Commit Graph
156 Commits
Author SHA1 Message Date
MarMar Labs 2738be2025 fix(scripts): use 127.0.0.1 for remaining localhost service URLs (#16409) 2026-08-19 15:49:41 +07:00
Vasco SchiavoandGraham Neubig 475a73162f feat(automations): add a Git Sync page (#16521)
Co-authored-by: Graham Neubig <neubig@gmail.com>
2026-08-17 07:41:36 +00:00
bab1baf2de fix(dev): stop baking absolute VITE_BACKEND_BASE_URL in npm run dev (#16605)
Co-authored-by: neubig <neubig@users.noreply.github.com>
Co-authored-by: openhands <openhands@all-hands.dev>
2026-08-15 00:21:45 -04:00
83ba34cce6 chore: bump SDK deps (software-agent-sdk 1.42.1, automation 1.7.1, typescript-client 1.38.0) (#16554)
Co-authored-by: neubig <neubig@users.noreply.github.com>
Co-authored-by: openhands <openhands@all-hands.dev>
2026-08-12 21:16:34 -04:00
Christopher HaugenandCopilot 2e1502f39d fix: spawn launcher services without implicit shell (#16093)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19deb2d0-75af-4fcf-ac1d-a6933c00769f
2026-08-11 10:50:54 -04:00
Rohit Malhotraandopenhands 68de5c5887 fix: configure agent-server telemetry in Canvas launchers (#16348)
Co-authored-by: openhands <openhands@all-hands.dev>
2026-08-08 21:37:31 -04:00
52fb583107 feat(conversations): add tag chips, overflow, and hovercard labels (#16346)
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: hieptl <hieptl.developer@gmail.com>
2026-08-07 14:07:55 +00:00
4d3d9d197c feat(settings): polish Agent Canvas version update UI (#16343)
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: hieptl <hieptl.developer@gmail.com>
2026-08-06 20:24:06 +07:00
Hiep Le 9a023b28bf fix: rename desktop app to OpenHands Agent Canvas (#16353) 2026-08-06 11:56:13 +00:00
Hiep Le 31b94014e0 fix: ship multi-size app icons for Windows and macOS (#16352) 2026-08-06 18:25:57 +07:00
Hiep Le f191d3f115 chore: bump agent-server 1.40.1 and automation 1.6.0 (#16334) 2026-08-05 22:19:37 +07:00
YUN GU 0ffcb659d1 fix: use IPv4 loopback for local proxy targets (#16290) 2026-08-04 11:46:30 +02:00
george larson 54d9f30cd3 fix: clean up dev services on SIGHUP (#16239) 2026-08-03 13:41:58 +02:00
e0b115757b fix: route runtime services through server_info (#16090)
Co-authored-by: neubig <398875+neubig@users.noreply.github.com>
Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: neubig <neubig@users.noreply.github.com>
2026-08-02 22:39:43 -04:00
Hiep LeandGraham Neubig 8e5dc43004 feat: add a domain-neutral extension-manifest host (#16127)
Co-authored-by: Graham Neubig <neubig@gmail.com>
2026-07-31 12:07:48 +07:00
Hiep Le ca982d66bb chore: bump agent-server 1.39.1, automation 1.5.0, typescript-client 1.36.1 (#16197) 2026-07-30 19:05:17 +07:00
7fbc01824a test: add Stryker mutation testing (#16184)
Co-authored-by: Ai Vong <ai.vong@openhands.dev>
Co-authored-by: Engel Nyst <engel.nyst@gmail.com>
2026-07-30 08:39:49 +02:00
Rohit Malhotraandopenhands c86824bafd fix: update release repository metadata (#16186)
Co-authored-by: openhands <openhands@all-hands.dev>
2026-07-29 22:47:31 -04:00
Hiep Le 1afddcdf67 chore: bump software-agent-sdk to 1.38.0 and automation to 1.4.1 (#16129) 2026-07-28 22:13:48 +07:00
simonrosenberg 4c5bcdcc12 feat(settings): add title generation profile preference (#1910)
* feat(settings): add title generation profile preference

* test: wait for profile rename completion
2026-07-24 16:50:53 +00:00
Hiep Le 7b1e07d6f8 feat: add windows desktop installer build, docs, and win32 fixes (#1897)
* feat: add Windows desktop installer build, docs, and win32 fixes

* fix: failing tests

* refactor: update the code based on feedback
2026-07-24 06:25:07 +00:00
Rohit Malhotraandopenhands 22fe594133 feat: forward automation telemetry context (#1917)
* feat: forward telemetry context to automations

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: sync automation telemetry consent

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: default automation telemetry key in launchers

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: bake production telemetry defaults into npm package

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: dedupe automation consent sync

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump automation version to 1.3.0

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-07-24 05:47:26 +00:00
Hiep Le d814348263 feat: add macos build workflow and document the install path (#1911)
* feat: add macOS DMG build workflow and document the install path

* fix: failing workflow

* refactor: update the code based on feedback
2026-07-23 19:15:10 +00:00
Hiep Le 1450d21308 chore: bump software-agent-sdk to 1.37.0 and automation to 1.2.0 (#1906) 2026-07-23 11:56:45 +02:00
Hiep Le 5f77656b76 feat: add Agent Canvas update-availability card to settings (#1898) 2026-07-22 14:44:49 +00:00
Hiep Le 4e9ea1334a feat: add electron desktop app (#1864) 2026-07-20 15:06:31 +00:00
Vasco Schiavo 2d7a3985b3 fix: spawn dev services without a shell on Windows (#1859)
On Windows, spawnService ran uvx through cmd.exe (shell: true), so the `<`
in the `agent-client-protocol<0.11` version constraint was parsed as input
redirection and agent-server exited immediately with "The system cannot find
the file specified."

