- Clear rich memory after plain-only browser and Tauri copies\n- Bind paste-to-replace memory fallback to the current native text\n- Preserve selection when asynchronous native cuts race with selection changes
* refactor(app): isolate system clipboard adapters
- Split browser and Tauri clipboard behavior into focused adapters\n- Inject browser clipboard capabilities into unit-testable operations\n- Remove navigator and document mutation from headless clipboard tests
* refactor(app): delegate browser clipboard fallbacks
- Use copy-to-clipboard for modern rich MIME writes and execCommand fallback\n- Keep OpenPencil-specific HTML and plain-text payload construction at the adapter boundary\n- Remove hand-rolled browser capability and selection handling
* test(clipboard): verify rich browser menu round-trip
- Exercise copy from the browser Edit menu under a user gesture\n- Verify text/html and text/plain ClipboardItem formats\n- Paste the system clipboard payload back into the canvas
* refactor(clipboard): reduce adapter surface
- Expose only command dispatch and the injectable system clipboard contract\n- Keep browser and Tauri copy/paste operations private to their adapters\n- Rename the in-memory DataTransfer fallback and share design HTML recognition
* fix(clipboard): harden format and fallback handling
- Require complete OpenPencil or Figma clipboard markers\n- Await browser writes so adapter failures resolve false\n- Write plain-only Tauri payloads as text and reject unrelated clipboard text
* fix(clipboard): reject unrelated current browser data
* fix(clipboard): bind fallbacks to copied selection
- Match cached rich HTML to the current Tauri plain-text fallback\n- Preserve nodes when selection changes during an asynchronous cut\n- Reject unrelated current browser HTML before consulting memory
* fix(clipboard): reuse the shared memory payload type
* fix(clipboard): scan design markers linearly
* fix(clipboard): distinguish unavailable and empty reads
* style(clipboard): use includes for marker closure
* test(clipboard): avoid wall-clock marker assertions
Merges the contributor clipboard fallback fix with maintainer follow-ups for browser cut safety and isolated fallback tests. Selections are preserved when clipboard serialization fails, and clipboard fallback tests no longer depend on host APIs.
Merges the contributor fix with maintainer follow-up coverage. MCP results now treat omitted isError as success, scope detection to mcp__ tools, and preserve generic tool error handling.
* feat(app): make crash recovery configurable
- Add an enabled-by-default persisted recovery preference and General settings control
- Stop recovery writes and remove the active document snapshot when disabled
- Suppress startup recovery discovery while the preference is disabled
- Cover disabled persistence and re-enable behavior
* fix(i18n): translate recovery preferences
* fix(app): serialize recovery disable cleanup
- Block re-enabled persistence until pending snapshot removal completes
- Preserve disable generations so stale cleanup cannot reset newer recovery state
- Display runtime-overridden recovery state in Settings
- Deep-clone nested preferences before updating recovery
- Register the Vite-owned MCP child as a worktree-prefixed Portless sibling service\n- Inject HTTPS and WebSocket automation URLs into the browser instead of assuming port 7600\n- Isolate development socket and discovery files while preserving fixed-port non-Portless flows
- Carry normalized tool-name arrays through app and development JSON configuration
- Serialize the legacy CSV format only at child-process environment boundaries
- Bound, validate, trim, and deduplicate development tool policy input
- Keep browser root routes compatible with existing editor workflows
- Open the files workspace explicitly from browser navigation while desktop still starts on New tab
- Show storage setup guidance when the unified workspace is not configured
- Keep New tabs provisional so opening or creating a design reuses the active tab
- Separate recent document, storage, menu, worker, and workspace responsibilities
- Add source-aware recents, responsive files UI, loading states, and localized copy
- Preserve native local Open Recent behavior while supporting remote storage history
- Publish explicit effective tool state while retaining disabled tools for Settings
- Classify filesystem writes as side effects and localize category labels
- Stop failed restarts and return precise development control status codes
- Encapsulate app-global runtime state in a testable service
- Serialize health refresh, start, stop, and restart operations
- Validate health metadata and clean state after failures
- Remove duplicated document-access declarations from core tools
- Replace the MCP catalog with typed descriptors, capabilities, and policy
- Emit standard MCP annotations through type-safe registration
- Restart the Vite-managed MCP server with the current authentication, root, and tool settings
- Keep the development control endpoint protected by the local token
- Cover explicit no-auth and configured-root environment propagation
- Persist whether the desktop MCP server requires a bearer token
- Start localhost MCP without a generated token when authentication is disabled
- Warn in Settings and require a server restart to apply the preference
- Collect tool metadata through the existing registration wrapper
- Expose the runtime catalog to Settings without a parallel MCP-only list
- Keep disabled tools discoverable so they can be re-enabled
- Persist an optional MCP filesystem root selected from Settings
- Default file-scoped tools to the user home directory
- Apply the configured root when the desktop MCP server restarts
- Declare inspection or modification access on every canonical tool definition
- Add bulk category controls while preserving individual disabled-tool storage
- Keep runtime availability separate from document access semantics