* perf(stores): defer safeStorage writes off the interaction path
Session switches funnel every persisted store slice through safeStorage.setItem,
and doing those large JSON.stringify writes synchronously blocked the main
thread for over a second. Add a write-behind buffer that:
- Defers each setItem/removeItem to a later task via setTimeout(0) so the
click-to-paint path is not blocked.
- Coalesces repeated writes to the same key into a single backing flush.
- Serves pending values from memory so read-after-write stays consistent
within the deferral window.
- Flushes synchronously on pagehide/beforeunload/visibilitychange/freeze so
deferred state survives tab close, reload, and the mobile freeze lifecycle.
Adds a test covering write deferral, coalescing, and pending read serving.
* fix(stores): defer persisted JSON serialization
* fix(stores): defer direct safeStorage writes
---------
Co-authored-by: Bohdan Triapitsyn <artmore@protonmail.com>
Packaged desktop showed no sessions in 1.12.4. Root cause: the sanitized
session-list proxy path added in #1538 forwarded the renderer's
"authorization" header (the OpenChamber UI client token) to the managed
OpenCode upstream alongside the managed "Authorization" credential.
OpenCode does not recognize UI client tokens, so every session-list
request answered 401 — only in the packaged app, because only its
renderer (openchamber-ui:// origin) attaches a bearer token; dev web and
dev Electron run same-origin without one. The legacy http-proxy path
overwrote the header correctly, which is why everything except session
lists kept working.
Proxy fix:
- proxy-headers: filter the client "authorization" header out of
forwarded request headers; the OpenCode upstream must only ever see
its own managed credentials. Covered by tests.
Desktop cwd:
- electron: launch the managed OpenCode CLI from the user home instead
of app userData, matching upstream desktop behavior. userData-as-cwd
made OpenCode treat the app-data folder as a separate empty workspace.
Home directory poisoning loop:
- directoryPersistence: stop replaying localStorage homeDirectory
through synchronizeHomeDirectory on boot/auth resync. The persisted
value is only a boot-time cache; replaying it re-wrote stale values
(e.g. a project path) into desktop settings on every start, overriding
the authoritative /api/fs/home resolution.
- persistence: never overwrite an injected window.__OPENCHAMBER_HOME__
with a persisted value.
- useDirectoryStore: host switches happen in place (no reload), so
re-resolve home from the new runtime's /api/fs/home on endpoint
change instead of keeping the previous host's value.
- opencode client: only short-circuit to the injected desktop home when
the active runtime is local; remote runtimes ask /api/fs/home.
Settings hygiene:
- persistSettings: log field names only — change payloads can carry
credentials (UI password, client tokens, tunnel tokens) that must not
reach the log file; drop step-by-step log chatter.
- validateProjectEntries: only stat project paths when the incoming
update actually touches the projects list, not on every settings save.
- remove the write-only approvedDirectories setting everywhere and add
a migration that strips the stale key from persisted settings.
Tests:
- usePluginsStore.test: register an own runtime-fetch module mock so the
suite is independent of process-global mock.module leakage from other
files, and restore globalThis.fetch after the suite.
- persistence.test: clean up the window global created for the suite.
On Windows, SSE events from OpenCode arrive with native backslash
separators and system-cased drive letters (e.g. D:\Dev\...), while the
UI child store keys use forward slashes with lowercase drive letters
from VS Code's workspace folder (e.g. d:/Dev/...). This mismatch
caused the child store Map lookup to silently miss on every directory
event, preventing session data, messages, and streaming responses from
reaching the React UI.
Changes:
- sync-context.tsx: Normalize incoming SSE event directory paths by
converting backslashes to forward slashes and uppercasing Windows
drive letters before the child store lookup.
- useDirectoryStore.ts: Add drive letter uppercasing to
normalizeDirectoryPath, aligning it with normalizeCandidatePath in
client.ts and normalizeWorkspacePath in main.tsx.
Both normalizations are no-ops on macOS/Linux where paths already use
forward slashes and have no drive letters.
Closes#816
* feat: enable local-origin desktop features and copy in terminal support
- Enable arbitrary web loads in desktop web content for TAURI apps.
- Guard directory dialog access behind local-origin origin check.
- Add copy-to-clipboard support for terminal selections via common shortcuts.
* fix: improve initial directory resolution and persistence in directory store
## What / Why
This PR finishes the desktop refactor: the Tauri app is now a thin shell that launches the web server as a sidecar and loads the UI from `http://127.0.0.1:<port>`. All real backend logic lives in `packages/web/server/index.js`; desktop Rust keeps only native integrations (menu/dialog/notifications/updater/deep-link + window chrome).
