Commit Graph
619 Commits
Author SHA1 Message Date
jubaoliangandCursor 09d72e603b feat(dashboard): add remember-me checkbox on the login page
Default stays persistent (localStorage). Unchecking keeps the JWT in
sessionStorage for this tab only; SSO popups post the token back so the
opener can store it correctly.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:22:16 +08:00
Grapette.L f2d0baeb4e fix(config): bound OCTOP_PORT and --port to a bindable range (#1150)
* fix(config): 绑定端口越界时告警回落,--port 越界直接报错

OCTOP_PORT 只按 int() 解析、octop run --port 也只有 type=int,70000/-1
这类根本无法绑定的取值会盖掉 config.json 里本来可用的端口,进程死在
socket.bind 抛出的 OverflowError 里,报错既不含变量名也看不出端口来源;
--port 更是在启动之前就把该值写进 config.json,之后每次 octop run 都继续继承。

现按 resolve_bind 已经支持的「0 表示由系统随机分配端口」把取值收口到
0-65535:环境变量越界沿用「告警 + 不覆盖」的既有契约回落配置文件端口,
命令行 --port 越界交给 click.IntRange 在使用期错误里拦下、不落盘。

* docs: 补上绑定端口的取值范围说明

`octop run --port` 现在会渲染成 `INTEGER RANGE … [0<=x<=65535]`,环境变量表也顺手写明
`OCTOP_PORT` 接受 0–65535(0 = 由系统随机分配),与 `OCTOP_LOG_LEVEL` 那行「One of …」的写法一致。
2026-09-26 20:14:30 +08:00
HuiandClaude Opus 5.5 eb007ee434 fix(api): bound the audit-log limit before it reaches SQL LIMIT
GET /api/admin/audit-log forwarded an unvalidated `limit` into `LIMIT ?`,
the same gap #1018 closed for the thread list. SQLite reads a negative LIMIT
as "no limit", so ?limit=-1 returned the whole audit log in one response and
?limit=0 returned an empty page. Bound it with Query(ge=1, le=500), the
largest page the Settings -> Security audit panel offers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 19:57:35 +08:00
yc2bgr8 1711bd2e6a docs(cn): sync README_CN CLI reference with memory commands
README.md documents `octop memory list/slim` and the /memory slim
chat commands, but README_CN.md's CLI reference table predates them.
Add the three memory rows and the /memory slim paragraph in Chinese,
matching the English README.
2026-09-26 19:29:00 +08:00
jubaoliangandCursor 4c3bf76479 fix: team chat/IM UX, ACP sandbox, channel thinking, and related polish
Improve team streaming visibility (live speakers, generating footer, IM
dispatch/wrap-up), relax ACP tool enable under sandbox while locking
runners, strip channel think tags per show_thinking, and clarify provider
CLI usage in the assistant skill. Includes self-update/UpdateConfig WIP
from the same working tree.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 23:59:46 +08:00
HUANG Chengandjubaoliang bd73bb60aa fix(plugins): offload oversized octop_ui payloads to ToolMessage.artifact (#1032) (#1116)
Plugin tools returning large octop_ui payloads (e.g. a bangumi season
with 1200+ episodes, ~228KB JSON) blew up the LLM context because the
same tool-result string served both the model and the UI.

Add OctopUiOffloadMiddleware at the innermost agent middleware layer:
when a ToolMessage content is a >=4000-char string carrying a non-empty
octop_ui renderer and data (and no file:// media refs), the payload is
moved in-place to ToolMessage.artifact and the model-visible content is
replaced by a compact result that keeps title/summary. Tool id,
tool_call_id, name and status are preserved.

Frontend restores rendering from artifact: ToolCallData.artifact,
closeToolCall extraction, history replay path, and resolvePluginUiData
prefers explicit data over data_ref. serialize.py surfaces artifact on
tool_result blocks; history recorder backfills artifact as fallback.

