Commit Graph

257 Commits

Author SHA1 Message Date
Michael Ramos 0b4c499988 fix(remote): notify URL in remote mode for OpenCode and Pi (#663)
* fix(remote): notify URL in remote mode for OpenCode and Pi (#551, #574)

PR #440 removed writeRemoteShareLink from OpenCode because the base64
share URL flooded the TUI — but no replacement was added. Remote users
got zero feedback about where the server was listening.

OpenCode: log the short localhost URL via client.app.log() in all onReady
callbacks (submit_plan, review, annotate, annotate-last, archive).

Pi: check isRemoteSession() directly instead of relying on the openBrowser
return value, which only sets isRemote when BROWSER env is unset. Users
running via Cursor (which sets BROWSER) now get the notification.

* fix(pi): use neutral URL notification for remote sessions

The previous wording ("Remote session. Open manually:") implied the
browser failed even when BROWSER env successfully opened it via port
forwarding. Use a neutral informational message instead.
2026-05-04 22:17:53 -07:00
Michael Ramos 6fc60a6a84 chore: bump version to 0.19.7
For provenance purposes, this commit was AI assisted.
2026-05-02 14:01:25 -07:00
Michael Ramos 6324a0c859 chore: bump version to 0.19.6
Co-authored-by: Eric Clemmons <15182+ericclemmons@users.noreply.github.com>

For provenance purposes, this commit was AI assisted.
2026-05-01 18:38:10 -07:00
Michael Ramos 5aabace2ee feat(opencode): agent picker dropdown on Approve button (#648)
Surface agent switching directly on the Approve button as a split
dropdown for OpenCode users, so they can pick which agent to switch
to (or disable switching) without hunting through Settings.

Also fix the "approved with notes" prompt to not say "Proceed with
implementation" when agent switching is disabled.

Closes #575, closes #114, closes #106, closes #159
2026-05-01 18:05:50 -07:00
Michael Ramos 5aaac6bc88 chore: bump version to 0.19.5
For provenance purposes, this commit was AI assisted.
2026-05-01 00:14:59 -07:00
Michael Ramos 9b7c39d2a4 fix(review): move hide-whitespace to server-side git diff -w (#635 follow-up) (#638)
The client-side approach from PR #635 normalized file contents before
diffing, which destroyed all indentation. Move whitespace handling to
the server by threading a `-w` flag through the git diff pipeline.

- Add `GitDiffOptions` to review-core.ts, inject `-w` in all 7 diff
  type paths + untracked file diffs
- Thread options through git.ts → vcs.ts → review.ts / Pi server
- Read `hideWhitespace` from ~/.plannotator/config.json on startup so
  the initial diff already respects the persisted preference
- Accept `hideWhitespace` in `/api/diff/switch`, echo in responses
- Client toggles trigger a lightweight server refetch that preserves
  the active file (no panel reset)
- Handle edge case where current file disappears when `-w` removes
  whitespace-only diffs
- Remove broken client-side parseDiffFromFile/normalize hack
- Update API docs in AGENTS.md

Closes the indentation bug reported by @zeroZshadow on PR #631.

For provenance purposes, this commit was AI assisted.
2026-04-30 17:23:55 -07:00
Michael Ramos 3636e9ed76 chore: bump version to 0.19.4
For provenance purposes, this commit was AI assisted.
2026-04-30 11:09:41 -07:00
Michael Ramos 117c7c8ad1 chore: bump version to 0.19.3
For provenance purposes, this commit was AI assisted.
2026-04-29 00:30:37 -07:00
Michael Ramos 64c845fd2e feat(feedback): configurable plan, annotation, and review feedback (#627)
Unified feedback pipeline for all plan approvals, plan denials, annotation
feedback, and review suffixes. Users customize messages via config.json with
{{variable}} template interpolation and per-runtime overrides.

Closes #624

Co-authored-by: Aviad Shiber <aviadshiber@users.noreply.github.com>

For provenance purposes, this commit was AI assisted.
2026-04-29 00:06:05 -07:00
Orestis Ioannou b2eae468d7 feat(review): add configurable approval prompts (#561)
* feat(review): add configurable approval prompts

Let users override the agent message Plannotator sends after approving a code review. Keep the existing behavior by default while supporting runtime-specific overrides in ~/.plannotator/config.json.

