Commit Graph
53 Commits
Author SHA1 Message Date
george larson 54d9f30cd3 fix: clean up dev services on SIGHUP (#16239) 2026-08-03 13:41:58 +02:00
e0b115757b fix: route runtime services through server_info (#16090)
Co-authored-by: neubig <398875+neubig@users.noreply.github.com>
Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: neubig <neubig@users.noreply.github.com>
2026-08-02 22:39:43 -04:00
Rohit Malhotraandopenhands 22fe594133 feat: forward automation telemetry context (#1917)
* feat: forward telemetry context to automations

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: sync automation telemetry consent

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: default automation telemetry key in launchers

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: bake production telemetry defaults into npm package

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: dedupe automation consent sync

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump automation version to 1.3.0

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-07-24 05:47:26 +00:00
Hiep Le 4e9ea1334a feat: add electron desktop app (#1864) 2026-07-20 15:06:31 +00:00
Vasco Schiavo 2d7a3985b3 fix: spawn dev services without a shell on Windows (#1859)
On Windows, spawnService ran uvx through cmd.exe (shell: true), so the `<`
in the `agent-client-protocol<0.11` version constraint was parsed as input
redirection and agent-server exited immediately with "The system cannot find
the file specified."

Resolve the command to its absolute path with where.exe and spawn it directly,
with no shell, so argument metacharacters stay literal. npm is unaffected: it is
already wrapped in cmd.exe by buildNpmScriptCommand before it reaches
spawnService.
2026-07-20 11:00:13 +02:00
519c856c37 feat: support serving Canvas under a subpath (#1796)
* feat: support serving canvas under subpath

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: redirect root app routes to canvas base path

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: hieptl <hieptl.developer@gmail.com>
2026-07-15 12:24:11 -04:00
Graham Neubigandopenhands c552545926 feat(mcp): add OAuth support to MCP install flow
Squash merge PR #1583.

This merge commit was created by an AI agent (OpenHands) on behalf of Graham Neubig.

Co-authored-by: openhands <openhands@all-hands.dev>
2026-07-07 12:03:36 +02:00
Tim O'Farrellandopenhands c7a00b14ab fix: seed AUTOMATION_KV_SECRET for local dev stack (#1414)
* fix: seed AUTOMATION_KV_SECRET for local dev

The KV store (automation PR#69) requires AUTOMATION_KV_SECRET to be set
or every KV endpoint returns 503. In a local dev stack the secret is never
configured, so the store is silently unavailable.

Fall back to sessionApiKey when the env var is not set explicitly — the
same zero-config pattern already used for AUTOMATION_AGENT_SERVER_URL,
AUTOMATION_BASE_URL, and AUTOMATION_WORKSPACE_BASE.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump openhands-automation to 1.0.0a10

Update to the latest released version of openhands-automation on PyPI.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-17 14:31:56 -06:00
Tim O'Farrellandopenhands e1c9e6ab33 chore: remove redundant automationSdk version — derive from agentServer (#1333)
The automationSdk version was always intended to equal agentServer.
Having a separate field creates a maintenance foothole where the two
values can silently drift. Remove automationSdk from defaults.json and
have all consumers (check-sdk-version-sync, dev-with-automation,
agent-canvas CLI --version output) read versions.agentServer directly.
The sync check still catches any mismatch between the released
openhands-automation package and the expected SDK version.

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-15 16:18:15 +00:00
dcf469855a UI polish: drawer tabs, empty states, and browser chrome (#1288)
* chore: bump version to 1.0.0-beta.1

* chore: publish beta and rc versions as 'latest' dist-tag

* chore: bump version to 1.0.0-beta.2

* fix: use X-Session-API-Key for local automation auth in prompts and RUNTIME_SERVICES (#999)

Fixes #980

The agent prompt in recommended-automations-launcher and the
RUNTIME_SERVICES block in agent-server-adapter both advertised
X-API-Key as the auth header for the local automation backend.
The automation service (openhands-automation) does not accept
X-API-Key — it accepts Authorization: Bearer and X-Session-API-Key.

X-Session-API-Key is the established local convention: the agent
server uses it, the frontend automation API client uses it (with an
explicit comment that both backends share the same header), and
auth.py describes it as matching that convention. Update both call
sites and the corresponding test assertion to use X-Session-API-Key.

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: reuse mock-LLM E2E tests for Docker image validation (#992)

* feat: reuse mock-LLM E2E tests for Docker image validation

Add a Docker-specific Playwright config (playwright.mock-llm-docker.config.ts)
that runs the exact same test specs and helpers against the agent-canvas Docker
image instead of the npm build path (bin/agent-canvas.mjs + uvx).

Key changes:

- Split MOCK_LLM_BASE_URL into two constants in mock-llm-helpers.ts:
  - MOCK_LLM_BASE_URL: always host-local, used by tests for admin API
  - MOCK_LLM_AGENT_URL: env-overridable, used when configuring the LLM
    profile (the URL the agent-server uses for inference). Defaults to
    MOCK_LLM_BASE_URL for backward compatibility with the npm path.

- New playwright.mock-llm-docker.config.ts:
  - Starts the mock LLM server on the host (same as npm path)
  - Runs the Docker container with --network host (Linux CI)
  - Points to the same testDir (tests/e2e/mock-llm/) and specs
  - Separate output dirs to avoid collision with npm path results

- New CI workflow (.github/workflows/mock-llm-docker-e2e.yml):
  - Builds the Docker image from current code (or uses a pre-built image)
  - Runs the same specs against the container
  - Posts PR comment with differentiated report title

- render-mock-llm-report.mjs: accept --title flag for Docker vs npm reports
- npm run test:e2e:mock-llm:docker script added
- .gitignore updated for docker test output dirs

The npm path (test:e2e:mock-llm) is fully backward-compatible — no env var
override needed since MOCK_LLM_AGENT_URL defaults to MOCK_LLM_BASE_URL.

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: chain Docker E2E off existing Docker CI via workflow_run

Instead of rebuilding the Docker image in the E2E workflow (duplicating
~10-15 min of Docker build time), use workflow_run to trigger automatically
after the existing 'Docker' workflow completes successfully.

The workflow now:
- Triggers on: workflow_run (Docker completed) + workflow_dispatch (manual)
- Derives the image tag from the Docker build's commit SHA
  (ghcr.io/openhands/agent-canvas:sha-<short>-amd64)
- Pulls the already-built image from GHCR — no rebuild needed
- Checks out code at the same SHA as the Docker build
- Extracts PR number from workflow_run.pull_requests[] for comments

Removed: Docker build steps, Buildx setup, build-arg resolution.
All image building stays in docker.yml where it belongs.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: replace flaky 1s timeout with polling for Active badge assertion

The 'Active badge' check in step 2 used a hardcoded 1-second
waitForTimeout before reloading. On a loaded CI runner the profile
activation mutation may not persist in time, causing the reload to
show stale state. This is a pre-existing flake (identical test code
passed on the first push and failed on the second).

Replace with expect.poll() that retries the reload+check cycle with
increasing intervals (1s, 2s, 3s) up to 15 seconds total.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: add pull_request trigger for Docker E2E (workflow_run bootstrap)

workflow_run only fires when the workflow file exists on the default
branch (main). Since mock-llm-docker-e2e.yml is new and only on the
PR branch, GitHub doesn't recognize it as a workflow_run listener yet.

Add pull_request trigger (gated by 'e2e-tests' label, skip forks) that
polls the Docker workflow via gh API until it completes for the PR's
head SHA, then pulls the already-built image from GHCR and runs tests.

After merge, workflow_run takes over as the primary automatic trigger.
The pull_request path remains as a fallback for label-gated runs.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: add FILE_STORE, AUTOMATION_BASE_URL, AUTOMATION_WORKSPACE_BASE to Docker entrypoint

The Docker entrypoint was missing several environment variables that the npm
path (dev-with-automation.mjs) sets for the automation backend:

- FILE_STORE=local — without this, the automation backend may fall back to
  cloud storage (S3/GCS) which fails without credentials, causing tarball-
  based presets (preset/prompt, preset/plugin) to silently error
- LOCAL_STORAGE_PATH — where to store files on the local filesystem
- AUTOMATION_BASE_URL — publicly-reachable base URL for callback URLs
- AUTOMATION_WORKSPACE_BASE — where automation runs unpack tarballs

This explains the Docker E2E failure: the agent's curl to create an automation
via /api/automation/v1/preset/prompt returned an error (likely 500 from missing
storage config), but the mock LLM doesn't care about terminal output and
proceeded to return the scripted final reply. The test then found 0 automations.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: exclude auth-modes spec from Docker E2E tests

The mock-llm-auth-modes.spec.ts tests npm-binary-specific --auth-required
behaviour (a second static-server instance on port 18301). The Docker image
doesn't provide this second server — it has its own auth handling. Exclude
the spec from the Docker test run via testIgnore.

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: run auth-modes tests inside Docker via PUBLIC_MODE_PORT

Instead of excluding the auth-modes spec from the Docker E2E run or
spinning up a host-side static server with a duplicate build/ directory,
the Docker entrypoint now supports an optional PUBLIC_MODE_PORT env var.

When set, entrypoint.sh starts a second static-server instance from the
same baked-in frontend assets with --auth-required (no session key
injected). This tests the actual Docker image's auth gate behaviour —
not a host-side approximation.

The Playwright Docker config passes -e PUBLIC_MODE_PORT=18301 to the
container and exports MOCK_LLM_PUBLIC_MODE_URL so the auth-modes spec
can reach it. With --network host the port is accessible from the host.

Co-authored-by: openhands <openhands@all-hands.dev>

* address review feedback: drop unlabeled trigger, improve error messages, document env vars

- Drop 'unlabeled' from pull_request trigger types to avoid wasted
  workflow runs when any label is removed (the job-level if: condition
  would skip immediately anyway)
- Distinguish 'no Docker run found' vs 'didn't complete in time' in
  the polling loop's final error message
- Add comment explaining /api/automation/v1 probe returns 200 without
  auth so the readiness check won't spin for 180s
- Document FILE_STORE, LOCAL_STORAGE_PATH, AUTOMATION_BASE_URL, and
  AUTOMATION_WORKSPACE_BASE in the entrypoint header — these affect
  production deployments, not just E2E tests

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump version to 1.0.0-beta.3

* ci: trigger CI on rel-* branch pushes for tag protection rule (#1004)

The Release Tag ruleset requires test-and-build (ubuntu) to pass
before v* tags can be pushed, but CI previously only ran on main and
pull_request events. This caused rel-* version bump commits to fail
the tag protection check unless a workaround PR was opened.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump version to 1.0.0-beta.4

* chore: auto-graduate npm dist-tag from latest to per-tier once first stable release ships (#1028)

* chore: always publish to npm with --tag latest until first stable release

All alpha/beta/rc versions now get the 'latest' dist-tag so plain
'npm install @openhands/agent-canvas' always resolves to the newest
published release. The per-tier dist-tags (alpha/beta/rc) can be
re-introduced once the first full stable version is ready to ship.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: auto-graduate npm dist-tag when first stable release ships

At publish time, query npm for any published version without a pre-release
suffix. If none exists, all releases (alpha/beta/rc/stable) use --tag latest
so plain 'npm install' always resolves to the newest build. Once a stable
version has been published, pre-release versions revert to their own
dist-tags (alpha/beta/rc) automatically — no workflow change required.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump version to 1.0.0-beta.5

* feat(mcp): render markdown links in helperText; update Slack catalog pin (#1012)

* feat(mcp): render markdown links in helperText; bump extensions to slack field-order PR commit

- Add renderHelperText() to install-server-modal.tsx that converts
  [text](url) patterns into <a> elements with target=_blank, so the
  Slack workspace-ID helper text (and any future catalog entries) can
  embed clickable docs links inline.
- Bump @openhands/extensions to commit 2d43e9c (branch
  slack-catalog-field-order-and-helper-links, PR #285) which:
    • moves SLACK_TEAM_ID before SLACK_BOT_TOKEN in the install modal
    • replaces the plain SLACK_TEAM_ID helper text with linked copy:
      'First visit [here](...#find-your-url) to get your Slack URL
       and then visit [here](...#find-your-workspace-or-org-id) to
       get your workspace ID.'
- Removes stale integrity hash from package-lock.json for the
  @openhands/extensions entry; npm install will recompute it.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump @openhands/extensions to d186872 (SLACK_BOT_TOKEN helperText)

Add inline linked helperText for SLACK_BOT_TOKEN in slack.json (PR #285,
commit d186872): 'You'll need to create or update a Slack App as shown
[here](https://github.com/zencoderai/slack-mcp-server#slack-bot-setup).'
Drops the now-redundant helperLink field.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump @openhands/extensions to b45d3a1 (SLACK_TEAM_ID helperText rewrite)

Update SLACK_TEAM_ID helperText to named links:
'First get your [Slack URL](...). Then use that to get your [Workspace ID](...).'

