Collapse the dual user_role_id / role model so users.role and invites.role
hold the template public id, block deleting roles still in use, and keep
the chat composer visible under mobile browser visualViewport.
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Store group order, item placement, and hidden entries on the user so navigation can be rearranged without showing items the account cannot access.
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Dark-theme surfaces that use var(--fn-bg-container, #fff) — most
visibly the knowledge-base Markdown preview body, toolbar and outline
panel — resolved to a white background while text stayed light, leaving
preview content invisible. Define the variable as #ffffff (light) and
#141414 (dark), and point the Admin/Users badge tints that borrowed the
name for a translucent fill at --fn-bg-tertiary so their look is
unchanged.
Fixes#1215
origin/develop already carried two identical copies of the same case;
keep a single assertion.
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Match the admin reset-password inputs by prefixing current/new password with Lock and confirm with LockOpen.
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Avoid leaking internal names like execute in the live process hint; always use the shared “正在调用工具” copy while a tool is running.
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
* feat(users): add role templates, invite snapshots, and profile avatars
Roles fill defaults for create, edit, and invite without rewriting existing users. Account type stays independent of the selected role.
Co-authored-by: Cursor <cursoragent@cursor.com>
* style: format role and invite repositories for ruff
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix: narrow invite role name before lookup
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Lock in that a team member stays in liveSpeakers through tool rounds even after the host done frees the composer.
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(chat): default-collapse thinking in team rooms only
Keep solo chat expanded by default, and store team/solo preferences under separate localStorage keys so toggling one does not affect the other.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(chat): keep team member replies in one bubble and clear stale live state
Continue member answer text across completed tools in team rooms, and stop
snapshots/wrap-up from leaving finished speakers marked live in the footer.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Default stays persistent (localStorage). Unchecking keeps the JWT in
sessionStorage for this tab only; SSO popups post the token back so the
opener can store it correctly.
Co-authored-by: Cursor <cursoragent@cursor.com>
Improve team streaming visibility (live speakers, generating footer, IM
dispatch/wrap-up), relax ACP tool enable under sandbox while locking
runners, strip channel think tags per show_thinking, and clarify provider
CLI usage in the assistant skill. Includes self-update/UpdateConfig WIP
from the same working tree.
Co-authored-by: Cursor <cursoragent@cursor.com>
Plugin tools returning large octop_ui payloads (e.g. a bangumi season
with 1200+ episodes, ~228KB JSON) blew up the LLM context because the
same tool-result string served both the model and the UI.
Add OctopUiOffloadMiddleware at the innermost agent middleware layer:
when a ToolMessage content is a >=4000-char string carrying a non-empty
octop_ui renderer and data (and no file:// media refs), the payload is
moved in-place to ToolMessage.artifact and the model-visible content is
replaced by a compact result that keeps title/summary. Tool id,
tool_call_id, name and status are preserved.
Frontend restores rendering from artifact: ToolCallData.artifact,
closeToolCall extraction, history replay path, and resolvePluginUiData
prefers explicit data over data_ref. serialize.py surfaces artifact on
tool_result blocks; history recorder backfills artifact as fallback.
Spec: docs/octop-ui-payload-offload.md
Co-authored-by: jubaoliang <jubaoliang@gmail.com>
Persist member file refs and tool history on team walls, open docks by producer agent, and inject truncated member answers into host follow-up so wrap-up can follow their advice.
Co-authored-by: Cursor <cursoragent@cursor.com>
Apply the remaining working-tree changes: connectors empty-state layout,
plus the knowledge, HITL, captcha, workspace, user-cache, and SSRF
adjustments with matching tests.
Co-authored-by: Cursor <cursoragent@cursor.com>
* feat: admin user batch policies, token UX, default FS root, and media push hardening
Add admin user batch enable/disable/delete and resource policies (token quota,
max experts), improve token inputs with K/M presets, default unrestricted
local backends to host filesystem root, and tighten gateway tool-media push
with clearer path-outside-root stream errors.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(workspace): treat Windows drive roots as host-root sentinels
Default FS-root backends use C:/ on Windows; treating that as a scoped
jail put workspaces under the drive root and broke bootstrap/invite tests.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Managing skills and subagents already covers install and copy, so the extra add actions only duplicated that entry.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(acp): block outbound runners under directory sandbox
Host-spawned acp_runner would bypass a scoped root_dir jail; gate the
per-agent tool in API/runtime and gray the ACP UI while inbound octop acp stays available.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(acp): allow workspace-scoped local roots for outbound runners
Windows rewrites host `/` to the agent workspace; treating that as a
directory sandbox made ACP enable/round-trip fail on win32 CI.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Team rooms used a hardcoded "#管理团队" / "#Manage team" string instead of
the agent name already passed into WelcomeScreen.
