Commit Graph
732 Commits
Author SHA1 Message Date
Federico Jaramillo Martinez d29fbb98b2 Merge pull request #70 from jmfederico/agent/issue-67
fix(terminals): load interactive login profiles
2026-07-18 21:46:57 +02:00
Federico Jaramillo Martinez 55cc1b7a3b test(auth): cover completion machine affinity
Verify that an auth flow's terminal status refresh remains targeted at the flow's originating machine after the selected machine changes.\n\nRefs #74
2026-07-18 21:18:53 +02:00
Federico Jaramillo Martinez 62396c3165 fix(auth): bind flows to their originating machine
Retain client-owned machine affinity for each interactive auth flow and use it for prompt responses, polling, cancellation, and completion refreshes. This prevents a later machine selection from forwarding secrets to a different remote.\n\nRefs #74
2026-07-18 21:09:51 +02:00
Federico Jaramillo Martinez 67f673b227 fix(auth): cancel stale started flows
Best-effort cancel a running auth flow when its start response arrives after the browser operation was closed or superseded, so sessiond does not retain orphaned provider polling or callback listeners.\n\nRefs #72
2026-07-18 20:55:28 +02:00
Federico Jaramillo Martinez bd99c44286 Merge pull request #71 from jmfederico/agent/issue-68
fix(sessions): surface extension command notifications
2026-07-18 20:54:39 +02:00
Federico Jaramillo Martinez d72a0012c7 fix(sessions): surface extension command notifications 2026-07-18 20:49:41 +02:00
Federico Jaramillo Martinez 2b1507ba35 fix(terminals): load interactive login profiles 2026-07-18 20:47:07 +02:00
Federico Jaramillo Martinez d2e2d512cd Merge pull request #64 from jmfederico/fix/issue-62-authstorage
fix: migrate auth/model plumbing to ModelRuntime (fixes #62)
2026-07-18 18:20:03 +02:00
Federico Jaramillo Martinez 5ebcd34690 docs: clarify supported Pi range 2026-07-18 08:40:12 +02:00
Federico Jaramillo Martinez 65350fd1b5 fix(realtime): terminate failed sockets 2026-07-18 08:33:51 +02:00
Federico Jaramillo Martinez c569a03f54 fix(auth): make API-key setup and status truthful 2026-07-18 08:28:03 +02:00
Federico Jaramillo Martinez cc8f379143 fix(auth): invalidate stale browser OAuth operations 2026-07-18 08:06:18 +02:00
Federico Jaramillo Martinez 3c3741b565 fix(auth): reconcile committed OAuth cancellation 2026-07-18 07:48:27 +02:00
Federico Jaramillo Martinez aca168a311 fix(runtime): align supported requirements and release hygiene 2026-07-18 00:10:47 +02:00
Federico Jaramillo Martinez 1f13bab58a fix(realtime): isolate notification failures 2026-07-17 23:58:56 +02:00
Federico Jaramillo Martinez 45f068ef05 fix(runtime): reload model config at service boundaries 2026-07-17 23:48:32 +02:00
Federico Jaramillo Martinez 3a208e648e fix(auth): preserve OAuth interaction semantics 2026-07-17 23:34:58 +02:00
Federico Jaramillo Martinez a39cf49f3a fix(auth): prevent API key reuse across login prompts 2026-07-17 23:18:58 +02:00
Federico Jaramillo Martinez fe9374c059 Merge pull request #66 from jmfederico/fix/flaky-filetree-truncation-test
test: stabilize fileTreeService truncation test on slow filesystems
2026-07-17 23:09:41 +02:00
Federico Jaramillo Martinez 68d8bd1788 test: stabilize fileTreeService truncation test on slow filesystems 2026-07-17 23:03:13 +02:00
Federico Jaramillo Martinez 71ca256015 Merge pull request #65 from jmfederico/cleanup/auth-provider-hardcodes
refactor: derive auth-provider login options from SDK data
2026-07-17 23:01:41 +02:00
Federico Jaramillo Martinez 910c6b5ae0 refactor: derive auth-provider login options from SDK data instead of hardcoded provider lists 2026-07-17 22:57:33 +02:00
Federico Jaramillo Martinez 50defbae58 refactor(test): remove unused template-inspection helpers
Remove the three shared template-inspection test helpers that had no
consumer after the Slice B migrations: templateStaticMarkup,
collectTemplateStrings, and collectStringValues. They were kept alive
only by a temporary @public knip shim; with no in-window test needing
them, the finish-line requirement forbids dead helpers, so remove them
outright. knip is now satisfied without the shim.
2026-07-17 22:17:09 +02:00
Federico Jaramillo Martinez 28f328f475 refactor(test): use deterministic waits instead of sleeps in spawnSubsession test 2026-07-17 22:10:25 +02:00
Federico Jaramillo Martinez f539193c3d docs(changeset): add Pi 0.80.8+ ModelRuntime auth migration changeset (slice 6)
Relay issue-62-authstorage leg 7 (final): add patch changeset for the
session-daemon crash fix on Pi >=0.80.8, re-verify green, confirm goal
criteria and cleanup. Relay complete.
2026-07-17 22:01:36 +02:00
Federico Jaramillo Martinez dafc2d9c5f relay(issue-62-authstorage): leg 6 status/log (slice 5 done, verify green) 2026-07-17 21:58:54 +02:00
Federico Jaramillo Martinez d0cc55cce3 Migrate test doubles + testSupport to ModelRuntime/InMemoryCredentialStore (slice 5)
Replace AuthStorage.inMemory / ModelRegistry.create|inMemory across all test
and support code with the pi-ai InMemoryCredentialStore + async
ModelRuntime.create({ credentials }). Add shared test-runtime seams
(createTestModelRuntime, testModelRuntime, seedCredential) in testSupport.ts
and thread modelRuntime into fakeRuntime and every PiSessionService
construction (now a required dependency). Rework the anthropic subscription
warning tests onto a temp auth.json seam read via readStoredCredential, and
the auth-loss warning test onto a live credential store + runtime refresh.
Make getLoginProviderOptions synchronous and fix associated await/lint sites.

