Repository navigation
Add WebAuthn/FIDO2/YubiKey passthrough for browser panel - #2
Merged
Merged
Conversation
Implement full WebAuthn support via JS bridge + AuthenticationServices, enabling hardware security key (YubiKey) and passkey authentication in the cmux browser for GSuite, GitHub, GitLab, etc. - WebAuthnBridgeJavaScript: intercepts navigator.credentials.create/get, serializes ArrayBuffer↔base64url, constructs spec-compliant clientDataJSON and PublicKeyCredential response objects - WebAuthnCoordinator: native bridge using ASAuthorizationController with both SecurityKey and Platform credential providers, state machine, origin validation, exhaustive error mapping - Integrated into BrowserPanel.bindWebView and BrowserPopupWindowController so WebAuthn works in both main browser and popup OAuth flows - Added com.apple.developer.web-browser.public-key-credential entitlement - Created cmux.embedded.entitlements for CLI/helper (narrow, no passkey) - Fixed codesign order in release/nightly/build scripts: sign app --deep first, then re-sign embedded binaries with narrow entitlements - Added NSBluetoothAlwaysUsageDescription for cross-device passkey flows Addresses #124, manaflow-ai#1278. Supersedes approach from manaflow-ai#1021, manaflow-ai#1823.
Jesssullivan
added a commit
that referenced
this pull request
Mar 29, 2026
- Update .gitmodules URL from manaflow-ai/ghostty to Jesssullivan/ghostty - Submodule at 90a26469 with GHOSTTY_PLATFORM_LINUX in embedded.zig (Jesssullivan/ghostty#1) and #undef linux macro fix (#2) - Update docs/ghostty-fork.md: document patch #8 (linux Platform variant) and switch header from manaflow-ai to Jesssullivan
Jesssullivan
added a commit
that referenced
this pull request
Mar 29, 2026
* Switch ghostty submodule to Jesssullivan/ghostty with linux Platform - Update .gitmodules URL from manaflow-ai/ghostty to Jesssullivan/ghostty - Submodule at 90a26469 with GHOSTTY_PLATFORM_LINUX in embedded.zig (Jesssullivan/ghostty#1) and #undef linux macro fix (#2) - Update docs/ghostty-fork.md: document patch #8 (linux Platform variant) and switch header from manaflow-ai to Jesssullivan * Scaffold cmux-linux GTK4 application (#77-83) 12 Zig source files implementing the full M5a Terminal MVP scope: Sprint 1 - Foundation: - main.zig: GtkApplication + libghostty init/wakeup/tick integration - app.zig: Runtime callbacks (action, clipboard, close_surface) - surface.zig: GtkGLArea + GHOSTTY_PLATFORM_LINUX surface creation - c_api.zig: @cImport bindings for GTK4, libadwaita, ghostty.h - config.zig: JSON config parser matching macOS schema (427 lines) - build.zig: Links libghostty.so + GTK4 + libadwaita + OpenGL Sprint 2 - Core UI: - window.zig: AdwApplicationWindow + AdwTabView + AdwTabBar - tab_manager.zig: Workspace list mapped to AdwTabView pages - split_tree.zig: Binary tree split pane model with GtkPaned - workspace.zig: Workspace data model (panels, title, color, status) - sidebar.zig: AdwNavigationSplitView + GtkListBox workspace list Sprint 3 - Platform Integration: - socket.zig: Unix domain socket JSON-RPC server (XDG paths) - session.zig: Session snapshot/restore (autosave 8s, atomic writes) Compiles and links on Ubuntu, Fedora 42, and Arch Linux. Closes #77, #78, #79, #80, #81, #82, #83. * Add libghostty + cmux-linux build to CI, fix macOS xcframework linux-ci.yml: Add libghostty build (-Dapp-runtime=none -Drenderer=opengl) and cmux-linux build steps to all 3 Linux jobs (Ubuntu, Fedora, Arch). Add font/rendering deps (freetype, harfbuzz, fontconfig, libpng, mesa). Add zig build test step for config parser unit tests. fork-ci.yml: Build GhosttyKit.xcframework from source instead of downloading from manaflow-ai/ghostty releases. Uses native target for faster CI builds. * Add cmux-linux-build-check NixOS VM test Verify GTK4 + libadwaita runtime libs are present in the NixOS VM. Stepping stone toward full graphical cmux-linux tests (blocked on Nix packaging of the libghostty build chain). Update basic-window-check-gnome TODO to reflect PR #104 progress.
Jesssullivan
added a commit
that referenced
this pull request
Mar 29, 2026
* Switch ghostty submodule to Jesssullivan/ghostty with linux Platform - Update .gitmodules URL from manaflow-ai/ghostty to Jesssullivan/ghostty - Submodule at 90a26469 with GHOSTTY_PLATFORM_LINUX in embedded.zig (Jesssullivan/ghostty#1) and #undef linux macro fix (#2) - Update docs/ghostty-fork.md: document patch #8 (linux Platform variant) and switch header from manaflow-ai to Jesssullivan * Scaffold cmux-linux GTK4 application (#77-83) 12 Zig source files implementing the full M5a Terminal MVP scope: Sprint 1 - Foundation: - main.zig: GtkApplication + libghostty init/wakeup/tick integration - app.zig: Runtime callbacks (action, clipboard, close_surface) - surface.zig: GtkGLArea + GHOSTTY_PLATFORM_LINUX surface creation - c_api.zig: @cImport bindings for GTK4, libadwaita, ghostty.h - config.zig: JSON config parser matching macOS schema (427 lines) - build.zig: Links libghostty.so + GTK4 + libadwaita + OpenGL Sprint 2 - Core UI: - window.zig: AdwApplicationWindow + AdwTabView + AdwTabBar - tab_manager.zig: Workspace list mapped to AdwTabView pages - split_tree.zig: Binary tree split pane model with GtkPaned - workspace.zig: Workspace data model (panels, title, color, status) - sidebar.zig: AdwNavigationSplitView + GtkListBox workspace list Sprint 3 - Platform Integration: - socket.zig: Unix domain socket JSON-RPC server (XDG paths) - session.zig: Session snapshot/restore (autosave 8s, atomic writes) Compiles and links on Ubuntu, Fedora 42, and Arch Linux. Closes #77, #78, #79, #80, #81, #82, #83. * Add libghostty + cmux-linux build to CI, fix macOS xcframework linux-ci.yml: Add libghostty build (-Dapp-runtime=none -Drenderer=opengl) and cmux-linux build steps to all 3 Linux jobs (Ubuntu, Fedora, Arch). Add font/rendering deps (freetype, harfbuzz, fontconfig, libpng, mesa). Add zig build test step for config parser unit tests. fork-ci.yml: Build GhosttyKit.xcframework from source instead of downloading from manaflow-ai/ghostty releases. Uses native target for faster CI builds. * Add cmux-linux-build-check NixOS VM test Verify GTK4 + libadwaita runtime libs are present in the NixOS VM. Stepping stone toward full graphical cmux-linux tests (blocked on Nix packaging of the libghostty build chain). Update basic-window-check-gnome TODO to reflect PR #104 progress. * M5d: Linux packaging — desktop file, Flatpak, DEB, COPR (#97-100) dist/linux/: - com.jesssullivan.cmux.desktop — desktop entry for app launchers - com.jesssullivan.cmux.metainfo.xml — AppStream metadata - icons/ — 16x16, 128x128, 256x256, 512x512 PNGs flatpak/: - com.jesssullivan.cmux.yml — Flatpak manifest targeting org.gnome.Platform 47, builds libghostty + cmux-linux debian/: - control, rules, changelog, copyright — DEB packaging for Ubuntu 24.04+ (libgtk-4-1, libadwaita-1-0 deps) dist/: - cmux.spec — Fedora COPR RPM spec file App ID: com.jesssullivan.cmux (consistent across all formats) Closes #97, #98, #99, #100.
github-actions Bot
pushed a commit
that referenced
this pull request
Apr 13, 2026
The Ghostty upgrade made paste_from_clipboard a performable binding. In performKeyEquivalent, the !isPerformable guard prevented the menu from handling Cmd+V, so keyDown was called directly. Inside keyDown, interpretKeyEvents triggered paste: (clipboard request #1) and then ghostty_surface_key fired the same binding (clipboard request #2), causing a double-paste race that corrupted the output. Remove the !isPerformable exclusion so performable bindings like paste also try the Edit menu first, restoring the single-request flow.
3 tasks
Jesssullivan
added a commit
that referenced
this pull request
Apr 18, 2026
…others
Promotes the three relative-close surface.action variants from stub
"not implemented" errors to working handlers.
Semantics match macOS v2TabAction:
- close_left: remove all surfaces left of the anchor in ordered_panels
- close_right: remove all surfaces right of the anchor
- close_others: remove all surfaces except the anchor
- Pinned surfaces are skipped in all three (skipped_pinned count echoed)
- Focus is forced to the anchor surface after batch removal
- Split tree and widget tree are rebuilt after mutations
Returns {action, surface_id, closed, skipped_pinned} matching the macOS
response shape.
Adds tests_v2/test_surface_action_close_variants.py covering the full
matrix: close_right from middle, close_left from middle, close_others,
pinned-surface skip, and no-op close_left at index 0.
Refs #220 (Sprint A item #2).
This was referenced Apr 18, 2026
Jesssullivan
added a commit
that referenced
this pull request
Apr 18, 2026
…others
Promotes the three relative-close surface.action variants from stub
"not implemented" errors to working handlers.
Semantics match macOS v2TabAction:
- close_left: remove all surfaces left of the anchor in ordered_panels
- close_right: remove all surfaces right of the anchor
- close_others: remove all surfaces except the anchor
- Pinned surfaces are skipped in all three (skipped_pinned count echoed)
- Focus is forced to the anchor surface after batch removal
- Split tree and widget tree are rebuilt after mutations
Returns {action, surface_id, closed, skipped_pinned} matching the macOS
response shape.
Adds tests_v2/test_surface_action_close_variants.py covering the full
matrix: close_right from middle, close_left from middle, close_others,
pinned-surface skip, and no-op close_left at index 0.
Refs #220 (Sprint A item #2).
Jesssullivan
added a commit
that referenced
this pull request
Apr 18, 2026
…others (#227) Promotes the three relative-close surface.action variants from stub "not implemented" errors to working handlers. Semantics match macOS v2TabAction: - close_left: remove all surfaces left of the anchor in ordered_panels - close_right: remove all surfaces right of the anchor - close_others: remove all surfaces except the anchor - Pinned surfaces are skipped in all three (skipped_pinned count echoed) - Focus is forced to the anchor surface after batch removal - Split tree and widget tree are rebuilt after mutations Returns {action, surface_id, closed, skipped_pinned} matching the macOS response shape. Adds tests_v2/test_surface_action_close_variants.py covering the full matrix: close_right from middle, close_left from middle, close_others, pinned-surface skip, and no-op close_left at index 0. Refs #220 (Sprint A item #2).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Addresses upstream #124, manaflow-ai#1278. Supersedes approach from upstream manaflow-ai#1021, manaflow-ai#1823.
Test plan
./scripts/reload.sh --tag webauthn