Commit Graph

8347 Commits

Author SHA1 Message Date
Pierre Tachoire
1baa8de09d Merge pull request #2585 from lightpanda-io/cookie_store_tweaks
Remove CookieListItem Interface
2026-06-01 09:04:35 +02:00
Adrià Arrufat
204e3aa31b Merge branch 'main' into agent 2026-06-01 08:04:44 +02:00
Karl Seguin
295bcf5cda Merge pull request #2583 from jschaf/codex/fix-relative-url-fragment
browser/URL: ignore query and fragment slashes in URL resolve
2026-06-01 13:07:06 +08:00
Karl Seguin
a937d559de Remove the navigator.getBattery dummy implementation
Firefox currently doesn't implement this API. Sites already have to check if
it exists, e.g `navigator.getBattery == undefined`. Implementing the method
but making it fail, it's the worst of both wolds.
2026-06-01 12:58:13 +08:00
Karl Seguin
644cea4ea9 An about:blank iframe/popup inherits its parent's base_url 2026-06-01 12:00:31 +08:00
Karl Seguin
b17ff37f8d Merge pull request #2587 from lightpanda-io/websocket_cookies
Websocket cookies
2026-06-01 11:06:19 +08:00
Karl Seguin
14f1ef35f1 URL.isHTTPs -> URL.isSecure and consider wss://
Use conn.setCookie in websocket
2026-06-01 08:35:19 +08:00
Adrià Arrufat
668f8a07dc test: add extract follow test fixtures 2026-05-31 18:49:29 +02:00
Adrià Arrufat
cf65a00a8f extract: add declarative follow option
Allows fetching sub-pages per row and resolving nested fields against
them. Supports string templates with sibling placeholders (e.g., `{id}`)
and element-specs. Updates the JS walker to be async.
2026-05-31 17:07:42 +02:00
Adrià Arrufat
85facd2fc7 eval: auto-serialize non-JSON values in save 2026-05-31 16:31:06 +02:00
Adrià Arrufat
fc15027100 eval: clarify automatic JSON serialization
Update agent docs and tool descriptions to note that objects and
arrays are automatically serialized to JSON, making manual
`JSON.stringify` calls unnecessary.
2026-05-31 16:27:28 +02:00
Adrià Arrufat
ab3deec523 eval: serialize returned objects as JSON
Objects and arrays returned from eval now serialize to JSON instead of
"[object Object]". Native errors and functions retain their string form.
2026-05-31 16:19:34 +02:00
Adrià Arrufat
27c2fe00c7 eval: support top-level await and return
Falls back to compiling the script inside an async IIFE if the initial
block-scoped compilation fails. This enables top-level await and return
statements directly in the eval tool.
2026-05-31 16:10:42 +02:00
Adrià Arrufat
63f2706202 terminal: remove bare command validation
Stop highlighting bare tokens matching tool names as errors. Also
updates the zenai dependency.
2026-05-31 15:29:53 +02:00
Adrià Arrufat
0d22bd32a5 build: bump zenai dependency 2026-05-31 15:25:56 +02:00
Adrià Arrufat
7204de5a1b agent: prompt for provider selection when multiple found
Allows interactive selection of an LLM provider when multiple keys are
detected in the environment. Saves the choice to `.lp-agent.zon`.
2026-05-31 14:33:57 +02:00
Adrià Arrufat
de0eff05f6 terminal: simplify interactive choice selection
Remove number typing input and only support arrow keys and Enter.
2026-05-31 13:21:44 +02:00
Francis Bouvier
99ef54a557 agent: add arrow-key navigation to provider picker
Make the numbered agent choice prompt interactive on TTYs: Up/Down
moves the selected row, Enter confirms it, and numeric input still works as before.

Keep the line-based numbered prompt as the non-interactive fallback, restore
terminal settings after the raw-mode picker exits, and render raw-mode output
with CRLF so menu rows stay aligned. Dim the picker hint text to match existing
terminal command hints.
2026-05-31 13:21:44 +02:00
Karl Seguin
5181cf4a14 zig fmt 2026-05-31 18:50:43 +08:00
Karl Seguin
7e0cc672be Remove CookieListItem Interface
CookieStore get/getAll return a play JS object, not an WebAPI interface.
`typeof CookieListItem === undefined` in browsers. This removes the interface
and returns the CookieListItem as a plain object.

Also adds various name/value validation based on WPT tests
2026-05-31 18:48:20 +08:00
Joe Schafer
bf1b5e5506 browser/URL: ignore query and fragment slashes in URL resolve
Resolve relative request URLs against only the path component of the
base URL. Previously, URL.resolve searched for the last slash in the
whole base URL after the authority, so slashes inside a query string or
hash route could be mistaken for path directory separators.

