Commit Graph
100 Commits
Author SHA1 Message Date
oxoxDevandGitHub 2f4c3f397d feat(integrations): Polymarket trading + market data (#1398, venue 1/3) (#2145) 2026-05-19 19:15:20 +05:30
dfb2a6caa1 feat(agent): cross-chat context retrieval for same-user threads (#1505) (#2054)
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-18 15:57:35 +05:30
4d73bf869a fix(whatsapp): recover DOM message bodies — telemetry, tier-3 fallback, source tag, synthetic chat_id (#1376) (#1804)
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-15 20:29:29 -07:00
9a73cb24c6 fix(app): split connectivity into internet/core/backend channels (#1527) (#1727)
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-15 15:56:00 -07:00
40cce5c409 fix(observability): close 3 transient-failure leak paths in Sentry classifier (#1608) (#1798)
Co-authored-by: Cyrus Gray <cyrus@tinyhumans.ai>
2026-05-16 00:16:48 +05:30
20c61a9bdd test(composio): pin compound retry count to 4 (unblock CI for #1719/#1727/#1795) (#1803)
Co-authored-by: Cyrus Gray <cyrus@tinyhumans.ai>
2026-05-16 00:15:19 +05:30
b778433c8a fix(observability): demote composio validation noise to expected user-state (#3R #3S #33 #34 #97) (#1795)
Co-authored-by: Cyrus Gray <cyrus@tinyhumans.ai>
2026-05-15 18:59:44 +05:30
eecd11cf0b fix(observability): drop 401 session-expired Sentry noise (#25, #1Q, #27, #1G) (#1719)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-15 04:13:44 -07:00
oxoxDevandGitHub f583829d10 Filter transient updater Sentry noise (#1716) 2026-05-14 21:36:36 -07:00
72a365c9ce fix(channels): demote channel-message 404s to typed error (OPENHUMAN-TAURI-2Y) (#1732)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-14 21:07:13 -07:00
oxoxDevandGitHub 23fbaecc19 Fix composio integrations URL base normalization (#1715) 2026-05-14 04:59:14 -07:00
bf9404a42f fix(providers): drop budget-exhausted 400s from Sentry (#3M, #12, #13) (#1633)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-14 04:18:30 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>Claude Opus 4.7Steven EnamakelZavian Wangobchain
5e6073baaa fix(windows): retry-with-backoff for transient FS errors on auth-profiles.lock + .openhuman wipe (#9E, #9C, #4Y, #61, #5Q, #9F, #4M) (#1641)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
Co-authored-by: Zavian Wang <36817799+Zavianx@users.noreply.github.com>
Co-authored-by: obchain <167975049+obchain@users.noreply.github.com>
2026-05-13 20:07:55 -07:00
c2502a6c1a fix(agent): skip Sentry on max-iteration cap, emit info (#99, #98) (#1634)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-13 20:05:13 -07:00
70083897a0 fix(integrations): fall back to default backend when api_url points at local AI (#51, #80, #7Z) (#1630)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-13 19:44:18 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>Claude Opus 4.7
9363ec9d54 fix(si_server): idempotent start_session, suppress benign 'session already active' (#5J, #5H) (#1635)
Signed-off-by: oxoxDev <nikhil@tinyhumans.ai>
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-13 14:27:52 -07:00
41e548b3d8 fix(observability): drop transient backend_api + integrations failures from Sentry (#1632)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-13 14:20:33 -07:00
57b4e0e3b8 fix(core_process): demote expected port-clash + Windows bind ACL to warn (#2B, #AT, #BV, #BT) (#1628)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-13 10:51:26 -07:00
6d2e722fa8 fix(threads): typed ThreadNotFound error + skip Sentry for stale-thread RPCs (OPENHUMAN-TAURI-4H, -60) (#1570)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-12 21:30:34 -07:00
afdc268040 fix(observability): drop transient upstream HTTP from Sentry (429/408/502/503/504) (#1529)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-12 20:45:06 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>Claude Opus 4.7Steven Enamakel
721cb2b64c fix(util): UTF-8-safe truncation helpers + audit unsafe byte-slice call sites (OPENHUMAN-TAURI-7G) (#1549)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-12 19:57:34 -07:00
29f4b02d3b fix(socket): follow HTTP 3xx during WebSocket handshake (OPENHUMAN-TAURI-9X) (#1547)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-12 19:57:18 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>Steven Enamakel
2f2f98516a fix(rpc): normalize legacy un-namespaced method names in dispatcher (OPENHUMAN-TAURI-9Q) (#1541)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-12 19:56:51 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>Claude Opus 4.7Steven Enamakel
d762660ea3 fix(si_server): skip embedded server autostart on non-macOS (OPENHUMAN-TAURI-50) (#1542)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-12 19:56:40 -07:00
3bfe53aaa9 fix(tauri): hide instead of destroy main window on Windows close (OPENHUMAN-TAURI-2X) (#1548)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-12 19:51:31 -07:00
54a9396f88 fix(ollama): URL builder + local-AI noise suppression bundle (#1553)
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-12 19:50:33 -07:00
af4d231ced chore(branding): refresh app icons across all sizes (#1571)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 11:30:29 -07:00
3db3b92992 fix(webview-accounts): typed error wrap for openWebviewAccount (#1472) (#1521)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 00:22:29 -07:00
oxoxDevandGitHub ef998ca16c fix(openUrl): fall back to window.open when CEF IPC handle not ready (#1472) (#1491) 2026-05-11 12:07:42 -07:00
2426110c5d feat(auth): classify RPC 401s + global reauth bus (#1472) (#1495)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-11 11:34:08 -07:00
oxoxDevandGitHub 49398094e8 fix(human/mascot): consume orphan audio-stopped rejections (#1472) (#1494) 2026-05-11 09:29:47 -07:00
b5bedd6b2c fix(tauri): align staging datadir resolution with core (#1490) (#1492)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-11 09:26:38 -07:00
0f6cc583f3 feat(tools/whatsapp_data): expose local WhatsApp store to agent (#1341) (#1373)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-08 19:04:15 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
530e18e372 feat(redirect-links): stage util to append ?u= on openhm.xyz URLs (#1164) (#1184)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
2026-05-07 12:34:19 -07:00
a3f8321303 fix(integrations): propagate backend error body in non-2xx responses (#1296) (#1330)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-07 12:30:39 -07:00
b7f743d461 fix(webview-accounts): zoom Sign in with Google escapes to system browser (#1294) (#1329)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-07 12:28:25 -07:00
44062fae8c fix(webview/cdp): replace wall-clock load timeout with idle-watchdog (#1213) (#1312)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-07 12:06:21 -07:00
oxoxDevandGitHub 7b0eff2d14 feat(tools/computer): humanize MouseTool cursor motion (#682) (#1309) 2026-05-07 12:05:56 -07:00
ba88d8cfc3 fix(webview/meet): gate orchestrator handoff on user opt-in (#1299) (#1310)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-06 17:43:21 -07:00
oxoxDevandGitHub bbdb823eda fix(webview/slack): first-load + Google auth (#1036) (#1249) 2026-05-06 16:47:21 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>Claude Opus 4.7
d0dc31c53f test(settings): dev-options + data-management E2E coverage (#969) (#1220)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-06 13:17:50 -07:00
9379a2b86b fix(macos/plist): add Bluetooth + privacy keys to prevent Gmeet sign-in crash (#1288) (#1297)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-06 13:10:35 -07:00
oxoxDevandGitHub 44c8b834fb feat(webview-accounts): faster + clearer cold opens (#1233 #1284) (#1285) 2026-05-06 13:09:17 -07:00
oxoxDevandGitHub 13d3cedfbc docs(gmeet-parity): row 15 codec-gap status post #1251 build infra (#1223) (#1282) 2026-05-06 13:07:54 -07:00
oxoxDevandGitHub 5f3a9693d9 fix(tauri): clean shutdown + orphan reap (#1060) (#1248) 2026-05-05 22:36:33 -07:00
4d08ada637 fix(autocomplete): suppress macOS Apple Events permission popup spam (#985) (#1188)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-05 15:44:56 -07:00
oxoxDevandGitHub 91555caba3 feat(cef-build): proprietary-codec build infra for Gmeet dynamic backgrounds (#1223) (#1251) 2026-05-05 15:34:49 -07:00
be9bc54fbb fix(webview/gmeet): cold-add reliability + Phase A diagnosis of bg effects (#1053) (#1222)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-05 14:02:20 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>Claude Opus 4.7
a274adc81e feat(agent): orchestrator worker thread depth=1 (#930) (#1221)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-05 11:06:43 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
34a6b4021f feat(composio): format trigger slugs into human-readable labels (#1129) (#1179)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
2026-05-04 12:34:38 -07:00
oxoxDevGitHubgoogle-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
8f38f4e582 refactor(composio): hide raw connection ID, derive friendly label (#1153) (#1185)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
2026-05-04 10:49:25 -07:00
995669fc0a fix(cef): popup paint dies after first frame — skip blank-page guard for popups (#1079) (#1182)
Co-authored-by: Steven Enamakel <31011319+senamakel@users.noreply.github.com>
2026-05-04 08:56:12 -07:00
262d92db22 fix(webview/slack): media perms + deep-link isolation (#1074) (#1080)
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-01 17:54:05 -07:00
c7c9c629ad fix(webview-accounts): retry data-dir purge so CEF handle race doesn't leak cookies (#1076) (#1081)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-05-01 17:53:40 -07:00
oxoxDevandGitHub fbd4c7ee11 fix(app): reload webview instead of restart_app in dev mode (#1068) (#1071) 2026-05-01 17:45:34 -07:00
7bd83dd872 fix(welcome): re-enable OAuth buttons with focus/timeout recovery (#1049) (#1069)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-01 17:33:40 +05:30
oxoxDevandGitHub 8c65f10863 feat(webview/gmeet): native cam/mic/screenshare + keep Meet routing in-app (#1022) (#1054) 2026-04-30 08:56:38 -07:00
84d78145fd fix(webview/slack): scanner spawn + notifications + post-pushState target match (#1016) (#1028)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 18:44:45 -07:00
oxoxDevandGitHub 975614d0ec fix(webview/whatsapp): IDB walk + DOM scrape + active-chat plumbing (#1017) (#1034) 2026-04-29 15:38:09 -07:00
a09222b4ec feat(ci): tighten PR template + add soft-fail quality gates (#965) (#1001)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-29 11:09:54 -07:00
f7f9fa2044 test: rewards & progression coverage (#970) (#1003)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 19:33:02 -07:00
dcbcf7cc4e test(e2e): system tool coverage — fs/shell/git/browser (#967) (#1002)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 18:56:10 -07:00
d88bc5ed0e docs(release): add manual smoke checklist (#971) (#1000)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 18:55:08 -07:00
0d3428ea9d docs(domains): add foundation domain READMEs (#966) (#999)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 18:54:54 -07:00
e782f1ad22 fix(auth): close cross-user state + CEF cookie leak (#900) (#1007)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 18:53:25 -07:00
oxoxDevandGitHub 1a25f5ba5c fix(ui): refetch snapshot on turn boundary so progress UI re-syncs (#924) (#981) 2026-04-28 16:19:15 +05:30
4f9da9eb8d test(foundation): coverage matrix + strategy + gap-fill batch (#773) (#980)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-28 16:13:48 +05:30
oxoxDevandGitHub 215a776eea feat(ux): lock UI to welcome agent until chat onboarding completes (#883) (#892) 2026-04-24 15:46:31 -07:00
fc4b97abc2 feat(accounts): loading overlay for first-time webview opens (#867) (#887)
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-04-24 15:46:00 -07:00
oxoxDevandGitHub 116fa86838 fix(cef): preflight cache-lock check on macOS (#864) (#879) 2026-04-24 09:37:49 -07:00
oxoxDevandGitHub 9ffc61a461 feat(webview): in-page screen-share picker for getDisplayMedia (#713) (#809) 2026-04-24 17:31:13 +05:30
oxoxDevandGitHub 5a246bc5b6 feat(accounts): Zoom webview account + zoomus:// deep-link rewrite (#657) (#853) 2026-04-24 17:24:49 +05:30
b329e45cdb feat(skills): uninstall for user-scope SKILL.md skills (#781) (#833)
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-24 17:23:40 +05:30
9d7237bb91 feat(skills): agentic loop wiring for SKILL.md bodies (#781) (#807)
- Add Skill::read_body to fetch SKILL.md instruction text during agent inference.
- Implement a skill matcher supporting explicit @ mentions and automatic keyword/tag heuristics.
- Create a rendering system for skill injection with an 8KB budget and truncation handling.
- Wire skill matching and instruction body injection into the Agent::turn execution path.
- Include 24 unit tests for skill matching, ranking logic, and size-cap enforcement.

Closes #781

Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
2026-04-23 13:44:26 -07:00
581f37965c feat(skills): SKILL.md skills UI — browse, create, install from URL (#681) (#740)
* feat(skills/core): add read_skill_resource with size + traversal guards (#681)

Introduces `read_skill_resource(skill_id, relative_path)` in the skills
ops module. Used by the new `skills.read_resource` RPC (landed in a
follow-up commit) to let the UI preview files bundled alongside a
SKILL.md without having to shell out to the Node runtime.

