Commit Graph

58 Commits

Author SHA1 Message Date
Saurav Panda 92defb6eae fix(mcp): default retry_with_browser_use_agent allowed_domains to None
GHSA-vfcm-843v-w6v3.

`retry_with_browser_use_agent` defaulted `allowed_domains` to `[]` when the
client omitted the argument, and then forwarded that value to
`BrowserProfile(allowed_domains=[])`. `SecurityWatchdog` interprets the empty
list as "no allowlist configured — allow every URL", silently disabling any
admin-configured allowlist on the underlying profile.

Default to `None` so admin profile defaults are preserved when the client
omits the argument, and treat an explicit empty list the same as omitting
(falsy override is not applied). Schema default removed and description
updated so MCP clients see the new contract.
2026-05-18 13:38:13 -07:00
Laith Weinberger 4476f6e16e fix input clear fallbacks and clarify clear-then-type behavior 2026-04-15 17:31:04 -04:00
Laith Weinberger df4e2f9f15 fix: handle BrokenPipeError gracefully when MCP client disconnects 2026-04-12 11:34:39 -04:00
Laith Weinberger 674547a414 fix: guard against missing stdin in MCP stdio server startup 2026-04-08 17:21:11 -04:00
laithrw 6094cddd90 Merge branch 'main' into fix/mcp-browser-click-oneof-schema 2026-03-26 10:59:46 -04:00
Laith Weinberger 086f18cf53 lint 2026-03-01 16:05:07 -05:00
Laith Weinberger 3a03d14f9b use MCP ImageContent for screenshots instead of embedding base64 in JSON 2026-03-01 15:59:18 -05:00
laithrw 2a955de5c9 Merge branch 'main' into fix/mcp-aws-sso-auth 2026-03-01 14:11:25 -05:00
Laith Weinberger 50b22b2472 fix(mcp): use configured default model instead of hardcoding gpt-4o 2026-03-01 14:03:42 -05:00
Br1an67 db2f7d94be fix: read aws_sso_auth from config instead of hardcoding True
The MCP server hardcoded aws_sso_auth=True, breaking all non-SSO
Bedrock users (IAM key-based auth). Now reads aws_sso_auth from
llm_config with a default of False, letting boto3's standard
credential chain work correctly.

Also replaced a Chinese-language comment with an English one.

Fixes #4148
2026-03-01 14:23:47 +08:00
gabros20 217b451dc5 fix(mcp): remove oneOf from browser_click schema, breaking Claude API clients
The browser_click tool used oneOf at the top level of inputSchema to
express the index-vs-coordinates constraint. Claude's API (and other
strict JSON Schema validators) reject oneOf/allOf/anyOf at the top
level of a tool input schema with a 400 error, which cascades and
breaks all MCP tools registered in the same session.

The _click() handler already validates at runtime and returns a clear
error string when neither index nor coordinates are provided, so the
oneOf constraint was redundant. Move the constraint into the property
descriptions instead.