* fix(shared): export prompts helper

Expose the new shared prompts module through @plannotator/shared so Bun can resolve it during hook builds and CI.

* fix: add Gemini CLI to agent origin detection chain

Gemini CLI sets GEMINI_CLI=1 in the environment. Add it to the
detectedOrigin chain so runtime-specific prompt overrides work
on all paths (review, annotate, plan), not just plan review.

For provenance purposes, this commit was AI assisted.

---------

Co-authored-by: Michael Ramos <mdramos8@gmail.com>
2026-04-28 15:59:19 -07:00
Michael Ramos 8a5082d3ed chore: bump version to 0.19.2
For provenance purposes, this commit was AI assisted.
2026-04-27 23:48:41 -07:00
Michael Ramos fdc4bc4656 feat(plan,annotate): include source line numbers in exported feedback (#623)
Each annotation in exported plan/annotate feedback now carries source
line numbers — single-line blocks show `(line N)`, multi-line blocks
show `(lines N–M)`. Diff-context and global comments stay lineless.

When the document was produced by Turndown/Jina (HTML file or URL),
the export carries a caveat that line numbers refer to the converted
markdown rather than the original source.

Key implementation details:
- extractFrontmatter() returns contentStartLine so block line numbers
  account for stripped YAML headers
- blockEndLine() computes end lines per block type, with code blocks,
  directives, and alerts accounting for stripped wrapper lines
- isConvertedSource() helper in url-to-markdown.ts centralizes the
  source-type check across all entry points
- sourceConverted threaded from all CLIs through annotate servers
  to the /api/plan payload; isConverted added to /api/doc responses
- Per-document conversion tracking in useLinkedDoc ensures the correct
  flag is used when viewing linked HTML docs

Supersedes #621.

For provenance purposes, this commit was AI assisted.
2026-04-27 23:13:52 -07:00
Michael Ramos 33f409adc1 docs: clarify OpenCode plugin configuration
Clarify how to attach Plannotator options when OpenCode has multiple plugins, and link the landing page OpenCode tab to setup and migration docs.
2026-04-27 10:33:49 -07:00
Michael Ramos f13807bd54 chore: bump version to 0.19.1 2026-04-23 22:49:29 -07:00
Michael Ramos d102c5f709 feat(annotate): add --gate, --json, and --silent-approve flags (#570)
Adds an opt-in review gate flow to annotation mode with three composable flags:

- `--gate`: 3-way UX (Approve / Send Annotations / Close)
- `--json`: structured decision output (`{"decision":"approved|annotated|dismissed"}`)
- `--silent-approve`: suppresses plaintext approve marker for naive hooks

Includes shared arg parser, @-reference handling, updated templates across all
harnesses (Claude Code, Copilot, Gemini, OpenCode, Pi), and full documentation.

Closes #570

For provenance purposes, this commit was AI assisted.
2026-04-23 17:40:40 -07:00
Michael Ramos 1338802a58 Scope OpenCode submit_plan to planning agents (#571) 2026-04-23 07:46:50 -07:00
Michael Ramos 289a2aa494 chore: bump version to 0.19.0
Bump version across all 7 package/plugin manifests. Also refresh
AGENTS.md (new Block types from #597, Code Tour endpoints from #569),
prune removed flags from the Pi README (--plan-file, /plannotator-set-file
from #595), and pin Renovate off bun-version bumps to keep the macOS
codesign hotfix from v0.17.9 in place.

For provenance purposes, this commit was AI assisted.
2026-04-21 19:36:02 -07:00
Michael Ramos 3a7f1156cd chore: bump version to 0.18.0
Also fix stale annotate description in README and add missing PLANNOTATOR_ORIGIN entry to the env vars table.

For provenance purposes, this commit was AI assisted.
2026-04-19 17:41:53 -07:00
Alexander Kolberg 54c206c77d Add ~ support for user-entered file paths (#572)
* refactor(path): centralize user path resolution

* fix(annotate): resolve user paths in file entrypoints

* fix(pi-extension): restore resolve import and add typecheck to CI

The refactor removed `resolve` from `node:path` imports, but `resolvePlanPath()`
and the planning-mode write/edit guards still call `resolve(...)`. That breaks
plan submission and plan-file restriction at runtime for Pi users.

