Repository navigation
fix(preview): recover managed previews during browser navigation - #384
Conversation
Recover the same-thread retained listener before agent or viewer navigation, verify that remote browser URLs identify the same development environment, and exchange a one-use credential only in the selected browser profile. Keep credentials out of URLs and drain in-flight cookie writes before handing browser control to another owner. Retain verified origin mappings across native page reattachment so remote address edits and reloads use the owned local listener. Clear those mappings when the preview session closes. This consistency check prevents accidental credential delivery to another development server. It does not authenticate a hostile server that copies the environment descriptor. Carry-Group: incubator
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 54f60093e5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Copy the opener's verified hosted-origin mappings when adopting a popup or attaching its native child. Keep each popup's copy for its own retained session so navigation and reload can recover the listener and renew authentication even after the opener closes. Carry-Group: incubator
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 64de5bec7a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Use the same recovery and profile authentication before client hard reloads and viewer Back/Forward navigation. Read the target history entry before moving, and preserve navigation cancellation during preparation. Clear requested storage before restoring the development session for a hard reload. Carry-Group: incubator
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 26946cb820
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Snapshot managed origins when adopting a popup, before the opener can close during publication or page attachment. Preserve the snapshot through desktop and CDP setup. Cover opener closure during both setup stages; each case fails with the prior source and passes with the snapshot. Carry-Group: incubator
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2a973cc6ff
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Redirect existing managed-preview navigation to the currently resolved browser address instead of authenticating the new destination and requesting a stale URL. Preserve browser history, including same-document traversal, and keep hard reloads uncached through loading. Verify all three service entry points after address changes and confirm history position and order in Chromium. Carry-Group: incubator
|
@codex review |
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
The real Chromium redirect fixture needs an ephemeral Node HTTP server. Limit the Effect diagnostic exception to that import, following existing native-boundary test fixtures. Carry-Group: incubator
|
@codex review |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Managed development previews can lose their server or authentication while an agent navigates, a viewer changes a remote URL, a client reloads, or a retained native page reattaches. Those browser entry points currently bypass the retained preview recovery and authentication used by the UI open path.
Recover the owned listener before navigation and verify that the resolved browser destination reports the same development environment before issuing a one-use credential. Exchange the credential in the selected profile without putting it in a URL. Preserve verified remote-to-local origin mappings across reattachment and capture popup mappings before asynchronous publication or attachment, so closing the opener cannot erase them. Hard reload and Back/Forward prepare the destination before Chromium requests it. When the resolved address changes, redirect the existing navigation to the current address while preserving history order, including same-document traversal. Keep redirected hard reloads uncached through page load. Cancel superseded preparation while draining cookie writes before control handoff.
Validation: focused Hosting, HostingAuth, ServerBrowser, and ServerBrowserPage tests pass (245 cases), with scoped lint, formatting, and diff checks. Independent Astra review is clean. Regression cases cover remote URL edits, reattachment, popup recovery after opener closure during desktop attachment and CDP setup, hard reload, Back/Forward, changed remote addresses, and control handoff; restoring late popup-map lookup or removing the reload/history fixes makes the corresponding cases fail. Four real Chromium cases verify changed-origin Back, Forward, reload, and same-document history preserve the history index, entry count, and subsequent traversal. All five service cases for address changes fail on stale-URL assertions with the pre-fix source. GitHub CI passed and Codex review is clean on 2231c18; all review threads are resolved.
Native acceptance remains open: the installed collaborative browser returns
Preview automation profiles is unavailable on client server-browser.and fails both profiled and ordinary background opens before creating a tab. This PR addresses managed-preview routing; it does not claim to repair that independent desktop command/reply failure or to complete native navigation, capture, delayed reopen, or authenticated screenshot/recording uploads.Implemented with GPT-6.1 Sol through the Codex harness; independently reviewed with GPT-6 Astra.