Skip to content

feat(web): copy an environment's MCP URL for outside agents - #16337

Merged
juliusmarminge merged 6 commits into
t3code/mcp/oauth-sign-infrom
t3code/mcp/copy-mcp-url
Oct 6, 2026
Merged

juliusmarminge merged 6 commits into
t3code/mcp/oauth-sign-infrom
t3code/mcp/copy-mcp-url

Conversation

@juliusmarminge

@juliusmarminge juliusmarminge commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Part 3 of 3 for MCP sign-in from outside T3 Code (access declarations → sign-in → this). Based on #16336. Replaces #15222, which GitHub would not move off its old stack.

Problem

After #16336 an outside agent can sign in to an environment's /mcp, but the user has to work out the right URL themselves. For a T3 Connect environment that address isn't shown anywhere in the UI.

Fix

  • Saved environments in Settings → Connections get Copy MCP URL in the row menu. The toast shows the URL and a claude mcp add example.
  • The URL comes from environmentMcpUrl in client-runtime (shared with mobile if it ever wants it): the bearer profile's httpBaseUrl, or relay discovery's endpoint.httpBaseUrl for T3 Connect environments. It is offered only for https or loopback addresses, because MCP clients refuse plain-http token endpoints elsewhere, and never for SSH, whose address is a local forward.
  • docs/user/remote-access.md gains "Connect an outside agent": add the URL, approve with a pairing code, choose Read only or a mode limit, which routes work, revoking in Connections, the 30-day sign-in.
  • Mobile: no UI by design; it's a client of agents, not where you set them up.

Evidence

Same saved environment (a second dev server served over Tailscale https), same viewport, base vs head:

Before (main) After
Before: the saved environment's menu has only Icon and Remove from this device After: the menu adds Copy MCP URL between Icon and Remove

After choosing it:

Toast reads MCP URL copied, with claude mcp add --transport http t3 https://cups.tail131df4.ts.net:38772/mcp

The "Updates Available" toast in the before shot is unrelated dev noise.

Verification

  • vp test run src/connection/presentation.test.ts (client-runtime): the https address yields /mcp, loopback http is allowed, and a plain-http tailnet IP yields nothing.
  • Typecheck clean for web and client-runtime.
  • End to end over a T3 Connect tunnel on a personal relay stage: claude mcp add --transport http t3 https://<tunnel>/mcp (the form this menu copies), then claude mcp login t3, signed in and ran T3 tools, including launching a thread. Details and approval-page screenshots are in feat(server): outside agents sign in to the T3 MCP server with OAuth #16336.

Model: Claude Opus 5.5 (1M context) via T3 Code's Claude Code harness.

🤖 Generated with Claude Code


Devin Review

@juliusmarminge
juliusmarminge added this pull request to stack #16338 October 6, 2026 03:23
@github-actions github-actions Bot added the vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. label Oct 6, 2026
@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 6, 2026
@github-actions github-actions Bot added the size:M 30-99 changed lines (additions + deletions). label Oct 6, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a new outside-agent MCP workflow with sign-in, pairing, revocation, and potentially supervised/full-access thread control. Although the code is localized and existing connection behavior is preserved, the new authentication-sensitive capability warrants human review.

No code changes detected at 2dfe3a7. Prior analysis still applies.

You can add or adjust custom eligibility rules. Learn more.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ℹ️ No successful main baseline artifact is available yet. This run establishes the initial measurement.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire — 5.0 KiB — 6.8 KiB ✅
Codex Thread snapshot wire — 3.8 KiB — 4.9 KiB ✅
Codex Live turn WebSocket wire — 1.2 KiB — 2.0 KiB ✅
Codex Live turn WebSocket decoded — 20.9 KiB — 29.3 KiB ✅
Codex Live turn messages — 2 — 8 ✅
Claude Total thread wire — 5.0 KiB — 6.8 KiB ✅
Claude Thread snapshot wire — 3.8 KiB — 4.9 KiB ✅
Claude Live turn WebSocket wire — 1.2 KiB — 2.0 KiB ✅
Claude Live turn WebSocket decoded — 21.2 KiB — 29.3 KiB ✅
Claude Live turn messages — 1 — 8 ✅

Baseline: unavailable · PR result: 2dfe3a7 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 108.5 KiB
  • Claude decoded thread snapshot: 108.8 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Team
  • Run ID: 31a704b9-5323-463f-927b-dd5e3e0acf0b
📥 Commits

Reviewing files that changed from the base of the PR and between 2b38f57 and 77a25b2.

