Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
4726 commits
Select commit Hold shift + click to select a range
698e380
fix(app): keep workspace switches coherent under load (#3977)
benjaminshafii Aug 20, 2026
6e4e261
refactor(evals): split docs-shot primitives and app-driver boundaries…
benjaminshafii Aug 20, 2026
48342d6
docs: add v0.18.31-v0.18.35 release notes (#3985)
benjaminshafii Aug 20, 2026
eecf13e
fix(app): explain unconfigured workspace errors (#3986)
benjaminshafii Aug 20, 2026
2b6117c
test(evals): cover Library inventory refresh (#3987)
benjaminshafii Aug 20, 2026
db5aeab
fix(server): preserve live agent runs across workspace switches (#3988)
benjaminshafii Aug 20, 2026
1d7da76
fix(app): keep Library Add visible during session restore (#3990)
benjaminshafii Aug 20, 2026
23ebf06
docs: distinguish local setup from managed Cloud (#3991)
benjaminshafii Aug 21, 2026
62db5a2
fix(chat): keep live thinking still when the user scrolls it (#3997)
reachjalil Aug 21, 2026
3109049
fix(server): refresh Connect MCP App catalog on cache miss (#3998)
reachjalil Aug 21, 2026
404c9de
fix(mcp): stop standalone GET retry loop (#4003)
reachjalil Aug 21, 2026
e27b872
fix(desktop): keep updater channel selection stable (#4000)
reachjalil Aug 21, 2026
e6c21ce
fix(automations): bound Den control-plane load (#4002)
reachjalil Aug 21, 2026
1d61672
Render hosted MCP Apps through the credential-bound Den gateway (#4004)
reachjalil Aug 21, 2026
9af67f8
fix(chat): ignore stale tool activity (#4010)
benjaminshafii Aug 22, 2026
ec988da
fix(app): identify latest aggregated tool (#4011)
benjaminshafii Aug 23, 2026
20b60f5
docs: clarify OpenCode and OpenWork models (#4013)
OmarMcAdam Aug 23, 2026
917ad9c
fix(den): consolidate Den URL derivation (#3925)
OmarMcAdam Aug 23, 2026
747f18a
fix(den-web): call Den API origin directly (#4017)
OmarMcAdam Aug 23, 2026
2592197
fix(den-web): omit cookies on direct API calls (#4018)
OmarMcAdam Aug 23, 2026
a047995
fix(den-web): keep auth callbacks on web host (#4019)
OmarMcAdam Aug 23, 2026
25a80bb
fix(den-web): omit cookies for public SSO resolve (#4020)
OmarMcAdam Aug 23, 2026
b438ff2
feat(evals): declarative worlds on a layered environment kernel (#4016)
benjaminshafii Aug 23, 2026
1ee5f1c
fix(den-web): filter auth proxy cookies (#4021)
OmarMcAdam Aug 23, 2026
85b07c4
fix(den-web): rewrite auth cookie domains (#4022)
OmarMcAdam Aug 23, 2026
eda9c2d
fix(den-web): preserve combined auth cookies (#4024)
OmarMcAdam Aug 24, 2026
0f0c7d4
fix(den-api): derive public API URL from auth origin (#4025)
OmarMcAdam Aug 24, 2026
48f5905
fix: restore local Den web lane (health probe + API origin derivation…
benjaminshafii Aug 24, 2026
ea2b7d5
docs(evals): add glossary, world CLI, recipes, and skills map to READ…
benjaminshafii Aug 24, 2026
c5fa7b2
feat(evals): add attach origin axis to worlds (#4029)
benjaminshafii Aug 24, 2026
41767f4
chore: remove legacy two-electron demo scripts in favor of worlds (#4…
benjaminshafii Aug 24, 2026
30dde6e
feat(evals): prove and complete the kind world substrate (#4023)
benjaminshafii Aug 24, 2026
5e64850
Delete prds directory (#4030)
benjaminshafii Aug 24, 2026
9ba56f2
fix(den-api): clear stale login session cookie (#4034)
OmarMcAdam Aug 24, 2026
9b350e2
fix(app): remint missing cloud MCP bearer (#4036)
OmarMcAdam Aug 24, 2026
f059c7d
fix(app): probe cloud mcp during maintenance (#4038)
OmarMcAdam Aug 24, 2026
2c5fe3f
fix(den-api): preserve legacy MCP callback URLs (#4039)
OmarMcAdam Aug 24, 2026
4892929
feat(evals): add live lane with prod Den signup+invite spec (#4032)
benjaminshafii Aug 24, 2026
739dc4e
docs: update hosted API origin (#4026)
OmarMcAdam Aug 24, 2026
d80e25d
fix(den-web): keep PostHog cookie off API host (#4041)
reachjalil Aug 24, 2026
3a44e2d
fix(den-api): allow explicit auth cookie domain (#4044)
OmarMcAdam Aug 24, 2026
f07861a
fix(den-web): preserve shared auth cookie domain (#4046)
OmarMcAdam Aug 24, 2026
5c74c25
fix(den-web): clear stale auth cookies on session miss (#4048)
OmarMcAdam Aug 24, 2026
13fa491
fix(app): load session lists for all workspaces on launch (#4049)
benjaminshafii Aug 24, 2026
fa5e5db
MCP Apps dashboard: per-user grid with add-from-Connect picker (#4045)
reachjalil Aug 24, 2026
c7e3781
fix(desktop): keep bootstrap and retained Den sessions origin-coheren…
reachjalil Aug 24, 2026
03d6602
fix(app): validate each conversation's own model for availability (#4…
reachjalil Aug 24, 2026
8fc2d61
fix(desktop): reconcile Connect policy across runtime generations (#4…
reachjalil Aug 24, 2026
00f4eed
feat(den): enable Code Mode and MCP Apps by default, retiring their r…
reachjalil Aug 25, 2026
226d014
fix(sandboxes): pin bun to 1.3.14 in sandbox and docker images (#4058)
benjaminshafii Aug 25, 2026
da3b3a9
fix(app): only derive the api. host for hosted openworklabs.com Dens …
