295 Commits
Author SHA1 Message Date
5b59b03959 feat: store role-template id on users.role and harden mobile composer (#1220)
Collapse the dual user_role_id / role model so users.role and invites.role
hold the template public id, block deleting roles still in use, and keep
the chat composer visible under mobile browser visualViewport.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 19:43:30 +08:00
51c937fbd4 style(dashboard): apply Prettier to files that drifted from the formatter (#1222)
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 18:36:14 +08:00
b920ed94dd feat(dashboard): let each account customize the sidebar (#1218)
Store group order, item placement, and hidden entries on the user so navigation can be rearranged without showing items the account cannot access.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 18:30:00 +08:00
Dang Zitou ec70e5f429 fix(dashboard): define missing --fn-bg-container theme variable (#1216)
Dark-theme surfaces that use var(--fn-bg-container, #fff) — most
visibly the knowledge-base Markdown preview body, toolbar and outline
panel — resolved to a white background while text stayed light, leaving
preview content invisible. Define the variable as #ffffff (light) and
#141414 (dark), and point the Admin/Users badge tints that borrowed the
name for a translucent fill at --fn-bg-tertiary so their look is
unchanged.

Fixes #1215
2026-09-27 17:50:26 +08:00
9a13f53feb fix(chat): dedupe duplicate team live-across-tool-gap test (#1187)
origin/develop already carried two identical copies of the same case;
keep a single assertion.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 00:32:37 +08:00
9be32b03f9 feat(connectors): 企查查同时支持一键 OAuth 与 API Key (#1186)
公网 HTTP 等无法完成 OAuth 回调的环境隐藏一键授权,改为打开授权页取 Key 后粘贴;两种方式二选一,切换时替换另一模式凭证。

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 00:22:44 +08:00
95a669b825 fix(dashboard): add lock icons to account change-password fields (#1184)
Match the admin reset-password inputs by prefixing current/new password with Lock and confirm with LockOpen.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 23:33:41 +08:00
8082add666 fix(chat): show generic “calling tools” status instead of tool names (#1182)
Avoid leaking internal names like execute in the live process hint; always use the shared “正在调用工具” copy while a tool is running.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 23:33:29 +08:00
ac8c233180 feat(users): add role templates, invite snapshots, and profile avatars (#1180)
* feat(users): add role templates, invite snapshots, and profile avatars

Roles fill defaults for create, edit, and invite without rewriting existing users. Account type stays independent of the selected role.

Co-authored-by: Cursor <cursoragent@cursor.com>

* style: format role and invite repositories for ruff

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: narrow invite role name before lookup

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:43:09 +08:00
0c57dbc80c test(chat): cover member live bit across tool gaps after host unlock (#1181)
Lock in that a team member stays in liveSpeakers through tool rounds even after the host done frees the composer.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:42:10 +08:00
0322d09ddd fix(chat): default-collapse thinking in team rooms only (#1179)
* fix(chat): default-collapse thinking in team rooms only

Keep solo chat expanded by default, and store team/solo preferences under separate localStorage keys so toggling one does not affect the other.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(chat): keep team member replies in one bubble and clear stale live state

Continue member answer text across completed tools in team rooms, and stop
snapshots/wrap-up from leaving finished speakers marked live in the footer.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:31:44 +08:00
jubaoliangandCursor 09d72e603b feat(dashboard): add remember-me checkbox on the login page
Default stays persistent (localStorage). Unchecking keeps the JWT in
sessionStorage for this tab only; SSO popups post the token back so the
opener can store it correctly.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:22:16 +08:00
jubaoliangandCursor 4c3bf76479 fix: team chat/IM UX, ACP sandbox, channel thinking, and related polish
Improve team streaming visibility (live speakers, generating footer, IM
dispatch/wrap-up), relax ACP tool enable under sandbox while locking
runners, strip channel think tags per show_thinking, and clarify provider
CLI usage in the assistant skill. Includes self-update/UpdateConfig WIP
from the same working tree.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 23:59:46 +08:00
HUANG Chengandjubaoliang bd73bb60aa fix(plugins): offload oversized octop_ui payloads to ToolMessage.artifact (#1032) (#1116)
Plugin tools returning large octop_ui payloads (e.g. a bangumi season
with 1200+ episodes, ~228KB JSON) blew up the LLM context because the
same tool-result string served both the model and the UI.

