mirror of
https://github.com/OpenHands/OpenHands.git
synced 2026-10-07 16:19:05 +08:00
* chore: bump version to 1.0.0-beta.1 * chore: publish beta and rc versions as 'latest' dist-tag * chore: bump version to 1.0.0-beta.2 * fix: use X-Session-API-Key for local automation auth in prompts and RUNTIME_SERVICES (#999) Fixes #980 The agent prompt in recommended-automations-launcher and the RUNTIME_SERVICES block in agent-server-adapter both advertised X-API-Key as the auth header for the local automation backend. The automation service (openhands-automation) does not accept X-API-Key — it accepts Authorization: Bearer and X-Session-API-Key. X-Session-API-Key is the established local convention: the agent server uses it, the frontend automation API client uses it (with an explicit comment that both backends share the same header), and auth.py describes it as matching that convention. Update both call sites and the corresponding test assertion to use X-Session-API-Key. Co-authored-by: openhands <openhands@all-hands.dev> * feat: reuse mock-LLM E2E tests for Docker image validation (#992) * feat: reuse mock-LLM E2E tests for Docker image validation Add a Docker-specific Playwright config (playwright.mock-llm-docker.config.ts) that runs the exact same test specs and helpers against the agent-canvas Docker image instead of the npm build path (bin/agent-canvas.mjs + uvx). Key changes: - Split MOCK_LLM_BASE_URL into two constants in mock-llm-helpers.ts: - MOCK_LLM_BASE_URL: always host-local, used by tests for admin API - MOCK_LLM_AGENT_URL: env-overridable, used when configuring the LLM profile (the URL the agent-server uses for inference). Defaults to MOCK_LLM_BASE_URL for backward compatibility with the npm path. - New playwright.mock-llm-docker.config.ts: - Starts the mock LLM server on the host (same as npm path) - Runs the Docker container with --network host (Linux CI) - Points to the same testDir (tests/e2e/mock-llm/) and specs - Separate output dirs to avoid collision with npm path results - New CI workflow (.github/workflows/mock-llm-docker-e2e.yml): - Builds the Docker image from current code (or uses a pre-built image) - Runs the same specs against the container - Posts PR comment with differentiated report title - render-mock-llm-report.mjs: accept --title flag for Docker vs npm reports - npm run test:e2e:mock-llm:docker script added - .gitignore updated for docker test output dirs The npm path (test:e2e:mock-llm) is fully backward-compatible — no env var override needed since MOCK_LLM_AGENT_URL defaults to MOCK_LLM_BASE_URL. Co-authored-by: openhands <openhands@all-hands.dev> * refactor: chain Docker E2E off existing Docker CI via workflow_run Instead of rebuilding the Docker image in the E2E workflow (duplicating ~10-15 min of Docker build time), use workflow_run to trigger automatically after the existing 'Docker' workflow completes successfully. The workflow now: - Triggers on: workflow_run (Docker completed) + workflow_dispatch (manual) - Derives the image tag from the Docker build's commit SHA (ghcr.io/openhands/agent-canvas:sha-<short>-amd64) - Pulls the already-built image from GHCR — no rebuild needed - Checks out code at the same SHA as the Docker build - Extracts PR number from workflow_run.pull_requests[] for comments Removed: Docker build steps, Buildx setup, build-arg resolution. All image building stays in docker.yml where it belongs. Co-authored-by: openhands <openhands@all-hands.dev> * fix: replace flaky 1s timeout with polling for Active badge assertion The 'Active badge' check in step 2 used a hardcoded 1-second waitForTimeout before reloading. On a loaded CI runner the profile activation mutation may not persist in time, causing the reload to show stale state. This is a pre-existing flake (identical test code passed on the first push and failed on the second). Replace with expect.poll() that retries the reload+check cycle with increasing intervals (1s, 2s, 3s) up to 15 seconds total. Co-authored-by: openhands <openhands@all-hands.dev> * fix: add pull_request trigger for Docker E2E (workflow_run bootstrap) workflow_run only fires when the workflow file exists on the default branch (main). Since mock-llm-docker-e2e.yml is new and only on the PR branch, GitHub doesn't recognize it as a workflow_run listener yet. Add pull_request trigger (gated by 'e2e-tests' label, skip forks) that polls the Docker workflow via gh API until it completes for the PR's head SHA, then pulls