Skip to content

Improve Web settings, browser control, native search and workbench UI - #711

Draft
testikun wants to merge 82 commits into
mainfrom
codex/settings-resources
Draft

testikun wants to merge 82 commits into
mainfrom
codex/settings-resources

Conversation

@testikun

@testikun testikun commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Web conversations need an opt-in way to verify current information through the active model's hosted search. Captured native searches also lacked ordinary tool-group identity/count/status, while merged commentary and final text left the introduction outside the completed-run fold.

Switching Sessions can leave a second usage strip from the previous Session. When Pi persists an image without its browser filename, the admitted preview can remain as another waiting turn even after the native answer has finished.

The browser panel could display pages but did not expose authorized model control or a common installation path across desktop browsers. Long setup steps were also clipped by the settings shell: the lower actions could not be reached with a mouse wheel.

Web settings do not reliably distinguish configured resources from loaded resources, or a saved model connection from the model selected for use. Account users have to leave Web to sign in, and multiple connections have no clear current-Session versus new-Session default choice. Usage is hidden behind disclosures; browser controls and side-chat editors have inconsistent visual hierarchy. Execution output can interrupt reading, while file and terminal actions need clearer labels, focus and feedback.

Fixes #710, #728, #729, #730 and #732; refs #597.

Value

Users can enable search for the current Session model with existing Pi credentials. Search remains off by default; unsupported connections receive no hosted tool and never fall back to Exa. Completed searches use the same tool groups, counts, query details and folding as other tools.

Add opt-in page reading, clicks, text input and screenshots through the existing OpenPI browser panel or a selected regular browser, with four-step setup for Chrome, Edge, Brave, Chromium, Safari and Firefox. Users can scroll the full guide in short/narrow windows or keep it in a separate window while completing native installation.

Make setup, model selection and execution state understandable in a consistent, restrained interface. Users can connect an account or API, choose an exact model for the current Session, and explicitly save a future default. Compact controls expose useful information immediately and disclose details when needed, while preserving Pi's native ownership and the existing workbench hierarchy.

Approach

  • Current-model search: add a repository-owned optional Pi extension at before_provider_request, provider_stream_event and message_end. The primary Pi request offers hosted search only when the exact provider/model/API/base-URL connection is supported and explicitly enabled. Preserve bounded opaque output and clickable citations on native assistant messages, and replay retained history only for the same connection. Pi continues to own transport, credentials, usage, compaction and cancellation. No independent provider client, cache, local executable search tool or new core tool group. Hosted search is excluded from child Sessions to preserve their allowlists. The existing optional-package installer remains a separate, explicitly reviewed choice.

  • Search presentation: project bounded native statuses/queries with provider-order positions, then reuse ProcessSequence and EvidenceDetails. Completed runs fold commentary and searches around the final answer; searches count as tools and retain their actual terminal status. Remove the dedicated search renderer/CSS/labels. The canonical setup status, configuration, settings, README and SETUP document the default-off current-model choice. See the search integration record; refs capabilities: 定义 Browser、Web、GitHub、Computer 与 Security 的外部 Provider Seam #169.

  • Expose one parent-only Pi-native openpi_browser tool, with exact browser/profile/document/turn binding, revocation and consumed observations. Pi core and upstream pi-computer-use are unchanged.

  • Browser Bridge 0.4.0 uses the existing CDP adaptation for Chromium embedded/native pages and private document ports for Safari/Firefox native tabs. Browser grants/default selection use the shared configuration writer and native setup events; installation, live connection and authorization remain distinct.

  • Share the four-step guide's React state with a floating Document Picture-in-Picture window or ordinary popup. Browser-specific illustrations identify native controls. Give the existing browser settings panel native vertical scrolling and remove delayed smooth positioning so manual wheel input keeps its position. No custom scroll controller is added.

  • Capture only the already-bounded visible browser clip; disable capture beyond the viewport so screenshot capture does not resize the layout and include the workbench footer.

  • Models and accounts: reuse Pi 0.99.1 ModelRuntime login/logout and AuthInteraction for native browser/device prompts, persistence and refresh. Bind the bounded temporary flow to exact Session/provider/flow/prompt identities; serialize idle admission, settle cancellation and clean up callbacks. Report saved credentials separately from failed availability refresh, and confirm shared-credential sign-out. Keep Account / Third-party providers / Custom model API in the existing settings shell and preserve independent drafts.

