Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
3960 commits
Select commit Hold shift + click to select a range
ae9d987
feat(diagnostics): add mock authorization MCP flow (#2947)
reachjalil Jul 21, 2026
f69efa9
chore: neutralize partner-identifying fixture names in tests and eval…
benjaminshafii Jul 21, 2026
e196604
revert(server): drop -32001/connect_url prompt dialect, keep raw tool…
benjaminshafii Jul 21, 2026
132ec10
fix: keep sign-in URL visible (#2948)
reachjalil Jul 21, 2026
4b8caee
feat(desktop): debug-only nuke & fresh start with full local wipe (#2…
benjaminshafii Jul 21, 2026
aba3c63
feat(evals): add enterprise gateway first-run demo (#2951)
benjaminshafii Jul 21, 2026
e236502
fix(app): show tool result copy action when expanded (#2956)
reachjalil Jul 21, 2026
95c9ebb
fix(app): keep model controls available during generation (#2958)
reachjalil Jul 21, 2026
4147b9c
fix(evals): bound desktop route waits (#2955)
reachjalil Jul 21, 2026
f1c0f05
fix(desktop): apply branded name to macOS menu (#2960)
reachjalil Jul 21, 2026
6f3d832
[WHATSMYAGEAGAIN] Hide OpenWork version from sidebar (#2959)
reachjalil Jul 21, 2026
424223e
ignore: update download stats 2026-07-21
actions-user Jul 21, 2026
28d9ad6
fix(desktop): preserve non-mac branding behavior (#2962)
reachjalil Jul 21, 2026
9eca0c6
fix(app): keep session spinner clear of title (#2957)
reachjalil Jul 21, 2026
cfce5c7
feat(desktop): make bootstrap preservation optional (#2964)
reachjalil Jul 21, 2026
39c3d77
feat: safely delete custom marketplaces (#2961)
reachjalil Jul 21, 2026
fc3f33f
fix(app): align code blocks with chat theme (#2970)
OmarMcAdam Jul 21, 2026
e967b25
feat(mcp): cloud MCP doctor — direct probe trace, engine refresh, adv…
reachjalil Jul 22, 2026
6bee537
feat(app): make session pinning global (#2978)
reachjalil Jul 22, 2026
90a9ba9
feat(server): inject remote Connect skills (#2965)
reachjalil Jul 22, 2026
ac435b5
chore(app): remove dead primitives (#2972)
benjaminshafii Jul 22, 2026
991bf4b
feat(diagnostics): add Connect debug proxy (#2979)
reachjalil Jul 22, 2026
ba29f20
test(den): cover MCP OAuth refresh lifecycle (#2952)
benjaminshafii Jul 22, 2026
9341754
feat: fail-proof org first connection (guided install link, first-run…
benjaminshafii Jul 22, 2026
a314ea9
refactor(app): consolidate markdown rendering (#2982)
benjaminshafii Jul 22, 2026
3e3a36c
fix(install-config): export TS source directly so consumers need no p…
benjaminshafii Jul 22, 2026
22e2b1e
feat(evals): typed runner core + automation/demo mode split (#2971)
benjaminshafii Jul 22, 2026
8e50a6e
fix(app): mark OpenWork Connect as beta (#2985)
reachjalil Jul 22, 2026
456d5d8
refactor(app): centralize workspace server clients (#2986)
benjaminshafii Jul 22, 2026
636bf2d
refactor(server): centralize runtime database setup (#2987)
benjaminshafii Jul 22, 2026
c146b89
feat: two-door install model — paste-gated installer, no artifact sta…
benjaminshafii Jul 22, 2026
87b7002
feat(evals): pretty screenshots — mesh-gradient frames from the scree…
benjaminshafii Jul 22, 2026
a2268db
feat: create sessions without UI control (#2981)
reachjalil Jul 22, 2026
1054c9e
chore(release): v0.17.37 (#2991)
benjaminshafii Jul 22, 2026
6d209cd
chore(aur): update PKGBUILD for 0.17.37
release-bot Jul 22, 2026
7fb35e9
fix(den-api): report newest desktop version (#2992)
benjaminshafii Jul 22, 2026
8b01e8c
fix(den-api): race-safe rate-limit upsert shared by handoff status + …
benjaminshafii Jul 22, 2026
8e38aa2
fix(den-api): use public URL for desktop handoff (#2995)
benjaminshafii Jul 22, 2026
839f207
fix(installer): retry busy Windows app launch (#2996)
benjaminshafii Jul 22, 2026
7a5ee02
fix(installer): mac clipboard + paste button, run-once DMG naming, se…
benjaminshafii Jul 22, 2026
8dd5f5c
chore(release): v0.17.38 (#3001)
benjaminshafii Jul 22, 2026
a4157cd
fix(installer): host-independent posix path logic for mac self-cleanu…
benjaminshafii Jul 22, 2026
968b3b6
chore(aur): update PKGBUILD for 0.17.38
release-bot Jul 22, 2026
b770998
ignore: update download stats 2026-07-22
actions-user Jul 22, 2026
6c5122b
fix(den): serialize default marketplace seeding (#3004)
reachjalil Jul 22, 2026
5f40b11
docs(skills): refresh release skill to the real dev-branch process (b…
benjaminshafii Jul 22, 2026
af70226
docs(mcp): add per-client OpenWork MCP setup pages and SEO hub (#3007)
benjaminshafii Jul 22, 2026
f5d06e0
feat(cloud): add organization super-admin role (#3008)
OmarMcAdam Jul 22, 2026
11fcf6b
fix(den-api): use public handoff URL for forwarded zero host (#3009)
benjaminshafii Jul 22, 2026
a08d96f
fix(landing): never serve paste-gated OpenWork-Installer assets from …
benjaminshafii Jul 22, 2026
d977391
feat(installer): apply DMG background art + Finder layout (run-once i…
benjaminshafii Jul 22, 2026
cdb086f
chore(release): bump version to 0.17.39
