Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
91 commits
Select commit Hold shift + click to select a range
d625e58
chore(deps): bump agent-client-protocol from 0.11.1 to 0.12.1 (#9381)
dependabot[bot] May 23, 2026
8689fdf
chore(deps): bump image from 0.24.9 to 0.25.10 (#9383)
dependabot[bot] May 23, 2026
ce004f7
fix(agents): serialize per-session agent creation to stop duplicate M…
fresh3nough May 23, 2026
c4d64d1
Fix desktop chat search session limiting (#9366)
angiejones May 24, 2026
e1cc44f
Build summon instructions per turn (#9329)
DOsinga May 25, 2026
ba16de9
docs: stats update (#9410)
angiejones May 25, 2026
a11843a
Simplify UI customization (#9353)
DOsinga May 26, 2026
6d544e7
chore(deps): bump qs from 6.14.2 to 6.15.2 in /evals/open-model-gym/m…
dependabot[bot] May 26, 2026
bf0da95
Add Turkish desktop locale (#9392)
seneroner77-cmd May 26, 2026
27dc0d5
Improve dependency hygiene (#9360)
jh-block May 26, 2026
dcdc7f6
fix(desktop): stop the main window growing taller on every launch (#9…
officialasishkumar May 26, 2026
b332f50
Russian language support (#9406)
besdar May 26, 2026
b0cd61a
chore(release): bump version to 1.36.0 (minor) (#9417)
github-actions[bot] May 26, 2026
7dc904e
add databricks ai gateway provider (#9274)
baxen May 26, 2026
1749354
Prefer goose aliases for Databricks v2 inventory (#9430)
baxen May 27, 2026
794402d
fix(ci): build linux x86_64 standard inside manylinux_2_28 for glibc …
88plug May 27, 2026
d90b349
feat: add /model slash command to CLI for session model switching (#8…
baxen May 27, 2026
27b41d9
local inference: stricter GGUF requirements, auto detection of tool c…
jh-block May 27, 2026
d017295
fix: tolerate missing responses output (#9449)
angiejones May 27, 2026
4f43ae4
fix(ui): preserve pending env vars in Add Extension form (#9285)
williams145 May 27, 2026
10ac6b1
feat: make tool output size limit configurable via GOOSE_MAX_TOOL_RES…
DOsinga May 27, 2026
1125e8d
fix: make azure api-version query param optional (#9221)
DOsinga May 27, 2026
35d1fc7
fix(desktop): start new chat in current window from recipe param moda…
michaelneale May 27, 2026
a18b92e
fix(desktop): refresh provider list in Switch Models picker (#9408)
officialasishkumar May 27, 2026
4c88f4b
feat(providers): add Alibaba (Qwen via DashScope) declarative provide…
jezweb May 27, 2026
e9b0d92
feat(providers): add Perplexity as a declarative OpenAI-compatible pr…
jliounis May 27, 2026
c9945bc
chore(deps): bump sha2 from 0.10.9 to 0.11.0 (#8963)
dependabot[bot] May 27, 2026
9c403b1
refactor: convert desktop v1 and goose-server extensions to ACP+ (#9448)
alexhancock May 27, 2026
27d68ba
doc: Add Scaleway provider (#9423)
Quentinchampenois May 28, 2026
d10d009
CLI to list skills with token counts (#9326)
jamadeo May 28, 2026
2116f88
feat: add `tui` feature flag to gate the tui command (#9428)
r0x0d May 28, 2026
1cb5cb0
Add Scholar Sidekick MCP extension (#9433)