Spec: docs/octop-ui-payload-offload.md

Co-authored-by: jubaoliang <jubaoliang@gmail.com>
2026-09-25 23:06:19 +08:00
347dee56f4 refactor(infra): group agents modules and clarify package ownership (#1164)
* refactor(agents): group thin modules into domain subpackages

Move plugin helpers, memory, settings stores, persona/MBTI, and avatar
bootstrap code under plugins/, memory/, settings/, persona/, and experts/
while keeping top-level import shims so existing call sites stay stable.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(agents): drop compatibility shims after subpackage move

Call sites already import the new package paths; remove the top-level
re-export stubs so the agents tree only shows real modules.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(agents): move thread helpers into threads/

Group artifact shaping, fork, and context breakdown under
agents/threads so top-level only keeps lifecycle/config adapters.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(agents): fold profile/runtime/tool catalog into settings/

Move the remaining config-surface helpers under settings/ and drop the
skill_package id-list aliases in favor of dump/parse_id_list.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(agents): group workspace_dir and execute_env under workspace/

Keep path resolution and harness execute-env injection together as one
workspace package; leave only manager and conversation_mode at top level.

Co-authored-by: Cursor <cursoragent@cursor.com>

* refactor(infra): fix history/SkillHub ownership and drop thin providers/

Move history_projection under history/, share SkillHub host/limits and
route expert skill downloads through skills.skillhub_market, and fold
Codex OAuth helpers into agents.providers to remove the tiny providers/
package.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs: sync AGENTS.md and guides with infra/agents layout

Reflect subpackages (settings/workspace/threads/persona, history/, skills/)
and drop stale runtime.py / mbti_profiles paths after the agents reorg.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 22:32:41 +08:00
DuhuandDuHu 7617133b31 feat(connectors): 恢复企查查一键 OAuth,保留 internal HTTP 工具加载 (#1106)
* QMCP-2014 feat(connectors): restore QCC OAuth with internal HTTP transport

* QMCP-2014 docs(connectors): record QCC OAuth end-to-end acceptance

---------

Co-authored-by: DuHu <duhu@greatld.com>
2026-09-25 21:51:33 +08:00
jubaoliangandCursor 1d2b2558fb feat(chat): team artifacts, fan-in tool trail, and host wrap-up context
Persist member file refs and tool history on team walls, open docks by producer agent, and inject truncated member answers into host follow-up so wrap-up can follow their advice.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 14:48:45 +08:00
2209cdc90f chore(deps): switch runtime packages to octop-* 1.0.0 (#1136)
Replace orcakit-harness-agent / harness-* with octop-harness, octop-gateway, octop-memory, and octop-browser, and align docs, UI copy, and generated paths.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 06:44:24 +08:00
jubaoliangandCursor 5e34c8a001 fix: connectors empty layout and restore prior control-plane behaviors
Apply the remaining working-tree changes: connectors empty-state layout,
plus the knowledge, HITL, captcha, workspace, user-cache, and SSRF
adjustments with matching tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 22:40:47 +08:00
jubaoliangandCursor 44023b192f docs: point README at TencentCloud octop-harness repos
The harness-* libraries are now published as octop-harness, octop-gateway,
octop-memory, and octop-browser.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 18:23:52 +08:00
689216e4b6 feat: admin user batch policies, token UX, default FS root, and media push hardening (#1114)
* feat: admin user batch policies, token UX, default FS root, and media push hardening

Add admin user batch enable/disable/delete and resource policies (token quota,
max experts), improve token inputs with K/M presets, default unrestricted
local backends to host filesystem root, and tighten gateway tool-media push
with clearer path-outside-root stream errors.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(workspace): treat Windows drive roots as host-root sentinels

Default FS-root backends use C:/ on Windows; treating that as a scoped
jail put workspaces under the drive root and broke bootstrap/invite tests.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 17:22:49 +08:00
4e09aeb956 fix(knowledge): map per-base document cap to KNOWLEDGE_DOC_LIMIT (#1013)
`_map_knowledge_error` matched the literal "at most 100" to classify the
document-cap error, but `KnowledgeRepo.create_document` interpolates the
per-base `max_documents`, which has been user-configurable since 90b8ca25.
Any cap other than the default 100 therefore fell through to the base-cap
branch (the repo message also contains "knowledge bases") and the user was
told they had created too many knowledge bases.

Classify both caps by the stable wording of their own messages instead of
a magic number, and drive the mapping from the real repo in a regression
test so the wording coupling cannot silently rot again.

