Commit Graph

832 Commits

Author SHA1 Message Date
jackwener d53d2a3c76 Fix automation window not closing on command failure
The error path in executeCommand did not call page.closeWindow(),
leaving the automation window open until the extension's idle timer
fires. On Windows, MV3 service worker suspension makes this timer
unreliable, causing windows to linger indefinitely.

Now closeWindow is called after diagnostic collection but before
rethrowing, ensuring the window is closed on both success and failure.
2026-04-13 16:41:47 +08:00
jakevin c42b040af4 Rename chatgpt adapters: desktop → chatgpt-app, web → chatgpt (#989)
* Rename chatgpt adapters: desktop → chatgpt-app, web → chatgpt

Aligns with existing `-app` suffix convention (discord-app, doubao-app):
- clis/chatgpt/ (desktop, AppleScript) → clis/chatgpt-app/
- clis/chatgptweb/ (browser, chatgpt.com) → clis/chatgpt/
- electron-apps.ts: chatgpt → chatgpt-app
- Updated all docs and README references

Closes #283

* Fix review findings: update cli-manifest.json and skill docs

- cli-manifest.json: update site/modulePath/sourceFile from chatgpt to chatgpt-app
- skills/opencli-usage/desktop.md: update commands from chatgpt to chatgpt-app
2026-04-13 14:33:32 +08:00
jakevin 79a15e8353 Remove unused OPENCLI_SKIP_FETCH env var (#987)
The adapter sync already has version caching (skips if same version)
and makes no network requests, so this opt-out flag adds no value.
2026-04-13 14:09:10 +08:00
jakevin 6d769ff354 docs: document undocumented environment variables (#983)
Add missing env vars to both README and README.zh-CN:
- OPENCLI_SKIP_FETCH: skip adapter sync on global install
- OUTPUT: override output format (json/yaml/table)
- DEBUG=opencli: internal debug logging
- DEBUG_SNAPSHOT: DOM snapshot debug output
2026-04-13 14:01:46 +08:00
jakevin 988ed19223 fix: clean up stale .yaml adapter files from older versions (#953) (#986)
* fix: clean up stale .yaml adapter files from older versions (#953)

Users upgrading from v1.6.x retain .yaml adapter files in
~/.opencli/clis/ that trigger "Ignoring YAML adapter" warnings on
every run. The hash-based sync only tracks .js files, so these
legacy .yaml files are never cleaned up.

Add a cleanup step (3b) that removes .yaml/.yml files from user
adapter directories when the corresponding site exists in the
official package (i.e., the site has been migrated to .js).

* fix(fetch-adapters): narrow stale yaml cleanup
2026-04-13 13:17:27 +08:00
jakevin 51bc48ec61 feat: decouple extension version from CLI version (#985)
* feat: decouple extension version from CLI version

Extension and CLI had tightly coupled version numbers (both 1.7.2),
requiring manual sync across 3 files on every release. This decouples
them so each can release independently.

Changes:
- Extension version reset to 1.0.0 with independent versioning
- Extension sends compatRange (e.g. ">=1.7.0") in hello message
  so doctor can check CLI/extension compatibility
- Daemon stores and exposes extensionCompatRange via /status
- Doctor uses compatRange for compatibility checks (falls back to
  major-version check for older extensions without compatRange)
- Doctor shows extension update availability from cached GitHub
  Releases data
- release.yml always builds and attaches extension zip to every
  CLI release, so users always find both in the same release page
- build-extension.yml triggers on ext-v* tags (not v*) to avoid
  duplicate builds

* fix: version extension release assets
2026-04-13 12:43:34 +08:00
jakevin 72bc86cf41 fix: code audit round 2 — safety, hot-reload, error diagnostics (#982)
* fix: code audit round 2 — pruneEmptyDirs, evaluateWithArgs, hot-reload, error cause chain

1. pruneEmptyDirs: use path.relative() instead of startsWith() to prevent
   false boundary matches on overlapping directory names
2. evaluateWithArgs: add safe evaluate method that auto-serializes args via
   JSON.stringify, preventing injection by design
3. Hot-reload: detect mtime changes on user adapter files in daemon mode,
   invalidate module cache so edits take effect without restart
4. toEnvelope: preserve error cause chain in verbose mode for better
   production debugging

* fix: address review feedback on code audit round 2

- pruneEmptyDirs: resolve() paths before relative() check
- evaluateWithArgs: validate keys are valid JS identifiers
- hot-reload: only bust ESM cache on reload, not first load
- toEnvelope: move cause serialization into toEnvelope itself
  so all consumers (AI agents, MCP tools) get cause chain
2026-04-13 09:36:53 +08:00
jakevin ffb61c51ea fix: address code audit findings (C1-C4, I1, I4, I6) (#981)
* fix: address code audit findings (C1-C4, I1, I4, I6)

Security:
- C1: Fix page.evaluate injection in browser type/select commands and
  6 adapter files by using JSON.stringify for user input interpolation
- C2: Close WebSocket on CDP connect timeout to prevent resource leak
- C3: Reject CDP connect promise on Page.enable failure instead of
  silently swallowing the error

Reliability:
- C4: Guard against corrupted adapter-manifest.json hashes to prevent
  false-positive override deletion
- I1: Throw on pre-navigation failure instead of warn-and-continue
- I4: Use Map<string, Promise<void>> for lazy module loading to prevent
  concurrent double-imports of the same adapter