mlava May 28, 2026
104cc17
Add ACP session system prompt setter (#9478)
baxen May 29, 2026
a3bdb91
fix(acp): forward ACP server context window size to clients (#9455)
matt2e May 29, 2026
25ff547
Expose raw provider supported models over ACP (#9475)
baxen May 29, 2026
13f7be2
feat: replay acp images on session load (#9496)
kalvinnchau May 29, 2026
8af2f76
feat(providers): add xAI SuperGrok OAuth subscription provider (#9420)
michaelneale Jun 1, 2026
5508079
chore: update canonical model registry (#9551)
baxen Jun 1, 2026
5e160e5
Honor blocking Stop hook decisions (#9468)
johnmatthewtennant Jun 1, 2026
f69a178
fix(otel): skip OTLP signals when protocol=grpc to avoid background-t…
joahg Jun 1, 2026
cd8f718
Fix scheduled recipe session params (#9553)
angiejones Jun 1, 2026
586bb15
fix(extension-manager): forward custom headers through OAuth connect …
hydrosquall Jun 2, 2026
942a456
Revert "refactor: convert desktop v1 and goose-server extensions to A…
alexhancock Jun 2, 2026
fdc1994
chore(release): bump version to 1.37.0 (minor) (#9557)
github-actions[bot] Jun 2, 2026
7982086
Pick the last canonical model (#9568)
DOsinga Jun 2, 2026
030dbb0
feat(security): Add directionality to egress logging (#9546)
dorien-koelemeijer Jun 2, 2026
502ee50
chore(release): release version 1.37.0 (#9565)
github-actions[bot] Jun 2, 2026
cd12199
Bench marking (#9465)
DOsinga Jun 2, 2026
003252f
Import sesssions (#9474)
DOsinga Jun 2, 2026
9626b4c
Replace review subprocess timeout with turn limits (#9571)
lucasconti-dev Jun 2, 2026
30034b9
Add Hugging Face OAuth support, add auth tab to settings (#9552)
jh-block Jun 3, 2026
f6caaa0
Fixed intermittent missing extension override on ui and cleanup (#9575)
lifeizhou-ap Jun 3, 2026
08e7480
Use LRU cache for token counting (#9586)
jh-block Jun 3, 2026
83a4abf
fix: quote release PR search phrase in pre-release.sh (#9573)
alexhancock Jun 3, 2026
0e4a367
chore(deps): bump the cargo-minor-and-patch group across 1 directory …
dependabot[bot] Jun 3, 2026
302dafc
chore(deps): bump mockall from 0.13.1 to 0.14.0 (#9511)
dependabot[bot] Jun 3, 2026
1ab48f5
chore(deps): bump pkcs8 from 0.10.2 to 0.11.0 (#9510)
dependabot[bot] Jun 3, 2026
dc3a63a
chore(deps): bump strum from 0.27.2 to 0.28.0 (#9509)
dependabot[bot] Jun 3, 2026
1205a4a
chore(deps): bump clap_mangen from 0.2.33 to 0.3.0 (#9508)
dependabot[bot] Jun 3, 2026
1a52f21
chore(deps): bump tokenizers from 0.21.4 to 0.22.2 (#9503)
dependabot[bot] Jun 3, 2026
34f33fc
chore(deps): bump EmbarkStudios/cargo-deny-action from 2.0.19 to 2.0.…
dependabot[bot] Jun 3, 2026
9646f70
chore(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.3 (#9501)
dependabot[bot] Jun 3, 2026
1cc5aa6
chore(deps): bump pnpm/action-setup from 6.0.5 to 6.0.8 (#9500)
dependabot[bot] Jun 3, 2026
dc59e41
Lifei/acp session setup refactor (#9488)
lifeizhou-ap Jun 4, 2026
6251e56
feat(sdk): minimal uniffi setup for cross language sdk (#9593)
