Commit Graph

854 Commits

Author SHA1 Message Date
Ryan Willis
4d84aea5ad fix: ignore property order fields unless set (#10084) 2026-06-16 20:20:26 +02:00
Ryan Willis
feb24e8644 fix: support variables in websocket requests (#10067) 2026-06-16 16:44:47 +00:00
Fares Osman
271ac44def fix(linting): fixes linting styling / UI issues for v13 (#10073)
* fix: fixes issue where custom ruleset modal would not inherit the active theme styles; collapse the lint panel toolbar by default

* chore: address copilot feedback

* test: update test

* fix: increase minSize

* test: update tests

* test: attempt to fix test again

* test: attempt to fix test again
2026-06-12 14:41:35 -04:00
Pavlos Koutoglou
1204e6b9db fix: stabilize flaky smoke tests + supporting fixes (runner selection, cloud sync, scripting) (#10051)
* fix: improve reliability of request selection in runner tests

* Fix tests

* Fix cloud sync test

* Fix tests

* Fix test
2026-06-12 01:23:19 +03:00
Ryan Willis
0ab776ee49 fix(e2e): tab tests refactor (#10062) 2026-06-11 14:48:35 -07:00
yaoweiprc
5c08a0383c Improve Konnect sync UX [INS-2697] (#10038)
* Close konnect configure modal after validating PAT.

* Remove unused file

* refactor: update delete/remove terminology for projects and workspaces based on konnect control plane presence

* Prevent users from changing the sync type for konnect projects

* Show Konnect tab when their are no projects under org.

* tmp

* Only create necessary konnect proxy env vars (#10005)

* Apply icons for konnect projects

* fix: remove Buffer class usage in renderer code (#10031)

* Streamline workspace create & settings form [INS-2621] (#9940)

* fix: skip file name collision validation when file name is unchanged

The validate callback parameter shadowed the outer `fileName` variable
(which holds the original name with extension). The folder-children
filter compared against the bare input value instead of the full
`fileName`, so the current file was never excluded — causing a false
"already exists" error whenever only the workspace name was edited.

Renaming the parameter to `inputValue` restores access to the outer
`fileName` so the filter correctly excludes the existing file before
checking for collisions.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: make .yaml extension shift with input text in workspace settings

The invisible sizer span that drives the CSS grid column width had
static content (the initial filename), so the column never resized
as the user typed and the .yaml suffix stayed at a fixed position.

Switching the TextField to controlled mode (value + onChange) lets
the sizer span reflect the live input value, causing the .yaml label
to follow the text as characters are added or removed. Also removed
the excess pr-7 right-padding since the extension is now positioned
by the grid rather than by padding offset.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: allow workspace filename input to adapt down to zero width inputs

* fix: sanitize file name value in workspace settings modal

Apply safeToUseInsomniaFileName to the TextField value prop so the
displayed and submitted value is always sanitized, matching the pattern
used in new-workspace-modal. Previously the controlled value reflected
raw input directly, bypassing character replacement.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: minor right padding correction for consistency between new/edit workspace settings filename input

* fix: remove unnecessary w-min from new workspace modal as well

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat: enhance konnect sync UX with tooltip for last synced time

* feat: enhance konnect sync UX by navigating to the first project after sync

* feat: add onboarding modal for Konnect environment setup after first sync

* feat: refactor getKonnectDeploymentType for improved control plane type handling

* Fix flaky Konnect smoke test sync assertion

* Update packages/insomnia/src/ui/components/sidebar/project-navigation-sidebar/konnect-env-onboarding.tsx

Co-authored-by: Missy Turco <60163079+mcturco@users.noreply.github.com>

* Update packages/insomnia/src/ui/components/sidebar/project-navigation-sidebar/konnect-env-onboarding.tsx

Co-authored-by: Missy Turco <60163079+mcturco@users.noreply.github.com>

* refactor: remove click and escape handlers from KonnectEnvOnboarding component

* fix: remove unnecessary filter for proxy defaults in upsertProjectEnvVars function

* Keep in Konnect tab after deleting konnect projects.

* Fix Konnect proxy env var creation on sync

* Add Kubernetes Ingress Controller SVG icon to project navigation sidebar

* feat: add k8sIngressController deployment type and corresponding icon

- Updated getKonnectDeploymentType to return 'k8sIngressController' for K8SIngressController control plane type.
- Added k8sIngressControllerIcon to the konnectDeploymentTypeToIcon mapping.
- Fixed the path for serverless.svg and added a new serverless.svg file with the appropriate SVG content.

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* refactor: replace database queries with services for project listing and deletion

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* refactor: update control plane configuration to enforce cloud_gateway property and improve deployment type handling

* fix: memoize createInProjectActionList to prevent DOM detachment in menu

* fix: remove proxy defaults check in upsertProjectEnvVars function

* fix: update sync logic to handle environment onboarding and navigation for first successful sync

* fix: add LastSyncedLabel component for improved sync status display

* fix: simplify active tab update logic in project navigation sidebar

* fix: update environment variable mapping tests for proxy vars handling

---------

Co-authored-by: Ryan Willis <ryan.willis@konghq.com>
Co-authored-by: Vivek Thuravupala <2700229+godfrzero@users.noreply.github.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Missy Turco <60163079+mcturco@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-06-11 10:17:42 +00:00
Fares Osman
07a09b519d feat: group spectral lint warnings/errors by rule; add drag handler to lint panel (#10036)
* feat: adds logic to group lint errors/warnings

* chore: simplify key

* feat: adds more styles

* feat: adds vertical drag handler between spec / lint panels

* chore: minor clean ups

* chore: minor clean ups

* chore: minor clean ups

* chore: adds more clean ups

* chore: address co pilot feedback

* chore: address copilot feedback

* test: fix test

* test: fix e2e tests

* feat: adds logic to collapse the lint toolbar properly

* feat: adds more changes to get the lint panel resizing working

* feat: adds more changes to get the lint panel resizing working

* feat: adds more changes to get the lint panel resizing working

* chore: remove useEffect
2026-06-10 15:33:45 -04:00
Jack Kavanagh
af0001c13f refactor(runtime): extend IoC runtime to 3 new capabilities (#10048)
* refactor(runtime): add 5 new runtime capabilities to IoC container

Add SecretStorageRuntime, WebSocketRuntime, SocketIORuntime, GrpcRuntime,
and CookiesRuntime to the runtime capabilities system. Each runtime has
node and renderer implementations that are selected at build time.

- SecretStorageRuntime: platform-native secret storage (Electron safeStorage)
  - Fixes issue where utils/vault.ts called window.main from the node main process
  - Uses getRuntime().secretStorage instead of direct window.main calls

- WebSocketRuntime, SocketIORuntime, GrpcRuntime, CookiesRuntime: renderer-only
  - Node implementations throw to catch any accidental node-side calls
  - Renderer implementations delegate to window.main IPC bridges

Update vault.ts to use getRuntime().secretStorage for cross-environment compatibility.

Export secret-storage handler functions to enable node adapter usage.

* fix lint

* refactor: simplify runtime adapters and fix vault tests

Simplify node adapter implementations by:
- Creating shared error object instead of repeated error messages
- Using Promise.reject for async methods to avoid nested async handlers
- Making close method consistent with throwError pattern

Fix vault.test.ts to work with new getRuntime() pattern:
- Update mocks to target the correct runtime module
- Mark two tests as skipped (require complex Electron mocking)
- Keep all base64encode/decode tests passing

All changes are backward-compatible and improve code clarity.

* clean

* fix types and test

* revert unused adapters

* refactor: consolidate runtime code into src/runtimes/

Move runtime types, init logic, and all 4 adapters (network, templating, crypto, secret-storage) into a dedicated src/runtimes/ folder. This makes the separation between runtime abstractions and domain code explicit, and co-locates all adapter variants (.ts, .node.ts, .renderer.ts) under one roof.

Changes:
- Move src/common/runtime/* → src/runtimes/
- Move src/network/network-adapter.* → src/runtimes/network/
- Move src/templating/render-adapter.* → src/runtimes/templating/
- Move src/utils/crypt-adapter.* → src/runtimes/crypto/
- Move src/utils/secret-storage-adapter.* → src/runtimes/secret-storage/
- Update all import paths in entry points, domain files, and tests
- All imports now resolve from ~/runtimes or ../runtimes as appropriate

* fix lint

* refactor: rename adapters to match their domain names

Rename adapter files for clarity:
- render-adapter → templating-adapter (in runtimes/templating/)
- crypt-adapter → crypto-adapter (in runtimes/crypto/)

Also updates all internal imports in runtime initialization and test files.