benjaminshafii Aug 25, 2026
3adde20
test(evals): cross-workspace session switch composer readiness and dr…
benjaminshafii Aug 25, 2026
313d01d
Licensing v0.5: OpenWork EE License for ee/ + public pricing (Free ≤5…
benjaminshafii Aug 25, 2026
54b349a
perf(daytona): bake deps and Den builds into the server snapshot for …
benjaminshafii Aug 25, 2026
0607e4f
fix(den-web): temporarily disable posthog (#4062)
OmarMcAdam Aug 25, 2026
9653cd2
fix(den): route auth callbacks through API origin (#4063)
OmarMcAdam Aug 25, 2026
dbedda3
fix(den-api): build telemetry package (#4065)
benjaminshafii Aug 25, 2026
1b7965f
fix(den-web): add temporary auth recovery notice (#4068)
benjaminshafii Aug 25, 2026
5f872cf
fix(den-web): show auth notice in MCP flow (#4071)
benjaminshafii Aug 25, 2026
73b3d03
fix(den-api): rename better auth session cookie (#4072)
OmarMcAdam Aug 25, 2026
b2c88d3
fix(den-web): scope Vercel workspace install (#4073)
benjaminshafii Aug 25, 2026
8f2bfa1
fix(den-web): forward renamed auth cookies (#4074)
OmarMcAdam Aug 25, 2026
a39b71f
fix(den-api): enforce production build contract (#4069)
benjaminshafii Aug 25, 2026
c41e2c5
feat(evals): launch dev desktop with live production state (#4075)
benjaminshafii Aug 25, 2026
64d2d37
feat(connect): support stateless MCP 2026 (#4055)
reachjalil Aug 25, 2026
148c7a3
fix(evals): avoid parallel build races (#4078)
benjaminshafii Aug 25, 2026
3c0b038
Org-managed Dashboards: define, assign, and render granted MCP App da…
reachjalil Aug 25, 2026
4921a02
Render managed dashboards in Desktop (#4082)
reachjalil Aug 25, 2026
423f6bf
fix(den): link docs to public site (#4083)
benjaminshafii Aug 25, 2026
7554ec4
perf(server): slim per-request Connect prompt blocks and keep them ca…
benjaminshafii Aug 25, 2026
fb2911d
fix: reconcile unfinished tool lifecycle (#4085)
reachjalil Aug 25, 2026
b8fd07c
fix(updates): keep installed alpha builds eligible (#4087)
reachjalil Aug 25, 2026
874b450
feat(app): add artifact code browser (#4084)
benjaminshafii Aug 25, 2026
ed57d9c
fix(server): isolate artifact catalog test (#4090)
benjaminshafii Aug 25, 2026
e35331e
Make MCP dashboards load instantly and refresh automatically (#4089)
reachjalil Aug 25, 2026
a7242b7
feat(world): share headless lifecycle engine (#4091)
benjaminshafii Aug 25, 2026
2478f94
feat(app): streamline chat and model controls (#4088)
benjaminshafii Aug 25, 2026
ef8455c
Show only MCPs with Apps in dashboard picker (#4093)
reachjalil Aug 25, 2026
73530ae
Render dashboard apps without waiting on every MCP (#4094)
reachjalil Aug 25, 2026
c3ce535
fix(app): keep Settings workspace runtime coherent (#4097)
reachjalil Aug 26, 2026
6a99542
fix(app): stabilize desktop render cycles (#4098)
reachjalil Aug 26, 2026
4bc6c29
fix(den): remove brand appearance preview card (#4100)
reachjalil Aug 26, 2026
2402e4e
feat(app): improve keyboard, Library, and artifact workflows (#4099)
benjaminshafii Aug 26, 2026
d4a15d8
fix(app): isolate streaming chat render work (#4104)
reachjalil Aug 26, 2026
3d7a772
feat(app): keep workspace sidebar order stable (#4105)
reachjalil Aug 26, 2026
76f6a7a
Gate Dashboard availability by deployment (#4106)
reachjalil Aug 26, 2026
e4f9f2e
feat(app): brand connector tool calls (#4107)
reachjalil Aug 26, 2026
fa9724b
fix(app): preserve composer focus through refresh (#4108)
reachjalil Aug 26, 2026
657b0b1
feat(app): gate Dashboard by Den availability (#4110)
reachjalil Aug 26, 2026
bd04a0f
feat(app): shimmer running delegated tasks (#4109)
reachjalil Aug 26, 2026
4474078
Fix Azure managed provider credential selection (#4114)
OmarMcAdam Aug 26, 2026
b0cbe84
Explain Azure Foundry resource names in BYOK setup (#4116)
OmarMcAdam Aug 26, 2026
e5cb283
test(evals): prove Azure BYOK end to end (#4115)
benjaminshafii Aug 26, 2026
2e742c8
feat(app): refine chat activity treatments (#4117)
benjaminshafii Aug 26, 2026
747ed7e
feat(app): polish tool call rows and artifact panel (#4118)
benjaminshafii Aug 26, 2026
57aeb15
fix(chat): keep interleaved thoughts chronological between tool aggre…
reachjalil Aug 26, 2026
0aab895
fix(desktop,server): keep live runs across workspace switches; contin…
reachjalil Aug 26, 2026
8e4720a
feat(chat): fold alternating thoughts and commands into one aggregate…
reachjalil Aug 26, 2026
fe8ff8b
fix(app): seed live session status on event stream connect (#4123)
reachjalil Aug 26, 2026
75b52d7
fix(app): keep live run status across navigation (#4122)
reachjalil Aug 26, 2026
45e50d5
feat(app): resume interrupted runs from the transcript error card (#4…
reachjalil Aug 26, 2026
4073972
feat(app): support cross-workspace split view (#4126)
benjaminshafii Aug 26, 2026
1c0a3ca
fix(server): keep managed-provider runtime generation coherent (#4128)
reachjalil Aug 26, 2026
584daec
fix(server): make task command admission acknowledgment-safe (#4129)