Co-authored-by: Cursor <cursoragent@cursor.com>
Align skill packages, knowledge bases, browser, and desktop idle tips
with borderless layout and shared mascot sizing; move desktop Check/
Connect into the guide; and use Route for chat model Auto to avoid the
skills Sparkles collision.
Co-authored-by: Cursor <cursoragent@cursor.com>
* refactor: update layout styles to support safe area insets
Modified padding and margin properties across various components to utilize environment variables for safe area insets, ensuring better compatibility with devices that have notches or rounded corners. This includes updates to index.html, offline.html, and several layout components to enhance the overall responsiveness and user experience.
* fix: update keyboard offset handling and layout styles
Refactored keyboard offset calculations in the useKeyboardOffset hook to improve handling of soft keyboard visibility. Adjusted layout styles across various components to utilize the largest viewport height (lvh) for better compatibility with devices featuring home indicators. This includes updates to padding, height properties, and background colors to enhance the user experience in chat and main layout components.
* refactor: update chat layout styles for improved responsiveness
Adjusted padding, width, and margin properties across various chat components to utilize environment variables for better responsiveness. This includes updates to the chat input, message list, and welcome components, ensuring consistent spacing and alignment across different screen sizes. Enhanced mobile styles to accommodate varying avatar sizes and maintain layout integrity.
* refactor: enhance chat component styles for consistency and responsiveness
Updated layout styles in chat components to ensure consistent spacing and alignment. Adjusted margin and gap properties to utilize environment variables, improving responsiveness across different screen sizes. Enhanced mobile styles for better alignment of avatars and message bubbles, ensuring a cohesive user experience.
* feat: implement theme management in index.html and update logo assets
Added a script to manage dashboard theme based on user preferences and system settings, ensuring the correct theme is applied before the first paint. Updated CSS to utilize data attributes for theme styling. Replaced existing logo assets with new vertical and horizontal versions for both light and dark themes, and updated references throughout the application. Removed outdated logo files to streamline asset management.
* refactor: update layout styles to improve safe area handling
Enhanced layout components by adjusting padding and margin properties to better utilize environment variables for safe area insets. This includes updates to the PageShell, Sidebar, MainLayout, Login, and Setup components, ensuring improved responsiveness and compatibility with devices featuring notches or rounded corners.
* feat(provider): add name parameter to provider model interfaces and update session header logic
- Introduced a `name` parameter in `FetchProviderModelsParams` and related interfaces to enhance provider identification.
- Updated `fetchProviderModels` and modal components to utilize the new `name` parameter.
- Enhanced session header management in `opencode_session` to support bundled presets and custom providers.
- Adjusted tests to validate the new functionality and ensure proper session header injection for OpenCode presets.
* feat(deps): add mise.toml for local toolchain configuration and update orcakit-harness-agent to version 1.0.14
- Introduced a new mise.toml file to specify local toolchain versions for Python, Node, NPM, and UV.
- Updated the orcakit-harness-agent dependency version from 1.0.13 to 1.0.14 in pyproject.toml and uv.lock to ensure compatibility with the latest features and fixes.
* refactor(probe): streamline session header construction in probe.py
- Consolidated the session header construction for both `build_probe_chat_model` and `fetch_openai_compatible_models` functions into single-line calls for improved readability and maintainability.
An agent with no MBTI persona rendered "已选中「」", which reads as a
selection whose name was lost. Render a dedicated unset line, and fall
back to the bare code when the catalogue does not know it.
Keep tool-approval bypass on the conversation (allow this tool / allow all)
without changing global security settings. Also let expert create carry
welcome quick prompts, and replace the login forgot-password tip with a
platform-specific CLI dialog.
Co-authored-by: Cursor <cursoragent@cursor.com>
When the chat dock is open the floating workspace/browser/terminal
buttons disappear; expose the same actions from a title-bar + menu and
keep the popup mask from closing while that menu is open.
