34 Commits
Author SHA1 Message Date
Tao Xin a4a57dac87 docs(extensions): new translations for vscode ext (#1381)
* register package jsons

* chore: translations
2026-09-21 17:24:13 +08:00
Tao Xin edc2f85f6b docs(review): synchronize exclude & secret patterns (#1491)
* docs(review): synchronize exclude & secret patterns

* chore: format with prettier
2026-09-21 15:14:56 +08:00
Tao Xinandgithub-actions[bot] c5eb9e02be chore: translations (#1437)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-19 09:45:24 +08:00
Tao XinandKite edf30576f6 feat(viewer): restyle the sessions list page (#1377)
* feat(viewer): restyle the sessions list page (#1323)

Match the sessions mockup: the chevron back control and title row, the ten-column table with a truncated session id, the accent Check action, and bottom-right pagination driven by static/sessions.js.

* chore: docs update

---------

Co-authored-by: Kite <254839944+lizhengfeng101@users.noreply.github.com>
2026-09-18 11:34:35 +08:00
Tao XinandKite 75d7bc9b4e feat(pages): standardize web crawler policy (#939)
* feat: standardize web crawler policies

* js sitemap gen core

* route package

* robots.txt modifications & deploy & test

* chore: issues for OCR

* remove sitemap.xml

* feat: Apply suggestion from @lizhengfeng101

---------

Co-authored-by: Kite <254839944+lizhengfeng101@users.noreply.github.com>
2026-09-17 14:27:36 +08:00
Tao Xin 1f5caf4d5b chore: remove stale alias pointing to deepseek-flash (#1219) 2026-09-14 17:55:46 +08:00
Tao XinandKite 78a6978296 feat(git): validate if PATH git version is safe git (#865)
* import gitcmd and use it

* add versioner

* tests: new git version tests (AI)

* mega fixes

* mega fixes

* fix: no call on not needed

* chore: fix bad merge

* fix: review

chore: write tests (AI)

* fix: Apply suggestion from @lizhengfeng101

---------

Co-authored-by: Kite <254839944+lizhengfeng101@users.noreply.github.com>
2026-09-14 11:27:54 +08:00
Tao Xin 9dbc534a95 chore: synchronize glm-5.3 to from z-ai coding plan to z ai api (#923) 2026-09-12 21:20:01 +08:00
Tao Xinandkite b523997b54 docs: enforce responsible AI usage (#1037)
* docs: enforce responsible AI usage

- add the development-assistance rules to AGENTS.md and CONTRIBUTING.md in every locale
- state the AI policy in SECURITY.md
- require AI/LLM disclosure in the issue and pull request templates
- keep the local-reproduction checkbox out of the AI disclosure group
- forbid AI co-author trailers in the commit command
- keep CONTRIBUTING.ko-KR.md and the Korean docs page identical
- import AGENTS.md from CLAUDE.md so Claude Code actually loads the rules

* docs: rewrite AI-usage policy text in original wording

The AI-Assisted Development section (CONTRIBUTING + docs, all locales) and
the SECURITY.md AI Policy were adapted closely from third-party sources
(Kazumi, GPL-3.0; Homebrew, unlicensed). Rewrite the borrowed prose in our
own words with the same meaning, and drop the unrelated Local Reproduction
checkbox from the bug-report template.

---------

Co-authored-by: kite <lizhengfeng.lzf@alibaba-inc.com>
2026-09-10 22:11:31 +08:00
24edcbd3b7 feat(cmd, viewer): open viewer URL in default browser (#1108)
* feat(viewer): open URL in default browser

* chore: write tests (AI)

* fix: TCP listener created by net.Listen is not explicitly closed via defer

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix: no interactive prompt in non-interactives

* fixes qwq

* fix: no new line

* refactor

* chore: write test (AI)

* apply suggestions & new example

* docs: update (AI)

* fix(viewer): address review feedback on browser auto-open

- displayURL takes the host from the requested addr and only the port from
  the listener. net.Listen resolves a hostname to an IP literal while
  hostGuard's allowlist is built from the requested addr, so
  `--addr box.local:5483` auto-opened a URL its own host guard answered with
  403 forbidden host. Taking only the port keeps `--addr :0` reporting the
  port the kernel assigned.

