mirror of
https://github.com/OpenHands/OpenHands.git
synced 2026-10-06 12:03:07 +08:00
main
11 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
e1c9e6ab33 |
chore: remove redundant automationSdk version — derive from agentServer (#1333)
The automationSdk version was always intended to equal agentServer. Having a separate field creates a maintenance foothole where the two values can silently drift. Remove automationSdk from defaults.json and have all consumers (check-sdk-version-sync, dev-with-automation, agent-canvas CLI --version output) read versions.agentServer directly. The sync check still catches any mismatch between the released openhands-automation package and the expected SDK version. Co-authored-by: openhands <openhands@all-hands.dev> |
||
|
|
bbf9ce9667 |
[codex] Bump minimum compatible agent server (#1342)
* Bump minimum compatible agent server * Apply version compatibility to backend health * Explain backend health failures in manage modal --------- Co-authored-by: neubig <398875+neubig@users.noreply.github.com> |
||
|
|
8bb2b8c518 |
Add frontend-only and backend-only agent-canvas modes (#1040)
* Add partial stack modes to agent-canvas Co-authored-by: openhands <openhands@all-hands.dev> * fix: address PR review feedback (#1040) - Replace padEnd(75) with ANSI-aware ansiPadEnd helper in printBanner; String.padEnd counts invisible escape bytes as visible chars, causing the box border to misalign in colour terminals - Deduplicate storage directory creation in ensureDirectories; was being pushed once per launchAgentServer block and once per launchAutomation block (always both true together) — move to a shared unconditional slot - Add explanatory comment to the checkNpm two-clause OR condition Co-authored-by: openhands <openhands@all-hands.dev> * test: add e2e tests for --frontend-only, --backend-only, and port conflicts Add mock-llm-partial-stack.spec.ts with three test groups: 1. --frontend-only: verifies static frontend is served (200 on /), backend routes return 503 (/server_info, /api/settings, /api/automation/v1), and the browser shows the manage-backends modal. 2. --backend-only: verifies /server_info returns 200, /api/settings is reachable, automation endpoint works, and root/asset requests return 503 (no frontend configured). 3. Port conflict: verifies the process exits non-zero with a clear error when the ingress port is occupied, then starts successfully on a free port. Unlike the other mock-llm specs, these tests spawn their own bin/agent-canvas.mjs child processes with isolated state dirs and high port numbers (18310+ range) to avoid collisions. Co-authored-by: openhands <openhands@all-hands.dev> * fix: adjust frontend-only test to expect SPA fallback instead of 503 In frontend-only mode the ingress has no backend routes — all requests (including /server_info, /api/*) fall through to the static server's default backend, which returns index.html via SPA fallback (200 with HTML). The test now verifies that /server_info returns HTML (not JSON) and that the browser detects the missing backend and shows the manage-backends modal. Co-authored-by: openhands <openhands@all-hands.dev> * feat: add --reject-prefix to static server for clean 503 on missing backends In --frontend-only mode the static server was SPA-fallbacking API paths (/server_info, /api/*, /sockets, etc.) to index.html, returning 200 with HTML content instead of a clear failure. This made the frontend's /server_info probe ambiguous. Add a --reject-prefix flag to static-server.mjs: any matching request returns 503 ('Service Unavailable') before the SPA fallback runs. Wire it through dev-with-automation.mjs: getRejectPrefixes(config) computes which API prefixes have no backend configured (e.g. all of them in frontend-only mode) and buildRejectPrefixArgs() passes them as --reject-prefix flags to the static server. Restore the e2e test to assert 503 for /server_info, /api/settings, and /api/automation/v1 in frontend-only mode. Co-authored-by: openhands <openhands@all-hands.dev> * fix: treat non-401 HTTP errors from /server_info as unavailable loadAgentServerInfo was re-throwing all SDK HttpErrors (including 503) as-is, but root.tsx only checks for AgentServerUnavailableError. A 503 from the static server in --frontend-only mode (or any non-401 error) would fall through to the Outlet instead of showing the manage-backends modal. Narrow the re-throw to only preserve 401 (needed for the auth screen in public mode). All other HTTP errors are now wrapped as AgentServerUnavailableError so the app shows the correct recovery UI. Co-authored-by: openhands <openhands@all-hands.dev> * fix: poll automation readiness in backend-only test; retry on 5xx The automation backend starts independently from the agent-server and may not be ready when /server_info first returns 200. pollUrl now treats 5xx responses as 'not ready yet' and keeps retrying. The backend-only test also polls /api/automation/v1 before asserting on it. Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev> Co-authored-by: Rohit Malhotra <rohitvinodmalhotra@gmail.com> |
||
|
|
14b1b1e8ad |
feat: two auth modes — local (auto-key) and public (paste-key) (#790)
