* fix(github): load PR diffs for Enterprise remotes
* fix(github): encode PR content paths by segment
* Fix PR review actions failing on GitHub Enterprise remotes
- Threads GitHub host identity (not just owner/repo) through the client,
work-item-details, issues, and RPC layers so gh commands target the
correct Enterprise server instead of silently falling back to github.com
- Adds a shared github-api-repository helper to resolve/host-qualify repo
identity consistently across REST, GraphQL, and CLI shorthand calls
- Scopes the gh rate-limit breaker and singleton rate-limit snapshot by
host/runtime so a github.com block or probe can't affect GHES or WSL
- Coalesces concurrent host-auth probes and paginates PR file fetching
beyond 100 results
- Propagates `host` through renderer PR caches, checks-panel keys, and
preload IPC types so Enterprise and github.com data never collide
* Route gh host qualification through runner options instead of argv sniff
Move GHES/GH_HOST resolution from parsing --hostname/--repo out of gh argv to an explicit options.host passed through ghExecFileAsync, since SSH-backed repos spawn gh with no cwd and argv sniffing couldn't reliably detect the target host. The runner now injects --hostname and qualifies --repo/-R at spawn time from options.host, and rate-limit scoping/guards use the same explicit host instead of inferring it. Also adds a shared githubRepoIdentityKey helper to keep cache/store keys consistent with the new host-aware repository identity.
* Fix gh CLI GHES host pinning and rate-limit scope leaks
- Pin `--host` on every gh call site so a process-level GH_HOST can't
silently redirect requests, and qualify `-R`/`-R=` repo shorthand
alongside the existing `--repo=` handling.
- Check the target scope for an active rate-limit block before each
WSL/native or host fallback retry, not just on the initial attempt,
so a blocked scope can't be hit again through a fallback path.
- Compute idempotency once per call instead of re-deriving it after
fallback reassigns args.
* Fix GitHub Enterprise host identity loss across PR/work-item paths
- Thread `host` through mobile PR RPC params, IPC work-item lookups, and
RPC schemas so GHES identity survives the renderer/mobile/main boundary
instead of silently falling back to a same-named github.com repo.
- Qualify `--repo`/`-R` args for github.com too (not just GHES), since
gh resolves bare shorthand against a process-level GH_HOST that can
redirect pinned github.com commands.
- Cache `getOriginGitHubApiRepository` to avoid a per-call uncached
`git remote get-url` round trip on connection-backed repos.
- Add a local-fork fallback in `getWorkItemDetails` so PRs living on a
base repo (not visible via the origin slug) still resolve via cwd.
- Centralize the github.com-vs-GHES host predicate in
`isDefaultGitHubHost` so cache keys, quota scoping, and identity
checks can't drift out of sync.
* Make repository identity host-aware across all GitHub surfaces
Generalize the auth-gated enterprise resolver to any remote and build a
cached hosted-identity family (origin/issue/candidates/source) on top of
it, then migrate every github.com-only consumer: Tasks listing/counting,
branch-to-PR discovery, push targets, fork upstream, issue operations,
Projects, web links, avatars, and PR-link facts. Scope the rate-limit
breaker probe per runtime:host and classify WSL UNC cwds correctly.
Co-authored-by: Orca <help@stably.ai>
* Fix expected slug to include host field in GitHub PR link test
Updates the smart-source paste-intent test fixture to match the
repository slug shape that now carries a `host` field, keeping GHES
host identity intact through the paste-intent parsing path.
* Surface per-host gh auth state for GitHub Enterprise
diagnoseGhAuth accepts the host a surface needs credentials for, scopes
the account/scope diagnosis to that host, and reports whether gh has any
login there; GhAuthErrorHelp renders host-qualified login/refresh
commands so an unauthenticated GHES host stops masquerading as a
github.com scope problem. Also fixes the mobile paste-intent expectation
for host-carrying parsed links.
Co-authored-by: Orca <help@stably.ai>
* Bound GHES identity caches and preserve non-default ports in host identity
Cap the origin-repo and host-auth caches like ownerRepoCache; keep ports
from remote/link URLs so GHES on a non-default port is a distinct
identity; make positional github.com slugs explicit against GH_HOST;
compare work-item sources by host-aware identity key; bail cwd-less
branch lookups when no repository candidate resolved; thread host
through the renderer work-item slug lookup.
Co-authored-by: Orca <help@stably.ai>
* Thread GitHub host through issue detail requests
Incorporates ghes-issue-host-support (ed6bb96ef): one hosted issue
repository identity is resolved before the details fan-out so comments,
timeline, participants, and mention lookups cannot drift across hosts,
with SSH guards so unresolved issue/PR repositories never fall through
to gh's default host.
Co-authored-by: Orca <help@stably.ai>
* Scope remaining GitHub rate-limit accounting
* Resolve typed PR lookups across hosted repository candidates
getWorkItem's PR path probes upstream-then-origin hosted candidates
instead of origin alone, so fork checkouts resolve the base repo's PR
with the right host; issue detail resolution reuses the up-front hosted
identity and keeps the SSH unresolved-host guards.
Co-authored-by: Orca <help@stably.ai>
* Refactor GitHub repository execution setup
* Carry host on smart-submit link intents
Co-authored-by: Orca <help@stably.ai>
* Carry the project host on GitHub item dialog origins
Co-authored-by: Orca <help@stably.ai>
* Keep GHES web ports but drop SSH transport ports in host identity
Supersedes PR #9118 on this branch: http(s) remote ports identify the
Enterprise web/API endpoint and are preserved, while ssh/git transport
ports (including ssh.github.com:443) never leak into gh's host identity.
Replaces the ssh.github.com:443 special case with the structural
protocol split and ports the PR's parsing test suite.
Co-authored-by: Orca <help@stably.ai>
* Support GitHub Enterprise diffs and mutations with host-scoped caches
Parse GitHub host identity from work-item URLs and carry it through PR/issue mutations, labels, and assignments. Bound rate-limit and scope-probe caches (1024 and 512 entries) to prevent unbounded growth when interacting with multiple GHES instances. Normalize repository identity keys to include host so github.com and GHES slugs don't collide in cache and equality checks.
* Support GitHub Enterprise diffs and mutations with host-scoped caches
- Carry host identity through PR mutations and reads so fork PRs on
different GHES instances don't collide in cache or state tracking.
- Validate host authentication before routing requests to unconfigured
Enterprise servers; ambient credentials must never reach untrusted hosts.
- Scope rate-limit guards and spend tracking per host so GHES quota stays
independent from github.com quota.
- Respect explicit --hostname arguments in gh CLI calls ahead of GH_HOST or
ambient defaults, so breaker state follows the actual request target.
- Detect implicit WSL runtimes from UNC paths for consistent host auth and
execution-options scoping across mobile and desktop clients.
* Support GitHub Enterprise work-item diffs with host-scoped execution
Enterprise PRs must use their selected host consistently across diff, comments,
and file-content loads. Validate repository slugs before authenticated execution
to prevent path-injection via renderer overrides. Scope project browsing cache
and rate-limit tracking by host to prevent cross-host pollution. Use parsed
URLs as authoritative over ambient hosts for project resolution.
* Support GitHub Enterprise work-item diffs with host-scoped execution
Preserve host identity on PR/issue work items throughout the mutation and diff
pipeline so Enterprise instances (including ported endpoints like
github.acme.test:8443) can execute mutations without ambiguity. Rate-limit gh
commands by the pre-qualified --repo host, cache auth state per ported host,
and surface Enterprise hosts in project metadata and error messages.
* fix(review): drop dead rateLimitGuard/noteRateLimitSpend re-export
Both callers (project-view.ts, mutations.ts) moved to the host-scoped
repositoryRateLimitGuard/noteRepositoryRateLimitSpend; the bucket-only
re-export in internals.ts had zero importers left.
