github agegr/pi-web v0.11.0

5 hours ago

中文

这一版有两件大事:侧边栏重新设计,以及修复了一个严重的安全漏洞。请所有用户尽快升级:

npm install -g @agegr/pi-web@latest

⚠️ 安全修复(请尽快升级)

  • 0.11.0 之前的版本,密码保护可以被绕过。 之前每个 npm 包里都带着同一组固定的内部密钥。任何人从公开的 npm 包里读到它,就能绕过 Pi Web 的密码登录和来源检查(Host / Origin)。如果你把 Pi Web 开放到局域网或公网,别人就能直接操作你的 Pi Web:执行命令、读写文件。即使只在本机使用,也建议升级。
    • 新版本每次启动都会生成新的随机密钥,包里的旧值不再有效。
    • 如果安装目录不可写,启动时会打印警告,请换一个可写的位置重新安装。
    • 感谢腾讯玄武实验室 XlabAI Team 报告这个问题。
  • Windows 上,git diff 接口可以通过目录联接(junction)读到允许范围以外的文件,现已修复。(#1039)
  • Next.js 升级到 16.3.8,包含上游的多项安全修复。

侧边栏重新设计

  • 所有项目同时显示:每个项目是一个可折叠的分组,不用再来回切换项目。分组折叠时也能看到运行中和未读会话的数量。
  • 置顶和归档:会话可以置顶,也可以归档(10 秒内可撤销),不用再靠删除来整理列表。可以一键归档某个项目里 7 天前的会话。已归档的会话收到新消息后会自动回到列表。
  • 项目顺序不再乱跳:有新消息时项目不再跳到最上面。拖动分组标题(手机上长按后拖动),或者用菜单里的「上移 / 下移」来调整顺序。置顶、归档和顺序在所有浏览器和设备之间同步。
  • 在侧边栏分叉会话:会话菜单里的「分叉」会把当前分支复制成一个新会话,名称是原标题加一个短后缀。会话运行中也能分叉。
  • 「会话 | 文件」两个标签:文件浏览器占满侧边栏高度。顶部是项目和工作树选择,以及常用按钮:终端、在文件管理器中打开、上传、刷新、显示被忽略的文件、改动视图。在文件标签下,搜索按钮用来搜索文件。
  • 新建会话时直接选择项目和工作树:新会话页面顶部可以切换项目和工作树,已经写好的草稿、图片、所选模型和推理等级都会一起带过去。
  • 会话行改成单行,更紧凑;悬停或右键打开菜单(置顶、重命名、标为已读/未读、归档、删除)。手机上菜单从底部弹出。

新增

  • 把文件拖进聊天框,就会上传到工作目录,并自动 @ 提及这些文件。(#1094)
  • 设置里可以自定义界面字体、代码字体和字重。(#1074)
  • 文件浏览器可以显示被 Git 忽略的文件,变暗显示并注明原因。(#1092)
  • 扩展可以在状态栏放命令按钮,例如 ctx.ui.setStatus("command:/mode toggle", "Build")。(#1030)
  • 子代理配置支持 skills: 预加载指定技能,extensions: 只加载列出的扩展。(#1034, #1091)
  • write 工具卡片直接显示写入的文件内容。(#1024)

修复

  • 扩展对话框和自定义面板会按内容自动加宽,长 SQL、diff 不再挤在窄框里。(#1032)
  • 升级后偶尔打开显示「Pi Web is offline」的问题。(#1089)
  • 上传覆盖文件失败时不再丢失原文件。(#1039)
  • 中文标点旁边的 粗体 和 斜体 能正确显示了。(#1072)
  • 表格里很长的单元格会换行,宽表格仍可横向滚动。(#1056)
  • 运行过程中,上下文用量会及时更新。(#1058)
  • 在 session_start 时才注册的模型提供商(如 pi-claude-bridge)不再从模型列表里消失。(#1071)
  • 只配置了模型列表的提供商会保留原来的 API 协议。(#1050)
  • 子代理的回合上限、结束状态和恢复时的参数处理更准确。(#1093)
  • 其他:切换主题后代码块和文件源码视图的背景不再丢失;从手机宽度切回桌面时恢复侧边栏;删除已经离开的会话后不再被跳到空白聊天;插入的文件提及可以撤销。(#1060, #1059, #1083, #1098)

改进

  • 运行中的转圈动画改用 CSS 实现,GPU 占用明显下降。(#1042)
  • 升级到 pi 1.1.0:
    • 项目的 .pi/mcp.json 可以只调整某个全局 MCP 服务器的开关和暴露方式;「设置 › MCP」里可以只对当前项目开关全局服务器。
    • 手动停止的运行不再播放完成提示音,也不再发送「任务完成」通知。
    • 工具卡片显示真实的执行耗时。