Also wires pi-extension's tsconfig into the root `typecheck` script so CI
catches this class of missing-symbol regression in the future. Required
adding @mariozechner/pi-* packages as explicit devDependencies so tsc can
resolve them (they were previously only reachable transitively via the
peer dep, which Bun keeps in its `.bun/` store unhoisted).

For provenance purposes, this commit was AI assisted.

* fix(path): reject whitespace-only user paths and run vendor before typecheck

resolveUserPath() trims input, so whitespace-only customPath/vaultPath
resolved to process.cwd(). Plans silently wrote into the repo root and
Obsidian notes landed in <cwd>/plannotator/ instead of erroring.

Guard at both call sites (getPlanDir, saveToObsidian — Bun + Pi copies).

Also prepend vendor.sh to the root typecheck script so fresh-clone
`bun run typecheck` works without a separate vendoring step.

For provenance purposes, this commit was AI assisted.

* fix(path): short-circuit resolveUserPath on empty input

Trimming in normalizeUserPathInput meant whitespace-only input resolved
to cwd/baseDir. Callers like the annotate CLI and reference API endpoints
would then list the project root instead of erroring. Return "" early so
downstream existsSync/resolveMarkdownFile checks fail naturally.

For provenance purposes, this commit was AI assisted.

---------

Co-authored-by: Michael Ramos <mdramos8@gmail.com>
2026-04-19 16:54:15 -07:00
Michael Ramos ea758f9978 Add configurable paste service URL for self-hosting (#582)
* Wire PLANNOTATOR_PASTE_URL through opencode/pi servers and Landing demo link

OpenCode plugin only read PLANNOTATOR_SHARE_URL; add a getPasteApiUrl helper
and thread it into plan/annotate/archive server starts. Pi extension's
serverReview gains the same shareBaseUrl/pasteApiUrl env-var pair already
used by serverPlan/serverAnnotate. Landing.tsx now accepts a shareBaseUrl
prop for self-hosters' demo link. Paste-service CORS defaults grow a
comment clarifying that self-hosters must override ALLOWED_ORIGINS.

* Embed custom paste origin in short URL fragment

When PLANNOTATOR_PASTE_URL is set to a non-default paste service, the
generated short link now includes a base64url-encoded paste param in the
fragment (#key=...&paste=...). The share portal and importFromShareUrl
extract it on load so they can fetch from the right paste backend without
needing a server — fixing broken short links for self-hosters who use a
custom paste service but keep the hosted share portal.

Backward compatible: links without a paste param continue to use the
default or server-provided paste API URL as before.

For provenance purposes, this commit was AI assisted.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-04-17 22:21:49 -07:00
Andrei Neculau a8dc9e8f4b don't change current agent (#564)
agent_cycle is not the correct command as the user may have several agents defined, not only build and plan
2026-04-15 16:40:06 -07:00
Orestis Ioannou 14bff361f8 fix(opencode): reuse local server for review flows (#567)
* fix(opencode): reuse local server for review flows

Try the default local OpenCode server before spawning a new one, and resolve bundled assets and command paths correctly when the plugin is loaded from source during local testing.

* Fix typecheck after narrowing the opencode type to the sdk
2026-04-15 08:22:55 -07:00
Michael Ramos e22c911c2c chore: bump version to 0.17.10
For provenance purposes, this commit was AI assisted.
2026-04-13 08:02:26 -07:00
Michael Ramos b780739291 feat(annotate): support HTML files and URL annotation (#545)
* fix(annotate): sanitize dangerous link protocols in markdown renderer

Block javascript:, data:, and vbscript: URLs in InlineMarkdown link
rendering. Links with dangerous protocols render as plain text instead
of clickable anchors. Uses a blocklist approach so existing links with
custom protocols (obsidian://, vscode://, Windows C:\ paths) continue
to work.

For provenance purposes, this commit was AI assisted.

* feat(annotate): add HTML-to-markdown and URL-to-markdown utilities

- html-to-markdown.ts: Turndown wrapper with GFM table rule, strips
  script/style/noscript tags
- url-to-markdown.ts: Jina Reader (free, returns markdown) with
  fetch+Turndown fallback. Warns on Jina failure, auto-skips Jina for
  local/private URLs (localhost, 192.168.*, 10.*, etc.)
- config.ts: add jina setting and resolveUseJina() with priority chain
  --no-jina flag > PLANNOTATOR_JINA env > config.json > default true

For provenance purposes, this commit was AI assisted.