Performance:
- I6: Replace O(n) registry alias cleanup with O(k) direct deletion

* fix: address self-review findings on PR #981

- C1: add quotes around CSS selector attribute values in browser
  type/select to match other commands (get text/value/attributes)
- C2: clear this._ws in timeout handler to prevent race with open event
- C4: refine corruption guard — treat null/undefined hashes as empty,
  only skip sync for truly invalid types (string, number, array)
2026-04-13 09:24:01 +08:00
AstroHan 5dcbf92a59 fix(douban): classify tv search results correctly (#979) 2026-04-13 08:41:19 +08:00
AstroHan 83dce2430e fix(xiaohongshu): harden anti-detection flows (#980) 2026-04-13 08:40:48 +08:00
Tony Simons 4d1fa8a6e2 feat(clis/chatgptweb): add ChatGPT web image generation command (#973)
* feat(clis/chatgptweb): add ChatGPT web image generation command

Add `opencli chatgptweb image` command that generates images using
ChatGPT web (GPT-4o image generation) and saves them locally.

Features:
- Navigates to chatgpt.com/new with full page reload to ensure clean state
- Uses Playwright's page.type() for reliable text input in TipTap editor
- Closes sidebar if open (covers the chat composer on some layouts)
- Polls for response completion (handles thinking/throttling states)
- Extracts generated images from DOM (backend-api/estuary/content URLs)
- Downloads and saves as PNG/JPEG files to user-specified directory
- Supports --op for output directory and --sd to skip download

Files:
- clis/chatgptweb/image.js: CLI command definition
- clis/chatgptweb/utils.js: DOM helpers, send/wait/export functions

Works cross-platform (Linux/macOS/Windows) via OpenCLI browser automation.

* fix(chatgptweb): stabilize image generation flow

* docs(chatgptweb): add browser adapter guide

---------

Co-authored-by: Tony Simons <tony@tonysimons.dev>
Co-authored-by: jackwener <jakevingoo@gmail.com>
2026-04-12 21:24:03 +08:00
Harvey Yue aa47de726d feat(bilibili): add feed-detail and enhance feed command (#974)
* feat(bilibili): add feed-detail and enhance feed command

* docs: add binance adapter documentation

* docs: add feed-detail command to bilibili docs

* docs: sync bilibili adapter contract for feed-detail

* docs: add ke adapter page for doc coverage

---------

Co-authored-by: jackwener <jakevingoo@gmail.com>
2026-04-12 21:19:12 +08:00
runzhliu 232b6828be feat(ke): add Beike (贝壳找房) adapter with ershoufang, xiaoqu, zufang, chengjiao commands (#975)
Support browsing second-hand houses, neighborhoods, rentals, and
transaction records on ke.com with city/district/price filtering.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-12 16:21:59 +08:00
Ivan Xia 20e024a001 feat(maimai): add talent search with multi-dimensional filters (#977)
* feat(maimai): add talent search with multi-dimensional filters

Add maimai.cn talent search adapter with support for:
- Keyword search (query)
- Company filtering (multiple companies supported)
- School filtering (with 985/211 options)
- Location filtering (province/city)
- Work experience and education level filters
- Industry and position filters
- Direct chat availability
- Sort by relevance, activity, work years, or education

Features:
- Reuses Chrome login session for authentication
- Extracts candidate info: name, job title, company, work history
- Shows work years, education, age, active status
- Displays skill tags and mutual friends count

* fix docs and strategy for maimai adapter

---------

Co-authored-by: jackwener <jakevingoo@gmail.com>
2026-04-12 16:16:55 +08:00
Alex Yang 01957bf654 feat(discord-app): add delete command to remove a message by ID (#976)
* feat(discord-app): add delete command to remove a message by ID

Adds a new `delete` command for the discord-app CLI that deletes a
message in the active channel by its snowflake ID. Uses the UI strategy
to hover the message, open the "More" menu, click "Delete Message", and
confirm the deletion dialog.

* docs: add binance adapter doc and update discord doc with delete command
2026-04-12 16:07:14 +08:00
jakevin 315cc59f8a chore: bump version to 1.7.2 (#972) v1.7.2 2026-04-11 22:14:43 +08:00
jakevin ebe6be945e fix(zsxq): update topic test for group_id parameter added in #963 (#971)
The test mock was missing the evaluate call for getActiveGroupId,
which was added when #963 introduced the group_id parameter.
2026-04-11 22:12:26 +08:00
iiilin b0a019121e feat(weibo): support for-you and following feed types (#959)
* feat(weibo): support for-you and following feed types

* docs: clarify weibo feed types

---------

Co-authored-by: iiilin <19162130+iiilin@users.noreply.github.com>
Co-authored-by: jackwener <jakevingoo@gmail.com>
2026-04-11 22:04:01 +08:00
Paul Zhu c63bad34b0 feat(twitter): add lists command to retrieve user lists (#958)
* feat(twitter): add lists command to retrieve user lists

Add twitter/lists command that fetches Twitter/X lists for a user.
Supports:
- Lists with member and follower counts
- Private/public mode detection
- Default to current user if no user specified
- Works for any Twitter user

* docs: add lists command to twitter commands in README

Add twitter lists command to Built-in Commands table in both
English and Chinese README files

* fix(twitter): parse lists from card DOM instead of locale-specific page text

---------

Co-authored-by: isanwenyu <isanwenyu@users.noreply.github.com>
Co-authored-by: jackwener <jakevingoo@gmail.com>
2026-04-11 21:58:46 +08:00
Hoshea 1ffe12f85e fix(zsxq): accept topic_id as string in getTopicFromResponse (#963)
* fix(zsxq): accept topic_id as string in getTopicFromResponse

The ZSXQ API returns topic_id as a string, but getTopicFromResponse()
only checked for typeof === 'number', causing it to fall through and
return null. This made 'opencli zsxq topic <id>' fail with NOT_FOUND
for all valid topic IDs.

