argenis de la rosa
d63a6a8ceb
feat(security): unify URL validation with configurable CIDR/domain allowlist
2026-02-26 22:07:07 -05:00
argenis de la rosa
b27b44829a
chore: promote dev snapshot to main (resolve #1978/#1970)
2026-02-26 21:09:33 -05:00
Chum Yin
9b0e70b2f2
supersede: file-replay changes from #1895 ( #1926 )
...
Automated conflict recovery via changed-file replay on latest main.
2026-02-26 04:15:47 -05:00
Chummy
e0f6f24a5e
merge: promote dev into main (dev-first conflict resolution)
2026-02-26 03:41:59 +00:00
Chummy
b4df1dc30d
feat(tools): add web_fetch provider dispatch and shared URL validation
2026-02-25 03:30:45 +08:00
Chummy
bf1d7ac928
supersede: file-replay changes from #1317
...
Automated conflict recovery via changed-file replay on latest dev.
2026-02-24 23:46:04 +08:00
Chummy
c9d76780f0
fix(security): harden redirect/browser_open and restore masked secrets
2026-02-24 16:03:01 +08:00
Nguyen Minh Thai
77a3b39ff7
feat(tools): Use system default browser instead of hard-coded Brave Browser ( #1453 )
...
* ci(homebrew): prefer HOMEBREW_UPSTREAM_PR_TOKEN with fallback
* ci(homebrew): handle existing upstream remote and main base
* feat(tools): Use system default browser instead of hard-coded Brave Browser
---------
Co-authored-by: Will Sarg <12886992+willsarg@users.noreply.github.com>
2026-02-24 16:03:00 +08:00
Nguyen Minh Thai
87ac60c71d
feat(tools): Use system default browser instead of hard-coded Brave Browser ( #1453 )
...
* ci(homebrew): prefer HOMEBREW_UPSTREAM_PR_TOKEN with fallback
* ci(homebrew): handle existing upstream remote and main base
* feat(tools): Use system default browser instead of hard-coded Brave Browser
---------
Co-authored-by: Will Sarg <12886992+willsarg@users.noreply.github.com>
2026-02-23 05:57:21 -05:00
Chummy
ccd0de36aa
fix(tools): honor wildcard allowed_domains for browser and http_request
2026-02-21 17:08:08 +08:00
argenis de la rosa
3d91c40970
refactor: simplify CLI commands and update architecture docs
...
1. Simplify CLI:
- Make 'onboard' quick setup default (remove --quick)
- Add --interactive flag for full wizard
- Make 'status' detailed by default (remove --verbose)
- Remove 'tools list/test' and 'integrations list' commands
- Add 'channel doctor' command
2. Update Docs:
- Update architecture.svg with Channel allowlists, Browser allowlist, and latest stats
- Update README.md with new command usage and browser/channel config details
3. Polish:
- Browser tool integration
- Channel allowlist logic (empty = deny all)
2026-02-14 05:17:16 -05:00