Delete app.json (pingdotgg#8934)
* fix(web): show scrollbar for wide markdown tables (pingdotgg#8868)
* fix(mobile): shimmer active tool rows (pingdotgg#8932)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(deps): bump Electron to 43.4.1 (pingdotgg#8626)
* fix(chat): smooth worktree setup status (pingdotgg#8922)
* feat(mobile): add video playback with native iOS controls (pingdotgg#8919)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent chat metadata overlap (pingdotgg#8851)
* fix(server): preserve usage cache outside walked roots (pingdotgg#8540)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(mobile): add native image and PDF previews (pingdotgg#8959)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): allow long thread IDs in HTTP routes (pingdotgg#8898)
* fix(shared): preserve Windows shell PATH priority (pingdotgg#8748)
* fix(web): make WSL settings searchable (pingdotgg#8881)
* feat(web): add expand/collapse all control to the files surface (pingdotgg#8889)
* Add auto_review configuration to coderabbit.yaml
* style: format CodeRabbit configuration
* feat(mobile): upload attachments while composing (pingdotgg#8978)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(chat): keep agent activity visible between actions (pingdotgg#8984)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): isolate remote web session cookies (pingdotgg#8085)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(pull-requests): link GitHub references in markdown (pingdotgg#8812)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* perf(server): reduce frequency of full tool call output being loaded into memory from db (pingdotgg#8988)
* feat(web): add pull request list filters (pingdotgg#8809)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(web): search individual settings by detail (pingdotgg#8831)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(client): render viewed images in work logs (pingdotgg#8936)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(client): use package import for markdown image helpers (pingdotgg#9010)
* test: remove static presentation snapshots (pingdotgg#9008)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* perf(server): bound snapshot activity payload memory (pingdotgg#9000)
* perf(server): cut idle CPU use and stop provider event leaks (pingdotgg#8187)
* perf(server): scan only appended transcript bytes for usage summaries (pingdotgg#9024)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): cut chatty tool-update frames by 90% (pingdotgg#8368)
* fix(server): settle threads server-side (pingdotgg#8600)
* fix(clients): dedupe skills in composer menus (pingdotgg#8043)
* fix(server): stop OpenCode child sessions (pingdotgg#9005)
* perf(web): defer pull request line stats until visible (pingdotgg#6471)
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): skip full-message reads while streaming (pingdotgg#9032)
* perf(client-runtime): halve server config bootstrap traffic (pingdotgg#8367)
Reuse one server config subscription for session bootstrap and live updates.
Preserve environment theme opt-in, replay, deletion, slow subscriber recovery, and config stream failure handling.
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
* fix(web): align un-settle banner action (pingdotgg#9033)
* fix(web): block type-to-focus behind open dialogs (pingdotgg#8139)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(shortcuts): copy active thread reference (pingdotgg#8994)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(mobile): keep thread scroll bounds current after animations (pingdotgg#9013)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): cache project favicon resolution (pingdotgg#9080)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(claude): add Claude Fable 5.1 model (pingdotgg#9078)
* fix(preview): restore recording and macOS rendering after Electron 43 (pingdotgg#9001)
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
* feat(desktop): add configurable quit shortcut confirmation (pingdotgg#9076)
* feat(web): open project settings from thread menus (pingdotgg#8925)
* fix(chat): reuse one row for live activity (pingdotgg#9062)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(models): discover Claude models from remote manifest (pingdotgg#9084)
* Revert "fix(chat): reuse one row for live activity" (pingdotgg#9096)
* fix(web): sync sidebar PR state from open panel (pingdotgg#9092)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): changing projects no longer creates a draft (pingdotgg#9097)
* fix(web): keep theme placeholder text dimmer than entered text (pingdotgg#9104)
* fix(web): keep the selected environment when changing projects (pingdotgg#9102)
* docs(plans): t3o-31 upstream sync to v0.0.38
* fix(board): clear the ten pre-existing typecheck errors before the upstream sync (t3o-31 P0)
Two test fakes failed with a bare Error in the Effect failure channel, a
closure-assigned let narrowed to never, and a single-override pill read
overriddenRows[0] under noUncheckedIndexedAccess. None changed behaviour;
they were masked because the recursive typecheck never reached apps/server.
* fix(sync): the three type errors and two test failures the v0.0.38 merge caused
- BoardModelRow reads planModeEnabled from client settings, as the composer does.
- findBranchPullRequest resolves the default branch for upstream's widened PR
cache key instead of passing null.
- The orphaned-session integration test mocks the supervisor reactor that the
startup seam yields (new inventory row).
- The projection resume test seeds board projector watermarks into
boards.projection_state, where t3o-26 reads them, and asserts over the union.
- searchSettings("work") now also matches upstream's worktree/network items.
* refactor(board): native title attributes become BoardHint tooltips
Upstream's new no-native-title-tooltip rule flags every intrinsic-element
title= in the board (61 sites). BoardHint wraps the styled Tooltip primitive
and renders its child as the trigger, so layout is unchanged; a nullish label
renders the child alone.
* docs(seams): record the v0.0.38 sync (t3o-31)
Merge-log row, the decisions taken (plans stay tracked, upstream's settlement
reactor accepted after audit, projector-enumeration policy, launcher protocol
note), an unmarked-edits debt table for the next sync, a marker census, the
three new upstream workflows to disable, and the runbook's per-package
verification notes.
* review(t3o-31): announce the board's status dots, and order the merge log
Round-1 nitpicks: a bare span's aria-label is not announced, so the working,
running and awaiting dots now carry role="img"; the v0.0.38 merge-log row
moves below the two 2026-08-09 rows so the table reads chronologically.
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: abcdmku <63693423+abcdmku@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: Rishet11 <154429365+Rishet11@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Naveed Iqbal <naveediqbal949@gmail.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: Tristan Knight <admin@snappeh.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Pavlo Trinko <paul.trinko95@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Rodrigo Brechard <rodrigobrechard@gmail.com>
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
Co-authored-by: spiky02plateau <155588579+spiky02plateau@users.noreply.github.com>
Co-authored-by: Carlos Jimenez <cjimenez@r21digital.com>
Co-authored-by: Mark Griffin <mrmg@deflexion.net>
Co-authored-by: MacKinley Smith <smithmackinley@gmail.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Mohtasham Murshid <154406804+MohtashamMurshid@users.noreply.github.com>
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
Co-authored-by: Vitaly Iegorov <vitalyiegorov@gmail.com>
Co-authored-by: Ahmed Besic <ahmed.besic2000@gmail.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: Matthew Feroz <136640686+MatthewFeroz@users.noreply.github.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: Will Sheldon <will@autimo.com>
Co-authored-by: mic <85814106+q1@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Integrated browser preview blocks OAuth popup authentication

3 participants

@walid-baharwal@MatthewFeroz@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(desktop): oauth popups open from the browser preview - #8435

Merged
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups
Aug 28, 2026
Merged

fix(desktop): oauth popups open from the browser preview#8435
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups

Conversation

@walid-baharwal

@walid-baharwalwalid-baharwal commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

What Changed

Two changes, both needed for an OAuth popup to work in the integrated browser preview.

apps/web/src/browser/HostedBrowserWebview.tsx sets allowpopups as an attribute on the <webview> element instead of from the ref callback. Electron reads that flag when the guest attaches, and the ref callback runs after the element is already in the DOM, so every preview guest attached with popups disabled.

apps/desktop/src/preview/Manager.ts reads the disposition the window-open handler already received. A new-window disposition with an http or https URL now opens a real window; everything else, target="_blank" links included, keeps loading in the preview tab as before. The popup is created with contextIsolation, sandbox, and nodeIntegration: false set explicitly, since a popup is not a webview attach and never passes the will-attach-webview hardening in DesktopWindow. It also gets a deny-only window-open handler of its own, so a page inside it cannot spawn native windows without limit. about:blank popups keep loading in the preview tab: Chromium copies the guest preferences for them and gives no way to override.

Why

A local app opened in the preview cannot finish an OAuth popup flow. Firebase signInWithPopup(auth, new GoogleAuthProvider()) reports auth/popup-blocked and no window appears, while the same app works in a normal Chrome or Firefox window.

Two separate causes stack up. window.open was denied and the URL was force-loaded into the same webContents, so window.open() returned null (the SDK reads that as a blocked popup) and the in-tab load destroyed the opener the popup needs to postMessage its credential back to. Underneath that, the guest attached with allowpopups false, so Electron blocked the call before the handler ran at all.

Instrumenting will-attach-webview in a running desktop build showed it directly:

[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":false} before
[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":true} after

Surfaces

Desktop only in behavior. The <webview> element lives in apps/web because the desktop app wraps the web client, but the tag only exists inside Electron and remote web previews never reach setWindowOpenHandler. No contract, provider, or docs change.

UI Changes

No layout, styling, or motion changed. The observable difference is whether a popup window exists, captured below in a dev build against a local page that calls window.open(url, name, "width=520,height=640"), the same shape signInWithPopup uses.

Before

window.open() returns null and no window opens.

Before: popup blocked

After

window.open() returns a window handle.

After: popup opens

The popup window itself, sized from the requested window features:

After: the popup window

Verification

Run in a dev desktop build (dev:desktop) with the preview open on a local page:

  • Scripted popup: window.open(...) returns a handle. Handler logged disposition: "new-window" and decided popup.
  • The popup reports window.opener present and typeof require === "undefined", so the opener survives and the hardening applied.
  • A nested window.open from inside the popup returns null.
  • A target="_blank" link logs disposition: "foreground-tab", decides navigate, and loads in the preview tab.
  • previewWindowOpenAction has focused unit tests next to isPreviewRefreshShortcut, the existing pure helper in the same file.

Checks run locally:

  • vp test run apps/desktop/src/preview/Manager.test.ts — 66 passed
  • tsgo --noEmit in apps/web and apps/desktop — clean
  • vp lint and vp fmt --check on the changed files — clean

The attach-timing half is not unit-testable in a meaningful way. A rendered-DOM assertion passes either way, because the ref callback does set the attribute, just too late for Electron to read it.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • Before/after evidence included

Fixes#6561

Written with Claude Opus 5 in Claude Code.


Note

Medium Risk
Changes preview navigation and spawns hardened native windows from third-party pages; security-sensitive but scoped to http/https scripted popups with explicit hardening and nested popup denial.

Overview
Fixes OAuth and other scripted window.open flows in the integrated browser preview by enabling popups at attach time and opening real windows when appropriate instead of navigating the preview tab.

HostedBrowserWebview sets allowpopups="true" on the <webview> element at render time (not in a ref callback), so Electron sees it before the guest attaches.

PreviewManager adds previewWindowOpenAction: scripted popups (new-window + http:/https:) are allowed as separate BrowserWindows with contextIsolation, sandbox, and no Node integration; target="_blank" and non-hardenable URLs (about:blank, file:, javascript:, etc.) still load in the preview tab. Child OAuth windows get a deny-all setWindowOpenHandler via did-create-window.

Unit tests cover the new helper’s popup vs navigate decisions.

Reviewed by Cursor Bugbot for commit 3f60be1. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix OAuth popups in desktop browser preview with hardened window.open handling

  • Adds previewWindowOpenAction in Manager.ts to classify window.open requests: http/https scripted popups return 'popup' and open as real BrowserWindows; target=_blank tabs and disallowed/invalid schemes (about, javascript, file, vscode) return 'navigate' and load in the existing preview tab.
  • New popup windows use hardened webPreferences (contextIsolation: true, nodeIntegration: false, sandbox: true) and deny further window.open calls from within them.
  • Fixes HostedBrowserWebview.tsx so the <webview> element reliably gets the allowpopups attribute at attach time.
  • Behavioral Change: setWindowOpenHandler now receives full details and uses details.url instead of bare url; non-http(s) URLs that previously may have opened as popups now navigate the current tab instead.

Macroscope summarized 3f60be1.

@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e56baf0c-bdec-4082-8fa9-d71789606066

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 27, 2026
Scripted `window.open` calls inside the integrated browser preview were denied
and loaded in the preview tab instead. Firebase `signInWithPopup` got a null
window handle back and reported `auth/popup-blocked`, and the in-tab load also
dropped the opener the popup needs to post the credential back to.
Popups with a `new-window` disposition and an http or https URL now get a real
window, with context isolation and the sandbox turned back on: a popup is not a
webview attach, so the `will-attach-webview` hardening never sees it and an
unoverridden child would inherit the picker preload's relaxed posture.
`about:blank` popups keep loading in the preview tab, since Chromium copies the
guest preferences for them and forbids overriding. Links with `target="_blank"`
are unchanged.
Fixespingdotgg#6561
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from e598878 to 8fa05aeCompareAugust 27, 2026 18:16
Comment threadapps/desktop/src/preview/Manager.ts
Comment threadapps/desktop/src/preview/Manager.ts
An allowed popup carried Electron's default window-open behavior, so a page
inside it could spawn native windows without limit. The popup now denies its
own window.open calls; no OAuth flow opens a second popup.
The popup preferences also drop nodeIntegrationInSubFrames, matching the three
keys every other hardened window in the app sets.
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from d2ce056 to 7c5b69aCompareAugust 27, 2026 18:31
Electron reads allowpopups when the guest attaches. The attribute was set from
the ref callback, which runs after the element is in the DOM, so every preview
guest attached with popups disabled and Electron blocked window.open before the
window-open handler ran.
Verified in a running desktop build: will-attach-webview reported
allowpopups: false before this change and true after.
@walid-baharwal
walid-baharwal marked this pull request as ready for review August 27, 2026 22:31

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding in the web scope: the new allowpopups JSX attribute is the right ownership fix, but its string value conflicts with React's element typing, so apps/web typecheck (tsgo --noEmit) breaks. Details inline.

Posted via Macroscope — UI Consistency

Comment threadapps/web/src/browser/HostedBrowserWebview.tsx Outdated

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

nodeIntegration: false,
sandbox: true,
},
} satisfies Electron.BrowserWindowConstructorOptions;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Popup may inherit picker preload

High Severity

POPUP_WINDOW_OPTIONS overrides isolation flags but never clears preload. Electron merges overrideBrowserWindowOptions with the guest's preferences, so the picker preload can still run in the OAuth window and observe keystrokes and clicks on a third-party login page.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I could not reproduce this one, so I am leaving the code as is. Details, in case I tested the wrong thing.

A popup opened from a webview guest does not inherit the guest's preload, with or without overrideBrowserWindowOptions. I checked with a standalone Electron 41.5.0 app that mirrors the preview setup: a <webview allowpopups> with a preload and contextIsolation=false, whose preload announces itself over IPC on load, then window.open(...) from inside the guest.

The preload reports from the guest and never from the popup:

RESULT preload-ran in: http://127.0.0.1:8899/popup-repro.html
RESULT popup created:

Same result with the override removed, and same with data: and http: popup URLs, so the override is not what is clearing it — the inheritance does not happen in the first place.

One thing worth flagging for anyone reading this later: webContents.getLastWebPreferences() does not report preload at all. It omits the key even for the guest, which definitely has one, so it cannot be used to check this.

If you have a case where the preload does reach the popup, I would like to see it — the exposure you describe would be real, since that preload listens for keydown and pointerdown.

@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR changes production preview behavior by enabling OAuth popup windows and altering Electron renderer security boundaries across the desktop and webview layers. An unresolved security concern about the preview preload potentially reaching third-party OAuth pages still requires validation.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

React types allowpopups as boolean, so the string literal failed apps/web's
tsgo --noEmit. Passing a real boolean typechecks but regresses the fix, since
react-dom drops boolean values for unrecognized attributes and sets nothing,
so the guest would attach with popups disabled again.
Verified after the change: the element carries allowpopups="true" and a
scripted window.open returns a window handle.
@MatthewFeroz

Copy link
Copy Markdown
Contributor

hoping this gets merged!

@MatthewFeroz

Copy link
Copy Markdown
Contributor

I double-checked the preload concern in Electron 41.5.0 and tested it myself. The preview’s preload script ran only inside the preview, not inside the popup. Electron’s code also confirms that preload scripts are not copied into new windows. This matches the author’s test, so I don’t think the Cursor warning is a real issue.

@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Status summary, since the Approvability verdict above predates the current head and reads as the most visible signal on this PR.

That verdict was posted at 8fa05ae and gives one reason: the preview picker preload may still execute in the popup and observe input. Two independent checks say it does not.

I tested it with a standalone Electron 41.5.0 app mirroring the preview setup — a <webview allowpopups> with a preload and contextIsolation=false, the preload announcing itself over IPC. It reports from the guest and never from the popup, with and without overrideBrowserWindowOptions, for both data: and http: popup URLs. @MatthewFeroz reproduced this independently and additionally checked Electron's source, which does not copy preload scripts into new windows.

Worth flagging for anyone testing this themselves: webContents.getLastWebPreferences() omits preload entirely, even for a webContents that has one, so it cannot be used to check this.

The popup is also created with contextIsolation: true, sandbox: true, nodeIntegration: false — verified at runtime as typeof require === "undefined" inside it — and denies its own window.open, so it cannot spawn further windows.

Current head is 8db8d83. All checks green, including Macroscope UI Consistency after the typing fix. Locally: 66 tests in Manager.test.ts pass, tsgo --noEmit clean for apps/web and apps/desktop, lint and format clean on the changed files.

No action needed from me unless something new turns up.

@MatthewFeroz

Copy link
Copy Markdown
Contributor

Just sent a video to the maintainers of this working. Small limitation in this is that passkeys don't function but I think that's out of scope for this PR. Great work!

@juliusmarminge
juliusmarminge merged commit 0e2905e into pingdotgg:mainAug 28, 2026
22 checks passed
@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Thanks for running it and recording the video — I could not produce one myself, so that fills the gap CONTRIBUTING asks for on interaction changes.

On passkeys: that is pre-existing and tracked separately in #5665 ("In app browser not triggering passkey fingerprint to sign in on mac", open since 2026-08-07), so it predates this branch. Nothing here touches WebAuthn — the change only decides whether window.open gets a real window and what preferences that window is created with. A passkey prompt failing inside the preview fails the same way on main today, with or without a popup involved.

So I agree it is out of scope, and I would rather not widen this PR to chase it.

