Repository navigation
fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines - #17264
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe Electron runtime name now combines the branding base name with the stage label. The About panel and macOS application menu labels use the environment display name. ChangesDesktop branding
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The branding change is ready to merge after normal checks; no actionable risk remains identified. Security Architecture ReviewSecurity architecture risk: ⚪ Minimal · up to The change corrects runtime branding without introducing a new externally callable interface or changing credential storage, preview-session ownership, or menu privileges. No material security risk was identified in the reviewed change. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
## What's Changed * fix(server): pairing tokens work on Node versions that cannot bind booleans by @chisewaguri in pingdotgg/t3code#16730 * fix(mobile): HTML pages in a thread no longer trap scrolling on Android by @SunkenInTime in pingdotgg/t3code#17211 * fix(web): centered scrollers no longer shift when the scrollbar appears by @maria-rcks in pingdotgg/t3code#17077 * fix(web): distinguish thread search matches from code tints by @Yash-Singh1 in pingdotgg/t3code#17263 * fix(server): Pi extension wakes get an owned continuation turn by @StiensWout in pingdotgg/t3code#17214 * fix(server): Pi discovers optional T3 tools on demand by @StiensWout in pingdotgg/t3code#17220 * fix(web): stack merge dialog closes as soon as you confirm by @flamboh in pingdotgg/t3code#17116 * fix(server): Pi editor dialogs prefill the answer composer by @StiensWout in pingdotgg/t3code#17206 * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines by @jztmanyl in pingdotgg/t3code#17264 * fix(server): Pi discovers workspace skills and commands by @StiensWout in pingdotgg/t3code#17190 * fix(mobile): preserve navigation after native swipe back by @juliusmarminge in pingdotgg/t3code#17268 * fix(server): keep newly discovered models out of legacy groups by @Bil0000 in pingdotgg/t3code#14314 * feat(editors): open remote projects in JetBrains IDEs over SSH by @juliusmarminge in pingdotgg/t3code#17271 * test(desktop): expect JetBrains IDEs among remote editors by @juliusmarminge in pingdotgg/t3code#17291 * fix(server): recognize authenticated GitHub Enterprise hosts by @alimek in pingdotgg/t3code#11059 * fix(connect): relay client updates itself and skips incompatible cloudflared by @juliusmarminge in pingdotgg/t3code#17275 * fix(shared): relay client install waits out a brief Windows file lock by @ScottN-PV in pingdotgg/t3code#16998 * fix(shared): release relay install locks on cancellation by @yashranaway in pingdotgg/t3code#10585 * chore(shared): bump managed cloudflared to 2026.10.0 by @bompus in pingdotgg/t3code#11184 * fix(shared): bound cloudflared download with 10-minute timeout by @kvnloo in pingdotgg/t3code#14139 * refactor(provider-core): add provider-core and provider-testing packages by @juliusmarminge in pingdotgg/t3code#17299 * refactor(settings): drop the legacy per-driver providers map by @juliusmarminge in pingdotgg/t3code#17300 * refactor(provider-pi): move Pi into its own provider package by @juliusmarminge in pingdotgg/t3code#17302 * feat(models): tell users when a CLI update unlocks a new model by @juliusmarminge in pingdotgg/t3code#17307 * fix(web): collapsed composer reserves room for wide send actions by @maria-rcks in pingdotgg/t3code#17016 * fix(muse): workflow subagents no longer stall on hidden approvals by @t3dotgg in pingdotgg/t3code#17329 ## New Contributors * @chisewaguri made their first contribution in pingdotgg/t3code#16730 * @jztmanyl made their first contribution in pingdotgg/t3code#17264 * @alimek made their first contribution in pingdotgg/t3code#11059 * @kvnloo made their first contribution in pingdotgg/t3code#14139 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261008.2833...v0.0.46-nightly.20261008.2849 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261008.2849
## What's Changed * fix(server): pairing tokens work on Node versions that cannot bind booleans by @chisewaguri in pingdotgg/t3code#16730 * fix(mobile): HTML pages in a thread no longer trap scrolling on Android by @SunkenInTime in pingdotgg/t3code#17211 * fix(web): centered scrollers no longer shift when the scrollbar