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump @openhands/extensions to 84a0a6e (SLACK_BOT_TOKEN named link)

Update SLACK_BOT_TOKEN helperText to:
"You'll need to create or update a [Slack App](...#slack-bot-setup)."

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump @openhands/extensions to e07f427 (SLACK_BOT_TOKEN helperText)

Update SLACK_BOT_TOKEN helperText to:
"You'll need to create or update a [Slack App](...) to get a Bot token"

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump @openhands/extensions to 5efd1b8

Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285).

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump @openhands/extensions to 952c759

Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285).

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump @openhands/extensions to f30dbfb

Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285).

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump @openhands/extensions to 02715f4

Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285).

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump @openhands/extensions to cb092c8

Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285).

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(mcp): validate URL scheme in renderHelperText; use matchAll

- Guard href against javascript:/data: XSS via /^https?:\/\//i test
- Replace exec-in-while with matchAll to drop the eslint-disable comment

Addresses review bot feedback on PR #1012.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(mcp): use double quotes for fallback href to satisfy Prettier

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: update @openhands/extensions to latest main (62594156)

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump version to 1.0.0-beta.6

* chore: bump version to 1.0.0-beta.7

* fix(mcp): drop duplicate renderHelperText after main merge

* chore: bump version to 1.0.0-beta.8

* docs: update README version to 1.0.0-beta.8

* fix: default LLM setup to Anthropic Claude Opus 4.8 (#1089)

* chore: bump version to 1.0.0-beta.9

* docs: update README version to 1.0.0-beta.9

* docs: update README.windows.md version to 1.0.0-beta.9

* fix(dev): align Vite dev origin with ingress and add chat footer padding

Route modules loaded from :3001 while the app opened on :8000, causing blank
screens on npm run dev. Point Vite server.origin/HMR at the ingress URL and add
bottom spacing under the archived conversation banner footer.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): polish spinners, settings empty states, and archived conversation UX

Remove grey track rings from all loading spinners so only the animated arc
remains visible. Wrap bare settings empty/error messages (SDK schema
unavailable, profile load failures, empty profiles/skills/secrets/MCP) in
the shared bordered empty-state container for visual consistency.

Canonicalize 127.0.0.1 backend URLs to localhost so health probes reach the
ingress proxy instead of Vite HMR on macOS dual-stack dev stacks, and sync
stored default-local backend host alongside the session key.

Disable conversation controls for archived sandboxes (MISSING/ERROR) with
tooltips explaining unavailability, using shared archive-status helpers.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): restore light foreground on conversation tab loading state

Use the semantic text-foreground token for the spinner and label so loading copy stays readable on the dark surface background.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): polish conversation tab loading and automations empty state

Conversation tab loading:
- Use TextShimmer on the loading label (same treatment as message sending)
  with block w-full text-center so the sweep flows across the word, not per
  character
- Keep the spinner on text-tertiary-light for readable secondary grey
- Add ConversationTabContentCrossfade to cross-fade between loading and loaded
  content (agent init and lazy tab chunks); content preloads underneath at
  opacity 0 while the overlay fades out over 350ms; reduced-motion falls back
  to an instant swap

Automations empty state:
- Add a top border above the create-instructions section to separate it from
  the hint copy

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): unify drawer empty/loading states and polish browser/files tabs

Align Changes, VS Code, and runtime waiting states with shared drawer patterns, add browser chrome bar with inactive nav when empty, and improve Files tab empty state and tree toggle icon.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): remove browser screenshot rounding and improve panel fill

Drop rounded corners on the screenshot viewer and use min-h-0 flex layout so the browser tab fills the drawer edge-to-edge and collapses correctly.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): polish protip banner, browser chrome, and tab crossfade

Hide non-functional browser nav controls, restyle the changes-tab protip with icon and muted subtext, drop Customize label colons, and fix Suspense fallback setState during render.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): move VS Code to files toolbar and refresh drawer icons

Relocate editor access from the drawer Code tab into a bordered Files toolbar button, swap tab icons to Lucide, add a terminal empty state, and update the VS Code logo asset.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): animate drawer tab label reveal and icon shifts

Use Framer Motion layout transitions so the active tab label expands in and sibling icons slide smoothly when switching drawer tabs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): pin VS Code in drawer tab row and fix tab drag animation

Move VS Code to the drawer header, portal the overflow menu so it is not clipped, and disable tab layout animations while resizing the panel so icons only animate on click.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ui): shrink drawer tab icons to match standard chrome size

Use h-4 w-4 for drawer tab icons so they align with the ellipsis and other inline controls in the top row.

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(home): allow changing repo, branch, or workspace before launch

Replace static git-control-bar link chips on the home screen with the same
dropdowns used in the open-workspace and open-repository dialogs so users
can revise their selection until they send the first message.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Revert "feat(home): allow changing repo, branch, or workspace before launch"

This reverts commit 569bf18bd18dbbe2bd2eaec5747737a162079e0e.

* refactor: remove unrelated files

* refactor: remove unrelated files

* refactor: remove unrelated files

* refactor: remove unrelated files

* refactor: remove unrelated files

* refactor: vscode tab

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: Tim O'Farrell <tofarr@gmail.com>
Co-authored-by: Rohit Malhotra <rohitvinodmalhotra@gmail.com>
Co-authored-by: chuckbutkus <chuck@openhands.dev>
Co-authored-by: Hiep Le <69354317+hieptl@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: hieptl <hieptl.developer@gmail.com>
2026-06-10 12:35:34 +07:00
Tim O'Farrellandopenhands 90754e2571 feat: add daily-rotating file logger for dev scripts (closes #815) (#1181)
* feat: add daily-rotating file logger for dev scripts (issue #815)

Add winston + winston-daily-rotate-file to write all dev-server log
output to logs/agent-canvas.YYYY-MM-DD.log alongside the existing
console output (which is unchanged).

- scripts/logger.mjs  — shared module; exports fileLog(level, msg)
  and stripAnsi(str). DailyRotateFile transport stores files in
  logs/ relative to the project root, rotates at midnight, and
  auto-deletes files older than 7 days.
- scripts/dev-with-automation.mjs — logService / logStep /
  logSuccess / logError each call fileLog as a side-channel. The
  shutdown message, startup title, checkPrerequisites uvx-error, and
  printBanner summary are also captured.
- scripts/dev-safe.mjs — spawnProcess errors, main() startup lines,
  the unexpected-exit error, and the fatal-error handler all call
  fileLog.
- logs/ was already in .gitignore.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: store log files in agent-canvas state dir, not project root

Use OH_CANVAS_SAFE_STATE_DIR (or ~/.openhands/agent-canvas as
the default) to match where all other agent-canvas runtime state
lives, e.g. ~/.openhands/agent-canvas/logs/agent-canvas.YYYY-MM-DD.log

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-05 10:34:30 -06:00
Tim O'Farrellandopenhands 80e01e099d fix: single-line agent-server logs in dev:automation mode (#1178)
Switch the agent-server to LOG_JSON=true so the Python SDK emits one
JSON object per log record instead of Rich-formatted output.  Rich was
wrapping long lines across multiple entries and prepending its own
timestamp on top of the HH:MM:SS [agent-server] prefix that logService
already provides.

Add parseAgentServerLogLine() which turns each JSON record into a clean
single-line string:

  INFO     127.0.0.1:51658 - "GET /api/..." 200  h11_impl.py:481

Level-based ANSI colouring is also applied (dim for DEBUG, yellow for
WARNING, red for ERROR/CRITICAL, blue for INFO) so errors still stand
out.  Non-JSON lines (e.g. startup text) fall back to the original
yellow stderr / service-colour stdout behaviour unchanged.

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-05 07:43:33 -06:00
Graham Neubig fe26cfa2e4 Allow automation CORS origin override (#1160)
Merged by request after local validation.
2026-06-04 20:35:25 -04:00
7dbe8fd7de fix: populate <RUNTIME_SERVICES> in static builds so automations work (#1125)
* fix: populate <RUNTIME_SERVICES> in static builds so automations work

The agent's <RUNTIME_SERVICES> system-prompt block is built from
VITE_RUNTIME_SERVICES_INFO, which the dev launchers set at build time.
Static builds (the Docker image and the published binary) run
`npm run build` without it, so the block is dropped and the agent does
not know how to reach the local automation backend — it falls back to
the cloud API (app.all-hands.dev) and automation creation fails.

Inject the info at serve time, mirroring the existing --session-api-key
path:

- scripts/static-server.mjs: new --runtime-services-info flag injects
  the JSON as window.__AGENT_CANVAS_RUNTIME_SERVICES_INFO__
- src/api/agent-server-adapter.ts: parseRuntimeServicesInfo() falls back
  to that window global when the env var is empty
- docker/entrypoint.sh: builds the JSON from the sandbox-facing service
  URLs (AGENT_SERVER_URL, AUTOMATION_BASE_URL) and passes it to the
  static server(s)

Refs #1098

* refactor: extract runtime-services-info into a shared module

Replace the inline JSON building in docker/entrypoint.sh with a single
source of truth for the <RUNTIME_SERVICES> shape.

buildRuntimeServicesInfo now lives in scripts/runtime-services-info.mjs
(moved out of dev-safe.mjs, which re-exports it for back-compat) and
gains:
- optional full-URL overrides (agentServerUrl, automation.url) so the
  container can pass its runtime-resolved AGENT_SERVER_URL /
  AUTOMATION_BASE_URL and use 127.0.0.1 (avoiding IPv6 loopback) instead
  of build-time ports, and
- a CLI entrypoint so docker/entrypoint.sh emits the JSON by running the
  same builder the dev stack uses, rather than a hand-rolled node -e blob.

The Dockerfile ships the new dependency-free module into the image.

* fix: pass --runtime-services-info in static mode and verify in automation e2e

- startStaticFrontend() in dev-with-automation.mjs now builds the
  runtime-services info JSON via buildAutomationRuntimeServicesInfo()
  and passes it to static-server.mjs via --runtime-services-info.
  Without this, the npm binary / dev:static path served pre-built
  frontends that never populated the agent's <RUNTIME_SERVICES>
  system-prompt block (the Docker entrypoint already did this).

- The mock-LLM automation e2e test now verifies that the
  <RUNTIME_SERVICES> block is present in the system messages sent
  to the LLM, and that it includes the expected service entries
  (Agent Server, Automation backend, /api/automation).

Co-authored-by: openhands <openhands@all-hands.dev>

* docs: update AGENTS.md with runtime-services-info plumbing changes

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: Rohit Malhotra <rohitvinodmalhotra@gmail.com>
Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-04 18:28:35 +00:00
Rohit Malhotraandopenhands b1ece3d1d3 fix: use dual-stack (::) binding for static-server to fix Docker e2e connection errors (#1104)
* fix: use dual-stack (::) binding for static-server to fix Docker e2e connection errors

The Docker e2e tests suffered frequent ECONNREFUSED errors because
static-server.mjs defaulted to 0.0.0.0 (IPv4-only), while localhost
can resolve to ::1 (IPv6) on CI runners. Meanwhile, ingress.mjs (used
by the npm path) already bound to :: (dual-stack) and never had this
problem.

Changes:
- static-server.mjs: default host from 0.0.0.0 → :: (dual-stack)
- docker/entrypoint.sh: --host 0.0.0.0 → --host :: for both
  static-server instances
- playwright.mock-llm-docker.config.ts: switch URLs from 127.0.0.1 to
  localhost (now safe since the server accepts both IPv4 and IPv6)
- playwright.mock-llm.config.ts: drop explicit --host 0.0.0.0 from
  public-mode server (inherits the new :: default)
- dev-static.mjs, dev-with-automation.mjs: drop explicit --host 0.0.0.0
  (inherits the new :: default)
- AGENTS.md: replace IPv4-only guidance with dual-stack documentation

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: skip partial-stack/cross-connect tests when build/ is absent (Docker e2e)

The partial-stack and cross-connect tests spawn bin/agent-canvas.mjs
locally, which requires a pre-built build/ directory. In the Docker e2e
workflow there is no host-side build — the frontend lives inside the
Docker image. These tests are already covered by the npm e2e workflow.

Convert the hard expect(existsSync(...)).toBe(true) assertions to
test.skip() so they are gracefully skipped instead of failing.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: add test.skip to port-conflict test for missing build dir

The port-conflict test also spawns bin/agent-canvas.mjs --frontend-only,
which fails before reaching the port conflict when no build/ exists.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: handle EPIPE/socket errors in static-server proxy to prevent crashes

The static-server reverse proxy crashed with an unhandled 'error' event
(EPIPE) when a client disconnected mid-response — e.g. during browser
navigation or health-check probes. This killed the entire process and
caused cascading ECONNREFUSED in subsequent Docker e2e tests.