- runBrowserCmd reads cmd.Wait() within a bounded window instead of trusting
  Start(). xdg-open exits non-zero when no handler is registered and open
  exits non-zero when no application claims the scheme, both after a
  successful fork/exec, so those failures left the user with neither a
  browser nor a warning. An opener that outlives the window is treated as
  success because it became the browser, but a later failure still warns.
  The child's stderr is folded into the error, and every candidate's failure
  is reported rather than only the first.

- --open=auto|always|never replaces --no-open, matching the existing --color.
  The boolean could only suppress opening, never force it, leaving no way out
  when the heuristic declines wrongly. The auto-mode suppression reason is
  appended to the ready line so it cannot be mistaken for a broken open,
  $BROWSER is honored on Unix, and SSH is judged together with the display
  variables so `ssh -X` opens without an override.

- ASSURANCE_CASE.md no longer claims every exec.Command call runs git. It
  already had four kinds of exception before this one.

Browser handling moves to internal/viewer/browser.go, covered through a
helper-process test that exercises the exec paths without launching a real
browser. Docs updated across en/ja/ko/ru/zh.

* fix(viewer): correct $BROWSER attribution and harden open-mode test

browserCandidates credited the colon-separated list and %s placeholder to
the Go toolchain, but cmd/internal/browser treats $BROWSER as a single
executable path with neither. Attribute the parsing to the freedesktop
convention as Python's webbrowser implements it, and note the divergence so
the richer parsing reads as this package's choice rather than something
inherited. Move the Go reference to browserWaitWindow, which is what is
actually borrowed from it (appearsSuccessful, also 3s).

TestViewerCmd_RejectsInvalidOpenMode called RunE directly. Dropping the
ValidateOpenMode guard does not make RunE return an error there: it falls
through to StartServer, which serves until the listener fails and so never
returns, turning the regression into a suite-wide timeout panic that blames
whichever test the runner happened to be on. Run RunE under a deadline and
bind port 0 so a regression reports the actual cause instead of hanging, and
restore addr alongside open. Confirmed by deleting the guard: the test now
fails in 5s with "--open is not validated before StartServer binds".

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: kite <lizhengfeng.lzf@alibaba-inc.com>
2026-09-01 20:42:40 +08:00
Tao Xin 124bfc3b9e fix(security): prevent rule.json from reading arbitrary files on the review host (#1100)
* Block path-traversal in repository rule.json file references
* Fix case-insensitive path matching on Windows
* Add comprehensive test coverage
2026-08-28 20:56:56 +08:00
Tao Xinandkite 68492a5372 feat(installation): support asset download via OCR_GITHUB_MIRROR (#893)
* rewrite mirrored install shell script

* rewrite mirrored install pwsh script and code cmt

* scripts updates

* spelling qwq

* docs: update

* docs: powershell users

* merge scripts

* warn about security risks & docs

* trim the DOMAIN string

* fix spelling

* docs: update

fix naming

* docs: refactor docs

* fixes

* apply suggestions

* fix: download checksums from mirror

* docs: clarify mirror security

* fix(installation): normalize OCR_GITHUB_MIRROR input across platforms

- Strip https://, http:// scheme prefix and trailing slash automatically
- Unify whitespace handling: trim leading/trailing only, error on internal spaces
- Both install.sh and install.ps1 now behave identically for edge inputs

---------

Co-authored-by: kite <lizhengfeng.lzf@alibaba-inc.com>
2026-08-19 09:45:32 +08:00
Tao XinandKite 35a06a4951 feat(providers): add gemini to built-in providers (#930)
* add gemini providers and tests