  • Connection to model: open an inline chooser after a connection is saved and expose the same action on configured rows. Keep current-Session selection separate from the top New-session default row, with an explicit checkbox to apply both. Save defaults through Pi's native SettingsManager, flush/reload and verify the persisted provider/model pair; retain unrelated fields and show trusted project overrides. Exact Session/path and native availability checks reject stale or unavailable writes. Partial current/default success stays visible. Provider-scoped search filters before bounding results, preserving same-name and large-catalog identities.

  • Provider marks: reuse local MIT-licensed OpenCode SVG geometry with restrained brand accents and neutral controls. Unknown/custom IDs use one neutral Server outline in defaults, configured rows, selectors and both composers, replacing inconsistent name initials. Display names never imply an official brand. No new picker framework, credential registry, model-default store, automatic routing or appearance preference.

  • Skills and Plugins: add source/scope search, source forms, invocation controls and reviewed individual or filtered bulk requests through canonical /openpi-setup. Project native SettingsManager/PackageManager configuration alongside loaded resources, including disabled, missing and zero-resource identities. Explicit reload uses the serialized idle boundary, exact Session identity and native missing/version preflight. Admission, persistence and loading remain distinct.

  • Usage and browser: show input, output and context/capacity together; disclose precise context, native cache-inclusive totals, workspace and folded Session ID. Preserve unknown versus zero. Give usage and overview distinct React sibling identities while retaining exact Session ID/path. Reconcile admitted user-image previews without browser-only filenames, retaining native-order anchors, queue bounds and one-to-one projection; this is presentation matching, not a delivery receipt. Soften existing tabs and browser controls with rounded surfaces, grouped navigation, a capsule address field and quiet borders.

  • Side conversation: reuse the main composer, attachment action, model control and circular send/stop controls. Focused/narrow side chat has one visible editor while retaining independent mounted drafts and return focus. Preserve native child identity, lifecycle, locking and cancellation.

  • Execution and reading: group native reasoning/tools/activities chronologically, fold settled processes around the exact final answer and retain human steering. Keep complete available thinking pageable by native identity. Upward reading pauses following; deliberate return or the latest-content control resumes it. Restore saved anchors through necessary disclosure ancestors, retain inner offsets and move keyboard focus to the latest answer. Respect reduced motion; project native retry, compaction and observed-completion facts without a second execution store.

  • Files, Changes and Terminal: retain New / Import / More text menus and labelled compact icons, explicit target directories, revision-checked editing and Save / Saving / Saved feedback. Tooltips explain hover/focus actions and dismiss before their containing panels. Keep tool selection anchored above active content; show native comparison status once and retain viewed marks. Derive terminal return-to-bottom from xterm's viewport, retain necessary restore synchronization and distinguish hiding from process-ending close.

  • Preserve the integrated file-toolbar updates from 60ff9816 and regenerate tracked Web assets. Ownership, accepted design, ablation and evidence are recorded in model connections, resource settings, Session usage, browser chrome, side conversation, execution activity and workbar tools.

Validation

  • Native-search and transcript source c11d8abf: bun run check and complete bun run test passed: 2,374 Node passes, nine skips, zero failures; 1,279 UI passes across 87 files. Actual Pi HTTP fixtures cover default-off/unsupported omission, exact connection identity, retained-history replay, Session restoration/isolation, conflicting tools with zero provider requests and GPT-5 minimal mode. Protocol/UI tests distinguish terminal evidence from claims, preserve opaque Anthropic blocks, and verify ordered native activity, tool counts, nested disclosures, visible final answers and clickable sources. Removing ordinary tool-group metadata reproduces the missing count; the restored implementation passes. Exact connection-identity ablation fails its eligibility/replay regressions.

  • Installed runtime c11d8abf at local port 57161 reused the existing Pi connection and restored the user's image question with four completed hosted calls. Manual browser acceptance verified the collapsed final-only view, the four-tool completed group, four visible queries after expansion and individual query disclosure. The Session file's SHA-256 was unchanged. An earlier isolated original-image/followup acceptance recorded four plus one completed native calls. Frozen receipts, screenshots and full logs remain in the private web-search-integration-20261010 archive; credentials, image bytes and private Sessions are not committed. Hosted activities are currently displayed at message_end; live provider progress was not added. Anthropic live-provider verification and automatic pause_turn continuation remain outside this acceptance. New-head CI is not claimed.