📒 Files selected for processing (1)
  • docs/user/remote-access.md

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The client runtime builds MCP URLs for eligible connections. Saved environment menus offer a copy action with success and failure toasts. Remote-access documentation describes agent setup, access modes, accepted addresses, revocation, and sign-in duration.

Changes

MCP URL access

Layer / File(s) Summary
MCP URL generation and validation
packages/client-runtime/src/connection/presentation.ts, packages/client-runtime/src/connection/presentation.test.ts
environmentMcpUrl builds /mcp URLs for eligible connections. Tests cover HTTPS, loopback HTTP, and plain-HTTP LAN addresses.
Saved environment copy flow and access instructions
apps/web/src/components/settings/ConnectionsSettings.tsx, docs/user/remote-access.md
Saved environment menus offer a copy action when an MCP URL is available. The UI retains the last discovered relay HTTP base URL and displays copy result toasts. Documentation describes outside-agent access and sign-in rules.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: t3dotgg

Merge Risk: ⚪ Minimal · up to 77a25

This change adds a way to copy an eligible environment’s MCP URL and instructions for outside-agent access. No actionable defect remains in the reviewed material, so no material merge risk is identified.

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes the main change: adding a way to copy an environment’s MCP URL for outside agents.
Description check ✅ Passed The description explains the problem, the change, the scope rationale, and focused verification. It also includes before-and-after screenshots and reports observed test and typecheck results. It refer…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from d804515 to c992e47 Compare October 6, 2026 07:20
@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from c992e47 to 679ad32 Compare October 6, 2026 08:25
@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from 679ad32 to 143b767 Compare October 6, 2026 09:49
@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from 143b767 to e0e8d7d Compare October 6, 2026 11:31
@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from e0e8d7d to 8e425ad Compare October 6, 2026 11:50
@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from 8e425ad to 2b38f57 Compare October 6, 2026 12:33
@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from 2b38f57 to 77a25b2 Compare October 6, 2026 16:19
@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from 77a25b2 to cf6e210 Compare October 6, 2026 17:21
@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from cf6e210 to 8845742 Compare October 6, 2026 17:46
juliusmarminge and others added 3 commits October 6, 2026 12:42
Saved environments in Settings → Connections get a "Copy MCP URL" action
so a user can add the environment to Claude Code or another MCP client.
It is offered only for HTTPS or loopback addresses, since MCP clients
refuse to sign in through a plain-http token endpoint elsewhere, and not
for SSH connections, whose address is a local forward. The user guide
gains a section on connecting an outside agent.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@juliusmarminge
juliusmarminge force-pushed the t3code/mcp/copy-mcp-url branch from 8845742 to 5df97c5 Compare October 6, 2026 19:50
@juliusmarminge
juliusmarminge merged commit fbe5df2 into main Oct 6, 2026
36 of 56 checks passed
@juliusmarminge
juliusmarminge deleted the t3code/mcp/copy-mcp-url branch October 6, 2026 21:09
aorwall added a commit to aorwall/t3code that referenced this pull request Oct 7, 2026
Merges `pingdotgg/t3code` `cd41c4ada0` into the fork: 81 upstream
commits since `442735897f`, the base pingdotgg#207 landed.

> [!IMPORTANT]
> **Merge with "Create a merge commit", not squash.** Squashing pingdotgg#207
broke the merge base and `main` had to be force-pushed back to a real
merge commit. A squash here would do the same.