benjaminshafii Jul 22, 2026
28ce5d3
fix(den): inject assigned marketplace skills (#3014)
reachjalil Jul 22, 2026
a7126d1
chore(aur): update PKGBUILD for 0.17.39
release-bot Jul 22, 2026
2bfda8f
fix(server): route remote skill loading through Connect (#3015)
reachjalil Jul 22, 2026
ee2a7dd
test(landing): lock public /download asset selection against gated in…
benjaminshafii Jul 22, 2026
ec0ac4e
fix(den-api): stop capability discovery from dropping query params — …
benjaminshafii Jul 22, 2026
835c941
feat(den): polish branded organization onboarding (#3003)
reachjalil Jul 22, 2026
b352d9f
fix(server): scope Connect skill catalog to the host, not a workspace…
benjaminshafii Jul 22, 2026
5467041
fix(den-web): show signed-in desktop handoff with pasteable openwork …
benjaminshafii Jul 22, 2026
3ff2e48
fix(server): skip dead openwork-cloud configs when resolving Connect …
benjaminshafii Jul 22, 2026
5e4e836
fix(mcp): preserve OAuth sessions across token refresh (#2993)
reachjalil Jul 23, 2026
8daed8a
refactor: remove skill hubs, migrate skills to single-skill plugins (…
benjaminshafii Jul 23, 2026
3da9003
fix(connect): preserve marketplace skill discovery metadata (#3030)
reachjalil Jul 23, 2026
69ed24e
fix(den): preserve deprecated skill hub contract (#3033)
OmarMcAdam Jul 23, 2026
b72c58b
fix(ci): survive transient pscale errors in den-db-migrate; recovery …
benjaminshafii Jul 23, 2026
260d994
refactor(extensions): compose prompt sections and drop stale local bu…
benjaminshafii Jul 23, 2026
b64a294
fix(app): restore Google Workspace and Ollama built-in extensions (#3…
benjaminshafii Jul 23, 2026
92e0474
fix(den): never point install links at releases without installer ass…
benjaminshafii Jul 23, 2026
c308206
fix(den): unrestricted installer downloads follow the latest publishe…
benjaminshafii Jul 23, 2026
f233263
fix(den-db): apply schema insight index fixes (#3037)
OmarMcAdam Jul 23, 2026
4c959a3
fix(skills): select local or Cloud authoring context (#3039)
reachjalil Jul 23, 2026
820d00a
feat(app): unify skills and extensions inventory (#3040)
reachjalil Jul 23, 2026
9e964cb
feat(app): show chat attachments as expandable inline badges (#3041)
benjaminshafii Jul 23, 2026
4a931e8
fix(app): open chat images in a modal instead of expand overlay (#3043)
benjaminshafii Jul 23, 2026
cefd1b8
fix(skills): normalize Cloud skill metadata (#3042)
reachjalil Jul 23, 2026
5ef8568
fix(cloud): clarify OpenWork Models entitlement and self-heal member …
benjaminshafii Jul 23, 2026
6fb4034
feat(app): keep queued drafts rich and allow send-now (#3046)
benjaminshafii Jul 23, 2026
bcb3197
fix(branding): stop cleared icons from returning after restart (#3047)
benjaminshafii Jul 23, 2026
fd2d0e6
fix(skills): hide legacy OpenCode customization skill (#3048)
reachjalil Jul 23, 2026
48cc26a
feat(skills): support Cloud-native skill updates (#3049)
reachjalil Jul 23, 2026
f7b1bf5
fix(skills): retire legacy OpenWork skills (#3051)
reachjalil Jul 23, 2026
f2606b7
feat(app): add semantic agent surface (#3050)
benjaminshafii Jul 23, 2026
b9df098
refactor(skills): remove local Cloud migration helper (#3052)
reachjalil Jul 23, 2026
b54ff19
ignore: update download stats 2026-07-23
actions-user Jul 23, 2026
e6f2c60
fix(skills): retire local import guidance (#3053)
reachjalil Jul 23, 2026
de5d738
fix(release): retry notarization stapling to survive transient Apple …
benjaminshafii Jul 23, 2026
ab0b4f8
fix(agent): publish semantic UI MCP cleanly (#3055)
benjaminshafii Jul 23, 2026
1a0eed9
refactor(agent): drop legacy OpenWork tool aliases (#3056)
benjaminshafii Jul 23, 2026
dcba0d3
fix(skills): expose default creator as cloud skill (#3057)
reachjalil Jul 23, 2026
dd68c89
fix(app): show API key save feedback (#3058)
benjaminshafii Jul 23, 2026
0b02d62
Revert "fix(skills): expose default creator as cloud skill (#3057)"
benjaminshafii Jul 23, 2026
72cbe2d
fix(skills): expose three narrow builtin Cloud authoring skills (#3060)
benjaminshafii Jul 23, 2026
e8428d4
chore(release): bump to 0.17.40
benjaminshafii Jul 23, 2026
7df13c9
chore(aur): update PKGBUILD for 0.17.40
release-bot Jul 23, 2026
01e317c
feat(mcp): accept Cursor Desktop OAuth callback via exact allowlist (…
benjaminshafii Jul 23, 2026
37e1d9b
feat(sidebar): implement Paper improved-sidebar redesign (#3064)
benjaminshafii Jul 23, 2026
ff21a8e
feat(chat): render capability calls as sentences, not JSON cards
benjaminshafii Jul 23, 2026
4883a2b
feat(chat): aggregate consecutive command/edit/read/search tool calls
benjaminshafii Jul 23, 2026
eb1e72d
feat(chat): failure-as-instruction lines and two-line sub-agent runs
benjaminshafii Jul 23, 2026
9dd6076
fix(chat): separate merged reasoning sections with a paragraph break
benjaminshafii Jul 23, 2026
f359bfb
feat(chat): linkify bare https:// URLs in user message bubbles
benjaminshafii Jul 23, 2026
