- Add a dedicated MCP connections destination to Settings navigation
- Keep ModelsPanel focused on model profiles and assignments
- Update documentation, changelog, and browser coverage for the new location
* feat(acp): add reusable MCP connections
- Store named Streamable HTTP connections separately from model providers
- Keep bearer tokens in the credential manager and resolve them per ACP session
- Add localized settings, validation, documentation, and focused coverage
* test(acp): harden MCP connection workflow
- Label credential inputs and confirm destructive connection removal
- Exercise MCP server delivery through an in-memory ACP session
- Extend the browser smoke test to cover accessible input and confirmation flows
* fix(acp): validate MCP connection lifecycle
- Keep non-browser storage initialization in memory and restore the German model copy
- Reject persisted name collisions and invalid draft IDs
- Preserve connections on credential failures and require credentials before enablement
* perf(app): defer inactive Code panel generation
- Skip JSX serialization and syntax highlighting while the Code tab is hidden
- Restore code generation when desktop or mobile users activate the tab
- Cover large Design-tab selections without hidden Code-panel work
* test(app): cover deferred Code panel updates
- Keep mobile JSX generation inactive while the drawer is closed
- Measure the complete two-frame inactive selection flow
- Verify mobile Code output refreshes when the drawer reopens
- Show complete user messages with every image immediately after sending
- Analyze up to four bounded images without adding pixels to Design context
- Organize image handling under the extensible attachment domain
- Add a canonical 24, 28, and 32 pixel control scale
- Rebuild the AI prompt as a multiline compound input
- Keep property-panel icon actions at the explicit compact size
- Route bounded selection renders through the optional Vision model
- Return compact text findings without retaining image data in Design chat history
- Bound MCP and AI image exports by their longest pixel edge
- Track loaded font provenance and aggregate page-level face fidelity, including synthesized styles and active Inter substitutions
- Add a localized warning banner with retry and affected-layer actions
- Expose get_font_status through the Figma API and MCP tool registry
- Serialize recovery cleanup with active snapshot writes
- Preserve version ordering across autosave, restore, and cleanup
- Fall back to memory when IndexedDB operations fail
- Persist debounced FIG snapshots for source-less documents in IndexedDB
- Restore or discard orphaned snapshots from the editor startup dialog
- Clear recovery data after successful saves and explicit tab closure
- Redact and bound provider error details in copied logs
- Avoid repeat toasts after locale changes
- Show reasoning effort only for supported providers
- Report credit and output-limit failures through localized toasts and debug logs
- Persist optional provider-specific reasoning effort on model profiles
- Classify insufficient-credit connection tests and cover failure diagnostics
* fix(tauri): prevent Windows font loading crashes
- Return native font files over binary Tauri IPC instead of JSON byte arrays
- Resolve desktop script fallbacks without parsing large system fonts in JavaScript
* fix(core): restore quality checks
- Use the shared Vector primitive for render-bound offsets
- Remove unsupported SLICE handling from SceneGraph rescaling
- Drop an unused generated-text test binding
* chore: address font fix review
- Place the release note under the Fixed heading
- Name fallback resolution options and use the shared Tauri constant
* fix(mcp): close orphaned servers that no app ever claims
- Add ServerOptions.appAttachTimeoutMs: if no app registers within this
window after startup, the server closes itself and removes its
discovery file, instead of squatting the port indefinitely.
- Wire it through the openpencil-mcp-http CLI as
OPENPENCIL_MCP_APP_TIMEOUT_MS (opt-in, unset/0 disables it — a bare
CLI invocation for manual testing should not self-terminate).
- The desktop app opts in with a 30s timeout when it spawns the server.
Without this, a server that outlives its spawning app (renderer crash,
forced reload) keeps holding its port with a stale discovery file. The
app's liveness check only asks whether something answers /health, not
whether an app has ever registered (see /health's no_app status) — so
every later launch finds the orphan already listening and defers to
it, and MCP tool calls fail with "app is not connected" until someone
manually kills the orphaned process. Closing self-caused orphans at
the source means the next launch finds no discovery file and takes
the normal fresh-spawn path.