reachjalil Aug 26, 2026
f9f0aab
fix(app): classify interactive command lifecycle accurately (#4131)
reachjalil Aug 26, 2026
fe1f35a
fix(app): keep reattached session observers live (#4127)
reachjalil Aug 26, 2026
b5e2b8c
feat(den-api): remote-session capabilities on the MCP gateway (cloud …
benjaminshafii Aug 26, 2026
637ce73
test(evals): align unfinished tool lifecycle spec with the unknown st…
reachjalil Aug 26, 2026
b0f4e52
fix(server): keep opencode proxy requests off the workspace bootstrap…
reachjalil Aug 26, 2026
af788dc
perf(app): keep streaming responsive under long active tasks (#4130)
reachjalil Aug 26, 2026
a19fa86
Polish chat tool-call activity presentation (#4134)
benjaminshafii Aug 26, 2026
791ff2b
fix(cloud): make worker provisioning recovery single-owner (#4142)
benjaminshafii Aug 26, 2026
cdc18ac
Unify the Add to Library choices and add recognizable connector logos…
reachjalil Aug 26, 2026
ddf8515
Licensing v0.5.1: Enterprise Features scoping, stewardship page, DCO,…
benjaminshafii Aug 26, 2026
277a7f5
fix(app): make Cloud extension status reflect real connectivity (#4145)
reachjalil Aug 27, 2026
ad0342c
fix(app): keep Web composer drafts private and conflict-safe (#4146)
reachjalil Aug 27, 2026
d5a715a
perf(server): make per-turn instruction assembly single-pass (#4147)
reachjalil Aug 27, 2026
a386382
fix(den-web): propagate cancellation and deadlines through the Den pr…
reachjalil Aug 27, 2026
03664d1
feat(packaging): add pull-only Docker evaluation stack (#4154)
benjaminshafii Aug 27, 2026
cc6a773
fix(den-web): keep internal API URL out of runtime config (#4156)
benjaminshafii Aug 27, 2026
5a7ea5a
fix(evals): reset dirty Daytona snapshots before checkout (#4159)
benjaminshafii Aug 27, 2026
ea3bb84
fix(app): bound workspace session hydration (#4161)
benjaminshafii Aug 27, 2026
20f2898
feat(world): add Daytona k3s network primitives (#4160)
benjaminshafii Aug 27, 2026
92f4f3f
refactor(cloud): remove the legacy worker proxy path (#4157)
benjaminshafii Aug 27, 2026
00486aa
fix(sso): allow super-admin provider setup (#4164)
benjaminshafii Aug 27, 2026
252bb7c
fix(cloud): harden stable worker compatibility routing (#4165)
benjaminshafii Aug 27, 2026
27e8762
fix(app): make the Web session shell narrow-screen safe (#4144)
reachjalil Aug 27, 2026
63cd087
feat(app): add word-wrap control to rendered code blocks (#4151)
reachjalil Aug 27, 2026
b3e76c6
fix(app): keep the artifact rail count badge inside the rail (#4152)
reachjalil Aug 27, 2026
4e9b6ea
fix(den-api): heartbeat provisioning claims so orphaned cloud workers…
reachjalil Aug 27, 2026
88cbb9f
feat(app): render Mermaid diagrams safely (#4171)
benjaminshafii Aug 27, 2026
7011e23
fix(app): make the queued-message drain admission-aware so it cannot …
reachjalil Aug 27, 2026
e263bae
fix(app): stop Settings visits from restarting a healthy local server…
reachjalil Aug 27, 2026
df6bd7b
test(evals): prove cloud model creation end to end on a real worker r…
benjaminshafii Aug 27, 2026
f664079
fix(app): restart a dead workspace event stream when the sync token g…
reachjalil Aug 27, 2026
761ee0e
fix(app): treat an accepted admission that goes idle with no assistan…
reachjalil Aug 27, 2026
350a6f0
Correct Electron remote binary upload and download transport (#4148)
reachjalil Aug 27, 2026
2d3b7de
feat(cloud): per-member credential bindings for managed LLM providers…
benjaminshafii Aug 27, 2026
d82cdba
feat(den): add paid OpenWork Web organization access (#4102)
reachjalil Aug 27, 2026
758c37a
feat(den-api): web-to-desktop remote-session dispatch over the runner…
benjaminshafii Aug 27, 2026
3c53d4d
Move session files out of chat transcript (#4177)
benjaminshafii Aug 27, 2026
63625a4
feat(examples): sync LiteLLM model metadata (#4181)
benjaminshafii Aug 27, 2026
d3e8535
feat(desktop): deliver remote-session commands into native local sess…
benjaminshafii Aug 27, 2026
37a8679
docs: point LiteLLM example link to dev (#4182)
benjaminshafii Aug 27, 2026
f8b76de
docs(changelog): add v0.18.36-v0.18.39 release notes (#4183)
benjaminshafii Aug 28, 2026
1b39f7b
feat(evals): add LiteLLM per-member world (#4184)
benjaminshafii Aug 28, 2026
757601b
fix(sso): validate SAML responses against the SP-advertised ACS origi…
benjaminshafii Aug 28, 2026
c7b3996
fix(app): stop the Library page from refetching opencode-config on ev…
benjaminshafii Aug 28, 2026
47a1e16
fix(den-api): authenticate organization API keys (#4201)
OmarMcAdam Aug 28, 2026
d220e7b
fix(server): reclaim idle per-directory engine instances (#4208)
reachjalil Aug 28, 2026
2af0c98
refactor(server): remove ~4k LOC of dead legacy surface from openwork…
benjaminshafii Aug 28, 2026
153cc76
fix(server): enforce workspace scope on opencode proxy (#4189)
benjaminshafii Aug 28, 2026
9544222
fix(app): stop composer draft render loop (#4209)