* feat: two auth modes — local (auto-key) and public (paste-key) Local mode (agent-canvas, no flags): - Ingress binds to 127.0.0.1 only - Auto-generates session API key - Writes /backends.json to static dir so frontend auto-authenticates - Zero setup for localhost use Public mode (agent-canvas --public): - Ingress binds to 0.0.0.0 (all interfaces) - Requires LOCAL_BACKEND_API_KEY env var - Does NOT write /backends.json - Frontend shows API key entry screen on 401 Co-authored-by: openhands <openhands@all-hands.dev> * refactor: reuse BackendForm in public-mode API key entry screen Replace the bespoke ApiKeyEntryScreen form with BackendForm configured for the public-auth use case: - Host field is auto-filled from window.location.origin and read-only - Name field is hidden (auto-derived from the existing backend) - Only the API key input is exposed to the user - Uses the same SettingsInput / BrandButton components as the backend connection modals for visual consistency BackendForm gains three optional props to support this: - hideName: hides the name input and uses a fallback name - hostReadOnly: disables the host input - onSubmitPayload: receives the submitted payload for side-effects (the API key screen uses it to persist to agent-server-config and reload the page) Co-authored-by: openhands <openhands@all-hands.dev> * docs: update AGENTS.md with ApiKeyEntryScreen BackendForm reuse details Co-authored-by: openhands <openhands@all-hands.dev> * feat: implement public mode auth flow (--public flag) - Add --public flag to dev-with-automation.mjs and bin/agent-canvas.mjs - In public mode: require LOCAL_BACKEND_API_KEY, use as session key, don't bake into frontend (no VITE_SESSION_API_KEY / --session-api-key) - Add isAgentServerAuthError() to detect 401 from /server_info probe - root.tsx shows ApiKeyEntryScreen when 401 detected (lazy loaded) - useConfig skips retries on 401 for instant auth screen display - ApiKeyEntryScreen now has default export for React.lazy compatibility Co-authored-by: openhands <openhands@all-hands.dev> * fix: use VITE_AUTH_REQUIRED flag instead of 401 detection for public mode The 401-based approach was unreliable — /server_info may not require auth on all server versions. Instead: - dev-with-automation.mjs sets VITE_AUTH_REQUIRED=true in public mode - isAuthRequiredAndMissing() checks the flag + localStorage for a key - root.tsx gates on the flag BEFORE the /server_info probe, so the auth screen appears instantly with zero network round-trips - 401 fallback kept as safety net for edge cases Co-authored-by: openhands <openhands@all-hands.dev> * fix: handle stale key via 401 detection in public mode When the server restarts with a new LOCAL_BACKEND_API_KEY, the browser still has the old key in localStorage. isAuthRequiredAndMissing() returns false (key exists), so the /server_info probe fires and 401s. isAgentServerAuthError() now checks VITE_AUTH_REQUIRED=true AND 401 status, so it only triggers in public mode (a 401 in local mode is a misconfiguration, not a key-rotation event). useConfig skips retries on 401 to show the auth screen immediately. Two gates, one screen: - No key at all → flag check, instant, no network - Stale key → /server_info 401, one round-trip Co-authored-by: openhands <openhands@all-hands.dev> * fix: validate stale keys against GET /api/settings (protected) /server_info is unprotected — it returns 200 even with a wrong key. In public mode, after the /server_info probe succeeds, we now hit GET /api/settings to verify the stored key is still valid. A 401 from that endpoint triggers the auth screen via isAgentServerAuthError(). Co-authored-by: openhands <openhands@all-hands.dev> * fix: rewrite ApiKeyEntryScreen — validate before save, always empty key, match add-modal UI Three fixes: 1. Stale key conflict: The form now always starts with an empty API key field instead of pre-filling from the backend registry. Stale credentials from a previous session never bleed into the input. 2. Wrong key indicator: On submit, the key is validated against GET /api/settings (protected endpoint) BEFORE persisting. Wrong keys show an inline red status dot + 'Invalid API key' error via BackendStatusDot. Only validated keys trigger the reload. 3. UI parity with add-backend modal: Replaced BackendForm wrapper with direct SettingsInput fields matching ManualConnectionColumn's layout — host (read-only + helper text), API key (password with placeholder), status indicator, and Connect button. No cloud OAuth column. New i18n key: AUTH$INVALID_KEY (all 15 languages). Co-authored-by: openhands <openhands@all-hands.dev> * feat: match add-backend modal UI + add test coverage ApiKeyEntryScreen now renders the exact same card chrome as BackendFormModal add-mode: same title ('Add a Backend'), same Name/Host/API Key fields, same Connect button styling. Host is pre-filled and read-only; no cloud OAuth column. New tests (12 total): - api-key-entry-screen.test.tsx (7 tests): - UI field parity with add-backend modal - Stale key wipe (empty API key field despite stale localStorage) - Connect disabled until name + key filled - Valid key: validates → persists → reloads - Invalid key: error indicator, no persist, no reload - Retry flow: wrong key → error → correct key → success - Stale key isolation: only fresh key persisted - agent-server-config.test.ts (5 new tests for isAuthRequiredAndMissing): - Flag unset → false - Flag set, no key → true - Flag set, localStorage key → false - Flag set, VITE_SESSION_API_KEY → false - Flag not 'true' → false Co-authored-by: openhands <openhands@all-hands.dev> * fix: distinguish 401 from other errors in ApiKeyEntryScreen The catch-all was showing 'Invalid API key' for EVERY failure — including 500s, network errors, and timeouts — even when the key was correct. Now: - 401 → 'Invalid API key. Please check the key and try again.' - Anything else → 'Connection failed: <actual error message>' This reveals the real problem when a correct key fails for a non-auth reason (e.g. server misconfiguration, missing OH_SECRET_KEY). New i18n key: AUTH$CONNECTION_FAILED (all 15 languages). New test: non-401 errors show 'Connection failed' + detail. Co-authored-by: openhands <openhands@all-hands.dev> * fix: agent-server receives wrong session key in public mode startAgentServer() called buildSafeDevConfig() which generated its own random session key, ignoring config.sessionApiKey (which holds LOCAL_BACKEND_API_KEY in public mode). The agent-server was started with a random key while users were told to paste the LOCAL_BACKEND_API_KEY value — every key was rejected with 401. Fix: override OH_SESSION_API_KEYS_0 in the agent-server env with config.sessionApiKey so both the agent-server and the frontend agree on which key is valid. Co-authored-by: openhands <openhands@all-hands.dev> * refactor: address review comments on ApiKeyEntryScreen 1. Remove dead BackendFormProps (hideName, hostReadOnly, onSubmitPayload) — ApiKeyEntryScreen is standalone so no caller used these props. 2. Auto-generate backend name from window.location.hostname instead of requiring users to type one. Only the API key field is required now, reducing public-mode auth to a single-field flow. 3. Simplify redundant ternary: connectionStatus === 'success' ? true : false → connectionStatus === 'success'. Co-authored-by: openhands <openhands@all-hands.dev> * fix: address second round of review comments 1. Use shared isSdkHttpError() helper in ApiKeyEntryScreen instead of duplicating the SDK error shape check inline. Exported the helper from agent-server-compatibility.ts. 2. Add code comment acknowledging the edge case where a network hiccup between /server_info and getSettings() probes lets the app load with an unvalidated key. Acceptable since the window is narrow and a page refresh recovers. 3. Add --auth-required flag to static-server.mjs so pre-built static binaries (npx @openhands/agent-canvas --public) show the API key entry screen without needing VITE_AUTH_REQUIRED baked in at build time. The flag injects window.__AGENT_CANVAS_AUTH_REQUIRED__=true into index.html at runtime. Frontend isAuthRequired() checks both the build-time env var and the runtime window flag. Co-authored-by: openhands <openhands@all-hands.dev> * fix: use double cast (unknown) to satisfy strict TS on window flag access window cannot be cast directly to Record<string, unknown> — TypeScript requires going through unknown first for unrelated types. (window as unknown as Record<string, unknown>).__AGENT_CANVAS_AUTH_REQUIRED__ This fixes the CI typecheck failure introduced in aa76c01a. Co-authored-by: openhands <openhands@all-hands.dev> * fix: address remaining review comments on auth modes PR - Use isAuthRequired() instead of raw import.meta.env.VITE_AUTH_REQUIRED in isAgentServerAuthError() so the runtime window flag injected by static-server.mjs in pre-built binaries is also honoured (bug fix). - Preserve existing backend name during re-authentication flow in ApiKeyEntryScreen; only fall back to window.location.hostname for the initial entry so users don't lose custom labels on key rotation. Co-authored-by: openhands <openhands@all-hands.dev> * fix: restore MCP-to-integrations migration from main A prior merge into this branch incorrectly kept the old @openhands/extensions/mcps imports instead of the @openhands/extensions/integrations paths introduced by d41bfe15 on main. Restore all affected files from origin/main so the extensions package (which no longer exports ./mcps) resolves correctly. Files restored from main: - src/utils/mcp-marketplace-utils.ts - src/routes/mcp.tsx - src/components/features/mcp-logo-badge.tsx - src/components/features/mcp-page/* (6 files) - src/components/features/automations/* (2 files) - __tests__/ (4 test files) Co-authored-by: openhands <openhands@all-hands.dev> * style: fix prettier formatting and remove unused eslint-disable in api-key-entry-screen Co-authored-by: openhands <openhands@all-hands.dev> * fix: address remaining PR review comments - Extract isSdkHttpStatusError() helper in agent-server-compatibility.ts to DRY up the SDK error status check (review comment #3321202503). Both isAgentServerAuthError() and ApiKeyEntryScreen now use it. - Use AUTH i18n keys in api-key-entry-screen.tsx: • Heading: AUTH$API_KEY_REQUIRED_TITLE ('API Key Required') • Description: AUTH$API_KEY_REQUIRED_DESCRIPTION added below heading • Button: AUTH$CONNECT ('Connect') (review comments #3325478721, #3325478729) - Fix nested <main> landmark in root.tsx: remove the outer <main> wrapper since ApiKeyEntryScreen already provides its own semantic container (review comment #3325478704). - Change ApiKeyEntryScreen root element from <main> to <div> so the Layout's own landmarks are not violated. Co-authored-by: openhands <openhands@all-hands.dev> * test: add coverage for window.