* fix(zsxq): use group-scoped topic endpoint instead of bare /v2/topics/{id}

The ZSXQ API requires topics to be fetched within their group context.
Change /v2/topics/{id} -> /v2/groups/{groupId}/topics/{id} for both
the detail and comments endpoints. Also adds optional --group_id arg.
2026-04-11 21:49:02 +08:00
jakevin 30f216b2c1 fix: include adapter tests in default npm test (#969)
* fix: include adapter tests in default npm test

`npm test` only ran unit + extension projects, so adapter tests
(clis/**/*.test.js) were never exercised by the default test command.
Add --project adapter so they run alongside unit and extension tests.

* test: include adapter project in default npm test
2026-04-11 21:33:50 +08:00
jakevin 3c088da53e refactor: smart sync adapters — hash-based diff instead of full copy (#966)
* refactor: smart sync adapters instead of full copy (#sparse-override)

Replace unconditional full-copy of all adapters to ~/.opencli/clis/ with
hash-based smart sync that only copies files whose content has changed.

Changes:
- fetch-adapters.js: use SHA-256 content hashes to skip unchanged files;
  store per-file hashes in adapter-manifest.json
- discovery.ts: simplify ensureUserAdapters() to only create the directory
  (no longer triggers full copy on first run)
- main.ts: fix fast completion to check manifest file existence instead of
  directory existence (sparse override may have empty user dir)
- cli.ts: add `opencli adapter eject/reset/status` commands for managing
  local adapter overrides
- engine.test.ts: add tests for empty user dir and ensureUserAdapters

* fix: address review blockers — site-level sync + reset --all

1. Fix `adapter reset --all`: change <site> from required to optional
   argument so --all can be used without specifying a site name.

2. Change smart sync from file-level to site-level granularity:
   if any file in a site has changed upstream, overwrite the entire
   site directory. This matches the agreed product semantics — local
   modifications to any file in a site are replaced when upstream
   updates that site.

* fix: delete old site dir before writing updated adapter files

When a site has upstream changes, delete the entire site directory
first, then write the new version. This prevents stale files from
older versions lingering in the user directory.

* fix: reset --all preserves custom sites, only removes official overrides

Blocker 3 fix: reset --all now checks BUILTIN_CLIS to identify official
sites and only deletes those, preserving user-created custom sites.

* refactor: sparse sync deletes local overrides instead of copying new versions

Changed fetch-adapters.js semantics per team agreement:
- When an official site has upstream changes, DELETE the local override
  instead of copying the new version into ~/.opencli/clis/
- Runtime automatically falls back to package baseline
- ~/.opencli/clis/ becomes a true sparse override layer

* fix: reset <site> rejects custom sites, only allows official overrides

Single-site reset now checks BUILTIN_CLIS before deleting, matching
the same protection that reset --all already has.

* fix: reset <site> allows custom sites per product decision

Per @WAWQAQ: explicit single-site reset should work on custom sites too.
Differentiate messaging: official sites say "using official baseline",
custom sites say "removed custom site".

reset --all still only removes official overrides (bulk safety).

* fix: reset --all deletes all local sites including custom per product decision

Per @WAWQAQ: --all should clear the entire local working cache,
including custom sites. Single-site reset already handles both types.
2026-04-11 21:28:40 +08:00
jakevin 00e200b0b7 migrate: move binance adapters from src/clis/ to clis/ (#967)
Binance was the only adapter left in src/clis/ after the TS→JS
migration (PR #928). Move all 11 adapters and the test file to
clis/binance/, strip TypeScript syntax from the test, and switch
the test import to the @jackwener/opencli/pipeline package export.
2026-04-11 21:21:52 +08:00
jakevin 1fd578c404 chore: bump version to 1.7.1 (#965) v1.7.1 2026-04-11 20:28:23 +08:00
jakevin b0fd95279c docs: add CHANGELOG.md entry for v1.7.0 (#955)
Comprehensive release notes covering all changes since v1.6.1:
- Breaking changes: Node >= 21, YAML deprecated, .ts no longer loaded,
  error output as YAML envelope, tabId → targetId, operate → browser
- 10+ new adapters, 15+ adapter enhancements
- Major refactors: JS-first adapters, registry validation, strategy normalization
- Performance: P0 optimizations, fast-path completion, browser pipeline
- Upgrade guide with step-by-step migration instructions
2026-04-11 13:51:51 +08:00
jakevin 892ddcb19f docs: fix stale .ts adapter references in skills and guides (#954)
* docs: fix stale .ts adapter references in skills and guides

All adapters are now .js files. Update references in:
- opencli-oneshot SKILL.md (7 instances)
- opencli-autofix SKILL.md (1 instance)
- opencli-explorer references (15 instances)
- electron-app-cli guide (5 instances)

* docs: fix stale YAML/TS references in READMEs and zh docs

- Plugin type column: YAML/TS → JS (all 4 plugins have JS conversion PRs)
- synthesize command: "YAML adapters" / "TS adapters" → "JS adapters"
- zh index: remove "YAML 声明式" reference
- zh README: add missing vk plugin entry