升级注意

  • Azure 提供商改名:pi 1.1 把 azure-openai-responses 改名为 azure。如果你在用它,请在 auth.json(或重新 /login)、models.json 和 settings.json 里改成新名字。
  • 置顶、归档和项目顺序保存在 ~/.pi/agent/pi-web-session-state.json,不会改动会话文件。pi CLI 的 /resume 仍会列出已归档的会话。
  • 强调符号的规则有所调整,少数旧消息里原本显示为粗体或斜体的文字,可能会露出星号。

npm:@agegr/pi-web@0.11.0

English

Two big things in this release: a redesigned sidebar, and a fix for a serious security vulnerability. Everyone should upgrade:

npm install -g @agegr/pi-web@latest

⚠️ Security fixes (please upgrade)

  • Before 0.11.0, the password protection could be bypassed. Every npm package shipped the same fixed internal secrets. Anyone who read them from the public package could skip Pi Web's password login and its origin checks (Host / Origin). If you expose Pi Web on a LAN or the internet, someone else could operate your Pi Web: run commands, read and write files. Upgrade even if you only use it on your own machine.
    • Pi Web now generates fresh random secrets on every start, so the values in the package no longer work.
    • If the install directory is read-only, startup prints a warning. Reinstall Pi Web somewhere writable.
    • Thanks to XlabAI Team of Tencent Xuanwu Lab for reporting it.
  • On Windows, the git diff endpoint could read files outside the allowed folders through a directory junction. Fixed. (#1039)
  • Next.js 16.3.8, with several upstream security fixes.

Redesigned sidebar

  • Every project at once: each project is a collapsible group, so there is no more switching between projects. A collapsed group still shows how many sessions are running or unread.
  • Pin and archive: pin a session, or archive it (undo within 10 s) instead of deleting it to tidy up. Archive a project's sessions older than 7 days in one go. An archived session comes back when it gets a new message.
  • Projects stay where you put them: new activity no longer moves a project to the top. Drag a group header (long-press first on touch), or use Move up / Move down in its menu. Pins, archive and order sync across browsers and devices.
  • Fork from the sidebar: Fork in a session's menu copies its current branch into a new session, named after the original with a short suffix. It works while the session runs.
  • Sessions | Files tabs: the file explorer gets the full sidebar height, with the project and worktree pickers and the common buttons on top: terminal, open in file manager, upload, refresh, show ignored files, changes view. On the Files tab, the search button searches files.
  • Pick the project and worktree when starting a session: the new-session page lets you switch project and worktree, and your draft, images, model and reasoning level come along.
  • Session rows are a single compact line. Hover or right-click for the menu (pin, rename, mark read/unread, archive, delete). On phones the menu slides up from the bottom.

Added

  • Drop files onto the chat to upload them into the working directory and @mention them. (#1094)
  • Custom interface and code font families and weights in Settings. (#1074)
  • The file explorer can show Git-ignored files, dimmed, with the reason. (#1092)
  • Extensions can put command buttons in the status bar, e.g. ctx.ui.setStatus("command:/mode toggle", "Build"). (#1030)
  • Subagent profiles: skills: preloads the named skills, extensions: loads only the listed extensions. (#1034, #1091)
  • write tool cards show the written file as readable text. (#1024)

Fixed

  • Extension dialogs and custom panels widen to fit their content, so long SQL and diffs are no longer squeezed. (#1032)
  • Pi Web sometimes opened on "Pi Web is offline" after an upgrade. (#1089)
  • A failed upload that overwrites a file no longer loses the original. (#1039)
  • Bold and italic next to CJK punctuation render correctly. (#1072)
  • Long table cells wrap, and wide tables still scroll sideways. (#1056)
  • Context usage updates during a run. (#1058)
  • Providers that extensions register at session_start (e.g. pi-claude-bridge) no longer vanish from the model list. (#1071)
  • Providers configured with only a model list keep their API protocol. (#1050)
  • Subagent turn limits, final states and resume options are handled more accurately. (#1093)
  • Also: code blocks and the file source view keep their background across theme switches; the desktop sidebar comes back after a phone-width resize; deleting a session you already left no longer jumps to an empty chat; file mentions can be undone. (#1060, #1059, #1083, #1098)

Improved

  • The running spinner uses CSS animations, which cuts GPU use noticeably. (#1042)
  • pi 1.1.0:
    • A project's .pi/mcp.json can adjust just the switch and exposure of a global MCP server; Settings › MCP can turn a global server on or off for the current project alone.
    • Stopping a run by hand no longer plays the completion sound or sends a "Task finished" notification.
    • Tool cards show the real execution time.

Upgrade notes

  • Azure provider renamed: pi 1.1 renames azure-openai-responses to azure. If you use it, update the name in auth.json (or run /login again), models.json and settings.json.
  • Pins, archive and project order are stored in ~/.pi/agent/pi-web-session-state.json; session files are not touched. pi CLI's /resume still lists archived sessions.
  • Emphasis parsing changed slightly: a few older messages that used to render bold or italic may now show their asterisks.

npm: @agegr/pi-web@0.11.0

Don't miss a new pi-web release

NewReleases is sending notifications on new releases.