Guards rejecting each known attack surface have their own unit test:
- empty skill_id / empty relative_path
- unknown skill
- absolute paths
- `..` traversal escapes (checked after canonicalization against the
  skill root, reusing the pattern from the Node exec allowlist)
- directory targets
- symlinked leaves (reject via `symlink_metadata` before open)
- files over the 128 KB cap
- non-UTF-8 content (binary allowlist is text-only)

Happy-path test covers a small text resource under the skill root.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(skills/core): wire skills.read_resource RPC + namespace (#681)

Adds `skills` RPC namespace with `skills.list` and `skills.read_resource`
handlers. `read_resource` delegates to `read_skill_resource` (previous
commit) and surfaces path-traversal / size / encoding errors back to the
caller verbatim so the UI can render the error string as-is.

- `src/openhuman/skills/schemas.rs` (new): controller + schema
  definitions, plus unit tests for schema name stability, round-trip of
  the minimum `SkillSummary` fields, and controller list/schema length
  parity.
- `src/openhuman/skills/mod.rs`: declare `pub mod schemas` and re-export
  `all_skills_controller_schemas`, `all_skills_registered_controllers`,
  and `skills_schemas`.
- `src/core/all.rs`: register the controllers + schemas and add a
  namespace description so the RPC discovery endpoint surfaces it.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(app/api): typed skillsApi client for list + read_resource (#681)

Thin typed wrapper around the `skills.list` and `skills.read_resource`
RPCs added in the previous commit. The client normalises the backend
response shape (bytes + UTF-8 content) and rethrows backend error
strings verbatim so the preview pane can render them unchanged.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(app/ui): SkillResourceTree groups bundled resources by top dir (#681)

Presentational component that takes the `resources: PathBuf[]` from a
loaded Skill and renders it as a grouped list (scripts, assets,
references, etc. based on the first path segment). Selecting a leaf
calls `onSelect(relativePath)` so the parent drawer can drive preview
state.

Stateless — no fetching, no effects. Styling follows the stone/coral
design tokens used across the Skills page.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(app/ui): SkillResourcePreview size-gated viewer + specs (#681)

Presentational component that fetches a single bundled resource via
`skillsApi.readSkillResource`. Backend caps payloads at 128 KB and
either returns UTF-8 text or a plain error string, so the preview pane
has three visual states: loading, error, success.

- On error (e.g. "path escape", ">128KB", "non-UTF-8"), renders the
  backend message verbatim in a coral panel.
- On success, renders a monospace pre block with the byte count in the
  footer.
- `key={id:path}` on the mount site (in SkillDetailDrawer, next commit)
  drives a remount when the selected resource changes — so no
  setState-in-effect hack is needed to reset loading state.

Vitest specs cover: loading state, success rendering with byte footer,
error rendering for traversal / oversize / encoding strings, cancelled
fetch guard on unmount.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(app/ui): SkillDetailDrawer right-side detail panel + specs (#681)

Slide-in right-hand drawer that displays frontmatter metadata
(description, version, author, license, tags, allowed_tools) and hosts
SkillResourceTree + SkillResourcePreview. Opened by clicking a skill
card on the Skills page (wired in the next commit).

- Focus management: on mount, focuses the close button via
  `window.requestAnimationFrame` and restores the previously focused
  element on unmount.
- Esc + backdrop click dismiss.
- Preview pane is conditionally rendered and keyed on
  `${skill.id}:${selectedResource}` so changing the selected resource
  remounts the previewer (avoids setState-in-effect pattern).

Vitest specs cover: render with frontmatter, resource tree click opens
preview, close button / Esc / backdrop dismiss paths, focus
restoration, empty-resources case.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(app/ui): open SkillDetailDrawer on skill card click (#681)

Wires the Skills page to the new drawer: clicking a skill card sets
`selectedSkill` state, which mounts `SkillDetailDrawer`. Dismissing the
drawer clears the state. Cards gain an explicit "View details"
affordance for discoverability.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(skills/core): add skills.create RPC for scaffolded SKILL.md authoring (#681)

Adds `create_skill` in ops.rs plus the `skills.create` controller + handler
in schemas.rs. Writes a minimal SKILL.md (with optional license/author/tags/
allowed-tools frontmatter) under the selected scope, scaffolds scripts/
references/assets subdirs, and re-discovers the skill to return the parsed
SkillSummary. Legacy scope rejects; Project scope requires the trust marker;
User scope is always allowed when a home directory is available.

Hardened against path traversal the same way read_skill_resource is:
canonicalize the scope root, canonicalize the target dir, reject unless the
target starts with the root. Slug derivation is ASCII-only (collapse whitespace/
-/_ to a single hyphen, drop other chars, trim hyphens, enforce MAX_NAME_LEN).

Tests (hermetic via create_skill_inner):
- user-scope happy path (slug, metadata, SKILL.md on disk, subdirs)
- slug collision rejection
- invalid name (no alphanumerics) rejection
- project-scope without trust marker rejection
- project-scope with trust marker happy path
- legacy-scope rejection
- empty-description rejection
- slugify edge cases

Closes part of #681 (backend scope for create flow).

* feat(skills/core): add skills.install_from_url RPC via npx skills add (#681)

Introduces `install_skill_from_url(url, timeout_secs?)` — a JSON-RPC method
that shells out to `npx --yes skills add <url>` under the managed Node
runtime so the UI can install published SKILL.md packages directly.

Security posture:
- https scheme only (no http, file, ssh, git+https…)
- Rejects `localhost`, `*.localhost`, `*.local`, RFC1918 private IPv4,
  loopback, link-local, multicast, broadcast, unspecified, 100.64/10 CGN,
  0.0.0.0/8, and IPv6 loopback/unspecified/multicast, fc00::/7 ULA,
  fe80::/10 link-local. Explicitly covers 169.254.169.254 cloud metadata.
- Trims + caps URL at 2048 chars; parses with the `url` crate.
- IPv6 brackets stripped from `host_str()` before address parse.

Process posture:
- Reuses `NodeBootstrap` so the managed toolchain resolves first.
- `env_clear()` + explicit PATH injection (bootstrap bin_dir first) + a
  narrow safe-env allow-list (HOME, TERM, LANG, LC_ALL, LC_CTYPE, USER,
  SHELL, TMPDIR). Matches the npm_exec pattern from #723.
- Default 60s wall-clock timeout, capped at 600s.
- Captures stdout/stderr; returns both on success or failure.
- Diff-based `new_skills`: snapshots discovered skills pre-install and
  reports slugs that appear post-install.

Surface:
- JSON-RPC: `openhuman.skills_install_from_url`
  params:  { url: string, timeout_secs?: number }
  result:  { url, stdout, stderr, new_skills[] }
- Wired into `all_skills_controller_schemas()` and
  `all_skills_registered_controllers()`.

Tests (5 new unit tests, all pass — 51/51 in skills::):
- validate_install_url_accepts_public_https
- validate_install_url_rejects_non_https_scheme (http, file, ftp, ssh,
  git+https, javascript)
- validate_install_url_rejects_empty_and_oversized
- validate_install_url_rejects_private_and_loopback (20 URLs inc. CGN,
  cloud metadata, IPv6 ULA/link-local/loopback/multicast)
- validate_install_url_rejects_malformed (missing scheme, empty host,
  non-https scheme, unparseable bracketed host)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(app/api): skillsApi.createSkill + installSkillFromUrl wrappers (#681)

Adds typed frontend wrappers for the two new skill-authoring RPC methods:

- `skillsApi.createSkill(input)` — scaffolds a new SKILL.md skill via
  `openhuman.skills_create`. Accepts camelCase `allowedTools` and rekeys
  it to the `allowed-tools` spelling the SKILL.md frontmatter convention
  expects, matching `SkillsCreateParams` in `src/openhuman/skills/schemas.rs`.
  Optional fields are only sent when explicitly provided so the Rust
  `#[serde(default)]` defaults apply cleanly.

- `skillsApi.installSkillFromUrl(input)` — installs a published skill
  package via `openhuman.skills_install_from_url`. Accepts camelCase
  `timeoutSecs` and rekeys it to `timeout_secs`. Normalizes the response
  (snake_case `new_skills` -> camelCase `newSkills`, missing list -> []).

Both wrappers reuse the existing `unwrapEnvelope` helper so they
tolerate either a bare RPC payload or the `{ data: … }` envelope some
transports emit.

Adds `CreateSkillInput`, `InstallSkillFromUrlInput`, and
`InstallSkillFromUrlResult` type exports for downstream modal components.

Tests (vitest, 6 new specs, all pass):
- createSkill forwards inputs and rekeys allowedTools
- createSkill omits optional fields when absent
- createSkill unwraps envelope responses
- installSkillFromUrl forwards url and rekeys timeoutSecs
- installSkillFromUrl omits timeout_secs + defaults newSkills to []
- installSkillFromUrl unwraps envelope responses

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(app/ui): CreateSkillModal for scaffolding SKILL.md skills (#681)

Adds a centered white modal that scaffolds a new SKILL.md skill via
`skillsApi.createSkill`, matching the settings-modal design rules
(520px desktop, 16px radius, backdrop+blur, Escape/click-out to close,
focus capture).

Form fields mirror the Rust `SkillsCreateParams` schema:
  - name (required) — display name, also slugified into the on-disk
    directory; a live slug preview surfaces what will hit disk
  - description (required) — short prose; written as the
    `description:` field in the generated YAML frontmatter
  - scope (user | project radio) — `legacy` is hidden because that
    layout is read-only and being phased out
  - license (optional) — free-form SPDX-style string
  - author (optional)
  - tags (optional, CSV) — normalised client-side; empty entries dropped
  - allowedTools (optional, CSV) — rekeyed to `allowed-tools` on the
    JSON-RPC wire by `skillsApi.createSkill`

The slug preview mirrors `slugify_skill_name` on the Rust side
(lowercase ASCII alnum + `-`, collapse repeats, trim edge hyphens) so
the user sees what the Rust slugifier will produce; the Rust side stays
authoritative when the skill is persisted.

On success `onCreated(skill)` fires with the freshly-discovered
`SkillSummary`, letting the parent grid insert the new row without a
full refetch. On failure the Rust error string is surfaced verbatim in
a coral-styled alert and the submit button re-enables.

Vitest specs cover: required-field rendering, live slug preview,
submit-disabled gating, Escape close, wire-format rekey of
`allowedTools` → `'allowed-tools'`, `onCreated` dispatch, and
error-banner recovery.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(app/ui): InstallSkillDialog for npx skills add <url> (#681)

Adds a centered white modal that installs a published skill package
via `skillsApi.installSkillFromUrl`. The Rust side shells out to
`npx --yes skills add <url>` under the managed Node toolchain, with
an allow-list on the URL (https only, no private/loopback/link-local/
multicast/cloud-metadata hosts) and a wall-clock timeout (default 60s,
max 600s).

UI contract:
  - Single URL input plus optional timeout in seconds.
  - Client-side `isLikelyValidUrl` fails fast on non-https URLs so the
    user doesn't pay a round-trip for shape errors the Rust side would
    reject anyway; the Rust side remains authoritative.
  - Timeout field validates `1 <= n <= 600` client-side to mirror the
    server-side clamp range.
  - While the RPC is in flight we render a spinner with "Running
    `npx skills add`…" copy and disable close / backdrop dismiss so we
    don't orphan the subprocess.
  - On success we surface the list of `newSkills` (ids that appeared
    post-install) plus captured stdout/stderr panes inside collapsible
    <details> elements, then hand the full result back to the caller
    via `onInstalled` so the parent can refetch the skills list and
    auto-select the new row.
  - On failure the Rust error string is rendered verbatim in a coral
    alert and the submit button re-enables.

Vitest specs cover: required-field rendering, URL shape gating (empty,
malformed, http://, https://), timeout range validation, `timeoutSecs`
forwarding on submit, success panel with newSkills rendering, blank
timeout omitted from payload, and error-banner recovery.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(app/ui): wire New skill + Install from URL into Skills page (#681)

Adds a header row on the Skills page with two buttons:
  - **New skill** → opens `CreateSkillModal`
  - **Install from URL** → opens `InstallSkillDialog`

Extracts the existing `listSkills` effect into a reusable
`refreshDiscoveredSkills` helper so both new flows can reconcile their
results against the freshly-discovered `SkillSummary` rows rather than
relying on the optimistic payload from the RPC alone.

Create flow:
  - Optimistically appends the returned `SkillSummary` to
    `discoveredSkills` (dedupe by id).
  - Auto-opens the detail drawer for the new skill so the user lands in
    context — matches the install flow's UX.
  - Follows up with `refreshDiscoveredSkills()` so version/author/
    warnings picked up by the Rust discoverer end up in state too.

Install flow:
  - Always refreshes the list (the install can add multiple skills if
    the package declares several).
  - Auto-opens the detail drawer for the first newly-installed skill
    when at least one id is reported back; otherwise leaves the grid in
    its refreshed state.