  • Display-recovery implementation 29f56717: bun run check and the complete canonical VITEST_MAX_WORKERS=1 bun run test passed: 2,354 Node passes, nine platform skips, zero failures; 1,276 UI passes across 87 files. The subsequent evidence-only update also passed bun run check. All 135 scoped component checks and three installed-Chrome image admission/history/cancellation regressions passed. Repeated Session switches, the same ID at different paths and native images without filenames reproduce the original defects; removing the two corrections fails the two new regressions, and restoring the checked bytes passes the three targeted cases.

  • Restarted both frontend and native backend at 30142 on 29f56717, after checking native idle/sign-in state and the sole OpenPI package source. Served asset hashes matched the build; existing configuration and Session bytes were preserved. One real text request through the ordinary Pi runtime used codex-local/gpt-6.1-sol / medium, returned “连接成功” and settled idle. Reopening the original image Session showed one usage strip, one user input and no waiting turn. Its two upstream 502 attempts had already recovered to a successful native answer; retry/provider behavior was not changed. A fresh test-image upload was declined by browser approval and was not attempted through another channel, so fresh provider image acceptance is not claimed. Logs, bounded native receipts and screenshots remain in the private session-display-recovery-* archive identified in the Session usage record.

  • Final integrated source 92a722c2: bun run check passed; VITEST_MAX_WORKERS=4 bun run test passed 2,354 Node tests (nine skips) and 1,274 UI tests across 87 files. Final Edge browser regressions passed 21/21, including wheel access at 1147 × 640 and 390 × 640, independent guide windows, embedded/native control, resource/model settings, account-entry UI and workbench interactions.

  • The wheel regression failed on the clipped panel before the fix. Desktop and narrow cases now reach the complete lower action and scroll back to the heading while the close button remains visible. Removing smooth positioning prevents an in-flight animation from undoing manual input. Exact iframe screenshot/pixel checks passed three consecutive runs with capture limited to the viewport. An older elapsed-time E2E expectation was aligned with the compact format already required by Improve Web settings, browser control, native search and workbench UI #711's component tests.

  • Real provider acceptance at browser source fbd070b4 used Pi 0.99.1 and gpt-6.1-sol / medium: actual Edge 155.0.4283.45 completed four calls/one screenshot, and actual Safari 26.6.2 completed eight calls/two screenshots across two pages; both had zero tool errors and independently verified saved Chinese values. Safari installation was approved natively and limited to 127.0.0.1 for one day. Firefox physical testing was explicitly waived. Those provider runs retain that revision boundary; the current combined source has separate regression evidence.

  • The source-backed 30144 preview was restarted on the integrated checkout. Its sole Pi package and served JavaScript/CSS hashes were verified; actual Chrome scrolling exposes the entire step-three action while keeping the settings header visible. No new provider request or browser permission was needed for this scroll check.

  • Frozen browser/provider evidence is in local archive browser-multi-20261010; this integration's source, failure history, screenshots and full gate logs are in browser-scroll-20261010. The browser setup record links the implementation, lifecycle and limitations. Credentials and private Session receipts remain outside Git.

  • Earlier model-settings source 66360854 passed bun run check and the complete canonical VITEST_MAX_WORKERS=1 bun run test: 2,334 Node passes, nine platform skips, zero failures; 1,269 UI passes across 86 files. Its subsequent design-record update also passed bun run check. Existing bundle-size and JSDOM capability notices remain.

  • Four installed-Chrome regressions passed at 66360854: current/default selection with shared model IDs, 320px light/dark AA checks, and both account/browser and device fixtures. At 4c82bf4f, the nine scoped cases also covered resource settings, General preferences, model editing/discovery and both side-conversation cases. These are scoped regressions, not a complete browser-suite claim.

  • Real Pi fixtures verify native default-file preservation, a fresh native Session using the saved default, current model selection retaining that default, exact stale/unavailable rejection, trusted project overrides and malformed-file preservation. Large catalogs and similarly named providers remain exact. UI cases cover explicit opt-in, rejected current selection and partial default failure.