npm run verify green (typecheck + lint + knip + 1390 tests).
2026-07-17 21:56:53 +02:00
Federico Jaramillo Martinez 0c04c9b19c refactor(test): use vi.waitFor instead of sleeps in promptQueue test 2026-07-17 21:54:29 +02:00
Federico Jaramillo Martinez 2d7ff629be refactor(test): migrate promptAttachmentCapture.test.ts to shared template-inspection seam 2026-07-17 21:47:28 +02:00
Federico Jaramillo Martinez 9a94f41a61 refactor(test): migrate ChatView.test.ts to shared template-inspection seam
Reclassify ChatView.test.ts per the testing-guide skill: move content/text/
attribute/ordering assertions to new pure public seams on ChatView.ts
(chatSessionWarningRows, chatQueuedSectionShowsClearAction, chatGroupAnchorKey,
chatEventAnchorKey, chatGroupScrollMarkerId, chatMessageGroupClassName,
chatMessageGroupLabel) with the component render code delegating to them, and
route the genuine Clear-queue/dismiss/toggle event wiring through the shared
templateInspection.testSupport helpers with escape-hatch comments. Delete the
per-file TemplateResult-inspection cluster. Drop the now-consumed @public tag
from templateEventHandlerNearMarker.
2026-07-17 21:37:30 +02:00
Federico Jaramillo Martinez 0706cc26a5 relay(issue-62-authstorage): leg 5 status/log (slice 4 done) 2026-07-17 21:33:14 +02:00
Federico Jaramillo Martinez 4ccd4f81fc Migrate piSessionService to ModelRuntime (slice 4)
Pass modelRuntime to createAgentSessionServices instead of authStorage +
modelRegistry; carry ModelRuntime on PiAgentSession; make modelRuntime a
required PiSessionService dependency (sessiond already injects auth.runtime).
Switch anthropicSubscriptionWarning to readStoredCredential, and rederive
model reads (availableModels/setModel/syncCurrentModelAuthWarning) via the
runtime (getAvailableSnapshot/getModel/hasConfiguredAuth). sessiond.ts and
piSessionService.ts now typecheck; only slice-5 test/support files remain.
2026-07-17 21:32:02 +02:00
Federico Jaramillo Martinez 6ba215503f refactor(test): migrate ChatView image test to shared inspection seam
Replace the per-file TemplateResult inspection helper cluster in
ChatView.image.test.ts with the shared templateInspection.testSupport
escape hatch for genuine event wiring (@load re-pin, @click zoom), and
move content/attribute assertions to new pure public seams on ChatView
(chatImagePartSource, chatToolOutputLabel, chatMessageAnchorKey) that
the component's own render code now delegates to.
2026-07-17 21:15:35 +02:00
Federico Jaramillo Martinez 7543982e3b Relay issue-62-authstorage: leg 4 handoff (slice 3 complete) 2026-07-17 21:10:32 +02:00
Federico Jaramillo Martinez 1c3d6db109 Migrate oauthLoginFlowService to pi-ai AuthInteraction contract
Reimplement OAuthLoginFlowService against the pi-ai AuthInteraction
({ signal?, prompt(AuthPrompt), notify(AuthEvent) }) contract instead of
the removed OAuthLoginCallbacks shape, and drive login via
runtime.login(providerId, "oauth", interaction). start() now takes a
ModelRuntime instead of authStorage, resolving the authService.ts line-83
error. AuthPrompt text/secret/manual_code/select map onto the existing
web-UI prompt/select flow state; auth_url/device_code map onto the auth
field; info/progress append to progress. Per-prompt AuthPrompt.signal now
cancels just that pending request without ending the flow.