Add error handlers on all piped sockets (req, res, proxySocket, socket)
so write errors from client disconnects are absorbed instead of crashing
the server process.

Also add test.skip for the port-conflict test when build/ is missing.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-03 20:54:52 +00:00
b9d78d3116 Simplify backend registry selection (#1046)
* Add partial stack modes to agent-canvas

Co-authored-by: openhands <openhands@all-hands.dev>

* Simplify backend registry selection

Co-authored-by: openhands <openhands@all-hands.dev>

* Fix backend selection CI regressions

* Seed local proxy backend in cloud tests

* Stabilize onboarding snapshot navigation

* Stabilize ingress tests on Windows

* Remove local backend fallback for cloud calls

* Fix frontend-only backend proxy target

* Test backend-only launch without build

* Add pending workflow and status updates

* Use active LLM profile for setup banner

* Show backend connection errors before saving

* Validate backend keys in health checks

* Update backend selector health test mock

* Fix frontend-only workspace path

* Preserve OpenHands proxy base URL

* Address backend review comments

* Preserve profile config when switching models

* Fail fast on profile export errors

* Throw AgentServerUnavailableError when backend registry is empty

When no backend is configured (empty registry / NO_BACKEND sentinel),
loadAgentServerInfo() was returning null without throwing, causing
OptionService.getConfig() to succeed silently. root.tsx then rendered
the home page instead of the MissingAgentServerScreen with the manage
backends modal.

Now loadAgentServerInfo() checks for the NO_BACKEND sentinel when
getEffectiveLocalBackend() returns null and throws
AgentServerUnavailableError, which root.tsx already handles by showing
the manage backends modal. The cloud-backend path (also null from
getEffectiveLocalBackend) is preserved — it still returns null.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: Remove PR-only artifacts

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: allhands-bot <allhands-bot@users.noreply.github.com>
2026-06-03 15:26:51 +00:00
8bb2b8c518 Add frontend-only and backend-only agent-canvas modes (#1040)
* Add partial stack modes to agent-canvas

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address PR review feedback (#1040)

- Replace padEnd(75) with ANSI-aware ansiPadEnd helper in printBanner;
  String.padEnd counts invisible escape bytes as visible chars, causing
  the box border to misalign in colour terminals
- Deduplicate storage directory creation in ensureDirectories; was being
  pushed once per launchAgentServer block and once per launchAutomation
  block (always both true together) — move to a shared unconditional slot
- Add explanatory comment to the checkNpm two-clause OR condition

Co-authored-by: openhands <openhands@all-hands.dev>

* test: add e2e tests for --frontend-only, --backend-only, and port conflicts

Add mock-llm-partial-stack.spec.ts with three test groups:

1. --frontend-only: verifies static frontend is served (200 on /),
   backend routes return 503 (/server_info, /api/settings,
   /api/automation/v1), and the browser shows the manage-backends modal.

2. --backend-only: verifies /server_info returns 200, /api/settings
   is reachable, automation endpoint works, and root/asset requests
   return 503 (no frontend configured).

3. Port conflict: verifies the process exits non-zero with a clear
   error when the ingress port is occupied, then starts successfully
   on a free port.

Unlike the other mock-llm specs, these tests spawn their own
bin/agent-canvas.mjs child processes with isolated state dirs and
high port numbers (18310+ range) to avoid collisions.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: adjust frontend-only test to expect SPA fallback instead of 503

In frontend-only mode the ingress has no backend routes — all requests
(including /server_info, /api/*) fall through to the static server's
default backend, which returns index.html via SPA fallback (200 with
HTML). The test now verifies that /server_info returns HTML (not JSON)
and that the browser detects the missing backend and shows the
manage-backends modal.

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: add --reject-prefix to static server for clean 503 on missing backends

In --frontend-only mode the static server was SPA-fallbacking API paths
(/server_info, /api/*, /sockets, etc.) to index.html, returning 200
with HTML content instead of a clear failure. This made the frontend's
/server_info probe ambiguous.

Add a --reject-prefix flag to static-server.mjs: any matching request
returns 503 ('Service Unavailable') before the SPA fallback runs.

Wire it through dev-with-automation.mjs: getRejectPrefixes(config)
computes which API prefixes have no backend configured (e.g. all of
them in frontend-only mode) and buildRejectPrefixArgs() passes them
as --reject-prefix flags to the static server.

Restore the e2e test to assert 503 for /server_info, /api/settings,
and /api/automation/v1 in frontend-only mode.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: treat non-401 HTTP errors from /server_info as unavailable

loadAgentServerInfo was re-throwing all SDK HttpErrors (including 503)
as-is, but root.tsx only checks for AgentServerUnavailableError. A 503
from the static server in --frontend-only mode (or any non-401 error)
would fall through to the Outlet instead of showing the manage-backends
modal.

Narrow the re-throw to only preserve 401 (needed for the auth screen in
public mode). All other HTTP errors are now wrapped as
AgentServerUnavailableError so the app shows the correct recovery UI.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: poll automation readiness in backend-only test; retry on 5xx

The automation backend starts independently from the agent-server and
may not be ready when /server_info first returns 200. pollUrl now treats
5xx responses as 'not ready yet' and keeps retrying. The backend-only
test also polls /api/automation/v1 before asserting on it.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: Rohit Malhotra <rohitvinodmalhotra@gmail.com>
2026-06-03 06:27:25 +00:00
Tim O'Farrellandopenhands 5a3011c001 fix: align dev-stack OH_PERSISTENCE_DIR and automation DB path with Docker (#960)
* fix: align dev-stack OH_PERSISTENCE_DIR and automation DB path with Docker

Two path mismatches between `npm run dev` and Docker prevented config and
automation data from being shared across the two modes:

1. **OH_PERSISTENCE_DIR wrong (supersedes PR #959)**
   Docker's entrypoint.sh sets OH_PERSISTENCE_DIR to $HOME/.openhands
   (OPENHANDS_DIR). PR #959 added the env var to buildAgentServerEnv() but
   used config.stateDir (~/.openhands/agent-canvas) — one level too deep.
   Settings and secrets written by Docker live at ~/.openhands/settings.toml
   etc; dev wrote to ~/.openhands/agent-canvas/settings.toml.
   Fix: use path.dirname(config.stateDir) = ~/.openhands, matching Docker.

2. **Automation DB in wrong directory**
   dev-with-automation.mjs put the SQLite DB at
   ~/.openhands/agent-canvas/automations.db. Docker puts it at
   ~/.openhands/automation/automations.db (from config/defaults.json
   paths.automationDb = "automation/automations.db" relative to OPENHANDS_DIR).
   Fix: use join(dirname(config.stateDir), SHARED_DEFAULTS.paths.automationDb)
   so both modes resolve to ~/.openhands/automation/automations.db.
   Also ensure the directory is created on startup (mirrors Docker's mkdir -p).

3. **Mock-LLM test cleanup**
   Update playwright.mock-llm.config.ts to clean both STATE_DIR and the new
   AUTOMATION_DB_DIR (.tmp/automation/) before each test run, since the DB now
   lives outside STATE_DIR.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: use dev_conversations dir for npm to isolate from Docker conversations

npm dev mode now writes conversations to ~/.openhands/agent-canvas/dev_conversations
instead of conversations, keeping them separate from Docker's conversations dir.

OH_CONVERSATIONS_PATH (set via buildAgentServerEnv) is the single control point;
all mkdir and releaseStaleConversationLeases calls updated to match.

Also condense verbose multi-line comments on OH_PERSISTENCE_DIR and
AUTOMATION_DB_URL to single lines.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: use join(config.stateDir, dev_conversations) in ensureDirectories

The outer config in dev-with-automation.mjs does not have conversationsPath
(that is a SafeDevConfig property). Use the same join(stateDir, ...) pattern
as the other dirs in the list.

Also removes the debug console.log and restores dev-safe.mjs and dev-static.mjs
to dev_conversations after the manual revert.

Co-authored-by: openhands <openhands@all-hands.dev>

* test: update conversationsPath assertion to match dev_conversations

The implementation in buildConfigFromPorts was changed to use
'dev_conversations' as the subdirectory name, but the corresponding
test assertion was not updated.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-02 15:26:19 +00:00
14b1b1e8ad feat: two auth modes — local (auto-key) and public (paste-key) (#790)
* feat: two auth modes — local (auto-key) and public (paste-key)

Local mode (agent-canvas, no flags):
- Ingress binds to 127.0.0.1 only
- Auto-generates session API key
- Writes /backends.json to static dir so frontend auto-authenticates
- Zero setup for localhost use

Public mode (agent-canvas --public):
- Ingress binds to 0.0.0.0 (all interfaces)
- Requires LOCAL_BACKEND_API_KEY env var
- Does NOT write /backends.json
- Frontend shows API key entry screen on 401

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: reuse BackendForm in public-mode API key entry screen

Replace the bespoke ApiKeyEntryScreen form with BackendForm configured
for the public-auth use case:

- Host field is auto-filled from window.location.origin and read-only
- Name field is hidden (auto-derived from the existing backend)
- Only the API key input is exposed to the user
- Uses the same SettingsInput / BrandButton components as the backend
  connection modals for visual consistency

BackendForm gains three optional props to support this:
- hideName: hides the name input and uses a fallback name
- hostReadOnly: disables the host input
- onSubmitPayload: receives the submitted payload for side-effects
  (the API key screen uses it to persist to agent-server-config and
  reload the page)

Co-authored-by: openhands <openhands@all-hands.dev>

* docs: update AGENTS.md with ApiKeyEntryScreen BackendForm reuse details

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: implement public mode auth flow (--public flag)

- Add --public flag to dev-with-automation.mjs and bin/agent-canvas.mjs
- In public mode: require LOCAL_BACKEND_API_KEY, use as session key,
  don't bake into frontend (no VITE_SESSION_API_KEY / --session-api-key)
- Add isAgentServerAuthError() to detect 401 from /server_info probe
- root.tsx shows ApiKeyEntryScreen when 401 detected (lazy loaded)
- useConfig skips retries on 401 for instant auth screen display
- ApiKeyEntryScreen now has default export for React.lazy compatibility

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: use VITE_AUTH_REQUIRED flag instead of 401 detection for public mode

The 401-based approach was unreliable — /server_info may not require
auth on all server versions. Instead:

- dev-with-automation.mjs sets VITE_AUTH_REQUIRED=true in public mode
- isAuthRequiredAndMissing() checks the flag + localStorage for a key
- root.tsx gates on the flag BEFORE the /server_info probe, so the
  auth screen appears instantly with zero network round-trips
- 401 fallback kept as safety net for edge cases

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: handle stale key via 401 detection in public mode

When the server restarts with a new LOCAL_BACKEND_API_KEY, the browser
still has the old key in localStorage. isAuthRequiredAndMissing() returns
false (key exists), so the /server_info probe fires and 401s.

isAgentServerAuthError() now checks VITE_AUTH_REQUIRED=true AND 401
status, so it only triggers in public mode (a 401 in local mode is a
misconfiguration, not a key-rotation event). useConfig skips retries
on 401 to show the auth screen immediately.

Two gates, one screen:
- No key at all → flag check, instant, no network
- Stale key → /server_info 401, one round-trip

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: validate stale keys against GET /api/settings (protected)

/server_info is unprotected — it returns 200 even with a wrong key.
In public mode, after the /server_info probe succeeds, we now hit
GET /api/settings to verify the stored key is still valid. A 401
from that endpoint triggers the auth screen via isAgentServerAuthError().

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: rewrite ApiKeyEntryScreen — validate before save, always empty key, match add-modal UI

Three fixes:

1. Stale key conflict: The form now always starts with an empty API key
   field instead of pre-filling from the backend registry. Stale
   credentials from a previous session never bleed into the input.

2. Wrong key indicator: On submit, the key is validated against
   GET /api/settings (protected endpoint) BEFORE persisting. Wrong
   keys show an inline red status dot + 'Invalid API key' error
   via BackendStatusDot. Only validated keys trigger the reload.

3. UI parity with add-backend modal: Replaced BackendForm wrapper
   with direct SettingsInput fields matching ManualConnectionColumn's
   layout — host (read-only + helper text), API key (password with
   placeholder), status indicator, and Connect button. No cloud
   OAuth column.

New i18n key: AUTH$INVALID_KEY (all 15 languages).

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: match add-backend modal UI + add test coverage

ApiKeyEntryScreen now renders the exact same card chrome as
BackendFormModal add-mode: same title ('Add a Backend'), same
Name/Host/API Key fields, same Connect button styling. Host is
pre-filled and read-only; no cloud OAuth column.