* docs: fix remaining .ts references found in review

- electron-app-cli.md: "TypeScript desktop adapter" → "desktop adapter", file layout .ts → .js
- adapter-templates.md: section title "提取 utils.ts" → "提取 utils.js"
- opencli-explorer SKILL.md: "写 following.ts" → "写 following.js"
2026-04-11 13:13:27 +08:00
jakevin ee8d7cce77 docs: fix stale adapter counts and .ts reference (#950)
- README.md: "70+ pre-built adapters" → "87+"
- docs/comparison.md: "73+ sites" → "87+", ".ts adapter" → ".js adapter"
2026-04-11 13:13:21 +08:00
jakevin 420dc0f3c8 fix: DEBUG_SNAPSHOT should work without DEBUG=opencli (#952)
log.debug() requires DEBUG=opencli to output, which means
DEBUG_SNAPSHOT=1 alone no longer shows snapshot fallback diagnostics.
Use process.stderr.write directly since the DEBUG_SNAPSHOT guard
already controls when this diagnostic fires.
2026-04-11 13:13:14 +08:00
jakevin 0f90b42f71 fix: warn users when .ts adapters are found but not loaded (#951)
Users who created custom .ts adapters in ~/.opencli/clis/ will see
their commands silently disappear after upgrading to the JS-only
version. Add an explicit warning so they know to convert to .js.
2026-04-11 13:13:07 +08:00
jakevin 2469d12efd fix: resolve alias target correctly in validate command (#949)
The alias resolution logic checked `!registry.has(target)` before
calling `registry.get(target)`, which always returned undefined.
Moreover, aliases registered as `site/alias` keys meant `registry.has`
returned true, skipping the block entirely. The canonical name was
never resolved, so `validate site/alias` silently checked 0 commands.

Simplify to always resolve via `registry.get(target)` which handles
both canonical keys and alias keys correctly.
2026-04-11 13:13:02 +08:00
Harvey Yue 25014f1067 fix(bilibili): add missing domain for following cli (#947) 2026-04-11 12:36:41 +08:00
jakevin 63b7b291ab fix: clean up stale .ts adapter files during upgrade (#948)
Older versions (pre-1.7.1) shipped adapters as .ts files. When users
upgrade to a .js-only version, the old .ts files are left orphaned in
~/.opencli/clis/. Add a cleanup step that removes .ts files when a
corresponding .js official adapter exists.
2026-04-11 12:36:02 +08:00
jakevin 4a0b8054b2 fix: batch quality improvements — dedupe completion, unify logging, fix docs (#945)
* fix: batch quality improvements — dedupe completion, unify logging, fix docs

1. Extract shared completion code (BUILTIN_COMMANDS + shell scripts) into
   completion-shared.ts, eliminating duplication between completion.ts and
   completion-fast.ts.

2. Replace console.error/warn/log with log.* from logger.ts in:
   - daemon.ts (7 occurrences)
   - runtime.ts (1 occurrence)
   - cli.ts browserAction error handler (3 occurrences)
   - base-page.ts snapshot fallback (1 occurrence)
   - download/index.ts cookie warning (1 occurrence)
   - commands/daemon.ts (2 occurrences)

3. Fix Node version in build-extension.yml: 20 → 22 (matches package.json >=21)

4. Fix error handling consistency: tap.ts now throws CliError instead of bare Error

5. Remove 31 duplicate rows in docs/adapters/index.md (grok, gemini, yuanbao,
   notebooklm, doubao, weread + 25 more entries duplicated without .md suffix)

6. Update skill version: opencli-usage SKILL.md 1.6.9 → 1.7.0, adapter count 79 → 87

* fix: update daemon.test.ts to match logger migration

Tests now spy on process.stderr.write (used by log.*) instead of
console.log/console.error (no longer used by daemonStop).

* fix: address review feedback on PR #945

1. base-page.ts: restore DEBUG_SNAPSHOT env guard — log.debug uses a
   different env var (DEBUG=opencli), so keep the original gate to
   avoid breaking existing users.

2. daemon.ts: remove dead `prefix` variable left over from console.error
   migration.
2026-04-11 01:45:00 +08:00
jakevin 575986c656 perf: P0 performance optimizations (#944)
* perf: P0 performance optimizations — VM context reuse, startup parallelization, stealth caching

1. Reuse VM sandbox context in pipeline template engine instead of creating
   a new vm.createContext() on every expression evaluation. This eliminates
   ~0.3ms per call in map/filter loops over large arrays.

2. Cache sanitizeContext() results via WeakMap keyed by object reference.
   In pipeline loops, `args` and `data` are the same object across all
   iterations — the expensive JSON round-trip now runs only once per step.

3. Parallelize independent startup I/O: built-in CLI discovery now runs
   concurrently with ensureUserCliCompatShims and ensureUserAdapters,
   saving ~30-50ms on cold start.

4. Cache the stealth JS string (350 lines, pure static) after first
   generation — every subsequent goto() reuses the cached string.

* fix: address review feedback on P0 perf optimizations

1. sanitizeContext: cache JSON string instead of parsed object to prevent
   sandbox mutation from polluting subsequent calls
2. VM sandbox: clean non-whitelisted properties before each execution to
   prevent cross-expression state leakage
3. Startup parallelization: document registry overwrite semantics and
   confirm no shared-state race between parallel tasks
2026-04-11 01:31:34 +08:00
jakevin 110e047b3c refactor(validate): switch from YAML to registry-based validation (#943)
* refactor(validate): switch from YAML scanning to registry-based validation

The validate/verify commands only scanned YAML files, which are no
longer supported. Rewrite to validate commands from the in-memory
registry populated by discoverClis(), aligning with the JS-first
adapter architecture.

