v0.13.6
Bug Fixes
-
ChatGPT Plus title regeneration recovers from unavailable mini models — If the account rejects the configured utility model (such as
gpt-5.4-mini), title generation and regeneration now fall back to compatible models from the same connection's provider, including the session's selected model. This also works for sessions reopened after a restart; working mini models and API-key connections keep their existing first choice. -
Transcript paths no longer gain stray dots — Fixes #1056.
session.jsonlstored tool paths such as./Users/…or/Volumes./home/…because paths were relativized against the app's process directory, which is/when launched from Finder. Tool inputs and results are now relativized against the session's working directory only, and paths outside it stay absolute. Thanks to @samflorentine for the report. -
Header-authenticated API sources send the key, not a JSON object — Fixes #1067. A credential entered through the multi-header prompt for a single-header source went on the wire as
{"x-goog-api-key":"…"}, andsource_testreported success anyway. Credential parsing and header assembly are now shared between the runtime andsource_test, so a passing authenticated test means real calls authenticate, and the test shows the API's error body on 400, 401 and 403. Thanks to @CoachSteff for the report. -
allowedWritePathsapplies in Ask to Edit mode — Fixes #1065. Writes inside the workspace allowlist no longer prompt in Ask to Edit, matching Explore mode, so automations can run there instead of in Execute. Thanks to @ZerVisionGo for the report and the fix (PR #1066). -
Messages sent during a Pi
/compactare delivered — Fixes #1058 and #1060. A message sent while a manual compaction ran was steered into a turn with nothing to receive it and vanished; it is now queued and replayed once compaction finishes. A compaction that exceeds its 300 s deadline is cancelled in the Pi subprocess instead of running on, and the subprocess no longer spends that whole deadline waiting on a stuck earlier compaction. Thanks to @Code-MonkeyZhang and @xunhuang071-source for the reports. -
Built-in browser recovers after closing popups — Fixes #1059. Closing a popup window and then terminating the browser left a dead instance behind, and every later
browser_toolcall failed with "Object has been destroyed" until the app restarted. Teardown no longer touches destroyed windows and always completes. Thanks to @Code-MonkeyZhang for the report. -
Connection test works when editing a saved connection — Fixes #1048. Testing an edited connection without retyping the key sent the masked placeholder and failed. The stored key is used, and a missing key asks you to re-enter it. Thanks to @Code-MonkeyZhang for the report and the fix (PR #1049).
-
CRAFT_CONFIG_DIRmoves everything — Fixes #1062. Twenty code paths still used~/.craft-agentregardless ofCRAFT_CONFIG_DIR, so a second instance shared credentials, workspaces, logs and window state with the default one. Every path now derives from the one configured directory. Thanks to @ZerVisionGo for the report and the fix (PR #1061). -
Interceptor debug log is bounded — Fixes #1033. In development builds run with
--debug,~/.craft-agent/logs/interceptor.loggrew without limit and recorded full request bodies. It now rotates at 32 MiB, caps single entries, and omits request bodies unlessCRAFT_DEBUG_FULL_BODIES=1. Packaged builds never wrote this log. Thanks to @2314254971 for the report and @lau0708 for the fix (PR #1063). -
MCP OAuth works with resource-bound servers — Fixes #1054. Servers that scope tokens to a resource (RFC 8707 with RFC 9728 metadata) rejected every token because the
resourceparameter was never sent. It is now sent on the authorization, token and refresh requests, taken from the server's protected resource metadata, and dropped automatically for servers that reject it. API sources with manual OAuth config can setoauth.resource. Thanks to @alansmodic for the report and the fix (PR #1055). -
Slack sign-in works again on desktop — Fixes #1068. Slack rejected the desktop OAuth redirect because a relay URL it did not have registered was used. Desktop flows use the registered Slack relay again. Thanks to @awabrh for the report.
-
MCP source connection failures are now visible — Fixes #1071. When an MCP source failed to connect, the error was silently dropped at two layers (debug-level log in the pool, discarded return value in the agent). Failures now emit a
console.warnnaming each affected source, and connections are established in parallel so one slow stdio spawn no longer delays the rest. Thanks to @szymongalecki for the report. -
Pi/DeepSeek warns when reasoning consumes the full output budget — Fixes #1072. With thinking enabled at high or max levels, DeepSeek models count reasoning tokens against the shared output budget; at large context sizes the turn can produce zero text with no visible error. The agent now logs a warning when output tokens are present but text is empty, pointing at the likely cause and remediation (lower the thinking level or start a fresh session). Thanks to @szymongalecki for the report.