Co-authored-by: Orca <help@stably.ai>
* fix(ci): split Enterprise host work-item tests under max-lines
Move GHES/SSH host-routing cases out of work-item-details.test.ts so
the suite stays within the 800-line test max-lines budget.
* test(github): align mocks with host-scoped repository resolution
- Route origin repository resolution through getOwnerRepoForRemote, not getOwnerRepo, to match production path
- Pin github.com host on origin results so host-less fixtures pass host gate in resolveGitHubApiRepository
- Add generation-based invalidation to prevent stale slug-cache writes from in-flight resolutions
- Fix ref-sync race in ProjectPicker: use useLayoutEffect so committed tree owns browse cache key
- Defer handledCrossRepoUrlRef assignment in SmartWorkspaceNameField until resolution succeeds
- Update Enterprise host routing: found work items must not silently fall back to default host when unresolved
- Normalize GHES avatar URLs: accept explicit port 443 as canonical form, not a fallback trigger
---------
Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
Co-authored-by: Orca <help@stably.ai>
* fix(issues): replace cursor-based pagination with page-number Search API
Problem
=======
Issue pagination (#8649) had two bugs:
1. Pages 6-16 were unreachable — clicking page 16 highlighted page 5;
clicking 6/7 did nothing. The old cursor-based approach
(updated:<CURSOR) broke with Search API's relevance sorting —
pages after the first few returned no items even though more
issues existed.
2. Issue numbers appeared out of order on loaded pages (e.g. #1082
between #1308 and #1499), because client-side sort used
updatedAt instead of issue number.
Root Cause
==========
The pagination used two separate GitHub API strategies:
- Initial page 0 load: REST endpoints (repos/:owner/:repo/issues,
repos/:owner/:repo/pulls) sorted by updatedAt
- Subsequent pages: Search API with cursor (updated:<DATE)
These two sources returned items in different orders, causing items
to go missing or appear on wrong pages across page boundaries.
Solution
========
1. Unified on GitHub Search API for all pages — initial load and
pagination both use search/issues?q=...&page=N, eliminating the
REST-vs-Search inconsistency.
2. Changed from cursor-based (update:<DATE) to page-number-based
pagination (page=N), which the Search API supports natively.
3. Switched client-side sort from updatedAt to issue number
(sortWorkItemsByNumber), matching GitHub's default Issues view.
4. Parallelized page fetches in handleLoadNextPage — clicking page
16 now fetches all intermediate pages concurrently (~2s) instead
of sequentially (~30s).
5. Cleaned up dead legacy gh issue list / gh pr list code path,
extracted quoteForSearch helper, shortened overlong comments.
Files changed: 11 files, +140/-127 lines
Closes#8649
* chore: remove unrelated merge formatting
---------
Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
* chore(lint): upgrade oxlint to 1.71 and enable 7 new rules
Upgrade oxlint 1.67.0 -> 1.71.0 (1.72 was blocked by the repo's 3-day
minimum-release-age supply-chain guard; nothing here needs it). The
bump is a no-op on the existing config.
Enable 3 error rules (backlog autofixed to zero in this commit) and
4 warn rules (surface signal without gating CI):
error (autofixed, behavior-preserving):
- unicorn/prefer-node-protocol (~1531 sites: bare builtin -> node:)
- typescript/no-import-type-side-effects (~36: all-inline-type -> import type)
- unicorn/no-array-reverse (19: copy-then-reverse -> toReversed)
warn (real signal, current fires are test-only/correct):
- unicorn/no-array-fill-with-reference-type (aliasing footgun guard)
- typescript/no-unsafe-function-type (bans bare Function type)
- unicorn/prefer-array-flat-map (map().flat() -> flatMap())
- unicorn/prefer-regexp-test (.match() in bool ctx -> .test())
mobile/.oxlintrc.json extends root, so it inherits all 7; the autofix
ran from root and covered mobile/ too.
Verification (all green): oxlint 0 errors (root+mobile+aux configs),
oxfmt clean, typecheck (node+cli+web), vitest 22795 passed / 0 failed,
builds (electron-vite + web + cli) succeed. node: rewrites confirmed to
skip embedded SSH/CLI string payloads (AST-only); all toReversed sites
verified to operate on fresh copies or write-once locals.
* chore(lint): bump mobile oxlint to 1.71 so inherited rules parse
mobile/ is a standalone pnpm project pinning its own oxlint@1.67, which
lacks unicorn/no-array-fill-with-reference-type (needs >=1.70). Since
mobile/.oxlintrc.json extends the root config, mobile CI's 'cd mobile &&
oxlint' failed to parse the new rule. Bump mobile to match root (1.71).
Verified in mobile/: oxlint 0 errors, oxfmt --check clean, tsc --noEmit
pass, vitest 978 passed / 0 failed.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
Ensure that when a visible fallback PR has been merged (e.g., outside
Orca with a deleted head branch), it is still accepted and refreshed by
branch lookup instead of being discarded as an implicit merged PR.
* Add `acceptMergedFallbackPR` option to GitHub branch lookups
* Enable this option during manual and background refreshes of fallback PRs
* Plumb the new option through preload APIs, IPC handlers, and RPC protocols
- Retrieve and propagate `autoMergeAllowed` from GitHub repo metadata.
- Suppress auto-merge action in UI if disallowed by the repository.
- Support specifying the merge method (e.g., squash) when auto-merging.
* Restore the outlined server card for host headers
Feedback: the bordered card with the server glyph made it clearer that
a host section is a separate machine, not just another group. Bring
that back while keeping the recent quieting: no status dot when
healthy (marks only for connecting/blocked/error/disconnected), no
'This computer' detail on the local host, and collapse/menu/count
behavior unchanged.
Co-authored-by: Orca <help@stably.ai>
* Anchor host badge to its label, indent rows under host cards
Sidebar polish from review:
- The count badge sat in dead space between the label and the
hover-only chevron/menu; it now hugs the label like repo headers
- Rows under a host card get a left inset so projects and workspaces
visibly belong to the machine above them
- A host whose only visible row is a collapsed repo group counted 0
while the group badge said 9; host counts now fall back to header
counts for groups contributing no visible items
Co-authored-by: Orca <help@stably.ai>
* Two-tier sticky headers: pinned host card above pinned group header
When scrolling inside a host section, the host card now stays pinned at
the top (z-30) while project/status group headers hand off beneath it
(z-20, offset by the pinned card height). The host is the outer
hierarchy level, so it is the most persistent context — previously the
first repo header replaced it, losing 'which machine am I on' exactly
when it mattered. The pinned card keeps its collapse/menu/warning
affordances. Handoff rules: the next host card pushes the previous one
out at the viewport top; a group pins only once it reaches the slot
beneath the host card, and a previous host's group can never pin under
the next host. Without host sections the logic degrades to the original
single-tier behavior.
Co-authored-by: Orca <help@stably.ai>
* Revert host-section row indent
The two-tier sticky host card now provides continuous 'inside this
machine' context at any scroll depth, making the static indent
redundant — and it cost 12px of sidebar width on every row while
making multi-host layouts misalign with single-host ones. Host cards
bracketing their sections plus the pinned header carry the ownership
signal on their own.