Resolve the command to its absolute path with where.exe and spawn it directly,
with no shell, so argument metacharacters stay literal. npm is unaffected: it is
already wrapped in cmd.exe by buildNpmScriptCommand before it reaches
spawnService.
2026-07-20 11:00:13 +02:00
Hiep Le 321c682d3d chore: bump software-agent-sdk to 1.36.1 and automation to 1.1.7 (#1810)
* chore: bump software-agent-sdk to 1.36.1 and automation to 1.1.7

* fix: failing tests
2026-07-16 00:17:25 +07:00
519c856c37 feat: support serving Canvas under a subpath (#1796)
* feat: support serving canvas under subpath

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: redirect root app routes to canvas base path

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: hieptl <hieptl.developer@gmail.com>
2026-07-15 12:24:11 -04:00
2b7ceea667 refactor: define canvas UI as an SDK client tool (#1797)
* refactor: define canvas UI as an SDK client tool

Send a JSON-defined canvas_ui_client tool on new, profile-based, and resumed conversation requests while retaining the legacy Python registration for persisted conversations. Normalize the new SDK event kinds to the existing Canvas UI rendering.

Co-authored-by: smolpaws <engel@enyst.org>

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: omit canvas client tool from ACP launches

* refactor: rename canvas client tool

Use the semantic canvas_ui_control name and contain the SDK-generated action discriminator behind exported constants.

Co-authored-by: Engel Nyst <engel.nyst@gmail.com>

---------

Co-authored-by: Engel Nyst <engel.nyst@gmail.com>
Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: Debug Agent <157206163+simonrosenberg@users.noreply.github.com>
2026-07-15 09:40:57 +00:00
🐾 smolpawsandEngel Nyst 4baec98fef chore: bump agent-server SDK to 1.35.0 and automation to 1.1.6 (#1666)
Bump the pinned agent-server/openhands-sdk version from 1.33.0 to 1.35.0 and
the automation package from 1.1.4 to 1.1.6. openhands-automation 1.1.6
(published to PyPI) depends on openhands-sdk/openhands-workspace 1.35.0, so
this keeps Canvas in sync with the released automation package.

Verified with: EXPECTED_SDK_VERSION=1.35.0 node scripts/check-sdk-version-sync.mjs
--check-pypi -> 'All SDK versions are in sync!'. dev-safe tests pass (52/52).

Co-authored-by: Engel Nyst <engel.nyst@gmail.com>
2026-07-11 22:55:04 +02:00
simonrosenbergandClaude Opus 4.8 ebeaca4f4d chore: bump agent-server SDK to 1.33.0 and automation to 1.1.4 (#1622)
* chore: bump agent-server SDK to 1.33.0 and automation to 1.1.4

Bump config/defaults.json pins:
- versions.agentServer 1.32.0 -> 1.33.0
- versions.automation  1.1.3 -> 1.1.4

Everything else (dev-safe.mjs, docker.yml, mock-llm workflows) reads these
from defaults.json. Updated the dev-safe.test.ts expectations and the two
concrete AGENTS.md version references to match.

The agent-client-protocol<0.11 guard stays: openhands-sdk 1.33.0 still pins
agent-client-protocol>=0.10.1 (unchanged from 1.32.0), so acp 0.11.0 would
still break the ACP client.

Blocked until openhands-automation 1.1.4 (pinned to SDK 1.33.0) publishes to
PyPI, since the sdk-version-sync check resolves the released automation's SDK
deps. Draft until then.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore: sync remaining 1.32.0 version examples to 1.33.0

The drift-detection test (docs-version-sync) requires JSDoc examples in
scripts/dev-safe.mjs and scripts/check-sdk-version-sync.mjs to match the
config/defaults.json agent-server pin. Also refresh the acp-constraint
comments in mock-llm-e2e.yml and defaults.json for consistency.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-08 11:54:38 +02:00
Graham Neubigandopenhands c552545926 feat(mcp): add OAuth support to MCP install flow
Squash merge PR #1583.

This merge commit was created by an AI agent (OpenHands) on behalf of Graham Neubig.

Co-authored-by: openhands <openhands@all-hands.dev>
2026-07-07 12:03:36 +02:00
Hiep Le 2e63845a3f chore: bump software-agent-sdk to 1.31.1 and automation to 1.1.2 (#1609)
* chore: bump software-agent-sdk to 1.31.1 and automation to 1.1.2

* fix: pin agent-client-protocol <0.11 and sync version docs
2026-07-07 00:02:46 +07:00
74f06866ec Use libraries for local proxy and static serving (#1543)
* Use libraries for local proxy and static serving

* Fix CI for proxy library refactor

* Fix static server CI failures

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-30 06:07:20 -07:00
b2ba5889d3 fix(examples): inherit acp-docker image from config/defaults.json (#1434)
* fix(examples): inherit acp-docker image from config/defaults.json

examples/acp-docker/docker-compose.yml hardcoded the agent-server image at
`1.25.0-python`. Canvas enforces `compatibility.minimumAgentServer` (1.28.0)
from the repo's single source of truth, so the example default fell below the
floor and rendered "Disconnected — requires 1.28.0 or newer" — a reviewer
following the quickstart as written never reached the feature.

examples/acp-docker was the lone in-repo file hardcoding a version instead of
inheriting from config/defaults.json (14 other files read it; check-sdk-version
-sync only validates the released PyPI package, not in-repo files).

- scripts/gen-acp-docker-env.mjs: read defaults.json, pin AGENT_SERVER_IMAGE to
  `${images.agentServer}:${versions.agentServer}-python` in examples/acp-docker
  /.env (idempotent upsert; mirrors scripts/docker-build.mjs).
- package.json: `npm run example:acp-docker:env`.
- docker-compose.yml: no-config fallback `1.25.0-python` -> `latest-python`,
  always >= the compatibility floor, so zero-config `docker compose up` never
  shows "Disconnected"; the generated .env overrides with the pinned SoT
  version for the reproducible path.
- .env.example / README.md: document both paths; correct the version narrative
  (floor is the defaults.json compatibility pin; #3510 is the deeper functional
  floor at/below it).
- __tests__/scripts/acp-docker-env-sync.test.ts: assert the generator's tag
  matches defaults.json, the pin satisfies the floor, and the compose fallback
  stays `latest-python`. Mirrors docs-version-sync.test.ts — the guard that
  makes "can't silently drift" true.

