Repository navigation
fix(desktop): prevent browser screenshot filename collisions - #14784
Conversation
ApprovabilityVerdict: Approved at Macroscope's review found this PR approvable — This is a small, self-contained desktop bug fix that adds a UUID suffix to screenshot filenames to prevent overwrites. Capture behavior, artifact structure, and the IPC contract remain unchanged, with focused regression coverage added. You can add or adjust custom eligibility rules. Learn more. |
Dismissing prior approval to re-evaluate 47a86a7
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughScreenshot artifact IDs now include an eight-character UUID suffix. A regression test checks that same-site captures with the same timestamp receive distinct IDs and paths. ChangesScreenshot artifact ID uniqueness
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The UUID suffix distinguishes same-time screenshot filenames, and inspected desktop consumers do not depend on the old ID format. No known workflow issue remains before merge. Security Architecture ReviewSecurity architecture risk: ⚪ Minimal · up to The change reduces accidental screenshot overwrites without expanding access or changing the storage destination. No material security risk was identified in the reviewed change. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
aa7e93c to
53488e8
Compare
53488e8 to
fa56909
Compare
|
Rebased onto current |
Dismissing prior approval to re-evaluate fa56909
|
Review requested
Logged so this PR shows when a maintainer was asked to review it. |
## What's Changed * refactor(server,relay): webhook capabilities live in services, not handlers by @juliusmarminge in pingdotgg/t3code#16232 * fix(server): a T3 Connect preferences save finishes even if the client disconnects by @juliusmarminge in pingdotgg/t3code#16266 * refactor(server): import service modules as namespaces, not aliased layers by @juliusmarminge in pingdotgg/t3code#16267 * feat(server): log how long PR watches stay quiet before they end by @t3dotgg in pingdotgg/t3code#16262 * feat(server,web): choose where new worktrees are created by @juliusmarminge in pingdotgg/t3code#16231 * perf(server): idle status polls and PR sweeps start fewer git processes by @t3dotgg in pingdotgg/t3code#16272 * perf(server): PR watches spend ~90% fewer GitHub points by checking a 1-point fingerprint first by @t3dotgg in pingdotgg/t3code#16270 * fix(pull-requests): PR detail reads no longer drain the GitHub quota by @t3dotgg in pingdotgg/t3code#16280 * refactor: layer variables are named layer or layerXyz by @juliusmarminge in pingdotgg/t3code#16282 * refactor(server): T3 Connect link capabilities live in a CloudLink service by @juliusmarminge in pingdotgg/t3code#16265 * fix(web): sidebar drag and drop no longer snaps back by @t3dotgg in pingdotgg/t3code#16291 * fix(web): inline HTML renders no longer trap the thread's scroll by @t3dotgg in pingdotgg/t3code#16283 * refactor(server): one module per service instead of Services/ and Layers/ folders by @juliusmarminge in pingdotgg/t3code#16295 * chore(review): configure CodeRabbit in TypeScript by @esthor in pingdotgg/t3code#16281 * docs: put the Effect and web UI review rules in the docs by @esthor in pingdotgg/t3code#16286 * chore(lint): require a reason on every lint and type-checker suppression by @esthor in pingdotgg/t3code#16294 * refactor(relay): import HookInboxObject once, as a namespace by @juliusmarminge in pingdotgg/t3code#16307 * fix(web): a rejected desktop-local credential is not retried every poll by @juliusmarminge in pingdotgg/t3code#16273 * feat(desktop): the renderer's bootstrap token rotates every 12 hours by @juliusmarminge in pingdotgg/t3code#16275 * fix(web): recover from a closed IndexedDB connection by @juliusmarminge in pingdotgg/t3code#16311 * fix(relay): stop forcing manual relay deploys by default by @juliusmarminge in pingdotgg/t3code#13563 * feat(relay): measure the managed tunnel backlog by @juliusmarminge in pingdotgg/t3code#13564 * feat(relay): clean up tunnels of hosts that