daniel-lxs
1c7700eb69
feat(images): enforce 10MB limit UI+backend; reuse original base64 via cache to avoid re-encoding
...
UI: early-reject >10MB in ChatTextArea paste/drop handlers. Backend: validate >10MB in savePastedImageToTemp(). Cache base64 mapped to file path and consume in normalizeImageRefsToDataUrls() to avoid re-encoding UI-pasted images.
2025-10-28 11:33:08 -05:00
daniel-lxs
5d3f45bec0
fix(image-uris): broaden Unix path regex to include common Linux roots
...
Use /^[^?#]*\/(?:Users|home|root|var|tmp|opt)\/[^?#]{1,300}\.(png|jpg|jpeg|gif|webp)$/i to support Linux/macOS while keeping bounds and avoiding backtracking.
2025-10-27 20:46:27 -05:00
daniel-lxs
634ee677d9
fix(image-uris): resolve review-bot issues
...
ClineProvider.convertToWebviewUri: align JSDoc with non-throwing behavior and fallback to file URI.
imageDataUrl.webviewUriToFilePath: remove impossible CDN host check from vscode-resource branch; expand Windows path regex to allow spaces while keeping bounds.
ChatTextArea: clear pendingImageUploadsRef via captured ref in cleanup to avoid stale closure.
2025-10-27 20:30:25 -05:00
daniel-lxs
9dc853cf7f
feat(images): persist base64 in backend messages; normalize URIs once at ingestion; support VS Code CDN webview URLs in normalization
2025-10-27 19:30:16 -05:00
daniel-lxs
3d796de327
security: fix host injection vulnerability in URL validation
...
- Replace dangerous substring check webviewUri.includes('vscode-cdn.net')
- Add proper URL host validation using URL constructor
- Check url.host === 'vscode-cdn.net' to prevent injection via paths/queries
- Graceful fallback when URL parsing fails
- Addresses final CodeQL warning for incomplete URL substring sanitization
2025-10-27 14:33:42 -05:00
daniel-lxs
a1c402e77b
security: harden URL parsing against ReDoS and injection attacks
...
- Add strict prefix validation: require vscode-resource://vscode-webview/ prefix
- Add URI length limits (max 2048 chars) to prevent DoS
- Replace potentially vulnerable regex with bounded, anchored patterns
- Use ^ and $ anchors to prevent partial matches
- Limit character classes to prevent backtracking (e.g., [a-zA-Z0-9._-]{1,50})
- Add proper error handling for decode failures
- Addresses CodeQL warnings for polynomial regex and incomplete URL sanitization
2025-10-27 14:26:28 -05:00
daniel-lxs
7029f1d6f8
security: fix polynomial regex and improve URL sanitization in imageDataUrl.ts
...
- Replace potentially polynomial regex /(?:Users|C:)([^?#]+\.(?:png|jpg|jpeg|gif|webp))/i
- Split into separate bounded patterns for Unix and Windows paths
- Add length limit {0,500} to prevent ReDoS attacks
- Improve URL substring sanitization for vscode-userdata and vscode-cdn.net URIs
- Addresses GitHub CodeQL security warnings for polynomial regex vulnerability
2025-10-27 14:24:06 -05:00
daniel-lxs
32b708592d
optimize: implement efficient approach for PR #8225 - store base64 directly in backend messages
...
- Remove unnecessary memory caching logic
- Store base64 data URLs directly in ClineMessage.images[] and ApiMessage content when first received
- Eliminate conversion overhead at API call time (base64 already available)
- Keep frontend memory efficient with webview URIs for display
- Much simpler and more efficient than caching approach
- One-time conversion: webview URI → base64 when storing in backend
- API calls use pre-stored base64 directly (no file I/O or conversion needed)
This achieves PR goals with optimal performance: frontend memory efficiency + instant API calls
2025-10-27 13:42:41 -05:00
daniel-lxs
e7531e5b6e
fix: complete PR #8225 - add missing webview URI to base64 conversion
...
- Add normalizeImageRefsToDataUrls() function to convert webview URIs to base64 data URLs
- Add formatImagesIntoBlocksAsync() for async image processing in backend
- Update Task.ts to use async conversion when storing images in backend messages
- Backend now stores base64 (for API calls), frontend displays webview URIs (memory efficient)
- Fixes OpenRouter and other providers not being able to see attached images
- Maintains PR goals: webview memory efficiency + working image functionality
2025-10-27 12:42:27 -05:00
Daniel
f34243e1c9
Merge branch 'main' into feat/webview-image-uri
2025-09-25 18:36:43 -05:00
Matt Rubens
8485548f53
Show the Roo provider on the welcome screen ( #8317 )
2025-09-25 16:13:04 -04:00
Hannes Rudolph
ab0644d367
Correct tool use suggestion to improve model adherence to suggestion ( #8315 )
...
