* feat(viewer): restyle the sessions list page (#1323)
Match the sessions mockup: the chevron back control and title row, the ten-column table with a truncated session id, the accent Check action, and bottom-right pagination driven by static/sessions.js.
* chore: docs update
---------
Co-authored-by: Kite <254839944+lizhengfeng101@users.noreply.github.com>
* import gitcmd and use it
* add versioner
* tests: new git version tests (AI)
* mega fixes
* mega fixes
* fix: no call on not needed
* chore: fix bad merge
* fix: review
chore: write tests (AI)
* fix: Apply suggestion from @lizhengfeng101
---------
Co-authored-by: Kite <254839944+lizhengfeng101@users.noreply.github.com>
* docs: enforce responsible AI usage
- add the development-assistance rules to AGENTS.md and CONTRIBUTING.md in every locale
- state the AI policy in SECURITY.md
- require AI/LLM disclosure in the issue and pull request templates
- keep the local-reproduction checkbox out of the AI disclosure group
- forbid AI co-author trailers in the commit command
- keep CONTRIBUTING.ko-KR.md and the Korean docs page identical
- import AGENTS.md from CLAUDE.md so Claude Code actually loads the rules
* docs: rewrite AI-usage policy text in original wording
The AI-Assisted Development section (CONTRIBUTING + docs, all locales) and
the SECURITY.md AI Policy were adapted closely from third-party sources
(Kazumi, GPL-3.0; Homebrew, unlicensed). Rewrite the borrowed prose in our
own words with the same meaning, and drop the unrelated Local Reproduction
checkbox from the bug-report template.
---------
Co-authored-by: kite <lizhengfeng.lzf@alibaba-inc.com>
* feat(viewer): open URL in default browser
* chore: write tests (AI)
* fix: TCP listener created by net.Listen is not explicitly closed via defer
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* fix: no interactive prompt in non-interactives
* fixes qwq
* fix: no new line
* refactor
* chore: write test (AI)
* apply suggestions & new example
* docs: update (AI)
* fix(viewer): address review feedback on browser auto-open
- displayURL takes the host from the requested addr and only the port from
the listener. net.Listen resolves a hostname to an IP literal while
hostGuard's allowlist is built from the requested addr, so
`--addr box.local:5483` auto-opened a URL its own host guard answered with
403 forbidden host. Taking only the port keeps `--addr :0` reporting the
port the kernel assigned.
- runBrowserCmd reads cmd.Wait() within a bounded window instead of trusting
Start(). xdg-open exits non-zero when no handler is registered and open
exits non-zero when no application claims the scheme, both after a
successful fork/exec, so those failures left the user with neither a
browser nor a warning. An opener that outlives the window is treated as
success because it became the browser, but a later failure still warns.
The child's stderr is folded into the error, and every candidate's failure
is reported rather than only the first.
- --open=auto|always|never replaces --no-open, matching the existing --color.
The boolean could only suppress opening, never force it, leaving no way out
when the heuristic declines wrongly. The auto-mode suppression reason is
appended to the ready line so it cannot be mistaken for a broken open,
$BROWSER is honored on Unix, and SSH is judged together with the display
variables so `ssh -X` opens without an override.
- ASSURANCE_CASE.md no longer claims every exec.Command call runs git. It
already had four kinds of exception before this one.
Browser handling moves to internal/viewer/browser.go, covered through a
helper-process test that exercises the exec paths without launching a real
browser. Docs updated across en/ja/ko/ru/zh.
* fix(viewer): correct $BROWSER attribution and harden open-mode test
browserCandidates credited the colon-separated list and %s placeholder to
the Go toolchain, but cmd/internal/browser treats $BROWSER as a single
executable path with neither. Attribute the parsing to the freedesktop
convention as Python's webbrowser implements it, and note the divergence so
the richer parsing reads as this package's choice rather than something
inherited. Move the Go reference to browserWaitWindow, which is what is
actually borrowed from it (appearsSuccessful, also 3s).
TestViewerCmd_RejectsInvalidOpenMode called RunE directly. Dropping the
ValidateOpenMode guard does not make RunE return an error there: it falls
through to StartServer, which serves until the listener fails and so never
returns, turning the regression into a suite-wide timeout panic that blames
whichever test the runner happened to be on. Run RunE under a deadline and
bind port 0 so a regression reports the actual cause instead of hanging, and
restore addr alongside open. Confirmed by deleting the guard: the test now
fails in 5s with "--open is not validated before StartServer binds".
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: kite <lizhengfeng.lzf@alibaba-inc.com>
* chore: new extensions for `.ipynb`
* docs: update site docs
* chore(allowlist): skip Jupyter .ipynb_checkpoints autosaves
Jupyter writes autosave copies of a notebook into a sibling
.ipynb_checkpoints/ directory. Now that .ipynb is in the extension
allowlist, an accidentally committed checkpoint would be reviewed as a
regular file and produce comments duplicating those on the real
notebook. Exclude the directory by default, alongside the other
tool-generated artifacts.
---------
Co-authored-by: kite <lizhengfeng.lzf@alibaba-inc.com>
* feat: new support for R
* docs: update
* chore: update site docs
* fixup: missing * for mapper
* chore; switch r to uppercase
* fix: `internal/config/allowlist/allowed_ext_test.go`
* feat(llm): add Novita AI as a built-in provider
Novita's endpoint (https://api.novita.ai/v3/openai) is OpenAI-compatible,
so it registers like the other OpenAI-protocol providers (deepseek, kimi,
z-ai, ...). Adds the registry entry, the matching name in the
provider-order test, and the provider table in the en/zh/ja
configuration docs. Model ids are taken from the live
/v3/openai/models endpoint.
* fix(llm): correct Novita base URL to current documented endpoint
The registry entry, tests-adjacent docs tables (en/ja/zh configuration.md)
used https://api.novita.ai/v3/openai. That path still resolves today, but
Novita's current documentation (novita.ai/docs/guides/llm-api) no longer
shows it; the current documented OpenAI-compatible endpoint is
https://api.novita.ai/openai. Verified live 2026-08-01: both paths return
identical /models and /chat/completions results, so this is a stale-citation
fix, not a functional break.
* Recommend Novita's current flagship models
The models listed for Novita were older ids that no longer reflect what
the platform leads with. Point the recommendations at the three current
flagships instead, each verified against api.novita.ai:
moonshotai/kimi-k3 1M context, native vision
zai-org/glm-5.2 1M context, long-horizon agentic work
deepseek/deepseek-v4-flash-0731 1M context, cheapest of the three
Context windows, output limits, input modalities and pricing were taken
from the live /openai/v1/models response rather than carried over.
* Apply suggestion from @wu21-web
Co-authored-by: Tao Xin <wu2196674@icloud.com>
* Sync provider registry with upstream to resolve merge conflict
Rebase-equivalent update of internal/llm/providers.go,
internal/llm/providers_test.go, and the en/ja/zh/ru configuration docs
to match upstream/main's current content (minimax-cn, mistral, model
list refreshes) while keeping the novita entry this branch adds. This
is a targeted content sync of the six files that conflicted, not a
full merge, so unrelated upstream changes (workflows, CI, etc.) are
left untouched. Also adds the novita row to the ru docs table, which
was missing.
---------
Co-authored-by: kite <254839944+lizhengfeng101@users.noreply.github.com>