b656e30
style(chat): drop traffic-light status colors from tool call lines
benjaminshafii Jul 23, 2026
a95756e
feat(chat): collapse thinking by default, clickable file rows in aggr…
benjaminshafii Jul 23, 2026
3a48552
feat(chat): humanize native and plugin execute_capability calls
benjaminshafii Jul 23, 2026
634873f
style(sidebar): drop workspace color dot from pinned and archived rows
benjaminshafii Jul 23, 2026
8ecfc4d
style(chat): remove static gray status dots from tool call lines
benjaminshafii Jul 23, 2026
3e1b14f
feat(sidebar): move conversation history back/forward controls into s…
benjaminshafii Jul 23, 2026
e000657
feat(chat): collapsed failed capability line expanding into Paper fai…
benjaminshafii Jul 23, 2026
f7d2bed
feat(chat): render site favicons next to links in user and assistant …
benjaminshafii Jul 23, 2026
7e8620b
feat(chat): Paper file chips in aggregate rows and per-turn FILES art…
benjaminshafii Jul 23, 2026
a41599b
style(sidebar): move history arrows to top right of sidebar titlebar row
benjaminshafii Jul 23, 2026
8bab21b
style(sidebar): align history arrows with titlebar toggle row
benjaminshafii Jul 23, 2026
ced40fd
style(sidebar): add vertical spacing between session rows
benjaminshafii Jul 23, 2026
b7f3a48
style(sidebar): apply row gap inside reorder groups and group content
benjaminshafii Jul 23, 2026
5936d6a
style(sidebar): selected session uses subtle color emphasis instead o…
benjaminshafii Jul 23, 2026
ac12358
test(evals): chat-transcript-sentences fraimz with dev-only transcrip…
benjaminshafii Jul 23, 2026
fd8d0e8
style(chat): remove underline from links; assert no-underline in fraimz
benjaminshafii Jul 24, 2026
552fc80
test(evals): make chat-transcript flow idempotent via renderer reload
benjaminshafii Jul 24, 2026
88dc9f6
feat(diagnostics): add Connect incident portal (#3072)
reachjalil Jul 24, 2026
f583acb
feat(mcp): expose desktop policies as OpenWork Cloud MCP capabilities
benjaminshafii Jul 23, 2026
50e62d1
fix(den): tolerate JSON-string desktop-policy columns (MariaDB)
benjaminshafii Jul 23, 2026
abbcfc9
fix(evals): create a workspace via control action when the desktop ha…
benjaminshafii Jul 23, 2026
ef8710d
fix(desktop): treat IPv6 loopback as loopback in main-window navigati…
benjaminshafii Jul 23, 2026
bcbc397
fix(evals): drive Den web through the built-in browser tab in the pol…
benjaminshafii Jul 23, 2026
4536a02
feat(den): owner-only organization deletion + fix admin user delete
benjaminshafii Jul 23, 2026
fcceb4a
chore(den-web): restore generated tsbuildinfo
benjaminshafii Jul 23, 2026
51999e2
test(evals): org-delete danger zone + admin user delete fraimz flow
benjaminshafii Jul 23, 2026
43810f0
fix(enterprise-mcp): require invalid_token proof before destroying cr…
benjaminshafii Jul 24, 2026
ecaf072
feat(workbench): vertical tabs in sidebar, Arc-style split view, hist…
benjaminshafii Jul 24, 2026
12fc291
fix(installer): trust OS certificate store and brand the installer (#…
benjaminshafii Jul 24, 2026
3fdb7ef
feat(attachments): accept any file type and route model parts by prov…
benjaminshafii Jul 24, 2026
7b86265
ignore: update download stats 2026-07-24
actions-user Jul 24, 2026
f1d394f
chore(release): bump to 0.17.41
benjaminshafii Jul 24, 2026
a1fb03e
chore(aur): update PKGBUILD for 0.17.41
release-bot Jul 24, 2026
8e91863
feat(attachments): transcript badges for any attachment, clickable ar…
benjaminshafii Jul 24, 2026
2f3c580
fix(den): gate OAuth refresh on session liveness and stop reporting i…
benjaminshafii Jul 24, 2026
7ae6950
Arc-style shell: floating panel cards, denser chrome, sidebar account…
benjaminshafii Jul 24, 2026
59136b1
feat(den-web): server-render the workspace favicon from the org squar…
benjaminshafii Jul 24, 2026
03d837e
chore(release): bump to 0.18.0
benjaminshafii Jul 24, 2026
9f7a504
chore(aur): update PKGBUILD for 0.18.0
release-bot Jul 24, 2026
68ce4e5
fix(installer): trust every OS certificate source on inspected networ…
benjaminshafii Jul 24, 2026
218a13c
fix(den): attribute our own MCP lifecycle deadline to OpenWork (#3088)
benjaminshafii Jul 24, 2026
12b0e88
feat(composer): render skills as /slug pills; default to empty state …
benjaminshafii Jul 24, 2026
39e734a
test(installer): prove OS trust-store pickup on real Windows (#3089)
benjaminshafii Jul 24, 2026
73893d2
feat: add guided organization install activation (#3084)
benjaminshafii Jul 24, 2026
8ea3d9b
fix(composer): align the new-task composer with the cards below it (#…
benjaminshafii Jul 25, 2026
b60c1f4
fix(nuke): wipe workspace and session state on fresh start (#3094)
benjaminshafii Jul 25, 2026
09dc7c0
chore(release): v0.18.1 (#3095)
benjaminshafii Jul 25, 2026
cb9ecdf
chore(aur): update PKGBUILD for 0.18.1
release-bot Jul 25, 2026
d0aac1e
feat(shell): fold the bottom status bar into the sidebar account menu…