alexhancock Jun 4, 2026
ec519ee
feat: Only send custom notifications when ACP client specifies this c…
lifeizhou-ap Jun 4, 2026
65b72b2
refactor: remove dead component and useNavigationSessions cleanup (#9…
lifeizhou-ap Jun 5, 2026
2f99664
feat: acp methods for config extensions (#9581)
lifeizhou-ap Jun 5, 2026
826f13f
create goose-providers crate with canonical models, conversation and …
jamadeo Jun 5, 2026
4904e3c
Image read tool (#9607)
DOsinga Jun 5, 2026
e5fd568
move formats/openai.rs into goose-providers crate, along with several…
jamadeo Jun 8, 2026
8eb6cd6
fix: compatibility of config extension acp call in TUI (#9683)
lifeizhou-ap Jun 9, 2026
0ab4b84
chore: pause tui release (#9685)
lifeizhou-ap Jun 9, 2026
e309083
fix: goose-sdk release compat check with new schema (#9697)
lifeizhou-ap Jun 9, 2026
f4ecdae
feat: use acp list sessions and manage sessions in Desktop (#9687)
lifeizhou-ap Jun 9, 2026
d396767
chore: refresh canonical model registry (#9709)
baxen Jun 9, 2026
f52d717
feat(security): enable prompt injection mitigation by default for int…
dorien-koelemeijer Jun 10, 2026
390dfb8
feat(security): Re-adjust pattern-based detection for prompt injectio…
dorien-koelemeijer Jun 10, 2026
10e665a
expose ACP thinking effort config option (#9711)
morgmart Jun 10, 2026
d2ab786
feat: acp list session with keyword and type filter (#9695)
lifeizhou-ap Jun 10, 2026
9455f8a
docs: fix typo in MCP blog post (#9641)
Nukually Jun 10, 2026
fde407c
Update analyze extension instructions (#9585)
DOsinga Jun 10, 2026
40315b5
feat: steering messages with ACP (#9560)
michaelneale Jun 10, 2026
be91189
feat: use acp search session in Desktop (#9717)
lifeizhou-ap Jun 10, 2026
58185fe
pin goose-sdk package in tui (#9712)
lifeizhou-ap Jun 10, 2026
32722e6
feat: surface Anthropic stream refusals as visible errors (#9724)
kalvinnchau Jun 10, 2026
e8d5622
feat(acp): support GOOSE_SERVER__SECRET_KEY at goose serve acp endpoi…
kalvinnchau Jun 10, 2026
523aaee
feat: custom acp method to get session info (#9729)
lifeizhou-ap Jun 11, 2026
4207b7e
docs: fix stale session navigation/delete docs (Session History) (#9727)
michaelneale Jun 11, 2026
13b6032
Merge remote-tracking branch 'upstream/main' into chore/sync-upstream…
earayu Jun 11, 2026
611ab0e
Fix upstream sync CI failures
earayu Jun 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 6 additions & 3 deletions .github/workflows/pr-website-preview.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,10 @@ jobs:
build:
if: github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
env:
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.PAGES_PR_PREVIEW_CF_ACCOUNT_ID }}
CLOUDFLARE_API_TOKEN: ${{ secrets.PAGES_PR_PREVIEW_CF_API_TOKEN }}
CLOUDFLARE_PAGES_PROJECT_NAME: ${{ secrets.PAGES_PR_PREVIEW_CF_PAGES_PROJECT_NAME }}
permissions:
contents: read
pull-requests: write
Expand Down Expand Up @@ -52,12 +56,10 @@ jobs:
node-version: 22