* test(examples): harden acp-docker env-sync per review

Addresses the cli-review-panel findings worth acting on (the rest were
cosmetic or matched the no-validation idiom of scripts/docker-build.mjs):

- gte() in the test guarded with parseSemver — a non-numeric pin (sha /
  pre-release) now fails the floor check loudly instead of silently
  comparing NaN. The floor check is a CI gate; its one piece of logic
  shouldn't mis-compare in silence.
- compose-fallback assertion derives the registry from config.images
  .agentServer instead of hardcoding ghcr.io/openhands/... — a registry
  change no longer false-fails a test that only cares about the latest-python
  tag.
- upsertEnvLine now has unit tests (append / replace-in-place+preserve /
  idempotent / commented-template-line / keyless-line guard), making the
  "idempotent upsert" claim defensible. It was the one untested piece of real
  logic.
- upsertEnvLine guards a keyless line (no "=") with a clear throw, instead of
  an empty key matching every line and rewriting the whole file.

* fix(examples): guard acp-docker env-sync entrypoint against undefined argv[1]

The CLI entrypoint guard called pathToFileURL(process.argv[1]) unconditionally.
process.argv[1] is undefined in some ESM contexts (e.g. importing the module for
its exports via `node --input-type=module -e "import(...)"`), so the guard threw
ERR_INVALID_ARG_TYPE at import, before any exported helper was reachable.

Short-circuit on process.argv[1] before pathToFileURL so importing the module is
side-effect-free while the CLI path is unchanged. Add a regression test that
reproduces the bare-import context and asserts a clean exit.

Addresses the review finding on #1434.

* docs(acp-docker): trim verbose comments per review

Address all-hands-bot's review suggestions on #1434:
- test header describes the current invariant, not the prior-state history
  (that narration belonged in the PR description)
- docker-compose.yml: condense the image-pin comment to the how-to-override;
  the compatibility-floor / #3510 rationale already lives in README §1 + the test
- .env.example: 7-line pin explainer down to 2

Comment-only; env-sync test still 10/10 green, prettier clean.

* Clarify ACP Docker image version guidance

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: enyst <engel.nyst@gmail.com>
Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-26 23:21:32 +00:00
Hiep Le c3f20e0df5 chore: bump typescript-client 1.28.0 + agent-server/openhands-sdk 1.29.3 (#1507)
* chore: bump typescript-client 1.28.0 + agent-server/openhands-sdk 1.29.3

* chore: automation
2026-06-26 17:52:18 +00:00
37b8bc6e41 Add command-k menu (#1206)
* Add command menu

Co-authored-by: openhands <openhands@all-hands.dev>

* Add command menu keyboard coverage

* Translate command menu strings

* Stabilize command menu sidebar action

* Stabilize command menu item definitions

* chore: add live evidence for PR #1206 under .pr/

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: neubig <398875+neubig@users.noreply.github.com>
Co-authored-by: Graham Neubig <gneubig@users.noreply.github.com>
2026-06-26 12:46:37 -04:00
3f52df2e39 feat(settings): add Cloud link to settings sidebar for cloud backends (#1453)
* feat(settings): add Cloud link to settings sidebar for cloud backends

Add a "Cloud" external link at the bottom of the Settings sidebar that
appears only when the active backend is a Cloud backend. It links to
`{cloudHost}/settings` (opens in a new tab) with an external-link icon,
giving users a quick path to their hosted account/settings page. Local
backends and the no-backend state render nothing.

- New `CloudSettingsLink` component reads the active backend and renders
  only for cloud backends, normalizing the host (trailing slash) before
  appending `/settings`.
- Added to the desktop sidebar, mobile hub, and mobile drawer (next to
  the existing backend-synced badge).
- New i18n key `SETTINGS$CLOUD_SETTINGS_LINK` (allowlisted as a brand
  name since "Cloud" is identical across locales).
- Added unit tests covering cloud/local/no-backend cases and URL building.

Screenshot of the new Cloud button in the Settings window: .pr/settings-cloud-button.png

Co-authored-by: openhands <openhands@all-hands.dev>

* docs(pr): replace screenshot with correct Settings sidebar view

The previous screenshot captured the manage-backends overlay that
appears for a logged-out cloud backend, not the Settings sidebar.
Re-captured against a connected cloud backend so the Cloud link is
visible at the bottom of the Settings sidebar alongside the nav items.

Co-authored-by: openhands <openhands@all-hands.dev>

* feat(settings): add cloud glyph to Cloud settings sidebar link

Render the Cloud settings link with a leading cloud icon (lucide `Cloud`)
next to the "Cloud" label, keeping the trailing external-link icon so
users can tell it opens the hosted page in a new tab. Matches the other
iconified rows in the Settings sidebar.

Update the PR screenshot to show the new two-icon layout.

* feat(settings): place Cloud link below Secrets with nav-row styling

Move the Cloud settings link out of the sidebar footer into the nav
list, directly below the Secrets entry and above the synced-settings
badge, so it sits where users expect a settings sub-page to be.

Restyle the link to match the other sidebar nav rows: reuse the shared
sidebar-layout classes (sidebarNavRowClassName + SIDEBAR_ROW_INTERACTIVE
idle, SIDEBAR_ICON_SLOT_CLASS, sidebarNavLabelClassName) so it has the
same height, padding, border-radius, transparent idle background, and
hover background as Secrets/LLM/etc. Drop the bespoke bordered card.
Still renders a leading cloud glyph, the "Cloud" label, and a trailing
external-link icon.

Apply the same placement in the mobile hub and mobile drawer.

* chore: Remove PR-only artifacts

* docs(settings): simplify CloudSettingsLink JSDoc; add PR screenshots

- Apply reviewer suggestion to trim verbose JSDoc (keep only the
  non-obvious note about why local backends are excluded).
- Add the three evidence screenshots referenced in the PR description
  to .pr/ so the Video/Screenshots links resolve on the branch.