__AGENT_CANVAS_AUTH_REQUIRED__ runtime flag Add isAuthRequired() test block covering the window flag path used by pre-built static binaries (static-server.mjs --auth-required). Also add window-flag variants to isAuthRequiredAndMissing() tests. Addresses review comment #3325587577. Co-authored-by: openhands <openhands@all-hands.dev> * refactor!: deduplicate SESSION_API_KEY into LOCAL_BACKEND_API_KEY BREAKING CHANGE: The user-facing env var for setting the API key is now `LOCAL_BACKEND_API_KEY` everywhere. The old `SESSION_API_KEY`, `OH_SESSION_API_KEYS_0`, and `VITE_SESSION_API_KEY` env vars are no longer read by launchers as user-facing configuration. Internal plumbing (`config.sessionApiKey`, `VITE_SESSION_API_KEY` build injection, `OH_SESSION_API_KEYS_0` agent-server env) is unchanged — only the user-facing surface is unified into a single env var. Changes: - scripts/dev-safe.mjs: read LOCAL_BACKEND_API_KEY instead of SESSION_API_KEY / OH_SESSION_API_KEYS_0 / VITE_SESSION_API_KEY - scripts/dev-with-automation.mjs: unify key resolution through buildSafeDevConfig for both public and local modes - bin/agent-canvas.mjs: update CLI help text and examples - docker/entrypoint.sh: read LOCAL_BACKEND_API_KEY, migrate legacy session-api-key.txt → api-key.txt - scripts/static-server.mjs: add mutual-exclusion guard for --session-api-key + --auth-required flags - playwright configs: pass LOCAL_BACKEND_API_KEY instead of the old trio - test helpers: prefer LOCAL_BACKEND_API_KEY fallback chain - Update tests and documentation Co-authored-by: openhands <openhands@all-hands.dev> * fix: address review comments — narrow settings probe rethrow and use shared client options - loadAgentServerInfo: narrow getSettings() catch to rethrow only 401 errors. Other HTTP errors (403, 5xx) and non-HTTP errors (network, timeout) are now swallowed with a console.warn, since the server is confirmed up (via /server_info) and the probe is best-effort. This prevents misconfigured servers from silently falling through to <Outlet /> without showing either the auth or unavailable screen. - ApiKeyEntryScreen: replace hand-rolled SettingsClient options with getAgentServerClientOptions() so transport-level settings (e.g. VITE_INSECURE_SKIP_VERIFY) are honoured. Uses the sessionApiKey override to pass the freshly-entered key. Co-authored-by: openhands <openhands@all-hands.dev> * fix: rewrite git+ssh to git+https for @openhands/extensions in lockfile npm normalizes GitHub URLs to git+ssh:// in the lockfile, but machines without SSH keys for GitHub (or with stale npm caches) can end up installing a wrong version of the package. This causes the Vite resolve error: "./integrations" is not exported under the conditions [...] The same pattern was already fixed for @openhands/typescript-client (see #384). vercel-install.sh already does a blanket sed rewrite, but the committed lockfile itself should use git+https:// so local npm ci works without SSH keys. Co-authored-by: openhands <openhands@all-hands.dev> * refactor: align public auth screen with Add Backend form layout Replace the custom 'API Key Required' screen with the same form layout used by the 'Add a Backend' left column in BackendFormModal: - Heading changed from 'API Key Required' to 'Add a Backend' - Added backend Name field (required, same as ManualConnectionColumn) - Host field remains pre-filled and disabled (from window.location.origin) - API Key field unchanged - Submit button now uses BACKEND$CONNECT label (matching the modal) - Removed the subtitle description paragraph for cleaner parity - Name is persisted to the backend registry on submit Tests updated: fillApiKey → fillRequiredFields (name + apiKey), assertions cover the new name field and dual-field submit gating. Co-authored-by: openhands <openhands@all-hands.dev> * chore: remove unused AUTH$ i18n keys from this PR The UI refactor (02faa0b0) switched ApiKeyEntryScreen to the BACKEND$* keys. Drop the three AUTH$ entries that were introduced and then superseded within this same PR: - AUTH$API_KEY_REQUIRED_TITLE - AUTH$API_KEY_REQUIRED_DESCRIPTION - AUTH$CONNECT Co-authored-by: openhands <openhands@all-hands.dev> * fix: sync stale session API key on boot when LOCAL_BACKEND_API_KEY changes When a user restarts the stack with a different LOCAL_BACKEND_API_KEY, the new VITE_SESSION_API_KEY is baked in correctly, but localStorage may still hold the old key in two places: 1. openhands-agent-server-config.sessionApiKey (written by onboarding or the Settings page) 2. openhands-backends[].apiKey (seeded on first load, never re-synced) The existing syncDefaultLocalBackendAuth() in storage.ts already tries to fix #2 by comparing against makeDefaultLocalBackend(), but that function reads through getConfiguredSessionApiKey() which hits #1 (stale localStorage) before falling back to VITE_SESSION_API_KEY. So a stale #1 defeats the #2 sync. Fix: add syncBakedSessionApiKey() which runs from readStoredBackends() before any key resolution. When VITE_SESSION_API_KEY is set and the stored key in openhands-agent-server-config differs, overwrite it. This ensures getConfiguredSessionApiKey() and makeDefaultLocalBackend() both return the correct key, and the downstream backend-registry sync works as intended. Also fix the static-server.mjs injection script to always overwrite a stored key that differs from the runtime key (was guarded by `if(!