Co-authored-by: Orca <help@stably.ai>
* Checkpoint multi-host sidebar and project-first notes
Co-authored-by: Orca <help@stably.ai>
* Add project-first compatibility persistence
Co-authored-by: Orca <help@stably.ai>
* Expose project host setup APIs
Co-authored-by: Orca <help@stably.ai>
* Group sidebar rows by project setup
Co-authored-by: Orca <help@stably.ai>
* Document project-first host model discussion
Co-authored-by: Orca <help@stably.ai>
* Resolve workspace creation through project host setups
Co-authored-by: Orca <help@stably.ai>
* Stamp workspace ownership with project host setup
Co-authored-by: Orca <help@stably.ai>
* Add project host setup existing folder API
Co-authored-by: Orca <help@stably.ai>
* Summarize project-first host model discussion
Co-authored-by: Orca <help@stably.ai>
* Add project host setup CLI commands
Co-authored-by: Orca <help@stably.ai>
* Allow CLI worktree creation by project host setup
Co-authored-by: Orca <help@stably.ai>
* Add workspace host setup picker
Co-authored-by: Orca <help@stably.ai>
* Add project host setup settings summary
Co-authored-by: Orca <help@stably.ai>
* Make project host setup settings navigable
Co-authored-by: Orca <help@stably.ai>
* Stabilize project host setup settings selector
Co-authored-by: Orca <help@stably.ai>
* Add project host existing-folder setup form
Co-authored-by: Orca <help@stably.ai>
* Update project host model implementation status
Co-authored-by: Orca <help@stably.ai>
* Keep projects outermost in default sidebar view
Co-authored-by: Orca <help@stably.ai>
* Update project-first sidebar status
Co-authored-by: Orca <help@stably.ai>
* Show host context in project sidebar groups
Co-authored-by: Orca <help@stably.ai>
* Show unavailable hosts in workspace run target
Co-authored-by: Orca <help@stably.ai>
* Import missing project host from composer
Co-authored-by: Orca <help@stably.ai>
* Clone project host setup from composer
Co-authored-by: Orca <help@stably.ai>
* Persist project host setup method
Co-authored-by: Orca <help@stably.ai>
* Clone project hosts over SSH
Co-authored-by: Orca <help@stably.ai>
* Improve SSH clone cancellation cleanup
Co-authored-by: Orca <help@stably.ai>
* Backfill workspace project host ownership
Co-authored-by: Orca <help@stably.ai>
* Gate project host setup runtime capability
Co-authored-by: Orca <help@stably.ai>
* Preserve independent project host setups
Co-authored-by: Orca <help@stably.ai>
* Add project host setup update API
Co-authored-by: Orca <help@stably.ai>
* Add project host setup delete API
Co-authored-by: Orca <help@stably.ai>
* Add project host setup create API
Co-authored-by: Orca <help@stably.ai>
* Expose project host setup lifecycle in renderer store
Co-authored-by: Orca <help@stably.ai>
* Handle independent project host setups in settings
Co-authored-by: Orca <help@stably.ai>
* Add pending host setup action in project settings
Co-authored-by: Orca <help@stably.ai>
* Show pending project host setup status in composer
Co-authored-by: Orca <help@stably.ai>
* Report pending setup state in workspace target resolution
Co-authored-by: Orca <help@stably.ai>
* Use shared host registry for project setup choices
Co-authored-by: Orca <help@stably.ai>
* Add settings clone flow for project host setups
Co-authored-by: Orca <help@stably.ai>
* Gate unavailable project host setup options
Co-authored-by: Orca <help@stably.ai>
* Gate unavailable project setup hosts in settings
Co-authored-by: Orca <help@stably.ai>
* Stream SSH clone progress to renderer
Co-authored-by: Orca <help@stably.ai>
* Update project host model status notes
Co-authored-by: Orca <help@stably.ai>
* Add CLI project host setup clone command
Co-authored-by: Orca <help@stably.ai>
* Make add project host aware
Co-authored-by: Orca <help@stably.ai>
* Complete project host setup validation
Co-authored-by: Orca <help@stably.ai>
* Recover floating workspace terminal WebGL atlas on reopen (#5069)
Co-authored-by: Orca <help@stably.ai>
* Fix stale terminal daemon spawn health (#5064)
Co-authored-by: Orca <help@stably.ai>
* Suspend floating workspace terminal WebGL while the panel is closed (#5073)
Co-authored-by: Orca <help@stably.ai>
* Fix source control branch compare base (#5074)
Co-authored-by: Orca <help@stably.ai>
* Fix workspace-creation tour panel clipped by the Create Worktree dialog (#5078)
* Fix workspace-creation tour panel clipped by the composer dialog
The tour panel portals into dialog/sheet content that clips overflow, but
its position was clamped against the window viewport. With the Project
field spanning nearly the dialog's full width, the panel landed past the
dialog's right edge and overflow-hidden cut it down to a sliver. Clamp
hosted panels within the host's bounds instead, so the panel flips below
the target and stays fully visible.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* Add JSDoc docstrings to satisfy CodeRabbit docstring coverage check
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Test hosted contextual tour overlay positioning
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
* release: v1.4.56
* Handle buffer overflows gracefully and truncate diffs fairly (#5083)
- Gracefully fall back to file-name summaries when staged diffs exceed
node/ssh execution maxBuffer limits, preventing generation failures.
- Split oversized diffs by file and allocate budget via water-filling,
ensuring single huge files do not starve smaller human changes.
- Clip truncated diff sections on line boundaries to avoid half-lines.
* Wrap AI generation controls with tooltips and clean i18n dependencies (#5087)
- Wrap the AI generation button in a tooltip so users can see the
disabled reason or the action description on hover.
- Add unit tests verifying tooltip triggers and aria-label safety.
- Simplify memo dependencies in settings metadata and worktree palette
by using 'useTranslation()' to handle language-change rerenders
directly without needing 'i18n.language'.
* fix: address review findings (#5088)
* Fix localization in repository hooks and base ref suggestion toast (#5089)
* Fix localization in base ref toast and custom hook description
- Localize the "commit"/"commits" plural nouns in the base ref toast.
- Translate missing suggestion toast strings for JA, KO, and ZH locales.
- Pass `{{artifact_url}}` as a literal template variable to translate
calls to prevent i18next from treating it as a dynamic placeholder.
* Fix localization reactivity in RepositoryHooksSection
Move static variables containing translation calls into helper functions
and subscribe to translation updates using useTranslation. This ensures
that localized options, descriptions, and error messages refresh
dynamically when the user changes the UI language.
* Fix task page labels after language changes (#5086)
Co-authored-by: Orca <help@stably.ai>
* release: v1.4.57
* Fix automation tabs showing a shell instead of the live agent (#5099)
* Fix automation tabs showing a shell instead of the live agent
Opening a background automation's terminal tab showed a bare shell while
the agent (Claude) kept running headless — the sidebar updated but the
pane was attached to the wrong PTY.
On first mount the restored ptyId equals the tab ptyId, and
isSessionOwnedByWorktree() returns true for it, so connectPanePty routed
the still-live eagerly-spawned PTY into the daemon-reattach branch
(transport.connect({ sessionId })), which spawns a fresh shell and
orphans the live agent PTY instead of adopting it via attach()+replay.
Part A: gate the deferred reattach on the absence of a live eager buffer.
A live eager buffer means the PTY is a still-running local session to
adopt (attach + replay), not a daemon session to re-connect. Daemon
reattach and remote PTYs are unaffected (gated on the eager buffer).
Part B: publish never-mounted background automation tabs into the runtime
graph (gated on a live eager buffer) so the live agent PTY binds to its
real tab instead of surfacing as an orphan `pty:<id>` terminal — fixing
`orca terminal list`, the CLI, and automation session-reuse.