## What changed in the merge

- **Counts:** 853 files landed against 853 in the upstream range. The
fork delta is 765 files. The [tracker
entry](docs/fork/upstream-merge-log.md) explains the three files on each
side that differ.
- **Conflicts:** 36 files, resolved by the verdicts `preflight.mjs`
printed. The ones that needed more than a mechanical resolution:
- **Preview:** upstream now runs the browser on the environment server
(pingdotgg#15328). The fork's iframe preview is kept beside it in `PreviewView`,
`ThreadPreviewMiniPlayer` and `PreviewPanel`. The frame picker now uses
upstream's per-pick token for `pickActiveRef`.
- **Permissions:** upstream split its coarse scopes into granular ones
(pingdotgg#9786–pingdotgg#9791). Upstream's new gates are combined with the fork's
`FEATURES` gates in Sidebar, ProviderSettingsPanel, ChatMarkdown,
ProjectSettingsPanel, GitActionsControl and others.
- **`ws.ts` instrumentation:** upstream replaced `observeRpcEffect` with
an `RpcInstrumentation` middleware. The fork's 15 stub handlers for
Moatless-only methods are unwrapped, and those methods are added to
`RPC_AGGREGATES`.
- **`ChatView.tsx`:** the woke, parked and resume-compaction banners are
dropped, because upstream deleted them. The fork's sandbox-commands
banner and the path that runs a script from a draft thread are kept.
- **`runOnSettle`** (pingdotgg#16290): carried on the script. The editor has no
switch for it because Moatless runs no script on settle.
- **Unsupported methods:** `preview.adjust`, `preview.clearProfile` and
`terminal.observe` now declare `UnsupportedMethodError`.
- **Fork tests:** five upstream tests were adapted to the fork's deltas,
each with a `Fork:` comment.
- **Docs:**
- [`gaps.md`](docs/fork/gaps.md) adds entries for the granular scopes
and for MCP sign-in, and extends the scripts, methods and settlement
entries.
- The auth bootstrap suite entry is struck, because that file now passes
36 of 36.
- [`upstream-merge-log.md`](docs/fork/upstream-merge-log.md) has the
2026-10-07 entry.

## Usable as-is

- Upstream's granular permission gates work today. Moatless sends no
`permissions` record, so `sessionGrantsScope` falls back to
`legacyParents`, which grant every new scope (pingdotgg#10298).
- File preview errors show the path that was attempted (pingdotgg#15628).
- The diff panel keeps the chosen scope while a turn runs (pingdotgg#16571).
- The desktop browser no longer gives two screenshots the same filename
(pingdotgg#14784).
- Assorted MCP fixes on upstream's server have no effect here.

## Unsupported in Moatless / needs implementation

- **Server-hosted browser** (pingdotgg#15328): `preview.adjust` and
`preview.clearProfile`, and the `serverBrowser` capability. Moatless
doesn't report the capability, so the web client keeps its frame
runtime.
- **Passive terminal observation** (pingdotgg#9791): `terminal.observe`. A client
sends it only to a session with `terminal:read` and without
`terminal:operate`. Moatless grants operate to every session.
- **Granular scopes:** Moatless can't grant less than everything. It
needs to send a `permissions` record from `session_state` in
`crates/t3code/src/rpc/config.rs`.
- **MCP OAuth for outside agents** (pingdotgg#16336, pingdotgg#16718, pingdotgg#16335): the
`/connect-agent` consent page and "Copy MCP URL" (pingdotgg#16337). The copy
button is already hidden by `FEATURES.connections`. The route is
reachable only by a typed URL.
- **Run a project action when a worktree thread settles** (pingdotgg#16290):
needs `runOnSettle` stored on the script in
`crates/t3code/src/projection/project.rs`, and a backend that runs the
script on settle.

## Backend behavior to consider reproducing in Moatless

- **pingdotgg#16761:** a thread settles as soon as a client sees its PR merge,
without waiting for the server's poll.
- **pingdotgg#16762:** settled threads stop polling their pull requests. Moatless
polls linked PRs and would save the same requests.
- **pingdotgg#16290:** running a designated script when a worktree thread
settles, such as a teardown.

## Verification

`verify.mjs --sequential` passed every check except `test`:
duplicate-adds, tripwires, resolution-check, unsupported-methods,
lockfile, fmt, lint, typecheck and build.

