Dark-Alex-17
f2a0e7453e
feat: copy host OAuth tokens into sandbox at launch
...
Projects ~/.cache/coyote/oauth/ from the host into /home/agent/.cache/coyote/oauth/
inside the sandbox so agents can call OAuth-authenticated providers without
re-authenticating. Same trust model as the existing config-dir and vault-password
copies. One-way copy (not bind-mount) — matches Docker's universal support
surface. Refreshed tokens die with the sandbox instance; run coyote --authenticate
inside if a fresh token is needed (Device Flow works via the QR code render).
2026-07-20 15:23:52 -06:00
Dark-Alex-17
0fe430102a
feat: implement OAuth 2.0 Device Authorization Grant (RFC 8628)
...
Adds a third OAuthFlow variant (device_code) alongside the existing pkce and
client_credentials flows. Device flow enables OAuth for headless environments
where a browser-based callback listener isn't available — the user visits a
verification URL on any device and enters a short user_code.
- OAuthFlow::DeviceCode variant + serde 'device_code' string
- OAuthConfig fields: device_authorization_url, use_pkce_in_device_flow
- OAuthProvider trait: device_authorization_url() / use_pkce_in_device_flow()
- OpenAICompatibleOAuthProvider passes both through from config
- run_device_code_flow() polls the token endpoint per RFC 8628 §3.4–§3.5:
handles authorization_pending, slow_down (+5s backoff), expired_token,
access_denied, and unknown errors distinctly
- Sandbox-gated QR code display (via qrcode crate) — scanning with a phone
is dramatically faster than copy-pasting the URL from a container
- Optional PKCE per draft-ietf-oauth-device-flow §5.4 (default off)
- run_oauth_flow and prepare_oauth_access_token dispatchers wire DeviceCode
in; refresh path shared with PKCE since both flows produce refresh_tokens
2026-07-20 15:21:32 -06:00
Dark-Alex-17
107419966d
style: Cleaned up some comments and imports
2026-07-20 13:46:41 -06:00
Dark-Alex-17
344ef7526f
feat: hint that browser 'paste code' pages can be ignored during callback capture
2026-07-20 13:29:37 -06:00
Dark-Alex-17
13d31f850c
fix: OAuth callback listener skips speculative/malformed browser connections
2026-07-20 13:21:44 -06:00
Dark-Alex-17
f6bd02dc73
feat: openai-compatible wizard offers OAuth when provider has bundled oauth defaults
2026-07-20 13:17:26 -06:00
Dark-Alex-17
31df1a720d
test: unit tests for OAuthConfig merge + get_oauth_provider_for_client
2026-07-20 13:12:38 -06:00
Dark-Alex-17
ab85a4f534
feat: validate unique client names at config load
2026-07-20 13:07:41 -06:00
Dark-Alex-17
420447275c
refactor: main.rs resolve_oauth_client uses new dispatcher
2026-07-20 13:05:57 -06:00
Dark-Alex-17
c611685033
feat: OAuth branch in openai_compatible prepare_* fns
2026-07-20 13:01:28 -06:00
Dark-Alex-17
cac2a3eba0
feat: get_oauth_provider_for_client dispatcher + client_config_info update
2026-07-20 12:57:10 -06:00
Dark-Alex-17
66bbb34d7f
feat: OpenAICompatibleOAuthProvider (config-driven OAuthProvider impl)
2026-07-20 12:55:30 -06:00
Dark-Alex-17
68177fdb6a
feat: add auth + oauth fields to OpenAICompatibleConfig
2026-07-20 12:51:09 -06:00
Dark-Alex-17
1acaad223f
feat: add oauth field to ProviderModels
2026-07-20 12:46:18 -06:00
Dark-Alex-17
aa0270602d
feat: add client_credentials support to prepare_oauth_access_token
2026-07-20 12:44:53 -06:00
Dark-Alex-17
4669958bdd
refactor: split run_oauth_flow into pkce + client_credentials dispatchers
2026-07-20 12:43:53 -06:00
Dark-Alex-17
559107073d
feat: add OAuthConfig + OAuthFlow types to oauth.rs
2026-07-20 12:41:24 -06:00
Dark-Alex-17
ad6d0a2e0e
fix: resolve reasoning effort for the prompt for global defaults as well
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-17 17:52:38 -06:00
Dark-Alex-17
50911b99ef
fix: Account for default model reasoning_effort when supplying that value for the REPL prompts
CI / All (ubuntu-latest) (push) Failing after 26s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-17 17:42:10 -06:00
Dark-Alex-17
44783c5573
feat: Added reasoning effort to the right prompt
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-17 17:34:10 -06:00
Dark-Alex-17
8629c1ca15
feat: Improved support for Anthropic's extended thinking
2026-07-17 17:26:41 -06:00
Dark-Alex-17
078e6e3744
fix: model narration included in history and between tool calls to prevent repetition
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-17 16:57:51 -06:00
Dark-Alex-17