the already-built image from GHCR and runs tests. After merge, workflow_run takes over as the primary automatic trigger. The pull_request path remains as a fallback for label-gated runs. Co-authored-by: openhands <openhands@all-hands.dev> * fix: add FILE_STORE, AUTOMATION_BASE_URL, AUTOMATION_WORKSPACE_BASE to Docker entrypoint The Docker entrypoint was missing several environment variables that the npm path (dev-with-automation.mjs) sets for the automation backend: - FILE_STORE=local — without this, the automation backend may fall back to cloud storage (S3/GCS) which fails without credentials, causing tarball- based presets (preset/prompt, preset/plugin) to silently error - LOCAL_STORAGE_PATH — where to store files on the local filesystem - AUTOMATION_BASE_URL — publicly-reachable base URL for callback URLs - AUTOMATION_WORKSPACE_BASE — where automation runs unpack tarballs This explains the Docker E2E failure: the agent's curl to create an automation via /api/automation/v1/preset/prompt returned an error (likely 500 from missing storage config), but the mock LLM doesn't care about terminal output and proceeded to return the scripted final reply. The test then found 0 automations. Co-authored-by: openhands <openhands@all-hands.dev> * fix: exclude auth-modes spec from Docker E2E tests The mock-llm-auth-modes.spec.ts tests npm-binary-specific --auth-required behaviour (a second static-server instance on port 18301). The Docker image doesn't provide this second server — it has its own auth handling. Exclude the spec from the Docker test run via testIgnore. Co-authored-by: openhands <openhands@all-hands.dev> * feat: run auth-modes tests inside Docker via PUBLIC_MODE_PORT Instead of excluding the auth-modes spec from the Docker E2E run or spinning up a host-side static server with a duplicate build/ directory, the Docker entrypoint now supports an optional PUBLIC_MODE_PORT env var. When set, entrypoint.sh starts a second static-server instance from the same baked-in frontend assets with --auth-required (no session key injected). This tests the actual Docker image's auth gate behaviour — not a host-side approximation. The Playwright Docker config passes -e PUBLIC_MODE_PORT=18301 to the container and exports MOCK_LLM_PUBLIC_MODE_URL so the auth-modes spec can reach it. With --network host the port is accessible from the host. Co-authored-by: openhands <openhands@all-hands.dev> * address review feedback: drop unlabeled trigger, improve error messages, document env vars - Drop 'unlabeled' from pull_request trigger types to avoid wasted workflow runs when any label is removed (the job-level if: condition would skip immediately anyway) - Distinguish 'no Docker run found' vs 'didn't complete in time' in the polling loop's final error message - Add comment explaining /api/automation/v1 probe returns 200 without auth so the readiness check won't spin for 180s - Document FILE_STORE, LOCAL_STORAGE_PATH, AUTOMATION_BASE_URL, and AUTOMATION_WORKSPACE_BASE in the entrypoint header — these affect production deployments, not just E2E tests Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump version to 1.0.0-beta.3 * ci: trigger CI on rel-* branch pushes for tag protection rule (#1004) The Release Tag ruleset requires test-and-build (ubuntu) to pass before v* tags can be pushed, but CI previously only ran on main and pull_request events. This caused rel-* version bump commits to fail the tag protection check unless a workaround PR was opened. Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump version to 1.0.0-beta.4 * chore: auto-graduate npm dist-tag from latest to per-tier once first stable release ships (#1028) * chore: always publish to npm with --tag latest until first stable release All alpha/beta/rc versions now get the 'latest' dist-tag so plain 'npm install @openhands/agent-canvas' always resolves to the newest published release. The per-tier dist-tags (alpha/beta/rc) can be re-introduced once the first full stable version is ready to ship. Co-authored-by: openhands <openhands@all-hands.dev> * chore: auto-graduate npm dist-tag when first stable release ships At publish time, query npm for any published version without a pre-release suffix. If none exists, all releases (alpha/beta/rc/stable) use --tag latest so plain 'npm install' always resolves to the newest build. Once a stable version has been published, pre-release versions revert to their own dist-tags (alpha/beta/rc) automatically — no workflow change required. Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump version to 1.0.0-beta.5 * feat(mcp): render markdown links in helperText; update Slack catalog pin (#1012) * feat(mcp): render markdown links in helperText; bump extensions to slack field-order PR commit - Add renderHelperText() to install-server-modal.tsx that converts [text](url) patterns into <a> elements with target=_blank, so the Slack workspace-ID helper text (and any future catalog entries) can embed clickable docs links inline. - Bump @openhands/extensions to commit 2d43e9c (branch slack-catalog-field-order-and-helper-links, PR #285) which: • moves SLACK_TEAM_ID before SLACK_BOT_TOKEN in the install modal • replaces the plain SLACK_TEAM_ID helper text with linked copy: 'First visit [here](...#find-your-url) to get your Slack URL and then visit [here](...#find-your-workspace-or-org-id) to get your workspace ID.' - Removes stale integrity hash from package-lock.json for the @openhands/extensions entry; npm install will recompute it. Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump @openhands/extensions to d186872 (SLACK_BOT_TOKEN helperText) Add inline linked helperText for SLACK_BOT_TOKEN in slack.json (PR #285, commit d186872): 'You'll need to create or update a Slack App as shown [here](https://github.com/zencoderai/slack-mcp-server#slack-bot-setup).' Drops the now-redundant helperLink field. Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump @openhands/extensions to b45d3a1 (SLACK_TEAM_ID helperText rewrite) Update SLACK_TEAM_ID helperText to named links: 'First get your [Slack URL](...). Then use that to get your [Workspace ID](...).' Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump @openhands/extensions to 84a0a6e (SLACK_BOT_TOKEN named link) Update SLACK_BOT_TOKEN helperText to: "You'll need to create or update a [Slack App](...#slack-bot-setup)." Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump @openhands/extensions to e07f427 (SLACK_BOT_TOKEN helperText) Update SLACK_BOT_TOKEN helperText to: "You'll need to create or update a [Slack App](...) to get a Bot token" Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump @openhands/extensions to 5efd1b8 Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285). Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump @openhands/extensions to 952c759 Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285). Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump @openhands/extensions to f30dbfb Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285). Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump @openhands/extensions to 02715f4 Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285). Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump @openhands/extensions to cb092c8 Sync to latest commit on slack-catalog-field-order-and-helper-links (PR #285). Co-authored-by: openhands <openhands@all-hands.dev> * fix(mcp): validate URL scheme in renderHelperText; use matchAll - Guard href against javascript:/data: XSS via /^https?:\/\//i test - Replace exec-in-while with matchAll to drop the eslint-disable comment Addresses review bot feedback on PR #1012. Co-authored-by: openhands <openhands@all-hands.dev> * fix(mcp): use double quotes for fallback href to satisfy Prettier Co-authored-by: openhands <openhands@all-hands.dev> * chore: update @openhands/extensions to latest main (62594156) Co-authored-by: openhands <openhands@all-hands.dev> --------- Co-authored-by: openhands <openhands@all-hands.dev> * chore: bump version to 1.0.0-beta.6 * chore: bump version to 1.0.0-beta.7 * fix(mcp): drop duplicate renderHelperText after main merge * chore: bump version to 1.0.0-beta.8 * docs: update README version to 1.0.0-beta.8 * fix: default LLM setup to Anthropic Claude Opus 4.8 (#1089) * chore: bump version to 1.0.0-beta.9 * docs: update README version to 1.0.0-beta.9 * docs: update README.windows.md version to 1.0.0-beta.9 * fix(dev): align Vite dev origin with ingress and add chat footer padding Route modules loaded from :3001 while the app opened on :8000, causing blank screens on npm run dev. Point Vite server.origin/HMR at the ingress URL and add bottom spacing under the archived conversation banner footer. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): polish spinners, settings empty states, and archived conversation UX Remove grey track rings from all loading spinners so only the animated arc remains visible. Wrap bare settings empty/error messages (SDK schema unavailable, profile load failures, empty profiles/skills/secrets/MCP) in the shared bordered empty-state container for visual consistency. Canonicalize 127.0.0.1 backend URLs to localhost so health probes reach the ingress proxy instead of Vite HMR on macOS dual-stack dev stacks, and sync stored default-local backend host alongside the session key. Disable conversation controls for archived sandboxes (MISSING/ERROR) with tooltips explaining unavailability, using shared archive-status helpers. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): restore light foreground on conversation tab loading state Use the semantic text-foreground token for the spinner and label so loading copy stays readable on the dark surface background. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): polish conversation tab loading and automations empty state Conversation tab loading: - Use TextShimmer on the loading label (same treatment as message sending) with block w-full text-center so the sweep flows across the word, not per character - Keep the spinner on text-tertiary-light for readable secondary grey - Add ConversationTabContentCrossfade to cross-fade between loading and loaded content (agent init and lazy tab chunks); content preloads underneath at opacity 0 while the overlay fades out over 350ms; reduced-motion falls back to an instant swap Automations empty state: - Add a top border above the create-instructions section to separate it from the hint copy Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): unify drawer empty/loading states and polish browser/files tabs Align Changes, VS Code, and runtime waiting states with shared drawer patterns, add browser chrome bar with inactive nav when empty, and improve Files tab empty state and tree toggle icon. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): remove browser screenshot rounding and improve panel fill Drop rounded corners on the screenshot viewer and use min-h-0 flex layout so the browser tab fills the drawer edge-to-edge and collapses correctly. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): polish protip banner, browser chrome, and tab crossfade Hide non-functional browser nav controls, restyle the changes-tab protip with icon and muted subtext, drop Customize label colons, and fix Suspense fallback setState during render. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): move VS Code to files toolbar and refresh drawer icons Relocate editor access from the drawer Code tab into a bordered Files toolbar button, swap tab icons to Lucide, add a terminal empty state, and update the VS Code logo asset. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): animate drawer tab label reveal and icon shifts Use Framer Motion layout transitions so the active tab label expands in and sibling icons slide smoothly when switching drawer tabs. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): pin VS Code in drawer tab row and fix tab drag animation Move VS Code to the drawer header, portal the overflow menu so it is not clipped, and disable tab layout animations while resizing the panel so icons only animate on click. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): shrink drawer tab icons to match standard chrome size Use h-4 w-4 for drawer tab icons so they align with the ellipsis and other inline controls in the top row. Co-authored-by: Cursor <cursoragent@cursor.com> * feat(home): allow changing repo, branch, or workspace before launch Replace static git-control-bar link chips on the home screen with the same dropdowns used in the open-workspace and open-repository dialogs so users can revise their selection until they send the first message. Co-authored-by: Cursor <cursoragent@cursor.com> * Revert "feat(home): allow changing repo, branch, or workspace before launch" This reverts commit 569bf18bd18dbbe2bd2eaec5747737a162079e0e. * refactor: remove unrelated files * refactor: remove unrelated files * refactor: remove unrelated files * refactor: remove unrelated files * refactor: remove unrelated files * refactor: vscode tab --------- Co-authored-by: openhands <openhands@all-hands.dev> Co-authored-by: Tim O'Farrell <tofarr@gmail.com> Co-authored-by: Rohit Malhotra <rohitvinodmalhotra@gmail.com> Co-authored-by: chuckbutkus <chuck@openhands.dev> Co-authored-by: Hiep Le <69354317+hieptl@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: hieptl <hieptl.developer@gmail.com>