Slice 3 of the issue-62 authStorage migration relay.
2026-07-17 21:09:39 +02:00
Federico Jaramillo Martinez d02bbfa545 refactor(test): migrate WorkspaceFilesPanel test to shared template-inspection seam
Route genuine Lit event-wiring (upload input change, form submit, file-tree
row clicks) through the shared templateInspection.testSupport escape hatch and
add the required proportionality comment. Move viewer content messaging
(empty/loading/binary states) to a new public workspaceFileViewerStatusLabel
seam on the component instead of scraping Lit markup for text. Delete the
per-file inspection helper cluster; drop @public from the two shared helpers
that now have a real importer.
2026-07-17 21:06:12 +02:00
Federico Jaramillo Martinez d273a3d8c4 relay issue-62-authstorage: leg 3 (slice 2) status + log 2026-07-17 20:59:39 +02:00
Federico Jaramillo Martinez d09d7cc1ff Migrate authProviderOptions to ModelRuntime API
Rederive login/logout provider options from runtime.getProviders() +
listCredentials() + getProviderAuthStatus() instead of the removed
authStorage.getOAuthProviders()/list()/get() + getAll()/
getProviderDisplayName() surface (Pi 0.80.8+).

- Replace the AuthProviderModelRegistry structural interface with a
  runtime-shaped AuthProviderRuntime (getProviders/listCredentials/
  getProviderAuthStatus); a real ModelRuntime satisfies it.
- Make getLoginProviderOptions/getLogoutProviderOptions async to match
  the await call sites already in authService.ts.
- OAuth-capable providers = auth.oauth present; api-key providers =
  auth.apiKey present, preserving OAUTH_ONLY_PROVIDERS /
  isApiKeyLoginProvider logic. Display names from Provider.name.
- Update the test double to the new runtime shape.

Slice 2 of the authStorage migration relay. tsc: 31 -> 28 errors
(remaining are cross-slice: slices 3/4/5).
2026-07-17 20:58:46 +02:00
Federico Jaramillo Martinez 842e651658 relay issue-62-authstorage: leg 2 status/log (slice 1 done) 2026-07-17 20:54:56 +02:00
Federico Jaramillo Martinez e37148c193 Migrate authService to async ModelRuntime API (slice 1)
Move AuthService off the removed AuthStorage / ModelRegistry.create surface
onto the async ModelRuntime API:

- AuthService.create({ agentDir | runtime }) async factory wrapping
  ModelRuntime.create({ authPath, modelsPath }); createModelRuntimeForAgentDir
  replaces createModelRegistryForAgentDir.
- saveApiKey -> runtime.login(providerId, "api_key", nonInteractive) so the
  key is persisted through the runtime credential store.
- logoutProvider -> runtime.logout; refreshAuthState -> await runtime.refresh().
- startOAuthLogin now passes the runtime into OAuthLoginFlowService.start.
- authProviders/requireOAuthLoginProvider became async around getLogin/Logout
  provider options.
- sessiond.ts: async createRuntime, AuthService.create, pass modelRuntime to
  PiSessionService; sessionDaemonStartup awaits createRuntime.

Cross-slice: authProviderOptions (2), oauthLoginFlowService (3), and
piSessionService (4) still expose the old ModelRegistry shape, so the tree does
not fully typecheck yet. Session-daemon path changed -> manual sessiond restart
needed once the migration lands.
2026-07-17 20:53:42 +02:00
Federico Jaramillo Martinez e7926e173b refactor(test): route SettingsDialog panel test through a public seam
Replace the SettingsDialog.general.test.ts markup-scraping assertion (which
scraped the rendered TemplateResult for '<settings-general-panel', 'scope-note',
'This tab edits:') with an exported pure routing seam activeSettingsPanelTag()
and assert the section->panel contract directly. Delete the now-unused
collectTemplateStrings helper and its private template-reflection cluster from
SettingsDialog.testSupport.ts.