New tests (12 total):
- api-key-entry-screen.test.tsx (7 tests):
  - UI field parity with add-backend modal
  - Stale key wipe (empty API key field despite stale localStorage)
  - Connect disabled until name + key filled
  - Valid key: validates → persists → reloads
  - Invalid key: error indicator, no persist, no reload
  - Retry flow: wrong key → error → correct key → success
  - Stale key isolation: only fresh key persisted
- agent-server-config.test.ts (5 new tests for isAuthRequiredAndMissing):
  - Flag unset → false
  - Flag set, no key → true
  - Flag set, localStorage key → false
  - Flag set, VITE_SESSION_API_KEY → false
  - Flag not 'true' → false

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: distinguish 401 from other errors in ApiKeyEntryScreen

The catch-all was showing 'Invalid API key' for EVERY failure —
including 500s, network errors, and timeouts — even when the key
was correct. Now:

- 401 → 'Invalid API key. Please check the key and try again.'
- Anything else → 'Connection failed: <actual error message>'

This reveals the real problem when a correct key fails for a
non-auth reason (e.g. server misconfiguration, missing OH_SECRET_KEY).

New i18n key: AUTH$CONNECTION_FAILED (all 15 languages).
New test: non-401 errors show 'Connection failed' + detail.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: agent-server receives wrong session key in public mode

startAgentServer() called buildSafeDevConfig() which generated its
own random session key, ignoring config.sessionApiKey (which holds
LOCAL_BACKEND_API_KEY in public mode). The agent-server was started
with a random key while users were told to paste the LOCAL_BACKEND_API_KEY
value — every key was rejected with 401.

Fix: override OH_SESSION_API_KEYS_0 in the agent-server env with
config.sessionApiKey so both the agent-server and the frontend
agree on which key is valid.

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: address review comments on ApiKeyEntryScreen

1. Remove dead BackendFormProps (hideName, hostReadOnly, onSubmitPayload)
   — ApiKeyEntryScreen is standalone so no caller used these props.

2. Auto-generate backend name from window.location.hostname instead of
   requiring users to type one. Only the API key field is required now,
   reducing public-mode auth to a single-field flow.

3. Simplify redundant ternary: connectionStatus === 'success' ? true : false
   → connectionStatus === 'success'.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address second round of review comments

1. Use shared isSdkHttpError() helper in ApiKeyEntryScreen instead of
   duplicating the SDK error shape check inline. Exported the helper
   from agent-server-compatibility.ts.

2. Add code comment acknowledging the edge case where a network hiccup
   between /server_info and getSettings() probes lets the app load with
   an unvalidated key. Acceptable since the window is narrow and a page
   refresh recovers.

3. Add --auth-required flag to static-server.mjs so pre-built static
   binaries (npx @openhands/agent-canvas --public) show the API key
   entry screen without needing VITE_AUTH_REQUIRED baked in at build
   time. The flag injects window.__AGENT_CANVAS_AUTH_REQUIRED__=true
   into index.html at runtime. Frontend isAuthRequired() checks both
   the build-time env var and the runtime window flag.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: use double cast (unknown) to satisfy strict TS on window flag access

window cannot be cast directly to Record<string, unknown> — TypeScript
requires going through unknown first for unrelated types.

  (window as unknown as Record<string, unknown>).__AGENT_CANVAS_AUTH_REQUIRED__

This fixes the CI typecheck failure introduced in aa76c01a.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address remaining review comments on auth modes PR

- Use isAuthRequired() instead of raw import.meta.env.VITE_AUTH_REQUIRED
  in isAgentServerAuthError() so the runtime window flag injected by
  static-server.mjs in pre-built binaries is also honoured (bug fix).

- Preserve existing backend name during re-authentication flow in
  ApiKeyEntryScreen; only fall back to window.location.hostname for
  the initial entry so users don't lose custom labels on key rotation.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: restore MCP-to-integrations migration from main

A prior merge into this branch incorrectly kept the old
@openhands/extensions/mcps imports instead of the
@openhands/extensions/integrations paths introduced by d41bfe15
on main. Restore all affected files from origin/main so the
extensions package (which no longer exports ./mcps) resolves
correctly.

Files restored from main:
- src/utils/mcp-marketplace-utils.ts
- src/routes/mcp.tsx
- src/components/features/mcp-logo-badge.tsx
- src/components/features/mcp-page/* (6 files)
- src/components/features/automations/* (2 files)
- __tests__/ (4 test files)

Co-authored-by: openhands <openhands@all-hands.dev>

* style: fix prettier formatting and remove unused eslint-disable in api-key-entry-screen

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address remaining PR review comments

- Extract isSdkHttpStatusError() helper in agent-server-compatibility.ts
  to DRY up the SDK error status check (review comment #3321202503).
  Both isAgentServerAuthError() and ApiKeyEntryScreen now use it.

- Use AUTH i18n keys in api-key-entry-screen.tsx:
  • Heading: AUTH$API_KEY_REQUIRED_TITLE ('API Key Required')
  • Description: AUTH$API_KEY_REQUIRED_DESCRIPTION added below heading
  • Button: AUTH$CONNECT ('Connect')
  (review comments #3325478721, #3325478729)

- Fix nested <main> landmark in root.tsx: remove the outer <main>
  wrapper since ApiKeyEntryScreen already provides its own semantic
  container (review comment #3325478704).

- Change ApiKeyEntryScreen root element from <main> to <div> so
  the Layout's own landmarks are not violated.

Co-authored-by: openhands <openhands@all-hands.dev>

* test: add coverage for window.__AGENT_CANVAS_AUTH_REQUIRED__ runtime flag

Add isAuthRequired() test block covering the window flag path used by
pre-built static binaries (static-server.mjs --auth-required). Also add
window-flag variants to isAuthRequiredAndMissing() tests.

Addresses review comment #3325587577.

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor!: deduplicate SESSION_API_KEY into LOCAL_BACKEND_API_KEY

BREAKING CHANGE: The user-facing env var for setting the API key is now
`LOCAL_BACKEND_API_KEY` everywhere. The old `SESSION_API_KEY`,
`OH_SESSION_API_KEYS_0`, and `VITE_SESSION_API_KEY` env vars are no
longer read by launchers as user-facing configuration.

Internal plumbing (`config.sessionApiKey`, `VITE_SESSION_API_KEY` build
injection, `OH_SESSION_API_KEYS_0` agent-server env) is unchanged — only
the user-facing surface is unified into a single env var.

Changes:
- scripts/dev-safe.mjs: read LOCAL_BACKEND_API_KEY instead of
  SESSION_API_KEY / OH_SESSION_API_KEYS_0 / VITE_SESSION_API_KEY
- scripts/dev-with-automation.mjs: unify key resolution through
  buildSafeDevConfig for both public and local modes
- bin/agent-canvas.mjs: update CLI help text and examples
- docker/entrypoint.sh: read LOCAL_BACKEND_API_KEY, migrate legacy
  session-api-key.txt → api-key.txt
- scripts/static-server.mjs: add mutual-exclusion guard for
  --session-api-key + --auth-required flags
- playwright configs: pass LOCAL_BACKEND_API_KEY instead of the old trio
- test helpers: prefer LOCAL_BACKEND_API_KEY fallback chain
- Update tests and documentation

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address review comments — narrow settings probe rethrow and use shared client options

- loadAgentServerInfo: narrow getSettings() catch to rethrow only 401
  errors. Other HTTP errors (403, 5xx) and non-HTTP errors (network,
  timeout) are now swallowed with a console.warn, since the server is
  confirmed up (via /server_info) and the probe is best-effort. This
  prevents misconfigured servers from silently falling through to
  <Outlet /> without showing either the auth or unavailable screen.

- ApiKeyEntryScreen: replace hand-rolled SettingsClient options with
  getAgentServerClientOptions() so transport-level settings (e.g.
  VITE_INSECURE_SKIP_VERIFY) are honoured. Uses the sessionApiKey
  override to pass the freshly-entered key.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: rewrite git+ssh to git+https for @openhands/extensions in lockfile

npm normalizes GitHub URLs to git+ssh:// in the lockfile, but machines
without SSH keys for GitHub (or with stale npm caches) can end up
installing a wrong version of the package. This causes the Vite resolve
error:

  "./integrations" is not exported under the conditions [...]

The same pattern was already fixed for @openhands/typescript-client
(see #384). vercel-install.sh already does a blanket sed rewrite, but
the committed lockfile itself should use git+https:// so local npm ci
works without SSH keys.

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: align public auth screen with Add Backend form layout

Replace the custom 'API Key Required' screen with the same form
layout used by the 'Add a Backend' left column in BackendFormModal:

- Heading changed from 'API Key Required' to 'Add a Backend'
- Added backend Name field (required, same as ManualConnectionColumn)
- Host field remains pre-filled and disabled (from window.location.origin)
- API Key field unchanged
- Submit button now uses BACKEND$CONNECT label (matching the modal)
- Removed the subtitle description paragraph for cleaner parity
- Name is persisted to the backend registry on submit

Tests updated: fillApiKey → fillRequiredFields (name + apiKey),
assertions cover the new name field and dual-field submit gating.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: remove unused AUTH$ i18n keys from this PR

The UI refactor (02faa0b0) switched ApiKeyEntryScreen to the
BACKEND$* keys. Drop the three AUTH$ entries that were introduced
and then superseded within this same PR:

- AUTH$API_KEY_REQUIRED_TITLE
- AUTH$API_KEY_REQUIRED_DESCRIPTION
- AUTH$CONNECT

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: sync stale session API key on boot when LOCAL_BACKEND_API_KEY changes

When a user restarts the stack with a different LOCAL_BACKEND_API_KEY,
the new VITE_SESSION_API_KEY is baked in correctly, but localStorage
may still hold the old key in two places:

  1. openhands-agent-server-config.sessionApiKey (written by onboarding
     or the Settings page)
  2. openhands-backends[].apiKey (seeded on first load, never re-synced)

The existing syncDefaultLocalBackendAuth() in storage.ts already tries
to fix #2 by comparing against makeDefaultLocalBackend(), but that
function reads through getConfiguredSessionApiKey() which hits #1
(stale localStorage) before falling back to VITE_SESSION_API_KEY.
So a stale #1 defeats the #2 sync.

Fix: add syncBakedSessionApiKey() which runs from readStoredBackends()
before any key resolution. When VITE_SESSION_API_KEY is set and the
stored key in openhands-agent-server-config differs, overwrite it.
This ensures getConfiguredSessionApiKey() and makeDefaultLocalBackend()
both return the correct key, and the downstream backend-registry sync
works as intended.

Also fix the static-server.mjs injection script to always overwrite a
stored key that differs from the runtime key (was guarded by
`if(!_c.sessionApiKey)` which skipped updates when any key existed).

Add mock-LLM E2E tests for:
- Key rotation recovery: seeds stale localStorage, verifies app loads
- Public-mode auth gate: tests auth screen visibility, wrong key
  rejection, and correct key acceptance

Co-authored-by: openhands <openhands@all-hands.dev>

* docs: document key rotation resilience in AGENTS.md

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: add syncBakedSessionApiKey to vi.mock stubs and use click-then-fill in E2E

Three test files mock #/api/agent-server-config without exporting
syncBakedSessionApiKey, which storage.ts now calls at import time.
Add the missing vi.fn() stub to all three.

Also fix the public-mode auth E2E test: use the click() → fill()
pattern for React controlled inputs (matching the established
convention in mock-llm-conversation.spec.ts) so the SettingsInput
onChange fires reliably in Playwright.

Co-authored-by: openhands <openhands@all-hands.dev>

* test: add public-mode key rotation E2E test

Simulates a server key rotation: localStorage holds a stale key from
a previous session, the server now has a new key. Verifies the app
detects the 401 from the stale key probe, shows the auth screen, and
accepts the new key.

Flow: stale key in localStorage → probe /server_info → 401 →
isAgentServerAuthError → ApiKeyEntryScreen → user pastes new key →
reload → app loads normally.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(e2e): suppress consent modal in public-mode auth tests

The analytics consent modal overlays the auth screen on first visit
(clean localStorage). Playwright's click() on the form inputs was
intercepted by the modal overlay, causing a 60s timeout loop (121
retries). Add a beforeEach that seeds 'analytics-consent' and
'openhands-telemetry-consent' in localStorage before navigation.

Also deduplicate the consent seeding from the key-rotation test's
addInitScript since the beforeEach now handles it.

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: deduplicate readStoredConfig() call in syncBakedSessionApiKey

Capture the first readStoredConfig() result and reuse it in the
spread instead of hitting localStorage twice.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore(docker): remove legacy session-api-key.txt migration

The backwards-compatibility shim that migrated the old
session-api-key.txt to api-key.txt is no longer needed — a breaking
change here is acceptable.