github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Aug 29, 2026
## What's Changed
* fix(grok): improve skills, plans, usage, and turn reliability by @t3dotgg in pingdotgg/t3code#8358
* fix(server): recover stale Codex approval callbacks by @luckyPipewrench in pingdotgg/t3code#5195
* test(server): remove duplicate missing worktree test by @t3-code[bot] in pingdotgg/t3code#8252
* fix(server): replay all un-applied events during projection bootstrap by @krutftw in pingdotgg/t3code#7538
* test: remove low-signal test files by @t3-code[bot] in pingdotgg/t3code#8397
* test: prune trivial error and layout tests by @t3-code[bot] in pingdotgg/t3code#8400
* Fix Android adaptive launcher icon by @colonelpanic8 in pingdotgg/t3code#4332
* feat(web): split provider settings into list and editor by @t3dotgg in pingdotgg/t3code#8380
* fix(codex): accept Codex 0.150 account plans by @gsimone in pingdotgg/t3code#8447
* fix(tooling): allow ignored-only staged changes by @juliusmarminge in pingdotgg/t3code#8468
* fix(mobile): keep iOS home header stable by @juliusmarminge in pingdotgg/t3code#8467
* fix(web): stop showing red x summaries for ordinary tool failures by @t3dotgg in pingdotgg/t3code#8395
* fix(mobile): refine Git action toast glass styling by @juliusmarminge in pingdotgg/t3code#8399
* fix(desktop): allow preview automation in agent-created threads by @t3dotgg in pingdotgg/t3code#8483
* test(web): remove redundant cache key test by @t3-code[bot] in pingdotgg/t3code#8484
* fix(release): move nightly schedule to minute 38 by @t3dotgg in pingdotgg/t3code#8509
* fix(web): stabilize the provider settings editor by @t3dotgg in pingdotgg/t3code#8472
* fix(web): open GitHub pull requests in browser when loading fails by @t3dotgg in pingdotgg/t3code#8507
* fix(codex): show sub-agent models by @t3dotgg in pingdotgg/t3code#8502
* feat(analytics): report connected client platforms by @t3dotgg in pingdotgg/t3code#8481
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB by @t3dotgg in pingdotgg/t3code#8235
* feat(web): toggle a thread's pin from the keyboard by @ipanasenko in pingdotgg/t3code#8440
* fix(web): add back button to project settings by @StiensWout in pingdotgg/t3code#8168
* refactor(mobile): compile semantic themes for Uniwind by @juliusmarminge in pingdotgg/t3code#7327
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times by @ikifar2012 in pingdotgg/t3code#5769
* fix(mobile): show OpenCode model sources in picker by @juliusmarminge in pingdotgg/t3code#8573
* fix(clients): honor project default models in new threads by @anirudhsama in pingdotgg/t3code#6011
* fix(mobile): show file actions on Android by @none23 in pingdotgg/t3code#8215
* fix(connect): explain DPoP connection failures by @extoci in pingdotgg/t3code#8351
* feat(web): make the sidebar project filter a searchable combobox by @SunkenInTime in pingdotgg/t3code#5931
* fix(server): a draft can retry its first send after a failed bootstrap by @shivamhwp in pingdotgg/t3code#8226
* fix(desktop): stop hidden previews draining battery by @Bil0000 in pingdotgg/t3code#8567
* fix(desktop): oauth popups open from the browser preview by @walid-baharwal in pingdotgg/t3code#8435
* fix(web): keep long task drawers usable on small screens by @shivamhwp in pingdotgg/t3code#8313
* fix(opencode): handle child approvals, stops, and model catalogs by @t3dotgg in pingdotgg/t3code#8480
* fix: make thread auto-settling opt-in by @shivamhwp in pingdotgg/t3code#8321
* fix(web): stop session activity timing test from blocking releases by @t3dotgg in pingdotgg/t3code#8585
* fix(mobile): show composer menus when starting a task by @juliusmarminge in pingdotgg/t3code#8587
* fix(web): show the configured stash shortcut by @UtkarshUsername in pingdotgg/t3code#8437
* feat(web): add toggleable confirmation before unpinning a thread by @UtkarshUsername in pingdotgg/t3code#7313
* fix: restore automatic thread settling defaults by @t3dotgg in pingdotgg/t3code#8596
* fix(mobile): restore composer glass and rounded shadows by @juliusmarminge in pingdotgg/t3code#8597
## New Contributors
* @luckyPipewrench made their first contribution in pingdotgg/t3code#5195
* @krutftw made their first contribution in pingdotgg/t3code#7538
* @colonelpanic8 made their first contribution in pingdotgg/t3code#4332
* @ikifar2012 made their first contribution in pingdotgg/t3code#5769
* @walid-baharwal made their first contribution in pingdotgg/t3code#8435
**Full Changelog**: pingdotgg/t3code@v0.0.35...v0.0.36
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.36
aaditagrawal added a commit to aaditagrawal/t3code that referenced this pull request Aug 29, 2026
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
bcotrim pushed a commit to bcotrim/mognet that referenced this pull request Aug 30, 2026
)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
(cherry picked from commit 0e2905e)
brentkelly added a commit to brentkelly/t3code-orchestrator that referenced this pull request Sep 2, 2026
* feat(analytics): threads and turns now know which client started them (pingdotgg#7774)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop marking mixed tool runs as failed (pingdotgg#7893)
* fix(web): command-click spaced folder links (pingdotgg#6439)
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(chat): stop pushing follow-up messages to the top (pingdotgg#7897)
* test(desktop): remove redundant release note assertion (pingdotgg#7873)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): handle wide ordered-list marker edge cases (pingdotgg#7856)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(ssh): restore user PATH for remote servers (pingdotgg#7213)
* fix(desktop): keep tailscale spawn defects from breaking advertised endpoints (pingdotgg#7116)
* fix(web): keep Codex service tier labels readable (pingdotgg#4503)
* fix: render workspace images in chat markdown (pingdotgg#6433)
* fix(clients): keep opening responses visible after turns settle (pingdotgg#7723)
* feat(web): add appearance contrast control (pingdotgg#7906)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop completed Codex threads from staying stuck on working (pingdotgg#7937)
* fix(mobile): preserve markdown image dimensions (pingdotgg#7940)
* fix(web): remove duplicate provider update progress (pingdotgg#7761)
* fix(server): fall back to the remote default branch instead of assuming main (pingdotgg#7078)
* fix(web): give sidebar project menu rows the same side padding as other menus (pingdotgg#7913)
* fix(clients): reconnect after credentials fail during remote server updates (pingdotgg#7953)
* feat(codex): submit thread feedback to OpenAI (pingdotgg#7949)
* fix(server): stop kills lingering Claude work (pingdotgg#5891)
* fix(ci): let Macroscope approve pull requests again (pingdotgg#7970)
* fix(clients): move settled pinned threads into the settled section (pingdotgg#7969)
* perf(ci): speed up release builds and Windows packaging (pingdotgg#7975)
* fix(web): stop tool calls from leaving a blank page in threads (pingdotgg#7971)
* fix(web): stop recovered tool failures from marking work logs red (pingdotgg#7999)
* fix(mobile): isolate markdown image requests (pingdotgg#7942)
* feat(web): redesign skills in `$` menu and in `/` menu (pingdotgg#8009)
* fix(web): restore right panel toggle clicks after closing on desktop (pingdotgg#8016)
* fix(web): keep server update banners flush with the composer (pingdotgg#8000)
* perf(web): reuse work log rows during streaming (pingdotgg#8006)
* fix(web): keep provider badge legible in dark themes (pingdotgg#7968)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): treat configured urls with uppercase schemes as secure (pingdotgg#8005)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(desktop): keep release notes visible while downloading (pingdotgg#6412)
* fix(web): show only providers with usage in usage views (pingdotgg#7563)
* fix(web): prevent expanded tool calls from hiding thread content (pingdotgg#8052)
* test(server): remove no-op live activity tests (pingdotgg#8056)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): clarify terminal sidebar grouping (pingdotgg#7967)
* fix(codex): show app access approval prompts (pingdotgg#8058)
* feat(web): upload image attachments before sending (pingdotgg#8048)
* fix(server): bound OpenCode skill discovery output (pingdotgg#7675)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(mobile): persist thread shelf collapse state (pingdotgg#5152)
* fix(mobile): restore Android tablet thread controls, clean up header (pingdotgg#5385)
* fix(mobile): land the first thread open above the composer on Android (pingdotgg#5585)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(server): check out submodules in a new worktree (pingdotgg#7674)
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
* fix(server): preserve merged PR badges after branch deletion (pingdotgg#6216)
* fix(server): return fresh live pull request reads (pingdotgg#6472)
* fix(web): compare client and server versions as semver, not strings (pingdotgg#7579)
* fix(web): stop follow-ups from leaving giant blank space (pingdotgg#8068)
* fix(marketing): stop automatic Vercel deployments on pull requests (pingdotgg#8070)
* chore: vouch repeat contributors (pingdotgg#8071)
* fix(server): keep the authoritative subagent model when snapshots race task_started (pingdotgg#7583)
* fix(server): honor auto-accept edits for the OpenCode provider (pingdotgg#7100)
* fix(server): run the CLI on Node versions without import.meta.main (pingdotgg#7141)
* fix(server): recover from provider interrupt failures (pingdotgg#7412)
* fix(server): recreate a thread's worktree before starting a turn (pingdotgg#7839)
* fix(server): thread delete no longer fails on already-removed worktrees (pingdotgg#8076)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop update notices showing through the composer (pingdotgg#8083)
* fix(web): detect outdated nightly servers (pingdotgg#8124)
* fix(web): align usage page skeleton layout (pingdotgg#8111)
* fix(web): make terminal links appear clickable only when clickable (pingdotgg#7488)
* fix(web): make Windows file links clickable in chat (pingdotgg#8081)
* fix(web): sort usage models by token count (pingdotgg#8108)
* fix: open agent file links in the file viewer (pingdotgg#8098)
* fix(server): stop routine events from rescanning thread history (pingdotgg#8150)
* fix(deps): stop pnpm installs from changing the lockfile (pingdotgg#8163)
* feat(web): settle and restore threads with a keyboard shortcut (pingdotgg#8089)
* perf(desktop): cut macOS signing calls by 81% (pingdotgg#8093)
* feat: link pull requests to threads (pingdotgg#8160)
* feat(web): safely attach HEIC photos as JPEG images (pingdotgg#8161)
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
* feat(mobile): track device models and OS versions (pingdotgg#8169)
* fix(grok): bound cumulative tool output updates (pingdotgg#7279)
* fix(web): delay thread shortcut hints by 200 ms (pingdotgg#8172)
* fix(server): stop probing Cursor until enabled (pingdotgg#8175)
* docs(release): verify remote updates with database migrations (pingdotgg#8177)
* fix(server): keep provider CLIs available in the macOS service (pingdotgg#8173)
* feat(claude): compact old threads before they burn through usage (pingdotgg#8144)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(client-runtime): retry queries after connection interruption (pingdotgg#8117)
* fix(server): keep previously used providers working after upgrades (pingdotgg#8176)
* feat(desktop): build macOS previews from a PR label (pingdotgg#8182)
* fix(web): thread jump hints no longer stick after a dictation paste (pingdotgg#8189)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): keep grouped project renames (pingdotgg#7831)
* feat(web): reveal chat file chips in the system file manager (pingdotgg#7140)
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(server): push no longer writes a feature branch's commits to its base branch (pingdotgg#8228)
* chore(deps): bump @clerk/electron to 0.0.37 (pingdotgg#8240)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(server): fetch legacy model classification from a hosted manifest (pingdotgg#8227)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* chore(release): prepare v0.0.34
* fix(desktop): let Clerk UI receive stable auth fixes (pingdotgg#8248)
* fix(app): un-settled threads return to the top of the list (pingdotgg#8231)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* perf(ci): cut about a minute from every release (pingdotgg#8250)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(ci): download macOS preview DMGs without signing in (pingdotgg#8243)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(codex): accept Codex 0.150 multi-agent events (pingdotgg#8346)
* chore(release): prepare v0.0.35
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
* Require human review for pull requests changing product defaults (pingdotgg#8603)
* fix(codex): avoid quadratic app-server input buffering (pingdotgg#8605)
* fix(mobile): stabilize iOS header item transitions (pingdotgg#8607)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(mobile): upgrade to Expo SDK 57 (pingdotgg#8609)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(mobile): harden native header toolbar items (pingdotgg#8611)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): stop querying Claude context usage after turns (pingdotgg#8610)
* chore: vouch ryanrhughes (pingdotgg#8613)
* feat(web): attach PDFs, ZIPs, and other files to a turn (pingdotgg#8236)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): pass stashShortcutLabel in the mixed-attachments stash test
PRs pingdotgg#8437 and pingdotgg#8236 crossed: one made stashShortcutLabel a required
ComposerStashMenu prop, the other added a test case without it, so
main fails web typecheck.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat(web): keybinding settings as settings rows (pingdotgg#8532)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat: let an environment publish themes as a file (pingdotgg#8569)
Co-authored-by: Theo Browne <me@t3.gg>
* fix(web): clean up provider settings list and editor (pingdotgg#8504)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep project picker popup inside the sidebar (pingdotgg#8627)
* fix(mobile): prevent header overflow and back-button artifacts (pingdotgg#8624)
* fix(server): retry automatic thread title generation (pingdotgg#8087)
* fix(client-runtime): refresh edited pull request comments (pingdotgg#8094)
* fix(web): four composer spacing defects (pingdotgg#8090)
* perf(desktop): skip duplicate browser updates (pingdotgg#8018)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): render nested markdown images correctly (pingdotgg#8501)
* fix(web): unify activity logs and composer banners (pingdotgg#8693)
* fix(mobile): reduce dev-client reload and Metro startup cost (pingdotgg#8694)
Co-authored-by: Julius Marminge <julius@mac.lan>
* revert(web): restore previous composer banners (pingdotgg#8733)
* test(web): remove tests for unreachable helpers (pingdotgg#8738)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* feat(mobile): update tool summaries and chat transitions (pingdotgg#8793)
* feat(web): play video attachments in chat (pingdotgg#8688)
* fix(web,mobile): snooze menu no longer offers the same wake time twice (pingdotgg#8741)
* fix(grok): allow model changes in existing threads (pingdotgg#8392)
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
* feat(mobile): pick, share, and receive files in threads (pingdotgg#8237)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): reduce title bar scroll fade height (pingdotgg#8799)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(windows): strip quotes from repaired PATH (pingdotgg#8746)
* fix(web): open agent images in expanded preview (pingdotgg#8807)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(git): follow repository instructions in generated source control text (pingdotgg#8804)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop overpricing cached Claude tokens (pingdotgg#8806)
* fix(web): keep image preview above sidebar control (pingdotgg#8811)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): keep right panel synced with agent edits (pingdotgg#8803)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web,mobile): render Codex citations and artifact templates (pingdotgg#8584)
* chore: add Windows setup script to t3.json (pingdotgg#8814)
* fix(web): fold interim turn responses (pingdotgg#8828)
* fix(web): use circle alert for failed tool calls (pingdotgg#8840)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(mobile): add offline iPhone voice input (pingdotgg#8614)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent pull request metadata overlap (pingdotgg#8790)
* chore(release): prepare v0.0.37
* Add mobile composer attachment menu with video support (pingdotgg#8843)
* fix(mobile): map native menu icon colors explicitly
* fix(web): restore unified activity logs and composer banners (pingdotgg#8734)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
* fix(web): address composer banner review follow-ups (pingdotgg#8850)
* fix(web): widen sync banners and simplify the working timer (pingdotgg#8855)
* fix(preview): improve browser recording quality (pingdotgg#8839)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): mark pull request links as external (pingdotgg#8856)
* fix(mobile): replace Callstack glass with Expo glass (pingdotgg#8862)
* fix(server): skip IDE detection in Claude probes (pingdotgg#8634)
* chore(macroscope): review diagnostic overrides (pingdotgg#8917)
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* fix(contracts): accept CLI event origins (pingdotgg#8905)
* fix(web): hide invalid slash skill completions (pingdotgg#8904)
* fix(mobile): defer draft navigation until submission completes (pingdotgg#8914)
* chore: disable CodeRabbit review status (pingdotgg#8933)
* Delete app.json (pingdotgg#8934)
* fix(web): show scrollbar for wide markdown tables (pingdotgg#8868)
* fix(mobile): shimmer active tool rows (pingdotgg#8932)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(deps): bump Electron to 43.4.1 (pingdotgg#8626)
* fix(chat): smooth worktree setup status (pingdotgg#8922)
* feat(mobile): add video playback with native iOS controls (pingdotgg#8919)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent chat metadata overlap (pingdotgg#8851)
* fix(server): preserve usage cache outside walked roots (pingdotgg#8540)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(mobile): add native image and PDF previews (pingdotgg#8959)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): allow long thread IDs in HTTP routes (pingdotgg#8898)
* fix(shared): preserve Windows shell PATH priority (pingdotgg#8748)
* fix(web): make WSL settings searchable (pingdotgg#8881)
* feat(web): add expand/collapse all control to the files surface (pingdotgg#8889)
* Add auto_review configuration to coderabbit.yaml
* style: format CodeRabbit configuration
* feat(mobile): upload attachments while composing (pingdotgg#8978)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(chat): keep agent activity visible between actions (pingdotgg#8984)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): isolate remote web session cookies (pingdotgg#8085)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(pull-requests): link GitHub references in markdown (pingdotgg#8812)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* perf(server): reduce frequency of full tool call output being loaded into memory from db (pingdotgg#8988)
* feat(web): add pull request list filters (pingdotgg#8809)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(web): search individual settings by detail (pingdotgg#8831)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(client): render viewed images in work logs (pingdotgg#8936)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(client): use package import for markdown image helpers (pingdotgg#9010)
* test: remove static presentation snapshots (pingdotgg#9008)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* perf(server): bound snapshot activity payload memory (pingdotgg#9000)
* perf(server): cut idle CPU use and stop provider event leaks (pingdotgg#8187)
* perf(server): scan only appended transcript bytes for usage summaries (pingdotgg#9024)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): cut chatty tool-update frames by 90% (pingdotgg#8368)
* fix(server): settle threads server-side (pingdotgg#8600)
* fix(clients): dedupe skills in composer menus (pingdotgg#8043)
* fix(server): stop OpenCode child sessions (pingdotgg#9005)
* perf(web): defer pull request line stats until visible (pingdotgg#6471)
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): skip full-message reads while streaming (pingdotgg#9032)
* perf(client-runtime): halve server config bootstrap traffic (pingdotgg#8367)
Reuse one server config subscription for session bootstrap and live updates.
Preserve environment theme opt-in, replay, deletion, slow subscriber recovery, and config stream failure handling.
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
* fix(web): align un-settle banner action (pingdotgg#9033)
* fix(web): block type-to-focus behind open dialogs (pingdotgg#8139)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(shortcuts): copy active thread reference (pingdotgg#8994)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(mobile): keep thread scroll bounds current after animations (pingdotgg#9013)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): cache project favicon resolution (pingdotgg#9080)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(claude): add Claude Fable 5.1 model (pingdotgg#9078)
* fix(preview): restore recording and macOS rendering after Electron 43 (pingdotgg#9001)
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
* feat(desktop): add configurable quit shortcut confirmation (pingdotgg#9076)
* feat(web): open project settings from thread menus (pingdotgg#8925)
* fix(chat): reuse one row for live activity (pingdotgg#9062)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(models): discover Claude models from remote manifest (pingdotgg#9084)
* Revert "fix(chat): reuse one row for live activity" (pingdotgg#9096)
* fix(web): sync sidebar PR state from open panel (pingdotgg#9092)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): changing projects no longer creates a draft (pingdotgg#9097)
* fix(web): keep theme placeholder text dimmer than entered text (pingdotgg#9104)
* fix(web): keep the selected environment when changing projects (pingdotgg#9102)
* docs(plans): t3o-31 upstream sync to v0.0.38
* fix(board): clear the ten pre-existing typecheck errors before the upstream sync (t3o-31 P0)
Two test fakes failed with a bare Error in the Effect failure channel, a
closure-assigned let narrowed to never, and a single-override pill read
overriddenRows[0] under noUncheckedIndexedAccess. None changed behaviour;
they were masked because the recursive typecheck never reached apps/server.
* fix(sync): the three type errors and two test failures the v0.0.38 merge caused
- BoardModelRow reads planModeEnabled from client settings, as the composer does.
- findBranchPullRequest resolves the default branch for upstream's widened PR
cache key instead of passing null.
- The orphaned-session integration test mocks the supervisor reactor that the
startup seam yields (new inventory row).
- The projection resume test seeds board projector watermarks into
boards.projection_state, where t3o-26 reads them, and asserts over the union.
- searchSettings("work") now also matches upstream's worktree/network items.
* refactor(board): native title attributes become BoardHint tooltips
Upstream's new no-native-title-tooltip rule flags every intrinsic-element
title= in the board (61 sites). BoardHint wraps the styled Tooltip primitive
and renders its child as the trigger, so layout is unchanged; a nullish label
renders the child alone.
* docs(seams): record the v0.0.38 sync (t3o-31)
Merge-log row, the decisions taken (plans stay tracked, upstream's settlement
reactor accepted after audit, projector-enumeration policy, launcher protocol
note), an unmarked-edits debt table for the next sync, a marker census, the
three new upstream workflows to disable, and the runbook's per-package
verification notes.
* review(t3o-31): announce the board's status dots, and order the merge log
Round-1 nitpicks: a bare span's aria-label is not announced, so the working,
running and awaiting dots now carry role="img"; the v0.0.38 merge-log row
moves below the two 2026-08-09 rows so the table reads chronologically.
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: abcdmku <63693423+abcdmku@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: Rishet11 <154429365+Rishet11@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Naveed Iqbal <naveediqbal949@gmail.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: Tristan Knight <admin@snappeh.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Pavlo Trinko <paul.trinko95@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Rodrigo Brechard <rodrigobrechard@gmail.com>
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
Co-authored-by: spiky02plateau <155588579+spiky02plateau@users.noreply.github.com>
Co-authored-by: Carlos Jimenez <cjimenez@r21digital.com>
Co-authored-by: Mark Griffin <mrmg@deflexion.net>
Co-authored-by: MacKinley Smith <smithmackinley@gmail.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Mohtasham Murshid <154406804+MohtashamMurshid@users.noreply.github.com>
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
Co-authored-by: Vitaly Iegorov <vitalyiegorov@gmail.com>
Co-authored-by: Ahmed Besic <ahmed.besic2000@gmail.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: Matthew Feroz <136640686+MatthewFeroz@users.noreply.github.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: Will Sheldon <will@autimo.com>
Co-authored-by: mic <85814106+q1@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Integrated browser preview blocks OAuth popup authentication

3 participants

@walid-baharwal@MatthewFeroz@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(desktop): oauth popups open from the browser preview - #8435

Merged
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups
Aug 28, 2026
Merged

fix(desktop): oauth popups open from the browser preview#8435
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups

Conversation

@walid-baharwal

@walid-baharwalwalid-baharwal commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

What Changed

Two changes, both needed for an OAuth popup to work in the integrated browser preview.

apps/web/src/browser/HostedBrowserWebview.tsx sets allowpopups as an attribute on the <webview> element instead of from the ref callback. Electron reads that flag when the guest attaches, and the ref callback runs after the element is already in the DOM, so every preview guest attached with popups disabled.

apps/desktop/src/preview/Manager.ts reads the disposition the window-open handler already received. A new-window disposition with an http or https URL now opens a real window; everything else, target="_blank" links included, keeps loading in the preview tab as before. The popup is created with contextIsolation, sandbox, and nodeIntegration: false set explicitly, since a popup is not a webview attach and never passes the will-attach-webview hardening in DesktopWindow. It also gets a deny-only window-open handler of its own, so a page inside it cannot spawn native windows without limit. about:blank popups keep loading in the preview tab: Chromium copies the guest preferences for them and gives no way to override.

Why

A local app opened in the preview cannot finish an OAuth popup flow. Firebase signInWithPopup(auth, new GoogleAuthProvider()) reports auth/popup-blocked and no window appears, while the same app works in a normal Chrome or Firefox window.

Two separate causes stack up. window.open was denied and the URL was force-loaded into the same webContents, so window.open() returned null (the SDK reads that as a blocked popup) and the in-tab load destroyed the opener the popup needs to postMessage its credential back to. Underneath that, the guest attached with allowpopups false, so Electron blocked the call before the handler ran at all.

Instrumenting will-attach-webview in a running desktop build showed it directly:

[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":false} before
[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":true} after

Surfaces

Desktop only in behavior. The <webview> element lives in apps/web because the desktop app wraps the web client, but the tag only exists inside Electron and remote web previews never reach setWindowOpenHandler. No contract, provider, or docs change.

UI Changes

No layout, styling, or motion changed. The observable difference is whether a popup window exists, captured below in a dev build against a local page that calls window.open(url, name, "width=520,height=640"), the same shape signInWithPopup uses.

Before

window.open() returns null and no window opens.

Before: popup blocked

After

window.open() returns a window handle.

After: popup opens

The popup window itself, sized from the requested window features:

After: the popup window

Verification

Run in a dev desktop build (dev:desktop) with the preview open on a local page:

  • Scripted popup: window.open(...) returns a handle. Handler logged disposition: "new-window" and decided popup.
  • The popup reports window.opener present and typeof require === "undefined", so the opener survives and the hardening applied.
  • A nested window.open from inside the popup returns null.
  • A target="_blank" link logs disposition: "foreground-tab", decides navigate, and loads in the preview tab.
  • previewWindowOpenAction has focused unit tests next to isPreviewRefreshShortcut, the existing pure helper in the same file.

Checks run locally:

  • vp test run apps/desktop/src/preview/Manager.test.ts — 66 passed
  • tsgo --noEmit in apps/web and apps/desktop — clean
  • vp lint and vp fmt --check on the changed files — clean

The attach-timing half is not unit-testable in a meaningful way. A rendered-DOM assertion passes either way, because the ref callback does set the attribute, just too late for Electron to read it.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • Before/after evidence included

Fixes#6561

Written with Claude Opus 5 in Claude Code.


Note

Medium Risk
Changes preview navigation and spawns hardened native windows from third-party pages; security-sensitive but scoped to http/https scripted popups with explicit hardening and nested popup denial.

Overview
Fixes OAuth and other scripted window.open flows in the integrated browser preview by enabling popups at attach time and opening real windows when appropriate instead of navigating the preview tab.

HostedBrowserWebview sets allowpopups="true" on the <webview> element at render time (not in a ref callback), so Electron sees it before the guest attaches.

PreviewManager adds previewWindowOpenAction: scripted popups (new-window + http:/https:) are allowed as separate BrowserWindows with contextIsolation, sandbox, and no Node integration; target="_blank" and non-hardenable URLs (about:blank, file:, javascript:, etc.) still load in the preview tab. Child OAuth windows get a deny-all setWindowOpenHandler via did-create-window.

Unit tests cover the new helper’s popup vs navigate decisions.

Reviewed by Cursor Bugbot for commit 3f60be1. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix OAuth popups in desktop browser preview with hardened window.open handling

  • Adds previewWindowOpenAction in Manager.ts to classify window.open requests: http/https scripted popups return 'popup' and open as real BrowserWindows; target=_blank tabs and disallowed/invalid schemes (about, javascript, file, vscode) return 'navigate' and load in the existing preview tab.
  • New popup windows use hardened webPreferences (contextIsolation: true, nodeIntegration: false, sandbox: true) and deny further window.open calls from within them.
  • Fixes HostedBrowserWebview.tsx so the <webview> element reliably gets the allowpopups attribute at attach time.
  • Behavioral Change: setWindowOpenHandler now receives full details and uses details.url instead of bare url; non-http(s) URLs that previously may have opened as popups now navigate the current tab instead.

Macroscope summarized 3f60be1.

@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e56baf0c-bdec-4082-8fa9-d71789606066

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 27, 2026
Scripted `window.open` calls inside the integrated browser preview were denied
and loaded in the preview tab instead. Firebase `signInWithPopup` got a null
window handle back and reported `auth/popup-blocked`, and the in-tab load also
dropped the opener the popup needs to post the credential back to.
Popups with a `new-window` disposition and an http or https URL now get a real
window, with context isolation and the sandbox turned back on: a popup is not a
webview attach, so the `will-attach-webview` hardening never sees it and an
unoverridden child would inherit the picker preload's relaxed posture.
`about:blank` popups keep loading in the preview tab, since Chromium copies the
guest preferences for them and forbids overriding. Links with `target="_blank"`
are unchanged.
Fixespingdotgg#6561
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from e598878 to 8fa05aeCompareAugust 27, 2026 18:16
Comment threadapps/desktop/src/preview/Manager.ts
Comment threadapps/desktop/src/preview/Manager.ts
An allowed popup carried Electron's default window-open behavior, so a page
inside it could spawn native windows without limit. The popup now denies its
own window.open calls; no OAuth flow opens a second popup.
The popup preferences also drop nodeIntegrationInSubFrames, matching the three
keys every other hardened window in the app sets.
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from d2ce056 to 7c5b69aCompareAugust 27, 2026 18:31
Electron reads allowpopups when the guest attaches. The attribute was set from
the ref callback, which runs after the element is in the DOM, so every preview
guest attached with popups disabled and Electron blocked window.open before the
window-open handler ran.
Verified in a running desktop build: will-attach-webview reported
allowpopups: false before this change and true after.
@walid-baharwal
walid-baharwal marked this pull request as ready for review August 27, 2026 22:31

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding in the web scope: the new allowpopups JSX attribute is the right ownership fix, but its string value conflicts with React's element typing, so apps/web typecheck (tsgo --noEmit) breaks. Details inline.

Posted via Macroscope — UI Consistency

Comment threadapps/web/src/browser/HostedBrowserWebview.tsx Outdated

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

nodeIntegration: false,
sandbox: true,
},
} satisfies Electron.BrowserWindowConstructorOptions;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Popup may inherit picker preload

High Severity

POPUP_WINDOW_OPTIONS overrides isolation flags but never clears preload. Electron merges overrideBrowserWindowOptions with the guest's preferences, so the picker preload can still run in the OAuth window and observe keystrokes and clicks on a third-party login page.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I could not reproduce this one, so I am leaving the code as is. Details, in case I tested the wrong thing.

A popup opened from a webview guest does not inherit the guest's preload, with or without overrideBrowserWindowOptions. I checked with a standalone Electron 41.5.0 app that mirrors the preview setup: a <webview allowpopups> with a preload and contextIsolation=false, whose preload announces itself over IPC on load, then window.open(...) from inside the guest.

The preload reports from the guest and never from the popup:

RESULT preload-ran in: http://127.0.0.1:8899/popup-repro.html
RESULT popup created:

Same result with the override removed, and same with data: and http: popup URLs, so the override is not what is clearing it — the inheritance does not happen in the first place.

One thing worth flagging for anyone reading this later: webContents.getLastWebPreferences() does not report preload at all. It omits the key even for the guest, which definitely has one, so it cannot be used to check this.

If you have a case where the preload does reach the popup, I would like to see it — the exposure you describe would be real, since that preload listens for keydown and pointerdown.

@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR changes production preview behavior by enabling OAuth popup windows and altering Electron renderer security boundaries across the desktop and webview layers. An unresolved security concern about the preview preload potentially reaching third-party OAuth pages still requires validation.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

React types allowpopups as boolean, so the string literal failed apps/web's
tsgo --noEmit. Passing a real boolean typechecks but regresses the fix, since
react-dom drops boolean values for unrecognized attributes and sets nothing,
so the guest would attach with popups disabled again.
Verified after the change: the element carries allowpopups="true" and a
scripted window.open returns a window handle.
@MatthewFeroz

Copy link
Copy Markdown
Contributor

hoping this gets merged!

@MatthewFeroz

Copy link
Copy Markdown
Contributor

I double-checked the preload concern in Electron 41.5.0 and tested it myself. The preview’s preload script ran only inside the preview, not inside the popup. Electron’s code also confirms that preload scripts are not copied into new windows. This matches the author’s test, so I don’t think the Cursor warning is a real issue.

@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Status summary, since the Approvability verdict above predates the current head and reads as the most visible signal on this PR.

That verdict was posted at 8fa05ae and gives one reason: the preview picker preload may still execute in the popup and observe input. Two independent checks say it does not.

I tested it with a standalone Electron 41.5.0 app mirroring the preview setup — a <webview allowpopups> with a preload and contextIsolation=false, the preload announcing itself over IPC. It reports from the guest and never from the popup, with and without overrideBrowserWindowOptions, for both data: and http: popup URLs. @MatthewFeroz reproduced this independently and additionally checked Electron's source, which does not copy preload scripts into new windows.

Worth flagging for anyone testing this themselves: webContents.getLastWebPreferences() omits preload entirely, even for a webContents that has one, so it cannot be used to check this.

The popup is also created with contextIsolation: true, sandbox: true, nodeIntegration: false — verified at runtime as typeof require === "undefined" inside it — and denies its own window.open, so it cannot spawn further windows.

Current head is 8db8d83. All checks green, including Macroscope UI Consistency after the typing fix. Locally: 66 tests in Manager.test.ts pass, tsgo --noEmit clean for apps/web and apps/desktop, lint and format clean on the changed files.

No action needed from me unless something new turns up.

@MatthewFeroz

Copy link
Copy Markdown
Contributor

Just sent a video to the maintainers of this working. Small limitation in this is that passkeys don't function but I think that's out of scope for this PR. Great work!

@juliusmarminge
juliusmarminge merged commit 0e2905e into pingdotgg:mainAug 28, 2026
22 checks passed
@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Thanks for running it and recording the video — I could not produce one myself, so that fills the gap CONTRIBUTING asks for on interaction changes.

On passkeys: that is pre-existing and tracked separately in #5665 ("In app browser not triggering passkey fingerprint to sign in on mac", open since 2026-08-07), so it predates this branch. Nothing here touches WebAuthn — the change only decides whether window.open gets a real window and what preferences that window is created with. A passkey prompt failing inside the preview fails the same way on main today, with or without a popup involved.