New checks: missing description, browser commands without domain,
pipeline step name typos, commands without func/pipeline, duplicate
arg names, and positional arg ordering.

* fix(validate): treat lazy-loaded commands as valid

Manifest-registered commands have _lazy=true and no func/pipeline
until execution time. Recognize this as a valid execution form.

* fix(validate): warn on empty registry, support alias targets

- Emit warning when registry is empty instead of silent PASS
- Resolve alias targets to canonical key before filtering
2026-04-11 01:17:14 +08:00
jakevin a9d21f3de0 fix: project hygiene — docs, lint, daemon restart (#942)
* fix: project hygiene — docs, lint, daemon restart, code fence

- Update Node version requirement from >= 20 to >= 21 in 7 doc files
  (README, README.zh-CN, installation guides, troubleshooting)
- Update adapter count from 79+ to 87+ in READMEs
- Remove duplicate `lint` script (identical to `typecheck`)
- Fix TESTING.md CI matrix: Node ['22'] instead of ['20', '22']
- Fix autofix SKILL.md code fence escaping (\``` → ~~~)
- Add daemon restart to postinstall so updated adapters are picked up
- Fix preuninstall to respect OPENCLI_DAEMON_PORT env var

* fix: align docs and skills with JS-first adapter contract

Adapters are now .js files (not .ts). Update all references across:
- README.md, README.zh-CN.md, CONTRIBUTING.md
- docs/guide/getting-started.md, docs/index.md
- skills/opencli-browser/SKILL.md, skills/opencli-explorer/SKILL.md

The runtime (discovery.ts) only loads .js from user clis/ directories,
and `opencli browser init` generates .js scaffolds. Documentation was
still teaching users to create .ts files.

* fix: update CI matrix to Node 22 only (drop Node 20)

package.json requires Node >= 21 (styleText dependency). The CI matrix
was still testing Node 20 which doesn't meet this requirement.

* fix: revert incorrect daemon restart from postinstall

The daemon (browser bridge) only handles CDP communication — it has no
knowledge of adapters. Adapter discovery, loading, and execution all
happen in the CLI process, which is fresh each invocation. The
_loadedModules cache in execution.ts is process-local and not a real
staleness concern. Remove the unnecessary restartDaemon() call.
2026-04-11 00:50:05 +08:00
jakevin 383d28fcf7 refactor: normalize strategy into runtime fields at registration time (#941)
Strategy is a 5-value enum (PUBLIC/COOKIE/HEADER/INTERCEPT/UI) that
the execution path was reading at two points — resolvePreNav() and
shouldUseBrowserSession() — to make decisions that are already fully
expressible by the existing `browser` and `navigateBefore` fields.

This commit introduces normalizeCommand() inside registerCommand(),
which expands strategy into concrete runtime fields at registration
time. After normalization, execution code never reads cmd.strategy.

normalizeCommand expansion rules:
  - strategy → browser: PUBLIC defaults to false, others to true.
    Explicit browser value always wins.
  - strategy + domain → navigateBefore:
    · COOKIE/HEADER + domain → 'https://{domain}' (pre-navigate)
    · Non-PUBLIC without domain → true (needs auth context, no URL)
    · PUBLIC → undefined (no auth needed)
    Explicit navigateBefore (false or string) always wins.

This matters because commands enter the registry from 4 sources
(cli(), manifest, generate-verified, tests), and previously only
cli() did strategy derivation. The other 3 constructed CliCommand
directly, leaving strategy as a runtime dependency. Now all sources
converge through registerCommand → normalizeCommand.

Changes:
  - registry.ts: add normalizeCommand(); simplify cli() to delegate
    all derivation to normalizeCommand via registerCommand()
  - execution.ts: resolvePreNav() no longer reads strategy; just
    reads the already-expanded navigateBefore field. Strategy import
    removed.
  - capabilityRouting.ts: shouldUseBrowserSession() checks
    cmd.navigateBefore (truthy = needs browser session) instead of
    cmd.strategy !== PUBLIC. Strategy import removed.
  - discovery.ts: manifest path no longer hardcodes browser default;
    delegates to normalizeCommand.
  - capabilityRouting.test.ts: test now reflects normalized command
    shape (navigateBefore: true for COOKIE without domain).

strategy is preserved as metadata on CliCommand — opencli list,
cascade probe, adapter generation, and documentation continue to
read it. Only the execution path stops consuming it.
2026-04-11 00:37:31 +08:00
jakevin f92f7571b4 chore: remove unused test-site.mjs script (#940)
Not referenced in package.json, CI, or documentation.
2026-04-11 00:19:02 +08:00
jakevin 93bd1eb88a docs: document autofix issue filing flow (#939) 2026-04-10 23:52:45 +08:00
jakevin 39a1d673ac feat(skill): add upstream issue filing step to opencli-autofix (#938)
Add Step 6 to the autofix skill: after a verified local fix, prepare a
GitHub issue draft and file it (with user confirmation) via `gh issue
create`. Pure skill/documentation approach — no new runtime code.

Closes the need addressed by #936 with zero code, zero tests to maintain.
2026-04-10 23:46:54 +08:00
jakevin cc18ed67b7 fix: sync package-lock.json to unblock CI (#937)
* fix: sync package-lock.json with package.json dependencies

package-lock.json was missing @emnapi/core@1.9.2 and
@emnapi/runtime@1.9.2 (transitive deps of @emnapi/wasi-threads),
causing `npm ci` to fail on all CI jobs.