- **web:** five tests failed because upstream's new tests don't know the
fork's deltas. After the fixes, `--only test --package @t3tools/web`
passes all 496 files and 6,523 tests.
- **server:** four files fail because of the sandbox, not the code:
- `OpenCodeServerLedger`, `AcpAdapterV2` and
`OrchestratorReplayFixtures` fail as they did in the 2026-10-06 merge.
The sandbox doesn't reap detached process groups, and its
`CLAUDE_CONFIG_DIR` leaks into an auth error message.
- The new `ServerBrowserPage.test.ts` needs Playwright's
`chromium_headless_shell-1223`, which the sandbox lacks.
- The fork's only changes to the server areas these tests cover are 12
lines in `Orchestrator.ts` and its testkit, which none of the failing
tests touch.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---
Moatless task:
https://moatless.soaplabstest.com/tasks/b9b339cd-86dd-464d-8b37-1dd4a0ff4be7
Andrey170170 added a commit to Andrey170170/t3code that referenced this pull request Oct 9, 2026
…raming (#28)

* fix(server): forks no longer merge into their upstream repo's project group (pingdotgg#16353)

Fixes pingdotgg#4880. Originally pingdotgg#14639 by @Project516.

Co-authored-by: Project516 <138796702+Project516@users.noreply.github.com>

* fix(server): stop the startup project sync from delaying the app window (pingdotgg#14912)

* fix(web): avoid blocking image preparation conversions (pingdotgg#13342)

* fix(server): return partial workspace index on timeout (pingdotgg#11500)

* fix(server): probe project favicon candidates concurrently (pingdotgg#12543)

* fix(observability): a failing trace disk no longer stalls the server (pingdotgg#13758)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): status polling no longer locks the git index (pingdotgg#14718)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf(shared): scan PATH once per command before spawning, not on every spawn (pingdotgg#12600)

* fix(server): main's startup auto-pull test compiles again (pingdotgg#16357)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): project favicons stop being rescanned every minute (pingdotgg#16206)

Favicons in ProjectEnrichmentService now keep for 15 minutes. Repository identity keeps its 1-minute TTL, so remote changes still show within a minute.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): Claude limits load again for users with large transcript histories (pingdotgg#16358)

The Claude capabilities probe now asks for usage with skipBehaviors, so it no longer scans every local transcript and misses its 4 s deadline. Takes over pingdotgg#14456.

Co-authored-by: Ashkaan <a@ashkaan.me>

* Add esthor to the list of GitHub users

* fix(server): caches and ids are written atomically (pingdotgg#16242)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): one-shot initializers no longer race (pingdotgg#16260)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): the PR cache sweep only removes real entry files (pingdotgg#16285)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: keep one copy each of undici 8 and ws 8 (pingdotgg#16211)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(shared): DrainableWorker keeps running after a failed item (pingdotgg#16223)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): metrics count interrupted work on the monotonic clock (pingdotgg#16207)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(web): import connection storage as a namespace in its test (pingdotgg#16315)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(contracts): trimmed IDs round-trip (pingdotgg#16300)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): main's settings, keybindings and session tests compile again (pingdotgg#16363)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(lint): catch known tags with Effect.catchTags (pingdotgg#16361)

* fix(observability): T3 Connect tracing stops at the relay boundary (pingdotgg#16314)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(relay): error and deadline responses carry CORS headers (pingdotgg#16253)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): bring back the live shimmer on work log rows (pingdotgg#16372)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto (pingdotgg#16377)

* fix(relay): export traces through one tracer, one request span each (pingdotgg#16382)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): Pi thread titles use linked PR context (pingdotgg#16210)

* fix(desktop): retry transient bearer bootstrap and degrade on session fetch failure (pingdotgg#12919)

* fix(server): avoid scanning completed history for pending secrets (pingdotgg#16409)

* fix(orchestration-v2): let Stop recover stalled runs (pingdotgg#15442)

* fix(release): resolve version-qualified catalog overrides (pingdotgg#16411)

* fix(web): type in front of bold that starts a composer line (pingdotgg#13217)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

* fix(desktop): prevent browser screenshot filename collisions (pingdotgg#14784)

* fix(server): end clone options before the repository URL (pingdotgg#14781)

* fix(web): queued messages no longer split the composer notice stack (pingdotgg#16400)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>

* fix(server): reject invalid explicit Bitbucket repositories (pingdotgg#15876)

* fix(desktop): use the crypto service for screenshot IDs (pingdotgg#16415)