benjaminshafii Aug 28, 2026
a3bcd17
refactor(desktop): use opencode SDK in automation runner (#4190)
benjaminshafii Aug 28, 2026
dad264e
refactor(headless): use opencode SDK for threads (#4191)
benjaminshafii Aug 28, 2026
51176e9
refactor(app): list sessions through opencode SDK (#4192)
benjaminshafii Aug 28, 2026
b8810d9
refactor(app): use opencode SDK for session reads (#4193)
benjaminshafii Aug 28, 2026
8cfef5d
feat(gmail): collapsible reply quoting, reply attachments, and https …
reachjalil Aug 28, 2026
ab18836
feat(den): grant complimentary OpenWork Web access (#4185)
reachjalil Aug 28, 2026
baa6325
fix(den-api): normalize remote session bodies (#4205)
benjaminshafii Aug 28, 2026
05a65ff
refactor(plugin): use native opencode session routes (#4194)
benjaminshafii Aug 28, 2026
7a05596
refactor(server): remove duplicate session routes (#4195)
benjaminshafii Aug 28, 2026
2e8ccab
refactor(runtime): add an optional thin session client port (#4196)
benjaminshafii Aug 28, 2026
2855be4
chore(evals): add coverage scripts, flake-rate reporting, and scenari…
benjaminshafii Aug 28, 2026
6c979e4
fix(web): enforce Den organization access at hosted origin (#4214)
reachjalil Aug 28, 2026
66cf3e3
test: pre-merge regression witnesses + repair the local desktop E2E l…
benjaminshafii Aug 28, 2026
bbf3a84
fix managed provider auth reload ordering (#3745)
reachjalil Aug 28, 2026
7541aa2
perf(app): bound renderer module caches (#4212)
reachjalil Aug 28, 2026
246a27a
fix(server): never abort an actively streaming session at the engine …
reachjalil Aug 28, 2026
458182f
feat: support portable Agent Plugins (#3594)
reachjalil Aug 28, 2026
90d1f4b
fix(app): prevent workspace sidebar hydration errors (#4216)
benjaminshafii Aug 28, 2026
2134e42
fix(desktop): recover from socket and renderer crashes (#4207)
reachjalil Aug 28, 2026
f467107
perf(server): use one global drain activity stream (#4217)
reachjalil Aug 28, 2026
72def8a
fix(evals): resolve workspace packages from source (#4221)
reachjalil Aug 28, 2026
6081213
fix(app): dedupe session search results (#4222)
benjaminshafii Aug 28, 2026
3719e99
test(evals): prove organization API keys authenticate enterprise LLM-…
benjaminshafii Aug 28, 2026
8c929be
fix(app): keep macOS titlebar controls clear (#4226)
benjaminshafii Aug 28, 2026
cc3b6de
fix(cloud): expose sandbox startup failures (#4219)
reachjalil Aug 28, 2026
953b0b9
ci: publish nightly pr-lane flake report and alert on unreliable spec…
benjaminshafii Aug 28, 2026
473a203
fix(cloud): harden workspace recovery (#4227)
reachjalil Aug 28, 2026
fda0bab
fix(app): let the left sidebar expand wide enough for long titles (#4…
reachjalil Aug 29, 2026
c10eb81
feat(automations): pin Automations to an explicit workspace (#4218)
benjaminshafii Aug 29, 2026
ce5ef7d
fix(ci): install Bun for nightly flake report (#4238)
benjaminshafii Aug 29, 2026
ac761d6
fix(app): stop persisted composer draft reload loop (#4243)
benjaminshafii Aug 30, 2026
86ccda5
fix(app): keep Library skill details stable (#4242)
benjaminshafii Aug 30, 2026
e192c64
fix(app): stop desktop policy refresh request storms (#4244)
benjaminshafii Aug 30, 2026
214c32b
fix(app): stop den-session settings echo loop (#4246)
benjaminshafii Aug 31, 2026
c951e1c
fix(security): remediate CodeQL findings (#4220)
benjaminshafii Aug 31, 2026
2f9b7cd
fix(app): preserve session activity snapshots (#4237)
reachjalil Aug 31, 2026
db415e7
fix(server): isolate provider sync contexts (#4233)
reachjalil Aug 31, 2026
64be577
fix(app): drain queued composer messages while the session is not in …
benjaminshafii Aug 31, 2026
d939dd3
fix(app): show minutes in live Working counters past 60s (#4252)
reachjalil Aug 31, 2026
dc9e6e5
fix(server): bound engine event-stream establishment and frame memory…
reachjalil Aug 31, 2026
8942f04
fix(app): stop errored runs from ticking Working forever (#4253)
reachjalil Aug 31, 2026
015a70f
Serialize and bound desktop automation lifecycle requests (#4254)
reachjalil Aug 31, 2026
c98817f
feat(app): report web boot failures and Stripe webhook errors to Sent…
reachjalil Aug 31, 2026
570c06b
fix(app): archive sessions from non-selected workspaces correctly (#4…
benjaminshafii Aug 31, 2026
696e839
fix(den): harden Google Workspace retrieval (#4260)
reachjalil Aug 31, 2026
77ff438
fix(app): reconcile active session completion (#4262)
reachjalil Aug 31, 2026
d1eed3b
docs(readme): add contributor getting-started guide (#4250)
reachjalil Sep 1, 2026
e2981d4
docs(skills): refresh stale repo skill references (#4251)
reachjalil Sep 1, 2026
d388bd0
refactor(evals): replace declarative worlds with script worlds (#4261)
benjaminshafii Sep 1, 2026
2b7df46
fix(app): fade sidebar titles only at hidden edges (#4263)
reachjalil Sep 1, 2026
6488f33
test(evals): map the full E2E inventory to spec-impact contracts with…