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: neubig <398875+neubig@users.noreply.github.com>
Co-authored-by: allhands-bot <allhands-bot@users.noreply.github.com>
2026-06-25 21:16:21 +00:00
Vasco Schiavo 32d2e12042 chore(deps): bump typescript-client 1.27.0 + agent-server/openhands-sdk 1.29.0 (#1486)
* chore(deps): bump @openhands/typescript-client to 1.27.0

* test: update ACP provider/model fixtures for typescript-client 1.27.0

1.27.0 refreshed the claude-code/codex ACP registry data: provider command
versions (claude-agent-acp 0.30.0->0.44.0, codex-acp 0.15.0->0.16.0),
claude-code model ids (claude-opus-4-8->opus[1m], claude-sonnet-4-6->sonnet,
claude-haiku-4-5->haiku) plus a new well-labeled "default" option, and the
codex default (gpt-5.5/medium->gpt-5.5).

Canvas sources these lists from the client registry (closes #740), so the
source was already correct -- only the hardcoded test expectations were
stale. Also relaxed the acp-providers placeholder guard to accept the SDK's
intentional "Default (recommended)" entry.

* chore(deps): bump agent-server/openhands-sdk to 1.29.0

Align the spawned agent-server SDK release train (openhands-sdk,
openhands-tools, openhands-workspace, openhands-agent-server) with the
version @openhands/typescript-client 1.27.0 is validated against
(agent-server 1.29.0-python). Bump the coupled openhands-automation pin
to 1.0.0a12, whose SDK deps resolve to 1.29.0, to satisfy the
check-sdk-version-sync gate. minimumAgentServer compat floor unchanged.

Doc/JSDoc/test references updated to keep docs-version-sync green.
2026-06-25 15:03:07 +00:00
a1c68313b2 Add lock-to-cloud backend setup mode (#1389)
* Show onboarding before public backend auth gate

Co-authored-by: openhands <openhands@all-hands.dev>

* Make backend setup the first onboarding step

Co-authored-by: openhands <openhands@all-hands.dev>

* Restore Cloud backend option in onboarding

Co-authored-by: openhands <openhands@all-hands.dev>

* Make first-run backend onboarding calmer

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: update public onboarding e2e expectation

* fix: cover onboarding-first public auth e2e

* test: keep ProgressEvent polyfill through teardown

* chore: refresh PR checks after QA

* Add lock-to-cloud backend setup mode

Co-authored-by: openhands <openhands@all-hands.dev>

* Hide skip on locked Cloud backend onboarding

Co-authored-by: openhands <openhands@all-hands.dev>

* Remove add-backend onboarding subtitle

Co-authored-by: openhands <openhands@all-hands.dev>

* Skip healthy backend onboarding step

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: support skipped backend step in onboarding e2e

* chore: Remove PR-only artifacts

* fix: address onboarding review nits

* fix: show onboarding for locked cloud first run

* ci: support stacked mock llm runs

* test: assert scoped shell background

* fix: resolve merge conflicts with main (fix-public-onboarding stacking)

- Remove duplicate handleConnected/actionRowClassName/titleKey declarations
  in check-backend-step.tsx that resulted from merging the parent PR's
  changes on top of our lock-to-cloud additions
- Remove erroneous waitFor(onboarding-backend-connected) steps from the
  'shows a connection error' test which uses a no-backend context where
  the connection banner is never shown

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: remove unused isLockedToCloud export

All callsites use getLockedCloudHost() !== null directly.
Remove the redundant helper to keep the public API intentional.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: show onboarding first in locked-cloud mode when a session key is present

On PR #1389 Hiep reported that `static-server.mjs --lock-to-cloud ...`
landed on the Manage Backends recovery modal ("Add Backend") instead of
first-run onboarding after a fresh `~/.openhands`.

Root cause: when the build had a baked-in `VITE_SESSION_API_KEY` (or one
was injected via `--session-api-key`), `makeDefaultLocalBackend()` seeded
a Local backend even in locked-to-Cloud mode. That made `isNoBackend()`
false, so `lockedNoBackend` was false and first-run onboarding was
skipped; the subsequent `/server_info` probe failed and `root.tsx`
rendered `MissingAgentServerScreen` (Manage Backends recovery modal).

Fix:
- `makeDefaultLocalBackend()` returns null when `getLockedCloudHost()` is
  set, so locked mode never auto-seeds a Local backend.
- `root.tsx` broadens the gate to `lockedNeedsOnboarding`: locked + (no
  backend OR active backend is not Cloud) triggers onboarding, covering a
  stale persisted Local backend from a previous non-locked session too.

Verified by building with a baked `VITE_SESSION_API_KEY` and serving with
`--lock-to-cloud`: the app now shows the first-run onboarding Cloud-login
screen instead of the recovery modal, and no Local backend is seeded.
Non-locked mode still seeds the Local backend as before.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: locked-cloud onboarding layout + restore CI test mock

CI fix:
- `use-create-conversation-metadata.test.ts` mocks the whole
  `agent-server-config` module but was missing `getLockedCloudHost`, which
  `makeDefaultLocalBackend()` now imports. Add it (returning null) so the
  default local backend seeds and the create-conversation mutation
  succeeds again.

Onboarding layout (locked-to-Cloud first-run step):
- Drop the `max-w-sm` cap on the locked CloudLoginColumn so the "Skip the
  setup — connect instantly with your OpenHands Cloud account." text fills
  the modal content width instead of wrapping in a narrow centered column.
- Add `pb-7` to the onboarding scroll area so the "Login with OpenHands
  Cloud" button is no longer flush with / cut off by the modal bottom.
  Widening the text (fewer lines) plus the bottom padding together give
  the button breathing room.

Co-authored-by: openhands <openhands@all-hands.dev>

* test: add getLockedCloudHost to agent-server-config test mocks

`makeDefaultLocalBackend()` now imports `getLockedCloudHost` from
`agent-server-config`. Two tests that fully mock that module were missing
the export, so the default local backend never seeded and every create-/
read-conversation path threw `NoBackendAvailableError`:

- `agent-server-conversation-service.test.ts` (23 failures on ubuntu CI)
- `use-create-conversation-metadata.test.ts` (already fixed in prev commit)

Add `getLockedCloudHost: vi.fn(() => null)` to both mocks so the non-locked
default-backend seeding path works again.