* feat(annotate): support HTML files and URLs in annotate command

Extend the annotate subcommand to accept .html/.htm local files
(converted via Turndown) and https:// URLs (fetched via Jina Reader
with fetch+Turndown fallback). URL content is fetched terminal-side
before opening the browser.

Add --no-jina global flag to disable Jina Reader per-invocation.
Add 10MB file size guard for local HTML files.

For provenance purposes, this commit was AI assisted.

* feat(annotate): HTML files in folder browser and on-demand conversion

- Widen file browser glob to include .html/.htm alongside markdown
- handleDoc converts HTML files via Turndown on demand when selected
- hasMarkdownFiles accepts optional extensions param for folder validation
- Add sourceInfo field to annotate server API response
- Add _site/, public/, out/, .docusaurus/, .jekyll-cache/,
  storybook-static/ to FILE_BROWSER_EXCLUDED

For provenance purposes, this commit was AI assisted.

* feat(annotate): source attribution badge for HTML/URL annotations

Show a subtle badge in DocBadges displaying the URL hostname or HTML
filename for converted content. Thread sourceInfo from API response
through App → Viewer → DocBadges.

Also update Pi extension to accept HTML-only folders in annotate mode.

For provenance purposes, this commit was AI assisted.

* test: update CLI help text assertion for HTML/URL annotate support

For provenance purposes, this commit was AI assisted.

* fix(annotate): address PR review findings

Security:
- Add project-root containment check for HTML files in /api/doc handler
  using exported isWithinProjectRoot() from resolve-file.ts
- Blocks path traversal via absolute paths or ../ escapes

isLocalUrl fixes:
- Add bracketed IPv6 loopback [::1] detection
- Replace hostname.startsWith('10.') with proper IPv4 regex to avoid
  matching public hostnames like 10.example.com

Revert Pi extension change:
- Pi server doesn't implement HTML file browsing or conversion yet
- Keep Pi folder validation markdown-only until both implementations
  are updated per CLAUDE.md guidelines

Cleanup:
- Remove dead el.children || el.childNodes fallback in table rule
- Extract hostnameOrFallback() helper to @plannotator/shared/project
  replacing duplicated try/catch IIFEs in DocBadges and index.ts

For provenance purposes, this commit was AI assisted.

* feat(annotate): Pi extension HTML annotation parity

Bring the Pi extension to full parity with the Bun server for HTML
annotation support:

- Vendor html-to-markdown and url-to-markdown via vendor.sh
- walkMarkdownFiles now scans .html/.htm alongside markdown
- handleDocRequest converts HTML files on-demand via Turndown with
  isWithinProjectRoot containment check
- serverAnnotate includes sourceInfo in /api/plan response
- index.ts supports URL detection (Jina Reader + fallback), HTML file
  detection with Turndown conversion, folder HTML validation, and 10MB
  file size guard
- openMarkdownAnnotation accepts and threads sourceInfo
- Add turndown as a Pi extension dependency

For provenance purposes, this commit was AI assisted.

* fix(pi): Obsidian vault walks stay markdown-only, add try/catch for HTML

- Add extensions param to walkMarkdownFiles (default: HTML-inclusive)
- Obsidian callers pass /\.mdx?$/i to match Bun server behavior
- Add try/catch around HTML file reads in handleDocRequest

For provenance purposes, this commit was AI assisted.

* fix(annotate): address second review — base-block traversal, metadata IP, dead code

Security:
- Add isWithinProjectRoot check to the base-relative block for HTML
  files in both Bun and Pi /api/doc handlers. Previously HTML files
  served via the base query param bypassed the containment guard.
- Add 169.254.0.0/16 (link-local / cloud metadata) to isLocalUrl
  private IP ranges

Cleanup:
- Remove dead hostname === "[::1]" check (WHATWG URL parser strips
  brackets; hostname === "::1" already handles it)
- Remove dead parent?.childNodes fallback in table cell() function

For provenance purposes, this commit was AI assisted.

