diff --git a/AGENTS.md b/AGENTS.md index 312a110a79..9e5dd80c9c 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -491,10 +491,10 @@ When adding code that needs a new string, decide up front which rule it falls un - `scripts/dev-safe.mjs` uses `uvx` for temporary agent-server installation — no permanent `uv tool install` needed. Environment variables (highest precedence first): - `OH_AGENT_SERVER_LOCAL_PATH` — absolute path to a local `software-agent-sdk` checkout. Runs the local checkout via `uvx` with `--with-editable` for `openhands-sdk`/`openhands-tools`/`openhands-workspace` and `--reinstall` for `openhands-agent-server`, so SDK edits are picked up on restart. Highest precedence. - `OH_AGENT_SERVER_GIT_REF` — git commit SHA or branch name (takes precedence over version) - - `OH_AGENT_SERVER_VERSION` — specific PyPI version (e.g., "1.38.0") + - `OH_AGENT_SERVER_VERSION` — specific PyPI version (e.g., "1.39.1") - `OH_SECRET_KEY` — secret key for settings encryption; auto-generated and persisted to `~/.openhands/agent-canvas/secret-key.txt` on first run (same file Docker uses), ensuring dev mode and Docker share the same key when both mount the same `~/.openhands` directory. Override with the env var to pin a specific key. - `SESSION_API_KEY` / `OH_SESSION_API_KEYS_0` / `VITE_SESSION_API_KEY` — session API key for agent-server authentication; auto-generated using `crypto.randomBytes(32)` if not set, passed to both agent-server (`OH_SESSION_API_KEYS_0`) and frontend (`VITE_SESSION_API_KEY`) - - Default: released PyPI version `1.38.0` for agent-server SDK libraries + - Default: released PyPI version `1.39.1` for agent-server SDK libraries - Security: launchers generate and persist a 64-character session API key at `~/.openhands/agent-canvas/session-api-key.txt` unless overridden. The agent-server and automation backend share that session key. `OH_SECRET_KEY` protects settings encryption and is persisted separately at `~/.openhands/agent-canvas/secret-key.txt`. - `scripts/dev-safe.mjs` should fail fast if `uvx` cannot be spawned (for example missing PATH entries). diff --git a/__tests__/scripts/dev-safe.test.ts b/__tests__/scripts/dev-safe.test.ts index 397b517283..8948450619 100644 --- a/__tests__/scripts/dev-safe.test.ts +++ b/__tests__/scripts/dev-safe.test.ts @@ -389,18 +389,18 @@ describe("buildAgentServerCommand", () => { // Defaults to the released PyPI version with all SDK packages pinned to same version expect(cmd.args).toEqual([ "--from", - "openhands-agent-server==1.38.0", + "openhands-agent-server==1.39.1", "--with", - "openhands-sdk==1.38.0", + "openhands-sdk==1.39.1", "--with", - "openhands-tools==1.38.0", + "openhands-tools==1.39.1", "--with", - "openhands-workspace==1.38.0", + "openhands-workspace==1.39.1", "--with", "agent-client-protocol<0.11", "agent-server", ]); - expect(cmd.source).toBe("PyPI (1.38.0, default)"); + expect(cmd.source).toBe("PyPI (1.39.1, default)"); }); it("uses specific PyPI version when OH_AGENT_SERVER_VERSION is set with all packages pinned", () => { diff --git a/config/defaults.json b/config/defaults.json index f21953d30b..83ddc4db8d 100644 --- a/config/defaults.json +++ b/config/defaults.json @@ -1,9 +1,9 @@ { "_comment": "Single source of truth for version pins, ports, paths, and defaults shared across the npm and Docker install paths. Read by scripts/dev-safe.mjs, scripts/dev-with-automation.mjs, docker/entrypoint.sh (via generated defaults.env), and .github/workflows/docker.yml.", "versions": { - "agentServer": "1.38.0", + "agentServer": "1.39.1", "agentCanvas": "1.7.2", - "automation": "1.4.1" + "automation": "1.5.0" }, "compatibility": { "minimumAgentServer": "1.28.0" diff --git a/package-lock.json b/package-lock.json index b709f9b96e..6f5f991025 100644 --- a/package-lock.json +++ b/package-lock.json @@ -13,7 +13,7 @@ "@microlink/react-json-view": "1.31.20", "@monaco-editor/react": "4.7.0", "@openhands/extensions": "0.11.0", - "@openhands/typescript-client": "1.34.0", + "@openhands/typescript-client": "1.36.1", "@react-router/node": "7.17.0", "@react-router/serve": "7.17.0", "@tailwindcss/vite": "4.2.4", @@ -4181,9 +4181,9 @@ } }, "node_modules/@openhands/typescript-client": { - "version": "1.34.0", - "resolved": "https://registry.npmjs.org/@openhands/typescript-client/-/typescript-client-1.34.0.tgz", - "integrity": "sha512-29nuKB7m1aOBHJWPgAY8ahZlsnJGkgByuoAQzYjY/lHzUClhM9RCJ0vgghm9cblADiYf+mUAOEL9AaOkXH2ahQ==", + "version": "1.36.1", + "resolved": "https://registry.npmjs.org/@openhands/typescript-client/-/typescript-client-1.36.1.tgz", + "integrity": "sha512-5/o5woxXH5YU0Ve6uvG+vhBHfb3kNB4pBzKBPqefj+EpaCZI/ue8xm3TuGApGzEEf4wQErFM7Vi81xU+L/mC7A==", "license": "MIT", "dependencies": { "@openrouter/sdk": "^0.13.24", diff --git a/package.json b/package.json index 577fcb102f..bacc7ac828 100644 --- a/package.json +++ b/package.json @@ -24,7 +24,7 @@ "@microlink/react-json-view": "1.31.20", "@monaco-editor/react": "4.7.0", "@openhands/extensions": "0.11.0", - "@openhands/typescript-client": "1.34.0", + "@openhands/typescript-client": "1.36.1", "@react-router/node": "7.17.0", "@react-router/serve": "7.17.0", "@tailwindcss/vite": "4.2.4", diff --git a/scripts/check-sdk-version-sync.mjs b/scripts/check-sdk-version-sync.mjs index a858df74fa..deffcf94d6 100644 --- a/scripts/check-sdk-version-sync.mjs +++ b/scripts/check-sdk-version-sync.mjs @@ -19,7 +19,7 @@ * * Usage: * node scripts/check-sdk-version-sync.mjs - * EXPECTED_SDK_VERSION=1.38.0 node scripts/check-sdk-version-sync.mjs + * EXPECTED_SDK_VERSION=1.39.1 node scripts/check-sdk-version-sync.mjs * node scripts/check-sdk-version-sync.mjs --check-pypi * * Environment variables: @@ -78,7 +78,7 @@ Triggering from other repos: -H "Authorization: token \$GITHUB_TOKEN" \\ -H "Accept: application/vnd.github.v3+json" \\ https://api.github.com/repos/OpenHands/OpenHands/dispatches \\ - -d '{"event_type": "sdk-version-check", "client_payload": {"version": "1.38.0"}}' + -d '{"event_type": "sdk-version-check", "client_payload": {"version": "1.39.1"}}' `); process.exit(0); } @@ -260,9 +260,9 @@ async function fetchPyPIDependencies(packageName, version) { * Parse PyPI requires_dist array and extract SDK package versions * * PyPI returns dependencies in PEP 508 format like: - * "openhands-sdk>=1.38.0,<2.0.0" - * "openhands-tools==1.38.0" - * "openhands-workspace (>=1.38.0)" + * "openhands-sdk>=1.39.1,<2.0.0" + * "openhands-tools==1.39.1" + * "openhands-workspace (>=1.39.1)" */ function parseSdkVersionsFromRequiresDist(requiresDist) { const versions = {}; @@ -276,7 +276,7 @@ function parseSdkVersionsFromRequiresDist(requiresDist) { } // Extract the version number - look for patterns like: - // ">=1.38.0", "==1.38.0", "(>=1.38.0)", "~=1.38.0" + // ">=1.39.1", "==1.39.1", "(>=1.39.1)", "~=1.39.1" // After the package name and before any comma or closing paren const versionPattern = /[><=~!]+\s*([0-9]+(?:\.[0-9]+)*)/; const match = dep.match(versionPattern); diff --git a/scripts/dev-safe.mjs b/scripts/dev-safe.mjs index f2b2601a9c..bd4d004f1c 100644 --- a/scripts/dev-safe.mjs +++ b/scripts/dev-safe.mjs @@ -48,7 +48,7 @@ const LOCAL_AGENT_SERVER_SUBDIRS = [ "openhands-workspace", ]; const DEFAULT_AGENT_SERVER_VERSION = SHARED_DEFAULTS.versions.agentServer; -// Temporary transitive-dep pin: openhands-sdk 1.38.0 leaves agent-client-protocol +// Temporary transitive-dep pin: openhands-sdk 1.39.1 leaves agent-client-protocol // unbounded (>=0.10.1), but acp 0.11.0 reordered the ACP prompt() args and breaks // the SDK's ACP client. Hold acp <0.11 until a fixed SDK ships. See config/defaults.json. const AGENT_CLIENT_PROTOCOL_CONSTRAINT = @@ -399,7 +399,7 @@ export function validateFrontendDependencies( * edits are picked up without a manual reinstall. The agent-server itself * is rebuilt from local source on each invocation (--reinstall). * - OH_AGENT_SERVER_GIT_REF: Git commit SHA or branch name - * - OH_AGENT_SERVER_VERSION: Specific PyPI version (e.g., "1.38.0") + * - OH_AGENT_SERVER_VERSION: Specific PyPI version (e.g., "1.39.1") * * If none are set, defaults to the released version specified by * DEFAULT_AGENT_SERVER_VERSION. Set OH_AGENT_SERVER_GIT_REF to use a diff --git a/src/api/mcp-service/mcp-service.api.ts b/src/api/mcp-service/mcp-service.api.ts index 66ecd6027f..2f2549b34d 100644 --- a/src/api/mcp-service/mcp-service.api.ts +++ b/src/api/mcp-service/mcp-service.api.ts @@ -338,11 +338,15 @@ class McpService { return client.startOAuth(request as MCPTestRequest); } + // typescript-client 1.36 types the OAuth probes with the generated + // agent-server models, which describe the opaque `oauth_state` JSON blobs as + // `unknown` rather than the recursive `MCPJsonValue` the local types use. The + // wire shape is unchanged, so narrow back to the app's boundary type. private static async getOAuthStatusWithClient( client: MCPClient, jobId: string, ): Promise { - return client.getOAuthStatus(jobId); + return (await client.getOAuthStatus(jobId)) as MCPOAuthStatusResponse; } private static async submitOAuthCallbackWithClient( @@ -350,7 +354,9 @@ class McpService { jobId: string, callbackUrl: string, ): Promise { - return client.submitOAuthCallback(jobId, { callback_url: callbackUrl }); + return (await client.submitOAuthCallback(jobId, { + callback_url: callbackUrl, + })) as MCPOAuthStatusResponse; } }