Both buttons sit in a flush `max-w-lg` header above the existing
search bar, styled consistent with `UnifiedSkillCard` CTAs — ocean
primary for "New skill" (positive action), neutral stone for "Install
from URL" (secondary).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(skills/core): direct SKILL.md fetch replaces npx skills add (#681)

Installer no longer shells out to the vercel-labs/skills CLI. It now fetches
SKILL.md over HTTPS, validates YAML frontmatter, and writes into the user's
skills dir. Size cap (1 MiB), timeout clamp (1-600s), GitHub blob->raw URL
normalization, and path-traversal guards are covered by unit tests.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* refactor(app/ui): install dialog copy + categorized errors for direct fetch (#681)

Dialog subtitle, helper text, and in-flight indicator reflect the new direct
SKILL.md fetch flow. Errors from the core are categorized into friendly titles
(URL rejected, too large, timeout, parse failure, already installed, write
failed) with the raw backend message tucked under a details disclosure.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* test(app/ui): dialog specs cover direct-fetch fixtures + error categorization (#681)

Fixtures updated to raw GitHub SKILL.md URLs. New cases assert the
categorization helper surfaces the right title for invalid SKILL.md, unsupported
URL form, and unknown backend errors (raw text hidden under details).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(skills/core): install_from_url writes to user scope (#681)

Project scope (`<ws>/.openhuman/skills/`) is gated on a `<ws>/.openhuman/trust`
marker that the workspace rarely has, so freshly-installed skills were
invisible to `skills.list` until the user opted the workspace into trust.
Route installs to `~/.openhuman/skills/<slug>` — the user-scope root that
`discover_skills` always scans — so "Install from URL" surfaces the new
skill immediately.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* docs(skills): align install_from_url docs with direct-fetch impl (#681)

`install_from_url` stopped shelling out to `npx --yes skills add <url>` when
it was rewritten to fetch SKILL.md over HTTPS directly, but schema
descriptions and SDK wrappers still described the old subprocess flow. Fix
the module-level rustdoc, the JSON-RPC schema `description`/`comment`
fields, and the TS client wrapper doc comments so the surface documents
what actually runs.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(skills/core): DNS-to-private-IP SSRF guard + install rollback (#681)

Two fixes surfaced by CodeRabbit review on PR #740:

* `validate_install_url` only inspected literal-IP hosts, so a
  public-looking hostname like `evil.example.com` with an A record
  pointing at `127.0.0.1` / `169.254.x` / etc. would still be handed to
  `reqwest`. Resolve the host via `tokio::net::lookup_host` before the
  GET and reject if any returned address falls in loopback / private /
  link-local / multicast / unspecified ranges. Document the remaining
  DNS-rebinding gap (pinning to a `SocketAddr` + custom reqwest
  resolver is tracked separately).
* If `std::fs::write` or `std::fs::rename` fails after `create_dir_all`
  succeeded, the empty/partial target directory used to survive and
  permanently block retries under the same slug. Wrap the write+rename
  in a rollback that removes the temp file + the just-created directory
  on failure (best-effort; cleanup errors are logged and the original
  write error is surfaced).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* style(skills): cargo fmt break long Host::Ipv6 conditional (#681)

CI's cargo fmt (stable) rewraps the long `.map(..).unwrap_or(false)` chain
that passed local fmt. Apply the break so the pre-push hook and the
upstream lint job agree.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-22 13:45:12 -07:00
8f927369d1 feat(telegram): CDP-driven Telegram Web K scanner (#630) (#638)
* feat(accounts): implement accounts management with webview integration

- Added a new Accounts page for managing user accounts, including the ability to add and remove accounts.
- Introduced AddAccountModal for selecting account providers and initiating account setup.
- Implemented WebviewHost to display third-party web applications (e.g., WhatsApp Web) within the app.
- Enhanced routing to include a protected route for the Accounts page.
- Updated the BottomTabBar to include an Accounts tab for easy navigation.
- Integrated Redux for state management of accounts, messages, and logs, ensuring a seamless user experience.
- Updated dependencies in Cargo.lock to version 0.52.9 for compatibility.

This commit significantly enhances the application's functionality by allowing users to manage accounts directly within the app, improving overall user engagement and experience.

* refactor(accounts): clean up Accounts component layout and improve readability

- Removed unnecessary comments and simplified the structure of the Accounts component for better clarity.
- Adjusted the rendering logic to enhance the layout of the active account section, improving user experience.
- Reformatted text in the no accounts message for better readability.
- Streamlined the import statements by consolidating related imports, enhancing code organization.

* feat(accounts): enhance account management with new providers and routing updates

- Introduced support for additional account providers: Telegram, LinkedIn, Gmail, and Slack, expanding user options for account management.
- Updated routing to replace the old /conversations path with /chat, streamlining navigation and improving user experience.
- Refactored the App component to include an AppShell for better layout management, ensuring the bottom tab bar visibility aligns with the selected account.
- Enhanced the BottomTabBar component to reflect the new routing and account options, improving accessibility and usability.
- Implemented fullscreen logic for accounts, allowing for a more immersive experience when interacting with selected accounts.
- Added utility functions for managing fullscreen states and account provider icons, enhancing code organization and maintainability.

This commit significantly improves the application's account management capabilities, providing users with a more flexible and engaging experience.

* feat(cef): integrate Chromium Embedded Framework support and enhance webview functionality

- Added support for the Chromium Embedded Framework (CEF) as an alternative runtime, allowing for improved webview capabilities.
- Updated Cargo.toml to include new dependencies and features for CEF integration, ensuring compatibility with existing Tauri plugins.
- Enhanced the WhatsApp recipe to include ghost-text autocomplete functionality, improving user experience during message composition.
- Implemented WebSocket observation in the WhatsApp recipe to capture and forward relevant message frames, enhancing real-time interaction.
- Introduced user agent spoofing for specific providers to bypass fingerprinting checks, ensuring better compatibility with services like Slack and LinkedIn.
- Refactored various components to accommodate the new runtime and improve overall code organization and maintainability.

This commit significantly enhances the application's webview capabilities and user interaction with messaging services, providing a more robust and flexible experience.

* feat(cef): add development command for CEF and update configuration

- Introduced a new development command `dev:cef` in both package.json files to streamline the development process for the Chromium Embedded Framework (CEF).
- Updated Cargo.toml to include the `tauri/devtools` feature alongside `tauri/cef`, enhancing debugging capabilities.
- Modified tauri.conf.json to adjust visibility settings for the application window and refined the Content Security Policy (CSP) for improved security.
- Enhanced resource paths in tauri.conf.json to support recursive file inclusion for better resource management.
- Updated the Rust code to bypass macOS Keychain prompts when using CEF, improving user experience during development.

This commit enhances the development workflow for CEF integration, providing better tools and configurations for developers.

* fix(cef): update development command for CEF to include signing identity

- Modified the `dev:cef` command in package.json to include the `APPLE_SIGNING_IDENTITY` environment variable, enhancing the development process for CEF on macOS.
- This change improves the build process by ensuring proper code signing during development, streamlining the workflow for developers working with CEF integration.

* feat(cef): enhance development command for CEF with safe storage setup

- Updated the `dev:cef` command in package.json to include a call to a new script, `setup-chromium-safe-storage.sh`, which pre-seeds the "Chromium Safe Storage" keychain entry with a permissive ACL.
- Added the `setup-chromium-safe-storage.sh` script to ensure that CEF/Chromium can read the keychain entry without prompting, improving the development experience on macOS.
- This change streamlines the setup process for developers working with CEF integration, ensuring a smoother workflow.

* feat(whatsapp): enhance message ingestion and IndexedDB integration

- Introduced a new `IngestMessage` interface to standardize message structure for WhatsApp.
- Updated `IngestPayload` to include additional fields for better message handling, including `provider`, `chatId`, and `day`.
- Implemented a new function `persistWhatsappChatDay` to handle the ingestion of chat messages by day, improving data organization and retrieval.
- Enhanced the WhatsApp recipe to utilize IndexedDB for direct data access, eliminating the need for DOM scraping and improving performance.
- Updated the Tauri configuration to enable development tools for easier debugging of webview accounts.

This commit significantly improves the application's ability to manage and ingest WhatsApp messages, providing a more robust and efficient user experience.

* feat(cdp): integrate IndexedDB scanner for WhatsApp via Chrome DevTools Protocol

- Added a new module for scanning IndexedDB using the Chrome DevTools Protocol (CDP), enabling direct access to WhatsApp data without DOM scraping.
- Implemented a scanner that communicates with the embedded CEF instance to read and decrypt messages stored in IndexedDB.
- Updated the Tauri application to manage the new scanner, ensuring it operates seamlessly with existing webview accounts.
- Enhanced the Cargo.toml and Cargo.lock files to include necessary dependencies such as `tokio-tungstenite` and `futures-util` for asynchronous operations.
- Refactored the WhatsApp recipe to utilize the new scanning capabilities, improving performance and data handling.

This commit significantly enhances the application's ability to interact with WhatsApp's IndexedDB, providing a more efficient and robust user experience.

* feat(cdp): enhance message diagnostics in IndexedDB scanner

- Updated the ScanSnapshot struct to include new fields for message diagnostics: `messageKeyUnion`, `messageTypeBreakdown`, and `sampleByType`, providing a comprehensive overview of message structures and types.
- Modified the scanner logic to capture and log detailed information about message types and their shapes, improving debugging capabilities.
- Refactored the JavaScript scanner to aggregate message key signatures and counts, enhancing the analysis of message records.

This commit significantly improves the application's ability to analyze and log message data from WhatsApp's IndexedDB, facilitating better debugging and data handling.

* feat(cdp): implement fast DOM scraping and crypto key extraction for WhatsApp

- Introduced a new fast-tick DOM scraping mechanism to extract rendered WhatsApp message bodies, enabling near real-time message updates without relying on IndexedDB.
- Added scripts for capturing and logging CryptoKey operations within WhatsApp's workers, allowing for better analysis of key derivations and decryptions.
- Enhanced the CDP scanner to interleave fast DOM scans with full IndexedDB scans, optimizing data retrieval and reducing UI spamming during idle periods.
- Updated the ScanSnapshot struct to include new fields for DOM-scraped messages and crypto operation statistics, improving the overall diagnostic capabilities of the application.

This commit significantly enhances the application's ability to interact with WhatsApp's messaging system, providing a more efficient and responsive user experience.

* feat(whatsapp): replace cdp_indexeddb with whatsapp_scanner for enhanced message handling

- Replaced the `cdp_indexeddb` module with `whatsapp_scanner` to streamline the scanning process for WhatsApp messages.
- Updated the application to manage the new `ScannerRegistry` for WhatsApp, improving the integration with the Chrome DevTools Protocol.
- Introduced new scripts for fast DOM scraping and full IndexedDB scanning, optimizing data retrieval and enhancing real-time message updates.
- Added a new `dom_scan.js` for efficient extraction of rendered message bodies directly from the DOM, reducing reliance on IndexedDB.
- Enhanced the `ScanSnapshot` struct to accommodate new fields for DOM-scraped messages, improving diagnostic capabilities.

This commit significantly improves the application's ability to interact with WhatsApp, providing a more efficient and responsive user experience.

* refactor(whatsapp): replace JavaScript DOM scanning with Rust-based DOM snapshot

- Removed the `dom_scan.js` script and replaced it with a new Rust module `dom_snapshot.rs` that captures DOM snapshots directly via the Chrome DevTools Protocol, enhancing performance and reliability.
- Introduced a new `idb.rs` module for scanning WhatsApp's IndexedDB, streamlining data retrieval and improving integration with the Rust backend.
- Updated the `ScanSnapshot` struct to accommodate changes in data handling, ensuring compatibility with the new scanning methods.
- Enhanced overall message handling capabilities, providing a more efficient and responsive user experience.

This commit significantly improves the application's ability to interact with WhatsApp, leveraging Rust for better performance and reducing reliance on JavaScript for DOM operations.

* feat(docs): add webview integration playbook for third-party messaging

- Introduced a comprehensive playbook detailing the process for integrating third-party webviews (e.g., Instagram, Messenger) into the application.
- Documented architecture, workflow, and best practices for building and debugging new integrations, leveraging Rust and Chrome DevTools Protocol.
- Included step-by-step instructions for setting up scanners, monitoring logs, and optimizing message handling, ensuring a streamlined development experience for future integrations.

This addition enhances the documentation, providing developers with a clear guide to implement and maintain webview integrations effectively.

* docs(webview): improve table formatting for clarity

- Enhanced the formatting of tables in the webview integration playbook to improve readability and consistency.
- Adjusted column headers and alignment for better presentation of job intervals and costs, ensuring clearer communication of scanning processes and common pitfalls.

This update aims to provide a more user-friendly documentation experience for developers integrating third-party webviews.

* feat(slack): integrate Slack scanner for message extraction and management

- Updated the OpenHuman package version to 0.52.15 in both Cargo.lock files.
- Introduced a new Slack scanner module to extract messages, users, and channels from Slack's IndexedDB using the Chrome DevTools Protocol.
- Added functionality to manage Slack accounts within the application, allowing for automatic opening of Slack webviews based on environment variables.
- Enhanced the existing webview account management to support Slack integration, ensuring seamless interaction with the Slack API.

This commit significantly improves the application's ability to interact with Slack, providing a robust framework for message handling and account management.

* fix(slack): one-doc-per-channel + omit CDP indexName param

CEF 146's IndexedDB.requestData rejects `indexName: ""` with "Could not
get index"; the CDP spec says empty string means the primary-key index
but this backend only accepts the field unset. Omit it entirely so the
Slack Redux-persist dump actually comes back.