Co-authored-by: openhands <openhands@all-hands.dev>

* Enhance conversation sidebar with pinned section and grouped organization (#1144)

* Add pinned conversations and reorderable workspace folders to the sidebar.

Persist pins per backend with a capped pinned section, pin-on-hover cards that keep the icon aligned with hover actions via an invisible ellipsis spacer, and drag-and-drop folder ordering stored in panel preferences.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify grouped folder rows for drag and expand.

Drop the grip and chevron controls, remove selection highlight and layout animation, and drag or click the folder label directly while keeping row hover feedback.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Polish folder drag-and-drop and pinned section visuals.

Drag the whole folder (and contents) as the drag image, show an accent drop
line between folders with position-aware reordering, and animate sibling
folders into place only around a reorder. Swap the folder icon to its open or
closed counterpart on hover, add a chronological-view divider plus an outline
pin icon to the pinned section header, and render that header in normal weight.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add hover metadata popover for sidebar conversations.

Show a modal-styled popover on conversation hover with the full title, status
dot, and repo/branch-or-directory, model, and created-date rows. Reserve the
action overlay width so titles truncate instead of colliding with the pin,
drop the small status tooltip, and gate the popover behind a new "Hover
metadata" toggle in the filter dropdown (persisted, on by default).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Improve folder drag preview and placeholder.

Show a rounded, surfaced drag image anchored to the grab point and blank the
original row (preserving its height) via opacity so Chrome does not cancel the
native drag.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Harden sidebar "Load more" pagination

Dedupe loaded conversations by id and keep fetching pages until the
visible list actually grows, so a single "Load more" click reliably
surfaces new rows despite the 10s background refetch dropping in-flight
fetchNextPage calls or pages yielding zero visible rows. Show the
skeleton throughout. Also drop the native title tooltip on card titles
and record the still-intermittent double-click symptom as a KNOWN ISSUE.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Keep pinned conversations exclusive to the pinned section.

Filter pinned threads out of grouped/chronological lists to prevent duplicates, add regression coverage for both list modes, and add the missing upgrade-button translation key with typed i18n usage.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: failing tests

* fix: lint

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: hieptl <hieptl.developer@gmail.com>

* Fix locked cloud onboarding follow-ups

Co-authored-by: openhands <openhands@all-hands.dev>

* Slow down onboarding follow-up GIFs

Co-authored-by: openhands <openhands@all-hands.dev>

* Skip onboarding when active backend already has a configured LLM

Detect returning users via flat `llm_api_key_set` + `agent_settings.llm.model` (or subscription auth), regardless of backend kind. Locked-Cloud-not-logged-in and stale local backend still fall through to the modal so the existing recovery paths kick in.

Co-authored-by: openhands <openhands@all-hands.dev>

* Scope onboarding skip rule to Cloud backends only

Local agent-servers can be started with an env-injected `LLM_API_KEY`, which makes `llm_api_key_set` an unreliable returning-user signal — Mock-LLM E2E fresh-install tests were tripping on the SDK default model + env key combo. For Local backends the skip stays driven by the existing `openhands-onboarded` localStorage flag; Cloud backends continue to use the settings-based rule.

Co-authored-by: openhands <openhands@all-hands.dev>

* Trigger CI re-run (empty commit)

Workflows didn't fire on 80ea575a — pushing empty commit to nudge the webhook.

Co-authored-by: openhands <openhands@all-hands.dev>

* Always pre-fill onboarding LLM step with OpenAI GPT-5.5 default

The returning-Cloud-user case is now handled at the host level (OnboardingHost skips the whole modal). Users who actually reach the LLM step are first-time installs who want the default pre-filled — restoring the pre-PR-1389 behavior that the onboarding-regressions E2E asserts. Also drops the now-empty unit test that mirrored the old step-level preservation.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: Update PR QA artifacts

* Generalize onboarding-skip to Local backends with configured LLMs

Hiep flagged that the onboarding modal still walks users through Set Up
your LLM after they connect to a pre-configured backend. Investigation:

  * On Cloud, the fast-path keyed off settings.llm_api_key_set + a
    non-empty llm.model. That worked.
  * On Local, the fast-path bailed early on backend.kind !== 'cloud'.
    But the local agent-server reports the exact same readiness signal
    via llm_api_key_is_set (and the local settings-service mapper
    already remaps that to llm_api_key_set on the way through). The
    only reason the skip didn't fire was the explicit kind gate.

Drop the gate, accept either field name, and rename the predicate to
reflect what it actually checks (isBackendLlmReady). A truly fresh
agent-server reports both flags as false, so the modal still shows for
genuine first-run setup.

Tests:
  * Updated 'does not skip onboarding for a Local backend' to its
    inverse: 'skips for a Local backend with an LLM already configured'.
  * Added 'still shows the modal for a fresh Local agent-server with no
    API key set' to lock in the fresh-install case.
  * All 3328 vitest tests pass; typecheck clean.

Refs Hiep's review comment on PR #1389.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(onboarding): address Hiep's review on PR #1389 (#1389)

Resolves the three issues Hiep reported on PR #1389:

1. **Choose Agent step gets skipped after Cloud login.** When the
   backend slide finished via Cloud login and `skipBackendStep` flipped
   true, the slide indices renumbered (agent: 1→0, setup: 2→1). The
   user's numeric `currentStep` of 1 — pointing at Choose Agent before
   the flip — now pointed at Set Up LLM, and the corrective effect that
   decremented it ran a render too late. Track the user's *phase*
   ("backend" | "agent" | "setup" | "hello") instead of a numeric
   step. The visible slide index is derived from phase + slideOrder, so
   renumbering can never move the user onto a different logical step.
   The previous `wasSkippingBackendStep` ref + decrement effect is
   replaced by a single effect that snaps phase forward only when the
   current phase is no longer in slideOrder (e.g. "backend" right
   after the slide collapsed).

2. **Existing Cloud LLM settings not shown to returning users.** The
   skip-onboarding fix from commit 78254e1b already routes returning
   users with a configured LLM around the onboarding modal entirely,
   so they never hit the Set Up LLM step in the first place. The new
   phase-based flow preserves that behavior; no further change needed.