benjaminshafii Jul 25, 2026
fcb2a62
chore(installer): report the real release version (#3098)
benjaminshafii Jul 25, 2026
dd6f3f0
refactor: collapse path, base-URL and workspace-store duplication int…
benjaminshafii Jul 25, 2026
087ef0e
fix(shell): keep live status inside the account menu, not on the coll…
benjaminshafii Jul 25, 2026
363ab0a
fix(den): bound config object version payloads
benjaminshafii Jul 25, 2026
d2b6199
fix(den): widen config object version payload columns
benjaminshafii Jul 25, 2026
b8546fd
fix(den): preserve admin capability arguments (#3102)
benjaminshafii Jul 25, 2026
c82f8bb
test(den): add config object payload boundary smoke (#3103)
benjaminshafii Jul 25, 2026
0c75029
feat(den-web): rework "Continue on your computer" install step (#3099)
benjaminshafii Jul 25, 2026
2fda607
fix(sidebar): align every row on shared glyph and label lanes (#3116)
benjaminshafii Jul 25, 2026
e61c527
docs: document team prompts and token usage (#3109)
benjaminshafii Jul 25, 2026
0bbe89d
docs: add capability concept tutorials (#3108)
benjaminshafii Jul 25, 2026
569008b
test(den-web): assert install-link error intent instead of stale copy…
benjaminshafii Jul 25, 2026
ea58461
fix(settings): wire extension readiness routing (#3111)
benjaminshafii Jul 25, 2026
9a40556
feat(den-web): preview desktop prompt cards (#3114)
benjaminshafii Jul 25, 2026
8f3e837
chore(installer): report the real release version (#3105)
benjaminshafii Jul 25, 2026
4746abb
Revert "feat(den-web): preview desktop prompt cards (#3114)"
benjaminshafii Jul 25, 2026
81c4b79
fix(den-web): describe the real macOS installer steps (#3121)
benjaminshafii Jul 25, 2026
60f31db
test(evals): refresh the installer release contract for DMG artifacts…
benjaminshafii Jul 25, 2026
34cbd65
fix(den): restore the external MCP tool-call budget on the live clien…
benjaminshafii Jul 25, 2026
d0ccf3a
test(evals): drop core flow reopen requirement (#3123)
benjaminshafii Jul 25, 2026
1345d51
feat(desktop): isolate dev profiles per worktree (#3124)
benjaminshafii Jul 25, 2026
2cbc4c7
docs: refresh create skill from chat flow (#3130)
benjaminshafii Jul 25, 2026
72fb04e
fix(desktop): route updater manifest through OS trust and guard bare …
benjaminshafii Jul 25, 2026
cb4c139
docs(enterprise): document outbound network access and guard it in CI…
benjaminshafii Jul 25, 2026
7148bda
docs(helm): expose the private-network MCP opt-out to operators (#3133)
benjaminshafii Jul 25, 2026
bf32618
docs(self-host): make the cloud catalog diagnostic actionable on-prem…
benjaminshafii Jul 25, 2026
5fc4a4b
docs(self-host): document the private-network (semi air-gapped) deplo…
benjaminshafii Jul 25, 2026
4e675e0
test(evals): pin the semi air-gapped Den deployment contract (#3136)
benjaminshafii Jul 25, 2026
743d7d8
docs(self-host): consolidate network, air-gap, and certificate guidan…
benjaminshafii Jul 25, 2026
a529b45
test(den): make Skill CRUD proof Daytona-ready (#3141)
reachjalil Jul 26, 2026
bc6b20d
fix(evals): start native MariaDB in root runtimes (#3142)
reachjalil Jul 26, 2026
9859662
fix(evals): resume authenticated native MariaDB (#3143)
reachjalil Jul 26, 2026
b92be76
fix(evals): resolve source exports in Den seed (#3145)
reachjalil Jul 26, 2026
9c8099c
fix(evals): allow isolated Den demo signup (#3146)
reachjalil Jul 26, 2026
f9c6192
fix(evals): clear stale Den Web build cache (#3147)
reachjalil Jul 26, 2026
6a1260d
fix(evals): trust Den proof loopback origins (#3148)
reachjalil Jul 26, 2026
85f149e
fix(policy): actually enforce org-managed models on the desktop (#3140)
benjaminshafii Jul 26, 2026
a3cf39b
feat(cloud): OpenWork Cloud alpha — a full instance in the browser, n…
benjaminshafii Jul 26, 2026
a0758de
fix(desktop): keep external fetches on Chromium network stack (#3149)
benjaminshafii Jul 26, 2026
776d079
chore: release v0.18.2
benjaminshafii Jul 26, 2026
2d5d7f4
fix(cloud): complete the web sign-in loop back into the instance (#3151)
benjaminshafii Jul 26, 2026
ba5a26a
fix(models): recover managed model empty state (#3150)
benjaminshafii Jul 26, 2026
cfec9f0
fix(den): answer CORS for the handoff exchange from Cloud instance or…
benjaminshafii Jul 26, 2026
2f73ebc
fix(release): stage server npm package (#3152)
benjaminshafii Jul 26, 2026
5e7e788
fix(den-web): let signed-in Cloud instances reach Den, bearer-only (#…
benjaminshafii Jul 26, 2026
1f3928a
chore(aur): update PKGBUILD for 0.18.2
release-bot Jul 26, 2026
b0f3d17
fix(cloud): require org choice after handoff (#3154)
benjaminshafii Jul 26, 2026
1a609e4
chore: bump version to 0.18.3
benjaminshafii Jul 26, 2026
0cfe388
chore(aur): update PKGBUILD for 0.18.3
release-bot Jul 26, 2026
e75aa18
fix(cloud): per-user instances and a safe worker state machine (#3156)
benjaminshafii Jul 26, 2026
b4a10e8
fix(cloud): ship the OpenCode plugins in the Cloud snapshot (#3157)