Also switch memory grouping from (channel, day) → channel. Each Slack
channel is now one long-running memory doc keyed by channel name
(e.g. `general`, `team-product`, `elvin516`), falling back to channel
id for non-slug names. Every transcript line carries its own
`YYYY-MM-DD HH:MM` stamp and the header records the full date range.

`infer_team_id` updated to Slack's real DB naming pattern
`objectStore-<TEAM>-<USER>` (not `ReduxPersistIDB:` as initially
assumed).

* fix(onboarding): update navigation and test descriptions in OnboardingOverlay tests

- Changed the navigation path from '/conversations' to '/chat' in the OnboardingOverlay tests to reflect the updated routing logic.
- Updated test descriptions for clarity, ensuring they accurately describe the functionality being tested.

These changes enhance the accuracy and readability of the onboarding tests, aligning them with the current application flow.

* fix(conversations): add return statement to Conversations component

- Introduced a return statement in the Conversations component to ensure proper rendering of the sidebar or page variant.
- This change enhances the component's functionality by ensuring it returns the expected JSX structure.

These modifications improve the overall structure and behavior of the Conversations component.

* feat(accounts): add Discord integration and enhance AddAccountModal

- Introduced Discord as a new account provider, including its icon and service details.
- Updated the AddAccountModal to filter out already connected providers, improving user experience.
- Enhanced the UI to display a message when all providers are connected, ensuring clarity for users.
- Implemented context menu functionality for account management, allowing users to log out directly from the accounts list.

These changes expand the application's capabilities by integrating Discord and refining account management features.

* feat(discord): integrate Discord scanner for HTTP and WebSocket monitoring

- Added a new `discord_scanner` module to capture Discord API calls and WebSocket frames using the Chrome DevTools Protocol (CDP).
- Updated the `lib.rs` to manage the new Discord scanner alongside existing WhatsApp and Slack scanners.
- Enhanced the `webview_accounts` module to support Discord account management, including scanner registration and cleanup.

These changes expand the application's capabilities by enabling real-time monitoring of Discord interactions, enhancing user experience and functionality.

* feat(google-meet): integrate Google Meet as a new account provider

- Added Google Meet as a supported account provider, including its icon and service details.
- Updated the account management logic to handle Google Meet interactions, including recipe integration for call monitoring and notifications.
- Enhanced the UI to accommodate the new provider, ensuring a seamless user experience when managing accounts.

These changes expand the application's capabilities by integrating Google Meet, allowing users to join calls and receive notifications directly within the app.

* refactor(runtime): remove notification handling and composer autocomplete

- Eliminated the notification interception logic and associated functions, streamlining the runtime code.
- Removed composer autocomplete features, transferring responsibility for ghost-text overlays to the UI host.
- Updated comments to reflect the changes and clarify the remaining functionality.

These modifications simplify the runtime script, focusing on core features while delegating UI responsibilities.

* feat(google-meet): enhance Google Meet integration with lifecycle event handling

- Implemented lifecycle event handling for Google Meet, including events for call start, captions, and call end.
- Introduced in-memory storage for caption snapshots during meetings, allowing for the generation of markdown transcripts upon call completion.
- Added interfaces for payload structures related to Google Meet events, improving type safety and clarity in the codebase.
- Updated the webview account service to manage active meetings and flush transcripts to memory, ensuring a seamless user experience.

These changes significantly enhance the Google Meet integration, enabling real-time caption handling and transcript generation, thereby improving the overall functionality of the application.

* feat(cef): integrate CEF-based notification handling and update dependencies

- Added support for native OS notifications through the `tauri-runtime-cef` crate, enabling interception of browser notifications in embedded webviews.
- Introduced a new submodule for `tauri-cef` to manage CEF dependencies and facilitate notification handling.
- Updated the `.gitignore` to exclude CEF-related build artifacts and lock files.
- Removed the deprecated `notification_scanner` module, streamlining the codebase and focusing on the new CEF integration.
- Enhanced the `webview_accounts` module to register and manage CEF browser notifications, improving user experience with real-time alerts.

These changes significantly enhance the application's notification capabilities, leveraging CEF for a more integrated and responsive user experience.

* feat(cef): update CEF integration and dependency management

- Added `cef` and `tauri-runtime-cef` as dependencies to enhance CEF support.
- Updated `Cargo.toml` to reference `tauri-runtime-cef` from a local path, ensuring proper integration with the vendored CEF submodule.
- Removed direct Git references for Tauri packages, streamlining dependency management by using local paths.

These changes improve the application's CEF capabilities and simplify the dependency structure, facilitating better integration and maintenance.

* feat(browserscan): add BrowserScan as a new account provider with associated resources

- Introduced BrowserScan as a development-only account provider, including its icon and service details.
- Updated the account provider types and management logic to accommodate BrowserScan, enhancing the application's capabilities.
- Added a new recipe and manifest for BrowserScan, ensuring it integrates seamlessly into the existing webview account lifecycle.
- Enhanced the UI to display BrowserScan, providing users with a bot-detection sandbox for testing purposes.

These changes expand the application's functionality by integrating BrowserScan, allowing for improved testing and development workflows.

* feat(google-meet): enhance Google Meet integration with new transcript handling and session recovery

- Introduced a new service to handle Google Meet transcripts, enabling structured note extraction and proactive follow-up actions.
- Implemented session recovery logic to manage in-progress meetings when navigating away from the call.
- Updated the webview account service to log call events and captions, improving monitoring and debugging capabilities.
- Enhanced the Google Meet recipe to persist meeting state across navigations, ensuring seamless user experience.

These changes significantly improve the Google Meet integration, allowing for better management of meeting transcripts and user interactions.

* refactor(App): reorganize imports and clean up code structure

- Removed unused imports from App.tsx to streamline the code.
- Adjusted the import order for better readability and consistency.
- Enhanced the BottomTabBar component by simplifying the button rendering logic.
- Cleaned up the AddAccountModal component by consolidating prop destructuring.
- Improved formatting in various components for better code clarity.

These changes enhance code maintainability and readability across the application.

* update tauri

* feat(google-meet): improve caption handling and speaker identification logic

- Enhanced the logic for extracting speaker names from Google Meet rows, adding checks to filter out icon ligatures and irrelevant text.
- Updated the caption processing to better identify and score caption regions, ensuring more accurate transcript generation.
- Introduced new utility functions to differentiate between real captions and icon names, improving the overall reliability of the captioning feature.

These changes significantly enhance the accuracy and usability of the Google Meet integration, providing users with clearer and more relevant caption data.

* build(cef): bump vendor/tauri-cef to include full cef-helper source tree (#630)

Picks up 1b58f715 which fixes the bundler to copy the entire cef-helper/src/
tree instead of only main.rs — required for our CEF helper's Web Notifications
interception to link properly in downstream consumers.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* build(cef): patch cef-dll-sys to fix/146-location-windows (#630)

The vendor tauri-cef workspace pins cef-dll-sys to the
fix/146-location-windows branch via its own [patch.crates-io], but cargo patches
do not propagate through path dependencies. Without pinning cef-dll-sys here
too, helper processes crash with `CefApp_0_CToCpp called with invalid version
-1` because the app-side bindings target a different CEF ABI than what the
vendor's cef-helper was built against.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(telegram): scaffold CDP-driven Telegram Web K scanner module (#630)

New telegram_scanner module mirrors the Slack/WhatsApp scanner shape from
PR #629 but targets Telegram Web K's IndexedDB surface via CDP:

- mod.rs: per-account poller + ScannerRegistry; connects to CDP on
  127.0.0.1:9222, picks the Telegram target, and runs an IDB tick every 30s.
  Emits webview:event and POSTs openhuman.memory_doc_ingest so memory fills
  even when the main window is hidden.
- idb.rs: IndexedDB walker — requestDatabaseNames / requestDatabase /
  requestData, with record caps per store.
- extract.rs: peer-grouped message/user/chat extraction from the `tweb`
  snapshot.

cef-only (wry has no remote-debugging port).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(telegram): register scanner registry and dev-auto env (#630)

Wires telegram_scanner into the Tauri builder:
- Registers ScannerRegistry as managed state (cef-only).
- Adds OPENHUMAN_DEV_AUTO_TELEGRAM=<uuid> helper mirroring the Slack /
  Google Meet dev-auto flow — opens the Telegram Web K account webview
  2s after startup so the CDP scanner has a target without manual UI
  clicks. Useful for iterating on the scanner end-to-end.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(telegram): dispatch scanner on telegram account open/close/purge (#630)

Mirrors the slack/discord branches in webview_accounts:
- open(provider="telegram"): look up the telegram ScannerRegistry and
  ensure a CDP scanner is running for this account.
- close / purge: forget the account's scanner entry alongside the other
  providers so we don't leak poll loops.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* style: apply pre-push formatting

* fix(telegram): bind CDP scanner to account-marked targets

---------

Co-authored-by: Steven Enamakel <enamakel@tinyhumans.ai>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-21 13:58:06 -07:00
3da80d852e feat(skills,node): integrate SKILL.md + managed Node runtime (#681) (#723)
* build(skills): add serde_yaml for SKILL.md frontmatter (#681)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(skills): parse SKILL.md frontmatter and add multi-path discovery (#681)

Extends the skills module with agentskills.io-style discovery:

* Parses YAML frontmatter in SKILL.md (name, description, version,
  author, tags, allowed-tools, license) via serde_yaml, with a
  catch-all extras map for forward-compatible keys.
* Adds SkillScope (User / Project / Legacy) and discover_skills(),
  which scans ~/.openhuman/skills, ~/.agents/skills, <ws>/.openhuman/
  skills, <ws>/.agents/skills and the legacy <ws>/skills directory.
* Gates project-scope loading behind an explicit
  <ws>/.openhuman/trust marker (is_workspace_trusted helper).
* Resolves name collisions with project > user > legacy precedence
  and surfaces shadowing as per-skill warnings.
* Inventories bundled resources under scripts/, references/, assets/.
* Keeps the existing load_skills(workspace_dir) API as a
  backwards-compatible wrapper for existing callers.
* Preserves legacy skill.json fallback (marked legacy = true).
* Lenient validation: missing / mismatched / oversized name or
  description produce warnings instead of errors.
* Adds 12 unit tests covering frontmatter parsing, trust gating,
  collision shadowing, lenient fallbacks, legacy JSON and resource
  inventory. One existing prompt test updated to use
  ..Default::default() for the expanded struct.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(skills): align frontmatter with agentskills.io spec (#681)

Per the agentskills.io SKILL.md spec, only name, description, license,
compatibility, metadata, and allowed-tools are valid top-level keys.
Our SkillFrontmatter had version, author, and tags as top-level fields,
which drifted from the spec and would silently swallow mis-shaped data
for skills authored against the canonical schema.

Demote version/author/tags into the metadata map. Non-spec top-level
keys still parse via #[serde(flatten)] into extra, and when present
there we emit a migration warning and still populate the derived Skill
fields so existing skills keep working. Add compatibility as an
optional string alongside license.

New tests cover the spec-compliant metadata shape, the deprecated
top-level fallback path, and verify that the full spec frontmatter
parses without leaking into extras.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* build(runtime): add tar+xz2+zip for node runtime extraction (#681)

Node.js distributions ship as .tar.xz on Unix and .zip on Windows. The
upcoming Node runtime bootstrap extracts these in pure Rust; xz2 is
built with the `static` feature so liblzma is bundled and not a system
dependency. zip is pinned to default-features = false + deflate to
avoid pulling in bzip2/zstd/aes which we don't need for Node archives.

Deps only — no behavior change.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(config): add NodeConfig with env overrides (#681)

Introduce managed Node.js runtime configuration so skills that require
`node`/`npm` (agentskills.io packages with build steps) can be wired in
behind a single config switch. Fields:

- `node.enabled` — master switch (default true)
- `node.version` — pinned release (default `v22.11.0` LTS)
- `node.cache_dir` — absolute path for managed distributions; empty = use
  workspace default
- `node.prefer_system` — reuse matching system `node` when found (default
  true); set false for reproducible CI / airgapped deploys

Env overrides land in load.rs alongside the existing LOCAL_AI_TIER block:
- OPENHUMAN_NODE_ENABLED
- OPENHUMAN_NODE_VERSION
- OPENHUMAN_NODE_CACHE_DIR
- OPENHUMAN_NODE_PREFER_SYSTEM

No resolver / downloader yet — subsequent commits in the #681 series
consume this config to bootstrap the runtime.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(node_runtime): detect compatible system node on PATH (#681)

Introduce the `openhuman::node_runtime` module and its first piece: a
synchronous resolver that walks `PATH`, probes `node --version`, and
returns a `SystemNode` when the host toolchain major-version matches the
configured target.

Why resolve first: a successful probe lets the bootstrap skip a
~60 MB download per managed install. Matching is intentionally loose on
the patch level (Node LTS lines are ABI-stable and skills pin their own
deps via package-lock.json); operators needing strict pinning can set
`node.prefer_system = false`.

Tracing is verbose by design — resolver decisions gate the download
path, so operators need a clear breadcrumb trail at `debug`/`info`.

Includes unit tests for `parse_node_version` covering `v` prefix,
whitespace, major-only, and malformed inputs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(node_runtime): SHASUMS256-verified distribution downloader (#681)

Add the second piece of the managed Node.js runtime: streaming download
of OS/arch-specific prebuilt archives from nodejs.org, gated by a
SHA-256 match against the release's signed `SHASUMS256.txt`.