3. **Redundant 'Or' divider** between manual and Cloud columns in
   BackendConnectionOptions. Both columns have prominent titles
   ("OpenHands Cloud" with logo on the right) and a generous gap
   already; the explicit divider added visual noise without
   information. Remove the divider markup.

Also gitignores local static-server runtime artifacts (workspace/,
build-fresh/) that were getting picked up by 'git add -A'.

Two regression tests cover the standard (non-locked-cloud) flow: one
verifies the user stays on Choose Agent after completing Cloud login
from the side-by-side picker, and one verifies the 'Or' divider is
gone. All 3,241 unit tests pass; lint and typecheck are clean.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: suppress Add Backend modal in locked-to-cloud mode

Resolves hieptl's review feedback on PR #1389: when the static server is
launched with --lock-to-cloud, navigating to the app showed the Manage
Backends recovery modal ("Add Backend") instead of going straight to
Cloud onboarding/login.

Root cause: the `openhands-onboarded` localStorage flag is origin-scoped
and persists across deployments. A user who previously completed
onboarding in a non-locked session on the same origin carries that flag
into a locked-to-Cloud session. The stale flag suppressed
first-run onboarding (`shouldShowFirstRunOnboarding` was gated on
`!onboardingCompleted`), so the app fell through to the
`/server_info` probe. With no usable local backend in locked mode the
probe throws `AgentServerUnavailableError`, and root.tsx renders the
`MissingAgentServerScreen` / `ManageBackendsModal` recovery modal.

Fix: when `lockedNeedsOnboarding` is true, ignore the completion flag
and force first-run onboarding (which owns the Cloud login). The
non-locked path is unchanged — `onboardingCompleted` still suppresses
the modal for returning users with a configured backend.

Also confirms the minor cleanup from the bot review: `isLockedToCloud()`
was already removed in commit addda40e; no remaining references.

Adds a regression test reproducing hieptl's exact scenario (stale
`openhands-onboarded` flag + locked-to-Cloud + no backend) and asserting
the onboarding modal renders instead of the Manage Backends modal.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(onboarding): don't skip onboarding modal for launcher-seeded backend

PR #1389 generalized the OnboardingHost "returning user with a
configured LLM" skip from Cloud-only to all backends (commit 78254e1b).
That broke the mock-LLM E2E fresh-install / onboarding-happy-path /
onboarding-regressions specs:

  tests/e2e/mock-llm/backends/mock-llm-auth-modes.spec.ts:57
    "auth mode: fresh install with runtime-injected key ›
     reaches the onboarding modal without pre-seeded localStorage"

The mock-LLM E2E stack runs every spec serially against a single
shared agent-server. Earlier specs configure an LLM profile that
persists in the server's settings, so by the time the fresh-install
spec runs (with a clean browser context, no `openhands-onboarded`
flag, and a launcher-seeded default-local backend), the server
reports `llm_api_key_is_set: true` + a non-empty model.
`OnboardingHost.isBackendLlmReady` then returned true, so the host
marked onboarding complete and returned null — the first-run modal
never mounted and the test timed out waiting for
`onboarding-step-choose-agent`. Main is green on the same test
because main's skip was Cloud-only.

The settings-based LLM-ready signal is unreliable for the
launcher-seeded default-local backend: the agent-server can be
started with an env-injected LLM key, and shared-server deployments
retain configured LLMs across browser sessions. Keying first-run
onboarding off the server's LLM state would suppress the modal for
a genuinely fresh browser install.

Fix: keep the skip for Cloud backends and for Local backends the
user explicitly added via "Add Backend" (which carry a non-default
id), but suppress it for the launcher-seeded default-local backend
(`SEEDED_DEFAULT_BACKEND_ID`). First-run detection for that backend
stays driven by the `openhands-onboarded` localStorage flag, matching
main's behavior and restoring the E2E fresh-install contract. The
PR's core intent (suppress the Add Backend recovery modal in
locked-to-Cloud mode, commit 47619f11) is unchanged.

Tests:
  * Updated "skips the modal for a Local backend..." to seed a
    user-added Local backend (non-default id) so the skip still
    fires for the Add-Backend scenario.
  * Added "still shows the modal for a launcher-seeded default-local
    backend even when the agent-server reports a configured LLM" to
    lock in the fresh-install regression.
  * All 3332 vitest tests pass; typecheck + lint + build clean.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(onboarding): don't auto-complete onboarding for launcher-seeded backend

Commit 9029e036 fixed OnboardingHost so the first-run onboarding modal
shows for the launcher-seeded default-local backend even when the
shared mock-LLM agent-server reports a configured LLM. But the same
over-suppression existed in src/root.tsx: a separate
`isBackendLlmReady` check (no default-local exclusion) fed a
`markCompleted()` effect that persisted `openhands-onboarded=1`
whenever the active backend reported a ready LLM — including the
launcher-seeded default-local backend.

That root-level effect was the remaining cause of the
mock-llm-onboarding-regressions.spec.ts:16 failure
("keeps the modal open on backdrop click and Escape"):

  * The OnboardingModal already renders with no `onClose` on its
    ModalBackdrop, so backdrop clicks and Escape are no-ops — the
    modal itself was never closeable that way.
  * The test failure was actually the `expect.poll` asserting
    `openhands-onboarded` stays null: root.tsx's `markCompleted`
    effect fired (agent-server had a configured LLM from earlier
    serial specs) and persisted completion, even though the modal
    stayed mounted.

Fix: apply the same `SEEDED_DEFAULT_BACKEND_ID` exclusion to
root.tsx's `isBackendLlmReady` that OnboardingHost already uses.
The settings-based LLM-ready signal is unreliable for the
launcher-seeded default backend (env-injected keys, shared-server
LLM persistence across browser sessions), so first-run detection
there stays driven by the `openhands-onboarded` localStorage flag.
The skip still fires for Cloud backends and for Local backends the
user explicitly added via "Add Backend" (non-default id).