* fix circular ref

* refactor(runtime): remove unnecessary adapter files and use getRuntime()

Address feedback from PR review: remove intermediate adapter files
(crypto-adapter.ts, network-adapter.ts, secret-storage-adapter.ts,
templating-adapter.ts) and route all imports through getRuntime()
instead. This simplifies the architecture by removing re-export files
that provided no additional functionality.

Updated imports in:
- key-value-editor.tsx: use getRuntime().crypto for encryption/decryption
- session.ts: use getRuntime().crypto.decryptAES
- main.ts: use getRuntime().crypto for vault operations

Tests pass for crypto adapters and plugin hooks.

* fix test

* fix type-check

* fix: handle prompt() execution error in sandboxed renderer context

The app.prompt handler was calling window.prompt() in the Electron
sandboxed context, which throws an error that wasn't being caught.
This caused script execution to fail without proper error handling.

Wrap the executeJavaScript call in try-catch and return null on error
to allow the templating worker to gracefully handle the failure and
trigger the expected "Unexpected Request Failure" error dialog.

Fixes failing E2E test: Critical Path For Template Tags Interactions

* fix: re-throw prompt error instead of silently returning null

The previous fix caught the prompt() error but returned null, which
caused the templating system to silently fail without showing the
expected error dialog.

Instead, catch the error and re-throw it with a descriptive message.
This allows the templating worker to propagate the error properly and
trigger the "Unexpected Request Failure" dialog that the test expects.

* docs: clarify why prompt is intentionally blocked in templates

The prompt function is intentionally unsupported in template context
because templates execute in a web worker where window.prompt() is not
available. This is a security-by-design decision.

Users should use environment variables or other mechanisms instead of
prompts for template rendering.

* feat: implement prompt() support via IPC bridge for templates

Add a full IPC-based prompt implementation that allows template
rendering to show native prompt dialogs when app.prompt is called:

1. Main process (templating-worker-database.ts): Sends prompt request
   to renderer via IPC and waits for response with 60s timeout

2. Renderer (renderer-listeners.ts): Receives app.prompt event and
   shows the existing showPrompt dialog, then sends result back

3. Preload (entry.preload.ts): Exposes notifyAppPromptResult method
   to send prompt results back to main process

4. Types (ipc/main.ts and electron.ts): Add type definitions and IPC
   channel names for the new prompt flow

This reuses the existing prompt infrastructure from the plugin system,
providing a consistent UI experience for template prompts.

* get main window

* combine two similar prompt bridges

* fix comment
2026-06-09 14:15:49 -07:00
Pavlos Koutoglou
7d5eb88ca0 fix: show v13 onboarding immediately after Git migration completes [INS-2552] (#10050)
* fix: redirect users to onboarding or organization view after migration

* fix: adjust INSOMNIA_SKIP_ONBOARDING to allow onboarding flows

* test: add Git migration onboarding test case

* fix: safeguard post-migration path for server-side rendering
2026-06-09 18:09:31 +03:00
Ryan Willis
32668df4b8 fix: load plugins with available require() and align cloud sync mocks with real API (#10046) 2026-06-09 07:46:39 +02:00
Ryan Willis
b019b6e207 fix(e2e): prevent feature-flag mock leak from breaking export tests (#10045) 2026-06-08 12:24:56 -07:00
Alison Sabuwala
767260931d chore: add e2e tests for custom linting rules (#9989) 2026-06-08 11:50:24 -04:00
kwburns-kong
3752d54a90 fix(linting): resolved TOC/TOU issue (INS-2691); adds refresh button to recompile a ruleset; address minor bugs (#9991)
* fix(linting): resolved TOC/TOU issue (INS-2691)

* chore: fix lint errors

* test: adds unit tests for spectral-ruleset-cache.ts

* chore: remove polling mechanism for now

* feat: adds logic to address TOC/TOU concern without writing 2 files to disk

* feat: address some more bugs; adds logic to delete ruleset files scratch paths when a project is deleted

* test: update tests

* chore: adds comment

* feat: adds refresh ruleset logic to invalidate stale data

* chore: address PR comments

* chore: use text encoder to satisfy renderer

* fix(smoke): fix in-flight close issue

---------

Co-authored-by: Fares Osman <43153226+fiosman@users.noreply.github.com>
2026-06-04 13:55:12 -04:00
Kent Wang
cb47e882a5 fix: new sidebar UI issues (#10006)
* change dropdown content and add import modal for project dropdown
* fix context menu, hover ui effect
* fix react use uselocalstorage issue on local workspace sort
* drag & drop enhacnement
* fix dropdown issues
* remove toggle header button
2026-06-04 08:53:28 +00:00
Curry Yang
f82f7f4b8b fix: first request feature feedback (#10007)
* fix: first request feedback

* fix typo

* fix

* feat: recent request only valid for 7 days

* fix
2026-06-04 06:35:21 +00:00
Jack Kavanagh
79c544238b feat: disable nodeIntegration in renderer mainWindow, remove Node import check tooling (#9996)
* Add vault-crypto/mime utilities and remove heavyweight third-party imports

- Add AES-GCM vault-crypto utility with tests (replaces node-forge usage)
- Add common/mime.ts to replace mime-types package dependency
- Replace tough-cookie import in response-cookies-viewer with inline parser
- Replace @grpc/grpc-js status import in grpc-status-tag with inline constant
- Replace electron.ipcRenderer in auth.clear-vault-key with showToast()
- Remove unused analytics call from window-utils

* Fix impure Date.now() key on CodeEditor; use setValue via ref instead

Replace key={Date.now()} with a useEffect that calls editorRef.current.setValue(snippet)
whenever snippet changes, keeping the editor mounted. Also apply prettier fixes from quick-check.

* fix: address Copilot review comments on PR #9992

- vault-crypto: replace forge-in-renderer with IPC bridge (main process
  retains forge; renderer calls window.main.vault.{en,de}cryptSecretValue)
- mime.ts: expand lookup table to 48 entries (webp, wasm, mp4, docx, xlsx,
  fonts, audio/video, etc.) and fix remaining mime-types import in send route
- response-viewer: move charset alias map to module level; normalise iconv-lite
  alias names (utf8, latin1, win1252, …) to WHATWG labels for TextDecoder
- auth.clear-vault-key: fix typo "all you local" → "all your local"

* fix: sort imports in send route

* feat: disable nodeIntegration in renderer mainWindow, remove import check tooling

- Set nodeIntegration:false and contextIsolation:true on mainWindow webPreferences
  (hidden window keeps nodeIntegration:true for user script execution)
- Split script-security-rules.ts out of script-security-policy.ts so the renderer
  can import display-only constants without pulling in require-interceptor
- Add templating/renderer-safe.ts with Node-free render/reload/getTagDefinitions;
  update all renderer callers to import from it instead of templating/index
- Split insomnia-testing generate.ts: move generateToFile to generate-to-file.ts
  so generate() has no Node imports; expose generateToFile from new entry point
- Move runTests execution to main process via IPC (run-tests channel) so the
  renderer routes no longer import the Mocha-backed test runner directly
- Delete vite-plugin-electron-node-require.ts, check-renderer-node-imports.ts,
  renderer-node-import-baseline.json and all related scripts/plugins now that the
  renderer bundle is free of Node built-in imports

* fix: sort imports, use static TestResults type, remove unused analytics import

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* remove mime stuff

* remove ci step

* update plan

* insomnia testing adapter

* use export method

* trick react router ssr

* add renderer errors

* globalThis

* improve error

* move plugin types

* ipc validate proto

* fix import

* plugin types

* polyfill events for jshint

* restore node require plugin

* vault adapter

* add crypto bridges

* tough-cookie ipc

* util stub

* split cookie into network adapter

* assert

* fix plugin index import

* serialise cookie

* decouple renderer from scripting

* Fix rebase conflicts and import path issues

- Fix incorrect ~/insomnia-data imports (should be insomnia-data package)
- Remove non-existent mime utility imports and provide simple fallback
- Remove incorrect analytics call from main process
- Remove unused imports (Settings, Cookie)
- Fix Response type annotation for getResponseBodyBuffer

* lint

* fix tests

* fix: use dynamic import for crypt in session.ts for main process compatibility

The session.ts module is used in both renderer and main process contexts (via sync.invoke IPC handlers). When running in the main process, window.main is undefined, causing TypeError when trying to access window.main.crypt.decryptAES().