Adds a characterization test (fails on the old code, passes now) and a
runtime-graph publish test.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Harden eager PTY tab adoption
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
* Fix i18n label spacing in menus and settings (#5108)
* fix i18n label spacing
* Fix localized account runtime labels
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Jinwoo-H <jinwoo0825@gmail.com>
Co-authored-by: Orca <help@stably.ai>
* Improve localization catalog sync workflow (#5110)
Co-authored-by: Orca <help@stably.ai>
* Add Warp terminal theme import (#4714)
Co-authored-by: Orca <help@stably.ai>
* release: v1.4.58
* Tidy README badge layout
* Handle integration credential decrypt failures (#4683)
Co-authored-by: Orca <help@stably.ai>
* Fix git repo telemetry for repo adds (#5121)
Co-authored-by: Orca <help@stably.ai>
* Add feature interaction usage bucket telemetry (#5119)
Co-authored-by: Orca <help@stably.ai>
* Reset WebGL glyph atlases globally to stop cross-terminal glyph corruption (#5122)
Co-authored-by: Orca <help@stably.ai>
* perf(windows): fix 60s startup ACL walk and OpenCode streaming freeze, with benchmark harnesses (#5124)
* release: v1.4.59-rc.0
* Fix packaged shell PATH order (#5125)
Co-authored-by: Orca <help@stably.ai>
* Add Floating Workspace contextual tour (#5062)
* Add floating workspace contextual tour
Co-authored-by: Orca <help@stably.ai>
* Clarify floating workspace tour intro copy
Co-authored-by: Orca <help@stably.ai>
* Differentiate floating workspace tour steps instead of repeating examples
Co-authored-by: Orca <help@stably.ai>
* Lead floating workspace tour with the user benefit
Co-authored-by: Orca <help@stably.ai>
* Pitch floating workspace tour around cross-repo agents
Co-authored-by: Orca <help@stably.ai>
* Refine floating workspace tour step 1 copy
Co-authored-by: Orca <help@stably.ai>
* Anchor floating workspace tour step 2 on the minimize control
Co-authored-by: Orca <help@stably.ai>
* Restore floating workspace tour step 2
Co-authored-by: Orca <help@stably.ai>
* Anchor floating workspace tour steps on New Terminal and New Markdown Note
Co-authored-by: Orca <help@stably.ai>
* Retitle floating workspace tour step 2 as scratchpad
Co-authored-by: Orca <help@stably.ai>
* Add why-comments for tour selector fallback and placement flipping
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* Fix source control compare base ambiguity (#5127)
Co-authored-by: Orca <help@stably.ai>
* release: v1.4.59-rc.1 [rc-slot:2026-06-10-15]
* release: v1.4.59
* Default-driven create-project flow: name-first form with sensible defaults (#5115)
Co-authored-by: Orca <help@stably.ai>
* Redesign Connect integrations (#4531)
Co-authored-by: Orca <help@stably.ai>
* Expose E2E store via build mode
* File search match counts (#5085)
* Add matchCount to SearchFileResult for accurate per-file hit counts
Co-authored-by: Orca <help@stably.ai>
* Add file search match count design
* rm design doc
---------
Co-authored-by: Orca <help@stably.ai>
* fix: address review findings (#5139)
* perf(windows): avoid blocking daemon pid checks (#5137)
* release: v1.4.60-rc.0
* release: v1.4.60
* Preserve core workflow terms in English and apply CJK spacing (#5141)
* Preserve core workflow and product terms in English across locales
Update translation policy to prevent localization of key terms such as
"Agent", "Commit", "Markdown", and "Terminal". This ensures consistent
jargon and product branding.
Introduce CJK-Latin term spacing to keep these Latin terms legible
when combined with CJK text, while adjusting Korean particle spacing.
Also add overrides to prevent network proxy settings from being
mistranslated as "Agent".
* Preserve repo terminology in English and localize source control labels
Treat "repo" and "repos" (and their capitalized forms) as brand terms
that should remain in English/Latin across CJK and Spanish locales.
Update translation files and policies to replace translated words like
"repositorio" or "リポジトリ" with "repo"/"repos", and fix an issue where
latin brand terms could be incorrectly matched as substrings in larger
words during cleanup.
Additionally, externalize and localize the "Staged Changes", "Changes",
and "Untracked Files" section labels in the source control sidebar.
* UX (#5143)
* UX/copy tweaks (#5142)
* UX/copy tweaks
* UX/copy tweaks
* Fix missed star UI translations (#5148)
* fix: make windows ssh relay deploy survive session teardown (#5136)
* Add option to remove child projects when deleting repo groups (#4702)
Co-authored-by: Orca <help@stably.ai>
* fix: remove checks panel response badge (#5147)
* Add read-only `orca linear` CLI with trusted launch-prompt pointer (V1) (#5126)
Co-authored-by: Orca <help@stably.ai>
* Add AI Vault session history
## Summary
- add AI Vault session scanning and resume command construction
- add the Agents sidebar panel with filtering, grouping, copy/open actions, and local resume launch
- support dragging saved sessions onto terminal split panes
## Validation
- pnpm run lint
- pnpm run typecheck
- pnpm exec vitest run --config config/vitest.config.ts src/main/ipc/register-core-handlers.test.ts src/main/ai-vault/session-scanner.test.ts src/renderer/src/components/right-sidebar/ai-vault-session-filters.test.ts src/renderer/src/lib/ai-vault-session-drag.test.ts src/renderer/src/lib/launch-ai-vault-session.test.ts
* Default agent launches to yolo permissions mode (#5145)
* Default agent launches to yolo mode
* test: update launch default validations
* Fix Claude usage refresh error copy (#5155)
Co-authored-by: Orca <help@stably.ai>
* Move workspace board to sidebar bottom toolbar (#5146)
Co-authored-by: Orca <help@stably.ai>
* Rebuild contextual tour positioning on floating-ui; fix hosted dialog placement and arrow seam (#5154)
Co-authored-by: Orca <help@stably.ai>
* Fix missing spaces in cross-repo switch dialog (#5158)
* Fix Ctrl+Tab switcher selection on release (#5116)
* Fix additional i18n spacing regressions from #4995 (#5159)
* Refine add project selection styling (#5160)
Co-authored-by: Orca <help@stably.ai>
* improve chinese localization (#5162)
* Fix floating workspace needing two clicks after app switch (macOS) (#5128)
* Autofocus feedback textarea when Send Feedback dialog opens (#5164)
* fix: address pr-bug-scan validated finding from #4683 (#5151)
Isolated CredentialDecryptionError per-item in Linear getClients (client.ts:518) and Jira getClients (client.ts:373) on the 'all' selection so one bad credential no longer collapses healthy workspaces
Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
* fix: enable claude agent teams by default (#5168)
* Refresh Jira and Linear status after credential errors (#5169)
* fix: address pr-bug-scan validated finding from #4683
Isolated CredentialDecryptionError per-item in Linear getClients (client.ts:518) and Jira getClients (client.ts:373) on the 'all' selection so one bad credential no longer collapses healthy workspaces
* Refresh Jira and Linear status to clear stale credential errors
Ensure stale credential decryption errors are cleared from the store
status once a successful API read completes. By updating the check in
shouldRefreshStatusAfterRead to trigger when a credentialError is
currently set, successful issue or list fetches will trigger a status
check and remove stale error flags.
---------
Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
* Hide internal context from AI Vault titles (#5175)
* Fix detached HEAD publish actions (#5173)
* Keep freshly split terminal pane mounted if newborn PTY exits early (#5171)
Prevent a newly split pane from collapsing immediately if its PTY exits
during initial setup before any output is received or input is sent.
This ensures a failed startup session remains visible to the user.
* Route task PR queries by upstream source (#5176)
* Route task PR queries by upstream source
Implements the routing described in docs/tasks-pr-upstream-source.md so task PR and issue queries stay scoped to the selected source.
* rm design doc
* Prevent stale PR refreshes from restoring unlinked review state (#5180)
- Pass `worktreeId` to `fetchPRForBranch` to track active worktree context
- Ignore inflight or queued PR fetches if the worktree has been unlinked
- Include linked PR/MR metadata in the checks panel snapshot key to trigger updates immediately on link/unlink events
* Fix Claude agents management status detection (#5179)
Co-authored-by: Orca <help@stably.ai>
* fix: address review findings (#5177)
* Allow resolving selected review comments with AI (#5184)
* Allow resolving selected PR/MR review comments with AI
Users can now select specific unresolved review comments or threads in
the Checks panel sidebar, queue them, and trigger an AI agent to address
them, marking resolved threads on the host upon agent launch.