benjaminshafii Jul 26, 2026
dd6b1be
docs: clarify connectors, skills, and plugins (#3129)
benjaminshafii Jul 26, 2026
1f41a52
ignore: update download stats 2026-07-26
actions-user Jul 26, 2026
1333a38
feat(den-web): make cloud setup two steps — install the app, turn on …
benjaminshafii Jul 27, 2026
7567eae
fix(den): download desktop app directly (#3166)
reachjalil Jul 27, 2026
35c2d22
fix(den-web): align org chooser with desktop sign-in card (#3167)
benjaminshafii Jul 27, 2026
c23f487
fix(desktop): scope nuke to the profile that ran it; opt-in bootstrap…
benjaminshafii Jul 27, 2026
7dc9438
fix(sidebar): nest sessions under folders and add workspace avatars (…
benjaminshafii Jul 27, 2026
581a50a
chore(settings): remove the Customization tab (#3172)
benjaminshafii Jul 27, 2026
b5b3bc6
feat(den-web): rename LLM Providers to Bring your Own Keys and rebuil…
benjaminshafii Jul 27, 2026
129a446
feat(den-web): rebuild OpenWork Models page on shared den primitives …
benjaminshafii Jul 27, 2026
840c7ba
feat(den-web): rebuild onboarding around the desktop app and model ch…
benjaminshafii Jul 27, 2026
bfd9897
Add Den-activated enterprise desktop distribution (#3170)
reachjalil Jul 27, 2026
76565e9
chore(release): v0.18.4
benjaminshafii Jul 27, 2026
8782c0a
fix(desktop): stop pinning the updater test to a released version (#3…
benjaminshafii Jul 27, 2026
6c70f18
feat(den-web): rebuild OpenWork Models page on the Paper redesign (#3…
benjaminshafii Jul 27, 2026
a137da6
fix(release): unblock Daytona and AUR publishing (#3175)
benjaminshafii Jul 27, 2026
fe00265
chore(aur): update PKGBUILD for 0.18.4
release-bot Jul 27, 2026
ee4ec02
fix(connect): align OAuth windows with install UI (#3169)
reachjalil Jul 27, 2026
dc75c67
fix(desktop): reveal enterprise activation gate (#3179)
reachjalil Jul 27, 2026
4b93ea0
feat: add sign-in-required OpenWork Cloud installer (#3177)
reachjalil Jul 27, 2026
50a300a
chore(release): v0.18.5
benjaminshafii Jul 27, 2026
f50999f
ignore: update download stats 2026-07-27
actions-user Jul 27, 2026
e84ef30
feat(extensions): unify Extensions inventory and retire Connect tab (…
benjaminshafii Jul 27, 2026
f2ab33f
chore(aur): update PKGBUILD for 0.18.5
release-bot Jul 27, 2026
b4e16c1
chore: update models snapshot (#3183)
github-actions[bot] Jul 27, 2026
d7e295a
fix(desktop): keep Enterprise activation isolated (#3185)
reachjalil Jul 27, 2026
90983ea
fix(den-web): remove redundant cloud download action (#3186)
reachjalil Jul 27, 2026
eb5a9fb
chore(release): v0.18.6
benjaminshafii Jul 27, 2026
9ef5364
chore(aur): update PKGBUILD for 0.18.6
release-bot Jul 27, 2026
2e84099
fix(app): restore the Extensions typecheck (#3192)
benjaminshafii Jul 27, 2026
ede90f6
fix(composer): collapse pasted text only when it would scroll (#3193)
reachjalil Jul 27, 2026
a6080f8
fix(app): render markdown tables in the artifact editor (#3190)
benjaminshafii Jul 27, 2026
9d14c9b
chore: remove the openwork-orchestrator (#3181)
benjaminshafii Jul 27, 2026
173bab4
feat(extensions): name apps, connections, and MCPs consistently (#3196)
benjaminshafii Jul 27, 2026
dda3325
feat(diagnostics): add independent runtime MCP verification with deta…
reachjalil Jul 27, 2026
c0cd5ae
feat(den-gateway): serve the app and route each user to their own ins…
benjaminshafii Jul 27, 2026
0fcc716
fix(diagnostics): probe activated on-prem Den origins and correct eng…
reachjalil Jul 27, 2026
2fe88f8
chore(release): v0.18.7
reachjalil Jul 27, 2026
ae887a2
chore(aur): update PKGBUILD for 0.18.7
release-bot Jul 27, 2026
85fdf06
feat(den-gateway): one origin, gateway sign-in returns, and a publish…
benjaminshafii Jul 27, 2026
514d853
fix(desktop): load system CAs from OS trust stores; remove obsolete i…
benjaminshafii Jul 27, 2026
6b12dd0
fix(updater): keep staged updates installable and self-heal the insta…
benjaminshafii Jul 27, 2026
d1c395b
feat(diagnostics): capture MCP registration errors and cloud endpoint…
benjaminshafii Jul 27, 2026
0589602
fix(diagnostics): omit SNI servername for IP-literal cloud endpoints …
benjaminshafii Jul 27, 2026
965de30
fix(app): stabilize gateway bootstrap snapshot (#3205)
benjaminshafii Jul 27, 2026
e08e0a1
fix(gateway): send sign-in to den-web and approve the gateway return …
benjaminshafii Jul 27, 2026
d6bec90
fix(app): reflect the Den session after a web handoff instead of show…
benjaminshafii Jul 27, 2026
1aba9e3
feat(den-web): replace cloud tab with web launch (#3215)
benjaminshafii Jul 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
38 changes: 38 additions & 0 deletions .devcontainer/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
# Full Electron + Den dev environment for Daytona sandboxes.
#
# Clones the repo from GitHub, installs deps, and provides
# Xvfb + noVNC so you can see/steer the real Electron app
# from your browser.