appears by @maria-rcks in pingdotgg/t3code#17077 * fix(web): distinguish thread search matches from code tints by @Yash-Singh1 in pingdotgg/t3code#17263 * fix(server): Pi extension wakes get an owned continuation turn by @StiensWout in pingdotgg/t3code#17214 * fix(server): Pi discovers optional T3 tools on demand by @StiensWout in pingdotgg/t3code#17220 * fix(web): stack merge dialog closes as soon as you confirm by @flamboh in pingdotgg/t3code#17116 * fix(server): Pi editor dialogs prefill the answer composer by @StiensWout in pingdotgg/t3code#17206 * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines by @jztmanyl in pingdotgg/t3code#17264 * fix(server): Pi discovers workspace skills and commands by @StiensWout in pingdotgg/t3code#17190 * fix(mobile): preserve navigation after native swipe back by @juliusmarminge in pingdotgg/t3code#17268 * fix(server): keep newly discovered models out of legacy groups by @Bil0000 in pingdotgg/t3code#14314 * feat(editors): open remote projects in JetBrains IDEs over SSH by @juliusmarminge in pingdotgg/t3code#17271 * test(desktop): expect JetBrains IDEs among remote editors by @juliusmarminge in pingdotgg/t3code#17291 * fix(server): recognize authenticated GitHub Enterprise hosts by @alimek in pingdotgg/t3code#11059 * fix(connect): relay client updates itself and skips incompatible cloudflared by @juliusmarminge in pingdotgg/t3code#17275 * fix(shared): relay client install waits out a brief Windows file lock by @ScottN-PV in pingdotgg/t3code#16998 * fix(shared): release relay install locks on cancellation by @yashranaway in pingdotgg/t3code#10585 * chore(shared): bump managed cloudflared to 2026.10.0 by @bompus in pingdotgg/t3code#11184 * fix(shared): bound cloudflared download with 10-minute timeout by @kvnloo in pingdotgg/t3code#14139 * refactor(provider-core): add provider-core and provider-testing packages by @juliusmarminge in pingdotgg/t3code#17299 * refactor(settings): drop the legacy per-driver providers map by @juliusmarminge in pingdotgg/t3code#17300 * refactor(provider-pi): move Pi into its own provider package by @juliusmarminge in pingdotgg/t3code#17302 * feat(models): tell users when a CLI update unlocks a new model by @juliusmarminge in pingdotgg/t3code#17307 * fix(web): collapsed composer reserves room for wide send actions by @maria-rcks in pingdotgg/t3code#17016 * fix(muse): workflow subagents no longer stall on hidden approvals by @t3dotgg in pingdotgg/t3code#17329 ## New Contributors * @chisewaguri made their first contribution in pingdotgg/t3code#16730 * @jztmanyl made their first contribution in pingdotgg/t3code#17264 * @alimek made their first contribution in pingdotgg/t3code#11059 * @kvnloo made their first contribution in pingdotgg/t3code#14139 **Full Changelog**: pingdotgg/t3code@v0.0.46-nightly.20261008.2833...v0.0.46-nightly.20261008.2849 Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.46-nightly.20261008.2849
Brings in upstream through pingdotgg#17405 (43f8a8d). - Adapted: Windows work-account sign-in in the server browser now runs after upstream's presentAsChrome (pingdotgg#16963) on each headless tab. ServerBrowser.test.ts checks that persistent tabs pause Entra sign-in and incognito tabs do not, and is now in personal-fixes. - Adapted: since pingdotgg#17316 the desktop runs tabs Ved opens for a remote environment locally, so the desktop's sign-in path carries them again. BrowserSession.test.ts checks that persistent sessions get the sign-in hook. browser-import.md says which account each tab uses. - BrowserSession.ts: kept the sign-in hook beside upstream's external-protocol prompt (pingdotgg#16961). - Remote open: kept Cody's Tailscale SSH login (user@host) for VS Code and Zed beside upstream's JetBrains Toolbox links (pingdotgg#17271). JetBrains links carry no login, as upstream designed. - DesktopAppIdentity: took upstream's RFC 9110 runtime name (pingdotgg#17264), so Cody's runtime name is "Cody <stage>". The About panel still says "Cody". - OpenCode package split (pingdotgg#17345): the Copilot usage limits, MCP re-add, and final-answer instruction patches moved with their files. The driver calls readOpenCodeUsageLimits from the new package. - personal-fixes.json: points the OpenCode tests at their new package paths and adds runtimeInstructions.test.ts. Drops opencodeUsageReader.test.ts, a path that never existed. - Superseded: none this round.