- name: Deploy preview to Cloudflare Pages
if: env.CLOUDFLARE_ACCOUNT_ID != '' && env.CLOUDFLARE_API_TOKEN != '' && env.CLOUDFLARE_PAGES_PROJECT_NAME != ''
id: cloudflare-pages
working-directory: ./documentation
env:
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.PAGES_PR_PREVIEW_CF_ACCOUNT_ID }}
CLOUDFLARE_API_TOKEN: ${{ secrets.PAGES_PR_PREVIEW_CF_API_TOKEN }}
CLOUDFLARE_PAGES_PROJECT_NAME: ${{ secrets.PAGES_PR_PREVIEW_CF_PAGES_PROJECT_NAME }}
PR_NUMBER: ${{ github.event.number }}
run: |
set -euo pipefail
Expand All @@ -76,6 +78,7 @@ jobs:
echo "preview-url=$preview_url" >> "$GITHUB_OUTPUT"

- name: Comment preview URL
if: steps.cloudflare-pages.outputs.preview-url != ''
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
PREVIEW_URL: ${{ steps.cloudflare-pages.outputs.preview-url }}
Expand Down
3 changes: 2 additions & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

16 changes: 11 additions & 5 deletions crates/goose-cli/src/cli.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1326,7 +1326,7 @@ async fn handle_serve_command(host: String, port: u16, builtins: Vec<String>) ->
use goose::config::paths::Paths;
use std::net::SocketAddr;
use std::sync::Arc;
use tracing::info;
use tracing::{info, warn};

let builtins = if builtins.is_empty() {
vec!["developer".to_string()]
Expand All @@ -1353,12 +1353,18 @@ async fn handle_serve_command(host: String, port: u16, builtins: Vec<String>) ->
goose_platform: GoosePlatform::GooseCli,
additional_source_roots,
}));
let secret_key = std::env::var(GOOSE_SERVER_SECRET_KEY_ENV)
let env_secret = std::env::var(GOOSE_SERVER_SECRET_KEY_ENV)
.ok()
.map(|secret| secret.trim().to_string())
.filter(|secret| !secret.is_empty())
.unwrap_or_else(generate_serve_secret_key);
let router = create_router(server, secret_key);
.filter(|secret| !secret.is_empty());
let require_token = env_secret.is_some();
if !require_token {
warn!(
"{GOOSE_SERVER_SECRET_KEY_ENV} is not set; the ACP endpoint will accept unauthenticated connections"
);
}
let secret_key = env_secret.unwrap_or_else(generate_serve_secret_key);
let router = create_router(server, secret_key, require_token);

let addr: SocketAddr = format!("{}:{}", host, port).parse()?;
info!("Starting ACP server on {}", addr);
Expand Down
16 changes: 16 additions & 0 deletions crates/goose-providers/src/conversation/message.rs
Original file line number Diff line number Diff line change
Expand Up @@ -667,6 +667,11 @@ pub struct MessageMetadata {
pub agent_visible: bool,
#[serde(skip_serializing_if = "Option::is_none")]
pub inference: Option<InferenceMetadata>,
/// Whether this message is a steer injected into an active run. UI-only:
/// surfaced as `_meta.goose.steer` so clients can mark the steer boundary
/// without matching user-visible text. Never sent to providers.
#[serde(default, skip_serializing_if = "std::ops::Not::not")]
pub steer: bool,
}

impl Default for MessageMetadata {
Expand All @@ -675,6 +680,7 @@ impl Default for MessageMetadata {
user_visible: true,
agent_visible: true,
inference: None,
steer: false,
}
}
}
Expand Down Expand Up @@ -743,6 +749,11 @@ impl MessageMetadata {
self.inference = Some(inference);
self
}

pub fn with_steer(mut self) -> Self {
self.steer = true;
self
}
}

#[derive(ToSchema, Clone, PartialEq, Serialize, Deserialize, Debug)]
Expand Down Expand Up @@ -1028,6 +1039,11 @@ impl Message {
self
}

pub fn with_steer(mut self) -> Self {
self.metadata.steer = true;
self
}

pub fn with_inference_if_assistant(self, inference: InferenceMetadata) -> Self {
if self.role == Role::Assistant && self.metadata.inference.is_none() {
self.with_inference(inference)
Expand Down
15 changes: 15 additions & 0 deletions crates/goose-providers/src/errors.rs
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,12 @@ pub enum ProviderError {
details: String,
top_up_url: Option<String>,
},

#[error("Provider refused request: {details}")]
Refusal {
details: String,
category: Option<String>,
},
}

impl ProviderError {
Expand All @@ -58,12 +64,21 @@ impl ProviderError {
ProviderError::NotImplemented(_) => "not_implemented",
ProviderError::EndpointNotFound(_) => "endpoint_not_found",
ProviderError::CreditsExhausted { .. } => "credits_exhausted",
ProviderError::Refusal { .. } => "refusal",
}
}

pub fn is_endpoint_not_found(&self) -> bool {
matches!(self, ProviderError::EndpointNotFound(_))
}

