GHSA-vfcm-843v-w6v3.
`retry_with_browser_use_agent` defaulted `allowed_domains` to `[]` when the
client omitted the argument, and then forwarded that value to
`BrowserProfile(allowed_domains=[])`. `SecurityWatchdog` interprets the empty
list as "no allowlist configured — allow every URL", silently disabling any
admin-configured allowlist on the underlying profile.
Default to `None` so admin profile defaults are preserved when the client
omits the argument, and treat an explicit empty list the same as omitting
(falsy override is not applied). Schema default removed and description
updated so MCP clients see the new contract.
The MCP server hardcoded aws_sso_auth=True, breaking all non-SSO
Bedrock users (IAM key-based auth). Now reads aws_sso_auth from
llm_config with a default of False, letting boto3's standard
credential chain work correctly.
Also replaced a Chinese-language comment with an English one.
Fixes#4148
The browser_click tool used oneOf at the top level of inputSchema to
express the index-vs-coordinates constraint. Claude's API (and other
strict JSON Schema validators) reject oneOf/allOf/anyOf at the top
level of a tool input schema with a 400 error, which cascades and
breaks all MCP tools registered in the same session.
The _click() handler already validates at runtime and returns a clear
error string when neither index nor coordinates are provided, so the
oneOf constraint was redundant. Move the constraint into the property
descriptions instead.
Fixes#4211
- Introduced a utility function `create_task_with_error_handling` to manage asyncio tasks with proper exception logging and suppression options.
- Updated multiple components, including `SessionManager`, `BrowserSession`, and various watchdogs, to utilize the new error handling mechanism for background tasks.
- Enhanced overall robustness of asynchronous operations by ensuring exceptions are logged and handled appropriately, improving maintainability and debugging capabilities.
- Changed 'type': 'str' to 'type': 'string' for tab_id parameters
- Fixes JSON Schema draft 2020-12 validation error with Claude Code
- Added test case to validate JSON schema correctness
🤖 Generated with [Claude Code](https://claude.ai/code)
Co-Authored-By: Claude <noreply@anthropic.com>