* refactor(annotate): replace custom table rules with turndown-plugin-gfm

Drop ~60 lines of hand-rolled GFM table conversion that had a bug
(tables without explicit <thead> produced invalid GFM). Use the
official turndown-plugin-gfm plugin (24KB) which correctly handles
all table patterns plus adds strikethrough and task list support.

For provenance purposes, this commit was AI assisted.

* fix(annotate): handle all CommonMark backslash escapes in InlineMarkdown

Expand the backslash escape regex to cover all CommonMark-defined
escapable characters (. ) - # > + | { } &), not just the subset
the parser uses for formatting. Fixes literal backslashes appearing
in rendered output for Turndown-escaped content like "1\." → "1.".

For provenance purposes, this commit was AI assisted.

* fix(annotate): prevent SSRF via redirect to private/local URLs

Replace redirect: "follow" with redirect: "manual" in fetchViaTurndown
and validate each redirect hop against isLocalUrl. Blocks attacks where
an external URL redirects to cloud metadata endpoints (169.254.169.254)
or other private IPs. Limits redirect chain to 10 hops.

For provenance purposes, this commit was AI assisted.

* chore: update lockfile for turndown-plugin-gfm in Pi extension

bun install needed to resolve turndown-plugin-gfm in the Pi extension
workspace after adding it to apps/pi-extension/package.json.

For provenance purposes, this commit was AI assisted.

* fix(annotate): switch to @joplin/turndown-plugin-gfm, fix TS errors

Replace unmaintained turndown-plugin-gfm (2017, v1.0.2) with the
actively maintained Joplin fork (2025, v1.0.64, 16KB).

Fix TypeScript errors that broke CI:
- Add @ts-expect-error for untyped @joplin/turndown-plugin-gfm import
- Restructure fetchViaTurndown redirect loop to avoid uninitialized
  variable — first fetch before loop, loop only for redirects

For provenance purposes, this commit was AI assisted.

* fix(annotate): use proper declarations.d.ts instead of ts-expect-error

Add declarations.d.ts for @joplin/turndown-plugin-gfm with typed
function signatures, remove the ts-expect-error suppression.

For provenance purposes, this commit was AI assisted.

* fix: explicitly include declarations.d.ts in shared tsconfig

CI's tsc wasn't finding the ambient module declaration with implicit
include. Add explicit include to ensure declarations.d.ts is always
picked up regardless of environment.

For provenance purposes, this commit was AI assisted.

* fix: use ts-expect-error for @joplin/turndown-plugin-gfm types

CI's tsc does not pick up ambient declarations.d.ts files despite
local tsc finding them — likely a module resolution discrepancy
between environments. Revert to @ts-expect-error which passes in
both CI and local typecheck.

For provenance purposes, this commit was AI assisted.

* fix(annotate): body size limit for URL fetches, redirect error, file: protocol

- Add 10MB body size limit to both Jina and fetch+Turndown URL paths,
  matching the local HTML file guard. Streams response body and aborts
  if limit exceeded.
- Distinguish "Too many redirects" from a genuine 3xx response after
  redirect loop exhaustion.
- Add file: to the dangerous protocol blocklist in sanitizeLinkUrl.

For provenance purposes, this commit was AI assisted.

* fix(annotate): HTML folder outside cwd, HTML linked doc navigation

- Remove containment check from base-relative block for HTML files in
  both Bun and Pi /api/doc handlers. Matches markdown behavior so HTML
  files in annotated folders outside cwd are served correctly.
  Standalone block (no base) retains its cwd check as fallback.
- Widen isLocalMd → isLocalDoc to treat .html/.htm links as linked
  documents. Clicking [Next](next.html) in a converted page now opens
  it via /api/doc with Turndown conversion instead of a new browser tab.

For provenance purposes, this commit was AI assisted.

* fix(annotate): full loopback range, drain redirect bodies, document env vars

- Expand loopback check from just 127.0.0.1 to the full 127.0.0.0/8
  range so all loopback addresses skip Jina Reader
- Cancel redirect response body before re-fetching to avoid leaking
  TCP connections back to the pool
- Document PLANNOTATOR_JINA and JINA_API_KEY in CLAUDE.md env var table

For provenance purposes, this commit was AI assisted.