/// Recover a typed `ProviderError` from a streaming decode error, falling
/// back to `RequestFailed` for errors that did not originate as one.
pub fn from_stream_error(error: anyhow::Error) -> Self {
error
.downcast()
.unwrap_or_else(|e| ProviderError::RequestFailed(format!("Stream decode error: {e}")))
}
}

fn is_network_error(err: &reqwest::Error) -> bool {
Expand Down
44 changes: 43 additions & 1 deletion crates/goose-sdk-types/src/custom_requests.rs
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
use agent_client_protocol::schema::McpServer;
use agent_client_protocol::schema::{ContentBlock, McpServer, SessionInfo};
use agent_client_protocol::{JsonRpcRequest, JsonRpcResponse};
use schemars::JsonSchema;
use serde::{Deserialize, Serialize};
Expand Down Expand Up @@ -140,6 +140,30 @@ pub struct SetSessionSystemPromptRequest {
pub text: String,
}

/// Add user input to the currently active prompt without starting a new prompt.
#[derive(Debug, Default, Clone, Serialize, Deserialize, JsonSchema, JsonRpcRequest)]
#[request(
method = "_goose/unstable/session/steer",
response = SteerSessionResponse
)]
#[serde(rename_all = "camelCase")]
pub struct SteerSessionRequest {
pub session_id: String,
#[serde(default)]
pub prompt: Vec<ContentBlock>,
pub expected_run_id: String,
}

#[derive(Debug, Default, Clone, Serialize, Deserialize, JsonSchema, JsonRpcResponse)]
#[serde(rename_all = "camelCase")]
pub struct SteerSessionResponse {
pub run_id: String,
/// Stable id of the queued steer message. The same id later appears as
/// `messageId` on the streamed `UserMessageChunk` (with `_meta.goose.steer`),
/// letting clients correlate a queued steer with its pickup.
pub message_id: String,
}

/// Delete a session.
#[derive(Debug, Default, Clone, Serialize, Deserialize, JsonSchema, JsonRpcRequest)]
#[request(method = "session/delete", response = EmptyResponse)]
Expand Down Expand Up @@ -314,6 +338,7 @@ pub struct PreferencesRemoveRequest {
pub enum PreferenceKey {
#[default]
AutoCompactThreshold,
GooseThinkingEffort,
VoiceAutoSubmitPhrases,
VoiceDictationProvider,
VoiceDictationPreferredMic,
Expand Down Expand Up @@ -449,6 +474,23 @@ pub struct DictationSecretDeleteRequest {
pub provider: String,
}

/// Return list-style metadata for a single session without loading the conversation.
#[derive(Debug, Default, Clone, Serialize, Deserialize, JsonSchema, JsonRpcRequest)]
#[request(
method = "_goose/unstable/session/info",
response = GetSessionInfoResponse
)]
#[serde(rename_all = "camelCase")]
pub struct GetSessionInfoRequest {
pub session_id: String,
}

#[derive(Debug, Clone, Serialize, Deserialize, JsonSchema, JsonRpcResponse)]
#[serde(rename_all = "camelCase")]
pub struct GetSessionInfoResponse {
pub session: SessionInfo,
}