The reported failure was a hash-routed page loaded at
http://127.0.0.1:8123/#/login. When that page ran
fetch("api/users/login", { method: "POST" }), browser-compatible URL
resolution should have requested
http://127.0.0.1:8123/api/users/login. Instead, Lightpanda 0.3.1
reported the response URL as
http://127.0.0.1:8123/#/api/users/login, and the HTTP server received
POST /.

That meant the server returned the single-page app shell instead of the
JSON login response. The failure broke a RealWorld/Conduit-style SPA
benchmark after login because the app used relative API URLs such as
api/users/login. Changing the benchmark fixture to root-absolute API
URLs, such as /api/users/login, worked around the benchmark failure, but
left Lightpanda incompatible with normal browser behavior for relative
request URLs on hash-routed pages.

The same issue was not limited to fragments. A base URL such as
https://example/app/page?next=/foo/bar also contains slashes after the
path component. Those slashes must not affect how path-relative inputs
such as api/users/login or ../api/users/login are merged with the base
path.

This change bounds the directory calculation at the first ? or # in the
base URL and searches for the last path slash only inside that path
component. Root-absolute inputs still keep only the scheme and
authority, query-only inputs still replace the query on the current
path, and fragment-only inputs still replace the fragment on the
current path.

This matches the behavior of the WHATWG URL algorithm, Chromium's
relative URL canonicalization, Node's WHATWG URL implementation, Go's
net/url ResolveReference, and Python's urllib.parse.urljoin for the
cases covered here. All of those implementations split the base URL into
components before merging a path-relative reference, so slashes in the
query or fragment do not change the base directory.

The URL resolver tests now cover the original hash-route repro, slashes
inside query strings and fragments, host-only bases with query or
fragment components, dot-segment paths, query-only references, and
fragment-only references. The fetch Web API tests also move a page to
/#/login and POST fetch("xhr"), expecting the request URL to resolve to
http://127.0.0.1:9582/xhr rather than the hash route.

Verified with:

mise x zig@0.15.2 -- zig fmt --check ./*.zig ./**/*.zig
mise x zig@0.15.2 rust@stable -- make ZIG=zig test
2026-05-31 00:44:33 -07:00
Karl Seguin
760ac00580 Merge pull request #2579 from lightpanda-io/custom_element_define_reentrancy
Fix potential segfault in CustomElement definition
2026-05-31 07:28:18 +08:00
Adrià Arrufat
88fdeeade8 refactor: extract JSON formatting and timeout helpers 2026-05-30 23:48:50 +02:00
Adrià Arrufat
53ba47cbec agent: suggest closest slash command on typo
Implements Levenshtein distance-based suggestions for unknown slash
commands. If a typo is within two edits of a valid command, the
terminal suggests it with "Did you mean ...?".
2026-05-30 23:40:34 +02:00
Adrià Arrufat
e42862e544 terminal: add ghost hints for slash commands 2026-05-30 23:26:40 +02:00
Adrià Arrufat
58caf9faf7 agent: pretty-print JSON command results
Re-indents JSON output with 2-space indentation for better readability
in the terminal, while keeping non-JSON output unchanged.
2026-05-30 23:12:54 +02:00
Adrià Arrufat
2eb995e0ee links: return structured link objects with text and node ID
Updates `collectLinks` to return a `Link` struct containing the href,
visible text, and backend node ID. The links tool now outputs JSON.
2026-05-30 22:55:53 +02:00
Adrià Arrufat
ee96d8e813 browser: report timeout status in goto tool
Adds `WaitResult` to track whether a wait completed or timed out.
Updates the goto tool to report when a timeout occurs.
2026-05-30 22:41:24 +02:00
Tom Clarke
2ecf9ced5d Send cookies on WebSocket upgrade requests
The WebSocket upgrade handshake is an HTTP/1.1 request (RFC 6455 §4.1)
and follows ordinary cookie semantics — RFC 6265 §5.4 attaches matching
cookies to "any HTTP request" by domain/path. Without this, cookie-
authenticated WebSocket endpoints (anything session-gated, e.g. Phoenix
LiveView) reject the upgrade because their auth cookie never arrives.

Read matching cookies from the session jar with the same opts shape
HTTPDocument uses (`is_http: true, is_navigation: false`), and add a
`Cookie:` request header on the upgrade if any apply.