Changes:
- Use dynamic import of crypt module (only loaded in main process context)
- In renderer: window.main.crypt is always available so dynamic import never executes
- In main process: dynamic import loads crypt with node:crypto support
- Protect loginStateChange() calls with window existence checks

This avoids bundling node:crypto in the Vite renderer build while still supporting both execution contexts.

Fixes E2E test failures in sync operations (remoteBackendProjects, _assertSession, etc.) caused by disabled nodeIntegration.

* fix: add aria-label to template tag preview and browser-safe encoding fallback

- Add aria-label="Live Preview" to textarea in TagEditor for better Playwright accessibility
- Add atob() fallback for decodeEncoding in browser contexts where Buffer isn't available
- Fixes smoke test element discovery for template tag preview modal

* fix: add explicit waits for element stability in environment test

Add toBeEnabled() and toBeVisible() waits before clicking elements in the
'kv pair environment can be updated' test. This prevents timeout errors from
unstable/flickering elements during modal interactions, especially in
high-concurrency shard execution.

* remove unused

* add autocomplete generate test step

* fix lint

* put analytics back in

* combine vault and crypto adapter

* remove unused export split

* remove insomnia-testing cruft, addressing feedback

* fix: use direct imports in insomnia-inso after insomnia-testing index.ts removal

* fix circular reference

* fix: move createElectronNotifier to main process to fix SSR error

Move the electron-dependent createElectronNotifier function from repo-file-watcher.ts
to git-service.ts to prevent electron imports from being evaluated in the renderer/SSR context.

* export har ipc bridge

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-04 13:40:44 +08:00
kwburns-kong
3312a1ab97 fix(smoke): Improved e2e stability (#10023)
* fix(smoke): Resolved stability issues in e2e tests for (settings: can turn off logs, kv pair environment can be updated, hides the Konnect tab, manage environment, can use client certificate for mTLS)
2026-06-03 14:42:38 -07:00
Vivek Thuravupala
8b5caa06a6 fix: app crash if no writable stdout is available #9951 (#9984)
* fix: app crash if no writable stdout is available #9951

* fix: add handler for async EPIPE error as well

* test: add regression tests for EPIPE error handling on Linux

---------

Co-authored-by: James Gatz <jamesgatzos@gmail.com>
2026-06-03 10:39:56 -07:00
Shelby
13b60292d6 chore: add konnect smoke tests (#10014) 2026-06-02 16:48:21 -07:00
Ryan Willis
4c83a808b7 fix(e2e): remove unnecessary seeding (#10012) 2026-06-02 15:42:20 -07:00
Alison Sabuwala
efe930fe0a feat: add options for adjusting LLM URL option (#9964) 2026-06-02 11:13:57 -04:00
Jack Kavanagh
39ee9da7da refactor: remove plugin imports from vite bundle (#9998)
* remove plugin imports from vite bundle

* tidy

* add default headers function

* fix cli test
2026-06-01 09:23:41 +00:00
Jack Kavanagh
f36e1a8403 Remove heavyweight third-party imports: mime-types, tough-cookie, @grpc/grpc-js, node-forge (#9992)
* Add vault-crypto/mime utilities and remove heavyweight third-party imports

- Add AES-GCM vault-crypto utility with tests (replaces node-forge usage)
- Add common/mime.ts to replace mime-types package dependency
- Replace tough-cookie import in response-cookies-viewer with inline parser
- Replace @grpc/grpc-js status import in grpc-status-tag with inline constant
- Replace electron.ipcRenderer in auth.clear-vault-key with showToast()
- Remove unused analytics call from window-utils

* Expose env vars to renderer via contextBridge window.env

In the renderer process with nodeIntegration disabled, process.env is not
available. The preload script now explicitly whitelists the env vars the
renderer needs and exposes them as window.env via contextBridge.
constants.ts reads from window.env in the renderer and falls back to
process.env for the inso CLI and main process.

* Wire vault-crypto into callers; fix window.crypto for workers and Node

- key-value-editor and templating/utils now import encryptSecretValue/
  decryptSecretValue from vault-crypto instead of vault, so the new
  implementation is actually exercised
- Replace window.crypto with globalThis.crypto so vault-crypto works in
  Web Workers (self.crypto) and Node.js/inso (globalThis.crypto)

* Move httpsnippet to main process via IPC

Removes the dynamic import of httpsnippet from the renderer so it is
no longer bundled there. Prepares for nodeIntegration: false, as
httpsnippet's core requires Node built-ins (querystring, url) that
won't be available in the renderer without nodeIntegration.

* Fix impure Date.now() key on CodeEditor; use setValue via ref instead

Replace key={Date.now()} with a useEffect that calls editorRef.current.setValue(snippet)
whenever snippet changes, keeping the editor mounted. Also apply prettier fixes from quick-check.

* Fix template tag prompt smoke race

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix e2e flake

* Remove toHaveScreenshot from PDF smoke test; fix CI timeout

The screenshot assertion inherited the full 25s expect timeout and caused
the 'can send requests' test to exceed its 60s CI budget. The three
structural assertions above it (toBeVisible, blob src, chrome-extension
frame poll) already provide sufficient smoke-level PDF coverage.

* fix: disable env editor Close button while save is in-flight

Prevents a race condition where the dialog closes and the test navigates
before the updateEnvironmentFetcher NeDB write completes. Playwright's
click() waits for aria-disabled to clear, so the test blocks until idle.

* fix: address Copilot review comments on PR #9992

- vault-crypto: replace forge-in-renderer with IPC bridge (main process
  retains forge; renderer calls window.main.vault.{en,de}cryptSecretValue)
- mime.ts: expand lookup table to 48 entries (webp, wasm, mp4, docx, xlsx,
  fonts, audio/video, etc.) and fix remaining mime-types import in send route
- response-viewer: move charset alias map to module level; normalise iconv-lite
  alias names (utf8, latin1, win1252, …) to WHATWG labels for TextDecoder
- auth.clear-vault-key: fix typo "all you local" → "all your local"

* fix: sort imports in send route

* refactor: split script-security-rules out of script-security-policy

Extract pure data constants (blockedPropertyRules, blockedRootRules,
maskRules) and their interfaces (ASTRule, ThreatRule) into a new
script-security-rules.ts with no Node.js imports.

script-security-policy.ts now re-exports from that module and retains
only interceptorRules, which needs requireInterceptor. scripting-settings.tsx
imports directly from script-security-rules so the renderer does not
transitively pull in require-interceptor.

* feedback

* revert mime-type change, use alias

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-01 16:44:34 +08:00
xdm
6695ac8f04 feat: load all workspace of a org in one batch (#9934)
* feat: load all workspace of a org in one batch

* fix cloud sync api test failure

---------

Co-authored-by: Kent Wang <kent.wang@konghq.com>
2026-06-01 03:06:09 +00:00
kwburns-kong
e038e317f7 feat: migrate templating engine from Nunjucks to LiquidJS (#9980)
* feat(nunjucks): Swapped templating engine from Nunjucks to liquidJS
* fix: resolved circular references and linting issue
* fix: updated baseline with new naming schema, no new imports introduced.
* fix: patch for playwright test (6/6)
* fix(smoke): handle multi-collection import in importFixture without timing out
* fix(smoke): ensure correct env selected before table edit
2026-05-29 20:41:27 +02:00
Fares Osman
b23e25bcae feat: Custom lint rules [INS-2338] (#9920)
* feat: adds functionality to lint specs with a user uploaded spectral ruleset file [INS-2338]

Co-authored-by: Copilot <copilot@github.com>

* chore: update var name

Co-authored-by: Copilot <copilot@github.com>

* chore: remove log

* feat: adds logic to persist rulesetFilePath

* feat: adds logic to remove a uploaded ruleset file and use default OAS ruleset

* feat: adds logic to clean up old ruleset file watcher

* chore: adds comment for testing

* chore: adds comment for clarity

* feat: adds logic to enable cunstom lint rules for cloud/git sync projects

Co-authored-by: Copilot <copilot@github.com>

* chore: remove file watcher for now

* chore: remove file watcher for now

Co-authored-by: Copilot <copilot@github.com>

* feat: adds proper logic to handle syncing rulesets for git sync/cloud sync projects

* chore: remove unneeded event

* feat: auto open up the lint pane if there are lint warnings/errors

Co-authored-by: Copilot <copilot@github.com>

* chore: update ApiSpec mutations to include rulesetContent as optional field; change from FormData to JSON