So I agree it is out of scope, and I would rather not widen this PR to chase it.

github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Aug 29, 2026
## What's Changed
* fix(grok): improve skills, plans, usage, and turn reliability by @t3dotgg in pingdotgg/t3code#8358
* fix(server): recover stale Codex approval callbacks by @luckyPipewrench in pingdotgg/t3code#5195
* test(server): remove duplicate missing worktree test by @t3-code[bot] in pingdotgg/t3code#8252
* fix(server): replay all un-applied events during projection bootstrap by @krutftw in pingdotgg/t3code#7538
* test: remove low-signal test files by @t3-code[bot] in pingdotgg/t3code#8397
* test: prune trivial error and layout tests by @t3-code[bot] in pingdotgg/t3code#8400
* Fix Android adaptive launcher icon by @colonelpanic8 in pingdotgg/t3code#4332
* feat(web): split provider settings into list and editor by @t3dotgg in pingdotgg/t3code#8380
* fix(codex): accept Codex 0.150 account plans by @gsimone in pingdotgg/t3code#8447
* fix(tooling): allow ignored-only staged changes by @juliusmarminge in pingdotgg/t3code#8468
* fix(mobile): keep iOS home header stable by @juliusmarminge in pingdotgg/t3code#8467
* fix(web): stop showing red x summaries for ordinary tool failures by @t3dotgg in pingdotgg/t3code#8395
* fix(mobile): refine Git action toast glass styling by @juliusmarminge in pingdotgg/t3code#8399
* fix(desktop): allow preview automation in agent-created threads by @t3dotgg in pingdotgg/t3code#8483
* test(web): remove redundant cache key test by @t3-code[bot] in pingdotgg/t3code#8484
* fix(release): move nightly schedule to minute 38 by @t3dotgg in pingdotgg/t3code#8509
* fix(web): stabilize the provider settings editor by @t3dotgg in pingdotgg/t3code#8472
* fix(web): open GitHub pull requests in browser when loading fails by @t3dotgg in pingdotgg/t3code#8507
* fix(codex): show sub-agent models by @t3dotgg in pingdotgg/t3code#8502
* feat(analytics): report connected client platforms by @t3dotgg in pingdotgg/t3code#8481
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB by @t3dotgg in pingdotgg/t3code#8235
* feat(web): toggle a thread's pin from the keyboard by @ipanasenko in pingdotgg/t3code#8440
* fix(web): add back button to project settings by @StiensWout in pingdotgg/t3code#8168
* refactor(mobile): compile semantic themes for Uniwind by @juliusmarminge in pingdotgg/t3code#7327
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times by @ikifar2012 in pingdotgg/t3code#5769
* fix(mobile): show OpenCode model sources in picker by @juliusmarminge in pingdotgg/t3code#8573
* fix(clients): honor project default models in new threads by @anirudhsama in pingdotgg/t3code#6011
* fix(mobile): show file actions on Android by @none23 in pingdotgg/t3code#8215
* fix(connect): explain DPoP connection failures by @extoci in pingdotgg/t3code#8351
* feat(web): make the sidebar project filter a searchable combobox by @SunkenInTime in pingdotgg/t3code#5931
* fix(server): a draft can retry its first send after a failed bootstrap by @shivamhwp in pingdotgg/t3code#8226
* fix(desktop): stop hidden previews draining battery by @Bil0000 in pingdotgg/t3code#8567
* fix(desktop): oauth popups open from the browser preview by @walid-baharwal in pingdotgg/t3code#8435
* fix(web): keep long task drawers usable on small screens by @shivamhwp in pingdotgg/t3code#8313
* fix(opencode): handle child approvals, stops, and model catalogs by @t3dotgg in pingdotgg/t3code#8480
* fix: make thread auto-settling opt-in by @shivamhwp in pingdotgg/t3code#8321
* fix(web): stop session activity timing test from blocking releases by @t3dotgg in pingdotgg/t3code#8585
* fix(mobile): show composer menus when starting a task by @juliusmarminge in pingdotgg/t3code#8587
* fix(web): show the configured stash shortcut by @UtkarshUsername in pingdotgg/t3code#8437
* feat(web): add toggleable confirmation before unpinning a thread by @UtkarshUsername in pingdotgg/t3code#7313
* fix: restore automatic thread settling defaults by @t3dotgg in pingdotgg/t3code#8596
* fix(mobile): restore composer glass and rounded shadows by @juliusmarminge in pingdotgg/t3code#8597
## New Contributors
* @luckyPipewrench made their first contribution in pingdotgg/t3code#5195
* @krutftw made their first contribution in pingdotgg/t3code#7538
* @colonelpanic8 made their first contribution in pingdotgg/t3code#4332
* @ikifar2012 made their first contribution in pingdotgg/t3code#5769
* @walid-baharwal made their first contribution in pingdotgg/t3code#8435
**Full Changelog**: pingdotgg/t3code@v0.0.35...v0.0.36
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.36
aaditagrawal added a commit to aaditagrawal/t3code that referenced this pull request Aug 29, 2026
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
bcotrim pushed a commit to bcotrim/mognet that referenced this pull request Aug 30, 2026
)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
(cherry picked from commit 0e2905e)
brentkelly added a commit to brentkelly/t3code-orchestrator that referenced this pull request Sep 2, 2026
* feat(analytics): threads and turns now know which client started them (pingdotgg#7774)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop marking mixed tool runs as failed (pingdotgg#7893)
* fix(web): command-click spaced folder links (pingdotgg#6439)
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(chat): stop pushing follow-up messages to the top (pingdotgg#7897)
* test(desktop): remove redundant release note assertion (pingdotgg#7873)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): handle wide ordered-list marker edge cases (pingdotgg#7856)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(ssh): restore user PATH for remote servers (pingdotgg#7213)
* fix(desktop): keep tailscale spawn defects from breaking advertised endpoints (pingdotgg#7116)
* fix(web): keep Codex service tier labels readable (pingdotgg#4503)
* fix: render workspace images in chat markdown (pingdotgg#6433)
* fix(clients): keep opening responses visible after turns settle (pingdotgg#7723)
* feat(web): add appearance contrast control (pingdotgg#7906)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop completed Codex threads from staying stuck on working (pingdotgg#7937)
* fix(mobile): preserve markdown image dimensions (pingdotgg#7940)
* fix(web): remove duplicate provider update progress (pingdotgg#7761)
* fix(server): fall back to the remote default branch instead of assuming main (pingdotgg#7078)
* fix(web): give sidebar project menu rows the same side padding as other menus (pingdotgg#7913)
* fix(clients): reconnect after credentials fail during remote server updates (pingdotgg#7953)
* feat(codex): submit thread feedback to OpenAI (pingdotgg#7949)
* fix(server): stop kills lingering Claude work (pingdotgg#5891)
* fix(ci): let Macroscope approve pull requests again (pingdotgg#7970)
* fix(clients): move settled pinned threads into the settled section (pingdotgg#7969)
* perf(ci): speed up release builds and Windows packaging (pingdotgg#7975)
* fix(web): stop tool calls from leaving a blank page in threads (pingdotgg#7971)
* fix(web): stop recovered tool failures from marking work logs red (pingdotgg#7999)
* fix(mobile): isolate markdown image requests (pingdotgg#7942)
* feat(web): redesign skills in `$` menu and in `/` menu (pingdotgg#8009)
* fix(web): restore right panel toggle clicks after closing on desktop (pingdotgg#8016)
* fix(web): keep server update banners flush with the composer (pingdotgg#8000)
* perf(web): reuse work log rows during streaming (pingdotgg#8006)
* fix(web): keep provider badge legible in dark themes (pingdotgg#7968)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): treat configured urls with uppercase schemes as secure (pingdotgg#8005)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(desktop): keep release notes visible while downloading (pingdotgg#6412)
* fix(web): show only providers with usage in usage views (pingdotgg#7563)
* fix(web): prevent expanded tool calls from hiding thread content (pingdotgg#8052)
* test(server): remove no-op live activity tests (pingdotgg#8056)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): clarify terminal sidebar grouping (pingdotgg#7967)
* fix(codex): show app access approval prompts (pingdotgg#8058)
* feat(web): upload image attachments before sending (pingdotgg#8048)
* fix(server): bound OpenCode skill discovery output (pingdotgg#7675)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(mobile): persist thread shelf collapse state (pingdotgg#5152)
* fix(mobile): restore Android tablet thread controls, clean up header (pingdotgg#5385)
* fix(mobile): land the first thread open above the composer on Android (pingdotgg#5585)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(server): check out submodules in a new worktree (pingdotgg#7674)
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
* fix(server): preserve merged PR badges after branch deletion (pingdotgg#6216)
* fix(server): return fresh live pull request reads (pingdotgg#6472)
* fix(web): compare client and server versions as semver, not strings (pingdotgg#7579)
* fix(web): stop follow-ups from leaving giant blank space (pingdotgg#8068)
* fix(marketing): stop automatic Vercel deployments on pull requests (pingdotgg#8070)
* chore: vouch repeat contributors (pingdotgg#8071)
* fix(server): keep the authoritative subagent model when snapshots race task_started (pingdotgg#7583)
* fix(server): honor auto-accept edits for the OpenCode provider (pingdotgg#7100)
* fix(server): run the CLI on Node versions without import.meta.main (pingdotgg#7141)
* fix(server): recover from provider interrupt failures (pingdotgg#7412)
* fix(server): recreate a thread's worktree before starting a turn (pingdotgg#7839)
* fix(server): thread delete no longer fails on already-removed worktrees (pingdotgg#8076)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop update notices showing through the composer (pingdotgg#8083)
* fix(web): detect outdated nightly servers (pingdotgg#8124)
* fix(web): align usage page skeleton layout (pingdotgg#8111)
* fix(web): make terminal links appear clickable only when clickable (pingdotgg#7488)
* fix(web): make Windows file links clickable in chat (pingdotgg#8081)
* fix(web): sort usage models by token count (pingdotgg#8108)
* fix: open agent file links in the file viewer (pingdotgg#8098)
* fix(server): stop routine events from rescanning thread history (pingdotgg#8150)
* fix(deps): stop pnpm installs from changing the lockfile (pingdotgg#8163)
* feat(web): settle and restore threads with a keyboard shortcut (pingdotgg#8089)
* perf(desktop): cut macOS signing calls by 81% (pingdotgg#8093)
* feat: link pull requests to threads (pingdotgg#8160)
* feat(web): safely attach HEIC photos as JPEG images (pingdotgg#8161)
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
* feat(mobile): track device models and OS versions (pingdotgg#8169)
* fix(grok): bound cumulative tool output updates (pingdotgg#7279)
* fix(web): delay thread shortcut hints by 200 ms (pingdotgg#8172)
* fix(server): stop probing Cursor until enabled (pingdotgg#8175)
* docs(release): verify remote updates with database migrations (pingdotgg#8177)
* fix(server): keep provider CLIs available in the macOS service (pingdotgg#8173)
* feat(claude): compact old threads before they burn through usage (pingdotgg#8144)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(client-runtime): retry queries after connection interruption (pingdotgg#8117)
* fix(server): keep previously used providers working after upgrades (pingdotgg#8176)
* feat(desktop): build macOS previews from a PR label (pingdotgg#8182)
* fix(web): thread jump hints no longer stick after a dictation paste (pingdotgg#8189)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): keep grouped project renames (pingdotgg#7831)
* feat(web): reveal chat file chips in the system file manager (pingdotgg#7140)
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(server): push no longer writes a feature branch's commits to its base branch (pingdotgg#8228)
* chore(deps): bump @clerk/electron to 0.0.37 (pingdotgg#8240)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(server): fetch legacy model classification from a hosted manifest (pingdotgg#8227)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* chore(release): prepare v0.0.34
* fix(desktop): let Clerk UI receive stable auth fixes (pingdotgg#8248)
* fix(app): un-settled threads return to the top of the list (pingdotgg#8231)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* perf(ci): cut about a minute from every release (pingdotgg#8250)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(ci): download macOS preview DMGs without signing in (pingdotgg#8243)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(codex): accept Codex 0.150 multi-agent events (pingdotgg#8346)
* chore(release): prepare v0.0.35
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
* Require human review for pull requests changing product defaults (pingdotgg#8603)
* fix(codex): avoid quadratic app-server input buffering (pingdotgg#8605)
* fix(mobile): stabilize iOS header item transitions (pingdotgg#8607)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(mobile): upgrade to Expo SDK 57 (pingdotgg#8609)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(mobile): harden native header toolbar items (pingdotgg#8611)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): stop querying Claude context usage after turns (pingdotgg#8610)
* chore: vouch ryanrhughes (pingdotgg#8613)
* feat(web): attach PDFs, ZIPs, and other files to a turn (pingdotgg#8236)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): pass stashShortcutLabel in the mixed-attachments stash test
PRs pingdotgg#8437 and pingdotgg#8236 crossed: one made stashShortcutLabel a required
ComposerStashMenu prop, the other added a test case without it, so
main fails web typecheck.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat(web): keybinding settings as settings rows (pingdotgg#8532)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat: let an environment publish themes as a file (pingdotgg#8569)
Co-authored-by: Theo Browne <me@t3.gg>
* fix(web): clean up provider settings list and editor (pingdotgg#8504)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep project picker popup inside the sidebar (pingdotgg#8627)
* fix(mobile): prevent header overflow and back-button artifacts (pingdotgg#8624)
* fix(server): retry automatic thread title generation (pingdotgg#8087)
* fix(client-runtime): refresh edited pull request comments (pingdotgg#8094)
* fix(web): four composer spacing defects (pingdotgg#8090)
* perf(desktop): skip duplicate browser updates (pingdotgg#8018)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): render nested markdown images correctly (pingdotgg#8501)
* fix(web): unify activity logs and composer banners (pingdotgg#8693)
* fix(mobile): reduce dev-client reload and Metro startup cost (pingdotgg#8694)
Co-authored-by: Julius Marminge <julius@mac.lan>
* revert(web): restore previous composer banners (pingdotgg#8733)
* test(web): remove tests for unreachable helpers (pingdotgg#8738)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* feat(mobile): update tool summaries and chat transitions (pingdotgg#8793)
* feat(web): play video attachments in chat (pingdotgg#8688)
* fix(web,mobile): snooze menu no longer offers the same wake time twice (pingdotgg#8741)
* fix(grok): allow model changes in existing threads (pingdotgg#8392)
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
* feat(mobile): pick, share, and receive files in threads (pingdotgg#8237)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): reduce title bar scroll fade height (pingdotgg#8799)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(windows): strip quotes from repaired PATH (pingdotgg#8746)
* fix(web): open agent images in expanded preview (pingdotgg#8807)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(git): follow repository instructions in generated source control text (pingdotgg#8804)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop overpricing cached Claude tokens (pingdotgg#8806)
* fix(web): keep image preview above sidebar control (pingdotgg#8811)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): keep right panel synced with agent edits (pingdotgg#8803)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web,mobile): render Codex citations and artifact templates (pingdotgg#8584)
* chore: add Windows setup script to t3.json (pingdotgg#8814)
* fix(web): fold interim turn responses (pingdotgg#8828)
* fix(web): use circle alert for failed tool calls (pingdotgg#8840)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(mobile): add offline iPhone voice input (pingdotgg#8614)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent pull request metadata overlap (pingdotgg#8790)
* chore(release): prepare v0.0.37
* Add mobile composer attachment menu with video support (pingdotgg#8843)
* fix(mobile): map native menu icon colors explicitly
* fix(web): restore unified activity logs and composer banners (pingdotgg#8734)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
* fix(web): address composer banner review follow-ups (pingdotgg#8850)
* fix(web): widen sync banners and simplify the working timer (pingdotgg#8855)
* fix(preview): improve browser recording quality (pingdotgg#8839)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): mark pull request links as external (pingdotgg#8856)
* fix(mobile): replace Callstack glass with Expo glass (pingdotgg#8862)
* fix(server): skip IDE detection in Claude probes (pingdotgg#8634)
* chore(macroscope): review diagnostic overrides (pingdotgg#8917)
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* fix(contracts): accept CLI event origins (pingdotgg#8905)
* fix(web): hide invalid slash skill completions (pingdotgg#8904)
* fix(mobile): defer draft navigation until submission completes (pingdotgg#8914)
* chore: disable CodeRabbit review status (pingdotgg#8933)
* Delete app.json (pingdotgg#8934)
* fix(web): show scrollbar for wide markdown tables (pingdotgg#8868)
* fix(mobile): shimmer active tool rows (pingdotgg#8932)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(deps): bump Electron to 43.4.1 (pingdotgg#8626)
* fix(chat): smooth worktree setup status (pingdotgg#8922)
* feat(mobile): add video playback with native iOS controls (pingdotgg#8919)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent chat metadata overlap (pingdotgg#8851)
* fix(server): preserve usage cache outside walked roots (pingdotgg#8540)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(mobile): add native image and PDF previews (pingdotgg#8959)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): allow long thread IDs in HTTP routes (pingdotgg#8898)
* fix(shared): preserve Windows shell PATH priority (pingdotgg#8748)
* fix(web): make WSL settings searchable (pingdotgg#8881)
* feat(web): add expand/collapse all control to the files surface (pingdotgg#8889)
* Add auto_review configuration to coderabbit.yaml
* style: format CodeRabbit configuration
* feat(mobile): upload attachments while composing (pingdotgg#8978)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(chat): keep agent activity visible between actions (pingdotgg#8984)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): isolate remote web session cookies (pingdotgg#8085)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(pull-requests): link GitHub references in markdown (pingdotgg#8812)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* perf(server): reduce frequency of full tool call output being loaded into memory from db (pingdotgg#8988)
* feat(web): add pull request list filters (pingdotgg#8809)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(web): search individual settings by detail (pingdotgg#8831)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(client): render viewed images in work logs (pingdotgg#8936)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(client): use package import for markdown image helpers (pingdotgg#9010)
* test: remove static presentation snapshots (pingdotgg#9008)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* perf(server): bound snapshot activity payload memory (pingdotgg#9000)
* perf(server): cut idle CPU use and stop provider event leaks (pingdotgg#8187)
* perf(server): scan only appended transcript bytes for usage summaries (pingdotgg#9024)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): cut chatty tool-update frames by 90% (pingdotgg#8368)
* fix(server): settle threads server-side (pingdotgg#8600)
* fix(clients): dedupe skills in composer menus (pingdotgg#8043)
* fix(server): stop OpenCode child sessions (pingdotgg#9005)
* perf(web): defer pull request line stats until visible (pingdotgg#6471)
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): skip full-message reads while streaming (pingdotgg#9032)
* perf(client-runtime): halve server config bootstrap traffic (pingdotgg#8367)
Reuse one server config subscription for session bootstrap and live updates.
Preserve environment theme opt-in, replay, deletion, slow subscriber recovery, and config stream failure handling.
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
* fix(web): align un-settle banner action (pingdotgg#9033)
* fix(web): block type-to-focus behind open dialogs (pingdotgg#8139)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(shortcuts): copy active thread reference (pingdotgg#8994)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(mobile): keep thread scroll bounds current after animations (pingdotgg#9013)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): cache project favicon resolution (pingdotgg#9080)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(claude): add Claude Fable 5.1 model (pingdotgg#9078)
* fix(preview): restore recording and macOS rendering after Electron 43 (pingdotgg#9001)
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
* feat(desktop): add configurable quit shortcut confirmation (pingdotgg#9076)
* feat(web): open project settings from thread menus (pingdotgg#8925)
* fix(chat): reuse one row for live activity (pingdotgg#9062)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(models): discover Claude models from remote manifest (pingdotgg#9084)
* Revert "fix(chat): reuse one row for live activity" (pingdotgg#9096)
* fix(web): sync sidebar PR state from open panel (pingdotgg#9092)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): changing projects no longer creates a draft (pingdotgg#9097)
* fix(web): keep theme placeholder text dimmer than entered text (pingdotgg#9104)
* fix(web): keep the selected environment when changing projects (pingdotgg#9102)
* docs(plans): t3o-31 upstream sync to v0.0.38
* fix(board): clear the ten pre-existing typecheck errors before the upstream sync (t3o-31 P0)
Two test fakes failed with a bare Error in the Effect failure channel, a
closure-assigned let narrowed to never, and a single-override pill read
overriddenRows[0] under noUncheckedIndexedAccess. None changed behaviour;
they were masked because the recursive typecheck never reached apps/server.
* fix(sync): the three type errors and two test failures the v0.0.38 merge caused
- BoardModelRow reads planModeEnabled from client settings, as the composer does.
- findBranchPullRequest resolves the default branch for upstream's widened PR
cache key instead of passing null.
- The orphaned-session integration test mocks the supervisor reactor that the
startup seam yields (new inventory row).
- The projection resume test seeds board projector watermarks into
boards.projection_state, where t3o-26 reads them, and asserts over the union.
- searchSettings("work") now also matches upstream's worktree/network items.
* refactor(board): native title attributes become BoardHint tooltips
Upstream's new no-native-title-tooltip rule flags every intrinsic-element
title= in the board (61 sites). BoardHint wraps the styled Tooltip primitive
and renders its child as the trigger, so layout is unchanged; a nullish label
renders the child alone.
* docs(seams): record the v0.0.38 sync (t3o-31)
Merge-log row, the decisions taken (plans stay tracked, upstream's settlement
reactor accepted after audit, projector-enumeration policy, launcher protocol
note), an unmarked-edits debt table for the next sync, a marker census, the
three new upstream workflows to disable, and the runbook's per-package
verification notes.
* review(t3o-31): announce the board's status dots, and order the merge log
Round-1 nitpicks: a bare span's aria-label is not announced, so the working,
running and awaiting dots now carry role="img"; the v0.0.38 merge-log row
moves below the two 2026-08-09 rows so the table reads chronologically.
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: abcdmku <63693423+abcdmku@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: Rishet11 <154429365+Rishet11@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Naveed Iqbal <naveediqbal949@gmail.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: Tristan Knight <admin@snappeh.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Pavlo Trinko <paul.trinko95@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Rodrigo Brechard <rodrigobrechard@gmail.com>
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
Co-authored-by: spiky02plateau <155588579+spiky02plateau@users.noreply.github.com>
Co-authored-by: Carlos Jimenez <cjimenez@r21digital.com>
Co-authored-by: Mark Griffin <mrmg@deflexion.net>
Co-authored-by: MacKinley Smith <smithmackinley@gmail.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Mohtasham Murshid <154406804+MohtashamMurshid@users.noreply.github.com>
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
Co-authored-by: Vitaly Iegorov <vitalyiegorov@gmail.com>
Co-authored-by: Ahmed Besic <ahmed.besic2000@gmail.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: Matthew Feroz <136640686+MatthewFeroz@users.noreply.github.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: Will Sheldon <will@autimo.com>
Co-authored-by: mic <85814106+q1@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Integrated browser preview blocks OAuth popup authentication

3 participants

@walid-baharwal@MatthewFeroz@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(desktop): oauth popups open from the browser preview - #8435

Merged
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups
Aug 28, 2026
Merged

fix(desktop): oauth popups open from the browser preview#8435
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups

Conversation

@walid-baharwal

@walid-baharwalwalid-baharwal commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

What Changed

Two changes, both needed for an OAuth popup to work in the integrated browser preview.

apps/web/src/browser/HostedBrowserWebview.tsx sets allowpopups as an attribute on the <webview> element instead of from the ref callback. Electron reads that flag when the guest attaches, and the ref callback runs after the element is already in the DOM, so every preview guest attached with popups disabled.

apps/desktop/src/preview/Manager.ts reads the disposition the window-open handler already received. A new-window disposition with an http or https URL now opens a real window; everything else, target="_blank" links included, keeps loading in the preview tab as before. The popup is created with contextIsolation, sandbox, and nodeIntegration: false set explicitly, since a popup is not a webview attach and never passes the will-attach-webview hardening in DesktopWindow. It also gets a deny-only window-open handler of its own, so a page inside it cannot spawn native windows without limit. about:blank popups keep loading in the preview tab: Chromium copies the guest preferences for them and gives no way to override.

Why

A local app opened in the preview cannot finish an OAuth popup flow. Firebase signInWithPopup(auth, new GoogleAuthProvider()) reports auth/popup-blocked and no window appears, while the same app works in a normal Chrome or Firefox window.

Two separate causes stack up. window.open was denied and the URL was force-loaded into the same webContents, so window.open() returned null (the SDK reads that as a blocked popup) and the in-tab load destroyed the opener the popup needs to postMessage its credential back to. Underneath that, the guest attached with allowpopups false, so Electron blocked the call before the handler ran at all.

Instrumenting will-attach-webview in a running desktop build showed it directly:

[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":false} before
[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":true} after

Surfaces

Desktop only in behavior. The <webview> element lives in apps/web because the desktop app wraps the web client, but the tag only exists inside Electron and remote web previews never reach setWindowOpenHandler. No contract, provider, or docs change.

UI Changes

No layout, styling, or motion changed. The observable difference is whether a popup window exists, captured below in a dev build against a local page that calls window.open(url, name, "width=520,height=640"), the same shape signInWithPopup uses.

Before

window.open() returns null and no window opens.

Before: popup blocked

After

window.open() returns a window handle.

After: popup opens

The popup window itself, sized from the requested window features:

After: the popup window

Verification

Run in a dev desktop build (dev:desktop) with the preview open on a local page:

  • Scripted popup: window.open(...) returns a handle. Handler logged disposition: "new-window" and decided popup.
  • The popup reports window.opener present and typeof require === "undefined", so the opener survives and the hardening applied.
  • A nested window.open from inside the popup returns null.
  • A target="_blank" link logs disposition: "foreground-tab", decides navigate, and loads in the preview tab.
  • previewWindowOpenAction has focused unit tests next to isPreviewRefreshShortcut, the existing pure helper in the same file.

Checks run locally:

  • vp test run apps/desktop/src/preview/Manager.test.ts — 66 passed
  • tsgo --noEmit in apps/web and apps/desktop — clean
  • vp lint and vp fmt --check on the changed files — clean

The attach-timing half is not unit-testable in a meaningful way. A rendered-DOM assertion passes either way, because the ref callback does set the attribute, just too late for Electron to read it.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • Before/after evidence included

Fixes#6561

Written with Claude Opus 5 in Claude Code.


Note

Medium Risk
Changes preview navigation and spawns hardened native windows from third-party pages; security-sensitive but scoped to http/https scripted popups with explicit hardening and nested popup denial.

Overview
Fixes OAuth and other scripted window.open flows in the integrated browser preview by enabling popups at attach time and opening real windows when appropriate instead of navigating the preview tab.

HostedBrowserWebview sets allowpopups="true" on the <webview> element at render time (not in a ref callback), so Electron sees it before the guest attaches.

PreviewManager adds previewWindowOpenAction: scripted popups (new-window + http:/https:) are allowed as separate BrowserWindows with contextIsolation, sandbox, and no Node integration; target="_blank" and non-hardenable URLs (about:blank, file:, javascript:, etc.) still load in the preview tab. Child OAuth windows get a deny-all setWindowOpenHandler via did-create-window.

Unit tests cover the new helper’s popup vs navigate decisions.

Reviewed by Cursor Bugbot for commit 3f60be1. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix OAuth popups in desktop browser preview with hardened window.open handling

  • Adds previewWindowOpenAction in Manager.ts to classify window.open requests: http/https scripted popups return 'popup' and open as real BrowserWindows; target=_blank tabs and disallowed/invalid schemes (about, javascript, file, vscode) return 'navigate' and load in the existing preview tab.
  • New popup windows use hardened webPreferences (contextIsolation: true, nodeIntegration: false, sandbox: true) and deny further window.open calls from within them.
  • Fixes HostedBrowserWebview.tsx so the <webview> element reliably gets the allowpopups attribute at attach time.
  • Behavioral Change: setWindowOpenHandler now receives full details and uses details.url instead of bare url; non-http(s) URLs that previously may have opened as popups now navigate the current tab instead.

Macroscope summarized 3f60be1.

@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e56baf0c-bdec-4082-8fa9-d71789606066

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 27, 2026
Scripted `window.open` calls inside the integrated browser preview were denied
and loaded in the preview tab instead. Firebase `signInWithPopup` got a null
window handle back and reported `auth/popup-blocked`, and the in-tab load also
dropped the opener the popup needs to post the credential back to.
Popups with a `new-window` disposition and an http or https URL now get a real
window, with context isolation and the sandbox turned back on: a popup is not a
webview attach, so the `will-attach-webview` hardening never sees it and an
unoverridden child would inherit the picker preload's relaxed posture.
`about:blank` popups keep loading in the preview tab, since Chromium copies the
guest preferences for them and forbids overriding. Links with `target="_blank"`
are unchanged.
Fixespingdotgg#6561
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from e598878 to 8fa05aeCompareAugust 27, 2026 18:16
Comment threadapps/desktop/src/preview/Manager.ts
Comment threadapps/desktop/src/preview/Manager.ts
An allowed popup carried Electron's default window-open behavior, so a page
inside it could spawn native windows without limit. The popup now denies its
own window.open calls; no OAuth flow opens a second popup.
The popup preferences also drop nodeIntegrationInSubFrames, matching the three
keys every other hardened window in the app sets.
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from d2ce056 to 7c5b69aCompareAugust 27, 2026 18:31
Electron reads allowpopups when the guest attaches. The attribute was set from
the ref callback, which runs after the element is in the DOM, so every preview
guest attached with popups disabled and Electron blocked window.open before the
window-open handler ran.
Verified in a running desktop build: will-attach-webview reported
allowpopups: false before this change and true after.
@walid-baharwal
walid-baharwal marked this pull request as ready for review August 27, 2026 22:31

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding in the web scope: the new allowpopups JSX attribute is the right ownership fix, but its string value conflicts with React's element typing, so apps/web typecheck (tsgo --noEmit) breaks. Details inline.