* Correct tool use suggestion to improve model adherence to suggestion
* tweak
2025-09-25 11:53:31 -06:00
roomote[bot]
43c1de0d7e
feat: log out from cloud when resetting extension state ( #8312 )
...
Co-authored-by: Roo Code <roomote@roocode.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-25 12:24:46 -04:00
github-actions[bot]
bf1aafad9b
Changeset version bump ( #8306 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-25 10:25:30 -04:00
Hannes Rudolph
798801d582
Fix frequent "No tool used" errors by clarifying tool-use rules ( #8292 )
2025-09-25 09:24:46 -04:00
Hannes Rudolph
2f1b94f430
fix: include initial ask in condense summarization ( #8293 ) ( #8298 )
...
* fix: include initial ask in condense summarization (#8293 )
---------
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-24 23:14:44 -06:00
github-actions[bot]
8dbd8c4b1b
Changeset version bump ( #8271 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-23 19:14:03 -04:00
Bruno Bergher
d8dd19a6ed
ux: Collapse thinking blocks by default (but control all of them with a keyboard shortcut) ( #8254 )
...
Co-authored-by: ellipsis-dev[bot] <65095814+ellipsis-dev[bot]@users.noreply.github.com>
Co-authored-by: Roo Code <roomote@roocode.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-23 18:48:04 -04:00
Matt Rubens
0682629ac8
Cloud account switcher ( #8223 )
...
* Cloud account switcher
* Bare metal evals fixes (#8224 )
Co-authored-by: Roo Code <roomote@roocode.com>
* Rounded icons in chat account switcher
* Visual tweaks to CloudView
* Remove hardcoded timeout
* Safer check
* PR feedback
* Fix test
* Check for org mismatches in handleCredentialsChange
* Cloud: use the existing auth event flow to handle org switching
* Cleanup: broadcast() might be confusingly named.
---------
Co-authored-by: Chris Estreich <cestreich@gmail.com>
Co-authored-by: Roo Code <roomote@roocode.com>
Co-authored-by: Bruno Bergher <bruno@roocode.com>
Co-authored-by: John Richmond <5629+jr@users.noreply.github.com>
2025-09-23 18:18:28 -04:00
roomote[bot]
382ab63ea1
feat: add zai-org/GLM-4.5-turbo model to Chutes provider ( #8157 )
...
Co-authored-by: Roo Code <roomote@roocode.com>
2025-09-23 17:33:44 -04:00
daniel-lxs
ab402bf1d9
fix: improve vscode-cdn.net URL validation and add copy action check
...
- Fixed CodeQL security issue by properly validating vscode-cdn.net domain instead of substring check
- Added missing copy action check for HTTPS/vscode-cdn URLs before opening image
- Updated tests to match the more secure URL validation logic
2025-09-23 15:06:27 -05:00
daniel-lxs
b10c87422a
feat: add clipboard copy functionality to openImage for file paths
2025-09-23 14:57:26 -05:00
daniel-lxs
addd1bc6e7
feat: enhance openImage function to handle vscode webview CDN URLs
2025-09-23 14:53:09 -05:00
github-actions[bot]
44cbee5e75
Changeset version bump ( #8262 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-23 14:02:01 -04:00
roomote[bot]
807cc999a5
feat: add package.nls.json checking to find-missing-translations script ( #8255 )
...
Co-authored-by: ellipsis-dev[bot] <65095814+ellipsis-dev[bot]@users.noreply.github.com>
Co-authored-by: Roo Code <roomote@roocode.com>
Co-authored-by: daniel-lxs <ricciodaniel98@gmail.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-23 11:10:23 -04:00
roomote[bot]
12f94fc727
fix: respect Ollama Modelfile num_ctx configuration ( #7798 )
...
Co-authored-by: Roo Code <roomote@roocode.com>
Co-authored-by: Hannes Rudolph <hrudolph@gmail.com>
Co-authored-by: daniel-lxs <ricciodaniel98@gmail.com>
2025-09-22 23:08:09 -04:00
Daniel
9dabb85007
Fix: Improve reasoning block formatting for better readability ( #7868 )
2025-09-22 23:02:11 -04:00
Chris Estreich
0e1b23d09c
Bare metal evals fixes ( #8224 )
...
Co-authored-by: Roo Code <roomote@roocode.com>
2025-09-22 12:54:56 -07:00
daniel-lxs
e71ec43d0b
webview: never render base64; render backend-saved image URIs; allow globalStorage URIs; fix 401
2025-09-22 14:46:36 -05:00
Bruno Bergher
6c2aa63cfd
feat: Add keyboard shortcut for toggling auto-approve (Cmd/Ctrl+Alt+A) ( #8214 )
...
Co-authored-by: ellipsis-dev[bot] <65095814+ellipsis-dev[bot]@users.noreply.github.com>
Co-authored-by: Roo Code <roomote@roocode.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-22 11:26:29 -04:00
github-actions[bot]
ceb9d2b9f2
Changeset version bump ( #8199 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-09-20 14:29:01 -07:00
Matt Rubens
32d7e6f2ad
Add an announcement for Supernova ( #8197 )
...