never registered recovery by @juliusmarminge in pingdotgg/t3code#13565 * perf(relay): delete expired tunnels four at a time within a time budget by @juliusmarminge in pingdotgg/t3code#13566 * feat(connect): tell users when an idle tunnel was removed by @juliusmarminge in pingdotgg/t3code#13567 * docs(relay): add the legacy tunnel cleanup rollout runbook by @juliusmarminge in pingdotgg/t3code#13568 * chore(review): point CodeRabbit at the web UI conventions by @esthor in pingdotgg/t3code#16324 * chore(review): turn off CodeRabbit's docstring coverage check by @esthor in pingdotgg/t3code#16328 * refactor(server): CloudLink keeps only the link lifecycle; pure checks live beside it by @juliusmarminge in pingdotgg/t3code#16340 * refactor(server): CloudLink fails with its own errors; the connect routes map them to HTTP by @juliusmarminge in pingdotgg/t3code#16341 * refactor(server): replay guards stay in CloudLink by @juliusmarminge in pingdotgg/t3code#16349 * fix(server): forks no longer merge into their upstream repo's project group by @t3dotgg in pingdotgg/t3code#16353 * fix(server): stop the startup project sync from delaying the app window by @Mnigos in pingdotgg/t3code#14912 * fix(web): avoid blocking image preparation conversions by @Bil0000 in pingdotgg/t3code#13342 * fix(server): return partial workspace index on timeout by @Michel-Liao in pingdotgg/t3code#11500 * fix(server): probe project favicon candidates concurrently by @ishaanko in pingdotgg/t3code#12543 * fix(observability): a failing trace disk no longer stalls the server by @t3dotgg in pingdotgg/t3code#13758 * fix(server): status polling no longer locks the git index by @ahalekelly in pingdotgg/t3code#14718 * perf(shared): scan PATH once per command before spawning, not on every spawn by @SkiTee3000 in pingdotgg/t3code#12600 * fix(server): main's startup auto-pull test compiles again by @t3dotgg in pingdotgg/t3code#16357 * fix(server): project favicons stop being rescanned every minute by @t3dotgg in pingdotgg/t3code#16206 * fix(server): Claude limits load again for users with large transcript histories by @t3dotgg in pingdotgg/t3code#16358 * fix(server): caches and ids are written atomically by @juliusmarminge in pingdotgg/t3code#16242 * fix(server): one-shot initializers no longer race by @juliusmarminge in pingdotgg/t3code#16260 * fix(server): the PR cache sweep only removes real entry files by @juliusmarminge in pingdotgg/t3code#16285 * chore: keep one copy each of undici 8 and ws 8 by @juliusmarminge in pingdotgg/t3code#16211 * fix(shared): DrainableWorker keeps running after a failed item by @juliusmarminge in pingdotgg/t3code#16223 * fix(server): metrics count interrupted work on the monotonic clock by @juliusmarminge in pingdotgg/t3code#16207 * refactor(web): import connection storage as a namespace in its test by @juliusmarminge in pingdotgg/t3code#16315 * fix(contracts): trimmed IDs round-trip by @juliusmarminge in pingdotgg/t3code#16300 * fix(server): main's settings, keybindings and session tests compile again by @juliusmarminge in pingdotgg/t3code#16363 * chore(lint): catch known tags with Effect.catchTags by @esthor in pingdotgg/t3code#16361 * fix(observability): T3 Connect tracing stops at the relay boundary by @juliusmarminge in pingdotgg/t3code#16314 * fix(relay): error and deadline responses carry CORS headers by @juliusmarminge in pingdotgg/t3code#16253 * fix(web): bring back the live shimmer on work log rows by @juliusmarminge in pingdotgg/t3code#16372 * refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto by @esthor in pingdotgg/t3code#16377 * fix(relay): export traces through one tracer, one request span each by @juliusmarminge in pingdotgg/t3code#16382 * fix(server): Pi thread titles use linked PR context by @juliusmarminge in pingdotgg/t3code#16210 * fix(desktop): retry transient bearer bootstrap and degrade on session fetch failure by @jamesvillarrubia in pingdotgg/t3code#12919 * fix(server): avoid scanning completed history for pending secrets by @Yash-Singh1 in pingdotgg/t3code#16409 * fix(orchestration-v2): let Stop recover stalled runs by @Yash-Singh1 in pingdotgg/t3code#15442 * fix(release): resolve version-qualified catalog overrides by @Yash-Singh1 in pingdotgg/t3code#16411 * fix(web): type in front of bold that starts a composer line by @saphid in pingdotgg/t3code#13217 * fix(desktop): prevent browser screenshot filename collisions by @saphid in pingdotgg/t3code#14784 * fix(server): end clone options before the repository URL by @saphid in pingdotgg/t3code#14781 * fix(web): queued messages no longer split the composer notice stack by @tristanmanchester in pingdotgg/t3code#16400 * fix(server): reject invalid explicit Bitbucket repositories by @aravhawk in pingdotgg/t3code#15876 * fix: restore desktop and server typechecks on main by @Yash-Singh1 in pingdotgg/t3code#16415 * fix(shared): find versioned JetBrains macOS app bundles by @Sypher760-gif in pingdotgg/t3code#16246 * fix(server): OpenCode 2 threads get T3 Code's MCP tools by @nkoynov in pingdotgg/t3code#16142 * feat(preview): run the browser on the environment server by @maria-rcks in pingdotgg/t3code#15328 * fix: restore service references breaking ci by @maria-rcks in pingdotgg/t3code#16495 * fix(mcp): mark declared tool failures as errors by @maria-rcks in pingdotgg/t3code#15617 * fix(release): unblock nightly browser tests and cli builds by @maria-rcks in pingdotgg/t3code#16515 ## New Contributors * @esthor made their first contribution in pingdotgg/t3code#16281 * @ahalekelly made their first contribution in pingdotgg/t3code#14718 * @SkiTee3000 made their first contribution in pingdotgg/t3code#12600 * @jamesvillarrubia made their first contribution in pingdotgg/t3code#12919 * @Sypher760-gif made their first contribution in pingdotgg/t3code#16246 * @nkoynov made their first contribution in pingdotgg/t3code#16142 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261005.2702...v0.0.46-nightly.20261006.2735 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261006.2735
## What's Changed * refactor(server,relay): webhook capabilities live in services, not handlers by @juliusmarminge in pingdotgg/t3code#16232 * fix(server): a T3 Connect preferences save finishes even if the client disconnects by @juliusmarminge in pingdotgg/t3code#16266 * refactor(server): import service modules as namespaces, not aliased layers by @juliusmarminge in pingdotgg/t3code#16267 * feat(server): log how long PR watches stay quiet before they end by @t3dotgg in pingdotgg/t3code#16262 * feat(server,web): choose where new worktrees are created by @juliusmarminge in pingdotgg/t3code#16231 * perf(server): idle status polls and PR sweeps start fewer git processes by @t3dotgg in pingdotgg/t3code#16272 * perf(server): PR watches spend ~90% fewer GitHub points by checking a 1-point fingerprint first by @t3dotgg in pingdotgg/t3code#16270 * fix(pull-requests): PR detail reads no longer drain the GitHub quota by @t3dotgg in pingdotgg/t3code#16280 * refactor: layer variables are named layer or layerXyz by @juliusmarminge in pingdotgg/t3code#16282 * refactor(server): T3 Connect link capabilities live in a CloudLink service by @juliusmarminge in pingdotgg/t3code#16265 * fix(web): sidebar drag and drop no longer snaps back by @t3dotgg in pingdotgg/t3code#16291 * fix(web): inline HTML renders no longer trap the thread's scroll by @t3dotgg in pingdotgg/t3code#16283 * refactor(server): one module per service instead of Services/ and Layers/ folders by @juliusmarminge in pingdotgg/t3code#16295 * chore(review): configure CodeRabbit in TypeScript by @esthor in pingdotgg/t3code#16281 * docs: put the Effect and web UI review rules in the docs by @esthor in pingdotgg/t3code#16286 * chore(lint): require a reason on every lint and type-checker suppression by @esthor in pingdotgg/t3code#16294 * refactor(relay): import HookInboxObject once, as a namespace by @juliusmarminge in pingdotgg/t3code#16307 * fix(web): a rejected desktop-local credential is not retried every poll by @juliusmarminge in pingdotgg/t3code#16273 * feat(desktop): the