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: dedup ApiKeyEntryScreen against BackendForm

ApiKeyEntryScreen now renders BackendForm with three new props instead
of reimplementing the name/host/API-key inputs from scratch:

- hostReadOnly: locks the host field (pre-filled from window.origin)
- requireApiKey: forces a non-empty API key for local backends
- onSubmitOverride: replaces the default sync persist with async
  server-side validation (GET /api/settings) before persisting

The auth-gate-specific chrome (full-screen wrapper, connection status
indicator, validating/error state) stays in ApiKeyEntryScreen via the
existing renderActions slot.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: chuckbutkus <chuck@openhands.dev>
2026-06-01 12:02:37 -06:00
Tim O'Farrellandopenhands eb3ae22b23 fix: fast-fail dev scripts when ports are already in use (#939)
* fix: fast-fail dev scripts when ports are already in use

Add `assertPortsFree` to `scripts/dev-safe.mjs` that checks each
preferred port and throws a descriptive error if any are already bound,
rather than silently binding to an alternative port.

- `buildSafeDevConfigAsync` now calls `assertPortsFree` before
  returning config, so `npm run dev:minimal` exits immediately with a
  clear message when the agent-server port is occupied.
- `dev-with-automation.mjs`'s `buildConfig` does the same for all four
  service ports (ingress, agent-server, automation, vite), covering
  `npm run dev` and `npm run dev:static`.
- `buildConfig` gains env-var overrides for internal service ports
  (`OH_CANVAS_SAFE_BACKEND_PORT`, `OH_CANVAS_SAFE_AUTOMATION_PORT`,
  `OH_CANVAS_SAFE_VITE_PORT`) so tests and advanced users can redirect
  ports without touching production defaults.

Tests updated accordingly:
- Old "falls back when port is busy" tests replaced with "throws when
  port is busy" equivalents.
- New `assertPortsFree` describe block with three targeted cases.
- `envWithIsolatedKeyPath` in `dev-with-automation.test.ts` now seeds
  high free ports so the pre-flight check passes when a real dev stack
  is running during local test execution.

Closes #934

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: address review bot suggestions on assertPortsFree

- Check ports in parallel with Promise.all instead of sequentially
  (each check is independent I/O, so parallel is faster and more idiomatic)
- Include vscode port in the buildSafeDevConfigAsync pre-flight check
  alongside the agent-server port, so a conflict on that internal port
  is also caught with a helpful message rather than a cryptic spawn error

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-29 17:25:52 +00:00
Rohit Malhotraandopenhands caef236c10 mock-llm e2e: use bin/agent-canvas.mjs (production binary path) (#906)
Switch mock-LLM E2E tests from npm run dev:minimal (Vite dev server +
agent-server only) to the full agent-canvas binary entry point — the same
path real users exercise when they run `npx @openhands/agent-canvas`.

This means tests now launch:
  - Pre-built static frontend (via static-server.mjs)
  - Agent-server via uvx
  - Automation backend via uvx
  - Ingress proxy unifying all routes on a single port

Changes:
- playwright.mock-llm.config.ts: replaced dev-safe.mjs webServer with
  bin/agent-canvas.mjs; single ingress port (18300) serves both the
  browser UI and proxied API calls; conditional build step for build/
- scripts/dev-with-automation.mjs: buildConfig now respects
  OH_CANVAS_SAFE_STATE_DIR from env (needed for test isolation)
- tests/e2e/mock-llm/utils/mock-llm-helpers.ts: BACKEND_URL now
  defaults to the ingress URL (API calls are proxied transparently)
- .github/workflows/mock-llm-e2e.yml: added npm run build:app step
  before tests (pre-build for CI caching)
- AGENTS.md: added Mock-LLM E2E Tests section documenting the new
  production-fidelity test architecture

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-28 19:17:59 +00:00
b570b4a2f6 fix: buildNpmScriptCommand always uses cmd.exe on Windows (#734)
* fix: buildNpmScriptCommand always uses cmd.exe on Windows

On Windows, npm sets npm_execpath to a path like
  C:\Program Files\nodejs\node_modules\npm\bin\npm-cli.js
which contains spaces. buildNpmScriptCommand was returning that
path as a spawn argument with the full node.exe path as the command.
spawnService uses shell:true on Windows, so Node.js passes the
unquoted command to cmd.exe:

  cmd.exe /d /s /c C:\Program Files\nodejs\node.exe ...

cmd.exe splits on the space and fails with
  'C:\Program' is not recognized as an internal or external command
causing Vite to exit with code 1 immediately after npm run dev.

Fix: check platform === 'win32' BEFORE checking npm_execpath so
Windows always uses the safe cmd.exe /d /s /c npm run <script> form.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: buildNpmScriptCommand always uses cmd.exe on Windows

On Windows, npm sets npm_execpath to a path like
  C:\Program Files\nodejs\node_modules\npm\bin\npm-cli.js
which contains spaces. buildNpmScriptCommand was returning that
path as a spawn argument with the full node.exe path as the command.
spawnService uses shell:true on Windows, so Node.js passes the
unquoted command to cmd.exe:

  cmd.exe /d /s /c C:\Program Files\nodejs\node.exe ...

cmd.exe splits on the space and fails with
  'C:\Program' is not recognized as an internal or external command
causing Vite to exit with code 1 immediately after npm run dev.

Fix: check platform === 'win32' BEFORE checking npm_execpath so
Windows always uses the safe cmd.exe /d /s /c npm run <script> form.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: AnimatePresence mode=wait expects one child, not two

ChatStatusIndicator had two separately-keyed motion.span children inside
<AnimatePresence mode="wait">. framer-motion's wait mode expects exactly ONE
child to exit before the next enters; two children trigger the repeated warning:
  "attempting to animate multiple children within AnimatePresence,
   but its mode is set to 'wait'"

Fix: wrap both elements in a single motion.span with unified key={status}
and className="contents" (CSS display:contents preserves flex layout).

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: set PYTHONUTF8=1 in agent-server/automation env on Windows

Python on Windows defaults to the system ANSI codepage (cp1252). The agent-server
writes metadata JSON containing emoji (e.g. U+2705 ✅) that cp1252 cannot encode,
producing UnicodeEncodeError → POST /api/conversations 500. Old UTF-8 conversation
files also fail to load at startup (UnicodeDecodeError). PYTHONUTF8=1 enables
Python's UTF-8 mode (PEP 540) for the process, matching Linux/macOS behaviour.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: set PYTHONUTF8=1 in agent-server/automation env on Windows

Python on Windows defaults to the system ANSI codepage (cp1252). The agent-server
writes metadata JSON containing emoji (e.g. U+2705 ✅) that cp1252 cannot encode,
producing UnicodeEncodeError → POST /api/conversations 500. Old UTF-8 conversation
files also fail to load at startup (UnicodeDecodeError). PYTHONUTF8=1 enables
Python's UTF-8 mode (PEP 540) for the process, matching Linux/macOS behaviour.

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: remove unrelated file

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: hieptl <hieptl.developer@gmail.com>
2026-05-28 16:29:55 +07:00
cbeeee002e fix: inject runtime session key into index.html for published binary (#795)
* fix: inject runtime session key into index.html for published binary

The globally installed agent-canvas binary starts the agent-server with a
persisted session API key (~/.openhands/agent-canvas/session-api-key.txt)
as OH_SESSION_API_KEYS_0, making auth required. However, the pre-built
static frontend in the npm package has a different (or empty)
VITE_SESSION_API_KEY baked in at publish time, so every API request gets
401 Unauthorized.

Fix: static-server.mjs now accepts --session-api-key <key> and injects a
tiny bootstrap <script> before </head> in every index.html response. The
script seeds the key into localStorage['openhands-agent-server-config']
only if no key is already stored there, so explicit user overrides (via
Settings > Agent Server) are always preserved.

dev-with-automation.mjs and dev-static.mjs both pass
--session-api-key ${config.sessionApiKey} when spawning the static server,
so the runtime key is always available regardless of what was baked into
the bundle.

Tests: added 8 new cases to __tests__/scripts/static-server.test.ts
covering parseArgs, injection in direct and SPA-fallback index.html
responses, no injection for non-html assets, cache headers, and null key.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(docker): pass runtime session key to static-server so frontend can authenticate

The entrypoint computed EFFECTIVE_SESSION_KEY and forwarded it to the
agent-server (OH_SESSION_API_KEYS_0) and automation backends, but did not
pass it to the static-server. As a result the pre-built index.html served
with no session key injected, so every browser API call received 401.

Wire --session-api-key "$EFFECTIVE_SESSION_KEY" into the static-server
launch command so the runtime key is injected into index.html responses
(via the mechanism added in this branch to static-server.mjs).

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address review suggestions on session key injection

- static-server.mjs: add comment clarifying replace() targets first
  </head> only; fall back to inserting before </body> when </head> is
  absent (avoids prepending before <!DOCTYPE html>)
- docker/entrypoint.sh: add comment documenting source of
  EFFECTIVE_SESSION_KEY before the static-server invocation
- static-server.test.ts: add test for </head>-absent fallback path
  confirming injection lands before </body>

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: Rohit Malhotra <rohitvinodmalhotra@gmail.com>
2026-05-27 11:12:23 -04:00
Rohit Malhotraandopenhands e2dd1b5f17 fix: unify session and automation API keys into a single credential with consistent header (#681)
* fix: unify session and automation API keys into a single credential

Both the agent-server and automation backend now share the same API key
value. The agent-server validates it via `X-Session-API-Key` and the
automation backend validates it via `Authorization: Bearer …` — different
header formats, same credential.

Changes:
- Frontend: automation axios client reads `VITE_SESSION_API_KEY` instead
  of the now-removed `VITE_AUTOMATION_API_KEY`
- Dev launcher: removed separate `AUTOMATION_LOCAL_API_KEY` generation
  and persistence (`automation-api-key.txt`); `localApiKey` is set to
  `sessionApiKey` so both backends receive the same value
- Static build: stopped baking `VITE_AUTOMATION_API_KEY` (the frontend
  reads from `VITE_SESSION_API_KEY`)
- Docker entrypoint: `OPENHANDS_AUTOMATION_API_KEY`,
  `AUTOMATION_LOCAL_API_KEY`, and `AUTOMATION_AGENT_SERVER_API_KEY` all
  default to the session key when not explicitly overridden
- Tests updated to verify unified key behavior

Fixes the 401 on `/api/automation/v1` when the automation backend is
running but no separate `VITE_AUTOMATION_API_KEY` was configured.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: use X-Session-API-Key header for automation backend auth (consistent with agent-server)

Switch automation backend requests from `Authorization: Bearer …` to
`X-Session-API-Key` header, matching the agent-server's auth pattern.
Both backends now authenticate using the same header and the same key
value (`VITE_SESSION_API_KEY`).

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address review — remove localApiKey alias, dead constant, add entrypoint guard

- Remove `localApiKey` from config; all call sites now use
  `config.sessionApiKey` directly, making the unified-key intent obvious.
- Delete `DEFAULT_AUTOMATION_API_KEY_PATH` constant and its export
  (no downstream consumers in beta).
- Add fail-fast guard in docker/entrypoint.sh when no session key is
  available, instead of silently exporting empty strings.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: update stale comment on AUTOMATION_LOCAL_API_KEY to reflect unified session key

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-26 22:15:27 +00:00
Hiep Le f42d684a03 fix(frontend): validate OH_AGENT_SERVER_LOCAL_PATH in dev-with-automation (#650)
* fix: validate OH_AGENT_SERVER_LOCAL_PATH in dev-with-automation

* fix: failing tests
2026-05-20 15:29:24 +07:00
Rohit Malhotraandopenhands 979e64fe19 feat: add Docker CI to build all-in-one image with agent-server + automation + frontend (#634)
* feat: add Docker CI to build all-in-one image with agent-server + automation + frontend

Adds a GitHub Actions workflow (.github/workflows/docker.yml) that builds and
publishes ghcr.io/openhands/agent-canvas — a single Docker image combining:

  1. Agent Server (ghcr.io/openhands/agent-server base image from SDK repo)
  2. Automation server (pip-installed from openhands-automation)
  3. agent-canvas frontend (static build from this repo)

The automation server is pip-installed rather than copied from its Docker image
because both services share openhands-sdk, fastapi, uvicorn, pydantic, httpx
etc. — installing into the agent-server's Python 3.13 deduplicates all shared
packages. Only automation-specific deps (asyncpg, sqlalchemy, boto3, …) are
added on top.

An entrypoint script starts all three services and a static-server proxy that
unifies them behind a single port (default 8000):
  /api/automation/* → automation backend (:18001)
  /api/*            → agent-server (:18000)
  /*                → static frontend + SPA fallback

Workflow triggers:
  - Push to main: builds and pushes with branch + SHA tags
  - v* tags (releases): also pushes semver tags (1.2.3, 1.2, 1, latest)
  - PRs: builds, pushes SHA-tagged image, updates PR description with
    pull/run instructions (same pattern as the SDK repo)
  - workflow_dispatch: supports overriding base image and automation version

Files added:
  - docker/Dockerfile (multi-stage: frontend build + agent-server base)
  - docker/entrypoint.sh (process manager for all three services)
  - .dockerignore
  - .github/workflows/docker.yml

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: build multi-arch Docker images (amd64 + arm64)

Adds QEMU setup for cross-compilation and defaults the platform matrix
to linux/amd64,linux/arm64 so the image works on both Intel and Apple
Silicon machines.