* fix(annotate): IPv6 loopback, readBodyWithLimit fallback, env var docs, comments

- Add [::1] back to isLocalUrl — WHATWG URL hostname getter preserves
  brackets for IPv6 (verified: Bun and Node both return "[::1]").
  Add comment explaining the empirical verification so future reviewers
  don't re-flag.
- Fix readBodyWithLimit null-body fallback to still enforce the 10MB
  limit via text length check instead of silently falling through.
- Document PLANNOTATOR_JINA and JINA_API_KEY in AGENTS.md env var table
  (CLAUDE.md is a symlink to AGENTS.md).
- Add comments to base-relative blocks in both Bun and Pi handleDoc
  explaining the intentional lack of containment check (matches
  pre-existing markdown behavior, base is set server-side).

For provenance purposes, this commit was AI assisted.

* fix(annotate): block IPv4-mapped IPv6 and private IPv6 ranges in isLocalUrl

Add PRIVATE_IPV6 regex matching bracketed IPv6 private/reserved ranges:
- ::ffff: (IPv4-mapped — embeds private IPv4 as hex, e.g. [::ffff:c0a8:1])
- fe80: (link-local)
- fc00::/7 (unique-local, covers fc00:: through fdff::)

Closes the redirect-SSRF bypass where a public URL redirects to a
private address expressed as IPv4-mapped IPv6, e.g.
http://[::ffff:169.254.169.254]/latest/meta-data/

For provenance purposes, this commit was AI assisted.

* fix(annotate): document IPv6 hostname verification, sourceInfo type, annotate flow

- Expand isLocalUrl comment with full empirical verification table
  showing actual hostname getter output for every IPv6 format in both
  Bun and Node — prevents false-positive review findings about brackets
- Add sourceInfo to /api/plan response type in App.tsx for type safety
- Update CLAUDE.md annotate flow diagram to reflect HTML/URL/folder
  input types

For provenance purposes, this commit was AI assisted.

* fix(annotate): escape \(, cancel response bodies on error, doc sourceInfo

- Add ( to backslash escape regex alongside existing ) — Turndown
  emits \( in link-adjacent contexts
- Cancel response body before throwing on !res.ok in both fetchViaJina
  and fetchViaTurndown error paths (redirect loop already did this)
- Document sourceInfo field in AGENTS.md annotate server API table

For provenance purposes, this commit was AI assisted.

* fix(annotate): skip base injection for URL annotations, body cleanup

- Skip dirname(filePath) base injection when filePath is a URL in both
  Bun and Pi annotate servers. dirname on a URL string produces a
  nonsensical filesystem path, causing linked doc clicks to 404.
  URL annotations now let links open normally instead.
- Cancel response body before throwing on content-type mismatch and
  content-length overflow in fetchViaTurndown/readBodyWithLimit.
- Fix double parseInt in readBodyWithLimit content-length check.
- Correct AGENTS.md flow diagram: OpenCode not yet implemented for
  HTML/URL annotation.

For provenance purposes, this commit was AI assisted.

* feat(annotate): OpenCode HTML file and URL annotation support

Add URL detection (Jina Reader + fallback), HTML file detection with
Turndown conversion, 10MB file size guard, and sourceInfo threading
to OpenCode's handleAnnotateCommand. Uses the same shared utilities
as the Bun CLI and Pi extension.

OpenCode uses the Bun server directly (startAnnotateServer from
@plannotator/server/annotate), so no server-side changes needed —
only the command handler routing was missing.

Note: folder annotation mode is not added (OpenCode didn't have it
before this PR for markdown either — separate scope).

For provenance purposes, this commit was AI assisted.

* chore(annotate): update slash command description, align fetch log messages

- OpenCode plannotator-annotate.md description now mentions HTML/URL
- Align fetch progress messages across all three clients: all now show
  "(via Jina Reader)" or "(via fetch+Turndown)" consistently

For provenance purposes, this commit was AI assisted.

* fix(annotate): skip conversion for .md URLs, wikilink HTML targets, cleanup

- URLs ending in .md/.mdx are fetched raw — no Jina, no Turndown.
  Content is already markdown. Removes text/plain from fetchViaTurndown
  content-type whitelist since .md URLs are now short-circuited.
- Wikilink regex widened to preserve .html/.htm targets instead of
  appending .md (e.g. [[page.html]] no longer becomes page.html.md)
- Remove redundant existsSync before statSync in OpenCode handler

For provenance purposes, this commit was AI assisted.