FROM node:20-bookworm

# System deps for Electron / Chromium + virtual display + utils
RUN apt-get update && apt-get install -y --no-install-recommends \
git unzip dbus dbus-x11 \
libgtk-3-0 libnotify-dev libnss3 libxss1 libasound2 \
libxtst6 libatk-bridge2.0-0 libdrm2 libgbm1 libxrandr2 \
libxcomposite1 libxdamage1 libxfixes3 libcups2 \
libpango-1.0-0 libcairo2 \
xvfb x11vnc novnc websockify fluxbox xterm \
default-mysql-client \
&& rm -rf /var/lib/apt/lists/*

# pnpm + bun
RUN corepack enable && corepack prepare pnpm@latest --activate
RUN npm install -g bun

# noVNC index
RUN ln -sf /usr/share/novnc/vnc.html /usr/share/novnc/index.html

ENV DISPLAY=:99
ENV ELECTRON_DISABLE_SANDBOX=1
ENV PNPM_HOME=/root/.local/share/pnpm
ENV PATH=$PNPM_HOME:$PATH

# Clone and install
ARG REPO_URL=https://github.com/different-ai/openwork.git
ARG BRANCH=dev
WORKDIR /workspace
RUN git clone --depth 1 --branch $BRANCH $REPO_URL . && pnpm install --frozen-lockfile || pnpm install

EXPOSE 3005 5173 6080 8788 9825
36 changes: 36 additions & 0 deletions .devcontainer/Dockerfile.daytona-server
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# Daytona image for the OpenWork Den server stack.
#
# This intentionally does not run Docker inside Daytona. The sandbox runs the
# same services as packaging/docker/docker-compose.den-dev.yml directly:
# MySQL, Den API, Den Web, and the worker proxy.
FROM daytonaio/sandbox:0.6.0

USER root

RUN apt-get update \
&& DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
ca-certificates \
curl \
default-mysql-client \
default-mysql-server \
git \
procps \
sudo \
&& /usr/local/share/nvm/current/bin/npm install -g pnpm@10.27.0 bun \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/* /root/.cache /root/.npm /tmp/*

WORKDIR /workspace

RUN git clone --depth 1 --branch dev https://github.com/different-ai/openwork.git . \
&& mkdir -p /workspace/.openwork-daytona \
&& sha256sum /workspace/pnpm-lock.yaml | cut -d ' ' -f 1 > /workspace/.openwork-daytona/pnpm-lock.sha256 \
&& git gc --prune=now \
&& rm -rf /home/daytona/.cache /home/daytona/.npm /home/daytona/.local/share/pnpm/store \
/workspace/node_modules

RUN chown -R daytona:daytona /workspace \
&& printf 'daytona ALL=(ALL) NOPASSWD:ALL\n' >/etc/sudoers.d/daytona-openwork \
&& chmod 0440 /etc/sudoers.d/daytona-openwork

USER daytona
29 changes: 29 additions & 0 deletions .devcontainer/Dockerfile.daytona-vnc
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Daytona VNC/Computer Use image with OpenWork preinstalled.
#
# Use this for Electron/noVNC tests instead of the generic devcontainer image.
# The base image already contains the desktop stack Daytona expects:
# Xvfb, XFCE, x11vnc, noVNC, websockify, and dbus-x11.
FROM daytonaio/sandbox:0.6.0

USER root

RUN apt-get update \
&& apt-get install -y --no-install-recommends ffmpeg \
&& rm -rf /var/lib/apt/lists/*

RUN /usr/local/share/nvm/current/bin/npm install -g pnpm@10.27.0 bun

WORKDIR /workspace

RUN git clone --depth 1 --branch dev https://github.com/different-ai/openwork.git . \
&& mkdir -p /workspace/.openwork-daytona \
&& sha256sum /workspace/pnpm-lock.yaml | cut -d ' ' -f 1 > /workspace/.openwork-daytona/pnpm-lock.sha256 \
&& /usr/local/share/nvm/current/bin/npm cache clean --force \
&& git gc --prune=now \
&& rm -rf /root/.cache /root/.npm \
/home/daytona/.cache /home/daytona/.npm /home/daytona/.local/share/pnpm/store \
/workspace/node_modules /tmp/*

RUN chown -R daytona:daytona /workspace

USER daytona
159 changes: 159 additions & 0 deletions .devcontainer/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,159 @@
# Daytona / Dev Container Setup

Full-stack dev environment that runs the **real Electron app** + Den stack in a cloud sandbox. You see and steer the desktop app through your browser via noVNC.

## What's included

| Service | Port | Description |
|---------|------|-------------|
| **Desktop App (noVNC)** | 6080 | The real Electron app rendered in a virtual display, accessible in your browser |
| **Den Web** | 3005 | Admin dashboard for managing orgs, restrictions, providers |
| **Den API** | 8788 | Control plane API |
| **CDP Debug** | 9825 | Chrome DevTools Protocol — for app and browser automation |
| **Vite HMR** | 5173 | Hot module replacement for the React UI |
| **MySQL** | 3306 | Database (internal) |

## Quick start with Daytona Electron/noVNC

```bash
bash .devcontainer/create-daytona-openwork-snapshot.sh # one-time / refresh when deps change
bash .devcontainer/test-on-daytona.sh [branch-or-commit]
```

The test script creates a sandbox from the reusable `openwork-eval-vnc` snapshot
when present, checks out the target ref, skips `pnpm install` if the lockfile is
unchanged, starts XFCE/noVNC, Vite, and Electron, then prints the noVNC and CDP
URLs. If the snapshot is missing, it fails fast and tells you to create it. The
snapshot intentionally does not bake `node_modules`; installs use the reusable
`openwork-eval-pnpm-store` volume so the image stays under Daytona's 20 GB limit.