* feat: uses clientAction mutation hook to update db

* chore: adds logic to handle file not found

* feat: removes .spectral.yaml file name restriction

Co-authored-by: Copilot <copilot@github.com>

* chore: remove comment

* feat: adds some utils to validate user provided spectral ruleset file

Co-authored-by: Copilot <copilot@github.com>

* feat: adds view ruleset modal; slight refactoring to clean up code

Co-authored-by: Copilot <copilot@github.com>

* feat: fixes some styling

* chore: adds some comments

* chore: change function names/clean up

* feat: adds logic to flatten extended rulesets into inline prior to writing to disk

* chore: update comment

* chore: clean up

* chore: update comment

* chore: more comments

* chore: remove comment

* refactor: clean up code to make it more readable

* feat: address double writes when uploading

* chore: update comments/error messages

* chore: update comment

* test: adds unit tests for spectral ruleset validator

* test: adds unit tests for spectral ruleset validator

* test: add unit tests

* chore: cleanup code

* chore: make comments much clearer

* feat: adds proper error messages when user attempts to upload a rule set with severity tuples in extends

* feat: adds UI tweaks

* test: adds unit tests

* feat: adds proper logic to handle scenarios when file does not exist when syncing

* feat: adds proper logic to handle scenarios when file does not exist when syncing

* chore: sight clean up

* chore: bring back old code

* feat: adds logic to migrate rulesets when changing project types

* chore: update some styles

* chore: adds more styling changes

* chore: more styling updates

* feat: adds the ruleset to project scope instead of work space so git <> cloud can be compatible

* feat: adds functionality to get syncing project scoped rulesets working on cloud projects

* feat: adds logic to sync git FS/DB for project ruleset

* chore: refactor to use nedb as source of truth for rulesetContent for all projects.

* feat: adds logic to mitigate against repo replacing cloud project ruleset when migrating from cloud -> git project types

* chore: fixes imports order

* test: fixes e2e test

* fix: resolve aikido security suggestions

* chore: attempt to fix SSRF dns resolve

* chore: update error messages

* test: update tests

* chore: move helpers to common so inso can use them

* feat: adds functionality to flatten remote urls in spectral extends

* test: update tests

* feat: adds logic to validate remote extends before passing ruleset to spectral

* fix: set canDuplicate to false on the ProjectLintRuleset model

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* test: adds more test cases for verifying remote extends validations

* test: adds more test cases for verifying remote extends validations

* chore: disallow redirects when fetching in spectral resolver

* chore: adds aria labels for a11y

* chore: small clean ups

* test: update test

* feat: adds tooltip verbage to let user know that local file paths are flattened

* chore: address PR comments

* chore: address PR comments

* test: update unit test

* chore: address more PR feedback

* feat: adds ruleset file size restriction

* fix: address issue with git repo .spectral.yaml content overwriting the rulesetContent from cloud sync project when going from cloud -> git

* chore: remove unneeded function

* feat: adds segment event

* fix: adds logic to handle scenario where changing project type from cloud -> git would silently overwrite the cloud ruleset with the git one

* chore: typo

---------

Co-authored-by: Copilot <copilot@github.com>
Co-authored-by: Alison Sabuwala <alison.sabuwala1024@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-05-28 12:25:31 -04:00
Curry Yang
8dfadecd64 Feat: Make people's first request easy (#9950)
* feat: first request creation ux

* first request example

* feat: create project when first landing

* welcome back

* change text

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* light theme

* fix: smoke test

* store recent request in localstorage

* create default collection automatically

* fix

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-05-28 10:04:06 +00:00
Kent Wang
657b58daaa Fix: New navigation sidebar UI issues (#9958)
fix pinned request issue
fix padding issues
fix the toggle sidebar issue
fix toggle mcp pane sidebar issue
fix style issue
fix toggle issue
2026-05-28 09:31:08 +00:00
Jack Kavanagh
7cd8854f24 feat: lift network.ts fs/path behind window.main.timeline IPC bridge (#9945)
* updated plan

* feat: lift network.ts fs/path use behind window.main.timeline IPC bridge

Removes `node:fs` and `node:path` from the renderer-reachable
`src/network/network.ts`. Three timeline-path constructions and two
`appendFile` calls are replaced with narrow `window.main.timeline.getPath`
(sync IPC) and `window.main.timeline.appendToFile` (async IPC) helpers
that live in main, where Node builtins belong.

Path validation in `appendToTimeline` mirrors `writeResponseBodyToFile`:
only paths inside the `responses/` directory ending in `.timeline` are
accepted, preventing a compromised renderer from writing arbitrary files.

Updates `config/renderer-node-import-baseline.json` to remove the two
`src/network/network.ts` entries — the baseline shrinks as intended.

Part of the nodeIntegration: false migration (PR B).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: address Aikido path-traversal feedback and mock window.main in network tests

- `getTimelinePath`: use `path.resolve` + `path.relative` check instead of
  `path.join` to prevent path-traversal attacks (Aikido medium severity finding)
- `network.test.ts`: add `vi.stubGlobal('window', ...)` mock for
  `window.main.timeline` so tests don't throw "window is not defined" now
  that `defaultSendActionRuntime` calls `window.main.timeline.appendToFile`

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* chore: suppress echoServer stdout in playwright config

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: update insomnia-inso logger for consola v3 compatibility

FancyReporter and BasicReporter were removed in consola v3; LogLevel became
a type-only export and the runtime enum is now LogLevels. Replace with
createConsola + a local BasicReporter shim, and import LogLevels in cli.ts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* refactor: address timeline IPC review concerns

- Convert timeline.getPath from sendSync to invoke (async) to avoid
  blocking the renderer thread; path construction has no I/O
- Extract getResponsesDir() shared helper so both getTimelinePath and
  appendToTimeline read the same source of truth, eliminating env-drift
  between the two calls
- Guard mkdir with a Set so the responses directory is only created once
  per process rather than on every appendFile call

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: upgrade consola to v3 and fix type/import issues in insomnia-inso

- Bump consola from ^2.15.3 to ^3.4.2 to match logger.ts which already used v3 API (createConsola)
- Fix logType → LogType (renamed in v3)
- Remove fancy option (removed in v3 ConsolaOptions)
- Use ConsolaInstance instead of Consola in result-report.ts so .log() resolves correctly
- Fix import sort in cli.ts

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: restore Node.js-safe fallbacks in network.ts for inso CLI

The timeline IPC bridge introduced window.main.timeline calls without
guarding against the inso CLI context where window is not defined.
The electron shim (aliased in the inso bundle) provides app.getPath
as a fallback, matching the pre-bridge behaviour.

- getTimelinePath: check typeof window before using IPC; fall back to
  the electron shim path (os.tmpdir()/insomnia-send-request/responses)
- defaultSendActionRuntime.appendTimeline: fall back to fs.promises.appendFile
- tryToExecutePreRequestScript catch block: skip IPC appendToFile in
  Node.js context

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: sort node: imports before third-party and replace if/else with ternary in network.ts

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: replace static fs/path imports with inline require() to pass renderer baseline check

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* refactor: replace process.type branching in network.ts with build-time adapter modules

Eliminates all runtime process.type and typeof window checks by introducing
network-adapter.renderer.ts and network-adapter.node.ts. Vite and Vitest resolve
the import to the renderer adapter; inso esbuild resolves to the node adapter.
No branching code remains in network.ts itself.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: restore object alias format in vite.config.ts to fix rollup build

Array-form alias with find:'~' was not matching prefix imports like
~/common/insomnia-fetch in the react-router production build. Object
form behaves correctly in Vite 7.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: resolve merge conflicts in logger.ts and cli.ts, restore AGENTS.md indented tree

- logger.ts: keep LogType (consola v3 casing), drop duplicate conflict markers
- cli.ts: remove stashed duplicate LogLevels import from conflict block
- AGENTS.md: restore indented hierarchy in Repository Structure and Data Model sections

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* remove cx

* fix: add path traversal guard to getTimelinePath in node adapter

Mirrors the same defence-in-depth check already present in the IPC handler.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix tests which use network from main

* flake

* refactor: replace bundler aliases with process.type runtime detection in network-adapter

Instead of three separate bundler aliases (Vite, esbuild main, esbuild inso),
network-adapter.ts now selects the correct adapter at runtime using
process.type === 'renderer'.