benjaminshafii Sep 1, 2026
56bc651
ci: prune tagged release Daytona snapshots with a 20-newest retention…
reachjalil Sep 1, 2026
06b00b1
fix(app): coalesce workspace session loads (#4232)
reachjalil Sep 1, 2026
8ab7ded
ci: fast-path models snapshot updates (#4278)
benjaminshafii Sep 1, 2026
a888304
chore: update models snapshot (#4277)
github-actions[bot] Sep 1, 2026
ce21533
feat(world): stage-isolated receipts, plan, and idempotent up for scr…
benjaminshafii Sep 1, 2026
33b0862
ci(evals): add a bi-daily Daytona E2E singles lane for per-test topol…
benjaminshafii Sep 1, 2026
37fb919
ci(evals): run the Daytona E2E regression suite bi-daily and fix matc…
benjaminshafii Sep 1, 2026
e16e121
fix(app,server): stop Working timers from ticking unvalidated when th…
reachjalil Sep 1, 2026
dd6ac0d
feat(world): resource ledger and reaper so crashed worlds never leak …
benjaminshafii Sep 1, 2026
c23119c
fix(hosts): never prune a live sibling desktop's profile when spawnin…
benjaminshafii Sep 1, 2026
b8c01e5
fix(app): give workspace names the task-row title reveal (#4282)
reachjalil Sep 1, 2026
def4908
feat(landing): show SOC 2 Type I badge and status (#4285)
benjaminshafii Sep 1, 2026
f74c268
feat(world): live CLI view for world up — steps, resources, heartbeat…
benjaminshafii Sep 1, 2026
3f35620
test(evals): derive the Daytona regression inventory invariant instea…
yomgui Sep 2, 2026
89ff0a1
fix(app,server): connect Den providers from locally saved Desktop cre…
yomgui Sep 2, 2026
6223144
feat(world): structured outputs with secrets, groups, and world outpu…
benjaminshafii Sep 2, 2026
eb68753
fix(world): make receipt writes atomic and receipt polls tolerant of …
benjaminshafii Sep 2, 2026
bfc4b83
feat(app): surface child permission requests in parent tasks (#4270)
reachjalil Sep 2, 2026
25d191b
fix: wrap long unbroken text in queued follow-up drafts (#4272)
reachjalil Sep 2, 2026
42c942c
fix(server): keep the OpenWork system prompt in a single system messa…
reachjalil Sep 2, 2026
0757e29
feat(landing): add /dashboard page for OpenWork Dashboard (MCP Apps) …
benjaminshafii Sep 2, 2026
cc11d4c
feat(landing): widget-first copy and interactive dashboard preview on…
benjaminshafii Sep 2, 2026
87e6bee
docs: add Dashboards guide with MCP App widget tutorial (#4304)
benjaminshafii Sep 2, 2026
8cb25bd
perf(vercel): skip unaffected builds and serve /api/den redirects at …
reachjalil Sep 2, 2026
f08281e
fix(den-api): show manual-close guidance when the browser blocks clos…
yomgui Sep 2, 2026
b36ca0e
fix(chat): reveal full commands, search patterns, and errors in tool …
yomgui Sep 2, 2026
a9fb9a7
fix(chat): size the image lightbox to the window instead of the 448px…
yomgui Sep 2, 2026
cd303e8
fix(app): hide subagent sessions from the sidebar when their parent i…
yomgui Sep 2, 2026
6c72717
feat(session): name the workspace in the session header after the tit…
yomgui Sep 2, 2026
dcb0cfe
docs(changelog): add v0.18.40-v0.18.41 release notes (#4314)
yomgui Sep 2, 2026
7de4010
docs(changelog): dedupe the New Features filter tag (#4315)
yomgui Sep 2, 2026
ef446e3
chore(deps): bump mysql2 to 3.22.0 (#4319)
OmarMcAdam Sep 2, 2026
f3866e0
fix(app): emphasize account menu sign in (#4323)
OmarMcAdam Sep 2, 2026
a4936b1
fix(sso): validate config before enforcement (#4324)
OmarMcAdam Sep 2, 2026
dc6e8f3
docs: add Google SSO and SCIM guidance (#4326)
OmarMcAdam Sep 2, 2026
0dfe7d9
fix(app): keep binary file paths out of Read-expanded prompt parts (#…
reachjalil Sep 2, 2026
dde1034
fix(app): keep a way out of Settings in narrow windows (#4301)
reachjalil Sep 2, 2026
564db8c
feat(connect): expose an MCP connection directly as a standard MCP se…
reachjalil Sep 2, 2026
e0ce31d
docs(helm): surface Automations flags in every starter example (#4274)
reachjalil Sep 2, 2026
114ecbd
ci(changelog): generate real release notes on every stable release (#…
yomgui Sep 2, 2026
1785d36
fix(desktop): stop the blank initialize load from aborting browser.op…
reachjalil Sep 2, 2026
b0b5179
docs(helm): hard-disable Automations in the starter examples (#4335)
reachjalil Sep 2, 2026
b675a2e
feat(app): scrollable, copyable command boxes in chat; double-click a…
reachjalil Sep 2, 2026
8b786a4
fix(prompt): state each OpenWork rule once and give the agent the use…
reachjalil Sep 2, 2026
dad6a79
fix(connect): configure plugin MCP servers like connectors and retire…
reachjalil Sep 2, 2026
9267847
feat: first-class Excel workbooks for agents and the artifact preview…
reachjalil Sep 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
40 changes: 40 additions & 0 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
# Full Electron + Den dev environment for Daytona sandboxes.
#
# Clones the repo from GitHub, installs deps, and provides
# Xvfb + noVNC so you can see/steer the real Electron app
# from your browser.