_c.sessionApiKey)` which skipped updates when any key existed). Add mock-LLM E2E tests for: - Key rotation recovery: seeds stale localStorage, verifies app loads - Public-mode auth gate: tests auth screen visibility, wrong key rejection, and correct key acceptance Co-authored-by: openhands <openhands@all-hands.dev> * docs: document key rotation resilience in AGENTS.md Co-authored-by: openhands <openhands@all-hands.dev> * fix: add syncBakedSessionApiKey to vi.mock stubs and use click-then-fill in E2E Three test files mock #/api/agent-server-config without exporting syncBakedSessionApiKey, which storage.ts now calls at import time. Add the missing vi.fn() stub to all three. Also fix the public-mode auth E2E test: use the click() → fill() pattern for React controlled inputs (matching the established convention in mock-llm-conversation.spec.ts) so the SettingsInput onChange fires reliably in Playwright. Co-authored-by: openhands <openhands@all-hands.dev> * test: add public-mode key rotation E2E test Simulates a server key rotation: localStorage holds a stale key from a previous session, the server now has a new key. Verifies the app detects the 401 from the stale key probe, shows the auth screen, and accepts the new key. Flow: stale key in localStorage → probe /server_info → 401 → isAgentServerAuthError → ApiKeyEntryScreen → user pastes new key → reload → app loads normally. Co-authored-by: openhands <openhands@all-hands.dev> * fix(e2e): suppress consent modal in public-mode auth tests The analytics consent modal overlays the auth screen on first visit (clean localStorage). Playwright's click() on the form inputs was intercepted by the modal overlay, causing a 60s timeout loop (121 retries). Add a beforeEach that seeds 'analytics-consent' and 'openhands-telemetry-consent' in localStorage before navigation. Also deduplicate the consent seeding from the key-rotation test's addInitScript since the beforeEach now handles it. Co-authored-by: openhands <openhands@all-hands.dev> * refactor: deduplicate readStoredConfig() call in syncBakedSessionApiKey Capture the first readStoredConfig() result and reuse it in the spread instead of hitting localStorage twice. Co-authored-by: openhands <openhands@all-hands.dev> * chore(docker): remove legacy session-api-key.txt migration The backwards-compatibility shim that migrated the old session-api-key.txt to api-key.txt is no longer needed — a breaking change here is acceptable. Co-authored-by: openhands <openhands@all-hands.dev> * refactor: dedup ApiKeyEntryScreen against BackendForm ApiKeyEntryScreen now renders BackendForm with three new props instead of reimplementing the name/host/API-key inputs from scratch: - hostReadOnly: locks the host field (pre-filled from window.origin) - requireApiKey: forces a non-empty API key for local backends - onSubmitOverride: replaces the default sync persist with async server-side validation (GET /api/settings) before persisting The auth-gate-specific chrome (full-screen wrapper, connection status indicator, validating/error state) stays in ApiKeyEntryScreen via the existing renderActions slot. Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev> Co-authored-by: chuckbutkus <chuck@openhands.dev> |
||
|
|
231367a62b |
feat(cli): add --info flag to show default stack versions and ports (#902)
agent-canvas --version only shows the package version. The new --info flag reads config/defaults.json and prints the full picture: agent-canvas version, default agent-server/automation/SDK versions, default ports, and the env vars available to override them. Co-authored-by: openhands <openhands@all-hands.dev> |
||
|
|
f2d19c8923 |
Add GitHub bug report issue template (#813)
* Add GitHub bug report issue template - Bug report form with install method dropdown (npm, Docker, source, other) and version dropdown listing all pre-release versions (alpha.2–alpha.6) - Includes optional agent-server version, environment, logs/screenshots fields Co-authored-by: openhands <openhands@all-hands.dev> * Remove agent server version field from bug report template Co-authored-by: openhands <openhands@all-hands.dev> * Remove environment field from bug report template Co-authored-by: openhands <openhands@all-hands.dev> * Add OS dropdown to bug report template Co-authored-by: openhands <openhands@all-hands.dev> * Address review feedback on bug report template - Convert version dropdown to free-text input to avoid maintenance burden - Fix docker inspect description to include image reference - Add Actual Behavior field between Steps to Reproduce and Expected Behavior - Split Logs/Screenshots into separate fields so render:shell doesn't break images Co-authored-by: openhands <openhands@all-hands.dev> * Add --version flag to CLI and version label to Docker image - bin/agent-canvas.mjs: add -v/--version flag that reads version from package.json - docker/Dockerfile: add AGENT_CANVAS_VERSION build arg and org.opencontainers.image.version label - .github/workflows/docker.yml: extract version from package.json, pass as build arg - bug_report.yml: update version field description with the actual commands users can run Co-authored-by: openhands <openhands@all-hands.dev> * Update version description: use image tag for Docker (label not yet released) Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev> |