Co-authored-by: Cursor <cursoragent@cursor.com>
The 32px buttons were clipping selected labels. Match the other toolbar icons, keep the selection in the tooltip, and show provider logos in the model picker.
Co-authored-by: Cursor <cursoragent@cursor.com>
* feat(chat): add Ask / Plan / Craft conversation modes
Keep mode sticky per thread, enforce Ask/Plan in harness-agent, and let Plan write a workspace plan before Craft executes it.
Co-authored-by: Cursor <cursoragent@cursor.com>
* Update pyproject.toml
Open workspace in the same right/bottom/popup tabs as browser and file
changes, and send Help & Feedback to https://octop.cloud.
Co-authored-by: Cursor <cursoragent@cursor.com>
* harness agent upgrade for cache polish
* format
* feat(memory): add coordinated memory slim commands and progress UI
* build(deps): require harness-memory 0.9.11
* fix(deps): restore harness-memory 0.9.11 floor after merge
* fix(agents): await async shutdown to drain SQLite workers
Use HarnessAgentManager.aclose() during shutdown so SQLite cleanup
finishes before the event loop closes, preventing background threads
from raising "Event loop is closed".
Add a real SQLite regression test and preserve the existing ordering
that waits for memory slimming to finish before closing agents.
Validation: make all — 3582 passed, 17 skipped.
Adds 极验行为验 v4 to the login captcha layer, following the provider
plug-in seam (one dataclass + register call backend-side, one widget
adapter frontend-side; the settings UI is data-driven so only locale
keys were needed):
- providers.py: _GeetestV4Provider — login token carries the frontend
getValidate() result as JSON (lot_number / captcha_output /
pass_token / gen_time); siteverify posts form-urlencoded to
gcaptcha4.geetest.com/validate?captcha_id=<id> with
sign_token = HMAC-SHA256(captcha_key, lot_number); only
result == "success" passes (fail / status:error both reject).
Aliases: geetest, geetest4, gt4. Fail-closed on transport errors,
consistent with the other providers.
- CaptchaField: geetest-v4 popup via gt4.js bind mode — initGeetest4,
showCaptcha on ready, getValidate() serialized as the captcha_token;
error/close resolve undefined so login re-prompts.
- Settings UI: captcha_id / captcha_key fields via locale keys.
Tests: provider unit tests (URL + form fields + HMAC against an
independent computation, malformed/missing-field rejection, interpret
matrix), ensure_captcha flow through a local siteverify double (form
body + signature asserted; fail result rejects), popup adapter tests
(validate payload JSON, error path), builtin-order + integration list
assertions updated. Locale parity green.
Keep the login form quiet: show a Forgot password? control first, then
expand admin-first help with the host CLI command as secondary detail.
Co-authored-by: Cursor <cursoragent@cursor.com>
Allow editing AGENTS.md, picking marketplace or other-expert skills, and
adding subagents in the create/edit drawers. Default is a blank AGENTS.md
template; marketplace or copy failures warn instead of aborting create.
Co-authored-by: Cursor <cursoragent@cursor.com>
The KB selection was one global useState plus a touched flag reset on
expert switch: Expert B's selection leaked into Expert A's composer on
an existing thread (prev won over defaults), and A's manual selection
was never restored when switching back — new sessions reset to defaults,
existing threads showed B's ids. Connectors already persisted per agent
(chatStorage.saveConnectors) but shared the same leak: without a state
reset on switch, A's connectors carried into B's existing threads.
Align both selectors on the stricter per-expert semantics:
- chatStorage: save/load/hasSavedKnowledgeBaseIds keyed per agent
("octop:chat-knowledge:<agent_id>"), explicit empty preserved
- manual changes persist per expert (KBs now, connectors already)
- on expert switch both in-memory selections reset; the catalog effects
resolve via the same selection-generic resolver (prev > saved-per-
agent > defaults, filtered against allowed), so each expert restores
its own last manual choice — never the other expert's
- new sessions still ignore saved prefs and start from expert defaults
Tests: renderHook A -> B -> A restores each expert's manual KB selection,
a cleared selection stays cleared, and connectors get the same isolation.
Mutation-checked: KB tests fail against the old global-state code; the
connector test fails without the switch reset (leak reproduced).