* fix: resolve remaining CI failures after TS-to-JS adapter migration

- vitest.config.ts: update adapter project include/exclude from .test.ts
  to .test.{ts,js} to match converted adapter test files
- check-doc-coverage.sh: skip adapter directories containing only utility
  files (prefixed with _), fixing false positive for clis/slock/
- linux-do/topic-content.test.js: fix hardcoded reference to topic.ts
  (now topic.js after PR #928 migration)
2026-04-10 23:29:09 +08:00
jakevin 91c208c855 fix: address deep review findings (security, correctness, consistency) (#935)
* fix: address deep review findings (security, correctness, consistency)

1. Security: add path traversal guard for plugin manifest entry.path
2. Security: sanitize evaluate() index param via JSON.stringify
3. Correctness: fix startNetworkCapture idempotency (don't wipe entries on re-call)
4. Correctness: log pre-navigation failures instead of silently swallowing
5. Consistency: replace console.log/error with log module in commanderAdapter, external
6. Consistency: add PluginError class, convert user-facing plugin errors
7. Dedup: remove local isRecord() in plugin.ts, use shared utils.ts version
8. Clarify: document intentional double validateArgs call

* chore: remove unused chalk imports from external.ts and commanderAdapter.ts

* refactor: replace chalk with Node.js built-in util.styleText

- Remove chalk dependency, use `styleText` from `node:util` (stable in Node 21+)
- Bump engines to Node >= 21
- Update all 10 source files that used chalk
- Remove stale chalk mock from daemon.test.ts
- One fewer runtime dependency

* fix: tighten deep-review follow-up
2026-04-10 22:59:41 +08:00
jakevin 2288cf7149 fix: clean up legacy shim files and stale tmp files on upgrade (#934)
* fix: clean up legacy shim files and stale tmp files on upgrade

Add cleanup steps to fetch-adapters.js that run on every version upgrade:

1. Remove legacy compat shim files from ~/.opencli/ (registry.js,
   errors.js, utils.js, etc.) that were created by an older approach
   using file:// re-exports. Current approach uses node_modules symlink.
   Only deletes files containing "export * from 'file://" to avoid
   removing user-created files.

2. Remove legacy compat shim directories (browser/, download/, errors/,
   etc.) using the same safety check.

3. Clean up stale .plugins.lock.json.tmp-* files left behind by
   crashed processes. These accumulate over time (108 found on one
   machine) and clutter ~/.opencli/.

* fix: check every file in legacy shim directories before deleting

Instead of checking only the first file and deleting the entire
directory, now checks each file individually and only deletes files
matching the shim pattern. Directory is removed only if empty after
individual file cleanup.
2026-04-10 18:58:44 +08:00
jakevin 2457002167 chore: remove migration residuals (mapDistToSource, clean-yaml) (#931)
- Remove mapDistToSource() from diagnostic.ts — mapped dist/clis/
  paths back to clis/ but dist/clis/ no longer exists after JS-first
  migration. The function always returned null.
- Simplify resolveAdapterSourcePath() to check candidates directly
  without the dead dist→source mapping detour.
- Delete scripts/clean-yaml.cjs — walked dist/clis/ to delete YAML
  files, but dist/clis/ no longer exists.
- Remove clean-yaml script entry from package.json.
2026-04-10 16:41:44 +08:00
jakevin 714df646a5 fix(security): escape codegen strings and redact diagnostic body (#930)
1. candidateToJs: escape single quotes in site, name, domain, and arg
   name/type fields to prevent syntax errors in generated JS adapters.
   Previously only description and help fields were escaped.

2. diagnostic: pass network request body through redactText() to
   prevent sensitive data (JWT, bearer tokens) from leaking into
   repair context. responseBody/responsePreview already used
   sanitizeCapturedValue which calls redactText, but the body field
   only had truncation.
2026-04-10 15:29:32 +08:00
jakevin d2974a9ff6 refactor(adapters): convert adapter layer from TypeScript to JavaScript (#928)
* refactor(adapters): convert adapter layer from TypeScript to JavaScript

Core framework stays TypeScript; adapter layer moves to JS-first.
Adapters are essentially "executable config + browser scripts" that
barely use TS features — this simplifies the build/distribution pipeline
by removing the dist/clis/ intermediate compilation step.

Changes:
- Convert all 753 adapter files in clis/ from .ts to .js
- Update tsconfig to exclude clis/ from compilation
- Simplify build-manifest to scan clis/*.js directly (no dist/clis/)
- Update discovery, main, fetch-adapters to load JS adapters from clis/
- Update generate-verified to output .js artifacts
- Update package.json files field: dist/clis/ → clis/
- Fix all test files for the .ts → .js transition

* fix(main): use findPackageRoot for BUILTIN_CLIS path

The previous relative path (../../clis from __dirname) only worked for
dist/src/main.js but broke dev mode (tsx src/main.ts) where __dirname
is <repo>/src — resolving to /clis instead of <repo>/clis.

Use findPackageRoot() which works for both dev and prod paths.
2026-04-10 14:52:18 +08:00
jakevin b45a64d91d fix(build-manifest): import compiled JS from dist/clis/ instead of raw TS (#926)
* fix(build-manifest): import compiled JS from dist/clis/ instead of raw TS

Node's type stripping does not rewrite '.js' → '.ts' in import
specifiers, so dynamically importing .ts source files fails whenever
they contain relative imports like './utils.js'.