* fix(shared): find versioned JetBrains macOS app bundles (pingdotgg#16246)

* fix(server): OpenCode 2 threads get T3 Code's MCP tools (pingdotgg#16142)

* feat(preview): run the browser on the environment server (pingdotgg#15328)

* fix: restore service references breaking ci (pingdotgg#16495)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(mcp): mark declared tool failures as errors (pingdotgg#15617)

* fix(release): unblock nightly browser tests and cli builds (pingdotgg#16515)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(mcp): preserve thread command rejection reasons (pingdotgg#15627)

* chore(deps): upgrade @effect/tsgo to 0.46.1 (pingdotgg#16360)

Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(orchestration-v2): show reported subagent models (pingdotgg#14108)

Co-authored-by: Yash Singh <saiansh2525@gmail.com>

* fix(web): Apple logo no longer dips below the device host label (pingdotgg#14825)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): show subagent effort and speed in hover cards (pingdotgg#13056)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* feat(web): reopen closed tabs across the app (pingdotgg#15207)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(web): stop wide ordered list markers from clipping (pingdotgg#16523)

* fix(desktop): build AppImage with the static runtime toolset (fixes libfuse2 launch failure) (pingdotgg#7765)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(mobile): keep usage-limit notice opaque (pingdotgg#15602)

* feat(server): GitHub API transport that uses gh only for the token (pingdotgg#16319)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): pull requests talk to GitHub's API instead of the gh CLI (pingdotgg#16320)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): source control, media and discovery use GitHub's API instead of gh (pingdotgg#16321)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat: choose the GitHub account per host, save a GitHub token, and fewer reads per PR action (pingdotgg#16322)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): Rebase stack moves each layer onto the rebased layer below it (pingdotgg#16551)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): diff panel keeps the chosen scope while a turn runs (pingdotgg#16571)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(desktop): honor the telemetry opt-out from the shell profile (pingdotgg#16563)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs(marketing): disclose product usage data in the privacy policy (pingdotgg#16562)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): note anonymous usage data in onboarding and link the privacy policy (pingdotgg#16564)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* perf(web): diff panel no longer re-renders every file header each time a patch arrives (pingdotgg#16033)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): every T3 MCP tool declares who may call it (pingdotgg#16335)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server): outside agents sign in to the T3 MCP server with OAuth (pingdotgg#16336)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): copy an environment's MCP URL for outside agents (pingdotgg#16337)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(tsconfig): turn off the Schema-over-JSON diagnostic in test files (pingdotgg#16375)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(review): CodeRabbit gates outside contributors' pull requests (pingdotgg#16332)

* fix(desktop): include Linux package license and app metadata (pingdotgg#16597)

* fix(server): one failing RPC handler no longer ends the client's other requests (pingdotgg#15515)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(contracts): a context record that cannot be encoded no longer fails the send (pingdotgg#16398)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): open pull request row actions on right-click (pingdotgg#16612)

* fix(web): show attempted paths in file preview errors (pingdotgg#15628)

* fix(vcs): passive sidebar rows stop retaining remote pollers (pingdotgg#15666)

* feat(web): group keybindings settings by area with a page toolbar (pingdotgg#12822)

* feat(web): stop T3-owned subagents from Lineage (pingdotgg#15211)

* feat(web): add fast actions to linked pull requests (pingdotgg#16627)

* feat(web): open right panel tab menu with Mod+T (pingdotgg#15686)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): provider sessions clean up when their start is interrupted (pingdotgg#15571)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): show "No project" near the top of the new thread picker (pingdotgg#16628)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refactor(server): instrument WS RPCs in group middleware (pingdotgg#15548)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore(deps): upgrade @pierre/diffs to 1.5.2 and @pierre/trees to beta.6 (pingdotgg#16644)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(relay): a host restarting onto a deleted tunnel gets a new one (pingdotgg#16649)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): recover a deleted tunnel when Cloudflare says "Tunnel not found" (pingdotgg#16648)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): iPhone Duo fold controls follow the phone's orientation (pingdotgg#16630)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): keep workspace options when expanding lineage (pingdotgg#16635)

* fix(web): preserve bare anchor placeholders in markdown (pingdotgg#16637)