The OnboardingModal's non-dismissible backdrop/Escape behavior is
unchanged and already correct (ModalBackdrop receives no `onClose`,
so `closeOnEscape`/`closeOnBackdropClick` default-true handlers
call `onClose?.()` which is a no-op).

Tests:
  * Added root.test.tsx case "does not mark onboarding complete for
    the launcher-seeded default-local backend even when the
    agent-server reports a configured LLM" — verified it fails
    without the root.tsx fix and passes with it.
  * All 3333 vitest tests pass; typecheck + lint + build clean.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: force Cloud replacement for stale Local backend in locked mode

Critical fixes for the locked-to-Cloud flow (PR #1389 review):

1. root.tsx: the ready-backend fast-path in locked mode now requires the
   active backend to match the locked Cloud host (normalized via the new
   isSameCloudHost helper), not just . A reachable stale
   Local backend (or a Cloud backend on a different host) that reports a
   configured LLM no longer bypasses the Cloud login/replacement flow.
   The markCompleted effect is also guarded so it only persists completion
   for the legitimate locked Cloud host.

2. onboarding-modal.tsx: in locked mode, CheckBackendStep is only skipped
   when the active backend IS the locked Cloud host. A reachable stale
   Local backend keeps the backend slide visible so Cloud login can
   replace it.

Also addresses minor review suggestions:
- LOCK_TO_CLOUD_WINDOW_KEY is now module-private (only getLockedCloudHost
  reads it; static-server.mjs/tests use the literal string).
- Extract shared isBackendLlmReady helper into its own module
  (is-backend-llm-ready.ts) so root.tsx and OnboardingHost stay in sync
  without duplicating the rule and without pulling the onboarding modal
  graph into root's eager bundle.
- Inline the no-op initialValueOverrides intermediate in setup-llm-step.

Adds regression tests for the stale-Local-backend and other-Cloud-host
scenarios in both root.test.tsx and onboarding-modal.test.tsx.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(onboarding): close stale-backend lock-to-Cloud bypass in CheckBackendStep (#1389)

PR-review bot pointed out (HEAD 55d382be) that keeping the backend
slide visible for a non-matching backend in locked mode is insufficient:
CheckBackendStep itself still hits its connected-backend shortcut for
a reachable stale Local backend, hiding the Cloud login UI and showing
a Next button that lets the user continue as Local.

Apply the same host-match guard inside CheckBackendStep. A new local
`treatAsNoBackend` (= noBackendSelected || lockedCloudHostMismatch)
drives:
  - title: ONBOARDING$LOGIN_TO_CLOUD_TITLE (not BACKEND_TITLE)
  - render: BackendConnectionOptions (Cloud login UI), no ConnectionBanner
  - no "Show configuration" toggle and no Next-shortcut action row

`noBackendSelected` still governs whether handleConnected calls
`addBackend` or `updateBackend`, so the stale backend is replaced
rather than duplicated.

Strengthen the regression test the bot flagged: it now asserts the
Cloud login title and login button are visible, and that the
`onboarding-backend-show-configuration` toggle, `onboarding-backend-next`
button, and the (misleading) Connected subtitle are all absent.

All 3,249 unit tests pass; lint and typecheck are clean.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(onboarding): clear stale active org_id when replacing a Cloud backend host (#1389)

PR-review bot raised one remaining state carry-over: replacing a
mismatched Cloud backend updates its host/apiKey via `updateBackend`,
but the persisted `active.orgId` (X-Org-Id) is keyed to the OLD
host's org list. The newly-locked Cloud backend would keep sending an
invalid `X-Org-Id` until the user manually re-picked an org.

Fix in CheckBackendStep.handleConnected: when the submitted payload's
host differs from the previously-active backend's host, call
`setActive(backend.id, null)` to drop the now-invalid org selection.
The user re-picks an org on the new host via the usual org switcher.

Local-only edits are unaffected because Local backends always carry
`active.orgId === null`, so the conditional is a no-op there.

New regression test seeds a Cloud backend at other-cloud.example.com
with `orgId="stale-org-from-other-host"`, drives the Cloud login
button, and asserts `getActiveSelection().orgId === null` while the
backend row is updated in place (same id).

All 3,250 unit tests pass; lint and typecheck are clean.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix(onboarding): dismiss modal immediately after Cloud login in locked mode (#1389)

Resolves the flicker hieptl reported on PR #1389: after logging into
OpenHands Cloud in locked-to-Cloud mode, the onboarding modal advanced
to the Choose Agent slide (the "next window"), then got torn down by
the root first-run gate, then briefly remounted via OnboardingHost —
appearing to flash in and out.

Cloud login IS the onboarding completion in locked mode, so:
- CheckBackendStep now calls onClose (dismiss) instead of onNext when
  a Cloud login succeeds in locked-to-Cloud mode, so the next slide
  never shows. Standard (non-locked) mode still walks the user through
  agent/LLM setup via onNext.
- root.tsx's locked-mode first-run gate now treats onboardingCompleted
  as authoritative once the active backend IS the locked Cloud host,
  so the first-run screen hides immediately on login (without waiting
  for the Cloud settings probe to confirm a configured LLM). The flag
  is still ignored when the active backend is not the locked Cloud
  host, preserving the stale-flag bypass protection.

Added failing tests (now passing) reproducing both halves of the flicker:
- onboarding-modal: Cloud login in locked mode calls onClose, not onNext.
- root: the first-run screen hides immediately after Cloud login
  completes (post-login state with no configured LLM), instead of
  reopening via OnboardingHost.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: Remove PR-only artifacts

* ci: revert docker.yml pull_request branch filter change

Reverts the removal of `branches: [main]` from the `pull_request`
trigger in .github/workflows/docker.yml (introduced in 5bb8049f). That
change is unrelated to the locked-to-Cloud onboarding work on this PR
and is out of scope. Restores the file to match main exactly so the
Docker workflow again only runs on PRs targeting `main`.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
Co-authored-by: Graham Neubig <gneubig@users.noreply.github.com>
Co-authored-by: neubig <398875+neubig@users.noreply.github.com>
Co-authored-by: allhands-bot <allhands-bot@users.noreply.github.com>
Co-authored-by: hieptl <hieptl.developer@gmail.com>
Co-authored-by: FraterCCCLXIII <panentheum@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 16:06:12 +00:00
Tim O'Farrellandopenhands c7a00b14ab fix: seed AUTOMATION_KV_SECRET for local dev stack (#1414)
* fix: seed AUTOMATION_KV_SECRET for local dev

The KV store (automation PR#69) requires AUTOMATION_KV_SECRET to be set
or every KV endpoint returns 503. In a local dev stack the secret is never
configured, so the store is silently unavailable.

Fall back to sessionApiKey when the env var is not set explicitly — the
same zero-config pattern already used for AUTOMATION_AGENT_SERVER_URL,
AUTOMATION_BASE_URL, and AUTOMATION_WORKSPACE_BASE.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump openhands-automation to 1.0.0a10

Update to the latest released version of openhands-automation on PyPI.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-17 14:31:56 -06:00
Tim O'Farrellandopenhands e1c9e6ab33 chore: remove redundant automationSdk version — derive from agentServer (#1333)
The automationSdk version was always intended to equal agentServer.
Having a separate field creates a maintenance foothole where the two
values can silently drift. Remove automationSdk from defaults.json and
have all consumers (check-sdk-version-sync, dev-with-automation,
agent-canvas CLI --version output) read versions.agentServer directly.
The sync check still catches any mismatch between the released
openhands-automation package and the expected SDK version.

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-15 16:18:15 +00:00
Graham Neubigandneubig df93ca36a7 Add Windows portability guards for workspace flows (#1311)
* Add Windows portability guards for workspace flows

* Increase snapshot workflow timeout

* Trigger CI after timeout update

* Fix windows portability PR after main merge

---------

Co-authored-by: neubig <398875+neubig@users.noreply.github.com>
2026-06-12 19:14:03 -04:00
OpenHands Bot 82ea2b609a feat: save hosted MCP credentials as secrets (#1331) 2026-06-12 20:03:46 +00:00
Tim O'Farrellandopenhands 910b19ae76 chore: bump agent-server → 1.28.1, automation → 1.0.0a9, extensions → 0.4.1 (#1319)
* chore: bump agent-server → 1.28.1, automation → 1.0.0a9, extensions → 0.4.1

Co-authored-by: openhands <openhands@all-hands.dev>

* Test fixes

* fix: inject proxy base_url for litellm_proxy/* when server omits it (agent-server ≥1.28)

Agent-server ≥1.28 may return base_url:null when fetching a litellm_proxy/*
profile config, even when the profile was saved with the All-Hands proxy URL.
This caused the Basic-tab re-save flow in LlmSettingsLocalView.handleSave to
call isOpenHandsProxyModel(model, null) → false, hitting the else-branch that
deletes base_url and stranding the profile (issue #1146).

Fix: add a secondary check — litellm_proxy/* with a missing base_url is treated
the same as litellm_proxy/* with the proxy URL already set, and
OPENHANDS_LLM_PROXY_BASE_URL is injected before the save request is sent.

Also updates the mock-LLM E2E test to accept both storage representations:
- litellm_proxy/* + proxyBaseUrl  (pre-1.28, guards issue #1146 regression)
- openhands/*     + null          (1.28+, server-managed routing)

And adds a unit test exercising the base_url:null path.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-11 19:16:03 -04:00
Tim O'Farrellandopenhands 8071edf72a Revert "chore: bump agent-server → 1.28.1, automation → 1.0.0a9, extensions → 0.4.1 (#1315)" (#1318)
This reverts commit 1917b5d39fbf09dc51213b4b484698fe394314c7.

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-11 21:28:04 +00:00
Tim O'Farrellandopenhands 15a52fea75 chore: bump agent-server → 1.28.1, automation → 1.0.0a9, extensions → 0.4.1 (#1315)
* chore: bump agent-server → 1.28.1, automation → 1.0.0a9, extensions → 0.4.1

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: update doc examples to reference agent-server 1.28.1

Update version references in AGENTS.md, scripts/dev-safe.mjs, and
scripts/check-sdk-version-sync.mjs from 1.27.0 → 1.28.1 to stay
in sync with the agentServer pin in config/defaults.json.

Fixes: docs-version-sync.test.ts failures

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: inject proxy base_url for litellm_proxy/* when server omits it (agent-server ≥1.28)

Agent-server ≥1.28 may return base_url:null when fetching a litellm_proxy/*
profile config, even when the profile was saved with the All-Hands proxy URL.
This caused the Basic-tab re-save flow in LlmSettingsLocalView.handleSave to
call isOpenHandsProxyModel(model, '') → false, hitting the else-branch that
deletes base_url and stranding the profile (issue #1146).

Fix: add a secondary check for litellm_proxy/* models with a missing base_url
(null/undefined/empty), treating them the same as a stored proxy URL and
injecting OPENHANDS_LLM_PROXY_BASE_URL before the save request is sent.

Also adds a unit test exercising the base_url:null path.

Co-authored-by: openhands <openhands@all-hands.dev>

* test(e2e): accept agent-server 1.28 model rewrite in proxy profile test

Agent-server 1.28 normalises litellm_proxy/* → openhands/* on storage
and manages the proxy URL internally (returning base_url:null). The old
assertions hard-coded the pre-1.28 storage format (litellm_proxy/* +
explicit proxy URL), causing the test to fail on every 1.28 run.

Extract assertProxyProfileConfig() helper that accepts both storage
representations:
- litellm_proxy/* + proxyBaseUrl   (pre-1.28, guards issue #1146 regression)
- openhands/*     + null           (1.28+, server-managed routing)

The issue #1146 guard is preserved: a litellm_proxy/* profile without a
proxy URL is still flagged as a stranded profile.

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-06-11 21:00:05 +00:00
Hiep Le 66394db18a fix: translate English-copied keys and guard against untranslated values (#1305) 2026-06-11 17:28:49 +00:00
Hiep Le 10f622a430 chore: remove one-off migration codemods, demo recorder, and unused beep asset (#1232) 2026-06-10 20:30:08 +07:00