* fix(web): link pull requests to threads in folders that aren't Git repos (pingdotgg#15946) Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): find messages and plans in the current thread (pingdotgg#10439) Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): improve terminal scrollback navigation and snapshots (pingdotgg#17091) * docs(internals): add a checklist for adding a provider (pingdotgg#17229) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(mobile): keep native screens ordered during stack pops (pingdotgg#17231) * fix(server): pairing tokens work on Node versions that cannot bind booleans (pingdotgg#16730) * fix(mobile): HTML pages in a thread no longer trap scrolling on Android (pingdotgg#17211) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): centered scrollers no longer shift when the scrollbar appears (pingdotgg#17077) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(web): distinguish thread search matches from code tints (pingdotgg#17263) * fix(server): Pi extension wakes get an owned continuation turn (pingdotgg#17214) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): Pi discovers optional T3 tools on demand (pingdotgg#17220) * fix(web): stack merge dialog closes as soon as you confirm (pingdotgg#17116) * fix(server): Pi editor dialogs prefill the answer composer (pingdotgg#17206) * fix(desktop): generate valid User-Agent that follows RFC 9110 guidelines (pingdotgg#17264) * fix(server): Pi discovers workspace skills and commands (pingdotgg#17190) * fix(mobile): preserve navigation after native swipe back (pingdotgg#17268) * fix(server): keep newly discovered models out of legacy groups (pingdotgg#14314) Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(editors): open remote projects in JetBrains IDEs over SSH (pingdotgg#17271) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * test(desktop): expect JetBrains IDEs among remote editors (pingdotgg#17291) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): recognize authenticated GitHub Enterprise hosts (pingdotgg#11059) Co-authored-by: Claude Code <noreply@anthropic.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> * fix(connect): relay client updates itself and skips incompatible cloudflared (pingdotgg#17275) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(shared): relay client install waits out a brief Windows file lock (pingdotgg#16998) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(shared): release relay install locks on cancellation (pingdotgg#10585) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * chore(shared): bump managed cloudflared to 2026.10.0 (pingdotgg#11184) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(shared): bound cloudflared download with 10-minute timeout (pingdotgg#14139) Co-authored-by: Kevin Rajan <kevin@kvnloo.dev> * refactor(provider-core): add provider-core and provider-testing packages (pingdotgg#17299) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(settings): drop the legacy per-driver providers map (pingdotgg#17300) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-pi): move Pi into its own provider package (pingdotgg#17302) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * feat(models): tell users when a CLI update unlocks a new model (pingdotgg#17307) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): collapsed composer reserves room for wide send actions (pingdotgg#17016) * fix(muse): workflow subagents no longer stall on hidden approvals (pingdotgg#17329) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-core): share attachment prompts, notifications, and event loggers (pingdotgg#17330) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): file previews handle downloads, in-page links, and repo paths, and favicons stop leaking internal hosts (pingdotgg#16950) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): environment-hosted browser tabs behave like a normal browser (pingdotgg#16963) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(desktop): browser tab fixes for fullscreen, shortcuts, links, reload and hidden tabs (pingdotgg#16961) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): desktop opens remote environments' browser tabs locally (pingdotgg#17316) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(desktop): the t3 command warns instead of installing behind another t3 (pingdotgg#17351) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): images, video, HTML and PDF preview in a thread before its first message (pingdotgg#17352) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-muse): move Muse Code into its own provider package (pingdotgg#17331) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): semantic branch naming hint lines up with its setting (pingdotgg#16972) * fix(mobile): restore chat image previews in the v5 stack (pingdotgg#17361) * feat(mobile): fade working threads and match web's status labels (pingdotgg#17368) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): agent browser tools stop bloating history, fall back sensibly, and respect ownership (pingdotgg#16956) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): add room for thread timeline markers (pingdotgg#17372) * fix(web): drop sidebar context before cancelling pointer drag (pingdotgg#17373) * refactor(providers): namespace-import service modules in core, Muse, Pi, and testing (pingdotgg#17375) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(auth): show connection permissions and enforce session lifetime (pingdotgg#17370) Co-authored-by: Bear Huddleston <bear@bearhuddleston.dev> * refactor(provider-opencode): move OpenCode into its own provider package (pingdotgg#17345) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-cursor): move Cursor into its own provider package (pingdotgg#17349) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-acp): move the shared ACP adapter into its own package (pingdotgg#17354) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * refactor(provider-grok): move