* Add an announcement for Supernova
* Remove duplicate keys
2025-09-20 16:28:28 -04:00
Hannes Rudolph
d956cdb727
Fix duplicate rehydrate during reasoning; centralize rehydrate and preserve cancel metadata ( #8171 )
...
Co-authored-by: daniel-lxs <ricciodaniel98@gmail.com>
2025-09-20 00:34:21 -04:00
roomote[bot]
c0e2c5ef5b
fix: apply tiered pricing for Gemini models via Vertex AI ( #8018 )
...
* fix: apply tiered pricing for Gemini models via Vertex AI
- Modified calculateCost method to handle models where cacheReadsPrice is only defined in tiers
- Added comprehensive tests for Vertex AI tiered pricing calculation
- Fixes issue where local cost calculation always showed highest tier rates
Fixes #8017
* Delete src/api/providers/__tests__/vertex-tiered-pricing.spec.ts
---------
Co-authored-by: Roo Code <roomote@roocode.com>
Co-authored-by: Daniel <57051444+daniel-lxs@users.noreply.github.com>
2025-09-19 22:49:42 -04:00
roomote[bot]
f7a6589719
fix: support dash prefix in parseMarkdownChecklist for todo lists ( #8055 )
...
- Updated regex pattern to support optional dash prefix (e.g., "- [ ] Task")
- Added comprehensive test coverage for both formats
- Fixes issue where todo lists with dash prefixes were not being parsed correctly
Fixes #8054
Co-authored-by: Roo Code <roomote@roocode.com>
2025-09-19 22:45:46 -04:00
github-actions[bot]
b75ef1dd83
Changeset version bump ( #8183 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-19 16:55:05 -04:00
Chris Estreich
a255c95bd0
Get the model id property for a given provider ( #8009 )
2025-09-17 15:24:27 -07:00
roomote[bot]
6d8de53c8f
fix: skip flaky Windows test in custom-system-prompt.spec.ts ( #8023 )
...
Co-authored-by: roomote[bot] <219738659+roomote[bot]@users.noreply.github.com>
Co-authored-by: Roo Code <roomote@roocode.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-16 13:47:56 -04:00
github-actions[bot]
4fe051f4b5
Changeset version bump ( #8026 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-16 12:19:46 -04:00
roomote[bot]
fc9c395af2
feat: Replace + icon with edit icon for New Task button ( #7942 )
...
Co-authored-by: Roo Code <roomote@roocode.com>
2025-09-16 11:55:17 -04:00
roomote[bot]
cde738a450
fix: handle square bracket HTML entities in Gemini responses ( #7577 )
...
Co-authored-by: Roo Code <roomote@roocode.com>
2025-09-16 11:53:52 -04:00
roomote[bot]
6fe90713ab
fix: filter out Claude Code built-in tools (ExitPlanMode, BashOutput, KillBash) ( #7818 )
...
Co-authored-by: Roo Code <roomote@roocode.com>
2025-09-16 11:51:17 -04:00
Daniel
759454b455
fix: handle ByteString conversion errors in OpenAI embedders ( #8008 )
2025-09-15 22:56:20 -04:00
roomote[bot]
beb0a59470
feat: add keyboard shortcut for "Add to Context" action ( #7908 )
...
Co-authored-by: daniel-lxs <ricciodaniel98@gmail.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-15 22:53:40 -04:00
dependabot[bot]
68c5be8030
chore(deps): bump axios from 1.9.0 to 1.12.0 ( #7963 )
...
Bumps [axios](https://github.com/axios/axios ) from 1.9.0 to 1.12.0.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.9.0...v1.12.0 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.12.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-15 15:48:36 -07:00
Daniel
3fe2918e67
Add Z.ai coding plan support ( #8003 )
2025-09-15 17:53:20 -04:00
roomote[bot]
94b4511053
feat: Move slash commands to Settings tab with gear icon for discoverability ( #7988 )
...
Co-authored-by: ellipsis-dev[bot] <65095814+ellipsis-dev[bot]@users.noreply.github.com>
Co-authored-by: Roo Code <roomote@roocode.com>
Co-authored-by: Bruno Bergher <me@brunobergher.com>
Co-authored-by: Mubeen Zulfiqar <mubeen_zulfiqar@yahoo.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-15 15:41:00 -04:00
Mubeen Zulfiqar
1b4819c086
fix: corrected C# tree-sitter query ( #7813 )
2025-09-15 14:10:45 -04:00
github-actions[bot]
d54ff8a604
Changeset version bump ( #7980 )
...
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Matt Rubens <mrubens@users.noreply.github.com>
2025-09-14 15:16:24 -04:00
Chris Estreich
b309a6ad8b
Disable Roomote Control on logout ( #7976 )
2025-09-14 10:47:16 -07:00