For provider evals, create/populate the reusable Daytona secrets volume once:

```bash
bash .devcontainer/setup-daytona-secrets-volume.sh .newtoken
bash .devcontainer/setup-daytona-secrets-volume.sh .anthropic anthropic.env
```

Future Daytona test sandboxes mount `openwork-eval-secrets:/daytona-secrets`
and source every `/daytona-secrets/*.env` file automatically before Electron
starts. Use this volume for provider keys and other eval-only secrets; never
commit those files into the repo.

For downloadable eval artifacts or optional video recording, use:

```bash
bash .devcontainer/test-on-daytona.sh [branch-or-commit] --artifacts-volume
bash .devcontainer/test-on-daytona.sh [branch-or-commit] --record-video
```

The artifacts flow mounts `openwork-eval-artifacts:/daytona-artifacts`, starts a
static download server on port 8090, and prints a Daytona preview URL. Recording
writes mp4 files to `/daytona-artifacts/recordings` and prints the direct video
URL. Screenshots write png files to `/daytona-artifacts/screenshots` for quick
AI/human validation checkpoints. Stop recording with
`.devcontainer/stop-daytona-recording.sh` so ffmpeg finalizes the file cleanly.

Do not use the generic `daytona create https://github.com/different-ai/openwork`
flow for Electron/noVNC tests. The default resource size is too small and the
generic image path does not guarantee the desktop stack we need.

## Quick start with Daytona server

```bash
bash .devcontainer/create-daytona-openwork-server-snapshot.sh # one-time / refresh when deps change
bash .devcontainer/test-server-on-daytona.sh [branch-or-commit]
```

The server helper creates a separate public Daytona sandbox for the Den stack:
MySQL, Den API, Den Web, and the worker proxy. It prints public preview URLs and
the exact Electron command to point a desktop sandbox at that server:

```bash
bash .devcontainer/test-on-daytona.sh [branch-or-commit] \
--den-base-url https://3005-...daytonaproxy... \
--den-api-base-url https://8788-...daytonaproxy...
```

This keeps the architecture simple: the server sandbox owns cloud auth, orgs,
policies, workers, and persistence; the Electron sandbox stays a real desktop
client and talks to the server through public Daytona preview URLs.

## How it works

1. `.devcontainer/Dockerfile.daytona-vnc` starts from `daytonaio/sandbox:0.6.0`,
which includes Daytona's expected desktop packages: Xvfb, XFCE, x11vnc,
noVNC, websockify, and dbus-x11.
2. `.devcontainer/create-daytona-openwork-snapshot.sh` bakes that image into
`openwork-eval-vnc` without `node_modules`.
3. `/opt/openwork-daytona/start-daytona-vnc.sh` starts Xvfb, XFCE, x11vnc, and
noVNC on display `:99`.
4. `test-on-daytona.sh` installs dependencies through the reusable
`openwork-eval-pnpm-store` volume when `node_modules` is missing or the
lockfile changed.
5. Vite serves the React UI on port 5173.
6. `/opt/openwork-daytona/start-daytona-electron.sh` sources optional secrets,
applies Daytona-safe Chromium flags, and starts Electron on display `:99`.
7. **CDP on port 9825** enables Chrome MCP and browser-tool automation.
8. Optional artifact capture mounts `/daytona-artifacts`, serves it on port 8090,
records display `:99` with ffmpeg when `--record-video` is passed, and can
capture screenshot checkpoints with `.devcontainer/capture-daytona-screenshot.sh`.

## Validation Evidence

Use three layers of evidence for Daytona UI work:

- **CDP assertions:** use browser tools against port 9825 to inspect text, URL,
state, and accessibility snapshots. This is the primary AI validation path.
- **Screenshots:** run `daytona exec "$SANDBOX" -- 'bash .devcontainer/capture-daytona-screenshot.sh'` after important states. These png files live in `/daytona-artifacts/screenshots`.
- **Recordings:** start with `--record-video --recording-name <name>` for flows
that need PR evidence. These mp4 files live in `/daytona-artifacts/recordings`.

Recordings prove the flow to humans. CDP assertions and screenshots give the AI
fast checkpoints to decide whether behavior is correct before reporting success.

## AI Skills

The Daytona toolbox is exposed to opencode through focused skills:

- `daytona-dev`: overview of the Daytona setup and when to use each piece.
- `daytona-cloud-server`: Den Web/API, worker proxy, marketplace, cloud auth, and org policy flows.
- `daytona-secrets-volume`: add and verify provider keys or eval-only secrets in `/daytona-secrets`.
- `daytona-electron-test`: run and drive the real Electron app through CDP/noVNC.
- `daytona-recording-artifacts`: screenshots, recordings, before/after videos, and PR evidence.
- `run-evals`: orchestrates evals and pulls in the relevant Daytona skill based on the flow.

## Testing the customization system

1. Open **Den Web** (port 3005) in a separate tab
2. Sign up → create org → Org Settings → UI Customization
3. Set overrides → Save
4. In the **Electron app** (noVNC on port 6080):
- Cloud → developer mode → base URL `http://localhost:3005`
- Sign in → Settings → see the desktop policy banner

## Architecture

```
Your Browser
├── :6080 noVNC ──▶ x11vnc ──▶ XFCE/Xvfb ──▶ Electron App
│ │
│ ├── CDP :9825 (automatable)
│ └── Vite HMR :5173
├── :3005 Den Web (Next.js)
└── :8788 Den API (Hono) ──▶ MySQL :3306
```

With a separate server sandbox, the Electron box uses Daytona preview URLs for
Den Web/API instead of `localhost`, while the server sandbox still keeps its
internal service graph local.

## Automation

The Electron app exposes CDP on port 9825. You can:

- Connect Playwright: `const browser = await chromium.connectOverCDP('ws://localhost:9825')`
- Connect Chrome MCP for AI agent testing
- Take screenshots, run UI tests, etc.
63 changes: 63 additions & 0 deletions .devcontainer/capture-daytona-screenshot.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
#!/usr/bin/env bash
set -euo pipefail

# Capture a single Daytona Electron display frame as a PNG artifact. Screenshots
# are for quick AI/human validation; videos are still the durable PR evidence.