Switch to scanning dist/clis/ for compiled .js files after tsc runs.
This eliminates all 268 "Cannot find module" warnings and increases
manifest entries from 254 to 532 (previously half were silently skipped).

* fix: write manifest to dist/cli-manifest.json where runtime expects it

The runtime resolves BUILTIN_CLIS to dist/clis/ (relative to
dist/src/main.js), so discoverClis() looks for manifest at
dist/cli-manifest.json. Previously it was written to the package root
where the runtime never found it — manifest was effectively unused,
always falling through to filesystem scanning.
2026-04-10 12:58:34 +08:00
jakevin dbac7fc921 refactor(errors): unify error output as YAML envelope to stderr (#923)
* refactor(errors): unify error output as YAML envelope to stderr

Replace the 100+ line chalk renderError() switch-case with a single
YAML envelope output path. All errors now output a structured
{ok, error: {code, message, help, exitCode}} envelope to stderr,
regardless of TTY status.

This simplifies the error system from 5 mechanisms to 3:
1. Error Envelope (YAML → stderr) — unified error output
2. Exit codes (sysexits.h) — process exit semantics
3. Diagnostic (OPENCLI_DIAGNOSTIC=1) — autofix repair context

Removed: chalk error rendering, ERROR_ICONS map, classifyGenericError
regex classifier, BrowserConnectError-specific bridge status display.
Added: toEnvelope() utility, ErrorEnvelope type.

* refactor(errors): migrate adapters to throw CliError, update docs

- Migrate xueqiu adapters from return [{error,help}] to throw CliError
- xueqiu/utils.ts: fetchXueqiuJson now throws AuthRequiredError/
  CommandExecutionError instead of returning {error, help} objects
- Remove resolveColumns error fallback from output.ts (no longer needed)
- Add verbose stack trace support to error envelope
- Add ADAPTER_LOAD to AutoFix hint trigger codes
- Update skill docs (adapter-templates, explorer, oneshot, advanced-patterns)
  to recommend throw CliError pattern instead of return [{error, help}]

* fix: remove remaining dead error-forwarding in 4 xueqiu adapters + review fixes

- Remove `if ('error' in d) return [d]` from feed, hot, search, kline
  (fetchXueqiuJson now throws, so these were dead code)
- Add `stack?: string` to ErrorEnvelope interface (removes type cast hack)
- Fix adapter-templates.md: use AuthRequiredError instead of plain Error

* fix: migrate barchart/quote and yahoo-finance/quote to throw CliError

Last two adapters that silently returned [] on error instead of
throwing CommandExecutionError.

* fix: self-review fixes — doc evaluate crash, error messages, kline consistency

- adapter-templates.md: getServerContext was throwing AuthRequiredError
  inside a function serialized into page.evaluate() (browser has no
  CliError). Reverted to return {error} sentinel + func() body throw.
- yahoo-finance/quote, barchart/quote: include symbol in fallback error msg
- xueqiu/kline: throw EmptyResultError instead of returning [] for
  consistency with other xueqiu adapters
2026-04-10 03:20:53 +08:00
jakevin 309dadcf46 refactor(adapters): migrate pipeline adapters to func() + { error, help } pattern; docs: skill improvements (#922)
* docs(skills): add Tier 2.5 localStorage Bearer, SPA discovery, and test standards

From real-world experience building slock.ai CLI adapters:

- oneshot: add network-empty diagnosis, SPA baseURL bundle search, Tier 2.5
  localStorage Bearer template (with multi-tenant X-Server-Id pattern),
  updated auth quick-reference, file path note, opencli browser verify test flow
- explorer: add Tier 2.5 to decision tree and strategy table, update test section
  with opencli browser verify + Done standard, fix Step 5 path to ~/.opencli/clis/,
  add 4 new pitfall rows (SPA HTML, 400 context header, empty network, wrong dir)

* docs(skills): fix path conflict + add anti-change patterns from real adapters

Fix reviewer blocking issue:
- Remove the contradictory "~/.opencli/clis/" note that mixed user-local and
  repo-contributor workflows; replace with explicit two-scenario callout in
  Step 4, Step 5, pitfall table, and oneshot test section
- Template comments in oneshot restored to clis/<site>/<name>.ts (repo path)

Add "抗变更模式" section to explorer, based on opencli's own production code:
- Pattern 1: dynamic queryId discovery (twitter/shared.ts resolveTwitterQueryId)
  — scan loaded JS bundle by operationName (stable) to find queryId (unstable)
- Pattern 2: semantic DOM priority fallback (web/read.ts)
  — article > [role=main] > main > class-hint > body, pick largest text block
- Pattern 3: ordered selector array + timestamp comments (xiaohongshu/publish.ts)
  — first-match wins, comment records UI version and observed attribute values
- Pattern 4: nullish-coalescing field multi-path (xiaohongshu/user-helpers.ts)
  — covers camelCase/snake_case variants without assuming fixed key name

* docs(explorer): split SKILL.md into reference sub-documents

- Shrink main SKILL.md from 994 to 270 lines — core workflow only
- Extract all TS templates (Tier 1~4, pagination) to references/adapter-templates.md
- Add error handling standard: { error, remedy } pattern (remedy > hint)
- Add Tier 2.5 localStorage Bearer template with multi-tenant X-Server-Id example
- Extract cascading requests, tap debug, verbose mode, anti-change patterns to references/advanced-patterns.md
- Extract record workflow to references/record-workflow.md