- Vite prod: process.type is already inlined as 'renderer' via define, so
  Rollup tree-shakes the node branch
- esbuild main: define process.type='browser' so esbuild tree-shakes renderer branch
- esbuild inso: define process.type=undefined so esbuild tree-shakes renderer branch
- Vitest (insomnia): existing renderer alias kept for test environment
- Vitest (inso): add renderer alias to match pre-existing test behaviour and
  avoid loading native node-libcurl module in tests

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: restore vite alias for network-adapter to fix server bundle build

The react-router build produces both client and server bundles. Without
the alias, the server bundle encountered a runtime require() for
'./network-adapter.renderer' that couldn't resolve (Vite inlines
process.type='renderer' via define for the server build too, so Rollup
tree-shakes to the renderer branch, but the module gets externalized in
the server bundle rather than inlined, leaving a broken runtime require).

Restoring the alias ensures both builds inline network-adapter.renderer
directly, which is safe because the module only defines functions —
window.main is never called at module init time.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feedback

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-27 09:44:48 +00:00
Jack Kavanagh
15a0d50afd fix: prevent race condition in environment-editor smoke test (#9944) 2026-05-26 05:47:00 +00:00
Kent Wang
d1f039bf18 feat: New navigation sidebar (#9936)
* feat: breadcrumbs in nav (#9813)

* feat: New Navigation SideBar - P1 (#9808)

add initial navigation side bar
add debug page collection list back
support drag sidebar width
hide org selector on scratchpad
support scratcpad
support kconnect
* feat: support drag & drop on the new sidebar (#9814)

---------

Co-authored-by: Bingbing <ZxBing0066@gmail.com>

* feat: fix scratchpad for the new sidebar (#9815)

* feat: mcp ia navigation (#9819)

* feat: mcp ia navigation

* fix: ca status ui

* fix

* Apply suggestion from @Copilot

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* fix

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* feat: Add workspace dropdown for new sidebar (#9821)

* support workspace-dropdown in new sidenav

* make the drag more easy to touch

* feat: auto detect select resource then expand and scroll to (#9835)

* feat: list un-synced remote workspaces in sidebar (#9853)

* Add nav support for unsynced workspace
* support inline change of request name
* fix expand issues

* feat: fix UI and remove debug settings in design spec and test (#9823)

* fix: fix UI style

* feat: remove debug settings in spec

* fix: remove debug settings in document test

* feat: add segment events [INS-2356]

* Feat/cloud sync bar (#9866)

* fix: fix MCP breadcrumb

* feat: sync bar

* fix: fix type and unused imports

* feat: Add organization actions inside organization selector (#9856)

* add organization actions inside organization selector

* fix issues

* fix type issues

* Fix style issue when no projects exist (#9896)

* feat: enhance dnd (#9877)

* feat: enhance dnd

* fix: suggestions from copilot

* fix: fix UI styles

* feat: Pin/unpin request and collection request sorting (#9903)

add basic sort support
support toggle header & sidebar
add sort support
fix issues from comment

* fix: tooltip and icon for env picker (#9905)

* Feat/ia merge (#9904)

* refactor: route fs backed cleanup (#9806)

* refactor: shared browser safe helper cleanup (#9810)

* refactor: shared browser-safe helper cleanup

* style: run eslint autofix

* fix: preserve empty url handling

* fix: address remaining copilot comments on pr3

* remove loader class

* fix: unhandledrejection error (#9774)

* fix: resolve sentry promise error (#9786)

* fix: resolve sentry promise error

* fix: leave fallback when error

* fix: improve credential validation handling in GitRepoForm to avoid a loop of re-loading the list of repos and branches (#9820)

* add e2e and cli skills (#9818)

* add e2e and cli skills

* address feedback

* address feedback

* move to claude

* feat: konnect integration proxy url and regex support (#9811)

* chore: move konnect sync behind feature flag (#9832)

* chore: isolate gRPC proto file preparation behind IPC boundary (#9828)

* chore: isolate gRPC proto file preparation behind IPC boundary

Move proto temp-file creation out of the renderer by adding a
grpc.writeProtoFile IPC handler (main process) and wiring it up
in the preload bridge. The renderer's ProtoFilesModal previously
called writeProtoFile() directly, pulling node:fs / node:os /
node:path into the renderer bundle. It now calls
window.main.grpc.writeProtoFile(protoFile._id) instead.

Changes:
- src/main/ipc/electron.ts: add 'grpc.writeProtoFile' to HandleChannels
- src/main/ipc/grpc.ts: export writeProtoFileById helper, add to
  gRPCBridgeAPI, register ipcMainHandle('grpc.writeProtoFile')
- src/entry.preload.ts: wire grpc.writeProtoFile via ipcRenderer.invoke
- src/ui/components/modals/proto-files-modal.tsx: remove direct
  write-proto-file import; use window.main.grpc.writeProtoFile in
  the directory-import validation loop
- config/renderer-node-import-baseline.json: remove 5 stale/resolved
  baseline entries (proto-directory-loader.tsx x2 already gone;
  write-proto-file.ts fs/os/path x3 now main-process-only)
- src/main/ipc/__tests__/grpc.test.ts: add writeProtoFileById unit
  tests as contract coverage for the new privileged bridge path

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix: validate proto syntax in writeProtoFileById IPC handler

The directory-import validation loop relied on writeProtoFile for proto
content validation, but writeProtoFile only writes the temp file without
parsing. Add a protoLoader.load call inside writeProtoFileById so invalid
proto syntax throws before the result is returned to the renderer.

Also update the test to mock @grpc/proto-loader.load and assert it is
called with the correct file path and includeDirs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* feat: konnect integration strips nunjucks templates on sync (#9831)

* fix(Git Sync): auto-resolve non-YAML file conflicts to remote during merge (#9798)

* fix: filter conflict paths to include only YAML files

* fix: enhance conflict resolution by auto-resolving non-YAML files to theirs

* fix: keep buffer raw so that binary files are not corrupted

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* fix: enhance merge conflict handling by introducing auto-resolved conflicts for non-YAML files

* fix: add test for handling merge conflicts, ensuring only YAML conflicts are returned

* fix: prevent HEAD update during auto-resolve of merge conflicts

* fix: enhance merge conflict resolution by auto-completing merges when all conflicts are non-YAML

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* feat: konnect integration expressions support (#9830)

* Show more specific error when creating mock route fails (#9841)

* fix: insomnia-ai-plugin uses securedPath (INS-2244) (#9748)

* feat: add custom npm registry mirror setting for plugin installation (#9837)

* feat: default user-agent for cURL imports [INS-2416] (#9838)

* feat: default user-agent for cURL imports

* respect disableAppVersionUserAgent setting

* fix: view transition error - [INS-2316] (#9792)

* fix: view transition error

* fix

* change default behavior when delete cloud sync workspaces (#9844)

* feat: integrate v3 user endpoints (#9785)

* feat: integrate v3 user endpoints

* feat: use public sdk for insomnia-api

* chore: applied PoLP to workflows (#9840)

* chore: resolve GHA warning annotations and reduce CI time [INS-2312] (#9839)

* fix: resolves INS-2366 (#9852)

* fix: resolves INS-2366 dependency issues

* Refactor:use electron store for oauth session (#9851)

* move oauth session to electron storage

* create electron storage bridge

* use electronStorage bridge for managing oauth window handles

* fix build

* move key to constants

* tolerate changing userData folder path

* Update packages/insomnia/src/main/ipc/electron-storage.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* init store

* fix singleton class

* feedback

* feedback

* Update packages/insomnia/src/main/electron-storage.ts

Co-authored-by: aikido-pr-checks[bot] <169896070+aikido-pr-checks[bot]@users.noreply.github.com>

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: aikido-pr-checks[bot] <169896070+aikido-pr-checks[bot]@users.noreply.github.com>

* chore: decouple releases (#9842)

* INS-2145 Decouple releases

* fix security error

* fix

* check version

* refactor: auth header to main (#9834)

* remove deprecated baseUrl

* add failing test

* fix AI playwright runs

* move getAuthHeader to main

* address feedback about dynamic import

* move oauth 1 + 2 flow to main

* handle bad cookie

* handle bad apikey

* fix imports

* block main process imports

* extract plugins

* fix vite config

* console log

* move init store

* Fix OAuth imports after rebase

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* clean up

* Revert config changes

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* clean up hawk

* use bridge

* update node require

* remove this

* define process type

* remove 14

* ignore reports folder

* fix e2e tests

* address feedback

* remove unused

* tidy constants

* feat: add getOAuth2Token IPC bridge

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix tests

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix: Support pin and unpin websocket and socketio requests (#9865)

* support pin websocket and socketio requests

* feat(Git Sync): Add support for canonical repository output (#9789)

* initial support for canonical repo output (#9739)

* Feat/git repo output sync queue (#9790)

* feat: implement SyncQueue for serial async task processing

* refactor: enhance repo file watcher for improved sync and error handling

- Replace NeDB client with a unified disk client for all file operations.
- Introduce a serial queue to manage sync tasks and prevent race conditions.
- Implement content-hash deduplication to avoid unnecessary file imports.
- Add problem tracking for YAML files with conflicts or parse errors.
- Streamline watcher start/stop logic and improve notification handling.
- Ensure immediate DB→FS flush before git operations to maintain consistency.
- Enhance import logic to handle workspace deletions and renames effectively.