058810137c
fix: Don't terminate agent loops early for null tool output
CI / All (ubuntu-latest) (push) Failing after 26s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-17 16:17:29 -06:00
Dark-Alex-17
c979041161
fix: reduce code duplication by reusing the new concrete_tool_names function in .list tools
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-17 15:51:01 -06:00
Dark-Alex-17
a606ea552d
fix: Agent tools can only be modified via .tool enable/disable using tools in the allowed whitelist in the agent
2026-07-17 15:42:57 -06:00
Dark-Alex-17
39a654a79e
fix: re-render agent sessions when entering agents with either pre-configured agent_session or when entering an agent directly into a session
2026-07-17 15:08:19 -06:00
Dark-Alex-17
17d1decce6
feat: Also support GEMINI.md workspace instructions
2026-07-17 15:05:16 -06:00
Dark-Alex-17
a45e66c634
feat: Improved workspace instructions support
2026-07-17 14:52:35 -06:00
Dark-Alex-17
8c885d9a77
feat: also detect .mcp.json configurations at workspace roots
2026-07-17 14:03:08 -06:00
Dark-Alex-17
6dd1e59815
fix: Per RFC 9728, enable dynamic discovery of OAuth endpoints in MCP using path-aware discovery
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-17 13:28:55 -06:00
Dark-Alex-17
f5085a773a
fix: hot-attach to MCP servers that require auth after running .mcp auth <name>
2026-07-17 13:16:25 -06:00
Dark-Alex-17
09afdeaf7c
feat: Created new .tool enable/disable and .mcp enable/disable aliases to make REPL usage more egonomic
2026-07-17 12:53:59 -06:00
Dark-Alex-17
0216d84eee
feat: Created a new .list <kind> REPL command to make discoveribility easier in the REPL
2026-07-17 11:49:49 -06:00
Dark-Alex-17
320dbf2479
fix: Correctly inherit graph-global model for extractor model if none is defined
2026-07-17 11:42:28 -06:00
Dark-Alex-17
6958e9cba8
feat: Support claude-style hidden workspace MCP configuration files via .mcp.json
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-17 10:46:26 -06:00
Dark-Alex-17
825f9f6bf5
feat: Allow users to customize the workspace-specific configuration directory name so they can use Coyote with other CLI clients like .claude
2026-07-17 10:38:35 -06:00
Dark-Alex-17
863740f916
fix: no cursor timeout when user scrolls away from ongoing streaming output
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-16 16:01:19 -06:00
Dark-Alex-17
304088bf5c
tests: Added tests for graph-based RAG
CI / All (ubuntu-latest) (push) Failing after 24s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-16 14:33:52 -06:00
Dark-Alex-17
9b3ae761f3
feat: Add reasoning_effort validation for the main configuration file
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-16 13:18:28 -06:00
Dark-Alex-17
0f7877aafc
feat: Add validation for reasoning_effort settings to prevent users from specifying erroneous values
2026-07-16 13:12:11 -06:00
Dark-Alex-17
e9a8c01dc4
feat: Added support for modifying the reasoning effort of reasoning models
2026-07-16 12:28:04 -06:00
Dark-Alex-17
e9c52566b8
feat: Explicitly Prevent .undo usage in graph agents
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-15 16:27:57 -06:00
Dark-Alex-17
4c7de650c0
feat: Added an .undo command to the REPL to let users have more control over the conversation
2026-07-15 16:23:59 -06:00
Dark-Alex-17
8bbbd71fec
fix: default to the nano or notepad when a configured editor is not found
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-15 15:32:07 -06:00
Dark-Alex-17
7f89a80f7e
fix: When EDITOR, VISUAL, or config.editor is defined, don't verify via which
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-15 15:16:41 -06:00
Dark-Alex-17
7b00638476
style: removed redundant '&' from functions module
2026-07-13 18:11:03 -06:00
Dark-Alex-17
6733b3600f
test: Fixed flaky python AST parser test for macOS
CI / All (ubuntu-latest) (push) Failing after 24s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-13 17:46:34 -06:00
Dark-Alex-17
de6010d525
docs: Organized coyote --help output to be more readable
CI / All (ubuntu-latest) (push) Failing after 25s
CI / All (macos-latest) (push) Has been cancelled
CI / All (windows-latest) (push) Has been cancelled
2026-07-13 17:31:20 -06:00
Dark-Alex-17
382916c3ee
style: Removed redundant '&' from paths module function calls
2026-07-13 17:12:58 -06:00
Dark-Alex-17
bc3cc10a7b
feat: Support workspace-local skill definitions and MCP configurations
2026-07-13 17:12:34 -06:00