FROM node:20-bookworm

# System deps for Electron / Chromium + virtual display + utils
RUN apt-get update && apt-get install -y --no-install-recommends \
git unzip dbus dbus-x11 \
libgtk-3-0 libnotify-dev libnss3 libxss1 libasound2 \
libxtst6 libatk-bridge2.0-0 libdrm2 libgbm1 libxrandr2 \
libxcomposite1 libxdamage1 libxfixes3 libcups2 \
libpango-1.0-0 libcairo2 \
xvfb x11vnc novnc websockify fluxbox xterm \
default-mysql-client \
&& rm -rf /var/lib/apt/lists/*

# pnpm + bun
RUN corepack enable && corepack prepare pnpm@latest --activate
# Pin bun to the CI-proven 1.3 line; unpinned installs picked up bun 1.4.0,
# which breaks the Den/desktop sandbox stack (sign-in grant exchange fails).
RUN npm install -g bun@1.3.14

# noVNC index
RUN ln -sf /usr/share/novnc/vnc.html /usr/share/novnc/index.html

ENV DISPLAY=:99
ENV ELECTRON_DISABLE_SANDBOX=1
ENV PNPM_HOME=/root/.local/share/pnpm
ENV PATH=$PNPM_HOME:$PATH

# Clone and install
ARG REPO_URL=https://github.com/different-ai/openwork.git
ARG BRANCH=dev
WORKDIR /workspace
RUN git clone --depth 1 --branch $BRANCH $REPO_URL . && pnpm install --frozen-lockfile || pnpm install

EXPOSE 3005 5173 6080 8788 9825
73 changes: 73 additions & 0 deletions .devcontainer/Dockerfile.daytona-server
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
# Daytona image for the OpenWork Den server stack.
#
# This intentionally does not run Docker inside Daytona. The sandbox runs the
# same services as packaging/docker/docker-compose.den-dev.yml directly:
# MySQL, Den API, and Den Web.
FROM daytonaio/sandbox:0.6.0

USER root

RUN apt-get update \
&& DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
ca-certificates \
curl \
default-mysql-client \
default-mysql-server \
git \
procps \
sudo \
&& /usr/local/share/nvm/current/bin/npm install -g pnpm@10.27.0 bun@1.3.14 \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/* /root/.cache /root/.npm /tmp/* \
&& printf 'daytona ALL=(ALL) NOPASSWD:ALL\n' >/etc/sudoers.d/daytona-openwork \
&& chmod 0440 /etc/sudoers.d/daytona-openwork \
&& install -d -o daytona -g daytona /workspace

WORKDIR /workspace

ENV PATH="/usr/local/share/nvm/current/bin:$PATH"

# Everything under /workspace is created as the daytona user so no later
# chown layer is needed: a recursive chown in its own layer copy-on-write
# duplicates the entire baked workspace and pushed the image past the 20 GB
# snapshot limit.
USER daytona

RUN git clone --depth 1 --branch dev https://github.com/different-ai/openwork.git . \
&& mkdir -p /workspace/.openwork-daytona \
&& sha256sum /workspace/pnpm-lock.yaml | cut -d ' ' -f 1 > /workspace/.openwork-daytona/pnpm-lock.sha256 \
&& git rev-parse HEAD > /workspace/.openwork-daytona/base-commit \
&& git gc --prune=now

# Bake dependencies and the sandbox-invariant Den builds so a boot from this
# snapshot only pays checkout + delta install + service start. The Den Web
# production build bakes no per-sandbox values: NEXT_PUBLIC_* inputs are fixed
# and every DEN_* value is runtime env consumed by `next start`.
# .devcontainer/start-daytona-server.sh skips these rebuilds when the git tree
# hashes recorded here still match the checked-out ref.
# Only the server packages' dependency graph is installed, and Electron and
# browser binaries are skipped: the server stack never runs them, and the
# smaller node_modules keeps the image inside the snapshot size limits. The
# full-lockfile sha marker stays valid because a filtered install uses the
# same lockfile; a ref that changes the lockfile reinstalls at boot.
RUN CI=1 ELECTRON_SKIP_BINARY_DOWNLOAD=1 PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1 \
PUPPETEER_SKIP_DOWNLOAD=1 CYPRESS_INSTALL_BINARY=0 \
pnpm install --store-dir /workspace/.openwork-daytona/pnpm-store --frozen-lockfile \
--filter @openwork-ee/den-api... \
--filter @openwork-ee/den-web... \
--filter @openwork-ee/den-db... \
--filter @openwork/ui... \
--filter @openwork-ee/utils... \
--filter @openwork/mcp-apps... \
&& NEXT_PUBLIC_POSTHOG_KEY= NEXT_PUBLIC_POSTHOG_API_KEY= \
pnpm --filter @openwork/ui build \
&& NEXT_PUBLIC_POSTHOG_KEY= NEXT_PUBLIC_POSTHOG_API_KEY= \
pnpm --filter @openwork-ee/utils build \
&& NEXT_PUBLIC_POSTHOG_KEY= NEXT_PUBLIC_POSTHOG_API_KEY= \
pnpm --filter @openwork-ee/den-web build \
&& pnpm --filter @openwork-ee/den-api run build:mcp-apps \
&& { git rev-parse HEAD:packages/ui HEAD:ee/packages/utils HEAD:ee/apps/den-web; cat /workspace/.openwork-daytona/pnpm-lock.sha256; } \
| sha256sum | cut -d ' ' -f 1 > /workspace/.openwork-daytona/den-web-build.tree \
&& { git rev-parse HEAD:packages/mcp-apps; cat /workspace/.openwork-daytona/pnpm-lock.sha256; } \
| sha256sum | cut -d ' ' -f 1 > /workspace/.openwork-daytona/den-api-assets.tree \
&& rm -rf /home/daytona/.cache /home/daytona/.npm /home/daytona/.local/share/pnpm/store
29 changes: 29 additions & 0 deletions .devcontainer/Dockerfile.daytona-vnc
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Daytona VNC/Computer Use image with OpenWork preinstalled.
#
# Use this for Electron/noVNC tests instead of the generic devcontainer image.
# The base image already contains the desktop stack Daytona expects:
# Xvfb, XFCE, x11vnc, noVNC, websockify, and dbus-x11.
FROM daytonaio/sandbox:0.6.0