Posted via Macroscope — UI Consistency

Comment threadapps/web/src/browser/HostedBrowserWebview.tsx Outdated

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

nodeIntegration: false,
sandbox: true,
},
} satisfies Electron.BrowserWindowConstructorOptions;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Popup may inherit picker preload

High Severity

POPUP_WINDOW_OPTIONS overrides isolation flags but never clears preload. Electron merges overrideBrowserWindowOptions with the guest's preferences, so the picker preload can still run in the OAuth window and observe keystrokes and clicks on a third-party login page.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I could not reproduce this one, so I am leaving the code as is. Details, in case I tested the wrong thing.

A popup opened from a webview guest does not inherit the guest's preload, with or without overrideBrowserWindowOptions. I checked with a standalone Electron 41.5.0 app that mirrors the preview setup: a <webview allowpopups> with a preload and contextIsolation=false, whose preload announces itself over IPC on load, then window.open(...) from inside the guest.

The preload reports from the guest and never from the popup:

RESULT preload-ran in: http://127.0.0.1:8899/popup-repro.html
RESULT popup created:

Same result with the override removed, and same with data: and http: popup URLs, so the override is not what is clearing it — the inheritance does not happen in the first place.

One thing worth flagging for anyone reading this later: webContents.getLastWebPreferences() does not report preload at all. It omits the key even for the guest, which definitely has one, so it cannot be used to check this.

If you have a case where the preload does reach the popup, I would like to see it — the exposure you describe would be real, since that preload listens for keydown and pointerdown.

@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR changes production preview behavior by enabling OAuth popup windows and altering Electron renderer security boundaries across the desktop and webview layers. An unresolved security concern about the preview preload potentially reaching third-party OAuth pages still requires validation.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

React types allowpopups as boolean, so the string literal failed apps/web's
tsgo --noEmit. Passing a real boolean typechecks but regresses the fix, since
react-dom drops boolean values for unrecognized attributes and sets nothing,
so the guest would attach with popups disabled again.
Verified after the change: the element carries allowpopups="true" and a
scripted window.open returns a window handle.
@MatthewFeroz

Copy link
Copy Markdown
Contributor

hoping this gets merged!

@MatthewFeroz

Copy link
Copy Markdown
Contributor

I double-checked the preload concern in Electron 41.5.0 and tested it myself. The preview’s preload script ran only inside the preview, not inside the popup. Electron’s code also confirms that preload scripts are not copied into new windows. This matches the author’s test, so I don’t think the Cursor warning is a real issue.

@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Status summary, since the Approvability verdict above predates the current head and reads as the most visible signal on this PR.

That verdict was posted at 8fa05ae and gives one reason: the preview picker preload may still execute in the popup and observe input. Two independent checks say it does not.

I tested it with a standalone Electron 41.5.0 app mirroring the preview setup — a <webview allowpopups> with a preload and contextIsolation=false, the preload announcing itself over IPC. It reports from the guest and never from the popup, with and without overrideBrowserWindowOptions, for both data: and http: popup URLs. @MatthewFeroz reproduced this independently and additionally checked Electron's source, which does not copy preload scripts into new windows.

Worth flagging for anyone testing this themselves: webContents.getLastWebPreferences() omits preload entirely, even for a webContents that has one, so it cannot be used to check this.

The popup is also created with contextIsolation: true, sandbox: true, nodeIntegration: false — verified at runtime as typeof require === "undefined" inside it — and denies its own window.open, so it cannot spawn further windows.

Current head is 8db8d83. All checks green, including Macroscope UI Consistency after the typing fix. Locally: 66 tests in Manager.test.ts pass, tsgo --noEmit clean for apps/web and apps/desktop, lint and format clean on the changed files.

No action needed from me unless something new turns up.

@MatthewFeroz

Copy link
Copy Markdown
Contributor

Just sent a video to the maintainers of this working. Small limitation in this is that passkeys don't function but I think that's out of scope for this PR. Great work!

@juliusmarminge
juliusmarminge merged commit 0e2905e into pingdotgg:mainAug 28, 2026
22 checks passed
@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Thanks for running it and recording the video — I could not produce one myself, so that fills the gap CONTRIBUTING asks for on interaction changes.

On passkeys: that is pre-existing and tracked separately in #5665 ("In app browser not triggering passkey fingerprint to sign in on mac", open since 2026-08-07), so it predates this branch. Nothing here touches WebAuthn — the change only decides whether window.open gets a real window and what preferences that window is created with. A passkey prompt failing inside the preview fails the same way on main today, with or without a popup involved.

So I agree it is out of scope, and I would rather not widen this PR to chase it.

github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Aug 29, 2026
## What's Changed
* fix(grok): improve skills, plans, usage, and turn reliability by @t3dotgg in pingdotgg/t3code#8358
* fix(server): recover stale Codex approval callbacks by @luckyPipewrench in pingdotgg/t3code#5195
* test(server): remove duplicate missing worktree test by @t3-code[bot] in pingdotgg/t3code#8252
* fix(server): replay all un-applied events during projection bootstrap by @krutftw in pingdotgg/t3code#7538
* test: remove low-signal test files by @t3-code[bot] in pingdotgg/t3code#8397
* test: prune trivial error and layout tests by @t3-code[bot] in pingdotgg/t3code#8400
* Fix Android adaptive launcher icon by @colonelpanic8 in pingdotgg/t3code#4332
* feat(web): split provider settings into list and editor by @t3dotgg in pingdotgg/t3code#8380
* fix(codex): accept Codex 0.150 account plans by @gsimone in pingdotgg/t3code#8447
* fix(tooling): allow ignored-only staged changes by @juliusmarminge in pingdotgg/t3code#8468
* fix(mobile): keep iOS home header stable by @juliusmarminge in pingdotgg/t3code#8467
* fix(web): stop showing red x summaries for ordinary tool failures by @t3dotgg in pingdotgg/t3code#8395
* fix(mobile): refine Git action toast glass styling by @juliusmarminge in pingdotgg/t3code#8399
* fix(desktop): allow preview automation in agent-created threads by @t3dotgg in pingdotgg/t3code#8483
* test(web): remove redundant cache key test by @t3-code[bot] in pingdotgg/t3code#8484
* fix(release): move nightly schedule to minute 38 by @t3dotgg in pingdotgg/t3code#8509
* fix(web): stabilize the provider settings editor by @t3dotgg in pingdotgg/t3code#8472
* fix(web): open GitHub pull requests in browser when loading fails by @t3dotgg in pingdotgg/t3code#8507
* fix(codex): show sub-agent models by @t3dotgg in pingdotgg/t3code#8502
* feat(analytics): report connected client platforms by @t3dotgg in pingdotgg/t3code#8481
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB by @t3dotgg in pingdotgg/t3code#8235
* feat(web): toggle a thread's pin from the keyboard by @ipanasenko in pingdotgg/t3code#8440
* fix(web): add back button to project settings by @StiensWout in pingdotgg/t3code#8168
* refactor(mobile): compile semantic themes for Uniwind by @juliusmarminge in pingdotgg/t3code#7327
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times by @ikifar2012 in pingdotgg/t3code#5769
* fix(mobile): show OpenCode model sources in picker by @juliusmarminge in pingdotgg/t3code#8573
* fix(clients): honor project default models in new threads by @anirudhsama in pingdotgg/t3code#6011
* fix(mobile): show file actions on Android by @none23 in pingdotgg/t3code#8215
* fix(connect): explain DPoP connection failures by @extoci in pingdotgg/t3code#8351
* feat(web): make the sidebar project filter a searchable combobox by @SunkenInTime in pingdotgg/t3code#5931
* fix(server): a draft can retry its first send after a failed bootstrap by @shivamhwp in pingdotgg/t3code#8226
* fix(desktop): stop hidden previews draining battery by @Bil0000 in pingdotgg/t3code#8567
* fix(desktop): oauth popups open from the browser preview by @walid-baharwal in pingdotgg/t3code#8435
* fix(web): keep long task drawers usable on small screens by @shivamhwp in pingdotgg/t3code#8313
* fix(opencode): handle child approvals, stops, and model catalogs by @t3dotgg in pingdotgg/t3code#8480
* fix: make thread auto-settling opt-in by @shivamhwp in pingdotgg/t3code#8321
* fix(web): stop session activity timing test from blocking releases by @t3dotgg in pingdotgg/t3code#8585
* fix(mobile): show composer menus when starting a task by @juliusmarminge in pingdotgg/t3code#8587
* fix(web): show the configured stash shortcut by @UtkarshUsername in pingdotgg/t3code#8437
* feat(web): add toggleable confirmation before unpinning a thread by @UtkarshUsername in pingdotgg/t3code#7313
* fix: restore automatic thread settling defaults by @t3dotgg in pingdotgg/t3code#8596
* fix(mobile): restore composer glass and rounded shadows by @juliusmarminge in pingdotgg/t3code#8597
## New Contributors
* @luckyPipewrench made their first contribution in pingdotgg/t3code#5195
* @krutftw made their first contribution in pingdotgg/t3code#7538
* @colonelpanic8 made their first contribution in pingdotgg/t3code#4332
* @ikifar2012 made their first contribution in pingdotgg/t3code#5769
* @walid-baharwal made their first contribution in pingdotgg/t3code#8435
**Full Changelog**: pingdotgg/t3code@v0.0.35...v0.0.36
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.36
aaditagrawal added a commit to aaditagrawal/t3code that referenced this pull request Aug 29, 2026
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
bcotrim pushed a commit to bcotrim/mognet that referenced this pull request Aug 30, 2026
)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
(cherry picked from commit 0e2905e)
brentkelly added a commit to brentkelly/t3code-orchestrator that referenced this pull request Sep 2, 2026
* feat(analytics): threads and turns now know which client started them (pingdotgg#7774)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop marking mixed tool runs as failed (pingdotgg#7893)
* fix(web): command-click spaced folder links (pingdotgg#6439)
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(chat): stop pushing follow-up messages to the top (pingdotgg#7897)
* test(desktop): remove redundant release note assertion (pingdotgg#7873)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): handle wide ordered-list marker edge cases (pingdotgg#7856)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(ssh): restore user PATH for remote servers (pingdotgg#7213)
* fix(desktop): keep tailscale spawn defects from breaking advertised endpoints (pingdotgg#7116)
* fix(web): keep Codex service tier labels readable (pingdotgg#4503)
* fix: render workspace images in chat markdown (pingdotgg#6433)
* fix(clients): keep opening responses visible after turns settle (pingdotgg#7723)
* feat(web): add appearance contrast control (pingdotgg#7906)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop completed Codex threads from staying stuck on working (pingdotgg#7937)
* fix(mobile): preserve markdown image dimensions (pingdotgg#7940)
* fix(web): remove duplicate provider update progress (pingdotgg#7761)
* fix(server): fall back to the remote default branch instead of assuming main (pingdotgg#7078)
* fix(web): give sidebar project menu rows the same side padding as other menus (pingdotgg#7913)
* fix(clients): reconnect after credentials fail during remote server updates (pingdotgg#7953)
* feat(codex): submit thread feedback to OpenAI (pingdotgg#7949)
* fix(server): stop kills lingering Claude work (pingdotgg#5891)
* fix(ci): let Macroscope approve pull requests again (pingdotgg#7970)
* fix(clients): move settled pinned threads into the settled section (pingdotgg#7969)
* perf(ci): speed up release builds and Windows packaging (pingdotgg#7975)
* fix(web): stop tool calls from leaving a blank page in threads (pingdotgg#7971)
* fix(web): stop recovered tool failures from marking work logs red (pingdotgg#7999)
* fix(mobile): isolate markdown image requests (pingdotgg#7942)
* feat(web): redesign skills in `$` menu and in `/` menu (pingdotgg#8009)
* fix(web): restore right panel toggle clicks after closing on desktop (pingdotgg#8016)
* fix(web): keep server update banners flush with the composer (pingdotgg#8000)
* perf(web): reuse work log rows during streaming (pingdotgg#8006)
* fix(web): keep provider badge legible in dark themes (pingdotgg#7968)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): treat configured urls with uppercase schemes as secure (pingdotgg#8005)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(desktop): keep release notes visible while downloading (pingdotgg#6412)
* fix(web): show only providers with usage in usage views (pingdotgg#7563)
* fix(web): prevent expanded tool calls from hiding thread content (pingdotgg#8052)
* test(server): remove no-op live activity tests (pingdotgg#8056)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): clarify terminal sidebar grouping (pingdotgg#7967)
* fix(codex): show app access approval prompts (pingdotgg#8058)
* feat(web): upload image attachments before sending (pingdotgg#8048)
* fix(server): bound OpenCode skill discovery output (pingdotgg#7675)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(mobile): persist thread shelf collapse state (pingdotgg#5152)
* fix(mobile): restore Android tablet thread controls, clean up header (pingdotgg#5385)
* fix(mobile): land the first thread open above the composer on Android (pingdotgg#5585)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(server): check out submodules in a new worktree (pingdotgg#7674)
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
* fix(server): preserve merged PR badges after branch deletion (pingdotgg#6216)
* fix(server): return fresh live pull request reads (pingdotgg#6472)
* fix(web): compare client and server versions as semver, not strings (pingdotgg#7579)
* fix(web): stop follow-ups from leaving giant blank space (pingdotgg#8068)
* fix(marketing): stop automatic Vercel deployments on pull requests (pingdotgg#8070)
* chore: vouch repeat contributors (pingdotgg#8071)
* fix(server): keep the authoritative subagent model when snapshots race task_started (pingdotgg#7583)
* fix(server): honor auto-accept edits for the OpenCode provider (pingdotgg#7100)
* fix(server): run the CLI on Node versions without import.meta.main (pingdotgg#7141)
* fix(server): recover from provider interrupt failures (pingdotgg#7412)
* fix(server): recreate a thread's worktree before starting a turn (pingdotgg#7839)
* fix(server): thread delete no longer fails on already-removed worktrees (pingdotgg#8076)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop update notices showing through the composer (pingdotgg#8083)
* fix(web): detect outdated nightly servers (pingdotgg#8124)
* fix(web): align usage page skeleton layout (pingdotgg#8111)
* fix(web): make terminal links appear clickable only when clickable (pingdotgg#7488)
* fix(web): make Windows file links clickable in chat (pingdotgg#8081)
* fix(web): sort usage models by token count (pingdotgg#8108)
* fix: open agent file links in the file viewer (pingdotgg#8098)
* fix(server): stop routine events from rescanning thread history (pingdotgg#8150)
* fix(deps): stop pnpm installs from changing the lockfile (pingdotgg#8163)
* feat(web): settle and restore threads with a keyboard shortcut (pingdotgg#8089)
* perf(desktop): cut macOS signing calls by 81% (pingdotgg#8093)
* feat: link pull requests to threads (pingdotgg#8160)
* feat(web): safely attach HEIC photos as JPEG images (pingdotgg#8161)
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
* feat(mobile): track device models and OS versions (pingdotgg#8169)
* fix(grok): bound cumulative tool output updates (pingdotgg#7279)
* fix(web): delay thread shortcut hints by 200 ms (pingdotgg#8172)
* fix(server): stop probing Cursor until enabled (pingdotgg#8175)
* docs(release): verify remote updates with database migrations (pingdotgg#8177)
* fix(server): keep provider CLIs available in the macOS service (pingdotgg#8173)
* feat(claude): compact old threads before they burn through usage (pingdotgg#8144)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(client-runtime): retry queries after connection interruption (pingdotgg#8117)
* fix(server): keep previously used providers working after upgrades (pingdotgg#8176)
* feat(desktop): build macOS previews from a PR label (pingdotgg#8182)
* fix(web): thread jump hints no longer stick after a dictation paste (pingdotgg#8189)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): keep grouped project renames (pingdotgg#7831)
* feat(web): reveal chat file chips in the system file manager (pingdotgg#7140)
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(server): push no longer writes a feature branch's commits to its base branch (pingdotgg#8228)
* chore(deps): bump @clerk/electron to 0.0.37 (pingdotgg#8240)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(server): fetch legacy model classification from a hosted manifest (pingdotgg#8227)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* chore(release): prepare v0.0.34
* fix(desktop): let Clerk UI receive stable auth fixes (pingdotgg#8248)
* fix(app): un-settled threads return to the top of the list (pingdotgg#8231)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* perf(ci): cut about a minute from every release (pingdotgg#8250)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(ci): download macOS preview DMGs without signing in (pingdotgg#8243)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(codex): accept Codex 0.150 multi-agent events (pingdotgg#8346)
* chore(release): prepare v0.0.35
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
* Require human review for pull requests changing product defaults (pingdotgg#8603)
* fix(codex): avoid quadratic app-server input buffering (pingdotgg#8605)
* fix(mobile): stabilize iOS header item transitions (pingdotgg#8607)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(mobile): upgrade to Expo SDK 57 (pingdotgg#8609)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(mobile): harden native header toolbar items (pingdotgg#8611)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): stop querying Claude context usage after turns (pingdotgg#8610)
* chore: vouch ryanrhughes (pingdotgg#8613)
* feat(web): attach PDFs, ZIPs, and other files to a turn (pingdotgg#8236)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): pass stashShortcutLabel in the mixed-attachments stash test
PRs pingdotgg#8437 and pingdotgg#8236 crossed: one made stashShortcutLabel a required
ComposerStashMenu prop, the other added a test case without it, so
main fails web typecheck.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat(web): keybinding settings as settings rows (pingdotgg#8532)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat: let an environment publish themes as a file (pingdotgg#8569)
Co-authored-by: Theo Browne <me@t3.gg>
* fix(web): clean up provider settings list and editor (pingdotgg#8504)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep project picker popup inside the sidebar (pingdotgg#8627)
* fix(mobile): prevent header overflow and back-button artifacts (pingdotgg#8624)
* fix(server): retry automatic thread title generation (pingdotgg#8087)
* fix(client-runtime): refresh edited pull request comments (pingdotgg#8094)
* fix(web): four composer spacing defects (pingdotgg#8090)
* perf(desktop): skip duplicate browser updates (pingdotgg#8018)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): render nested markdown images correctly (pingdotgg#8501)
* fix(web): unify activity logs and composer banners (pingdotgg#8693)
* fix(mobile): reduce dev-client reload and Metro startup cost (pingdotgg#8694)
Co-authored-by: Julius Marminge <julius@mac.lan>
* revert(web): restore previous composer banners (pingdotgg#8733)
* test(web): remove tests for unreachable helpers (pingdotgg#8738)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* feat(mobile): update tool summaries and chat transitions (pingdotgg#8793)
* feat(web): play video attachments in chat (pingdotgg#8688)
* fix(web,mobile): snooze menu no longer offers the same wake time twice (pingdotgg#8741)
* fix(grok): allow model changes in existing threads (pingdotgg#8392)
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
* feat(mobile): pick, share, and receive files in threads (pingdotgg#8237)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): reduce title bar scroll fade height (pingdotgg#8799)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(windows): strip quotes from repaired PATH (pingdotgg#8746)
* fix(web): open agent images in expanded preview (pingdotgg#8807)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(git): follow repository instructions in generated source control text (pingdotgg#8804)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop overpricing cached Claude tokens (pingdotgg#8806)
* fix(web): keep image preview above sidebar control (pingdotgg#8811)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): keep right panel synced with agent edits (pingdotgg#8803)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web,mobile): render Codex citations and artifact templates (pingdotgg#8584)
* chore: add Windows setup script to t3.json (pingdotgg#8814)
* fix(web): fold interim turn responses (pingdotgg#8828)
* fix(web): use circle alert for failed tool calls (pingdotgg#8840)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(mobile): add offline iPhone voice input (pingdotgg#8614)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent pull request metadata overlap (pingdotgg#8790)
* chore(release): prepare v0.0.37
* Add mobile composer attachment menu with video support (pingdotgg#8843)
* fix(mobile): map native menu icon colors explicitly
* fix(web): restore unified activity logs and composer banners (pingdotgg#8734)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
* fix(web): address composer banner review follow-ups (pingdotgg#8850)
* fix(web): widen sync banners and simplify the working timer (pingdotgg#8855)
* fix(preview): improve browser recording quality (pingdotgg#8839)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): mark pull request links as external (pingdotgg#8856)
* fix(mobile): replace Callstack glass with Expo glass (pingdotgg#8862)
* fix(server): skip IDE detection in Claude probes (pingdotgg#8634)
* chore(macroscope): review diagnostic overrides (pingdotgg#8917)
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* fix(contracts): accept CLI event origins (pingdotgg#8905)
* fix(web): hide invalid slash skill completions (pingdotgg#8904)
* fix(mobile): defer draft navigation until submission completes (pingdotgg#8914)
* chore: disable CodeRabbit review status (pingdotgg#8933)
* Delete app.json (pingdotgg#8934)
* fix(web): show scrollbar for wide markdown tables (pingdotgg#8868)
* fix(mobile): shimmer active tool rows (pingdotgg#8932)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(deps): bump Electron to 43.4.1 (pingdotgg#8626)
* fix(chat): smooth worktree setup status (pingdotgg#8922)
* feat(mobile): add video playback with native iOS controls (pingdotgg#8919)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent chat metadata overlap (pingdotgg#8851)
* fix(server): preserve usage cache outside walked roots (pingdotgg#8540)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(mobile): add native image and PDF previews (pingdotgg#8959)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): allow long thread IDs in HTTP routes (pingdotgg#8898)
* fix(shared): preserve Windows shell PATH priority (pingdotgg#8748)
* fix(web): make WSL settings searchable (pingdotgg#8881)
* feat(web): add expand/collapse all control to the files surface (pingdotgg#8889)
* Add auto_review configuration to coderabbit.yaml
* style: format CodeRabbit configuration
* feat(mobile): upload attachments while composing (pingdotgg#8978)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(chat): keep agent activity visible between actions (pingdotgg#8984)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): isolate remote web session cookies (pingdotgg#8085)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(pull-requests): link GitHub references in markdown (pingdotgg#8812)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* perf(server): reduce frequency of full tool call output being loaded into memory from db (pingdotgg#8988)
* feat(web): add pull request list filters (pingdotgg#8809)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(web): search individual settings by detail (pingdotgg#8831)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(client): render viewed images in work logs (pingdotgg#8936)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(client): use package import for markdown image helpers (pingdotgg#9010)
* test: remove static presentation snapshots (pingdotgg#9008)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* perf(server): bound snapshot activity payload memory (pingdotgg#9000)
* perf(server): cut idle CPU use and stop provider event leaks (pingdotgg#8187)
* perf(server): scan only appended transcript bytes for usage summaries (pingdotgg#9024)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): cut chatty tool-update frames by 90% (pingdotgg#8368)
* fix(server): settle threads server-side (pingdotgg#8600)
* fix(clients): dedupe skills in composer menus (pingdotgg#8043)
* fix(server): stop OpenCode child sessions (pingdotgg#9005)
* perf(web): defer pull request line stats until visible (pingdotgg#6471)
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): skip full-message reads while streaming (pingdotgg#9032)
* perf(client-runtime): halve server config bootstrap traffic (pingdotgg#8367)
Reuse one server config subscription for session bootstrap and live updates.
Preserve environment theme opt-in, replay, deletion, slow subscriber recovery, and config stream failure handling.
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
* fix(web): align un-settle banner action (pingdotgg#9033)
* fix(web): block type-to-focus behind open dialogs (pingdotgg#8139)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(shortcuts): copy active thread reference (pingdotgg#8994)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(mobile): keep thread scroll bounds current after animations (pingdotgg#9013)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): cache project favicon resolution (pingdotgg#9080)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(claude): add Claude Fable 5.1 model (pingdotgg#9078)
* fix(preview): restore recording and macOS rendering after Electron 43 (pingdotgg#9001)
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
* feat(desktop): add configurable quit shortcut confirmation (pingdotgg#9076)
* feat(web): open project settings from thread menus (pingdotgg#8925)
* fix(chat): reuse one row for live activity (pingdotgg#9062)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(models): discover Claude models from remote manifest (pingdotgg#9084)
* Revert "fix(chat): reuse one row for live activity" (pingdotgg#9096)
* fix(web): sync sidebar PR state from open panel (pingdotgg#9092)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): changing projects no longer creates a draft (pingdotgg#9097)
* fix(web): keep theme placeholder text dimmer than entered text (pingdotgg#9104)
* fix(web): keep the selected environment when changing projects (pingdotgg#9102)
* docs(plans): t3o-31 upstream sync to v0.0.38
* fix(board): clear the ten pre-existing typecheck errors before the upstream sync (t3o-31 P0)
Two test fakes failed with a bare Error in the Effect failure channel, a
closure-assigned let narrowed to never, and a single-override pill read
overriddenRows[0] under noUncheckedIndexedAccess. None changed behaviour;
they were masked because the recursive typecheck never reached apps/server.
* fix(sync): the three type errors and two test failures the v0.0.38 merge caused
- BoardModelRow reads planModeEnabled from client settings, as the composer does.
- findBranchPullRequest resolves the default branch for upstream's widened PR
cache key instead of passing null.
- The orphaned-session integration test mocks the supervisor reactor that the
startup seam yields (new inventory row).
- The projection resume test seeds board projector watermarks into
boards.projection_state, where t3o-26 reads them, and asserts over the union.
- searchSettings("work") now also matches upstream's worktree/network items.
* refactor(board): native title attributes become BoardHint tooltips
Upstream's new no-native-title-tooltip rule flags every intrinsic-element
title= in the board (61 sites). BoardHint wraps the styled Tooltip primitive
and renders its child as the trigger, so layout is unchanged; a nullish label
renders the child alone.
* docs(seams): record the v0.0.38 sync (t3o-31)
Merge-log row, the decisions taken (plans stay tracked, upstream's settlement
reactor accepted after audit, projector-enumeration policy, launcher protocol
note), an unmarked-edits debt table for the next sync, a marker census, the
three new upstream workflows to disable, and the runbook's per-package
verification notes.
* review(t3o-31): announce the board's status dots, and order the merge log
Round-1 nitpicks: a bare span's aria-label is not announced, so the working,
running and awaiting dots now carry role="img"; the v0.0.38 merge-log row
moves below the two 2026-08-09 rows so the table reads chronologically.
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: abcdmku <63693423+abcdmku@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: Rishet11 <154429365+Rishet11@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Naveed Iqbal <naveediqbal949@gmail.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: Tristan Knight <admin@snappeh.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Pavlo Trinko <paul.trinko95@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Rodrigo Brechard <rodrigobrechard@gmail.com>
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
Co-authored-by: spiky02plateau <155588579+spiky02plateau@users.noreply.github.com>
Co-authored-by: Carlos Jimenez <cjimenez@r21digital.com>
Co-authored-by: Mark Griffin <mrmg@deflexion.net>
Co-authored-by: MacKinley Smith <smithmackinley@gmail.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Mohtasham Murshid <154406804+MohtashamMurshid@users.noreply.github.com>
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
Co-authored-by: Vitaly Iegorov <vitalyiegorov@gmail.com>
Co-authored-by: Ahmed Besic <ahmed.besic2000@gmail.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: Matthew Feroz <136640686+MatthewFeroz@users.noreply.github.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: Will Sheldon <will@autimo.com>
Co-authored-by: mic <85814106+q1@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Integrated browser preview blocks OAuth popup authentication

3 participants

@walid-baharwal@MatthewFeroz@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(desktop): oauth popups open from the browser preview - #8435

Merged
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups
Aug 28, 2026
Merged

fix(desktop): oauth popups open from the browser preview#8435
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups

Conversation

@walid-baharwal

@walid-baharwalwalid-baharwal commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

What Changed

Two changes, both needed for an OAuth popup to work in the integrated browser preview.

apps/web/src/browser/HostedBrowserWebview.tsx sets allowpopups as an attribute on the <webview> element instead of from the ref callback. Electron reads that flag when the guest attaches, and the ref callback runs after the element is already in the DOM, so every preview guest attached with popups disabled.

apps/desktop/src/preview/Manager.ts reads the disposition the window-open handler already received. A new-window disposition with an http or https URL now opens a real window; everything else, target="_blank" links included, keeps loading in the preview tab as before. The popup is created with contextIsolation, sandbox, and nodeIntegration: false set explicitly, since a popup is not a webview attach and never passes the will-attach-webview hardening in DesktopWindow. It also gets a deny-only window-open handler of its own, so a page inside it cannot spawn native windows without limit. about:blank popups keep loading in the preview tab: Chromium copies the guest preferences for them and gives no way to override.