* test(annotate): add htmlToMarkdown conversion tests

Tests cover the core conversion utility that all three clients depend on:
- Basic HTML → markdown (headings, paragraphs, links, code blocks)
- Tables with and without <thead> (the GFM plugin bug that was caught)
- Script/style/noscript stripping
- Strikethrough (GFM)
- Empty HTML handling
- Dangerous links preserved (sanitization is in the renderer, not here)

For provenance purposes, this commit was AI assisted.

* fix(annotate): check content-type before treating .md URLs as raw markdown

URLs ending in .md/.mdx (e.g. GitHub's viewer page for README.md)
may return HTML instead of raw markdown. fetchRawText now checks the
response content-type — if the server returns HTML, returns null so
the caller falls through to Jina/Turndown for proper conversion.

For provenance purposes, this commit was AI assisted.

* fix(annotate): add SSRF redirect protection to fetchRawText

fetchRawText (for .md/.mdx URLs) was using default redirect: "follow"
with no isLocalUrl validation on redirect hops — a .md URL redirecting
to 169.254.169.254 would be followed and credentials returned as
"markdown". Now uses redirect: "manual" with per-hop isLocalUrl checks,
matching fetchViaTurndown's SSRF protection.

For provenance purposes, this commit was AI assisted.
2026-04-12 18:56:28 -07:00
Michael Ramos 3f3b0f63cc fix: pin Bun to 1.3.11 to fix macOS binary codesign regression (Bun 1.3.12)
Bun 1.3.12 introduced a regression where cross-compiled macOS binaries
lose their ad-hoc linker signature, causing macOS Sequoia to SIGKILL
them immediately. Pin bun-version to 1.3.11 across all three workflow
jobs (test, build, npm-publish) until the Bun issue is resolved.

Fixes #541

Bumps version to 0.17.9.
2026-04-11 12:00:07 -07:00
Michael Ramos 6677e3f280 chore: bump version to 0.17.8 2026-04-10 17:27:09 -07:00
Michael Ramos 0287b96b63 feat(review): configurable default diff type (#531)
feat(review): configurable default diff type with first-run setup

Add `defaultDiffType` as a persistent user setting (cookie + config.json) with 'unstaged' as the default, matching `git diff` semantics. A first-run setup dialog prompts users to choose their preferred default on first review session. The setting is also available in Settings > Display.

Entry points (hook, opencode, pi-extension) read the config via `resolveDefaultDiffType()` instead of hardcoding. The setup dialog applies the chosen diff type to the active review immediately. P4 users are excluded from the Git-specific dialog.

Based on the community contribution in #521 by Hendrik Richert.

Co-authored-by: Hendrik Richert <hendrik.richert@swisscom.com>
2026-04-10 14:54:21 -07:00
Vladyslav Hrabovyi 3b1b3317ae feat(review,annotate): add Close button to exit sessions without feedback (#523)
Adds a Close button to review and annotation sessions so users can exit
cleanly without sending feedback or killing the agent. Works across all
agent origins and includes a warning dialog when annotations would be lost.

Fixes #522

Co-authored-by: gwynnnplaine <vladyslav.hrabovyii@gmail.com>
2026-04-09 19:22:01 -07:00
Michael Ramos bac424d056 chore: bump version to 0.17.7
For provenance purposes, this commit was AI assisted.
2026-04-09 09:35:27 -07:00
Michael Ramos 93b09c7dc2 chore: bump version to 0.17.6
For provenance purposes, this commit was AI assisted.
2026-04-09 08:05:34 -07:00
Michael Ramos 29fc7920f8 chore: bump version to 0.17.5
For provenance purposes, this commit was AI assisted.
2026-04-09 07:08:01 -07:00
Michael Ramos 93b4a4a070 chore: bump version to 0.17.4 2026-04-08 16:20:24 -07:00
Michael Ramos 667eb12e8a chore: bump version to 0.17.3
For provenance purposes, this commit was AI assisted.
2026-04-08 07:39:12 -07:00
Michael Ramos ede9cb77d8 chore: bump version to 0.17.2
Includes bun.lock update for @pierre/diffs dep added in #509.