USER root

RUN apt-get update \
&& apt-get install -y --no-install-recommends ffmpeg \
&& rm -rf /var/lib/apt/lists/*

RUN /usr/local/share/nvm/current/bin/npm install -g pnpm@10.27.0 bun

WORKDIR /workspace

RUN git clone --depth 1 --branch dev https://github.com/different-ai/openwork.git . \
&& mkdir -p /workspace/.openwork-daytona \
&& sha256sum /workspace/pnpm-lock.yaml | cut -d ' ' -f 1 > /workspace/.openwork-daytona/pnpm-lock.sha256 \
&& /usr/local/share/nvm/current/bin/npm cache clean --force \
&& git gc --prune=now \
&& rm -rf /root/.cache /root/.npm \
/home/daytona/.cache /home/daytona/.npm /home/daytona/.local/share/pnpm/store \
/workspace/node_modules /tmp/*

RUN chown -R daytona:daytona /workspace

USER daytona
159 changes: 159 additions & 0 deletions .devcontainer/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,159 @@
# Daytona / Dev Container Setup

Full-stack dev environment that runs the **real Electron app** + Den stack in a cloud sandbox. You see and steer the desktop app through your browser via noVNC.

## What's included

| Service | Port | Description |
|---------|------|-------------|
| **Desktop App (noVNC)** | 6080 | The real Electron app rendered in a virtual display, accessible in your browser |
| **Den Web** | 3005 | Admin dashboard for managing orgs, restrictions, providers |
| **Den API** | 8788 | Control plane API |
| **CDP Debug** | 9825 | Chrome DevTools Protocol — for app and browser automation |
| **Vite HMR** | 5173 | Hot module replacement for the React UI |
| **MySQL** | 3306 | Database (internal) |

## Quick start with Daytona Electron/noVNC

```bash
bash .devcontainer/create-daytona-openwork-snapshot.sh # one-time / refresh when deps change
bash .devcontainer/test-on-daytona.sh [branch-or-commit]
```

The test script creates a sandbox from the reusable `openwork-eval-vnc` snapshot
when present, checks out the target ref, skips `pnpm install` if the lockfile is
unchanged, starts XFCE/noVNC, Vite, and Electron, then prints the noVNC and CDP
URLs. If the snapshot is missing, it fails fast and tells you to create it. The
snapshot intentionally does not bake `node_modules`; installs use the reusable
`openwork-eval-pnpm-store` volume so the image stays under Daytona's 20 GB limit.

For provider evals, create/populate the reusable Daytona secrets volume once:

```bash
bash .devcontainer/setup-daytona-secrets-volume.sh .newtoken
bash .devcontainer/setup-daytona-secrets-volume.sh .anthropic anthropic.env
```

Future Daytona test sandboxes mount `openwork-eval-secrets:/daytona-secrets`
and source every `/daytona-secrets/*.env` file automatically before Electron
starts. Use this volume for provider keys and other eval-only secrets; never
commit those files into the repo.

For downloadable eval artifacts or optional video recording, use:

```bash
bash .devcontainer/test-on-daytona.sh [branch-or-commit] --artifacts-volume
bash .devcontainer/test-on-daytona.sh [branch-or-commit] --record-video
```

The artifacts flow mounts `openwork-eval-artifacts:/daytona-artifacts`, starts a
static download server on port 8090, and prints a Daytona preview URL. Recording
writes mp4 files to `/daytona-artifacts/recordings` and prints the direct video
URL. Screenshots write png files to `/daytona-artifacts/screenshots` for quick
AI/human validation checkpoints. Stop recording with
`.devcontainer/stop-daytona-recording.sh` so ffmpeg finalizes the file cleanly.

Do not use the generic `daytona create https://github.com/different-ai/openwork`
flow for Electron/noVNC tests. The default resource size is too small and the
generic image path does not guarantee the desktop stack we need.

## Quick start with Daytona server

```bash
bash .devcontainer/create-daytona-openwork-server-snapshot.sh # one-time / refresh when deps change
bash .devcontainer/test-server-on-daytona.sh [branch-or-commit]
```

The server helper creates a separate public Daytona sandbox for the Den stack:
MySQL, Den API, and Den Web. It prints public preview URLs and
the exact Electron command to point a desktop sandbox at that server:

```bash
bash .devcontainer/test-on-daytona.sh [branch-or-commit] \
--den-base-url https://3005-...daytonaproxy... \
--den-api-base-url https://8788-...daytonaproxy...
```

This keeps the architecture simple: the server sandbox owns cloud auth, orgs,
policies, workers, and persistence; the Electron sandbox stays a real desktop
client and talks to the server through public Daytona preview URLs.