Add OctopUiOffloadMiddleware at the innermost agent middleware layer:
when a ToolMessage content is a >=4000-char string carrying a non-empty
octop_ui renderer and data (and no file:// media refs), the payload is
moved in-place to ToolMessage.artifact and the model-visible content is
replaced by a compact result that keeps title/summary. Tool id,
tool_call_id, name and status are preserved.

Frontend restores rendering from artifact: ToolCallData.artifact,
closeToolCall extraction, history replay path, and resolvePluginUiData
prefers explicit data over data_ref. serialize.py surfaces artifact on
tool_result blocks; history recorder backfills artifact as fallback.

Spec: docs/octop-ui-payload-offload.md

Co-authored-by: jubaoliang <jubaoliang@gmail.com>
2026-09-25 23:06:19 +08:00
jubaoliangandCursor 1d2b2558fb feat(chat): team artifacts, fan-in tool trail, and host wrap-up context
Persist member file refs and tool history on team walls, open docks by producer agent, and inject truncated member answers into host follow-up so wrap-up can follow their advice.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 14:48:45 +08:00
2209cdc90f chore(deps): switch runtime packages to octop-* 1.0.0 (#1136)
Replace orcakit-harness-agent / harness-* with octop-harness, octop-gateway, octop-memory, and octop-browser, and align docs, UI copy, and generated paths.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 06:44:24 +08:00
jubaoliangandCursor 5e34c8a001 fix: connectors empty layout and restore prior control-plane behaviors
Apply the remaining working-tree changes: connectors empty-state layout,
plus the knowledge, HITL, captcha, workspace, user-cache, and SSRF
adjustments with matching tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 22:40:47 +08:00
689216e4b6 feat: admin user batch policies, token UX, default FS root, and media push hardening (#1114)
* feat: admin user batch policies, token UX, default FS root, and media push hardening

Add admin user batch enable/disable/delete and resource policies (token quota,
max experts), improve token inputs with K/M presets, default unrestricted
local backends to host filesystem root, and tighten gateway tool-media push
with clearer path-outside-root stream errors.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(workspace): treat Windows drive roots as host-root sentinels

Default FS-root backends use C:/ on Windows; treating that as a scoped
jail put workspaces under the drive root and broke bootstrap/invite tests.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 17:22:49 +08:00
jubaoliangandCursor 6ede49b2f5 fix(experts): drop redundant add buttons from the edit drawer
Managing skills and subagents already covers install and copy, so the extra add actions only duplicated that entry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 23:02:04 +08:00
4ea7963b2d fix(acp): 沙箱环境下禁用向外委托 Runner (#1061)
* fix(acp): block outbound runners under directory sandbox

Host-spawned acp_runner would bypass a scoped root_dir jail; gate the
per-agent tool in API/runtime and gray the ACP UI while inbound octop acp stays available.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(acp): allow workspace-scoped local roots for outbound runners

Windows rewrites host `/` to the agent workspace; treating that as a
directory sandbox made ACP enable/round-trip fail on win32 CI.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 22:48:13 +08:00
jubaoliangandCursor 963cb14007 fix(chat): show the real team name on the welcome heading
Team rooms used a hardcoded "#管理团队" / "#Manage team" string instead of
the agent name already passed into WelcomeScreen.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 17:50:34 +08:00
jubaoliangandCursor df7f7d187c feat(connectors): 企查查改为 API Key,并用 internal 模式加载工具
公网 HTTP 无法完成 OAuth 回调;对话若按 gateway 注入会得到空工具表。改为粘贴 Key,harness 走内部 HTTP 聚合五个 MCP。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 17:50:19 +08:00
6f7815bb71 feat(connectors): 新增企查查 OAuth 连接器,一次授权接入五类 MCP 服务 (#1033)
* QMCP-2014 feat(connectors): add QCC MCP OAuth connector