Key contracts:

- `NodeDistribution::for_host(version)` picks the right archive for the
  current OS/arch tuple. Supported matrix:
  * darwin-{arm64,x64}.tar.xz
  * linux-{arm64,x64,armv7l}.tar.xz
  * win-{arm64,x64}.zip
  Unsupported hosts surface a clear error so the caller can flip
  `node.enabled = false` or point at a pre-installed toolchain.

- `fetch_shasums(client, version)` parses `SHASUMS256.txt` into a
  filename -> hex digest map. Tolerant of trailing / signature blocks.

- `download_distribution(...)` streams chunks into the target path,
  computes SHA-256 on the fly, and wipes the partial file if the
  digest does not match. Integrity check is mandatory — skills will
  execute untrusted code inside the resolved runtime.

Verbose tracing at `info` and `debug` follows the repo debug-logging
rule; operators can grep `[node_runtime::downloader]` to trace every
GET, chunk boundary (via total-bytes log), and hash decision.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(node_runtime): archive extraction + atomic install (#681)

Extract downloaded Node.js distributions and move them into the final
cache path without leaving the reader observing a half-populated
directory.

- `extract_distribution(archive, extract_root, is_zip)` — wraps the
  synchronous `tar`/`xz2`/`zip` crates in `spawn_blocking` and returns
  the single top-level folder produced by the archive (`node-vX.Y.Z-
  <os>-<arch>/`). `set_preserve_permissions(true)` + `set_overwrite(
  true)` on the tar side keeps the `node` binary's `+x` bit. The zip
  path restores Unix mode bits via `unix_mode()` so cross-OS builds
  still land correct permissions.
- `atomic_install(staged, final_dest)` — renames a staged directory
  into place via a single `rename(2)`, moving any pre-existing install
  to a `.old-<pid>` sibling first and cleaning it up on success. This
  gives concurrent readers a "before" or "after" view, never a
  partial one.
- Unsafe zip paths (`enclosed_name()` rejection) are logged and
  skipped rather than traversed — defence against malicious archives,
  even though the digest check in the downloader already rules out
  tampered official releases.

No new tests here: the logic leans on upstream tar/zip crates, and
meaningful end-to-end coverage requires a real archive on disk — that
comes in the integration-test commit later in this series.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(node_runtime): bootstrap mutex + cache + bin path helper (#681)

Stitch resolver, downloader, and extractor into a single idempotent
entry point callers use at startup (or lazily before the first
`node_exec`/`npm_exec` call).

`NodeBootstrap::resolve()` contract:
1. Return cached `ResolvedNode` if a previous call already succeeded.
2. Bail when `node.enabled = false`.
3. If `node.prefer_system`, probe the host PATH. Matching major
   version wins — return a `System`-sourced `ResolvedNode`.
4. Otherwise compute the install path
   (`{cache_dir}/node-v{version}-{os}-{arch}/`). If it already contains
   valid bins, reuse it. This makes the bootstrap ~free across
   restarts once a managed install lands.
5. Else fetch `SHASUMS256.txt`, locate the expected digest for our
   archive, stream the download, extract into a `.stage-<pid>` scratch
   dir, `atomic_install` the top-level folder into the final path, and
   remove scratch + archive to reclaim disk.

Concurrency is handled by a `tokio::sync::Mutex<Option<ResolvedNode>>`
— parallel callers queue behind the first one; the winner memoises,
the losers pick up the cached result. No race can produce two
concurrent downloads of the same archive.

Platform-specific bin layout lives in `managed_bin_dir` / `build_
resolved`:
- Unix: `<install>/bin/{node,npm}`
- Windows: `<install>/{node.exe,npm.cmd}`

This closes the resolver/downloader/cache layer promised in the #681
checkpoint. Tools (`node_exec`, `npm_exec`) and shell-PATH injection
layer on top in the next batch of commits.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(tools): node_exec runs JS via managed node runtime (#681)

Executes `inline_code` (via `node -e`) or a workspace-relative
`script_path` through the NodeBootstrap-resolved `node` binary. POSIX
single-quote quoting keeps user input inert; `env_clear` + allow-list
mirrors the shell tool so secrets never leak. 300s default timeout
(capped at 1800s), 1MB stdout/stderr caps. PATH is prepended with the
resolved bin dir so child processes see managed `node`/`npm`.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(tools): npm_exec runs npm via managed node runtime (#681)

Thin npm CLI wrapper paired with node_exec. Subcommands go through
`is_sane_subcommand` (alphanumerics + `._-:` only) and a deny-list
(publish/adduser/login/token/…) blocks registry-mutation and auth
flows. `cwd` is resolved under the workspace — absolute paths and
`..` components are rejected. 600s default timeout (1800s ceiling),
1MB stdout/stderr caps. PATH prepended with managed bin dir so
npm's own node/corepack lookups hit the managed toolchain.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(tools): shell prepends managed node bin to PATH when cached (#681)

Adds a non-blocking `NodeBootstrap::try_cached()` primitive that peeks the
memoised `ResolvedNode` without holding the async lock or triggering a
download. ShellTool gains an optional `node_bootstrap` field wired through
a new `with_node_bootstrap` constructor; when set, each shell invocation
consults `try_cached()` and, on a hit, prepends the managed bin dir to
the child PATH using the platform separator. Unrelated shell commands
stay byte-identical — no download is ever forced from the shell path.

Consequence: once `node_exec`/`npm_exec` have resolved the toolchain
once, skills that shell out to `node`/`npm`/`npx`/`corepack` transparently
pick up the managed install without any per-command coordination.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(tools): register node_exec + npm_exec behind node.enabled (#681)

Wires the skills-oriented Node.js toolchain into the tool registry:

* Constructs one session-scoped `NodeBootstrap` in `all_tools_with_runtime`
  when `root_config.node.enabled` is true — all three consumers (ShellTool,
  NodeExecTool, NpmExecTool) share the same `Arc<NodeBootstrap>` so the
  download/extract/install pipeline runs at most once per session and the
  memoised `ResolvedNode` is reused across every shelling-out call.
* Swaps ShellTool to `with_node_bootstrap(...)` when the bootstrap exists
  so shell PATH injection fires automatically once any node/npm tool has
  resolved the runtime.
* Registers `node_exec` and `npm_exec` only when the flag is on — flipping
  `node.enabled = false` cleanly removes both tools and falls back to the
  legacy ShellTool construction.
* Adds two regression tests (`all_tools_registers_node_exec_when_node_enabled`
  and `all_tools_excludes_node_exec_when_node_disabled`) so future refactors
  can't silently drop the wiring.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(agents): grant node_exec + npm_exec to code_executor + tool_maker (#681)

code_executor is the sandboxed developer sub-agent — it writes, runs, and
debugs code — and tool_maker is the narrow self-healing agent that polyfills
missing commands. Both now see the managed Node.js tools so skills and
polyfills can call into the resolved runtime directly rather than relying on
whatever `node`/`npm` happens to be on the host PATH.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style(core): apply cargo fmt auto-fixes (#681)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* chore(cargo): sync Cargo.lock to OpenHuman v0.52.26 after rebase (#681)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(node_runtime): strip leading v/V defensively in resolve_from_system (#681)

CodeRabbit R1 flagged that build_resolved receives a raw version string from
SystemNode. detect_system_node already trims the prefix, but trim defensively
at the resolve_from_system boundary too so any future code path constructing
SystemNode with an un-normalised version won't emit "vvX.Y.Z".

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(node_runtime): propagate flush errors and clean up partial archives (#681)

CodeRabbit R2 flagged that download_distribution silently swallowed flush
errors via `.ok()` and left partial files on disk when any chunk/write/flush
step errored. Wrap the streaming loop in an async block returning Result<()>,
propagate flush errors, and on any failure delete the partial archive so a
retry starts clean and callers never see a half-written file.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(node_runtime): restore previous install on staged rename failure (#681)

CodeRabbit R3 flagged that atomic_install left the user with no Node runtime
on disk if the staged->final rename failed after a backup had been taken.
Wrap the rename in `if let Err`, restore the backup if present, log restore
failures separately (warning), and always return the original error so the
caller sees the true failure cause.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(node_runtime): enforce real 5s timeout on node --version probe (#681)

CodeRabbit R4 flagged that probe_node_version used Command::output() with no
real timeout — a broken shim or FUSE-backed binary could hang the bootstrap
forever. Add wait-timeout crate dep and rewrite the probe to spawn with
piped stdio, wait_timeout(5s), kill on timeout, and read stdout/stderr from
the piped handles after exit. Logs a warning when a probe times out so the
install can be diagnosed.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(tools): reject script_path escapes in node_exec (#681)

CodeRabbit R5 flagged that node_exec joined user-supplied script_path onto
the workspace without rejecting `..` segments or absolute paths, letting a
prompt-injected `../../../etc/passwd` read arbitrary files via node. Add a
resolve_script_path helper mirroring npm_exec::resolve_cwd — reject empty,
absolute, parent-dir, and Windows-prefix components. Extra positional args
stay opaque (shell-quoted, not path-checked) and get an explanatory comment
at the call site. Unit tests cover each rejection case plus the relative-
subdir happy path.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(skills): drop dead SKILL.md branch in legacy manifest loader (#681)

CodeRabbit N1 flagged dead code: load_from_legacy_manifest only runs when
load_skill_dir already determined SKILL.md is absent, so the fallback that
re-checked for SKILL.md and its helper read_skill_md_description could
never execute. Simplify to a direct description/location decision and
delete the dead helper.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(config): extract parse_env_bool helper with warn on unknown values (#681)

CodeRabbit N2 flagged two near-identical boolean env-override match blocks
for OPENHUMAN_NODE_ENABLED and OPENHUMAN_NODE_PREFER_SYSTEM. Extract a
module-level parse_env_bool helper that accepts 1/true/yes/on and
0/false/no/off (case-insensitive) and emits a tracing::warn when the value
is unrecognised so silent mis-spellings don't invisibly leave the config
unchanged.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(node_runtime): detect corrupted cache missing npm (#723)

`probe_managed_install` now verifies the npm launcher exists before
reusing an extracted install. A download interrupted after `node` was
extracted but before `npm` would otherwise be cached forever and
`npm_exec` could never self-heal — now the corrupted cache forces a
fresh download via the normal resolve path.

Addresses CodeRabbit review feedback on PR #723.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(node_runtime): skip non-executable PATH shims when probing node (#723)

`which_node` previously returned the first matching filename on `PATH`
regardless of its execute bit. A non-executable `node` placeholder
earlier in `PATH` (e.g. an unprivileged shim left by a failed install)
would mask a valid later install and force the managed runtime download.

Now checks `file && (mode & 0o111 != 0)` on Unix to mirror shell `which`
behaviour. Windows remains unchanged — `.exe` suffix already encodes
executability for the loader.

Addresses CodeRabbit review feedback on PR #723.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(skills): deterministic entry order in scan_root (#723)

`read_dir` order is unspecified by the OS. When two sibling skill
directories declare the same logical `frontmatter.name` (which can
differ from the folder name), cross-scope/same-scope deduplication
downstream would pick a non-deterministic winner across runs.

Sort entries by on-disk directory name for a stable, reproducible
order so collision resolution is deterministic.

Addresses CodeRabbit review feedback on PR #723.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(skills): surface YAML parse errors as skill warnings (#723)

`parse_skill_md` previously swallowed the `serde_yaml` error via `log::warn!`
and fell back to an empty `SkillFrontmatter`, then the catalog reported a
generic "could not parse — exposing directory as placeholder". Skill
authors had no way to see the real cause without scraping logs.

Return parse-level diagnostics as a third tuple element. `load_from_skill_md`
merges them into the skill's user-visible `warnings`, so the catalog now
surfaces the actual YAML error (e.g. "frontmatter parse error: mapping
values are not allowed here at line 3 column 12").

Addresses CodeRabbit review feedback on PR #723.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(skills): skip symlinks when walking skill resources (#723)

`walk_files` used `is_dir()` / `is_file()` which transparently follow
symlinks. Two failure modes:

1. **Unbounded recursion** — a skill resource symlink that points back
   at an ancestor (e.g. `resources/self -> resources/`) would cause
   infinite traversal, eventually blowing the stack.
2. **Silent out-of-tree leakage** — a symlink pointing at `/`, `/etc`,
   or another skill's directory would enumerate its contents into the
   current skill's resource listing.

Switch to `entry.file_type()` and skip symlinks before descending.
Directories and regular files behave as before.

Addresses CodeRabbit review feedback on PR #723.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(node_runtime): default managed cache to user-owned OS cache (#723)

Default `cache_root()` to `dirs::cache_dir()/openhuman/node-runtime/` so a
repo cannot ship a checked-in `./node-runtime/` and have the bootstrap
reuse it as a trusted managed install. Explicit `config.cache_dir` still
wins; workspace-local falls back only when `dirs::cache_dir()` is
unavailable, and we emit a warning on that fallback.

As a second line of defence, `probe_managed_install()` now canonicalises
both the install dir and the cache root and refuses any install that
escapes the cache tree.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(node_runtime): require npm when accepting system node (#723)

On distros that package `node` and `npm` separately (Debian/Ubuntu,
Alpine `nodejs-current`, some NixOS setups) the host `node` can be
present without `npm`. `npm_exec` then fails every call because the
resolved `SystemNode` has no usable npm launcher.