Fixes #4211
2026-02-25 20:46:06 +01:00
Saurav Panda 552b2f3b60 fixed ruff format 2026-02-19 18:38:23 -08:00
Saurav Panda a3eee8edfe fixed mcp issue 2026-02-19 15:55:22 -08:00
Saurav Panda 3f63677756 new direct cli mode 2026-02-19 10:18:12 -08:00
Laith Weinberger 1737c5bea4 lint 2026-02-08 16:36:45 -05:00
Laith Weinberger 4d05218d7d fix: redirect logging to stderr so MCP stdio doesn't break (#2748) 2026-02-08 16:29:05 -05:00
mertunsall 839ef52d3e quick hack 2025-11-26 10:40:34 -08:00
reformedot b4e9ffa984 refactor: implement error handling for asyncio tasks across various components
- Introduced a utility function `create_task_with_error_handling` to manage asyncio tasks with proper exception logging and suppression options.
- Updated multiple components, including `SessionManager`, `BrowserSession`, and various watchdogs, to utilize the new error handling mechanism for background tasks.
- Enhanced overall robustness of asynchronous operations by ensuring exceptions are logged and handled appropriately, improving maintainability and debugging capabilities.
2025-11-11 17:27:54 -08:00
zhenhuae 9bfdb4ac85 feat: support amazon bedrock model fix check style 2025-10-14 21:03:09 +08:00
zhenhuae a95d4db9c5 feat: support amazon bedrock model fix check style 2025-10-14 21:03:09 +08:00
zhenhuae 9a7eeb7eab feat: support amazon bedrock model 2025-10-14 21:03:09 +08:00
Magnus Müller b53a7c116a Update outdated function names 2025-10-05 19:12:52 -07:00
Mert Unsal f0beb014a9 Merge branch 'main' into fix/MCP-Server-extract_content-always-returning-"No-content-extracted" 2025-09-23 03:17:54 +02:00
Chris Schnabl 03608b62a2 Remove unused paramter 2025-09-21 21:38:42 -07:00
Saurav Panda 126d800df4 remove sensitive data from agent history and logging 2025-09-16 14:41:24 -07:00
Saurav Panda 43359143fc fix: session management tool placement 2025-09-07 20:14:23 -07:00
Saurav Panda 12a0c76a32 feat: fix MCP server JSON-RPC corruption and removed http mode 2025-09-07 19:22:59 -07:00
lienminhquang 491df67c3e fix: typo
Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
2025-09-03 09:30:30 +07:00
lienminhquang 64b220453d Merge branch 'browser-use:main' into fix/MCP-Server-extract_content-always-returning-"No-content-extracted" 2025-09-02 12:37:34 +07:00
quanglm 8406528c08 fix: MCP Server extract_content always returning 'No content extracted' 2025-09-02 12:34:17 +07:00
krishna f430e2fc69 Minor documentation changes for consistency. 2025-08-27 20:36:52 +05:30
Magnus Müller f36279b7f3 Merge remote-tracking branch 'origin/main' into dev 2025-08-27 00:41:27 -07:00
Magnus Müller 78cb7e5466 Remove 25 unused parameters 2025-08-26 16:19:53 -07:00
Magnus Müller caa0e7ef1b Rename controller to tools instances 2025-08-26 11:30:39 -07:00
Magnus Müller 13dd73b23a Update Tool imports in docs, readme, and docstrings 2025-08-26 11:13:27 -07:00
Magnus Müller e89e78842c Rename controller file to tools 2025-08-26 11:06:28 -07:00
Magnus Müller 2a83442f17 Rename Controller to Tools 2025-08-26 11:04:16 -07:00
Tyler Folkman b2da2fec89 fix: correct JSON schema type definitions in MCP server tools
- Changed 'type': 'str' to 'type': 'string' for tab_id parameters
- Fixes JSON Schema draft 2020-12 validation error with Claude Code
- Added test case to validate JSON schema correctness

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-08-24 10:04:19 -06:00
Nick Sweeting 99a0e5a3bd rename ClickElementEvent.new_tab to while_holding_ctrl 2025-08-16 16:25:15 -07:00
Nick Sweeting 8d86832095 fix SwitchTab by using TargetID for all tab_ids 2025-08-15 16:45:27 -07:00
Anirudha619 eaad171101 add StreamableHttp to mcp 2025-08-14 00:32:50 +05:30
Nick Sweeting 3bb8fb0fee improve focus tracking 2025-08-08 07:15:04 -07:00
Nick Sweeting db4c4e9b49 fix duplicate typed keystrokes 2025-08-08 04:13:44 -07:00
Nick Sweeting e9add2d745 add screenshot watchdog 2025-08-07 17:49:25 -07:00
Nick Sweeting 46dd9bd584 wip 2025-08-05 17:45:48 -07:00
Nick Sweeting 328a4b5be4 Merge branch 'feature/new-dom-extraction-layer' into local-remote-split 2025-08-05 03:12:48 -07:00
Gregor Žunič 0aa3d54233 Merge commit '9b882faa10c54be5a870cc5d8abd6ddb19d0682f' into feature/new-dom-extraction-layer 2025-08-02 11:41:28 -07:00
Nick Sweeting ebc3a3846f wip cleanup flow] 2025-07-31 22:10:25 -07:00
Nick Sweeting 6445a746aa fix uvx browser-use examples to use cli optionals 2025-07-29 11:16:05 -07:00
Magnus Müller c688056d37 Wait before get state so that we can check require_healthy_browser for get_state and dont check page in _get_updated_state 2025-07-18 23:09:41 +02:00