* QMCP-2014 feat(connectors): share QCC OAuth across five MCP servers

---------

Co-authored-by: DuHu <duhu@greatld.com>
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 15:45:02 +08:00
locip123 7047a4ebac feat(connectors): add OpenAlex connector (#1009)
* feat(connectors): add OpenAlex connector

* feat(connectors): add OpenAlex connector
2026-09-23 15:43:59 +08:00
Fish 5e597312dd fix(chat): avoid carrying prefill across expert switches (#920) 2026-09-23 15:40:50 +08:00
jubaoliangandCursor f6a20b713f fix: NSIS pep440 VI version, experts empty guide, CodeQL URL hostname checks
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 01:09:27 +00:00
jubaoliangandCursor c7f828676e feat(dashboard): unify empty guides with Tasks-like plain style
Align skill packages, knowledge bases, browser, and desktop idle tips
with borderless layout and shared mascot sizing; move desktop Check/
Connect into the guide; and use Route for chat model Auto to avoid the
skills Sparkles collision.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 22:31:51 +08:00
liukewia 35abf52626 fix(dashboard): honor PWA safe-area insets and widen mobile chat bubbles (#666)
* refactor: update layout styles to support safe area insets

Modified padding and margin properties across various components to utilize environment variables for safe area insets, ensuring better compatibility with devices that have notches or rounded corners. This includes updates to index.html, offline.html, and several layout components to enhance the overall responsiveness and user experience.

* fix: update keyboard offset handling and layout styles

Refactored keyboard offset calculations in the useKeyboardOffset hook to improve handling of soft keyboard visibility. Adjusted layout styles across various components to utilize the largest viewport height (lvh) for better compatibility with devices featuring home indicators. This includes updates to padding, height properties, and background colors to enhance the user experience in chat and main layout components.

* refactor: update chat layout styles for improved responsiveness

Adjusted padding, width, and margin properties across various chat components to utilize environment variables for better responsiveness. This includes updates to the chat input, message list, and welcome components, ensuring consistent spacing and alignment across different screen sizes. Enhanced mobile styles to accommodate varying avatar sizes and maintain layout integrity.

* refactor: enhance chat component styles for consistency and responsiveness

Updated layout styles in chat components to ensure consistent spacing and alignment. Adjusted margin and gap properties to utilize environment variables, improving responsiveness across different screen sizes. Enhanced mobile styles for better alignment of avatars and message bubbles, ensuring a cohesive user experience.

* feat: implement theme management in index.html and update logo assets

Added a script to manage dashboard theme based on user preferences and system settings, ensuring the correct theme is applied before the first paint. Updated CSS to utilize data attributes for theme styling. Replaced existing logo assets with new vertical and horizontal versions for both light and dark themes, and updated references throughout the application. Removed outdated logo files to streamline asset management.

* refactor: update layout styles to improve safe area handling

Enhanced layout components by adjusting padding and margin properties to better utilize environment variables for safe area insets. This includes updates to the PageShell, Sidebar, MainLayout, Login, and Setup components, ensuring improved responsiveness and compatibility with devices featuring notches or rounded corners.
2026-09-22 22:02:18 +08:00
liukewia a6798d75ec Fix OpenCode session header matching and bump harness-agent to 1.0.14 (#992)
* feat(provider): add name parameter to provider model interfaces and update session header logic

- Introduced a `name` parameter in `FetchProviderModelsParams` and related interfaces to enhance provider identification.
- Updated `fetchProviderModels` and modal components to utilize the new `name` parameter.
- Enhanced session header management in `opencode_session` to support bundled presets and custom providers.
- Adjusted tests to validate the new functionality and ensure proper session header injection for OpenCode presets.

* feat(deps): add mise.toml for local toolchain configuration and update orcakit-harness-agent to version 1.0.14

- Introduced a new mise.toml file to specify local toolchain versions for Python, Node, NPM, and UV.
- Updated the orcakit-harness-agent dependency version from 1.0.13 to 1.0.14 in pyproject.toml and uv.lock to ensure compatibility with the latest features and fixes.