## How it works

1. `.devcontainer/Dockerfile.daytona-vnc` starts from `daytonaio/sandbox:0.6.0`,
which includes Daytona's expected desktop packages: Xvfb, XFCE, x11vnc,
noVNC, websockify, and dbus-x11.
2. `.devcontainer/create-daytona-openwork-snapshot.sh` bakes that image into
`openwork-eval-vnc` without `node_modules`.
3. `/opt/openwork-daytona/start-daytona-vnc.sh` starts Xvfb, XFCE, x11vnc, and
noVNC on display `:99`.
4. `test-on-daytona.sh` installs dependencies through the reusable
`openwork-eval-pnpm-store` volume when `node_modules` is missing or the
lockfile changed.
5. Vite serves the React UI on port 5173.
6. `/opt/openwork-daytona/start-daytona-electron.sh` sources optional secrets,
applies Daytona-safe Chromium flags, and starts Electron on display `:99`.
7. **CDP on port 9825** enables Chrome MCP and browser-tool automation.
8. Optional artifact capture mounts `/daytona-artifacts`, serves it on port 8090,
records display `:99` with ffmpeg when `--record-video` is passed, and can
capture screenshot checkpoints with `.devcontainer/capture-daytona-screenshot.sh`.

## Validation Evidence

Use three layers of evidence for Daytona UI work:

- **CDP assertions:** use browser tools against port 9825 to inspect text, URL,
state, and accessibility snapshots. This is the primary AI validation path.
- **Screenshots:** run `daytona exec "$SANDBOX" -- 'bash .devcontainer/capture-daytona-screenshot.sh'` after important states. These png files live in `/daytona-artifacts/screenshots`.
- **Recordings:** start with `--record-video --recording-name <name>` for flows
that need PR evidence. These mp4 files live in `/daytona-artifacts/recordings`.

Recordings prove the flow to humans. CDP assertions and screenshots give the AI
fast checkpoints to decide whether behavior is correct before reporting success.

## AI Skills

The Daytona toolbox is exposed to opencode through focused skills:

- `daytona-dev`: overview of the Daytona setup and when to use each piece.
- `daytona-cloud-server`: Den Web/API, marketplace, cloud auth, and org policy flows.
- `daytona-secrets-volume`: add and verify provider keys or eval-only secrets in `/daytona-secrets`.
- `daytona-electron-test`: run and drive the real Electron app through CDP/noVNC.
- `daytona-recording-artifacts`: screenshots, recordings, before/after videos, and PR evidence.
- `run-tests`: runs `evals/specs` coverage locally or with the relevant Daytona environment.

## Testing the customization system

1. Open **Den Web** (port 3005) in a separate tab
2. Sign up → create org → Org Settings → UI Customization
3. Set overrides → Save
4. In the **Electron app** (noVNC on port 6080):
- Cloud → developer mode → base URL `http://localhost:3005`
- Sign in → Settings → see the desktop policy banner

## Architecture

```
Your Browser
├── :6080 noVNC ──▶ x11vnc ──▶ XFCE/Xvfb ──▶ Electron App
│ │
│ ├── CDP :9825 (automatable)
│ └── Vite HMR :5173
├── :3005 Den Web (Next.js)
└── :8788 Den API (Hono) ──▶ MySQL :3306
```

With a separate server sandbox, the Electron box uses Daytona preview URLs for
Den Web/API instead of `localhost`, while the server sandbox still keeps its
internal service graph local.

## Automation

The Electron app exposes CDP on port 9825. You can:

- Connect Playwright: `const browser = await chromium.connectOverCDP('ws://localhost:9825')`
- Connect Chrome MCP for AI agent testing
- Take screenshots, run UI tests, etc.
63 changes: 63 additions & 0 deletions .devcontainer/capture-daytona-screenshot.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
#!/usr/bin/env bash
set -euo pipefail

# Capture a single Daytona Electron display frame as a PNG artifact. Screenshots
# are for quick AI/human validation; videos are still the durable PR evidence.

OUTPUT="/daytona-artifacts/screenshots/daytona-screenshot-$(date +%Y%m%d-%H%M%S).png"
SIZE="1920x1080"

while [ "$#" -gt 0 ]; do
case "$1" in
--output)
shift
OUTPUT="${1:?missing output path}"
;;
--size)
shift
SIZE="${1:?missing screenshot size}"
;;
--help|-h)
printf '%s\n' \
"Usage: capture-daytona-screenshot.sh [--output PATH] [--size WxH]" \
"" \
"Captures DISPLAY, defaulting to :99, and writes a PNG file."
exit 0
;;
--*)
echo "Unknown option: $1" >&2
exit 1
;;
*)
echo "Unexpected argument: $1" >&2
exit 1
;;
esac
shift
done

if ! command -v ffmpeg >/dev/null 2>&1; then
echo "ERROR: ffmpeg is required for Daytona screenshots." >&2
exit 1
fi

if [[ ! "$SIZE" =~ ^[0-9]+x[0-9]+$ ]]; then
echo "ERROR: screenshot size must use WxH format, for example 1920x1080" >&2
exit 1
fi

FINAL_OUTPUT="$OUTPUT"
CAPTURE_OUTPUT="$OUTPUT"
if [[ "$OUTPUT" = /daytona-artifacts/* ]]; then
CAPTURE_OUTPUT="/tmp/daytona-screenshot-$(basename "$OUTPUT")"
fi

mkdir -p "$(dirname "$CAPTURE_OUTPUT")"
ffmpeg -y -f x11grab -video_size "$SIZE" -i "${DISPLAY:-:99}" -frames:v 1 "$CAPTURE_OUTPUT" >/tmp/daytona-screenshot.log 2>&1

if [ "$CAPTURE_OUTPUT" != "$FINAL_OUTPUT" ]; then
mkdir -p "$(dirname "$FINAL_OUTPUT")"
cp "$CAPTURE_OUTPUT" "$FINAL_OUTPUT"
fi

echo "Screenshot saved: $FINAL_OUTPUT"
Loading