- Adds checkboxes and action/send buttons to select and queue comments.
- Builds a structured, robust prompt with sanitized comment metadata.
- Optimistically marks threads resolved on launch with rollback on error.
- Supports both GitHub PRs and GitLab MRs.
* Consolidate PR comment selection state and eliminate effects
Combine independent selection states and context-tracking into a single
state object. Derive active selection data and prune ineligible comments
during render using useMemo instead of relying on asynchronous
useEffect synchronization hooks.
* Improve source control action dialog layout and recipe saving UX (#5153)
* Improve source control agent action dialog layout and recipe UX
- Constrain dialog and scroll area heights to prevent viewport overflow.
- Add variable chips to easily insert the base prompt with tooltip previews.
- Keep the recipe save controls visible when a recipe is already saved, showing informational status text instead of hiding them.
- Update localized copy across multiple languages and reduce textarea rows.
- Add unit tests for the variable chip preview and save target visibility.
* Fix recipe-saved check in source control action dialog
* Evaluate only the selected save target instead of checking all available targets, as the action only writes to the selected target.
* Update daemon PTY adapter test fake PID to prevent collision with real host OS processes during runtime directory lookups.
* fix: remove unsupported agent launch defaults (#5185)
* Update Chinese and Japanese translations for worktrees and fixes (#5187)
- Correct awkward Chinese translation of "fix" ("使固定") to "修复" and "基本的" to "主工作树" (main worktree).
- Improve Japanese translation of "fix" from physical repair ("修理") to software correction ("修正").
* Embed hosted review creation composer directly in Checks panel (#5140)
* Embed hosted review creation composer directly in the Checks panel
- Replaces the modal pull request/merge request creation dialog with an
inline composer embedded in the empty state of the Checks sidebar.
- Extracts and moves pull request generation state to a dedicated store
slice so AI-generated details are persisted across sidebar unmounts.
* Fix hosted review composer feedback
* Combine file search and file explorer right sidebar tabs (#5182)
Unifies file discovery and tree navigation under a single Explorer domain, simplifying the right sidebar activity bar and reducing tab clutter.
* Replaces the standalone 'search' activity bar tab with a nested 'search' subview inside the File Explorer tab
* Introduces 'rightSidebarExplorerView' ('files' | 'search') state to manage the active subview inside the Explorer
* Adds a search button to the File Explorer toolbar and a back button to the search subview for seamless transition
* Exposes 'showRightSidebarFiles' and 'showRightSidebarSearch' store actions to route and seed search queries/include patterns
* Adapts file explorer keybindings, git status polling, and external workspace watchers to respect the active subview
* Maps legacy persisted search tab state to the new explorer search view for backward compatibility
* release: v1.4.61-rc.1
* Add multi-repo folder workspaces (v1) (#5172)
Co-authored-by: Orca <help@stably.ai>
* release: v1.4.61-rc.2
* Hide unavailable project hosts in worktree composer
Co-authored-by: Orca <help@stably.ai>
* Remove inline project host setup from composer
Co-authored-by: Orca <help@stably.ai>
* Mark imported project host setup methods
Co-authored-by: Orca <help@stably.ai>
* Fix rebase merge fallout
Co-authored-by: Orca <help@stably.ai>
* Disable unavailable Add Project hosts
Co-authored-by: Orca <help@stably.ai>
* Compact Add Project host selector
Co-authored-by: Orca <help@stably.ai>
* Hide redundant SSH target chooser
Co-authored-by: Orca <help@stably.ai>
* Browse SSH clone destinations
Co-authored-by: Orca <help@stably.ai>
* Avoid local clone defaults for SSH hosts
Co-authored-by: Orca <help@stably.ai>
* Polish host-aware Add Project flows
Co-authored-by: Orca <help@stably.ai>
* Polish remote host add project flows
Co-authored-by: Orca <help@stably.ai>
* Remove redundant host kind chips
Co-authored-by: Orca <help@stably.ai>
* Fix remote project setup UX gaps
Co-authored-by: Orca <help@stably.ai>
* Fix multihost workspace composer project identity
Co-authored-by: Orca <help@stably.ai>
* Finish host context merge repair
Co-authored-by: Orca <help@stably.ai>
* Continue host context checklist implementation
Co-authored-by: Orca <help@stably.ai>
* Route Linear and Jira tasks by source context
Co-authored-by: Orca <help@stably.ai>
* Preserve Linear task source context in history
Co-authored-by: Orca <help@stably.ai>
* Scope task retry state by source context
Co-authored-by: Orca <help@stably.ai>
* Route GitHub drawer reads by source context
Co-authored-by: Orca <help@stably.ai>
* Guard GitLab selectors with repo context
Co-authored-by: Orca <help@stably.ai>
* Guard GitHub metadata selectors
Co-authored-by: Orca <help@stably.ai>
* Route GitHub task row actions by source context
Co-authored-by: Orca <help@stably.ai>
* Update GitHub source-context checklist status
Co-authored-by: Orca <help@stably.ai>
* Show host ownership for CLI provider accounts
Co-authored-by: Orca <help@stably.ai>
* Persist GitLab task detail source context
Co-authored-by: Orca <help@stably.ai>
* Show host scope for provider API budgets
Co-authored-by: Orca <help@stably.ai>
* Preserve Jira task source context
Co-authored-by: Orca <help@stably.ai>
* Scope Jira optimistic task patches
Co-authored-by: Orca <help@stably.ai>
* Resolve task PR bases on run host
Co-authored-by: Orca <help@stably.ai>
* Record Jira task workspace usage
Co-authored-by: Orca <help@stably.ai>
* Scope Linear optimistic task patches
Co-authored-by: Orca <help@stably.ai>
* Scope GitHub optimistic task patches
Co-authored-by: Orca <help@stably.ai>
* Clean host copy in onboarding flows
Co-authored-by: Orca <help@stably.ai>
* Preserve automation CLI run context
Co-authored-by: Orca <help@stably.ai>
* Add automation CLI source context selector
Co-authored-by: Orca <help@stably.ai>
* Clarify unavailable task source hosts
Co-authored-by: Orca <help@stably.ai>
* Surface host model runtime capability skew
Co-authored-by: Orca <help@stably.ai>
* Use SSH host copy in reconnect dialog
Co-authored-by: Orca <help@stably.ai>
* Show host context in task source picker
Co-authored-by: Orca <help@stably.ai>
* Mark task source display complete
Co-authored-by: Orca <help@stably.ai>
* Clarify provider account host selection
Co-authored-by: Orca <help@stably.ai>
* Guard task source switching boundary
Co-authored-by: Orca <help@stably.ai>
* Mark task source diagnostics persisted
Co-authored-by: Orca <help@stably.ai>
* Mark base resolution host boundary
Co-authored-by: Orca <help@stably.ai>
* Clarify external automation source states
Co-authored-by: Orca <help@stably.ai>
* Harden project host compatibility projection
Co-authored-by: Orca <help@stably.ai>
* Finish host copy audit
Co-authored-by: Orca <help@stably.ai>
* Add provider host scope controls
Co-authored-by: Orca <help@stably.ai>
* Show task source account labels
Co-authored-by: Orca <help@stably.ai>