Why

A local app opened in the preview cannot finish an OAuth popup flow. Firebase signInWithPopup(auth, new GoogleAuthProvider()) reports auth/popup-blocked and no window appears, while the same app works in a normal Chrome or Firefox window.

Two separate causes stack up. window.open was denied and the URL was force-loaded into the same webContents, so window.open() returned null (the SDK reads that as a blocked popup) and the in-tab load destroyed the opener the popup needs to postMessage its credential back to. Underneath that, the guest attached with allowpopups false, so Electron blocked the call before the handler ran at all.

Instrumenting will-attach-webview in a running desktop build showed it directly:

[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":false} before
[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":true} after

Surfaces

Desktop only in behavior. The <webview> element lives in apps/web because the desktop app wraps the web client, but the tag only exists inside Electron and remote web previews never reach setWindowOpenHandler. No contract, provider, or docs change.

UI Changes

No layout, styling, or motion changed. The observable difference is whether a popup window exists, captured below in a dev build against a local page that calls window.open(url, name, "width=520,height=640"), the same shape signInWithPopup uses.

Before

window.open() returns null and no window opens.

Before: popup blocked

After

window.open() returns a window handle.

After: popup opens

The popup window itself, sized from the requested window features:

After: the popup window

Verification

Run in a dev desktop build (dev:desktop) with the preview open on a local page:

  • Scripted popup: window.open(...) returns a handle. Handler logged disposition: "new-window" and decided popup.
  • The popup reports window.opener present and typeof require === "undefined", so the opener survives and the hardening applied.
  • A nested window.open from inside the popup returns null.
  • A target="_blank" link logs disposition: "foreground-tab", decides navigate, and loads in the preview tab.
  • previewWindowOpenAction has focused unit tests next to isPreviewRefreshShortcut, the existing pure helper in the same file.

Checks run locally:

  • vp test run apps/desktop/src/preview/Manager.test.ts — 66 passed
  • tsgo --noEmit in apps/web and apps/desktop — clean
  • vp lint and vp fmt --check on the changed files — clean

The attach-timing half is not unit-testable in a meaningful way. A rendered-DOM assertion passes either way, because the ref callback does set the attribute, just too late for Electron to read it.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • Before/after evidence included

Fixes#6561

Written with Claude Opus 5 in Claude Code.


Note

Medium Risk
Changes preview navigation and spawns hardened native windows from third-party pages; security-sensitive but scoped to http/https scripted popups with explicit hardening and nested popup denial.

Overview
Fixes OAuth and other scripted window.open flows in the integrated browser preview by enabling popups at attach time and opening real windows when appropriate instead of navigating the preview tab.

HostedBrowserWebview sets allowpopups="true" on the <webview> element at render time (not in a ref callback), so Electron sees it before the guest attaches.

PreviewManager adds previewWindowOpenAction: scripted popups (new-window + http:/https:) are allowed as separate BrowserWindows with contextIsolation, sandbox, and no Node integration; target="_blank" and non-hardenable URLs (about:blank, file:, javascript:, etc.) still load in the preview tab. Child OAuth windows get a deny-all setWindowOpenHandler via did-create-window.

Unit tests cover the new helper’s popup vs navigate decisions.

Reviewed by Cursor Bugbot for commit 3f60be1. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix OAuth popups in desktop browser preview with hardened window.open handling

  • Adds previewWindowOpenAction in Manager.ts to classify window.open requests: http/https scripted popups return 'popup' and open as real BrowserWindows; target=_blank tabs and disallowed/invalid schemes (about, javascript, file, vscode) return 'navigate' and load in the existing preview tab.
  • New popup windows use hardened webPreferences (contextIsolation: true, nodeIntegration: false, sandbox: true) and deny further window.open calls from within them.
  • Fixes HostedBrowserWebview.tsx so the <webview> element reliably gets the allowpopups attribute at attach time.
  • Behavioral Change: setWindowOpenHandler now receives full details and uses details.url instead of bare url; non-http(s) URLs that previously may have opened as popups now navigate the current tab instead.

Macroscope summarized 3f60be1.

@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e56baf0c-bdec-4082-8fa9-d71789606066

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 27, 2026
Scripted `window.open` calls inside the integrated browser preview were denied
and loaded in the preview tab instead. Firebase `signInWithPopup` got a null
window handle back and reported `auth/popup-blocked`, and the in-tab load also
dropped the opener the popup needs to post the credential back to.
Popups with a `new-window` disposition and an http or https URL now get a real
window, with context isolation and the sandbox turned back on: a popup is not a
webview attach, so the `will-attach-webview` hardening never sees it and an
unoverridden child would inherit the picker preload's relaxed posture.
`about:blank` popups keep loading in the preview tab, since Chromium copies the
guest preferences for them and forbids overriding. Links with `target="_blank"`
are unchanged.
Fixespingdotgg#6561
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from e598878 to 8fa05aeCompareAugust 27, 2026 18:16
Comment threadapps/desktop/src/preview/Manager.ts
Comment threadapps/desktop/src/preview/Manager.ts
An allowed popup carried Electron's default window-open behavior, so a page
inside it could spawn native windows without limit. The popup now denies its
own window.open calls; no OAuth flow opens a second popup.
The popup preferences also drop nodeIntegrationInSubFrames, matching the three
keys every other hardened window in the app sets.
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from d2ce056 to 7c5b69aCompareAugust 27, 2026 18:31
Electron reads allowpopups when the guest attaches. The attribute was set from
the ref callback, which runs after the element is in the DOM, so every preview
guest attached with popups disabled and Electron blocked window.open before the
window-open handler ran.
Verified in a running desktop build: will-attach-webview reported
allowpopups: false before this change and true after.
@walid-baharwal
walid-baharwal marked this pull request as ready for review August 27, 2026 22:31

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding in the web scope: the new allowpopups JSX attribute is the right ownership fix, but its string value conflicts with React's element typing, so apps/web typecheck (tsgo --noEmit) breaks. Details inline.

Posted via Macroscope — UI Consistency

Comment threadapps/web/src/browser/HostedBrowserWebview.tsx Outdated

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

nodeIntegration: false,
sandbox: true,
},
} satisfies Electron.BrowserWindowConstructorOptions;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Popup may inherit picker preload

High Severity

POPUP_WINDOW_OPTIONS overrides isolation flags but never clears preload. Electron merges overrideBrowserWindowOptions with the guest's preferences, so the picker preload can still run in the OAuth window and observe keystrokes and clicks on a third-party login page.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I could not reproduce this one, so I am leaving the code as is. Details, in case I tested the wrong thing.

A popup opened from a webview guest does not inherit the guest's preload, with or without overrideBrowserWindowOptions. I checked with a standalone Electron 41.5.0 app that mirrors the preview setup: a <webview allowpopups> with a preload and contextIsolation=false, whose preload announces itself over IPC on load, then window.open(...) from inside the guest.

The preload reports from the guest and never from the popup:

RESULT preload-ran in: http://127.0.0.1:8899/popup-repro.html
RESULT popup created:

Same result with the override removed, and same with data: and http: popup URLs, so the override is not what is clearing it — the inheritance does not happen in the first place.

One thing worth flagging for anyone reading this later: webContents.getLastWebPreferences() does not report preload at all. It omits the key even for the guest, which definitely has one, so it cannot be used to check this.

If you have a case where the preload does reach the popup, I would like to see it — the exposure you describe would be real, since that preload listens for keydown and pointerdown.

@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR changes production preview behavior by enabling OAuth popup windows and altering Electron renderer security boundaries across the desktop and webview layers. An unresolved security concern about the preview preload potentially reaching third-party OAuth pages still requires validation.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

React types allowpopups as boolean, so the string literal failed apps/web's
tsgo --noEmit. Passing a real boolean typechecks but regresses the fix, since
react-dom drops boolean values for unrecognized attributes and sets nothing,
so the guest would attach with popups disabled again.
Verified after the change: the element carries allowpopups="true" and a
scripted window.open returns a window handle.
@MatthewFeroz

Copy link
Copy Markdown
Contributor

hoping this gets merged!

@MatthewFeroz

Copy link
Copy Markdown
Contributor

I double-checked the preload concern in Electron 41.5.0 and tested it myself. The preview’s preload script ran only inside the preview, not inside the popup. Electron’s code also confirms that preload scripts are not copied into new windows. This matches the author’s test, so I don’t think the Cursor warning is a real issue.

@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Status summary, since the Approvability verdict above predates the current head and reads as the most visible signal on this PR.

That verdict was posted at 8fa05ae and gives one reason: the preview picker preload may still execute in the popup and observe input. Two independent checks say it does not.

I tested it with a standalone Electron 41.5.0 app mirroring the preview setup — a <webview allowpopups> with a preload and contextIsolation=false, the preload announcing itself over IPC. It reports from the guest and never from the popup, with and without overrideBrowserWindowOptions, for both data: and http: popup URLs. @MatthewFeroz reproduced this independently and additionally checked Electron's source, which does not copy preload scripts into new windows.

Worth flagging for anyone testing this themselves: webContents.getLastWebPreferences() omits preload entirely, even for a webContents that has one, so it cannot be used to check this.

The popup is also created with contextIsolation: true, sandbox: true, nodeIntegration: false — verified at runtime as typeof require === "undefined" inside it — and denies its own window.open, so it cannot spawn further windows.

Current head is 8db8d83. All checks green, including Macroscope UI Consistency after the typing fix. Locally: 66 tests in Manager.test.ts pass, tsgo --noEmit clean for apps/web and apps/desktop, lint and format clean on the changed files.

No action needed from me unless something new turns up.

@MatthewFeroz

Copy link
Copy Markdown
Contributor

Just sent a video to the maintainers of this working. Small limitation in this is that passkeys don't function but I think that's out of scope for this PR. Great work!

@juliusmarminge
juliusmarminge merged commit 0e2905e into pingdotgg:mainAug 28, 2026
22 checks passed
@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Thanks for running it and recording the video — I could not produce one myself, so that fills the gap CONTRIBUTING asks for on interaction changes.

On passkeys: that is pre-existing and tracked separately in #5665 ("In app browser not triggering passkey fingerprint to sign in on mac", open since 2026-08-07), so it predates this branch. Nothing here touches WebAuthn — the change only decides whether window.open gets a real window and what preferences that window is created with. A passkey prompt failing inside the preview fails the same way on main today, with or without a popup involved.

So I agree it is out of scope, and I would rather not widen this PR to chase it.

github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Aug 29, 2026
## What's Changed
* fix(grok): improve skills, plans, usage, and turn reliability by @t3dotgg in pingdotgg/t3code#8358
* fix(server): recover stale Codex approval callbacks by @luckyPipewrench in pingdotgg/t3code#5195
* test(server): remove duplicate missing worktree test by @t3-code[bot] in pingdotgg/t3code#8252
* fix(server): replay all un-applied events during projection bootstrap by @krutftw in pingdotgg/t3code#7538
* test: remove low-signal test files by @t3-code[bot] in pingdotgg/t3code#8397
* test: prune trivial error and layout tests by @t3-code[bot] in pingdotgg/t3code#8400
* Fix Android adaptive launcher icon by @colonelpanic8 in pingdotgg/t3code#4332
* feat(web): split provider settings into list and editor by @t3dotgg in pingdotgg/t3code#8380
* fix(codex): accept Codex 0.150 account plans by @gsimone in pingdotgg/t3code#8447
* fix(tooling): allow ignored-only staged changes by @juliusmarminge in pingdotgg/t3code#8468
* fix(mobile): keep iOS home header stable by @juliusmarminge in pingdotgg/t3code#8467
* fix(web): stop showing red x summaries for ordinary tool failures by @t3dotgg in pingdotgg/t3code#8395
* fix(mobile): refine Git action toast glass styling by @juliusmarminge in pingdotgg/t3code#8399
* fix(desktop): allow preview automation in agent-created threads by @t3dotgg in pingdotgg/t3code#8483
* test(web): remove redundant cache key test by @t3-code[bot] in pingdotgg/t3code#8484
* fix(release): move nightly schedule to minute 38 by @t3dotgg in pingdotgg/t3code#8509
* fix(web): stabilize the provider settings editor by @t3dotgg in pingdotgg/t3code#8472
* fix(web): open GitHub pull requests in browser when loading fails by @t3dotgg in pingdotgg/t3code#8507
* fix(codex): show sub-agent models by @t3dotgg in pingdotgg/t3code#8502
* feat(analytics): report connected client platforms by @t3dotgg in pingdotgg/t3code#8481
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB by @t3dotgg in pingdotgg/t3code#8235
* feat(web): toggle a thread's pin from the keyboard by @ipanasenko in pingdotgg/t3code#8440
* fix(web): add back button to project settings by @StiensWout in pingdotgg/t3code#8168
* refactor(mobile): compile semantic themes for Uniwind by @juliusmarminge in pingdotgg/t3code#7327
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times by @ikifar2012 in pingdotgg/t3code#5769
* fix(mobile): show OpenCode model sources in picker by @juliusmarminge in pingdotgg/t3code#8573
* fix(clients): honor project default models in new threads by @anirudhsama in pingdotgg/t3code#6011
* fix(mobile): show file actions on Android by @none23 in pingdotgg/t3code#8215
* fix(connect): explain DPoP connection failures by @extoci in pingdotgg/t3code#8351
* feat(web): make the sidebar project filter a searchable combobox by @SunkenInTime in pingdotgg/t3code#5931
* fix(server): a draft can retry its first send after a failed bootstrap by @shivamhwp in pingdotgg/t3code#8226
* fix(desktop): stop hidden previews draining battery by @Bil0000 in pingdotgg/t3code#8567
* fix(desktop): oauth popups open from the browser preview by @walid-baharwal in pingdotgg/t3code#8435
* fix(web): keep long task drawers usable on small screens by @shivamhwp in pingdotgg/t3code#8313
* fix(opencode): handle child approvals, stops, and model catalogs by @t3dotgg in pingdotgg/t3code#8480
* fix: make thread auto-settling opt-in by @shivamhwp in pingdotgg/t3code#8321
* fix(web): stop session activity timing test from blocking releases by @t3dotgg in pingdotgg/t3code#8585
* fix(mobile): show composer menus when starting a task by @juliusmarminge in pingdotgg/t3code#8587
* fix(web): show the configured stash shortcut by @UtkarshUsername in pingdotgg/t3code#8437
* feat(web): add toggleable confirmation before unpinning a thread by @UtkarshUsername in pingdotgg/t3code#7313
* fix: restore automatic thread settling defaults by @t3dotgg in pingdotgg/t3code#8596
* fix(mobile): restore composer glass and rounded shadows by @juliusmarminge in pingdotgg/t3code#8597
## New Contributors
* @luckyPipewrench made their first contribution in pingdotgg/t3code#5195
* @krutftw made their first contribution in pingdotgg/t3code#7538
* @colonelpanic8 made their first contribution in pingdotgg/t3code#4332
* @ikifar2012 made their first contribution in pingdotgg/t3code#5769
* @walid-baharwal made their first contribution in pingdotgg/t3code#8435
**Full Changelog**: pingdotgg/t3code@v0.0.35...v0.0.36
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.36
aaditagrawal added a commit to aaditagrawal/t3code that referenced this pull request Aug 29, 2026
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
bcotrim pushed a commit to bcotrim/mognet that referenced this pull request Aug 30, 2026
)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
(cherry picked from commit 0e2905e)
brentkelly added a commit to brentkelly/t3code-orchestrator that referenced this pull request Sep 2, 2026
* feat(analytics): threads and turns now know which client started them (pingdotgg#7774)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop marking mixed tool runs as failed (pingdotgg#7893)
* fix(web): command-click spaced folder links (pingdotgg#6439)
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(chat): stop pushing follow-up messages to the top (pingdotgg#7897)
* test(desktop): remove redundant release note assertion (pingdotgg#7873)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): handle wide ordered-list marker edge cases (pingdotgg#7856)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(ssh): restore user PATH for remote servers (pingdotgg#7213)
* fix(desktop): keep tailscale spawn defects from breaking advertised endpoints (pingdotgg#7116)
* fix(web): keep Codex service tier labels readable (pingdotgg#4503)
* fix: render workspace images in chat markdown (pingdotgg#6433)
* fix(clients): keep opening responses visible after turns settle (pingdotgg#7723)
* feat(web): add appearance contrast control (pingdotgg#7906)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop completed Codex threads from staying stuck on working (pingdotgg#7937)
* fix(mobile): preserve markdown image dimensions (pingdotgg#7940)
* fix(web): remove duplicate provider update progress (pingdotgg#7761)
* fix(server): fall back to the remote default branch instead of assuming main (pingdotgg#7078)
* fix(web): give sidebar project menu rows the same side padding as other menus (pingdotgg#7913)
* fix(clients): reconnect after credentials fail during remote server updates (pingdotgg#7953)
* feat(codex): submit thread feedback to OpenAI (pingdotgg#7949)
* fix(server): stop kills lingering Claude work (pingdotgg#5891)
* fix(ci): let Macroscope approve pull requests again (pingdotgg#7970)
* fix(clients): move settled pinned threads into the settled section (pingdotgg#7969)
* perf(ci): speed up release builds and Windows packaging (pingdotgg#7975)
* fix(web): stop tool calls from leaving a blank page in threads (pingdotgg#7971)
* fix(web): stop recovered tool failures from marking work logs red (pingdotgg#7999)
* fix(mobile): isolate markdown image requests (pingdotgg#7942)
* feat(web): redesign skills in `$` menu and in `/` menu (pingdotgg#8009)
* fix(web): restore right panel toggle clicks after closing on desktop (pingdotgg#8016)
* fix(web): keep server update banners flush with the composer (pingdotgg#8000)
* perf(web): reuse work log rows during streaming (pingdotgg#8006)
* fix(web): keep provider badge legible in dark themes (pingdotgg#7968)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): treat configured urls with uppercase schemes as secure (pingdotgg#8005)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(desktop): keep release notes visible while downloading (pingdotgg#6412)
* fix(web): show only providers with usage in usage views (pingdotgg#7563)
* fix(web): prevent expanded tool calls from hiding thread content (pingdotgg#8052)
* test(server): remove no-op live activity tests (pingdotgg#8056)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): clarify terminal sidebar grouping (pingdotgg#7967)
* fix(codex): show app access approval prompts (pingdotgg#8058)
* feat(web): upload image attachments before sending (pingdotgg#8048)
* fix(server): bound OpenCode skill discovery output (pingdotgg#7675)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(mobile): persist thread shelf collapse state (pingdotgg#5152)
* fix(mobile): restore Android tablet thread controls, clean up header (pingdotgg#5385)
* fix(mobile): land the first thread open above the composer on Android (pingdotgg#5585)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(server): check out submodules in a new worktree (pingdotgg#7674)
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
* fix(server): preserve merged PR badges after branch deletion (pingdotgg#6216)
* fix(server): return fresh live pull request reads (pingdotgg#6472)
* fix(web): compare client and server versions as semver, not strings (pingdotgg#7579)
* fix(web): stop follow-ups from leaving giant blank space (pingdotgg#8068)
* fix(marketing): stop automatic Vercel deployments on pull requests (pingdotgg#8070)
* chore: vouch repeat contributors (pingdotgg#8071)
* fix(server): keep the authoritative subagent model when snapshots race task_started (pingdotgg#7583)
* fix(server): honor auto-accept edits for the OpenCode provider (pingdotgg#7100)
* fix(server): run the CLI on Node versions without import.meta.main (pingdotgg#7141)
* fix(server): recover from provider interrupt failures (pingdotgg#7412)
* fix(server): recreate a thread's worktree before starting a turn (pingdotgg#7839)
* fix(server): thread delete no longer fails on already-removed worktrees (pingdotgg#8076)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop update notices showing through the composer (pingdotgg#8083)
* fix(web): detect outdated nightly servers (pingdotgg#8124)
* fix(web): align usage page skeleton layout (pingdotgg#8111)
* fix(web): make terminal links appear clickable only when clickable (pingdotgg#7488)
* fix(web): make Windows file links clickable in chat (pingdotgg#8081)
* fix(web): sort usage models by token count (pingdotgg#8108)
* fix: open agent file links in the file viewer (pingdotgg#8098)
* fix(server): stop routine events from rescanning thread history (pingdotgg#8150)
* fix(deps): stop pnpm installs from changing the lockfile (pingdotgg#8163)
* feat(web): settle and restore threads with a keyboard shortcut (pingdotgg#8089)
* perf(desktop): cut macOS signing calls by 81% (pingdotgg#8093)
* feat: link pull requests to threads (pingdotgg#8160)
* feat(web): safely attach HEIC photos as JPEG images (pingdotgg#8161)
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
* feat(mobile): track device models and OS versions (pingdotgg#8169)
* fix(grok): bound cumulative tool output updates (pingdotgg#7279)
* fix(web): delay thread shortcut hints by 200 ms (pingdotgg#8172)
* fix(server): stop probing Cursor until enabled (pingdotgg#8175)
* docs(release): verify remote updates with database migrations (pingdotgg#8177)
* fix(server): keep provider CLIs available in the macOS service (pingdotgg#8173)
* feat(claude): compact old threads before they burn through usage (pingdotgg#8144)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(client-runtime): retry queries after connection interruption (pingdotgg#8117)
* fix(server): keep previously used providers working after upgrades (pingdotgg#8176)
* feat(desktop): build macOS previews from a PR label (pingdotgg#8182)
* fix(web): thread jump hints no longer stick after a dictation paste (pingdotgg#8189)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): keep grouped project renames (pingdotgg#7831)
* feat(web): reveal chat file chips in the system file manager (pingdotgg#7140)
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(server): push no longer writes a feature branch's commits to its base branch (pingdotgg#8228)
* chore(deps): bump @clerk/electron to 0.0.37 (pingdotgg#8240)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(server): fetch legacy model classification from a hosted manifest (pingdotgg#8227)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* chore(release): prepare v0.0.34
* fix(desktop): let Clerk UI receive stable auth fixes (pingdotgg#8248)
* fix(app): un-settled threads return to the top of the list (pingdotgg#8231)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* perf(ci): cut about a minute from every release (pingdotgg#8250)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(ci): download macOS preview DMGs without signing in (pingdotgg#8243)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(codex): accept Codex 0.150 multi-agent events (pingdotgg#8346)
* chore(release): prepare v0.0.35
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
* Require human review for pull requests changing product defaults (pingdotgg#8603)
* fix(codex): avoid quadratic app-server input buffering (pingdotgg#8605)
* fix(mobile): stabilize iOS header item transitions (pingdotgg#8607)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(mobile): upgrade to Expo SDK 57 (pingdotgg#8609)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(mobile): harden native header toolbar items (pingdotgg#8611)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): stop querying Claude context usage after turns (pingdotgg#8610)
* chore: vouch ryanrhughes (pingdotgg#8613)
* feat(web): attach PDFs, ZIPs, and other files to a turn (pingdotgg#8236)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): pass stashShortcutLabel in the mixed-attachments stash test
PRs pingdotgg#8437 and pingdotgg#8236 crossed: one made stashShortcutLabel a required
ComposerStashMenu prop, the other added a test case without it, so
main fails web typecheck.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat(web): keybinding settings as settings rows (pingdotgg#8532)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat: let an environment publish themes as a file (pingdotgg#8569)
Co-authored-by: Theo Browne <me@t3.gg>
* fix(web): clean up provider settings list and editor (pingdotgg#8504)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep project picker popup inside the sidebar (pingdotgg#8627)
* fix(mobile): prevent header overflow and back-button artifacts (pingdotgg#8624)
* fix(server): retry automatic thread title generation (pingdotgg#8087)
* fix(client-runtime): refresh edited pull request comments (pingdotgg#8094)
* fix(web): four composer spacing defects (pingdotgg#8090)
* perf(desktop): skip duplicate browser updates (pingdotgg#8018)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): render nested markdown images correctly (pingdotgg#8501)
* fix(web): unify activity logs and composer banners (pingdotgg#8693)
* fix(mobile): reduce dev-client reload and Metro startup cost (pingdotgg#8694)
Co-authored-by: Julius Marminge <julius@mac.lan>
* revert(web): restore previous composer banners (pingdotgg#8733)
* test(web): remove tests for unreachable helpers (pingdotgg#8738)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* feat(mobile): update tool summaries and chat transitions (pingdotgg#8793)
* feat(web): play video attachments in chat (pingdotgg#8688)
* fix(web,mobile): snooze menu no longer offers the same wake time twice (pingdotgg#8741)
* fix(grok): allow model changes in existing threads (pingdotgg#8392)
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
* feat(mobile): pick, share, and receive files in threads (pingdotgg#8237)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): reduce title bar scroll fade height (pingdotgg#8799)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(windows): strip quotes from repaired PATH (pingdotgg#8746)
* fix(web): open agent images in expanded preview (pingdotgg#8807)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(git): follow repository instructions in generated source control text (pingdotgg#8804)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop overpricing cached Claude tokens (pingdotgg#8806)
* fix(web): keep image preview above sidebar control (pingdotgg#8811)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): keep right panel synced with agent edits (pingdotgg#8803)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web,mobile): render Codex citations and artifact templates (pingdotgg#8584)
* chore: add Windows setup script to t3.json (pingdotgg#8814)
* fix(web): fold interim turn responses (pingdotgg#8828)
* fix(web): use circle alert for failed tool calls (pingdotgg#8840)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(mobile): add offline iPhone voice input (pingdotgg#8614)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent pull request metadata overlap (pingdotgg#8790)
* chore(release): prepare v0.0.37
* Add mobile composer attachment menu with video support (pingdotgg#8843)
* fix(mobile): map native menu icon colors explicitly
* fix(web): restore unified activity logs and composer banners (pingdotgg#8734)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
* fix(web): address composer banner review follow-ups (pingdotgg#8850)
* fix(web): widen sync banners and simplify the working timer (pingdotgg#8855)
* fix(preview): improve browser recording quality (pingdotgg#8839)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): mark pull request links as external (pingdotgg#8856)
* fix(mobile): replace Callstack glass with Expo glass (pingdotgg#8862)
* fix(server): skip IDE detection in Claude probes (pingdotgg#8634)
* chore(macroscope): review diagnostic overrides (pingdotgg#8917)
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* fix(contracts): accept CLI event origins (pingdotgg#8905)
* fix(web): hide invalid slash skill completions (pingdotgg#8904)
* fix(mobile): defer draft navigation until submission completes (pingdotgg#8914)
* chore: disable CodeRabbit review status (pingdotgg#8933)
* Delete app.json (pingdotgg#8934)
* fix(web): show scrollbar for wide markdown tables (pingdotgg#8868)
* fix(mobile): shimmer active tool rows (pingdotgg#8932)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(deps): bump Electron to 43.4.1 (pingdotgg#8626)
* fix(chat): smooth worktree setup status (pingdotgg#8922)
* feat(mobile): add video playback with native iOS controls (pingdotgg#8919)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent chat metadata overlap (pingdotgg#8851)
* fix(server): preserve usage cache outside walked roots (pingdotgg#8540)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(mobile): add native image and PDF previews (pingdotgg#8959)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): allow long thread IDs in HTTP routes (pingdotgg#8898)
* fix(shared): preserve Windows shell PATH priority (pingdotgg#8748)
* fix(web): make WSL settings searchable (pingdotgg#8881)
* feat(web): add expand/collapse all control to the files surface (pingdotgg#8889)
* Add auto_review configuration to coderabbit.yaml
* style: format CodeRabbit configuration
* feat(mobile): upload attachments while composing (pingdotgg#8978)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(chat): keep agent activity visible between actions (pingdotgg#8984)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): isolate remote web session cookies (pingdotgg#8085)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(pull-requests): link GitHub references in markdown (pingdotgg#8812)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* perf(server): reduce frequency of full tool call output being loaded into memory from db (pingdotgg#8988)
* feat(web): add pull request list filters (pingdotgg#8809)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(web): search individual settings by detail (pingdotgg#8831)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(client): render viewed images in work logs (pingdotgg#8936)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(client): use package import for markdown image helpers (pingdotgg#9010)
* test: remove static presentation snapshots (pingdotgg#9008)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* perf(server): bound snapshot activity payload memory (pingdotgg#9000)
* perf(server): cut idle CPU use and stop provider event leaks (pingdotgg#8187)
* perf(server): scan only appended transcript bytes for usage summaries (pingdotgg#9024)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): cut chatty tool-update frames by 90% (pingdotgg#8368)
* fix(server): settle threads server-side (pingdotgg#8600)
* fix(clients): dedupe skills in composer menus (pingdotgg#8043)
* fix(server): stop OpenCode child sessions (pingdotgg#9005)
* perf(web): defer pull request line stats until visible (pingdotgg#6471)
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): skip full-message reads while streaming (pingdotgg#9032)
* perf(client-runtime): halve server config bootstrap traffic (pingdotgg#8367)
Reuse one server config subscription for session bootstrap and live updates.
Preserve environment theme opt-in, replay, deletion, slow subscriber recovery, and config stream failure handling.
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
* fix(web): align un-settle banner action (pingdotgg#9033)
* fix(web): block type-to-focus behind open dialogs (pingdotgg#8139)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(shortcuts): copy active thread reference (pingdotgg#8994)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(mobile): keep thread scroll bounds current after animations (pingdotgg#9013)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): cache project favicon resolution (pingdotgg#9080)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(claude): add Claude Fable 5.1 model (pingdotgg#9078)
* fix(preview): restore recording and macOS rendering after Electron 43 (pingdotgg#9001)
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
* feat(desktop): add configurable quit shortcut confirmation (pingdotgg#9076)
* feat(web): open project settings from thread menus (pingdotgg#8925)
* fix(chat): reuse one row for live activity (pingdotgg#9062)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(models): discover Claude models from remote manifest (pingdotgg#9084)
* Revert "fix(chat): reuse one row for live activity" (pingdotgg#9096)
* fix(web): sync sidebar PR state from open panel (pingdotgg#9092)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): changing projects no longer creates a draft (pingdotgg#9097)
* fix(web): keep theme placeholder text dimmer than entered text (pingdotgg#9104)
* fix(web): keep the selected environment when changing projects (pingdotgg#9102)
* docs(plans): t3o-31 upstream sync to v0.0.38
* fix(board): clear the ten pre-existing typecheck errors before the upstream sync (t3o-31 P0)
Two test fakes failed with a bare Error in the Effect failure channel, a
closure-assigned let narrowed to never, and a single-override pill read
overriddenRows[0] under noUncheckedIndexedAccess. None changed behaviour;
they were masked because the recursive typecheck never reached apps/server.
* fix(sync): the three type errors and two test failures the v0.0.38 merge caused
- BoardModelRow reads planModeEnabled from client settings, as the composer does.
- findBranchPullRequest resolves the default branch for upstream's widened PR
cache key instead of passing null.
- The orphaned-session integration test mocks the supervisor reactor that the
startup seam yields (new inventory row).
- The projection resume test seeds board projector watermarks into
boards.projection_state, where t3o-26 reads them, and asserts over the union.
- searchSettings("work") now also matches upstream's worktree/network items.
* refactor(board): native title attributes become BoardHint tooltips
Upstream's new no-native-title-tooltip rule flags every intrinsic-element
title= in the board (61 sites). BoardHint wraps the styled Tooltip primitive
and renders its child as the trigger, so layout is unchanged; a nullish label
renders the child alone.
* docs(seams): record the v0.0.38 sync (t3o-31)
Merge-log row, the decisions taken (plans stay tracked, upstream's settlement
reactor accepted after audit, projector-enumeration policy, launcher protocol
note), an unmarked-edits debt table for the next sync, a marker census, the
three new upstream workflows to disable, and the runbook's per-package
verification notes.
* review(t3o-31): announce the board's status dots, and order the merge log
Round-1 nitpicks: a bare span's aria-label is not announced, so the working,
running and awaiting dots now carry role="img"; the v0.0.38 merge-log row
moves below the two 2026-08-09 rows so the table reads chronologically.
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: abcdmku <63693423+abcdmku@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: Rishet11 <154429365+Rishet11@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Naveed Iqbal <naveediqbal949@gmail.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: Tristan Knight <admin@snappeh.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Pavlo Trinko <paul.trinko95@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Rodrigo Brechard <rodrigobrechard@gmail.com>
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
Co-authored-by: spiky02plateau <155588579+spiky02plateau@users.noreply.github.com>
Co-authored-by: Carlos Jimenez <cjimenez@r21digital.com>
Co-authored-by: Mark Griffin <mrmg@deflexion.net>
Co-authored-by: MacKinley Smith <smithmackinley@gmail.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Mohtasham Murshid <154406804+MohtashamMurshid@users.noreply.github.com>
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
Co-authored-by: Vitaly Iegorov <vitalyiegorov@gmail.com>
Co-authored-by: Ahmed Besic <ahmed.besic2000@gmail.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: Matthew Feroz <136640686+MatthewFeroz@users.noreply.github.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: Will Sheldon <will@autimo.com>
Co-authored-by: mic <85814106+q1@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Integrated browser preview blocks OAuth popup authentication