* docs: update

* chore: add more models

* chore: reorder models

* fix: Apply suggestion from @lizhengfeng101

---------

Co-authored-by: Kite <254839944+lizhengfeng101@users.noreply.github.com>
2026-08-18 21:20:03 +08:00
Tao Xinandkite 24c2dd0cde feat(language): add support for .ipynb files (#980)
* chore: new extensions for `.ipynb`

* docs: update site docs

* chore(allowlist): skip Jupyter .ipynb_checkpoints autosaves

Jupyter writes autosave copies of a notebook into a sibling
.ipynb_checkpoints/ directory. Now that .ipynb is in the extension
allowlist, an accidentally committed checkpoint would be reviewed as a
regular file and produce comments duplicating those on the real
notebook. Exclude the directory by default, alongside the other
tool-generated artifacts.

---------

Co-authored-by: kite <lizhengfeng.lzf@alibaba-inc.com>
2026-08-18 20:24:20 +08:00
Tao Xin 9a01ec0427 feat(lang): review support for R (#988)
* feat: new support for R

* docs: update

* chore: update site docs

* fixup: missing * for mapper

* chore; switch r to uppercase

* fix: `internal/config/allowlist/allowed_ext_test.go`
2026-08-18 17:10:03 +08:00
Tao Xin b712856403 docs(site): update for elm (#978) 2026-08-17 20:22:12 +08:00
Tao Xin 6cc10949a6 fix(ci): line endings check fails on symbolic links (#952)
* fix(ci): line endings check fails on symbolic links

* chore: update err msg
2026-08-17 20:10:58 +08:00
Tao Xin ec5f6851d2 fix(pages): make install-channel command box scrollable (#912) 2026-08-17 19:53:04 +08:00
Tao XinandKite e288e1a33f fix(pages): serve 404 pages on non-existent GET requests but render no React Route (#955)
* core: NotFoundPage Page for 404

* chore: write tests(AI)

* route 404 request to ./pages/NotFoundPage

* chore: write tests (AI)

* chore: translations sync

* fixup: updated webpack cfg so unknown HTML paths are also rewritten to the app shell

* refactor: enhance NotFoundPage tests with dynamic translation handling

* docs: Apply suggestion from @lizhengfeng101

---------

Co-authored-by: Kite <254839944+lizhengfeng101@users.noreply.github.com>
2026-08-17 15:24:01 +08:00
Tao Xin 1abfb70fcb docs(cli-reference): add missing ocr review flags examples (#920)
* document flags

* translations sync

fixup

fixup

* remove conflicting `--exclude` in docs
2026-08-15 17:24:50 +08:00
Tao Xin d59eddaa5a feat(pages): add macports to pages homepage (#873)
* docs: translations update keys

* tsx: new macports hero and import mp svg icon

* new macports svg

* add options

* keys translations

* tsx updates

* fix typo

* fixes

* tests: new
2026-08-14 15:30:32 +08:00
Tao Xin ab741e6334 docs(pages): update CLI reference and i18n for --format sarif (#874)
* docs: update cli-refs

* docs: update ci.md

* i18n: update corresponding keys
2026-08-14 12:00:38 +08:00
Tao Xin 9148bfdded chore: remove Chinese doc references from retry test comments (#886)
* remove invalid refs and add bypasses

* chore: retrigger tests
2026-08-13 15:41:28 +08:00
Tao Xin a7f149929a fix(LE): normalize line endings via .gitattributes (#858)
* add .gitattributes

* agents.md: add instructions

* add workflow step

* docs: update

* fix

* remove svg from .gitattributes
2026-08-12 14:55:58 +08:00
73c7f0f714 feat(providers): add siliconflow (GLOBAL) to built-in providers (#772)
* outline siliconflow provider structure

* tests: add siliconflow to expected providers

* docs: update

* add models

* fix alphabet order

* Update internal/llm/providers.go

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix: naming to avoid clashing with cn version