This unblocks:
- consistent behavior across web/desktop/vscode (single backend)
- simpler desktop maintenance (no duplicated Rust backend)
- host switching between Local + remote instances in desktop
- reliable cold-start behavior on slow machines (VSCode + desktop)
## Key changes
- Desktop sidecar runtime
- build pipeline to bundle web dist + `openchamber-server` sidecar (`packages/desktop/scripts/build-sidecar.mjs`)
- robust local port selection (prefer saved/default, fallback to random; persisted in `~/.config/openchamber/settings.json`)
- improved PATH handling so the sidecar can locate `opencode` CLI (incl `~/.opencode/bin`, overrides, common bins)
- disable native right-click context menu in production builds (dev keeps it)
- Desktop instance switcher (Tauri-only)
- header button + modal to add/edit/delete remote hosts, set default, probe status/ping, switch back to Local escape hatch
- auth gate includes host switcher so you can recover when a remote host is broken/auth-required
- host list stored desktop-locally (not tied to the currently selected remote server)
- Notifications
- decision logic moved server-side; desktop notifications emitted via sidecar stdout and shown natively by Tauri
- prevent double-notifications on desktop Local origin (UI ignores SSE notification when native path is active)
- restore macOS notification sound
- Updates
- Tauri updater used only when viewing Local instance in desktop shell (avoid “remote web update” triggering desktop restart)
- Settings persistence & UX polish
- persist model favorites/recents via `/api/config/settings` (works for web + desktop; not origin-dependent)
- persist per-project sidebar collapse state in `projects[].sidebarCollapsed` via `/api/config/settings` (with debounce on toggles)
- macOS header sizing/traffic-lights offsets fixed (marketing macOS major injected from desktop; MultiRun header aligned)
- VSCode cold-start: keep retrying provider/agent loads after connection to avoid empty UI on slow machines
- misc lint/type fixes + bun.lock sync
- Desktop bootstrap / resiliency
- show onboarding screen when OpenCode CLI is missing (desktop Local origin), with retry hook to restart OpenCode after install
## Testing notes
- Desktop (macOS): switch Local <-> remote, set default host, verify auth gate recovery, native notifications (with sound), updater gated to Local
- Web: favorites/recents + per-project collapsed state persist across reload/restart
- VSCode: slow startup no longer results in missing providers/agents/models
Add copy diagnostics button in About dialog.
Button copies report with OpenChamber state, OpenCode health, directories, and projects.
Show success or error toasts after copying attempt.
* feat: Implement project management store with project path validation and synchronization
- Added `useProjectsStore` for managing projects, including adding, removing, renaming, and validating project paths.
- Implemented persistence for projects and active project ID using safe storage.
- Introduced synchronization from desktop settings to keep project data consistent.
- Enhanced session store to manage sessions by directory and added new methods for session management.
- Updated todo store to fetch session todos based on the directory context.
- Refactored server code to validate and resolve project directories for various API endpoints.
- Added project entry validation and sanitization to ensure data integrity.
* feat(settings): migrate legacy project settings and update settings loading logic
* feat: enhance project management with directory-aware settings and improved agent/command source handling
* feat: enhance session and project management with directory-aware settings and improved configuration refresh logic
* feat: enhance project management with worktree manager integration and project directory resolution
* feat: enhance agent groups store with project directory resolution and loading logic
* feat: add heartbeat management and global wrapping for SSE blocks in agent and chat providers
* feat: refactor command and project handling in useCommandsStore
- Replaced useDirectoryStore with useProjectsStore to manage project paths.
- Introduced getRequestDirectory function to determine the active project directory.
- Updated command fetching to respect project-level scoping.
- Enhanced error handling and logging for command configuration fetching.
- Improved command configuration saving and updating to utilize project directory context.
feat: enhance project path normalization in useProjectsStore
- Added resolveTildePath function to expand paths starting with ~.
- Updated normalizeProjectPath to utilize home directory for path expansion.
fix: update permission handling in useSessionStore
- Changed Permission type to PermissionRequest for clarity.
- Updated respondToPermission method to use requestId instead of permissionId.
refactor: improve permission utilities
- Introduced types for PermissionAction and PermissionRule.
- Enhanced getAgentDefinition and resolveConfigStore functions for better type safety.
- Added resolvePermissionAction to streamline permission resolution logic.
feat: add agent configuration retrieval endpoint
- Implemented new API endpoint to fetch agent configuration based on project directory.
- Enhanced getAgentPermissionSource to prioritize project-level permissions.
chore: update SDK version in package.json files
- Bumped @opencode-ai/sdk version to ^1.1.1 across all relevant package.json files.
refactor: streamline bridge message handling
- Updated handleBridgeMessage to accept directory parameter for agent and command requests.
- Improved local API request handling to extract directory from query parameters and headers.
feat: enhance project configuration management
- Added functions to retrieve and merge project configuration paths.
- Improved handling of existing project configuration files for agents and commands.
* feat: enhance VSCode integration and session management
- Added support for a sticky sidebar header background in light and dark themes.
- Introduced functions to read VSCode workspace directory and check if running in VSCode.
- Implemented detailed logging for session loading and creation processes.
- Enhanced session filtering based on directory structure and canonical paths.
- Added a new method to reorder projects and prevent modifications in VSCode workspace.
- Improved error handling and logging for app initialization and markdown file parsing.
- Updated API checks and health checks to ensure readiness before proceeding.
- Refactored code for better readability and maintainability across various modules.
* feat: improve agent and branch selection logic, enhance session management, and update multi-run creation response
* feat: add worktree management actions in agent group detail and sidebar, including delete and keep only options
* fix(ui): share IME guard and cover multi-run
* fix(session): reduce maximum visible sessions in group from 7 to 5