Co-authored-by: sxh <sunxianhong@ncti-gba.cn>
Co-authored-by: sxh313 <sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:11:19 +08:00
02b807fd9e fix(knowledge): keep the suffix that keys a renamed document (#1108)
files.document_path() keys the stored bytes on {doc_id}{suffix}, so a rename
that drops or swaps the extension moves the row off its own file: the
original-file route 404s, delete_document() unlinks the wrong key with
missing_ok=True and leaks the bytes, and re-saving an md/txt document
writes a second file. rename_document() now restores the document suffix
the way create_text_document() already normalises it; folders and names that
already carry the right extension are untouched.

Closes #1107

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:11:04 +08:00
af2c742801 fix(api): bound the thread-list limit before it reaches SQL LIMIT (#1018)
GET /api/agents/{agent_id}/threads forwarded an unvalidated `limit` into
`LIMIT ?`. SQLite reads a negative LIMIT as "no limit", so ?limit=-1 returned the
caller's whole thread collection and ?limit=0 returned an empty page; the same
statement reaches psycopg unchanged, where a negative LIMIT is an error. Bound it
with Query(ge=1, le=HISTORY_MAX_LIMIT), the ceiling this module already uses for
message pages.

Co-authored-by: sxh <sunxianhong@ncti-gba.cn>
Co-authored-by: sxh313 <sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:10:42 +08:00
lihongyuan99andjubaoliang aeb486c722 fix(security): keep IPv6 brackets and path params when rebuilding pinned URLs (#1092)
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:10:19 +08:00
0559b0cf5d fix(agents): HITL 会话跳过策略不再按进程缓存 (#1090)
threads.hitl_policy 是策略的唯一事实来源:每次判定都回查该行。
octop run --workers N(或 CLI 与服务并发)共用一个库时,进程内缓存会让
另一个进程撤销的跳过继续自动放行工具调用,也会让新授予的跳过不生效;
写库失败时缓存里还会留下一个从未落库的豁免策略。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:09:58 +08:00
309db11140 fix(users): 角色与禁用状态改为读库,多 worker 下撤权不再滞后 (#1102) (#1103)
UserManager.get_by_id 与 authenticate 从进程内镜像回答,而 deps.py 的
resolve_user_from_token 每个认证请求都要经过 get_by_id。octop run
--workers N,或 CLI 离线写同一 SQLite 时,另一个进程的 set_role /
disable / remove 不会更新这份镜像:被降级的管理员、被禁用甚至已删除的
用户在其它 worker 上仍按旧身份通过鉴权。

现在两个读取点回到 users 行——行不存在或 disabled 时返回 None,并顺手
清掉镜像里的过期条目;authenticate 用它本来就已经取到的行构造 User。
disable / remove 一直会弹出本地镜像,所以单进程语义不变,登录响应的
role 也不再来自这份进程私有副本。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:09:37 +08:00
62218f6914 fix(backup): 导入工作区 zip 时跳过 Octop 自有的 _builtin_skills 条目 (#1104) (#1105)
POST /workspace/archive 直接把归档条目写进工作区,唯一的规则
_safe_zip_name 只防目录穿越,不防保留前缀,所以一个 zip 可以在
_builtin_skills/ 和 .octop/_builtin_skills/ 下落盘。该前缀是 Octop
自有目录:delete/move 走 _assert_workspace_mutable 会拒绝它,
sync_octop_builtin_skills 也只清理 RETIRED_BUILTIN_SKILLS,于是植入的
技能既按 kind="builtin" 被加载,又无法通过 API 删除。

现在在解包处过滤该前缀,并沿用已有 warnings 字段报告跳过的条数,
imported 不再把保留路径算成成功导入。导出本来就会打包该前缀,但
无需在恢复时还原:每次 agent 启动都会从包内重新写入自有文件。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:09:19 +08:00
de0f7a89a4 fix(workspace): PUT /file 与 POST /upload 补上 _builtin_skills 写保护 (#1100) (#1101)
同一文件里 mkdir / delete / move / PUT /doc 都用 _assert_workspace_mutable
拦下 Octop 内置技能根 _builtin_skills,只有这两个写接口漏了:owner 可以往
_builtin_skills/<name>/SKILL.md 写内容,_resolve_skill 之后会把它当作
kind="builtin" 的技能列出来,而 delete/move 与 skills 的删除接口对 builtin
一律拒绝,重启同步也只清 RETIRED_BUILTIN_SKILLS 白名单,所以写进去就删不掉。