||
|
|
edb998220a |
Remove Docker dependency from dev workflow (#635)
- Delete scripts/dev-docker.mjs and its test - Simplify package.json: 'npm run dev' now runs local uvx stack directly (agent-server + automation + Vite + ingress), no Docker needed - Remove dev:docker, dev:docker:dynamic, dev:dangerously-dockerless scripts - Add dev:static for production-build frontend variant - Update bin/agent-canvas.mjs CLI to use uvx-based stack - Rename Docker-specific variables: DOCKER_PROJECTS_PATH → PROJECTS_PATH, shouldDefaultToDockerProjects → shouldDefaultToProjectsPath - Update i18n: HOST_HOME_NOT_MOUNTED_HINT no longer references Docker - Update all docs (README, DEVELOPMENT, SELF_HOSTING, AGENTS.md, CHANGELOG) - Rename e2e snapshot: docker-workspace-browser → projects-workspace-browser - Fix all tests to reflect new script names and remove Docker references Co-authored-by: openhands <openhands@all-hands.dev> |
||
|
|
5c42bd3492 |
Rename PROJECT_PATH to PROJECTS_PATH (#521)
* Rename PROJECT_PATH to PROJECTS_PATH Co-authored-by: openhands <openhands@all-hands.dev> * Apply suggestion from @enyst --------- Co-authored-by: openhands <openhands@all-hands.dev> |
||
|
|
b2b71855c6 |
feat(dev): surface dev-stack runtime services in agent system prompt (#503)
* feat(dev): surface dev-stack runtime services in agent system prompt Add a structured 'runtime services' info object that the dev launchers (`dev:safe`, `dev:automation`, `dev:docker`, and the published `agent-canvas` binary) propagate to the frontend via `VITE_RUNTIME_SERVICES_INFO`. The frontend renders it into a `<RUNTIME_SERVICES>` markdown block and attaches it as `AgentContext.system_message_suffix` on every `POST /api/conversations`. This means agents start each conversation knowing exactly what services exist in the current dev stack (ingress URL, automation backend URL + `/api/automation` prefix, auth header, etc.), instead of having to probe or — worse — assume `localhost:8000` is the automation server when it is actually the Agent Server they are running inside of. URLs are written from the agent's point of view: dockerless modes use `localhost`, `dev:docker` uses `host.docker.internal`. When automation isn't running in the current mode (e.g. `dev:safe`), the block says so explicitly so agents know to skip `/api/automation` calls. Co-authored-by: openhands <openhands@all-hands.dev> * fix(runtime-services): address review feedback on PR #503 - Validate required `agentServerPort` in `buildRuntimeServicesInfo`; previously a missing port baked `http://localhost:undefined` into the agent's system prompt. - Skip the automation entry when the supplied `automation` object has no `port` (e.g. a bare `{}` from a misconfigured launcher). - Rename the JSON service key from `vite` to `frontend` and add a `kind: "vite" | "static"` discriminator + mode-aware description, so static-build dev stacks (`dev:docker`, the published binary, ...) no longer surface a misleading "Vite dev server" line in the agent system prompt. The renderer still accepts the legacy `vite` key. - Anchor the "don't guess" warning to the actual agent-server URL from runtime info instead of hardcoded `localhost:8000`, since the agent-server uses different ports across dev modes (18000 in dev:safe, 8000 in dev:docker, ...). - Plumb `frontendKind` through `buildAutomationRuntimeServicesInfo` and stamp `config.frontendKind` in `dev-with-automation.mjs::main` so both Vite spawn and static-build paths describe the frontend correctly. - Expand AGENTS.md with the JSON schema of `VITE_RUNTIME_SERVICES_INFO` and a concrete example of the rendered `<RUNTIME_SERVICES>` block. - Tests: assert the new URL-in-warning behavior, the new `frontend` / legacy `vite` rendering, the `agentServerPort`-required guard, the `automation: {}` skip, and the legacy `vitePort` alias. Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev> |
||
|
|
b5f01f366f |
feat: npm publish workflow with OIDC trusted publishing (#358)