* docs(skills): fix verify command — split by dev scenario

browser verify only reads ~/.opencli/clis/, not repo's clis/.
Split all verify instructions:
- Repo 贡献: npm run build + opencli <site> <cmd>
- 私人 adapter: opencli browser verify <site>/<name>

Fixes blocker in explorer:L209, L224 and oneshot:L286, L298

* docs(adapter-templates): add utils.ts extraction pattern for same-site adapters

* docs(skills): add decision matrix, stop conditions, sync comments

explorer: add path decision matrix before core workflow
oneshot: add explicit stop/switch conditions (when to escalate to explorer)
both: add keep-in-sync comment on the two-scenario verify block

* feat(slock): extract utils.ts + apply { error, help } pattern; docs: remedy→help

slock/utils.ts: new — getSlockContext(), resolveChannelId()
  - Shared token + workspace resolution, no more 4-line duplication
  - UUID regex (/^[0-9a-f]{8}-...$/) replaces fragile !includes('-')
  - Returns { error, help } instead of throwing

tasks.ts / members.ts / send.ts:
  - Import from utils.ts, remove all duplicated auth boilerplate
  - All errors return [{ error, help }], no more throw
  - members.ts: add limit arg (was unbounded before)

docs: rename remedy → help across all skill references

* refactor(adapters): migrate pipeline adapters to func() with { error, help } pattern

- slock: agents, channels, messages, servers now use getSlockContext/resolveChannelId
  from utils.ts; error handling uses { error, help } return instead of bare throws
- linux-do: export fetchLinuxDoJson from feed.ts; migrate search, topic, categories,
  tags, user-posts, user-topics from pipeline+throw to func() using fetchLinuxDoJson
- xueqiu: add utils.ts with fetchXueqiuJson helper; migrate hot, feed, search, stock,
  watchlist, hot-stock, groups, kline, earnings-date from pipeline+throw to func()

* fix(output): show error rows in table/csv/markdown when columns declared

When a command declares columns (e.g. ['rank', 'title', 'value']) but
returns an error row ({ error, help }), the declared columns would
render empty cells. Now resolveColumns detects the error key and falls
back to the row's actual keys, making diagnostics visible in all output
formats.

* chore: remove slock adapters from this PR

Slock adapters should be in a separate PR, not bundled with the
adapter refactor and skill docs improvements.
2026-04-10 02:29:35 +08:00
jakevin 56f371fbad docs(skills): improve oneshot & explorer with real-world SaaS patterns (#921)
* docs(skills): add Tier 2.5 localStorage Bearer, SPA discovery, and test standards

From real-world experience building slock.ai CLI adapters:

- oneshot: add network-empty diagnosis, SPA baseURL bundle search, Tier 2.5
  localStorage Bearer template (with multi-tenant X-Server-Id pattern),
  updated auth quick-reference, file path note, opencli browser verify test flow
- explorer: add Tier 2.5 to decision tree and strategy table, update test section
  with opencli browser verify + Done standard, fix Step 5 path to ~/.opencli/clis/,
  add 4 new pitfall rows (SPA HTML, 400 context header, empty network, wrong dir)

* docs(skills): fix path conflict + add anti-change patterns from real adapters

Fix reviewer blocking issue:
- Remove the contradictory "~/.opencli/clis/" note that mixed user-local and
  repo-contributor workflows; replace with explicit two-scenario callout in
  Step 4, Step 5, pitfall table, and oneshot test section
- Template comments in oneshot restored to clis/<site>/<name>.ts (repo path)

Add "抗变更模式" section to explorer, based on opencli's own production code:
- Pattern 1: dynamic queryId discovery (twitter/shared.ts resolveTwitterQueryId)
  — scan loaded JS bundle by operationName (stable) to find queryId (unstable)
- Pattern 2: semantic DOM priority fallback (web/read.ts)
  — article > [role=main] > main > class-hint > body, pick largest text block
- Pattern 3: ordered selector array + timestamp comments (xiaohongshu/publish.ts)
  — first-match wins, comment records UI version and observed attribute values
- Pattern 4: nullish-coalescing field multi-path (xiaohongshu/user-helpers.ts)
  — covers camelCase/snake_case variants without assuming fixed key name

* docs(explorer): split SKILL.md into reference sub-documents

- Shrink main SKILL.md from 994 to 270 lines — core workflow only
- Extract all TS templates (Tier 1~4, pagination) to references/adapter-templates.md
- Add error handling standard: { error, remedy } pattern (remedy > hint)
- Add Tier 2.5 localStorage Bearer template with multi-tenant X-Server-Id example
- Extract cascading requests, tap debug, verbose mode, anti-change patterns to references/advanced-patterns.md
- Extract record workflow to references/record-workflow.md

* docs(skills): fix verify command — split by dev scenario

browser verify only reads ~/.opencli/clis/, not repo's clis/.
Split all verify instructions:
- Repo 贡献: npm run build + opencli <site> <cmd>
- 私人 adapter: opencli browser verify <site>/<name>

Fixes blocker in explorer:L209, L224 and oneshot:L286, L298

* docs(adapter-templates): add utils.ts extraction pattern for same-site adapters

* docs(skills): add decision matrix, stop conditions, sync comments

explorer: add path decision matrix before core workflow
oneshot: add explicit stop/switch conditions (when to escalate to explorer)
both: add keep-in-sync comment on the two-scenario verify block
2026-04-10 01:47:37 +08:00