校验放在取 workspace 之前(与其余写接口一致),upload 校验的是最终真正使用的
target,并且先于读取请求体。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:09:01 +08:00
5bb827f37b fix(auth): OCTOP_CAPTCHA_V3_MIN_SCORE 只接受 [0, 1] 内的有限值 (#1087) (#1088)
nan / -inf / 负数会被 float() 成功解析并原样透传给 recaptcha-v3 的判定式
`float(score) < min_score`,而该式对 NaN 恒为 False,等于静默关闭分数门槛;
inf / >1 则反向锁死所有登录。现在沿用同一解析点已有的"值不可用即回落
0.5"规则,只放行 [0, 1] 内的有限值。

Co-authored-by: sxh313 <250161920+sxh313@users.noreply.github.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 15:08:22 +08:00
lihongyuan99 dfd7fd0c9f fix(plugins): keep wiki_summary requests under *.wikipedia.org (#1027)
wiki_summary interpolates its `lang` argument straight into the URL host
(`https://{lang}.wikipedia.org/...`), and the tool schema the harness
builds from the signature gives the model an unconstrained `str`. A value
like "evil.com#" makes httpx resolve host=evil.com, and "localhost:8443/"
reaches a loopback port -- the response's `extract` is then echoed back
into the chat, so it is also a read-back channel.

Validate `lang` as a bare subdomain label and return the usual error card
otherwise; real codes (zh, en, zh-classical, simple, nb) are unaffected.
2026-09-24 15:04:12 +08:00
github-actions[bot] 02a6e28d23 Merge pull request #1079 from TencentCloud/chore/sync-develop-after-1.0.2b2
chore: sync main into develop after 1.0.2b2
2026-09-23 15:27:21 +00:00
jubaoliang c04aacc604 Merge pull request #1076 from TencentCloud/release/1.0.2b2
chore: release 1.0.2b2
v1.0.2b2
2026-09-23 23:14:35 +08:00
jubaoliangandCursor cf99ab89df chore: sync uv.lock for 1.0.2b2
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 15:09:50 +00:00
jubaoliangandCursor f6acc87e62 chore: release 1.0.2b2
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 15:06:20 +00:00
jubaoliangandCursor 6ede49b2f5 fix(experts): drop redundant add buttons from the edit drawer
Managing skills and subagents already covers install and copy, so the extra add actions only duplicated that entry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 23:02:04 +08:00
jubaoliangandCursor 494a921cfc fix(fnos): parse prerelease versions for FPK builds
Digits-only sed left VER as the whole pyproject line for 1.0.2b1, so
native upload and GHCR wait both failed and no .fpk was attached.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 22:48:41 +08:00
694a8cea8d feat(teams): 主持人先改写再派工,成员回复同步到 IM 通道 (#1064)
用户原话不再原样转给成员;通道原先只看得到主持人短答,成员收口后补推带说话人的完整消息。

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 22:48:26 +08:00
4ea7963b2d fix(acp): 沙箱环境下禁用向外委托 Runner (#1061)
* fix(acp): block outbound runners under directory sandbox

Host-spawned acp_runner would bypass a scoped root_dir jail; gate the
per-agent tool in API/runtime and gray the ACP UI while inbound octop acp stays available.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(acp): allow workspace-scoped local roots for outbound runners

Windows rewrites host `/` to the agent workspace; treating that as a
directory sandbox made ACP enable/round-trip fail on win32 CI.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 22:48:13 +08:00
jubaoliangandCursor 963cb14007 fix(chat): show the real team name on the welcome heading
Team rooms used a hardcoded "#管理团队" / "#Manage team" string instead of
the agent name already passed into WelcomeScreen.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 17:50:34 +08:00
jubaoliangandCursor df7f7d187c feat(connectors): 企查查改为 API Key,并用 internal 模式加载工具
公网 HTTP 无法完成 OAuth 回调;对话若按 gateway 注入会得到空工具表。改为粘贴 Key,harness 走内部 HTTP 聚合五个 MCP。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 17:50:19 +08:00
6f7815bb71 feat(connectors): 新增企查查 OAuth 连接器,一次授权接入五类 MCP 服务 (#1033)
* QMCP-2014 feat(connectors): add QCC MCP OAuth connector