Before returning `Some(SystemNode)`, locate `npm` on `PATH` and probe
`npm --version` through the same `wait_timeout` path as the node probe.
Either missing gate falls back to the managed download flow.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(skills): surface user-scope skills via load_skills (#723)

Existing production callers (`agent::harness::session::builder`,
`channels::runtime::startup`) reach the skill catalog via
`load_skills(workspace_dir)`. Previously this shim passed `None` for
the home directory, so skills installed under `~/.openhuman/skills/`
and `~/.agents/skills/` were silently dropped even after the
multi-scope discovery landed in `discover_skills`. Delegate to
`discover_skills_inner` with `dirs::home_dir()` so user-scope skills
reach the runtime; project-scope still wins on name collision.

Tests stay hermetic via a `load_skills_ws` helper that preserves the
old workspace-only semantics. A new `load_skills_surfaces_user_scope`
test drives a tempdir-as-home through `discover_skills` and asserts
the user-scope skill is returned with `SkillScope::User`.

Addresses CodeRabbit review comment 3116332244.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(skills): skip symlinked skill dirs during scan (#723)

`scan_root` previously accepted any entry where `path.is_dir()`
returned true. `is_dir()` dereferences symlinks, so a link from
`<skills-root>/foo -> /some/external/tree` would load as a
legitimate skill even though `walk_files` already rejects
symlinks deeper in the resource walker. Attacker-authored
symlinks in a skills root would therefore have one remaining
escape hatch.

Switch to `entry.file_type()` (non-dereferencing) and reject
both symlinked and non-directory entries at the top level.
Treat a failed `file_type()` probe as "not safe to traverse"
and skip.

A new `symlinked_skill_dirs_are_skipped` test (Unix-only, since
symlinks are the platform guarantee being tested) creates an
external skill tempdir, links it into the workspace skills root,
and asserts `load_skills_ws` returns empty.

Addresses CodeRabbit review comment 3116332252.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(skills): reject symlinked resource roots (#723)

`inventory_resources` gated each resource sub-root (`scripts/`,
`references/`, `assets/`) on `root.is_dir()`. `is_dir()` follows
symlinks, so a `scripts -> /etc` link inside a skill directory
would pass the check and `walk_files` would inventory the
external tree. Deeper symlinks inside the walk were already
rejected by `walk_files`, but the root-level check was the
missing layer.

Use `std::fs::symlink_metadata` for a non-dereferencing probe
and reject roots whose own `file_type().is_symlink()` returns
true. Treat any `symlink_metadata` error as a non-existent root
and skip.

A new `symlinked_resource_roots_are_rejected` test (Unix-only)
links a skill's `assets/` sub-root to an external tempdir with a
file inside and asserts `inventory_resources` returns empty.

Addresses CodeRabbit review comment 3116332260.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-21 10:59:21 -07:00
a29056fa6f feat(webview): browser-like permission management for embedded apps (#713) (#721)
* chore(cef): bump submodule to include permission handler (#713)

Picks up permission handler from tauri-cef feat/713-webview-permissions:
  c17221ea8 feat(cef): add permissions helper module with unit tests
  c7213ceb4 feat(cef): allow desktop-capture + deny-by-default prompts

Enables mic / camera / screen-share / notifications / clipboard /
persistent-storage prompts in embedded webviews (Slack, Discord, Meet,
WhatsApp Web).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(cef): enable SharedArrayBuffer for embedded app huddles (#713)

Slack Huddles, Meet, and Discord voice rely on SharedArrayBuffer-backed
WebRTC audio worklets / Opus encoders. Chromium gates SharedArrayBuffer
behind cross-origin isolation (COOP/COEP) by default, and embedded apps
don't send those headers, so the feature silently disappears — huddle
and call buttons become unresponsive because init aborts before any
getUserMedia / permission-handler path is reached.

Passing --enable-features=SharedArrayBuffer to CEF's command line makes
the constructor available again in top-level secure contexts, matching
the default behaviour of desktop Chrome. Verified in DevTools console
on app.slack.com: typeof SharedArrayBuffer === "function" after the
flag, "undefined" before.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(macos): add NSCameraUsageDescription for embedded webview calls (#713)

macOS TCC rejects any camera access request from an app bundle that
doesn't declare a purpose string in Info.plist. Without this key the
OS silently denies getUserMedia({video:true}) before the user ever
sees a prompt, which breaks video calls in every embedded app (Google
Meet, Discord, Slack huddles).

Paired with NSMicrophoneUsageDescription so mic + camera are both
covered for the CEF permission handler landing in the companion
submodule bump.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(macos): grant camera entitlement for embedded video calls (#713)

The Hardened Runtime entitlement com.apple.security.device.camera is
required for the signed app bundle to receive the macOS TCC camera
prompt. Without it, getUserMedia({video:true}) inside embedded
webviews (Google Meet, Discord, Slack huddles) is refused at the OS
layer regardless of the CEF permission handler decision.

Mirrors the existing audio-input entitlement so mic + camera both
work end-to-end once the CEF handler permits the request.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* chore(deps): sync Cargo.lock with v0.52.26 release bump

Cargo.toml versions bumped to 0.52.26 in prior release commits but the
lockfiles still recorded 0.52.24. Regenerated via cargo check — no
dependency graph changes.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* chore(vendor): bump tauri-cef to include loopback/local-network perms (#713)

Bumps the tauri-cef submodule to e2471bb80 on feat/cef, which adds
CEF_PERMISSION_TYPE_LOOPBACK_NETWORK / LOCAL_NETWORK / LOCAL_NETWORK_ACCESS
to the auto-accepted prompt mask. Required so embedded WebRTC call flows
(Slack Huddles, Meet, Discord voice) don't stall during STUN/TURN local
candidate gathering.

Upstream PR: tinyhumansai/tauri-cef#6

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(permissions): clarify mic/camera Info.plist usage for huddles (#713)

Previous NSMicrophoneUsageDescription only mentioned voice dictation
and NSCameraUsageDescription mentioned video calls but not huddles
explicitly. Updates both strings to name the huddle/call flows in
embedded apps (Slack, Meet, Discord) that drive the macOS TCC prompt,
so the first-launch dialog is accurate about why the permission is
being requested.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(webview): route Slack huddle popups in-app (#722)

Slack Huddles use openManagedChildWindow, which calls
window.open("about:blank", …) and then programmatically navigates the
returned popup to the huddle UI. The previous deny-all policy on
on_new_window meant window.open returned null, and Slack's caller
aborts the huddle flow with a beacon/error when the handle is falsey.

Adds popup_should_stay_in_app() with a narrow per-provider allowlist:
- Slack: about:blank + app.slack.com / *.slack.com hosts
- All other providers / URLs: existing deny-and-hand-to-system-browser
  behavior is preserved

Popups matching the allowlist return NewWindowResponse::Allow so CEF's
default handling spawns an in-app child window with a real handle.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-21 18:52:00 +05:30
c7487324cc feat(channels): dynamic filler messages during long agent turns (#600) (#636)
* refactor(channels): add extract_message_id helper for varied response shapes

Backend send_channel_message responses use at least three shapes:
{"id":"..."}, {"data":{"id":"..."}}, and {"messageId":1456,"success":true}.
The last one returns the id as a JSON number, so the prior inline
as_str()-only extraction silently dropped it. Consolidate the extraction
into a single helper that handles str/i64/u64 candidates and routes both
streaming-edit and thinking-message send paths through it. Fixes the
silent id loss that left thinking bubbles undeletable (#600).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(channels): latch thinking edits off when first POST yields no id

When the initial thinking POST returned 200 but carried no message id
(either because the response shape was unexpected or the send itself
failed before C1), every subsequent thinking_dirty tick re-entered the
"send new message" branch. The user then saw one standalone italic
bubble per accumulated snippet instead of a single evolving one. Add a
thinking_edit_disabled latch that is set in both failure paths and
guard the edit_timer branch on it so we post at most one thinking
bubble per turn when the id is unrecoverable (#600).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* style(channels): label thinking bubble with explicit "Thinking:" header

A bare italicized snippet under a 💭 emoji reads ambiguously in chat —
it could be a user quote, a system note, or assistant output. Prefix
the italic body with an explicit "Thinking:" line so the ephemeral
bubble is unmistakably the LLM's reasoning stream and visually distinct
from both filler messages and the final reply (#600).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(channels): reply-first finalize with orphan draft recovery

Two problems in the old finalize path. (1) The thinking bubble was
deleted before the reply was sent, leaving the chat momentarily empty
between the two round-trips. (2) When the final edit failed, the half-
streamed draft was left in place and the user never received the
canonical response — a silent data-loss hole during edit-endpoint
flakiness. Wrap the three delivery paths in a 'send: labeled block so
they share a single cleanup tail, delete the orphan draft and send a
fresh atomic reply on edit failure, and move the thinking-bubble
deletion to after the reply is on screen so the chat never blinks
empty (#600).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(channels): ephemeral filler messages every 13s with dynamic snippets

Long agent turns (30–90 s) leave the chat static once the thinking
stream goes quiet and progressive edits stop, which reads as a frozen
bot. Add a third timer branch in the inbound loop that posts a short
"still working" message every FILLER_INTERVAL (13 s, tuned to stay
inside Telegram's ~1 msg/sec chat cap with headroom).

Each filler prefers a tail slice of the live thinking_accumulator
(last MAX_FILLER_CHARS = 200 Unicode scalars, trimmed at a word
boundary so it reads cleanly) so the user sees the agent's actual
reasoning instead of canned text. When the accumulator hasn't advanced
since the last filler we fall through to a rotating STATIC_FILLERS
pool ("💭 Still working on it…", etc.) so the chat still moves. All
filler ids are tracked in StreamingState.filler_message_ids and
deleted in finalize_channel_reply alongside the thinking bubble, so
the user ends each turn seeing only the canonical reply. A
filler_disabled latch stops hammering endpoints that reject filler
sends twice in a row.

Verified end-to-end on Telegram with both long (74 s, 5 fillers) and
short (32 s, 2 fillers) turns — all ephemeral messages cleaned up
cleanly after the final reply landed (#600).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-17 13:03:49 -07:00
da5fe9260b fix(local_ai): hard-override to disabled until explicit opt-in (#573) (#637)
* refactor(local_ai): default to opt-in on all devices (#573)

Local AI now defaults to disabled whenever the user has not explicitly
picked a tier, regardless of device RAM. The onboarding flow and
Settings panel remain the only ways to turn it on. Previously the
bootstrap only disabled local AI on <8 GB devices and auto-applied a
recommended preset on larger hosts; this flip completes the MVP goal
of cloud-first defaults with a single, opt-in local model.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* style(local_ai): apply cargo fmt to bootstrap tests (#573)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(onboarding): present cloud AI as default on sufficient-RAM path (#573)

Flips the LocalAIStep sufficient-RAM screen so the primary button is
"Continue with Cloud" and local AI appears as an explicit opt-in
("Use local AI instead"). This aligns onboarding with the new opt-in
bootstrap: every device now starts on cloud unless the user chooses
local AI. The low-RAM cloud-fallback screen is unchanged.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* test(onboarding): cover opt-in local AI semantics in LocalAIStep (#573)

Updates the sufficient-RAM path tests to match the cloud-primary UI:
the default "Continue with Cloud" click advances without triggering
local AI bootstrap, and the secondary "Use local AI instead" opt-in
still starts the recommended-preset bootstrap and propagates errors.
Low-RAM cloud-fallback tests are unchanged.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(local_ai): add opt_in_confirmed marker to local AI config (#573)

Bootstrap will hard-override `enabled=false` unless this marker is true,
ensuring existing installs with a stale `selected_tier` from the pre-MVP
default-on era fall back to cloud until the user explicitly re-opts in.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(local_ai): hard-override local AI to disabled until explicit opt-in (#573)

Every bootstrap path now returns `enabled=false` unless `opt_in_confirmed`
is true, regardless of device RAM or `selected_tier`. This closes the
regression where upgrading users with a persisted `selected_tier` bypassed
the onboarding opt-in and started local AI without consent.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* refactor(local_ai): set opt_in_confirmed on apply_preset and surface MVP tier only (#573)

`apply_preset` is the single source of truth for the opt-in marker: any
non-disabled tier flips it true, `disabled` clears it. The preset RPC now
returns `mvp_presets()` so the Settings UI exposes only the allowlisted
`ram_2_4gb` tier, matching the MVP scope already enforced on the
onboarding path.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* revert(local_ai): keep full preset catalog in presets RPC (#573)

Revert the `mvp_presets()` swap in `handle_local_ai_presets`. PR #588
already renders all 5 tier cards in Settings with non-MVP tiers shown
as "Coming soon" / non-selectable, and that roadmap visibility is the
intended UX. Returning only the MVP tier from the RPC hid the other 4
cards entirely and broke that signal.

The opt-in gate still holds: `apply_preset` remains the single writer
of `opt_in_confirmed`, the RPC guard continues to reject non-MVP
apply_preset calls, and the bootstrap hard-override still clamps
stale configs. This commit only rolls back the UI catalog surface.