Grok into its own provider package (pingdotgg#17357) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): speed up long thread message sync (pingdotgg#17387) * fix(desktop): cancel backend pipe reads to avoid slow shutdown (pingdotgg#17386) * refactor(providers): adapter factories yield their services (pingdotgg#17381) * fix(web): show a row spinner instead of a banner when expanding a folder (pingdotgg#17378) * fix(server): a timed-out browser drag no longer exits the server (pingdotgg#17360) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(server): a logged-out Claude CLI no longer reports as authenticated (pingdotgg#15459) * fix(server): Pi loads every selected skill without losing prompt text (pingdotgg#17194) * fix(server): keep the Claude MCP token out of process arguments (pingdotgg#17408) * fix(server): reconcile Pi native session rewinds (pingdotgg#13839) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * test(provider-pi): cover continuation offers through the driver (pingdotgg#17407) * refactor(provider-acp-registry): move the ACP Registry into its own package (pingdotgg#17405) * fix(server): relay client updates no longer drop the host off T3 Connect (pingdotgg#17366) Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com> Co-authored-by: PR Batch Tester <agent@local.test> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Jono Kemball <Noojuno@users.noreply.github.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com> Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: chise <lqff.yt@gmail.com> Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com> Co-authored-by: maria <maria@kuuro.net> Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com> Co-authored-by: jztmanyl <jztmanyl@gmail.com> Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com> Co-authored-by: Grzegorz Mandziak <4248465+alimek@users.noreply.github.com> Co-authored-by: Scott Norteman <snorteman@gmail.com> Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com> Co-authored-by: Aaron Queen <bompus@users.noreply.github.com> Co-authored-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com> Co-authored-by: Kevin Rajan <kevin@kvnloo.dev> Co-authored-by: Theo Browne <me@t3.gg> Co-authored-by: Daniel Alvim <danielalvim@tuta.io> Co-authored-by: Bear Huddleston <bear@bearhuddleston.dev> Co-authored-by: Yordis Prieto <yordis.prieto@gmail.com>
Problem
The desktop preview sends an invalid User-Agent product token in nightly, stable (Alpha), and development builds. A .NET gateway forwarding the header with
HttpRequestMessage.Headers.Add("User-Agent", value)throwsFormatException, preventing the page from loading.Nightly
0.0.43-nightly.20260929.2428sendsT3Code(Nightly)/0.0.43-nightly.20260929.2428; stable0.0.45sendsT3Code(Alpha)/0.0.45. Parentheses are not allowed in the product-name token by RFC 9110. Electron 44.4.2 derives the native User-Agent fromapp.getName(), removing ASCII spaces but retaining parentheses.Reproduction: open a page in a desktop preview and forward its received User-Agent using:
With the old nightly name, the isolated reproduction reports the same error as the affected gateway:
Change
Configure Electron's internal runtime name as
T3 Code Nightly,T3 Code Alpha, orT3 Code Dev. Electron then generates valid native product tokens, includingT3CodeNightly/0.0.43-nightly.20260929.2428.Keep the existing display name in the About panel and macOS application menu, including the About, Hide, and Quit labels. This menu change is needed to preserve branding when the internal runtime name changes. Electron's internal name override does not change the OS application name or packaged product metadata.
Preview sessions retain Electron's own User-Agent. This preserves the approach established in #7110: no session or request-header overrides, no removal of the app or Electron identity, and no changes to Chromium version or browser hints.
Scope and approval
This uses the very small, focused fix for an obvious bug exception: an invalid HTTP product token causes a reproducible parser failure, and the fix makes the existing native identity valid. The application-menu changes and focused tests belong to that same correction. There are no new settings, browser workflows, or gateway changes.
Searched existing User-Agent and malformed-header reports. #7110 documents the native-identity constraint; #16617 proposes optional browser compatibility settings and addresses a different problem.
Verification
vp test run apps/desktop/src/app/DesktopAppIdentity.test.ts apps/desktop/src/window/DesktopApplicationMenu.test.ts apps/desktop/src/preview/BrowserSession.test.ts: 23 tests passed in three files, including a final run with Node 24.13.1. Covers valid product names for Alpha/Nightly/Dev, preserved display branding and macOS role labels, and the existing native preview identity behavior.pnpm --filter @t3tools/desktop typecheck: passed. File-scopedvp lint,vp fmt --check, andgit diff --check: passed.DesktopAppIdentity.configureand existingBrowserSession.getSession, with a local ASP.NET 10.0.400 SDK endpoint performing the exactHeaders.Addoperation above: five checks passed. The old nightly and stable names were rejected; the fixed nightly, stable, and development names were accepted. Each check verified thatapp.userAgentFallback, session identity,navigator.userAgent, and the actually received request header were identical. Every run used temporary app storage and an ephemeral preview partition.600010console messages were recorded during a 30-second observation. Credentials were not submitted, and full authentication/Turnstile challenge completion was not established.The deployed gateway, a complete packaged T3 client, Windows, and Linux were not exercised. The local endpoint reproduces the reported forwarding failure. Temporary harnesses and evidence are outside the repository.
Prepared with GPT-6.1-Sol using the Codex harness in T3 Code.