* QMCP-2014 feat(connectors): share QCC OAuth across five MCP servers

---------

Co-authored-by: DuHu <duhu@greatld.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 15:45:02 +08:00
locip123 7047a4ebac feat(connectors): add OpenAlex connector (#1009)
* feat(connectors): add OpenAlex connector

* feat(connectors): add OpenAlex connector
2026-09-23 15:43:59 +08:00
Fish 5e597312dd fix(chat): avoid carrying prefill across expert switches (#920) 2026-09-23 15:40:50 +08:00
theater 2d679cbfb5 fix(update): checkpoint SQLite WAL before desktop process restart (#918)
* fix(update): checkpoint SQLite WAL before desktop process restart

In desktop/portable mode, POST /api/update/restart replaced the process
image with os.execv without flushing the SQLite WAL. Because SqlitePool
uses WAL mode with a large autocheckpoint window, all writes since the
last checkpoint were lost on restart (#800).

Change _restart_desktop_process to accept the OctopServer, and before
execv run PRAGMA wal_checkpoint(TRUNCATE) and close the pool when the
database is SQLite. The restart endpoint now injects the server via
Depends(get_server).

Fixes #800.

* style(tests): format desktop restart regression cases
2026-09-23 15:40:44 +08:00
sxhandsxh313 728ca52106 fix(cron): a failed agent run still leaves its prompt in the thread (#984)
`fresh_thread` deliveries reset the session to a brand-new thread before the
run, but the history projection only happened after the response passed the
"visible reply" checks. A run that raised — a failing tool call, a HITL
request, an empty reply — therefore left that thread with zero rows, so
opening the conversation after 立即执行 showed a blank chat.

Project in a finally, the same way the interactive processor persists an
incomplete turn, so the prompt and whatever the model streamed before the
failure are recorded. Push and toast stay unchanged: nothing is delivered
until there is a visible reply.

Co-authored-by: sxh313 <sxh313@users.noreply.github.com>
2026-09-23 14:58:51 +08:00
Dang Zitou e75a0387ae fix(connectors): secure OAuth callbacks with regression coverage 2026-09-23 14:57:58 +08:00
github-actions[bot] b1c7ba9b31 Merge pull request #1030 from TencentCloud/chore/sync-develop-after-1.0.2b1
chore: sync main into develop after 1.0.2b1
2026-09-23 03:01:05 +00:00
jubaoliang c02c32c7e2 Merge pull request #1008 from TencentCloud/release/1.0.2b1
chore: release 1.0.2b1
v1.0.2b1
2026-09-23 10:49:03 +08:00
jubaoliangandCursor 49bceee5d2 fix(desktop): write NSIS version defines via Python, avoid PowerShell $vars
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 02:34:07 +00:00
jubaoliangandCursor 58d960e37a fix(ci,security): retry NSIS install and harden CodeQL hotspots
Retry Chocolatey NSIS with SourceForge fallback; rebuild safe_request URL after validation; use hostname checks in Codex OAuth tests; stop exposing polish exception text.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 02:17:41 +00:00
jubaoliangandCursor f6a20b713f fix: NSIS pep440 VI version, experts empty guide, CodeQL URL hostname checks
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 01:09:27 +00:00
jubaoliangandCursor d46ba606d1 chore: release 1.0.2b1
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 15:05:49 +00:00
jubaoliangandCursor c7f828676e feat(dashboard): unify empty guides with Tasks-like plain style
Align skill packages, knowledge bases, browser, and desktop idle tips
with borderless layout and shared mascot sizing; move desktop Check/
Connect into the guide; and use Route for chat model Auto to avoid the
skills Sparkles collision.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 22:31:51 +08:00
liukewia 35abf52626 fix(dashboard): honor PWA safe-area insets and widen mobile chat bubbles (#666)
* refactor: update layout styles to support safe area insets

Modified padding and margin properties across various components to utilize environment variables for safe area insets, ensuring better compatibility with devices that have notches or rounded corners. This includes updates to index.html, offline.html, and several layout components to enhance the overall responsiveness and user experience.