Fixes failing `json_rpc_local_ai_device_profile_and_presets` integration
test which expects 5 presets.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-17 13:03:34 -07:00
5082f3e741 feat(overlay): activate main window on orb click (#605) (#611)
* feat(tauri): add activate_main_window command for overlay (#605)

Exposes the existing show_main_window helper as a Tauri command so the
overlay webview can bring the main window to front. The command is
whitelisted in allow-core-process.toml so the overlay window capability
can invoke it.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(overlay): activate main window on orb click (#605)

The overlay orb had no click behavior. Now clicking it in idle mode
invokes activate_main_window, bringing the main app window to the front
(mirrors the tray icon flow).

Since the overlay is an NSPanel NonactivatingPanel on macOS, React's
synthesized onClick does not fire. Instead we record the press position
on mousedown and emulate click on mouseup when the pointer stayed within
a 4px slop. Dragging is deferred to mousemove past the slop so startDragging
doesn't swallow the mouseup event.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(window): propagate show_main_window errors instead of swallowing them (#605)

`show_main_window` silently logged failures and returned `()`, so the
`activate_main_window` Tauri command could report success on a no-op. Thread
`Result<(), String>` through so JS `invoke().catch()` sees real failures, and
preserve the previous log-on-error behavior at the tray/Reopen call sites
where no caller consumes the result.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(overlay): stabilize orb click vs drag vs double-click (#605)

Two follow-ups to the deferred-drag pattern:

1. Drop stale pressRef when the primary button is no longer held during
   mousemove. Window-drag / focus changes can steal the mouseup, leaving
   the ref populated so the next idle hover would start a spurious drag.

2. Debounce the synthetic click by 250 ms so a follow-up dblclick can
   cancel it — the double-click-to-reset gesture was firing activate +
   reset together. Clear the timer on dblclick and on unmount.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-17 10:10:13 -07:00
6733720df9 fix(channels): delete thinking messages after final response (#600) (#612)
* feat(channels): add send_channel_delete to REST client (#600)

Add DELETE method to BackendOAuthClient for removing channel messages.
Used to clean up ephemeral thinking indicators after final response delivery.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(channels): show thinking ephemerally and delete on final response (#600)

Thinking deltas are accumulated and sent as a temporary "💭" message
on the channel. When the final agent response is ready the thinking
message is deleted via the new DELETE endpoint so the user only sees
the clean reply. This replaces the previous behaviour where thinking
messages persisted permanently in the Telegram chat.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style(channels): apply cargo fmt to bus.rs (#600)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-16 23:04:00 -07:00
8ab2c6b540 fix(overlay): restore status bubble visibility during voice dictation (#604) (#614)
Reverts to CSS-transition-based visibility so the bubble wrapper
stays mounted in the DOM. The prior conditional mount (`status === 'active' && bubble`)
raced with the async Tauri window resize — the bubble component mounted
before the overlay webview had grown from 50x50 to 224x208, and
`overflow: hidden` on the webview clipped the bubble above the visible
area.

With the wrapper always mounted and toggled via `max-w-0 opacity-0` ↔
`max-w-[184px] opacity-100`, the typewriter status text ("Listening…",
"Transcribing…") reappears reliably when the hotkey is held.

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-04-16 20:43:13 -07:00
923c920ad5 fix(tauri): hide main window on close instead of destroying it (#601) (#610)
* fix(tauri): hide main window on close instead of destroying it (#601)

On macOS, clicking the close button destroyed the main window. Since a
tray icon keeps the process alive, subsequent dock-icon clicks fired
RunEvent::Reopen but get_webview_window("main") returned None — the
window was gone. Now CloseRequested is intercepted: the close is
prevented and the window is hidden instead, so Reopen and tray clicks
can show it again.

Closes #601

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style(tauri): cargo fmt line wrap

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-16 10:18:46 -07:00
7f686003a0 feat(core): gate service lifecycle on user login/logout (#582) (#603)
* refactor(voice): wrap CancellationToken in Mutex for restart support

The VoiceServer singleton uses OnceCell so it can't be recreated.
CancellationToken is one-shot — once cancelled, stays cancelled.
Wrapping it in std::sync::Mutex + adding fresh_cancel() allows
stop() then run() to work within the same process (logout → re-login).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(screen_intelligence): wrap CancellationToken in Mutex for restart support

Same pattern as voice server — enables stop() then run() within the
same process for logout → re-login cycles.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(credentials): add start/stop helpers for login-gated services

Add start_login_gated_services() and stop_login_gated_services() to
credentials/ops.rs. Wire start into store_session() (after login) and
stop into clear_session() (on logout) so voice, autocomplete, screen
intelligence, and local AI are properly managed around auth lifecycle.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(core): defer service startup behind login gate in jsonrpc.rs

Replace the unconditional service startup block with a login check.
If active_user.toml exists, start services immediately via the new
start_login_gated_services() helper. Otherwise defer until the login
handler triggers it. Autocomplete shutdown hook remains unconditional.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(screen_intelligence): wait for Stopped state in stop() to prevent restart race

stop() now polls until the run-loop sets ServerState::Stopped (5s timeout).
Prevents fast logout→login from seeing stale Idle/Running state and
skipping the restart.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(dictation): add stop() to prevent listener accumulation across re-logins

Store the spawned task JoinHandle and abort it on stop(). Prevents
duplicate rdev hotkey listeners from stacking across logout→login cycles.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(credentials): call dictation_listener::stop() on logout

Wire the new dictation stop into stop_login_gated_services() so the
hotkey forwarder task is aborted when the user logs out.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-16 10:12:56 -07:00
d4f5b9a357 fix(overlay): fullscreen visibility, voice server reliability, and resize (#528) (#585)
* fix(overlay): shrink initial overlay window to match idle orb dimensions (#528)

The Tauri overlay window was 248×228 px while the idle orb renders at
50×50. The excess transparent area wasted compositing resources and
created an invisible click-absorbing region. Reduce to 60×60 to tightly
frame the idle orb with minimal padding.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(overlay): add native drag support with position persistence (#528)

- Mouse-down on the orb initiates Tauri startDragging() for native
  window drag
- Dragged position is saved to localStorage and survives mode changes
  (idle ↔ active) so the orb stays where the user placed it
- Double-click resets to the default bottom-right corner
- Cursor changes to grab/grabbing for affordance
- Skip default repositioning when a saved position exists

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(overlay): reclass NSWindow to NSPanel for fullscreen visibility (#528)

macOS fullscreen apps run in separate Spaces where standard NSWindow
cannot follow. Use object_setClass() to reclass the Tauri overlay
window from NSWindow to NSPanel at runtime, then configure it with
NonactivatingPanel style mask and Transient collection behavior —
matching the working Swift accessibility helper pattern.

Key configuration that makes this work:
- object_setClass(NSWindow → NSPanel) — in-place reclass, no reparenting
- NSWindowStyleMask::NonactivatingPanel — critical for panel behavior
- NSWindowCollectionBehavior::Transient (not Stationary) — follows Spaces
- Window level 25 (NSStatusWindowLevel) — floats above fullscreen apps
- setFloatingPanel(true), setHidesOnDeactivate(false)

Previous approaches that failed:
1. CGShieldingWindowLevel + CanJoinAllSpaces — hidden (NSWindow limitation)
2. Window level i32::MAX-17 + Stationary — hidden (Space membership issue)
3. CGS private API CGSSetWindowTags sticky bit — blocked on Sonoma
4. object_setClass WITHOUT NonactivatingPanel mask — hidden
5. Create new NSPanel + reparent webview — CRASH (Tao delegate panic)

Also removes unused objc2-core-graphics and objc2-foundation deps.

Ref: https://github.com/tauri-apps/tauri/issues/11488

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(sidecar): make dev signing non-fatal in stage script

codesign failures no longer call process.exit(), preventing
yarn tauri dev from hanging when the dev signing identity is
missing or the keychain rejects the request.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): prevent race condition and fix restart after stop

- Atomically transition Stopped → Idle at start of run() to prevent
  duplicate run() calls during slow globe listener compilation
- Wrap CancellationToken in Mutex so run() creates a fresh token on
  each start — a cancelled token cannot be reused after stop()
- Reset state to Stopped if hotkey listener fails to start

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): capture server errors from spawned run() task

Store errors from the background server.run() task via
set_last_error() so they surface in voice_server_status RPC
responses instead of being silently lost.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(overlay): enable programmatic resize and shrink idle dimensions

- Change overlay window from 60x60 to 50x50 to match idle orb size
- Remove minWidth/minHeight constraints that blocked dynamic resize
- Set resizable: true so setSize() calls work for bubble expansion

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(overlay): simplify window resize and bubble rendering

- Clear min/max constraints before resizing to avoid clamping
- Replace CSS transition-based bubble visibility with conditional
  mount for more reliable rendering when mode changes

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* chore: fix fmt and remove unused bubbles variable

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): enforce lock ordering to prevent race between run() and stop()

Acquire cancel lock before state lock in run() — same order as stop() —
so stop() cannot cancel a stale token between setting Idle and swapping.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(overlay): restore saved position on resize and format with prettier

Parse and apply saved drag coordinates instead of just using their
presence as a sentinel. Also reformats for prettier compliance.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(sidecar): fail-fast on dev signing failure in CI environments

Add CI detection so signing failures abort the build in CI but remain
non-fatal for local development.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* chore: fix cargo fmt on Tauri shell import

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-16 04:52:14 +05:30
f014058417 feat(local_ai): MVP model lockdown — lock selection to 2-4 GB tier (#573) (#588)
* feat(local_ai): add MVP tier ceiling and cap model recommendation (#573)

Introduce MVP_MAX_TIER constant (Ram2To4Gb), is_mvp_allowed() gate,
mvp_presets() filter, and cap recommend_tier() so auto-provisioning
never selects a model above the MVP ceiling regardless of device RAM.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(local_ai): enforce MVP model allowlists on resolved IDs (#573)

Add per-category allowlists (chat, vision, embedding) so that
effective_*_model_id() silently redirects any non-MVP model to the
default. Prevents config-file edits from bypassing the 2-4 GB tier
restriction.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(local_ai): reject non-MVP tiers in RPC and clamp at bootstrap (#573)

apply_preset handler now returns an error for tiers above the MVP
ceiling. Bootstrap clamps any existing out-of-range tier selection
down to the recommended (capped) preset on startup.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(ui): lock model tier selection and show full roadmap (#573)

Replace clickable tier buttons with static cards. Active tier shows
"Active" badge; locked tiers show "Coming soon" with reduced opacity.
Add MVP info banner. Fix download size to 1 decimal place.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(local_ai): resolve CI failures — fmt, unused props, dead code (#573)

Apply cargo fmt to single-element array constants. Remove unused
isApplyingPreset/onApplyPreset props and applyPreset function from
the settings panel since tier switching is disabled for MVP.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style: apply Prettier formatting to settings panels (#573)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-16 04:50:28 +05:30
b2c74458d3 fix(voice): enable GPU detection and Metal acceleration for whisper (#558) (#571)
* fix(device): expand GPU detection with Intel Mac and NVIDIA probes (#558)

Add Intel Mac detection (no Metal GPU for whisper), nvidia-smi probe
for Windows/Linux NVIDIA GPUs, and diagnostic tracing at each
decision point in detect_gpu().

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* build(cargo): enable whisper-rs Metal feature on macOS (#558)

Add target-specific dependency for macOS that enables the `metal`
feature on whisper-rs, compiling whisper.cpp with Metal GPU support.
Cargo merges features from both declarations so non-macOS builds
are unaffected.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(whisper): configure GPU params from device profile (#558)

Accept has_gpu and gpu_description in load_engine() and explicitly
set use_gpu and flash_attn on WhisperContextParameters instead of
relying on the compile-time default. Log the selected acceleration
backend at startup.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(local_ai): pass GPU info to whisper engine load paths (#558)

Thread DeviceProfile has_gpu and gpu_description through both the
bootstrap (startup) and speech (lazy) whisper engine load calls so
the engine can configure Metal or CUDA acceleration at runtime.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-14 13:06:08 -07:00
933c233704 fix(voice): add hallucination filter to chat voice path (#553) (#556)
* fix(voice): add hallucination filter to chat voice path and improve detector (#553)

The chat voice transcription pipeline (ops.rs voice_transcribe_bytes) had
no hallucination filtering, unlike the desktop dictation server which has
had it since inception. This caused Whisper to inject repetitive garbage
text ("it... it... it...", "Thank you. Thank you. Thank you.") into chat
voice input, especially on short/silent recordings.

Changes:
- Extract hallucination detection into shared voice/hallucination.rs module
- Add hallucination filter to voice_transcribe_bytes (chat voice path)
- Improve detector: strip punctuation before word comparison, add
  dominant-word ratio check (>40%), catch "it... it... it..." patterns
- Add 14 unit tests covering exact match, repetition, ratio, and
  legitimate speech cases

Closes #553

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(voice): introduce HallucinationMode enum with split pattern lists

Split monolithic HALLUCINATION_PATTERNS into ALWAYS_HALLUCINATION
(blank-audio, YouTube phrases — filtered in all modes) and
DICTATION_ONLY_PATTERNS (single-word noise like "yes", "okay" —
filtered only in desktop dictation). Add repeating n-gram detection
for looping phrases ("Thank you. Thank you. Thank you.") and raise
dominant-word ratio from >40%/3 to >60%/5 to prevent false positives
on emphatic speech like "no no no don't do that".