renderer's bootstrap token rotates every 12 hours by @juliusmarminge in pingdotgg/t3code#16275 * fix(web): recover from a closed IndexedDB connection by @juliusmarminge in pingdotgg/t3code#16311 * fix(relay): stop forcing manual relay deploys by default by @juliusmarminge in pingdotgg/t3code#13563 * feat(relay): measure the managed tunnel backlog by @juliusmarminge in pingdotgg/t3code#13564 * feat(relay): clean up tunnels of hosts that never registered recovery by @juliusmarminge in pingdotgg/t3code#13565 * perf(relay): delete expired tunnels four at a time within a time budget by @juliusmarminge in pingdotgg/t3code#13566 * feat(connect): tell users when an idle tunnel was removed by @juliusmarminge in pingdotgg/t3code#13567 * docs(relay): add the legacy tunnel cleanup rollout runbook by @juliusmarminge in pingdotgg/t3code#13568 * chore(review): point CodeRabbit at the web UI conventions by @esthor in pingdotgg/t3code#16324 * chore(review): turn off CodeRabbit's docstring coverage check by @esthor in pingdotgg/t3code#16328 * refactor(server): CloudLink keeps only the link lifecycle; pure checks live beside it by @juliusmarminge in pingdotgg/t3code#16340 * refactor(server): CloudLink fails with its own errors; the connect routes map them to HTTP by @juliusmarminge in pingdotgg/t3code#16341 * refactor(server): replay guards stay in CloudLink by @juliusmarminge in pingdotgg/t3code#16349 * fix(server): forks no longer merge into their upstream repo's project group by @t3dotgg in pingdotgg/t3code#16353 * fix(server): stop the startup project sync from delaying the app window by @Mnigos in pingdotgg/t3code#14912 * fix(web): avoid blocking image preparation conversions by @Bil0000 in pingdotgg/t3code#13342 * fix(server): return partial workspace index on timeout by @Michel-Liao in pingdotgg/t3code#11500 * fix(server): probe project favicon candidates concurrently by @ishaanko in pingdotgg/t3code#12543 * fix(observability): a failing trace disk no longer stalls the server by @t3dotgg in pingdotgg/t3code#13758 * fix(server): status polling no longer locks the git index by @ahalekelly in pingdotgg/t3code#14718 * perf(shared): scan PATH once per command before spawning, not on every spawn by @SkiTee3000 in pingdotgg/t3code#12600 * fix(server): main's startup auto-pull test compiles again by @t3dotgg in pingdotgg/t3code#16357 * fix(server): project favicons stop being rescanned every minute by @t3dotgg in pingdotgg/t3code#16206 * fix(server): Claude limits load again for users with large transcript histories by @t3dotgg in pingdotgg/t3code#16358 * fix(server): caches and ids are written atomically by @juliusmarminge in pingdotgg/t3code#16242 * fix(server): one-shot initializers no longer race by @juliusmarminge in pingdotgg/t3code#16260 * fix(server): the PR cache sweep only removes real entry files by @juliusmarminge in pingdotgg/t3code#16285 * chore: keep one copy each of undici 8 and ws 8 by @juliusmarminge in pingdotgg/t3code#16211 * fix(shared): DrainableWorker keeps running after a failed item by @juliusmarminge in pingdotgg/t3code#16223 * fix(server): metrics count interrupted work on the monotonic clock by @juliusmarminge in pingdotgg/t3code#16207 * refactor(web): import connection storage as a namespace in its test by @juliusmarminge in pingdotgg/t3code#16315 * fix(contracts): trimmed IDs round-trip by @juliusmarminge in pingdotgg/t3code#16300 * fix(server): main's settings, keybindings and session tests compile again by @juliusmarminge in pingdotgg/t3code#16363 * chore(lint): catch known tags with Effect.catchTags by @esthor in pingdotgg/t3code#16361 * fix(observability): T3 Connect tracing stops at the relay boundary by @juliusmarminge in pingdotgg/t3code#16314 * fix(relay): error and deadline responses carry CORS headers by @juliusmarminge in pingdotgg/t3code#16253 * fix(web): bring back the live shimmer on work log rows by @juliusmarminge in pingdotgg/t3code#16372 * refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto by @esthor in pingdotgg/t3code#16377 * fix(relay): export traces through one tracer, one request span each by @juliusmarminge in pingdotgg/t3code#16382 * fix(server): Pi thread titles use linked PR context by @juliusmarminge in pingdotgg/t3code#16210 * fix(desktop): retry transient bearer bootstrap and degrade on session fetch failure by @jamesvillarrubia in pingdotgg/t3code#12919 * fix(server): avoid scanning completed history for pending secrets by @Yash-Singh1 in pingdotgg/t3code#16409 * fix(orchestration-v2): let Stop recover stalled runs by @Yash-Singh1 in pingdotgg/t3code#15442 * fix(release): resolve version-qualified catalog overrides by @Yash-Singh1 in pingdotgg/t3code#16411 * fix(web): type in front of bold that starts a composer line by @saphid in pingdotgg/t3code#13217 * fix(desktop): prevent browser screenshot filename collisions by @saphid in pingdotgg/t3code#14784 * fix(server): end clone options before the repository URL by @saphid in pingdotgg/t3code#14781 * fix(web): queued messages no longer split the composer notice stack by @tristanmanchester in pingdotgg/t3code#16400 * fix(server): reject invalid explicit Bitbucket repositories by @aravhawk in pingdotgg/t3code#15876 * fix: restore desktop and server typechecks on main by @Yash-Singh1 in pingdotgg/t3code#16415 * fix(shared): find versioned JetBrains macOS app bundles by @Sypher760-gif in pingdotgg/t3code#16246 * fix(server): OpenCode 2 threads get T3 Code's MCP tools by @nkoynov in pingdotgg/t3code#16142 * feat(preview): run the browser on the environment server by @maria-rcks in pingdotgg/t3code#15328 * fix: restore service references breaking ci by @maria-rcks in pingdotgg/t3code#16495 * fix(mcp): mark declared tool failures as errors by @maria-rcks in pingdotgg/t3code#15617 * fix(release): unblock nightly browser tests and cli builds by @maria-rcks in pingdotgg/t3code#16515 ## New Contributors * @esthor made their first contribution in pingdotgg/t3code#16281 * @ahalekelly made their first contribution in pingdotgg/t3code#14718 * @SkiTee3000 made their first contribution in pingdotgg/t3code#12600 * @jamesvillarrubia made their first contribution in pingdotgg/t3code#12919 * @Sypher760-gif made their first contribution in pingdotgg/t3code#16246 * @nkoynov made their first contribution in pingdotgg/t3code#16142 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261005.2702...v0.0.46-nightly.20261006.2735 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261006.2735
Merges `pingdotgg/t3code` `cd41c4ada0` into the fork: 81 upstream commits since `442735897f`, the base pingdotgg#207 landed. > [!IMPORTANT] > **Merge with "Create a merge commit", not squash.** Squashing pingdotgg#207 broke the merge base and `main` had to be force-pushed back to a real merge commit. A squash here would do the same. ## What changed in the merge - **Counts:** 853 files landed against 853 in the upstream range. The fork delta is 765 files. The [tracker entry](docs/fork/upstream-merge-log.md) explains the three files on each side that differ. - **Conflicts:** 36 files, resolved by the verdicts `preflight.mjs` printed. The ones that needed more than a mechanical resolution: - **Preview:** upstream now runs the browser on the environment server (pingdotgg#15328). The fork's iframe preview is kept beside it in `PreviewView`, `ThreadPreviewMiniPlayer` and `PreviewPanel`. The frame picker now uses upstream's per-pick token for `pickActiveRef`. - **Permissions:** upstream split its coarse scopes into granular ones (pingdotgg#9786–pingdotgg#9791). Upstream's new gates are combined with the fork's `FEATURES` gates in Sidebar, ProviderSettingsPanel, ChatMarkdown, ProjectSettingsPanel, GitActionsControl and others. - **`ws.ts` instrumentation:** upstream replaced `observeRpcEffect` with an `RpcInstrumentation` middleware. The fork's 15 stub handlers for Moatless-only methods are unwrapped, and those methods are added to `RPC_AGGREGATES`. - **`ChatView.tsx`:** the woke, parked and resume-compaction banners are dropped, because upstream deleted them. The fork's sandbox-commands