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: rewrite Docker workflow to match SDK repo structure

Replace the single-job QEMU approach with the same architecture-matrix
pattern used by the SDK repo's server.yml:

  1. build-and-push-image — matrix over {amd64, arm64} with native runners
     (ubuntu-24.04 for amd64, ubuntu-24.04-arm for arm64). Each job pushes
     arch-suffixed tags (e.g. sha-abc1234-amd64) and uploads build-info
     artifacts.

  2. merge-manifests — downloads both arch build-infos, strips the -amd64
     suffix from amd64 tags to derive manifest tags, and creates multi-arch
     manifests via `docker buildx imagetools create`.

  3. consolidate-build-info — aggregates all build-info and manifest-info
     artifacts into a single JSON summary (PR-only).

  4. update-pr-description — renders the summary into the PR body between
     AGENT_CANVAS_DOCKER_START/END markers.

Native runners avoid the 3-5× slowdown of QEMU emulation for arm64
builds.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: sanitize branch names in Docker tags (/ is not allowed)

Branch names like 'feat/docker-ci' produce invalid Docker tags because
'/' is forbidden in tag names. Replace '/' with '-' so the tag becomes
'feat-docker-ci-amd64'.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: default automation to SQLite and fix wait blocking proxy startup

Two bugs:

1. The automation server defaults to PostgreSQL on localhost, which
   doesn't exist in the all-in-one container. Default AUTOMATION_DB_URL
   to sqlite+aiosqlite:// so it works out of the box. Users can override
   with a real Postgres URL for production.

2. The bare 'wait' command waited for ALL background children — including
   the long-running agent-server and automation processes — so the
   static-server/proxy on port 8000 never started. Fix by waiting only
   for the wait_for_port subshell PIDs.

Verified locally: all three services start, endpoints respond correctly,
no more scheduler ConnectionRefusedError.

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: add VOLUME directives for persistence and project mounts

Declare /home/openhands/.openhands (settings, secrets, conversations,
automation SQLite DB) and /projects (user code) as Docker volumes so
data survives container restarts by default. Users should bind-mount
these for durable persistence:

  docker run -v ~/.openhands:/home/openhands/.openhands \
             -v ~/projects:/projects \
             -p 8000:8000 ghcr.io/openhands/agent-canvas

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: set OH_SECRET_KEY default and pre-create persistence dirs

Three issues fixed:

1. OH_SECRET_KEY was not set → agent-server refused to return encrypted
   secrets → conversation creation failed with 503. Set the same static
   default used by dev-safe.mjs / dev-docker.mjs.

2. Persistence dirs (conversations, bash_events, automation DB) were not
   pre-created → the openhands user got PermissionError when the VOLUME
   directive created them as root. Pre-create with correct ownership
   before the USER switch in the Dockerfile.

3. Set OH_PERSISTENCE_DIR, OH_CONVERSATIONS_PATH, OH_BASH_EVENTS_DIR
   defaults in the entrypoint (matching dev-docker.mjs) so data lands
   under the well-known ~/.openhands tree.

Verified locally: all three services start clean, no warnings about
OH_SECRET_KEY, SQLite migrations apply successfully.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: merge main and remove stale dev-docker.mjs references

Main removed scripts/dev-docker.mjs (Docker is no longer a dependency of
the npm package flow). Update comments in docker.yml, entrypoint.sh, and
AGENTS.md that referenced the deleted file.

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: centralize config into config/defaults.json (single source of truth)

All version pins, port defaults, persistence paths, package names, and
the dev secret key now live in config/defaults.json. Consumers read from
it instead of hardcoding values:

- scripts/dev-safe.mjs: reads via JSON.parse(readFileSync(...))
- scripts/dev-with-automation.mjs: same
- scripts/check-sdk-version-sync.mjs: same (no longer regex-parses JS)
- docker/Dockerfile: config-gen build stage converts JSON to
  /opt/agent-canvas/defaults.env (shell-sourceable)
- docker/entrypoint.sh: sources defaults.env at startup; also adds
  session API key auto-generation so the image doesn't run wide-open
- .github/workflows/docker.yml: reads versions from JSON in a setup
  step (no more hardcoded env vars)

To bump a version, edit config/defaults.json only.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address PR review feedback (#634)

- Fix PID tracking bug: move PIDS+=($!) inside if/elif branches so the
  else (automation-not-found) path doesn't add a stale PID
- chmod 600 session API key file to prevent credential leak
- Warn when using insecure default OH_SECRET_KEY in Docker entrypoint
- Add try/catch + field validation for config/defaults.json loading in
  check-sdk-version-sync.mjs
- Fix semver tag parsing: strip pre-release/build metadata, only create
  abbreviated tags (major.minor, major, latest) for stable releases
- Sanitize branch names for Docker tags (tr invalid chars, strip leading
  dot/dash) to handle branches with #, @, spaces, etc.
- Add arch validation before manifest merge (assert both amd64.json and
  arm64.json exist)
- Remove $schema reference to non-existent defaults.schema.json

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: remove hardcoded version defaults from Dockerfile

Replace hardcoded ARG defaults (AGENT_SERVER_IMAGE, AUTOMATION_VERSION)
with empty ARGs. Values are always derived from config/defaults.json:
- CI: reads JSON in the workflow config step, passes --build-arg
- Local: new scripts/docker-build.mjs helper reads JSON and invokes
  docker build with the correct --build-arg values

Added npm run build:docker convenience script.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: stabilize snapshot tests and auto-generate Docker secret key

Two fixes:

1. **Flaky snapshot tests**: The 'Local pagination fixture' mock conversation
   used a fixed absolute timestamp (PAGINATION_BASE_TIME = May 13, 2026) for
   its created_at/updated_at, while 'Errored Project' used a relative
   timestamp (now - 7d). As real time progressed past the crossover point,
   their sort order in the sidebar flipped, causing 30/73 snapshot diffs on
   every PR. Fix: use relative timestamps (now - 6d) for the pagination
   fixture's conversation listing fields. The internal event timestamps
   (used by pagination tests) still use PAGINATION_BASE_TIME — only the
   sidebar ordering is affected.

2. **Docker OH_SECRET_KEY**: The entrypoint used a static insecure default
   for OH_SECRET_KEY and warned about it. Now mirrors the session API key
   pattern: auto-generate a cryptographic random key on first run, persist
   it to ~/.openhands/agent-canvas/secret-key.txt, and reuse on restart.
   Users can still override via the OH_SECRET_KEY env var. Removed the
   now-unused CONFIG_SECRET_KEY from the Docker defaults.env generation.
   Also deduped STATE_DIR computation (was repeated for session key path).

Co-authored-by: openhands <openhands@all-hands.dev>

* docs: update AGENTS.md with mock timestamp and Docker secret key notes

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: include canvas_ui tool in Docker image

The Docker image was missing the tools/ directory and OH_EXTRA_PYTHON_PATH,
so the agent-server couldn't import canvas_ui_tool.py when the frontend
sent canvas_ui in the conversation tools list. This caused:

  HTTP 500: ToolDefinition 'canvas_ui' is not registered

Fix: COPY tools/ into the image and set OH_EXTRA_PYTHON_PATH in the
entrypoint, matching what scripts/dev-safe.mjs already does for local dev.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-20 04:24:45 +00:00
Rohit Malhotraandopenhands edb998220a Remove Docker dependency from dev workflow (#635)
- Delete scripts/dev-docker.mjs and its test
- Simplify package.json: 'npm run dev' now runs local uvx stack directly
  (agent-server + automation + Vite + ingress), no Docker needed
- Remove dev:docker, dev:docker:dynamic, dev:dangerously-dockerless scripts
- Add dev:static for production-build frontend variant
- Update bin/agent-canvas.mjs CLI to use uvx-based stack
- Rename Docker-specific variables: DOCKER_PROJECTS_PATH → PROJECTS_PATH,
  shouldDefaultToDockerProjects → shouldDefaultToProjectsPath
- Update i18n: HOST_HOME_NOT_MOUNTED_HINT no longer references Docker
- Update all docs (README, DEVELOPMENT, SELF_HOSTING, AGENTS.md, CHANGELOG)
- Rename e2e snapshot: docker-workspace-browser → projects-workspace-browser
- Fix all tests to reflect new script names and remove Docker references

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-19 15:27:25 -04:00
90ad71dbd9 Add recommended automations and MCP marketplace setup flow (#504)
* Add recommended automations marketplace flow

Co-authored-by: openhands <openhands@all-hands.dev>

* Update GitHub MCP QA findings

Co-authored-by: openhands <openhands@all-hands.dev>

* Polish MCP and automation marketplace UI

Add a shared MCP logo badge, make marketplace cards more compact, and show required MCP logos prominently on recommended automation cards. Update the extensions package lock to the per-entry catalog split and save QA screenshots/results in .pr/.

Co-authored-by: openhands <openhands@all-hands.dev>

* Align recommended automations styling

Remove the custom gradient treatment and match the recommended automation cards and setup modal to the existing Automations and MCP page surfaces, spacing, borders, and typography.

Co-authored-by: openhands <openhands@all-hands.dev>

* Show existing automations before recommendations

Move the recommended automations section below the current automation list and creation guidance so the page prioritizes the user existing automation state.

Co-authored-by: openhands <openhands@all-hands.dev>

* Add recommendations to onboarding

Show recommended automations below the Say Hello input so new users can launch a curated automation from the final onboarding step.

Co-authored-by: openhands <openhands@all-hands.dev>

* Use extensions MCP marketplace exports

Remove the local MCP marketplace wrapper and consume MCP catalog data plus logo mappings directly from @openhands/extensions/mcps.

Co-authored-by: openhands <openhands@all-hands.dev>

* Archive previous PR QA and add refreshed artifacts

Co-authored-by: openhands <openhands@all-hands.dev>

* Add scheduled automation QA evidence

Co-authored-by: openhands <openhands@all-hands.dev>

* Streamline recommended automation launch

Co-authored-by: openhands <openhands@all-hands.dev>

* Refresh QA evidence and remove old artifacts

Co-authored-by: openhands <openhands@all-hands.dev>

* Ensure canvas tools are on Python path

* Require MCP installs before launching recommendations

* Remove archived PR artifacts

* Drop redundant PYTHONPATH launcher changes

* Inline recommended automation catalog

* Point extensions dependency at main

* Augment recommended automation prompts with explicit API instructions

When a recommended automation is selected, the pre-filled prompt now
includes backend-specific API instructions so the agent calls the
correct endpoint:

- Local backends: directs the agent to use the local automation API
  from <RUNTIME_SERVICES> with $OPENHANDS_AUTOMATION_API_KEY auth,
  and explicitly tells it NOT to call the cloud API at app.all-hands.dev.

- Cloud backends: directs the agent to use the OpenHands Cloud
  Automations API at app.all-hands.dev with Bearer $OPENHANDS_API_KEY.

The buildAutomationPrompt() helper is exported for testability.
Three new unit tests cover both backend kinds and prompt preservation.

Co-authored-by: openhands <openhands@all-hands.dev>

* Fix recommended automation launch regressions

Co-authored-by: openhands <openhands@all-hands.dev>

* Expose local automation API key to agent terminals

Co-authored-by: openhands <openhands@all-hands.dev>

* Stabilize conversation panel stop menu test

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: Remove PR-only artifacts

* fix: pin @openhands/extensions to specific commit for reproducibility

Updates the dependency from #main to the exact commit SHA
(3bba8e3b) that contains the MCP and automation catalogs
added in extensions#237.

This ensures reproducible builds since npm ci will use the
locked SHA instead of potentially picking up a newer main.

* Address final automation marketplace review comments

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: allhands-bot <allhands-bot@users.noreply.github.com>
2026-05-19 15:04:53 -04:00
Tim O'Farrellandopenhands 1ee1de48cd fix(dev:docker): use localhost for AUTOMATION_AGENT_SERVER_URL, separate sandbox URL (#609)
The previous attempt (#603) collapsed the host-side and sandbox-side
agent-server URLs onto a single value, `host.docker.internal:<hostPort>`,
on the assumption that the host's /etc/hosts would alias it back to
loopback. That holds on Docker Desktop macOS but NOT on OrbStack / colima
/ Linux hosts, where `host.docker.internal` only exists inside
containers. On those hosts the automation backend (which runs on the
host via uvx) fails to resolve the URL on its very first `_upload`
call:

  [Errno 8] nodename nor servname provided, or not known

so dispatch never reaches `_start_bash`, and every automation run ends
up with `bash_command_id: NULL`.