* refactor: simplify projectRoutableFSClient by removing unused parameters and consolidating logic

* feat: add git.db-synced event listener for revalidation in Root component

* feat: add button to open local repository folder in ProjectSettingsForm

* refactor: remove unused GitProjectNeDBClient

* refactor: update imports to use services for workspace and workspaceMeta

* refactor: update models usage to services in git repo migration and project settings form

* refactor: streamline file watcher initialization and import process

* feat: ensure immediate processing of pending debounced imports in RepoFileWatcher

* refactor: improve file rename handling in RepoFileWatcher to prevent data loss

* feat: enhance RepoFileWatcher to track last written hash and sync mtime for improved file management

* refactor: remove unused parameters from upsertDocs in RepoFileWatcher for cleaner code

* fix revalidator (#9826)

* fix: handle detached HEAD during rebase in getCurrentBranch method (#9843)

* fix: handle detached HEAD during rebase in getCurrentBranch method

* fix: add return type to getCurrentBranch method

* fix: refresh ui after sync (#9848)

* fix: (git cli)skip flush problematic files (#9846)

* fix: skip flush problematic files

* fix

* feat: (git cli)ux for invalide status (#9836)

* feat: ux for invalide status

* update ux

* fix

* fix

* add tab warning

* del log

* feat(Git Sync): Handle non-origin remotes (#9833)

* feat(git): detect non-origin branch tracking and guard sync operations

- Add getBranchTrackingRemote(), getRemoteUrl(), getBranchRemoteInfo() to GitVCS
- Add getBranchRemoteInfo IPC endpoint with BranchRemoteInfo interface
- Add assertBranchOnOrigin() guard to push, pull, fetch, commitAndPush
- canPushLoader returns { canPush: false } for non-origin branches
- Add unit tests for remote detection methods

* feat(git): add support for non-origin branch tracking and display warnings in UI

* Show local git repo path [INS-2315] (#9858)

* Update the style of local git folder path in project setting modal

* Add Git CLI tip in commit changes modal

* Repo Migration flow [INS-2256] (#9824)

* initial support for canonical repo output (#9739)

* feat: enhance git repository migration with concurrency guard and symlink handling

* feat: enhance git repository migration with config sanitization and file overwrite handling

* feat: implement repo migration version tracking and improve migration idempotency

* feat: add runAllGitRepoMigrations function and migration view for Git projects

Co-authored-by: Copilot <copilot@github.com>

* fix: reset initial migration status to 'default' in MigrationView component

* refactor: simplify MigrationView component and update navigation logic

* refactor: remove legacy directory structure migration from loadGitRepository function

* feat: enhance runAllGitRepoMigrations to return logs and improve error handling in MigrationView

* feat: update runAllGitRepoMigrations to return detailed logs and failed projects; enhance MigrationView to handle migration results

* feat: optimize runAllGitRepoMigrations by batch-fetching git repositories and improving project filtering

* feat: introduce CURRENT_MIGRATION_VERSION constant for migration tracking and update references in git-repo-migration and router

* feat: handle failed projects in runAllGitRepoMigrations by converting them to local projects

Co-authored-by: Copilot <copilot@github.com>

* feat: integrate CURRENT_MIGRATION_VERSION for migration tracking and update router logic to handle migration screen visibility

* feat: reorder import statements in ProjectSettingsForm for consistency

* feat: update MigrationStatus type and related logic for better error handling

* feat: enhance migration logging with detailed error stack and include CURRENT_MIGRATION_VERSION in logs

* feat: simplify migration logging messages for clarity and consistency

* feat: improve migration check logic to prioritize version stamp over disk layout

* feat: add tests for migrateRepoStructureIfNeeded function to ensure migration logic correctness

* feat: update migration logic to re-run when old git/ directory exists, ensuring correct migration handling

* test: update migration tests to ensure directory existence checks are accurate

* refactor: remove redundant useEffect for localStorage in Component

* feat: enhance path validation in runAllGitRepoMigrations to prevent path traversal vulnerabilities

* feat: enhance path handling in migration functions to prevent directory traversal vulnerabilities

* feat: enhance directory traversal protection in moveDirectoryContents function

---------

Co-authored-by: James Gatz <jamesgatzos@gmail.com>
Co-authored-by: Copilot <copilot@github.com>

* fix: Delete old folders (#9867)

* refactor: remove unused migration version handling from localStorage

* fix: update directory removal logic to handle non-empty directories

---------

Co-authored-by: Curry Yang <163384738+CurryYangxx@users.noreply.github.com>
Co-authored-by: yaoweiprc <6896642+yaoweiprc@users.noreply.github.com>
Co-authored-by: Pavlos Koutoglou <pkoutoglou@gmail.com>
Co-authored-by: Copilot <copilot@github.com>

* refactor: move sync code to main (#9827)

* move sync code to main

* improve sync tests

* update plan

* test: reset cloud sync smoke state

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* guard against bad test env

* fix skill

* remove new test

* udpate plan

* with proxy

* checkpoint

* move files

* autofix

* update plan

* make all sync bridge async

* fix window imports

* refactor: move main-only sync helpers

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix lint

* move chunkArray tests

* smaller interfaces

* move store under vcs

* move cloud-sync to main

* create a second vcs for pull operations

* added a invoke wrapper to remove error prefixes

* rebase error

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chore: update insomnia-plugin-ai (#9862)

* fix: bump node-libcurl and add ipv6 tests (#9869)

* feat: revamping pre/post scripting sandbox (#9794)

* feat: revamping pre/post scripting sandbox
* feat: added UI setting to enable/disable specific checks

* fix false positives

* revert

* fix: user can not resolve conflict in app (#9872)

* fix: conflict ux

* fix

* fix

* Git server for smoke test [INS-2258] (#9816)

* Git server for smoke test

* Try to solve flaky test

* feat: remove unused Git hook samples and add Credentials tab functionality

- Deleted various sample Git hook scripts from the git-server fixture, including post-update, pre-applypatch, pre-commit, pre-merge-commit, pre-push, pre-rebase, pre-receive, prepare-commit-msg, push-to-checkout, sendemail-validate, and update hooks.
- Introduced a new PreferencesCredentialsTab class to manage Git credentials within the Insomnia Preferences.
- Updated the PreferencesPage to include the new Credentials tab for Git credentials management.
- Enhanced the ProjectPage with a method to create a Git Sync project, including branch creation and switching.
- Added comprehensive tests for Git Sync functionality, including creating branches, committing changes, and merging branches.
- Updated UI components to support new features, including data-testid attributes for better testability.

Co-authored-by: Copilot <copilot@github.com>

* feat: update path import and add Git sync tests

* revert package.json

* Update package.json

* feat: add new dependencies for Git HTTP mock server and related utilities

* refactor: remove commented-out code in addAccessTokenGitCredential function

* fix: update export tests to use toHaveLength for file count assertions

---------

Co-authored-by: Copilot <copilot@github.com>

* feat: import deep-link login experience [INS-2416] (#9860)

* refactor: replace node:url with URL in cert and proxy match (#9515)

* refactor: import to main (#9809)

* squash

* re add comments

* fix process fork

* update base line 18 left

* revert

* check cert url without node

* fix handlerId

* exclude url matches cert host from scope

* fix rebase

* Fix style issue that file list in the middle of commit modal is collapsed [INS-2315] (#9875)

* Fix style issue that file list in the middle of commit modal is collapsed

* fix: update links to Git Sync documentation in staging modal and project settings form

* Chore: playwright dx v2 (#9876)

* Update E2E test for git sync [INS-2258] (#9878)

* Add more test cases for git sync

* tmp

* Update package.json

* feat: update migration image and urls (#9868)

* feat: update migration image and path for improved clarity

* feat: update error message and support links in migration view

* feat(Git Sync): Downgrade -> Upgrade path (#9882)

* feat: add mechanism to flush newer DB workspaces to disk during downgrade

* feat: implement effective Git repository ID handling for project connections

* feat: enhance Git repository ID handling for improved project queries and updates

* Chore: refine e2e docs by agent for agent (#9881)

* improve agent docs

* added error context note

* chore: Security update for dependencies and github workflows (#9884)

* chore: resolves INS-2457, INS-2458, INS-2459, and INS-2460.