* refactor(probe): streamline session header construction in probe.py

- Consolidated the session header construction for both `build_probe_chat_model` and `fetch_openai_compatible_models` functions into single-line calls for improved readability and maintainability.
2026-09-22 20:14:24 +08:00
sxh313 2aa7f0e9bb fix(dashboard): show an unset state instead of empty quotes in the MBTI header
An agent with no MBTI persona rendered "已选中「」", which reads as a
selection whose name was lost. Render a dedicated unset line, and fall
back to the bare code when the catalogue does not know it.
2026-09-22 17:26:06 +08:00
jubaoliangandCursor 69f31656c3 feat(chat): add per-thread HITL allow policy
Keep tool-approval bypass on the conversation (allow this tool / allow all)
without changing global security settings. Also let expert create carry
welcome quick prompts, and replace the login forgot-password tip with a
platform-specific CLI dialog.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 17:14:28 +08:00
薄生 339c78deff Feature/support discord (#972)
* feat(discord): add channel setup and default all-channel access

* build(deps): require harness-gateway 0.9.9 for Discord
2026-09-22 16:42:51 +08:00
jubaoliangandCursor f5a6404a83 feat(chat): add + menu to open dock panels while right rail is hidden
When the chat dock is open the floating workspace/browser/terminal
buttons disappear; expose the same actions from a title-bar + menu and
keep the popup mask from closing while that menu is open.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 16:41:03 +08:00
Pandaandleoxyang c24a1a1cb0 feat(media): add multi-provider configuration and routing UI (#951)
* feat(media): add multi-provider generation settings

* chore(deps): sync harness-agent lock to 1.0.13

---------

Co-authored-by: leoxyang <leoxyang@tencent.com>
2026-09-22 16:16:29 +08:00
jubaoliangandCursor c81bd7295f fix(chat): make composer mode and model triggers icon-only
The 32px buttons were clipping selected labels. Match the other toolbar icons, keep the selection in the tooltip, and show provider logos in the model picker.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 11:26:24 +08:00
jubaoliangandCursor ae7dfc8b0f feat(chat): add Ask / Plan / Craft conversation modes (#934)
* feat(chat): add Ask / Plan / Craft conversation modes

Keep mode sticky per thread, enforce Ask/Plan in harness-agent, and let Plan write a workspace plan before Craft executes it.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Update pyproject.toml
2026-09-21 22:18:28 +08:00
jubaoliangandCursor f951aadf3b feat(dashboard): put chat workspace in the dock and point help to octop.cloud
Open workspace in the same right/bottom/popup tabs as browser and file
changes, and send Help & Feedback to https://octop.cloud.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-21 21:15:31 +08:00
薄生 e512f05bf5 Feature/memory slim tool (#865)
* harness agent upgrade for cache polish

* format

* feat(memory): add coordinated memory slim commands and progress UI

* build(deps): require harness-memory 0.9.11

* fix(deps): restore harness-memory 0.9.11 floor after merge

* fix(agents): await async shutdown to drain SQLite workers

Use HarnessAgentManager.aclose() during shutdown so SQLite cleanup
finishes before the event loop closes, preventing background threads
from raising "Event loop is closed".

Add a real SQLite regression test and preserve the existing ordering
that waits for memory slimming to finish before closing agents.

Validation: make all — 3582 passed, 17 skipped.
2026-09-21 15:44:19 +08:00
HUANG Cheng 297326734f feat(auth): GeeTest v4 login captcha provider (#870) (#900)
Adds 极验行为验 v4 to the login captcha layer, following the provider
plug-in seam (one dataclass + register call backend-side, one widget
adapter frontend-side; the settings UI is data-driven so only locale
keys were needed):

- providers.py: _GeetestV4Provider — login token carries the frontend
  getValidate() result as JSON (lot_number / captcha_output /
  pass_token / gen_time); siteverify posts form-urlencoded to
  gcaptcha4.geetest.com/validate?captcha_id=<id> with
  sign_token = HMAC-SHA256(captcha_key, lot_number); only
  result == "success" passes (fail / status:error both reject).
  Aliases: geetest, geetest4, gt4. Fail-closed on transport errors,
  consistent with the other providers.
- CaptchaField: geetest-v4 popup via gt4.js bind mode — initGeetest4,
  showCaptcha on ready, getValidate() serialized as the captcha_token;
  error/close resolve undefined so login re-prompts.
- Settings UI: captcha_id / captcha_key fields via locale keys.