Fix:

* Restore `AUTOMATION_AGENT_SERVER_URL` to `http://localhost:<hostPort>`
  in every mode. localhost on the host always resolves to the published
  agent-server port; this is the URL the *backend* uses for HTTP calls.
* Add a new launcher option `sandboxAgentServerUrl` that is exported
  as `AUTOMATION_SANDBOX_AGENT_SERVER_URL`. The automation backend
  (OpenHands/automation#125) uses this to override the AGENT_SERVER_URL
  it exports into the in-sandbox bash chain. In dev:docker this is
  `http://127.0.0.1:8000` — the agent-server's in-container loopback,
  which avoids bouncing through the host port-forward.
* Plumb `sandboxAgentServerUrl` through dev-with-automation.mjs::main
  (mirrors the existing `automationApiHost` / `automationWorkspaceBase`
  pattern) and set it in dev-docker.mjs.
* Older automation backends that don't recognise
  AUTOMATION_SANDBOX_AGENT_SERVER_URL ignore it and fall back to
  AUTOMATION_AGENT_SERVER_URL, so this is forward-compatible.

Dockerless modes (`dev`, `dev:automation`) leave
`sandboxAgentServerUrl` undefined; the backend falls back to
AUTOMATION_AGENT_SERVER_URL, which is correct for them.

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-18 19:31:42 -06:00
Tim O'Farrellandopenhands 2ac97d1bd8 fix(dev:docker): container-safe automation paths, hostnames, and AGENT_SERVER_URL alias (#603)
* fix(dev:docker): set AUTOMATION_WORKSPACE_BASE to a container-safe path

When agent-canvas is started via `npm run dev:docker`, the agent-server
runs in a container but the automation backend runs on the host via uvx.
The dispatcher resolves `AUTOMATION_WORKSPACE_BASE` on the host (where
it expands to the host's $HOME, e.g. /Users/<you>/.openhands/...) and
then embeds that absolute path into a `mkdir -p ...` shell command
that is executed *inside* the agent-server container. The container
has no /Users directory and the non-root user can't write to /, so
every preset automation fails with:

  mkdir: cannot create directory '/Users': Permission denied

Fix:
* Thread a new `automationWorkspaceBase` option through the launcher
  (mirroring the existing `viteWorkingDir` pattern).
* `dev-docker.mjs` now passes `CONTAINER_WORKSPACES_DIR` — the same
  in-container path already used as the agent-server's working-dir
  root, so it's guaranteed to exist and be writable.
* Resolution order for `AUTOMATION_WORKSPACE_BASE` is now:
  1) explicit user env var (wins over everything; previously the
     hard-coded value silently clobbered user-set values)
  2) launcher-provided default (container-safe in docker mode)
  3) host-side fallback under config.stateDir (unchanged for dockerless)

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(dev:docker): route AUTOMATION_BASE_URL through host.docker.internal

In `npm run dev:docker`, the automation backend's `AUTOMATION_BASE_URL`
was hard-coded to `http://localhost:${ingressPort}`. That URL is then:

  1. propagated into each automation sandbox as `AUTOMATION_API_URL`
     (dispatcher.py:213), and
  2. consumed by the auto-generated `setup.sh` inside the sandbox to
     hit `${AUTOMATION_API_URL}/sdk-version`.

The sandbox is a separate Docker container, so `localhost` resolves to
the sandbox itself, not the host ingress. Every preset automation run
therefore failed at the very first step with:

  [setup] ERROR: Failed to fetch SDK version from
  http://localhost:8000/api/automation/sdk-version

Reachability check from inside a container in the same network:

  http://localhost:8000/api/automation/sdk-version          -> 404
  http://host.docker.internal:8000/api/automation/sdk-version -> 200

Fix (mirrors the existing `automationWorkspaceBase` plumbing for the
same host-vs-container class of bug):

* New `automationApiHost` launcher option threaded through main() and
  stamped onto config.
* `dev-docker.mjs` passes `automationApiHost: "host.docker.internal"`.
* `startAutomationBackend` resolves `AUTOMATION_BASE_URL` with
  precedence: user env > launcher-provided host > `localhost`.

Dockerless modes (`dev`, `dev:automation`) are unaffected — they
don't pass `automationApiHost` and fall back to the existing
`http://localhost:${ingressPort}` value.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(dev:docker): expose AGENT_SERVER_URL and SESSION_API_KEY aliases to the sandbox

The OpenHands SDK boilerplate emitted by automation prompt/plugin presets
reads AGENT_SERVER_URL and SESSION_API_KEY in main.py / setup.sh when
calling back into the agent-server from an automation run. The
agent-server itself sets OH_INTERNAL_SERVER_URL at startup and we set
OH_SESSION_API_KEYS_0 via the container/process env, but neither of the
unprefixed aliases the SDK actually reads were defined — so every preset
automation hit ECONNREFUSED / 401 the moment its setup.sh tried to hit
the agent-server.

Mirror the values under their canonical SDK names in both the dockerless
buildAgentServerEnv() (covers dev / dev:automation) and in dev-docker.mjs
containerEnv (covers dev:docker). Inside the dev:docker container the
agent-server always listens on port 8000, and 0.0.0.0 normalises to
127.0.0.1 (matching the agent-server's own OH_INTERNAL_SERVER_URL
construction), so the docker path uses http://127.0.0.1:8000 directly.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(dev:docker): route AUTOMATION_AGENT_SERVER_URL via host.docker.internal

This env var plays a dual role: the automation backend uses it directly
to call the agent-server's upload/bash REST APIs (host-side), and the
same value is exported as AGENT_SERVER_URL into the in-sandbox bash
command that main.py uses to call back. In dev:docker the script runs
inside the agent-server container, so the URL has to be reachable from
both sides.

http://localhost:${agentServerPort} was fine for dockerless modes
(both backend and agent-server live on the host) but broke dev:docker:
from inside the container localhost:${hostPort} doesn't resolve, and
`main.py` failed at the first RemoteWorkspace call.

Reuse the same automationApiHost launcher option already plumbed for
AUTOMATION_BASE_URL (Bug 2): dev:docker passes host.docker.internal, so
the URL works as a loopback alias from the host and bounces back into
the container via the published port-forward from the sandbox side.
Dockerless modes keep the previous `localhost` default.

Co-authored-by: openhands <openhands@all-hands.dev>

* revert: drop SESSION_API_KEY alias from agent-server env

The OpenHands SDK's sanitized_env() strips SESSION_API_KEY from every
bash subprocess as a (cosmetic) defense-in-depth measure, so setting
this alias on the agent-server's process env had no effect on what the
sandbox script actually sees. Worse, it created cross-purposes between
the dev stack (which exports it) and the SDK (which strips it).

Keep the AGENT_SERVER_URL alias — that one is genuinely needed and
isn't subject to filtering. SESSION_API_KEY is now obtained inside the
sandbox script via OH_SESSION_API_KEYS_0 (handled in an accompanying
PR against openhands/automation), which the SDK does not strip.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-18 16:32:38 -06:00
Tim O'Farrellandopenhands b2b71855c6 feat(dev): surface dev-stack runtime services in agent system prompt (#503)
* feat(dev): surface dev-stack runtime services in agent system prompt

Add a structured 'runtime services' info object that the dev launchers
(`dev:safe`, `dev:automation`, `dev:docker`, and the published
`agent-canvas` binary) propagate to the frontend via
`VITE_RUNTIME_SERVICES_INFO`. The frontend renders it into a
`<RUNTIME_SERVICES>` markdown block and attaches it as
`AgentContext.system_message_suffix` on every `POST /api/conversations`.

This means agents start each conversation knowing exactly what services
exist in the current dev stack (ingress URL, automation backend URL +
`/api/automation` prefix, auth header, etc.), instead of having to probe
or — worse — assume `localhost:8000` is the automation server when it is
actually the Agent Server they are running inside of.

URLs are written from the agent's point of view: dockerless modes use
`localhost`, `dev:docker` uses `host.docker.internal`. When automation
isn't running in the current mode (e.g. `dev:safe`), the block says so
explicitly so agents know to skip `/api/automation` calls.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(runtime-services): address review feedback on PR #503

- Validate required `agentServerPort` in `buildRuntimeServicesInfo`;
  previously a missing port baked `http://localhost:undefined` into
  the agent's system prompt.
- Skip the automation entry when the supplied `automation` object has
  no `port` (e.g. a bare `{}` from a misconfigured launcher).
- Rename the JSON service key from `vite` to `frontend` and add a
  `kind: "vite" | "static"` discriminator + mode-aware description,
  so static-build dev stacks (`dev:docker`, the published binary, ...)
  no longer surface a misleading "Vite dev server" line in the agent
  system prompt. The renderer still accepts the legacy `vite` key.
- Anchor the "don't guess" warning to the actual agent-server URL from
  runtime info instead of hardcoded `localhost:8000`, since the
  agent-server uses different ports across dev modes (18000 in
  dev:safe, 8000 in dev:docker, ...).
- Plumb `frontendKind` through `buildAutomationRuntimeServicesInfo`
  and stamp `config.frontendKind` in `dev-with-automation.mjs::main`
  so both Vite spawn and static-build paths describe the frontend
  correctly.
- Expand AGENTS.md with the JSON schema of `VITE_RUNTIME_SERVICES_INFO`
  and a concrete example of the rendered `<RUNTIME_SERVICES>` block.
- Tests: assert the new URL-in-warning behavior, the new `frontend` /
  legacy `vite` rendering, the `agentServerPort`-required guard, the
  `automation: {}` skip, and the legacy `vitePort` alias.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-15 20:53:45 -06:00
Tim O'Farrellandopenhands 4db59b8b94 Proxy agent-server FastAPI docs (/docs, /redoc, /openapi.json) through the ingress (#501)
* feat(ingress): route /docs to the agent server

Add /docs to the list of prefixes proxied to the agent-server in:
  - vite.config.ts (Vite dev server proxy)
  - scripts/dev-with-automation.mjs (ingress + static-server fallback)
  - scripts/dev-static.mjs (ingress + static-server fallback)

Update the explanatory comment in scripts/static-server.mjs to match.

This exposes the agent-server's FastAPI Swagger UI at `/docs` on the
ingress port, alongside the automation backend's existing
`/api/automation/docs`.

Co-authored-by: openhands <openhands@all-hands.dev>

* feat(ingress): also route /redoc and /openapi.json to the agent server

Without /openapi.json, the Swagger UI page served at /docs (added in the
previous commit) renders but fails to load any spec. /redoc is the
FastAPI-served ReDoc alternative and benefits from the same fix.

Routes are added everywhere /docs already is:
  - vite.config.ts (Vite dev server proxy)
  - scripts/dev-with-automation.mjs (ingress + static-server fallback)
  - scripts/dev-static.mjs (ingress + static-server fallback)

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-15 18:46:13 -06:00
Hiep Le 2d5a52d4be chore: bump agent-server default to 1.22.1 (#477)
* chore: bump agent-server default to 1.22.1

* chore: update OH_AUTOMATION_VERSION

* chore: update DEFAULT_AUTOMATION_SDK_VERSION
2026-05-16 02:38:59 +07:00
2899c7b383 Fix static automation auth and switch LLM tool (#474)
* Fix static automation auth and switch LLM tool

* Allow automation SDK release lag in sync check

* chore: update baseline snapshots [skip ci]

* chore: trigger CI after snapshot update

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-05-15 15:30:29 +00:00
Xingyao Wangandopenhands e5711e74b2 Clean up dev stack process trees on shutdown (#475)
Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-15 10:48:28 -04:00
Graham Neubigandopenhands a4089e0e4a Default user launchers to static frontend (#434)
Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-14 18:18:36 +00:00
Graham Neubigandopenhands 5ccc8e627c Fail fast when frontend deps are missing (#404)
Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-14 10:32:03 -04:00
Graham Neubigandopenhands 12bd8171cb Fix automation agent-server auth (#410)
Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-13 00:02:09 -04:00
Rohit Malhotraandopenhands 4738f5b7c6 Add npm publish workflow and release infrastructure (#330)
* Add npm publish workflow and release infrastructure

- Add .github/workflows/npm-publish.yml for automated npm publishing on GitHub releases
- Update CI to verify library build (npm run build:lib) and package contents
- Add CHANGELOG.md for version history tracking
- Update README.md with npm installation and usage documentation

Closes #197

Co-authored-by: openhands <openhands@all-hands.dev>

* correct package version

* chore: update npm-publish workflow for trusted publishing

- Remove NODE_AUTH_TOKEN secret dependency
- Keep id-token: write permission for OIDC
- Add provenance flag for npm attestations
- Add comment explaining trusted publisher setup on npmjs.com

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: add CLI entry point for npx execution

- Add bin/agent-canvas.mjs as executable CLI
- Add bin field to package.json for npm bin linking
- Include bin/ and build/ directories in published files
- CLI serves the built application with SPA routing support
- Supports --port, --host, and --help options

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: consolidate npm executable to use dev-docker infrastructure

- bin/agent-canvas.mjs now uses dev-with-automation.mjs main() with
  dev-docker.mjs's Docker-specific agent-server starter
- Added --static and --static-dir support to dev-with-automation.mjs
  so the npm executable serves pre-built static assets instead of Vite
- Added startStaticFrontend() function that uses static-server.mjs
- npm executable runs full stack: Docker agent-server + uvx automation
  backend + static frontend + ingress proxy

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: include scripts/ in npm package files

The bin/agent-canvas.mjs executable imports from scripts/dev-with-automation.mjs
and scripts/dev-docker.mjs, so the scripts directory must be included in the
published package.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address review comments

- Fix CHANGELOG.md version mismatch: 1.6.0 -> 1.0.0-alpha.1 to match package.json
- Add NODE_AUTH_TOKEN env var to npm-publish workflow for authentication
- Add CLI entry point mention to CHANGELOG

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: use OIDC trusted publishing (no NPM_TOKEN needed)

npm trusted publishing with OIDC doesn't require NODE_AUTH_TOKEN.
Instead it uses short-lived OIDC tokens generated by GitHub Actions.