/// Update the project association for a session.
#[derive(Debug, Default, Clone, Serialize, Deserialize, JsonSchema, JsonRpcRequest)]
#[request(method = "_goose/unstable/session/project/update", response = EmptyResponse)]
Expand Down
1 change: 0 additions & 1 deletion crates/goose-server/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,6 @@ tokio-tungstenite = { version = "0.29", default-features = false, features = ["c
url = { workspace = true }
rand = { workspace = true }
hex = { version = "0.4.3", default-features = false, features = ["std"] }
subtle = { version = "2.5", default-features = false, features = ["std"] }
socket2 = { version = "0.6", default-features = false }
fs2 = { workspace = true }
rustls = { workspace = true, optional = true }
Expand Down
32 changes: 2 additions & 30 deletions crates/goose-server/src/auth.rs
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,8 @@ use axum::{
middleware::Next,
response::Response,
};
use subtle::ConstantTimeEq;

fn token_matches(candidate: Option<&str>, expected: &str) -> bool {
candidate
.map(|key| bool::from(key.as_bytes().ct_eq(expected.as_bytes())))
.unwrap_or(false)
}
pub use goose::acp::transport::auth::check_acp_token;
use goose::acp::transport::auth::token_matches;

pub async fn check_token(
State(state): State<String>,
Expand All @@ -36,26 +31,3 @@ pub async fn check_token(
Err(StatusCode::UNAUTHORIZED)
}
}

pub async fn check_acp_token(
State(state): State<String>,
request: Request,
next: Next,
) -> Result<Response, StatusCode> {
let header_token = request
.headers()
.get("X-Secret-Key")
.and_then(|value| value.to_str().ok());

let query_token = request.uri().query().and_then(|query| {
url::form_urlencoded::parse(query.as_bytes())
.find(|(key, _)| key == "token")
.map(|(_, value)| value.into_owned())
});

if token_matches(header_token, &state) || token_matches(query_token.as_deref(), &state) {
Ok(next.run(request).await)
} else {
Err(StatusCode::UNAUTHORIZED)
}
}
11 changes: 1 addition & 10 deletions crates/goose-server/src/openapi.rs
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ use goose::download_manager::{DownloadProgress, DownloadStatus};
use goose::model::ModelConfig;
use goose::permission::permission_confirmation::{Permission, PrincipalType};
use goose::providers::base::{ConfigKey, ModelInfo, ProviderMetadata, ProviderType};
use goose::session::{Session, SessionInsights, SessionType, SystemInfo};
use goose::session::{Session, SessionType, SystemInfo};
use goose_providers::thinking::ThinkingEffort;
use rmcp::model::{
Annotations, Content, EmbeddedResource, Icon, IconTheme, ImageContent, JsonObject,
Expand Down Expand Up @@ -440,14 +440,8 @@ derive_utoipa!(IconTheme as IconThemeSchema);
super::routes::session_events::session_events,
super::routes::session_events::session_reply,
super::routes::session_events::session_cancel,
super::routes::session::list_sessions,
super::routes::session::search_sessions,
super::routes::session::get_session,
super::routes::session::get_session_insights,
super::routes::session::update_session_name,
super::routes::session::delete_session,
super::routes::session::export_session,
super::routes::session::import_session,
super::routes::session::share_session_nostr,
super::routes::session::import_session_nostr,
super::routes::session::update_session_user_recipe_values,
Expand Down Expand Up @@ -522,11 +516,9 @@ derive_utoipa!(IconTheme as IconThemeSchema);
super::routes::session_events::SessionReplyRequest,
super::routes::session_events::SessionReplyResponse,
super::routes::session_events::CancelRequest,
super::routes::session::ImportSessionRequest,
super::routes::session::ShareSessionNostrRequest,
super::routes::session::ShareSessionNostrResponse,
super::routes::session::ImportSessionNostrRequest,
super::routes::session::SessionListResponse,
super::routes::session::UpdateSessionNameRequest,
super::routes::session::UpdateSessionUserRecipeValuesRequest,
super::routes::session::UpdateSessionUserRecipeValuesResponse,
Expand Down Expand Up @@ -587,7 +579,6 @@ derive_utoipa!(IconTheme as IconThemeSchema);
super::routes::config_management::ProviderModelInfoQuery,
Session,
goose::config::goose_mode::GooseMode,
SessionInsights,
SessionType,
SystemInfo,
Conversation,
Expand Down
Loading
Loading