* Add npm publish workflow and release infrastructure - Add .github/workflows/npm-publish.yml for automated npm publishing on GitHub releases - Update CI to verify library build (npm run build:lib) and package contents - Add CHANGELOG.md for version history tracking - Update README.md with npm installation and usage documentation Closes #197 Co-authored-by: openhands <openhands@all-hands.dev> * correct package version * chore: update npm-publish workflow for trusted publishing - Remove NODE_AUTH_TOKEN secret dependency - Keep id-token: write permission for OIDC - Add provenance flag for npm attestations - Add comment explaining trusted publisher setup on npmjs.com Co-authored-by: openhands <openhands@all-hands.dev> * feat: add CLI entry point for npx execution - Add bin/agent-canvas.mjs as executable CLI - Add bin field to package.json for npm bin linking - Include bin/ and build/ directories in published files - CLI serves the built application with SPA routing support - Supports --port, --host, and --help options Co-authored-by: openhands <openhands@all-hands.dev> * refactor: consolidate npm executable to use dev-docker infrastructure - bin/agent-canvas.mjs now uses dev-with-automation.mjs main() with dev-docker.mjs's Docker-specific agent-server starter - Added --static and --static-dir support to dev-with-automation.mjs so the npm executable serves pre-built static assets instead of Vite - Added startStaticFrontend() function that uses static-server.mjs - npm executable runs full stack: Docker agent-server + uvx automation backend + static frontend + ingress proxy Co-authored-by: openhands <openhands@all-hands.dev> * fix: include scripts/ in npm package files The bin/agent-canvas.mjs executable imports from scripts/dev-with-automation.mjs and scripts/dev-docker.mjs, so the scripts directory must be included in the published package. Co-authored-by: openhands <openhands@all-hands.dev> * fix: address review comments - Fix CHANGELOG.md version mismatch: 1.6.0 -> 1.0.0-alpha.1 to match package.json - Add NODE_AUTH_TOKEN env var to npm-publish workflow for authentication - Add CLI entry point mention to CHANGELOG Co-authored-by: openhands <openhands@all-hands.dev> * fix: use OIDC trusted publishing (no NPM_TOKEN needed) npm trusted publishing with OIDC doesn't require NODE_AUTH_TOKEN. Instead it uses short-lived OIDC tokens generated by GitHub Actions. Requirements: - id-token: write permission (already set) - npm CLI 11.5.1+ (added npm install -g npm@latest step) - Trusted publisher configured on npmjs.com See: https://docs.npmjs.com/trusted-publishers/ Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump version to 1.0.0-alpha.2 Co-authored-by: openhands <openhands@all-hands.dev> * Build app assets before npm publish Co-authored-by: openhands <openhands@all-hands.dev> * fix: use Node 24 for npm trusted publishing Trusted publishing requires Node 22.14.0+ and npm 11.5.1+. Node 24 ships with npm 11.x which meets the requirement. Node 22.12.0 (previous) ships with npm 10.x which doesn't support OIDC. Also removed the manual npm upgrade step since Node 24 includes a compatible npm version by default. Co-authored-by: openhands <openhands@all-hands.dev> * chore: align all workflows to Node 24 and regenerate lockfile - Update ci.yml to use Node 24 - Update sdk-version-sync.yml to use Node 24 - Regenerate package-lock.json with npm 11.12.1 All workflows now use Node 24 which ships with npm 11.x, required for OIDC trusted publishing (npm 11.5.1+). Co-authored-by: openhands <openhands@all-hands.dev> * fix: remove incorrect LLM env vars from CLI help LLM_MODEL and LLM_API_KEY were listed in the help text but aren't actually used by the scripts. LLM settings are configured through the web UI settings page instead. Co-authored-by: openhands <openhands@all-hands.dev> * fix: address PR review feedback Critical fixes: - Guard prepare script to only run in dev context (check for ../.git) - Add missing existsSync import in dev-with-automation.mjs Workflow improvements: - Update checkout/setup-node actions to v6 for consistency - Add npm version validation (must be 11.5.1+ for trusted publishing) - Add package version validation (must match release tag) CLI improvements: - Add try-catch for dynamic imports with helpful error message - Use console.error directly instead of imported logError/c Documentation: - Fix README export names: ChatInterface→ChatPanel, Terminal→TerminalPanel - Add dist/ to .gitignore Co-authored-by: openhands <openhands@all-hands.dev> * ci: trigger npm publish on tag push instead of release Simpler workflow - just push a tag like v1.0.0-alpha.2 to publish. Co-authored-by: openhands <openhands@all-hands.dev> * chore: remove tarball and add *.tgz to gitignore Co-authored-by: openhands <openhands@all-hands.dev> * fix: npm publish errors 1. Fix bin path - remove './' prefix (npm pkg fix) 2. Add --tag for prerelease versions (alpha/beta/rc) Co-authored-by: openhands <openhands@all-hands.dev> * fix: add repository field for npm provenance verification npm provenance requires repository.url to match the GitHub Actions source. Also added description, homepage, and bugs fields. Co-authored-by: openhands <openhands@all-hands.dev> * fix: add .npmignore to include build/ directory in package npm respects .gitignore when there's no .npmignore, which was excluding the build/ directory from the published package. The .npmignore explicitly lists what to exclude (src/, tests/, dev configs) while allowing build/ and dist/ to be included. Co-authored-by: openhands <openhands@all-hands.dev> * fix: correct BUILD_DIR path in CLI entry point The react-router build outputs to build/ directly (not build/client/) because react-router.config.ts has unpackClientDirectory that moves files from build/client/ to build/ and removes the client/ folder. Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump version to 1.0.0-alpha.3 Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev> |
||
|
|
4738f5b7c6 |
Add npm publish workflow and release infrastructure (#330)