* Show automation run context in CLI
Co-authored-by: Orca <help@stably.ai>
* Scope Jira task cache lookups by source
Co-authored-by: Orca <help@stably.ai>
* Seed workspace creation from task source context
Co-authored-by: Orca <help@stably.ai>
* Explain disabled external automation actions
Co-authored-by: Orca <help@stably.ai>
* Surface task source runtime capability gaps
Co-authored-by: Orca <help@stably.ai>
* Persist automation run context from UI saves
Co-authored-by: Orca <help@stably.ai>
* Require workspace run capability for setup hosts
Co-authored-by: Orca <help@stably.ai>
* Disable automation runs for stale host setup
Co-authored-by: Orca <help@stably.ai>
* Route GitHub drawer metadata by source host
Co-authored-by: Orca <help@stably.ai>
* Guard runtime project setup mutations by host model
Co-authored-by: Orca <help@stably.ai>
* Route PR page metadata by repo host
Co-authored-by: Orca <help@stably.ai>
* Route PR mention metadata by repo host
Co-authored-by: Orca <help@stably.ai>
* Route GitHub Project edits by view source
Co-authored-by: Orca <help@stably.ai>
* Clarify runtime automation disabled states
Co-authored-by: Orca <help@stably.ai>
* Guard runtime automation backend dispatch
Co-authored-by: Orca <help@stably.ai>
* Preserve GitLab task source identity
Co-authored-by: Orca <help@stably.ai>
* Remove redundant SSH target row in add project
Co-authored-by: Orca <help@stably.ai>
* Add task source provider availability reasons
Co-authored-by: Orca <help@stably.ai>
* Surface task provider preflight availability
Co-authored-by: Orca <help@stably.ai>
* Record local GitHub task source verification
Co-authored-by: Orca <help@stably.ai>
* Record Linear task source verification
Co-authored-by: Orca <help@stably.ai>
* Show automation source context in details
Co-authored-by: Orca <help@stably.ai>
* Record remote capability negotiation coverage
Co-authored-by: Orca <help@stably.ai>
* Record local add project create verification
Co-authored-by: Orca <help@stably.ai>
* Scope Linear cached task reads by source
Co-authored-by: Orca <help@stably.ai>
* Preserve PR generation host ownership
Co-authored-by: Orca <help@stably.ai>
* Route git operations by owner host
Co-authored-by: Orca <help@stably.ai>
* Route delete warnings by worktree owner
Co-authored-by: Orca <help@stably.ai>
* Route editor drops by worktree owner
Co-authored-by: Orca <help@stably.ai>
* Route agent draft paste by tab owner
Co-authored-by: Orca <help@stably.ai>
* Route file explorer requests by worktree owner
Co-authored-by: Orca <help@stably.ai>
* Document remaining host context gaps
Co-authored-by: Orca <help@stably.ai>
* Check runtime task source provider auth
Co-authored-by: Orca <help@stably.ai>
* Validate automation source availability
Co-authored-by: Orca <help@stably.ai>
* Route remaining UI requests by owner host
Co-authored-by: Orca <help@stably.ai>
* Route quick open file listing by worktree owner
Co-authored-by: Orca <help@stably.ai>
* Route typed GitHub lookups by source host
Co-authored-by: Orca <help@stably.ai>
* Centralize automation run identity fallback
Co-authored-by: Orca <help@stably.ai>
* Surface unsupported task source providers
Co-authored-by: Orca <help@stably.ai>
* Document automation legacy repo compatibility
Co-authored-by: Orca <help@stably.ai>
* Record live host model verification
Co-authored-by: Orca <help@stably.ai>
* Quiet disconnected SSH polling
Co-authored-by: Orca <help@stably.ai>
* Verify task drawer source boundaries
Co-authored-by: Orca <help@stably.ai>
* Verify GitLab repo source selectors
Co-authored-by: Orca <help@stably.ai>
* Route automations through owning host
Co-authored-by: Orca <help@stably.ai>
* Update host context verification checklist
Co-authored-by: Orca <help@stably.ai>
* Run remote automations headlessly in serve mode
Co-authored-by: Orca <help@stably.ai>
* Keep setup guide entry stable during refresh
Co-authored-by: Orca <help@stably.ai>
* Keep setup script prompt stable during host switches
Co-authored-by: Orca <help@stably.ai>
* Deduplicate Tasks project picker sources
Co-authored-by: Orca <help@stably.ai>
* Use project identity for Tasks picker dedupe
Co-authored-by: Orca <help@stably.ai>
* Add Tasks source host switcher
Co-authored-by: Orca <help@stably.ai>
* Refine Tasks source picker disclosure
Co-authored-by: Orca <help@stably.ai>
* Polish Tasks source picker hover
Co-authored-by: Orca <help@stably.ai>
* Open Tasks source menu on hover
Co-authored-by: Orca <help@stably.ai>
* Match Tasks source submenu hover behavior
Co-authored-by: Orca <help@stably.ai>
* Open Tasks source submenu from project row hover
Co-authored-by: Orca <help@stably.ai>
* Group automation project hosts
Co-authored-by: Orca <help@stably.ai>
* Tighten automation project picker density
Co-authored-by: Orca <help@stably.ai>
* Show selected host in Tasks project picker
Co-authored-by: Orca <help@stably.ai>
* Hide host labels for single-host project pickers
Co-authored-by: Orca <help@stably.ai>
* Use saved remote server names in host pickers
Co-authored-by: Orca <help@stably.ai>
* Use standard add project start for remote servers
Co-authored-by: Orca <help@stably.ai>
* Use saved host labels in workspace surfaces
Co-authored-by: Orca <help@stably.ai>
* Route remote browser tabs through runtime hosts
Co-authored-by: Orca <help@stably.ai>
* Keep sidebar project-first across grouping modes
Co-authored-by: Orca <help@stably.ai>
* Polish multi-host remote runtime UX
Co-authored-by: Orca <help@stably.ai>
* Fix CI lint and remove design notes
Co-authored-by: Orca <help@stably.ai>
* Fix CI test failures
Co-authored-by: Orca <help@stably.ai>
* Fix Windows CLI path expectation
Co-authored-by: Orca <help@stably.ai>
* Fix CI renderer test expectations
Co-authored-by: Orca <help@stably.ai>
* Fix remaining verify test failures
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: Bryant Ung <bryant.ung@outlook.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
Co-authored-by: Borja <3930245+BorjaLL@users.noreply.github.com>
Co-authored-by: Parker Rex <me@parkerrex.com>
Co-authored-by: Brennan Benson <79079362+brennanb2025@users.noreply.github.com>
Co-authored-by: Trevin Chow <trevin@trevinchow.com>
Co-authored-by: buf0-bot[bot] <252831055+buf0-bot[bot]@users.noreply.github.com>
Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
* Default repo avatars to the GitHub upstream owner and flag forks
Make the GitHub owner avatar the default repo icon and surface it as the
primary choice in the icon picker (the "Image" tab becomes "Avatar",
moves first, and opens by default). For forks, resolve the upstream/
parent owner so the avatar reflects the source repo instead of the
personal fork, and show a fork indicator (GitFork glyph + "Fork of
owner/repo" tooltip) next to the repo in the sidebar and settings.
Fork detection prefers the offline `upstream` remote, falling back to a
`gh repo view --json isFork,parent` lookup; the resolved upstream is
stored on the repo. Existing repos self-correct via a one-time startup
backfill (local repos) and a lazy backfill when their icon settings open
(SSH repos); new repos resolve at add-time. Reset now restores the
default (re-detecting the upstream) instead of clearing to the Folder
icon.