3 participants

@walid-baharwal@MatthewFeroz@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(desktop): oauth popups open from the browser preview - #8435

Merged
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups
Aug 28, 2026
Merged

fix(desktop): oauth popups open from the browser preview#8435
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups

Conversation

@walid-baharwal

@walid-baharwalwalid-baharwal commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

What Changed

Two changes, both needed for an OAuth popup to work in the integrated browser preview.

apps/web/src/browser/HostedBrowserWebview.tsx sets allowpopups as an attribute on the <webview> element instead of from the ref callback. Electron reads that flag when the guest attaches, and the ref callback runs after the element is already in the DOM, so every preview guest attached with popups disabled.

apps/desktop/src/preview/Manager.ts reads the disposition the window-open handler already received. A new-window disposition with an http or https URL now opens a real window; everything else, target="_blank" links included, keeps loading in the preview tab as before. The popup is created with contextIsolation, sandbox, and nodeIntegration: false set explicitly, since a popup is not a webview attach and never passes the will-attach-webview hardening in DesktopWindow. It also gets a deny-only window-open handler of its own, so a page inside it cannot spawn native windows without limit. about:blank popups keep loading in the preview tab: Chromium copies the guest preferences for them and gives no way to override.

Why

A local app opened in the preview cannot finish an OAuth popup flow. Firebase signInWithPopup(auth, new GoogleAuthProvider()) reports auth/popup-blocked and no window appears, while the same app works in a normal Chrome or Firefox window.

Two separate causes stack up. window.open was denied and the URL was force-loaded into the same webContents, so window.open() returned null (the SDK reads that as a blocked popup) and the in-tab load destroyed the opener the popup needs to postMessage its credential back to. Underneath that, the guest attached with allowpopups false, so Electron blocked the call before the handler ran at all.

Instrumenting will-attach-webview in a running desktop build showed it directly:

[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":false} before
[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":true} after

Surfaces

Desktop only in behavior. The <webview> element lives in apps/web because the desktop app wraps the web client, but the tag only exists inside Electron and remote web previews never reach setWindowOpenHandler. No contract, provider, or docs change.

UI Changes

No layout, styling, or motion changed. The observable difference is whether a popup window exists, captured below in a dev build against a local page that calls window.open(url, name, "width=520,height=640"), the same shape signInWithPopup uses.

Before

window.open() returns null and no window opens.

Before: popup blocked

After

window.open() returns a window handle.

After: popup opens

The popup window itself, sized from the requested window features:

After: the popup window

Verification

Run in a dev desktop build (dev:desktop) with the preview open on a local page:

  • Scripted popup: window.open(...) returns a handle. Handler logged disposition: "new-window" and decided popup.
  • The popup reports window.opener present and typeof require === "undefined", so the opener survives and the hardening applied.
  • A nested window.open from inside the popup returns null.
  • A target="_blank" link logs disposition: "foreground-tab", decides navigate, and loads in the preview tab.
  • previewWindowOpenAction has focused unit tests next to isPreviewRefreshShortcut, the existing pure helper in the same file.

Checks run locally:

  • vp test run apps/desktop/src/preview/Manager.test.ts — 66 passed
  • tsgo --noEmit in apps/web and apps/desktop — clean
  • vp lint and vp fmt --check on the changed files — clean

The attach-timing half is not unit-testable in a meaningful way. A rendered-DOM assertion passes either way, because the ref callback does set the attribute, just too late for Electron to read it.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • Before/after evidence included

Fixes#6561

Written with Claude Opus 5 in Claude Code.


Note

Medium Risk
Changes preview navigation and spawns hardened native windows from third-party pages; security-sensitive but scoped to http/https scripted popups with explicit hardening and nested popup denial.

Overview
Fixes OAuth and other scripted window.open flows in the integrated browser preview by enabling popups at attach time and opening real windows when appropriate instead of navigating the preview tab.

HostedBrowserWebview sets allowpopups="true" on the <webview> element at render time (not in a ref callback), so Electron sees it before the guest attaches.

PreviewManager adds previewWindowOpenAction: scripted popups (new-window + http:/https:) are allowed as separate BrowserWindows with contextIsolation, sandbox, and no Node integration; target="_blank" and non-hardenable URLs (about:blank, file:, javascript:, etc.) still load in the preview tab. Child OAuth windows get a deny-all setWindowOpenHandler via did-create-window.

Unit tests cover the new helper’s popup vs navigate decisions.

Reviewed by Cursor Bugbot for commit 3f60be1. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix OAuth popups in desktop browser preview with hardened window.open handling

  • Adds previewWindowOpenAction in Manager.ts to classify window.open requests: http/https scripted popups return 'popup' and open as real BrowserWindows; target=_blank tabs and disallowed/invalid schemes (about, javascript, file, vscode) return 'navigate' and load in the existing preview tab.
  • New popup windows use hardened webPreferences (contextIsolation: true, nodeIntegration: false, sandbox: true) and deny further window.open calls from within them.
  • Fixes HostedBrowserWebview.tsx so the <webview> element reliably gets the allowpopups attribute at attach time.
  • Behavioral Change: setWindowOpenHandler now receives full details and uses details.url instead of bare url; non-http(s) URLs that previously may have opened as popups now navigate the current tab instead.

Macroscope summarized 3f60be1.

@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e56baf0c-bdec-4082-8fa9-d71789606066

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 27, 2026
Scripted `window.open` calls inside the integrated browser preview were denied
and loaded in the preview tab instead. Firebase `signInWithPopup` got a null
window handle back and reported `auth/popup-blocked`, and the in-tab load also
dropped the opener the popup needs to post the credential back to.
Popups with a `new-window` disposition and an http or https URL now get a real
window, with context isolation and the sandbox turned back on: a popup is not a
webview attach, so the `will-attach-webview` hardening never sees it and an
unoverridden child would inherit the picker preload's relaxed posture.
`about:blank` popups keep loading in the preview tab, since Chromium copies the
guest preferences for them and forbids overriding. Links with `target="_blank"`
are unchanged.
Fixespingdotgg#6561
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from e598878 to 8fa05aeCompareAugust 27, 2026 18:16
Comment threadapps/desktop/src/preview/Manager.ts
Comment threadapps/desktop/src/preview/Manager.ts
An allowed popup carried Electron's default window-open behavior, so a page
inside it could spawn native windows without limit. The popup now denies its
own window.open calls; no OAuth flow opens a second popup.
The popup preferences also drop nodeIntegrationInSubFrames, matching the three
keys every other hardened window in the app sets.
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from d2ce056 to 7c5b69aCompareAugust 27, 2026 18:31
Electron reads allowpopups when the guest attaches. The attribute was set from
the ref callback, which runs after the element is in the DOM, so every preview
guest attached with popups disabled and Electron blocked window.open before the
window-open handler ran.
Verified in a running desktop build: will-attach-webview reported
allowpopups: false before this change and true after.
@walid-baharwal
walid-baharwal marked this pull request as ready for review August 27, 2026 22:31

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding in the web scope: the new allowpopups JSX attribute is the right ownership fix, but its string value conflicts with React's element typing, so apps/web typecheck (tsgo --noEmit) breaks. Details inline.

Posted via Macroscope — UI Consistency

Comment threadapps/web/src/browser/HostedBrowserWebview.tsx Outdated

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

nodeIntegration: false,
sandbox: true,
},
} satisfies Electron.BrowserWindowConstructorOptions;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Popup may inherit picker preload

High Severity

POPUP_WINDOW_OPTIONS overrides isolation flags but never clears preload. Electron merges overrideBrowserWindowOptions with the guest's preferences, so the picker preload can still run in the OAuth window and observe keystrokes and clicks on a third-party login page.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I could not reproduce this one, so I am leaving the code as is. Details, in case I tested the wrong thing.

A popup opened from a webview guest does not inherit the guest's preload, with or without overrideBrowserWindowOptions. I checked with a standalone Electron 41.5.0 app that mirrors the preview setup: a <webview allowpopups> with a preload and contextIsolation=false, whose preload announces itself over IPC on load, then window.open(...) from inside the guest.

The preload reports from the guest and never from the popup:

RESULT preload-ran in: http://127.0.0.1:8899/popup-repro.html
RESULT popup created:

Same result with the override removed, and same with data: and http: popup URLs, so the override is not what is clearing it — the inheritance does not happen in the first place.

One thing worth flagging for anyone reading this later: webContents.getLastWebPreferences() does not report preload at all. It omits the key even for the guest, which definitely has one, so it cannot be used to check this.

If you have a case where the preload does reach the popup, I would like to see it — the exposure you describe would be real, since that preload listens for keydown and pointerdown.

@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR changes production preview behavior by enabling OAuth popup windows and altering Electron renderer security boundaries across the desktop and webview layers. An unresolved security concern about the preview preload potentially reaching third-party OAuth pages still requires validation.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

React types allowpopups as boolean, so the string literal failed apps/web's
tsgo --noEmit. Passing a real boolean typechecks but regresses the fix, since
react-dom drops boolean values for unrecognized attributes and sets nothing,
so the guest would attach with popups disabled again.
Verified after the change: the element carries allowpopups="true" and a
scripted window.open returns a window handle.
@MatthewFeroz

Copy link
Copy Markdown
Contributor

hoping this gets merged!

@MatthewFeroz

Copy link
Copy Markdown
Contributor

I double-checked the preload concern in Electron 41.5.0 and tested it myself. The preview’s preload script ran only inside the preview, not inside the popup. Electron’s code also confirms that preload scripts are not copied into new windows. This matches the author’s test, so I don’t think the Cursor warning is a real issue.

@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Status summary, since the Approvability verdict above predates the current head and reads as the most visible signal on this PR.

That verdict was posted at 8fa05ae and gives one reason: the preview picker preload may still execute in the popup and observe input. Two independent checks say it does not.

I tested it with a standalone Electron 41.5.0 app mirroring the preview setup — a <webview allowpopups> with a preload and contextIsolation=false, the preload announcing itself over IPC. It reports from the guest and never from the popup, with and without overrideBrowserWindowOptions, for both data: and http: popup URLs. @MatthewFeroz reproduced this independently and additionally checked Electron's source, which does not copy preload scripts into new windows.

Worth flagging for anyone testing this themselves: webContents.getLastWebPreferences() omits preload entirely, even for a webContents that has one, so it cannot be used to check this.

The popup is also created with contextIsolation: true, sandbox: true, nodeIntegration: false — verified at runtime as typeof require === "undefined" inside it — and denies its own window.open, so it cannot spawn further windows.

Current head is 8db8d83. All checks green, including Macroscope UI Consistency after the typing fix. Locally: 66 tests in Manager.test.ts pass, tsgo --noEmit clean for apps/web and apps/desktop, lint and format clean on the changed files.

No action needed from me unless something new turns up.

@MatthewFeroz

Copy link
Copy Markdown
Contributor

Just sent a video to the maintainers of this working. Small limitation in this is that passkeys don't function but I think that's out of scope for this PR. Great work!

@juliusmarminge
juliusmarminge merged commit 0e2905e into pingdotgg:mainAug 28, 2026
22 checks passed
@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Thanks for running it and recording the video — I could not produce one myself, so that fills the gap CONTRIBUTING asks for on interaction changes.

On passkeys: that is pre-existing and tracked separately in #5665 ("In app browser not triggering passkey fingerprint to sign in on mac", open since 2026-08-07), so it predates this branch. Nothing here touches WebAuthn — the change only decides whether window.open gets a real window and what preferences that window is created with. A passkey prompt failing inside the preview fails the same way on main today, with or without a popup involved.

So I agree it is out of scope, and I would rather not widen this PR to chase it.