* Add npm publish workflow and release infrastructure - Add .github/workflows/npm-publish.yml for automated npm publishing on GitHub releases - Update CI to verify library build (npm run build:lib) and package contents - Add CHANGELOG.md for version history tracking - Update README.md with npm installation and usage documentation Closes #197 Co-authored-by: openhands <openhands@all-hands.dev> * correct package version * chore: update npm-publish workflow for trusted publishing - Remove NODE_AUTH_TOKEN secret dependency - Keep id-token: write permission for OIDC - Add provenance flag for npm attestations - Add comment explaining trusted publisher setup on npmjs.com Co-authored-by: openhands <openhands@all-hands.dev> * feat: add CLI entry point for npx execution - Add bin/agent-canvas.mjs as executable CLI - Add bin field to package.json for npm bin linking - Include bin/ and build/ directories in published files - CLI serves the built application with SPA routing support - Supports --port, --host, and --help options Co-authored-by: openhands <openhands@all-hands.dev> * refactor: consolidate npm executable to use dev-docker infrastructure - bin/agent-canvas.mjs now uses dev-with-automation.mjs main() with dev-docker.mjs's Docker-specific agent-server starter - Added --static and --static-dir support to dev-with-automation.mjs so the npm executable serves pre-built static assets instead of Vite - Added startStaticFrontend() function that uses static-server.mjs - npm executable runs full stack: Docker agent-server + uvx automation backend + static frontend + ingress proxy Co-authored-by: openhands <openhands@all-hands.dev> * fix: include scripts/ in npm package files The bin/agent-canvas.mjs executable imports from scripts/dev-with-automation.mjs and scripts/dev-docker.mjs, so the scripts directory must be included in the published package. Co-authored-by: openhands <openhands@all-hands.dev> * fix: address review comments - Fix CHANGELOG.md version mismatch: 1.6.0 -> 1.0.0-alpha.1 to match package.json - Add NODE_AUTH_TOKEN env var to npm-publish workflow for authentication - Add CLI entry point mention to CHANGELOG Co-authored-by: openhands <openhands@all-hands.dev> * fix: use OIDC trusted publishing (no NPM_TOKEN needed) npm trusted publishing with OIDC doesn't require NODE_AUTH_TOKEN. Instead it uses short-lived OIDC tokens generated by GitHub Actions. Requirements: - id-token: write permission (already set) - npm CLI 11.5.1+ (added npm install -g npm@latest step) - Trusted publisher configured on npmjs.com See: https://docs.npmjs.com/trusted-publishers/ Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump version to 1.0.0-alpha.2 Co-authored-by: openhands <openhands@all-hands.dev> * Build app assets before npm publish Co-authored-by: openhands <openhands@all-hands.dev> * fix: use Node 24 for npm trusted publishing Trusted publishing requires Node 22.14.0+ and npm 11.5.1+. Node 24 ships with npm 11.x which meets the requirement. Node 22.12.0 (previous) ships with npm 10.x which doesn't support OIDC. Also removed the manual npm upgrade step since Node 24 includes a compatible npm version by default. Co-authored-by: openhands <openhands@all-hands.dev> * chore: align all workflows to Node 24 and regenerate lockfile - Update ci.yml to use Node 24 - Update sdk-version-sync.yml to use Node 24 - Regenerate package-lock.json with npm 11.12.1 All workflows now use Node 24 which ships with npm 11.x, required for OIDC trusted publishing (npm 11.5.1+). Co-authored-by: openhands <openhands@all-hands.dev> * fix: remove incorrect LLM env vars from CLI help LLM_MODEL and LLM_API_KEY were listed in the help text but aren't actually used by the scripts. LLM settings are configured through the web UI settings page instead. Co-authored-by: openhands <openhands@all-hands.dev> * fix: address PR review feedback Critical fixes: - Guard prepare script to only run in dev context (check for ../.git) - Add missing existsSync import in dev-with-automation.mjs Workflow improvements: - Update checkout/setup-node actions to v6 for consistency - Add npm version validation (must be 11.5.1+ for trusted publishing) - Add package version validation (must match release tag) CLI improvements: - Add try-catch for dynamic imports with helpful error message - Use console.error directly instead of imported logError/c Documentation: - Fix README export names: ChatInterface→ChatPanel, Terminal→TerminalPanel - Add dist/ to .gitignore Co-authored-by: openhands <openhands@all-hands.dev> * ci: trigger npm publish on tag push instead of release Simpler workflow - just push a tag like v1.0.0-alpha.2 to publish. Co-authored-by: openhands <openhands@all-hands.dev> * chore: remove tarball and add *.tgz to gitignore Co-authored-by: openhands <openhands@all-hands.dev> * fix: npm publish errors 1. Fix bin path - remove './' prefix (npm pkg fix) 2. Add --tag for prerelease versions (alpha/beta/rc) Co-authored-by: openhands <openhands@all-hands.dev> * fix: add repository field for npm provenance verification npm provenance requires repository.url to match the GitHub Actions source. Also added description, homepage, and bugs fields. Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev> |