* Harden repo upstream avatar handling
---------
Co-authored-by: Neil <4138956+nwparker@users.noreply.github.com>
* Create GitHub issues with markdown and metadata
- Add a reusable rich markdown composer for GitHub issue bodies and comments
- Let new GitHub issues include selected labels and assignees through IPC/RPC
- Preserve created issue metadata in the task list and cover the new API path with tests
* fix: address review findings
- Use fallback PR numbers after branch lookup misses, including detached HEAD
- Preserve review cards for forked or deleted-head PRs across manual refreshes
- Clear stale GitHub PR cache entries when unlinking worktree review metadata
* Squashed commits
- WIP: uncommitted changes before rebase
- ci
- Show inline PR check details in task drawer
- Add a Checks tab that opens from the PR checks cell and expands runs inline
- Fetch check output, annotations, and workflow job steps through IPC/RPC
- Improve markdown/comment wrapping so long PR content stays within the drawer
* Use app-styled confirmations for PR actions (#2324)
Co-authored-by: Orca <help@stably.ai>
* fix: pr-bug-scan validated finding from #2274 (#2296)
Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
---------
Co-authored-by: Jinwoo Hong <73622457+Jinwoo-H@users.noreply.github.com>
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: buf0-bot[bot] <252831055+buf0-bot[bot]@users.noreply.github.com>
Co-authored-by: orca-bug-scan-bot <orca-bug-scan-bot@stably.ai>
Reopening a GitHub issue/PR drawer paid full IPC + `gh` startup latency on
every open. Two changes here:
1. Module-level SWR cache in GitHubItemDialog.tsx keyed by
(repoPath, issueSourcePreference, type, number). Reopening within 30s
paints cached data instantly; older entries paint stale-then-refresh.
Concurrent opens dedupe on a shared in-flight promise. Mutation
handlers invalidate by (repo, type, number); a cache-generation
counter prevents in-flight refetches from resurrecting stale data
after a mid-flight invalidation.
2. Collapsed GraphQL query for issue details replaces 3 serial `gh`
subprocesses (REST issue + REST comments + GraphQL participants) with
one round-trip. Falls back to the legacy fan-out on any GraphQL error
so historical contract is preserved.
Cross-window invalidation rides a new `gh:workItemMutated` IPC broadcast
that skips the originating sender (the source already updated its cache
optimistically — re-broadcasting would race the optimistic write).
`addIssueComment` now takes a `type` so the broadcast scopes correctly
when a PR shares its number with an issue.
Co-authored-by: Orca <help@stably.ai>
* fix(gh-project): diagnose env-shadowed gh tokens in auth errors
`gh auth refresh -s project` silently no-ops when GITHUB_TOKEN/GH_TOKEN
is exported in the user's shell — gh prefers env tokens and refuses to
modify them, exiting 0. Users follow the canned remediation, see no
error, retry, and stay stuck.
Add a one-shot `gh auth status` probe (gh:diagnoseAuth IPC) that:
- Detects env-shadowed credentials and rewrites the fix to `unset
GITHUB_TOKEN` plus a grep to find where it's exported.
- Detects missing gh install, plain missing-scope on a keyring login,
and SAML SSO authorization.
- Surfaces a tailored multi-button error UI in ProjectViewWrapper and
ProjectPicker instead of one canned 'Copy command'.
Co-authored-by: Orca <help@stably.ai>
* fix(gh-project): address review feedback
- Cross-platform shell guidance: PowerShell commands on Windows
(Get-ChildItem Env:, Remove-Item Env:, [Environment]::SetEnvironmentVariable)
via navigator.userAgent platform check.
- Use `window.api.shell.openUrl` for the docs button instead of
`window.open`, matching SidebarToolbar's external-URL pattern.
- Tighten gh auth status parser: accept single-label hostnames and
optional trailing colon; recover host from the inline 'Logged in to
<host>' line so a missed section header never silently drops accounts.
- Add tests for multi-host output and host-recovery fallback.
- Drop dead command/copy locals in ProjectViewWrapper.ErrorState by
short-circuiting the auth-error case before they're computed.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
When a worktree is created from a PR via the source picker, the new
local branch differs from the PR's head ref, so the branch-keyed PR
lookup misses and the worktree card shows no PR strip. Pass the
worktree's linkedPR number through the IPC call and fall back to a
number-based lookup in the main process. Also recover linkedPR from
a PR URL pasted into the workspace name when the user skips the
source picker. PR strip now wraps the whole row as the PR link.
Co-authored-by: Orca <help@stably.ai>
* Fix new workspace composer focus restore
* Unify new workspace source selection
* WIP: selected source pill in smart workspace name field
Co-authored-by: Orca <help@stably.ai>
* fix(new-workspace): truncate source pill so it doesn't expand the dialog
Co-authored-by: Orca <help@stably.ai>
* feat(new-workspace): add open-in-browser button to source pill, fix vertical alignment
Co-authored-by: Orca <help@stably.ai>
* refactor(new-workspace): drop redundant kind suffix, distinct PR/issue icons, tooltips on pill actions
Co-authored-by: Orca <help@stably.ai>
* fix(new-workspace): type linked URL into agent input without auto-submit
Co-authored-by: Orca <help@stably.ai>
* fix(new-workspace): use bracketed-paste for draft URL injection so it actually appears in the agent input
Co-authored-by: Orca <help@stably.ai>
* feat(agents): per-agent draft injection strategy (codex slow paste, pi/opencode type-chars)
Co-authored-by: Orca <help@stably.ai>
* fix(agents): smarter TUI-ready heuristic + bracketed paste for codex/pi/opencode
Replaces per-agent strategy guesswork with a measured readiness check:
title-idle / non-shell-foreground stable for 1.5s / 2.5s minimum floor.
Verified against codex, pi, opencode, claude in a node-pty + xterm-headless
test rig — bracketed paste lands in the input buffer for all four.
Co-authored-by: Orca <help@stably.ai>
* refactor(agents): drop unused per-agent draft strategy abstraction
The TUI-ready heuristic in agent-paste-draft.ts works for every tested
agent (claude/codex/pi/opencode), so the AgentDraftInjectionStrategy
field, type-chars + bracketed-paste-slow code paths, and per-agent
overrides are dead. Keep the `agent` arg on pasteDraftWhenAgentReady
for future per-agent escape hatches without touching every call site.
Co-authored-by: Orca <help@stably.ai>
* feat(agents): skip draft URL injection for copilot + cursor-agent
Both TUIs open with a 'Do you trust this folder?' menu on first launch
that consumes keystrokes as menu input — pasting a URL there either
selects an arbitrary option or quits the session. Mark them with
skipDraftUrlInjection so the workspace still opens cleanly; the user
types/pastes the URL themselves once past the trust menu.
Co-authored-by: Orca <help@stably.ai>
* feat(agents): native --prefill for claude, trust pre-write for cursor/copilot
Replaces the empirical TUI-ready waits with two deterministic mechanisms:
1) `claude --prefill <text>` flag — Claude launches with the URL already in
its input box, no submit. Eliminates the readiness/paste race entirely
for the most common agent.
2) DECSET 2004 (`\x1b[?2004h`) detection on the PTY data stream for every
other agent. That escape is the protocol-level "input layer ready,
accepting bracketed paste" handshake — emitted by claude/codex/pi/
opencode/gemini/cursor-agent/copilot the moment the input box mounts.
We tap it via a sidecar subscription on pty-dispatcher (no interference
with the primary xterm handler) and paste as soon as it lands. The
8s budget is now an upper bound, not a target.
Cursor-agent and Copilot's "Do you trust this folder?" menus are bypassed
by writing the same trust artifacts the CLIs themselves write after the
user accepts:
- Cursor: `~/.cursor/projects/<slug>/.workspace-trusted` (slug = abs path
with leading `/` stripped, remaining `/` → `-`).
- Copilot: append cwd to `trustedFolders` in `~/.copilot/config.json`
(the same array the bundled `addTrustedFolder` writes).
Verified against the cursor-agent CLI bundle (versions/2026.04.17-787b533/
index.js: `_=".workspace-trusted"`) and the @github/copilot 1.0.32 bundle
(`isFolderTrusted` / `addTrustedFolder` both read/write `trustedFolders`).