github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Aug 29, 2026
## What's Changed
* fix(grok): improve skills, plans, usage, and turn reliability by @t3dotgg in pingdotgg/t3code#8358
* fix(server): recover stale Codex approval callbacks by @luckyPipewrench in pingdotgg/t3code#5195
* test(server): remove duplicate missing worktree test by @t3-code[bot] in pingdotgg/t3code#8252
* fix(server): replay all un-applied events during projection bootstrap by @krutftw in pingdotgg/t3code#7538
* test: remove low-signal test files by @t3-code[bot] in pingdotgg/t3code#8397
* test: prune trivial error and layout tests by @t3-code[bot] in pingdotgg/t3code#8400
* Fix Android adaptive launcher icon by @colonelpanic8 in pingdotgg/t3code#4332
* feat(web): split provider settings into list and editor by @t3dotgg in pingdotgg/t3code#8380
* fix(codex): accept Codex 0.150 account plans by @gsimone in pingdotgg/t3code#8447
* fix(tooling): allow ignored-only staged changes by @juliusmarminge in pingdotgg/t3code#8468
* fix(mobile): keep iOS home header stable by @juliusmarminge in pingdotgg/t3code#8467
* fix(web): stop showing red x summaries for ordinary tool failures by @t3dotgg in pingdotgg/t3code#8395
* fix(mobile): refine Git action toast glass styling by @juliusmarminge in pingdotgg/t3code#8399
* fix(desktop): allow preview automation in agent-created threads by @t3dotgg in pingdotgg/t3code#8483
* test(web): remove redundant cache key test by @t3-code[bot] in pingdotgg/t3code#8484
* fix(release): move nightly schedule to minute 38 by @t3dotgg in pingdotgg/t3code#8509
* fix(web): stabilize the provider settings editor by @t3dotgg in pingdotgg/t3code#8472
* fix(web): open GitHub pull requests in browser when loading fails by @t3dotgg in pingdotgg/t3code#8507
* fix(codex): show sub-agent models by @t3dotgg in pingdotgg/t3code#8502
* feat(analytics): report connected client platforms by @t3dotgg in pingdotgg/t3code#8481
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB by @t3dotgg in pingdotgg/t3code#8235
* feat(web): toggle a thread's pin from the keyboard by @ipanasenko in pingdotgg/t3code#8440
* fix(web): add back button to project settings by @StiensWout in pingdotgg/t3code#8168
* refactor(mobile): compile semantic themes for Uniwind by @juliusmarminge in pingdotgg/t3code#7327
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times by @ikifar2012 in pingdotgg/t3code#5769
* fix(mobile): show OpenCode model sources in picker by @juliusmarminge in pingdotgg/t3code#8573
* fix(clients): honor project default models in new threads by @anirudhsama in pingdotgg/t3code#6011
* fix(mobile): show file actions on Android by @none23 in pingdotgg/t3code#8215
* fix(connect): explain DPoP connection failures by @extoci in pingdotgg/t3code#8351
* feat(web): make the sidebar project filter a searchable combobox by @SunkenInTime in pingdotgg/t3code#5931
* fix(server): a draft can retry its first send after a failed bootstrap by @shivamhwp in pingdotgg/t3code#8226
* fix(desktop): stop hidden previews draining battery by @Bil0000 in pingdotgg/t3code#8567
* fix(desktop): oauth popups open from the browser preview by @walid-baharwal in pingdotgg/t3code#8435
* fix(web): keep long task drawers usable on small screens by @shivamhwp in pingdotgg/t3code#8313
* fix(opencode): handle child approvals, stops, and model catalogs by @t3dotgg in pingdotgg/t3code#8480
* fix: make thread auto-settling opt-in by @shivamhwp in pingdotgg/t3code#8321
* fix(web): stop session activity timing test from blocking releases by @t3dotgg in pingdotgg/t3code#8585
* fix(mobile): show composer menus when starting a task by @juliusmarminge in pingdotgg/t3code#8587
* fix(web): show the configured stash shortcut by @UtkarshUsername in pingdotgg/t3code#8437
* feat(web): add toggleable confirmation before unpinning a thread by @UtkarshUsername in pingdotgg/t3code#7313
* fix: restore automatic thread settling defaults by @t3dotgg in pingdotgg/t3code#8596
* fix(mobile): restore composer glass and rounded shadows by @juliusmarminge in pingdotgg/t3code#8597
## New Contributors
* @luckyPipewrench made their first contribution in pingdotgg/t3code#5195
* @krutftw made their first contribution in pingdotgg/t3code#7538
* @colonelpanic8 made their first contribution in pingdotgg/t3code#4332
* @ikifar2012 made their first contribution in pingdotgg/t3code#5769
* @walid-baharwal made their first contribution in pingdotgg/t3code#8435
**Full Changelog**: pingdotgg/t3code@v0.0.35...v0.0.36
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.36
aaditagrawal added a commit to aaditagrawal/t3code that referenced this pull request Aug 29, 2026
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
bcotrim pushed a commit to bcotrim/mognet that referenced this pull request Aug 30, 2026
)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
(cherry picked from commit 0e2905e)
brentkelly added a commit to brentkelly/t3code-orchestrator that referenced this pull request Sep 2, 2026
* feat(analytics): threads and turns now know which client started them (pingdotgg#7774)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop marking mixed tool runs as failed (pingdotgg#7893)
* fix(web): command-click spaced folder links (pingdotgg#6439)
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(chat): stop pushing follow-up messages to the top (pingdotgg#7897)
* test(desktop): remove redundant release note assertion (pingdotgg#7873)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): handle wide ordered-list marker edge cases (pingdotgg#7856)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(ssh): restore user PATH for remote servers (pingdotgg#7213)
* fix(desktop): keep tailscale spawn defects from breaking advertised endpoints (pingdotgg#7116)
* fix(web): keep Codex service tier labels readable (pingdotgg#4503)
* fix: render workspace images in chat markdown (pingdotgg#6433)
* fix(clients): keep opening responses visible after turns settle (pingdotgg#7723)
* feat(web): add appearance contrast control (pingdotgg#7906)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop completed Codex threads from staying stuck on working (pingdotgg#7937)
* fix(mobile): preserve markdown image dimensions (pingdotgg#7940)
* fix(web): remove duplicate provider update progress (pingdotgg#7761)
* fix(server): fall back to the remote default branch instead of assuming main (pingdotgg#7078)
* fix(web): give sidebar project menu rows the same side padding as other menus (pingdotgg#7913)
* fix(clients): reconnect after credentials fail during remote server updates (pingdotgg#7953)
* feat(codex): submit thread feedback to OpenAI (pingdotgg#7949)
* fix(server): stop kills lingering Claude work (pingdotgg#5891)
* fix(ci): let Macroscope approve pull requests again (pingdotgg#7970)
* fix(clients): move settled pinned threads into the settled section (pingdotgg#7969)
* perf(ci): speed up release builds and Windows packaging (pingdotgg#7975)
* fix(web): stop tool calls from leaving a blank page in threads (pingdotgg#7971)
* fix(web): stop recovered tool failures from marking work logs red (pingdotgg#7999)
* fix(mobile): isolate markdown image requests (pingdotgg#7942)
* feat(web): redesign skills in `$` menu and in `/` menu (pingdotgg#8009)
* fix(web): restore right panel toggle clicks after closing on desktop (pingdotgg#8016)
* fix(web): keep server update banners flush with the composer (pingdotgg#8000)
* perf(web): reuse work log rows during streaming (pingdotgg#8006)
* fix(web): keep provider badge legible in dark themes (pingdotgg#7968)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): treat configured urls with uppercase schemes as secure (pingdotgg#8005)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(desktop): keep release notes visible while downloading (pingdotgg#6412)
* fix(web): show only providers with usage in usage views (pingdotgg#7563)
* fix(web): prevent expanded tool calls from hiding thread content (pingdotgg#8052)
* test(server): remove no-op live activity tests (pingdotgg#8056)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): clarify terminal sidebar grouping (pingdotgg#7967)
* fix(codex): show app access approval prompts (pingdotgg#8058)
* feat(web): upload image attachments before sending (pingdotgg#8048)
* fix(server): bound OpenCode skill discovery output (pingdotgg#7675)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(mobile): persist thread shelf collapse state (pingdotgg#5152)
* fix(mobile): restore Android tablet thread controls, clean up header (pingdotgg#5385)
* fix(mobile): land the first thread open above the composer on Android (pingdotgg#5585)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(server): check out submodules in a new worktree (pingdotgg#7674)
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
* fix(server): preserve merged PR badges after branch deletion (pingdotgg#6216)
* fix(server): return fresh live pull request reads (pingdotgg#6472)
* fix(web): compare client and server versions as semver, not strings (pingdotgg#7579)
* fix(web): stop follow-ups from leaving giant blank space (pingdotgg#8068)
* fix(marketing): stop automatic Vercel deployments on pull requests (pingdotgg#8070)
* chore: vouch repeat contributors (pingdotgg#8071)
* fix(server): keep the authoritative subagent model when snapshots race task_started (pingdotgg#7583)
* fix(server): honor auto-accept edits for the OpenCode provider (pingdotgg#7100)
* fix(server): run the CLI on Node versions without import.meta.main (pingdotgg#7141)
* fix(server): recover from provider interrupt failures (pingdotgg#7412)
* fix(server): recreate a thread's worktree before starting a turn (pingdotgg#7839)
* fix(server): thread delete no longer fails on already-removed worktrees (pingdotgg#8076)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop update notices showing through the composer (pingdotgg#8083)
* fix(web): detect outdated nightly servers (pingdotgg#8124)
* fix(web): align usage page skeleton layout (pingdotgg#8111)
* fix(web): make terminal links appear clickable only when clickable (pingdotgg#7488)
* fix(web): make Windows file links clickable in chat (pingdotgg#8081)
* fix(web): sort usage models by token count (pingdotgg#8108)
* fix: open agent file links in the file viewer (pingdotgg#8098)
* fix(server): stop routine events from rescanning thread history (pingdotgg#8150)
* fix(deps): stop pnpm installs from changing the lockfile (pingdotgg#8163)
* feat(web): settle and restore threads with a keyboard shortcut (pingdotgg#8089)
* perf(desktop): cut macOS signing calls by 81% (pingdotgg#8093)
* feat: link pull requests to threads (pingdotgg#8160)
* feat(web): safely attach HEIC photos as JPEG images (pingdotgg#8161)
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
* feat(mobile): track device models and OS versions (pingdotgg#8169)
* fix(grok): bound cumulative tool output updates (pingdotgg#7279)
* fix(web): delay thread shortcut hints by 200 ms (pingdotgg#8172)
* fix(server): stop probing Cursor until enabled (pingdotgg#8175)
* docs(release): verify remote updates with database migrations (pingdotgg#8177)
* fix(server): keep provider CLIs available in the macOS service (pingdotgg#8173)
* feat(claude): compact old threads before they burn through usage (pingdotgg#8144)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(client-runtime): retry queries after connection interruption (pingdotgg#8117)
* fix(server): keep previously used providers working after upgrades (pingdotgg#8176)
* feat(desktop): build macOS previews from a PR label (pingdotgg#8182)
* fix(web): thread jump hints no longer stick after a dictation paste (pingdotgg#8189)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): keep grouped project renames (pingdotgg#7831)
* feat(web): reveal chat file chips in the system file manager (pingdotgg#7140)
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(server): push no longer writes a feature branch's commits to its base branch (pingdotgg#8228)
* chore(deps): bump @clerk/electron to 0.0.37 (pingdotgg#8240)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(server): fetch legacy model classification from a hosted manifest (pingdotgg#8227)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* chore(release): prepare v0.0.34
* fix(desktop): let Clerk UI receive stable auth fixes (pingdotgg#8248)
* fix(app): un-settled threads return to the top of the list (pingdotgg#8231)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* perf(ci): cut about a minute from every release (pingdotgg#8250)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(ci): download macOS preview DMGs without signing in (pingdotgg#8243)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(codex): accept Codex 0.150 multi-agent events (pingdotgg#8346)
* chore(release): prepare v0.0.35
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
* Require human review for pull requests changing product defaults (pingdotgg#8603)
* fix(codex): avoid quadratic app-server input buffering (pingdotgg#8605)
* fix(mobile): stabilize iOS header item transitions (pingdotgg#8607)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(mobile): upgrade to Expo SDK 57 (pingdotgg#8609)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(mobile): harden native header toolbar items (pingdotgg#8611)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): stop querying Claude context usage after turns (pingdotgg#8610)
* chore: vouch ryanrhughes (pingdotgg#8613)
* feat(web): attach PDFs, ZIPs, and other files to a turn (pingdotgg#8236)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): pass stashShortcutLabel in the mixed-attachments stash test
PRs pingdotgg#8437 and pingdotgg#8236 crossed: one made stashShortcutLabel a required
ComposerStashMenu prop, the other added a test case without it, so
main fails web typecheck.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat(web): keybinding settings as settings rows (pingdotgg#8532)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat: let an environment publish themes as a file (pingdotgg#8569)
Co-authored-by: Theo Browne <me@t3.gg>
* fix(web): clean up provider settings list and editor (pingdotgg#8504)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep project picker popup inside the sidebar (pingdotgg#8627)
* fix(mobile): prevent header overflow and back-button artifacts (pingdotgg#8624)
* fix(server): retry automatic thread title generation (pingdotgg#8087)
* fix(client-runtime): refresh edited pull request comments (pingdotgg#8094)
* fix(web): four composer spacing defects (pingdotgg#8090)
* perf(desktop): skip duplicate browser updates (pingdotgg#8018)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): render nested markdown images correctly (pingdotgg#8501)
* fix(web): unify activity logs and composer banners (pingdotgg#8693)
* fix(mobile): reduce dev-client reload and Metro startup cost (pingdotgg#8694)
Co-authored-by: Julius Marminge <julius@mac.lan>
* revert(web): restore previous composer banners (pingdotgg#8733)
* test(web): remove tests for unreachable helpers (pingdotgg#8738)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* feat(mobile): update tool summaries and chat transitions (pingdotgg#8793)
* feat(web): play video attachments in chat (pingdotgg#8688)
* fix(web,mobile): snooze menu no longer offers the same wake time twice (pingdotgg#8741)
* fix(grok): allow model changes in existing threads (pingdotgg#8392)
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
* feat(mobile): pick, share, and receive files in threads (pingdotgg#8237)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): reduce title bar scroll fade height (pingdotgg#8799)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(windows): strip quotes from repaired PATH (pingdotgg#8746)
* fix(web): open agent images in expanded preview (pingdotgg#8807)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(git): follow repository instructions in generated source control text (pingdotgg#8804)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop overpricing cached Claude tokens (pingdotgg#8806)
* fix(web): keep image preview above sidebar control (pingdotgg#8811)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): keep right panel synced with agent edits (pingdotgg#8803)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web,mobile): render Codex citations and artifact templates (pingdotgg#8584)
* chore: add Windows setup script to t3.json (pingdotgg#8814)
* fix(web): fold interim turn responses (pingdotgg#8828)
* fix(web): use circle alert for failed tool calls (pingdotgg#8840)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(mobile): add offline iPhone voice input (pingdotgg#8614)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent pull request metadata overlap (pingdotgg#8790)
* chore(release): prepare v0.0.37
* Add mobile composer attachment menu with video support (pingdotgg#8843)
* fix(mobile): map native menu icon colors explicitly
* fix(web): restore unified activity logs and composer banners (pingdotgg#8734)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
* fix(web): address composer banner review follow-ups (pingdotgg#8850)
* fix(web): widen sync banners and simplify the working timer (pingdotgg#8855)
* fix(preview): improve browser recording quality (pingdotgg#8839)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): mark pull request links as external (pingdotgg#8856)
* fix(mobile): replace Callstack glass with Expo glass (pingdotgg#8862)
* fix(server): skip IDE detection in Claude probes (pingdotgg#8634)
* chore(macroscope): review diagnostic overrides (pingdotgg#8917)
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* fix(contracts): accept CLI event origins (pingdotgg#8905)
* fix(web): hide invalid slash skill completions (pingdotgg#8904)
* fix(mobile): defer draft navigation until submission completes (pingdotgg#8914)
* chore: disable CodeRabbit review status (pingdotgg#8933)
* Delete app.json (pingdotgg#8934)
* fix(web): show scrollbar for wide markdown tables (pingdotgg#8868)
* fix(mobile): shimmer active tool rows (pingdotgg#8932)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(deps): bump Electron to 43.4.1 (pingdotgg#8626)
* fix(chat): smooth worktree setup status (pingdotgg#8922)
* feat(mobile): add video playback with native iOS controls (pingdotgg#8919)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent chat metadata overlap (pingdotgg#8851)
* fix(server): preserve usage cache outside walked roots (pingdotgg#8540)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(mobile): add native image and PDF previews (pingdotgg#8959)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): allow long thread IDs in HTTP routes (pingdotgg#8898)
* fix(shared): preserve Windows shell PATH priority (pingdotgg#8748)
* fix(web): make WSL settings searchable (pingdotgg#8881)
* feat(web): add expand/collapse all control to the files surface (pingdotgg#8889)
* Add auto_review configuration to coderabbit.yaml
* style: format CodeRabbit configuration
* feat(mobile): upload attachments while composing (pingdotgg#8978)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(chat): keep agent activity visible between actions (pingdotgg#8984)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): isolate remote web session cookies (pingdotgg#8085)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(pull-requests): link GitHub references in markdown (pingdotgg#8812)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* perf(server): reduce frequency of full tool call output being loaded into memory from db (pingdotgg#8988)
* feat(web): add pull request list filters (pingdotgg#8809)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(web): search individual settings by detail (pingdotgg#8831)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(client): render viewed images in work logs (pingdotgg#8936)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(client): use package import for markdown image helpers (pingdotgg#9010)
* test: remove static presentation snapshots (pingdotgg#9008)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* perf(server): bound snapshot activity payload memory (pingdotgg#9000)
* perf(server): cut idle CPU use and stop provider event leaks (pingdotgg#8187)
* perf(server): scan only appended transcript bytes for usage summaries (pingdotgg#9024)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): cut chatty tool-update frames by 90% (pingdotgg#8368)
* fix(server): settle threads server-side (pingdotgg#8600)
* fix(clients): dedupe skills in composer menus (pingdotgg#8043)
* fix(server): stop OpenCode child sessions (pingdotgg#9005)
* perf(web): defer pull request line stats until visible (pingdotgg#6471)
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): skip full-message reads while streaming (pingdotgg#9032)
* perf(client-runtime): halve server config bootstrap traffic (pingdotgg#8367)
Reuse one server config subscription for session bootstrap and live updates.
Preserve environment theme opt-in, replay, deletion, slow subscriber recovery, and config stream failure handling.
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
* fix(web): align un-settle banner action (pingdotgg#9033)
* fix(web): block type-to-focus behind open dialogs (pingdotgg#8139)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(shortcuts): copy active thread reference (pingdotgg#8994)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(mobile): keep thread scroll bounds current after animations (pingdotgg#9013)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): cache project favicon resolution (pingdotgg#9080)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(claude): add Claude Fable 5.1 model (pingdotgg#9078)
* fix(preview): restore recording and macOS rendering after Electron 43 (pingdotgg#9001)
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
* feat(desktop): add configurable quit shortcut confirmation (pingdotgg#9076)
* feat(web): open project settings from thread menus (pingdotgg#8925)
* fix(chat): reuse one row for live activity (pingdotgg#9062)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(models): discover Claude models from remote manifest (pingdotgg#9084)
* Revert "fix(chat): reuse one row for live activity" (pingdotgg#9096)
* fix(web): sync sidebar PR state from open panel (pingdotgg#9092)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): changing projects no longer creates a draft (pingdotgg#9097)
* fix(web): keep theme placeholder text dimmer than entered text (pingdotgg#9104)
* fix(web): keep the selected environment when changing projects (pingdotgg#9102)
* docs(plans): t3o-31 upstream sync to v0.0.38
* fix(board): clear the ten pre-existing typecheck errors before the upstream sync (t3o-31 P0)
Two test fakes failed with a bare Error in the Effect failure channel, a
closure-assigned let narrowed to never, and a single-override pill read
overriddenRows[0] under noUncheckedIndexedAccess. None changed behaviour;
they were masked because the recursive typecheck never reached apps/server.
* fix(sync): the three type errors and two test failures the v0.0.38 merge caused
- BoardModelRow reads planModeEnabled from client settings, as the composer does.
- findBranchPullRequest resolves the default branch for upstream's widened PR
cache key instead of passing null.
- The orphaned-session integration test mocks the supervisor reactor that the
startup seam yields (new inventory row).
- The projection resume test seeds board projector watermarks into
boards.projection_state, where t3o-26 reads them, and asserts over the union.
- searchSettings("work") now also matches upstream's worktree/network items.
* refactor(board): native title attributes become BoardHint tooltips
Upstream's new no-native-title-tooltip rule flags every intrinsic-element
title= in the board (61 sites). BoardHint wraps the styled Tooltip primitive
and renders its child as the trigger, so layout is unchanged; a nullish label
renders the child alone.
* docs(seams): record the v0.0.38 sync (t3o-31)
Merge-log row, the decisions taken (plans stay tracked, upstream's settlement
reactor accepted after audit, projector-enumeration policy, launcher protocol
note), an unmarked-edits debt table for the next sync, a marker census, the
three new upstream workflows to disable, and the runbook's per-package
verification notes.
* review(t3o-31): announce the board's status dots, and order the merge log
Round-1 nitpicks: a bare span's aria-label is not announced, so the working,
running and awaiting dots now carry role="img"; the v0.0.38 merge-log row
moves below the two 2026-08-09 rows so the table reads chronologically.
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: abcdmku <63693423+abcdmku@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: Rishet11 <154429365+Rishet11@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Naveed Iqbal <naveediqbal949@gmail.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: Tristan Knight <admin@snappeh.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Pavlo Trinko <paul.trinko95@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Rodrigo Brechard <rodrigobrechard@gmail.com>
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
Co-authored-by: spiky02plateau <155588579+spiky02plateau@users.noreply.github.com>
Co-authored-by: Carlos Jimenez <cjimenez@r21digital.com>
Co-authored-by: Mark Griffin <mrmg@deflexion.net>
Co-authored-by: MacKinley Smith <smithmackinley@gmail.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Mohtasham Murshid <154406804+MohtashamMurshid@users.noreply.github.com>
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
Co-authored-by: Vitaly Iegorov <vitalyiegorov@gmail.com>
Co-authored-by: Ahmed Besic <ahmed.besic2000@gmail.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: Matthew Feroz <136640686+MatthewFeroz@users.noreply.github.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: Will Sheldon <will@autimo.com>
Co-authored-by: mic <85814106+q1@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Integrated browser preview blocks OAuth popup authentication

3 participants

@walid-baharwal@MatthewFeroz@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(desktop): oauth popups open from the browser preview - #8435

Merged
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups
Aug 28, 2026
Merged

fix(desktop): oauth popups open from the browser preview#8435
juliusmarminge merged 5 commits into
pingdotgg:mainfrom
walid-baharwal:fix/preview-oauth-popups

Conversation

@walid-baharwal

@walid-baharwalwalid-baharwal commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

What Changed

Two changes, both needed for an OAuth popup to work in the integrated browser preview.

apps/web/src/browser/HostedBrowserWebview.tsx sets allowpopups as an attribute on the <webview> element instead of from the ref callback. Electron reads that flag when the guest attaches, and the ref callback runs after the element is already in the DOM, so every preview guest attached with popups disabled.

apps/desktop/src/preview/Manager.ts reads the disposition the window-open handler already received. A new-window disposition with an http or https URL now opens a real window; everything else, target="_blank" links included, keeps loading in the preview tab as before. The popup is created with contextIsolation, sandbox, and nodeIntegration: false set explicitly, since a popup is not a webview attach and never passes the will-attach-webview hardening in DesktopWindow. It also gets a deny-only window-open handler of its own, so a page inside it cannot spawn native windows without limit. about:blank popups keep loading in the preview tab: Chromium copies the guest preferences for them and gives no way to override.

Why

A local app opened in the preview cannot finish an OAuth popup flow. Firebase signInWithPopup(auth, new GoogleAuthProvider()) reports auth/popup-blocked and no window appears, while the same app works in a normal Chrome or Firefox window.

Two separate causes stack up. window.open was denied and the URL was force-loaded into the same webContents, so window.open() returned null (the SDK reads that as a blocked popup) and the in-tab load destroyed the opener the popup needs to postMessage its credential back to. Underneath that, the guest attached with allowpopups false, so Electron blocked the call before the handler ran at all.

Instrumenting will-attach-webview in a running desktop build showed it directly:

[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":false} before
[popup-debug attach-webview] {"partition":"persist:t3code-preview-…","allowpopups":true} after

Surfaces

Desktop only in behavior. The <webview> element lives in apps/web because the desktop app wraps the web client, but the tag only exists inside Electron and remote web previews never reach setWindowOpenHandler. No contract, provider, or docs change.

UI Changes

No layout, styling, or motion changed. The observable difference is whether a popup window exists, captured below in a dev build against a local page that calls window.open(url, name, "width=520,height=640"), the same shape signInWithPopup uses.

Before

window.open() returns null and no window opens.

Before: popup blocked

After

window.open() returns a window handle.

After: popup opens

The popup window itself, sized from the requested window features:

After: the popup window

Verification

Run in a dev desktop build (dev:desktop) with the preview open on a local page:

  • Scripted popup: window.open(...) returns a handle. Handler logged disposition: "new-window" and decided popup.
  • The popup reports window.opener present and typeof require === "undefined", so the opener survives and the hardening applied.
  • A nested window.open from inside the popup returns null.
  • A target="_blank" link logs disposition: "foreground-tab", decides navigate, and loads in the preview tab.
  • previewWindowOpenAction has focused unit tests next to isPreviewRefreshShortcut, the existing pure helper in the same file.

Checks run locally:

  • vp test run apps/desktop/src/preview/Manager.test.ts — 66 passed
  • tsgo --noEmit in apps/web and apps/desktop — clean
  • vp lint and vp fmt --check on the changed files — clean

The attach-timing half is not unit-testable in a meaningful way. A rendered-DOM assertion passes either way, because the ref callback does set the attribute, just too late for Electron to read it.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • Before/after evidence included

Fixes#6561

Written with Claude Opus 5 in Claude Code.


Note

Medium Risk
Changes preview navigation and spawns hardened native windows from third-party pages; security-sensitive but scoped to http/https scripted popups with explicit hardening and nested popup denial.

Overview
Fixes OAuth and other scripted window.open flows in the integrated browser preview by enabling popups at attach time and opening real windows when appropriate instead of navigating the preview tab.

HostedBrowserWebview sets allowpopups="true" on the <webview> element at render time (not in a ref callback), so Electron sees it before the guest attaches.

PreviewManager adds previewWindowOpenAction: scripted popups (new-window + http:/https:) are allowed as separate BrowserWindows with contextIsolation, sandbox, and no Node integration; target="_blank" and non-hardenable URLs (about:blank, file:, javascript:, etc.) still load in the preview tab. Child OAuth windows get a deny-all setWindowOpenHandler via did-create-window.

Unit tests cover the new helper’s popup vs navigate decisions.

Reviewed by Cursor Bugbot for commit 3f60be1. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix OAuth popups in desktop browser preview with hardened window.open handling

  • Adds previewWindowOpenAction in Manager.ts to classify window.open requests: http/https scripted popups return 'popup' and open as real BrowserWindows; target=_blank tabs and disallowed/invalid schemes (about, javascript, file, vscode) return 'navigate' and load in the existing preview tab.
  • New popup windows use hardened webPreferences (contextIsolation: true, nodeIntegration: false, sandbox: true) and deny further window.open calls from within them.
  • Fixes HostedBrowserWebview.tsx so the <webview> element reliably gets the allowpopups attribute at attach time.
  • Behavioral Change: setWindowOpenHandler now receives full details and uses details.url instead of bare url; non-http(s) URLs that previously may have opened as popups now navigate the current tab instead.

Macroscope summarized 3f60be1.

@coderabbitai

coderabbitaiBot commented Aug 27, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e56baf0c-bdec-4082-8fa9-d71789606066

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:M 30-99 changed lines (additions + deletions). labels Aug 27, 2026
Scripted `window.open` calls inside the integrated browser preview were denied
and loaded in the preview tab instead. Firebase `signInWithPopup` got a null
window handle back and reported `auth/popup-blocked`, and the in-tab load also
dropped the opener the popup needs to post the credential back to.
Popups with a `new-window` disposition and an http or https URL now get a real
window, with context isolation and the sandbox turned back on: a popup is not a
webview attach, so the `will-attach-webview` hardening never sees it and an
unoverridden child would inherit the picker preload's relaxed posture.
`about:blank` popups keep loading in the preview tab, since Chromium copies the
guest preferences for them and forbids overriding. Links with `target="_blank"`
are unchanged.
Fixespingdotgg#6561
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from e598878 to 8fa05aeCompareAugust 27, 2026 18:16
Comment threadapps/desktop/src/preview/Manager.ts
Comment threadapps/desktop/src/preview/Manager.ts
An allowed popup carried Electron's default window-open behavior, so a page
inside it could spawn native windows without limit. The popup now denies its
own window.open calls; no OAuth flow opens a second popup.
The popup preferences also drop nodeIntegrationInSubFrames, matching the three
keys every other hardened window in the app sets.
@walid-baharwal
walid-baharwalforce-pushed the fix/preview-oauth-popups branch from d2ce056 to 7c5b69aCompareAugust 27, 2026 18:31
Electron reads allowpopups when the guest attaches. The attribute was set from
the ref callback, which runs after the element is in the DOM, so every preview
guest attached with popups disabled and Electron blocked window.open before the
window-open handler ran.
Verified in a running desktop build: will-attach-webview reported
allowpopups: false before this change and true after.
@walid-baharwal
walid-baharwal marked this pull request as ready for review August 27, 2026 22:31

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One finding in the web scope: the new allowpopups JSX attribute is the right ownership fix, but its string value conflicts with React's element typing, so apps/web typecheck (tsgo --noEmit) breaks. Details inline.

Posted via Macroscope — UI Consistency

Comment threadapps/web/src/browser/HostedBrowserWebview.tsx Outdated

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

nodeIntegration: false,
sandbox: true,
},
} satisfies Electron.BrowserWindowConstructorOptions;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Popup may inherit picker preload

High Severity

POPUP_WINDOW_OPTIONS overrides isolation flags but never clears preload. Electron merges overrideBrowserWindowOptions with the guest's preferences, so the picker preload can still run in the OAuth window and observe keystrokes and clicks on a third-party login page.

Additional Locations (1)
Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 0604de5. Configure here.

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I could not reproduce this one, so I am leaving the code as is. Details, in case I tested the wrong thing.

A popup opened from a webview guest does not inherit the guest's preload, with or without overrideBrowserWindowOptions. I checked with a standalone Electron 41.5.0 app that mirrors the preview setup: a <webview allowpopups> with a preload and contextIsolation=false, whose preload announces itself over IPC on load, then window.open(...) from inside the guest.

The preload reports from the guest and never from the popup:

RESULT preload-ran in: http://127.0.0.1:8899/popup-repro.html
RESULT popup created:

Same result with the override removed, and same with data: and http: popup URLs, so the override is not what is clearing it — the inheritance does not happen in the first place.

One thing worth flagging for anyone reading this later: webContents.getLastWebPreferences() does not report preload at all. It omits the key even for the guest, which definitely has one, so it cannot be used to check this.

If you have a case where the preload does reach the popup, I would like to see it — the exposure you describe would be real, since that preload listens for keydown and pointerdown.

@macroscopeapp

macroscopeappBot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR changes production preview behavior by enabling OAuth popup windows and altering Electron renderer security boundaries across the desktop and webview layers. An unresolved security concern about the preview preload potentially reaching third-party OAuth pages still requires validation.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

React types allowpopups as boolean, so the string literal failed apps/web's
tsgo --noEmit. Passing a real boolean typechecks but regresses the fix, since
react-dom drops boolean values for unrecognized attributes and sets nothing,
so the guest would attach with popups disabled again.
Verified after the change: the element carries allowpopups="true" and a
scripted window.open returns a window handle.
@MatthewFeroz

Copy link
Copy Markdown
Contributor

hoping this gets merged!

@MatthewFeroz

Copy link
Copy Markdown
Contributor

I double-checked the preload concern in Electron 41.5.0 and tested it myself. The preview’s preload script ran only inside the preview, not inside the popup. Electron’s code also confirms that preload scripts are not copied into new windows. This matches the author’s test, so I don’t think the Cursor warning is a real issue.

@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Status summary, since the Approvability verdict above predates the current head and reads as the most visible signal on this PR.

That verdict was posted at 8fa05ae and gives one reason: the preview picker preload may still execute in the popup and observe input. Two independent checks say it does not.

I tested it with a standalone Electron 41.5.0 app mirroring the preview setup — a <webview allowpopups> with a preload and contextIsolation=false, the preload announcing itself over IPC. It reports from the guest and never from the popup, with and without overrideBrowserWindowOptions, for both data: and http: popup URLs. @MatthewFeroz reproduced this independently and additionally checked Electron's source, which does not copy preload scripts into new windows.

Worth flagging for anyone testing this themselves: webContents.getLastWebPreferences() omits preload entirely, even for a webContents that has one, so it cannot be used to check this.

The popup is also created with contextIsolation: true, sandbox: true, nodeIntegration: false — verified at runtime as typeof require === "undefined" inside it — and denies its own window.open, so it cannot spawn further windows.

Current head is 8db8d83. All checks green, including Macroscope UI Consistency after the typing fix. Locally: 66 tests in Manager.test.ts pass, tsgo --noEmit clean for apps/web and apps/desktop, lint and format clean on the changed files.

No action needed from me unless something new turns up.

@MatthewFeroz

Copy link
Copy Markdown
Contributor

Just sent a video to the maintainers of this working. Small limitation in this is that passkeys don't function but I think that's out of scope for this PR. Great work!

@juliusmarminge
juliusmarminge merged commit 0e2905e into pingdotgg:mainAug 28, 2026
22 checks passed
@walid-baharwal

Copy link
Copy Markdown
ContributorAuthor

Thanks for running it and recording the video — I could not produce one myself, so that fills the gap CONTRIBUTING asks for on interaction changes.

On passkeys: that is pre-existing and tracked separately in #5665 ("In app browser not triggering passkey fingerprint to sign in on mac", open since 2026-08-07), so it predates this branch. Nothing here touches WebAuthn — the change only decides whether window.open gets a real window and what preferences that window is created with. A passkey prompt failing inside the preview fails the same way on main today, with or without a popup involved.