* feat(providers): update SiliconFlow models and remove stale entries

* Remove LongCat-2.0 from models list

* fix: correct indentation (spaces → tabs) in siliconflow provider

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: kite <lizhengfeng.lzf@alibaba-inc.com>
2026-08-12 11:29:11 +08:00
Tao Xin 4068a4bd25 feat(providers): add siliconflow-cn as a built-in model provider (#775) 2026-08-11 22:12:31 +08:00
Tao Xinandkite a9449db5d3 feat(llm): add novita api as a default provider (#829)
* feat(llm): add Novita AI as a built-in provider

Novita's endpoint (https://api.novita.ai/v3/openai) is OpenAI-compatible,
so it registers like the other OpenAI-protocol providers (deepseek, kimi,
z-ai, ...). Adds the registry entry, the matching name in the
provider-order test, and the provider table in the en/zh/ja
configuration docs. Model ids are taken from the live
/v3/openai/models endpoint.

* fix(llm): correct Novita base URL to current documented endpoint

The registry entry, tests-adjacent docs tables (en/ja/zh configuration.md)
used https://api.novita.ai/v3/openai. That path still resolves today, but
Novita's current documentation (novita.ai/docs/guides/llm-api) no longer
shows it; the current documented OpenAI-compatible endpoint is
https://api.novita.ai/openai. Verified live 2026-08-01: both paths return
identical /models and /chat/completions results, so this is a stale-citation
fix, not a functional break.

* Recommend Novita's current flagship models

The models listed for Novita were older ids that no longer reflect what
the platform leads with. Point the recommendations at the three current
flagships instead, each verified against api.novita.ai:

  moonshotai/kimi-k3              1M context, native vision
  zai-org/glm-5.2                 1M context, long-horizon agentic work
  deepseek/deepseek-v4-flash-0731 1M context, cheapest of the three

Context windows, output limits, input modalities and pricing were taken
from the live /openai/v1/models response rather than carried over.

* Apply suggestion from @wu21-web

Co-authored-by: Tao Xin <wu2196674@icloud.com>

* Sync provider registry with upstream to resolve merge conflict

Rebase-equivalent update of internal/llm/providers.go,
internal/llm/providers_test.go, and the en/ja/zh/ru configuration docs
to match upstream/main's current content (minimax-cn, mistral, model
list refreshes) while keeping the novita entry this branch adds. This
is a targeted content sync of the six files that conflicted, not a
full merge, so unrelated upstream changes (workflows, CI, etc.) are
left untouched. Also adds the novita row to the ru docs table, which
was missing.

---------

Co-authored-by: kite <254839944+lizhengfeng101@users.noreply.github.com>
2026-08-11 20:15:52 +08:00
Tao XinandLei Zhang 372d3dd160 fix(codeql): Workflow does not contain permissions (#814)
* fix(codeql): Workflow does not contain permissions

* 更新 translation-sync.yml

Co-authored-by: Lei Zhang <61303077+stay-foolish-forever@users.noreply.github.com>

---------

Co-authored-by: Lei Zhang <61303077+stay-foolish-forever@users.noreply.github.com>
2026-08-10 19:11:39 +08:00
Tao Xin f44821d9aa fix: no pages deployment on forks (#793) 2026-08-09 12:44:51 +08:00
Tao Xin c5621fc84b docs: fix invalid subject (#795)
contributers cannot be pushed
2026-08-09 12:09:41 +08:00
Tao Xin 8aa5cd3bad docs: remove stale ocr session comments from README and migrate to site docs (#774)
* docs: fill in missing translations

* Revert "docs: fill in missing translations"

This reverts commit c881e5da29.

* remove stale content from README
2026-08-08 21:26:16 +08:00
Tao Xin 7f8c22f9e2 docs: add instructions for macports (#769) 2026-08-07 17:58:24 +08:00
Tao Xin 6aa3f50033 fix(viewer): externalize repos page inline script to comply with CSP (#758)
* move inline scripts from repos.html to repos.js

* fixup

* fix: include repos.js in embedded assets
2026-08-07 11:35:17 +08:00
Tao Xin 4bcc95acec fix: remove timeout fields and more (#756)
Signed-off-by: wu21-web <xtao@yzu.edu.cn>
2026-08-06 22:19:27 +08:00