For provenance purposes, this commit was AI assisted.
2026-04-08 07:07:41 -07:00
Michael Ramos d710284020 chore: bump version to 0.17.1
For provenance purposes, this commit was AI assisted.
2026-04-06 18:14:11 -07:00
Michael Ramos 566df72f11 chore: bump version to 0.17.0
For provenance purposes, this commit was AI assisted.
2026-04-06 12:36:15 -07:00
foxytanuki 26364543b2 fix(remote): support explicit local override (#481) 2026-04-04 13:17:16 -07:00
Michael Ramos 70ad54dd70 chore: bump version to 0.16.7
For provenance purposes, this commit was AI assisted.
2026-04-02 15:33:48 -07:00
Michael Ramos a48fd8afb5 chore: bump version to 0.16.6
For provenance purposes, this commit was AI assisted.
2026-04-02 10:57:13 -07:00
Michael Ramos 070f75f804 chore: bump version to 0.16.5
For provenance purposes, this commit was AI assisted.
2026-04-01 22:13:51 -07:00
Michael Ramos 6735266d66 chore: bump version to 0.16.4 2026-04-01 15:08:26 -07:00
Michael Ramos fad822e6ca chore: bump version to 0.16.2 2026-03-30 21:49:08 -07:00
Michael Ramos b0980ef928 fix(opencode): remove verbose logs that flood the TUI (#440)
Remove writeRemoteShareLink stderr output from the OpenCode plugin —
the base64 share URL was flooding the TUI on remote sessions. Also
strip leftover console.log debug statements from the PR viewed files
feature in the review server.

Closes #435

For provenance purposes, this commit was AI assisted.
2026-03-30 10:51:27 -07:00
Michael Ramos a633e70597 chore: bump version to 0.16.1 2026-03-30 09:13:52 -07:00
Michael Ramos a88da925de chore: bump version to 0.16.0 2026-03-29 22:13:09 -07:00
Michael Ramos 8280cc0aca perf(opencode): lazy-load HTML to fix plugin startup time (#411)
* perf(opencode): lazy-load HTML to cut plugin startup from ~160ms to ~35ms

The two SPA HTML files (~20 MB combined) were inlined as string literals
via Bun's `with { type: "text" }` imports, forcing Bun to parse a 21 MB
bundle at module load time. Replace with lazy readFileSync getters and
background preload during plugin init, reducing the bundle to 0.81 MB.

Closes #410

For provenance purposes, this commit was AI assisted.

* test: add OpenCode plugin startup benchmark script

Measures real-world startup time across three scenarios:
no plugin, published npm, and local optimized. Uses
`opencode run` for non-interactive measurement and parses
log timing.

For provenance purposes, this commit was AI assisted.

* fix(bench): resolve project dir to repo root and auto-build before scenario 3

PROJECT_DIR pointed to tests/ instead of the repo root, so the local
plugin path was invalid and scenario 3 silently measured a no-plugin run.
Also auto-run build:opencode when dist/index.js is missing.

For provenance purposes, this commit was AI assisted.
2026-03-27 20:09:09 -07:00
Michael Ramos 9746344779 chore: bump version to 0.15.5
For provenance purposes, this commit was AI assisted.
2026-03-26 22:34:24 -07:00
Michael Ramos d49fb49281 chore: bump version to 0.15.2
For provenance purposes, this commit was AI assisted.
2026-03-25 00:34:25 -07:00
Michael Ramos 5e36960698 feat: add /plannotator-archive slash command (#388)
* feat: add /plannotator-archive slash command for Claude Code and OpenCode

The archive browser was only accessible via CLI (plannotator archive) and
Pi (/plannotator-archive). This adds slash command parity so users can
browse saved plan decisions from within Claude Code and OpenCode sessions.

Relates to #362

For provenance purposes, this commit was AI assisted.

* fix: re-fetch archive plans with custom path in standalone mode

The server pre-loads plans from ~/.plannotator/plans/ (default) because
no runtime passes customPlanPath. For users with a custom save directory,
the plan list was wrong and clicking any plan 404'd. Calling fetchPlans()
after init() re-fetches with the user's cookie-based custom path setting.

For provenance purposes, this commit was AI assisted.
2026-03-24 15:00:30 -07:00
Michael Ramos afc476c310 chore: bump version to 0.15.0
For provenance purposes, this commit was AI assisted.
2026-03-24 01:25:10 -07:00