github craft-ai-agents/craft-agents-oss v0.13.6

3 hours ago

v0.13.6

Bug Fixes

  • ChatGPT Plus title regeneration recovers from unavailable mini models — If the account rejects the configured utility model (such as gpt-5.4-mini), title generation and regeneration now fall back to compatible models from the same connection's provider, including the session's selected model. This also works for sessions reopened after a restart; working mini models and API-key connections keep their existing first choice.

  • Transcript paths no longer gain stray dots — Fixes #1056. session.jsonl stored tool paths such as ./Users/… or /Volumes./home/… because paths were relativized against the app's process directory, which is / when launched from Finder. Tool inputs and results are now relativized against the session's working directory only, and paths outside it stay absolute. Thanks to @samflorentine for the report.

  • Header-authenticated API sources send the key, not a JSON object — Fixes #1067. A credential entered through the multi-header prompt for a single-header source went on the wire as {"x-goog-api-key":"…"}, and source_test reported success anyway. Credential parsing and header assembly are now shared between the runtime and source_test, so a passing authenticated test means real calls authenticate, and the test shows the API's error body on 400, 401 and 403. Thanks to @CoachSteff for the report.

  • allowedWritePaths applies in Ask to Edit mode — Fixes #1065. Writes inside the workspace allowlist no longer prompt in Ask to Edit, matching Explore mode, so automations can run there instead of in Execute. Thanks to @ZerVisionGo for the report and the fix (PR #1066).

  • Messages sent during a Pi /compact are delivered — Fixes #1058 and #1060. A message sent while a manual compaction ran was steered into a turn with nothing to receive it and vanished; it is now queued and replayed once compaction finishes. A compaction that exceeds its 300 s deadline is cancelled in the Pi subprocess instead of running on, and the subprocess no longer spends that whole deadline waiting on a stuck earlier compaction. Thanks to @Code-MonkeyZhang and @xunhuang071-source for the reports.

  • Built-in browser recovers after closing popups — Fixes #1059. Closing a popup window and then terminating the browser left a dead instance behind, and every later browser_tool call failed with "Object has been destroyed" until the app restarted. Teardown no longer touches destroyed windows and always completes. Thanks to @Code-MonkeyZhang for the report.

  • Connection test works when editing a saved connection — Fixes #1048. Testing an edited connection without retyping the key sent the masked placeholder and failed. The stored key is used, and a missing key asks you to re-enter it. Thanks to @Code-MonkeyZhang for the report and the fix (PR #1049).

  • CRAFT_CONFIG_DIR moves everything — Fixes #1062. Twenty code paths still used ~/.craft-agent regardless of CRAFT_CONFIG_DIR, so a second instance shared credentials, workspaces, logs and window state with the default one. Every path now derives from the one configured directory. Thanks to @ZerVisionGo for the report and the fix (PR #1061).

  • Interceptor debug log is bounded — Fixes #1033. In development builds run with --debug, ~/.craft-agent/logs/interceptor.log grew without limit and recorded full request bodies. It now rotates at 32 MiB, caps single entries, and omits request bodies unless CRAFT_DEBUG_FULL_BODIES=1. Packaged builds never wrote this log. Thanks to @2314254971 for the report and @lau0708 for the fix (PR #1063).

  • MCP OAuth works with resource-bound servers — Fixes #1054. Servers that scope tokens to a resource (RFC 8707 with RFC 9728 metadata) rejected every token because the resource parameter was never sent. It is now sent on the authorization, token and refresh requests, taken from the server's protected resource metadata, and dropped automatically for servers that reject it. API sources with manual OAuth config can set oauth.resource. Thanks to @alansmodic for the report and the fix (PR #1055).

  • Slack sign-in works again on desktop — Fixes #1068. Slack rejected the desktop OAuth redirect because a relay URL it did not have registered was used. Desktop flows use the registered Slack relay again. Thanks to @awabrh for the report.

  • MCP source connection failures are now visible — Fixes #1071. When an MCP source failed to connect, the error was silently dropped at two layers (debug-level log in the pool, discarded return value in the agent). Failures now emit a console.warn naming each affected source, and connections are established in parallel so one slow stdio spawn no longer delays the rest. Thanks to @szymongalecki for the report.

  • Pi/DeepSeek warns when reasoning consumes the full output budget — Fixes #1072. With thinking enabled at high or max levels, DeepSeek models count reasoning tokens against the shared output budget; at large context sizes the turn can produce zero text with no visible error. The agent now logs a warning when output tokens are present but text is empty, pointing at the likely cause and remediation (lower the thinking level or start a fresh session). Thanks to @szymongalecki for the report.

Don't miss a new craft-agents-oss release

NewReleases is sending notifications on new releases.