Both check via realpath() before string-comparing, so the trust preset
canonicalizes too.
skipDraftUrlInjection is dropped — both agents now get the draft URL
paste once the trust menu is pre-resolved.
Tests: 24 passing across tui-agent-startup, agent-trust-presets,
pty-dispatcher routing.
Co-authored-by: Orca <help@stably.ai>
* fix(agents): wait for post-?2004h render burst to settle before paste
OpenCode emits DECSET 2004 at ~500ms during alt-screen setup, then runs
a 1.3s splash render with NO bytes on the PTY, then paints the actual
input box at ~1.85s. Pasting on the bare ?2004h signal lands during the
silent gap and the bytes are dropped.
The fix: take ?2004h as the necessary precondition, then wait for the
TUI's render burst to finish — defined as 1500ms of stream silence
after the most recent post-?2004h byte. This captures both the fast
TUIs (claude/pi/codex emit setup escapes in one burst then go quiet)
and the slow ones (opencode emits, sleeps for the splash, emits again,
then goes quiet).
Verified against opencode/claude/pi in a node-pty rig: paste lands on
the first try with the new strategy. The hard 8s timeout still caps
the wait when an agent fails to launch.
Co-authored-by: Orca <help@stably.ai>
* fix(agents): guard agentTrust IPC so stale preload doesn't crash launch
If the preload bundle is older than the renderer (a real situation in
electron-vite dev because preload changes only apply on full restart,
not HMR), `window.api.agentTrust` is undefined and the launch crashes
with "Cannot read properties of undefined (reading 'markTrusted')"
before the worktree even opens.
Guard the call sites in launch-work-item-direct and useComposerState
to skip the trust pre-write when the IPC isn't exposed, and wrap the
invoke in try/catch so an IPC error never blocks the launch — the user
just sees the trust menu and accepts it manually, same as before this
feature shipped.
Co-authored-by: Orca <help@stably.ai>
* feat(tasks): route 'Use' through the New Workspace dialog instead of yolo-create
The Use CTA on the Tasks page used to create+activate a worktree
synchronously, which surprised users — the worktree appeared in the
sidebar before they had a chance to confirm name / agent / setup. The
unified New Workspace dialog landed in this branch already supports
opening with a linked work item pre-filled (see openComposerForItem /
openComposerForLinearItem), so just route Use through it.
The launchWorkItemDirect helper stays exported for ProjectViewWrapper,
which has its own UX where the immediate-create flow is the right call.
Co-authored-by: Orca <help@stably.ai>
* test(agents): include `agent` field in autohand startup-plan assertion
Merging main brought in the Autohand Code agent test (PR #1382), which
predated this branch's addition of `agent` to AgentStartupPlan.
Aligning the assertion fixes the lone CI test failure on this PR.
Co-authored-by: Orca <help@stably.ai>
* refactor(agents): drop unused expectedProcess arg + snapshot sidecar set
Two minor follow-ups from self-review:
1. `pasteDraftWhenAgentReady` no longer reads `expectedProcess` — readiness
is gated on DECSET 2004 alone now, not on PTY foreground process. Drop
it from the signature and from the two callers (launch-work-item-direct,
new-workspace).
2. The pty-dispatcher's sidecar fan-out iterates the live Set, which is
safe against deleting the current element but not against a watcher
that synchronously subscribes a sibling. Snapshot via Array.from
before the loop. Cheap (Set is tiny) and removes the latent footgun.
No behavior change.
Co-authored-by: Orca <help@stably.ai>
* test(e2e): match the unified smart-name input's new placeholder
The CreateFromTab refactor in this branch replaced the separate "Workspace
name" Input with a single SmartWorkspaceNameField whose default-mode
placeholder is "Type a name, #1234, branch, GitHub or Linear URL". The
worktree-create e2e test was still anchoring on the old "Workspace name"
text and could not find the input.
Update the placeholder regex to match the new copy. Free-form text typed
into smart mode is treated as a workspace name by submitQuick — same
contract the test used before.
Verified locally: targeted e2e passes in 2.2s.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
* Render GitHub markdown safely
Co-authored-by: Orca <help@stably.ai>
* Support PR line comment ranges in diffs
Co-authored-by: Orca <help@stably.ai>
* Add GitHub item dialog review workflow
Co-authored-by: Orca <help@stably.ai>
* Make attribution tests environment-safe
Co-authored-by: Orca <help@stably.ai>
* Wire GitHubItemDialog for row clicks and bound file cache
Row clicks in the Tasks GitHub list now open the new GitHubItemDialog
instead of the legacy GitHubItemDrawer, making the PR review workflow
reachable from the main entry point. The unused drawer and its state
are removed.
Also bounds prFileContentCache at 64 entries with LRU eviction so the
module-level map can no longer grow without limit across many PR
openings in a session.
Co-authored-by: Orca <help@stably.ai>
* Convert GitHubItemDialog to a right-side drawer
Replaces the centered Dialog modal with a Sheet drawer (side=right,
max-w 960/1100/1280 across breakpoints) so the review surface slides
in from the side instead of popping over the task list.
Co-authored-by: Orca <help@stably.ai>
* Address review feedback on GitHub work-item details
- Restore full pagination in listAssignableUsers (REST /assignees --paginate)
so repos with >100 assignees no longer silently drop users from the picker.
- Drop redundant REST /users/<login> fan-out in getMentionParticipants; the
aliased GraphQL query already returns login/name/avatarUrl.
- Parallelize mention-participant lookup with checks/participants fetch.
- Avoid mutating caller-provided objects in mergeGitHubUsers.
- Type addIssueComment / addPRReviewComment(Reply) preload wrappers as
Promise<GitHubCommentResult> instead of Promise<unknown>.
- Use typeof startLine === 'number' to harden the review-comment guard.
Co-authored-by: Orca <help@stably.ai>
---------
Co-authored-by: Orca <help@stably.ai>
Co-authored-by: Jinjing <6427696+AmethystLiang@users.noreply.github.com>
Adds a + button on the tasks page that opens a dialog to create a new
GitHub issue in the selected repository. Wires createIssue through the
main/preload IPC using gh api, and refreshes the tasks list after
creation so the new issue shows up immediately.
Also clears a stray Radix pointer-events lock on GitHubItemDrawer mount
so Close/open-in-GitHub buttons remain clickable after the New Issue
dialog closes.
* New workspace page with agent catalog, composer modal, and terminal integration
* fix lint
* better blank state
* fix: resolve typecheck errors in new-workspace flow
- widen activateAndRevealWorktree's issueCommand to accept direct
command shape used by NewWorkspacePage, not just the main-process
runner-script variant
- use a ref object in pty-connection tests to dodge TS narrowing the
captured callback to never across the mock closure boundary
* fix: bound worktree name auto-suffix loop to prevent OOM in tests
The auto-suffix loop in createLocalWorktree had no termination cap.
When tests (or a misconfigured env) mocked getBranchConflictKind /
getPRForBranch to always return a collision, the loop ran forever and
the vitest worker crashed with "Ineffective mark-compacts near heap
limit".
Cap the search at 100 suffixes, and if all fail, fall back to the
original specific error messages (branch already exists / PR already
owns the name) instead of a generic failure.
Update the two tests that asserted the old throw-on-first-conflict
behavior to verify the new auto-suffix path end-to-end.
* Add richer feedback dialog
* Keep anonymous submission client-side only
* Use lowercase feedback API host
* Fallback feedback submission when api host is unavailable
The `gh api --cache 60s` flag caused stale check-run data even when
the user explicitly clicked refresh. Thread a `noCache` flag through
IPC so manual refreshes skip the gh CLI cache while polling still
benefits from it.