The TestWSServer captures the upgrade's Cookie header and exposes it
to fixtures via a new `get-cookie` command. A `cookies_on_upgrade`
fixture in websocket.html sets `document.cookie` then asserts the
server received it on the upgrade.
2026-05-30 16:37:05 -04:00
Adrià Arrufat
13e3de4b26 browser: floor remaining wait timeout to 1ms
Ensures `waitForSelector` and `waitForScript` perform at least one
check even if the timeout is 0 or already elapsed.
2026-05-30 22:34:03 +02:00
Adrià Arrufat
1ec65a00fb agent: improve command error messages
Suggest `/help` on unknown slash commands and handle `FrameNotLoaded`
by prompting the user to run `/goto <url>` first.
2026-05-30 22:31:18 +02:00
Adrià Arrufat
26cf182b38 agent: load external stylesheets by default with LLM
Enables `load_external_stylesheets` when an LLM client is active,
as LLM drivers reason about visibility and computed styles.
Updates the help documentation to reflect this change.
2026-05-30 22:16:18 +02:00
Adrià Arrufat
c9c962ec74 Merge branch 'main' into agent 2026-05-30 22:05:01 +02:00
Adrià Arrufat
c92dad165f command: add /logout and refactor LLM commands 2026-05-30 22:03:46 +02:00
Adrià Arrufat
b98a79e14e agent: derive llm commands from Command tags 2026-05-30 20:24:49 +02:00
Adrià Arrufat
74600833bc agent: add '[command]' hint to help command 2026-05-30 20:15:04 +02:00
Adrià Arrufat
17aeef886c terminal: show ghost text hints for /help arguments 2026-05-30 20:11:03 +02:00
Adrià Arrufat
47072a82e6 repl: use explicit summaries for command help
Replaces the fragile `firstSentence` parser with an explicit `summary`
field on tool definitions. Also standardizes user-facing REPL
terminology to "command" instead of "slash command" or "tool".
2026-05-30 20:06:30 +02:00
Adrià Arrufat
fb7dfc1410 refactor: clean up comments and remove redundant ping test 2026-05-30 19:53:43 +02:00
Adrià Arrufat
f51bda4d5a refactor: deduplicate comment writing and remove unused code 2026-05-30 19:32:59 +02:00
Adrià Arrufat
1f85de3d3d agent: use ZON format for remembered config
Migrates the `.lp-agent` file to `.lp-agent.zon` and uses `std.zon`
for serialization and parsing.
2026-05-30 19:10:40 +02:00
Francis Bouvier
8052f0ad81 Agent model provider picker (#2581)
* agent: add a /model command to chnage current model

And remove the pick-model CLI option

* agent: add /provider to change the current provider

* agent: extract requireLlmNoArg helper

* agent: simplify provider detection

* repl: add tab completion for /model and /provider

Changes `/model` and `/provider` to accept an optional name argument
instead of prompting with a numbered list. Bare commands now print the
current selection, while Tab dynamically completes candidates. Model
lists are fetched and cached to prevent redundant network requests.

* agent: remember last selected provider and model

Persists the last selected AI provider and model in a local
`.lp-agent` file and resumes it on startup. Removes the
interactive provider picker in favor of deterministic auto-detection.

* agent: simplify requireLlm and model resolution

Changes `requireLlm` to return a boolean instead of credentials, and
cleans up the model initialization logic to use `resolved` directly.
Also removes unused user errors.

---------

Co-authored-by: Adrià Arrufat <adria.arrufat@gmail.com>
2026-05-30 19:02:44 +02:00
Karl Seguin
490b48ecd0 zig fmt 2026-05-30 20:11:07 +08:00
Karl Seguin
eb5d46bb11 Fix potential segfault in CustomElement definition
Fixes crash in WPT /custom-elements/CustomElementRegistry.html

define has to get `observedAttributes` which itself could call define,
invalidating any GetOrPutEntry pointers. Need to do it as two distinct lookup.
2026-05-30 20:05:44 +08:00
Karl Seguin
ee7e9715a4 typo fix 2026-05-30 14:16:50 +08:00
Karl Seguin
5ac7b54f53 Apply suggestions from code review
Co-authored-by: Pierre Tachoire <pierre@tch.re>
2026-05-30 14:12:29 +08:00
Karl Seguin
b91b3ecd16 Merge pull request #2578 from lightpanda-io/cookie_store_crash_fix
Close session before freeing notification
2026-05-30 10:12:49 +08:00
Karl Seguin
732234c453 Merge pull request #2573 from lightpanda-io/notifiation_webapi
Add Notification WebAPI
2026-05-30 08:47:32 +08:00
Karl Seguin
a40c35ab5f Merge pull request #2574 from lightpanda-io/synthentic_transfer_double_free
Prevent double-free on Synthetic URL
2026-05-30 08:46:51 +08:00
Karl Seguin
a7d3a5968c Merge pull request #2572 from lightpanda-io/cookie_jar_ownership
Cleaner cookie ownership
2026-05-30 08:46:29 +08:00