OUTPUT="/daytona-artifacts/screenshots/daytona-screenshot-$(date +%Y%m%d-%H%M%S).png"
SIZE="1920x1080"

while [ "$#" -gt 0 ]; do
case "$1" in
--output)
shift
OUTPUT="${1:?missing output path}"
;;
--size)
shift
SIZE="${1:?missing screenshot size}"
;;
--help|-h)
printf '%s\n' \
"Usage: capture-daytona-screenshot.sh [--output PATH] [--size WxH]" \
"" \
"Captures DISPLAY, defaulting to :99, and writes a PNG file."
exit 0
;;
--*)
echo "Unknown option: $1" >&2
exit 1
;;
*)
echo "Unexpected argument: $1" >&2
exit 1
;;
esac
shift
done

if ! command -v ffmpeg >/dev/null 2>&1; then
echo "ERROR: ffmpeg is required for Daytona screenshots." >&2
exit 1
fi

if [[ ! "$SIZE" =~ ^[0-9]+x[0-9]+$ ]]; then
echo "ERROR: screenshot size must use WxH format, for example 1920x1080" >&2
exit 1
fi

FINAL_OUTPUT="$OUTPUT"
CAPTURE_OUTPUT="$OUTPUT"
if [[ "$OUTPUT" = /daytona-artifacts/* ]]; then
CAPTURE_OUTPUT="/tmp/daytona-screenshot-$(basename "$OUTPUT")"
fi

mkdir -p "$(dirname "$CAPTURE_OUTPUT")"
ffmpeg -y -f x11grab -video_size "$SIZE" -i "${DISPLAY:-:99}" -frames:v 1 "$CAPTURE_OUTPUT" >/tmp/daytona-screenshot.log 2>&1

if [ "$CAPTURE_OUTPUT" != "$FINAL_OUTPUT" ]; then
mkdir -p "$(dirname "$FINAL_OUTPUT")"
cp "$CAPTURE_OUTPUT" "$FINAL_OUTPUT"
fi

echo "Screenshot saved: $FINAL_OUTPUT"
34 changes: 34 additions & 0 deletions .devcontainer/create-daytona-openwork-server-snapshot.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
#!/usr/bin/env bash
set -euo pipefail

# Build/refresh the reusable Daytona snapshot used by Den server sandboxes.

ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
SNAPSHOT_NAME="${DAYTONA_SERVER_SNAPSHOT:-openwork-server}"
REGION="${DAYTONA_TARGET:-us}"

snapshot_id() {
daytona snapshot list -f json | node -e 'const name = process.argv[1]; let input = ""; process.stdin.on("data", (chunk) => input += chunk); process.stdin.on("end", () => { const snapshot = JSON.parse(input).find((item) => item.name === name); if (snapshot) process.stdout.write(snapshot.id || snapshot.name); });' "$1"
}

existing_snapshot_id="$(snapshot_id "$SNAPSHOT_NAME")"
if [ -n "$existing_snapshot_id" ]; then
echo "==> Deleting existing snapshot: $SNAPSHOT_NAME"
daytona snapshot delete "$existing_snapshot_id" >/dev/null <<< "y"
for _ in $(seq 1 60); do
if [ -z "$(snapshot_id "$SNAPSHOT_NAME")" ]; then
break
fi
sleep 5
done
fi

echo "==> Creating Daytona server snapshot: $SNAPSHOT_NAME"
daytona snapshot create "$SNAPSHOT_NAME" \
--dockerfile "$ROOT_DIR/.devcontainer/Dockerfile.daytona-server" \
--cpu 4 \
--memory 8 \
--disk 10 \
--region "$REGION"

echo "Snapshot ready: $SNAPSHOT_NAME"
33 changes: 33 additions & 0 deletions .devcontainer/create-daytona-openwork-snapshot.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
#!/usr/bin/env bash
set -euo pipefail

# Build/refresh the reusable Daytona VNC snapshot used by eval sandboxes from
# the prebuilt GHCR image. The image is built by GitHub Actions on dev pushes.

SNAPSHOT_NAME="${DAYTONA_EVAL_SNAPSHOT:-openwork-eval-vnc}"
IMAGE="${DAYTONA_EVAL_IMAGE:-ghcr.io/different-ai/openwork-eval-vnc:dev}"
REGION="${DAYTONA_TARGET:-us}"

existing_snapshot_id="$(daytona snapshot list -f json | node -e 'const name = process.argv[1]; let input = ""; process.stdin.on("data", (chunk) => input += chunk); process.stdin.on("end", () => { const snapshot = JSON.parse(input).find((item) => item.name === name); if (snapshot) process.stdout.write(snapshot.id || snapshot.name); });' "$SNAPSHOT_NAME")"

if [ -n "$existing_snapshot_id" ]; then
echo "==> Deleting existing snapshot: $SNAPSHOT_NAME"
daytona snapshot delete "$existing_snapshot_id" >/dev/null <<< "y"
for _ in $(seq 1 60); do
if ! daytona snapshot list -f json | node -e 'const name = process.argv[1]; let input = ""; process.stdin.on("data", (chunk) => input += chunk); process.stdin.on("end", () => { const snapshot = JSON.parse(input).find((item) => item.name === name); process.exit(snapshot ? 1 : 0); });' "$SNAPSHOT_NAME"; then
sleep 5
else
break
fi
done
fi

echo "==> Creating Daytona eval snapshot: $SNAPSHOT_NAME"
daytona snapshot create "$SNAPSHOT_NAME" \
--image "$IMAGE" \
--cpu 4 \
--memory 8 \
--disk 10 \
--region "$REGION"

echo "Snapshot ready: $SNAPSHOT_NAME"
Loading