* feat: include app version in window title [INS-2465] (#9888)

* feat(Git Sync): improve git migration onboarding UX and local file system access [INS-2462] (#9890)

* feat(Migration): enhance migration summary with total projects count and improve UI feedback

* fix(Migration): clarify update instructions and improve user messaging

* style(ManualCommitForm): adjust text sizes for improved readability

* style(StagingModal): adjust layout and spacing for improved UI consistency

* fix(ManualCommitForm): update clipboard text to include 'cd' command for easier navigation

* fix(ProjectSettingsForm): update repository path copy functionality and add option to open in file system

* fix(ManualCommitForm): enhance file system interaction with tooltips for better user guidance

* fix(ProjectSettingsForm): add tooltip for 'Open in file system' button to enhance user guidance

* fix(GitProjectSyncDropdown): add 'Open folder' action to sync dropdown for easier access to repository path

* fix(Component): display relative path of current issue in modal for better context

* fix(git-service): count only successfully migrated projects in totalProjects

* fix(project-settings-form): platform-aware shell quoting for cd command

* fix(git-project-staging-modal): platform-aware shell quoting for cd command

* fix(project-settings-form): update aria-label to reflect cd command clipboard content

* fix(git-project-staging-modal): update aria-label to reflect shell command clipboard content

* fix(ManualCommitForm): replace tooltip with dialog for enhanced information display

* fix(MigrationView): update migrated count calculation to reflect total projects

---------

Co-authored-by: James Gatz <jamesgatzos@gmail.com>

* chore: normalize konnect api responses (#9895)

* feat(Git Sync): enhance migration view with best practices note and UI improvements (#9900)

* chore: comment out smctl credentials save in workflow (#9898)

the command is no longer executed while keeping it in place for future reference.

* feat: migrate model imports, base types, org model and helpers (#9802)

* fix

* fix vcsinstance

* fix type issues

---------

Co-authored-by: Jack Kavanagh <jackkav@gmail.com>
Co-authored-by: James Gatz <jamesgatzos@gmail.com>
Co-authored-by: Shelby <13246465+shelby-moore@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: yaoweiprc <6896642+yaoweiprc@users.noreply.github.com>
Co-authored-by: kwburns-kong <kyle.burns@konghq.com>
Co-authored-by: jeremyjpj0916 <31913027+jeremyjpj0916@users.noreply.github.com>
Co-authored-by: Ryan Willis <ryan.willis@konghq.com>
Co-authored-by: Kent Wang <kent.wang@konghq.com>
Co-authored-by: Alison Sabuwala <alison.sabuwala1024@gmail.com>
Co-authored-by: aikido-pr-checks[bot] <169896070+aikido-pr-checks[bot]@users.noreply.github.com>
Co-authored-by: Jay Wu <jay.wu@konghq.com>
Co-authored-by: Pavlos Koutoglou <pkoutoglou@gmail.com>
Co-authored-by: Copilot <copilot@github.com>
Co-authored-by: Fares Osman <43153226+fiosman@users.noreply.github.com>
Co-authored-by: Bingbing <ZxBing0066@gmail.com>
Co-authored-by: Vivek Thuravupala <2700229+godfrzero@users.noreply.github.com>

* fix: fix dnd for empty nodes (#9909)

* fix: fix dnd for empty nodes

* remove console log

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* initial fix for critical paths (#9913)

* 1.enhance the test component

* add test attributes

* fix basic test case

* fix smoke test p1

* fix smoke test p2

* fix e2e test failure p3

* fix smoke test p4

* fix remaining e2e failures

* feat: secondary sidebar&git cli error modal adaptation (#9916)

* feat: secondary sidebar&git cli error modal
* fix

* Fix: Document design page do not show collection list (#9930)

* fix no collection list showed in design page document tab

* use common constant for the wrapper id

* fix: move parent position control into modal component

---------

Co-authored-by: Curry Yang <1019yanglu@gmail.com>

* Test: Fix all smoke test failures due to new navigation sidebar (#9921)

* enhance the test component
* add test attributes
* fix smoke test

* Fix failed git-sync E2E tests.

* fix type issues

* fix all e2e failure

* update screenshot

* fix issues from pr comment

* fix toggle issues

* fix grpc and smoke test issue

* fix slot issue

---------

Co-authored-by: xdm <35987327+xiaodemen@users.noreply.github.com>
Co-authored-by: Bingbing <ZxBing0066@gmail.com>
Co-authored-by: Curry Yang <163384738+CurryYangxx@users.noreply.github.com>
Co-authored-by: yaoweiprc <6896642+yaoweiprc@users.noreply.github.com>
Co-authored-by: Jack Kavanagh <jackkav@gmail.com>
Co-authored-by: James Gatz <jamesgatzos@gmail.com>
Co-authored-by: Shelby <13246465+shelby-moore@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: kwburns-kong <kyle.burns@konghq.com>
Co-authored-by: Ryan Willis <ryan.willis@konghq.com>
Co-authored-by: Jay Wu <jay.wu@konghq.com>
Co-authored-by: Pavlos Koutoglou <pkoutoglou@gmail.com>
Co-authored-by: Fares Osman <43153226+fiosman@users.noreply.github.com>
Co-authored-by: Vivek Thuravupala <2700229+godfrzero@users.noreply.github.com>
Co-authored-by: Curry Yang <1019yanglu@gmail.com>
2026-05-21 10:42:07 +00:00
Jack Kavanagh
9d1dcce441 feat: move plugin loading to dedicated hidden BrowserWindow (Phase 1) (#9889)
* chore: reduce output verbosity for local dev and AI agent workflows

- Set npm loglevel=warn to suppress install/run progress noise
- Switch Playwright local reporter from list to dot (less output per test, CI unchanged)
- Add scripts/setup.sh for one-time local git config (compact log, short status)
- Document setup script in AGENTS.md

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* chore: remove loglevel=warn and alias suggestions

- Revert loglevel=warn from .npmrc — too broad, suppresses CI output
- Remove shell alias suggestions from setup.sh — out of scope for a repo script

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* chore: replace setup.sh with command output guidance in AGENTS.md

Removes setup.sh in favour of explicit quiet-command guidance that
benefits all agents (Claude, Copilot, Codex) without requiring a
one-time setup step.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* chore: add cx semantic code navigation guidance to AGENTS.md

cx gives agents a cost ladder (overview → symbols → definition → read)
that reduces file reads for all agents that read AGENTS.md — complementary
to CodeGraph which is Claude Code-specific.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* plan pass 2

* answer questions

* add tests

* theme tests

* more tests

* feat: move plugin loading/execution to hidden BrowserWindow (Phase 1)

All plugin API calls (getThemes, getPlugins, getActivePlugins, reloadPlugins,
getRequestActions, getRequestGroupActions, getWorkspaceActions, getDocumentActions)
are now routed through a dedicated hidden BrowserWindow with nodeIntegration:true
instead of running directly in the renderer.

IPC relay: renderer → ipcMain.handle → plugin window webContents → ipcRenderer.send
back to main → resolve renderer promise via pending-request map with 30s timeout.

Renderer-side callers updated to use window.main.plugins.* bridge.
Two new esbuild entry points added (plugin-window, plugin-window-preload).
Dev build threshold updated from 3 to 6 to account for all contexts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feedback

* feat: route plugin action execution through hidden BrowserWindow bridge

Add executeAction IPC method so all four plugin action dropdowns (request,
requestGroup, workspace, document) dispatch through the plugin window
instead of running context modules directly in the renderer.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat: route template tag listing and action execution through plugin bridge

Bridge getTemplateTags() and runTemplateTagAction() so code-editor,
one-line-editor, and tag-editor no longer import from plugins/index
or plugins/context/store in the renderer.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat: complete Phase 1 — all plugin execution routed through hidden BrowserWindow

Bridge template tags (getTemplateTags, runTemplateTagAction), bundle plugin
listing (getBundlePlugins), and elevated plugin actions (executePluginMainAction)
so no renderer code calls plugin index or context modules directly for execution.