banner and the path that runs a script from a draft thread are kept. - **`runOnSettle`** (pingdotgg#16290): carried on the script. The editor has no switch for it because Moatless runs no script on settle. - **Unsupported methods:** `preview.adjust`, `preview.clearProfile` and `terminal.observe` now declare `UnsupportedMethodError`. - **Fork tests:** five upstream tests were adapted to the fork's deltas, each with a `Fork:` comment. - **Docs:** - [`gaps.md`](docs/fork/gaps.md) adds entries for the granular scopes and for MCP sign-in, and extends the scripts, methods and settlement entries. - The auth bootstrap suite entry is struck, because that file now passes 36 of 36. - [`upstream-merge-log.md`](docs/fork/upstream-merge-log.md) has the 2026-10-07 entry. ## Usable as-is - Upstream's granular permission gates work today. Moatless sends no `permissions` record, so `sessionGrantsScope` falls back to `legacyParents`, which grant every new scope (pingdotgg#10298). - File preview errors show the path that was attempted (pingdotgg#15628). - The diff panel keeps the chosen scope while a turn runs (pingdotgg#16571). - The desktop browser no longer gives two screenshots the same filename (pingdotgg#14784). - Assorted MCP fixes on upstream's server have no effect here. ## Unsupported in Moatless / needs implementation - **Server-hosted browser** (pingdotgg#15328): `preview.adjust` and `preview.clearProfile`, and the `serverBrowser` capability. Moatless doesn't report the capability, so the web client keeps its frame runtime. - **Passive terminal observation** (pingdotgg#9791): `terminal.observe`. A client sends it only to a session with `terminal:read` and without `terminal:operate`. Moatless grants operate to every session. - **Granular scopes:** Moatless can't grant less than everything. It needs to send a `permissions` record from `session_state` in `crates/t3code/src/rpc/config.rs`. - **MCP OAuth for outside agents** (pingdotgg#16336, pingdotgg#16718, pingdotgg#16335): the `/connect-agent` consent page and "Copy MCP URL" (pingdotgg#16337). The copy button is already hidden by `FEATURES.connections`. The route is reachable only by a typed URL. - **Run a project action when a worktree thread settles** (pingdotgg#16290): needs `runOnSettle` stored on the script in `crates/t3code/src/projection/project.rs`, and a backend that runs the script on settle. ## Backend behavior to consider reproducing in Moatless - **pingdotgg#16761:** a thread settles as soon as a client sees its PR merge, without waiting for the server's poll. - **pingdotgg#16762:** settled threads stop polling their pull requests. Moatless polls linked PRs and would save the same requests. - **pingdotgg#16290:** running a designated script when a worktree thread settles, such as a teardown. ## Verification `verify.mjs --sequential` passed every check except `test`: duplicate-adds, tripwires, resolution-check, unsupported-methods, lockfile, fmt, lint, typecheck and build. - **web:** five tests failed because upstream's new tests don't know the fork's deltas. After the fixes, `--only test --package @t3tools/web` passes all 496 files and 6,523 tests. - **server:** four files fail because of the sandbox, not the code: - `OpenCodeServerLedger`, `AcpAdapterV2` and `OrchestratorReplayFixtures` fail as they did in the 2026-10-06 merge. The sandbox doesn't reap detached process groups, and its `CLAUDE_CONFIG_DIR` leaks into an auth error message. - The new `ServerBrowserPage.test.ts` needs Playwright's `chromium_headless_shell-1223`, which the sandbox lacks. - The fork's only changes to the server areas these tests cover are 12 lines in `Orchestrator.ts` and its testkit, which none of the failing tests touch. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --- Moatless task: https://moatless.soaplabstest.com/tasks/b9b339cd-86dd-464d-8b37-1dd4a0ff4be7
Problem
If you take two desktop Browser screenshots of the same site in the same millisecond, both get the same filename. The second save silently overwrites the first image.