* fix: update keyboard offset handling and layout styles

Refactored keyboard offset calculations in the useKeyboardOffset hook to improve handling of soft keyboard visibility. Adjusted layout styles across various components to utilize the largest viewport height (lvh) for better compatibility with devices featuring home indicators. This includes updates to padding, height properties, and background colors to enhance the user experience in chat and main layout components.

* refactor: update chat layout styles for improved responsiveness

Adjusted padding, width, and margin properties across various chat components to utilize environment variables for better responsiveness. This includes updates to the chat input, message list, and welcome components, ensuring consistent spacing and alignment across different screen sizes. Enhanced mobile styles to accommodate varying avatar sizes and maintain layout integrity.

* refactor: enhance chat component styles for consistency and responsiveness

Updated layout styles in chat components to ensure consistent spacing and alignment. Adjusted margin and gap properties to utilize environment variables, improving responsiveness across different screen sizes. Enhanced mobile styles for better alignment of avatars and message bubbles, ensuring a cohesive user experience.

* feat: implement theme management in index.html and update logo assets

Added a script to manage dashboard theme based on user preferences and system settings, ensuring the correct theme is applied before the first paint. Updated CSS to utilize data attributes for theme styling. Replaced existing logo assets with new vertical and horizontal versions for both light and dark themes, and updated references throughout the application. Removed outdated logo files to streamline asset management.

* refactor: update layout styles to improve safe area handling

Enhanced layout components by adjusting padding and margin properties to better utilize environment variables for safe area insets. This includes updates to the PageShell, Sidebar, MainLayout, Login, and Setup components, ensuring improved responsiveness and compatibility with devices featuring notches or rounded corners.
2026-09-22 22:02:18 +08:00
liukewia 95d339b08d fix(update): unlock Windows self-upgrade when octop.exe is running (#1000)
* feat(self_update): implement stashing and restoring of console scripts on Windows during upgrades

Added functionality to rename console scripts before an upgrade to avoid file lock issues on Windows. Introduced methods to stash, restore, and discard stashed scripts, ensuring a smooth upgrade process. Enhanced tests to cover these new behaviors.

* test(self_update): enhance test for stashing console scripts on non-Windows platforms

Updated the test for stashing console scripts to include a monkeypatch for simulating a non-Windows environment. This ensures the test accurately reflects behavior when the system is not Windows, improving test coverage for the self-update functionality.
2026-09-22 22:01:04 +08:00
liukewia a6798d75ec Fix OpenCode session header matching and bump harness-agent to 1.0.14 (#992)
* feat(provider): add name parameter to provider model interfaces and update session header logic

- Introduced a `name` parameter in `FetchProviderModelsParams` and related interfaces to enhance provider identification.
- Updated `fetchProviderModels` and modal components to utilize the new `name` parameter.
- Enhanced session header management in `opencode_session` to support bundled presets and custom providers.
- Adjusted tests to validate the new functionality and ensure proper session header injection for OpenCode presets.

* feat(deps): add mise.toml for local toolchain configuration and update orcakit-harness-agent to version 1.0.14

- Introduced a new mise.toml file to specify local toolchain versions for Python, Node, NPM, and UV.
- Updated the orcakit-harness-agent dependency version from 1.0.13 to 1.0.14 in pyproject.toml and uv.lock to ensure compatibility with the latest features and fixes.

* refactor(probe): streamline session header construction in probe.py

- Consolidated the session header construction for both `build_probe_chat_model` and `fetch_openai_compatible_models` functions into single-line calls for improved readability and maintainability.
2026-09-22 20:14:24 +08:00
21760bbf56 fix(agents): serialize harness execution per thread for turns and HITL resume (#782) (#960)
Dashboard turns are queued per thread by the channel debounce lock, but
POST /chat/hitl/resume (and cron delivery) drive the same LangGraph
checkpoint without that lock. A resume racing an in-flight turn on the
same thread runs two concurrent harness executions whose checkpoint
writes interleave.

Acquire a per-(agent_id, thread_id) lock in AgentManager.stream and
AgentManager.resume_hitl — the single chokepoint every driver (dashboard,
IM, cron, team speaker, resume) routes through — so one thread's
checkpoint is only ever executed once at a time.

Co-authored-by: Dang Zitou <dengzitao888@163.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 17:26:42 +08:00