* fix(pi): preserve provider identity in discovered models (pingdotgg#16661)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(auth): preserve explicitly granted pairing scopes (pingdotgg#9785)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate environment administration permissions (pingdotgg#9786)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate source control write permissions (pingdotgg#9787)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate filesystem read and write permissions (pingdotgg#9788)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate browser preview control permissions (pingdotgg#9789)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): separate diagnostics and usage permissions (pingdotgg#9790)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(auth): allow passive terminal observation (pingdotgg#9791)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(auth): keep old clients connected across scope changes (pingdotgg#10298)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(server): hosted agents like ChatGPT can sign in to the T3 MCP server (pingdotgg#16718)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs: connect Claude Code, Codex, ChatGPT and bots over MCP (pingdotgg#16741)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(web): thread details card gives titles room to read (pingdotgg#16746)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(mcp): agent HTML pages stop painting slab backgrounds (pingdotgg#16752)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix: composer picks up new project skills without a server restart (pingdotgg#16750)

* feat(server): run a project action when a worktree thread settles (pingdotgg#16290)

Co-authored-by: spoukyii <61633921+spoukyii@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(web): old Claude threads compact on send instead of stacking notices (pingdotgg#16631)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): settled threads stop polling their pull requests (pingdotgg#16762)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): stop storing tool image bytes no client reads (pingdotgg#16652)

* fix(server): status refresh no longer pegs CPU in repos with thousands of untracked files (pingdotgg#16771)

Co-authored-by: Braulio Oliveira <brauliobo@gmail.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>

* perf(server): background branch lookups share one GitHub query per sweep (pingdotgg#16760)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): threads settle as soon as a client sees their PR merge (pingdotgg#16761)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* feat(server,web,mobile): agents see snooze state and link to threads (pingdotgg#16782)

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(release): Forgejo build resolves version-qualified catalog overrides

Upstream now pins overrides such as undici@^8 to the catalog; the packaging
script looked up the whole selector and failed. Mirrors upstream pingdotgg#16411.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): HTML renders and PDFs load behind a proxy that forbids framing

Clients frame asset documents from the environment's origin, which is
often not their own. A reverse proxy that adds X-Frame-Options: SAMEORIGIN
blanked every HTML render and PDF preview in that setup. Inline HTML and
PDF asset responses now carry `frame-ancestors *`, which browsers honour
in place of X-Frame-Options.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(server): desktop renderer may frame asset documents

CSP's `*` matches only http(s) ancestors, so the desktop app's custom
scheme origins are listed explicitly.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Project516 <138796702+Project516@users.noreply.github.com>
Co-authored-by: Igor Makowski <56691628+Mnigos@users.noreply.github.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Michel Liao <107891771+Michel-Liao@users.noreply.github.com>
Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: ahalekelly <7078138+ahalekelly@users.noreply.github.com>
Co-authored-by: SkiTee3000 <39069192+SkiTee3000@users.noreply.github.com>
Co-authored-by: Ashkaan <a@ashkaan.me>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Erik Thorelli <ethorelli@gmail.com>
Co-authored-by: James Villarrubia <8172873+jamesvillarrubia@users.noreply.github.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: Alex Southwell <saphid@gmail.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Tristan Manchester <108270628+tristanmanchester@users.noreply.github.com>
Co-authored-by: Arav Jain <aravhawk@gmail.com>
Co-authored-by: Sypher760-gif <sayffadil@gmail.com>
Co-authored-by: Nikita Koynov <43469098+nkoynov@users.noreply.github.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Jake Leventhal <jakeleventhal@me.com>
Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com>
Co-authored-by: Lorenzo <150276837+Bombatomica64@users.noreply.github.com>
Co-authored-by: Benedikt Rump <bjrump@gmail.com>
Co-authored-by: Stevan Borus <steva.borus@gmail.com>
Co-authored-by: Gabriel De Andrade <30420087+gabrielelpidio@users.noreply.github.com>
Co-authored-by: spoukyii <61633921+spoukyii@users.noreply.github.com>
Co-authored-by: Derek Trimm <275381468+derektrimm@users.noreply.github.com>
Co-authored-by: Braulio Oliveira <brauliobo@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:M 30-99 changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant