* fix: preflight stream proxy before SSE starts, let optimistic thread survive refetch
* fix: seed sidebar thread details as stale so mark-viewed fetch still fires
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: track PR lifecycle state per thread for sidebar
Persist a PR's draft/open/merged/closed state on the agent thread and keep
it in sync as PR webhooks fire, so the Agents UI can show per-thread PR
status the way Cursor does. open_pull_request now records the initial
draft/open state and pr_title; thread summaries expose diffStats; and the
PR webhook refreshes pr_state on close/reopen/draft/ready transitions.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* refactor: consolidate PR state mapping into shared derive_pr_state helper
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
- _origin_of: treat invalid ports as invalid origin instead of letting
urlparse ValueError turn CSRF rejections into 500s
- AgentsHome: reset submitting/draft when stream.submit rejects before a
thread id is minted, so the prompt isn't left disabled
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: add View PR link in git panel header
Surface a clickable "View PR" link in the agent git panel header so
users can jump straight from a chat thread to its pull request instead
of hunting for the URL in the conversation. Uses the pr.url already
captured in thread metadata.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* refactor: use shared buttonVariants for View PR link
Style the View PR link with the shared buttonVariants (outline/sm)
helper instead of hand-rolled classes, matching the existing
anchor-as-button pattern used in login.tsx and AutomationsList.tsx.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: show PR diff in git panel diff tab
Adds /threads/{id}/pr-diff endpoint fetching PR files + contents from GitHub;
git panel prefers it and falls back to the live message-derived diff.
* feat: auto-expand git panel when a PR lands mid-run
Panel still defaults to collapsed and remembers manual toggles; the
auto-expand is ephemeral and not written to localStorage.
* fix: git panel always starts collapsed
Drop localStorage persistence of collapsed state; panel opens only via
manual toggle or when a PR lands mid-run, and re-collapses on thread switch.
* fix: address PR review findings
Require user OAuth token for pr-diff (no app-token fallback) so GitHub
enforces current repo access; render placeholder for binary/oversized files.
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: distinguish agent code/shell blocks from user message bubbles
Code blocks and shell command output shared the same accent bubble
background as user message bubbles, making them hard to tell apart at
full width. Give them a distinct neutral gray background plus a subtle
border.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: apply neutral code bubble to all agent output cards + add second accent
Extend the neutral code-bubble background to the remaining agent output
cards (files-changed card, reply preview, edited-file diff, todo list,
streaming-turn cards) so none of them share the user message bubble
background. Introduce a violet --ui-accent-2 used on code/shell header
labels so the blocks pop.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: add right-click open trace context menu for threads
Add a context menu to sidebar thread rows exposing an Open trace action
that links to the LangSmith thread trace, surfaced via a new traceUrl
field on the thread summary.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* chore: drop stray yarn artifacts from PR
Remove accidentally committed ui/.yarnrc.yml and ui/.yarn/install-state.gz
that broke immutable installs against the v1 lockfile, and gitignore yarn
artifacts to prevent recurrence.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* chore: reuse thread_id var, drop redundant danger-color fallback
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: add pierre file tree to full-screen git panel
Render the dashboard git panel with real changed-file data using pierre
diffs, add a full-screen toggle, and show a pierre FileTree explorer on the
right when expanded.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: always show git panel as collapsible resizable card
- git panel renders on every thread with collapse to a floating expand
button and drag-resize, persisted to localStorage (matches left sidebar)
- panel content wrapped in a rounded card with Git/Desktop/Terminal tabs
above it; Desktop/Terminal and Review/Commits show Coming Soon
- send button morphs into a stop button during an active run
* fix: follow app theme for pierre diff rendering
diffOptions used themeType "system" so @pierre/diffs followed the OS
color scheme instead of the app's .dark class, producing unreadable
dark-on-light diffs when the two disagreed. Add useDiffOptions() which
resolves themeType from the app theme, and use it at all diff render
sites.
* fix: align git panel card bottom gutter with prompt bar
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: add cancel run button to agent UI
Wire the existing cancel-thread mutation into the agent thread view by
adding a stop button to the prompt bar that appears while a run is active.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: preserve thread messages when cancel response omits them
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: server-side Datadog/LangSmith observability tools + team creds
Add team-wide observability credential settings (Datadog DD_SITE/API/APP
keys, LangSmith API key) stored encrypted server-side, with an admin
dashboard section to connect/disconnect each provider. When connected,
get_agent loads read-only observability tools server-side: Datadog via its
hosted MCP server (langchain-mcp-adapters, toolsets=core) and LangSmith
read tools (langsmith_get_trace, langsmith_list_runs). Credentials live in
the LangGraph server process and are never exposed to the sandbox.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: address review on observability tools
Address PR review feedback:
- Authorize observability tools per triggering user (admins + the
OBSERVABILITY_AUTHORIZED_EMAILS allowlist) so prompt-injected runs from
untrusted contributors can't reach team Datadog/LangSmith data.
- Use the documented Datadog MCP auth headers DD_API_KEY / DD_APPLICATION_KEY.
- Store each provider's credentials under its own store key to avoid a
read-modify-write race dropping the other provider on concurrent saves.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: async email resolution in observability authorization gate
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Inline chat code blocks hardcoded the github-dark Shiki theme, so in light
mode dark-theme token colors rendered on a light bubble with poor contrast.
Resolve the Shiki theme from the active light/dark mode and cache tokens per
theme. Adds a reactive useResolvedTheme hook so blocks update live on toggle.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: render submitted user message immediately in web chat
Insert the optimistic prompt into local pendingPrompts state on submit so
the user's message appears right away instead of only after the agent
responds and thread.messages refetches.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: keep queued user prompts in submission order
Offset each pending prompt's insertAt by the number of prompts already
pending so multiple follow-ups queued before the backend echoes them
don't collide at the same splice index and render out of order. Applies
to both the local state and persisted sessionStorage paths.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: roll back optimistic message on send failure, single insertAt source
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: per-repo custom instructions for the coding agent
Adds per-repository custom instructions for the main coding agent,
mirroring the reviewer's per-repo style prompts. Instructions are stored
in the LangGraph Store, managed via dashboard API + UI (Monaco editor),
and appended to the agent's system prompt for runs targeting that repo.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* chore: wire agent instructions route into generated route tree
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: enforce repo access on instruction routes
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: let usage table expand to fill available width
The usage page was constrained to max-w-3xl while the leaderboard table
needs a 760px minimum for its 7 columns, so it always overflowed and
forced horizontal scrolling. Add an optional maxWidthClassName prop to
AppShell and widen the usage page to max-w-5xl so the table expands when
space allows, keeping overflow-x-auto as a narrow-screen fallback.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* refactor: use cn-merged className override on AppShell
Replace the single-purpose maxWidthClassName prop with a general
className prop merged via cn (twMerge), matching the shadcn pattern. This
lets callers override any of the content-container classes ad hoc rather
than adding a new prop per override. Usage page passes className=max-w-5xl.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
* fix: prevent thread prefetches from marking threads viewed
Sidebar prefetches now request thread details with mark_viewed=false so
loading /agents no longer clears the unread/finished indicator for
threads the user has not opened.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: always refetch active thread on mount to mark viewed
Prefetches cache details fetched with mark_viewed=false under the same
query key as the active thread. Forcing refetchOnMount="always" ensures
opening a thread issues a mark_viewed=true request, so last_viewed_* is
recorded even when prefetched data is still fresh.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
The Pierre diff view hardcoded the syntax-highlight theme to
pierre-light, but the diff background follows the app theme
(--ui-panel), so in dark mode light-theme token colors rendered on a
dark background with poor contrast. Provide both light/dark Pierre
themes and follow the document color-scheme via themeType "system".
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: add dark mode support to web UI
Add a persisted, system-aware theme with a Light/Dark/System toggle in
the sidebar user menu. An inline head script applies the stored theme
before paint to avoid a flash, and the agents-ui surface gets dark
overrides for its --ui-* variables.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: use static theme init script to satisfy CodeQL
Build the no-FOUC theme script from a fully static string literal
instead of interpolating THEME_STORAGE_KEY, so no value flows into
code construction (CodeQL "Improper code sanitization").
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: avoid theme flip on hydration for persisted preferences
Only apply a theme after the stored preference is read, instead of
eagerly applying the default "system" theme on first effect. This
prevented a brief flip to the OS theme (then back) on load for users
with a saved preference that differs from their OS setting.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Adds an admin-managed, org-wide review guidelines field to team settings
that the reviewer injects into every PR review across all repos, alongside
the existing per-repo style prompt and AGENTS.md context. Repo-specific
rules take precedence when they conflict.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: add scheduled web agents
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: secure scheduled agent repositories
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* feat: rebuild scheduled agents as Automations tab
Scrap the inline ScheduledAgentsPanel and replace it with a dedicated
Automations tab: sidebar nav entry, list view with stat cards + empty
state, and a full editor (name, Active toggle, repo, scheduled trigger
picker, agent instructions + model).
* fix: clear collapsed-sidebar button on mobile in Automations
* fix: allow clearing automation repo on update
---------
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: tidy agents home, mobile logo, and PWA dev/icon issues
- Remove recent-runs cards from the new agent page
- Scale the ASCII logo to fit narrow viewports instead of overflowing
- Serve manifest in dev and skip SW registration in dev to clear console errors
- Use a flat, opaque apple-touch-icon so iOS stops adding a black border
- Ignore generated ui/dev-dist
* feat: add send button and prevent iOS focus-zoom on chat input
- Add a circular send button (accent, spinner while sending) to the prompt bar
- Bump textarea to 16px on mobile so iOS doesn't zoom the viewport on focus
* fix: polish prompt bar and center logo
- Center the ASCII logo at all widths
- Prevent iOS focus-zoom via viewport maximum-scale instead of bumping the
input to 16px, so mobile text stays the intended size
- Give the model picker a chip/chevron treatment to anchor it next to the send button
* fix: simplify model picker to plain text + chevron
* fix: tighten prompt bar padding and shrink send button
---------
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* Make dashboard UI mobile-friendly
- Drop the thread title/repo header on the agent chat view.
- Expanded sidebar becomes a full-screen overlay on mobile (<768px) instead of a squished column; resize handle hidden.
- Default to collapsed on mobile first load so the chat stays visible; navigating a link/thread auto-collapses the overlay.
* Fix settings rows and run cards overflowing on small screens
- SettingsRow stacks label/control vertically below sm; reduce AppShell padding on mobile.
- Truncate long model/repo names in AgentRunCard metadata so cards stay within bounds.
* Keep collapsed-sidebar button from overlapping page titles on mobile
* Render page titles below the sidebar button on mobile instead of indenting
* Don't persist mobile auto-close to localStorage, preserving desktop preference
---------
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: stabilize agent defaults and repo selector
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: align default repo selector styling, restore text fallback
Match the repo selector to sibling settings controls (h-7, bg-input/20,
text-xs). Fall back to a text input when the repo list is empty so a
default repo can still be entered.
* fix: make repo selector dropdown more compact
---------
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: tag Slack threads with stored identity so they surface in web
process_slack_mention gated the run on mapped_login (resolved from the stable
Slack user id), but upsert_agent_thread_owner_metadata independently re-resolved
the GitHub login from the Slack profile email. When that email differs from the
user's mapping email (e.g. a personal vs work address), the lookup returned None,
so github_login was never stamped on the thread and the thread never surfaced in
the web Agents UI (which searches by github_login / triggering_user_email).
Resolve the GitHub user from the store via the Slack id, pass that login through
to the owner metadata, and use the mapping's stored work email (falling back to
the Slack profile email for unmapped users) for both the run config and the
thread tagging, so Slack-started threads reliably appear in web.
* fix: stamp github_login on Slack threads so they surface in web
process_slack_mention gated the run on mapped_login (resolved from the stable
Slack user id) but upsert_agent_thread_owner_metadata re-resolved the login from
the Slack profile email; when that email isn't the user's mapping email the
lookup returns None and github_login is never stamped, so the thread is invisible
in the web Agents UI (which searches by github_login / triggering_user_email).
Pass the already-resolved mapped_login through to the owner metadata. The
dashboard match keys on the stable GitHub login, so this is sufficient; the
triggering email stays the live Slack profile value.
* fix: preserve Slack email during account mapping
* fix: require Slack OIDC for email mappings
* chore: format Slack OIDC mapping cleanup
Slack thread replies and Linear comments showed only the bare tool name in the dashboard chat. Map them to dedicated 'slack'/'linear' toolKinds and render the message body in a ReplyCard, so Open-in-Web shows what the agent actually posted.
* fix: make repository optional when starting a dashboard run
The agent infers and clones the target repo from the task itself, so a
default repo is never actually required to run — but the dashboard 400'd
("no default repository configured") when a user had none set.
Treat repo as optional: _resolve_repo_config returns {} instead of
raising, repo metadata/config are only written when a repo is present,
and the "missing repository metadata" gate on follow-up messages is
dropped. UI hides the repo chip when absent.
* feat: add repo picker to the run prompt bar
Adds an optional, searchable repository selector next to the model picker
on the Agents home prompt bar (Cursor-style). It pre-fills the user's saved
default repo and can be cleared to "No repository" for a repo-less run.
Because the picker now resolves the default on the client, the create
endpoint honors the request value verbatim: _resolve_repo_config just parses
what's sent ({} when empty) instead of falling back to the saved default,
so an explicit "No repository" is respected.
* refactor: match Cursor layout for repo placement
Move the repo selector out of the prompt-box footer to a pill row above
the input (folder + caret, dropdown opens downward); the model picker
stays inside the box. In the thread view, show the thread title and repo
in a header at the top of the chat, with the follow-up input pinned to
the bottom as before.
Enable TanStack Start SPA mode so the build prerenders a static shell
(/_shell.html) and emits a fully static bundle under .output/public,
removing the Nitro serverless function from the Vercel deploy. The
dashboard is a thin client (all data via client-side fetch to the
FastAPI /dashboard/api/*), so SSR rendered nothing of value.
Point Vercel at the static output and add a SPA catch-all rewrite to
the shell for client-side routing, keeping the API proxy rewrite first.
Replace the floating absolute-positioned prompt bar (gradient overlay +
128px bottomInset) with a plain flex column: MessageView as flex-1 with a
shrink-0 prompt bar beneath it, matching open-swe-app's ChatView.
Also remove the redundant always-on 'Files Changed' panel — MessageView
already renders an inline TurnChangedFilesCard per agent turn, and the
duplicate was being clipped by the floating prompt bar. This eliminates
the large whitespace gap and the broken files-changed box.
* fix: deliver Slack account-link prompt as a visible threaded reply
Blocked Slack users got no prompt at all. Prod logs show chat.postEphemeral
returns ok, but ephemeral messages are silently dropped in Slack's assistant
threads (where Open SWE runs), so the user sees nothing. Post the prompt as a
normal threaded reply instead — the same channel the agent uses to reply.
* fix: deliver Slack auth-failure prompt as a visible threaded reply
leave_failure_comment() tried an ephemeral message first and only fell back
to a thread reply on failure. Ephemeral messages succeed (ok) but are dropped
in Slack's assistant threads, so the fallback never fired and the user saw no
auth-failure prompt. Post the visible threaded reply directly, matching the
account-link prompt fix.
* fix: prompt blocked Slack users with a generic, token-free dashboard link
Addresses the review findings that posting the per-user account-link token /
auth URL in a visible thread lets any channel member bind their GitHub account
to the triggering user's Slack identity.
Drop the per-user signed link entirely. Both the account-link prompt
(_post_account_link_prompt) and the runtime auth-failure prompt
(leave_failure_comment) now post a plain dashboard settings link
(build_settings_url) as a visible threaded reply. The user signs in with GitHub
from their own session and connects Slack via verified OIDC on the settings
page — no secret in the thread, nothing to hijack, and no DM machinery.