The .packages/.plugins/.sessiond siblings inspect no TemplateResult internals
(orchestration reflection only), so no migration was needed for them.
2026-07-17 20:48:17 +02:00
Federico Jaramillo Martinez 946f7612ae refactor(test): move SettingsSessiondPanel assertions to a public seam
Migrate the prime Finding-2 offender off Lit TemplateResult scraping. The
panel's dynamic notice-stack logic is extracted into an exported pure
sessiondPanelNotices() (plus SessiondPanelNoticeContext) and the existing
sessiondDescription is exported, so the test asserts notice
composition/ordering and the scope description through public seams instead of
flattening rendered template internals. Save and draft-preservation behavior
are observed via the injected onSave callback and public state.

Removes all per-file template-inspection helpers and the escape-hatch need for
this file (testing-guide Findings 1-3).
2026-07-17 20:41:49 +02:00
Federico Jaramillo Martinez 585c3bc89d docs(issue-62): record relay leg 1 (bootstrap) in packet 2026-07-17 20:36:05 +02:00
Federico Jaramillo Martinez 0fa9d0e4d2 chore(deps): require pi 0.80.8+ and correct dep ranges (issue #62)
Bump the three @earendil-works/* devDependencies to ^0.80.8 and tighten
peerDependencies from '>=0.80.0 <1' to '>=0.80.8 <0.81' so npm cannot
resolve the pre-0.80.8 line that still expected the removed AuthStorage
export. Installed lockfile pins 0.80.10.

The new export surface (ModelRuntime, readStoredCredential,
InMemoryCredentialStore) now resolves; remaining typecheck errors point at
the auth/model-registry migration sites under src/server/sessions/ and are
addressed in the following relay legs.

Refs #62
2026-07-17 20:35:16 +02:00
Federico Jaramillo Martinez 8225cf6fcd docs(issue-62): add relay plan for AuthStorage->ModelRuntime migration 2026-07-17 20:29:21 +02:00
Federico Jaramillo Martinez 9436c308c3 docs(issue-62): assess AuthStorage removal in Pi 0.80.8 2026-07-17 20:29:21 +02:00
Federico Jaramillo Martinez 55bc567b7b refactor(test): add shared template-inspection test helper (Slice A)
Consolidate the duplicated, per-file Lit TemplateResult inspection helper
cluster into one shared, strictly-typed, type-guarded seam at
src/client/src/templateInspection.testSupport.ts, documented as the
testing-guide escape hatch. Migrate PiWebApp.clearQueue.test.ts to it as a
proof and delete its local copies. Tag not-yet-consumed public entry points
with @public so knip does not flag them until Slice B adds consumers.

Relay: testing-skill-compliance leg 1 (Finding 1).
2026-07-17 20:23:21 +02:00
Federico Jaramillo Martinez caaa8c4ebc docs(test): audit testing-guide compliance gaps for fix relay 2026-07-17 19:35:40 +02:00
Federico Jaramillo Martinez aedcbf885e feat(sessions): surface live session startup warnings in the web UI
Show a pinned banner at the top of the session view with resource and
runtime diagnostics (skills, prompts, themes, extension load errors) plus
the Anthropic subscription-auth billing notice, recomputed live from the
current runtime so they stay accurate across browser reloads.

Warnings carry an optional dismiss capability; the Anthropic notice is
dismissable and durably suppressed through pi's own anthropicExtraUsage
warning setting. Also fixes the testing-guide skill frontmatter so it
loads.
2026-07-17 19:16:58 +02:00
Federico Jaramillo Martinez 2b17145291 feat(sessions): stream in-flight partial when joining a mid-turn session
Seed the in-flight partial assistant message (text, thinking, and
in-progress tool calls) when opening or reconnecting to a session that is
mid-stream, then continue streaming live deltas on top of it. Replaces the
blocking "Catching up..." placeholder and the end-of-turn transcript reload.

Server stamps every per-session UI event with a monotonic seq at the
SessionEventHub publish choke point and exposes
GET /sessions/:sessionId/stream-snapshot returning { seq, partial }. The
client fetches the snapshot on join, seeds the normalized partial into the
in-memory transcript (never the history cache), and applies buffered/live
events using the seq watermark for exactly-once delivery.

The snapshot is a progressive enhancement: a 404 from an older remote
pi-web or a not-yet-restarted session daemon falls back to an empty seed
(seq 0, drops nothing), so sessions still open and stream normally. The
stream-snapshot route is registered in the federation allowlist for
remote-machine proxying.
2026-07-17 14:49:56 +02:00