  • Earlier source-backed 30142 acceptance retained native backend 2c07c0f3 and reloaded frontend assets from 66360854 without a backend restart. The 29f56717 restart above supersedes that deployment boundary. Checkout revision, the single OpenPI source from pi list and served asset hashes were verified. Real inspection confirms identical custom marks in the default row, chooser, configured connection and composer. Private configuration hashes match the previous receipt; no model request or completed account authorization was performed. Earlier colored-provider and native-default checks retain their frozen source boundary in the linked record.

  • Prior installed acceptance for resources, browser chrome, scrolling/compaction, file editing and terminal reading retains its frozen revision and limits in the linked records. Real OpenAI/Anthropic login entry and cancellation at 5ed9fb8b released native callback listeners; completed external authorization, account entitlement and endpoint availability remain unverified. OpenCode dialogs are appearance references with the recorded frontend/backend version mismatch.

  • Ablation removes name slicing, the display-name icon prop and monogram typography while retaining exact provider identities and existing icon sizes. It also removes the always-visible search field for small model lists while retaining bounded large-catalog search. Earlier ablations remove the duplicate account editor/method state, redundant single-activity presentation, unneeded scrolling/terminal state and extra dismissal interception; removing required stable reading identity or nested dismissal depth fails its regression. Full receipts, private fixtures and screenshots remain outside Git. New-commit CI is not claimed.

Impact

  • Native search: adds canonical webSearch.enabled (default false) and exact connection support declarations, plus bounded native evidence on existing assistant messages. Unsupported connections remain unavailable with no alternate-provider fallback. Hosted declarations extend the primary model request without adding a local Pi tool; child authority remains bounded. Disabling search preserves retained history. External search-provider selection is outside this iteration, and the legacy package installer is not automatically activated.

  • Browser follow-up: adds opt-in browser grants/default selection and a parent-only browser tool. The tool uses Pi's existing Session/provider lifecycle, exact ephemeral transport and fresh observations for writes. Browser Bridge 0.4.0 must be loaded in the selected browser. Chromium supports embedded/native targets; Safari/Firefox support native tabs only, with temporary installations that need reloading after browser restart. Signed permanent distribution, Brave/Chromium physical installation and Windows/Linux launch helpers are not validated here.

  • User-visible: native account connection, clear current/future model selection, recognizable provider marks, useful resource state, glanceable usage, softer browser controls, one focused side-chat editor, readable execution progress and labelled file/terminal actions.

  • Model-visible: bounded resource-management context with exact targets and native review/persistence guidance. Browser control adds the parent-only Pi tool described above; no prescribed reasoning workflow is added.

  • Runtime/lifecycle: existing Pi Sessions, ModelRuntime, SettingsManager, resource reload, native events, file revision checks and PTY owners remain authoritative. New default writes reuse idle admission and exact Session identity; default-only saves do not change the active model or append transcript model changes.

  • Persisted config/data: credentials, model definitions and explicitly chosen defaults use Pi's native stores. No new OpenPI model/account preference, Session store or accounting store. Existing optional timing identity remains backward compatible; visit acknowledgements are tab-local.

  • Compatibility/risk: same-provider reauthentication replaces Pi's one credential for that ID; distinct custom connections use distinct IDs. Trusted project settings can override the global default. External authorization, provider availability and new-commit CI remain outside this acceptance. Unrelated local work and existing PR commits are preserved; the PR remains a draft for review.

@github-actions github-actions Bot added documentation Improvements or additions to documentation area:setup OpenPI setup, configuration, or setup documentation labels Oct 8, 2026
…dev/openpi into codex/settings-resources

# Conflicts:
#	web/dist/app.js
#	web/dist/styles.css
#	web/ui/src/features/workbar/WorkbarPanel.tsx
@testikun testikun changed the title Improve Web resource management and workbench UI Improve Web settings and workbench UI Oct 10, 2026
@testikun testikun changed the title Improve Web settings and workbench UI Improve Web settings, browser control and workbench UI Oct 10, 2026
@testikun testikun changed the title Improve Web settings, browser control and workbench UI Improve Web settings, browser control, native search and workbench UI Oct 10, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:setup OpenPI setup, configuration, or setup documentation documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Iterate Skills and Plugins settings with native catalog state and consistent UI

1 participant