* feat: nudge first-time users to connect Slack from the dashboard home
Show a Connect Slack banner on the agents landing page whenever Slack OAuth is
enabled and the user hasn't linked Slack yet. A first-time user (no Slack
mapping) sees it immediately after signing in; it disappears once connected.
* feat: prompt first-time users to connect Slack via a dialog
Replace the inline Connect Slack card on the agents home with a modal dialog
(Base UI). It opens automatically once the mapping query resolves to
"not connected" and closes itself once Slack is linked; "Maybe later" dismisses
it for the session. No new dependency — uses the design system's Base UI.
* copy: frame Slack connect as resolving the user's GitHub account
Drop 'act/reply on your behalf' wording across the connect-Slack dialog, the
Slack thread prompts (blocked + auth-failure), and the settings description.
Connecting Slack lets Open SWE resolve the user's GitHub account when they tag
it in Slack.
* feat: open Slack-triggered PRs as the triggering user
Route the Slack per-user GitHub token through the dashboard OAuth store
(the backend the self-service link prompt populates) and block runs that
lack a valid user token, prompting the user to (re-)link. Per-user OAuth
now wins over bot-token-only mode for mapped Slack/dashboard users.
Flip commit/PR authorship across all sources: the triggering user is the
commit author (via repo-local git identity using their resolvable GitHub
noreply email) and open-swe[bot] is the Co-authored-by collaborator.
* fix: address PR review — shell-escape commit identity, fix token cache impersonation
- Shell-escape the triggering user's name/email with shlex.quote before
embedding them in the repo-setup `git config` command, so a name like
O'Connor (or a crafted one) can't break or inject into the command.
- Stop consulting the shared thread-metadata token cache in
_resolve_dashboard_user_token. Slack thread ids are shared across the
conversation, so a cached token from a prior triggering user could be
returned for the current github_login. Always resolve by login from the
dashboard OAuth store instead.
* feat: dashboard self-service user mapping + UI cleanup
- Add session-scoped GET/PUT /dashboard/api/my-mapping so users can set their
own work email / Slack member ID (keyed by their GitHub login, source=self).
- Slack account-link prompt now redirects to Profile Settings after auth.
- Rename "My Settings" -> "Profile Settings" and "Cloud Agents" -> "Open SWE
Agent"; remove the Integrations tab/section (folded out, low value for now)
and redirect /integrations to Profile Settings.
- Add a "User mapping" section to Profile Settings (work email used by Slack
and Linear, optional Slack member ID).
- Make dashboard auth cookies scheme-aware: Secure;SameSite=None over HTTPS,
non-Secure;SameSite=Lax over http://localhost so local login works.
* feat: self-service Slack account linking via Sign in with Slack (OIDC)
Replace the spoofable manual work-email/Slack-ID form with a verified
"Sign in with Slack" flow so a logged-in GitHub user can only ever link
their own Slack identity.
- New agent/dashboard/slack_oauth.py: OIDC authorize URL, code exchange,
userInfo identity parse, optional workspace gate, configured check.
- routes.py: session-gated GET /slack/login and /slack/callback that upsert
the mapping from Slack-verified user_id + email (source=slack_oauth).
Remove the spoofable PUT /my-mapping; expose slack_oauth_enabled on /me.
- UI: drop the editable inputs; add a Connect Slack button + status to the
User mapping section.
Admin-managed mappings are unaffected and still resolve at trigger time.
* chore: remove legacy mapping + admin profiles section, page user mappings
- Delete the hardcoded github_user_email_map.py and the one-time
POST /admin/user-mappings/import endpoint + Import legacy mapping UI
button (the Store is now the sole source of truth post-import).
- Remove the per-user profiles admin section and its GET/PUT
/admin/profiles endpoints + ProfileForm component; users still manage
their own profile via My Settings.
- Page the user mappings list: /admin/user-mappings now takes
page/page_size and returns {items,total,page,page_size}; the admin UI
shows 20 rows per page with Previous/Next controls.
* Address review: fix stale import-button doc + clamp mappings page on shrink