Addresses CodeRabbit review on PR #556.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): use Conversation mode for chat, Dictation mode for desktop

Wire HallucinationMode into both voice paths:
- ops.rs (chat voice): HallucinationMode::Conversation — conservative
  filtering allows short replies like "yes", "okay", "thank you"
- server.rs (desktop dictation): HallucinationMode::Dictation —
  aggressive filtering drops single-word noise artifacts
- Update server.rs hallucination_detection test for new signature

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): redact user transcript content from debug logs

Remove raw text interpolation (normalized, first, word, pattern) from
hallucination detection debug logs to prevent leaking sensitive speech
content. Retain non-PII metadata (repeat counts, ratios, n-gram length)
for diagnostics.

Addresses CodeRabbit review on PR #556.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-14 07:33:33 -07:00
08d9fd2d4d fix(voice): recover buffered hotkey events after select! race (#527) (#545)
* fix(voice): return receiver count from publish_transcription

publish_transcription now returns the number of active TRANSCRIPTION_BUS
subscribers that received the message. When no receivers are connected
(e.g. Socket.IO bridge not yet subscribed), the function logs a warning
instead of silently discarding the broadcast.

This makes it possible to diagnose "transcription produced but never
delivered" scenarios from logs alone.

Closes #527 (partial)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): recover buffered hotkey events after select! race

On warm CPAL init (second+ recording), audio_capture::start_recording()
completes fast enough that the pending_ready branch and the hotkey_rx
branch are both ready simultaneously inside tokio::select!. select!
picks one pseudo-randomly — when it picks pending_ready, the Released
event sits unprocessed in hotkey_rx. The recording is stored as "live"
with no deferred stop, then the next loop iteration processes the
buffered Released and stops the recording almost immediately, producing
a near-zero-length clip that the duration gate silently drops.

Fix: after pending_ready resolves, call hotkey_rx.try_recv() to check
for a buffered stop event that lost the race. If found, apply the
deferred stop mechanism (MIN_RECORDING_AFTER_SETUP = 1500ms) instead
of treating the recording as live.

Also adds pipeline_id (UUID prefix) to all process_recording_bg log
lines for end-to-end correlation, and labels each pipeline stage
(stop_recording, gate_duration, gate_silence, transcribe, deliver)
so dropped recordings are diagnosable from logs.

Closes #527

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-13 14:07:28 -07:00
b8ded44fbf fix(core): send SIGTERM before SIGKILL on sidecar shutdown (#460) (#495)
The Tauri shell's CoreProcessHandle::shutdown() was calling child.kill()
which sends SIGKILL on Unix, instantly terminating the core process
without giving it a chance to run graceful shutdown hooks. This left the
autocomplete Swift overlay helper (unified_helper_bin) orphaned, causing
persistent error notifications even after the app was closed.

Now sends SIGTERM first and waits up to 5s for the core to exit
gracefully (running shutdown hooks that stop the autocomplete engine and
quit the Swift helper), then falls back to SIGKILL if still alive.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-10 21:51:28 +05:30
8e8da17ad9 fix(voice): cross-platform microphone permission handling (#489) (#491)
* fix(voice): add cross-platform microphone permission handling (#489)

Voice dictation in release DMG silently fails because the macOS hardened
runtime enforces entitlements and the sidecar plist lacked the audio-input
entitlement. This adds the entitlement, NSMicrophoneUsageDescription for
the system permission prompt, and cross-platform microphone permission
detection (CPAL device probe) with clear error messages on macOS, Windows,
and Linux.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(permissions): use plist file for infoPlist and fix cross-platform warnings (#489)

- infoPlist expects a file path, not inline JSON — create Info.plist with
  NSMicrophoneUsageDescription and reference it as a string
- Move Microphone permission request out of macOS-only cfg block since
  request_microphone_access() is cross-platform (fixes unused import warning on Linux CI)
- Treat persistent Unknown mic permission as Denied per CodeRabbit review

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Cyrus Gray <144336577+graycyrus@users.noreply.github.com>
2026-04-10 20:17:05 +05:30
0cd0f7a670 feat(voice): sync overlay orb with chat voice button state (#487) (#490)
* feat(voice): sync overlay orb with chat voice button state (#487)

The overlay orb already reacts to hotkey-based dictation via Socket.IO
events, but the chat "Start Talking" button used local React state only.
Add a new RPC method `openhuman.overlay_stt_notify` that the chat button
calls at each voice state transition, which publishes to the existing
DICTATION_BUS / TRANSCRIPTION_BUS broadcast channels — so the overlay
reflects recording/transcribing/idle from both input paths with zero
changes to the Socket.IO bridge or overlay event handlers.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): address CI formatting and CodeRabbit review feedback

- Run cargo fmt and prettier to fix formatting violations
- Use typed enum OverlaySttState instead of raw String for state param
  (serde rejects invalid states at deserialization, eliminating the
  unknown state branch)
- Require `text` field for transcription_done state (return error if
  missing instead of silently ignoring)
- Replace raw transcript logging with metadata-only (has_text, text_len)
  to avoid logging sensitive user speech content
- Use "Voice input active" aria-label (covers recording + linger phases)
- Convert notifyOverlaySttState to arrow function with async/await per
  repo TS conventions

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-10 18:25:08 +05:30
0b23ae6b96 fix(voice): resolve dictation pipeline in embedded Tauri app (#466)
* fix(voice): guard dictation_listener when voice_server is active

macOS only supports one rdev::listen() global event tap per process.
When voice_server.auto_start is true, skip starting the separate
dictation_listener — the voice server owns the single listener and
forwards hotkey events itself.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(voice): add TRANSCRIPTION_BUS broadcast channel

Make publish_dictation_event public so the voice server can forward
hotkey events. Add a new TRANSCRIPTION_BUS broadcast channel with
subscribe_transcription_results() and publish_transcription() for
delivering completed transcriptions to frontend clients via Socket.IO.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): forward hotkey events and route transcription delivery

In the voice server's hotkey handler, forward events to the dictation
bus so Socket.IO clients receive dictation:toggle even without the
separate dictation_listener running.

In process_recording_bg, detect when the OpenHuman app is focused and
deliver transcription via Socket.IO instead of OS-level Cmd+V paste,
preventing text from disappearing into the unfocused WebView.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(voice): bridge transcription results to Socket.IO

Subscribe to TRANSCRIPTION_BUS and emit dictation:transcription events
to all connected Socket.IO clients. This completes the Rust-side
pipeline for delivering transcribed text to the frontend.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(socket): queue listeners registered before socket connects

Add a pendingListeners queue to socketService so that on()/once()
calls made before the socket is established are replayed once the
connection opens, preventing silently dropped event listeners.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): use dedicated unauthenticated socket for dictation events

Replace the auth-gated socketService dependency with a direct Socket.IO
connection to the core process (127.0.0.1:7788). This bypasses the
SocketProvider auth requirement and ensures dictation:toggle and
dictation:transcription events are received regardless of login state.
Dispatches the existing dictation://insert-text DOM event to bridge
transcribed text into the Conversations chat input.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): fallback to default audio config when preferred config fails

macOS may advertise a 16kHz F32 config as supported but reject it at
stream creation time (known cpal quirk). Add a fallback path that
retries with the device's default_input_config(), handling F32, I16,
and U16 sample formats with proper resampling.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): add 3s timeout on Ollama LLM cleanup

Wrap the Ollama inference call in a 3-second tokio::time::timeout so
dictation feels responsive. If cleanup doesn't complete in time, fall
back to raw Whisper text immediately instead of blocking for 2+ minutes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-09 14:54:40 -07:00
f0118ab674 fix(autocomplete): graceful shutdown on app exit (#460)
* fix(autocomplete): graceful shutdown on app exit

Stop the autocomplete engine and quit the Swift overlay helper process
when the core receives a shutdown signal, preventing orphan processes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(core): extract shutdown logic into generic facility

Move domain-specific autocomplete cleanup out of the jsonrpc adapter
into a new `core::shutdown` module with a hook registry. Adds SIGTERM
handling alongside SIGINT via `tokio::select!` on Unix platforms.

Addresses CodeRabbit review feedback on PR #460:
- jsonrpc.rs stays transport-only (no domain logic)
- Process responds to both SIGINT and SIGTERM gracefully

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(autocomplete): suppress duplicate error notifications and auto-stop after repeated failures

The autocomplete polling loop was showing an error notification badge on
every single refresh cycle when a dependency was unavailable (e.g. Ollama
not running, macOS Automation permission denied). This caused floods of
identical macOS notifications.

Changes:
- Track last notified error message; skip badge if identical to previous
- Count consecutive errors; auto-stop engine after 5 failures with a
  clear log message, preventing endless notification spam
- Reset counters on successful refresh or engine restart

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-09 11:59:33 -07:00
4639913ddf fix(release): sync root Cargo version in release pipeline (#449) (#461)
* fix(release): sync root Cargo version in bump flow (#449)

Add root Cargo.toml to release version bumping and introduce a
version-sync verifier for all four release version sources.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* ci(release): enforce version sync before tagging (#449)

Run release version consistency verification and include root
Cargo.toml in the release commit staging list.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* chore(release): add local dmg preflight version dry-run (#449)

Add a local release dry-run script that builds frontend + release
sidecar, bundles app/dmg, and validates packaged core.version.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-09 10:44:46 -07:00
1ca4ea044a fix(chat): deduplicate assistant messages by subscribing to canonical events only (#432) (#439)
* fix(chat): deduplicate assistant messages by subscribing to canonical events only (#432)

The Rust core emits socket events with both snake_case and colon:case
aliases via emit_with_aliases(). The frontend was subscribing to both,
causing every chat event to fire twice and producing duplicate assistant
messages.

- Subscribe only to canonical snake_case events (tool_call, chat_segment,
  chat_done, chat_error) instead of both naming conventions
- Add safety-net dedup layer in Conversations.tsx using a seen-events map
  with TTL to guard against any remaining edge cases
- Add unit tests verifying only canonical events are processed

Closes #432

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style: apply prettier formatting to chatService test

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-09 02:57:25 +05:30
0f578382d1 fix(autocomplete): auto-start engine when config enabled (#412) (#442)
* fix(autocomplete): add start_if_enabled for engine auto-start at boot (#412)

The autocomplete engine was never started automatically when
config had autocomplete.enabled = true. Add start_if_enabled()
that checks config and starts the global engine singleton during
core process startup.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(autocomplete): wire engine startup into core server init (#412)

Call start_if_enabled() after config load in the JSON-RPC server
so the autocomplete engine runs automatically when the core process
boots with autocomplete enabled. Remove stale E2E test assertions
that conflicted with the new startup path.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(autocomplete): auto-start engine when enabled via set_style RPC (#412)

When the frontend enables autocomplete through set_style(enabled=true),
automatically start the engine so suggestions begin immediately without
requiring a separate start call or app restart.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-09 02:56:58 +05:30
2e7d1946b0 fix(ui): state-aware bootstrap buttons with user feedback (#353) (#426)
* fix(ui): state-aware bootstrap buttons with user feedback (#353)

When local AI state is "ready", replace the Bootstrap button with a
"Running" badge so clicking it no longer appears to do nothing.
Show "Retry" label when state is degraded.  Add transient success/error
messages after manual bootstrap/re-bootstrap actions so the user always
gets clear feedback.

Closes #353

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* test(ui): add unit tests for state-aware bootstrap buttons (#353)

Cover the four key rendering states of the Home local-AI card:
- "Running" badge when state is ready (Bootstrap button hidden)
- "Retry" label when state is degraded
- "Bootstrap" label when state is idle
- Transient "Re-bootstrap complete" message after successful re-bootstrap

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-08 20:03:48 +05:30
91996a1dd0 fix(voice): reduce dictation hallucinations and improve Fn/focus reliability (#385) (#409)
* fix(voice): add per-segment confidence validation in whisper engine (#385)

Reject whisper segments with avg token log-probability below -0.7 or
entropy above 2.4. Return TranscriptionResult with confidence metadata
instead of plain String. Update callers in speech.rs and streaming.rs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): upgrade default STT model from tiny to base (#385)

Base model produces significantly fewer hallucinations than tiny,
especially in noisy/quiet conditions. User can still override via config.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): add real-time silence gating in audio capture (#385)

Gate sustained silence (>500ms) from being sent to whisper to prevent
hallucinations. Maintain 100ms look-ahead ring buffer so speech onset
after pauses is not clipped. Thresholds adapt to source sample rate.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): fix Fn key timing race condition in hotkey event loop (#385)

start_recording() blocks 1-7s on cpal device init but macOS fires Fn
Release almost immediately, causing skipped cycles. Move recording
start to spawn_blocking so the event loop stays responsive. Buffer
Release events during setup and ensure minimum 1.5s recording duration
when release arrives before recording handle is ready.

Also includes: capture focused app on hotkey press, pass through
pipeline for focus validation before paste.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice): validate and restore focus before paste, attempt regardless (#385)

Add expected_app parameter to insert_text(). Before Cmd+V, validate
focus via accessibility API and restore via AppleScript if shifted.
Don't abort paste on focus validation failure — attempt insertion
regardless so text is never silently lost.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(voice-ui): align voice server RPC response shape in settings panel (#385)

* style(voice): apply rustfmt formatting in text_input

* fix(voice): address CodeRabbit regressions in server, streaming, and settings polling

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 09:11:57 -07:00