So I agree it is out of scope, and I would rather not widen this PR to chase it.

github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Aug 29, 2026
## What's Changed
* fix(grok): improve skills, plans, usage, and turn reliability by @t3dotgg in pingdotgg/t3code#8358
* fix(server): recover stale Codex approval callbacks by @luckyPipewrench in pingdotgg/t3code#5195
* test(server): remove duplicate missing worktree test by @t3-code[bot] in pingdotgg/t3code#8252
* fix(server): replay all un-applied events during projection bootstrap by @krutftw in pingdotgg/t3code#7538
* test: remove low-signal test files by @t3-code[bot] in pingdotgg/t3code#8397
* test: prune trivial error and layout tests by @t3-code[bot] in pingdotgg/t3code#8400
* Fix Android adaptive launcher icon by @colonelpanic8 in pingdotgg/t3code#4332
* feat(web): split provider settings into list and editor by @t3dotgg in pingdotgg/t3code#8380
* fix(codex): accept Codex 0.150 account plans by @gsimone in pingdotgg/t3code#8447
* fix(tooling): allow ignored-only staged changes by @juliusmarminge in pingdotgg/t3code#8468
* fix(mobile): keep iOS home header stable by @juliusmarminge in pingdotgg/t3code#8467
* fix(web): stop showing red x summaries for ordinary tool failures by @t3dotgg in pingdotgg/t3code#8395
* fix(mobile): refine Git action toast glass styling by @juliusmarminge in pingdotgg/t3code#8399
* fix(desktop): allow preview automation in agent-created threads by @t3dotgg in pingdotgg/t3code#8483
* test(web): remove redundant cache key test by @t3-code[bot] in pingdotgg/t3code#8484
* fix(release): move nightly schedule to minute 38 by @t3dotgg in pingdotgg/t3code#8509
* fix(web): stabilize the provider settings editor by @t3dotgg in pingdotgg/t3code#8472
* fix(web): open GitHub pull requests in browser when loading fails by @t3dotgg in pingdotgg/t3code#8507
* fix(codex): show sub-agent models by @t3dotgg in pingdotgg/t3code#8502
* feat(analytics): report connected client platforms by @t3dotgg in pingdotgg/t3code#8481
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB by @t3dotgg in pingdotgg/t3code#8235
* feat(web): toggle a thread's pin from the keyboard by @ipanasenko in pingdotgg/t3code#8440
* fix(web): add back button to project settings by @StiensWout in pingdotgg/t3code#8168
* refactor(mobile): compile semantic themes for Uniwind by @juliusmarminge in pingdotgg/t3code#7327
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times by @ikifar2012 in pingdotgg/t3code#5769
* fix(mobile): show OpenCode model sources in picker by @juliusmarminge in pingdotgg/t3code#8573
* fix(clients): honor project default models in new threads by @anirudhsama in pingdotgg/t3code#6011
* fix(mobile): show file actions on Android by @none23 in pingdotgg/t3code#8215
* fix(connect): explain DPoP connection failures by @extoci in pingdotgg/t3code#8351
* feat(web): make the sidebar project filter a searchable combobox by @SunkenInTime in pingdotgg/t3code#5931
* fix(server): a draft can retry its first send after a failed bootstrap by @shivamhwp in pingdotgg/t3code#8226
* fix(desktop): stop hidden previews draining battery by @Bil0000 in pingdotgg/t3code#8567
* fix(desktop): oauth popups open from the browser preview by @walid-baharwal in pingdotgg/t3code#8435
* fix(web): keep long task drawers usable on small screens by @shivamhwp in pingdotgg/t3code#8313
* fix(opencode): handle child approvals, stops, and model catalogs by @t3dotgg in pingdotgg/t3code#8480
* fix: make thread auto-settling opt-in by @shivamhwp in pingdotgg/t3code#8321
* fix(web): stop session activity timing test from blocking releases by @t3dotgg in pingdotgg/t3code#8585
* fix(mobile): show composer menus when starting a task by @juliusmarminge in pingdotgg/t3code#8587
* fix(web): show the configured stash shortcut by @UtkarshUsername in pingdotgg/t3code#8437
* feat(web): add toggleable confirmation before unpinning a thread by @UtkarshUsername in pingdotgg/t3code#7313
* fix: restore automatic thread settling defaults by @t3dotgg in pingdotgg/t3code#8596
* fix(mobile): restore composer glass and rounded shadows by @juliusmarminge in pingdotgg/t3code#8597
## New Contributors
* @luckyPipewrench made their first contribution in pingdotgg/t3code#5195
* @krutftw made their first contribution in pingdotgg/t3code#7538
* @colonelpanic8 made their first contribution in pingdotgg/t3code#4332
* @ikifar2012 made their first contribution in pingdotgg/t3code#5769
* @walid-baharwal made their first contribution in pingdotgg/t3code#8435
**Full Changelog**: pingdotgg/t3code@v0.0.35...v0.0.36
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.36
aaditagrawal added a commit to aaditagrawal/t3code that referenced this pull request Aug 29, 2026
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
bcotrim pushed a commit to bcotrim/mognet that referenced this pull request Aug 30, 2026
)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
(cherry picked from commit 0e2905e)
brentkelly added a commit to brentkelly/t3code-orchestrator that referenced this pull request Sep 2, 2026
* feat(analytics): threads and turns now know which client started them (pingdotgg#7774)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop marking mixed tool runs as failed (pingdotgg#7893)
* fix(web): command-click spaced folder links (pingdotgg#6439)
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(chat): stop pushing follow-up messages to the top (pingdotgg#7897)
* test(desktop): remove redundant release note assertion (pingdotgg#7873)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): handle wide ordered-list marker edge cases (pingdotgg#7856)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(ssh): restore user PATH for remote servers (pingdotgg#7213)
* fix(desktop): keep tailscale spawn defects from breaking advertised endpoints (pingdotgg#7116)
* fix(web): keep Codex service tier labels readable (pingdotgg#4503)
* fix: render workspace images in chat markdown (pingdotgg#6433)
* fix(clients): keep opening responses visible after turns settle (pingdotgg#7723)
* feat(web): add appearance contrast control (pingdotgg#7906)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop completed Codex threads from staying stuck on working (pingdotgg#7937)
* fix(mobile): preserve markdown image dimensions (pingdotgg#7940)
* fix(web): remove duplicate provider update progress (pingdotgg#7761)
* fix(server): fall back to the remote default branch instead of assuming main (pingdotgg#7078)
* fix(web): give sidebar project menu rows the same side padding as other menus (pingdotgg#7913)
* fix(clients): reconnect after credentials fail during remote server updates (pingdotgg#7953)
* feat(codex): submit thread feedback to OpenAI (pingdotgg#7949)
* fix(server): stop kills lingering Claude work (pingdotgg#5891)
* fix(ci): let Macroscope approve pull requests again (pingdotgg#7970)
* fix(clients): move settled pinned threads into the settled section (pingdotgg#7969)
* perf(ci): speed up release builds and Windows packaging (pingdotgg#7975)
* fix(web): stop tool calls from leaving a blank page in threads (pingdotgg#7971)
* fix(web): stop recovered tool failures from marking work logs red (pingdotgg#7999)
* fix(mobile): isolate markdown image requests (pingdotgg#7942)
* feat(web): redesign skills in `$` menu and in `/` menu (pingdotgg#8009)
* fix(web): restore right panel toggle clicks after closing on desktop (pingdotgg#8016)
* fix(web): keep server update banners flush with the composer (pingdotgg#8000)
* perf(web): reuse work log rows during streaming (pingdotgg#8006)
* fix(web): keep provider badge legible in dark themes (pingdotgg#7968)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): treat configured urls with uppercase schemes as secure (pingdotgg#8005)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(desktop): keep release notes visible while downloading (pingdotgg#6412)
* fix(web): show only providers with usage in usage views (pingdotgg#7563)
* fix(web): prevent expanded tool calls from hiding thread content (pingdotgg#8052)
* test(server): remove no-op live activity tests (pingdotgg#8056)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(web): clarify terminal sidebar grouping (pingdotgg#7967)
* fix(codex): show app access approval prompts (pingdotgg#8058)
* feat(web): upload image attachments before sending (pingdotgg#8048)
* fix(server): bound OpenCode skill discovery output (pingdotgg#7675)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* fix(mobile): persist thread shelf collapse state (pingdotgg#5152)
* fix(mobile): restore Android tablet thread controls, clean up header (pingdotgg#5385)
* fix(mobile): land the first thread open above the composer on Android (pingdotgg#5585)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(server): check out submodules in a new worktree (pingdotgg#7674)
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
* fix(server): preserve merged PR badges after branch deletion (pingdotgg#6216)
* fix(server): return fresh live pull request reads (pingdotgg#6472)
* fix(web): compare client and server versions as semver, not strings (pingdotgg#7579)
* fix(web): stop follow-ups from leaving giant blank space (pingdotgg#8068)
* fix(marketing): stop automatic Vercel deployments on pull requests (pingdotgg#8070)
* chore: vouch repeat contributors (pingdotgg#8071)
* fix(server): keep the authoritative subagent model when snapshots race task_started (pingdotgg#7583)
* fix(server): honor auto-accept edits for the OpenCode provider (pingdotgg#7100)
* fix(server): run the CLI on Node versions without import.meta.main (pingdotgg#7141)
* fix(server): recover from provider interrupt failures (pingdotgg#7412)
* fix(server): recreate a thread's worktree before starting a turn (pingdotgg#7839)
* fix(server): thread delete no longer fails on already-removed worktrees (pingdotgg#8076)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): stop update notices showing through the composer (pingdotgg#8083)
* fix(web): detect outdated nightly servers (pingdotgg#8124)
* fix(web): align usage page skeleton layout (pingdotgg#8111)
* fix(web): make terminal links appear clickable only when clickable (pingdotgg#7488)
* fix(web): make Windows file links clickable in chat (pingdotgg#8081)
* fix(web): sort usage models by token count (pingdotgg#8108)
* fix: open agent file links in the file viewer (pingdotgg#8098)
* fix(server): stop routine events from rescanning thread history (pingdotgg#8150)
* fix(deps): stop pnpm installs from changing the lockfile (pingdotgg#8163)
* feat(web): settle and restore threads with a keyboard shortcut (pingdotgg#8089)
* perf(desktop): cut macOS signing calls by 81% (pingdotgg#8093)
* feat: link pull requests to threads (pingdotgg#8160)
* feat(web): safely attach HEIC photos as JPEG images (pingdotgg#8161)
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
* feat(mobile): track device models and OS versions (pingdotgg#8169)
* fix(grok): bound cumulative tool output updates (pingdotgg#7279)
* fix(web): delay thread shortcut hints by 200 ms (pingdotgg#8172)
* fix(server): stop probing Cursor until enabled (pingdotgg#8175)
* docs(release): verify remote updates with database migrations (pingdotgg#8177)
* fix(server): keep provider CLIs available in the macOS service (pingdotgg#8173)
* feat(claude): compact old threads before they burn through usage (pingdotgg#8144)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(client-runtime): retry queries after connection interruption (pingdotgg#8117)
* fix(server): keep previously used providers working after upgrades (pingdotgg#8176)
* feat(desktop): build macOS previews from a PR label (pingdotgg#8182)
* fix(web): thread jump hints no longer stick after a dictation paste (pingdotgg#8189)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): keep grouped project renames (pingdotgg#7831)
* feat(web): reveal chat file chips in the system file manager (pingdotgg#7140)
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
* fix(server): push no longer writes a feature branch's commits to its base branch (pingdotgg#8228)
* chore(deps): bump @clerk/electron to 0.0.37 (pingdotgg#8240)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(server): fetch legacy model classification from a hosted manifest (pingdotgg#8227)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* chore(release): prepare v0.0.34
* fix(desktop): let Clerk UI receive stable auth fixes (pingdotgg#8248)
* fix(app): un-settled threads return to the top of the list (pingdotgg#8231)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* perf(ci): cut about a minute from every release (pingdotgg#8250)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(ci): download macOS preview DMGs without signing in (pingdotgg#8243)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(codex): accept Codex 0.150 multi-agent events (pingdotgg#8346)
* chore(release): prepare v0.0.35
* fix(grok): improve skills, plans, usage, and turn reliability (pingdotgg#8358)
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
* fix(server): recover stale Codex approval callbacks (pingdotgg#5195)
* test(server): remove duplicate missing worktree test (pingdotgg#8252)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(server): replay all un-applied events during projection bootstrap (pingdotgg#7538)
Co-authored-by: Theo Browne <me@t3.gg>
* test: remove low-signal test files (pingdotgg#8397)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* test: prune trivial error and layout tests (pingdotgg#8400)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* Fix Android adaptive launcher icon (pingdotgg#4332)
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
* feat(web): split provider settings into list and editor (pingdotgg#8380)
* fix(codex): accept Codex 0.150 account plans (pingdotgg#8447)
* fix(tooling): allow ignored-only staged changes (pingdotgg#8468)
* fix(mobile): keep iOS home header stable (pingdotgg#8467)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): stop showing red x summaries for ordinary tool failures (pingdotgg#8395)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(mobile): refine Git action toast glass styling (pingdotgg#8399)
* fix(desktop): allow preview automation in agent-created threads (pingdotgg#8483)
* test(web): remove redundant cache key test (pingdotgg#8484)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* fix(release): move nightly schedule to minute 38
Recent scheduled nightlies have been delayed or skipped.
Move the nightly cron from minute 7 to minute 38. Keep the existing three-hour interval. This tests a different point in each three-hour window without claiming it will fix GitHub schedule delivery.
Authored by GPT-5.6 Sol with the Codex harness.
* fix(web): stabilize the provider settings editor (pingdotgg#8472)
* fix(web): open GitHub pull requests in browser when loading fails (pingdotgg#8507)
* fix(codex): show sub-agent models (pingdotgg#8502)
* feat(analytics): report connected client platforms (pingdotgg#8481)
* feat(server): accept PDF, ZIP, and other file uploads up to 50MB (pingdotgg#8235)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(web): toggle thread pin from the keyboard
Add a mod+shift+p shortcut that pins or unpins the active thread. Ignore the shortcut during terminal focus and when the server does not support thread pinning.
* fix(web): add back button to project settings (pingdotgg#8168)
* refactor(mobile): compile semantic themes for Uniwind (pingdotgg#7327)
Co-authored-by: codex <codex@users.noreply.github.com>
* fix(desktop): Cache Runtime locally on WSL Filesystem, dramatically improving launch times (pingdotgg#5769)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
* fix(mobile): show OpenCode model sources in picker (pingdotgg#8573)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(clients): honor project default models in new threads (pingdotgg#6011)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(mobile): show file actions on Android (pingdotgg#8215)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix(connect): explain DPoP connection failures (pingdotgg#8351)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(web): make the sidebar project filter a searchable combobox (pingdotgg#5931)
* fix(server): a draft can retry its first send after a failed bootstrap (pingdotgg#8226)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(desktop): stop hidden previews draining battery (pingdotgg#8567)
* fix(desktop): oauth popups open from the browser preview (pingdotgg#8435)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep long task drawers usable on small screens (pingdotgg#8313)
* fix(opencode): handle child approvals, stops, and model catalogs (pingdotgg#8480)
* fix: make thread auto-settling opt-in (pingdotgg#8321)
* fix(web): stop session activity timing test from blocking releases (pingdotgg#8585)
* fix(mobile): show composer menus when starting a task (pingdotgg#8587)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): show the configured stash shortcut (pingdotgg#8437)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* feat(web): add toggleable confirmation before unpinning a thread (pingdotgg#7313)
Co-authored-by: Shivam Sharma <91240327+shivamhwp@users.noreply.github.com>
* fix: restore automatic thread settling defaults (pingdotgg#8596)
* fix(mobile): restore composer glass and rounded shadows (pingdotgg#8597)
Co-authored-by: Julius Marminge <julius@mac.lan>
* Remove Messages Glass Lab experiment (pingdotgg#8599)
* chore(release): prepare v0.0.36
* Require human review for pull requests changing product defaults (pingdotgg#8603)
* fix(codex): avoid quadratic app-server input buffering (pingdotgg#8605)
* fix(mobile): stabilize iOS header item transitions (pingdotgg#8607)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(mobile): upgrade to Expo SDK 57 (pingdotgg#8609)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(mobile): harden native header toolbar items (pingdotgg#8611)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): stop querying Claude context usage after turns (pingdotgg#8610)
* chore: vouch ryanrhughes (pingdotgg#8613)
* feat(web): attach PDFs, ZIPs, and other files to a turn (pingdotgg#8236)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix(web): pass stashShortcutLabel in the mixed-attachments stash test
PRs pingdotgg#8437 and pingdotgg#8236 crossed: one made stashShortcutLabel a required
ComposerStashMenu prop, the other added a test case without it, so
main fails web typecheck.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat(web): keybinding settings as settings rows (pingdotgg#8532)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat: let an environment publish themes as a file (pingdotgg#8569)
Co-authored-by: Theo Browne <me@t3.gg>
* fix(web): clean up provider settings list and editor (pingdotgg#8504)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): keep project picker popup inside the sidebar (pingdotgg#8627)
* fix(mobile): prevent header overflow and back-button artifacts (pingdotgg#8624)
* fix(server): retry automatic thread title generation (pingdotgg#8087)
* fix(client-runtime): refresh edited pull request comments (pingdotgg#8094)
* fix(web): four composer spacing defects (pingdotgg#8090)
* perf(desktop): skip duplicate browser updates (pingdotgg#8018)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): render nested markdown images correctly (pingdotgg#8501)
* fix(web): unify activity logs and composer banners (pingdotgg#8693)
* fix(mobile): reduce dev-client reload and Metro startup cost (pingdotgg#8694)
Co-authored-by: Julius Marminge <julius@mac.lan>
* revert(web): restore previous composer banners (pingdotgg#8733)
* test(web): remove tests for unreachable helpers (pingdotgg#8738)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* feat(mobile): update tool summaries and chat transitions (pingdotgg#8793)
* feat(web): play video attachments in chat (pingdotgg#8688)
* fix(web,mobile): snooze menu no longer offers the same wake time twice (pingdotgg#8741)
* fix(grok): allow model changes in existing threads (pingdotgg#8392)
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
* feat(mobile): pick, share, and receive files in threads (pingdotgg#8237)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* fix(web): reduce title bar scroll fade height (pingdotgg#8799)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(windows): strip quotes from repaired PATH (pingdotgg#8746)
* fix(web): open agent images in expanded preview (pingdotgg#8807)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(git): follow repository instructions in generated source control text (pingdotgg#8804)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): stop overpricing cached Claude tokens (pingdotgg#8806)
* fix(web): keep image preview above sidebar control (pingdotgg#8811)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): keep right panel synced with agent edits (pingdotgg#8803)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web,mobile): render Codex citations and artifact templates (pingdotgg#8584)
* chore: add Windows setup script to t3.json (pingdotgg#8814)
* fix(web): fold interim turn responses (pingdotgg#8828)
* fix(web): use circle alert for failed tool calls (pingdotgg#8840)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(mobile): add offline iPhone voice input (pingdotgg#8614)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent pull request metadata overlap (pingdotgg#8790)
* chore(release): prepare v0.0.37
* Add mobile composer attachment menu with video support (pingdotgg#8843)
* fix(mobile): map native menu icon colors explicitly
* fix(web): restore unified activity logs and composer banners (pingdotgg#8734)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
* fix(web): address composer banner review follow-ups (pingdotgg#8850)
* fix(web): widen sync banners and simplify the working timer (pingdotgg#8855)
* fix(preview): improve browser recording quality (pingdotgg#8839)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(web): mark pull request links as external (pingdotgg#8856)
* fix(mobile): replace Callstack glass with Expo glass (pingdotgg#8862)
* fix(server): skip IDE detection in Claude probes (pingdotgg#8634)
* chore(macroscope): review diagnostic overrides (pingdotgg#8917)
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
* fix(contracts): accept CLI event origins (pingdotgg#8905)
* fix(web): hide invalid slash skill completions (pingdotgg#8904)
* fix(mobile): defer draft navigation until submission completes (pingdotgg#8914)
* chore: disable CodeRabbit review status (pingdotgg#8933)
* Delete app.json (pingdotgg#8934)
* fix(web): show scrollbar for wide markdown tables (pingdotgg#8868)
* fix(mobile): shimmer active tool rows (pingdotgg#8932)
Co-authored-by: Julius Marminge <julius@mac.lan>
* chore(deps): bump Electron to 43.4.1 (pingdotgg#8626)
* fix(chat): smooth worktree setup status (pingdotgg#8922)
* feat(mobile): add video playback with native iOS controls (pingdotgg#8919)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(web): prevent chat metadata overlap (pingdotgg#8851)
* fix(server): preserve usage cache outside walked roots (pingdotgg#8540)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(mobile): add native image and PDF previews (pingdotgg#8959)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): allow long thread IDs in HTTP routes (pingdotgg#8898)
* fix(shared): preserve Windows shell PATH priority (pingdotgg#8748)
* fix(web): make WSL settings searchable (pingdotgg#8881)
* feat(web): add expand/collapse all control to the files surface (pingdotgg#8889)
* Add auto_review configuration to coderabbit.yaml
* style: format CodeRabbit configuration
* feat(mobile): upload attachments while composing (pingdotgg#8978)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(chat): keep agent activity visible between actions (pingdotgg#8984)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(server): isolate remote web session cookies (pingdotgg#8085)
Co-authored-by: Julius Marminge <julius0216@outlook.com>
* feat(pull-requests): link GitHub references in markdown (pingdotgg#8812)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* perf(server): reduce frequency of full tool call output being loaded into memory from db (pingdotgg#8988)
* feat(web): add pull request list filters (pingdotgg#8809)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(web): search individual settings by detail (pingdotgg#8831)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(client): render viewed images in work logs (pingdotgg#8936)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(client): use package import for markdown image helpers (pingdotgg#9010)
* test: remove static presentation snapshots (pingdotgg#9008)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
* perf(server): bound snapshot activity payload memory (pingdotgg#9000)
* perf(server): cut idle CPU use and stop provider event leaks (pingdotgg#8187)
* perf(server): scan only appended transcript bytes for usage summaries (pingdotgg#9024)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): cut chatty tool-update frames by 90% (pingdotgg#8368)
* fix(server): settle threads server-side (pingdotgg#8600)
* fix(clients): dedupe skills in composer menus (pingdotgg#8043)
* fix(server): stop OpenCode child sessions (pingdotgg#9005)
* perf(web): defer pull request line stats until visible (pingdotgg#6471)
Co-authored-by: Theo Browne <me@t3.gg>
* perf(server): skip full-message reads while streaming (pingdotgg#9032)
* perf(client-runtime): halve server config bootstrap traffic (pingdotgg#8367)
Reuse one server config subscription for session bootstrap and live updates.
Preserve environment theme opt-in, replay, deletion, slow subscriber recovery, and config stream failure handling.
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
* fix(web): align un-settle banner action (pingdotgg#9033)
* fix(web): block type-to-focus behind open dialogs (pingdotgg#8139)
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
* feat(shortcuts): copy active thread reference (pingdotgg#8994)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* fix(mobile): keep thread scroll bounds current after animations (pingdotgg#9013)
Co-authored-by: Julius Marminge <julius@mac.lan>
* fix(server): cache project favicon resolution (pingdotgg#9080)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat(claude): add Claude Fable 5.1 model (pingdotgg#9078)
* fix(preview): restore recording and macOS rendering after Electron 43 (pingdotgg#9001)
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
* feat(desktop): add configurable quit shortcut confirmation (pingdotgg#9076)
* feat(web): open project settings from thread menus (pingdotgg#8925)
* fix(chat): reuse one row for live activity (pingdotgg#9062)
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
* feat(models): discover Claude models from remote manifest (pingdotgg#9084)
* Revert "fix(chat): reuse one row for live activity" (pingdotgg#9096)
* fix(web): sync sidebar PR state from open panel (pingdotgg#9092)
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
* fix(web): changing projects no longer creates a draft (pingdotgg#9097)
* fix(web): keep theme placeholder text dimmer than entered text (pingdotgg#9104)
* fix(web): keep the selected environment when changing projects (pingdotgg#9102)
* docs(plans): t3o-31 upstream sync to v0.0.38
* fix(board): clear the ten pre-existing typecheck errors before the upstream sync (t3o-31 P0)
Two test fakes failed with a bare Error in the Effect failure channel, a
closure-assigned let narrowed to never, and a single-override pill read
overriddenRows[0] under noUncheckedIndexedAccess. None changed behaviour;
they were masked because the recursive typecheck never reached apps/server.
* fix(sync): the three type errors and two test failures the v0.0.38 merge caused
- BoardModelRow reads planModeEnabled from client settings, as the composer does.
- findBranchPullRequest resolves the default branch for upstream's widened PR
cache key instead of passing null.
- The orphaned-session integration test mocks the supervisor reactor that the
startup seam yields (new inventory row).
- The projection resume test seeds board projector watermarks into
boards.projection_state, where t3o-26 reads them, and asserts over the union.
- searchSettings("work") now also matches upstream's worktree/network items.
* refactor(board): native title attributes become BoardHint tooltips
Upstream's new no-native-title-tooltip rule flags every intrinsic-element
title= in the board (61 sites). BoardHint wraps the styled Tooltip primitive
and renders its child as the trigger, so layout is unchanged; a nullish label
renders the child alone.
* docs(seams): record the v0.0.38 sync (t3o-31)
Merge-log row, the decisions taken (plans stay tracked, upstream's settlement
reactor accepted after audit, projector-enumeration policy, launcher protocol
note), an unmarked-edits debt table for the next sync, a marker census, the
three new upstream workflows to disable, and the runbook's per-package
verification notes.
* review(t3o-31): announce the board's status dots, and order the merge log
Round-1 nitpicks: a bare span's aria-label is not announced, so the working,
running and awaiting dots now carry role="img"; the v0.0.38 merge-log row
moves below the two 2026-08-09 rows so the table reads chronologically.
---------
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: abcdmku <63693423+abcdmku@users.noreply.github.com>
Co-authored-by: Guilherme Barros <gbarros1095@gmail.com>
Co-authored-by: Rishet11 <154429365+Rishet11@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: maria <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Naveed Iqbal <naveediqbal949@gmail.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Rakshith Bhat <88523594+RakshithBhat03@users.noreply.github.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: Tristan Knight <admin@snappeh.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Pavlo Trinko <paul.trinko95@gmail.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Rodrigo Brechard <rodrigobrechard@gmail.com>
Co-authored-by: Rodrigo Brechard <rodrigo@clubtidy.fr>
Co-authored-by: Adamulek123 <adam.bogucki2018@gmail.com>
Co-authored-by: spiky02plateau <155588579+spiky02plateau@users.noreply.github.com>
Co-authored-by: Carlos Jimenez <cjimenez@r21digital.com>
Co-authored-by: Mark Griffin <mrmg@deflexion.net>
Co-authored-by: MacKinley Smith <smithmackinley@gmail.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: mweinbach <maxweinbach5@gmail.com>
Co-authored-by: Lars Nieuwenhuis <35393046+lnieuwenhuis@users.noreply.github.com>
Co-authored-by: Mohtasham Murshid <154406804+MohtashamMurshid@users.noreply.github.com>
Co-authored-by: Dara Adedeji <daraaded@amazon.com>
Co-authored-by: Dara Adedeji <daraadedeji07@gmail.com>
Co-authored-by: Ahmed Besic <ahmed-besic@users.noreply.github.com>
Co-authored-by: Michael Brown <michaeltbrown.mtb@gmail.com>
Co-authored-by: PC <pc@localhost>
Co-authored-by: 1xpixi <157762409+1xpixi@users.noreply.github.com>
Co-authored-by: Josh <gitlucky@pipelab.org>
Co-authored-by: Tradi3 <56069280+krutftw@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Ivan Malison <IvanMalison@gmail.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Julius Marminge <julius@mac.lan>
Co-authored-by: Illia Panasenko <hello@ipanasenko.me>
Co-authored-by: Matheson Steplock <ikifar2012@users.noreply.github.com>
Co-authored-by: Anirudh Coontoor <anirudh@gosupernova.live>
Co-authored-by: Nick Anisimov <n.anisimov.23@gmail.com>
Co-authored-by: Muhammad Waleed <114993336+walid-baharwal@users.noreply.github.com>
Co-authored-by: Ryan Hughes <ryan@heyoodle.com>
Co-authored-by: Vitaly Iegorov <vitalyiegorov@gmail.com>
Co-authored-by: Ahmed Besic <ahmed.besic2000@gmail.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: Matthew Feroz <136640686+MatthewFeroz@users.noreply.github.com>
Co-authored-by: Julius Marminge <jmarminge@gmail.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: Yukun Shan <92423096+nateEc@users.noreply.github.com>
Co-authored-by: Will Sheldon <will@autimo.com>
Co-authored-by: mic <85814106+q1@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <guillermo.casanova.b@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M30-99 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Integrated browser preview blocks OAuth popup authentication

3 participants

@walid-baharwal@MatthewFeroz@juliusmarminge