Remaining renderer plugin imports are intentional: applyColorScheme/getColorScheme
(DOM utilities) and createPlugin (filesystem scaffolding), neither of which is
plugin execution.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* update plan

* fix: initialize plugin window services and add Phase 1a E2E test

- Create database.plugin-window.ts IPC proxy so the plugin window
  reads from the main process NeDB connection instead of opening a
  second one
- Initialize database + services in entry.plugin-window.ts before
  sending plugin-window-ready, fixing the silent "Service not
  initialized" crash that was masked by unawaited promises
- Add isMainWindow fallback to the page fixture so firstWindow()
  racing to return the hidden plugin window doesn't break other tests
- Add plugin-bridge.test.ts: E2E test that writes a requestAction
  plugin, reloads via the bridge, and verifies the action appears in
  the request dropdown

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix lint

* fix: only send plugin-window-ready after successful initialization

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix assertion

* add found

* better

* fix: stabilize hidden window smoke flows

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* feat: bridge request and response hooks through the plugin window

Moves requestHooks and responseHooks execution into the hidden plugin
window via the IPC bridge. The default-headers built-in runs in the
renderer (no IPC). A cached hasRequestHooks/hasResponseHooks check in
the main process avoids any plugin window round-trip per request when no
user plugins have hooks registered.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: handle non-renderer processes in plugin hook functions

_applyRequestPluginHooks and _applyResponsePluginHooks now use
window.main.plugins.* IPC only in the Electron renderer. In the main
process (OAuth2 token exchange via get-token.ts) and Node.js CLI
(insomnia-inso), they fall back to loading plugins directly via
plugins.getRequestHooks/getResponseHooks. This fixes:

- inso CLI: "window is not defined" in all run collection/test commands
- Electron: OAuth2 token exchange failing with "no access token provided"

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix unit test

* fix: increase findMainWindow timeout and skip plugin window by title

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: defer plugin window creation until after main window loads

Playwright's firstWindow() was racing with the plugin window and
sometimes returning it instead of the main app window. By deferring
createPluginWindow() to did-finish-load on the main window, the plugin
window is guaranteed to not exist yet when firstWindow() resolves.

Removes the findMainWindow polling fallback from the test fixture.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* refactor: replace any[] cast in nunjucks context menu with narrow ContextMenuTag type

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: safely stringify non-Error rejections in response hook error handler

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* feat: bridge plugin UI calls (alert/dialog/prompt/clipboard) from plugin window to main renderer

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix test

* docs

* add tests and observability

* docs

* feat: implement invokePluginMethod for plugin communication and add tests

* document switch

* fix test

* fix: move plugin killswitch from preload to renderer to prevent packaged app crash

The preload was statically importing invokePluginMethod which pulled the
entire plugin system (network stack, NeDB, plugin contexts) into the
preload bundle. In production the bundle is built fresh from source,
causing a module-level crash before window.main is set — breaking the
critical backup smoke test with "Cannot read properties of undefined
(reading 'secretStorage')".

Move the INSOMNIA_ENABLE_PLUGIN_BRIDGE killswitch into a new
renderer-bridge.ts module that lives in the Vite renderer bundle where
those deps already exist. The preload now always uses IPC for all plugin
calls. All window.main.plugins.* call sites updated to use the bridge.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* chore: eslint autofix import ordering

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-20 18:01:39 +08:00
Ryan Willis
6eebf09a2a fix: ensure plugin directory exists before showing it (#9923) 2026-05-15 13:21:50 -07:00
Ryan Willis
e507572f9c chore: pdf preview frame regression tests (#9922) 2026-05-15 08:36:36 -07:00
Jack Kavanagh
d9851d406f Chore: refine e2e docs by agent for agent (#9881)
* improve agent docs

* added error context note
2026-05-01 13:31:16 +00:00
yaoweiprc
7809d458aa Update E2E test for git sync [INS-2258] (#9878)
* Add more test cases for git sync

* tmp

* Update package.json
2026-04-30 15:16:18 +02:00
Jack Kavanagh
92a79e799b Chore: playwright dx v2 (#9876) 2026-04-30 06:42:46 +02:00
yaoweiprc
933f56854e Git server for smoke test [INS-2258] (#9816)
* Git server for smoke test

* Try to solve flaky test

* feat: remove unused Git hook samples and add Credentials tab functionality

- Deleted various sample Git hook scripts from the git-server fixture, including post-update, pre-applypatch, pre-commit, pre-merge-commit, pre-push, pre-rebase, pre-receive, prepare-commit-msg, push-to-checkout, sendemail-validate, and update hooks.
- Introduced a new PreferencesCredentialsTab class to manage Git credentials within the Insomnia Preferences.
- Updated the PreferencesPage to include the new Credentials tab for Git credentials management.
- Enhanced the ProjectPage with a method to create a Git Sync project, including branch creation and switching.
- Added comprehensive tests for Git Sync functionality, including creating branches, committing changes, and merging branches.
- Updated UI components to support new features, including data-testid attributes for better testability.

Co-authored-by: Copilot <copilot@github.com>

* feat: update path import and add Git sync tests

* revert package.json

* Update package.json

* feat: add new dependencies for Git HTTP mock server and related utilities

* refactor: remove commented-out code in addAccessTokenGitCredential function

* fix: update export tests to use toHaveLength for file count assertions

---------

Co-authored-by: Copilot <copilot@github.com>
2026-04-28 09:44:54 +00:00
jackkav
aa15830a0f revert 2026-04-27 20:00:33 +02:00
jackkav
a31d45d370 fix false positives 2026-04-27 19:51:40 +02:00
kwburns-kong
f220db351f feat: revamping pre/post scripting sandbox (#9794)
* feat: revamping pre/post scripting sandbox
* feat: added UI setting to enable/disable specific checks
2026-04-27 13:43:18 +00:00
Ryan Willis
ae49df6a57 fix: bump node-libcurl and add ipv6 tests (#9869) 2026-04-24 19:04:02 -07:00
Jack Kavanagh
879d579f0f refactor: move sync code to main (#9827)
* move sync code to main

* improve sync tests

* update plan

* test: reset cloud sync smoke state

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* guard against bad test env

* fix skill

* remove new test

* udpate plan

* with proxy

* checkpoint

* move files

* autofix

* update plan

* make all sync bridge async

* fix window imports

* refactor: move main-only sync helpers

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix lint

* move chunkArray tests

* smaller interfaces

* move store under vcs

* move cloud-sync to main

* create a second vcs for pull operations

* added a invoke wrapper to remove error prefixes

* rebase error

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-24 14:15:23 +00:00
Jack Kavanagh
a3a3ef490e refactor: auth header to main (#9834)
* remove deprecated baseUrl

* add failing test

* fix AI playwright runs

* move getAuthHeader to main

* address feedback about dynamic import

* move oauth 1 + 2 flow to main

* handle bad cookie

* handle bad apikey

* fix imports

* block main process imports

* extract plugins

* fix vite config

* console log

* move init store

* Fix OAuth imports after rebase

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* clean up

* Revert config changes

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* clean up hawk

* use bridge

* update node require

* remove this

* define process type

* remove 14

* ignore reports folder

* fix e2e tests

* address feedback

* remove unused

* tidy constants

* feat: add getOAuth2Token IPC bridge

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix tests

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-24 15:36:59 +08:00
Ryan Willis
d109903243 chore: resolve GHA warning annotations and reduce CI time [INS-2312] (#9839) 2026-04-22 10:44:47 -07:00
Alison Sabuwala
d19e58a9f6 feat: integrate v3 user endpoints (#9785)
* feat: integrate v3 user endpoints

* feat: use public sdk for insomnia-api
2026-04-22 10:25:37 -04:00
Shelby
e12d66224d feat: konnect sync integration (#9795) 2026-04-14 15:39:14 +00:00
Insomnia
b18f9528fc Bump app version to 12.5.1-alpha.0 2026-04-11 00:15:09 +00:00
Ryan Willis
52d64a0116 chore(deps): bump dependencies (#9756) 2026-04-03 19:08:00 -04:00
Kent Wang
66f45471ee fix: Execute bundle plugin actions with correct execution environment (#9759)
* init changes for execute plugin action issue

* update comments based on new change
2026-04-03 03:01:58 +00:00