Why this qualifies
This is a small, obvious data-loss bug fix under CONTRIBUTING: every successful capture should keep its own file. There is no linked issue or prior maintainer discussion. The change is one expression in the desktop screenshot ID, plus one regression test. Capture, save, reveal, copy-path and copy-image behaviour are all unchanged.
Fix
PreviewManager.captureScreenshotnow adds an eight-character UUID suffix to the screenshot ID, and so to the filename. Agent MCP screenshots already use exactly this format, inapps/server/src/mcp/McpHttpServer.ts.Evidence
Environment: macOS 26.5.2 (arm64), a locally built Electron 44.4.2 desktop client and a disposable local page with isolated state. The window is 1280 × 850 CSS px, the Browser page is 539 × 758 CSS px, and DPR is 2.
Versions verified:
53488e872b). The images carry those labels.preview/Manager.ts,preload.ts, the desktop IPC channel and method,PreviewView.tsxand the contracts IPC type.Reproduction. Both runs use the same Browser panel, page and viewport, and start with an empty screenshot directory:
desktop:preview-capture-screenshotIPC handler.How the collision is forced. A hook at the capture boundary pins only the artifact naming timestamp, to
2026-10-03T00:00:00.000Z. Everything else is real: ElectroncapturePage, PNG conversion, file writes and rendering. The two requests started 62 ms apart on main and 72 ms apart with the fix. This reproduces the equal-timestamp collision deterministically. It does not claim the captures were naturally simultaneous.Before (main).
browser-screenshot-127-0-0-1-murml1c0and the same path.After (this PR).
Recordings: before, after.
Focused commands run at this head, on main f870c41:
vp test run src/preview/Manager.test.ts(fromapps/desktop), with main'sManager.tsexpected 'browser-screenshot-example-com-0' not to be 'browser-screenshot-example-com-0'vp run --filter @t3tools/desktop typecheckvp lint --report-unused-disable-directivesandvp fmt --checkon both changed filesvp run build:desktopnode scripts/release-smoke.tsnode apps/desktop/scripts/verify-preload-bundle.mjsprocess.platformset tolinux, which is how CI's Linux host runs itOn macOS, the preload verifier fails with
window is not definedat a darwin-only listener. That failure is not caused by this PR:mainfails the same way.preload.cjshas the same SHA-256 on main and on this branch.Surfaces
PreviewManager.captureScreenshotis the only place Browser panel screenshots get their name. Its only caller is the Browser panel's Capture screenshot control, through thedesktop:preview-capture-screenshotIPC handler.npx t3): not affected. Only the desktop Browser panel writes these files. The server's MCP screenshot path already uses this suffix.Not checked
GPT-6.1 Sol, GPT-6 Astra and Claude Opus 5.5 via T3 Code
🤖 Generated with Claude Code