Requirements:
- id-token: write permission (already set)
- npm CLI 11.5.1+ (added npm install -g npm@latest step)
- Trusted publisher configured on npmjs.com

See: https://docs.npmjs.com/trusted-publishers/

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump version to 1.0.0-alpha.2

Co-authored-by: openhands <openhands@all-hands.dev>

* Build app assets before npm publish

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: use Node 24 for npm trusted publishing

Trusted publishing requires Node 22.14.0+ and npm 11.5.1+.
Node 24 ships with npm 11.x which meets the requirement.
Node 22.12.0 (previous) ships with npm 10.x which doesn't support OIDC.

Also removed the manual npm upgrade step since Node 24 includes
a compatible npm version by default.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: align all workflows to Node 24 and regenerate lockfile

- Update ci.yml to use Node 24
- Update sdk-version-sync.yml to use Node 24
- Regenerate package-lock.json with npm 11.12.1

All workflows now use Node 24 which ships with npm 11.x,
required for OIDC trusted publishing (npm 11.5.1+).

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: remove incorrect LLM env vars from CLI help

LLM_MODEL and LLM_API_KEY were listed in the help text but aren't
actually used by the scripts. LLM settings are configured through
the web UI settings page instead.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address PR review feedback

Critical fixes:
- Guard prepare script to only run in dev context (check for ../.git)
- Add missing existsSync import in dev-with-automation.mjs

Workflow improvements:
- Update checkout/setup-node actions to v6 for consistency
- Add npm version validation (must be 11.5.1+ for trusted publishing)
- Add package version validation (must match release tag)

CLI improvements:
- Add try-catch for dynamic imports with helpful error message
- Use console.error directly instead of imported logError/c

Documentation:
- Fix README export names: ChatInterface→ChatPanel, Terminal→TerminalPanel
- Add dist/ to .gitignore

Co-authored-by: openhands <openhands@all-hands.dev>

* ci: trigger npm publish on tag push instead of release

Simpler workflow - just push a tag like v1.0.0-alpha.2 to publish.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: remove tarball and add *.tgz to gitignore

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: npm publish errors

1. Fix bin path - remove './' prefix (npm pkg fix)
2. Add --tag for prerelease versions (alpha/beta/rc)

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: add repository field for npm provenance verification

npm provenance requires repository.url to match the GitHub Actions
source. Also added description, homepage, and bugs fields.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-12 01:52:32 -04:00
Rohit Malhotraandopenhands 773cc72324 feat: update SDK to 1.22.0 and add CI version sync check (#333)
* feat: update SDK to 1.22.0 and add CI version sync check

- Update DEFAULT_AGENT_SERVER_VERSION from 1.21.1 to 1.22.0 in dev-safe.mjs
- Update SDK version references in AGENTS.md
- Add scripts/check-sdk-version-sync.mjs to verify automation project uses
  matching SDK versions for openhands-sdk, openhands-tools, openhands-workspace,
  and openhands-agent-server
- Add .github/workflows/sdk-version-sync.yml CI workflow with:
  - Path-filtered PR/push triggers for version-related file changes
  - repository_dispatch triggers (sdk-version-check, sdk-release) for
    external repos to notify when SDK deps change
  - workflow_dispatch with optional version override
  - Scheduled runs every 6 hours to catch upstream changes
  - PyPI version checking support (--check-pypi flag)

The check script supports:
- EXPECTED_SDK_VERSION env var override for CI triggers
- --check-pypi flag to also display latest PyPI versions
- --help for usage documentation

To trigger from external repos (e.g., OpenHands/automation or SDK repo):
  curl -X POST -H "Authorization: token \$GITHUB_TOKEN" \\
    https://api.github.com/repos/OpenHands/agent-canvas/dispatches \\
    -d '{"event_type": "sdk-version-check"}'

* fix: check released PyPI version instead of GitHub main branch

The SDK version sync check now fetches dependencies from the released
openhands-automation package on PyPI (version specified by
DEFAULT_AUTOMATION_VERSION in dev-with-automation.mjs) rather than
fetching pyproject.toml from the GitHub main branch.

This ensures we're checking the actual released version that users
would install, not the development version on main.

* fix: address review feedback for SDK version sync check

- Add env var overrides for automation package name and version
- Add retry logic with exponential backoff for PyPI API failures
- Add semantic version normalization for comparing versions
- Fix repository_dispatch to use client_payload.version
- Improve regex to handle parenthesized dependency formats
- Add comprehensive test coverage for helper functions

* fix: add type casts for dynamic module import in tests

* chore: update automation version to 1.0.0a2

- Update DEFAULT_AUTOMATION_VERSION in dev-with-automation.mjs
- Update AGENTS.md documentation
- Update test expectation

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-11 15:39:17 -04:00
Xingyao Wangandopenhands 18e51fa84d fix: move TMUX_TMPDIR to /tmp to avoid socket errors on mounted volumes (#325)
* fix: move TMUX_TMPDIR to /tmp to avoid socket errors on mounted volumes

Some filesystems (NFS, CIFS, certain FUSE/overlay mounts used by Docker
bind-mounts) do not support Unix domain sockets. When TMUX_TMPDIR pointed
to ~/.openhands/agent-canvas/tmux/ inside a container, tmux failed with:

  error connecting to .../tmux-10001/openhands (Operation not supported)

Move tmux socket directory to /tmp/openhands-agent-canvas-tmux which is
always on a local/tmpfs filesystem that supports Unix sockets. Tmux
sockets are ephemeral and don't need persistence across restarts.

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: drop explicit TMUX_TMPDIR from dev-docker.mjs, use system default

Per review feedback — the container's default TMUX_TMPDIR (/tmp) already
supports Unix domain sockets, so there's no need to set it explicitly.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-11 13:37:25 -04:00
Hiep Le 137fbae87f fix: pass container workspaces path as VITE_WORKING_DIR (#259) 2026-05-10 15:56:33 +07:00
Robert Brennanandopenhands 96ca8ebfe1 fix automation script (#237)
Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-09 13:00:20 -07:00
Robert Brennanandopenhands 157f394c62 docs: document dockerized dev setup as default (#232)
* docs: document dockerized dev setup as default

Add dev:docker npm script and update README to recommend the dockerized
agent-server workflow as the default, moving the direct-execution path to
an 'advanced' section with the existing filesystem-access warning.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix docker script

* more docker fixes

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-09 12:07:29 -07:00
Rohit Malhotraandopenhands 3207d90e72 feat: add dynamic port allocation with preferred port fallback (#223)
* feat: add dynamic port allocation with preferred port fallback

Implement dynamic port allocation for dev entrypoint scripts to gracefully
handle port conflicts. When a preferred port is busy, the system automatically
finds an alternative available port.

Changes:
- Add findFreePort() and findFreePorts() utilities to dev-safe.mjs
- Add buildSafeDevConfigAsync() for async config with dynamic allocation
- Update dev-with-automation.mjs to use async buildConfig with dynamic ports
- Update dev-static.mjs to use async buildConfig
- Add strictPort: true to vite.config.ts to fail-fast on conflicts
- Update tests for async buildConfig

The utilities try the preferred/default ports first, falling back to
OS-assigned ports only when needed. This preserves predictable defaults
while gracefully handling port conflicts.

Closes #222

* fix: address review feedback - add max retry, document race condition, improve tests

- Add max retry count (100 attempts) to port allocation loop to prevent
  infinite loops
- Fix findFreePort to handle preferredPort=0 correctly by skipping the
  port check and going straight to OS assignment
- Document race condition limitation in findFreePort JSDoc (accepted
  limitation with guidance on handling EADDRINUSE)
- Clarify JSDoc for buildSafeDevConfig vs buildSafeDevConfigAsync with
  clear guidance on when to use each
- Remove misleading 'must be after prereq check' comment
- Add comprehensive tests for findFreePort, findFreePorts, and
  buildSafeDevConfigAsync using actual port blocking
- Improve buildConfig tests with port uniqueness verification and
  fallback tests using high ports
- Use high ports (19xxx range) in tests to avoid conflicts with
  system services

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-09 14:46:10 -04:00
Rohit Malhotraandopenhands 0fd9800e74 feat: add VITE_LOAD_PUBLIC_SKILLS config to optionally disable public skills (#204)
* feat: add VITE_LOAD_PUBLIC_SKILLS config to optionally disable public skills

Add a new environment variable VITE_LOAD_PUBLIC_SKILLS that controls whether
skills from the OpenHands extensions marketplace (https://github.com/OpenHands/extensions)
are loaded. Defaults to true (enabled).

Changes:
- Add shouldLoadPublicSkills() function in agent-server-config.ts
- Update skills-service.ts to use the new config function
- Update agent-server-adapter.ts loadSkillsForConversation to use the config
- Document the new env var in .env.sample and AGENTS.md

Set VITE_LOAD_PUBLIC_SKILLS=false to disable loading public skills.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: pass VITE_SESSION_API_KEY to Vite dev server when SESSION_API_KEY is set

When running in environments with SESSION_API_KEY set (like OpenHands sandbox),
the agent-server requires authentication. This fix passes the session API key
to the Vite dev server so the frontend can authenticate API requests.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: pass load_public_skills and load_user_skills in agent_context when starting conversations

This is the critical fix - the agent_context.load_public_skills flag must be
passed in the start conversation request for the SDK to load skills from
https://github.com/OpenHands/extensions at runtime.

Previously we were only passing load_public=true to the /api/skills endpoint
which is used for UI display, but NOT passing it to the conversation start
payload which controls what skills are actually available during agent execution.

Changes:
- Add agent_context with load_public_skills and load_user_skills to the agent
  configuration in createAgentFromSettings()
- Uses shouldLoadPublicSkills() which respects VITE_LOAD_PUBLIC_SKILLS env var

Co-authored-by: openhands <openhands@all-hands.dev>

* test: add shouldLoadPublicSkills mock to all tests that mock agent-server-config

Fix failing tests by adding the new shouldLoadPublicSkills function to the
mock definition for #/api/agent-server-config.

Also add test assertion to verify agent_context is included in the start
conversation payload with load_public_skills and load_user_skills flags.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-09 00:27:35 -04:00
Rohit Malhotra 9098d9e6df feat: auto-generate random API keys for dev server authentication (#203) 2026-05-08 22:48:58 -04:00
Graham Neubig ffd19e977f Fix Windows dev script startup (#199)
* Fix Windows dev script startup

* Run CI on Windows

* Disable npm cache on Windows CI
2026-05-08 21:36:20 -04:00
Rohit Malhotraandopenhands 0b45d8c879 chore: default to released PyPI versions instead of git branches (#194)
- Change agent-server SDK default from git main to PyPI 1.21.1
- Change automation default from git main to PyPI 1.0.0a1
- Pin all SDK packages (agent-server, tools, workspace) to same version
- Keep ability to override with OH_AGENT_SERVER_GIT_REF/OH_AUTOMATION_GIT_REF
- Update tests and AGENTS.md documentation

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-08 15:08:01 -04:00
Rohit Malhotraandopenhands 7ebb116475 chore: update automation entrypoint to openhands.automation namespace (#191)
The automation package has been restructured to use the openhands.automation
namespace instead of the root automation namespace. This change updates the
uvicorn entrypoint from 'automation.app:app' to 'openhands.automation.app:app'.

Related: OpenHands/automation#101

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-08 14:23:50 -04:00