Fixes#488
* fix(mcp): clean up servers after app disconnects
- Re-arm the orphan watchdog when the registered app disconnects
- Cancel pending shutdown when the app reconnects within the grace period
- Reject timeout values that overflow the runtime timer range
* test(mcp): make watchdog reconnect coverage deterministic
- Wait for the disconnected health state before reconnecting
- Report distinct safe-integer and timer-range validation errors
---------
Co-authored-by: swe-sanad <sanad.arousi@export119.com>
* fix(storage): polish workspace and connection feedback
- Move Refresh into the Storage Workspace header and keep shell theme actions available outside the editor route
- Split native shell and editor menu listeners behind the app shell
- Replace permanent CORS controls and inline connection results with standard toasts and clearer browser guidance
* fix(app): harden native menu routing
- Dispose menu listeners that finish registering after their Vue scope closes
- Mark shell-owned actions in the shared menu schema instead of duplicating IDs
- Cover route-neutral shell action classification
- Use macOS predefined copy, cut, and paste menu items so WebKit routes accelerators to focused editing controls\n- Keep canvas clipboard events handled by OpenPencil and recognize composed contenteditable targets\n- Cover editable input and nested contenteditable event paths
- Localize import, collaboration, settings, color, font, and accessibility text across supported locales
- Synchronize the document language through reactive Unhead attributes
- Translate connection failures, browser fallbacks, notifications, and save prompts
- Load Prism JSX only after exposing the Prism runtime
- Treat unavailable MCP automation as optional during startup
- Connect the desktop automation bridge only after MCP is ready
- Discard stale provider refreshes and queued previews
- Guard malformed deflate data and listener failures
- Start periodic refresh without an immediate callback
- Validate ranged thumbnail payloads and S3 bounds
- Invalidate stale previews and expose loading errors
- Document the public document workspace composable
- Load embedded Figma thumbnails through bounded S3 byte-range requests
- Add a headless Vue workspace composable with lazy previews and refresh lifecycle
- Cache local previews and refresh the workspace after saves and synchronization
- Cover UI identifiers in the acronym guardrail
- Preserve FIG thumbnail and metadata values through archive parsing
- Use Vue-compatible acronym prop attributes
- Rename first-party API, RPC, JSON, CORS, SVG, JSX, and related identifiers to preserve acronym casing
- Keep upstream and serialized boundary names unchanged
- Add a lint guardrail and migration notes for exported APIs
- Separate model, connection, and advanced settings
- Resolve capabilities and output limits from provider catalogs
- Keep custom model compatibility declarations explicit
- Populate subsequent lazy pages in a development-only persistent worker
- Journal created, updated, and deleted graph state as field deltas
- Invalidate stale worker replicas after authoritative graph mutations
- Fall back to synchronous population when the worker is unavailable
- Centralize design-profile eligibility for the selector, role assignment, fallback, and tests
- Keep built-in provider model selection intact while switching saved custom profiles
- Add localized accessible labeling and constrain long profile names
The chat model chip is a dropdown for built-in providers but a static label
for OpenAI-compatible and custom-model setups, so anyone using a custom
endpoint had to open Settings to change models -- even with several models
already configured.
Add a profile switcher that reassigns the design role from the chat panel.
It lists saved profiles that can use tools, shows the profile name rather
than the raw model ID, and badges the vision-capable ones. It writes the
same assignments.design field the Settings dropdown does, so the two stay in
sync.
Only renders when more than one tools-capable profile exists; a single
profile keeps the existing label. Built-in providers keep ProviderModelSelect
unchanged.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
- Replace the full-width editor header action with a shared browser and native menu command
- Localize the destination and cover menu schema and browser navigation
Once a document is opened from the storage workspace there is no way back
to it: the only in-app route is Settings -> Cloud storage -> Open workspace,
and the desktop shell has no browser back at all.
Add an explicit button in the shared header row (rendered on both web and
Tauri, unlike the File/Edit menubar below it) that routes to /storage. It is
a fixed destination rather than history navigation, so it behaves the same
on both platforms.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Anthropic omits Access-Control-Allow-Origin unless the caller sends
anthropic-dangerous-direct-browser-access, so the web build failed with an
opaque "Could not reach this endpoint from the browser" for the anthropic
provider. @ai-sdk/anthropic does not send the header and neither did our
adapter.
Send it from the browser only. The desktop build routes through tauriFetch
and is not subject to CORS, so it does not need to advertise browser access.
Fixes#436
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
- Resolve the active graph at action time and map edit geometry through full world transforms
- Regenerate live path fills and discard stale imported stroke outlines after edits
- Preserve fill and stroke geometry through resize previews, undo, and redo
- Cover graph replacement, nested transforms, edit history, resizing, and CanvasKit output
Co-authored-by: Rob Coenen <753704+rcoenen@users.noreply.github.com>
- Export text and basic shapes as editable PowerPoint elements
- Rasterize unsupported geometry, effects, masks, and clipped content for fidelity
- Support app and CLI exports across multiple pages
Co-authored-by: TKman <102001532+greekr4@users.noreply.github.com>
- Default fresh browser sessions to encrypted credential persistence with an explicit session-only opt-out
- Keep API-key links left-aligned, legible, and limited to their text click target
- Update credential guidance and browser coverage