Tests: provider unit tests (URL + form fields + HMAC against an
independent computation, malformed/missing-field rejection, interpret
matrix), ensure_captcha flow through a local siteverify double (form
body + signature asserted; fail result rejects), popup adapter tests
(validate payload JSON, error path), builtin-order + integration list
assertions updated. Locale parity green.
2026-09-21 14:26:14 +08:00
jubaoliangandCursor bf1f95e7b8 fix(dashboard): collapse login forgot-password CLI tip
Keep the login form quiet: show a Forgot password? control first, then
expand admin-first help with the host CLI command as secondary detail.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-21 14:14:31 +08:00
jubaoliangandCursor f843e5f704 feat(experts): compose prompts and skills when creating experts
Allow editing AGENTS.md, picking marketplace or other-expert skills, and
adding subagents in the create/edit drawers. Default is a blank AGENTS.md
template; marketplace or copy failures warn instead of aborting create.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-21 12:59:17 +08:00
jubaoliang 9fac342e47 fix(auth): tell locked-out users how to reset a password (#869)
Merged from #880.
2026-09-21 03:03:58 +00:00
jubaoliang fcb49d31fb fix(pwa): stop iOS status bar from frosting page content (#874)
Merged from #878.
2026-09-21 03:03:41 +00:00
jubaoliang 32dce2d2b8 fix(dashboard): refresh agent context after saving runtime config
Merged from #882.
2026-09-21 03:03:08 +00:00
jubaoliang 06f632ec59 fix(hitl): stop dashboard ask cards from reappearing (#782)
Merged from #877.
2026-09-21 03:02:52 +00:00
yftx293 546dd5de39 fix(providers): report Codex OAuth start failures (#858) 2026-09-21 10:54:14 +08:00
jubaoliang 12e5b706cc feat(teams): add expert team hosts without changing 1:1 chat (#868) 2026-09-21 10:24:09 +08:00
jubaoliangandCursor e446463bb9 fix(chat): omit skills group from shortcut picker
Skills already have a dedicated picker; keep the quick-command popover to slash commands only.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-21 07:40:51 +08:00
jubaoliangandCursor ae62ec3088 fix: LAN MCP HTTP、TLS 公网 IP 预检与 Models 侧栏抽屉
允许本机/局域网 MCP 使用 HTTP 并返回结构化错误码;TLS 预检优先走云元数据与国内可达 IP 探测;send_file 工具错误不再误判为模型故障;模型配置弹窗改为右侧抽屉。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-20 20:00:39 +08:00
HUANG Cheng 9e273a78c5 fix(chat): per-expert composer selection for knowledge bases + connectors (#860)
The KB selection was one global useState plus a touched flag reset on
expert switch: Expert B's selection leaked into Expert A's composer on
an existing thread (prev won over defaults), and A's manual selection
was never restored when switching back — new sessions reset to defaults,
existing threads showed B's ids. Connectors already persisted per agent
(chatStorage.saveConnectors) but shared the same leak: without a state
reset on switch, A's connectors carried into B's existing threads.

Align both selectors on the stricter per-expert semantics:
- chatStorage: save/load/hasSavedKnowledgeBaseIds keyed per agent
  ("octop:chat-knowledge:<agent_id>"), explicit empty preserved
- manual changes persist per expert (KBs now, connectors already)
- on expert switch both in-memory selections reset; the catalog effects
  resolve via the same selection-generic resolver (prev > saved-per-
  agent > defaults, filtered against allowed), so each expert restores
  its own last manual choice — never the other expert's
- new sessions still ignore saved prefs and start from expert defaults

Tests: renderHook A -> B -> A restores each expert's manual KB selection,
a cleared selection stays cleared, and connectors get the same isolation.
Mutation-checked: KB tests fail against the old global-state code; the
connector test fails without the switch reset (leak reproduced).
2026-09-20 19:59:20 +08:00